diff --git a/Dockerfile b/Dockerfile index 6a61659..377bf7c 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,8 +1,8 @@ -FROM registry.fedoraproject.org/fedora:rawhide +FROM registry.fedoraproject.org/fedora:25 -ENV VERSION=0 RELEASE=1 ARCH=x86_64 +ENV VERSION=0 RELEASE=8 ARCH=x86_64 LABEL com.redhat.component="docker" \ - name="docker" \ + name="$FGC/docker" \ version="$VERSION" \ release="$RELEASE.$DISTTAG" \ architecture="$ARCH" \ @@ -11,8 +11,8 @@ LABEL com.redhat.component="docker" \ maintainer="Giuseppe Scrivano " \ atomic.type="system" -RUN dnf install --setopt=tsflags=nodocs -y docker container-storage-setup container-selinux cloud-utils-growpart python-docker-py docker-novolume-plugin lvm2 iptables procps-ng xz oci-register-machine \ - && rpm -V docker container-storage-setup container-selinux cloud-utils-growpart python-docker-py docker-novolume-plugin lvm2 iptables procps-ng xz oci-register-machine \ +RUN dnf install --setopt=tsflags=nodocs -y docker container-selinux cloud-utils-growpart python-docker-py docker-novolume-plugin lvm2 iptables procps-ng xz oci-register-machine \ + && rpm -V docker container-selinux cloud-utils-growpart python-docker-py docker-novolume-plugin lvm2 iptables procps-ng xz oci-register-machine \ && mkdir -p /usr/lib/modules && dnf clean all RUN ln -s /usr/libexec/docker/docker-runc-current /usr/bin/docker-runc @@ -25,6 +25,6 @@ COPY set_mounts.sh / COPY config.json.template service.template tmpfiles.template /exports/ COPY daemon.json /exports/hostfs/etc/docker/container-daemon.json # https://github.com/rhatdan/oci-umount/issues/2 -RUN cp /etc/oci-umount.conf /exports/hostfs/etc +RUN (test -e /etc/oci-umount.conf && cp /etc/oci-umount.conf /exports/hostfs/etc) || true CMD ["/usr/bin/init.sh"] diff --git a/config.json.template b/config.json.template index 3ce615c..cd433c3 100644 --- a/config.json.template +++ b/config.json.template @@ -5,6 +5,7 @@ "arch": "amd64" }, "process": { + "selinuxLabel": "system_u:system_r:container_runtime_t:s0", "terminal": false, "user": { "uid": 0, @@ -393,7 +394,6 @@ { "type": "mount" } - ], - "selinuxProcessLabel": "system_u:system_r:container_runtime_t:s0" + ] } } diff --git a/daemon.json b/daemon.json index ea5e789..445fe8a 100644 --- a/daemon.json +++ b/daemon.json @@ -1,6 +1,4 @@ - { - "authorization-plugins": ["rhel-push-plugin"], "default-runtime": "oci", "containerd": "/run/containerd.sock", "userland-proxy-path": "/usr/libexec/docker/docker-proxy-current", diff --git a/init.sh b/init.sh index ac03b38..4347c47 100755 --- a/init.sh +++ b/init.sh @@ -1,5 +1,10 @@ #!/bin/bash +# Ensure that new process maintain this SELinux label +PID=$$ +LABEL=`tr -d '\000' < /proc/$PID/attr/current` +printf %s $LABEL > /proc/self/attr/exec + source /run/docker-bash-env # set storage first @@ -22,7 +27,7 @@ do sleep 0.1 done -# Run all the installed containers +# Run all the installed plugins mkdir -p /run/docker/plugins/ ls -1 /usr/libexec/docker/*plugin | \ while read i;