Merge pull request #1564 from anderbubble/issues/1447

Use a sentinel file to determine container readonly state
This commit is contained in:
Christian Goll
2024-12-02 09:03:02 +01:00
committed by GitHub
5 changed files with 18 additions and 19 deletions

View File

@@ -67,6 +67,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/).
- Rename udev net naming file to 70-persistent-net.rules. #1227 - Rename udev net naming file to 70-persistent-net.rules. #1227
- Manage warewulfd template data as a pointer. #1548 - Manage warewulfd template data as a pointer. #1548
- Added test for sending grub.cfg.ww. #1548 - Added test for sending grub.cfg.ww. #1548
- Use a sentinel file to determine container readonly state. #1447
### Removed ### Removed

View File

@@ -120,7 +120,7 @@ func CobraRunE(cmd *cobra.Command, args []string) (err error) {
} }
ps1Str = fmt.Sprintf("[%s|ro|%s] Warewulf> ", containerName, nodename) ps1Str = fmt.Sprintf("[%s|ro|%s] Warewulf> ", containerName, nodename)
} }
if !util.IsWriteAble(containerPath) && nodename == "" { if !container.IsWriteAble(containerName) && nodename == "" {
wwlog.Verbose("mounting %s ro", containerPath) wwlog.Verbose("mounting %s ro", containerPath)
ps1Str = fmt.Sprintf("[%s|ro] Warewulf> ", containerName) ps1Str = fmt.Sprintf("[%s|ro] Warewulf> ", containerName)
err = syscall.Mount(containerPath, containerPath, "", syscall.MS_BIND, "") err = syscall.Mount(containerPath, containerPath, "", syscall.MS_BIND, "")

View File

@@ -2,6 +2,7 @@ package container
import ( import (
"os" "os"
"path/filepath"
"github.com/pkg/errors" "github.com/pkg/errors"
@@ -109,3 +110,7 @@ func DeleteImage(name string) error {
} }
return errors.Errorf("Image %s of container %s doesn't exist\n", imageFile, name) return errors.Errorf("Image %s of container %s doesn't exist\n", imageFile, name)
} }
func IsWriteAble(name string) bool {
return !util.IsFile(filepath.Join(SourceDir(name), "readonly"))
}

View File

@@ -565,21 +565,3 @@ func ByteToString(b int64) string {
} }
return fmt.Sprintf("%.1f %ciB", float64(b)/float64(div), "KMGTPE"[exp]) return fmt.Sprintf("%.1f %ciB", float64(b)/float64(div), "KMGTPE"[exp])
} }
/*
Check if the w-bit of a file/dir. unix.Access(file,unix.W_OK) will
not show this.
*/
func IsWriteAble(path string) bool {
info, err := os.Stat(path)
if err != nil {
return false
}
// Check if the user bit is enabled in file permission
if info.Mode().Perm()&(1<<(uint(7))) == 0 {
wwlog.Debug("Write permission bit is not set for: %s", path)
return false
}
return true
}

View File

@@ -464,3 +464,14 @@ tools 1.21 or newer. Below is an example for building wwclient for arm64:
# cp wwclient /var/lib/warewulf/overlays/wwclient_arm64/rootfs/warewulf # cp wwclient /var/lib/warewulf/overlays/wwclient_arm64/rootfs/warewulf
Then, apply the new "wwclient_arm64" system overlay to your arm64 node/profile Then, apply the new "wwclient_arm64" system overlay to your arm64 node/profile
Read-only containers
====================
A container may be marked "read-only" by creating a ``readonly`` file in its
source directory, typically next to ``rootfs``.
.. note::
Read-only containers are a preview feature primarily meant to enable future
support for container subscriptions and updates.