On 11/23/18 1:42 AM, Christian Ehrhardt
wrote:
As long as you have commit privileges, feel free to push once there is a Reviewed-by: (unless we are in freeze).
If it makes you feel any more confident about pushing - I had
personally expressed misgivings about this patch in IRC to Dan
because on first read it sounded like we might be exploiting a
security flaw in LXC to modify networking when it shouldn't
actually be allowed, but he convinced me that the situation isn't
that "bridge and tap device management via sysfs is blocked
because it should be, and ioctls are accidentally left enabled
when they should have been disabled", but rather that "bridge/tap
device management is acceptable in this situation, but sysfs is a
huge can of worms that can only be made read-only on a global
basis (and *must* be made read-only due to all the other things
that shouldn't be allowed in this case)". Based on that, I'm okay
with the patch as well.
|
Attachment:
pEpkey.asc
Description: application/pgp-keys
-- libvir-list mailing list libvir-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/libvir-list