Skip to content

oci-containers: consolidate capabilities interface#363574

Merged
benley merged 2 commits intoNixOS:masterfrom
Yethal:capabilities-consolidation-for-oci
Dec 12, 2024
Merged

oci-containers: consolidate capabilities interface#363574
benley merged 2 commits intoNixOS:masterfrom
Yethal:capabilities-consolidation-for-oci

Conversation

@Yethal
Copy link
Contributor

@Yethal Yethal commented Dec 9, 2024

capAdd and capDrop were consolidated into a single capabilities option.

Things done

  • Built on platform(s)
    • x86_64-linux
    • aarch64-linux
    • x86_64-darwin
    • aarch64-darwin
  • For non-Linux: Is sandboxing enabled in nix.conf? (See Nix manual)
    • sandbox = relaxed
    • sandbox = true
  • Tested, as applicable:
  • Tested compilation of all packages that depend on this change using nix-shell -p nixpkgs-review --run "nixpkgs-review rev HEAD". Note: all changes have to be committed, also see nixpkgs-review usage
  • Tested basic functionality of all binary files (usually in ./result/bin/)
  • 25.05 Release Notes (or backporting 24.11 and 25.05 Release notes)
    • (Package updates) Added a release notes entry if the change is major or breaking
    • (Module updates) Added a release notes entry if the change is significant
    • (Module addition) Added a release notes entry if adding a new NixOS module
  • Fits CONTRIBUTING.md.

Add a 👍 reaction to pull requests you find important.

@github-actions github-actions bot added 6.topic: nixos Issues or PRs affecting NixOS modules, or package usability issues specific to NixOS 8.has: module (update) This PR changes an existing module in `nixos/` labels Dec 9, 2024
@github-actions github-actions bot added 10.rebuild-darwin: 0 This PR does not cause any packages to rebuild on Darwin. 10.rebuild-linux: 1-10 This PR causes between 1 and 10 packages to rebuild on Linux. labels Dec 9, 2024
@benley
Copy link
Member

benley commented Dec 9, 2024

I was initially opposed to this approach but now that I see it implemented it actually looks pretty reasonable. Let's see what others might have to say about it.

Improved wording

Co-authored-by: Benjamin Staffin <benley@zoiks.net>
@Yethal
Copy link
Contributor Author

Yethal commented Dec 9, 2024

@benley @roberth Can we backport this to 24.11?

Copy link
Member

@roberth roberth left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This matches what I had in mind in our discussion.
The behavior seems to be well covered by the tests, the documentation is clear, and it now supports overriding.
It also matches what Arion does (a docker compose wrapper), which is nice, and also means that it's a proven solution.

@wegank wegank added the 12.approvals: 1 This PR was reviewed and approved by one person. label Dec 10, 2024
@wegank wegank added 12.approvals: 2 This PR was reviewed and approved by two persons. and removed 12.approvals: 1 This PR was reviewed and approved by one person. labels Dec 10, 2024
@roberth
Copy link
Member

roberth commented Dec 11, 2024

@benley @roberth Can we backport this to 24.11?

It's a grey area, but I'd support it for these reasons

  • these two PRs are low risk
  • backporting these changes makes future backports of fixes easier

@benley benley merged commit 91bb1c6 into NixOS:master Dec 12, 2024
@Yethal Yethal deleted the capabilities-consolidation-for-oci branch December 12, 2024 17:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

6.topic: nixos Issues or PRs affecting NixOS modules, or package usability issues specific to NixOS 8.has: module (update) This PR changes an existing module in `nixos/` 10.rebuild-darwin: 0 This PR does not cause any packages to rebuild on Darwin. 10.rebuild-linux: 1-10 This PR causes between 1 and 10 packages to rebuild on Linux. 12.approvals: 2 This PR was reviewed and approved by two persons.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants