From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: passt.top; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=U448x63q; dkim-atps=neutral Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by passt.top (Postfix) with ESMTPS id C2DFF5A0269 for ; Wed, 07 Oct 2026 18:45:23 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1791391522; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=UeY9mS6pox7WwsBYlJ5WlYUQMhMTqh1wMGaQJUKLlxg=; b=U448x63qg4DAshcc3cbFgKWQd71v1gdYpRYgfjo032pQ+xWfYaFhzlJXDKdI4I3jT+OfY9 Hn7CIgoHGhC5rnXisT8dzElRbyOFucpePCXMhz0Aq7ILe/FbkrKFefg+2hnX6ZHh7Way5J lC9dHSIlKOfQSwYle1iQeBfCZRvIRWg= Received: from mail-wr1-f72.google.com (mail-wr1-f72.google.com [209.85.221.72]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-217-O4v2j9J1PYqMift8kOV_HA-1; Wed, 07 Oct 2026 12:45:21 -0400 X-MC-Unique: O4v2j9J1PYqMift8kOV_HA-1 X-Mimecast-MFC-AGG-ID: O4v2j9J1PYqMift8kOV_HA_1791391520 Received: by mail-wr1-f72.google.com with SMTP id ffacd0b85a97d-4887e5afd67so3464958f8f.3 for ; Wed, 07 Oct 2026 09:45:20 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791391520; x=1791996320; h=date:content-transfer-encoding:content-type:mime-version :organization:references:in-reply-to:message-id:subject:cc:to:from :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=UeY9mS6pox7WwsBYlJ5WlYUQMhMTqh1wMGaQJUKLlxg=; b=fUh1eyY3118zpwHskcA5TwMBB09zTxrs6LdzR+e3q9F8hhSBIN+hZFvd7KR51mftak Z+/wy6IXb2jpJLDiswRxESZ/o9LNuiD+TJyAZ8OiGT6mVyyf79hOfYqcryZSbELAcrxm xrYzou3UtNEXZDyWzk5BNcAR1UDKk0snNMNOOLLEbJtCYctJJH+Acq6rIKy0W1MpnV/S EAeQsrG6IxyKx0pOGYhjlrkiJ0KDiF09EhOjmEDTfJFg0NQSfOeq0ns5r6f57SACiVzy 8bFW6DHeXoDHV4myMovuiULpo4+O5GXFhhaaGsUWHdjhWM2WqCVnEkDufot50WZAOtGQ bovA== X-Gm-Message-State: AFq9FYKE0SR2QGeGDBHM+H+twIrvB+26xsMKqAvxcE2z3+FpouWOZMNy t5XXUnxU+dhFjytlK+9LG8oQuq0l0U2G33b+YvRxwm24wiU/VT83pktg2Uh9lueP3j5NmDvhJv+ HVZyrgHSN1UTGtpaq5WG/hzMOYNaRipvpQNfwy7ouDeXYjuo568n+ls7c7GTx8g== X-Gm-Gg: AYBFou1jY3ULLRZPSuzDUTQab7vTVrCKC+/SeP6ADbYlWJ41vbyX83xZGzNNkn8B14Q ogH/GFlRLXrKI8Q3pMVbrVBhIe5pkHOZgrdi4PxX7AOsmu/Obu0COKuLPir1dvwbry+NSxYzIVV NQ3jZx+bEjPAdQbgj8wtIXXbegOYKv5rna8Ikryt622zFklpBnmYBeByK8EOxvNOUvCHIkjG3tG DqSu/qv/IDGz+DGL5jX9sT3o7tCOGlDZr7TfbuaLNN8IcnXWjPz8y2dAEGFdV4gksGZ8goBwowN +NptKVsXi+frG1+SLkSsn1oRCGlLXJL3BURqx0d974zZssdrlvaAWAisBUApYTmJF5R3P6c+NXn nRDHMP/Amaw== X-Received: by 2002:a05:6000:4b09:b0:48b:722:1c6d with SMTP id ffacd0b85a97d-48c7288afadmr6056924f8f.38.1791391519616; Wed, 07 Oct 2026 09:45:19 -0700 (PDT) X-Received: by 2002:a05:6000:4b09:b0:48b:722:1c6d with SMTP id ffacd0b85a97d-48c7288afadmr6056857f8f.38.1791391519051; Wed, 07 Oct 2026 09:45:19 -0700 (PDT) Received: from maya.myfinge.rs (ifcgrfdd.trafficplex.cloud. [2a10:fc81:a806:d6a9::1]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-48c71c0b604sm6393356f8f.13.2026.10.07.09.45.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 07 Oct 2026 09:45:18 -0700 (PDT) From: Stefano Brivio To: David Gibson Subject: Re: [PATCH] util: Make setting uidmap and gidmap errors non-fatal Message-ID: <20261007184516.38e87042@elisabeth> In-Reply-To: References: <20261002070050.2065232-1-sbrivio@redhat.com> Organization: Red Hat X-Mailer: Claws Mail 4.2.0 (GTK 3.24.49; x86_64-pc-linux-gnu) MIME-Version: 1.0 Date: Wed, 07 Oct 2026 18:45:17 +0200 (CEST) X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: fseBjhR3ilsc5vjHBiwEhs3a62P6CXig4qq3lK4OH_g_1791391520 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Message-ID-Hash: 4LQPUDLYEPYVMYF7MVLDCSK66NMCDR56 X-Message-ID-Hash: 4LQPUDLYEPYVMYF7MVLDCSK66NMCDR56 X-MailFrom: sbrivio@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: passt-dev@passt.top X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: On Tue, 6 Oct 2026 13:49:08 +1100 David Gibson wrote: > On Fri, Oct 02, 2026 at 09:00:50AM +0200, Stefano Brivio wrote: > > Starting from commit 7bf1595c9242 ("isolation: Don't create our userns > > as nobody"), we unconditionally set uidmap and gidmap in the detached > > user namespace. > > > > If passt is started from a detached PID namespace, but /proc hasn't > > been remounted to reflect this, we'll fail to write those entries. > > > > That's actually fine as uidmap and gidmap are something that, strictly > > speaking, we only need to write in pasta mode when a command is > > detached (it's now done in all cases for simplicity). > > > > Warn, because it's not the expected behaviour (/proc should probably > > be remounted first), but don't fail on that. > > > > Link: https://github.com/containers/crun/issues/2283 > > Suggested-by: David Gibson > > Signed-off-by: Stefano Brivio > > Since this can now fail non-fatally, I'd suggest adding a return code > to make_ugid_map(). The caller (create_userns()) should probably > die() if it fails when we're actually changing UID/GID. It sounds reasonable, feel free to send a patch, but note that we still have an issue here: https://github.com/containers/crun/issues/2283#issuecomment-6040477454 and my further patch linked below in that webpage might be needed. I would consider further changes only once that is fixed for good. -- Stefano