Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: Running a container with docker I see no seccomp support present $ docker run -it registry.fedoraproject.org/fedora:rawhide sh sh-5.1# grep Seccomp /proc/$$/status Seccomp: 0 Seccomp_filters: 0 $ wget https://raw.githubusercontent.com/docker/labs/master/security/seccomp/seccomp-profiles/default.json -O profile.json $ docker run --security-opt seccomp=~/profile.json -it registry.fedoraproject.org/fedora:rawhide sh docker: Error response from daemon: seccomp profiles are not supported on this daemon, you cannot specify a custom seccomp profile. ERRO[0001] error waiting for container: context canceled Version-Release number of selected component (if applicable): moby-engine-20.10.7-1.fc35.x86_64 How reproducible: Always Steps to Reproduce: 1. wget https://raw.githubusercontent.com/docker/labs/master/security/seccomp/seccomp-profiles/default.json -O profile.json 2. docker run --security-opt seccomp=~/profile.json -it registry.fedoraproject.org/fedora:rawhide sh Actual results: docker: Error response from daemon: seccomp profiles are not supported on this daemon, you cannot specify a custom seccomp profile. Expected results: Default container env is seccomp profiled, and can run with alternative seccomp profiles. Additional info:
The specfile contains: export BUILDTAGS="seccomp selinux journald" The actual variable docker wants is DOCKER_BUILDTAGS. This appears to be a regression introduced by this change: commit 37290ccb01de43c6bfecb87e93ccfbb9780fd6ab Author: Olivier Lemasle <o.lemasle> Date: Sun Mar 14 22:26:09 2021 +0100 Update to latest upstream 20.10.5 - fixes #1903426 Upstream brings compatibility with cgroups v2 - fixes #1746355 Remove package moby-engine-vim (dockerfile.vim has been merged in upstream vim) Remove firewalld docker zone, since dockerd can now communicate with firewalld - fixes #1852680 Build dockerd and docker-proxy from unbundled source packages This diff seems to fix it for me: @@ -402,7 +402,7 @@ mkdir -p _build # export LDFLAGS+=" -X github.com/docker/docker/dockerversion.GitCommit=%{shortcommit_moby}" # export LDFLAGS+=" -X github.com/docker/docker/dockerversion.IAmStatic=false" # export LDFLAGS+=" -X 'github.com/docker/docker/dockerversion.BuildTime=$(date -u --rfc-3339 ns)'" - export BUILDTAGS="seccomp selinux journald" + export DOCKER_BUILDTAGS="seccomp selinux journald" # %%gobuild -o _build/%%{service_name}d github.com/%%{service_name}/%%{service_name}/cmd/dockerd VERSION=%{version} DOCKER_GITCOMMIT=%{shortcommit_moby} bash -x hack/make.sh dynbinary mv bundles/dynbinary-daemon/dockerd-%{version} _build/dockerd I'm a little confused by selinux wasn't also broken by the original change though.
This bug appears to have been reported against 'rawhide' during the Fedora 35 development cycle. Changing version to 35.
FEDORA-2021-f9cb1288d8 has been submitted as an update to Fedora 35. https://bodhi.fedoraproject.org/updates/FEDORA-2021-f9cb1288d8
FEDORA-2021-f9cb1288d8 has been pushed to the Fedora 35 stable repository. If problem still persists, please make note of it in this bug report.
FEDORA-2021-8ad75e0fff has been submitted as an update to Fedora 36. https://bodhi.fedoraproject.org/updates/FEDORA-2021-8ad75e0fff
FEDORA-2021-8ad75e0fff has been pushed to the Fedora 36 stable repository. If problem still persists, please make note of it in this bug report.
FEDORA-2021-1437ef97e1 has been submitted as an update to Fedora 34. https://bodhi.fedoraproject.org/updates/FEDORA-2021-1437ef97e1
FEDORA-2021-1437ef97e1 has been pushed to the Fedora 34 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2021-1437ef97e1` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2021-1437ef97e1 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2021-1437ef97e1 has been pushed to the Fedora 34 stable repository. If problem still persists, please make note of it in this bug report.