|
From: | Ludovic Courtès |
Subject: | [bug#42849] [PATCH 2/3] linux-container: Add a jail? argument. |
Date: | Mon, 31 Aug 2020 15:36:06 +0200 |
User-agent: | Gnus/5.13 (Gnus v5.13) Emacs/26.3 (gnu/linux) |
Hi, Mathieu Othacehe <othacehe@gnu.org> skribis: >> Why not just change the caller to pass #:mounts '() then? Am I missing >> something? >> >> I’m reluctant to introducing “jail” because that’s undefined in this >> context (reminds me of FreeBSD). > > The purpose here is to avoid the "pivot-root" call that is done > unconditionally in "mount-file-systems". This way containerized process > can share the parent root file-system. Oh, I see. > Maybe something like that would make more sense: > > (lambda () > (unless (null? mounts) > (mount-file-systems root mounts > #:mount-/proc? (memq 'pid namespaces) > #:mount-/sys? (memq 'net > namespaces)))) Should it be (and (null? mounts) (null? namespaces)) or…? Ludo’.
[Prev in Thread] | Current Thread | [Next in Thread] |