Bug 1669728
| Summary: | SELinux is preventing docker-gen from 'connectto' accesses on the unix_stream_socket /run/docker.sock. | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | cje |
| Component: | selinux-policy | Assignee: | Lukas Vrabec <lvrabec> |
| Status: | CLOSED NOTABUG | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 29 | CC: | dwalsh, lvrabec, mgrepl, plautrba, zpytela |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Unspecified | ||
| Whiteboard: | abrt_hash:fdf9aaac7a2882bce79f0e6aa630ec59ea1a8af63e97922064af561a35e4b821;VARIANT_ID=workstation; | ||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2019-01-28 13:28:16 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
cje
2019-01-26 12:54:29 UTC
This is not a bug, you are leaking the docker socket into a container, which allows the container to easily break out. If you are going to do this, you need to disable the SELinux protection on the container. SELinux is doing exactly what it is supposed to do. docker run -ti --security-opt label=disabled ... Hi Dan, Thanks for stepping in and explaining. I've re-read a couple of your blog posts and found some articles on docker.sock security now :-) I might raise an issue at https://github.com/jwilder/nginx-proxy and https://github.com/JrCs/docker-letsencrypt-nginx-proxy-companion if i can reproduce it, but... i've "upgraded" from docker to moby-engine (and picked up container-selinux-2:2.80-1.git1b655d9.fc29 again as part of that) and the problem seems to have disappeared. /run/docker.sock is now system_u:object_r:container_var_run_t:s0 and restorecon doesn't appear to want to change that. Will keep checking. Thanks again! Realize that moby-engine by default is not running containers with --selinux-enabled turned on . So this might be why this is working. thanks again Dan, that explains it. I'm having a little trouble enabling it again but will comment on that in bug 1675125. BTW You should be able to use buildah if you want to build containers inside of a container or podman if you want to execute container commands in a container, without having to leak in the docker socket. |