mirror of
https://github.com/systemd/systemd.git
synced 2026-08-09 09:32:04 +00:00
We expose this via --private-users-delegate= which takes the number of ranges to delegate. On top of delegating the ranges, we also mount in the nsresourced socket and the mountfsd socket so that nested containers can use nsresourced to allocate from the delegated ranges and mountfsd to mount images. Finally, we also create /run/systemd/dissect-root with systemd-tmpfiles to make sure it is always available as unpriv users won't be able to create it themselves.
29 lines
1.3 KiB
Plaintext
29 lines
1.3 KiB
Plaintext
# This file is part of systemd.
|
|
#
|
|
# systemd is free software; you can redistribute it and/or modify it
|
|
# under the terms of the GNU Lesser General Public License as published by
|
|
# the Free Software Foundation; either version 2.1 of the License, or
|
|
# (at your option) any later version.
|
|
|
|
# See tmpfiles.d(5) for details.
|
|
|
|
Q /var/lib/machines 0700 - - -
|
|
|
|
# Remove old temporary snapshots, but only at boot. Ideally we'd have
|
|
# "self-destroying" btrfs snapshots that go away if the last
|
|
# reference to it does. To mimic a scheme like this at least remove
|
|
# the old snapshots on fresh boots, where we know they cannot be
|
|
# referenced anymore. Note that we actually remove all temporary files
|
|
# in /var/lib/machines/ at boot, which should be safe since the
|
|
# directory has defined semantics. In the root directory (where
|
|
# systemd-nspawn --ephemeral places snapshots) we are more strict, to
|
|
# avoid removing unrelated temporary files.
|
|
|
|
R! /var/lib/machines/.#*
|
|
R! /.#machine.*
|
|
|
|
# If the nsresourced/mountfsd sockets are mounted into /run/host, symlink them to their canonical
|
|
# location in /run/systemd.
|
|
L? /run/systemd/io.systemd.NamespaceResource - - - - /run/host/io.systemd.NamespaceResource
|
|
L? /run/systemd/io.systemd.MountFileSystem - - - - /run/host/io.systemd.MountFileSystem
|