[Bug]: copyFileToContainer retention of uid/gid breaks rootless Docker
维护者通常 1 天内回复
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 48/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 冷清
- 技术栈
- docker, java
- 领域
- devops, testing-qa
调研方向
从 container_copy_common.go 和报告中提到的 copyFileToContainer 路径开始,然后使用提供的所有权和权限详细信息,通过 rootless Docker 重现文件复制。追踪主机 UID/GID 的应用位置,并为所请求的行为添加覆盖;完成的标准是复制的文件可以被容器使用,且不会出现 rootless 权限错误。
由索引模型根据 Issue 内容生成。
描述
Module
Core
Testcontainers version
1.21.3
Using the latest Testcontainers version?
Yes
Host OS
OpenSuse
Host Arch
x86
Docker version
Docker version 28.5.1-ce
What happened?
Trying to solve this issue in keycloak dev container https://github.com/quarkusio/quarkus/issues/45940
I have found, that copyFileToContainer function sets owner of the copied file to the user id, which are not exists inside container
in my case it was:
-rw-r--r--. 1 439803918 439800513 1201 Feb 4 14:24 upconfig.json
Debugging through Test container source code I have found in container_copy_common.go following commentary:
// We optimistically chown to the host user. In case of a hypothetical
// container-to-container copy, the reading side will chown back to the
// container user.
There is no way to override this behavior, even if function is called without permission mask, file owner will be changed to host owner user id, which is not exist inside container.
This permission change accidentally works in rootfull docker , because as root you can set owner even if this owner does not exists, but does not work in rootless docker, because unprivileged user could not set owner to not existed user, leading to the described "Keycloak Dev Service fails to start on rootless Docker setup"
Unfortunately we was not able to find any workaround ad need this hard coded chown could be disabled in this function.
Relevant log output
Keycloak Devservice fails to start with rootless docker with following error log.
2025-01-29 09:09:18,785 INFO [tc.qua.io/.0.6] (build-23) Creating container for image: quay.io/keycloak/keycloak:25.0.6
2025-01-29 09:09:18,794 INFO [tc.tes.11.0] (build-23) Creating container for image: testcontainers/ryuk:0.11.0
2025-01-29 09:09:18,866 INFO [tc.tes.11.0] (build-23) Container testcontainers/ryuk:0.11.0 is starting: 721e3e87dd739f95f37021e640a42046a74833cc1bf8a3507cc7916814c5163d
2025-01-29 09:09:19,109 INFO [tc.tes.11.0] (build-23) Container testcontainers/ryuk:0.11.0 started in PT0.314788777S
<====2025-01-29 09:09:19,151 INFO [tc.qua.io/.0.6] (build-23) Container quay.io/keycloak/keycloak:25.0.6 is starting: c25e849df4aa9d8c18ab05109bb46990bf18f961a50cad35247e10948dc428f6
<====2025-01-29 09:09:20,007 INFO [io.qua.dev.key.KeycloakDevServicesProcessor] (docker-java-stream--1719331462) Keycloak: Changes detected in configuration. Updating the server image.
<====2025-01-29 09:09:20,023 INFO [io.qua.dev.key.KeycloakDevServicesProcessor] (docker-java-stream--1719331462) Keycloak: Updating the configuration and installing your custom providers, if any. Please wait.
<====2025-01-29 09:09:25,079 INFO [io.qua.dev.key.KeycloakDevServicesProcessor] (docker-java-stream--1719331462) Keycloak: 2025-01-29 08:09:25,078 INFO [io.qua.dep.QuarkusAugmentor] (main) Quarkus augmentation completed in 4490msEXECUTING [10s]
2025-01-29 09:09:25,091 INFO [io.qua.dev.key.KeycloakDevServicesProcessor] (docker-java-stream--1719331462) Keycloak: Server configuration updated and persisted. Run the following command to review the configuration:
2025-01-29 09:09:25,091 INFO [io.qua.dev.key.KeycloakDevServicesProcessor] (docker-java-stream--1719331462) Keycloak:
2025-01-29 09:09:25,091 INFO [io.qua.dev.key.KeycloakDevServicesProcessor] (docker-java-stream--1719331462) Keycloak: kc.sh show-config
2025-01-29 09:09:25,092 INFO [io.qua.dev.key.KeycloakDevServicesProcessor] (docker-java-stream--1719331462) Keycloak:
2025-01-29 09:09:25,093 INFO [io.qua.dev.key.KeycloakDevServicesProcessor] (docker-java-stream--1719331462) Keycloak: Next time you run the server, just run:
2025-01-29 09:09:25,093 INFO [io.qua.dev.key.KeycloakDevServicesProcessor] (docker-java-stream--1719331462) Keycloak:
2025-01-29 09:09:25,093 INFO [io.qua.dev.key.KeycloakDevServicesProcessor] (docker-java-stream--1719331462) Keycloak: kc.sh start --http-enabled=true --hostname-strict=false --spi-user-profile-declarative-user-profile-config-file=/opt/keycloak/upconfig.json --optimized
2025-01-29 09:09:25,093 INFO [io.qua.dev.key.KeycloakDevServicesProcessor] (docker-java-stream--1719331462) Keycloak:
2025-01-29 09:09:26,144 INFO [io.qua.dev.key.KeycloakDevServicesProcessor] (docker-java-stream--1719331462) Keycloak: ERROR: Unexpected error when starting the server in (production) mode
2025-01-29 09:09:26,144 INFO [io.qua.dev.key.KeycloakDevServicesProcessor] (docker-java-stream--1719331462) Keycloak: ERROR: Failed to start quarkus
2025-01-29 09:09:26,144 INFO [io.qua.dev.key.KeycloakDevServicesProcessor] (docker-java-stream--1719331462) Keycloak: ERROR: Failed to reaad default user profile configuration: /opt/keycloak/upconfig.json
2025-01-29 09:09:26,145 INFO [io.qua.dev.key.KeycloakDevServicesProcessor] (docker-java-stream--1719331462) Keycloak: ERROR: /opt/keycloak/upconfig.json (Permission denied)
2025-01-29 09:09:26,145 INFO [io.qua.dev.key.KeycloakDevServicesProcessor] (docker-java-stream--1719331462) Keycloak: For more details run the same command passing the '--verbose' option. Also you can use '--help' to see the details about the usage of the particular command.
It seems like the file permission of upconfig.json are not correct when copying the file to the container KeycloakDevServicesProcessor
drwxr-xr-x 1 keycloak root 4.0K Jan 29 08:10 .
drwxr-xr-x 1 root root 4.0K Sep 19 17:57 ..
drwxrwxr-x 3 keycloak root 4.0K Sep 19 17:53 bin
drwxrwxr-x 3 keycloak root 4.0K Sep 19 17:57 conf
drwxrwxr-x 2 keycloak root 4.0K Sep 19 17:57 data
drwxrwxr-x 1 keycloak root 4.0K Sep 19 17:53 lib
-rw-rw-r-- 1 keycloak root 12K Sep 19 17:43 LICENSE.txt
drwxrwxr-x 2 keycloak root 4.0K Sep 19 17:57 providers
-rw-rw-r-- 1 keycloak root 492 Sep 19 17:43 README.md
drwxrwxr-x 2 keycloak root 4.0K Sep 19 17:57 themes
-rw-r----- 1 5766578 20003 1.2K Jan 29 08:10 upconfig.json
-rw-rw-r-- 1 keycloak root 26 Sep 19 17:43 version.txt
5766578 is the UID of my local user.
Additional Information
No response
- 主要语言
- Java
- 星标
- 8.7k
- 派生
- 1.9k
- 平均合并
- 17 小时 38 分钟
- 30 天内合并 PR
- 3
环境准备
在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。
- 提供 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
testcontainers/testcontainers-java 的其他 Issue
-
[Bug]: Build fails with "Unknown cli flag: --scripts-prepend-node-path" due to outdated Spotless plugin可能已有人在做 @dhruv9b 于 34 天前认领。 未关闭type/bug
难度 2/5 1-3 小时 新手友好度 78/100
testcontainers/testcontainers-java#11997 · 1 条评论 ·
维护者通常 1 天内回复
-
[Enhancement]: Document why singleton containers are required under Spring's test context caching可能已有人在做 @zakaullah075 于 52 天前认领。 未关闭type/enhancement
难度 1/5 1 小时以内 新手友好度 85/100
testcontainers/testcontainers-java#11967 · 1 条评论 ·
维护者通常 1 天内回复
-
[Bug]: Cannot reuse Selenium BrowserWebDriverContainers under Linux可能已有人在做 @kdelay 于 73 天前认领。 未关闭type/bug
难度 2/5 1-3 小时 新手友好度 78/100
testcontainers/testcontainers-java#11941 ·
维护者通常 1 天内回复
-
[Bug]: DockerDesktopClientProviderStrategy is always applicable可能已有人在做 @seonwooj0810 于 122 天前认领。 未关闭type/bug
难度 2/5 1-3 小时 新手友好度 74/100
testcontainers/testcontainers-java#11829 · 1 条评论 ·
维护者通常 1 天内回复
-
[Enhancement]: cleanup document after removing junit4 support可能已有人在做 @SJvaca30 于 130 天前认领。 未关闭type/enhancement
难度 2/5 1-3 小时 新手友好度 65/100
testcontainers/testcontainers-java#11578 ·
维护者通常 1 天内回复
查看 testcontainers/testcontainers-java 的全部 Issue
相似的 Issue
-
难度 1/5 1 小时以内 新手友好度 90/100
bancolombia/scaffold-clean-architecture#1002 ·
维护者通常 1 天内回复
-
CalendarEventAttendance/get returns eventAttendanceStatus while the doc says attendanceStatus可能已有人在做 @chibenwa 今天认领。 未关闭bug claude
难度 1/5 1 小时以内 新手友好度 90/100
linagora/tmail-backend#2697 · 1 条评论 ·
维护者通常 1 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 75/100
apache/skywalking#14120 ·
维护者通常 1 天内回复
-
[BUG] Case-insensitive search suggestions miss items when the JVM default locale is Turkish可能已有人在做 @thswlsqls 今天认领。 未关闭
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复
-
enhancement
难度 2/5 1-3 小时 新手友好度 75/100
维护者通常 1 天内回复