-
Notifications
You must be signed in to change notification settings - Fork 176
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Default ping_group_range
value causes EINVAL when written from unshared ns
#345
Comments
Open a PR to fix. The intention is to only allow it for root, so if your change works, then it SGTM. |
maybe-sybr
added a commit
to maybe-sybr/common
that referenced
this issue
Nov 8, 2020
This sysctl is an inclusive range and since the intention is to only allow ping for root, setting it to `0 0` is adequate. This change ensures that if a container is run from a user namespace where GID 1 isn't mapped, we won't get an EINVAL back when attempting to write this sysctl value which would then cause an OCI runtime error. Fixes containers#345
This is now available in v0.27.0 |
Excellent, thanks!
…On 10 Nov 2020, 1:25 AM +1100, Daniel J Walsh ***@***.***>, wrote:
This is now available in v0.27.0
—
You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub, or unsubscribe.
|
M1cha
pushed a commit
to M1cha/common
that referenced
this issue
Dec 20, 2022
This includes an import fix for kernel v5.19, without this it is impossible to delete interfaces. Fixes containers#345 Signed-off-by: Paul Holzinger <pholzing@redhat.com>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
When I attempt to run podman containers from an unshared user namespace and network namespace (related to my adventures described in containers/podman#7774) I get OCI runtime errors caused by a failure to write the default
ping_group_range
value fromcontainers.conf
. I assume this to be because the group ID 1 probably isn't included in my subgidmap.The default value changed from
0 1000
->0 1
in #319 but neither value works for me. Instead, I think we should be using0 0
since theping_group_range
is inclusive pericmp(7)
. This config is vendorised in containers/podman and I think it'd need to land there to fix my issue. For the moment, it's easy for me to work around by having a per-usercontainers.conf
like:The text was updated successfully, but these errors were encountered: