ephemeral: Drop bwrap, just mount and chroot into the hybrid root - #395
Merged
Merged
Conversation
cgwalters
requested changes
Oct 1, 2026
| trap 'kill -TERM $NS_PID 2>/dev/null; exit 0' INT TERM | ||
|
|
||
| # Run bwrap in background so we can handle signals; xref | ||
| # https://github.com/containers/bubblewrap/pull/586 |
Collaborator
There was a problem hiding this comment.
Now the questions is do we still need this? I bet we don't and we could just exec?
Contributor
Author
There was a problem hiding this comment.
Right, we do not need it: the container already has its own mount and PID namespaces, so the entrypoint now does the mounts into /run/tmproot once in the container namespace and just exec chroots bcvk (the chroot is still needed for the host /usr). Squashed into 0b07a7e (retitled, your sign-off kept); run-ssh on c9s/c10s/f43 and the ephemeral+mount integration tests pass.
The ephemeral entrypoint only needs the hybrid root (host /usr, the container's /run, /dev and so on) as /. We are already privileged inside the podman container, which has its own mount and PID namespaces, so we want no sandboxing or extra namespaces on top: set up the mounts in the container's namespace once, then exec bcvk under chroot. That also drops the backgrounding and signal forwarding, since container-entrypoint handles SIGTERM and SIGINT itself, and stdin is simply inherited. bubblewrap is a dependency the target image may not ship, while mount and chroot come with util-linux and coreutils, which every bootc image has. Generated-by: AI Signed-off-by: Colin Walters <walters@verbum.org>
cgwalters-bot
force-pushed
the
bot/util-linux-spike
branch
from
October 2, 2026 05:17
dd28bd4 to
0b07a7e
Compare
alexlarsson
approved these changes
Oct 2, 2026
alexlarsson
left a comment
Contributor
There was a problem hiding this comment.
This looks good to me
cgwalters
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Spike for #329 (comment), an alternative to #329: keep the entrypoint script, but drop bwrap. We're already privileged inside the podman container, which has its own mount and PID namespaces, so no further namespace is needed: the entrypoint mounts
/run,/proc,/devand/var/tmpinto/run/tmprootonce, in the container's own mount namespace (laterpodman execinvocations share them), thenexec chroot /run/tmproot /run/selfexe container-entrypoint.container-entrypointhandles SIGTERM/SIGINT itself, so the bash supervisor and signal forwarding go away too. The target image only needsmount(util-linux) andchroot(coreutils).Tested on a devspace (RHEL 10, rootless podman only):
bcvk ephemeral run-sshon centos-bootc stream9 and stream10, on fedora-bootc 43, and on a stream10 derivative with bubblewrap removed;integration-tests --test-threads 2 ephemeral, andmount_feature): 32 + 2 passed, 0 failedNot tested: rootful podman.
The
Signed-off-by: Colin Walters <walters@verbum.org>on these commits was added on cgwalters's approval of the review draft: cgwalters-forge#12 (review)Generated-by: https://github.com/cgwalters/#llms