OverlayFS Adding Support For IDMAPPED Layers For Various Benefits

Written by Michael Larabel in Linux Storage on 30 May 2022 at 05:46 AM EDT. 10 Comments
LINUX STORAGE
Sent in this morning for the Linux 5.19 merge window were the OverlayFS updates of which the main feature addition this cycle is support for IDMAPPED layers.

Merged last year was the Linux kernel support for IDMAPPED mounts for some interesting use-cases. Subsequent kernel releases has expanded the IDMAPPED mounts support across more file-systems. Now for Linux 5.19 there is IDMAPPED layers support for OverlayFS, the union mount file-system that is commonly used by IoT devices, Live USB/DVD distributions, and more.

With the OverlayFS IDMAPPED layers support developed by Christian Brauner, this can be used for better container support -- including for unprivileged containers -- and increasing isolation between containers. IDMAPPED layers with OverlayFS also overcomes the significant run-time overhead when otherwise needing to recursively change ownership/permissions on bigger layers, support for container run-times to use OverlayFS inside LXD containers, better integration with systemd-homed, and better supporting systemd's system extension images. More details from the patch series' cover letter of all the improvements that IDMAPPED layers for OverlayFS will allow.

That support is part of the OverlayFS updates for the Linux 5.19 merge window plus some fixes and new helpers.
Related News
About The Author
Michael Larabel

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.

Popular News This Week