Use "new mount API" if available
Maintainers usually reply within 1 day
@xxyzz is already working on this.
Since Sep 15, 2026.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- c, linux
- Domain
- cli, operating-systems
Research direction
Start by reviewing bubblewrap's current mount(2) paths for --[ro-]bind-fd and the prerequisite in #754, then study open_tree(2), mount_setattr(), and move_mount(). Verify fallback behavior when kernels return ENOSYS or EINVAL and confirm bind-fd operations remain safe for attacker-controlled hierarchies; done means the new APIs are used when available without breaking older kernels.
Written by the indexing model from the issue text.
Description
bubblewrap currently uses the traditional mount(2) API for everything. This is not a great interface for container'y use cases.
In particular, the mount(2) API has the problem that it is path-based rather than fd-based, requiring some strange and non-robust code to implement --[ro-]bind-fd (which is necessary for Flatpak and other sandboxing frameworks that operate on attacker-controlled directory hierarchies, which need to use --[ro-]bind-fd to avoid vulnerabilities like CVE-2024-42472 and CVE-2026-34078).
If we use the "new mount APIs", it should be possible to implement --[ro-]bind-fd with open_tree(..., AT_EMPTY_PATH | OPEN_TREE_CLONE | AT_RECURSIVE) followed by mount_setattr() and move_mount(..., MOVE_MOUNT_F_EMPTY_PATH), similar to some of the examples in open_tree(2).
Similarly, --{,dev-,ro-}bind-fd could be implemented in a similar way, but starting from AT_FDCWD and an absolute path, rather than a fd and AT_EMPTY_PATH.
On older kernels, none of this would work (ENOSYS or EINVAL), and we'd have to fall back to the way things are currently done.
#754 should probably be done first - that's a much simpler use of the "new mount APIs".
A possible follow-up would be to increase the minimum kernel version to one that implements all of the necessary syscalls, but (like #754) that would mean abandoning the ability to run bubblewrap (and therefore Flatpak, the Steam Runtime, etc.) on older distros like RHEL 8 and Ubuntu 20.04, which is something we have historically tried hard not to do. If that is done, then I think it should be a separate PR and a separate issue.
[Tracked as steamrt/tasks#1005 elsewhere]
cc @ao2
- Dominant language
- C
- Stars
- 8.9k
- Forks
- 391
- Avg merge
- 17h 45m
- Merged PRs (30d)
- 10
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from containers/bubblewrap
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
containers/bubblewrap#813 · 1 reaction ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
containers/bubblewrap#767 · 2 comments ·
Maintainers usually reply within 1 day
-
Related project comparisons in README.md are outdatedMay be free again A pull request for this issue was closed without being merged. Open
Difficulty 1/5 Under an hour Newbie friendliness 88/100
containers/bubblewrap#743 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
containers/bubblewrap#298 · 4 comments · 5 reactions ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 52/100
containers/bubblewrap#811 ·
Maintainers usually reply within 1 day
All issues in containers/bubblewrap
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
UNIVERSE-HPC/course-material#283 ·
-
bug C/C++ code
Difficulty 1/5 Under an hour Newbie friendliness 78/100
webarkit/WebARKitLib#85 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 75/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 72/100