Note: This is a beta release of Red Hat Bugzilla 5.0. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Also email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback here.
Bug 1695126 - Docker runs containers from the same pod with different contexts
Summary: Docker runs containers from the same pod with different contexts
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Containers
Version: 3.11.0
Hardware: Unspecified
OS: Unspecified
Target Milestone: ---
: 4.1.0
Assignee: Daniel Walsh
QA Contact: weiwei jiang
Depends On:
TreeView+ depends on / blocked
Reported: 2019-04-02 14:22 UTC by Jan Safranek
Modified: 2019-04-02 16:52 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Last Closed: 2019-04-02 16:52:47 UTC
Target Upstream Version:

Attachments (Terms of Use)

Description Jan Safranek 2019-04-02 14:22:12 UTC
I have a pod with two containers:

- The first one is privileged and runs a storage driver. It creates a socket on the host in /var/lib/kubelet/plugins (labelled as var_lib_t). 

- The second one is not privileged and needs to connect to the socket created by the first container.

With cri-o, it works, because cri-o (or something in kubelet?) runs both containers with spc_t context, so the second container can access created by the first one.

With docker, it does not work. The first (privileged) container is started with spc_t (which is correct). The second (non-privileged) container starts with container_t:s0:cc38,c115 that can't access var_lib_t on the host and connect to the socket.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. run a pod with one unprivileged and one privileged container
2. ps -eZ (on the host)

Actual results:
the unprivileged container runs with system_u:system_r:container_t:s0:c38,c115

Expected results:
both containers run with system_u:system_r:spc_t:s0

I reproduced it with OpenShift 3.11, because we don't have RHEL7 + docker support in 4.1 yet. But I need a fix in 4.x, CSI (Container Storage Interface) depends on it.

Comment 1 Daniel Walsh 2019-04-02 14:31:18 UTC
There is no Docker support in 4.1.

Comment 2 Derek Carr 2019-04-02 16:52:47 UTC
4.1 is rhel 7 w/ cri-o only.

Note You need to log in before you can comment on or make changes to this bug.