1 /* SPDX-License-Identifier: LGPL-2.1-or-later */
9 #include "alloc-util.h"
10 #include "dissect-image.h"
11 #include "errno-util.h"
14 typedef enum MountAttrPropagationType
{
15 MOUNT_ATTR_PROPAGATION_INHERIT
, /* no special MS_* propagation flags */
16 MOUNT_ATTR_PROPAGATION_PRIVATE
, /* MS_PRIVATE */
17 MOUNT_ATTR_PROPAGATION_DEPENDENT
, /* MS_SLAVE */
18 MOUNT_ATTR_PROPAGATION_SHARED
, /* MS_SHARE */
20 _MOUNT_ATTR_PROPAGATION_TYPE_MAX
,
21 _MOUNT_ATTR_PROPAGATION_TYPE_INVALID
= -EINVAL
,
22 } MountAttrPropagationType
;
24 const char* mount_attr_propagation_type_to_string(MountAttrPropagationType t
) _const_
;
25 MountAttrPropagationType
mount_attr_propagation_type_from_string(const char *s
) _pure_
;
26 unsigned int mount_attr_propagation_type_to_flag(MountAttrPropagationType t
);
28 /* The limit used for /dev itself. 4MB should be enough since device nodes and symlinks don't
29 * consume any space and udev isn't supposed to create regular file either. There's no limit on the
30 * max number of inodes since such limit is hard to guess especially on large storage array
32 #define TMPFS_LIMITS_DEV ",size=4m"
34 /* The limit used for /dev in private namespaces. 4MB for contents of regular files. The number of
35 * inodes should be relatively low in private namespaces but for now use a 64k limit. */
36 #define TMPFS_LIMITS_PRIVATE_DEV ",size=4m,nr_inodes=64k"
38 /* Very little, if any use expected */
39 #define TMPFS_LIMITS_EMPTY_OR_ALMOST ",size=4m,nr_inodes=1k"
40 #define TMPFS_LIMITS_SYS TMPFS_LIMITS_EMPTY_OR_ALMOST
41 #define TMPFS_LIMITS_SYS_FS_CGROUP TMPFS_LIMITS_EMPTY_OR_ALMOST
43 /* On an extremely small device with only 256MB of RAM, 20% of RAM should be enough for the re-execution of
44 * PID1 because 16MB of free space is required. */
45 #define TMPFS_LIMITS_RUN ",size=20%,nr_inodes=800k"
47 /* The limit used for various nested tmpfs mounts, in particular for guests started by systemd-nspawn.
48 * 10% of RAM (using 16GB of RAM as a baseline) translates to 400k inodes (assuming 4k each) and 25%
49 * translates to 1M inodes.
50 * (On the host, /tmp is configured through a .mount unit file.) */
51 #define NESTED_TMPFS_LIMITS ",size=10%,nr_inodes=400k"
53 /* More space for volatile root and /var */
54 #define TMPFS_LIMITS_VAR ",size=25%,nr_inodes=1m"
55 #define TMPFS_LIMITS_ROOTFS TMPFS_LIMITS_VAR
56 #define TMPFS_LIMITS_VOLATILE_STATE TMPFS_LIMITS_VAR
58 int mount_fd(const char *source
, int target_fd
, const char *filesystemtype
, unsigned long mountflags
, const void *data
);
59 int mount_nofollow(const char *source
, const char *target
, const char *filesystemtype
, unsigned long mountflags
, const void *data
);
61 int repeat_unmount(const char *path
, int flags
);
62 int umount_recursive(const char *target
, int flags
);
64 int bind_remount_recursive_with_mountinfo(const char *prefix
, unsigned long new_flags
, unsigned long flags_mask
, char **deny_list
, FILE *proc_self_mountinfo
);
65 static inline int bind_remount_recursive(const char *prefix
, unsigned long new_flags
, unsigned long flags_mask
, char **deny_list
) {
66 return bind_remount_recursive_with_mountinfo(prefix
, new_flags
, flags_mask
, deny_list
, NULL
);
69 int bind_remount_one_with_mountinfo(const char *path
, unsigned long new_flags
, unsigned long flags_mask
, FILE *proc_self_mountinfo
);
71 int mount_switch_root(const char *path
, MountAttrPropagationType type
);
73 DEFINE_TRIVIAL_CLEANUP_FUNC_FULL(FILE*, endmntent
, NULL
);
74 #define _cleanup_endmntent_ _cleanup_(endmntentp)
76 int mount_verbose_full(
85 static inline int mount_follow_verbose(
91 const char *options
) {
92 return mount_verbose_full(error_log_level
, what
, where
, type
, flags
, options
, true);
95 static inline int mount_nofollow_verbose(
101 const char *options
) {
102 return mount_verbose_full(error_log_level
, what
, where
, type
, flags
, options
, false);
110 int mount_option_mangle(
112 unsigned long mount_flags
,
113 unsigned long *ret_mount_flags
,
114 char **ret_remaining_options
);
116 int mode_to_inaccessible_node(const char *runtime_dir
, mode_t mode
, char **dest
);
117 int mount_flags_to_string(unsigned long flags
, char **ret
);
119 /* Useful for usage with _cleanup_(), unmounts, removes a directory and frees the pointer */
120 static inline char* umount_and_rmdir_and_free(char *p
) {
123 (void) umount_recursive(p
, 0);
128 DEFINE_TRIVIAL_CLEANUP_FUNC(char*, umount_and_rmdir_and_free
);
130 int bind_mount_in_namespace(pid_t target
, const char *propagate_path
, const char *incoming_path
, const char *src
, const char *dest
, bool read_only
, bool make_file_or_directory
);
131 int mount_image_in_namespace(pid_t target
, const char *propagate_path
, const char *incoming_path
, const char *src
, const char *dest
, bool read_only
, bool make_file_or_directory
, const MountOptions
*options
);
133 int make_mount_point(const char *path
);
135 typedef enum RemountIdmapping
{
136 REMOUNT_IDMAPPING_NONE
,
137 /* Include a mapping from UID_MAPPED_ROOT (i.e. UID 2^31-2) on the backing fs to UID 0 on the
138 * uidmapped fs. This is useful to ensure that the host root user can safely add inodes to the
139 * uidmapped fs (which otherwise wouldn't work as the host root user is not defined on the uidmapped
140 * mount and any attempts to create inodes will then be refused with EOVERFLOW). The idea is that
141 * these inodes are quickly re-chown()ed to more suitable UIDs/GIDs. Any code that intends to be able
142 * to add inodes to file systems mapped this way should set this flag, but given it comes with
143 * certain security implications defaults to off, and requires explicit opt-in. */
144 REMOUNT_IDMAPPING_HOST_ROOT
,
145 /* Define a mapping from root user within the container to the owner of the bind mounted directory.
146 * This ensure no root-owned files will be written in a bind-mounted directory owned by a different
147 * user. No other users are mapped. */
148 REMOUNT_IDMAPPING_HOST_OWNER
,
149 _REMOUNT_IDMAPPING_MAX
,
150 _REMOUNT_IDMAPPING_INVALID
= -EINVAL
,
153 int remount_idmap(const char *p
, uid_t uid_shift
, uid_t uid_range
, uid_t owner
, RemountIdmapping idmapping
);
155 /* Creates a mount point (not parents) based on the source path or stat - ie, a file or a directory */
156 int make_mount_point_inode_from_stat(const struct stat
*st
, const char *dest
, mode_t mode
);
157 int make_mount_point_inode_from_path(const char *source
, const char *dest
, mode_t mode
);