Override symlink with a normal file
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 45/100
- issue の種類
- 機能追加
- 明瞭さ
- おおむね明確
- 活発さ
- 活発
- 技術スタック
- c, linux
- 領域
- cli, operating-systems
調査の方向性
Start with bubblewrap's command-line handling for --ro-bind-data and --file, then trace the existing symlink checks used by those options. Define and implement the requested opt-in behavior so a later data or file bind can create a normal file at a symlink path such as /etc/resolv.conf; done means the behavior is explicit and does not silently follow that symlink.
索引モデルが issue の本文から書いたものです。
説明
Under systemd /etc/resolv.conf is a symlink to /run/systemd/resolve/stub-resolv.conf
So under a systemd system I need to do like this to setup my mount namespace with my own content on /etc/resolv.conf
$ bwrap --dev-bind / / --proc /proc --tmpfs /run --tmpfs /tmp --unshare-net --ro-bind /run/systemd/resolve /run/systemd/resolve --ro-bind-data 13 /run/systemd/resolve/stub-resolv.conf bash 13< <(echo "nameserver 1.1.1.1")
I would like to see something like this instead
$ bwrap --dev-bind / / --proc /proc --tmpfs /run --tmpfs /tmp --unshare-net --ro-bind-data 13 /etc/resolv.conf bash 13< <(echo "nameserver 1.1.1.1")
Bubblewrap doesn't allow this, it will always resolve the symlink, I would like an option or flag to not resolve the symlink but instead create a normal file in the mount namespace, an overlay file
I know it can be dangerous to escape symlinks, that's why bubblewrap has the checks and this behavior, but I still think this is a legit thing you want to do sometimes, when you are aware of the risks
I would suggest something like a --no-follow-symlink or simliar flag I can do just before --ro-bind-data or --file which would change the behavior of the later, or a completely new data bind / file combo that doesn't follow the symlink first, but makes the user aware it can be dangerous
- 主要言語
- C
- スター
- 8.9k
- フォーク
- 391
- 平均マージ
- 1日 23時間
- マージ済み PR(30日)
- 13
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
containers/bubblewrap のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
containers/bubblewrap#767 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
containers/bubblewrap#743 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
containers/bubblewrap#298 · コメント 4 件 · リアクション 5 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 40/100
containers/bubblewrap#804 ·
メンテナーはふだん 1 日以内に返信
-
wontfix
難易度 4/5 3〜5日 初心者へのやさしさ 55/100
containers/bubblewrap#801 · コメント 3 件 ·
メンテナーはふだん 1 日以内に返信
containers/bubblewrap の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
メンテナーはふだん 1 日以内に返信
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
fastfetch-cli/fastfetch#2628 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
FujiNetWIFI/fujinet-firmware#1736 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
メンテナーはふだん 3 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100