Explorar o código

Merge pull request #7660 from rhatdan/selinux-volumes

Change default label of container volumes to shared SELinux Label
Jessie Frazelle %!s(int64=10) %!d(string=hai) anos
pai
achega
971240696f
Modificáronse 1 ficheiros con 7 adicións e 1 borrados
  1. 7 1
      daemon/graphdriver/vfs/driver.go

+ 7 - 1
daemon/graphdriver/vfs/driver.go

@@ -3,10 +3,12 @@ package vfs
 import (
 import (
 	"bytes"
 	"bytes"
 	"fmt"
 	"fmt"
-	"github.com/docker/docker/daemon/graphdriver"
 	"os"
 	"os"
 	"os/exec"
 	"os/exec"
 	"path"
 	"path"
+
+	"github.com/docker/docker/daemon/graphdriver"
+	"github.com/docker/libcontainer/label"
 )
 )
 
 
 func init() {
 func init() {
@@ -67,6 +69,10 @@ func (d *Driver) Create(id, parent string) error {
 	if err := os.Mkdir(dir, 0755); err != nil {
 	if err := os.Mkdir(dir, 0755); err != nil {
 		return err
 		return err
 	}
 	}
+	opts := []string{"level:s0"}
+	if _, mountLabel, err := label.InitLabels(opts); err == nil {
+		label.Relabel(dir, mountLabel, "")
+	}
 	if parent == "" {
 	if parent == "" {
 		return nil
 		return nil
 	}
 	}