-
Notifications
You must be signed in to change notification settings - Fork 302
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
crun: write setgroups=deny when mapping a single uid/gid #1089
Conversation
919d207
to
32a2a7c
Compare
@@ -2868,6 +2887,7 @@ libcrun_set_usernamespace (libcrun_container_t *container, pid_t pid, libcrun_er | |||
} | |||
|
|||
single_mapping = format_mount_mapping (container->container_uid, container->host_uid, 1, &single_mapping_len, true); | |||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
spurious change
32a2a7c
to
3dcac98
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM comment https://github.com/containers/crun/pull/1089/files#r1042260747 is still unresolved though
Ah, I replied on that comment in the wrong place: I included the whitespace change to align the gid case with the uid case, where there is an additional newline: Lines 2836 to 2838 in 2700598
Lines 2870 to 2871 in 2700598
... but I can just remove that if you prefer. |
you need to run |
3dcac98
to
ed1dbe8
Compare
Done. |
@lsm5 fedora-rawhide-mockbuild is failing |
nit, if you are going to re-push, could you make the first line shorter in the commit message (e.g. |
tests failures do not depend on this PR. It seems github moved to cgroup v2, opened a PR: #1090 |
ed1dbe8
to
eb79f1e
Compare
could you please rebase on top of main? |
Signed-off-by: Tim Besard <tim.besard@gmail.com>
eb79f1e
to
5e3ef32
Compare
Sure; done. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Closes #1088
cc @giuseppe