New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
policy: Add a bpf compiling option when enable-icmp-rules
flag is set
#17620
Conversation
enable-icmp-rules
flag setenable-icmp-rules
flag is set
ff20f84
to
7b0c0d4
Compare
enable-icmp-rules
flag is setenable-icmp-rules
flag is set
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the fix. Just one comment below, usually we we define these in the headerfiles instead of passing additional arguments directly to the compiler. Would be good to keep that consistent.
7b0c0d4
to
88558aa
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM, thanks.
I'm seeing Image CI builds fail, example: https://github.com/cilium/cilium/actions/runs/1362491757 These errors do not look related to the PR. I'll close/reopen the PR to see if that retriggers the CI correctly. |
Looks like the github image build actions are still failing. I've raised a thread on Slack to follow up on this, since it still doesn't look related to your PR. |
@chez-shanpu can you rebase your PR against the latest master tree? It looks like this is what is causing the image build failures. |
Oh, one more thing - Does this mean that we don't currently have tests for this functionality? Otherwise we could have maybe found this out earlier. |
By this commit, bpf program is compiled with `-DENABLE_ICMP_RULE` option when `enable-icmp-rules` flag is set. Signed-off-by: Tomoki Sugiura <tomoki.sugiura@mail.shanpu.info>
88558aa
to
ddbab5c
Compare
Yes. |
Given the code is not covered by CI, I think it's fine to merge this as-is. I would welcome followup to add coverage for this feature to CI somehow. |
Okay, I would open another PR (or use existing PR #17135) when I add an e2e test for this function. |
By this commit, bpf program is compiled with
-DENABLE_ICMP_RULE
option whenenable-icmp-rules
flag is set.Signed-off-by: Tomoki Sugiura tomoki.sugiura@mail.shanpu.info