runc 容器运行时 1.2.5 在 RHOCP 4 中导致容器创建失败
Issue
-
在升级 Rook-Ceph (ODF)、GPU 和 MetalLB FRR pod 后,设置了
shareProcessNamespace: true的 pod 会一直处于Init状态。 -
从 4.19.17 升级到 4.19.19 后,
frr-k8spod 卡在 Init 状态,并带有类似的错误:Failed to create pod sandbox: rpc error: code = Unknown desc = container create failed: time="2025-11-21T09:35:58Z" level=error msg="runc create failed: unable to start container process: error during container init: error closing exec fds: get handle to /proc/thread-self/fd: unsafe procfs detected: openat2 fsmount:fscontext:proc/thread-self/fd/: operation not permitted"
Environment
- Red Hat OpenShift Container Platform (RHOCP)
- 4.20.4+
- 4.19.19
- 4.19.20
- 4.18.29
- 4.17.44
- 4.16.53
- 4.14.59
- 4.12.83+
- runc 作为容器运行时
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.