Skip to content

Conversation

giuseppe
Copy link
Member

The find_first_rule_no_default function was modified to also check the simple case where there is only a default BLOCK ALL rule.

In addition, improve the function to skip to the first allow rule when the default BLOCK ALL rule is implicit.

Closes: #1597

The `find_first_rule_no_default` function was modified to also check
the simple case where there is only a default BLOCK ALL rule.

In addition, improve the function to skip to the first allow rule when
the default BLOCK ALL rule is implicit.

Closes: containers#1597

Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
@giuseppe
Copy link
Member Author

@saschagrunert @rhatdan PTAL

Copy link
Collaborator

@flouthoc flouthoc left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@giuseppe giuseppe merged commit 01830cb into containers:main Oct 31, 2024
57 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1.18.1 breaks podman --device

2 participants