Skip to content

Conversation

@mrunalp
Copy link
Collaborator

@mrunalp mrunalp commented Feb 2, 2017

Fixes #4

@runcom @rhatdan PTAL. This should unblock docker 1.13.

We ensure that mqueue is owned by user namespace root
by unsharing CLONE_NEWIPC after we become user namespace
root. This allows us to apply the container SELinux label
to mqueue.

Signed-off-by: Mrunal Patel <[email protected]>
@rhatdan
Copy link
Member

rhatdan commented Feb 2, 2017

Will this allow SELinux to work with User Namespace?

@mrunalp
Copy link
Collaborator Author

mrunalp commented Feb 2, 2017

@rhatdan Yes

@runcom
Copy link
Collaborator

runcom commented Feb 2, 2017

cool, LGTM

@mrunalp side note, should you update opencontainers/runc#959?

@runcom runcom merged commit 4c59d57 into docker-1.13 Feb 2, 2017
@runcom runcom deleted the fix_selinux_mqueue branch February 2, 2017 21:24
@mrunalp
Copy link
Collaborator Author

mrunalp commented Feb 2, 2017

@runcom Yeah, I am planning to do that.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants