On Tue, 6 Oct 2026 13:49:08 +1100
David Gibson
On Fri, Oct 02, 2026 at 09:00:50AM +0200, Stefano Brivio wrote:
Starting from commit 7bf1595c9242 ("isolation: Don't create our userns as nobody"), we unconditionally set uidmap and gidmap in the detached user namespace.
If passt is started from a detached PID namespace, but /proc hasn't been remounted to reflect this, we'll fail to write those entries.
That's actually fine as uidmap and gidmap are something that, strictly speaking, we only need to write in pasta mode when a command is detached (it's now done in all cases for simplicity).
Warn, because it's not the expected behaviour (/proc should probably be remounted first), but don't fail on that.
Link: https://github.com/containers/crun/issues/2283 Suggested-by: David Gibson
Signed-off-by: Stefano Brivio Since this can now fail non-fatally, I'd suggest adding a return code to make_ugid_map(). The caller (create_userns()) should probably die() if it fails when we're actually changing UID/GID.
It sounds reasonable, feel free to send a patch, but note that we still have an issue here: https://github.com/containers/crun/issues/2283#issuecomment-6040477454 and my further patch linked below in that webpage might be needed. I would consider further changes only once that is fixed for good. -- Stefano