Skip to content

Commit 3f5a07c

Browse files
committed
validate: do not check NET_ADMIN with ip link add
Signed-off-by: Antonio Murdaca <[email protected]>
1 parent e7a6236 commit 3f5a07c

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

pkg/validate/security_context.go

+2-1
Original file line numberDiff line numberDiff line change
@@ -825,7 +825,8 @@ func createPrivilegedContainer(rc internalapi.RuntimeService, ic internalapi.Ima
825825

826826
// checkNetworkManagement checks the container's network management works fine.
827827
func checkNetworkManagement(rc internalapi.RuntimeService, containerID string, manageable bool) {
828-
cmd := []string{"ip", "link", "add", "dummy0", "type", "dummy"}
828+
//cmd := []string{"sh", "-c", "echo 1000 > /sys/class/net/lo/tx_queue_len"}
829+
cmd := []string{"brctl", "addbr", "foobar"}
829830

830831
stdout, stderr, err := rc.ExecSync(containerID, cmd, time.Duration(defaultExecSyncTimeout)*time.Second)
831832
msg := fmt.Sprintf("cmd %v, stdout %q, stderr %q", cmd, stdout, stderr)

0 commit comments

Comments
 (0)