iptable just "return" by uid as the parameter u indicates#6561
iptable just "return" by uid as the parameter u indicates#6561rshriram merged 2 commits intoistio:masterfrom
Conversation
|
/assign @mandarjog |
|
/ok-to-test |
|
@hklai Could you review this? |
|
@nmittler should be a better person to review this. |
|
@costinm should take a look as well |
|
@costinm I'm not sure the original intent of matching on the group. Is this something that we can safely remove? |
|
If group has to be an option,it is better to provide -g param separately |
costinm
left a comment
There was a problem hiding this comment.
I believe tproxy is using the gid ( and it happens that gid and uid are the same ).
The right fix would be to add an explicit {gid} param, with same default value as uid.
TPROXY will be needed long term ( when we add UDP for example).
Codecov Report
@@ Coverage Diff @@
## master #6561 +/- ##
=======================================
- Coverage 68% 68% -<1%
=======================================
Files 357 357
Lines 31304 31153 -151
=======================================
- Hits 21204 20994 -210
- Misses 9254 9318 +64
+ Partials 846 841 -5
Continue to review full report at Codecov.
|
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: nmittler, rokii Assign the PR to them by writing The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
/retest |
|
@rokii: The following test failed, say
DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
* Revert "Remove v2 transition commands since everything is now v2 (#6665)" This reverts commit 6339eb6. * Revert "Pilot param clusterRegistriesNamespace should default to pilot namespace (#6446)" This reverts commit b9294f7. * Revert "iptable just "return" by uid as the parameter u indicates (#6561)" This reverts commit 22a0b88. * Revert "Remove node agent service, residue from flexvolume driver. (#6651)" This reverts commit db3da82. * Revert "Continuously reapply galley CA bundle to prevent overwrite (#6599)" This reverts commit f9e8fd8. * Revert "Do not count typeConfigs if it is error. (#6527)" This reverts commit eb1de31. * Revert "Make racetest green - Fixed data races and flakiness (#6625)" This reverts commit 30b8ecb. * Revert "Improve push squashing (#6641)" This reverts commit 399cd2d.
* just intercept by uid as the parameter u indicates * add -g param to exclude proxy traffic from redirects
* Revert "Remove v2 transition commands since everything is now v2 (istio#6665)" This reverts commit 6339eb6. * Revert "Pilot param clusterRegistriesNamespace should default to pilot namespace (istio#6446)" This reverts commit b9294f7. * Revert "iptable just "return" by uid as the parameter u indicates (istio#6561)" This reverts commit 22a0b88. * Revert "Remove node agent service, residue from flexvolume driver. (istio#6651)" This reverts commit db3da82. * Revert "Continuously reapply galley CA bundle to prevent overwrite (istio#6599)" This reverts commit f9e8fd8. * Revert "Do not count typeConfigs if it is error. (istio#6527)" This reverts commit eb1de31. * Revert "Make racetest green - Fixed data races and flakiness (istio#6625)" This reverts commit 30b8ecb. * Revert "Improve push squashing (istio#6641)" This reverts commit 399cd2d.
resolve this #6557