runtime: read_only local sources become :ro bind mounts

A local_code target can mark its tree read_only; collect_local_sources
forwards the flag and build_bind_mounts mounts the tree read-only instead
of relying on host mode bits, skipping the per-metadata remounts since the
whole tree is already immutable. Used for pulled container image layouts.
This commit is contained in:
Ahmed Allam 2026-09-20 03:03:28 +00:00 • committed by Ahmed Allam
parent 355a8bb437
commit 56e9ae982c
4 changed files with 43 additions and 5 deletions

View file

@ -1323,6 +1323,7 @@ def collect_local_sources(targets_info: list[dict[str, Any]]) -> list[dict[str,
"source_path": details["target_path"],
"workspace_subdir": workspace_subdir,
"protect_metadata": True,
"read_only": bool(details.get("read_only")),
}
)

View file

@ -70,8 +70,9 @@ def build_bind_mounts(local_sources: list[dict[str, Any]]) -> list[dict[str, Any
continue
resolved = Path(host_path).expanduser().resolve()
target = f"{_WORKSPACE_ROOT}/{ws_subdir}"
bind_mounts.append({"source": str(resolved), "target": target, "read_only": False})
if src.get("protect_metadata"):
read_only = bool(src.get("read_only"))
bind_mounts.append({"source": str(resolved), "target": target, "read_only": read_only})
if src.get("protect_metadata") and not read_only:
bind_mounts.extend(_metadata_mounts(resolved, target))
return bind_mounts

View file

@ -30,7 +30,26 @@ def _local_target(target_path: str) -> dict[str, Any]:
def test_collect_local_sources_protects_the_users_own_git() -> None:
sources = collect_local_sources([_local_target("/code")])
assert sources == [
{"source_path": "/code", "workspace_subdir": "repo", "protect_metadata": True}
{
"source_path": "/code",
"workspace_subdir": "repo",
"protect_metadata": True,
"read_only": False,
}
]
def test_collect_local_sources_forwards_read_only() -> None:
target = _local_target("/layout")
target["details"]["read_only"] = True
sources = collect_local_sources([target])
assert sources == [
{
"source_path": "/layout",
"workspace_subdir": "repo",
"protect_metadata": True,
"read_only": True,
}
]

View file

@ -27,8 +27,15 @@ from strix.runtime.session_manager import (
)
def _source(subdir: str, path: str, *, protect_metadata: bool = False) -> dict[str, Any]:
return {"source_path": path, "workspace_subdir": subdir, "protect_metadata": protect_metadata}
def _source(
subdir: str, path: str, *, protect_metadata: bool = False, read_only: bool = False
) -> dict[str, Any]:
return {
"source_path": path,
"workspace_subdir": subdir,
"protect_metadata": protect_metadata,
"read_only": read_only,
}
def test_source_becomes_writable_bind_mount(tmp_path: Path) -> None:
@ -124,6 +131,16 @@ def test_clone_keeps_its_git_writable(tmp_path: Path) -> None:
assert [m["target"] for m in mounts] == ["/workspace/clone"]
def test_read_only_source_is_one_read_only_mount(tmp_path: Path) -> None:
(tmp_path / ".git").mkdir()
mounts = build_bind_mounts(
[_source("image", str(tmp_path), protect_metadata=True, read_only=True)]
)
assert mounts == [
{"source": str(tmp_path.resolve()), "target": "/workspace/image", "read_only": True}
]
def test_multiple_sources_each_get_a_mount(tmp_path: Path) -> None:
first = tmp_path / "first"
second = tmp_path / "second"