[Bug 1758380] Re: unpriveleged containers no longer could start due to start.c: lxc_spawn: 1555 Failed initializing cgroup support

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxc (Ubuntu) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1758380 Title: unpriveleged containers no longer could start due to start.c:

[Bug 1556110] Re: package lxc (not installed) failed to install/upgrade: 子程序 已安裝的 post-installation script 傳回了錯誤退出狀態 1

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxc (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1556110 Title: package lxc (not installed) failed to install/upgrade: 子程序 已安裝的 post-

[Bug 1594751] Re: lxc-ls doesn't show nested containers when using an alternate lxc path

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
Is that still an issue with the modern lxc-ls (3.x or higher)? ** Changed in: lxc (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1594751 Title: lxc-ls

[Bug 1527374] Re: CVE-2015-8709

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** No longer affects: lxc (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1527374 Title: CVE-2015-8709 To manage notifications about this bug go to:

[Bug 1511197] Re: PCI Device Access Through /proc/

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxc (Ubuntu) Status: Triaged => Fix Released ** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1511197 Title: PCI

[Bug 1586608] Re: Can not start nested trusty container inside trusty container

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
trusty is EOL, cgmanager/cgproxy are dead and nesting works way better now thanks to cgroup namespaces. ** Changed in: lxc (Ubuntu) Status: New => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1590547] Re: LXC package for trusty no longer has configuration files

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxc (Ubuntu) Status: Confirmed => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1590547 Title: LXC package for trusty no longer has configuration files To manage

[Bug 1472929] Re: undefined symbol: cgmanager_get_pid_cgroup_abs_sync

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxc (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1472929 Title: undefined symbol: cgmanager_get_pid_cgroup_abs_sync To manage notifications

[Bug 1548497] Re: Cross-Container ARP Poisoning

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
As LXC doesn't directly manage bridges, we don't expect to do anything there, instead you can use network up/down hooks to manually setup filtering. LXD which does manage networks has support for ipv4, ipv6 and mac filtering on container interfaces. ** Changed in: lxc (Ubuntu) Status: New

[Bug 1521151] Re: init: lxc-instance main process terminated with status 255

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
trusty is EOL and upstart is unsupported at this time. ** Changed in: lxc (Ubuntu) Status: New => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1521151 Title: init: lxc-instance

[Bug 1537939] Re: apparmor profile for /var/lib/lxd denies mount operation on container creation

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxc (Ubuntu) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1537939 Title: apparmor profile for /var/lib/lxd denies mount operation on

[Bug 1537689] Re: ubuntu template fro lxc messes up proxies

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
We don't ship those templates anymore, instead relying on pre-made images which will not have any proxy set in them. ** Changed in: lxc (Ubuntu) Status: New => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1542438] Re: Python LXC api needs to be much better at error reporting

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxc (Ubuntu) Status: New => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1542438 Title: Python LXC api needs to be much better at error reporting To manage

[Bug 1359224] Re: Feature request: Add support for multiple bridges

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxc (Ubuntu) Status: New => Triaged ** Changed in: lxc (Ubuntu) Importance: Undecided => Wishlist -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1359224 Title: Feature

[Bug 1544157] Re: lxc exec not working in xenial

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxc (Ubuntu) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1544157 Title: lxc exec not working in xenial To manage notifications about

[Bug 1533244] Re: lxc-net thinks it's already running after it failed

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
Can someone check if that's still the case on something recent (3.x or 4.x)? ** Changed in: lxc (Ubuntu) Status: New => Incomplete ** Changed in: lxc (Ubuntu) Importance: Undecided => Low -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1532069] Re: Can't create a container with a loop backing store in 1.0.8

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
Has anyone seen this on something recent? Say LXC 3.x or 4.x? ** Changed in: lxc (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1532069 Title: Can't create

[Bug 1445539] Re: Can't create vivid lxc on trusty

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
We're now relying on lxc-download which doesn't have such problems. A backported version of lxc in trusty will work fine, though trusty is eol now. ** Changed in: lxc (Ubuntu) Status: Confirmed => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs,

[Bug 1436722] Re: lxc domain setup instructions are incorrect

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxc (Ubuntu) Status: New => Triaged ** Changed in: lxc (Ubuntu) Importance: Undecided => Low -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1436722 Title: lxc domain setup

[Bug 1441307] Re: lxc-clone makes new copies of each hardlinked file

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
Looking at the current LXC code, "-H" is part of our rsync flags now. ** Changed in: lxc (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1441307 Title:

[Bug 1548731] Re: autostart on boot not working

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
This is fixed in modern versions of LXC using systemd. ** Changed in: lxc (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1548731 Title: autostart on boot

[Bug 1519228] Re: Drop obsolete dh_installinit --upstart-only option

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxc (Ubuntu) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1519228 Title: Drop obsolete dh_installinit --upstart-only option To manage

[Bug 1510108] Re: pre-installed lxc in cloud-image means loss of access to 10.0.X.0/24

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** No longer affects: lxc (Ubuntu Wily) ** No longer affects: lxc (Ubuntu Xenial) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1510108 Title: pre-installed lxc in cloud-image means loss of access

[Bug 1530617] Re: FUSE in wily image with upstart installed causes chaos

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxc (Ubuntu) Status: Confirmed => Invalid ** Changed in: upstart (Ubuntu) Status: New => Won't Fix ** Changed in: linux (Ubuntu) Status: Incomplete => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed

[Bug 1452601] Re: vivid container's networking.service fails on boot with signal=PIPE

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxc (Ubuntu) Status: Confirmed => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1452601 Title: vivid container's networking.service fails on boot with signal=PIPE

[Bug 1184936] Re: lxc-clone freezes if copied container is running [12.04 kernel 3.8]

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxc (Ubuntu) Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1184936 Title: lxc-clone freezes if copied container is running [12.04 kernel 3.8]

[Bug 1475751] Re: need phablet support for mods to /etc/lxc/lxc-usernet (vivid+stable ppa overaly)

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxc (Ubuntu) Status: Triaged => Won't Fix ** Changed in: canonical-devices-system-image Status: Confirmed => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1475751

[Bug 1396536] Re: lxc_start - Exec format error - failed to exec /sbin/init

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
We've not seen any other issue like this in the past 5 years, users usually know to pick something that they can actually run or know that they'll need to setup emulation. The error reported as weird as it is, is the expected behavior from the kernel when asked to run a foreign architecture

[Bug 1450960] Re: dev file system is mounted without nosuid

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
Marking as triaged/wishlist for LXC, I can't think of a good reason not to mount with nosuid so such a patch would still be welcome. ** Changed in: lxc (Ubuntu) Status: Confirmed => Triaged -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed

[Bug 1389864] Re: /etc/dnsmasq.d-available/lxc has no effect on a NetworkManager system

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxc (Ubuntu) Status: Confirmed => Triaged -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1389864 Title: /etc/dnsmasq.d-available/lxc has no effect on a NetworkManager system

[Bug 1319525] Re: juju-local LXC containers hang due to AppArmor denial of rpc_pipefs mount with local charms

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
Been incomplete for years, closing. ** Changed in: lxc (Ubuntu) Status: Incomplete => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1319525 Title: juju-local LXC containers hang due

[Bug 1289482] Re: "iscsiadm discovery" succeeds but "iscsiadm login" fails inside ubuntu container.

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
I'm pretty sure we've completely disabled iscsid inside containers at this point due to its tight link to un-namespaced kernel features. Some specific server use cases should be possible, but anything client related is unlikely to succeed without some major kernel work. ** Changed in: lxc

[Bug 1266808] Re: No mechanism to wait until a started container is ready and has finished booting

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
After years of running LXC and LXD, this is a somewhat recurring topic which has no good answers, all distros do it differently and the definition of ready differs even user to user. So from LXC's point of view, it's best to stay away from this and instead have users actually check for what they

[Bug 1204662] Re: Language pack installation should be optional in ubuntu templates

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
We've moved away from those template scripts and are instead mostly relying on pre-made images. If building your own image through distrobuilder, you can add any additional packages you want at image building time. ** Changed in: lxc (Ubuntu) Status: Triaged => Won't Fix -- You

[Bug 1182458] Re: ubuntu-cloud template: use simplestreams to add integrity verification

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
The current donwload template model to download those images does do both https and gpg validation. ** Changed in: lxc (Ubuntu) Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1043004] Re: --bindhome option should be on lxc-create, not on lxc-ubuntu

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
With current LXC, those templates aren't really a thing anymore and most of our users use unprivileged containers which require quite a bit more involved configuration to pass a host directory than just injecting a mount entry. If this is a useful pattern for a user, writing a dedicated ".conf"

[Bug 1698868] Re: /usr/bin/lxcfs:11:find_mounted_controller:cgfs_get_key:fc_may_access:cg_opendir:do_cg_opendir

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxcfs (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1698868 Title:

[Bug 1860813] Re: LXC container reports spike in swap occasionally

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxcfs (Ubuntu) Status: New => Incomplete ** Changed in: lxcfs (Ubuntu) Status: Incomplete => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1860813 Title:

[Bug 1748790] Re: LXCFS upgrade request

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxcfs (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1748790 Title: LXCFS upgrade request To manage notifications about this bug go to:

[Bug 1807628] Re: segfault at 0 ip 00007fe70ae4e3b2 sp 00007fe70884fb70 error 4 in liblxcfs.so[7fe70ae46000+f000]

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxcfs (Ubuntu) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1807628 Title: segfault at 0 ip 7fe70ae4e3b2 sp 7fe70884fb70 error 4

[Bug 1868572] Re: [MIR] lxd-agent-loader

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
And uploaded the updated ubuntu-meta. Marking Fix released as the package is now in main. ** Changed in: lxd-agent-loader (Ubuntu) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1868572] Re: [MIR] lxd-agent-loader

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
Promoting to main now before I can update ubuntu-meta for the seed change: Override component to main lxd-agent-loader 0.3 in focal: universe/admin -> main lxd-agent-loader 0.3 in focal amd64: universe/misc/optional/100% -> main lxd-agent-loader 0.3 in focal arm64: universe/misc/optional/100% ->

[Bug 1868572] Re: [MIR] lxd-agent-loader

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
https://code.launchpad.net/~stgraber/ubuntu- seeds/+git/ubuntu/+merge/381171 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1868572 Title: [MIR] lxd-agent-loader To manage notifications about this

[Bug 1868572] Re: [MIR] lxd-agent-loader

2020-03-25 Thread Stéphane Graber via ubuntu-bugs
- "further confinement would be nice to have" This service is used to implement both the "lxc file" set of commands and the "lxc exec" set of commands. As such it needs to be able to read and write every file on the system and must be allowed to spawn unconfined commands. I don't see how either

[Bug 1867541] Re: [FFe] LXCFS 4.0 LTS

2020-03-24 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxcfs (Ubuntu) Status: Confirmed => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1867541 Title: [FFe] LXCFS 4.0 LTS To manage notifications about this bug go

[Bug 1868174] Re: [FFe] mstflint: enable mstreg command

2020-03-24 Thread Stéphane Graber via ubuntu-bugs
Package is in universe and not seeded so potential impact is minimal and this seems like a valuable small change for those using that hardware. FFe granted. ** Changed in: mstflint (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu

[Bug 1868281] Re: Please remove php-horde and php-horde-* from focal

2020-03-23 Thread Stéphane Graber via ubuntu-bugs
stgraber@castiana:~/data/code/ubuntu-archive/ubuntu-archive-tools$ for i in $(cat ~/removal/list); do ./remove-package -m "tests fail with php7.4, removal of php-horde stack. LP: #1868281" -s focal $i -y; done Removing packages from focal: php-horde-argv 2.1.0-1ubuntu1 in focal

[Bug 1868272] Re: FFe: bind9 9.16.1 update

2020-03-23 Thread Stéphane Graber via ubuntu-bugs
FFe granted, this feels more like a bugfix than a feature to me. So certainly fine to do for focal. ** Changed in: bind9 (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1868572] [NEW] [MIR] lxd-agent-loader

2020-03-23 Thread Stéphane Graber via ubuntu-bugs
Public bug reported: Availability: Currently in universe Rationale: LXD now supports virtual machines. In order for all features to work properly, an agent must be running in the image. As Ubuntu is a first class citizen in LXD, we'd like Ubuntu to ship with the integration bits needed to

[Bug 1867541] Re: [FFe] LXCFS 4.0 LTS

2020-03-22 Thread Stéphane Graber via ubuntu-bugs
4.0.1 has been released on Thursday with a number of fixes we came up with following the 4.0.0 rollout to our snap users. This is the release we'd be pushing into focal. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1867541] Re: [FFe] LXCFS 4.0 LTS

2020-03-22 Thread Stéphane Graber via ubuntu-bugs
https://discuss.linuxcontainers.org/t/lxcfs-4-0-1-lts-has-been- released/7130 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1867541 Title: [FFe] LXCFS 4.0 LTS To manage notifications about this

[Bug 1858801] Re: lxd ADT failure on Bionic with linux-raspi2-5.3 arm64

2020-03-21 Thread Stéphane Graber via ubuntu-bugs
*** This bug is a duplicate of bug 1849530 *** https://bugs.launchpad.net/bugs/1849530 ** This bug has been marked a duplicate of bug 1849530 lxd 3.0.3-0ubuntu1~18.04.1 ADT test failure on arm64 -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1833435] Re: RFC: Add url/urls/mirrors attribute for product items

2020-03-21 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxd (Ubuntu) Status: New => Triaged ** Changed in: lxd (Ubuntu) Importance: Undecided => Wishlist -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1833435 Title: RFC: Add

[Bug 1852148] Re: lxd 3.0.3-0ubuntu1~18.04.1 ADT test failure with bionic linux-hwe 5.0.0-34.36~18.04.1

2020-03-21 Thread Stéphane Graber via ubuntu-bugs
*** This bug is a duplicate of bug 1849530 *** https://bugs.launchpad.net/bugs/1849530 ** This bug has been marked a duplicate of bug 1849530 lxd 3.0.3-0ubuntu1~18.04.1 ADT test failure on arm64 -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1849530] Re: arm64 clustering hitting timeout (ADT failure)

2020-03-21 Thread Stéphane Graber via ubuntu-bugs
** Summary changed: - lxd 3.0.3-0ubuntu1~18.04.1 ADT test failure on arm64 + arm64 clustering hitting timeout (ADT failure) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1849530 Title: arm64

[Bug 1849530] Re: lxd 3.0.3-0ubuntu1~18.04.1 ADT test failure on arm64

2020-03-21 Thread Stéphane Graber via ubuntu-bugs
3.0.5 should be a bit more stable in that regard, when we get around to pushing it. Until then, yes, armhf/arm64 will tend to be a bit more racy due to slow crypto on some CPUs. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1829071] Re: Privilege escalation via LXD (local root exploit)

2020-03-21 Thread Stéphane Graber via ubuntu-bugs
For the deb we won't be changing the logic at this point and it's in line with what's done for libvirt, changing behavior at this point would cause more harm than good. For the snap, we don't auto-add users and as mentioned earlier, have updated our various documentations (those we maintain

[Bug 1828905] Re: go gnupg/clearsign issues

2020-03-21 Thread Stéphane Graber via ubuntu-bugs
LXD does not use clearsign. ** Changed in: lxd (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1828905 Title: go gnupg/clearsign issues To manage

[Bug 1712808] Re: udev interface fails in privileged containers

2020-03-21 Thread Stéphane Graber via ubuntu-bugs
At the last engineering sprint, Zygmunt on the snapd team indicate that this was or would soon be sorted out in snapd. ** Changed in: lxd (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1834501] Re: do-release-upgrade from bionic->any disables lxd without snapstore access

2020-03-21 Thread Stéphane Graber via ubuntu-bugs
** Changed in: lxd (Ubuntu) Status: Confirmed => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1834501 Title: do-release-upgrade from bionic->any disables lxd without snapstore

[Bug 1840428] Re: LXD has new LTS version 3.0.4

2020-03-21 Thread Stéphane Graber via ubuntu-bugs
We're quite aware since we're the ones who released it :) However 3.0.4 didn't feel like enough of an improvement at the time to justify the amount of work needed to push it to updates. Especially not when it's already readily available as a snap. Instead our plan is to jump straight to 3.0.5

[Bug 1851986] Re: LXD upgrade problem with existing container

2020-03-21 Thread Stéphane Graber via ubuntu-bugs
`raw.lxc` is a "use at your own risk" option which you can use to directly configure things outside of LXD's control. The upgrade from liblxc 2.0 to 3.0 came with backward incompatible config changes which indeed would hit those users directly using that key. We certainly don't want LXD to have

[Bug 1844562] Re: lxd cluster containers arbitrarily change ip address

2020-03-21 Thread Stéphane Graber via ubuntu-bugs
If connect to MAAS, then LXD has no influence on the container's IP whatsoever. All that LXD does in such a setup is bridge the container's network interface to the physical network. All IP allocation is then handled by MAAS. ** Changed in: lxd (Ubuntu) Status: New => Invalid -- You

[Bug 1850667] Re: cgroup v2 is not fully supported yet, proceeding with partial confinement

2020-03-21 Thread Stéphane Graber via ubuntu-bugs
LXD, LXCFS and LXC all have cgroupv2 support now. It's certainly not perfect and things like CRIU (lxc-checkpoint) will not work until such time as cgroupv2 support is fully on part in the kernel with cgroupv1 and the needed additional interfaces are added to projects like CRIU. But for normal

[Bug 1844663] Re: lxc list run via sudo creates root-owned files in the user's home directory

2020-03-21 Thread Stéphane Graber via ubuntu-bugs
Marking as invalid for LXD. This is a question of how you're using or configuring sudo. ** Changed in: lxd (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1844663

[Bug 1852156] Re: package lxd 3.0.3-0ubuntu1~18.04.1 failed to install/upgrade: new lxd package pre-installation script subprocess returned error exit status 1

2020-03-21 Thread Stéphane Graber via ubuntu-bugs
The latest version of the upgrade script allows for skipping in such cases. ** Changed in: lxd (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1852156

[Bug 1860859] Re: package lxd 3.0.3-0ubuntu1~18.04.1 failed to install/upgrade: new lxd package pre-installation script subprocess returned error exit status 1

2020-03-21 Thread Stéphane Graber via ubuntu-bugs
Looks like this happened inside a privileged LXD container, or at least the snapd error matches what you'd get in such a case. The issue is in snapd and has been resolved recently. If such an error occurs, re-trying should succeed. ** Changed in: lxd (Ubuntu) Status: Confirmed => Fix

[Bug 1858389] Re: lxd won't restart a container

2020-03-21 Thread Stéphane Graber via ubuntu-bugs
Moved the bug over to the kernel. Those log messages are caused by reference issues in a network namespace preventing it from being flushed, in turn preventing the LXC monitor from exiting, holding everything up. ** Package changed: lxd (Ubuntu) => linux (Ubuntu) -- You received this bug

[Bug 1860278] Re: package lxd 1:0.7 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting a removal

2020-03-21 Thread Stéphane Graber via ubuntu-bugs
We're missing the dpkg terminal logs to see what happened. Can you provide more details and ideally the terminal output? ** Changed in: lxd (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1867541] [NEW] [FFe] LXCFS 4.0 LTS

2020-03-15 Thread Stéphane Graber via ubuntu-bugs
Public bug reported: LXCFS 4.0 LTS was released last week. The highlights of this is: - cgroup2: Support for the new unified cgroup hierarchy - /proc/cpuinfo and cpu output in /proc/stat based on cpu shares - /proc/loadavg virtualization - pidfd supported process tracking All of those

[Bug 1867535] [NEW] [FFe] LXC 4.0.0 LTS

2020-03-15 Thread Stéphane Graber via ubuntu-bugs
Public bug reported: LXC 4.0 LTS will be tagged in the next week or so. LXC in Ubuntu is currently in universe as its main user is a snap nowadays (LXD) and builds directly from the upstream versions. We haven't written the changelog yet, but one thing worth noting is that it is 100% backward

[Bug 1864303] Re: Removing the e1000e module causes a crash

2020-02-22 Thread Stéphane Graber via ubuntu-bugs
** Changed in: linux-5.4 (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1864303 Title: Removing the e1000e module causes a crash To manage notifications

[Bug 1863772] Re: apparmor missing read permission for /var/lib/snapd/hostfs/usr/lib/os-release

2020-02-18 Thread Stéphane Graber via ubuntu-bugs
We figured it out, it's because the hooks are run inside the LXD snap mntns which we modify to have our own copy of etc. snapctl then ends up following a symlink in our modified /etc causing the issue. Adding system-observe to the hook should do the trick. ** Changed in: snapd Status: New

[Bug 1863772] Re: apparmor missing read permission for /var/lib/snapd/hostfs/usr/lib/os-release

2020-02-18 Thread Stéphane Graber via ubuntu-bugs
Re-opening as the analysis above is incorrect. The configure hook doesn't talk to LXD and doesn't use aa-exec so having the lxd-support interface wouldn't do anything for it. All the hook does is read/write files under ${SNAP_COMMON} and call snapctl. ** Changed in: snapd (Ubuntu)

[Bug 1661447] Re: Arbitrary code execution in centos template

2020-02-05 Thread Stéphane Graber via ubuntu-bugs
Yeah, we were originally considering fixing all of the individual templates but frankly it was just too much of a mess of bad patterns from a variety of different authors with no real consistency. Instead what we came up with is distrobuilder (https://github.com/lxc/distrobuilder) which has now

[Bug 1661447] Re: Arbitrary code execution in centos template

2020-02-05 Thread Stéphane Graber via ubuntu-bugs
We're marking this issue as "Fix Released" for LXC due to the removal of all those scripts from the standard LXC distribution, instead relying on distrobuilder for our users to generate custom LXC images (which can then be consumed by the lxc-local template). -- You received this bug

[Bug 1849904] Re: lxd init assumes ipv6 is available

2019-10-26 Thread Stéphane Graber via ubuntu-bugs
This is a non-standard configuration (disabling IPv6) and actually not recommended for any environment these days. The tool does mention the availability of "none" so, someone in such an environment should be able to make the connection and set to "none". "lxd init" cannot actually check whether

[Bug 1849904] Re: lxd init assumes ipv6 is available

2019-10-26 Thread Stéphane Graber via ubuntu-bugs
https://github.com/lxc/lxd/pull/6354 Closing bug as we don't normally track issues on Launchpad and there won't be any auto-closing on release. ** Changed in: lxd (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1848468] Re: package lxd 3.0.3-0ubuntu1~18.04.1 failed to install/upgrade: »neues lxd-Skript des Paketes pre-installation«-Unterprozess gab den Fehlerwert 1 zurück

2019-10-20 Thread Stéphane Graber via ubuntu-bugs
(It is annoying that there is no way to tell apport not to fire in such cases as it treats any dpkg failure as a bug, even when the failure was deliberate). -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1848794] Re: package lxd 3.0.3-0ubuntu1~18.04.1 failed to install/upgrade: new lxd package pre-installation script subprocess returned error exit status 1

2019-10-20 Thread Stéphane Graber via ubuntu-bugs
===> Aborting at user request So this was the user voluntarily aborting the upgrade following the inability to reach the store. Closing as invalid. ** Changed in: lxd (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1848587] Re: lxc 3.0.4-0ubuntu1 ADT test failure with linux 5.4.0-1.2

2019-10-20 Thread Stéphane Graber via ubuntu-bugs
Looking at the linked reports, it sounds like either /dev/network_latency doesn't exist in those systems (which would differ from standard kernel behavior on Ubuntu), or there is a legitimate issue with injecting that device afterwards. In either case, likely to be a kernel config change or a

[Bug 1848468] Re: package lxd 3.0.3-0ubuntu1~18.04.1 failed to install/upgrade: »neues lxd-Skript des Paketes pre-installation«-Unterprozess gab den Fehlerwert 1 zurück

2019-10-20 Thread Stéphane Graber via ubuntu-bugs
===> Aborting at user request So this was a manually interrupted upgrade due to inability to reach the store. Marking report as invalid. ** Changed in: lxd (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed

[Bug 1811087] Re: [cosmic] lxd-tools replaced by lxd snap, which is missing 'fuidshift' binary

2019-10-20 Thread Stéphane Graber via ubuntu-bugs
Marking as "won't fix" as we can't really ship `fuidshift` as part of a strictly confined snap. Those wanting this tool are probably best building it with a simple `go get github.com/lxc/lxd/fuidshift`. In theory a separate deb package for it could be introduced, but it's not something that the

[Bug 1777017] Re: snap install lxd doesn't work within a container

2019-09-26 Thread Stéphane Graber via ubuntu-bugs
You're trying to run a nested container without having allowed it in the parent container's configuration. You need to set "security.nesting" to "true" on the parent container and restart it before this would work. -- You received this bug notification because you are a member of Ubuntu Bugs,

[Bug 1845337] Re: Disco autopkgtest @ armhf fails root-unittests -> test-execute -> exec-dynamicuser-statedir.service

2019-09-26 Thread Stéphane Graber via ubuntu-bugs
/dev/.lxc/* shows up when nesting is enabled, so that's indeed related to the change Adam did. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1845337 Title: Disco autopkgtest @ armhf fails

[Bug 1845037] Re: autopkgtest package "lxd" test has started failing

2019-09-24 Thread Stéphane Graber via ubuntu-bugs
This is because the test is somehow passing data to "lxc init" or "lxc launch" through stdin. Up until LXD 3.17, we'd only consume stdin in some rare cases during init/launch. But now we're using it as a way to pre-seed the container's YAML configuration, as the data fed through stdin isn't a

[Bug 1843490] Re: lxc.cgroup.devices.allow prevents unprivileged container from starting

2019-09-10 Thread Stéphane Graber via ubuntu-bugs
"lxc.cgroup.devices" is meaningless for unprivileged containers as those can never create those devices anyway, so they'll only ever have access to whatever devices lxc provides and nothing more. All our own default configs specifically do not set that cgroup controller for unprivileged

[Bug 1843468] Re: nftables based iptables wrapper break userspace

2019-09-10 Thread Stéphane Graber via ubuntu-bugs
Ah, that's good to know and we should definitely aim at refreshing nftables prior to doing any amount of testing on the wrappers. The failure I've seen for LXD specifically was around complex protocol parsing (IPv6 router advertisements I believe) through ebtables, so not a very usual thing to

[Bug 1843468] [NEW] nftables based iptables wrapper break userspace

2019-09-10 Thread Stéphane Graber via ubuntu-bugs
Public bug reported: iptables just got replaced by the nftables wrappers, effectively changing all Ubuntu systems to using nftables rather than regular iptables/ip6tables/ebtables. Unfortunately those wrappers aren't perfect and don't convert every option properly, nor know about some of the

[Bug 1837888] Re: lxc 3.0.3-0ubuntu1 ADT test failure with linux 5.3.0-0.1

2019-07-25 Thread Stéphane Graber via ubuntu-bugs
Moving this bug to the kernel as investigation discovered a kernel regression in overmounting protection behavior in 5.3 rc1. So not a LXC bug but a kernel one. ** Package changed: lxc (Ubuntu) => linux (Ubuntu) ** Changed in: linux (Ubuntu) Status: New => Triaged -- You received this

[Bug 1833435] Re: RFC: Add url/urls/mirrors attribute for product items

2019-07-23 Thread Stéphane Graber via ubuntu-bugs
Considering we can quite likely get the reporter to extend our simplestreams implementation to support this, I'm fine with it :) It's not something we need for any of the existing servers on our end (be that cloud-images.ubuntu.com or images.linuxcontainers.org) but I see how this may be useful

[Bug 1834501] Re: do-release-upgrade from bionic->any disables lxd without snapstore access

2019-06-28 Thread Stéphane Graber via ubuntu-bugs
Hi, Indeed, this is a won't fix for LXD as we are snap only at this point and our preinst behavior is I believe correct in avoiding breaking systems. The post-upgrade deb is completely empty so allowing the update to proceed will completely break the existing LXD. The only options are then

[Bug 1834475] Re: lxd 3.0.3-0ubuntu1~18.04.1 ADT test failure with linux 4.15.0-54.58

2019-06-28 Thread Stéphane Graber via ubuntu-bugs
We've changed some of those timings in 3.0.4 which will make it in Ubuntu in the next month or so, but those tests can still be slightly flaky even in our CI as we're testing cluster recovery during random node losses, sometimes things take a bit longer than the 30s timeout to recover, especially

[Bug 1816642] Update Released

2019-04-17 Thread Stéphane Graber
The verification of the Stable Release Update for lxc has completed successfully and the package has now been released to -updates. Subsequently, the Ubuntu Stable Release Updates Team is being unsubscribed and will not receive messages about this bug report. In the event that you encounter a

[Bug 1816642] Re: SRU of LXC 2.0.11

2019-04-17 Thread Stéphane Graber
Did manual testing on LXC 2.0.11 both using it directly and through LXD with pre-existing and new containers. Also tested LXD on top of the updated go-lxc. ** Tags removed: verification-needed verification-needed-xenial ** Tags added: verification-done verification-done-xenial -- You received

[Bug 1824812] Re: apparmor does not start in Disco LXD containers

2019-04-16 Thread Stéphane Graber
** Tags added: shiftfs -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1824812 Title: apparmor does not start in Disco LXD containers To manage notifications about this bug go to:

[Bug 1824719] Re: shiftfs: Allow stacking overlayfs on top

2019-04-16 Thread Stéphane Graber
** Changed in: linux (Ubuntu) Status: Incomplete => Triaged ** Tags added: shiftfs -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1824719 Title: shiftfs: Allow stacking overlayfs on top To

[Bug 1824719] [NEW] [shiftfs] Allow stacking overlayfs on top

2019-04-14 Thread Stéphane Graber
Public bug reported: Shiftfs right now prevents stacking overlayfs on top of it which unfortunately means all users of Docker as well as some nested LXC users which aren't using btrfs are going to break when they get switched over to shiftfs. ** Affects: linux (Ubuntu) Importance: Undecided

[Bug 1824440] Re: snap.lxd.daemon.service reports unexpected response type 6

2019-04-12 Thread Stéphane Graber
Does this happen repeatedly? It's a glitch in dqlite which we've seen happen pretty rarely and that will go away with the complete rewrite of the database layer that's meant to land in a few months. Normally a simple "systemctl reload snap.lxd.daemon" or "snap restart lxd" gets you rid of this.

[Bug 1816642] Re: SRU of LXC 2.0.11

2019-04-09 Thread Stéphane Graber
For go-lxc, the goal is to get a clean autopkgtest result on all arches, manual testing of the package did show that we should be getting that now. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

<    1   2   3   4   5   6   7   8   9   10   >