From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from atuin.qyliss.net (localhost [IPv6:::1]) by atuin.qyliss.net (Postfix) with ESMTP id E05ED3D5D; Wed, 15 Jul 2026 18:28:38 +0000 (UTC) Received: by atuin.qyliss.net (Postfix, from userid 993) id 6A1A93D8E; Wed, 15 Jul 2026 18:28:36 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on atuin.qyliss.net X-Spam-Level: X-Spam-Status: No, score=-0.8 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DMARC_MISSING,RCVD_IN_DNSWL_LOW,SPF_HELO_PASS autolearn=unavailable autolearn_force=no version=4.0.1 Received: from fout-b8-smtp.messagingengine.com (fout-b8-smtp.messagingengine.com [202.12.124.151]) by atuin.qyliss.net (Postfix) with ESMTPS id 116323D8C for ; Wed, 15 Jul 2026 18:28:35 +0000 (UTC) Received: from phl-compute-11.internal (phl-compute-11.internal [10.202.2.51]) by mailfout.stl.internal (Postfix) with ESMTP id C3FB71D0006B; Wed, 15 Jul 2026 14:28:33 -0400 (EDT) Received: from phl-frontend-04 ([10.202.2.163]) by phl-compute-11.internal (MEProxy); Wed, 15 Jul 2026 14:28:33 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=alyssa.is; h=cc :cc:content-type:content-type:date:date:from:from:in-reply-to :in-reply-to:message-id:mime-version:references:reply-to:subject :subject:to:to; s=fm1; t=1784140113; x=1784226513; bh=wYvsgrVZxz w49Fa+qx5S0+2IPIbP2UKTu68y4J/aoPg=; b=Gnv73m2pVpyQHTBntgLNvTciZD 8+SirbZb7YCbOX+QmoL0v1SR76q2uqcA8qrv6B+KU0w20f6hkRQmJPJyzwEKopem PJVVQp/jYr79QNrOEpvq/I9genxfdBcpaLHx4YGwsoH7JLfoAH9nleJLWw8uNjnl 7ujKWHvZV1yI/FwMwaEIeemeYXw9TLfR72lUATQRdFDJIuPFLxzkDg5KkYBLSUrH GY9fD9v7GGrIa9ReDmJB9SFx+R4Cw9OrWRDtWEOu3gqo5+kgL2JvYmORDkVkWaSE mITsocSxNmSevoYM5quCRFVr29JgFEN+DDcvFYjR682dwSSyRVyL6l5Zr9wg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-type:content-type:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:subject:subject:to :to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t= 1784140113; x=1784226513; bh=wYvsgrVZxzw49Fa+qx5S0+2IPIbP2UKTu68 y4J/aoPg=; b=jmEcegDDPjhD8REZyk6j2Mx04M1uvKD8votPlrIs6v2x0yyOAAx 7o7p41HXvrximY32gXywajVJgX50z0cla5PNoLVIQAdYHfc1SWPVgnMp+UNWA9Ug SNpIjXkul9Bg6h7P54PW4TLm43BCMYNLocrRwhyJ13zUMvw92O5LEL/noJMWnOsV GaKq334y4eXotTCry0PW1VfOwkum3FCUc2jO2Mo5RryZ4HfuorZ6W5LbFF9Y9WCb 1HiahGTsF7RfPb15pd454ifiI6XCi7N6sW0ZanWQJnLU9k83de8CDzpYDG/J23WR 5fLZDOWLhoBo6WgYIEwZf4+W4TvNjI0Ux4A== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTFlqDyXQQAmH0pkciCfu/E4G8Thn4NeZdbxdxEAFOMWN5XIEN5HBUwN3dWOTIh7Of IhMwef/c+ORvdK9KqEpjdz4rz+4yIZ7ekwodrVSxp8HTpDU9MxABn4VLyqiXoXZhWRdWFg 8Kj86KfVKIsQ5O+dtq0C6F8ym/UFfTLzJIpZ4DkxH1SRVusw39os/GHZL7sHo8DSmmB+6H 3x35a40IA2+HoMzhbX4cLMex+ZG0uJM63mtU7y+KFUulbxCGIk1vOmjqBHp6prk5cr/7ut q2SHXdwzndHl/AU7yrSk3klDQXCmnIgD41+e/1ArHFLIXErYOFbXsqsVMfj49KWvzojhTy NvmrYaZucAYdnpt/NuX0QIWKvdMgr7gcRiIH2jZF4JOwyKgu6Cc9/Pikn3gVYlZsVchJps jGIFXiKOsOq5PQGOQjgRHEMBrsD5yzfxEggG8kC3Jc/wIfjvS/Vkz9Yo13/3l3+mn2wrc/ vThonC2VeJjNEYbLuEk8JlEmIbQV1IrFXy5dzfKcsSfKOJSBSj6YUtzSPfYCqd6I8uKnL1 o+1uHqtc5NqeqiO29mM0b3P8k4rz2Ks7Uf+MIf4wvhbFKFcssSWZa5oPyRubW3Vev3VxTW R1V3UV+UeP+lcxFsyggFNj0VFhSVaW22QlFcL9zUUJjt+JKeCrHB1yypAQjA X-ME-Proxy: Feedback-ID: i12284293:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Wed, 15 Jul 2026 14:28:31 -0400 (EDT) Received: by mbp.qyliss.net (Postfix, from userid 1000) id AE4DF89554C3; Wed, 15 Jul 2026 20:28:27 +0200 (CEST) From: Alyssa Ross To: Demi Marie Obenour Subject: Re: [PATCH v3 01/22] host/rootfs: Mount filesystems before s6-rc-init In-Reply-To: <39d4b506-294a-4ac1-b748-dcd05a8a11fe@gmail.com> References: <20260711-cgroups-v3-0-5cba61a20cba@gmail.com> <20260711-cgroups-v3-1-5cba61a20cba@gmail.com> <8733xn1b5p.fsf@alyssa.is> <39d4b506-294a-4ac1-b748-dcd05a8a11fe@gmail.com> Date: Wed, 15 Jul 2026 20:28:26 +0200 Message-ID: <878q7cqf91.fsf@alyssa.is> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" Message-ID-Hash: JCBQCIWEVPRRWJ4DYRVKZQQ5PU7HJ6HJ X-Message-ID-Hash: JCBQCIWEVPRRWJ4DYRVKZQQ5PU7HJ6HJ X-MailFrom: hi@alyssa.is X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.spectrum-os.org-0; header-match-devel.spectrum-os.org-1; header-match-devel.spectrum-os.org-2; header-match-devel.spectrum-os.org-3; header-match-devel.spectrum-os.org-4; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Spectrum OS Development X-Mailman-Version: 3.3.10 Precedence: list List-Id: Patches and low-level development discussion Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: --=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Demi Marie Obenour writes: > On 7/13/26 05:39, Alyssa Ross wrote: >> Demi Marie Obenour writes: >>=20 >>> cgroup-setup is written in Rust and uses the Rust standard library. FWIW it might be good to say "cgroup-setup, a tool which will be introduced in a later patch" or something. Otherwise I have to guess what this is referring to. >>> It also relies on cgroupfs being mounted at /sys/fs/cgroup. >>> Furthermore, it runs very, *very* early on, since it sets up the cgroups >>> in which s6-svscan and s6-supervise processes run. This allows setting >>> up sub-cgroups without having to worry about name collisions. >>> >>> While it would be possible to only mount the bare minimum necessary, >>> it's simpler to just mount everything before starting any services. >>> These mounts are all pseudo-filesystems or tmpfs instances, and none >>> have any dependencies. >>> >>> Signed-off-by: Demi Marie Obenour >>> --- >>> host/rootfs/image/etc/init | 11 ++++++++++- >>> host/rootfs/image/etc/s6-linux-init/scripts/rc.init | 9 +-------- >>> 2 files changed, 11 insertions(+), 9 deletions(-) >>> >>> diff --git a/host/rootfs/image/etc/init b/host/rootfs/image/etc/init >>> index db8a6d9c747e3d212c21b6c983c8f7e299822abe..8ec7859ab00e24007a93d40= 00c8f34e353de50ae 100755 >>> --- a/host/rootfs/image/etc/init >>> +++ b/host/rootfs/image/etc/init >>> @@ -1,6 +1,15 @@ >>> #!/bin/execlineb -Ws0 >>> # SPDX-License-Identifier: EUPL-1.2+ >>> -# SPDX-FileCopyrightText: 2022 Alyssa Ross >>> +# SPDX-FileCopyrightText: 2020-2022, 2024 Alyssa Ross >>>=20=20 >>> /bin/setpriv --no-new-privs -- >>> + >>> +if { /bin/ln -s /proc/self/fd /dev } >>> +if { /bin/ln -s /proc/self/fd/0 /dev/stdin } >>> +if { /bin/ln -s /proc/self/fd/1 /dev/stdout } >>> +if { /bin/ln -s /proc/self/fd/2 /dev/stderr } >>=20 >> I guess the idea is that the Rust standard library might want these? > > I don't know if it actually does, though I would not be surprised if > it is not tested without them. What *is* necessary is for a cgroup > filesystem to be mounted at /sys/fs/cgroup. This allows setting up > cgroup controllers and moving PID 1 to a sub-cgroup. Yeah, that's what I thought. It doesn't do any harm to create them early anyway, so this is fine. >>> + >>> +if { /bin/mount --make-shared / } >>> +if { /bin/mount -a --mkdir } >>> + >>> /bin/s6-linux-init -c /etc/s6-linux-init -s /run/param -- $@ >>> diff --git a/host/rootfs/image/etc/s6-linux-init/scripts/rc.init b/host= /rootfs/image/etc/s6-linux-init/scripts/rc.init >>> index f638e373589884acb959c868462fdf532380a851..fba305c4e9cbb9f7535f11b= b4c06d8da8a34837b 100755 >>> --- a/host/rootfs/image/etc/s6-linux-init/scripts/rc.init >>> +++ b/host/rootfs/image/etc/s6-linux-init/scripts/rc.init >>> @@ -4,13 +4,6 @@ >>>=20=20 >>> if { s6-rc-init -c /etc/s6-rc /run/service } >>>=20=20 >>> -if { ln -s /proc/self/fd /dev } >>> -if { ln -s /proc/self/fd/0 /dev/stdin } >>> -if { ln -s /proc/self/fd/1 /dev/stdout } >>> -if { ln -s /proc/self/fd/2 /dev/stderr } >>> - >>> -if { mount --make-shared / } >>> -if { mount --make-shared /run } >>> -if { mount -a --mkdir } >>> +if { /bin/mount --make-shared /run } >>=20 >> Presumably this does not actually suddenly need an absolute path. > > You are correct. Alright then, with that fixed: Reviewed-by: Alyssa Ross --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iHQEARYKAB0WIQRV/neXydHjZma5XLJbRZGEIw/wogUCalfRSgAKCRBbRZGEIw/w ojIjAP9cm3ljsmLZISx8GoLZABblq+q6gp5PhEyJJwWZjMcLPgD3ZAOQ+WYj4r/1 lvye6ruHf+RpNk08UOHFrEi34LWFBA== =aqAf -----END PGP SIGNATURE----- --=-=-=--