spiegel_podman/pkg
Matthew Heon 0cbd322590 Ensure that --userns=keep-id sets user in config
One of the side-effects of the `--userns=keep-id` command is
switching the default user of the container to the UID of the
user running Podman (though this can still be overridden by the
`--user` flag). However, it did this by setting the UID and GID
in the OCI spec, and not by informing Libpod of its intention to
switch users via the `WithUser()` option. Because of this, a lot
of the code that should have triggered when the container ran
with a non-root user was not triggering. In the case of the issue
that this fixed, the code to remove capabilities from non-root
users was not triggering. Adjust the keep-id code to properly
inform Libpod of our intention to use a non-root user to fix
this.

Also, fix an annoying race around short-running exec sessions
where Podman would always print a warning that the exec session
had already stopped.

Fixes #9919

Signed-off-by: Matthew Heon <matthew.heon@pm.me>
2021-04-16 13:05:11 -04:00
..
annotations Spelling 2020-12-22 13:34:31 -05:00
api [CI:DOCS] Update swagger definition of inspect manifest 2021-04-16 11:56:59 -04:00
auth Enable whitespace linter 2021-02-11 23:01:56 +01:00
autoupdate Do not leak libpod package into the remote client 2021-03-15 14:02:04 +01:00
bindings Fix flake on failed podman-remote build : try 2 2021-04-16 11:16:36 -04:00
cgroups cgroups: force 64 bits to ParseUint 2021-04-16 11:43:35 -04:00
channel fix closed the remote connection on pull causes service panic 2020-10-03 11:38:38 +08:00
checkpoint Use functions and defines from checkpointctl 2021-03-02 17:00:06 +00:00
copy podman cp: support copying on tmpfs mounts 2021-03-04 15:43:12 +01:00
criu Add helper function to read out CRIU version 2018-10-23 12:52:03 +02:00
ctime Re-add int64 casts for ctime 2019-07-23 15:43:40 -04:00
domain Volumes prune endpoint should use only prune filters 2021-04-16 11:55:51 -04:00
env Ensure DefaultEnvVariables is used in Specgen 2020-08-18 15:17:46 -04:00
errorhandling pkg/errorhandling.JoinErrors: don't throw away context for lone errors 2021-04-16 11:22:18 -04:00
hooks bump go module to v3 2021-02-22 09:03:51 +01:00
inspect bump go module to v3 2021-02-22 09:03:51 +01:00
kubeutils prune remotecommand dependency 2021-02-25 10:02:41 -06:00
lookup Enable whitespace linter 2021-02-11 23:01:56 +01:00
namespaces [CI:DOCS] BZ1860126 - Fix userns defaults in run man page 2020-08-07 15:42:13 -04:00
netns bump go module to v3 2021-02-22 09:03:51 +01:00
network Split libpod/network package 2021-03-15 14:01:52 +01:00
parallel bump go module to v3 2021-02-22 09:03:51 +01:00
ps bump go module to v3 2021-02-22 09:03:51 +01:00
registrar bump go module to v3 2021-02-22 09:03:51 +01:00
registries Document CONTAINERS_CONF/CONTAINERS_STORAGE_CONF Env variables 2021-03-10 06:34:47 -05:00
resolvconf bump go module to v3 2021-02-22 09:03:51 +01:00
rootless bump go module to v3 2021-02-22 09:03:51 +01:00
rootlessport Enable whitespace linter 2021-02-11 23:01:56 +01:00
seccomp Spelling 2020-12-22 13:34:31 -05:00
selinux Fix SELinux functions names to not be repetitive 2020-04-23 15:57:34 -04:00
signal Fix build for mips architecture follow-up 2021-01-07 15:04:22 +01:00
specgen Ensure that --userns=keep-id sets user in config 2021-04-16 13:05:11 -04:00
systemd podman generate systemd --new do not duplicate params 2021-03-29 11:46:36 -04:00
terminal pkg/terminal: use c/storage/pkg/homedir 2021-03-08 09:21:13 +01:00
timetype make lint: enable gocritic 2020-01-13 14:27:02 +01:00
trust Enable whitespace linter 2021-02-11 23:01:56 +01:00
util Unification of until filter across list/prune endpoints 2021-03-29 13:26:24 -04:00