Skip to content
Discussion options

You must be logged in to vote

Your mapping never maps GID 0, and that is what the container dies on. With podman 5.4.2 the same mapping gets rejected before crun is involved, with a message that names the problem:

$ podman run --rm --gidmap g1000:50 alpine echo ok
Error: container uses ID mappings ([]specs.LinuxIDMapping{specs.LinuxIDMapping{ContainerID:0x3e8, HostID:0x32, Size:0x1}}), but doesn't map GID 0

The write to ping_group_range is the same problem further down. podman sets that sysctl inside the container's namespace, the write is rejected because the ids involved are not mapped, and crun can only report the write that failed. So I would not file anything against crun. The message quoted above comes from pod…

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by funkyfuture
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants