2014-05-20 15:59:08 -04:00
|
|
|
|
;;; GNU Guix --- Functional package management for GNU
|
2019-07-19 05:48:19 -04:00
|
|
|
|
;;; Copyright © 2013, 2014, 2015, 2016, 2017, 2018, 2019 Ludovic Courtès <ludo@gnu.org>
|
2020-04-26 11:58:58 -04:00
|
|
|
|
;;; Copyright © 2020 Jakub Kądziołka <kuba@kadziolka.net>
|
2014-05-20 15:59:08 -04:00
|
|
|
|
;;;
|
|
|
|
|
;;; This file is part of GNU Guix.
|
|
|
|
|
;;;
|
|
|
|
|
;;; GNU Guix is free software; you can redistribute it and/or modify it
|
|
|
|
|
;;; under the terms of the GNU General Public License as published by
|
|
|
|
|
;;; the Free Software Foundation; either version 3 of the License, or (at
|
|
|
|
|
;;; your option) any later version.
|
|
|
|
|
;;;
|
|
|
|
|
;;; GNU Guix is distributed in the hope that it will be useful, but
|
|
|
|
|
;;; WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
|
;;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
|
;;; GNU General Public License for more details.
|
|
|
|
|
;;;
|
|
|
|
|
;;; You should have received a copy of the GNU General Public License
|
|
|
|
|
;;; along with GNU Guix. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
|
|
|
|
|
|
(define-module (gnu system file-systems)
|
2015-06-28 00:39:43 -04:00
|
|
|
|
#:use-module (ice-9 match)
|
2017-10-03 16:27:27 -04:00
|
|
|
|
#:use-module (rnrs bytevectors)
|
2017-02-06 09:42:00 -05:00
|
|
|
|
#:use-module (srfi srfi-1)
|
2018-05-18 07:43:07 -04:00
|
|
|
|
#:use-module (srfi srfi-9)
|
|
|
|
|
#:use-module (srfi srfi-9 gnu)
|
2014-05-20 15:59:08 -04:00
|
|
|
|
#:use-module (guix records)
|
2017-09-06 03:28:28 -04:00
|
|
|
|
#:use-module (gnu system uuid)
|
file-systems: Introduce (gnu system uuid).
* gnu/build/file-systems.scm (sub-bytevector)
(latin1->string, %fat32-endianness, fat32-uuid->string)
(%iso9660-uuid-rx, string->iso9660-uuid)
(iso9660-uuid->string, %network-byte-order)
(dce-uuid->string, %uuid-rx, string->dce-uuid)
(string->ext2-uuid, string->ext3-uuid, string->ext4-uuid)
(vhashq, %uuid-parsers, %uuid-printers, string->uuid)
(uuid->string): Move to...
* gnu/system/uuid.scm: ... here. New file.
* gnu/system/file-systems.scm (uuid): Move to the above file.
* gnu/system/vm.scm: Adjust accordingly.
* gnu/local.mk (GNU_SYSTEM_MODULES): Add uuid.scm.
2017-09-05 15:51:12 -04:00
|
|
|
|
#:re-export (uuid ;backward compatibility
|
|
|
|
|
string->uuid
|
2016-01-01 16:41:35 -05:00
|
|
|
|
uuid->string)
|
2018-05-18 04:11:17 -04:00
|
|
|
|
#:export (file-system
|
2014-05-20 15:59:08 -04:00
|
|
|
|
file-system?
|
|
|
|
|
file-system-device
|
2020-02-11 23:56:45 -05:00
|
|
|
|
file-system-device->string
|
2018-05-18 07:43:07 -04:00
|
|
|
|
file-system-title ;deprecated
|
2014-05-20 15:59:08 -04:00
|
|
|
|
file-system-mount-point
|
|
|
|
|
file-system-type
|
|
|
|
|
file-system-needed-for-boot?
|
|
|
|
|
file-system-flags
|
|
|
|
|
file-system-options
|
2015-12-21 18:25:40 -05:00
|
|
|
|
file-system-mount?
|
2014-07-22 16:53:36 -04:00
|
|
|
|
file-system-check?
|
|
|
|
|
file-system-create-mount-point?
|
2015-07-17 13:24:15 -04:00
|
|
|
|
file-system-dependencies
|
2017-10-04 15:35:31 -04:00
|
|
|
|
file-system-location
|
2014-05-20 15:59:08 -04:00
|
|
|
|
|
2017-03-21 16:55:20 -04:00
|
|
|
|
file-system-type-predicate
|
|
|
|
|
|
2018-05-18 07:43:07 -04:00
|
|
|
|
file-system-label
|
|
|
|
|
file-system-label?
|
|
|
|
|
file-system-label->string
|
|
|
|
|
|
2015-06-28 00:39:43 -04:00
|
|
|
|
file-system->spec
|
2016-11-10 11:45:54 -05:00
|
|
|
|
spec->file-system
|
2016-08-04 13:08:08 -04:00
|
|
|
|
specification->file-system-mapping
|
2015-06-28 00:39:43 -04:00
|
|
|
|
|
2018-04-27 09:31:37 -04:00
|
|
|
|
%pseudo-file-system-types
|
2014-05-20 15:59:08 -04:00
|
|
|
|
%fuse-control-file-system
|
2014-07-22 10:57:57 -04:00
|
|
|
|
%binary-format-file-system
|
2014-07-23 02:13:34 -04:00
|
|
|
|
%shared-memory-file-system
|
|
|
|
|
%pseudo-terminal-file-system
|
2016-09-27 05:20:40 -04:00
|
|
|
|
%tty-gid
|
2015-04-20 16:21:51 -04:00
|
|
|
|
%immutable-store
|
2015-06-18 20:40:57 -04:00
|
|
|
|
%control-groups
|
2015-09-03 16:58:08 -04:00
|
|
|
|
%elogind-file-systems
|
2014-07-22 10:57:57 -04:00
|
|
|
|
|
2014-09-11 17:39:15 -04:00
|
|
|
|
%base-file-systems
|
2015-06-28 00:42:16 -04:00
|
|
|
|
%container-file-systems
|
2014-09-11 17:39:15 -04:00
|
|
|
|
|
2015-06-27 10:45:34 -04:00
|
|
|
|
<file-system-mapping>
|
|
|
|
|
file-system-mapping
|
|
|
|
|
file-system-mapping?
|
|
|
|
|
file-system-mapping-source
|
|
|
|
|
file-system-mapping-target
|
|
|
|
|
file-system-mapping-writable?
|
|
|
|
|
|
2017-02-02 18:20:40 -05:00
|
|
|
|
file-system-mapping->bind-mount
|
|
|
|
|
|
2017-02-06 09:42:00 -05:00
|
|
|
|
%store-mapping
|
|
|
|
|
%network-configuration-files
|
|
|
|
|
%network-file-mappings))
|
2014-05-20 15:59:08 -04:00
|
|
|
|
|
|
|
|
|
;;; Commentary:
|
|
|
|
|
;;;
|
|
|
|
|
;;; Declaring file systems to be mounted.
|
|
|
|
|
;;;
|
2017-03-21 16:55:20 -04:00
|
|
|
|
;;; Note: this file system is used both in the Shepherd and on the "host
|
|
|
|
|
;;; side", so it must not include (gnu packages …) modules.
|
|
|
|
|
;;;
|
2014-05-20 15:59:08 -04:00
|
|
|
|
;;; Code:
|
|
|
|
|
|
|
|
|
|
;; File system declaration.
|
2018-05-18 07:43:07 -04:00
|
|
|
|
(define-record-type* <file-system> %file-system
|
2014-05-20 15:59:08 -04:00
|
|
|
|
make-file-system
|
|
|
|
|
file-system?
|
2018-05-18 07:43:07 -04:00
|
|
|
|
(device file-system-device) ; string | <uuid> | <file-system-label>
|
2014-05-20 15:59:08 -04:00
|
|
|
|
(mount-point file-system-mount-point) ; string
|
|
|
|
|
(type file-system-type) ; string
|
|
|
|
|
(flags file-system-flags ; list of symbols
|
|
|
|
|
(default '()))
|
|
|
|
|
(options file-system-options ; string or #f
|
|
|
|
|
(default #f))
|
2015-12-21 18:25:40 -05:00
|
|
|
|
(mount? file-system-mount? ; Boolean
|
|
|
|
|
(default #t))
|
2014-11-25 10:01:21 -05:00
|
|
|
|
(needed-for-boot? %file-system-needed-for-boot? ; Boolean
|
2014-05-20 15:59:08 -04:00
|
|
|
|
(default #f))
|
|
|
|
|
(check? file-system-check? ; Boolean
|
2014-07-22 16:53:36 -04:00
|
|
|
|
(default #t))
|
|
|
|
|
(create-mount-point? file-system-create-mount-point? ; Boolean
|
2015-07-17 13:24:15 -04:00
|
|
|
|
(default #f))
|
2015-10-29 13:22:19 -04:00
|
|
|
|
(dependencies file-system-dependencies ; list of <file-system>
|
2017-10-04 15:35:31 -04:00
|
|
|
|
(default '())) ; or <mapped-device>
|
|
|
|
|
(location file-system-location
|
|
|
|
|
(default (current-source-location))
|
|
|
|
|
(innate)))
|
2014-05-20 15:59:08 -04:00
|
|
|
|
|
2018-05-18 07:43:07 -04:00
|
|
|
|
;; A file system label for use in the 'device' field.
|
|
|
|
|
(define-record-type <file-system-label>
|
|
|
|
|
(file-system-label label)
|
|
|
|
|
file-system-label?
|
|
|
|
|
(label file-system-label->string))
|
|
|
|
|
|
|
|
|
|
(set-record-type-printer! <file-system-label>
|
|
|
|
|
(lambda (obj port)
|
|
|
|
|
(format port "#<file-system-label ~s>"
|
|
|
|
|
(file-system-label->string obj))))
|
|
|
|
|
|
|
|
|
|
(define-syntax report-deprecation
|
|
|
|
|
(lambda (s)
|
|
|
|
|
"Report the use of the now-deprecated 'title' field."
|
|
|
|
|
(syntax-case s ()
|
|
|
|
|
((_ field)
|
|
|
|
|
(let* ((source (syntax-source #'field))
|
|
|
|
|
(file (and source (assq-ref source 'filename)))
|
|
|
|
|
(line (and source
|
|
|
|
|
(and=> (assq-ref source 'line) 1+)))
|
|
|
|
|
(column (and source (assq-ref source 'column))))
|
|
|
|
|
(format (current-error-port)
|
|
|
|
|
"~a:~a:~a: warning: 'title' field is deprecated~%"
|
|
|
|
|
file line column)
|
|
|
|
|
#t)))))
|
|
|
|
|
|
|
|
|
|
;; Helper for 'process-file-system-declaration'.
|
|
|
|
|
(define-syntax device-expression
|
|
|
|
|
(syntax-rules (quote label uuid device)
|
|
|
|
|
((_ (quote label) dev)
|
|
|
|
|
(file-system-label dev))
|
|
|
|
|
((_ (quote uuid) dev)
|
|
|
|
|
(if (uuid? dev) dev (uuid dev)))
|
|
|
|
|
((_ (quote device) dev)
|
|
|
|
|
dev)
|
|
|
|
|
((_ title dev)
|
|
|
|
|
(case title
|
|
|
|
|
((label) (file-system-label dev))
|
|
|
|
|
((uuid) (uuid dev))
|
|
|
|
|
(else dev)))))
|
|
|
|
|
|
|
|
|
|
;; Helper to interpret the now-deprecated 'title' field. Detect forms like
|
|
|
|
|
;; (title 'label), remove them, and adjust the 'device' field accordingly.
|
|
|
|
|
;; TODO: Remove this once 'title' has been deprecated long enough.
|
|
|
|
|
(define-syntax process-file-system-declaration
|
|
|
|
|
(syntax-rules (device title)
|
|
|
|
|
((_ () (rest ...) #f #f) ;no 'title' and no 'device' field
|
|
|
|
|
(%file-system rest ...))
|
|
|
|
|
((_ () (rest ...) dev #f) ;no 'title' field
|
|
|
|
|
(%file-system rest ... (device dev)))
|
|
|
|
|
((_ () (rest ...) dev titl) ;got a 'title' field
|
|
|
|
|
(%file-system rest ...
|
|
|
|
|
(device (device-expression titl dev))))
|
|
|
|
|
((_ ((title titl) rest ...) (previous ...) dev _)
|
|
|
|
|
(begin
|
|
|
|
|
(report-deprecation (title titl))
|
|
|
|
|
(process-file-system-declaration (rest ...)
|
|
|
|
|
(previous ...)
|
|
|
|
|
dev titl)))
|
|
|
|
|
((_ ((device dev) rest ...) (previous ...) _ titl)
|
|
|
|
|
(process-file-system-declaration (rest ...)
|
|
|
|
|
(previous ...)
|
|
|
|
|
dev titl))
|
|
|
|
|
((_ (field rest ...) (previous ...) dev titl)
|
|
|
|
|
(process-file-system-declaration (rest ...)
|
|
|
|
|
(previous ... field)
|
|
|
|
|
dev titl))))
|
|
|
|
|
|
|
|
|
|
(define-syntax-rule (file-system fields ...)
|
|
|
|
|
(process-file-system-declaration (fields ...) () #f #f))
|
|
|
|
|
|
|
|
|
|
(define (file-system-title fs) ;deprecated
|
|
|
|
|
(match (file-system-device fs)
|
|
|
|
|
((? file-system-label?) 'label)
|
|
|
|
|
((? uuid?) 'uuid)
|
|
|
|
|
((? string?) 'device)))
|
|
|
|
|
|
2017-02-03 05:26:25 -05:00
|
|
|
|
;; Note: This module is used both on the build side and on the host side.
|
|
|
|
|
;; Arrange not to pull (guix store) and (guix config) because the latter
|
|
|
|
|
;; differs from user to user.
|
|
|
|
|
(define (%store-prefix)
|
|
|
|
|
"Return the store prefix."
|
2018-06-06 17:58:18 -04:00
|
|
|
|
;; Note: If we have (guix store database) in the search path and we do *not*
|
|
|
|
|
;; have (guix store) proper, 'resolve-module' returns an empty (guix store)
|
|
|
|
|
;; with one sub-module.
|
|
|
|
|
(cond ((and=> (resolve-module '(guix store) #:ensure #f)
|
|
|
|
|
(lambda (store)
|
|
|
|
|
(module-variable store '%store-prefix)))
|
2017-02-03 05:26:25 -05:00
|
|
|
|
=>
|
2018-06-06 17:58:18 -04:00
|
|
|
|
(lambda (variable)
|
|
|
|
|
((variable-ref variable))))
|
2017-02-03 05:26:25 -05:00
|
|
|
|
((getenv "NIX_STORE")
|
|
|
|
|
=> identity)
|
|
|
|
|
(else
|
|
|
|
|
"/gnu/store")))
|
|
|
|
|
|
2017-01-16 16:33:46 -05:00
|
|
|
|
(define %not-slash
|
|
|
|
|
(char-set-complement (char-set #\/)))
|
|
|
|
|
|
|
|
|
|
(define (file-prefix? file1 file2)
|
|
|
|
|
"Return #t if FILE1 denotes the name of a file that is a parent of FILE2,
|
|
|
|
|
where both FILE1 and FILE2 are absolute file name. For example:
|
|
|
|
|
|
|
|
|
|
(file-prefix? \"/gnu\" \"/gnu/store\")
|
|
|
|
|
=> #t
|
|
|
|
|
|
|
|
|
|
(file-prefix? \"/gn\" \"/gnu/store\")
|
|
|
|
|
=> #f
|
|
|
|
|
"
|
|
|
|
|
(and (string-prefix? "/" file1)
|
|
|
|
|
(string-prefix? "/" file2)
|
|
|
|
|
(let loop ((file1 (string-tokenize file1 %not-slash))
|
|
|
|
|
(file2 (string-tokenize file2 %not-slash)))
|
|
|
|
|
(match file1
|
|
|
|
|
(()
|
|
|
|
|
#t)
|
|
|
|
|
((head1 tail1 ...)
|
|
|
|
|
(match file2
|
|
|
|
|
((head2 tail2 ...)
|
|
|
|
|
(and (string=? head1 head2) (loop tail1 tail2)))
|
|
|
|
|
(()
|
|
|
|
|
#f)))))))
|
|
|
|
|
|
2020-02-11 23:56:45 -05:00
|
|
|
|
(define* (file-system-device->string device #:key uuid-type)
|
|
|
|
|
"Return the string representations of the DEVICE field of a <file-system>
|
|
|
|
|
record. When the device is a UUID, its representation is chosen depending on
|
|
|
|
|
UUID-TYPE, a symbol such as 'dce or 'iso9660."
|
|
|
|
|
(match device
|
|
|
|
|
((? file-system-label?)
|
|
|
|
|
(file-system-label->string device))
|
|
|
|
|
((? uuid?)
|
|
|
|
|
(if uuid-type
|
|
|
|
|
(uuid->string (uuid-bytevector device) uuid-type)
|
|
|
|
|
(uuid->string device)))
|
|
|
|
|
((? string?)
|
|
|
|
|
device)))
|
|
|
|
|
|
2017-01-16 16:33:46 -05:00
|
|
|
|
(define (file-system-needed-for-boot? fs)
|
|
|
|
|
"Return true if FS has the 'needed-for-boot?' flag set, or if it holds the
|
|
|
|
|
store--e.g., if FS is the root file system."
|
2014-11-25 10:01:21 -05:00
|
|
|
|
(or (%file-system-needed-for-boot? fs)
|
2017-01-16 16:33:46 -05:00
|
|
|
|
(and (file-prefix? (file-system-mount-point fs) (%store-prefix))
|
|
|
|
|
(not (memq 'bind-mount (file-system-flags fs))))))
|
2014-11-25 10:01:21 -05:00
|
|
|
|
|
2015-06-28 00:39:43 -04:00
|
|
|
|
(define (file-system->spec fs)
|
|
|
|
|
"Return a list corresponding to file-system FS that can be passed to the
|
|
|
|
|
initrd code."
|
|
|
|
|
(match fs
|
2018-05-18 07:43:07 -04:00
|
|
|
|
(($ <file-system> device mount-point type flags options _ _ check?)
|
|
|
|
|
(list (cond ((uuid? device)
|
|
|
|
|
`(uuid ,(uuid-type device) ,(uuid-bytevector device)))
|
|
|
|
|
((file-system-label? device)
|
|
|
|
|
`(file-system-label ,(file-system-label->string device)))
|
|
|
|
|
(else device))
|
|
|
|
|
mount-point type flags options check?))))
|
2015-06-28 00:39:43 -04:00
|
|
|
|
|
2016-11-10 11:45:54 -05:00
|
|
|
|
(define (spec->file-system sexp)
|
|
|
|
|
"Deserialize SEXP, a list, to the corresponding <file-system> object."
|
|
|
|
|
(match sexp
|
2018-05-18 07:43:07 -04:00
|
|
|
|
((device mount-point type flags options check?)
|
2016-11-10 11:45:54 -05:00
|
|
|
|
(file-system
|
2017-10-03 16:27:27 -04:00
|
|
|
|
(device (match device
|
|
|
|
|
(('uuid (? symbol? type) (? bytevector? bv))
|
|
|
|
|
(bytevector->uuid bv type))
|
2018-05-18 07:43:07 -04:00
|
|
|
|
(('file-system-label (? string? label))
|
|
|
|
|
(file-system-label label))
|
2017-10-03 16:27:27 -04:00
|
|
|
|
(_
|
|
|
|
|
device)))
|
2016-11-10 11:45:54 -05:00
|
|
|
|
(mount-point mount-point) (type type)
|
|
|
|
|
(flags flags) (options options)
|
|
|
|
|
(check? check?)))))
|
|
|
|
|
|
2016-08-04 13:08:08 -04:00
|
|
|
|
(define (specification->file-system-mapping spec writable?)
|
|
|
|
|
"Read the SPEC and return the corresponding <file-system-mapping>. SPEC is
|
|
|
|
|
a string of the form \"SOURCE\" or \"SOURCE=TARGET\". The former specifies
|
|
|
|
|
that SOURCE from the host should be mounted at SOURCE in the other system.
|
|
|
|
|
The latter format specifies that SOURCE from the host should be mounted at
|
|
|
|
|
TARGET in the other system."
|
|
|
|
|
(let ((index (string-index spec #\=)))
|
|
|
|
|
(if index
|
|
|
|
|
(file-system-mapping
|
|
|
|
|
(source (substring spec 0 index))
|
|
|
|
|
(target (substring spec (+ 1 index)))
|
|
|
|
|
(writable? writable?))
|
|
|
|
|
(file-system-mapping
|
|
|
|
|
(source spec)
|
|
|
|
|
(target spec)
|
|
|
|
|
(writable? writable?)))))
|
|
|
|
|
|
2015-07-14 09:06:46 -04:00
|
|
|
|
|
|
|
|
|
;;;
|
|
|
|
|
;;; Common file systems.
|
|
|
|
|
;;;
|
|
|
|
|
|
2018-04-27 09:31:37 -04:00
|
|
|
|
(define %pseudo-file-system-types
|
|
|
|
|
;; List of know pseudo file system types. This is used when validating file
|
|
|
|
|
;; system definitions.
|
2018-04-29 11:40:03 -04:00
|
|
|
|
'("binfmt_misc" "cgroup" "debugfs" "devpts" "devtmpfs" "efivarfs" "fusectl"
|
|
|
|
|
"hugetlbfs" "overlay" "proc" "securityfs" "sysfs" "tmpfs"))
|
2018-04-27 09:31:37 -04:00
|
|
|
|
|
2014-05-20 15:59:08 -04:00
|
|
|
|
(define %fuse-control-file-system
|
|
|
|
|
;; Control file system for Linux' file systems in user-space (FUSE).
|
|
|
|
|
(file-system
|
|
|
|
|
(device "fusectl")
|
|
|
|
|
(mount-point "/sys/fs/fuse/connections")
|
|
|
|
|
(type "fusectl")
|
|
|
|
|
(check? #f)))
|
|
|
|
|
|
|
|
|
|
(define %binary-format-file-system
|
|
|
|
|
;; Support for arbitrary executable binary format.
|
|
|
|
|
(file-system
|
|
|
|
|
(device "binfmt_misc")
|
|
|
|
|
(mount-point "/proc/sys/fs/binfmt_misc")
|
|
|
|
|
(type "binfmt_misc")
|
|
|
|
|
(check? #f)))
|
|
|
|
|
|
2014-07-22 17:13:53 -04:00
|
|
|
|
(define %tty-gid
|
|
|
|
|
;; ID of the 'tty' group. Allocate it statically to make it easy to refer
|
|
|
|
|
;; to it from here and from the 'tty' group definitions.
|
2014-07-24 18:12:35 -04:00
|
|
|
|
996)
|
2014-07-22 17:13:53 -04:00
|
|
|
|
|
|
|
|
|
(define %pseudo-terminal-file-system
|
|
|
|
|
;; The pseudo-terminal file system. It needs to be mounted so that
|
|
|
|
|
;; statfs(2) returns DEVPTS_SUPER_MAGIC like libc's getpt(3) expects (and
|
|
|
|
|
;; thus openpty(3) and its users, such as xterm.)
|
|
|
|
|
(file-system
|
|
|
|
|
(device "none")
|
|
|
|
|
(mount-point "/dev/pts")
|
|
|
|
|
(type "devpts")
|
|
|
|
|
(check? #f)
|
|
|
|
|
(needed-for-boot? #f)
|
|
|
|
|
(create-mount-point? #t)
|
|
|
|
|
(options (string-append "gid=" (number->string %tty-gid) ",mode=620"))))
|
2014-07-22 10:57:57 -04:00
|
|
|
|
|
2014-07-22 19:25:01 -04:00
|
|
|
|
(define %shared-memory-file-system
|
|
|
|
|
;; Shared memory.
|
|
|
|
|
(file-system
|
|
|
|
|
(device "tmpfs")
|
|
|
|
|
(mount-point "/dev/shm")
|
|
|
|
|
(type "tmpfs")
|
|
|
|
|
(check? #f)
|
|
|
|
|
(flags '(no-suid no-dev))
|
|
|
|
|
(options "size=50%") ;TODO: make size configurable
|
|
|
|
|
(create-mount-point? #t)))
|
|
|
|
|
|
2015-04-20 16:21:51 -04:00
|
|
|
|
(define %immutable-store
|
|
|
|
|
;; Read-only store to avoid users or daemons accidentally modifying it.
|
|
|
|
|
;; 'guix-daemon' has provisions to remount it read-write in its own name
|
|
|
|
|
;; space.
|
|
|
|
|
(file-system
|
|
|
|
|
(device (%store-prefix))
|
|
|
|
|
(mount-point (%store-prefix))
|
|
|
|
|
(type "none")
|
|
|
|
|
(check? #f)
|
2019-07-19 05:48:19 -04:00
|
|
|
|
(flags '(read-only bind-mount no-atime))))
|
2015-04-20 16:21:51 -04:00
|
|
|
|
|
2015-06-18 20:40:57 -04:00
|
|
|
|
(define %control-groups
|
2015-07-17 13:25:09 -04:00
|
|
|
|
(let ((parent (file-system
|
|
|
|
|
(device "cgroup")
|
|
|
|
|
(mount-point "/sys/fs/cgroup")
|
|
|
|
|
(type "tmpfs")
|
|
|
|
|
(check? #f))))
|
|
|
|
|
(cons parent
|
|
|
|
|
(map (lambda (subsystem)
|
|
|
|
|
(file-system
|
|
|
|
|
(device "cgroup")
|
|
|
|
|
(mount-point (string-append "/sys/fs/cgroup/" subsystem))
|
|
|
|
|
(type "cgroup")
|
|
|
|
|
(check? #f)
|
|
|
|
|
(options subsystem)
|
|
|
|
|
(create-mount-point? #t)
|
|
|
|
|
|
|
|
|
|
;; This must be mounted after, and unmounted before the
|
|
|
|
|
;; parent directory.
|
|
|
|
|
(dependencies (list parent))))
|
|
|
|
|
'("cpuset" "cpu" "cpuacct" "memory" "devices" "freezer"
|
2020-04-26 11:58:58 -04:00
|
|
|
|
"blkio" "perf_event" "pids")))))
|
2015-06-18 20:40:57 -04:00
|
|
|
|
|
2015-09-03 16:58:08 -04:00
|
|
|
|
(define %elogind-file-systems
|
|
|
|
|
;; We don't use systemd, but these file systems are needed for elogind,
|
|
|
|
|
;; which was extracted from systemd.
|
2017-12-22 02:43:24 -05:00
|
|
|
|
(append
|
|
|
|
|
(list (file-system
|
|
|
|
|
(device "none")
|
|
|
|
|
(mount-point "/run/systemd")
|
|
|
|
|
(type "tmpfs")
|
|
|
|
|
(check? #f)
|
|
|
|
|
(flags '(no-suid no-dev no-exec))
|
|
|
|
|
(options "mode=0755")
|
|
|
|
|
(create-mount-point? #t))
|
|
|
|
|
(file-system
|
|
|
|
|
(device "none")
|
|
|
|
|
(mount-point "/run/user")
|
|
|
|
|
(type "tmpfs")
|
|
|
|
|
(check? #f)
|
|
|
|
|
(flags '(no-suid no-dev no-exec))
|
|
|
|
|
(options "mode=0755")
|
|
|
|
|
(create-mount-point? #t))
|
|
|
|
|
;; Elogind uses cgroups to organize processes, allowing it to map PIDs
|
|
|
|
|
;; to sessions. Elogind's cgroup hierarchy isn't associated with any
|
|
|
|
|
;; resource controller ("subsystem").
|
|
|
|
|
(file-system
|
|
|
|
|
(device "cgroup")
|
|
|
|
|
(mount-point "/sys/fs/cgroup/elogind")
|
|
|
|
|
(type "cgroup")
|
|
|
|
|
(check? #f)
|
|
|
|
|
(options "none,name=elogind")
|
|
|
|
|
(create-mount-point? #t)
|
|
|
|
|
(dependencies (list (car %control-groups)))))
|
|
|
|
|
%control-groups))
|
2015-09-03 16:58:08 -04:00
|
|
|
|
|
2014-07-22 10:57:57 -04:00
|
|
|
|
(define %base-file-systems
|
|
|
|
|
;; List of basic file systems to be mounted. Note that /proc and /sys are
|
|
|
|
|
;; currently mounted by the initrd.
|
2017-12-22 02:43:24 -05:00
|
|
|
|
(list %pseudo-terminal-file-system
|
|
|
|
|
%shared-memory-file-system
|
|
|
|
|
%immutable-store))
|
2014-07-22 10:57:57 -04:00
|
|
|
|
|
2015-06-28 00:42:16 -04:00
|
|
|
|
;; File systems for Linux containers differ from %base-file-systems in that
|
|
|
|
|
;; they impose additional restrictions such as no-exec or need different
|
|
|
|
|
;; options to function properly.
|
|
|
|
|
;;
|
|
|
|
|
;; The file system flags and options conform to the libcontainer
|
|
|
|
|
;; specification:
|
|
|
|
|
;; https://github.com/docker/libcontainer/blob/master/SPEC.md#filesystem
|
|
|
|
|
(define %container-file-systems
|
|
|
|
|
(list
|
2015-07-13 10:10:40 -04:00
|
|
|
|
;; Pseudo-terminal file system.
|
2015-06-28 00:42:16 -04:00
|
|
|
|
(file-system
|
|
|
|
|
(device "none")
|
|
|
|
|
(mount-point "/dev/pts")
|
|
|
|
|
(type "devpts")
|
|
|
|
|
(flags '(no-exec no-suid))
|
|
|
|
|
(needed-for-boot? #t)
|
|
|
|
|
(create-mount-point? #t)
|
|
|
|
|
(check? #f)
|
|
|
|
|
(options "newinstance,ptmxmode=0666,mode=620"))
|
|
|
|
|
;; Shared memory file system.
|
|
|
|
|
(file-system
|
|
|
|
|
(device "tmpfs")
|
|
|
|
|
(mount-point "/dev/shm")
|
|
|
|
|
(type "tmpfs")
|
|
|
|
|
(flags '(no-exec no-suid no-dev))
|
|
|
|
|
(options "mode=1777,size=65536k")
|
|
|
|
|
(needed-for-boot? #t)
|
|
|
|
|
(create-mount-point? #t)
|
|
|
|
|
(check? #f))
|
|
|
|
|
;; Message queue file system.
|
|
|
|
|
(file-system
|
|
|
|
|
(device "mqueue")
|
|
|
|
|
(mount-point "/dev/mqueue")
|
|
|
|
|
(type "mqueue")
|
|
|
|
|
(flags '(no-exec no-suid no-dev))
|
|
|
|
|
(needed-for-boot? #t)
|
|
|
|
|
(create-mount-point? #t)
|
|
|
|
|
(check? #f))))
|
|
|
|
|
|
2015-06-27 10:45:34 -04:00
|
|
|
|
|
|
|
|
|
;;;
|
|
|
|
|
;;; Shared file systems, for VMs/containers.
|
|
|
|
|
;;;
|
|
|
|
|
|
|
|
|
|
;; Mapping of host file system SOURCE to mount point TARGET in the guest.
|
|
|
|
|
(define-record-type* <file-system-mapping> file-system-mapping
|
|
|
|
|
make-file-system-mapping
|
|
|
|
|
file-system-mapping?
|
|
|
|
|
(source file-system-mapping-source) ;string
|
|
|
|
|
(target file-system-mapping-target) ;string
|
|
|
|
|
(writable? file-system-mapping-writable? ;Boolean
|
|
|
|
|
(default #f)))
|
|
|
|
|
|
2017-02-02 18:20:40 -05:00
|
|
|
|
(define (file-system-mapping->bind-mount mapping)
|
|
|
|
|
"Return a file system that realizes MAPPING, a <file-system-mapping>, using
|
|
|
|
|
a bind mount."
|
|
|
|
|
(match mapping
|
|
|
|
|
(($ <file-system-mapping> source target writable?)
|
|
|
|
|
(file-system
|
|
|
|
|
(mount-point target)
|
|
|
|
|
(device source)
|
|
|
|
|
(type "none")
|
|
|
|
|
(flags (if writable?
|
|
|
|
|
'(bind-mount)
|
|
|
|
|
'(bind-mount read-only)))
|
|
|
|
|
(check? #f)
|
|
|
|
|
(create-mount-point? #t)))))
|
|
|
|
|
|
2015-06-27 10:45:34 -04:00
|
|
|
|
(define %store-mapping
|
|
|
|
|
;; Mapping of the host's store into the guest.
|
|
|
|
|
(file-system-mapping
|
|
|
|
|
(source (%store-prefix))
|
|
|
|
|
(target (%store-prefix))
|
|
|
|
|
(writable? #f)))
|
|
|
|
|
|
2017-02-06 09:42:00 -05:00
|
|
|
|
(define %network-configuration-files
|
|
|
|
|
;; List of essential network configuration files.
|
|
|
|
|
'("/etc/resolv.conf"
|
|
|
|
|
"/etc/nsswitch.conf"
|
|
|
|
|
"/etc/services"
|
|
|
|
|
"/etc/hosts"))
|
|
|
|
|
|
|
|
|
|
(define %network-file-mappings
|
|
|
|
|
;; List of file mappings for essential network files.
|
|
|
|
|
(filter-map (lambda (file)
|
|
|
|
|
(file-system-mapping
|
|
|
|
|
(source file)
|
|
|
|
|
(target file)
|
|
|
|
|
;; XXX: On some GNU/Linux systems, /etc/resolv.conf is a
|
|
|
|
|
;; symlink to a file in a tmpfs which, for an unknown reason,
|
|
|
|
|
;; cannot be bind mounted read-only within the container.
|
2019-11-04 17:00:08 -05:00
|
|
|
|
;; The same goes with /var/run/nscd, as discussed in
|
|
|
|
|
;; <https://bugs.gnu.org/37967>.
|
|
|
|
|
(writable? (or (string=? file "/etc/resolv.conf")
|
|
|
|
|
(string=? file "/var/run/nscd")))))
|
2019-09-12 16:17:43 -04:00
|
|
|
|
(cons "/var/run/nscd" %network-configuration-files)))
|
2017-02-06 09:42:00 -05:00
|
|
|
|
|
2017-03-18 05:38:51 -04:00
|
|
|
|
(define (file-system-type-predicate type)
|
2017-03-21 17:07:08 -04:00
|
|
|
|
"Return a predicate that, when passed a file system, returns #t if that file
|
|
|
|
|
system has the given TYPE."
|
2017-03-18 05:38:51 -04:00
|
|
|
|
(lambda (fs)
|
|
|
|
|
(string=? (file-system-type fs) type)))
|
|
|
|
|
|
2014-05-20 15:59:08 -04:00
|
|
|
|
;;; file-systems.scm ends here
|