diff --git a/Dockerfile b/Dockerfile index 6a61659..d0b2583 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,8 +1,8 @@ -FROM registry.fedoraproject.org/fedora:rawhide +FROM registry.fedoraproject.org/fedora:26 -ENV VERSION=0 RELEASE=1 ARCH=x86_64 +ENV VERSION=0 RELEASE=9 ARCH=x86_64 LABEL com.redhat.component="docker" \ - name="docker" \ + name="$FGC/docker" \ version="$VERSION" \ release="$RELEASE.$DISTTAG" \ architecture="$ARCH" \ @@ -13,7 +13,8 @@ LABEL com.redhat.component="docker" \ RUN dnf install --setopt=tsflags=nodocs -y docker container-storage-setup container-selinux cloud-utils-growpart python-docker-py docker-novolume-plugin lvm2 iptables procps-ng xz oci-register-machine \ && rpm -V docker container-storage-setup container-selinux cloud-utils-growpart python-docker-py docker-novolume-plugin lvm2 iptables procps-ng xz oci-register-machine \ - && mkdir -p /usr/lib/modules && dnf clean all + && mkdir -p /usr/lib/modules /exports/hostfs/etc/docker \ + && dnf clean all RUN ln -s /usr/libexec/docker/docker-runc-current /usr/bin/docker-runc @@ -25,6 +26,8 @@ COPY set_mounts.sh / COPY config.json.template service.template tmpfiles.template /exports/ COPY daemon.json /exports/hostfs/etc/docker/container-daemon.json # https://github.com/rhatdan/oci-umount/issues/2 -RUN cp /etc/oci-umount.conf /exports/hostfs/etc +# Copy config if available +RUN (test -e /etc/oci-umount.conf && cp /etc/oci-umount.conf /exports/hostfs/etc) || true + CMD ["/usr/bin/init.sh"] diff --git a/config.json.template b/config.json.template index 3ce615c..df3e4e5 100644 --- a/config.json.template +++ b/config.json.template @@ -5,6 +5,7 @@ "arch": "amd64" }, "process": { + "selinuxLabel": "system_u:system_r:container_runtime_t:s0", "terminal": false, "user": { "uid": 0, @@ -294,17 +295,6 @@ "mode=755" ] }, - { - "type": "bind", - "source": "/usr/share/rhel", - "destination": "/usr/share/rhel", - "options": [ - "rprivate", - "rbind", - "ro", - "mode=755" - ] - }, { "type": "bind", "source": "${RUN_DIRECTORY}", @@ -380,7 +370,7 @@ ], "hooks": {}, "linux": { - "rootfsPropagation": "private", + "rootfsPropagation": "rslave", "resources": { "devices": [ { @@ -393,7 +383,6 @@ { "type": "mount" } - ], - "selinuxProcessLabel": "system_u:system_r:container_runtime_t:s0" + ] } } diff --git a/daemon.json b/daemon.json index ea5e789..445fe8a 100644 --- a/daemon.json +++ b/daemon.json @@ -1,6 +1,4 @@ - { - "authorization-plugins": ["rhel-push-plugin"], "default-runtime": "oci", "containerd": "/run/containerd.sock", "userland-proxy-path": "/usr/libexec/docker/docker-proxy-current", diff --git a/init.sh b/init.sh index ac03b38..4347c47 100755 --- a/init.sh +++ b/init.sh @@ -1,5 +1,10 @@ #!/bin/bash +# Ensure that new process maintain this SELinux label +PID=$$ +LABEL=`tr -d '\000' < /proc/$PID/attr/current` +printf %s $LABEL > /proc/self/attr/exec + source /run/docker-bash-env # set storage first @@ -22,7 +27,7 @@ do sleep 0.1 done -# Run all the installed containers +# Run all the installed plugins mkdir -p /run/docker/plugins/ ls -1 /usr/libexec/docker/*plugin | \ while read i; diff --git a/service.template b/service.template index f7784d4..79835de 100644 --- a/service.template +++ b/service.template @@ -6,6 +6,7 @@ After=network.target EnvironmentFile=-/etc/sysconfig/docker-storage EnvironmentFile=-/etc/sysconfig/docker-network Environment=GOTRACEBACK=crash +SELinuxContext=system_u:system_r:container_runtime_t:s0 ExecStartPre=/bin/sh $DESTDIR/rootfs/set_mounts.sh ExecStartPre=/bin/bash -c 'export -p > /run/docker-bash-env' ExecStart=$EXEC_START