Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

@saschagrunert
Copy link
Member

What type of PR is this?

/kind feature

What this PR does / why we need it:

If a container or pod specifies the SELinux type spc_t, then we skip
the volume relabel.

Cherry-picked: 13182e6

Which issue(s) this PR fixes:

Refers to #5386

Special notes for your reviewer:

@cri-o/cri-o-maintainers PTAL

Does this PR introduce a user-facing change?

Skip SELinux volume relabeling for super privileged containers (`securityContext.seLinuxOptions.type = "spc_t"`).

@openshift-ci openshift-ci bot added release-note Denotes a PR that will be considered when it comes time to generate release notes. dco-signoff: yes Indicates the PR's author has DCO signed all their commits. kind/feature Categorizes issue or PR as related to a new feature. labels Oct 19, 2021
@openshift-ci
Copy link
Contributor

openshift-ci bot commented Oct 19, 2021

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: saschagrunert

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci bot requested review from sameo and vrothberg October 19, 2021 07:43
@openshift-ci openshift-ci bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Oct 19, 2021
@saschagrunert saschagrunert force-pushed the release-1.20-spc_t-relabel-skip branch 2 times, most recently from a066dd6 to ae7e601 Compare October 19, 2021 07:44
@haircommander haircommander force-pushed the release-1.20-spc_t-relabel-skip branch from ae7e601 to 1dd9079 Compare October 20, 2021 19:43
If a container or pod specifies the SELinux type `spc_t`, then we skip
the volume relabel.

Cherry-picked: 13182e6
Signed-off-by: Sascha Grunert <[email protected]>
@haircommander haircommander force-pushed the release-1.20-spc_t-relabel-skip branch from 1dd9079 to 8475160 Compare October 20, 2021 19:59
@haircommander
Copy link
Member

/retest

@haircommander
Copy link
Member

/lgtm

@openshift-ci openshift-ci bot added the lgtm Indicates that a PR is ready to be merged. label Oct 21, 2021
@openshift-merge-robot openshift-merge-robot merged commit e80c8db into cri-o:release-1.20 Oct 21, 2021
@saschagrunert saschagrunert deleted the release-1.20-spc_t-relabel-skip branch October 21, 2021 14:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. dco-signoff: yes Indicates the PR's author has DCO signed all their commits. kind/feature Categorizes issue or PR as related to a new feature. lgtm Indicates that a PR is ready to be merged. release-note Denotes a PR that will be considered when it comes time to generate release notes.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants