fix(pglite): mount a dedicated scratch dir as the guest /tmp

The whole pglite data dir was mounted as the guest's /tmp, which also
exposed the cluster twice. The guest only needs its password file and
the shared-memory stand-ins there, so <DataFolder>/pglite/tmp is mounted
instead. The cluster and /dev mounts are unchanged.
This commit is contained in:
Deluan 2026-09-05 01:34:35 -04:00
commit b5dc2e43b6
2 changed files with 6 additions and 4 deletions

View file

@ -116,10 +116,12 @@ func New(ctx context.Context, cfg Config) (*PGlite, error) {
}
pgdataDir := filepath.Join(pg.dataDir, "pgdata")
devDir := filepath.Join(pg.dataDir, "dev")
// The guest's /tmp is a scratch dir of its own (password file, shm stand-ins), not the data dir.
tmpDir := filepath.Join(pg.dataDir, "tmp")
start := time.Now()
pg.stdin = &switchableStdin{}
tracker := newFDTracker(pg.dataDir, pgdataDir, devDir)
tracker := newFDTracker(tmpDir, pgdataDir, devDir)
ctx = experimental.WithFunctionListenerFactory(ctx, tracker)
runtimeCfg := wazero.NewRuntimeConfig()
if cfg.CacheDir != "" {
@ -157,7 +159,7 @@ func New(ctx context.Context, cfg Config) (*PGlite, error) {
WithEnv("PGTZ", "UTC").
WithEnv("PATH", "/tmp/pglite/bin").
WithFSConfig(wazero.NewFSConfig().
WithDirMount(pg.dataDir, "/tmp").
WithDirMount(tmpDir, "/tmp").
WithDirMount(pgdataDir, guestPGData).
WithDirMount(devDir, "/dev")).
WithStdin(pg.stdin).

View file

@ -10,7 +10,7 @@ import (
// setupDataDir prepares the host directories the guest mounts (cluster, /dev/urandom stand-in,
// initdb password file) and reports whether initdb still has to run.
func setupDataDir(dataDir string) (fresh bool, err error) {
for _, dir := range []string{"pgdata", "dev", "pglite"} {
for _, dir := range []string{"pgdata", "dev", filepath.Join("tmp", "pglite")} {
if err := os.MkdirAll(filepath.Join(dataDir, dir), 0o700); err != nil {
return false, fmt.Errorf("creating %s: %w", dir, err)
}
@ -26,7 +26,7 @@ func setupDataDir(dataDir string) (fresh bool, err error) {
}
}
// initdb's --pwfile; the bridge never checks it.
if err := os.WriteFile(filepath.Join(dataDir, "pglite", "password"), []byte("password\n"), 0o600); err != nil {
if err := os.WriteFile(filepath.Join(dataDir, "tmp", "pglite", "password"), []byte("password\n"), 0o600); err != nil {
return false, fmt.Errorf("writing password file: %w", err)
}
return !fileExists(filepath.Join(dataDir, "pgdata", "PG_VERSION")), nil