Closed Lockszmith-GH closed 3 weeks ago
Please let me know if you were able to double check this. As mentioned in #150 I think it works as expected, so I'm inclined to close this issue to let other users know.
I ran through the instructions (without my addition) to the tee, this is what happens:
❯ jlmkr shell --uid 1000 rootless-podman
Connected to machine rootless-podman. Press ^] three times within 1s to exit session.
[rootless@rootless-podman ~]$ id
uid=1000(rootless) gid=1000(rootless) groups=1000(rootless)
[rootless@rootless-podman ~]$ podman run hello-world
ERRO[0000] running `/usr/bin/newuidmap 255 0 1000 1 1 65536 65536`: newuidmap: write to uid_map failed: Operation not permitted
Error: cannot set up namespace using "/usr/bin/newuidmap": should have setuid or have filecaps setuid: exit status 1
[rootless@rootless-podman ~]$ podman info
ERRO[0000] running `/usr/bin/newuidmap 275 0 1000 1 1 65536 65536`: newuidmap: write to uid_map failed: Operation not permitted
Error: cannot set up namespace using "/usr/bin/newuidmap": should have setuid or have filecaps setuid: exit status 1
[rootless@rootless-podman ~]$ exit
logout
Connection to machine rootless-podman terminated.
After running:
jlmkr shell rootless-podman
Connected to machine rootless-podman. Press ^] three times within 1s to exit session.
[root@rootless-podman ~]# rpm --restore shadow-utils
[root@rootless-podman ~]# exit
logout
Connection to machine rootless-podman terminated.
I can then shell in with --uid 1000
and run the podman
commands successfully.
Should be fixed in https://github.com/Jip-Hop/jailmaker/releases/tag/v1.4.0. Let me know if it's not.
Following the current rootless section in the podman readme when attempting to start the hello-world podman, I got the following error:
Some looking around, I ended up at this solution.
And indeed, running the following once inside th jail as root
rpm --restore shadow-utils
, resolved the issue, and I was able to run podman as the rootless user.Also noticed that this can't be added to the initial_setup step, as I get the following error:
So just modifying the README should be sufficient.