Bug 1713054
| Summary: | Runnning podman build as non root user fails | ||||||
|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Jakub Bittner <jbittner> | ||||
| Component: | podman | Assignee: | Giuseppe Scrivano <gscrivan> | ||||
| Status: | CLOSED NOTABUG | QA Contact: | atomic-bugs <atomic-bugs> | ||||
| Severity: | unspecified | Docs Contact: | |||||
| Priority: | unspecified | ||||||
| Version: | 8.0 | CC: | avi.kivity, dornelas, dwalsh, fedoraproject, jligon, jnovy, lsm5, mheon, tsweeney | ||||
| Target Milestone: | rc | ||||||
| Target Release: | 8.0 | ||||||
| Hardware: | x86_64 | ||||||
| OS: | Linux | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2019-07-29 07:44:56 UTC | Type: | Bug | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Attachments: |
|
||||||
Jakub a quick couple of questions. Can you include the Dockerfile that you're using when you're running into this issue as a reply to this email please? I unfortunately have to dash and won't be able to check until tomorrow. But I think the issue is you've setup the usernamespace appropriately, but have not told the build command how to use it. If you've the time, can you try: `podman build --userns-uid-map-user jbittner --userns-gid-map-group jbittner-t container-name .` Thanks! Jakub, do you have entryies for your username in /etc/subuid and /etc/subgid? dwalsh, yep he does. Jakub, I don't know if you've access, but the latest Podman on brew is 1.3.1. If you can upgrade from there, that would be of help. Unfortunately it's not yet in extras, only brew. I'm having trouble getting the same error as you. I'm running into a separate one where 'newuidmap' can't be found. One of my colleagues suggested adding the option `--isolation chroot` to your command ala ` podman build --isolation chroot -t container-name .`. I'm not sure that will cure it, but thought I'd let you know in case you want to try while I continue to work out my issues. Hey Tom, I have access to Brew, but I can see podman 1.3.1 builds for RHEL 7 only (I am running RHEL 8). Does it matter or should I try el7 version? `--isolation chroot` has the same problem. Hey Jakub, I've talked with a few folks here in the group and it looks like 1.3.1 won't help. We believe there's a kernel issue that may be keeping rootless Podman from working at this time on RHEL. https://bugzilla.redhat.com/show_bug.cgi?id=1713642 Will keep you posted. Hey Tom, I am running RHEL 8. If you just run $ podman run -ti ubi8 echo test Does this work? Could this be newuidmap and newgidmap are not using NSSWITCH to figure out the user name? $ podman run -ti ubi8 echo test error creating libpod runtime: Error running podman info while refreshing state: exit status 1 I use ipa enabled machine and user I run podman commands is in IPA only. Not a local user. cat /etc/nsswitch.conf|grep -v "^#" passwd: sss files systemd group: sss files systemd netgroup: sss files automount: sss files services: sss files shadow: files sss hosts: files dns myhostname bootparams: files ethers: files netmasks: files networks: files protocols: files rpc: files publickey: files aliases: files If you don't have local entries in /etc/subuid and /etc/subgid, then you can only use a signle UID within your container image. If UBI8 includes more then one UID, then it will fail. Daniel, I have entries in /etc/subuid and /etc/subgid. Even running command "podman info" produces error. $ podman info ERRO[0000] cannot setup namespace using newuidmap: exit status 1 cat /etc/subuid jbittner:100000:65536 cat /etc/subgid jbittner:100000:65536 First could you make sure this is not SELinux, by attempting to run with `setenforce 0` Can you execute buildah unshare To see if this passes? If this fails, try `buildah --debug unshare` I did, same result. # getenforce Permissive $ buildah unshare Error: error running newgidmap: exit status 1: newgidmap: write to gid_map failed: Invalid argument $ buildah --debug unshare DEBU[0000] running [buildah-in-a-user-namespace --debug unshare] with environment [LS_COLORS=rs=0:di=38;5;33:ln=38;5;51:mh=00:pi=40;38;5;11:so=38;5;13:do=38;5;5:bd=48;5;232;38;5;11:cd=48;5;232;38;5;3:or=48;5;232;38;5;9:mi=01;05;37;41:su=48;5;196;38;5;15:sg=48;5;11;38;5;16:ca=48;5;196;38;5;226:tw=48;5;10;38;5;16:ow=48;5;10;38;5;21:st=48;5;21;38;5;15:ex=38;5;40:*.tar=38;5;9:*.tgz=38;5;9:*.arc=38;5;9:*.arj=38;5;9:*.taz=38;5;9:*.lha=38;5;9:*.lz4=38;5;9:*.lzh=38;5;9:*.lzma=38;5;9:*.tlz=38;5;9:*.txz=38;5;9:*.tzo=38;5;9:*.t7z=38;5;9:*.zip=38;5;9:*.z=38;5;9:*.dz=38;5;9:*.gz=38;5;9:*.lrz=38;5;9:*.lz=38;5;9:*.lzo=38;5;9:*.xz=38;5;9:*.zst=38;5;9:*.tzst=38;5;9:*.bz2=38;5;9:*.bz=38;5;9:*.tbz=38;5;9:*.tbz2=38;5;9:*.tz=38;5;9:*.deb=38;5;9:*.rpm=38;5;9:*.jar=38;5;9:*.war=38;5;9:*.ear=38;5;9:*.sar=38;5;9:*.rar=38;5;9:*.alz=38;5;9:*.ace=38;5;9:*.zoo=38;5;9:*.cpio=38;5;9:*.7z=38;5;9:*.rz=38;5;9:*.cab=38;5;9:*.wim=38;5;9:*.swm=38;5;9:*.dwm=38;5;9:*.esd=38;5;9:*.jpg=38;5;13:*.jpeg=38;5;13:*.mjpg=38;5;13:*.mjpeg=38;5;13:*.gif=38;5;13:*.bmp=38;5;13:*.pbm=38;5;13:*.pgm=38;5;13:*.ppm=38;5;13:*.tga=38;5;13:*.xbm=38;5;13:*.xpm=38;5;13:*.tif=38;5;13:*.tiff=38;5;13:*.png=38;5;13:*.svg=38;5;13:*.svgz=38;5;13:*.mng=38;5;13:*.pcx=38;5;13:*.mov=38;5;13:*.mpg=38;5;13:*.mpeg=38;5;13:*.m2v=38;5;13:*.mkv=38;5;13:*.webm=38;5;13:*.ogm=38;5;13:*.mp4=38;5;13:*.m4v=38;5;13:*.mp4v=38;5;13:*.vob=38;5;13:*.qt=38;5;13:*.nuv=38;5;13:*.wmv=38;5;13:*.asf=38;5;13:*.rm=38;5;13:*.rmvb=38;5;13:*.flc=38;5;13:*.avi=38;5;13:*.fli=38;5;13:*.flv=38;5;13:*.gl=38;5;13:*.dl=38;5;13:*.xcf=38;5;13:*.xwd=38;5;13:*.yuv=38;5;13:*.cgm=38;5;13:*.emf=38;5;13:*.ogv=38;5;13:*.ogx=38;5;13:*.aac=38;5;45:*.au=38;5;45:*.flac=38;5;45:*.m4a=38;5;45:*.mid=38;5;45:*.midi=38;5;45:*.mka=38;5;45:*.mp3=38;5;45:*.mpc=38;5;45:*.ogg=38;5;45:*.ra=38;5;45:*.wav=38;5;45:*.oga=38;5;45:*.opus=38;5;45:*.spx=38;5;45:*.xspf=38;5;45: XDG_MENU_PREFIX=gnome- MODULES_RUN_QUARANTINE=LD_LIBRARY_PATH LANG=en_US.UTF-8 GDM_LANG=en_US.UTF-8 HISTCONTROL=ignoredups DISPLAY=:0 HOSTNAME=alca.users.ipa.redhat.com COLORTERM=truecolor USERNAME=jbittner XDG_VTNR=2 SSH_AUTH_SOCK=/run/user/102492/keyring/ssh XDG_SESSION_ID=2 MODULES_CMD=/usr/share/Modules/libexec/modulecmd.tcl USER=jbittner ENV=/usr/share/Modules/init/profile.sh DESKTOP_SESSION=gnome WAYLAND_DISPLAY=wayland-0 GNOME_TERMINAL_SCREEN=/org/gnome/Terminal/screen/05dd6cbf_3ce9_4e7a_b271_99fa8985d629 PWD=/home/jbittner HOME=/home/jbittner XDG_SESSION_TYPE=wayland KRB5CCNAME=KCM: BASH_ENV=/usr/share/Modules/init/bash XDG_DATA_DIRS=/home/jbittner/.local/share/flatpak/exports/share/:/var/lib/flatpak/exports/share/:/usr/local/share/:/usr/share/ XDG_SESSION_DESKTOP=gnome GJS_DEBUG_OUTPUT=stderr LOADEDMODULES= MAIL=/var/spool/mail/jbittner VTE_VERSION=5202 SHELL=/bin/bash TERM=xterm-256color QT_IM_MODULE=ibus XMODIFIERS=@im=ibus XDG_CURRENT_DESKTOP=GNOME GNOME_TERMINAL_SERVICE=:1.94 XDG_SEAT=seat0 SHLVL=2 MODULEPATH=/etc/scl/modulefiles:/etc/scl/modulefiles:/usr/share/Modules/modulefiles:/etc/modulefiles:/usr/share/modulefiles GDMSESSION=gnome GNOME_DESKTOP_SESSION_ID=this-is-deprecated LOGNAME=jbittner DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/102492/bus XDG_RUNTIME_DIR=/run/user/102492 MODULEPATH_modshare=/usr/share/modulefiles:1:/etc/modulefiles:1:/usr/share/Modules/modulefiles:1 PATH=/home/jbittner/.local/bin:/home/jbittner/bin:/home/jbittner/.local/bin:/home/jbittner/bin:/usr/share/Modules/bin:/usr/local/bin:/usr/local/sbin:/usr/bin:/usr/sbin MODULESHOME=/usr/share/Modules HISTSIZE=1000 GJS_DEBUG_TOPICS=JS ERROR;JS LOG SESSION_MANAGER=local/unix:@/tmp/.ICE-unix/8093,unix/unix:/tmp/.ICE-unix/8093 LESSOPEN=||/usr/bin/lesspipe.sh %s BASH_FUNC_module%%=() { _moduleraw "$@" 2>&1 } BASH_FUNC_switchml%%=() { typeset swfound=1; if [ "${MODULES_USE_COMPAT_VERSION:-0}" = '1' ]; then typeset swname='main'; if [ -e /usr/share/Modules/libexec/modulecmd.tcl ]; then typeset swfound=0; unset MODULES_USE_COMPAT_VERSION; fi; else typeset swname='compatibility'; if [ -e /usr/share/Modules/libexec/modulecmd-compat ]; then typeset swfound=0; MODULES_USE_COMPAT_VERSION=1; export MODULES_USE_COMPAT_VERSION; fi; fi; if [ $swfound -eq 0 ]; then echo "Switching to Modules $swname version"; source /usr/share/Modules/init/bash; else echo "Cannot switch to Modules $swname version, command not found"; return 1; fi } BASH_FUNC_scl%%=() { if [ "$1" = "load" -o "$1" = "unload" ]; then eval "module $@"; else /usr/bin/scl "$@"; fi } BASH_FUNC__moduleraw%%=() { unset _mlre _mlIFS _mlshdbg; if [ "${MODULES_SILENT_SHELL_DEBUG:-0}" = '1' ]; then case "$-" in *v*x*) set +vx; _mlshdbg='vx' ;; *v*) set +v; _mlshdbg='v' ;; *x*) set +x; _mlshdbg='x' ;; *) _mlshdbg='' ;; esac; fi; if [ -n "${IFS+x}" ]; then _mlIFS=$IFS; fi; IFS=' '; for _mlv in ${MODULES_RUN_QUARANTINE:-}; do if [ "${_mlv}" = "${_mlv##*[!A-Za-z0-9_]}" -a "${_mlv}" = "${_mlv#[0-9]}" ]; then if [ -n "`eval 'echo ${'$_mlv'+x}'`" ]; then _mlre="${_mlre:-}${_mlv}_modquar='`eval 'echo ${'$_mlv'}'`' "; fi; _mlrv="MODULES_RUNENV_${_mlv}"; _mlre="${_mlre:-}${_mlv}='`eval 'echo ${'$_mlrv':-}'`' "; fi; done; if [ -n "${_mlre:-}" ]; then eval `eval ${_mlre}/usr/bin/tclsh /usr/share/Modules/libexec/modulecmd.tcl bash '"$@"'`; else eval `/usr/bin/tclsh /usr/share/Modules/libexec/modulecmd.tcl bash "$@"`; fi; _mlstatus=$?; if [ -n "${_mlIFS+x}" ]; then IFS=$_mlIFS; else unset IFS; fi; if [ -n "${_mlshdbg:-}" ]; then set -$_mlshdbg; fi; unset _mlre _mlv _mlrv _mlIFS _mlshdbg; return $_mlstatus } _=/usr/bin/buildah _BUILDAH_STARTED_IN_USERNS=1 BUILDAH_ISOLATION=rootless], UID map [{HostID:102492 ContainerID:0 Size:1} {HostID:100000 ContainerID:1 Size:65536}], and GID map [{HostID:102492 ContainerID:0 Size:1} {HostID:100000 ContainerID:1 Size:65536}] Error: error running newgidmap: exit status 1: newgidmap: write to gid_map failed: Invalid argument ERRO[0000] exit status 1 Ok this looks like you UID == 102492 and podman is attempting to map it to 0 inside the container. BUT you are also mapping 65k UIDs starting at 100000 starting at UID 1. This means you are attempting to map UID == 102492 twice into your User Namespace. The range of UIDs specified in /etc/subuid, /etc/subgid, can not container your real UID. Fix these files to use a different range of UIDs. |
Created attachment 1572145 [details] podman build strace output Description of problem: Podman command run as non root user (user from IPA IDM realm) always fails with "ERRO[0000] cannot setup namespace using newuidmap: exit status 1" error message. Version-Release number of selected component (if applicable): podman-1.0.0-2.git921f98f.module+el8+2785+ff8a053f.x86_64 container-selinux-2.94-1.git1e99f1d.module+el8.0.0+2958+4e823551.noarch shadow-utils-4.6-7.el8.x86_64 How reproducible: Run podman build -t container-name . Steps to Reproduce: 1. Install RHEL 8 2. Join IPA IDM realm 3. Log in with user from realm 4. Run podman build command Actual results: ERRO[0000] cannot setup namespace using newuidmap: exit status 1 Expected results: Container gets build Additional info: # cat /etc/subuid jbittner:100000:65536 # cat /etc/subgid jbittner:100000:65536 I also have: /etc/subuid- /etc/subgid- with same content. # podman version Version: 1.0.2-dev Go Version: go1.11.5 OS/Arch: linux/amd64 # rpm -qV shadow-utils Returns nothing # getcap /usr/bin/newuidmap /usr/bin/newgidmap /usr/bin/newuidmap = cap_setuid+ep /usr/bin/newgidmap = cap_setgid+ep # mount /dev/mapper/rhel-home on /home type xfs (rw,relatime,seclabel,attr2,inode64,noquota)