-
Notifications
You must be signed in to change notification settings - Fork 334
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Youki fails when some unused capability is missing #1999
Comments
The issue is caused by |
@jprendes Thank you for the bug report. I believe the first step to address this issue is to set up an integration test like we do for containerd and k8s. Then we can start to explore how to consistently support the In addition, it would be good to understand why
This sounds like a bug to me. May be |
@yihuaf thanks for looking into this. Additionally, doing an
while
|
Yeah, I think this is the way to go. The problem is that the thread is that I've updated the PR to reflect this. |
I am trying to run
youki
in a container context (think Docker in Docker), and it fails to run if the container doesn't have all the capabilities enabled.In particular, this also happens if some capabilities added in kernel 5.8 / 5.9 are not present (like
CAP_BPF
orCAP_CHECKPOINT_RESTORE
). I haven't tested in a post-5.3 and pre-5.9 kernel, but I think it would hit the same issue.Note that
runc
does work in the same situation.Please see the attachment for reproduction steps: reproduction.zip
The text was updated successfully, but these errors were encountered: