You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
pmssUserTransferBuildRsyncCommand() (scripts/lib/userTransfer/remoteScripts.php) pulls as <remoteUser>, so the sending rsync on the source runs as the user. Rootless Docker keeps container-owned files under the user's sub-UIDs. Any image layer, volume or bind-mount file with an owner-only mode (0600/0700) owned by a non-root container UID is unreadable to the user. rsync logs send_files failed to open / opendir ... failed: Permission denied (13) on every pass, skips it (a directory takes its whole subtree along), and the target silently lacks it. Seen in production with containerd image-layer snapshots (Docker 29 containerd store) and with volume data. Users whose images carry no such files transfer cleanly.
Reproduce: rootless docker run -d -e POSTGRES_PASSWORD=x postgres (data dir 0700, container uid 999), transfer the user, then grep the log for Permission denied (13) and compare file counts as root.
Problem
pmssUserTransferBuildRsyncCommand()(scripts/lib/userTransfer/remoteScripts.php) pulls as<remoteUser>, so the sending rsync on the source runs as the user. Rootless Docker keeps container-owned files under the user's sub-UIDs. Any image layer, volume or bind-mount file with an owner-only mode (0600/0700) owned by a non-root container UID is unreadable to the user. rsync logssend_files failed to open/opendir ... failed: Permission denied (13)on every pass, skips it (a directory takes its whole subtree along), and the target silently lacks it. Seen in production with containerd image-layer snapshots (Docker 29 containerd store) and with volume data. Users whose images carry no such files transfer cleanly.Reproduce: rootless
docker run -d -e POSTGRES_PASSWORD=x postgres(data dir 0700, container uid 999), transfer the user, then grep the log forPermission denied (13)and compare file counts as root.Suggested fix (for review)
--rsync-path='unshare --map-auto --map-root-user rsync'(util-linux ≥ 2.38) or an equivalentnewuidmapwrapper. This needs no new privilege; the IDs come out namespace-relative, which fits the offset remap of userTransfer: rootless Docker ownership breaks when source/target subuid ranges differ (data-root keeps foreign sub-IDs, bind mounts get flattened) #961.Once the companion
.resourceDataexclude fix lands, a remaining rc=23 is a genuine "something was not copied" signal. Related: #961, #962.(Unreadable by design, uncopied by accident.)
Tier-3 declared at filing:
--why multiple-fix-paths— GH#631 tier gate. Declared fix size:20lines vs 14-line body — size gate (operator directive 2026-07-29). Owner:scripts/lib/userTransfer/remoteScripts.phpin MagnaCapax/PMSS — owner gate.