This repository was archived by the owner on May 7, 2021. It is now read-only.
Open
Conversation
5b4ca09 to
54a9356
Compare
54a9356 to
4a8f6db
Compare
Contributor
Author
|
Rebased to latest. |
With the current SELinux policy the core user does not have rights to execute RestartUnit. Set SELinux to permisive mode so this test can run. Fixes runtime errors like these: kolet: RestartUnit failed: Error: Timeout was reached Signed-off-by: Geoff Levand <geoff@infradead.org>
With the current SELinux policy the docker daemon does not have access to the '/root' directory. Set SELinux to permisive mode so this test can run. Fixes runtime errors like these: Error response from daemon: OCI runtime create failed: "mkdir /var/lib/docker/overlay2/.../merged/root: permission denied Signed-off-by: Geoff Levand <geoff@infradead.org>
A docker bug causes the docker daemon to fail in creating a container when the '--userns-remap' option is used and SELinux is enforcing. Set SELinux to permisive mode so this test can run. See: opencontainers/runc#1562 (nsenter: improve namespace creation and SELinux IPC handling). Fixes runtime errors like these: OCI runtime create failed: running exec setns process for init caused exit Signed-off-by: Geoff Levand <geoff@infradead.org>
Ensure that when SELinux is enforcing the docker daemon cannot create container instances with mounts to restricted directories. Signed-off-by: Geoff Levand <geoff@infradead.org>
Checks that no audit AVC messages appear in boot logs. Signed-off-by: Geoff Levand <geoff@infradead.org>
4a8f6db to
b973854
Compare
Contributor
Author
|
Rebased to latest. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Test fixups for SELinux policy update.
Related to coreos/coreos-overlay#3155 (Update selinux support), coreos/portage-stable#654 (Update selinux support)