devcontainers / devcontainers/cli

Podman: automatic `--userns=keep-id` breaks containers using host networking

オープン
#1,301 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
TypeScript
スター
3k
フォーク
457
平均マージ
13時間 17分
マージ済み PR(30日)
6

説明

I'm facing an issue when using podman and `--network=host` combination:

## Environment

- `@devcontainers/cli`: 0.88.0
- Podman client/server: 5.7.1
- Host: WSL2
- Podman server: rootful

## Problem

For Podman on Linux and a non-root `remoteUser`, Dev Containers automatically adds:

```text
--security-opt label=disable --userns=keep-id
```

See https://github.com/devcontainers/cli/issues/1004 and https://github.com/microsoft/vscode-remote-release/issues/10399.

When the configuration also requires `--network=host`, the container fails to start.

## Minimal underlying reproducer

This fails:

```sh
podman run --rm \
--network=host \
--userns=keep-id \
docker.io/library/alpine:3.20 \
true
```

Error:

```text
crun: mount `sysfs` to `sys`: Operation not permitted: OCI permission denied
```

Without `--userns=keep-id`, it succeeds:

```sh
podman run --rm \
--network=host \
docker.io/library/alpine:3.20 \
true
```

The CLI-generated `podman run` command contains both:

```text
--userns=keep-id --network=host
```

The automatic argument is added in:

```text
src/spec-node/singleContainer.ts
getPodmanArgs()
```

## Expected behavior

Users must be able to prevent the CLI from adding `--userns=keep-id`.

## Possible fixes

No one is perfect I'm afraid.

1. Do not add `--userns=keep-id` when `--network=host` is present.
2. Add a setting or CLI option to disable automatic Podman arguments.
3. Respect an explicit `--userns=...` in `runArgs` and do not add `--userns=keep-id`.
4. Make automatic `--userns=keep-id` opt-in instead of unconditional for non-root users.

Big thanks.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start in src/spec-node/singleContainer.ts at getPodmanArgs(), then compare how runArgs and --network=host are incorporated into the generated Podman command. Use the Alpine reproducer from the issue to verify the conflicting arguments, and confirm that an explicit user choice can prevent the failing automatic combination.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
typescript
領域
cli, devops
issue の種類
バグ
難易度
3/5
見積もり時間
1〜2日
活発さ
活発
明瞭さ
おおむね明確
初心者へのやさしさ
68/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。