From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from atuin.qyliss.net (localhost [IPv6:::1]) by atuin.qyliss.net (Postfix) with ESMTP id 1E8BC24D08; Thu, 11 Dec 2025 16:27:49 +0000 (UTC) Received: by atuin.qyliss.net (Postfix, from userid 993) id 07F6C24C74; Thu, 11 Dec 2025 16:27:46 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on atuin.qyliss.net X-Spam-Level: X-Spam-Status: No, score=-0.8 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DMARC_MISSING,RCVD_IN_DNSWL_LOW,SPF_HELO_PASS autolearn=unavailable autolearn_force=no version=4.0.1 Received: from fout-a7-smtp.messagingengine.com (fout-a7-smtp.messagingengine.com [103.168.172.150]) by atuin.qyliss.net (Postfix) with ESMTPS id 6966824CEB for ; Thu, 11 Dec 2025 16:27:44 +0000 (UTC) Received: from phl-compute-10.internal (phl-compute-10.internal [10.202.2.50]) by mailfout.phl.internal (Postfix) with ESMTP id 5D6F7EC04BF; Thu, 11 Dec 2025 11:27:42 -0500 (EST) Received: from phl-mailfrontend-02 ([10.202.2.163]) by phl-compute-10.internal (MEProxy); Thu, 11 Dec 2025 11:27:42 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=alyssa.is; h=cc :cc:content-transfer-encoding:content-type:date:date:from:from :in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:subject:subject:to:to; s=fm3; t=1765470462; x= 1765556862; bh=YrCqPdB5UE5jaWOBahAoy1oYVCo9G6N7bLRVDrvLPo0=; b=D Ug7ML33mRcWPXfVieW+nQplWI3r6UIhdTDrILH1U2/JsLZa7ACImWjzjE326hQqI BR3EU4ryMdYFpUw7SnkGw7cVwHw35BvJFpOqsReJwbLXrYrld9L5cCz0n2pvzzbc 7X5aFDKNchdk1T5zL0Z4GEH5wntt/36VGw+UwMHzXcdyAWML2CjBv8Wq6uxRWaR1 R0Nx/lCdFiBA5nQ1437XlwIPGLtFOtogOP3a7nW4nFmcBU4jfiM8gGs3snOMI3OH 02GdsOU5pURY8SKvoA6LEVqX55//s56tsv7go2naPirE7Grbo4AXv2tPyhdTXeUE 4fo4CBbgeh88gBuEULXxw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:subject:subject:to:to:x-me-proxy:x-me-sender :x-me-sender:x-sasl-enc; s=fm1; t=1765470462; x=1765556862; bh=Y rCqPdB5UE5jaWOBahAoy1oYVCo9G6N7bLRVDrvLPo0=; b=OVr8HRA/bbrO6M6jZ qSx5KhR0o9cERZ+tpF/yf5JF0kQibB5LIiFZsEhKjE3iCbvClJWRWyvnz89TTMyA 99g32PcWuHYRdxQ64WkwR11Q2AsuoGpU+/6WXQfY76pMLZM2XqyN/mBF7EWzgQFq yIk1lqtk7eKqdOBtrYSssRV4HcXYByiFJHeU0q1j8T3zACIfhwyjBK9oN504/buH etD24gY7i8Yfjx/fD0fhWtPGIQ4zcztNVEtt+l5Ii3dFHLYzzsLT0BeTAw5PfA2V 9EMHqlVp1rmsDS4PKb+ymuXibAHI3rU7Mu40/nrZm/b5EyPo+kji8x0DgzubqpFP 6WlNA== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefgedrtddtgddvheejkecutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpuffrtefokffrpgfnqfghnecuuegr ihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnthhsucdlqddutddtmdenucfjug hrpefhvfevufffkffojghfggfgsedtkeertdertddtnecuhfhrohhmpeetlhihshhsrgcu tfhoshhsuceohhhisegrlhihshhsrgdrihhsqeenucggtffrrghtthgvrhhnpeethfegie ffffelteduueeltdelueethfeuteevieetuefggeefuddvlefgtdefvdenucffohhmrghi nhepshhpvggtthhruhhmqdhoshdrohhrghenucevlhhushhtvghrufhiiigvpedtnecurf grrhgrmhepmhgrihhlfhhrohhmpehhihesrghlhihsshgrrdhishdpnhgspghrtghpthht ohepvddpmhhouggvpehsmhhtphhouhhtpdhrtghpthhtohepuggvmhhiohgsvghnohhurh esghhmrghilhdrtghomhdprhgtphhtthhopeguvghvvghlsehsphgvtghtrhhumhdqohhs rdhorhhg X-ME-Proxy: Feedback-ID: i12284293:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Thu, 11 Dec 2025 11:27:42 -0500 (EST) Received: by fw12.qyliss.net (Postfix, from userid 1000) id 52ED16F7490F; Thu, 11 Dec 2025 17:27:35 +0100 (CET) From: Alyssa Ross To: devel@spectrum-os.org Subject: [PATCH v2 6/8] host/rootfs: move xdp runtime dir out of VM dir Date: Thu, 11 Dec 2025 17:21:49 +0100 Message-ID: <20251211162145.124509-12-hi@alyssa.is> X-Mailer: git-send-email 2.51.0 In-Reply-To: <20251211162145.124509-2-hi@alyssa.is> References: <20251211162145.124509-2-hi@alyssa.is> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Message-ID-Hash: U6ZSELW7FJZ43NBRE5VDXMRHUNLSVXDW X-Message-ID-Hash: U6ZSELW7FJZ43NBRE5VDXMRHUNLSVXDW X-MailFrom: hi@alyssa.is X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-devel.spectrum-os.org-0; header-match-devel.spectrum-os.org-1; header-match-devel.spectrum-os.org-2; header-match-devel.spectrum-os.org-3; header-match-devel.spectrum-os.org-4; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Demi Marie Obenour X-Mailman-Version: 3.3.9 Precedence: list List-Id: Patches and low-level development discussion Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: This will enable running D-Bus as a user that does not have access to VM directories. Signed-off-by: Alyssa Ross --- v2: add comment explaining --make-shared v1: https://spectrum-os.org/lists/archives/spectrum-devel/20251210124757.1080443-6-hi@alyssa.is/ host/rootfs/image/usr/bin/create-vm-dependencies | 8 ++++++-- .../services/org.freedesktop.portal.Documents.service | 2 +- 2 files changed, 7 insertions(+), 3 deletions(-) diff --git a/host/rootfs/image/usr/bin/create-vm-dependencies b/host/rootfs/image/usr/bin/create-vm-dependencies index 34dace4b..fc2bec7b 100755 --- a/host/rootfs/image/usr/bin/create-vm-dependencies +++ b/host/rootfs/image/usr/bin/create-vm-dependencies @@ -4,7 +4,7 @@ if { mkdir -p - /run/vm/by-id/${1}/doc-run/doc + /run/doc/${1}/doc /run/vm/by-id/${1}/fs/config /run/vm/by-id/${1}/fs/doc /run/vm/by-id/${1}/ns @@ -27,7 +27,11 @@ if { # can be writable block-based bind mounted subdirectories. if { mount --rbind -o nofail /run/vm/by-id/${1}/config/fs /run/vm/by-id/${1}/fs/config } if { mount --rbind -o ro /run/vm/by-id/${1}/fs /run/vm/by-id/${1}/fs } - mount --rbind /run/vm/by-id/${1}/doc-run/doc /run/vm/by-id/${1}/fs/doc + + # Needs to be shared so that when xdg-document-portal mounts its fuse + # filesystem at /run/doc/${1}/doc, it will propagate to /run/fs/${1}/doc. + if { mount --make-shared --rbind /run/doc/${1} /run/doc/${1} } + mount --rbind /run/doc/${1}/doc /run/vm/by-id/${1}/fs/doc } if { s6-instance-create /run/service/vm-services $1 } diff --git a/host/rootfs/image/usr/share/dbus-1/services/org.freedesktop.portal.Documents.service b/host/rootfs/image/usr/share/dbus-1/services/org.freedesktop.portal.Documents.service index f4dd53e3..be24f080 100644 --- a/host/rootfs/image/usr/share/dbus-1/services/org.freedesktop.portal.Documents.service +++ b/host/rootfs/image/usr/share/dbus-1/services/org.freedesktop.portal.Documents.service @@ -3,4 +3,4 @@ [D-BUS Service] Name=org.freedesktop.portal.Documents -Exec=/bin/importas -Si VM export XDG_RUNTIME_DIR /run/vm/by-id/${VM}/doc-run xdg-document-portal +Exec=/bin/importas -Si VM export XDG_RUNTIME_DIR /run/doc/${VM} xdg-document-portal -- 2.51.0