Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 1713054

Summary: Runnning podman build as non root user fails
Product: Red Hat Enterprise Linux 8 Reporter: Jakub Bittner <jbittner>
Component: podmanAssignee: Giuseppe Scrivano <gscrivan>
Status: CLOSED NOTABUG QA Contact: atomic-bugs <atomic-bugs>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 8.0CC: avi.kivity, dornelas, dwalsh, fedoraproject, jligon, jnovy, lsm5, mheon, tsweeney
Target Milestone: rc   
Target Release: 8.0   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-07-29 07:44:56 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
podman build strace output none

Description Jakub Bittner 2019-05-22 18:30:36 UTC
Created attachment 1572145 [details]
podman build strace output

Description of problem:
Podman command run as non root user (user from IPA IDM realm) always fails with "ERRO[0000] cannot setup namespace using newuidmap: exit status 1" error message. 

Version-Release number of selected component (if applicable):
podman-1.0.0-2.git921f98f.module+el8+2785+ff8a053f.x86_64
container-selinux-2.94-1.git1e99f1d.module+el8.0.0+2958+4e823551.noarch
shadow-utils-4.6-7.el8.x86_64

How reproducible:
Run podman build -t container-name .

Steps to Reproduce:
1. Install RHEL 8
2. Join IPA IDM realm
3. Log in with user from realm
4. Run podman build command

Actual results:
ERRO[0000] cannot setup namespace using newuidmap: exit status 1

Expected results:
Container gets build

Additional info:
# cat /etc/subuid
jbittner:100000:65536

# cat /etc/subgid
jbittner:100000:65536

I also have: 
/etc/subuid-
/etc/subgid-
with same content.

# podman version
Version:       1.0.2-dev
Go Version:    go1.11.5
OS/Arch:       linux/amd64

# rpm -qV shadow-utils
Returns nothing

# getcap /usr/bin/newuidmap /usr/bin/newgidmap
/usr/bin/newuidmap = cap_setuid+ep
/usr/bin/newgidmap = cap_setgid+ep

# mount
/dev/mapper/rhel-home on /home type xfs (rw,relatime,seclabel,attr2,inode64,noquota)

Comment 1 Tom Sweeney 2019-05-22 19:31:33 UTC
Jakub a quick couple of questions.

Can you include the Dockerfile that you're using when you're running into this issue as a reply to this email please?

I unfortunately have to dash and won't be able to check until tomorrow.  But I think the issue is you've setup the usernamespace appropriately, but have not told the build command how to use it.  If you've the time, can you try:

`podman build --userns-uid-map-user jbittner --userns-gid-map-group jbittner-t container-name .`

Thanks!

Comment 3 Daniel Walsh 2019-05-23 20:57:06 UTC
Jakub, do you have entryies for your username in /etc/subuid and /etc/subgid?

Comment 4 Tom Sweeney 2019-05-23 22:16:54 UTC
dwalsh, yep he does.

Jakub, I don't know if you've access, but the latest Podman on brew is 1.3.1.  If you can upgrade from there, that would be of help.  Unfortunately it's not yet in extras, only brew.

I'm having trouble getting the same error as you.  I'm running into a separate one where 'newuidmap' can't be found.

One of my colleagues suggested adding the option `--isolation chroot` to your command ala ` podman build --isolation chroot -t container-name .`.  I'm not sure that will cure it, but thought I'd let you know in case you want to try while I continue to work out my issues.

Comment 5 Jakub Bittner 2019-05-24 06:12:03 UTC
Hey Tom,
I have access to Brew, but I can see podman 1.3.1 builds for RHEL 7 only (I am running RHEL 8). Does it matter or should I try el7 version?

`--isolation chroot` has the same problem.

Comment 6 Tom Sweeney 2019-05-24 18:25:22 UTC
Hey Jakub,

I've talked with a few folks here in the group and it looks like 1.3.1 won't help.  We believe there's a kernel issue that may be keeping rootless Podman from working at this time on RHEL.

https://bugzilla.redhat.com/show_bug.cgi?id=1713642

Will keep you posted.

Comment 7 Jakub Bittner 2019-05-24 18:48:21 UTC
Hey Tom,

I am running RHEL 8.

Comment 8 Daniel Walsh 2019-05-25 11:02:22 UTC
If you just run 
$ podman run -ti ubi8 echo test

Does this work?

Comment 9 Daniel Walsh 2019-05-25 11:03:54 UTC
Could this be newuidmap and newgidmap are not using NSSWITCH to figure out the user name?

Comment 10 Jakub Bittner 2019-05-27 09:15:29 UTC
$ podman run -ti ubi8 echo test
error creating libpod runtime: Error running podman info while refreshing state: exit status 1

I use ipa enabled machine and user I run podman commands is in IPA only. Not a local user.







cat /etc/nsswitch.conf|grep -v "^#"


passwd:     sss files systemd
group:      sss files systemd
netgroup:   sss files
automount:  sss files
services:   sss files




shadow:     files sss

hosts:      files dns myhostname

bootparams: files

ethers:     files
netmasks:   files
networks:   files
protocols:  files
rpc:        files


publickey:  files

aliases:    files

Comment 11 Daniel Walsh 2019-05-28 14:45:52 UTC
If you don't have local entries in /etc/subuid and /etc/subgid, then you can only use a signle UID within your container image.  If UBI8 includes more then one UID, then it will fail.

Comment 12 Jakub Bittner 2019-06-03 13:32:24 UTC
Daniel,

I have entries in  /etc/subuid and /etc/subgid. Even running command "podman info" produces error. 

$ podman info
ERRO[0000] cannot setup namespace using newuidmap: exit status 1

cat /etc/subuid
jbittner:100000:65536

cat /etc/subgid
jbittner:100000:65536

Comment 13 Daniel Walsh 2019-06-04 05:51:37 UTC
First could you make sure this is not SELinux, by attempting to run with `setenforce 0`

Can you execute

buildah unshare

To see if this passes?

If this fails, try `buildah --debug unshare`

Comment 14 Jakub Bittner 2019-06-04 06:55:17 UTC
I did, same result.


# getenforce 
Permissive

$ buildah unshare
Error: error running newgidmap: exit status 1: newgidmap: write to gid_map failed: Invalid argument


$ buildah --debug unshare
DEBU[0000] running [buildah-in-a-user-namespace --debug unshare] with environment [LS_COLORS=rs=0:di=38;5;33:ln=38;5;51:mh=00:pi=40;38;5;11:so=38;5;13:do=38;5;5:bd=48;5;232;38;5;11:cd=48;5;232;38;5;3:or=48;5;232;38;5;9:mi=01;05;37;41:su=48;5;196;38;5;15:sg=48;5;11;38;5;16:ca=48;5;196;38;5;226:tw=48;5;10;38;5;16:ow=48;5;10;38;5;21:st=48;5;21;38;5;15:ex=38;5;40:*.tar=38;5;9:*.tgz=38;5;9:*.arc=38;5;9:*.arj=38;5;9:*.taz=38;5;9:*.lha=38;5;9:*.lz4=38;5;9:*.lzh=38;5;9:*.lzma=38;5;9:*.tlz=38;5;9:*.txz=38;5;9:*.tzo=38;5;9:*.t7z=38;5;9:*.zip=38;5;9:*.z=38;5;9:*.dz=38;5;9:*.gz=38;5;9:*.lrz=38;5;9:*.lz=38;5;9:*.lzo=38;5;9:*.xz=38;5;9:*.zst=38;5;9:*.tzst=38;5;9:*.bz2=38;5;9:*.bz=38;5;9:*.tbz=38;5;9:*.tbz2=38;5;9:*.tz=38;5;9:*.deb=38;5;9:*.rpm=38;5;9:*.jar=38;5;9:*.war=38;5;9:*.ear=38;5;9:*.sar=38;5;9:*.rar=38;5;9:*.alz=38;5;9:*.ace=38;5;9:*.zoo=38;5;9:*.cpio=38;5;9:*.7z=38;5;9:*.rz=38;5;9:*.cab=38;5;9:*.wim=38;5;9:*.swm=38;5;9:*.dwm=38;5;9:*.esd=38;5;9:*.jpg=38;5;13:*.jpeg=38;5;13:*.mjpg=38;5;13:*.mjpeg=38;5;13:*.gif=38;5;13:*.bmp=38;5;13:*.pbm=38;5;13:*.pgm=38;5;13:*.ppm=38;5;13:*.tga=38;5;13:*.xbm=38;5;13:*.xpm=38;5;13:*.tif=38;5;13:*.tiff=38;5;13:*.png=38;5;13:*.svg=38;5;13:*.svgz=38;5;13:*.mng=38;5;13:*.pcx=38;5;13:*.mov=38;5;13:*.mpg=38;5;13:*.mpeg=38;5;13:*.m2v=38;5;13:*.mkv=38;5;13:*.webm=38;5;13:*.ogm=38;5;13:*.mp4=38;5;13:*.m4v=38;5;13:*.mp4v=38;5;13:*.vob=38;5;13:*.qt=38;5;13:*.nuv=38;5;13:*.wmv=38;5;13:*.asf=38;5;13:*.rm=38;5;13:*.rmvb=38;5;13:*.flc=38;5;13:*.avi=38;5;13:*.fli=38;5;13:*.flv=38;5;13:*.gl=38;5;13:*.dl=38;5;13:*.xcf=38;5;13:*.xwd=38;5;13:*.yuv=38;5;13:*.cgm=38;5;13:*.emf=38;5;13:*.ogv=38;5;13:*.ogx=38;5;13:*.aac=38;5;45:*.au=38;5;45:*.flac=38;5;45:*.m4a=38;5;45:*.mid=38;5;45:*.midi=38;5;45:*.mka=38;5;45:*.mp3=38;5;45:*.mpc=38;5;45:*.ogg=38;5;45:*.ra=38;5;45:*.wav=38;5;45:*.oga=38;5;45:*.opus=38;5;45:*.spx=38;5;45:*.xspf=38;5;45: XDG_MENU_PREFIX=gnome- MODULES_RUN_QUARANTINE=LD_LIBRARY_PATH LANG=en_US.UTF-8 GDM_LANG=en_US.UTF-8 HISTCONTROL=ignoredups DISPLAY=:0 HOSTNAME=alca.users.ipa.redhat.com COLORTERM=truecolor USERNAME=jbittner XDG_VTNR=2 SSH_AUTH_SOCK=/run/user/102492/keyring/ssh XDG_SESSION_ID=2 MODULES_CMD=/usr/share/Modules/libexec/modulecmd.tcl USER=jbittner ENV=/usr/share/Modules/init/profile.sh DESKTOP_SESSION=gnome WAYLAND_DISPLAY=wayland-0 GNOME_TERMINAL_SCREEN=/org/gnome/Terminal/screen/05dd6cbf_3ce9_4e7a_b271_99fa8985d629 PWD=/home/jbittner HOME=/home/jbittner XDG_SESSION_TYPE=wayland KRB5CCNAME=KCM: BASH_ENV=/usr/share/Modules/init/bash XDG_DATA_DIRS=/home/jbittner/.local/share/flatpak/exports/share/:/var/lib/flatpak/exports/share/:/usr/local/share/:/usr/share/ XDG_SESSION_DESKTOP=gnome GJS_DEBUG_OUTPUT=stderr LOADEDMODULES= MAIL=/var/spool/mail/jbittner VTE_VERSION=5202 SHELL=/bin/bash TERM=xterm-256color QT_IM_MODULE=ibus XMODIFIERS=@im=ibus XDG_CURRENT_DESKTOP=GNOME GNOME_TERMINAL_SERVICE=:1.94 XDG_SEAT=seat0 SHLVL=2 MODULEPATH=/etc/scl/modulefiles:/etc/scl/modulefiles:/usr/share/Modules/modulefiles:/etc/modulefiles:/usr/share/modulefiles GDMSESSION=gnome GNOME_DESKTOP_SESSION_ID=this-is-deprecated LOGNAME=jbittner DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/102492/bus XDG_RUNTIME_DIR=/run/user/102492 MODULEPATH_modshare=/usr/share/modulefiles:1:/etc/modulefiles:1:/usr/share/Modules/modulefiles:1 PATH=/home/jbittner/.local/bin:/home/jbittner/bin:/home/jbittner/.local/bin:/home/jbittner/bin:/usr/share/Modules/bin:/usr/local/bin:/usr/local/sbin:/usr/bin:/usr/sbin MODULESHOME=/usr/share/Modules HISTSIZE=1000 GJS_DEBUG_TOPICS=JS ERROR;JS LOG SESSION_MANAGER=local/unix:@/tmp/.ICE-unix/8093,unix/unix:/tmp/.ICE-unix/8093 LESSOPEN=||/usr/bin/lesspipe.sh %s BASH_FUNC_module%%=() {  _moduleraw "$@" 2>&1
} BASH_FUNC_switchml%%=() {  typeset swfound=1;
 if [ "${MODULES_USE_COMPAT_VERSION:-0}" = '1' ]; then
 typeset swname='main';
 if [ -e /usr/share/Modules/libexec/modulecmd.tcl ]; then
 typeset swfound=0;
 unset MODULES_USE_COMPAT_VERSION;
 fi;
 else
 typeset swname='compatibility';
 if [ -e /usr/share/Modules/libexec/modulecmd-compat ]; then
 typeset swfound=0;
 MODULES_USE_COMPAT_VERSION=1;
 export MODULES_USE_COMPAT_VERSION;
 fi;
 fi;
 if [ $swfound -eq 0 ]; then
 echo "Switching to Modules $swname version";
 source /usr/share/Modules/init/bash;
 else
 echo "Cannot switch to Modules $swname version, command not found";
 return 1;
 fi
} BASH_FUNC_scl%%=() {  if [ "$1" = "load" -o "$1" = "unload" ]; then
 eval "module $@";
 else
 /usr/bin/scl "$@";
 fi
} BASH_FUNC__moduleraw%%=() {  unset _mlre _mlIFS _mlshdbg;
 if [ "${MODULES_SILENT_SHELL_DEBUG:-0}" = '1' ]; then
 case "$-" in 
 *v*x*)
 set +vx;
 _mlshdbg='vx'
 ;;
 *v*)
 set +v;
 _mlshdbg='v'
 ;;
 *x*)
 set +x;
 _mlshdbg='x'
 ;;
 *)
 _mlshdbg=''
 ;;
 esac;
 fi;
 if [ -n "${IFS+x}" ]; then
 _mlIFS=$IFS;
 fi;
 IFS=' ';
 for _mlv in ${MODULES_RUN_QUARANTINE:-};
 do
 if [ "${_mlv}" = "${_mlv##*[!A-Za-z0-9_]}" -a "${_mlv}" = "${_mlv#[0-9]}" ]; then
 if [ -n "`eval 'echo ${'$_mlv'+x}'`" ]; then
 _mlre="${_mlre:-}${_mlv}_modquar='`eval 'echo ${'$_mlv'}'`' ";
 fi;
 _mlrv="MODULES_RUNENV_${_mlv}";
 _mlre="${_mlre:-}${_mlv}='`eval 'echo ${'$_mlrv':-}'`' ";
 fi;
 done;
 if [ -n "${_mlre:-}" ]; then
 eval `eval ${_mlre}/usr/bin/tclsh /usr/share/Modules/libexec/modulecmd.tcl bash '"$@"'`;
 else
 eval `/usr/bin/tclsh /usr/share/Modules/libexec/modulecmd.tcl bash "$@"`;
 fi;
 _mlstatus=$?;
 if [ -n "${_mlIFS+x}" ]; then
 IFS=$_mlIFS;
 else
 unset IFS;
 fi;
 if [ -n "${_mlshdbg:-}" ]; then
 set -$_mlshdbg;
 fi;
 unset _mlre _mlv _mlrv _mlIFS _mlshdbg;
 return $_mlstatus
} _=/usr/bin/buildah _BUILDAH_STARTED_IN_USERNS=1 BUILDAH_ISOLATION=rootless], UID map [{HostID:102492 ContainerID:0 Size:1} {HostID:100000 ContainerID:1 Size:65536}], and GID map [{HostID:102492 ContainerID:0 Size:1} {HostID:100000 ContainerID:1 Size:65536}] 
Error: error running newgidmap: exit status 1: newgidmap: write to gid_map failed: Invalid argument

ERRO[0000] exit status 1

Comment 15 Daniel Walsh 2019-06-05 06:22:45 UTC
Ok this looks like you UID == 102492  and podman is attempting to map it to 0 inside the container.  BUT
you are also mapping 65k UIDs starting at 100000 starting at UID 1.
This means you are attempting to map  UID == 102492 twice into your User Namespace.

The range of UIDs specified in /etc/subuid, /etc/subgid, can not container your real UID.  Fix these files to use a different range of UIDs.