Podman bug silently corrupts file ownership when exporting rootless keep-id containers
A confirmed bug in Podman 5.4.2 causes the 'podman export' command to silently shift all file ownership metadata when used with rootless containers created using the '--userns=keep-id' flag. The export process passes no ID mapping to its tar writer, meaning files that belonged to UID/GID 1000 inside the container are written as 0/0 in the tarball, while root-owned files shift to 1/1. The command exits with code 0 and produces no error output, making the corruption invisible until the imported image is actually used. Practical consequences include users being denied write access to their own home directories and setuid binaries like 'su' and 'passwd' becoming assigned to UID 1 (daemon), rendering them non-functional. A workaround exists via 'podman commit' followed by a fresh export, and a diagnostic script has been shared alongside an upstream bug report filed at podman#29856.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in