Closed cowlingj closed 1 month ago
can you share the output of ls -ld /home /home/jonathan
? I think there is no a+x
permission set in one of these two paths
hm.. that should not matter, at least from what I can observe locally. Do you mind to share the output of podman unshare cat /proc/self/mountinfo
too?
Looks like that was it, I didn't have the right permissions on the /home/jonathan
directory
does it work now? What have you changed?
I changed the permissions of my home directory to chmod a+x /home/jonathan
then I could run busybox just fine, I set the permissions back (to 0700) and it still works.
Here's the output of podman unshare cat /proc/self/mountinfo
96 95 8:50 / / rw,noatime master:1 - ext4 /dev/sdd2 rw
97 96 0:5 / /dev rw,nosuid,relatime master:2 - devtmpfs dev rw,size=16295884k,nr_inodes=4073971,mode=755,inode64
98 97 0:27 / /dev/pts rw,nosuid,noexec,relatime master:3 - devpts devpts rw,gid=5,mode=620,ptmxmode=000
171 97 0:28 / /dev/shm rw,nosuid,nodev master:4 - tmpfs tmpfs rw,inode64
245 97 0:20 / /dev/mqueue rw,nosuid,nodev,noexec,relatime master:15 - mqueue mqueue rw
246 97 0:33 / /dev/hugepages rw,nosuid,nodev,relatime master:16 - hugetlbfs hugetlbfs rw,pagesize=2M
247 96 0:22 / /proc rw,nosuid,nodev,noexec,relatime master:5 - proc proc rw
248 247 0:32 / /proc/sys/fs/binfmt_misc rw,relatime master:13 - autofs systemd-1 rw,fd=38,pgrp=1,timeout=0,minproto=5,maxproto=5,direct,pipe_ino=6829
249 248 0:48 / /proc/sys/fs/binfmt_misc rw,nosuid,nodev,noexec,relatime master:62 - binfmt_misc binfmt_misc rw
250 96 0:23 / /sys rw,nosuid,nodev,noexec,relatime master:6 - sysfs sys rw
341 250 0:25 / /sys/firmware/efi/efivars rw,nosuid,nodev,noexec,relatime master:7 - efivarfs efivarfs rw
342 250 0:6 / /sys/kernel/security rw,nosuid,nodev,noexec,relatime master:8 - securityfs securityfs rw
343 250 0:29 / /sys/fs/cgroup rw,nosuid,nodev,noexec,relatime master:9 - cgroup2 cgroup2 rw,nsdelegate,memory_recursiveprot
344 250 0:30 / /sys/fs/pstore rw,nosuid,nodev,noexec,relatime master:10 - pstore pstore rw
472 250 0:31 / /sys/fs/bpf rw,nosuid,nodev,noexec,relatime master:11 - bpf bpf rw,mode=700
473 250 0:12 / /sys/kernel/tracing rw,nosuid,nodev,noexec,relatime master:14 - tracefs tracefs rw
474 250 0:7 / /sys/kernel/debug rw,nosuid,nodev,noexec,relatime master:17 - debugfs debugfs rw
475 250 0:36 / /sys/kernel/config rw,nosuid,nodev,noexec,relatime master:20 - configfs configfs rw
476 250 0:37 / /sys/fs/fuse/connections rw,nosuid,nodev,noexec,relatime master:21 - fusectl fusectl rw
487 96 0:24 / /run rw,nosuid,nodev,relatime master:12 - tmpfs run rw,mode=755,inode64
491 487 0:34 / /run/credentials/systemd-udev-load-credentials.service ro,nosuid,nodev,noexec,relatime,nosymfollow master:19 - tmpfs tmpfs rw,size=1024k,nr_inodes=1024,mode=700,inode64,noswap
495 487 0:38 / /run/credentials/systemd-tmpfiles-setup-dev-early.service ro,nosuid,nodev,noexec,relatime,nosymfollow master:22 - tmpfs tmpfs rw,size=1024k,nr_inodes=1024,mode=700,inode64,noswap
496 487 0:39 / /run/credentials/systemd-tmpfiles-setup-dev.service ro,nosuid,nodev,noexec,relatime,nosymfollow master:23 - tmpfs tmpfs rw,size=1024k,nr_inodes=1024,mode=700,inode64,noswap
497 487 0:41 / /run/credentials/systemd-journald.service ro,nosuid,nodev,noexec,relatime,nosymfollow master:25 - tmpfs tmpfs rw,size=1024k,nr_inodes=1024,mode=700,inode64,noswap
498 487 0:35 / /run/credentials/systemd-sysctl.service ro,nosuid,nodev,noexec,relatime,nosymfollow master:18 - tmpfs tmpfs rw,size=1024k,nr_inodes=1024,mode=700,inode64,noswap
499 487 0:42 / /run/credentials/systemd-vconsole-setup.service ro,nosuid,nodev,noexec,relatime,nosymfollow master:50 - tmpfs tmpfs rw,size=1024k,nr_inodes=1024,mode=700,inode64,noswap
500 487 0:47 / /run/credentials/systemd-tmpfiles-setup.service ro,nosuid,nodev,noexec,relatime,nosymfollow master:60 - tmpfs tmpfs rw,size=1024k,nr_inodes=1024,mode=700,inode64,noswap
501 487 0:59 / /run/user/1000 rw,nosuid,nodev,relatime master:314 - tmpfs tmpfs rw,size=3262900k,nr_inodes=815725,mode=700,uid=1000,gid=1000,inode64
502 501 0:60 / /run/user/1000/gvfs rw,nosuid,nodev,relatime master:381 - fuse.gvfsd-fuse gvfsd-fuse rw,user_id=1000,group_id=1000
503 501 0:75 / /run/user/1000/doc rw,nosuid,nodev,relatime master:723 - fuse.portal portal rw,user_id=1000,group_id=1000
504 96 0:40 / /srv/games rw,relatime master:24 - autofs systemd-1 rw,fd=51,pgrp=1,timeout=0,minproto=5,maxproto=5,direct,pipe_ino=13512
505 96 0:44 / /tmp rw,noatime master:52 - tmpfs tmpfs rw,inode64
506 96 8:49 / /boot/efi rw,relatime master:54 - vfat /dev/sdd1 rw,fmask=0077,dmask=0077,codepage=437,iocharset=ascii,shortname=mixed,utf8,errors=remount-ro
507 96 0:43 / /home/jonathan rw,relatime master:56 - btrfs /dev/sda1 rw,space_cache=v2,subvolid=5,subvol=/
508 507 0:46 / /home/jonathan/.Encrypted rw,relatime master:58 - autofs systemd-1 rw,fd=62,pgrp=1,timeout=0,minproto=5,maxproto=5,direct,pipe_ino=7725
509 508 254:1 / /home/jonathan/.Encrypted rw,relatime master:579 - ext4 /dev/mapper/Games-jonathan2 rw
511 507 0:43 /.local/share/containers/storage/overlay /home/jonathan/.local/share/containers/storage/overlay rw,relatime - btrfs /dev/sda1 rw,space_cache=v2,subvolid=5,subvol=/
I've opened a PR for crun that should help to handle better with such configuration: https://github.com/containers/crun/pull/1503
A friendly reminder that this issue had no activity for 30 days.
Looks like @giuseppe got merged something that will make this easier for the user to discover. Closing.
Issue Description
Running any container in rootless mode results in an "OCI permission denied" error (running with sudo works)
Steps to reproduce the issue
Steps to reproduce the issue
Describe the results you received
Describe the results you expected
The container to run
podman info output
Podman in a container
No
Privileged Or Rootless
Rootless
Upstream Latest Release
Yes
Additional environment details
Additional environment details
podman run --log-level=debug busybox
Additional information
Additional information like issue happens only occasionally or issue happens with a particular architecture or on a particular setting