mirror of
https://github.com/podman-container-tools/podman.git
synced 2026-08-15 05:09:35 +00:00
closes: #27411
Adjust SUB_UID and SUB_GID ranges to support running rootless Podman inside a rootless run Podman container.
Also add a test to verify the change and prevent regression.
By default, a new user is assigned the following sub-ID ranges:
SUB_UID_MIN=100000, SUB_GID_MIN=100000, SUB_UID_COUNT=65536, SUB_GID_COUNT=65536
This means the user’s sub-UID and sub-GID ranges are 100000–165535.
When the container is run rootless with the user defined below, ID mappings occur as follows:
- Container ID 0 (root) maps to user ID 1000 on the host (which is the user created below).
- Container IDs 1–65536 map to IDs 100000–165535 on host (the subid range previously mentioned).
If a new user is created inside this container (to build containers for example), it will
attempt to use the default sub-ID range (100000–165535). However, this exceeds the container’s
available ID mapping, since only IDs up to 65536 are mapped. This causes nested rootless Podman
to fail.
To enable container-in-container builds, the sub-ID ranges for the user must be large enough
to provide at least 65536 usable IDs. A minimum SUB_UID_COUNT and SUB_GID_COUNT of 165536 is
required, but 1,000,000 is used here to provide additional margin.
1,000,000 matches the subid range other machines are using, defined in [ignition.go](
|
||
|---|---|---|
| .. | ||
| apple | ||
| applehv | ||
| compression | ||
| connection | ||
| define | ||
| e2e | ||
| env | ||
| hyperv | ||
| ignition | ||
| libkrun | ||
| lock | ||
| ocipull | ||
| os | ||
| ports | ||
| provider | ||
| proxyenv | ||
| qemu | ||
| shim | ||
| sockets | ||
| stdpull | ||
| vmconfigs | ||
| windows | ||
| wsl | ||
| cleanup.go | ||
| config.go | ||
| config_test.go | ||
| gvproxy.go | ||
| gvproxy_unix.go | ||
| gvproxy_windows.go | ||
| keys.go | ||
| machine_common.go | ||
| machine_unix.go | ||
| machine_unsupported.go | ||
| machine_windows.go | ||
| machine_windows_test.go | ||
| qemuprovider.go | ||
| ssh.go | ||
| ssh_unix.go | ||
| ssh_windows.go | ||
| update.go | ||
| volumes.go | ||