Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Override symlink with a normal file

Open
#808 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
45/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Active
Tech stack
c, linux

Research direction

Start with bubblewrap's command-line handling for --ro-bind-data and --file, then trace the existing symlink checks used by those options. Define and implement the requested opt-in behavior so a later data or file bind can create a normal file at a symlink path such as /etc/resolv.conf; done means the behavior is explicit and does not silently follow that symlink.

Written by the indexing model from the issue text.

Description

Under systemd /etc/resolv.conf is a symlink to /run/systemd/resolve/stub-resolv.conf

So under a systemd system I need to do like this to setup my mount namespace with my own content on /etc/resolv.conf

$ bwrap --dev-bind / / --proc /proc --tmpfs /run --tmpfs /tmp --unshare-net --ro-bind /run/systemd/resolve /run/systemd/resolve --ro-bind-data 13 /run/systemd/resolve/stub-resolv.conf bash 13< <(echo "nameserver 1.1.1.1")

I would like to see something like this instead

$ bwrap --dev-bind / / --proc /proc --tmpfs /run --tmpfs /tmp --unshare-net --ro-bind-data 13 /etc/resolv.conf bash 13< <(echo "nameserver 1.1.1.1")

Bubblewrap doesn't allow this, it will always resolve the symlink, I would like an option or flag to not resolve the symlink but instead create a normal file in the mount namespace, an overlay file

I know it can be dangerous to escape symlinks, that's why bubblewrap has the checks and this behavior, but I still think this is a legit thing you want to do sometimes, when you are aware of the risks

I would suggest something like a --no-follow-symlink or simliar flag I can do just before --ro-bind-data or --file which would change the behavior of the later, or a completely new data bind / file combo that doesn't follow the symlink first, but makes the user aware it can be dangerous

Dominant language
C
Stars
8.8k
Forks
387
Avg merge
2d 22h
Merged PRs (30d)
15

Getting set up

We have not checked this project's setup files yet. Start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from containers/bubblewrap

All issues in containers/bubblewrap

Similar issues

More C issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.