LINUXOR.SK ... open source notes ...

Namespaces 02 - MNT namespace

category: learnz/namespaces · date: 2016-11-01 · updated: 2017-01-16 · theme: github

Linux Namespaces Learning · Previous: Introduction · Next: UTS namespace

The Slovak original of this document: Namespaces 02 - MNT namespace (slovensky).

MNT (mount points and filesystems) namespaces in Linux

1 Introduction

The MNT namespace (mount points and filesystems) isolates the mount points a process, or a group of processes, can see, so programs in different MNT namespaces can have different views of the filesystem hierarchy. It is much like the isolation "chroot()" gives, except that an MNT namespace should be the safer and more flexible choice for the purpose.

MNT namespace
MNT namespace

2 Working with MNT namespaces

The examples use a user namespace (--user --map-root-user) so that no root is needed. As root the same commands work without these two options (unshare --mount ...).

2.1 The mounts of the default namespace

Count the mounts of the default namespace and note which MNT namespace the shell is in. Every process has its list of mounts in /proc/PID/mountinfo.

bash
$ wc -l < /proc/self/mountinfo
$ 28
$ head -2 /proc/self/mountinfo
$ 71 1 252:0 / / rw,relatime shared:1 - xfs /dev/mapper/vg-root rw,attr2,inode64,logbufs=8,logbsize=32k,noquota
$ 74 71 0:31 / /var/lib/nfs/rpc_pipefs rw,relatime shared:2 - rpc_pipefs rpc_pipefs rw
$ readlink /proc/self/ns/mnt
$ mnt:[4026531841]

2.2 Creating a new MNT namespace

Create a new MNT namespace and look at it from inside. It is a different namespace, yet it has the same 28 mounts: a new MNT namespace starts as a copy of the one it was created from, not as an empty tree.

bash
$ unshare --user --map-root-user --mount sh -c "readlink /proc/self/ns/mnt; wc -l < /proc/self/mountinfo"
$ mnt:[4026534269]
$ 28

2.3 A mount that only the new namespace sees

In terminal 1, create a MNT namespace, mount a tmpfs on /mnt in it, write a file there and leave a process running in the namespace.

bash
$ unshare --user --map-root-user --mount sh -c 'mount -t tmpfs none /mnt; echo hello > /mnt/file; findmnt /mnt; ls /mnt; exec sleep 611'
$ TARGET SOURCE FSTYPE OPTIONS
$ /mnt   none   tmpfs  rw,relatime,uid=1000,gid=1000,inode64
$ file

In terminal 2, in the default namespace, look for the same mount. findmnt prints nothing: the host does not see it.

bash
$ findmnt /mnt

What differs between two MNT namespaces is only what was mounted or unmounted after the copy was made.

2.4 Propagation

Whether a later mount is passed on to other namespaces is decided by the propagation type of each mount. On the host the root is shared. unshare sets everything in the new namespace to private, which is why the tmpfs above stayed inside.

bash
$ findmnt -o TARGET,PROPAGATION /
$ TARGET PROPAGATION
$ /      shared
$ unshare --user --map-root-user --mount findmnt -o TARGET,PROPAGATION /
$ TARGET PROPAGATION
$ /      private

2.5 Checking that the new MNT namespace exists

In terminal 2, find the namespace of the process left running in step 2.3 (here PID 1226729). Its mount list has one line more than the host, the tmpfs.

bash
$ readlink /proc/1226729/ns/mnt
$ mnt:[4026534269]
$ lsns -t mnt -p 1226729
$         NS TYPE NPROCS     PID USER COMMAND
$ 4026534269 mnt       1 1226729 user sleep 611
$ wc -l < /proc/1226729/mountinfo
$ 29
$ tail -1 /proc/1226729/mountinfo
$ 711 683 0:87 / /mnt rw,relatime - tmpfs none rw,uid=1000,gid=1000,inode64

2.6 Entering the namespace

nsenter runs a command in the namespaces of another process. The MNT namespace here belongs to a user namespace, so both are entered (-U -m); the file written in step 2.3 is there.

bash
$ nsenter -t 1226729 -U -m --preserve-credentials cat /mnt/file
$ hello
$ nsenter -t 1226729 -U -m --preserve-credentials findmnt /mnt
$ TARGET SOURCE FSTYPE OPTIONS
$ /mnt   none   tmpfs  rw,relatime,uid=1000,gid=1000,inode64

When the last process in the namespace ends (kill 1226729), the namespace and the tmpfs in it are gone.

Current practice (checked 2026-10)

noteThe article above was written in 2016; its practical part (section 2) was added in 2026 with current tools. This section lists what else is worth knowing today.

Sources:

← learnz/namespaces(EN | SK)