-
Notifications
You must be signed in to change notification settings - Fork 225
libnetwork/rootlessnetns: set mount propagation to slave #2431
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
libnetwork/rootlessnetns: set mount propagation to slave #2431
Conversation
Reviewer's Guide by SourceryThis pull request changes the mount propagation for the rootless network namespace from No diagrams generated as the changes look simple and do not need a visual representation. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hey @Luap99 - I've reviewed your changes and they look great!
Here's what I looked at during the review
- 🟢 General issues: all looks good
- 🟢 Security: all looks good
- 🟢 Testing: all looks good
- 🟢 Complexity: all looks good
- 🟢 Documentation: all looks good
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
|
@giuseppe PTAL, I assume using slave propagation for this is right? |
giuseppe
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
We don't want to leak our mounts to the host but we still like to to update mounts/umount events from the host. This is so when a fs is unmounted on the host we don't happen to keep it open in aardvark-dns. Fixes: containers/podman#25994 Fixes: 4225302 ("libnetwork/rootlessnetns: make mountns tree private") Signed-off-by: Paul Holzinger <[email protected]>
ed211d9 to
066beed
Compare
giuseppe
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: giuseppe, Luap99, sourcery-ai[bot] The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
@mheon PTAL |
|
/lgtm |
We don't want to leak our mounts to the host but we still like to to update mounts/umount events from the host. This is so when a fs is unmounted on the host we don't happen to keep it open in aardvark-dns.
Fixes: containers/podman#25994
Fixes: 4225302 ("libnetwork/rootlessnetns: make mountns tree private")
Summary by Sourcery
Bug Fixes: