Latest LQ Deal: Complete CCNA, CCNP & Red Hat Certification Training Bundle
Go Back > Forums > Linux Forums > Linux - Containers
User Name
Linux - Containers This forum is for the discussion of all topics relating to Linux containers. Docker, LXC, LXD, runC, containerd, CoreOS, Kubernetes, Mesos, rkt, and all other Linux container platforms are welcome.


  Search this Thread
Old 12-30-2017, 02:03 PM   #1
LQ Newbie
Registered: Jan 2016
Posts: 14

Rep: Reputation: Disabled
Networking worked fine on privileged containers but can't get it working on unprivileged container

Using archlinux.

I was able to set it up fine on privileged containers but now moving to unprivileged ones I can't get network going as yet. I followed the archwiki for linux conatiners and used the same details which worked for privileged ones, changing the respective paths to reflect their unprivileged equivalents. Below is the container's config file.

	# Template used to create this container: /usr/share/lxc/templates/lxc-download
	# Parameters passed to the template:
	# Template script checksum (SHA-1): b7de1d7259bdd66f5b8f0347f74b18c19729883a
	# For additional config options, please look at lxc.container.conf(5)
	# Uncomment the following line to support nesting containers:
	#lxc.include = /usr/share/lxc/config/nesting.conf
	# (Be aware this has security implications)
	# Distribution configuration
	lxc.include = /usr/share/lxc/config/archlinux.common.conf
	lxc.include = /usr/share/lxc/config/archlinux.userns.conf
	lxc.arch = x86_64
	# Container specific configuration
	lxc.idmap = u 0 100000 65536
	lxc.idmap = g 0 100000 65536
	lxc.rootfs.path = dir:/home/user1/.local/share/lxc/base-arch/rootfs = base-arch
	## network = veth = lxcbr0 = up = eth0 = ee:ec:fa:e9:56:7d
When I try and ping `network in unreachable`. `lxc-net` bridge is running.

user1 veth lxcbr0 10
When I restarted and looked in the container output

[FAILED] Failed to start Network Name Resolution.
See 'systemctl status systemd-resolved.service' for details.
[  OK  ] Stopped Network Name Resolution.
         Starting Network Name Resolution...
[FAILED] Failed to start Network Name Resolution.
See 'systemctl status systemd-resolved.service' for details.
Or that is just a symptom rather than a cause?

When I looked in journalctl in the running container I see

systemd-networkd.service: Failed to change ownership of session keyring: Permission denied
	systemd-networkd.service: Failed to set up kernel keyring: Permission denied
	systemd-networkd.service: Failed at step KEYRING spawning /usr/lib/systemd/systemd-networkd: Permission denied
Hmm ...

Also when I do `lspci -v` I get

02:00.0 Ethernet controller: Realtek Semiconductor Co., Ltd. RTL8111/8168/8411 PCI Express Gigabit Ethernet Controller (rev 09)
	        Subsystem: ASUSTeK Computer Inc. P8 series motherboard
	        Flags: bus master, fast devsel, latency 0, IRQ 45, NUMA node 0
	        I/O ports at d000 [size=256]
	        Memory at fa104000 (64-bit, prefetchable) [size=4K]
	        Memory at fa100000 (64-bit, prefetchable) [size=16K]
	        Capabilities: <access denied>
	        Kernel driver in use: r8169
So it is showing access denied under capabilities.

Could it still be a problem with not setting enough permissions on the $HOME folder? I did it in ACL with
setfacl -m "u:100000:--x" /home/user1
. Is it still not sufficient?

Last edited by Uzer40239028; 12-30-2017 at 02:06 PM.
Old 01-01-2018, 04:43 PM   #2
Registered: Jul 2005
Posts: 59

Rep: Reputation: 10

You found the solution at :-)



Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Solus: Network Manager worked fine for five or six months and now has stopped working dill0n Linux - Newbie 2 01-29-2017 12:30 AM
[SOLVED] LXC unprivileged container for Slackware guest mralk3 Slackware 64 05-23-2016 10:40 AM
Network help with unprivileged lxc containers on -current Rinndalir Slackware 6 09-10-2015 11:59 AM
LXC unprivileged container - operation no permitted gauthig Linux - Virtualization and Cloud 2 07-15-2014 03:34 PM > Forums > Linux Forums > Linux - Containers

All times are GMT -5. The time now is 02:43 PM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration