| Summary: |
docker run fails on rawhide with setenforce 1 |
| Product: |
[Fedora] Fedora
|
Reporter: |
Lokesh Mandvekar <lsm5> |
| Component: |
selinux-policy | Assignee: |
Lukas Vrabec <lvrabec> |
| Status: |
CLOSED
RAWHIDE
|
QA Contact: |
Fedora Extras Quality Assurance <extras-qa> |
| Severity: |
unspecified
|
Docs Contact: |
|
| Priority: |
unspecified
|
|
|
| Version: |
rawhide | CC: |
adimania, admiller, dominick.grift, dwalsh, golang-updates, hushan.jia, jchaloup, jperrin, lsm5, lvrabec, mattdm, me, mgoldman, mgrepl, miminar, plautrba, s, thrcka, vbatts
|
| Target Milestone: |
--- | |
|
| Target Release: |
--- | |
|
| Hardware: |
Unspecified | |
|
| OS: |
Unspecified | |
|
| Whiteboard: |
|
|
Fixed In Version:
|
|
Doc Type:
|
Bug Fix
|
|
Doc Text:
|
|
Story Points:
|
---
|
|
Clone Of:
|
|
Environment:
|
|
|
Last Closed:
|
2015-04-09 12:48:37 UTC
|
Type:
|
Bug
|
|
Regression:
|
---
|
Mount Type:
|
---
|
|
Documentation:
|
---
|
CRM:
|
|
|
Verified Versions:
|
|
Category:
|
---
|
|
oVirt Team:
|
---
|
RHEL 7.3 requirements from Atomic Host:
|
|
|
Cloudforms Team:
|
---
|
Target Upstream Version:
|
|
|
Embargoed:
|
|
| |
| Bug Depends On: |
|
|
|
| Bug Blocks: |
1194589
|
|
|
Description of problem: On rawhide, docker run commands fail with selinux enforcing. Feb 24 09:34:01 naruto kernel: [605832.428983] audit: type=1400 audit(1424792041.549:3572): avc: denied { entrypoint } for pid=19015 comm="docker" path="/var/lib/docker/init/dockerinit-1.5.0-dev" dev="sda2" ino=134594 scontext=system_u:system_r:spc_t:s0 tcontext=system_u:object_r:docker_var_lib_t:s0 tclass=file permissive=0 Feb 24 09:34:01 naruto kernel: [605832.429083] audit: type=1300 audit(1424792041.549:3572): arch=c000003e syscall=59 success=no exit=-13 a0=c208b05290 a1=c208602500 a2=c2085ceb20 a3=0 items=0 ppid=7465 pid=19015 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="docker" exe="/usr/bin/docker" subj=system_u:system_r:docker_t:s0 key=(null) Feb 24 09:34:01 naruto kernel: [605832.429110] audit: type=1327 audit(1424792041.549:3572): proctitle=2F7573722F62696E2F646F636B6572002D64002D2D73656C696E75782D656E61626C6564