You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description
After running the most recent Centos7 update, starting a container fails with
"standard_init_linux.go:178: exec user process caused "permission denied".
Seems to be realted to #24612 which is closed.
Description
After running the most recent Centos7 update, starting a container fails with
"standard_init_linux.go:178: exec user process caused "permission denied".
The reason seems to be:
ls -Z /usr/bin/docker*
-rwxr-xr-x. root root system_u:object_r:docker_exec_t:s0 /usr/bin/docker
-rwxr-xr-x. root root unconfined_u:object_r:bin_t:s0 /usr/bin/docker-compose
-rwxr-xr-x. root root system_u:object_r:bin_t:s0 /usr/bin/docker-containerd
-rwxr-xr-x. root root system_u:object_r:bin_t:s0 /usr/bin/docker-containerd-ctr
-rwxr-xr-x. root root system_u:object_r:bin_t:s0 /usr/bin/docker-containerd-shim
-rwxr-xr-x. root root system_u:object_r:bin_t:s0 /usr/bin/dockerd
-rwxr-xr-x. root root system_u:object_r:bin_t:s0 /usr/bin/docker-proxy
-rwxr-xr-x. root root system_u:object_r:bin_t:s0 /usr/bin/docker-runc
Workaround:
chcon -t docker_exec_t /usr/bin/docker*
Steps to reproduce the issue:
(except the system update which would be some work to reproduce)
Describe the results you received:
container did not start. /var/log/audit/audit.log contains:
type=SYSCALL msg=audit(1484225519.082:1472): arch=c000003e syscall=59 success=no exit=-13 a0=c8200efe20 a1=c8200efe30 a2=c8200956d0 a3=0 items=0 ppid=16257 pid=16272 auid=4294967295 uid=8002 gid=8002 euid=8002 suid=8002 fsuid=8002 egid=8002 sgid=8002 fsgid=8002 tty=pts1 ses=4294967295 comm="exe" exe="/usr/bin/docker-runc" subj=system_u:system_r:unconfined_service_t:s0 key=(null)
Describe the results you expected:
container would start.
Additional information you deem important (e.g. issue happens only occasionally):
Output of
docker version
:Output of
docker info
:Additional environment details (AWS, VirtualBox, physical, etc.):
KVM
The text was updated successfully, but these errors were encountered: