Skip to content

Nix silently refuses to setup a userns for the sandbox if kernel.unprivileged_userns_clone=0 #14914

@roberth

Description

@roberth

Describe the bug

Originally reported in #8165, then closed by author, lost on the pile, and referenced again by author. Still needs triage.

Steps To Reproduce

sysctl -w kernel.unprivileged_userns_clone=0; see #8165

Expected behavior

Success or explicit failure.

Metadata

Additional context

Checklist


Add 👍 to issues you find important.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugsandboxHow we isolate build impurities and protect the host

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions