Skip to content

Preserve readonly flag when converting mounts to -v for WSLc - #1314

Open
Akio Takahashi (akiotakahashi) wants to merge 2 commits into
devcontainers:mainfrom
akiotakahashi:fix-wslc-readonly-mounts
Open

Akio Takahashi (akiotakahashi) wants to merge 2 commits into
devcontainers:mainfrom
akiotakahashi:fix-wslc-readonly-mounts

Conversation

@akiotakahashi

Copy link
Copy Markdown

Problem

When the CLI drives WSL containers (--docker-path wslc, CLIVariant.Wslc added in #1249), --mount strings are converted to -v syntax by convertMountToVolume in src/spec-node/singleContainer.ts. The conversion only reads source and target, so the readonly / ro option is silently dropped for the workspaceMount and for every entry of mounts. Mounts that a devcontainer.json declares readonly end up writable inside the container.

Observed with @devcontainers/cli 0.89.0 and wslc 3.0.1 (GA) on Windows 11: a config with 15 readonly mounts produced a wslc run command line containing no :ro at all, and a file behind a readonly mount could be modified from inside the container.

wslc itself supports the readonly suffix — wslc run -v C:/path:/mnt:ro ... correctly yields a read-only mount (verified with wslc 3.0.1, including drive-letter source paths) — so this is purely a conversion issue.

Fix

convertMountToVolume now appends :ro when the mount string carries readonly or ro (bare, or with a value other than false/0), matching Docker's --mount semantics. Other options (type, consistency) are dropped as before.

The function is exported for testing and unit tests are added in src/test/singleContainer.test.ts covering the bare/valued readonly/ro forms, readonly=false, named volumes, Windows source paths, and the target-only and fallback paths.

Notes

  • Object-form mounts are unaffected: generateMountCommand never emits readonly for them, and the Mount interface has no such field.
  • Dependency installation was not possible in the environment used to author this change, so the new tests were not executed locally; relying on CI here.

🤖 Generated with Claude Code

https://claude.ai/code/session_018psPhUnN32LKjqd4ZkATtP

@akiotakahashi

Copy link
Copy Markdown
Author

@microsoft-github-policy-service agree

The WSLc code path converts --mount strings to -v syntax but dropped
the readonly/ro option, so every mount declared readonly in
devcontainer.json was mounted writable. wslc supports the
"-v source:target:ro" suffix (verified with wslc 3.0.1), so append
":ro" when the mount string carries readonly/ro unless its value is
explicitly false.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018psPhUnN32LKjqd4ZkATtP
Keep consistency=cached in the example so it still illustrates that
options other than source/target/readonly are dropped.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018psPhUnN32LKjqd4ZkATtP

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant