Skip to content

Fix runtime iptables selection for non-root Docker-in-Docker entrypoints - #1747

Open
Kaniska (v-Kaniska244) wants to merge 2 commits into
devcontainers:mainfrom
v-Kaniska244:d-in-d-investigate
Open

Kaniska (v-Kaniska244) wants to merge 2 commits into
devcontainers:mainfrom
v-Kaniska244:d-in-d-investigate

Conversation

@v-Kaniska244

@v-Kaniska244 Kaniska (v-Kaniska244) commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

What does this PR do?

Fixes Docker-in-Docker runtime iptables selection when the feature entrypoint runs as a non-root user reported in an issue devcontainers/images#2033 in images repository for universal image.

Observed the below failures in the Codespaces creation log with universal image:

Container started
update-alternatives: using /usr/sbin/iptables-legacy to provide /usr/sbin/iptables (iptables) in manual mode
update-alternatives: error: error creating symbolic link '/etc/alternatives/iptables.dpkg-tmp': Permission denied
update-alternatives: using /usr/sbin/ip6tables-legacy to provide /usr/sbin/ip6tables (ip6tables) in manual mode
update-alternatives: error: error creating symbolic link '/etc/alternatives/ip6tables.dpkg-tmp': Permission denied
Outcome: success User: codespace WorkspaceFolder: /workspaces/docker-api-solved
devcontainer process exited with exit code 0

Docker-in-Docker v4 selects the iptables backend at container startup. Images such as Universal configure codespace as the containerUser, causing update-alternatives to fail with permission errors under alternatives.

This change:

  • Defines sudo_if before runtime iptables selection.
  • Runs the iptables and ip6tables update-alternatives mutations through sudo_if.
  • Preserves root and non-root entrypoint behavior.
  • Bumps the feature version from 4.1.2 to 4.1.3.

Testing

Added an isolated Ubuntu Noble test that:

  • Removes the built-in ubuntu user.
  • Creates a non-root codespace user through common-utils.
  • Configures both containerUser and remoteUser as codespace.
  • Installs Docker-in-Docker after common-utils.
  • Confirms the entrypoint runs as codespace.
  • Confirms the runtime-selected iptables backend is legacy.

The scenario is excluded from shared test jobs and runs through the dedicated iptables-isolation workflow matrix, consistent with the existing Ubuntu iptables tests.

Validated with:

devcontainer features test . \
  -f docker-in-docker \
  --filter "docker_iptables_switch_at_runtime_non_root" \
  --skip-autogenerated

The test passes without update-alternatives permission errors.

@v-Kaniska244 Kaniska (v-Kaniska244) changed the title Add test for iptables switching at runtime for non root user Fix runtime iptables selection for non-root Docker-in-Docker entrypoints Oct 6, 2026
@v-Kaniska244
Kaniska (v-Kaniska244) marked this pull request as ready for review October 6, 2026 06:33
@v-Kaniska244
Kaniska (v-Kaniska244) requested a review from a team as a code owner October 6, 2026 06:33

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant