diff --git a/userns/userns_linux.go b/userns/userns_linux.go index 87c1c38e..8acf1195 100644 --- a/userns/userns_linux.go +++ b/userns/userns_linux.go @@ -5,8 +5,12 @@ import ( "fmt" "os" "sync" + "syscall" ) +// See PROC_USER_INIT_INO in https://github.com/torvalds/linux/blob/v7.1/include/uapi/linux/nsfs.h#L50. +const procUserInitIno = 0xEFFFFFFD + var inUserNS = sync.OnceValue(runningInUserNS) // runningInUserNS detects whether we are currently running in a user namespace. @@ -17,6 +21,15 @@ var inUserNS = sync.OnceValue(runningInUserNS) // [libcontainer/runc]: https://github.com/opencontainers/runc/blob/3778ae603c706494fd1e2c2faf83b406e38d687d/libcontainer/userns/userns_linux.go#L12-L49 // [lcx/incus]: https://github.com/lxc/incus/blob/e45085dd42f826b3c8c3228e9733c0b6f998eafe/shared/util.go#L678-L700 func runningInUserNS() bool { + var st syscall.Stat_t + if err := syscall.Stat("/proc/self/ns/user", &st); err == nil { + return st.Ino != procUserInitIno + } else if !os.IsNotExist(err) { + return false + } + + // TODO: Remove this fallback once Linux kernels older than 3.8 are no + // longer supported. file, err := os.Open("/proc/self/uid_map") if err != nil { // This kernel-provided file only exists if user namespaces are supported.