Bug 12413 - Add a more helpful error message if the workdir is owned by uid/gid 0
Summary: Add a more helpful error message if the workdir is owned by uid/gid 0
Status: RESOLVED FIXED
Alias: None
Product: CROPS
Classification: Yocto Project Subprojects
Component: crops-default (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: Medium enhancement
Target Milestone: Future
Assignee: Unassigned
QA Contact:
URL: https://github.com/crops/poky-contain...
Whiteboard:
Depends on:
Blocks:
 
Reported: 2017-12-11 16:51 UTC by Joshua Lock
Modified: 2024-05-09 14:56 UTC (History)
3 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Joshua Lock 2017-12-11 16:51:38 UTC
Currently if the uid or gid of the workdir are 0, then the user will get a relatively cryptic message

Refusing to use a gid of 0
Traceback (most recent call last):
  File "/usr/bin/usersetup.py", line 62, in <module>
    subprocess.check_call(cmd.split(), stdout=sys.stdout, stderr=sys.stderr)
  File "/usr/lib/python2.7/subprocess.py", line 541, in check_call
    raise CalledProcessError(retcode, cmd)
subprocess.CalledProcessError: Command '['sudo', 'restrict_groupadd.sh', '0', 'pokyuser']' returned non-zero exit status 1

This should be changed to something more user friendly explaining what may have happened.

In the most common case, the argument passed as --workdir and was bind mounted wasn't yet created before docker starts. For example if the below command was used:

docker run -it --rm -v /foo:/workdir crops/poky --workdir=/workdir

If /foo didn't exist before running docker, then docker will create /foo and give it a uid:gid of 0. While this behavior seems like the wrong action to take, docker chose to preserve it due to reasons of "not breaking workflows".

At that point all the user has to remove the directory docker created, and instead create it manually with the appropriate uid:gid.

Since the "--mount" option to docker will instead error if the directory doesn't exist, then the documentation could be changed to point out the "--mount" option as well. It however, can't be used on older version of docker.

Copied from https://github.com/crops/poky-container/issues/20