Details

    • Normal
    • sst_container_tools
    • ssg_security
    • 3
    • False
    • Hide

      None

      Show
      None
    • If docs needed, set a value

    Description

      Description of problem:
      After updating my system docker containers where unable to start.

      Even a blank alpine container did not start.

      Before the update with these policies it was still working:

      selinux-policy-34.1.44-1.el9.noarch
      selinux-policy-targeted-34.1.44-1.el9.noarch
      container-selinux-2.189.0-1.el9.noarch

      Version-Release number of selected component (if applicable):
      selinux-policy-38.1.2-1.el9.noarch
      selinux-policy-targeted-38.1.2-1.el9.noarch
      container-selinux-2.193.0-1.el9.noarch

      How reproducible:
      Update CentOS 9 stream to latest version and try to run any docker container.

      Steps to Reproduce:
      1.
      2.
      3.

      Actual results:
      docker: Error response from daemon: failed to create shim task: OCI runtime create failed: runc create failed: unable to start container process: error during container init: error setting cgroup config for procHooks process: load progra
      m: permission denied: processed 251 insns (limit 1000000) max_states_per_insn 2 total_states 27 peak_states 27 mark_read 2: unknown.

      Expected results:
      Containers should have the permission to run.

      Additional info:
      I have attached a policy to get my gitlab container running.

      Attachments

        Issue Links

          Activity

            People

              dwalsh@redhat.com Daniel Walsh
              jira-bugzilla-migration RH Bugzilla Integration
              Daniel Walsh
              Container Runtime Eng Bot Container Runtime Eng Bot
              Container Runtime Bugs Bot Container Runtime Bugs Bot
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: