当进入 chroot 时,有时需要使用 -rbind 而不是 -bind 挂载 /sys 和 /dev 以确保当有人去寻找时一切都在正确的位置。
卸载时出现问题。
一个简单的 umount 总是失败;随着孩子们也被安装,它似乎正在使用:
$ umount /mnt/chroot/sys
umount: /mnt/chroot/sys: device is busy.
(In some cases useful info about processes that use
the device is found by lsof(8) or fuser(1))
Run Code Online (Sandbox Code Playgroud)
另一种可能的解决方案是从 proc 中列出挂载,然后像这样卸载每个挂载:
$ grep /mnt/chroot/sys /proc/mounts | cut -f2 -d" " | sort -r | xargs umount
Run Code Online (Sandbox Code Playgroud)
但是,这也失败了,因为递归挂载实际上并未在 mtab 中注册:
/mnt/chroot/sys/kernel/security is not mounted (according to mtab)
Run Code Online (Sandbox Code Playgroud)
也许解决方案是执行惰性卸载,但这对我来说似乎很危险。
有没有更好的方法来做到这一点,我错过了?