From: AdrianF <adrian.freihofer@siemens.com>
To: openembedded-core@lists.openembedded.org
Cc: Adrian Freihofer <adrian.freihofer@siemens.com>
Subject: [PATCH 7/9] runqemu-export-rootfs: set PSEUDO_INCLUDE_PATHS for unfsd
Date: Sun, 6 Sep 2026 23:02:05 +0200 [thread overview]
Message-ID: <20260906210307.2793974-8-adrian.freihofer@siemens.com> (raw)
In-Reply-To: <20260906210307.2793974-1-adrian.freihofer@siemens.com>
From: Adrian Freihofer <adrian.freihofer@siemens.com>
pseudo inverted its path-matching logic some time ago: when set,
PSEUDO_INCLUDE_PATHS acts as an ownership-tracking allowlist, and
anything outside it silently falls through to real chown()/chmod()
instead of being recorded by pseudo. This script never set it, so an
inherited restrictive value could leave files touched by unfsd on
behalf of NFS clients with wrong ownership. Since this script only
ever touches NFS_EXPORT_DIR, setting PSEUDO_INCLUDE_PATHS to it is
enough.
Signed-off-by: Adrian Freihofer <adrian.freihofer@siemens.com>
---
scripts/runqemu-export-rootfs | 2 ++
1 file changed, 2 insertions(+)
diff --git a/scripts/runqemu-export-rootfs b/scripts/runqemu-export-rootfs
index 6a8acd0d5a..150513bc50 100755
--- a/scripts/runqemu-export-rootfs
+++ b/scripts/runqemu-export-rootfs
@@ -56,6 +56,8 @@ MOUNTPID=~/.runqemu-sdk/mount$NFS_INSTANCE.pid
PSEUDO_OPTS="-P $OECORE_NATIVE_SYSROOT/usr"
PSEUDO_LOCALSTATEDIR="$NFS_EXPORT_DIR/../$(basename $NFS_EXPORT_DIR).pseudo_state"
export PSEUDO_LOCALSTATEDIR
+PSEUDO_INCLUDE_PATHS="$NFS_EXPORT_DIR"
+export PSEUDO_INCLUDE_PATHS
if [ ! -d "$PSEUDO_LOCALSTATEDIR" ]; then
echo "Error: $PSEUDO_LOCALSTATEDIR does not exist."
--
2.55.0
next prev parent reply other threads:[~2026-09-06 21:03 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-06 21:01 [PATCH 0/9] devtool: ide-sdk: bug fixes, do_install-through-bitbake, NFS deploy prep AdrianF
2026-09-06 21:01 ` [PATCH 1/9] devtool: ide-sdk: fix GDB loading stale libs instead of recipe's own build AdrianF
2026-09-06 21:02 ` [PATCH 2/9] oe-selftest: devtool ide-sdk: do not guess the slirp SSH port AdrianF
2026-09-06 21:19 ` Patchtest results for " patchtest
2026-09-06 21:02 ` [PATCH 3/9] devtool: ide-sdk: pre-select attach process with processFilter AdrianF
2026-09-06 21:02 ` [PATCH 4/9] oe-selftest: tinfoil: test prepared task runner AdrianF
2026-09-06 21:02 ` [PATCH 5/9] devtool: ide-sdk: run do_install through BitBake AdrianF
2026-09-06 21:02 ` [PATCH 6/9] oe-selftest: devtool ide-sdk: test install task AdrianF
2026-09-06 21:02 ` AdrianF [this message]
2026-09-06 21:02 ` [PATCH 8/9] devtool: deploy: make pseudo calls independent of bitbake.conf AdrianF
2026-09-06 21:02 ` [PATCH 9/9] devtool: deploy: remove dead files_list computation AdrianF
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260906210307.2793974-8-adrian.freihofer@siemens.com \
--to=adrian.freihofer@siemens.com \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox