[Kernel-packages] [Bug 1496430] Re: Docker-1.8.2 can't create container, due to apparmor denying 'disconnected path'

2015-10-20 Thread Launchpad Bug Tracker
This bug was fixed in the package linux - 3.19.0-31.36

---
linux (3.19.0-31.36) vivid; urgency=low

  [ Luis Henriques ]

  * Release Tracking Bug
- LP: #1503703

  [ Andy Whitcroft ]

  * Revert "SAUCE: aufs3: mmap: Fix races in madvise_remove() and
sys_msync()"
- LP: #1503655

  [ Ben Hutchings ]

  * SAUCE: aufs3: mmap: Fix races in madvise_remove() and sys_msync()
- LP: #1503655
- CVE-2015-7312

linux (3.19.0-31.35) vivid; urgency=low

  [ Brad Figg ]

  * Release Tracking Bug
- LP: #1503005

  [ Ben Hutchings ]

  * SAUCE: aufs3: mmap: Fix races in madvise_remove() and sys_msync()
- CVE-2015-7312

  [ Craig Magina ]

  * [Config] Add XGENE_EDAC, EDAC_SUPPORT and EDAC_ATOMIC_SCRUB
- LP: #1494357

  [ John Johansen ]

  * SAUCE: (no-up) apparmor: fix mount not handling disconnected paths
- LP: #1496430

  [ Laurent Dufour ]

  * SAUCE: powerpc/hvsi: Fix endianness issues in the HVSI driver
- LP: #1499357

  [ Tim Gardner ]

  * [Config] CONFIG_RTC_DRV_XGENE=y for only arm64
- LP: #1499869

  [ Upstream Kernel Changes ]

  * Revert "sit: Add gro callbacks to sit_offload"
- LP: #1500493
  * ipmi/powernv: Fix minor locking bug
- LP: #1493017
  * mmc: sdhci-pci: set the clear transfer mode register quirk for O2Micro
- LP: #1472843
  * perf probe ppc: Fix symbol fixup issues due to ELF type
- LP: #1485528
  * perf probe ppc: Use the right prefix when ignoring SyS symbols on ppc
- LP: #1485528
  * perf probe ppc: Enable matching against dot symbols automatically
- LP: #1485528
  * perf probe ppc64le: Fix ppc64 ABIv2 symbol decoding
- LP: #1485528
  * perf probe ppc64le: Prefer symbol table lookup over DWARF
- LP: #1485528
  * perf probe ppc64le: Fixup function entry if using kallsyms lookup
- LP: #1485528
  * perf probe: Improve detection of file/function name in the probe
pattern
- LP: #1485528
  * perf probe: Ignore tail calls to probed functions
- LP: #1485528
  * seccomp: cap SECCOMP_RET_ERRNO data to MAX_ERRNO
- LP: #1496073
  * EDAC: Cleanup atomic_scrub mess
- LP: #1494357
  * arm64: Enable EDAC on ARM64
- LP: #1494357
  * MAINTAINERS: Add entry for APM X-Gene SoC EDAC driver
- LP: #1494357
  * Documentation: Add documentation for the APM X-Gene SoC EDAC DTS
binding
- LP: #1494357
  * EDAC: Add APM X-Gene SoC EDAC driver
- LP: #1494357
  * arm64: Add APM X-Gene SoC EDAC DTS entries
- LP: #1494357
  * EDAC, edac_stub: Drop arch-specific include
- LP: #1494357
  * NVMe: Fix blk-mq hot cpu notification
- LP: #1498778
  * blk-mq: Shared tag enhancements
- LP: #1498778
  * blk-mq: avoid access hctx->tags->cpumask before allocation
- LP: #1498778
  * x86/ldt: Make modify_ldt synchronous
- LP: #1500493
  * x86/ldt: Correct LDT access in single stepping logic
- LP: #1500493
  * x86/ldt: Correct FPU emulation access to LDT
- LP: #1500493
  * md: flush ->event_work before stopping array.
- LP: #1500493
  * ipv6: addrconf: validate new MTU before applying it
- LP: #1500493
  * virtio-net: drop NETIF_F_FRAGLIST
- LP: #1500493
  * RDS: verify the underlying transport exists before creating a
connection
- LP: #1500493
  * xen/gntdev: convert priv->lock to a mutex
- LP: #1500493
  * xen/gntdevt: Fix race condition in gntdev_release()
- LP: #1500493
  * PCI: Restore PCI_MSIX_FLAGS_BIRMASK definition
- LP: #1500493
  * USB: qcserial/option: make AT URCs work for Sierra Wireless
MC7305/MC7355
- LP: #1500493
  * USB: qcserial: Add support for Dell Wireless 5809e 4G Modem
- LP: #1500493
  * nfsd: Drop BUG_ON and ignore SECLABEL on absent filesystem
- LP: #1500493
  * usb: chipidea: ehci_init_driver is intended to call one time
- LP: #1500493
  * crypto: qat - Fix invalid synchronization between register/unregister
sym algs
- LP: #1500493
  * crypto: ixp4xx - Remove bogus BUG_ON on scattered dst buffer
- LP: #1500493
  * mfd: arizona: Fix initialisation of the PM runtime
- LP: #1500493
  * xen-blkfront: don't add indirect pages to list when !feature_persistent
- LP: #1500493
  * xen-blkback: replace work_pending with work_busy in
purge_persistent_gnt()
- LP: #1500493
  * usb: gadget: f_uac2: fix calculation of uac2->p_interval
- LP: #1500493
  * hwrng: core - correct error check of kthread_run call
- LP: #1500493
  * USB: sierra: add 1199:68AB device ID
- LP: #1500493
  * regmap: regcache-rbtree: Clean new present bits on present bitmap
resize
- LP: #1500493
  * target/iscsi: Fix double free of a TUR followed by a solicited NOPOUT
- LP: #1500493
  * rbd: fix copyup completion race
- LP: #1500493
  * md/raid1: extend spinlock to protect raid1_end_read_request against
inconsistencies
- LP: #1500493
  * target: REPORT LUNS should return LUN 0 even for dynamic ACLs
- LP: #1500493
  * MIPS: Fix sched_getaffinity with MT FPAFF enabled
- LP: 

[Kernel-packages] [Bug 1496430] Re: Docker-1.8.2 can't create container, due to apparmor denying 'disconnected path'

2015-10-19 Thread Launchpad Bug Tracker
This bug was fixed in the package linux - 3.13.0-66.108

---
linux (3.13.0-66.108) trusty; urgency=low

  [ Luis Henriques ]

  * Release Tracking Bug
- LP: #1503713

  [ Andy Whitcroft ]

  * Revert "SAUCE: aufs3: mmap: Fix races in madvise_remove() and
sys_msync()"
- LP: #1503655

  [ Ben Hutchings ]

  * SAUCE: aufs3: mmap: Fix races in madvise_remove() and sys_msync()
- LP: #1503655
- CVE-2015-7312

linux (3.13.0-66.107) trusty; urgency=low

  [ Brad Figg ]

  * Release Tracking Bug
- LP: #1503021

  [ Ben Hutchings ]

  * SAUCE: aufs3: mmap: Fix races in madvise_remove() and sys_msync()
- CVE-2015-7312

  [ John Johansen ]

  * SAUCE: (no-up) apparmor: fix mount not handling disconnected paths
- LP: #1496430

  [ Upstream Kernel Changes ]

  * mmc: sdhci-pci: set the clear transfer mode register quirk for O2Micro
- LP: #1472843
  * mmc: sdhci: Add a quirk for AMD SDHC transfer mode register need to be
cleared for cmd without data
- LP: #1472843
  * n_tty: Fix poll() when TIME_CHAR and MIN_CHAR == 0
- LP: #1397976
  * net: make skb_gso_segment error handling more robust
- LP: #1497048
  * net: gso: use feature flag argument in all protocol gso handlers
- LP: #1497048
  * md/raid10: always set reshape_safe when initializing reshape_position.
- LP: #1500810
  * md: flush ->event_work before stopping array.
- LP: #1500810
  * ipv6: addrconf: validate new MTU before applying it
- LP: #1500810
  * virtio-net: drop NETIF_F_FRAGLIST
- LP: #1500810
  * RDS: verify the underlying transport exists before creating a
connection
- LP: #1500810
  * xen/gntdev: convert priv->lock to a mutex
- LP: #1500810
  * xen/gntdevt: Fix race condition in gntdev_release()
- LP: #1500810
  * PCI: Restore PCI_MSIX_FLAGS_BIRMASK definition
- LP: #1500810
  * nfsd: Drop BUG_ON and ignore SECLABEL on absent filesystem
- LP: #1500810
  * crypto: ixp4xx - Remove bogus BUG_ON on scattered dst buffer
- LP: #1500810
  * xen-blkfront: don't add indirect pages to list when !feature_persistent
- LP: #1500810
  * xen-blkback: replace work_pending with work_busy in
purge_persistent_gnt()
- LP: #1500810
  * USB: sierra: add 1199:68AB device ID
- LP: #1500810
  * regmap: regcache-rbtree: Clean new present bits on present bitmap
resize
- LP: #1500810
  * target/iscsi: Fix double free of a TUR followed by a solicited NOPOUT
- LP: #1500810
  * rbd: fix copyup completion race
- LP: #1500810
  * md/raid1: extend spinlock to protect raid1_end_read_request against
inconsistencies
- LP: #1500810
  * target: REPORT LUNS should return LUN 0 even for dynamic ACLs
- LP: #1500810
  * MIPS: Fix sched_getaffinity with MT FPAFF enabled
- LP: #1500810
  * xhci: fix off by one error in TRB DMA address boundary check
- LP: #1500810
  * perf: Fix fasync handling on inherited events
- LP: #1500810
  * mm, vmscan: Do not wait for page writeback for GFP_NOFS allocations
- LP: #1500810
  * MIPS: Make set_pte() SMP safe.
- LP: #1500810
  * ipc: modify message queue accounting to not take kernel data structures
into account
- LP: #1500810
  * ocfs2: fix BUG in ocfs2_downconvert_thread_do_work()
- LP: #1500810
  * fsnotify: fix oops in fsnotify_clear_marks_by_group_flags()
- LP: #1500810
  * KVM: x86: Use adjustment in guest cycles when handling
MSR_IA32_TSC_ADJUST
- LP: #1500810
  * localmodconfig: Use Kbuild files too
- LP: #1500810
  * dm thin metadata: delete btrees when releasing metadata snapshot
- LP: #1500810
  * dm btree: add ref counting ops for the leaves of top level btrees
- LP: #1500810
  * drm/radeon: add new OLAND pci id
- LP: #1500810
  * libiscsi: Fix host busy blocking during connection teardown
- LP: #1500810
  * libfc: Fix fc_exch_recv_req() error path
- LP: #1500810
  * libfc: Fix fc_fcp_cleanup_each_cmd()
- LP: #1500810
  * EDAC, ppc4xx: Access mci->csrows array elements properly
- LP: #1500810
  * crypto: caam - fix memory corruption in ahash_final_ctx
- LP: #1500810
  * mm/hwpoison: fix page refcount of unknown non LRU page
- LP: #1500810
  * ipc,sem: fix use after free on IPC_RMID after a task using same
semaphore set exits
- LP: #1500810
  * ipc/sem.c: change memory barrier in sem_lock() to smp_rmb()
- LP: #1500810
  * ipc/sem.c: update/correct memory barriers
- LP: #1500810
  * Add factory recertified Crucial M500s to blacklist
- LP: #1500810
  * arm64: KVM: Fix host crash when injecting a fault into a 32bit guest
- LP: #1500810
  * batman-adv: protect tt_local_entry from concurrent delete events
- LP: #1500810
  * ip6_gre: release cached dst on tunnel removal
- LP: #1500810
  * net: Fix RCU splat in af_key
- LP: #1500810
  * rds: fix an integer overflow test in rds_info_getsockopt()
- LP: #1500810
  * udp: fix dst races with multicast early demux
- LP: #1500810
  

[Kernel-packages] [Bug 1496430] Re: Docker-1.8.2 can't create container, due to apparmor denying 'disconnected path'

2015-10-19 Thread Launchpad Bug Tracker
This bug was fixed in the package linux - 3.2.0-92.130

---
linux (3.2.0-92.130) precise; urgency=low

  [ Brad Figg ]

  * Release Tracking Bug
- LP: #1500854

  [ dan.street...@canonical.com ]

  * [Config] HOTPLUG_PCI_ACPI=y
- LP: #1479031

  [ John Johansen ]

  * SAUCE: (no-up) apparmor: fix mount not handling disconnected paths
- LP: #1496430

  [ Upstream Kernel Changes ]

  * RDS: verify the underlying transport exists before creating a
connection
- LP: #1496232
- CVE-2015-6937
  * virtio-net: drop NETIF_F_FRAGLIST
- LP: #1484793
- CVE-2015-5156

 -- Brad Figg   Mon, 05 Oct 2015 13:50:43 -0700

-- 
You received this bug notification because you are a member of Kernel
Packages, which is subscribed to linux-lts-utopic in Ubuntu.
https://bugs.launchpad.net/bugs/1496430

Title:
  Docker-1.8.2 can't create container, due to apparmor denying
  'disconnected path'

Status in AppArmor:
  In Progress
Status in linux package in Ubuntu:
  Fix Released
Status in linux-lts-utopic package in Ubuntu:
  Invalid
Status in linux source package in Precise:
  Fix Released
Status in linux-lts-utopic source package in Precise:
  Invalid
Status in linux source package in Trusty:
  Fix Released
Status in linux-lts-utopic source package in Trusty:
  Fix Released
Status in linux source package in Vivid:
  Fix Committed
Status in linux-lts-utopic source package in Vivid:
  Invalid
Status in linux source package in Wily:
  Fix Released
Status in linux-lts-utopic source package in Wily:
  Invalid

Bug description:
  I'm trying to get docker-1.8.2-rc1 to work on snappy, while doing so I
  got this apparmor denial:

  Sep 10 09:12:35 localhost.localdomain audit[1320]: AVC
  apparmor="DENIED" operation="mount" info="Failed name lookup -
  disconnected path" error=-13 profile="docker_docker-
  daemon_IAUSSaDNVTJR" name="/run/docker/netns/6901f2b6dd4c/" pid=1320
  comm="exe" srcname="" flags="rw, bind"

  and trying to chase it I got:
  http://paste.ubuntu.com/12341612/

  so docker is trying to issue this mount: 
  syscall.Mount("/proc/self/ns/net", /var/run/docker/netns/5b9b1ba4437b, 
"bind", 4096 (syscall.MS_BIND), "")

  from https://golang.org/pkg/syscall/#Mount
  func Mount(source string, target string, fstype string, flags uintptr, data 
string) (err error)

  which is denied as if there wasn't a source?

To manage notifications about this bug go to:
https://bugs.launchpad.net/apparmor/+bug/1496430/+subscriptions

-- 
Mailing list: https://launchpad.net/~kernel-packages
Post to : kernel-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~kernel-packages
More help   : https://help.launchpad.net/ListHelp


[Kernel-packages] [Bug 1496430] Re: Docker-1.8.2 can't create container, due to apparmor denying 'disconnected path'

2015-10-19 Thread Launchpad Bug Tracker
This bug was fixed in the package linux-lts-utopic -
3.16.0-51.69~14.04.1

---
linux-lts-utopic (3.16.0-51.69~14.04.1) trusty; urgency=low

  [ Luis Henriques ]

  * Release Tracking Bug
- LP: #1503717

  [ Andy Whitcroft ]

  * Revert "SAUCE: aufs3: mmap: Fix races in madvise_remove() and
sys_msync()"
- LP: #1503655

  [ Ben Hutchings ]

  * SAUCE: aufs3: mmap: Fix races in madvise_remove() and sys_msync()
- LP: #1503655
- CVE-2015-7312

linux-lts-utopic (3.16.0-51.68~14.04.1) trusty; urgency=low

  [ Luis Henriques ]

  * Release Tracking Bug
- LP: #1503239

  [ Ben Hutchings ]

  * SAUCE: aufs3: mmap: Fix races in madvise_remove() and sys_msync()
- CVE-2015-7312

  [ John Johansen ]

  * SAUCE: (no-up) apparmor: fix mount not handling disconnected paths
- LP: #1496430

  [ Leann Ogasawara ]

  * [Config] d-i -- Add sfc to nic-modules udeb
- LP: #1481490

  [ Upstream Kernel Changes ]

  * mmc: sdhci-pci: set the clear transfer mode register quirk for O2Micro
- LP: #1472843
  * mmc: sdhci: Add a quirk for AMD SDHC transfer mode register need to be
cleared for cmd without data
- LP: #1472843
  * md: use kzalloc() when bitmap is disabled
- LP: #1500484
  * sparc64: Fix userspace FPU register corruptions.
- LP: #1500484
  * ARM: OMAP2+: hwmod: Fix _wait_target_ready() for hwmods without sysc
- LP: #1500484
  * ASoC: pcm1681: Fix setting de-emphasis sampling rate selection
- LP: #1500484
  * iscsi-target: Fix use-after-free during TPG session shutdown
- LP: #1500484
  * iscsi-target: Fix iscsit_start_kthreads failure OOPs
- LP: #1500484
  * iscsi-target: Fix iser explicit logout TX kthread leak
- LP: #1500484
  * ARM: dts: i.MX35: Fix can support.
- LP: #1500484
  * ALSA: hda - Apply fixup for another Toshiba Satellite S50D
- LP: #1500484
  * vhost: actually track log eventfd file
- LP: #1500484
  * arm64/efi: map the entire UEFI vendor string before reading it
- LP: #1500484
  * xfs: remote attribute headers contain an invalid LSN
- LP: #1500484
  * xfs: remote attributes need to be considered data
- LP: #1500484
  * ALSA: hda - Apply a fixup to Dell Vostro 5480
- LP: #1500484
  * ALSA: usb-audio: add dB range mapping for some devices
- LP: #1500484
  * drm/i915: Replace WARN inside I915_READ64_2x32 with retry loop
- LP: #1500484
  * drm/radeon/combios: add some validation of lvds values
- LP: #1500484
  * x86/efi: Use all 64 bit of efi_memmap in setup_e820()
- LP: #1500484
  * ipr: Fix locking for unit attention handling
- LP: #1500484
  * ipr: Fix incorrect trace indexing
- LP: #1500484
  * ipr: Fix invalid array indexing for HRRQ
- LP: #1500484
  * ALSA: hda - Fix MacBook Pro 5,2 quirk
- LP: #1500484
  * x86/xen: Probe target addresses in set_aliased_prot() before the
hypercall
- LP: #1500484
  * netfilter: ctnetlink: put back references to master ct and expect
objects
- LP: #1500484
  * ipvs: do not use random local source address for tunnels
- LP: #1500484
  * ipvs: fix crash if scheduler is changed
- LP: #1500484
  * ipvs: fix crash with sync protocol v0 and FTP
- LP: #1500484
  * netfilter: nf_conntrack: Support expectations in different zones
- LP: #1500484
  * NFS: Don't revalidate the mapping if both size and change attr are up
to date
- LP: #1500484
  * ALSA: hda - fix cs4210_spdif_automute()
- LP: #1500484
  * net/mlx4_core: Fix wrong index in propagating port change event to VFs
- LP: #1500484
  * niu: don't count tx error twice in case of headroom realloc fails
- LP: #1500484
  * avr32: handle NULL as a valid clock object
- LP: #1500484
  * packet: missing dev_put() in packet_do_bind()
- LP: #1500484
  * packet: tpacket_snd(): fix signed/unsigned comparison
- LP: #1500484
  * bridge: mdb: fix delmdb state in the notification
- LP: #1500484
  * net: sched: fix refcount imbalance in actions
- LP: #1500484
  * act_pedit: check binding before calling tcf_hash_release()
- LP: #1500484
  * PCI: Restore PCI_MSIX_FLAGS_BIRMASK definition
- LP: #1500484
  * USB: qcserial/option: make AT URCs work for Sierra Wireless
MC7305/MC7355
- LP: #1500484
  * USB: qcserial: Add support for Dell Wireless 5809e 4G Modem
- LP: #1500484
  * nfsd: Drop BUG_ON and ignore SECLABEL on absent filesystem
- LP: #1500484
  * crypto: ixp4xx - Remove bogus BUG_ON on scattered dst buffer
- LP: #1500484
  * USB: sierra: add 1199:68AB device ID
- LP: #1500484
  * rbd: fix copyup completion race
- LP: #1500484
  * md/bitmap: return an error when bitmap superblock is corrupt.
- LP: #1500484
  * md/raid1: extend spinlock to protect raid1_end_read_request against
inconsistencies
- LP: #1500484
  * thermal: exynos: Disable the regulator on probe failure
- LP: #1500484
  * MIPS: Fix sched_getaffinity with MT FPAFF enabled
- LP: #1500484
  * MIPS: Malta: Don't 

[Kernel-packages] [Bug 1496430] Re: Docker-1.8.2 can't create container, due to apparmor denying 'disconnected path'

2015-10-13 Thread John Johansen
** Tags removed: verification-needed-trusty verification-needed-vivid
** Tags added: verification-done-trusty verification-done-vivid

-- 
You received this bug notification because you are a member of Kernel
Packages, which is subscribed to linux-lts-utopic in Ubuntu.
https://bugs.launchpad.net/bugs/1496430

Title:
  Docker-1.8.2 can't create container, due to apparmor denying
  'disconnected path'

Status in AppArmor:
  In Progress
Status in linux package in Ubuntu:
  Fix Released
Status in linux-lts-utopic package in Ubuntu:
  Invalid
Status in linux source package in Precise:
  Fix Committed
Status in linux-lts-utopic source package in Precise:
  Invalid
Status in linux source package in Trusty:
  Fix Committed
Status in linux-lts-utopic source package in Trusty:
  Fix Committed
Status in linux source package in Vivid:
  Fix Committed
Status in linux-lts-utopic source package in Vivid:
  Invalid
Status in linux source package in Wily:
  Fix Released
Status in linux-lts-utopic source package in Wily:
  Invalid

Bug description:
  I'm trying to get docker-1.8.2-rc1 to work on snappy, while doing so I
  got this apparmor denial:

  Sep 10 09:12:35 localhost.localdomain audit[1320]: AVC
  apparmor="DENIED" operation="mount" info="Failed name lookup -
  disconnected path" error=-13 profile="docker_docker-
  daemon_IAUSSaDNVTJR" name="/run/docker/netns/6901f2b6dd4c/" pid=1320
  comm="exe" srcname="" flags="rw, bind"

  and trying to chase it I got:
  http://paste.ubuntu.com/12341612/

  so docker is trying to issue this mount: 
  syscall.Mount("/proc/self/ns/net", /var/run/docker/netns/5b9b1ba4437b, 
"bind", 4096 (syscall.MS_BIND), "")

  from https://golang.org/pkg/syscall/#Mount
  func Mount(source string, target string, fstype string, flags uintptr, data 
string) (err error)

  which is denied as if there wasn't a source?

To manage notifications about this bug go to:
https://bugs.launchpad.net/apparmor/+bug/1496430/+subscriptions

-- 
Mailing list: https://launchpad.net/~kernel-packages
Post to : kernel-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~kernel-packages
More help   : https://help.launchpad.net/ListHelp


[Kernel-packages] [Bug 1496430] Re: Docker-1.8.2 can't create container, due to apparmor denying 'disconnected path'

2015-10-13 Thread John Johansen
** Tags removed: verification-needed-precise
** Tags added: verification-done-precise

-- 
You received this bug notification because you are a member of Kernel
Packages, which is subscribed to linux-lts-utopic in Ubuntu.
https://bugs.launchpad.net/bugs/1496430

Title:
  Docker-1.8.2 can't create container, due to apparmor denying
  'disconnected path'

Status in AppArmor:
  In Progress
Status in linux package in Ubuntu:
  Fix Released
Status in linux-lts-utopic package in Ubuntu:
  Invalid
Status in linux source package in Precise:
  Fix Committed
Status in linux-lts-utopic source package in Precise:
  Invalid
Status in linux source package in Trusty:
  Fix Committed
Status in linux-lts-utopic source package in Trusty:
  Fix Committed
Status in linux source package in Vivid:
  Fix Committed
Status in linux-lts-utopic source package in Vivid:
  Invalid
Status in linux source package in Wily:
  Fix Released
Status in linux-lts-utopic source package in Wily:
  Invalid

Bug description:
  I'm trying to get docker-1.8.2-rc1 to work on snappy, while doing so I
  got this apparmor denial:

  Sep 10 09:12:35 localhost.localdomain audit[1320]: AVC
  apparmor="DENIED" operation="mount" info="Failed name lookup -
  disconnected path" error=-13 profile="docker_docker-
  daemon_IAUSSaDNVTJR" name="/run/docker/netns/6901f2b6dd4c/" pid=1320
  comm="exe" srcname="" flags="rw, bind"

  and trying to chase it I got:
  http://paste.ubuntu.com/12341612/

  so docker is trying to issue this mount: 
  syscall.Mount("/proc/self/ns/net", /var/run/docker/netns/5b9b1ba4437b, 
"bind", 4096 (syscall.MS_BIND), "")

  from https://golang.org/pkg/syscall/#Mount
  func Mount(source string, target string, fstype string, flags uintptr, data 
string) (err error)

  which is denied as if there wasn't a source?

To manage notifications about this bug go to:
https://bugs.launchpad.net/apparmor/+bug/1496430/+subscriptions

-- 
Mailing list: https://launchpad.net/~kernel-packages
Post to : kernel-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~kernel-packages
More help   : https://help.launchpad.net/ListHelp


[Kernel-packages] [Bug 1496430] Re: Docker-1.8.2 can't create container, due to apparmor denying 'disconnected path'

2015-10-09 Thread Launchpad Bug Tracker
This bug was fixed in the package linux - 4.2.0-15.18

---
linux (4.2.0-15.18) wily; urgency=low

  [ Tim Gardner ]

  * Release Tracking Bug
- LP: #1503692

  [ Andy Whitcroft ]

  * Revert "SAUCE: aufs3: mmap: Fix races in madvise_remove() and sys_msync()"
Was incorrectly backported.

  [ Ben Hutchings ]

  * SAUCE: aufs3: mmap: Fix races in madvise_remove() and sys_msync()
- CVE-2015-7312

  [ Tim Gardner ]

  * [Debian] config-check and prepare using ${DEBIAN}/config/annotations
Makes the LTS update script work better.

linux (4.2.0-15.17) wily; urgency=low

  [ Tim Gardner ]

  * Release Tracking Bug
- LP: #1503016
  * rebase to v4.2.3

  [ Andrew Donnellan ]

  * SAUCE: cxl: fix leak of IRQ names in cxl_free_afu_irqs()
  * SAUCE: cxl: fix leak of ctx->irq_bitmap when releasing context via
kernel API
  * SAUCE: cxl: fix leak of ctx->mapping when releasing kernel API contexts

  [ Ben Hutchings ]

  * SAUCE: aufs3: mmap: Fix races in madvise_remove() and sys_msync()
- CVE-2015-7312

  [ Dan Carpenter ]

  * SAUCE: (noup) cxlflash: a couple off by one bugs
- LP: #1499849

  [ John Johansen ]

  * SAUCE: (no-up) apparmor: fix mount not handling disconnected paths
- LP: #1496430

  [ Manoj Kumar ]

  * SAUCE: (noup) cxlflash: Fix to avoid invalid port_sel value
- LP: #1499849
  * SAUCE: (noup) cxlflash: Replace magic numbers with literals
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix read capacity timeout
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix to double the delay each time
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix to escalate to LINK_RESET on login timeout
- LP: #1499849

  [ Matthew R. Ochs ]

  * SAUCE: (noup) cxlflash: Fix potential oops following LUN removal
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix data corruption when vLUN used over
multiple cards
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix to avoid sizeof(bool)
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix context encode mask width
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix to avoid CXL services during EEH
- LP: #1499849
  * SAUCE: (noup) cxlflash: Correct naming of limbo state and waitq
- LP: #1499849
  * SAUCE: (noup) cxlflash: Make functions static
- LP: #1499849
  * SAUCE: (noup) cxlflash: Refine host/device attributes
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix to avoid spamming the kernel log
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix to avoid stall while waiting on TMF
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix location of setting resid
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix host link up event handling
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix async interrupt bypass logic
- LP: #1499849
  * SAUCE: (noup) cxlflash: Remove dual port online dependency
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix AFU version access/storage and add check
- LP: #1499849
  * SAUCE: (noup) cxlflash: Correct usage of scsi_host_put()
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix to prevent workq from accessing freed
memory
- LP: #1499849
  * SAUCE: (noup) cxlflash: Correct behavior in device reset handler
following EEH
- LP: #1499849
  * SAUCE: (noup) cxlflash: Remove unnecessary scsi_block_requests
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix function prolog parameters and return codes
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix MMIO and endianness errors
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix to prevent EEH recovery failure
- LP: #1499849
  * SAUCE: (noup) cxlflash: Correct spelling, grammar, and alignment
mistakes
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix to prevent stale AFU RRQ
- LP: #1499849
  * SAUCE: (noup) MAINTAINERS: Add cxlflash driver
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix to avoid corrupting adapter fops
- LP: #1499849
  * SAUCE: (noup) cxlflash: Correct trace string
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix to avoid potential deadlock on EEH
- LP: #1499849
  * SAUCE: (noup) cxlflash: Fix to avoid leaving dangling interrupt
resources
- LP: #1499849

  [ Philippe Bergheaud ]

  * SAUCE: cxl: Workaround malformed pcie packets on some cards

  [ Tim Gardner ]

  * [Config] CONFIG_CC_STACKPROTECTOR_STRONG=y
- LP: #1380025
  * [Config] Add MMC modules sufficient for net booting
- LP: #1502772

  [ Upstream Kernel Changes ]

  * Initialize msg/shm IPC objects before doing ipc_addid()
  * RDS: verify the underlying transport exists before creating a
connection
  * cxl: abort cxl_pci_enable_device_hook() if PCI channel is offline
  * cxl: Fix build failure due to -Wunused-variable behaviour change
  * cxl: Fix lockdep warning while creating afu_err_buff attribute
  * USB: whiteheat: fix potential null-deref at probe
- LP: #1478826
- CVE-2015-5257
  * dcache: Handle escaped paths in prepend_path
- CVE-2015-2925
  * vfs: Test for and handle paths that are 

[Kernel-packages] [Bug 1496430] Re: Docker-1.8.2 can't create container, due to apparmor denying 'disconnected path'

2015-10-08 Thread Luis Henriques
This bug is awaiting verification that the kernel in -proposed solves
the problem. Please test the kernel and update this bug with the
results. If the problem is solved, change the tag 'verification-needed-
trusty' to 'verification-done-trusty'.

If verification is not done by 5 working days from today, this fix will
be dropped from the source code, and this bug will be closed.

See https://wiki.ubuntu.com/Testing/EnableProposed for documentation how
to enable and use -proposed. Thank you!

-- 
You received this bug notification because you are a member of Kernel
Packages, which is subscribed to linux-lts-utopic in Ubuntu.
https://bugs.launchpad.net/bugs/1496430

Title:
  Docker-1.8.2 can't create container, due to apparmor denying
  'disconnected path'

Status in AppArmor:
  In Progress
Status in linux package in Ubuntu:
  Incomplete
Status in linux-lts-utopic package in Ubuntu:
  Invalid
Status in linux source package in Precise:
  Fix Committed
Status in linux-lts-utopic source package in Precise:
  Invalid
Status in linux source package in Trusty:
  Fix Committed
Status in linux-lts-utopic source package in Trusty:
  Fix Committed
Status in linux source package in Vivid:
  Fix Committed
Status in linux-lts-utopic source package in Vivid:
  Invalid
Status in linux source package in Wily:
  Incomplete
Status in linux-lts-utopic source package in Wily:
  Invalid

Bug description:
  I'm trying to get docker-1.8.2-rc1 to work on snappy, while doing so I
  got this apparmor denial:

  Sep 10 09:12:35 localhost.localdomain audit[1320]: AVC
  apparmor="DENIED" operation="mount" info="Failed name lookup -
  disconnected path" error=-13 profile="docker_docker-
  daemon_IAUSSaDNVTJR" name="/run/docker/netns/6901f2b6dd4c/" pid=1320
  comm="exe" srcname="" flags="rw, bind"

  and trying to chase it I got:
  http://paste.ubuntu.com/12341612/

  so docker is trying to issue this mount: 
  syscall.Mount("/proc/self/ns/net", /var/run/docker/netns/5b9b1ba4437b, 
"bind", 4096 (syscall.MS_BIND), "")

  from https://golang.org/pkg/syscall/#Mount
  func Mount(source string, target string, fstype string, flags uintptr, data 
string) (err error)

  which is denied as if there wasn't a source?

To manage notifications about this bug go to:
https://bugs.launchpad.net/apparmor/+bug/1496430/+subscriptions

-- 
Mailing list: https://launchpad.net/~kernel-packages
Post to : kernel-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~kernel-packages
More help   : https://help.launchpad.net/ListHelp


[Kernel-packages] [Bug 1496430] Re: Docker-1.8.2 can't create container, due to apparmor denying 'disconnected path'

2015-10-08 Thread Luis Henriques
This bug is awaiting verification that the kernel in -proposed solves
the problem. Please test the kernel and update this bug with the
results. If the problem is solved, change the tag 'verification-needed-
vivid' to 'verification-done-vivid'.

If verification is not done by 5 working days from today, this fix will
be dropped from the source code, and this bug will be closed.

See https://wiki.ubuntu.com/Testing/EnableProposed for documentation how
to enable and use -proposed. Thank you!

-- 
You received this bug notification because you are a member of Kernel
Packages, which is subscribed to linux-lts-utopic in Ubuntu.
https://bugs.launchpad.net/bugs/1496430

Title:
  Docker-1.8.2 can't create container, due to apparmor denying
  'disconnected path'

Status in AppArmor:
  In Progress
Status in linux package in Ubuntu:
  Incomplete
Status in linux-lts-utopic package in Ubuntu:
  Invalid
Status in linux source package in Precise:
  Fix Committed
Status in linux-lts-utopic source package in Precise:
  Invalid
Status in linux source package in Trusty:
  Fix Committed
Status in linux-lts-utopic source package in Trusty:
  Fix Committed
Status in linux source package in Vivid:
  Fix Committed
Status in linux-lts-utopic source package in Vivid:
  Invalid
Status in linux source package in Wily:
  Incomplete
Status in linux-lts-utopic source package in Wily:
  Invalid

Bug description:
  I'm trying to get docker-1.8.2-rc1 to work on snappy, while doing so I
  got this apparmor denial:

  Sep 10 09:12:35 localhost.localdomain audit[1320]: AVC
  apparmor="DENIED" operation="mount" info="Failed name lookup -
  disconnected path" error=-13 profile="docker_docker-
  daemon_IAUSSaDNVTJR" name="/run/docker/netns/6901f2b6dd4c/" pid=1320
  comm="exe" srcname="" flags="rw, bind"

  and trying to chase it I got:
  http://paste.ubuntu.com/12341612/

  so docker is trying to issue this mount: 
  syscall.Mount("/proc/self/ns/net", /var/run/docker/netns/5b9b1ba4437b, 
"bind", 4096 (syscall.MS_BIND), "")

  from https://golang.org/pkg/syscall/#Mount
  func Mount(source string, target string, fstype string, flags uintptr, data 
string) (err error)

  which is denied as if there wasn't a source?

To manage notifications about this bug go to:
https://bugs.launchpad.net/apparmor/+bug/1496430/+subscriptions

-- 
Mailing list: https://launchpad.net/~kernel-packages
Post to : kernel-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~kernel-packages
More help   : https://help.launchpad.net/ListHelp


[Kernel-packages] [Bug 1496430] Re: Docker-1.8.2 can't create container, due to apparmor denying 'disconnected path'

2015-10-08 Thread Luis Henriques
This bug is awaiting verification that the kernel in -proposed solves
the problem. Please test the kernel and update this bug with the
results. If the problem is solved, change the tag 'verification-needed-
precise' to 'verification-done-precise'.

If verification is not done by 5 working days from today, this fix will
be dropped from the source code, and this bug will be closed.

See https://wiki.ubuntu.com/Testing/EnableProposed for documentation how
to enable and use -proposed. Thank you!


** Tags added: verification-needed-precise verification-needed-trusty 
verification-needed-vivid

-- 
You received this bug notification because you are a member of Kernel
Packages, which is subscribed to linux-lts-utopic in Ubuntu.
https://bugs.launchpad.net/bugs/1496430

Title:
  Docker-1.8.2 can't create container, due to apparmor denying
  'disconnected path'

Status in AppArmor:
  In Progress
Status in linux package in Ubuntu:
  Incomplete
Status in linux-lts-utopic package in Ubuntu:
  Invalid
Status in linux source package in Precise:
  Fix Committed
Status in linux-lts-utopic source package in Precise:
  Invalid
Status in linux source package in Trusty:
  Fix Committed
Status in linux-lts-utopic source package in Trusty:
  Fix Committed
Status in linux source package in Vivid:
  Fix Committed
Status in linux-lts-utopic source package in Vivid:
  Invalid
Status in linux source package in Wily:
  Incomplete
Status in linux-lts-utopic source package in Wily:
  Invalid

Bug description:
  I'm trying to get docker-1.8.2-rc1 to work on snappy, while doing so I
  got this apparmor denial:

  Sep 10 09:12:35 localhost.localdomain audit[1320]: AVC
  apparmor="DENIED" operation="mount" info="Failed name lookup -
  disconnected path" error=-13 profile="docker_docker-
  daemon_IAUSSaDNVTJR" name="/run/docker/netns/6901f2b6dd4c/" pid=1320
  comm="exe" srcname="" flags="rw, bind"

  and trying to chase it I got:
  http://paste.ubuntu.com/12341612/

  so docker is trying to issue this mount: 
  syscall.Mount("/proc/self/ns/net", /var/run/docker/netns/5b9b1ba4437b, 
"bind", 4096 (syscall.MS_BIND), "")

  from https://golang.org/pkg/syscall/#Mount
  func Mount(source string, target string, fstype string, flags uintptr, data 
string) (err error)

  which is denied as if there wasn't a source?

To manage notifications about this bug go to:
https://bugs.launchpad.net/apparmor/+bug/1496430/+subscriptions

-- 
Mailing list: https://launchpad.net/~kernel-packages
Post to : kernel-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~kernel-packages
More help   : https://help.launchpad.net/ListHelp


[Kernel-packages] [Bug 1496430] Re: Docker-1.8.2 can't create container, due to apparmor denying 'disconnected path'

2015-10-06 Thread Launchpad Bug Tracker
** Branch linked: lp:ubuntu/trusty-proposed/linux-lts-vivid

-- 
You received this bug notification because you are a member of Kernel
Packages, which is subscribed to linux-lts-utopic in Ubuntu.
https://bugs.launchpad.net/bugs/1496430

Title:
  Docker-1.8.2 can't create container, due to apparmor denying
  'disconnected path'

Status in AppArmor:
  In Progress
Status in linux package in Ubuntu:
  Incomplete
Status in linux-lts-utopic package in Ubuntu:
  Invalid
Status in linux source package in Precise:
  Fix Committed
Status in linux-lts-utopic source package in Precise:
  Invalid
Status in linux source package in Trusty:
  Fix Committed
Status in linux-lts-utopic source package in Trusty:
  Fix Committed
Status in linux source package in Vivid:
  Fix Committed
Status in linux-lts-utopic source package in Vivid:
  Invalid
Status in linux source package in Wily:
  Incomplete
Status in linux-lts-utopic source package in Wily:
  Invalid

Bug description:
  I'm trying to get docker-1.8.2-rc1 to work on snappy, while doing so I
  got this apparmor denial:

  Sep 10 09:12:35 localhost.localdomain audit[1320]: AVC
  apparmor="DENIED" operation="mount" info="Failed name lookup -
  disconnected path" error=-13 profile="docker_docker-
  daemon_IAUSSaDNVTJR" name="/run/docker/netns/6901f2b6dd4c/" pid=1320
  comm="exe" srcname="" flags="rw, bind"

  and trying to chase it I got:
  http://paste.ubuntu.com/12341612/

  so docker is trying to issue this mount: 
  syscall.Mount("/proc/self/ns/net", /var/run/docker/netns/5b9b1ba4437b, 
"bind", 4096 (syscall.MS_BIND), "")

  from https://golang.org/pkg/syscall/#Mount
  func Mount(source string, target string, fstype string, flags uintptr, data 
string) (err error)

  which is denied as if there wasn't a source?

To manage notifications about this bug go to:
https://bugs.launchpad.net/apparmor/+bug/1496430/+subscriptions

-- 
Mailing list: https://launchpad.net/~kernel-packages
Post to : kernel-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~kernel-packages
More help   : https://help.launchpad.net/ListHelp


[Kernel-packages] [Bug 1496430] Re: Docker-1.8.2 can't create container, due to apparmor denying 'disconnected path'

2015-10-01 Thread Luis Henriques
** Also affects: linux (Ubuntu)
   Importance: Undecided
   Status: New

** Also affects: linux (Ubuntu Trusty)
   Importance: Undecided
   Status: New

** Also affects: linux (Ubuntu Vivid)
   Importance: Undecided
   Status: New

** Also affects: linux (Ubuntu Precise)
   Importance: Undecided
   Status: New

** Also affects: linux-lts-utopic (Ubuntu)
   Importance: Undecided
   Status: New

** Changed in: linux-lts-utopic (Ubuntu Precise)
   Status: New => Invalid

** Changed in: linux-lts-utopic (Ubuntu Vivid)
   Status: New => Invalid

** Changed in: linux-lts-utopic (Ubuntu)
   Status: New => Invalid

** Changed in: linux (Ubuntu)
   Status: New => Invalid

** Changed in: linux (Ubuntu Precise)
   Status: New => Fix Committed

** Changed in: linux (Ubuntu Trusty)
   Status: New => Fix Committed

-- 
You received this bug notification because you are a member of Kernel
Packages, which is subscribed to linux in Ubuntu.
https://bugs.launchpad.net/bugs/1496430

Title:
  Docker-1.8.2 can't create container, due to apparmor denying
  'disconnected path'

Status in AppArmor:
  In Progress
Status in linux package in Ubuntu:
  Invalid
Status in linux-lts-utopic package in Ubuntu:
  Invalid
Status in linux source package in Precise:
  Fix Committed
Status in linux-lts-utopic source package in Precise:
  Invalid
Status in linux source package in Trusty:
  Fix Committed
Status in linux-lts-utopic source package in Trusty:
  Fix Committed
Status in linux source package in Vivid:
  New
Status in linux-lts-utopic source package in Vivid:
  Invalid

Bug description:
  I'm trying to get docker-1.8.2-rc1 to work on snappy, while doing so I
  got this apparmor denial:

  Sep 10 09:12:35 localhost.localdomain audit[1320]: AVC
  apparmor="DENIED" operation="mount" info="Failed name lookup -
  disconnected path" error=-13 profile="docker_docker-
  daemon_IAUSSaDNVTJR" name="/run/docker/netns/6901f2b6dd4c/" pid=1320
  comm="exe" srcname="" flags="rw, bind"

  and trying to chase it I got:
  http://paste.ubuntu.com/12341612/

  so docker is trying to issue this mount: 
  syscall.Mount("/proc/self/ns/net", /var/run/docker/netns/5b9b1ba4437b, 
"bind", 4096 (syscall.MS_BIND), "")

  from https://golang.org/pkg/syscall/#Mount
  func Mount(source string, target string, fstype string, flags uintptr, data 
string) (err error)

  which is denied as if there wasn't a source?

To manage notifications about this bug go to:
https://bugs.launchpad.net/apparmor/+bug/1496430/+subscriptions

-- 
Mailing list: https://launchpad.net/~kernel-packages
Post to : kernel-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~kernel-packages
More help   : https://help.launchpad.net/ListHelp


[Kernel-packages] [Bug 1496430] Re: Docker-1.8.2 can't create container, due to apparmor denying 'disconnected path'

2015-10-01 Thread Luis Henriques
** Changed in: linux-lts-utopic (Ubuntu Trusty)
   Status: New => Fix Committed

** Changed in: linux (Ubuntu Vivid)
   Status: New => Fix Committed

** Also affects: linux (Ubuntu Wily)
   Importance: Undecided
   Status: Invalid

** Also affects: linux-lts-utopic (Ubuntu Wily)
   Importance: Undecided
   Status: Invalid

** Changed in: linux (Ubuntu Wily)
   Status: Invalid => New

-- 
You received this bug notification because you are a member of Kernel
Packages, which is subscribed to linux-lts-utopic in Ubuntu.
https://bugs.launchpad.net/bugs/1496430

Title:
  Docker-1.8.2 can't create container, due to apparmor denying
  'disconnected path'

Status in AppArmor:
  In Progress
Status in linux package in Ubuntu:
  Incomplete
Status in linux-lts-utopic package in Ubuntu:
  Invalid
Status in linux source package in Precise:
  Fix Committed
Status in linux-lts-utopic source package in Precise:
  Invalid
Status in linux source package in Trusty:
  Fix Committed
Status in linux-lts-utopic source package in Trusty:
  Fix Committed
Status in linux source package in Vivid:
  Fix Committed
Status in linux-lts-utopic source package in Vivid:
  Invalid
Status in linux source package in Wily:
  Incomplete
Status in linux-lts-utopic source package in Wily:
  Invalid

Bug description:
  I'm trying to get docker-1.8.2-rc1 to work on snappy, while doing so I
  got this apparmor denial:

  Sep 10 09:12:35 localhost.localdomain audit[1320]: AVC
  apparmor="DENIED" operation="mount" info="Failed name lookup -
  disconnected path" error=-13 profile="docker_docker-
  daemon_IAUSSaDNVTJR" name="/run/docker/netns/6901f2b6dd4c/" pid=1320
  comm="exe" srcname="" flags="rw, bind"

  and trying to chase it I got:
  http://paste.ubuntu.com/12341612/

  so docker is trying to issue this mount: 
  syscall.Mount("/proc/self/ns/net", /var/run/docker/netns/5b9b1ba4437b, 
"bind", 4096 (syscall.MS_BIND), "")

  from https://golang.org/pkg/syscall/#Mount
  func Mount(source string, target string, fstype string, flags uintptr, data 
string) (err error)

  which is denied as if there wasn't a source?

To manage notifications about this bug go to:
https://bugs.launchpad.net/apparmor/+bug/1496430/+subscriptions

-- 
Mailing list: https://launchpad.net/~kernel-packages
Post to : kernel-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~kernel-packages
More help   : https://help.launchpad.net/ListHelp