Created attachment 5018 [details] /usr/bin/newuidmap is owned by user nobody when running yocto bitbake recipe. Docker build or Podman build fails from Yocto and seen no issue when run manually. Below are the error logs. Log data follows: | DEBUG: Executing shell function do_compile | Deleting any existing *tar.gz files | Building img_ui from | time="2024-02-13T08:51:23Z" level=error msg="invalid internal status, try resetting the pause process with "/usr/bin/podman system migrate": command required for rootless mode with multiple IDs: exec: "newuidmap": executable file not found in $PATH" | WARNING: /home/build/tmp/work/corei7-64-poky-linux/ui-docker/1.0-r0/temp/run.do_compile.48173:156 exit 1 from 'docker build -t img_ui -f /home/build/tmp/work/corei7-64-poky-linux/ui-docker/1.0-r0/Dockerfile /home/build/tmp/work/corei7-64-poky-linux/ui-docker/1.0-r0' | WARNING: Backtrace (BB generated script): | containers/podman-desktop#1: do_compile, /home/build/tmp/work/corei7-64-poky-linux/ui-docker/1.0-r0/temp/run.do_compile.48173, line 156 | containers/podman-desktop#2: main, /home/build/tmp/work/corei7-64-poky-linux/ui-docker/1.0-r0/temp/run.do_compile.48173, line 172 I see /usr/bin/newuidmap is owned by user nobody instead of root while running yocto bitbake recipe. is this causing issue ? Hardware: x86_64 desktop pc OS: RHEL 8.9
We don't usually take meta-virt bugs in this bugzilla so please post on the meta-virt email list. I've CCed Bruce and Mingli who work on docker and podman from time to time.
You can't run "docker build" or "podman build" directly in a recipe. They require permissions and utilities that can't run within the restricted pseudo controlled environment. I have ongoing efforts to cross install containers by working through these low level issues. While those fixes/features won't target a "build" operation, they may help them in the long run.