[uc18] docker overlayfs* seems broken
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
snapd |
Fix Released
|
Medium
|
Jamie Strandboge | ||
linux-raspi2 (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned | ||
Bionic |
Invalid
|
Undecided
|
Unassigned |
Bug Description
A customer recently reported that 'sudo docker run hello-world' fails on a pi3 or pi4 running UC18. Looking at the journal, the failure appears to be caused by an apparmor denial related docker's overlay2 storage driver. I've tried both the unified and the Pi3 specific UC18 images and both fail with the same error. The same command works fine on other devices running UC18 (I've tested multipass+macOS, and dragonboard), and also works on a Pi3b running our standard UC16 image.
Here are the details from the UC18 image.
$ snap list
core 16-2.43.3 8691 stable canonical✓ core
core18 20200124 1673 stable canonical✓ base
docker 18.09.9 427 stable canonical✓ -
pi 18-1 27 18-pi canonical✓ gadget
pi-kernel 5.3.0-1019.
snapd 2.43.3 6438 stable canonical✓ snapd
And here's the apparmor denial:
Mar 24 19:38:55 localhost sudo[3095]: awe : TTY=pts/0 ; PWD=/home/awe ; USER=root ; COMMAND=
Mar 24 19:39:02 localhost audit[2932]: AVC apparmor="DENIED" operation="open" profile=
I've been told this may end up being something that gets worked around in snapd, however as this looks like a regression, I'm erring on the side of caution and filing this bug anyways.
Please let me know if there's anything else I can provide.
Changed in snapd: | |
importance: | Undecided → Medium |
Changed in snapd: | |
milestone: | none → 2.45 |
Status changed to 'Confirmed' because the bug affects multiple users.