From 3b877dc7c272d9624b6fbef97e1846e32002e4a6 Mon Sep 17 00:00:00 2001 From: "Yann E. MORIN" Date: Wed, 9 Aug 2023 23:24:50 +0200 Subject: [PATCH] utils/docker-run: make it compatible with SELinux After switching to a fresh Fedora 38 installation with SELinux disabled, we noticed that utils/docker-run doesn't work as the applications running inside the container are not allowed to accept the data mounted through the bind mount. Since we do not really need to isolate and confine the build, but rather to provide a known environment, we don;t really need to enforce any SELinux confinment in the container. So, we tell docker to turn off label confinement for the container: https://manpages.org/docker-run --security-opt=[] Security Options [...] "label=disable" : Turn off label confinement for the container Suggested-by: Antoine Tenart Signed-off-by: Thomas Petazzoni [yann.morin.1998@free.fr: use Antoine's proposal] Signed-off-by: Yann E. MORIN --- utils/docker-run | 1 + 1 file changed, 1 insertion(+) diff --git a/utils/docker-run b/utils/docker-run index e64b4f10c0..33d2e63abc 100755 --- a/utils/docker-run +++ b/utils/docker-run @@ -18,6 +18,7 @@ declare -a docker_opts=( --rm --user "$(id -u):$(id -g)" --workdir "$(pwd)" + --security-opt label=disable ) declare -a mountpoints=(