[libvirt] [PATCHv3] lxc: give RW access to /proc/sys/net/ipv[46] to containers

Michal Privoznik mprivozn at redhat.com
Wed Dec 10 10:23:57 UTC 2014


On 10.12.2014 10:40, Cédric Bosdonnat wrote:
> Some programs want to change some values for the network interfaces
> configuration in /proc/sys/net/ipv[46] folders. Giving RW access on them
> allows wicked to work on openSUSE 13.2+.
>
> Reusing the lxcNeedNetworkNamespace function to tell
> lxcContainerMountBasicFS if the netns is disabled. When no netns is
> set up, then we don't mount the /proc/sys/net/ipv[46] folder RW as
> these would provide full access to the host NICs config.
> ---
>   Diff to v2:
>     * mount from /.oldroot as suggested by Dan... removed the whole temporary
>       mount related code as it turned out useless.
>
>   src/lxc/lxc_container.c | 64 +++++++++++++++++++++++++++++++------------------
>   1 file changed, 41 insertions(+), 23 deletions(-)

ACK and I think it's safe to push even during freeze.

Michal




More information about the libvir-list mailing list