Updated Docker in F25 again with the latest docker-selinux commit https://bodhi.fedoraproject.org/updates/docker-1.12.1-12.git9a3752d.fc25 On Mon, Sep 12, 2016 at 11:17:41AM -0400, Daniel J Walsh wrote: > > > On 09/12/2016 09:42 AM, Antonio Murdaca wrote: > > On Mon, Sep 12, 2016 at 07:05:37PM +0530, Kushal Das wrote: > >> On 12/09/16, Antonio Murdaca wrote: > >>> On Sep 12, 2016 2:45 PM, "Daniel J Walsh" <dwalsh redhat com> wrote: > >>>> > >>>> > >>>> On 09/11/2016 12:35 AM, Dusty Mabe wrote: > >>>>> In Fedora 25 I grabbed the new kernel with overlayfs support [1] and I > >>>>> configured docker to run with overlayfs by using > >>> DOCKER_STORAGE_OPTIONS="--storage-driver=overlay2" > >>>>> in /etc/sysconfig/docker-storage. > >>>>> > >>>>> [1] > >>> https://kojipkgs.fedoraproject.org//packages/kernel/4.8.0/0.rc5.git4.1.fc25/x86_64/kernel-core-4.8.0-0.rc5.git4.1.fc25.x86_64.rpm > >>>>> > >>>> You need an updated docker-selinux package in Rawhide we are running with > >>>> > >>>> docker-1.12.1-20.git2649fe1.fc26.x86_64 > >>>> > >>>> We need this update for F25. > >>>> > >>>> If you use > >>>> grep entrypoint /var/log/audit/audit.log | audit2allow -M myoverlay > >>>> semodule -i myoverlay.pp > >>>> > >>>> It should fix the problem for you. > >>>> > >>>> Lokesh and/or Antonio can you get an updated version of docker built in > >>> F25 to match the one in Rawhide. > >>> > >>> I submitted an update for F25 two days ago which contains the fix needed > >>> https://bodhi.fedoraproject.org/updates/FEDORA-2016-d372e43d2a > >>> > >> It seems to be failing with the same SELinux denials. I have commented > >> on the bodhi update. > > Alright, I figured we need at least the same docker-selinux commit in > > F25 (from Rawhide) since we build both from the master branch. I'll > > release another update for F25 this afternoon. > > > >> Kushal > >> -- > >> Fedora Cloud Engineer > >> CPython Core Developer > >> https://kushaldas.in > >> https://dgplug.org > Yes I would like to keep docker the same in F25 and Rawhide as best we > can, until docker-1.13 gets released. -- Antonio Murdaca IRC: runcom 2048R / 09B9 8F09 3E2D C310 E250 69B5 B2BE AD15 0DE9 36B9 https://pgp.mit.edu/pks/lookup?op=get&search=0xB2BEAD150DE936B9
Attachment:
signature.asc
Description: PGP signature