On Fri, Oct 02, 2026 at 09:00:50AM +0200, Stefano Brivio wrote: > Starting from commit 7bf1595c9242 ("isolation: Don't create our userns > as nobody"), we unconditionally set uidmap and gidmap in the detached > user namespace. > > If passt is started from a detached PID namespace, but /proc hasn't > been remounted to reflect this, we'll fail to write those entries. > > That's actually fine as uidmap and gidmap are something that, strictly > speaking, we only need to write in pasta mode when a command is > detached (it's now done in all cases for simplicity). > > Warn, because it's not the expected behaviour (/proc should probably > be remounted first), but don't fail on that. > > Link: https://github.com/containers/crun/issues/2283 > Suggested-by: David Gibson > Signed-off-by: Stefano Brivio Since this can now fail non-fatally, I'd suggest adding a return code to make_ugid_map(). The caller (create_userns()) should probably die() if it fails when we're actually changing UID/GID. > --- > util.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/util.c b/util.c > index c02aea9..ff1f19f 100644 > --- a/util.c > +++ b/util.c > @@ -1147,5 +1147,5 @@ void make_ugid_map(pid_t pid, uid_t uid, gid_t gid) > if (write_file(uidmap_path, uidmap) || > write_file(setgroups_path, "deny") || > write_file(gidmap_path, gidmap)) > - die("Couldn't configure user mappings"); > + warn("Couldn't configure user mappings"); > } > -- > 2.43.0 > -- David Gibson (he or they) | I'll have my music baroque, and my code david AT gibson.dropbear.id.au | minimalist, thank you, not the other way | around. http://www.ozlabs.org/~dgibson