Files
poky/meta/recipes-core/volatile-binds/files/mount-copybind
Maximilian Blenk e325390b91 mount-copybind: add rootcontext mountoption for overlayfs
If selinux is enabled, the context of the mountpoint for overlayfs
needs to be specified manually via the rootcontext option. To this
end, the required context is determined using matchpathcon(1) and
passed via the rootcontext mount option.

Additionally, if the mount source directory is created by mount-copybind
it also needs to take care that the context of the directory is correct

(From OE-Core rev: 57f51e8c73ab9f55f20815a9459c3afad2b281e6)

Signed-off-by: Tobias Kaufmann <Tobias.KA.Kaufmann@bmw.de>
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2021-10-11 18:41:38 +01:00

2.1 KiB
Executable File

#!/bin/sh

Perform a bind mount, copying existing files as we do so to ensure the

overlaid path has the necessary content.

if [ $# -lt 2 ]; then echo >&2 "Usage: $0 spec mountpoint [OPTIONS]" exit 1 fi

e.g. /var/volatile/lib

spec=$1

e.g. /var/lib

mountpoint=$2

if [ $# -gt 2 ]; then options=$3 else options= fi

[ -n "$options" ] && options=",$options"

mkdir -p "${spec%/*}"

if [ -d "$mountpoint" ]; then

if [ -d "$spec" ]; then
    specdir_existed=yes
else
    specdir_existed=no
    mkdir "$spec"
    # If the $spec directory is created we need to take care that
    # the selinux context is correct
    if command -v selinuxenabled > /dev/null 2>&1; then
        if selinuxenabled; then
            restorecon "$spec"
        fi
    fi
fi

# Fast version of calculating `dirname ${spec}`/.`basename ${spec}`-work
overlay_workdir="${spec%/*}/.${spec##*/}-work"
mkdir "${overlay_workdir}"

# Try to mount using overlay, which is must faster than copying files.
# If that fails, fall back to slower copy.
if command -v selinuxenabled > /dev/null 2>&1; then
    if selinuxenabled; then
        mountcontext=",rootcontext=$(matchpathcon -n $mountpoint)"
    fi
fi
if ! mount -t overlay overlay -olowerdir="$mountpoint",upperdir="$spec",workdir="$overlay_workdir""$mountcontext" "$mountpoint" > /dev/null 2>&1; then

    if [ "$specdir_existed" != "yes" ]; then
        cp -aPR "$mountpoint"/. "$spec/"
    fi

    mount -o "bind$options" "$spec" "$mountpoint"
    # restore the selinux context.
    if command -v selinuxenabled > /dev/null 2>&1; then
        if selinuxenabled; then
            restorecon -R "$mountpoint"
        fi
    fi
fi

elif [ -f "$mountpoint" ]; then if [ ! -f "$spec" ]; then cp -aP "$mountpoint" "$spec" fi

mount -o "bind$options" "$spec" "$mountpoint"
# restore the selinux context.
if command -v selinuxenabled > /dev/null 2>&1; then
    if selinuxenabled; then
        restorecon -R "$mountpoint"
    fi
fi

fi