rootful: do not set XDG_RUNTIME_DIR for cni plugins

The dnsname plugin tries to use XDG_RUNTIME_DIR to store files.
podman run will have XDG_RUNTIME_DIR set and thus the cni plugin can use
it. The problem is that XDG_RUNTIME_DIR is unset for the conmon process
for rootful users. This causes issues since the cleanup process is spawned
by conmon and thus not have XDG_RUNTIME_DIR set to same value as podman run.

Because of it dnsname will not find the config files and cannot correctly
cleanup.
To fix this we should also unset XDG_RUNTIME_DIR for the cni plugins as
rootful.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
This commit is contained in:
Paul Holzinger 2021-09-24 10:44:46 +02:00
parent 1cf66f514f
commit 6095c4fac0
No known key found for this signature in database
GPG Key ID: EB145DD938A3CAF2
1 changed files with 12 additions and 0 deletions

View File

@ -30,6 +30,7 @@ import (
"github.com/containernetworking/cni/pkg/invoke"
"github.com/containernetworking/cni/pkg/version"
"github.com/containers/podman/v3/pkg/rootless"
)
type cniExec struct {
@ -67,6 +68,17 @@ func (e *cniExec) ExecPlugin(ctx context.Context, pluginPath string, stdinData [
c.Stdout = stdout
c.Stderr = stderr
// The dnsname plugin tries to use XDG_RUNTIME_DIR to store files.
// podman run will have XDG_RUNTIME_DIR set and thus the cni plugin can use
// it. The problem is that XDG_RUNTIME_DIR is unset for the conmon process
// for rootful users. This causes issues since the cleanup process is spawned
// by conmon and thus not have XDG_RUNTIME_DIR set to same value as podman run.
// Because of it dnsname will not find the config files and cannot correctly cleanup.
// To fix this we should also unset XDG_RUNTIME_DIR for the cni plugins as rootful.
if !rootless.IsRootless() {
c.Env = append(c.Env, "XDG_RUNTIME_DIR=")
}
err := c.Run()
if err != nil {
return nil, annotatePluginError(err, pluginPath, stdout.Bytes(), stderr.Bytes())