-
Notifications
You must be signed in to change notification settings - Fork 29
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Selinux: Allow qm_t to mmap qm_file_t char devices #742
Conversation
Reviewer's Guide by SourceryThis pull request adds a rule to the SELinux policy that allows processes running in the No diagrams generated as the changes look simple and do not need a visual representation. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hey @alexlarsson - I've reviewed your changes - here's some feedback:
Overall Comments:
- Could you add a comment to the code explaining why this change is considered safe?
Here's what I looked at during the review
- 🟢 General issues: all looks good
- 🟢 Security: all looks good
- 🟢 Testing: all looks good
- 🟢 Complexity: all looks good
- 🟢 Documentation: all looks good
Help me be more useful! Please click 👍 or 👎 on each comment and I'll use the feedback to improve your reviews.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@alexlarsson please apply that one
https://github.com/containers/qm/pull/742/checks?check_run_id=38092074076
This allows qm apps to mmap /dev/zero which is a common operation, and should be safe. Fixes: #741 Signed-off-by: Alexander Larsson <[email protected]>
2d8dd15
to
05cfa40
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
This allows qm apps to mmap /dev/zero which is a common operation, and should be safe.
Fixes: #741
Summary by Sourcery
Bug Fixes: