Revert "spec: bind mount /sys only for rootless containers"
It breaks "podman run --net=host --uidmap=0:1:70000 --gidmap=0:20000:70000 busybox echo hi" Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com> Closes: #1285 Approved by: rhatdan
This commit is contained in:
parent
1003df3444
commit
c0abfaa7c3
|
@ -35,7 +35,7 @@ func CreateConfigToOCISpec(config *CreateConfig) (*spec.Spec, error) { //nolint
|
||||||
Options: []string{"nosuid", "noexec", "nodev", "rw"},
|
Options: []string{"nosuid", "noexec", "nodev", "rw"},
|
||||||
}
|
}
|
||||||
g.AddMount(sysMnt)
|
g.AddMount(sysMnt)
|
||||||
} else if rootless.IsRootless() && !config.UsernsMode.IsHost() && config.NetMode.IsHost() {
|
} else if !config.UsernsMode.IsHost() && config.NetMode.IsHost() {
|
||||||
addCgroup = false
|
addCgroup = false
|
||||||
g.RemoveMount("/sys")
|
g.RemoveMount("/sys")
|
||||||
sysMnt := spec.Mount{
|
sysMnt := spec.Mount{
|
||||||
|
|
Loading…
Reference in New Issue