-
Notifications
You must be signed in to change notification settings - Fork 113
device: Do not allow container access to the nvdimm rootfs #792
device: Do not allow container access to the nvdimm rootfs #792
Conversation
/test |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
thanks @amshinde - just one comment
device.go
Outdated
@@ -50,6 +50,7 @@ var ( | |||
getPCIDeviceName = getPCIDeviceNameImpl | |||
getDevicePCIAddress = getDevicePCIAddressImpl | |||
scanSCSIBus = scanSCSIBusImpl | |||
rootfsNvdimmDisk = "/dev/pmem0p1" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think there is a different way to get the rootfs device
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@devimc PR updated. PTAL
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
thanks
Codecov Report
@@ Coverage Diff @@
## master #792 +/- ##
==========================================
+ Coverage 60.26% 60.45% +0.18%
==========================================
Files 17 17
Lines 2640 2655 +15
==========================================
+ Hits 1591 1605 +14
- Misses 890 891 +1
Partials 159 159 |
With this change, a container is not longer given access to the underlying nvdimm root partition. This is done by explicitly adding the nvdimm root partition to the device cgroup of the container. Fixes kata-containers#791 Signed-off-by: Archana Shinde <archana.m.shinde@intel.com>
75e275f
to
a88af32
Compare
/test |
restarting ubuntu CI |
With this change, a container is not longer given access to
the underlying nvdimm root partition.
This is done by explicitly adding the nvdimm root partition
to the device cgroup of the container.
Fixes #791
Signed-off-by: Archana Shinde archana.m.shinde@intel.com