-
Notifications
You must be signed in to change notification settings - Fork 2.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Can't use attached --device in rootless container "Permission denied" #9706
Comments
Did you check SELinux? podman run --rm -it --security-opt label=disable --device=/dev/ttyACM0 ubuntu:latest /bin/bash |
I will check in the future if I can get it to work with SELinux too. |
Could you attach the AVCs? |
Haven’t had time to check SELinux yet. Will try to do it this weekend. When I do I can attach the AVCs. |
I have this issue now in Fedora 36 with podman 4.2.0 On host (I have created udev rules to give me the ownership of this device. But I got the exact same results when the device was owned by
In container (
Running podman with In SELinux logs on host:
|
Is this a BUG REPORT or FEATURE REQUEST? (leave only one on its own line)
/kind bug
Description
Can not use an "attached" USB device in rootless container via
--device
because of "Permission denied" on the USB device. I have tried using--annotation run.oci.keep_original_groups=1
but the original groups does not follow along to the container - or - I am misunderstanding and doing something wrong. Would be really glad for some help.Sidenote:
--annotation run.oci.keep_original_groups=1
does not appear to make any difference in root container either - but I have not investigated that further. Maybe it is intended?Steps to reproduce the issue:
On host:
Rootless container without
--annotation run.oci.keep_original_groups=1
:Rootless container with
--annotation run.oci.keep_original_groups=1
:Describe the results you received:
I can not use the attached --device in the container because of the "Permission denied".
Describe the results you expected:
I was hoping to be able to use the --device in a rootless container.
Additional information you deem important (e.g. issue happens only occasionally):
Output of
podman container inspect goofy_stonebraker | grep Annotations -A 9
on rootless container started with --annotation run.oci.keep_original_groups=1:I have checked issue #4477 which I thought could help me, but it does not help.
Output of
podman version
:Output of
podman info --debug
:Package info (e.g. output of
rpm -q podman
orapt list podman
):Have you tested with the latest version of Podman and have you checked the Podman Troubleshooting Guide?
Yes, 20) in https://github.com/containers/podman/blob/master/troubleshooting.md seems to be my problem.
Additional environment details (AWS, VirtualBox, physical, etc.):
Tested on "bare metal" on RPI 3B+ and in QEMU/KVM with the same result.
The text was updated successfully, but these errors were encountered: