docker exec doesnt work on centos stream 9 #43960
-
i use m1 mac + pd build a centos stream9 vm,then i remove podman,install dokcer ,i run docker pull nginx, docker run --name nginx -dp 80:80 nginx,then i run docker exec -it nginx bash, but error happend,the content is |
Beta Was this translation helpful? Give feedback.
Answered by
AkihiroSuda
Sep 5, 2022
Replies: 2 comments 5 replies
-
Looks to be SELinux blocking docker run -it --rm busybox
docker: Error response from daemon: failed to create shim task: OCI runtime create failed: runc create failed: unable to start container process: error during container init: open /dev/pts/0: operation not permitted: unknown.
ls -la /dev/pts/0
crw--w----. 1 root tty 136, 0 Aug 16 06:06 /dev/pts/0 ausearch -m avc --start recent
...
time->Tue Aug 16 06:11:12 2022
type=PROCTITLE msg=audit(1660644672.677:490): proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F32643961343339383566313539356238363132333135386637
type=SYSCALL msg=audit(1660644672.677:490): arch=c000003e syscall=321 success=no exit=-13 a0=d a1=c00013e040 a2=8 a3=7f7a553af3b0 items=0 ppid=13615 pid=13625 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:unconfined_service_t:s0 key=(null)
type=AVC msg=audit(1660644672.677:490): avc: denied { prog_run } for pid=13625 comm="runc" scontext=system_u:system_r:unconfined_service_t:s0 tcontext=system_u:system_r:init_t:s0 tclass=bpf permissive=0 Temporarily disabling selinux, it looks to be working; setenforce 0
docker run -it --rm busybox
/ # exit ausearch -m avc --start recent
...
time->Tue Aug 16 06:12:50 2022
type=PROCTITLE msg=audit(1660644770.358:506): proctitle=72756E63002D2D726F6F74002F7661722F72756E2F646F636B65722F72756E74696D652D72756E632F6D6F6279002D2D6C6F67002F72756E2F636F6E7461696E6572642F696F2E636F6E7461696E6572642E72756E74696D652E76322E7461736B2F6D6F62792F35613362303434333030316537666339316239303534353733
type=SYSCALL msg=audit(1660644770.358:506): arch=c000003e syscall=321 success=yes exit=17 a0=d a1=c00013e040 a2=8 a3=7f162404d3b0 items=0 ppid=13705 pid=13716 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="runc" exe="/usr/bin/runc" subj=system_u:system_r:unconfined_service_t:s0 key=(null)
type=AVC msg=audit(1660644770.358:506): avc: denied { prog_run } for pid=13716 comm="runc" scontext=system_u:system_r:unconfined_service_t:s0 tcontext=system_u:system_r:init_t:s0 tclass=bpf permissive=1 docker version and info
|
Beta Was this translation helpful? Give feedback.
5 replies
-
Fixed in https://github.com/opencontainers/runc/releases/tag/v1.1.4 |
Beta Was this translation helpful? Give feedback.
0 replies
Answer selected by
AkihiroSuda
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Fixed in https://github.com/opencontainers/runc/releases/tag/v1.1.4