feat(docker,podman): add SELinux label support for bind mounts - #2092
Merged
Conversation
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Add optional
selinux_labelfield to bind mount driver configs for both Docker and Podman drivers. On SELinux-enabled hosts (Fedora, RHEL), bind-mounted paths need relabelling so container processes can access them. This was missing from the bind mount support added in #1785.Related Issue
Extends #1785
Changes
SelinuxLabelenum (shared/private) toopenshell-core::driver_mountsMountAPI (which lacks SELinux support) to the legacy string-formatBindsfield, appending:zor:Zwhenselinux_labelis setselinux_labeltoPodmanDriverMountConfig::Bindand pushz/Zto the mount options vecdocs/reference/sandbox-compute-drivers.mdxmount schema tables for both driversTesting
cargo fmt --all -- --checkpassescargo clippy --workspacepassesChecklist