-
Notifications
You must be signed in to change notification settings - Fork 1.1k
server: conditionally relabel volumes given annotation #5373
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
wip because I have vendored opencontainers/selinux#161 |
3e426c9 to
502f4e9
Compare
Codecov Report
@@ Coverage Diff @@
## main #5373 +/- ##
==========================================
- Coverage 43.75% 43.73% -0.02%
==========================================
Files 118 118
Lines 11737 11746 +9
==========================================
+ Hits 5135 5137 +2
- Misses 6114 6121 +7
Partials 488 488 |
502f4e9 to
8dd0250
Compare
pkg/annotations/annotations.go
Outdated
| OCISeccompBPFHookAnnotation = "io.containers.trace-syscall" | ||
|
|
||
| // MaybeSELinuxLabelAnnotation is the annotation used for optionally skipping relabeling a volume with the specified SELinux label. | ||
| // The label will not happen if the top layer is already labeled correctly. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
nit: s/The label will not happen /The relabeling will be skipped /
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM overall, let's just wait for opencontainers/selinux#161
8dd0250 to
b21561f
Compare
|
we don't technically need the SELinux commit, though it makes it safer. I've dropped and it can be included asynchronously |
|
@cri-o/cri-o-maintainers PTAL |
server/container_create_linux.go
Outdated
| // of the translation between CRI config -> oci/storage container in the container package | ||
|
|
||
| // TODO: eventually, this should be in the container package, but it's going through a lot of churn | ||
| // and SpecAddAnnotations is already passed too many arguments |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
nit of a nit, ignore unless you get other changes
| // and SpecAddAnnotations is already passed too many arguments | |
| // and SpecAddAnnotations is already passing too many arguments |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
updated
|
LGTM |
saschagrunert
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM, just one non blocking nit
pkg/annotations/annotations.go
Outdated
| // MaybeSELinuxLabelAnnotation is the annotation used for optionally skipping relabeling a volume with the specified SELinux label. | ||
| // The relabeling will be skipped if the top layer is already labeled correctly. | ||
| MaybeSELinuxLabelAnnotation = "io.kubernetes.cri-o.MaybeSELinuxLabel" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
non blocking nit because this may already been discussed: I would prefer having something more specific here like "io.kubernetes.cri-o.SkipSELinuxLabel" or "io.kubernetes.cri-o.SkipVolumeSELinuxLabel"
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
changed it to TrySkipSELinuxLabel
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
does that work for you? also wondering @kolyshkin 's thought
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Works for me, yes thank you!
8c0675d to
d1b16bb
Compare
|
/retest-required |
|
@haircommander: Overrode contexts on behalf of haircommander: ci/openshift-jenkins/integration_rhel DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
/retest-required Please review the full test history for this PR and help us cut down flakes. |
5 similar comments
|
/retest-required Please review the full test history for this PR and help us cut down flakes. |
|
/retest-required Please review the full test history for this PR and help us cut down flakes. |
|
/retest-required Please review the full test history for this PR and help us cut down flakes. |
|
/retest-required Please review the full test history for this PR and help us cut down flakes. |
|
/retest-required Please review the full test history for this PR and help us cut down flakes. |
|
/hold found a bug |
ce3cfaa to
551d78a
Compare
|
/unhold it works 🎉 |
Signed-off-by: Peter Hunt <[email protected]>
Signed-off-by: Peter Hunt <[email protected]>
551d78a to
87b8e5d
Compare
|
/override ci/openshift-jenkins/e2e_rhel |
|
@haircommander: Overrode contexts on behalf of haircommander: ci/openshift-jenkins/e2e_rhel, ci/openshift-jenkins/integration_rhel DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
mrunalp
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: haircommander, kolyshkin, mrunalp, saschagrunert The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/retest-required Please review the full test history for this PR and help us cut down flakes. |
2 similar comments
|
/retest-required Please review the full test history for this PR and help us cut down flakes. |
|
/retest-required Please review the full test history for this PR and help us cut down flakes. |
|
@haircommander: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
|
/override ci/openshift-jenkins/integration_rhel |
|
@haircommander: Overrode contexts on behalf of haircommander: ci/openshift-jenkins/integration_rhel DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
What type of PR is this?
/kind feature
What this PR does / why we need it:
Which issue(s) this PR fixes:
Special notes for your reviewer:
Does this PR introduce a user-facing change?