Bug 1947432
Summary: | podman run --pid=host command causes OCI permission error | |||
---|---|---|---|---|
Product: | Red Hat Enterprise Linux 8 | Reporter: | Tom Sweeney <tsweeney> | |
Component: | podman | Assignee: | Jindrich Novy <jnovy> | |
Status: | CLOSED ERRATA | QA Contact: | Yuhui Jiang <yujiang> | |
Severity: | urgent | Docs Contact: | ||
Priority: | unspecified | |||
Version: | 8.4 | CC: | ajia, bbaude, dornelas, dwalsh, jligon, jnovy, kir, leiwang, lsm5, mheon, pthomas, tsweeney, umohnani, weshen, ypu, yujiang | |
Target Milestone: | rc | Keywords: | Triaged, ZStream | |
Target Release: | --- | |||
Hardware: | Unspecified | |||
OS: | Linux | |||
Whiteboard: | ||||
Fixed In Version: | runc-1.0.0-76.rc95.el8 or newer | Doc Type: | If docs needed, set a value | |
Doc Text: | Story Points: | --- | ||
Clone Of: | ||||
: | 1974907 2035227 (view as bug list) | Environment: | ||
Last Closed: | 2021-11-09 17:37:47 UTC | Type: | Bug | |
Regression: | --- | Mount Type: | --- | |
Documentation: | --- | CRM: | ||
Verified Versions: | Category: | --- | ||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
Cloudforms Team: | --- | Target Upstream Version: | ||
Embargoed: | ||||
Bug Depends On: | 1897579, 1989481 | |||
Bug Blocks: | 1974907, 2035227 |
Comment 2
Kir Kolyshkin
2021-04-08 17:30:36 UTC
After further discussions, we have decided to NOT deliver this in zero day, but instead, aim it towards RHEL 8.3.0.1. In addition, we will not be using Matt's workaround. We will backport the runc fix that Kir mentioned in https://bugzilla.redhat.com/show_bug.cgi?id=1947432#c2. Matt is working on readying that for RHEL. Ugh, dyslexia strikes again, in comment 3 I said we were aiming for 8.3.0.1, that is incorrect, we are aiming for 8.4.0.1. Apologies for the confusion. I gave a try for kolyshkin's patch, basically, it works for me w/ podman-3.0.1-6.module+el8.4.0+10487+af324045 and kernel-4.18.0-293, although I got some warning. https://github.com/opencontainers/runc/pull/2897#issuecomment-815975827 Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Moderate: container-tools:rhel8 security, bug fix, and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2021:4154 The needinfo request[s] on this closed bug have been removed as they have been unresolved for 500 days |