Skip to content

ephemeral: Drop bwrap, just mount and chroot into the hybrid root - #395

Merged
cgwalters merged 1 commit into
bootc-dev:mainfrom
cgwalters-forge:bot/util-linux-spike
Oct 2, 2026
Merged

cgwalters merged 1 commit into
bootc-dev:mainfrom
cgwalters-forge:bot/util-linux-spike

Conversation

@cgwalters-bot

@cgwalters-bot cgwalters-bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Spike for #329 (comment), an alternative to #329: keep the entrypoint script, but drop bwrap. We're already privileged inside the podman container, which has its own mount and PID namespaces, so no further namespace is needed: the entrypoint mounts /run, /proc, /dev and /var/tmp into /run/tmproot once, in the container's own mount namespace (later podman exec invocations share them), then exec chroot /run/tmproot /run/selfexe container-entrypoint. container-entrypoint handles SIGTERM/SIGINT itself, so the bash supervisor and signal forwarding go away too. The target image only needs mount (util-linux) and chroot (coreutils).

Tested on a devspace (RHEL 10, rootless podman only):

  • bcvk ephemeral run-ssh on centos-bootc stream9 and stream10, on fedora-bootc 43, and on a stream10 derivative with bubblewrap removed;
  • the ephemeral and mount integration tests (integration-tests --test-threads 2 ephemeral, and mount_feature): 32 + 2 passed, 0 failed

Not tested: rootful podman.

The Signed-off-by: Colin Walters <walters@verbum.org> on these commits was added on cgwalters's approval of the review draft: cgwalters-forge#12 (review)

Generated-by: https://github.com/cgwalters/#llms

trap 'kill -TERM $NS_PID 2>/dev/null; exit 0' INT TERM

# Run bwrap in background so we can handle signals; xref
# https://github.com/containers/bubblewrap/pull/586

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Now the questions is do we still need this? I bet we don't and we could just exec?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Right, we do not need it: the container already has its own mount and PID namespaces, so the entrypoint now does the mounts into /run/tmproot once in the container namespace and just exec chroots bcvk (the chroot is still needed for the host /usr). Squashed into 0b07a7e (retitled, your sign-off kept); run-ssh on c9s/c10s/f43 and the ephemeral+mount integration tests pass.

The ephemeral entrypoint only needs the hybrid root (host /usr, the
container's /run, /dev and so on) as /. We are already privileged inside
the podman container, which has its own mount and PID namespaces, so we
want no sandboxing or extra namespaces on top: set up the mounts in the
container's namespace once, then exec bcvk under chroot. That also drops
the backgrounding and signal forwarding, since container-entrypoint
handles SIGTERM and SIGINT itself, and stdin is simply inherited.

bubblewrap is a dependency the target image may not ship, while mount and
chroot come with util-linux and coreutils, which every bootc image has.

Generated-by: AI
Signed-off-by: Colin Walters <walters@verbum.org>
@cgwalters-bot cgwalters-bot changed the title ephemeral: Use util-linux unshare instead of bwrap ephemeral: Drop bwrap, just mount and chroot into the hybrid root Oct 2, 2026

@alexlarsson alexlarsson left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks good to me

@cgwalters
cgwalters merged commit d7ca988 into bootc-dev:main Oct 2, 2026
30 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants