Skip to content

mount2: add --direct-mount flag to prevent triggering fusermount SELi… - #10025

Open
nipil wants to merge 1 commit into
rclone:masterfrom
nipil:master
Open

nipil wants to merge 1 commit into
rclone:masterfrom
nipil:master

Conversation

@nipil

@nipil nipil commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

What does this change do?

Provides the --direct-mount flag with rclone mount2, and the option is not supported by rclone mount because legacy mount library does not support anything like this :

rclone mount2 --direct-mount remote:path /path/to/mountpoint

This flag makes rclone mount the filesystem directly via syscall.Mount instead of forking fusermount3. There is no fd transfer, no socketpair, and no behaviour SELinux would treat as a violation

By the way, --direct-mount requires access to /dev/fuse and of course appropriate permissions (root, or CAP_SYS_ADMIN plus proper AppArmor or seccomp configuration. I run it as root so these are validated for me.

I have used a coding agent to help me with this issue/PR.

I have run make quicktest, and all passed (once i put rclone in PATH or TestEndToEnd would fail)

I have tested this against the system which triggered the issue (debian 13 with SELinux enabled) and it solved my problem : rclone starts and works immediately even with SELinux enabled with an unchanged policy.

This is my first contribution to rclone, and i am new to go. Do not hesitate to tell me if anything needs changing.

Linked issue

#10024

Checklist

  • This change is trivial OR it has been discussed and agreed in the linked issue.
  • I have read the contribution guidelines.
  • (If I used AI tools to help write this code) I have read and understood the AI-assisted contributions guidance, and I have tested and take ownership of this change myself.
  • I have added tests for all changes in this PR if appropriate.
  • I have added documentation for the changes if appropriate.
  • All commit messages are in house style.
  • (Backend changes only) test_all passes for this backend and if submitting a new backend can provide a test account for the integration tester - see CONTRIBUTING.md.
  • This Pull Request is ready for review.

@nipil
nipil requested review from darthShadow and ncw as code owners October 2, 2026 07:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant