Bug 1473785 - /var/lib/docker folder permissions change on startup, causing OpenSCAP warning
/var/lib/docker folder permissions change on startup, causing OpenSCAP warning
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: docker (Show other bugs)
Unspecified Unspecified
medium Severity high
: rc
: 7.4
Assigned To: Lokesh Mandvekar
: Extras
Depends On:
Blocks: 1186913
  Show dependency treegraph
Reported: 2017-07-21 12:13 EDT by Ryan Howe
Modified: 2017-11-27 17:16 EST (History)
14 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2017-11-27 17:16:04 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Ryan Howe 2017-07-21 12:13:43 EDT
Description of problem:
When starting docker permissions change on /var/lib/docker and /etc/sysconfig/docker-storage, in turn causing OpenSCAP to warn about the permission change. 

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. Install docker
2. Start docker

Actual results:

(HIGH) Verify and Correct File Permissions with R= PM (xccdf_org.ssgproject.conte= nt_rule_rpm_verify_permissions)

Items found violating = mode of all files matches local rpm database: 

Expected results:
No findings, rpm to ship with right permissions or permissions remain unchanged. 

Additional info:

Verify and Correct File Permissions with RPM
   # rpm -V docker 
   I would expect the results to look similar to this: 

S.5....T.  c /etc/sysconfig/docker-storage
S.5....T.  c /etc/sysconfig/docker-storage-setup

  - Here Size,digest,and mtime differ which is to be expected. 

.M.......    /var/lib/docker

  - Here the mode differs, this happens when you start docker for the first time docker changing the permissions on /var/lib/docker 

Fresh Install:
drwx------. 2 root root 6 May 17 01:17 /var/lib/docker/
-rw-------. 1 root root 218 Jul 21 11:55 /etc/sysconfig/docker-storage

After starting docker service: 
drwx--x--x. 10 root root 124 Jun 20 14:15 /var/lib/docker/
-rw-r--r--. 1 root root 218 Jul 21 11:55 /etc/sysconfig/docker-storage
Comment 2 Daniel Walsh 2017-07-22 05:42:46 EDT
Lokesh can you just change the rpm permissions to match the final.
Comment 4 Daniel Walsh 2017-08-25 07:16:29 EDT
Franticek lets get this done.

Note You need to log in before you can comment on or make changes to this bug.