mirror of
https://github.com/moby/moby.git
synced 2022-11-09 12:21:53 -05:00
Merge pull request #11274 from MabinGo/selinux_enable_verify
Add logs when Docker enabled selinux (closes #11197)
This commit is contained in:
commit
fdf49d758f
1 changed files with 12 additions and 6 deletions
|
@ -866,9 +866,6 @@ func NewDaemonFromDirectory(config *Config, eng *engine.Engine) (*Daemon, error)
|
||||||
return nil, fmt.Errorf("Unable to get the full path to the TempDir (%s): %s", tmp, err)
|
return nil, fmt.Errorf("Unable to get the full path to the TempDir (%s): %s", tmp, err)
|
||||||
}
|
}
|
||||||
os.Setenv("TMPDIR", realTmp)
|
os.Setenv("TMPDIR", realTmp)
|
||||||
if !config.EnableSelinuxSupport {
|
|
||||||
selinuxSetDisabled()
|
|
||||||
}
|
|
||||||
|
|
||||||
// get the canonical path to the Docker root directory
|
// get the canonical path to the Docker root directory
|
||||||
var realRoot string
|
var realRoot string
|
||||||
|
@ -902,9 +899,18 @@ func NewDaemonFromDirectory(config *Config, eng *engine.Engine) (*Daemon, error)
|
||||||
}
|
}
|
||||||
})
|
})
|
||||||
|
|
||||||
// As Docker on btrfs and SELinux are incompatible at present, error on both being enabled
|
if config.EnableSelinuxSupport {
|
||||||
if selinuxEnabled() && config.EnableSelinuxSupport && driver.String() == "btrfs" {
|
if selinuxEnabled() {
|
||||||
return nil, fmt.Errorf("SELinux is not supported with the BTRFS graph driver!")
|
// As Docker on btrfs and SELinux are incompatible at present, error on both being enabled
|
||||||
|
if driver.String() == "btrfs" {
|
||||||
|
return nil, fmt.Errorf("SELinux is not supported with the BTRFS graph driver")
|
||||||
|
}
|
||||||
|
log.Debug("SELinux enabled successfully")
|
||||||
|
} else {
|
||||||
|
log.Warn("Docker could not enable SELinux on the host system")
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
selinuxSetDisabled()
|
||||||
}
|
}
|
||||||
|
|
||||||
daemonRepo := path.Join(config.Root, "containers")
|
daemonRepo := path.Join(config.Root, "containers")
|
||||||
|
|
Loading…
Reference in a new issue