Which capabilities are needed for statx to stop giving EPERM
Before 2018-03-06
statx
isn't included in the default seccomp
whitelist used by Docker as of present date.
You can use --security-opt seccomp=/path/to/seccomp/profile.json
to specify a different profile (presumably, one with this syscall added).
After 2018-03-06
moby/moby#36417
was merged to master as of March 6th, 2018.
It should be included in nightly builds going forward, and eventually in the Docker 18.04 release.
moc failing with 'Undefined interface' with Qt 5.10 in a Docker container
Running moc
under strace shows Operation not permitted
on various statx
calls, which sheds some light on why exactly it fails (also, related to this question). This pull request is hopefully going to fix this.
Why can't I install libpaper1 with remote Docker 17.09?
The error comes from statx
not from libepaper1
.statx
wasn't included in the default seccomp whitelist used by Docker before version 18.04.0, as we can see in the Docker Engine 18.04 release notes page.
Whitelist statx syscall. moby/moby#36417
Thats why upgrading docker is the solution.
Sources:
https://github.com/moby/moby/pull/36417
Which capabilities are needed for statx to stop giving EPERM
https://unix.stackexchange.com/questions/672183/cannot-install-ghostscript-libgs9-and-libpaper1-on-debian-bullseye
Related Topics
Bash: Update a Variable Within a File
Using Pipe in Linux Using Parent and Child Process
Bash Script to Remove Directories Based on Modified File Date
Phusion Passenger Nginx Module Installer V3.0.17 Issue on Debian 6.0.5 Amd64 Due to Broken Package
Bash/Linux Sort by 3Rd Column Using Custom Field Seperator
Shebang Not Working to Run Bash Scripts in Linux
Bash - How to Match Files Names to Use in Loop
Diff (Gnu Diffutils) 3.6 Exclude Directory
What Is an Absolute Pathname VS a Relative Pathname
How to Route Webcam Video to Virtual Video Device on Linux (Via Opencv)
Why Count Differs Between Ls and Ls -L Linux Command
How to Create an Alias in Linux
How to Read from User in Rpm Install Script
Ha Proxy Simple Forwarding with Docker
How to Find the File Which Contains a Specific Text in Linux
Allocating a Data Page in Linux with Nx Bit Turned Off
G++ Always Fails with Undefined Reference to _Unwind_Getipinfo