feat(vm): support shared folder mounts - #4179
Closed
hasnatelias wants to merge 1 commit into
Closed
hasnatelias wants to merge 1 commit into
hasnatelias wants to merge 1 commit into
Conversation
Signed-off-by: hasnatelias <eliashasnat@outlook.jp>
hasnatelias
requested review from
a team,
derekwaynecarr,
mrunalp and
sjenning
as code owners
October 4, 2026 11:27
|
Thank you for your interest in contributing to OpenShell, @hasnatelias. This project uses a vouch system for first-time contributors. Before submitting a pull request, you need to be vouched by a maintainer. To get vouched:
See CONTRIBUTING.md for details. |
|
Thank you for your submission! We ask that you sign our Developer Certificate of Origin before we can accept your contribution. You can sign the DCO by adding a comment below using this text: I have read the DCO document and I hereby sign the DCO. You can retrigger this bot by commenting recheck in this Pull Request. Posted by the DCO Assistant Lite bot. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds shared host-folder support for libkrun-based VM sandboxes using virtiofs. Operators can expose host directories inside a VM with live, bidirectional updates through VM-specific driver configuration.
Related Issue
WIP #2585
Changes
mountsconfiguration compatible with Docker and Podman bind-mount entries.enable_bind_mountsoperator-controlled safety gate.krun_add_virtiofs4.Architecture
flowchart LR subgraph Host["Host / Gateway Machine"] HD["Host directory<br/><code>/host/project</code>"] CFG["Sandbox configuration<br/><code>driver_config.vm.mounts[]</code>"] DRV["OpenShell VM driver<br/>Validate paths and assign<br/><code>osfs<N></code> tags"] KRUN["libkrun<br/><code>krun_add_virtiofs4(...)</code>"] HD --> CFG CFG --> DRV DRV --> KRUN end subgraph Guest["VM Sandbox"] BOOT["VM boot<br/>Read driver-owned<br/>mount manifest"] MOUNT["Guest initialization<br/><code>mount -t virtiofs</code>"] TARGET["Shared guest directory<br/><code>/sandbox/project</code>"] WORKLOAD["Sandbox workload"] BOOT --> MOUNT MOUNT --> TARGET TARGET --> WORKLOAD end KRUN -->|"virtiofs export"| BOOT TARGET -. "guest writes propagate to host" .-> HD HD -. "host writes appear in guest" .-> TARGETExample:
{ "vm": { "mounts": [ { "type": "bind", "source": "/host/project", "target": "/sandbox/project", "read_only": false } ] } }The gateway administrator must explicitly enable caller-provided configuration and VM bind mounts:
Testing
Current verification performed:
git diff --check— passed.VM guest-init shell syntax check with
bash -n— passed.VM E2E runner shell syntax check with
bash -n— passed.Added unit coverage for parsing, read-only defaults, multiple mounts, invalid sources and targets, duplicate and overlapping targets, reserved paths, QEMU rejection, manifest generation, and launch-argument parsing.
Added a VM E2E test covering host-to-guest visibility, guest-to-host writes, and read-only enforcement.
Rust formatting and tests were not executed locally because
cargoandmisewere unavailable.The VM E2E test was not executed locally because it requires a supported macOS/HVF or Linux/KVM host with libkrun.
Checks appropriate to the affected code and behavior pass
Unit tests added/updated
E2E tests added/updated
Checklist