[openstack-dev] [Nova] Moving the virt_mkfs flags to privsep
mikal at stillhq.com
Wed Nov 8 06:30:51 UTC 2017
That does work for me, except it means I'll still need to port it to
privsep to hit my goal of no rootwrap in Queens. I can live with that.
On Wed, Nov 8, 2017 at 4:54 PM, Matt Riedemann <mriedemos at gmail.com> wrote:
> On 11/8/2017 12:24 PM, Michael Still wrote:
>> a really really long time ago (think 2011), we added support in Nova for
>> configuring the mkfs commands that are run for new ephemeral disks using
>> the virt_mkfs command. The current implementation is in
>> nova/virt/disk/api.py for your reading pleasure.
>> I'm battling a little with how to move this code to privsep, because I
>> have resisted providing any method which just takes a command line and runs
>> it with escalated permissions, as I feel this defeats the purpose of
>> I could just pickup all the command line parsing code and move it into
>> privsep, but I am left wondering if anyone actually uses this
>> functionality, or if we should just deprecate it all?
>> I'd appreciate your thoughts.
>> OpenStack Development Mailing List (not for usage questions)
>> Unsubscribe: OpenStack-dev-request at lists.openstack.org?subject:unsubscrib
> Let's deprecate it, put a warning in the logs if it's used in Queens,
> deprecation release note and then remove it in Rocky.
> Does that work for you?
> OpenStack Development Mailing List (not for usage questions)
> Unsubscribe: OpenStack-dev-request at lists.openstack.org?subject:unsubscribe
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the OpenStack-dev