This repository has been archived by the owner on Oct 10, 2020. It is now read-only.
syscontainers: correctly setup the rootfs SELinux label #1185
Closed
giuseppe
wants to merge
1
commit into
projectatomic:master
from
giuseppe:syscontainers-create-root-correct-label
Closed
syscontainers: correctly setup the rootfs SELinux label #1185
giuseppe
wants to merge
1
commit into
projectatomic:master
from
giuseppe:syscontainers-create-root-correct-label
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
this is an urgent fix for running Open Shift with system containers, we should get it in a release |
giuseppe
force-pushed
the
syscontainers-create-root-correct-label
branch
from
February 13, 2018 12:49
e6273d9
to
5559fa5
Compare
LGTM |
Commit message looks slightly truncated...forgot to change "this"? Otherwise looks sane to me. |
The files inside the container are labelled by Skopeo when the image is pulled to the OSTree storage. Instead the root directory is created by atomic and by default it gets the label "unconfined_u:object_r:container_share_t:s0". Make sure we label the rootfs with the same label of '/'. We have changed the way files are labelled by Skopeo but we forgot to change the label for the rootfs created by atomic. This patch ensures the SELinux label for the rootfs is set. Closes: https://bugzilla.redhat.com/show_bug.cgi?id=1544175 Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
giuseppe
force-pushed
the
syscontainers-create-root-correct-label
branch
from
February 14, 2018 13:29
5559fa5
to
4ea5d5a
Compare
Thanks for the review, I've might have pressed C-k by mistake while editing the commit message. Fixed now. |
The failure is the common flake in |
ashcrow
approved these changes
Feb 14, 2018
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
can someone r+ it? :-) |
rh-atomic-bot
pushed a commit
that referenced
this pull request
Feb 14, 2018
The files inside the container are labelled by Skopeo when the image is pulled to the OSTree storage. Instead the root directory is created by atomic and by default it gets the label "unconfined_u:object_r:container_share_t:s0". Make sure we label the rootfs with the same label of '/'. We have changed the way files are labelled by Skopeo but we forgot to change the label for the rootfs created by atomic. This patch ensures the SELinux label for the rootfs is set. Closes: https://bugzilla.redhat.com/show_bug.cgi?id=1544175 Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com> Closes: #1185 Approved by: cgwalters
💔 Test failed - status-papr |
bot, retry |
@rh-atomic-bot retry |
☀️ Test successful - status-papr |
can we get a new build? This change is critical to run Open Shift as a system container |
eyusupov
pushed a commit
to eyusupov/atomic
that referenced
this pull request
Mar 10, 2018
The files inside the container are labelled by Skopeo when the image is pulled to the OSTree storage. Instead the root directory is created by atomic and by default it gets the label "unconfined_u:object_r:container_share_t:s0". Make sure we label the rootfs with the same label of '/'. We have changed the way files are labelled by Skopeo but we forgot to change the label for the rootfs created by atomic. This patch ensures the SELinux label for the rootfs is set. Closes: https://bugzilla.redhat.com/show_bug.cgi?id=1544175 Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com> Closes: projectatomic#1185 Approved by: cgwalters
miabbott
added a commit
to miabbott/atomic-host-tests
that referenced
this pull request
Mar 12, 2018
Two major changes here: 1) Pin the system containers to a previous version that was working 2) Make sure that 'atomic 1.22' is installed on the host The new requirement on 'atomic 1.22' is to resolve the following issue with SELinux labeling - projectatomic/atomic#1185 This is only a temporary change; once the latest versions of the system containers are known to be working, we can revert a lot of this.
mike-nguyen
pushed a commit
to projectatomic/atomic-host-tests
that referenced
this pull request
Mar 13, 2018
Two major changes here: 1) Pin the system containers to a previous version that was working 2) Make sure that 'atomic 1.22' is installed on the host The new requirement on 'atomic 1.22' is to resolve the following issue with SELinux labeling - projectatomic/atomic#1185 This is only a temporary change; once the latest versions of the system containers are known to be working, we can revert a lot of this.
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The files inside the container are labelled by Skopeo when the image is
pulled to the OSTree storage.
Instead the root directory is created by atomic and by default it gets
the label "unconfined_u:object_r:container_share_t:s0".
Make sure we label it with the same label of '/'.
We have changed the way files are labelled by Skopeo but we forgot to change
Closes: https://bugzilla.redhat.com/show_bug.cgi?id=1544175
Signed-off-by: Giuseppe Scrivano gscrivan@redhat.com