Comments (4)
From #98 (comment):
Hmm, @ibuildthecloud pointed me at https://github.com/containers/container-selinux/tree/RHEL7.5, will give this a try.
The RHEL7.5 branch is a no:
[vagrant@localhost container-selinux]$ git status
# On branch RHEL7.5
nothing to commit, working directory clean
[vagrant@localhost container-selinux]$ make install-policy
make -f /usr/share/selinux/devel/Makefile container.pp
make[1]: Entering directory `/home/vagrant/container-selinux'
/usr/share/selinux/devel/include/contrib/container.if:14: Error: duplicate definition of container_runtime_domtrans(). Original definition on 14.
/usr/share/selinux/devel/include/contrib/container.if:33: Error: duplicate definition of container_runtime_exec(). Original definition on 61.
/usr/share/selinux/devel/include/contrib/container.if:52: Error: duplicate definition of container_search_lib(). Original definition on 98.
/usr/share/selinux/devel/include/contrib/container.if:71: Error: duplicate definition of container_exec_lib(). Original definition on 117.
/usr/share/selinux/devel/include/contrib/container.if:90: Error: duplicate definition of container_read_lib_files(). Original definition on 136.
/usr/share/selinux/devel/include/contrib/container.if:109: Error: duplicate definition of container_read_share_files(). Original definition on 155.
/usr/share/selinux/devel/include/contrib/container.if:131: Error: duplicate definition of container_exec_share_files(). Original definition on 238.
/usr/share/selinux/devel/include/contrib/container.if:149: Error: duplicate definition of container_manage_lib_files(). Original definition on 275.
/usr/share/selinux/devel/include/contrib/container.if:169: Error: duplicate definition of container_manage_lib_dirs(). Original definition on 332.
/usr/share/selinux/devel/include/contrib/container.if:205: Error: duplicate definition of container_lib_filetrans(). Original definition on 368.
/usr/share/selinux/devel/include/contrib/container.if:223: Error: duplicate definition of container_read_pid_files(). Original definition on 386.
/usr/share/selinux/devel/include/contrib/container.if:242: Error: duplicate definition of container_systemctl(). Original definition on 405.
/usr/share/selinux/devel/include/contrib/container.if:267: Error: duplicate definition of container_rw_sem(). Original definition on 430.
/usr/share/selinux/devel/include/contrib/container.if:285: Error: duplicate definition of container_use_ptys(). Original definition on 467.
/usr/share/selinux/devel/include/contrib/container.if:303: Error: duplicate definition of container_filetrans_named_content(). Original definition on 485.
/usr/share/selinux/devel/include/contrib/container.if:336: Error: duplicate definition of container_stream_connect(). Original definition on 538.
/usr/share/selinux/devel/include/contrib/container.if:355: Error: duplicate definition of container_spc_stream_connect(). Original definition on 559.
/usr/share/selinux/devel/include/contrib/container.if:376: Error: duplicate definition of container_admin(). Original definition on 580.
/usr/share/selinux/devel/include/contrib/container.if:423: Error: duplicate definition of container_spc_read_state(). Original definition on 765.
/usr/share/selinux/devel/include/contrib/container.if:441: Error: duplicate definition of container_auth_domtrans(). Original definition on 627.
/usr/share/selinux/devel/include/contrib/container.if:460: Error: duplicate definition of container_auth_exec(). Original definition on 646.
/usr/share/selinux/devel/include/contrib/container.if:479: Error: duplicate definition of container_auth_stream_connect(). Original definition on 665.
/usr/share/selinux/devel/include/contrib/container.if:498: Error: duplicate definition of container_runtime_typebounds(). Original definition on 684.
container.if:14: Error: duplicate definition of container_runtime_domtrans(). Original definition on 14.
container.if:41: Error: duplicate definition of container_runtime_run(). Original definition on 41.
container.if:61: Error: duplicate definition of container_runtime_exec(). Original definition on 61.
container.if:80: Error: duplicate definition of container_read_state(). Original definition on 80.
container.if:98: Error: duplicate definition of container_search_lib(). Original definition on 98.
container.if:117: Error: duplicate definition of container_exec_lib(). Original definition on 117.
container.if:136: Error: duplicate definition of container_read_lib_files(). Original definition on 136.
container.if:155: Error: duplicate definition of container_read_share_files(). Original definition on 155.
container.if:176: Error: duplicate definition of container_runtime_read_tmpfs_files(). Original definition on 176.
container.if:197: Error: duplicate definition of container_manage_share_files(). Original definition on 197.
container.if:218: Error: duplicate definition of container_manage_share_dirs(). Original definition on 218.
container.if:238: Error: duplicate definition of container_exec_share_files(). Original definition on 238.
container.if:256: Error: duplicate definition of container_manage_config_files(). Original definition on 256.
container.if:275: Error: duplicate definition of container_manage_lib_files(). Original definition on 275.
container.if:295: Error: duplicate definition of container_manage_files(). Original definition on 295.
container.if:314: Error: duplicate definition of container_manage_dirs(). Original definition on 314.
container.if:332: Error: duplicate definition of container_manage_lib_dirs(). Original definition on 332.
container.if:368: Error: duplicate definition of container_lib_filetrans(). Original definition on 368.
container.if:386: Error: duplicate definition of container_read_pid_files(). Original definition on 386.
container.if:405: Error: duplicate definition of container_systemctl(). Original definition on 405.
container.if:430: Error: duplicate definition of container_rw_sem(). Original definition on 430.
container.if:449: Error: duplicate definition of container_append_file(). Original definition on 449.
container.if:467: Error: duplicate definition of container_use_ptys(). Original definition on 467.
container.if:485: Error: duplicate definition of container_filetrans_named_content(). Original definition on 485.
container.if:538: Error: duplicate definition of container_stream_connect(). Original definition on 538.
container.if:559: Error: duplicate definition of container_spc_stream_connect(). Original definition on 559.
container.if:580: Error: duplicate definition of container_admin(). Original definition on 580.
container.if:627: Error: duplicate definition of container_auth_domtrans(). Original definition on 627.
container.if:646: Error: duplicate definition of container_auth_exec(). Original definition on 646.
container.if:665: Error: duplicate definition of container_auth_stream_connect(). Original definition on 665.
container.if:684: Error: duplicate definition of container_runtime_typebounds(). Original definition on 684.
container.if:703: Error: duplicate definition of container_runtime_entrypoint(). Original definition on 703.
container.if:710: Error: duplicate definition of docker_exec_lib(). Original definition on 710.
container.if:714: Error: duplicate definition of docker_read_share_files(). Original definition on 714.
container.if:718: Error: duplicate definition of docker_exec_share_files(). Original definition on 718.
container.if:722: Error: duplicate definition of docker_manage_lib_files(). Original definition on 722.
container.if:727: Error: duplicate definition of docker_manage_lib_dirs(). Original definition on 727.
container.if:731: Error: duplicate definition of docker_lib_filetrans(). Original definition on 731.
container.if:735: Error: duplicate definition of docker_read_pid_files(). Original definition on 735.
container.if:739: Error: duplicate definition of docker_systemctl(). Original definition on 739.
container.if:743: Error: duplicate definition of docker_use_ptys(). Original definition on 743.
container.if:747: Error: duplicate definition of docker_stream_connect(). Original definition on 747.
container.if:751: Error: duplicate definition of docker_spc_stream_connect(). Original definition on 751.
container.if:765: Error: duplicate definition of container_spc_read_state(). Original definition on 765.
container.if:784: Error: duplicate definition of container_domain_template(). Original definition on 784.
container.if:812: Error: duplicate definition of container_spc_rw_pipes(). Original definition on 812.
Compiling targeted container module
/usr/bin/checkmodule: loading policy configuration from tmp/container.tmp
container.te:486:ERROR 'syntax error' at token 'fs_manage_fusefs_named_sockets' on line 18289:
fs_manage_fusefs_named_sockets(container_domain)
/usr/bin/checkmodule: error(s) encountered while parsing configuration
make[1]: *** [tmp/container.mod] Error 1
make[1]: Leaving directory `/home/vagrant/container-selinux'
make: *** [container.pp] Error 2
[vagrant@localhost container-selinux]$
from container-selinux.
SELINUX Policy has changed massively since RHEL7/CENTOS7, You need to use the RHEL7.5 branch.
from container-selinux.
@rhatdan as per #97 (comment), the RHEL7.5 branch errors.
from container-selinux.
What version so RHEL7 are you doing this on?
You could just comment out the
fs_manage_fusefs_named_sockets(container_domain)
line, and you should be fine.
from container-selinux.
Related Issues (20)
- Branch protection for main branch HOT 3
- gating tests? HOT 2
- iptables-restore cannot read file from inside a container HOT 6
- allow user_u to work with containers HOT 8
- Packit: Use packit for bumping official fedora package HOT 1
- CI: check for long-running relabels HOT 1
- [packit] Propose downstream failed for release v2.213.0 HOT 3
- Issues on Fedora (container-selinux-2.211.1) with container_domain_template HOT 5
- Issue on RHEL with iscsiadm on v2.205 HOT 4
- user_namespace { create } rule not working HOT 11
- Concern with use of dac_override in home_container.cil HOT 3
- `avc: denied { shutdown }` when using socket activation with rootless podman quadlet HOT 3
- dri_device_t cannot be accessed correctly by pods using device plugins. HOT 12
- Add support for `rpm --verify` HOT 3
- container_init_t does not possess ptrace process context HOT 13
- CRI-O CI broken due to SELinux AVC Denials with latest runc (main branch) build HOT 20
- systemd crashes while attempting to start under container_user_r role HOT 11
- /etc/kubernetes filetrans? HOT 1
- container_user_u issues related to `podmansh` HOT 2
- Supprot for RHEL 9 HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from container-selinux.