Rootless podman export of a keep-id container shifts every file owner, exit 0
TL;DR : podman export of a rootless container that was created with --userns=keep-id writes a tarball in which every file owner is shifted by the container's ID mapping. Inside the container the user's home is 1000/1000 and system files are 0/0 . In the export, the home is 0/0 , the 3257 root-owned files are 1/1 , and su , passwd and the other setuid binaries are setuid to UID 1. The export exits…
The issue lies with the way podman exports files from a rootless container created with --userns=keep-id. When the files are tarred during the export, their owner and group IDs are shifted by the container's ID mapping. This means that files that were previously owned by the container's user (UID 1000 in the example) appear in the exported tarball with owners UID 1, causing problems such as permissions errors when the exported tarball is imported and used in a new container.
For example, a note file created by the user inside the container would have its owner set to UID 1 in the exported tarball, preventing the user from writing to it upon importing the tarball. This issue impacts not only the user's home directory but also system files and setuid binaries, which are also affected by the shift in owners and groups.
The export process does not pass any ID mapping to the tar writer, which means the original owners and groups are not preserved. This behavior was present in podman version 5.4.2 and in the current main version, making it a consistent issue across different podman releases.
The problem is tricky to detect since the export command does not output any information about the file owners or IDs, and the man page does not mention user namespaces or ID mappings. The tarball itself appears to contain the correct files with their proper permission bits, but the owner and group columns in the `tar tv` list are incorrect.
To resolve this issue, the recommended solution is to use podman commit to create a new container image from the keep-id container. This new image will have the correct file ownerships, and exporting and importing this new image will result in the expected file permissions. The check-podman-export-idmap.sh script can be used to identify containers that are at risk of this issue.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.