Community Packages

Please read this before reporting a bug:

Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.

REPEAT: Do NOT report bugs for outdated packages!

FS#71397 - [containers-common] seccomp filter OCI permission denied

Attached to Project: Community Packages
Opened by Darrell (denns) - Tuesday, 29 June 2021, 16:38 GMT
Last edited by Morten Linderud (Foxboron) - Friday, 09 July 2021, 12:52 GMT
Task Type Bug Report
Category Packages
Status Closed
Assigned To David Runge (dvzrv)
Morten Linderud (Foxboron)
Architecture All
Severity Medium
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No


containers-common-0.40.1-1 breaks runc. Container's can't be started.

> pacman -Q containers-common podman runc
containers-common 0.40.1-1
podman 3.2.2-1
runc 1.0.0-1
> podman run -it --rm ubuntu:20.04
Error: container_linux.go:380: starting container process caused: error adding seccomp filter rule for syscall bdflush: permission denied: OCI permission denied

See also:

A workaround is to install crun, which containers-common will prefer by default if installed.
This task depends upon

Closed by  Morten Linderud (Foxboron)
Friday, 09 July 2021, 12:52 GMT
Reason for closing:  Fixed
Additional comments about closing:  Switched podman to crun