mirror of
https://github.com/containers/podman.git
synced 2026-10-07 10:42:28 -04:00
closes: #27411 Adjust SUB_UID and SUB_GID ranges to support running rootless Podman inside a rootless run Podman container. Also add a test to verify the change and prevent regression. By default, a new user is assigned the following sub-ID ranges: SUB_UID_MIN=100000, SUB_GID_MIN=100000, SUB_UID_COUNT=65536, SUB_GID_COUNT=65536 This means the user’s sub-UID and sub-GID ranges are 100000–165535. When the container is run rootless with the user defined below, ID mappings occur as follows: - Container ID 0 (root) maps to user ID 1000 on the host (which is the user created below). - Container IDs 1–65536 map to IDs 100000–165535 on host (the subid range previously mentioned). If a new user is created inside this container (to build containers for example), it will attempt to use the default sub-ID range (100000–165535). However, this exceeds the container’s available ID mapping, since only IDs up to 65536 are mapped. This causes nested rootless Podman to fail. To enable container-in-container builds, the sub-ID ranges for the user must be large enough to provide at least 65536 usable IDs. A minimum SUB_UID_COUNT and SUB_GID_COUNT of 165536 is required, but 1,000,000 is used here to provide additional margin. 1,000,000 matches the subid range other machines are using, defined in [ignition.go](https://github.com/containers/podman/blob/69b397af49acd595b8d5b36971988d49951c043a/pkg/machine/ignition/ignition.go#L284-L289). The script of other machines modify the subid files directly for 1 user, the `sed` command used in this fix mimics that. The test is added as en extension to the 'simple init with username' test case, to prevent having to create a new VM. Signed-off-by: dvorst <87502756+dvorst@users.noreply.github.com>