Bootstrap::SysrootNamespace
Inherits Bootstrap::CLI < Reference < Object
SysrootNamespace encapsulates user/mount namespaces and optional rootfs mounting to provide a sudo-less entrypoint into the sysroot when supported by the kernel.
Constants
Linux kernel sysctl: Documentation/admin-guide/LSM/apparmor.rst
Namespace and mount constants from Linux headers:
- linux/sched.h (CLONE_NEW*)
- linux/mount.h (MS_*)
Linux kernel sysctl: Documentation/admin-guide/sysctl/kernel.rst
Class methods
Returns a restriction message if AppArmor confinement is detected. This checks the current label and the sysctl that restricts unprivileged user namespaces.
Bind-mounts a source file to a file target.
Collects restriction messages that can prevent user-namespace mounts of proc/sys/dev from succeeding on the current host.
Raises a NamespaceError with a clear diagnostic when user namespaces are disabled via the kernel toggle.
Enter the provided rootfs by unsharing namespaces, bind-mounting the rootfs, mounting /proc, /dev, and /sys, then pivoting into the new root. When bind_host_dev is true, /dev is bind-mounted recursively from the host (Linux From Scratch kernfs style) to avoid relying on dev-enabled tmpfs inside user namespaces. When unmount_old_root is true, the old root is detached after pivot_root.
Enter a rootfs and apply the standard environment/toolchain setup.
Returns a list of filesystem types that are missing from /proc/filesystems.
Dispatch sysroot namespace subcommands by command name.
Returns the seccomp mode from /proc/self/status, or nil when absent.