-
Notifications
You must be signed in to change notification settings - Fork 230
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
overlay: set permissions on "diff" correctly #772
Conversation
LGTM |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
@@ -631,6 +626,18 @@ func (d *Driver) create(id, parent string, opts *graphdriver.CreateOpts) (retErr | |||
} | |||
} | |||
|
|||
perms := defaultPerms | |||
if d.options.forceMask != nil { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think this should have precedence and override the parent mode
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hmm, yeah, you're right. Changing it.
When creating a new layer that has a parent, assign the new layer's "diff" directory the same permissions as the parent layer's "diff" directory, rather than the permissions of the parent of its parent layer's "diff" directory. Before the recent round of changes, that directory would be initialized with 0700 permissions, so layers created by new code on top of layers created by the older version would be given 0700 permissions, and were not usable by UIDs other than 0. Signed-off-by: Nalin Dahyabhai <nalin@redhat.com>
2bac47d
to
a778488
Compare
When creating a new layer that has a parent, assign the new layer's "diff" directory the same permissions as the parent layer's "diff" directory, rather than the permissions of the parent of its parent layer's "diff" directory.
Before the recent round of changes, that directory would be initialized with 0700 permissions, so layers created by new code on top of layers created by the older version would be marked 0700, and were not usable by UIDs other than 0.
Spotted in CI tests for buildah that try to use overlay to create containers on top of base images that were imported using a slightly older version of podman, for example https://cirrus-ci.com/task/6024517489262592.