Documentation
¶
Overview ¶
Package virtiofs builds the explicit host/guest mount plan for a microVM.
Index ¶
Constants ¶
const (
// GuestSkillAssets is the only guest namespace used for materialized skill payloads.
GuestSkillAssets = "/run/mecatl/skill-assets"
)
Variables ¶
var ( // ErrUnsafeMount rejects an absent, symlinked, overlapping, or otherwise // implicit host mount input. ErrUnsafeMount = errors.New("unsafe virtio-fs mount input") )
Functions ¶
This section is empty.
Types ¶
type Asset ¶
Asset names one payload file to copy into a session-owned materialization. Name is its logical slash-separated guest name; SourcePath is never mounted.
type MaterializedAssets ¶
type MaterializedAssets struct {
// contains filtered or unexported fields
}
MaterializedAssets is a session-owned copy of explicitly named skill files. Its host path is intentionally private so callers cannot turn an arbitrary directory (for example, a user home) into the skill-assets capability.
func MaterializeAssets ¶
func MaterializeAssets(destination string, assets []Asset) (_ *MaterializedAssets, retErr error)
MaterializeAssets copies only the explicitly named regular files into a new session-owned directory. The source tree (and therefore a user's home or config directory) is never itself a mount input.
type MountPlan ¶
type MountPlan struct {
// contains filtered or unexported fields
}
MountPlan is an ordered, validated set of virtio-fs devices. Reconstructed metadata is mounted separately and guest exec pins GIT_DIR to that path, so the linked worktree's host-path .git file is never consumed.
func Plan ¶
func Plan(prepared *worktree.Prepared, assets *MaterializedAssets) (MountPlan, error)
Plan builds the fixed worktree/Git mount set and, when non-nil, one session-owned materialized skill-assets mount.
func (MountPlan) Configure ¶
func (p MountPlan) Configure(runtime MountRuntime) error
Configure registers every guest target and creates its libkrun device. A read-only device always uses krun_add_virtiofs3 with read_only=true; it never falls back to go-microvm's guest-only ReadOnly flag.
func (MountPlan) GoMicroVMMounts ¶
func (p MountPlan) GoMicroVMMounts() []gomicrovm.VirtioFSMount
GoMicroVMMounts projects the validated plan onto go-microvm v0.0.41's host-enforced ReadOnly mount contract.
func (MountPlan) PrepareWorkloadAccess ¶
PrepareWorkloadAccess preserves host ownership and modes. The Linux libkrun backend maps guest workload UID/GID 65532 to the daemon user through its unprivileged user namespace, so making host trees world-accessible is neither necessary nor permitted.