devcontainers / devcontainers/cli

Podman: automatic `--userns=keep-id` breaks containers using host networking

未关闭
#1,301 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
TypeScript
星标
3k
派生
457
平均合并
13 小时 17 分钟
30 天内合并 PR
6

描述

I'm facing an issue when using podman and `--network=host` combination:

## Environment

- `@devcontainers/cli`: 0.88.0
- Podman client/server: 5.7.1
- Host: WSL2
- Podman server: rootful

## Problem

For Podman on Linux and a non-root `remoteUser`, Dev Containers automatically adds:

```text
--security-opt label=disable --userns=keep-id
```

See https://github.com/devcontainers/cli/issues/1004 and https://github.com/microsoft/vscode-remote-release/issues/10399.

When the configuration also requires `--network=host`, the container fails to start.

## Minimal underlying reproducer

This fails:

```sh
podman run --rm \
--network=host \
--userns=keep-id \
docker.io/library/alpine:3.20 \
true
```

Error:

```text
crun: mount `sysfs` to `sys`: Operation not permitted: OCI permission denied
```

Without `--userns=keep-id`, it succeeds:

```sh
podman run --rm \
--network=host \
docker.io/library/alpine:3.20 \
true
```

The CLI-generated `podman run` command contains both:

```text
--userns=keep-id --network=host
```

The automatic argument is added in:

```text
src/spec-node/singleContainer.ts
getPodmanArgs()
```

## Expected behavior

Users must be able to prevent the CLI from adding `--userns=keep-id`.

## Possible fixes

No one is perfect I'm afraid.

1. Do not add `--userns=keep-id` when `--network=host` is present.
2. Add a setting or CLI option to disable automatic Podman arguments.
3. Respect an explicit `--userns=...` in `runArgs` and do not add `--userns=keep-id`.
4. Make automatic `--userns=keep-id` opt-in instead of unconditional for non-root users.

Big thanks.

贡献指南

打开贡献指南

调研方向

Start in src/spec-node/singleContainer.ts at getPodmanArgs(), then compare how runArgs and --network=host are incorporated into the generated Podman command. Use the Alpine reproducer from the issue to verify the conflicting arguments, and confirm that an explicit user choice can prevent the failing automatic combination.

由索引模型根据 Issue 内容生成。

评估

技术栈
typescript
领域
cli, devops
Issue 类型
缺陷
难度
3/5
预计耗时
1-2 天
活跃度
活跃
描述清晰度
基本清楚
新手友好度
68/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。