You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu 22.04本地编译uidmap后,无根Docker启动失败求助

自行编译uidmap导致Rootless Docker启动失败的原因与解决方案

问题概述

在Ubuntu 22.04 LTS环境下,自行编译uidmap并安装至$HOME/.local目录后,Rootless Docker启动时出现权限错误:

[rootlesskit:parent] error: failed to setup UID/GID map: newuidmap 3117138 [0 1002 1 1 231072 65536] failed: newuidmap: write to uid_map failed: Operation not permitted

而通过系统包管理器(需root权限)安装uidmap后,Rootless Docker可正常运行。

核心原因:Setuid权限要求

这是功能限制,而非操作失误。系统包管理安装的newuidmap和newgidmap二进制文件带有setuid root特殊权限,这是它们修改进程UID/GID映射的必要条件:

  • 系统安装的文件权限示例:

    ls -l /usr/bin/newuidmap
    # 输出:-rwsr-xr-x 1 root root ...
    

    其中的s位表示setuid,程序运行时会以root身份执行,从而获得修改/proc/[pid]/uid_map和/proc/[pid]/gid_map的权限。

  • 自行编译安装到用户目录的newuidmap无法拥有该权限——普通用户无法为自己的文件设置setuid root属性,因此运行时没有足够权限修改UID映射,触发报错。

解决方法

  1. 通过root权限安装系统版uidmap
    只有root用户能为newuidmap添加setuid权限,必须执行:

    sudo apt install uidmap
    
  2. 确认用户UID/GID映射范围配置
    确保当前用户已分配足够的子UID/GID范围(需root权限):

    sudo usermod --add-subuids 100000-165535 <你的用户名>
    sudo usermod --add-subgids 100000-165535 <你的用户名>
    

总结

自行编译的uidmap无法满足Rootless Docker的权限需求,因为缺少关键的setuid root属性,而普通用户无法为个人目录下的文件设置该属性。必须使用系统包管理器安装uidmap才能让Rootless Docker正常启动。

内容的提问来源于stack exchange,提问作者maxswjeon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 04:21:00