[jira] [Commented] (MESOS-9672) Docker containerizer should ignore pids of executors that do not pass the connection check.

2019-04-02 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9672?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16807461#comment-16807461 ] Qian Zhang commented on MESOS-9672: --- Instead of ignoring pids of executors that do not

[jira] [Commented] (MESOS-9672) Docker containerizer should ignore pids of executors that do not pass the connection check.

2019-04-02 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9672?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16807462#comment-16807462 ] Qian Zhang commented on MESOS-9672: --- Instead of ignoring pids of executors that do not

[jira] [Created] (MESOS-9695) Remove the duplicate pid check in Docker containerizer

2019-04-02 Thread Qian Zhang (JIRA)
Qian Zhang created MESOS-9695: - Summary: Remove the duplicate pid check in Docker containerizer Key: MESOS-9695 URL: https://issues.apache.org/jira/browse/MESOS-9695 Project: Mesos Issue Type: Im

[jira] [Comment Edited] (MESOS-9501) Mesos executor fails to terminate and gets stuck after agent host reboot.

2019-04-01 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9501?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16806707#comment-16806707 ] Qian Zhang edited comment on MESOS-9501 at 4/1/19 12:55 PM: T

[jira] [Comment Edited] (MESOS-9501) Mesos executor fails to terminate and gets stuck after agent host reboot.

2019-04-01 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9501?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16806707#comment-16806707 ] Qian Zhang edited comment on MESOS-9501 at 4/1/19 12:31 PM: T

[jira] [Commented] (MESOS-9501) Mesos executor fails to terminate and gets stuck after agent host reboot.

2019-04-01 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9501?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16806707#comment-16806707 ] Qian Zhang commented on MESOS-9501: --- This issue can actually happen even without an age

[jira] [Commented] (MESOS-9693) Add master validation for SeccompInfo.

2019-03-30 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9693?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16806041#comment-16806041 ] Qian Zhang commented on MESOS-9693: --- {quote}1. if seccomp is not enabled, we should ret

[jira] [Commented] (MESOS-9651) Design for docker registry v2 schema2 basic support.

2019-03-22 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9651?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16798779#comment-16798779 ] Qian Zhang commented on MESOS-9651: --- [https://docs.google.com/document/d/1AU5IXMbR0AGlu

[jira] [Commented] (MESOS-6934) Support pulling Docker images with V2 Schema 2 image manifest

2019-03-20 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-6934?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16797867#comment-16797867 ] Qian Zhang commented on MESOS-6934: --- Design doc:  https://docs.google.com/document/d/1A

[jira] [Commented] (MESOS-9641) Support GID manager with non-sharable persistent volume.

2019-03-18 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9641?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16795019#comment-16795019 ] Qian Zhang commented on MESOS-9641: --- Here is the patch to revert the above 3 patches:

[jira] [Commented] (MESOS-9641) Support GID manager with non-sharable persistent volume.

2019-03-18 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9641?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16795017#comment-16795017 ] Qian Zhang commented on MESOS-9641: --- Reopen this ticket. After second thought, I think

[jira] [Created] (MESOS-9643) Make setting volume ownership asynchronous in volume gid manager

2019-03-11 Thread Qian Zhang (JIRA)
Qian Zhang created MESOS-9643: - Summary: Make setting volume ownership asynchronous in volume gid manager Key: MESOS-9643 URL: https://issues.apache.org/jira/browse/MESOS-9643 Project: Mesos Iss

[jira] [Commented] (MESOS-6934) Support pulling Docker images with V2 Schema 2 image manifest

2019-03-07 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-6934?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16787480#comment-16787480 ] Qian Zhang commented on MESOS-6934: --- Reopen this ticket which was closed in favor of ME

[jira] [Commented] (MESOS-9620) Add metrics for volume gid manager

2019-03-04 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9620?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16783418#comment-16783418 ] Qian Zhang commented on MESOS-9620: --- RR: https://reviews.apache.org/r/70112/ > Add met

[jira] [Commented] (MESOS-9621) Mesos failed to build due to error LNK2019 on Windows using MSVC.

2019-03-01 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9621?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16782233#comment-16782233 ] Qian Zhang commented on MESOS-9621: --- RR: https://reviews.apache.org/r/70085/ > Mesos f

[jira] [Created] (MESOS-9620) Add metrics for volume gid manager

2019-02-28 Thread Qian Zhang (JIRA)
Qian Zhang created MESOS-9620: - Summary: Add metrics for volume gid manager Key: MESOS-9620 URL: https://issues.apache.org/jira/browse/MESOS-9620 Project: Mesos Issue Type: Task Repor

[jira] [Created] (MESOS-9591) Remove obsolete recovery code in Docker containerizer

2019-02-20 Thread Qian Zhang (JIRA)
Qian Zhang created MESOS-9591: - Summary: Remove obsolete recovery code in Docker containerizer Key: MESOS-9591 URL: https://issues.apache.org/jira/browse/MESOS-9591 Project: Mesos Issue Type: Imp

[jira] [Commented] (MESOS-8688) Persistent volumes under taskgroup non-root user may not be writable if executor user under root.

2019-02-13 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8688?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16767095#comment-16767095 ] Qian Zhang commented on MESOS-8688: --- This issue will be resolved by MESOS-8810. > Pers

[jira] [Commented] (MESOS-9507) Agent could not recover due to empty docker volume checkpointed files.

2019-02-13 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16766928#comment-16766928 ] Qian Zhang commented on MESOS-9507: --- RR: https://reviews.apache.org/r/69972/ > Agent c

[jira] [Assigned] (MESOS-9507) Agent could not recover due to empty docker volume checkpointed files.

2019-02-11 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9507?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Qian Zhang reassigned MESOS-9507: - Assignee: Qian Zhang (was: Andrei Budnik) > Agent could not recover due to empty docker volume

[jira] [Commented] (MESOS-9536) Nested container launched with non-root user may not be able to write to its sandbox via the environment variable `MESOS_SANDBOX`

2019-01-25 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9536?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16752017#comment-16752017 ] Qian Zhang commented on MESOS-9536: --- The root cause of this issue is, in this patch  [h

[jira] [Created] (MESOS-9536) Nested container launched with non-root user may not be able to write to its sandbox via the environment variable `MESOS_SANDBOX`

2019-01-25 Thread Qian Zhang (JIRA)
Qian Zhang created MESOS-9536: - Summary: Nested container launched with non-root user may not be able to write to its sandbox via the environment variable `MESOS_SANDBOX` Key: MESOS-9536 URL: https://issues.apache.org

[jira] [Commented] (MESOS-9501) Mesos executor fails to terminate and gets stuck after agent host reboot.

2019-01-11 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9501?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16740141#comment-16740141 ] Qian Zhang commented on MESOS-9501: --- RR: https://reviews.apache.org/r/69705/ > Mesos e

[jira] [Assigned] (MESOS-9501) Mesos executor fails to terminate and gets stuck after agent host reboot.

2019-01-09 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9501?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Qian Zhang reassigned MESOS-9501: - Assignee: Qian Zhang > Mesos executor fails to terminate and gets stuck after agent host reboot.

[jira] [Commented] (MESOS-7042) Send SIGKILL after SIGTERM to IOSwitchboard after container termination

2019-01-04 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-7042?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16733918#comment-16733918 ] Qian Zhang commented on MESOS-7042: --- RR: https://reviews.apache.org/r/69667/ > Send SI

[jira] [Assigned] (MESOS-7042) Send SIGKILL after SIGTERM to IOSwitchboard after container termination

2019-01-04 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-7042?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Qian Zhang reassigned MESOS-7042: - Assignee: Qian Zhang > Send SIGKILL after SIGTERM to IOSwitchboard after container termination >

[jira] [Created] (MESOS-9475) Task launched with non-root user cannot write to existing sub-dirs/files in persistent volume

2018-12-13 Thread Qian Zhang (JIRA)
Qian Zhang created MESOS-9475: - Summary: Task launched with non-root user cannot write to existing sub-dirs/files in persistent volume Key: MESOS-9475 URL: https://issues.apache.org/jira/browse/MESOS-9475

[jira] [Commented] (MESOS-9475) Task launched with non-root user cannot write to existing sub-dirs/files in persistent volume

2018-12-13 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9475?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16719918#comment-16719918 ] Qian Zhang commented on MESOS-9475: --- Actually the task has the write permission to the

[jira] [Comment Edited] (MESOS-8811) Grant non-root task user the permissions to access the image volume

2018-12-10 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8811?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16555780#comment-16555780 ] Qian Zhang edited comment on MESOS-8811 at 12/11/18 6:38 AM: -

[jira] [Comment Edited] (MESOS-8812) Grant non-root task user the permissions to access the DOCKER_VOLUME volume

2018-12-10 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8812?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16563303#comment-16563303 ] Qian Zhang edited comment on MESOS-8812 at 12/11/18 6:39 AM: -

[jira] [Comment Edited] (MESOS-8813) Make multiple tasks with different users can access a shared persistent volume

2018-12-10 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8813?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16566530#comment-16566530 ] Qian Zhang edited comment on MESOS-8813 at 12/10/18 5:18 PM: -

[jira] [Comment Edited] (MESOS-8810) Grant non-root task user the permissions to access the SANDBOX_PATH volume of PARENT type

2018-11-21 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8810?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16550481#comment-16550481 ] Qian Zhang edited comment on MESOS-8810 at 11/21/18 2:40 PM: -

[jira] [Commented] (MESOS-9332) Nested container should run as the same user of its parent container by default

2018-11-19 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9332?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16691705#comment-16691705 ] Qian Zhang commented on MESOS-9332: --- commit 22fa5aeac19416fd0c7c2284a1e48a5ee15bdd24 Au

[jira] [Commented] (MESOS-9332) Nested container should run as the same user of its parent container by default

2018-11-18 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9332?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16691339#comment-16691339 ] Qian Zhang commented on MESOS-9332: --- I added a test (https://reviews.apache.org/r/69389

[jira] [Commented] (MESOS-9332) Nested container should run as the same user of its parent container by default

2018-11-18 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9332?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16691178#comment-16691178 ] Qian Zhang commented on MESOS-9332: --- SHA of 1.7.x backport: 706170289a0d3558d788938eeba

[jira] [Commented] (MESOS-9332) Nested container should run as the same user of its parent container by default

2018-11-18 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9332?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16691168#comment-16691168 ] Qian Zhang commented on MESOS-9332: --- commit c5ecd424259651dcb47321516914295ebef2bc48 Au

[jira] [Commented] (MESOS-9332) Nested container should run as the same user of its parent container by default

2018-11-17 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9332?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16690567#comment-16690567 ] Qian Zhang commented on MESOS-9332: --- https://reviews.apache.org/r/69376/ > Nested cont

[jira] [Commented] (MESOS-9332) Nested container should run as the same user of its parent container by default

2018-11-17 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9332?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16690469#comment-16690469 ] Qian Zhang commented on MESOS-9332: --- The above fix caused an issue that nested containe

[jira] [Commented] (MESOS-9332) Nested container should run as the same user of its parent container by default

2018-11-14 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9332?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16687425#comment-16687425 ] Qian Zhang commented on MESOS-9332: --- SHA of 1.7.x backport: 222ec278aeb98ef9c6fc948df18

[jira] [Commented] (MESOS-9332) Debug container should run as the same user of its parent container by default

2018-11-08 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9332?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16679488#comment-16679488 ] Qian Zhang commented on MESOS-9332: --- After discussed [~gilbert], we agree that we shoul

[jira] [Commented] (MESOS-9164) Subprocess should unset CLOEXEC on whitelisted file descriptors.

2018-11-08 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9164?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16679389#comment-16679389 ] Qian Zhang commented on MESOS-9164: --- commit d9a02acb8c9440c29811e6f66fe2e1146a04aa52 Au

[jira] [Commented] (MESOS-9332) Nested container should run as the same user of its parent container by default

2018-11-08 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9332?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16679501#comment-16679501 ] Qian Zhang commented on MESOS-9332: --- commit be494213083b27bc768c919f3df1df2bca899955 Au

[jira] [Comment Edited] (MESOS-9332) Debug container should run as the same user of its parent container by default

2018-11-08 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9332?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16679488#comment-16679488 ] Qian Zhang edited comment on MESOS-9332 at 11/8/18 9:26 AM: A

[jira] [Commented] (MESOS-9152) Close all file descriptors except whitelist_fds in posix/subprocess.

2018-11-07 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9152?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16679390#comment-16679390 ] Qian Zhang commented on MESOS-9152: --- commit f539d1eba8c7b0fbc4ab040c9af357e016bfde12 Au

[jira] [Commented] (MESOS-9332) Debug container should run as the same user of its parent container by default

2018-11-01 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9332?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16672237#comment-16672237 ] Qian Zhang commented on MESOS-9332: --- RR: https://reviews.apache.org/r/69234/ > Debug c

[jira] [Commented] (MESOS-9334) Container stuck at ISOLATING state due to libevent poll never returns

2018-10-30 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9334?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16669327#comment-16669327 ] Qian Zhang commented on MESOS-9334: --- commit 610064942d4a75f16f045480ca9e3414d37f1ecc Au

[jira] [Commented] (MESOS-9334) Container stuck at ISOLATING state due to libevent poll never returns

2018-10-25 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9334?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16664603#comment-16664603 ] Qian Zhang commented on MESOS-9334: --- RR: https://reviews.apache.org/r/69123/ > Contain

[jira] [Assigned] (MESOS-9164) Subprocess should unset CLOEXEC on whitelisted file descriptors.

2018-10-25 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9164?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Qian Zhang reassigned MESOS-9164: - Assignee: Qian Zhang (was: James Peach) > Subprocess should unset CLOEXEC on whitelisted file d

[jira] [Comment Edited] (MESOS-9334) Container stuck at ISOLATING state due to libevent poll never returns

2018-10-24 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9334?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16661975#comment-16661975 ] Qian Zhang edited comment on MESOS-9334 at 10/24/18 9:17 AM: -

[jira] [Commented] (MESOS-9334) Container stuck at ISOLATING state due to libevent poll never returns

2018-10-24 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9334?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16661975#comment-16661975 ] Qian Zhang commented on MESOS-9334: --- After reading some libevent code and our code to c

[jira] [Comment Edited] (MESOS-9334) Container stuck at ISOLATING state due to libevent poll never returns

2018-10-22 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9334?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16658795#comment-16658795 ] Qian Zhang edited comment on MESOS-9334 at 10/22/18 2:14 PM: -

[jira] [Comment Edited] (MESOS-9334) Container stuck at ISOLATING state due to libevent poll never returns

2018-10-22 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9334?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16658795#comment-16658795 ] Qian Zhang edited comment on MESOS-9334 at 10/22/18 9:55 AM: -

[jira] [Commented] (MESOS-9334) Container stuck at ISOLATING state due to libevent poll never returns

2018-10-22 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9334?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16658795#comment-16658795 ] Qian Zhang commented on MESOS-9334: --- I added some logs into `libevent_poll.cpp` (see th

[jira] [Commented] (MESOS-9334) Container stuck at ISOLATING state due to libevent poll never returns

2018-10-19 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9334?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16656592#comment-16656592 ] Qian Zhang commented on MESOS-9334: --- I added some logs into Mesos agent and libprocess,

[jira] [Created] (MESOS-9334) Container stuck at ISOLATING state due to libevent poll never returns

2018-10-19 Thread Qian Zhang (JIRA)
Qian Zhang created MESOS-9334: - Summary: Container stuck at ISOLATING state due to libevent poll never returns Key: MESOS-9334 URL: https://issues.apache.org/jira/browse/MESOS-9334 Project: Mesos

[jira] [Commented] (MESOS-9332) Debug container should run as the same user of its parent container by default

2018-10-18 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9332?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16654873#comment-16654873 ] Qian Zhang commented on MESOS-9332: --- The possible solution would be, when setting the `

[jira] [Created] (MESOS-9332) Debug container should run as the same user of its parent container by default

2018-10-18 Thread Qian Zhang (JIRA)
Qian Zhang created MESOS-9332: - Summary: Debug container should run as the same user of its parent container by default Key: MESOS-9332 URL: https://issues.apache.org/jira/browse/MESOS-9332 Project: Mesos

[jira] [Commented] (MESOS-9164) Subprocess should unset CLOEXEC on whitelisted file descriptors.

2018-10-14 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9164?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16649406#comment-16649406 ] Qian Zhang commented on MESOS-9164: --- RR: https://reviews.apache.org/r/68644/ > Subproc

[jira] [Commented] (MESOS-9231) `docker inspect` may return an unexpected result to Docker executor due to a race condition

2018-09-30 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9231?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16633277#comment-16633277 ] Qian Zhang commented on MESOS-9231: --- commit d74779eba1ba1d6583c76052c38a98668847eb68 Au

[jira] [Comment Edited] (MESOS-9231) `docker inspect` may return an unexpected result to Docker executor due to a race condition

2018-09-29 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9231?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16624690#comment-16624690 ] Qian Zhang edited comment on MESOS-9231 at 9/30/18 1:29 AM: I

[jira] [Comment Edited] (MESOS-9231) `docker inspect` may return an unexpected result to Docker executor due to a race condition

2018-09-29 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9231?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16631446#comment-16631446 ] Qian Zhang edited comment on MESOS-9231 at 9/30/18 1:29 AM: I

[jira] [Comment Edited] (MESOS-9231) `docker inspect` may return an unexpected result to Docker executor due to a race condition

2018-09-29 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9231?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16622099#comment-16622099 ] Qian Zhang edited comment on MESOS-9231 at 9/30/18 1:28 AM: I

[jira] [Comment Edited] (MESOS-9231) `docker inspect` may return an incomplete result to Docker executor due to a race condition

2018-09-28 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9231?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16631447#comment-16631447 ] Qian Zhang edited comment on MESOS-9231 at 9/29/18 3:24 AM: R

[jira] [Commented] (MESOS-9231) `docker inspect` may return an incomplete result to Docker executor due to a race condition

2018-09-28 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9231?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16631447#comment-16631447 ] Qian Zhang commented on MESOS-9231: --- RR: https://reviews.apache.org/r/68872/ > `docker

[jira] [Commented] (MESOS-9231) `docker inspect` may return an incomplete result to Docker executor due to a race condition

2018-09-28 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9231?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16631446#comment-16631446 ] Qian Zhang commented on MESOS-9231: --- I thought this is a bug of Docker so I created an

[jira] [Commented] (MESOS-9231) `docker inspect` may return an incomplete result to Docker executor due to a race condition

2018-09-22 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9231?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16624690#comment-16624690 ] Qian Zhang commented on MESOS-9231: --- I tried a newer version of Docker (17.12.1-ce), un

[jira] [Commented] (MESOS-9231) `docker inspect` may return an incomplete result to Docker executor due to a race condition

2018-09-20 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9231?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16622099#comment-16622099 ] Qian Zhang commented on MESOS-9231: --- I added some logs in Mesos's Docker library (`src/

[jira] [Commented] (MESOS-9231) `docker inspect` may return an incomplete result to Docker executor due to a race condition

2018-09-13 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9231?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16614169#comment-16614169 ] Qian Zhang commented on MESOS-9231: --- And we may have similar race in Docker containeriz

[jira] [Created] (MESOS-9231) `docker inspect` may return an incomplete result to Docker executor due to a race condition

2018-09-13 Thread Qian Zhang (JIRA)
Qian Zhang created MESOS-9231: - Summary: `docker inspect` may return an incomplete result to Docker executor due to a race condition Key: MESOS-9231 URL: https://issues.apache.org/jira/browse/MESOS-9231 P

[jira] [Commented] (MESOS-9152) Close all file descriptors except whitelist_fds in posix/subprocess.

2018-09-05 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9152?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16605138#comment-16605138 ] Qian Zhang commented on MESOS-9152: --- RR: https://reviews.apache.org/r/68642/ > Close a

[jira] [Commented] (MESOS-8568) Command checks should always call `WAIT_NESTED_CONTAINER` before `REMOVE_NESTED_CONTAINER`

2018-09-05 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8568?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16604950#comment-16604950 ] Qian Zhang commented on MESOS-8568: --- commit ba370822c94c8e9881eff3f63a02b38e18335ae4 Au

[jira] [Commented] (MESOS-8568) Command checks should always call `WAIT_NESTED_CONTAINER` before `REMOVE_NESTED_CONTAINER`

2018-08-30 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8568?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16598177#comment-16598177 ] Qian Zhang commented on MESOS-8568: --- [~vinodkone] Done. > Command checks should always

[jira] [Comment Edited] (MESOS-8568) Command checks should always call `WAIT_NESTED_CONTAINER` before `REMOVE_NESTED_CONTAINER`

2018-08-24 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8568?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16591235#comment-16591235 ] Qian Zhang edited comment on MESOS-8568 at 8/24/18 7:05 AM: I

[jira] [Commented] (MESOS-8568) Command checks should always call `WAIT_NESTED_CONTAINER` before `REMOVE_NESTED_CONTAINER`

2018-08-24 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8568?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16591235#comment-16591235 ] Qian Zhang commented on MESOS-8568: --- I ran the exactly same reproduce steps with the ab

[jira] [Commented] (MESOS-8568) Command checks should always call `WAIT_NESTED_CONTAINER` before `REMOVE_NESTED_CONTAINER`

2018-08-23 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8568?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16591106#comment-16591106 ] Qian Zhang commented on MESOS-8568: --- RR: https://reviews.apache.org/r/68495/ > Command

[jira] [Comment Edited] (MESOS-8568) Command checks should always call `WAIT_NESTED_CONTAINER` before `REMOVE_NESTED_CONTAINER`

2018-08-23 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8568?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16591103#comment-16591103 ] Qian Zhang edited comment on MESOS-8568 at 8/24/18 3:20 AM: [

[jira] [Commented] (MESOS-8568) Command checks should always call `WAIT_NESTED_CONTAINER` before `REMOVE_NESTED_CONTAINER`

2018-08-23 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8568?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16591103#comment-16591103 ] Qian Zhang commented on MESOS-8568: --- [~vinodkone] Yeah, I noticed that as well. When th

[jira] [Comment Edited] (MESOS-8568) Command checks should always call `WAIT_NESTED_CONTAINER` before `REMOVE_NESTED_CONTAINER`

2018-08-22 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8568?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16588976#comment-16588976 ] Qian Zhang edited comment on MESOS-8568 at 8/22/18 3:02 PM: R

[jira] [Comment Edited] (MESOS-8568) Command checks should always call `WAIT_NESTED_CONTAINER` before `REMOVE_NESTED_CONTAINER`

2018-08-22 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8568?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16588976#comment-16588976 ] Qian Zhang edited comment on MESOS-8568 at 8/22/18 3:01 PM: R

[jira] [Comment Edited] (MESOS-8568) Command checks should always call `WAIT_NESTED_CONTAINER` before `REMOVE_NESTED_CONTAINER`

2018-08-22 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8568?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16588976#comment-16588976 ] Qian Zhang edited comment on MESOS-8568 at 8/22/18 2:56 PM: R

[jira] [Commented] (MESOS-8568) Command checks should always call `WAIT_NESTED_CONTAINER` before `REMOVE_NESTED_CONTAINER`

2018-08-22 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8568?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16588976#comment-16588976 ] Qian Zhang commented on MESOS-8568: --- Reproduce steps: 1. To simulate the failure of la

[jira] [Commented] (MESOS-9131) Health checks launching nested containers while a container is being destroyed lead to unkillable tasks

2018-08-20 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9131?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16586013#comment-16586013 ] Qian Zhang commented on MESOS-9131: --- The root cause of this issue is, the I/O switchboa

[jira] [Comment Edited] (MESOS-9131) Health checks launching nested containers while a container is being destroyed lead to unkillable tasks

2018-08-19 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9131?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16585328#comment-16585328 ] Qian Zhang edited comment on MESOS-9131 at 8/20/18 1:50 AM: I

[jira] [Comment Edited] (MESOS-9131) Health checks launching nested containers while a container is being destroyed lead to unkillable tasks

2018-08-19 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9131?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16585328#comment-16585328 ] Qian Zhang edited comment on MESOS-9131 at 8/20/18 1:36 AM: I

[jira] [Commented] (MESOS-9131) Health checks launching nested containers while a container is being destroyed lead to unkillable tasks

2018-08-19 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9131?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16585328#comment-16585328 ] Qian Zhang commented on MESOS-9131: --- I found a way to steadily reproduce this issue: 1

[jira] [Comment Edited] (MESOS-9031) Mesos CNI portmap plugins' iptables rules doesn't allow connections via host ip and port from the same bridge container network

2018-08-06 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9031?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16537867#comment-16537867 ] Qian Zhang edited comment on MESOS-9031 at 8/7/18 12:03 AM: F

[jira] [Comment Edited] (MESOS-8814) Mount the volume based on `Volume.mode`

2018-08-06 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8814?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16569023#comment-16569023 ] Qian Zhang edited comment on MESOS-8814 at 8/6/18 7:56 AM: --- RR:

[jira] [Commented] (MESOS-8814) Mount the volume based on `Volume.mode`

2018-08-03 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8814?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16569023#comment-16569023 ] Qian Zhang commented on MESOS-8814: --- RR: [https://reviews.apache.org/r/68203/] > Mount

[jira] [Commented] (MESOS-8813) Make multiple tasks with different users can access a shared persistent volume

2018-08-02 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8813?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16566530#comment-16566530 ] Qian Zhang commented on MESOS-8813: --- RR: https://reviews.apache.org/r/68161/ > Make mu

[jira] [Commented] (MESOS-8812) Grant non-root task user the permissions to access the DOCKER_VOLUME volume

2018-07-31 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8812?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16563303#comment-16563303 ] Qian Zhang commented on MESOS-8812: --- RR: https://reviews.apache.org/r/68125/ > Grant n

[jira] [Commented] (MESOS-8811) Grant non-root task user the permissions to access the image volume

2018-07-25 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8811?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16555780#comment-16555780 ] Qian Zhang commented on MESOS-8811: --- RR: https://reviews.apache.org/r/68040/ > Grant n

[jira] [Commented] (MESOS-7947) Add GC capability to nested containers

2018-07-22 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-7947?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16552237#comment-16552237 ] Qian Zhang commented on MESOS-7947: --- {quote}With 2) all those executors that use LAUNCH

[jira] [Commented] (MESOS-8810) Grant non-root task user the permissions to access the SANDBOX_PATH volume of PARENT type

2018-07-20 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-8810?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16550481#comment-16550481 ] Qian Zhang commented on MESOS-8810: --- RR: https://reviews.apache.org/r/67996/ > Grant n

[jira] [Comment Edited] (MESOS-7176) Add versioning support to network/cni isolator

2018-07-19 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-7176?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16374228#comment-16374228 ] Qian Zhang edited comment on MESOS-7176 at 7/20/18 1:19 AM: A

[jira] [Commented] (MESOS-9076) Mesos agent will be wrongly treated as unknown orphaned container if `--cgroups_root` has a leading slash

2018-07-16 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9076?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16544871#comment-16544871 ] Qian Zhang commented on MESOS-9076: --- The root cause of this issue is, a leading slash i

[jira] [Created] (MESOS-9076) Mesos agent will be wrongly treated as unknown orphaned container if `--cgroups_root` has a leading slash

2018-07-16 Thread Qian Zhang (JIRA)
Qian Zhang created MESOS-9076: - Summary: Mesos agent will be wrongly treated as unknown orphaned container if `--cgroups_root` has a leading slash Key: MESOS-9076 URL: https://issues.apache.org/jira/browse/MESOS-9076

[jira] [Commented] (MESOS-7947) Add GC capability to nested containers

2018-07-13 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-7947?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16542684#comment-16542684 ] Qian Zhang commented on MESOS-7947: --- For 2, It seems agent will not be notified with th

[jira] [Commented] (MESOS-9070) Support systemd and freezer cgroup subsystems bind mount for container with rootfs.

2018-07-12 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9070?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16541713#comment-16541713 ] Qian Zhang commented on MESOS-9070: --- RR: https://reviews.apache.org/r/67896/ > Support

[jira] [Assigned] (MESOS-9013) Support container Cgroup FS mount.

2018-07-12 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9013?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Qian Zhang reassigned MESOS-9013: - Assignee: Qian Zhang > Support container Cgroup FS mount. > -- >

[jira] [Assigned] (MESOS-9070) Support systemd and freezer cgroup subsystems bind mount for container with rootfs.

2018-07-11 Thread Qian Zhang (JIRA)
[ https://issues.apache.org/jira/browse/MESOS-9070?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Qian Zhang reassigned MESOS-9070: - Assignee: Qian Zhang > Support systemd and freezer cgroup subsystems bind mount for container wi

<    1   2   3   4   5   6   7   8   9   >