Re: [lxc-devel] Error "unshare: Operation not permitted" when trying to create user container

2014-02-21 Thread Serge Hallyn
Quoting Brian Campbell (lam...@continuation.org): > > On Feb 20, 2014, at 11:23 AM, Serge Hallyn wrote: > > > Quoting Brian Campbell (lam...@continuation.org): > >> On Feb 20, 2014, at 9:21 AM, Serge Hallyn wrote: > >> > >>> Quoting Brian Campbell (lam...@continuation.org): > On Feb 18, 2

Re: [lxc-devel] Error "unshare: Operation not permitted" when trying to create user container

2014-02-20 Thread Brian Campbell
On Feb 20, 2014, at 11:23 AM, Serge Hallyn wrote: > Quoting Brian Campbell (lam...@continuation.org): >> On Feb 20, 2014, at 9:21 AM, Serge Hallyn wrote: >> >>> Quoting Brian Campbell (lam...@continuation.org): On Feb 18, 2014, at 10:25 AM, Serge Hallyn wrote: > It looks like you're

Re: [lxc-devel] Error "unshare: Operation not permitted" when trying to create user container

2014-02-20 Thread Serge Hallyn
Quoting Brian Campbell (lam...@continuation.org): > On Feb 20, 2014, at 9:21 AM, Serge Hallyn wrote: > > > Quoting Brian Campbell (lam...@continuation.org): > >> On Feb 18, 2014, at 10:25 AM, Serge Hallyn wrote: > >>> It looks like you're in the root cgroup and starting as non-root. > >>> Withou

Re: [lxc-devel] Error "unshare: Operation not permitted" when trying to create user container

2014-02-20 Thread Brian Campbell
On Feb 20, 2014, at 9:21 AM, Serge Hallyn wrote: > Quoting Brian Campbell (lam...@continuation.org): >> On Feb 18, 2014, at 10:25 AM, Serge Hallyn wrote: >>> It looks like you're in the root cgroup and starting as non-root. >>> Without being root you indeed do not have the rights to create new >

Re: [lxc-devel] Error "unshare: Operation not permitted" when trying to create user container

2014-02-20 Thread Serge Hallyn
Quoting Brian Campbell (lam...@continuation.org): > On Feb 18, 2014, at 10:25 AM, Serge Hallyn wrote: > > It looks like you're in the root cgroup and starting as non-root. > > Without being root you indeed do not have the rights to create new > > cgroups there. You'll need to either use lxc as ro

Re: [lxc-devel] Error "unshare: Operation not permitted" when trying to create user container

2014-02-19 Thread Brian Campbell
On Feb 20, 2014, at 1:29 AM, Brian Campbell wrote: > On Feb 18, 2014, at 10:25 AM, Serge Hallyn wrote: > >> Quoting Brian Campbell (lam...@continuation.org): >>> On Feb 18, 2014, at 12:16 AM, Serge Hallyn wrote: >>> > Ah, that's the ticket: > > lambda@gherkin:~$ cat /proc/sys/ke

Re: [lxc-devel] Error "unshare: Operation not permitted" when trying to create user container

2014-02-19 Thread Brian Campbell
On Feb 18, 2014, at 10:25 AM, Serge Hallyn wrote: > Quoting Brian Campbell (lam...@continuation.org): >> On Feb 18, 2014, at 12:16 AM, Serge Hallyn wrote: >> Ah, that's the ticket: lambda@gherkin:~$ cat /proc/sys/kernel/unprivileged_userns_clone 0 Looks like this

Re: [lxc-devel] Error "unshare: Operation not permitted" when trying to create user container

2014-02-18 Thread Serge Hallyn
Quoting Brian Campbell (lam...@continuation.org): > On Feb 18, 2014, at 12:16 AM, Serge Hallyn wrote: > > >> Ah, that's the ticket: > >> > >> lambda@gherkin:~$ cat /proc/sys/kernel/unprivileged_userns_clone > >> 0 > >> > >> Looks like this is a Debian specific patch, > > > > *cough* pls not to

Re: [lxc-devel] Error "unshare: Operation not permitted" when trying to create user container

2014-02-17 Thread Brian Campbell
On Feb 18, 2014, at 12:16 AM, Serge Hallyn wrote: >> Ah, that's the ticket: >> >> lambda@gherkin:~$ cat /proc/sys/kernel/unprivileged_userns_clone >> 0 >> >> Looks like this is a Debian specific patch, > > *cough* pls not to ask how i knew to query it kthx > >> which is why looking at the ups

Re: [lxc-devel] Error "unshare: Operation not permitted" when trying to create user container

2014-02-17 Thread Serge Hallyn
Quoting Brian Campbell (lam...@continuation.org): > On Feb 17, 2014, at 11:11 AM, Serge Hallyn wrote: > > > Quoting Brian Campbell (lam...@continuation.org): > >> I tried the demo_userns.c example code from this LWN article > >> https://lwn.net/Articles/532593/ and got the same result: > >> > >

Re: [lxc-devel] Error "unshare: Operation not permitted" when trying to create user container

2014-02-17 Thread Brian Campbell
On Feb 17, 2014, at 11:11 AM, Serge Hallyn wrote: > Quoting Brian Campbell (lam...@continuation.org): >> I tried the demo_userns.c example code from this LWN article >> https://lwn.net/Articles/532593/ and got the same result: >> >> lambda@gherkin:userns$ ./demo_userns >> clone: Operation not p

Re: [lxc-devel] Error "unshare: Operation not permitted" when trying to create user container

2014-02-17 Thread Serge Hallyn
Quoting Brian Campbell (lam...@continuation.org): > I tried the demo_userns.c example code from this LWN article > https://lwn.net/Articles/532593/ and got the same result: > > lambda@gherkin:userns$ ./demo_userns > clone: Operation not permitted > > So it looks like something is preventing me f

Re: [lxc-devel] Error "unshare: Operation not permitted" when trying to create user container

2014-02-16 Thread Brian Campbell
On Feb 16, 2014, at 8:30 PM, Stéphane Graber wrote: > On Sun, Feb 16, 2014 at 08:22:40PM -0500, Brian Campbell wrote: >> >> On Feb 16, 2014, at 12:53 PM, Stéphane Graber wrote: >> >>> On Sun, Feb 16, 2014 at 12:49:44PM -0500, Brian Campbell wrote: On Feb 16, 2014, at 12:23 PM, Stéphane Gr

Re: [lxc-devel] Error "unshare: Operation not permitted" when trying to create user container

2014-02-16 Thread Stéphane Graber
On Sun, Feb 16, 2014 at 08:22:40PM -0500, Brian Campbell wrote: > > On Feb 16, 2014, at 12:53 PM, Stéphane Graber wrote: > > > On Sun, Feb 16, 2014 at 12:49:44PM -0500, Brian Campbell wrote: > >> On Feb 16, 2014, at 12:23 PM, Stéphane Graber wrote: > >> > >>> On Sun, Feb 16, 2014 at 03:51:50AM

Re: [lxc-devel] Error "unshare: Operation not permitted" when trying to create user container

2014-02-16 Thread Brian Campbell
On Feb 16, 2014, at 12:53 PM, Stéphane Graber wrote: > On Sun, Feb 16, 2014 at 12:49:44PM -0500, Brian Campbell wrote: >> On Feb 16, 2014, at 12:23 PM, Stéphane Graber wrote: >> >>> On Sun, Feb 16, 2014 at 03:51:50AM -0500, Brian Campbell wrote: I'm running Debian Jessie (testing), and co

Re: [lxc-devel] Error "unshare: Operation not permitted" when trying to create user container

2014-02-16 Thread Stéphane Graber
On Sun, Feb 16, 2014 at 12:49:44PM -0500, Brian Campbell wrote: > On Feb 16, 2014, at 12:23 PM, Stéphane Graber wrote: > > > On Sun, Feb 16, 2014 at 03:51:50AM -0500, Brian Campbell wrote: > >> I'm running Debian Jessie (testing), and compiled lxc from a fresh git > >> clone (7da8ab1: close inhe

Re: [lxc-devel] Error "unshare: Operation not permitted" when trying to create user container

2014-02-16 Thread Brian Campbell
On Feb 16, 2014, at 12:23 PM, Stéphane Graber wrote: > On Sun, Feb 16, 2014 at 03:51:50AM -0500, Brian Campbell wrote: >> I'm running Debian Jessie (testing), and compiled lxc from a fresh git clone >> (7da8ab1: close inherited fds when we still have proc mounted). I would like >> to create a u

Re: [lxc-devel] Error "unshare: Operation not permitted" when trying to create user container

2014-02-16 Thread Stéphane Graber
On Sun, Feb 16, 2014 at 03:51:50AM -0500, Brian Campbell wrote: > I'm running Debian Jessie (testing), and compiled lxc from a fresh git clone > (7da8ab1: close inherited fds when we still have proc mounted). I would like > to create a user container without using root privileges, so I set up UID