Bug 1986092 - dockerd daemon is built without seccomp support
Summary: dockerd daemon is built without seccomp support
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: moby-engine
Version: 35
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Olivier Lemasle
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-07-26 16:27 UTC by Daniel Berrangé
Modified: 2021-08-25 19:53 UTC (History)
3 users (show)

Fixed In Version: moby-engine-20.10.8-1.fc35 moby-engine-20.10.8-1.fc36 moby-engine-20.10.8-1.fc34
Clone Of:
Environment:
Last Closed: 2021-08-15 23:25:31 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Daniel Berrangé 2021-07-26 16:27:54 UTC
Description of problem:
Running a container with docker I see no seccomp support present


$ docker run -it registry.fedoraproject.org/fedora:rawhide sh 
sh-5.1# grep Seccomp /proc/$$/status
Seccomp:	0
Seccomp_filters:	0


$ wget https://raw.githubusercontent.com/docker/labs/master/security/seccomp/seccomp-profiles/default.json -O profile.json


$ docker run --security-opt seccomp=~/profile.json  -it registry.fedoraproject.org/fedora:rawhide sh
docker: Error response from daemon: seccomp profiles are not supported on this daemon, you cannot specify a custom seccomp profile.
ERRO[0001] error waiting for container: context canceled 


Version-Release number of selected component (if applicable):
moby-engine-20.10.7-1.fc35.x86_64

How reproducible:
Always

Steps to Reproduce:
1. wget https://raw.githubusercontent.com/docker/labs/master/security/seccomp/seccomp-profiles/default.json -O profile.json
2. docker run --security-opt seccomp=~/profile.json  -it registry.fedoraproject.org/fedora:rawhide sh


Actual results:
docker: Error response from daemon: seccomp profiles are not supported on this daemon, you cannot specify a custom seccomp profile.

Expected results:
Default container env is seccomp profiled, and can run with alternative seccomp profiles.

Additional info:

Comment 1 Daniel Berrangé 2021-07-26 16:43:49 UTC
The specfile contains:

         export BUILDTAGS="seccomp selinux journald"


The actual variable docker wants is  DOCKER_BUILDTAGS.

This appears to be a regression introduced by this change:

commit 37290ccb01de43c6bfecb87e93ccfbb9780fd6ab
Author: Olivier Lemasle <o.lemasle>
Date:   Sun Mar 14 22:26:09 2021 +0100

    Update to latest upstream 20.10.5 - fixes #1903426
    Upstream brings compatibility with cgroups v2 - fixes #1746355
    Remove package moby-engine-vim (dockerfile.vim has been merged in upstream vim)
    Remove firewalld docker zone, since dockerd can now communicate with firewalld - fixes #1852680
    Build dockerd and docker-proxy from unbundled source packages

This diff seems to fix it for me:

@@ -402,7 +402,7 @@ mkdir -p _build
         # export LDFLAGS+=" -X github.com/docker/docker/dockerversion.GitCommit=%{shortcommit_moby}"
         # export LDFLAGS+=" -X github.com/docker/docker/dockerversion.IAmStatic=false"
         # export LDFLAGS+=" -X 'github.com/docker/docker/dockerversion.BuildTime=$(date -u --rfc-3339 ns)'"
-        export BUILDTAGS="seccomp selinux journald"
+        export DOCKER_BUILDTAGS="seccomp selinux journald"
         # %%gobuild -o _build/%%{service_name}d github.com/%%{service_name}/%%{service_name}/cmd/dockerd
         VERSION=%{version} DOCKER_GITCOMMIT=%{shortcommit_moby} bash -x hack/make.sh dynbinary
         mv bundles/dynbinary-daemon/dockerd-%{version} _build/dockerd


I'm a little confused by selinux wasn't also broken by the original change though.

Comment 2 Ben Cotton 2021-08-10 13:14:56 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 35 development cycle.
Changing version to 35.

Comment 3 Fedora Update System 2021-08-15 23:23:43 UTC
FEDORA-2021-f9cb1288d8 has been submitted as an update to Fedora 35. https://bodhi.fedoraproject.org/updates/FEDORA-2021-f9cb1288d8

Comment 4 Fedora Update System 2021-08-15 23:25:31 UTC
FEDORA-2021-f9cb1288d8 has been pushed to the Fedora 35 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 5 Fedora Update System 2021-08-15 23:32:23 UTC
FEDORA-2021-8ad75e0fff has been submitted as an update to Fedora 36. https://bodhi.fedoraproject.org/updates/FEDORA-2021-8ad75e0fff

Comment 6 Fedora Update System 2021-08-15 23:34:32 UTC
FEDORA-2021-8ad75e0fff has been pushed to the Fedora 36 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 7 Fedora Update System 2021-08-16 20:01:20 UTC
FEDORA-2021-1437ef97e1 has been submitted as an update to Fedora 34. https://bodhi.fedoraproject.org/updates/FEDORA-2021-1437ef97e1

Comment 8 Fedora Update System 2021-08-17 01:09:46 UTC
FEDORA-2021-1437ef97e1 has been pushed to the Fedora 34 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2021-1437ef97e1`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2021-1437ef97e1

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 9 Fedora Update System 2021-08-25 19:53:53 UTC
FEDORA-2021-1437ef97e1 has been pushed to the Fedora 34 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.