From b5dc2e43b6eaccf1d8090ce90282c694f6519980 Mon Sep 17 00:00:00 2001 From: Deluan Date: Sat, 5 Sep 2026 01:34:35 -0400 Subject: [PATCH] fix(pglite): mount a dedicated scratch dir as the guest /tmp The whole pglite data dir was mounted as the guest's /tmp, which also exposed the cluster twice. The guest only needs its password file and the shared-memory stand-ins there, so /pglite/tmp is mounted instead. The cluster and /dev mounts are unchanged. --- db/pglite/pglite.go | 6 ++++-- db/pglite/setup.go | 4 ++-- 2 files changed, 6 insertions(+), 4 deletions(-) diff --git a/db/pglite/pglite.go b/db/pglite/pglite.go index 0d2bb0b62..bbe7feb46 100644 --- a/db/pglite/pglite.go +++ b/db/pglite/pglite.go @@ -116,10 +116,12 @@ func New(ctx context.Context, cfg Config) (*PGlite, error) { } pgdataDir := filepath.Join(pg.dataDir, "pgdata") devDir := filepath.Join(pg.dataDir, "dev") + // The guest's /tmp is a scratch dir of its own (password file, shm stand-ins), not the data dir. + tmpDir := filepath.Join(pg.dataDir, "tmp") start := time.Now() pg.stdin = &switchableStdin{} - tracker := newFDTracker(pg.dataDir, pgdataDir, devDir) + tracker := newFDTracker(tmpDir, pgdataDir, devDir) ctx = experimental.WithFunctionListenerFactory(ctx, tracker) runtimeCfg := wazero.NewRuntimeConfig() if cfg.CacheDir != "" { @@ -157,7 +159,7 @@ func New(ctx context.Context, cfg Config) (*PGlite, error) { WithEnv("PGTZ", "UTC"). WithEnv("PATH", "/tmp/pglite/bin"). WithFSConfig(wazero.NewFSConfig(). - WithDirMount(pg.dataDir, "/tmp"). + WithDirMount(tmpDir, "/tmp"). WithDirMount(pgdataDir, guestPGData). WithDirMount(devDir, "/dev")). WithStdin(pg.stdin). diff --git a/db/pglite/setup.go b/db/pglite/setup.go index 3a404165b..af20e1bc9 100644 --- a/db/pglite/setup.go +++ b/db/pglite/setup.go @@ -10,7 +10,7 @@ import ( // setupDataDir prepares the host directories the guest mounts (cluster, /dev/urandom stand-in, // initdb password file) and reports whether initdb still has to run. func setupDataDir(dataDir string) (fresh bool, err error) { - for _, dir := range []string{"pgdata", "dev", "pglite"} { + for _, dir := range []string{"pgdata", "dev", filepath.Join("tmp", "pglite")} { if err := os.MkdirAll(filepath.Join(dataDir, dir), 0o700); err != nil { return false, fmt.Errorf("creating %s: %w", dir, err) } @@ -26,7 +26,7 @@ func setupDataDir(dataDir string) (fresh bool, err error) { } } // initdb's --pwfile; the bridge never checks it. - if err := os.WriteFile(filepath.Join(dataDir, "pglite", "password"), []byte("password\n"), 0o600); err != nil { + if err := os.WriteFile(filepath.Join(dataDir, "tmp", "pglite", "password"), []byte("password\n"), 0o600); err != nil { return false, fmt.Errorf("writing password file: %w", err) } return !fileExists(filepath.Join(dataDir, "pgdata", "PG_VERSION")), nil