-
Notifications
You must be signed in to change notification settings - Fork 312
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Don't use overlayfs for /etc and /opt in sandbox
Unprivileged overlayfs isn't available everywhere (see #3054). So let's try to accomodate this a little by not using overlayfs for /etc and /opt from the sandbox tree and instead mounting them read-only into the sandbox. If required, scripts can still mount an overlayfs onto these if needed, we just don't do it by default anymore. This does mean we need to set up /etc with mountpoints and symlinks beforehand in install_sandbox_trees(), but this shouldn't be a huge problem.
- Loading branch information
1 parent
87284b0
commit 8a44bbc
Showing
3 changed files
with
47 additions
and
17 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters