-
Notifications
You must be signed in to change notification settings - Fork 106
Add the container_signull() interface #431
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Reviewer's guide (collapsed on small PRs)Reviewer's GuideAdds a new container_signull() interface to the container.if policy interface file, likely exposing a new permission or helper macro for signaling with null or checking signal permissions. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
Summary of ChangesHello @zpytela, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request enhances the SELinux policy by adding a new interface, Highlights
🧠 New Feature in Public Preview: You can now enable Memory to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console. Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here. You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension. Footnotes
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Code Review
This pull request introduces a new SELinux interface, container_signull, which allows a specified domain to send null signals to container processes. The implementation is correct, but the documentation for the new interface contains a misleading parameter name. My feedback includes a suggestion to correct this for better clarity and maintainability.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
9e89f8f to
2386592
Compare
|
Ephemeral COPR build failed. @containers/packit-build please check. |
2 similar comments
|
Ephemeral COPR build failed. @containers/packit-build please check. |
|
Ephemeral COPR build failed. @containers/packit-build please check. |
|
Tests failed. @containers/packit-build please check. |
lsm5
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is there any issue that could be referenced here?
Requesting changes for DCO.
|
Needed for fedora-selinux/selinux-policy#3007 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM pending sign-off for DCO.
|
@zpytela kinda-sorta related, would a |
|
That's a part of the current workflow, we use the latest container.if during selinux-policy build. |
Signed-off-by: Zdenek Pytela <zpytela@redhat.com>
2386592 to
caa0495
Compare
That would be an option if container-selinux-devel existed - do you really plan to split the package? It's size is 70K. |
lsm5
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
@haircommander @rhatdan PTAL
Shouldn't be a big deal either way. Right now container-selinux doesn't ship any source files in rpm.
Alright, I'll leave this be for now in that case. |
since 581898d
OK, thanks. |
Summary by Sourcery
Introduce the new container_signull() interface in the container.if policy interface file.