Closed dustymabe closed 5 years ago
could you try if setting the selinux boolean virt_sandbox_use_fusefs
make a difference?
@rhatdan since we are going to use fuse-overlayfs as the default for rootless containers, should we change the default value for the boolean?
We need to make the change in the spec file, to turn the boolean on, on initial update. then not change it again.
@lsm5 Could you look into this?
Basically once we make fuse-overlayfs the default we need to turn on the virt_sandbox_use_fusefs boolean.
We only want to do this once on initial install and on the first upgrade when we make the change. We don't want to change this afterwards, since if an ADMIN does a
setsebool -P virt_sandbox_use_fusefs 0
We don't want an update to override him.
I think we make this change in containers-common by adding a default nonroot-storage.conf file. And set the boolean there. That way we don't have to handle this in podman and buildah.
ack, will do
This is fixed in the current release.
Version info:
Fedora 29 Atomic Host
Description
I'm experimenting with using overlay as the backend since the vfs backend uses a lot of disk space. Once I finally got it configured right I'm seeing selinux denials on Fedora 29.
If I
setenforce 0
then my build continues. Is this a known issue?