Bug 1647769 - podman can't create rootless containers b/c newuidmap requires sys_admin
Summary: podman can't create rootless containers b/c newuidmap requires sys_admin
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: shadow-utils
Version: 29
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Tomas Mraz
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-11-08 10:33 UTC by Tomas Tomecek
Modified: 2018-12-01 20:40 UTC (History)
2 users (show)

Fixed In Version: shadow-utils-4.6-4.fc28 shadow-utils-4.6-4.fc29
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
: 1647778 (view as bug list)
Environment:
Last Closed: 2018-12-01 02:05:06 UTC


Attachments (Terms of Use)

Description Tomas Tomecek 2018-11-08 10:33:15 UTC
Description of problem:
newuidmap requires cap_sys_admin capability - this makes it impossible for podman to create new containers from within containers -- in a restricted environment.


Reproducer:
I am tracking the complete reproducer in a dedicated github repo. We are trying this in openshift directly.
https://github.com/TomasTomecek/rootless-podman-in-openshift


Additional info:
https://github.com/containers/libpod/issues/1092
https://github.com/genuinetools/img/issues/170
https://github.com/genuinetools/img/pull/171
https://github.com/shadow-maint/shadow/pull/132
https://github.com/shadow-maint/shadow/pull/136

Comment 1 Fedora Update System 2018-11-08 15:52:36 UTC
shadow-utils-4.6-4.fc29 has been submitted as an update to Fedora 29. https://bodhi.fedoraproject.org/updates/FEDORA-2018-053fa23050

Comment 2 Fedora Update System 2018-11-08 15:52:57 UTC
shadow-utils-4.6-4.fc28 has been submitted as an update to Fedora 28. https://bodhi.fedoraproject.org/updates/FEDORA-2018-783dfc5196

Comment 3 Fedora Update System 2018-11-09 07:45:12 UTC
shadow-utils-4.6-4.fc29 has been pushed to the Fedora 29 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2018-053fa23050

Comment 4 Fedora Update System 2018-11-09 07:50:05 UTC
shadow-utils-4.6-4.fc28 has been pushed to the Fedora 28 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2018-783dfc5196

Comment 5 Tomas Tomecek 2018-11-19 13:59:58 UTC
It fixes the issue.

Comment 6 Fedora Update System 2018-12-01 02:05:06 UTC
shadow-utils-4.6-4.fc28 has been pushed to the Fedora 28 stable repository. If problems still persist, please make note of it in this bug report.

Comment 7 Fedora Update System 2018-12-01 20:40:04 UTC
shadow-utils-4.6-4.fc29 has been pushed to the Fedora 29 stable repository. If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.