浏览代码

Merge pull request #32529 from runcom/relabel-secrets

daemon: relabel secrets path
Evan Hazlett 8 年之前
父节点
当前提交
2aec48f448
共有 1 个文件被更改,包括 2 次插入0 次删除
  1. 2 0
      daemon/container_operations_unix.go

+ 2 - 0
daemon/container_operations_unix.go

@@ -214,6 +214,8 @@ func (daemon *Daemon) setupSecretDir(c *container.Container) (setupErr error) {
 		}
 		}
 	}
 	}
 
 
+	label.Relabel(localMountPath, c.MountLabel, false)
+
 	// remount secrets ro
 	// remount secrets ro
 	if err := mount.Mount("tmpfs", localMountPath, "tmpfs", "remount,ro,"+tmpfsOwnership); err != nil {
 	if err := mount.Mount("tmpfs", localMountPath, "tmpfs", "remount,ro,"+tmpfsOwnership); err != nil {
 		return errors.Wrap(err, "unable to remount secret dir as readonly")
 		return errors.Wrap(err, "unable to remount secret dir as readonly")