virtiofs

package
v0.0.0-...-c6d7338 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 10, 2026 License: Apache-2.0 Imports: 10 Imported by: 0

Documentation

Overview

Package virtiofs builds the explicit host/guest mount plan for a microVM.

Index

Constants

View Source
const (
	// GuestSkillAssets is the only guest namespace used for materialized skill payloads.
	GuestSkillAssets = "/run/mecatl/skill-assets"
)

Variables

View Source
var (
	// ErrUnsafeMount rejects an absent, symlinked, overlapping, or otherwise
	// implicit host mount input.
	ErrUnsafeMount = errors.New("unsafe virtio-fs mount input")
)

Functions

This section is empty.

Types

type Asset

type Asset struct {
	Name       string
	SourcePath string
}

Asset names one payload file to copy into a session-owned materialization. Name is its logical slash-separated guest name; SourcePath is never mounted.

type MaterializedAssets

type MaterializedAssets struct {
	// contains filtered or unexported fields
}

MaterializedAssets is a session-owned copy of explicitly named skill files. Its host path is intentionally private so callers cannot turn an arbitrary directory (for example, a user home) into the skill-assets capability.

func MaterializeAssets

func MaterializeAssets(destination string, assets []Asset) (_ *MaterializedAssets, retErr error)

MaterializeAssets copies only the explicitly named regular files into a new session-owned directory. The source tree (and therefore a user's home or config directory) is never itself a mount input.

type MountPlan

type MountPlan struct {
	// contains filtered or unexported fields
}

MountPlan is an ordered, validated set of virtio-fs devices. Reconstructed metadata is mounted separately and guest exec pins GIT_DIR to that path, so the linked worktree's host-path .git file is never consumed.

func Plan

func Plan(prepared *worktree.Prepared, assets *MaterializedAssets) (MountPlan, error)

Plan builds the fixed worktree/Git mount set and, when non-nil, one session-owned materialized skill-assets mount.

func (MountPlan) Configure

func (p MountPlan) Configure(runtime MountRuntime) error

Configure registers every guest target and creates its libkrun device. A read-only device always uses krun_add_virtiofs3 with read_only=true; it never falls back to go-microvm's guest-only ReadOnly flag.

func (MountPlan) GoMicroVMMounts

func (p MountPlan) GoMicroVMMounts() []gomicrovm.VirtioFSMount

GoMicroVMMounts projects the validated plan onto go-microvm v0.0.41's host-enforced ReadOnly mount contract.

func (MountPlan) PrepareWorkloadAccess

func (MountPlan) PrepareWorkloadAccess() error

PrepareWorkloadAccess preserves host ownership and modes. The Linux libkrun backend maps guest workload UID/GID 65532 to the daemon user through its unprivileged user namespace, so making host trees world-accessible is neither necessary nor permitted.

type MountRuntime

type MountRuntime interface {
	SetGuestVirtioFSMount(tag, guestPath string) error
	AddVirtioFS(tag, hostPath string) error
	AddVirtioFS3(tag, hostPath string, daxWindowSize uint64, readOnly bool) error
}

MountRuntime is the narrow test seam for applying a validated mount plan.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL