-
Notifications
You must be signed in to change notification settings - Fork 2.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[CI:DOCS] Add SELinux information about boolean for using random devices #15937
Conversation
@giuseppe PTAL |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
@@ -12,3 +12,11 @@ The <<container|pod>> will only store the major and minor numbers of the host de | |||
Podman may load kernel modules required for using the specified | |||
device. The devices that Podman will load modules for when necessary are: | |||
/dev/fuse. | |||
|
|||
In rootless mode, the new device is bind mounted in the container from the host | |||
rather then Podman creating it within the container space. Because the bind |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
rather than, not then.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I get this wrong 100% of the time, and I can not fix my brain.
|
||
In rootless mode, the new device is bind mounted in the container from the host | ||
rather then Podman creating it within the container space. Because the bind | ||
mount retains it's SELinux label on SELinux systems, the container can get |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
No apostrophe in its.
@@ -12,3 +12,11 @@ The <<container|pod>> will only store the major and minor numbers of the host de | |||
Podman may load kernel modules required for using the specified | |||
device. The devices that Podman will load modules for when necessary are: | |||
/dev/fuse. | |||
|
|||
In rootless mode, the new device is bind mounted in the container from the host |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
One more: this option is also used in podman-build.1
. Does this text apply to podman-build
? (My impression is yes, it does, but please confirm).
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes it does.
Fixes: containers#15930 Signed-off-by: Daniel J Walsh <[email protected]>
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: edsantiago, giuseppe, rhatdan The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Fixes: #15930
Signed-off-by: Daniel J Walsh [email protected]
Does this PR introduce a user-facing change?