Bug 1297929
Summary: | Enable Docker SELinux enforcing mode with Overlayfs | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 7 | Reporter: | Subhendu Ghosh <sghosh> |
Component: | kernel | Assignee: | Miklos Szeredi <mszeredi> |
kernel sub component: | File Systems - Other | QA Contact: | Murphy Zhou <xzhou> |
Status: | CLOSED ERRATA | Docs Contact: | Marek Suchánek <msuchane> |
Severity: | medium | ||
Priority: | high | CC: | bbreard, brubisch, coughlan, cye, dornelas, dwalsh, eguan, erich, esandeen, ghelleks, jeder, lfriedma, lmiksik, mifiedle, mmalik, mmcgrath, mnavrati, mszeredi, owalsh, swhiteho, vgoyal |
Version: | 7.3 | ||
Target Milestone: | beta | ||
Target Release: | --- | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | aos-scalability-34 | ||
Fixed In Version: | kernel-3.10.0-517.el7 | Doc Type: | Release Note |
Doc Text: |
SELinux security labels are now supported on the OverlayFS file system
With this update, the OverlayFS file system now supports SELinux security labels. When using Docker containers with the OverlayFS storage driver, you no longer have to configure Docker to disable SELinux support for the containers.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2017-08-01 20:05:02 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1178944 | ||
Bug Blocks: | 1154205, 1203710, 1295567, 1295577, 1298243, 1313485, 1385242, 1411772 |
Description
Subhendu Ghosh
2016-01-12 19:24:07 UTC
I know we have customers looking to use overlayfs and having to disable SELinux makes for a bad security story for us. *** Bug 1178944 has been marked as a duplicate of this bug. *** This won't make it to 7.3 as patches are not ready yet. However things are progressing nicely and the feature should be ready for upstream kernel 4.8 or 4.9. Patch(es) committed on kernel repository and an interim kernel build is undergoing testing Patch(es) available on kernel-3.10.0-517.el7 Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2017:1842 Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2017:1842 |