mirror of
https://github.com/systemd/systemd
synced 2026-04-07 15:44:49 +02:00
Compare commits
No commits in common. "0da6973c17406f8ae222725e5d1ddd2f7d1c3b1e" and "fabf79b0dfb24d668a82b2fd70e73fcb8f575180" have entirely different histories.
0da6973c17
...
fabf79b0df
2
.github/dependabot.yml
vendored
2
.github/dependabot.yml
vendored
@ -5,5 +5,5 @@ updates:
|
|||||||
- package-ecosystem: "github-actions"
|
- package-ecosystem: "github-actions"
|
||||||
directory: "/"
|
directory: "/"
|
||||||
schedule:
|
schedule:
|
||||||
interval: "weekly"
|
interval: "daily"
|
||||||
open-pull-requests-limit: 2
|
open-pull-requests-limit: 2
|
||||||
|
|||||||
3
.github/workflows/codeql-analysis.yml
vendored
3
.github/workflows/codeql-analysis.yml
vendored
@ -5,8 +5,6 @@
|
|||||||
name: "CodeQL"
|
name: "CodeQL"
|
||||||
|
|
||||||
on:
|
on:
|
||||||
pull_request:
|
|
||||||
branches: [main]
|
|
||||||
# It takes the workflow approximately 30 minutes to analyze the code base
|
# It takes the workflow approximately 30 minutes to analyze the code base
|
||||||
# so it doesn't seem to make much sense to trigger it on every PR or commit.
|
# so it doesn't seem to make much sense to trigger it on every PR or commit.
|
||||||
# It runs daily at 01:00 to avoid colliding with the Coverity workflow.
|
# It runs daily at 01:00 to avoid colliding with the Coverity workflow.
|
||||||
@ -20,7 +18,6 @@ jobs:
|
|||||||
analyze:
|
analyze:
|
||||||
name: Analyze
|
name: Analyze
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
if: github.event_name == 'schedule' || github.event.pull_request.user.login == 'dependabot[bot]'
|
|
||||||
concurrency:
|
concurrency:
|
||||||
group: ${{ github.workflow }}-${{ matrix.language }}-${{ github.ref }}
|
group: ${{ github.workflow }}-${{ matrix.language }}-${{ github.ref }}
|
||||||
cancel-in-progress: true
|
cancel-in-progress: true
|
||||||
|
|||||||
2
.github/workflows/linter.yml
vendored
2
.github/workflows/linter.yml
vendored
@ -29,7 +29,7 @@ jobs:
|
|||||||
fetch-depth: 0
|
fetch-depth: 0
|
||||||
|
|
||||||
- name: Lint Code Base
|
- name: Lint Code Base
|
||||||
uses: github/super-linter@563be7dc5568017515b9e700329e9c6d3862f2b7
|
uses: github/super-linter@7d5dc989c55aaba9d3b7194a7496cdfaa4866af3
|
||||||
env:
|
env:
|
||||||
DEFAULT_BRANCH: main
|
DEFAULT_BRANCH: main
|
||||||
# Excludes:
|
# Excludes:
|
||||||
|
|||||||
@ -22,12 +22,10 @@ manager, please consider supporting the following interfaces.
|
|||||||
(that file overrides whatever is pre-initialized by the container manager).
|
(that file overrides whatever is pre-initialized by the container manager).
|
||||||
|
|
||||||
2. Make sure to pre-mount `/proc/`, `/sys/`, and `/sys/fs/selinux/` before
|
2. Make sure to pre-mount `/proc/`, `/sys/`, and `/sys/fs/selinux/` before
|
||||||
invoking systemd, and mount `/sys/`, `/sys/fs/selinux/` and `/proc/sys/`
|
invoking systemd, and mount `/proc/sys/`, `/sys/`, and `/sys/fs/selinux/`
|
||||||
read-only (the latter via e.g. a read-only bind mount on itself) in order
|
read-only in order to prevent the container from altering the host kernel's
|
||||||
to prevent the container from altering the host kernel's configuration
|
configuration settings. (As a special exception, if your container has
|
||||||
settings. (As a special exception, if your container has network namespaces
|
network namespaces enabled, feel free to make `/proc/sys/net/` writable).
|
||||||
enabled, feel free to make `/proc/sys/net/` writable. If it also has user, ipc,
|
|
||||||
uts and pid namespaces enabled, the entire `/proc/sys` can be left writable).
|
|
||||||
systemd and various other subsystems (such as the SELinux userspace) have
|
systemd and various other subsystems (such as the SELinux userspace) have
|
||||||
been modified to behave accordingly when these file systems are read-only.
|
been modified to behave accordingly when these file systems are read-only.
|
||||||
(It's OK to mount `/sys/` as `tmpfs` btw, and only mount a subset of its
|
(It's OK to mount `/sys/` as `tmpfs` btw, and only mount a subset of its
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user