{
  "id": 10829936,
  "title": "Rootless podman export of a keep-id container shifts every file owner, exit 0",
  "url": "https://urgent.news/2026/09/30/rootless-podman-export-of-a-keep-id-container-shifts-every-file-owner",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-30T01:51:19.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/homelabpm/rootless-podman-export-of-a-keep-id-container-shifts-every-file-owner-exit-0-o42"
  },
  "original_language": "en",
  "account": "The issue lies with the way podman exports files from a rootless container created with --userns=keep-id. When the files are tarred during the export, their owner and group IDs are shifted by the container's ID mapping. This means that files that were previously owned by the container's user (UID 1000 in the example) appear in the exported tarball with owners UID 1, causing problems such as permissions errors when the exported tarball is imported and used in a new container.\n\nFor example, a note file created by the user inside the container would have its owner set to UID 1 in the exported tarball, preventing the user from writing to it upon importing the tarball. This issue impacts not only the user's home directory but also system files and setuid binaries, which are also affected by the shift in owners and groups.\n\nThe export process does not pass any ID mapping to the tar writer, which means the original owners and groups are not preserved. This behavior was present in podman version 5.4.2 and in the current main version, making it a consistent issue across different podman releases.\n\nThe problem is tricky to detect since the export command does not output any information about the file owners or IDs, and the man page does not mention user namespaces or ID mappings. The tarball itself appears to contain the correct files with their proper permission bits, but the owner and group columns in the `tar tv` list are incorrect.\n\nTo resolve this issue, the recommended solution is to use podman commit to create a new container image from the keep-id container. This new image will have the correct file ownerships, and exporting and importing this new image will result in the expected file permissions. The check-podman-export-idmap.sh script can be used to identify containers that are at risk of this issue.",
  "summary": "TL;DR : podman export of a rootless container that was created with --userns=keep-id writes a tarball in which every file owner is shifted by the container's ID mapping. Inside the container the user's home is 1000/1000 and system files are 0/0 . In the export, the home is 0/0 , the 3257 root-owned files are 1/1 , and su , passwd and the other setuid binaries are setuid to UID 1. The export exits…",
  "key_points": [
    "Rootless podman export shifts file owners in keep-id containers.",
    "Exported tarball shows incorrect UID 1 for container user's files.",
    "Using podman commit resolves incorrect file ownerships in exported tarball."
  ],
  "editors_take": "This development highlights a security and permissions issue with rootless podman exports that can cause problems when importing tarballs, and reveals a needed update to preserve original file ownerships.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}