New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
mount through procfd: operation not permitted: OCI permission denied #15314
Comments
/kind bug |
Does running other images work? Does it work if you install |
I updated Podman to 4.1.1, but still get the same error: [cloud-user@preserve-olm-env2 interview]$ sudo dnf update podman
...
[cloud-user@preserve-olm-env2 interview]$ podman version
Client: Podman Engine
Version: 4.1.1
API Version: 4.1.1
Go Version: go1.17.7
Built: Mon Jul 11 22:56:53 2022
OS/Arch: linux/amd64
[cloud-user@preserve-olm-env2 interview]$ podman run quay.io/olmqe/interview:v1
Error: runc: container_linux.go:380: starting container process caused: process_linux.go:545: container init caused: rootfs_linux.go:75: mounting "sysfs" to rootfs at "/sys" caused: mount through procfd: operation not permitted: OCI permission denied |
Thanks! Seems like it works when specifying the [cloud-user@preserve-olm-env2 interview]$ dnf install crun
Repository google-cloud-sdk is listed more than once in the configuration
Error: This command has to be run with superuser privileges (under the root user on most systems).
[cloud-user@preserve-olm-env2 interview]$ sudo dnf install crun
Repository google-cloud-sdk is listed more than once in the configuration
Last metadata expiration check: 1:49:02 ago on Mon 15 Aug 2022 09:38:55 AM CST.
Dependencies resolved.
============================================================================================================================================================
Package Architecture Version Repository Size
============================================================================================================================================================
Installing:
crun x86_64 1.4.5-2.module+el8.6.0+15917+093ca6f8 rhel8appstream 209 k
Installing dependencies:
yajl x86_64 2.1.0-11.el8 appstream 41 k
Transaction Summary
============================================================================================================================================================
Install 2 Packages
Total download size: 250 k
Installed size: 602 k
Is this ok [y/N]: y
Downloading Packages:
(1/2): crun-1.4.5-2.module+el8.6.0+15917+093ca6f8.x86_64.rpm 4.3 MB/s | 209 kB 00:00
(2/2): yajl-2.1.0-11.el8.x86_64.rpm 88 kB/s | 41 kB 00:00
------------------------------------------------------------------------------------------------------------------------------------------------------------
Total 540 kB/s | 250 kB 00:00
Running transaction check
Transaction check succeeded.
Running transaction test
Transaction test succeeded.
Running transaction
Preparing : 1/1
Installing : yajl-2.1.0-11.el8.x86_64 1/2
Installing : crun-1.4.5-2.module+el8.6.0+15917+093ca6f8.x86_64 2/2
Running scriptlet: crun-1.4.5-2.module+el8.6.0+15917+093ca6f8.x86_64 2/2
Verifying : yajl-2.1.0-11.el8.x86_64 1/2
Verifying : crun-1.4.5-2.module+el8.6.0+15917+093ca6f8.x86_64 2/2
Installed:
crun-1.4.5-2.module+el8.6.0+15917+093ca6f8.x86_64 yajl-2.1.0-11.el8.x86_64
Complete!
[cloud-user@preserve-olm-env2 interview]$ podman run --runtime crun quay.io/olmqe/interview:v1
/bin/sh: 1: [./test]: not found |
I didn't find any introduction about the [cloud-user@preserve-olm-env2 interview]$ podman run --help|grep runtime
--cpu-rt-runtime int Limit the CPU real-time runtime in microseconds And, what's the default |
The default runtime everywhere except RHEL 8 is now The I advise that you file a Bugzilla against runc for this error. |
(Oh, I suppose that RHEL 7 also defaults to |
@mheon Thanks! I see now, report a bug here: https://bugzilla.redhat.com/show_bug.cgi?id=2118231 |
Since this is not a podman bug, closing. |
Is this a BUG REPORT or FEATURE REQUEST? (leave only one on its own line)
/kind bug
Description
Steps to reproduce the issue:
Describe the results you received:
Describe the results you expected:
Run this image successfully with rootless mode.
Additional information you deem important (e.g. issue happens only occasionally):
Output of
podman version
:Output of
podman info
:Package info (e.g. output of
rpm -q podman
orapt list podman
):Have you tested with the latest version of Podman and have you checked the Podman Troubleshooting Guide? (https://github.com/containers/podman/blob/main/troubleshooting.md)
No
Additional environment details (AWS, VirtualBox, physical, etc.):
Full log:
The text was updated successfully, but these errors were encountered: