Bug 1259342 - docker: Fail to start if selinux is enabled and overlayfs is being used as graph driver
docker: Fail to start if selinux is enabled and overlayfs is being used as gr...
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: docker (Show other bugs)
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: Sally
: Extras
Depends On:
Blocks: 1295567
  Show dependency treegraph
Reported: 2015-09-02 08:23 EDT by Vivek Goyal
Modified: 2016-04-01 10:25 EDT (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2016-03-31 19:22:29 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Vivek Goyal 2015-09-02 08:23:10 EDT
Description of problem:

Currently overlayfs does not work with selinux. By default selinux is enabled and if user chooses to use overlay as graph driver, there will be issues.

Modify docker so that it detects this situation during start and fails with appropriate error message.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:

Actual results:

Expected results:

Additional info:
Comment 2 Daniel Walsh 2015-09-02 11:16:46 EDT
Sally we already do this for BTRFS, you should just search the code and make the same change.
Comment 3 Sally 2015-09-02 15:56:08 EDT
submitted https://github.com/docker/docker/pull/16025
Comment 4 Vivek Goyal 2015-09-03 09:18:25 EDT
sally, has it been merged into docker we ship in rhel? MODIFIED flag means that patch has been committed in the source tree of redhat rpm.
Comment 5 Vivek Goyal 2015-09-03 09:19:06 EDT
Or rather, an rpm build has been done and rpm is available for testing. Then we will call it MODIFIED.
Comment 6 Sally 2015-09-03 09:32:16 EDT
Sorry for the confusion!  Dan also pointed out my misuse of 'MODIFIED'..
Now I know :)
Comment 7 Sally 2015-09-03 16:35:12 EDT
https://github.com/docker/docker/pull/16025 merged
Comment 8 Daniel Walsh 2015-09-28 14:41:47 EDT
Fixed in docker-1.9
Comment 10 Luwen Su 2016-02-03 03:49:29 EST
In docker-1.9.1-15.el7.x86_64

# docker daemon --storage-driver=overlay
INFO[0000] Firewalld running: false                     
INFO[0000] Default bridge (docker0) is assigned with an IP address Daemon option --bip can be used to set a preferred IP address 

# docker daemon --selinux-enabled --storage-driver=overlay
FATA[0000] Error starting daemon: SELinux is not supported with the overlay graph driver
Comment 12 errata-xmlrpc 2016-03-31 19:22:29 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.