-
Notifications
You must be signed in to change notification settings - Fork 1.1k
Fix RuntimeDefault seccomp behavior if disabled #4789
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix RuntimeDefault seccomp behavior if disabled #4789
Conversation
Codecov Report
@@ Coverage Diff @@
## master #4789 +/- ##
==========================================
- Coverage 43.02% 43.02% -0.01%
==========================================
Files 107 107
Lines 9773 9774 +1
==========================================
Hits 4205 4205
- Misses 5114 5115 +1
Partials 454 454 |
|
/hold |
|
/hold cancel Everything is fine. |
459a472 to
05187cc
Compare
The internal seccomp profile (`RuntimeDefault`) should be ignored in the same way as it was before using the new field. This aligns the implementation with CRI-O releases before v1.21.0. Signed-off-by: Sascha Grunert <[email protected]>
05187cc to
675dead
Compare
|
/retest LGTM |
|
@haircommander: once the present PR merges, I will cherry-pick it on top of release-1.21 in a new PR and assign it to you. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
/override ci/prow/e2e-agnostic |
|
@saschagrunert: Overrode contexts on behalf of saschagrunert: ci/prow/e2e-agnostic DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
LGTM |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: haircommander, mrunalp, saschagrunert The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/lgtm |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
2 similar comments
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
17 similar comments
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
@saschagrunert: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
1 similar comment
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/override ci/prow/e2e-gcp |
|
@saschagrunert: Overrode contexts on behalf of saschagrunert: ci/prow/e2e-gcp DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
/cherry-pick release-1.21 |
|
@haircommander: new pull request created: #4819 DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
What type of PR is this?
/kind bug
What this PR does / why we need it:
The internal seccomp profile (
RuntimeDefault) should be ignored in thesame way as it was before using the new field. This aligns the
implementation with CRI-O releases before v1.21.0.
Which issue(s) this PR fixes:
Fixes #4786
Special notes for your reviewer:
The bug comes up because
SecurityProfileTypeRuntimeDefault == 0(the default value if the field is not set)Does this PR introduce a user-facing change?