Refer to the notion of mount propagation instead which describes
the actual behaviour more clearly.
Reviewed-by: Peter Krempa <pkrempa@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
*
* Thus we call unshare(CLONE_NS) so that we can see
* the guest's new /dev/pts, without it becoming
- * visible to the host OS. We also put the root FS
- * into slave mode, just in case it was currently
- * marked as shared
+ * visible to the host OS. We also disable mount
+ * propagation out of the root FS, in case it was
+ * currently allowing bi-directional propagation.
*/
return virProcessSetupPrivateMountNS();
if (mount("", "/", "none", MS_SLAVE|MS_REC, NULL) < 0) {
virReportSystemError(errno, "%s",
- _("Failed to switch root mount into slave mode"));
+ _("Failed disable mount propagation out of the root filesystem"));
return -1;
}