aboutsummaryrefslogtreecommitdiff
path: root/cmd/podman/common
diff options
context:
space:
mode:
authorGiuseppe Scrivano <gscrivan@redhat.com>2020-04-24 15:37:31 +0200
committerGiuseppe Scrivano <gscrivan@redhat.com>2020-04-24 15:55:38 +0200
commit88f1994ab9a0bf3a8df3c8f74a39cd1db27c2070 (patch)
tree0cbd25a81bc2874613658dfe26db08db61d45795 /cmd/podman/common
parent64d8b4eebb01c6647b0588475c785cdd075389d3 (diff)
downloadpodman-88f1994ab9a0bf3a8df3c8f74a39cd1db27c2070.tar.gz
podman-88f1994ab9a0bf3a8df3c8f74a39cd1db27c2070.tar.bz2
podman-88f1994ab9a0bf3a8df3c8f74a39cd1db27c2070.zip
podman: assume user namespace if there are mappings
if some mappings are specified, assume there is a private user namespace. Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
Diffstat (limited to 'cmd/podman/common')
-rw-r--r--cmd/podman/common/specgen.go7
1 files changed, 6 insertions, 1 deletions
diff --git a/cmd/podman/common/specgen.go b/cmd/podman/common/specgen.go
index ce91e0b2e..ed45a6595 100644
--- a/cmd/podman/common/specgen.go
+++ b/cmd/podman/common/specgen.go
@@ -209,10 +209,15 @@ func FillOutSpecGen(s *specgen.SpecGenerator, c *ContainerCLIOpts, args []string
}
}
- s.IDMappings, err = util.ParseIDMapping(ns.UsernsMode(c.UserNS), c.UIDMap, c.GIDMap, c.SubUIDName, c.SubGIDName)
+ userNS := ns.UsernsMode(c.UserNS)
+ s.IDMappings, err = util.ParseIDMapping(userNS, c.UIDMap, c.GIDMap, c.SubUIDName, c.SubGIDName)
if err != nil {
return err
}
+ // If some mappings are specified, assume a private user namespace
+ if userNS.IsDefaultValue() && (!s.IDMappings.HostUIDMapping || !s.IDMappings.HostGIDMapping) {
+ s.UserNS.NSMode = specgen.Private
+ }
s.Terminal = c.TTY
ep, err := ExposedPorts(c.Expose, c.Net.PublishPorts, c.PublishAll, nil)