Repository navigation
Make HTTP support optional at compile time - #281
Open
congwang-mk wants to merge 3 commits into
Open
congwang-mk wants to merge 3 commits into
congwang-mk wants to merge 3 commits into
Conversation
More than half of sandlock-core's dependency graph (hyper, rustls, rcgen, bollard and what they pull in) exists only for the HTTP ACL proxy, credential injection and pulling images from a registry or the Docker daemon. Users who only need the syscall sandbox want to build without it, the way a kernel config drops subsystems it does not use. The http feature is on by default, so nothing changes unless a build opts out. Without it, a stub module stands in for the proxy and for credential injection, so call sites need no cfg, and the builder refuses any HTTP option rather than dropping a network restriction without a word. Networked image references fail with the same error, while oci: and oci-archive: images keep working. Signed-off-by: Cong Wang <cwang@multikernel.io>
Each crate took sandlock-core with its default features, so a build of the CLI, the C library or the OCI shim could never leave the HTTP stack out. They now depend on the core without defaults and expose the same http feature, on by default. learn always installed an HTTP request logger, which needs the proxy, so without the feature it would fail at policy build. It now records everything but HTTP requests in that case, and the tests that check HTTP capture only run when the feature is enabled. Signed-off-by: Cong Wang <cwang@multikernel.io>
The existing jobs only build the default feature set, so a cfg slip in the minimal build would go unnoticed. The new job asserts the minimal build pulls in no HTTP stack and runs the full test suite without the http feature. Signed-off-by: Cong Wang <cwang@multikernel.io>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Validation