Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save christian-korneck/e97c454020091df300617ce0803f7e12 to your computer and use it in GitHub Desktop.
Save christian-korneck/e97c454020091df300617ce0803f7e12 to your computer and use it in GitHub Desktop.
fix podman error `setting value of extended attribute "security.ima" on "/catatonit": operation not permitted`

Podman error setting value of extended attribute "security.ima" on "/catatonit": operation not permitted:

example error message (when trying to run a k8s yaml as unpriv'ed user)

[user@host]$ podman kube play boom.yml
Error: building local pause image: building at STEP "COPY /usr/libexec/podman/catatonit /catatonit": storing "/usr/libexec/podman/catatonit": error during bulk transfer for copier.request{Request:"PUT", Root:"/", preservedRoot:"/home/opc/.local/share/containers/storage/overlay/ba320139a68ad5418cef299dd724dc9fc53737c8a3cba1ad9d30c3a25dfcca45/merged", rootPrefix:"/home/opc/.local/share/containers/storage/overlay/ba320139a68ad5418cef299dd724dc9fc53737c8a3cba1ad9d30c3a25dfcca45/merged", Directory:"/", preservedDirectory:"/home/opc/.local/share/containers/storage/overlay/ba320139a68ad5418cef299dd724dc9fc53737c8a3cba1ad9d30c3a25dfcca45/merged", Globs:[]string{}, preservedGlobs:[]string{}, StatOptions:copier.StatOptions{CheckForArchives:false, Excludes:[]string(nil)}, GetOptions:copier.GetOptions{UIDMap:[]idtools.IDMap(nil), GIDMap:[]idtools.IDMap(nil), Excludes:[]string(nil), ExpandArchives:false, ChownDirs:(*idtools.IDPair)(nil), ChmodDirs:(*fs.FileMode)(nil), ChownFiles:(*idtools.IDPair)(nil), ChmodFiles:(*fs.FileMode)(nil), StripSetuidBit:false, StripSetgidBit:false, StripStickyBit:false, StripXattrs:false, KeepDirectoryNames:false, Rename:map[string]string(nil), NoDerefSymlinks:false, IgnoreUnreadable:false, NoCrossDevice:false}, PutOptions:copier.PutOptions{UIDMap:[]idtools.IDMap{}, GIDMap:[]idtools.IDMap{}, DefaultDirOwner:(*idtools.IDPair)(0x40001a2ef0), DefaultDirMode:(*fs.FileMode)(nil), ChownDirs:(*idtools.IDPair)(nil), ChmodDirs:(*fs.FileMode)(nil), ChownFiles:(*idtools.IDPair)(nil), ChmodFiles:(*fs.FileMode)(nil), StripSetuidBit:false, StripSetgidBit:false, StripStickyBit:false, StripXattrs:false, IgnoreXattrErrors:false, IgnoreDevices:true, NoOverwriteDirNonDir:false, NoOverwriteNonDirDir:false, Rename:map[string]string(nil)}, MkdirOptions:copier.MkdirOptions{UIDMap:[]idtools.IDMap(nil), GIDMap:[]idtools.IDMap(nil), ChownNew:(*idtools.IDPair)(nil), ChmodNew:(*fs.FileMode)(nil)}, RemoveOptions:copier.RemoveOptions{All:false}}: copier: put: error setting extended attributes on "/catatonit": setting value of extended attribute "security.ima" on "/catatonit": operation not permitted

Fix with:

dnf remove rpm-plugin-ima
dnf install --reinstall podman
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment