The propagation was previously set to rprivate and didn't propagate
mounts from the host mount namespace into the daemon's mount namespace.
Further information about --propagation: https://github.com/rootless-containers/rootlesskit/tree/v0.9.1#mount-propagation
RootlessKit changes: https://github.com/rootless-containers/rootlesskit/compare/v0.8.0...v0.9.1
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
| ... | ... |
@@ -82,6 +82,7 @@ if [ -z $_DOCKERD_ROOTLESS_CHILD ]; then |
| 82 | 82 |
--slirp4netns-seccomp=$DOCKERD_ROOTLESS_ROOTLESSKIT_SLIRP4NETNS_SECCOMP \ |
| 83 | 83 |
--disable-host-loopback --port-driver=builtin \ |
| 84 | 84 |
--copy-up=/etc --copy-up=/run \ |
| 85 |
+ --propagation=rslave \ |
|
| 85 | 86 |
$DOCKERD_ROOTLESS_ROOTLESSKIT_FLAGS \ |
| 86 | 87 |
$0 $@ |
| 87 | 88 |
else |