Repository navigation
Avoid noisy procfs errors in iptables detection - #589
penguineer wants to merge 1 commit into
Conversation
|
I believe this is the right change: it keeps the existing detection logic intact and only avoids calling I cannot fully test this in a Docker upstream development environment, though. I have only verified the original behavior on the affected DinD setup and reviewed the shell change itself. |
tianon
left a comment
There was a problem hiding this comment.
Simple, unobtrusive, and I've tested that it works correctly (originally this code used -s which is exactly what the cat + -n is emulating, but it turns out this simulated kernel filesystem doesn't report the filesize because it'd have to generate on-the-fly contents to do that, so -s/"is the filesize non-zero" doesn't work, but -r works correctly 👍)
Some optional /proc/net/*_tables_names files are absent when using the nftables backend. Check readability before calling cat so the expected absence does not produce misleading stderr output during normal DinD startup.
8983881 to
0ec19f6
Compare
|
(force-pushed to update the templated copies too, not just the template) |
This PR avoids misleading stderr output during normal DinD startup when optional
/proc/net/*_tables_namesfiles are absent.On systems using the nftables backend, files such as:
may not exist. The current probe calls
catunconditionally, which produces messages like:DinD then continues and starts normally.
The change adds a readability check to the existing conditional so
catis only called when the procfs entry is present/readable.This keeps the current detection logic intact while avoiding expected probe failures being emitted on stderr and subsequently classified as application errors by logging systems that use stdout/stderr as a severity signal.
Related: #524