mirror of
https://github.com/containers/podman.git
synced 2025-05-17 15:18:43 +08:00
podman: assume user namespace if there are mappings
if some mappings are specified, assume there is a private user namespace. Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
This commit is contained in:
@ -209,10 +209,15 @@ func FillOutSpecGen(s *specgen.SpecGenerator, c *ContainerCLIOpts, args []string
|
||||
}
|
||||
}
|
||||
|
||||
s.IDMappings, err = util.ParseIDMapping(ns.UsernsMode(c.UserNS), c.UIDMap, c.GIDMap, c.SubUIDName, c.SubGIDName)
|
||||
userNS := ns.UsernsMode(c.UserNS)
|
||||
s.IDMappings, err = util.ParseIDMapping(userNS, c.UIDMap, c.GIDMap, c.SubUIDName, c.SubGIDName)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
// If some mappings are specified, assume a private user namespace
|
||||
if userNS.IsDefaultValue() && (!s.IDMappings.HostUIDMapping || !s.IDMappings.HostGIDMapping) {
|
||||
s.UserNS.NSMode = specgen.Private
|
||||
}
|
||||
|
||||
s.Terminal = c.TTY
|
||||
ep, err := ExposedPorts(c.Expose, c.Net.PublishPorts, c.PublishAll, nil)
|
||||
|
@ -31,7 +31,7 @@ func (n CgroupMode) IsHost() bool {
|
||||
|
||||
// IsDefaultValue indicates whether the cgroup namespace has the default value.
|
||||
func (n CgroupMode) IsDefaultValue() bool {
|
||||
return n == ""
|
||||
return n == "" || n == defaultType
|
||||
}
|
||||
|
||||
// IsNS indicates a cgroup namespace passed in by path (ns:<path>)
|
||||
@ -102,6 +102,11 @@ func (n UsernsMode) IsAuto() bool {
|
||||
return parts[0] == "auto"
|
||||
}
|
||||
|
||||
// IsDefaultValue indicates whether the user namespace has the default value.
|
||||
func (n UsernsMode) IsDefaultValue() bool {
|
||||
return n == "" || n == defaultType
|
||||
}
|
||||
|
||||
// GetAutoOptions returns a AutoUserNsOptions with the settings to setup automatically
|
||||
// a user namespace.
|
||||
func (n UsernsMode) GetAutoOptions() (*storage.AutoUserNsOptions, error) {
|
||||
|
@ -218,7 +218,6 @@ var _ = Describe("Podman UserNS support", func() {
|
||||
})
|
||||
|
||||
It("podman --userns=container:CTR", func() {
|
||||
Skip(v2fail)
|
||||
ctrName := "userns-ctr"
|
||||
session := podmanTest.Podman([]string{"run", "-d", "--uidmap=0:0:1", "--uidmap=1:1:4998", "--name", ctrName, "alpine", "top"})
|
||||
session.WaitWithDefaultTimeout()
|
||||
|
Reference in New Issue
Block a user