Files
nova/releasenotes/notes/privsep-queens-rootwrap-adds-907aa1bc8e3eb2ca.yaml
Michael Still c7dae4e19b Move nbd commands to privsep.
The same pattern as previous patches. Some of these unit tests
are starting to be a bit simpler as we finish the transition.

Change-Id: If0e1fe4c0466f2f88525dc575af2ef366d4bb59d
blueprint: hurrah-for-privsep
2017-10-24 18:50:34 +11:00

16 lines
623 B
YAML

---
upgrade:
- |
A sys-admin privsep daemon has been added and needs to be included in your
rootwrap configuration.
- |
Calls to mount in the virt disk api no longer ignore the value of stderr.
- |
The nova-idmapshift binary has been removed. This has been replaced by
internal functionality using privsep.
- |
The following commands are no longer required to be listed in your rootwrap
configuration: cat; chown; cryptsetup; dd; losetup; lvcreate; lvremove;
lvs; mkdir; mount; nova-idmapshift; ploop; prl_disk_tool; qemu-nbd;
readlink; shred; tee; touch; umount; vgs; and xend.