mirror of
https://github.com/containers/podman.git
synced 2025-08-06 03:19:52 +08:00
Add container GID to additional groups
Mitigates a potential permissions issue. Mirrors Buildah PR #4200 and CRI-O PR #6159. Signed-off-by: Matthew Heon <mheon@redhat.com>
This commit is contained in:
@ -510,6 +510,7 @@ func SetupUserNS(idmappings *storage.IDMappingOptions, userns Namespace, g *gene
|
||||
idmappings = mappings
|
||||
g.SetProcessUID(uint32(uid))
|
||||
g.SetProcessGID(uint32(gid))
|
||||
g.AddProcessAdditionalGid(uint32(gid))
|
||||
user = fmt.Sprintf("%d:%d", uid, gid)
|
||||
if err := privateUserNamespace(idmappings, g); err != nil {
|
||||
return user, err
|
||||
@ -522,6 +523,7 @@ func SetupUserNS(idmappings *storage.IDMappingOptions, userns Namespace, g *gene
|
||||
idmappings = mappings
|
||||
g.SetProcessUID(uint32(uid))
|
||||
g.SetProcessGID(uint32(gid))
|
||||
g.AddProcessAdditionalGid(uint32(gid))
|
||||
user = fmt.Sprintf("%d:%d", uid, gid)
|
||||
if err := privateUserNamespace(idmappings, g); err != nil {
|
||||
return user, err
|
||||
|
Reference in New Issue
Block a user