Skip to content

crun: open /proc/sys/net/ipv4/ping_group_range: Permission denied: OCI permission denied #25517

Answered by Luap99
Egoistically asked this question in Q&A
Discussion options

You must be logged in to vote

see https://blog.podman.io/2023/12/interaction-between-user-namespaces-and-capabilities/

It doesn't describe your scenario but it is essentially the same thing. As soon as a new user namespace is created you cannot use any parent namespaces (unless you already happened to be in it but even then you loose all capabilities for it).

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@Egoistically
Comment options

@Luap99
Comment options

Answer selected by Egoistically
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants