Uploaded image for project: 'Cloud Infrastructure Security & Compliance'
  1. Cloud Infrastructure Security & Compliance
  2. CMP-4007

The spod pods failed to get running due to "fsmount:fscontext:proc/: could not get mount id: operation not permitted"

XMLWordPrintable

    • True
    • Hide

      The operator installation failed

      Show
      The operator installation failed
    • False
    • CMP Sprint 110, CMP Sprint 111
    • Important

      Description of problem:

       

      The spod pods failed to get running due to "fsmount:fscontext:proc/: could not get mount id: operation not permitted"
      oc  get daemonset spod -n openshift-security-profiles
      NAME   DESIRED   CURRENT   READY   UP-TO-DATE   AVAILABLE   NODE SELECTOR            AGE
      spod   6         6         0       6            0           kubernetes.io/os=linux   41m
      $ oc logs  pod/spod-257ff -n openshift-security-profiles --all-containers
      ...
      + semodule -i /usr/share/selinuxd/templates/base_container.cil /usr/share/selinuxd/templates/config_container.cil /usr/share/selinuxd/templates/home_container.cil /usr/share/selinuxd/templates/log_container.cil /usr/share/selinuxd/templates/net_container.cil /usr/share/selinuxd/templates/tmp_container.cil /usr/share/selinuxd/templates/tty_container.cil /usr/share/selinuxd/templates/virt_container.cil /usr/share/selinuxd/templates/x_container.cil
      + semodule -i /opt/spo-profiles/selinuxd.cil
      + semodule -i /opt/spo-profiles/selinuxrecording.cil
      reopen exec fifo: get safe /proc/thread-self/fd handle: check "thread-self" component is not overmounted: get root mount id: statx(STATX_MNT_ID_...) fsmount:fscontext:proc/: could not get mount id: operation not permitted
      {"level":"info","ts":1765181708.631539,"caller":"version/version.go:42","msg":"selinuxd information","version":"deeaf46","buildDate":"'2025-09-08T16:09:58Z'","compiler":"gc","platform":"linux/amd64"}
      {"level":"info","ts":1765181708.6316931,"caller":"daemon/daemon.go:31","msg":"Started daemon"}
      {"level":"info","ts":1765181708.638082,"logger":"state-server","caller":"daemon/status_server.go:178","msg":"Serving status","path":"/var/run/selinuxd/selinuxd.sock","uid":0,"gid":65535}
      {"level":"info","ts":1765181708.638149,"caller":"daemon/status_server.go:75","msg":"Status Server got READY signal"}
      

       

      Version-Release number of selected component (if applicable):

      4.15.0-0.nightly-2025-12-03-142922 + security-profiles-operator.v0.9.0  

      How reproducible:

         Always

      Steps to Reproduce:

      1.Install SPOv0.9.0

       

      Actual results:

      Operator installation failed because the necessary spod pods did not start.

       

      Expected results:

      Operator installation should succeed

              wenshen@redhat.com Vincent Shen
              xiyuan@redhat.com Xiaojie Yuan
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: