Re: [systemd-devel] about /run/cgmanager/fs

2015-11-19 Thread Cameron Norman
believe the lxc-users list is where cgmanager support questions should be directed to. Best regards, -- Cameron Norman ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org http://lists.freedesktop.org/mailman/listinfo/systemd-devel

[systemd-devel] systemd-sysctl: improvement in LXC containers

2015-10-30 Thread Cameron Norman
/`. The ExecStart would then be `/usr/lib/systemd/systemd-sysctl --prefix net`. Problem identified and worked around here: https://github.com/lxc/lxc/pull/683 Thank you, -- Cameron Norman ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org http

Re: [systemd-devel] Don't allow to restart emergency.service/rescue.service

2015-05-05 Thread Cameron Norman
On Mon, May 4, 2015 at 5:54 AM, Michael Biebl mbi...@gmail.com wrote: 2015-05-04 14:49 GMT+02:00 Michael Biebl mbi...@gmail.com: Since emergency.service has KillMode=process the running bash kept running, and the result was an unusable system. Btw, what's the reason for using

Re: [systemd-devel] Don't allow to restart emergency.service/rescue.service

2015-05-05 Thread Cameron Norman
On Tue, May 5, 2015 at 4:47 PM, Cameron Norman camerontnor...@gmail.com wrote: On Mon, May 4, 2015 at 5:54 AM, Michael Biebl mbi...@gmail.com wrote: 2015-05-04 14:49 GMT+02:00 Michael Biebl mbi...@gmail.com: Since emergency.service has KillMode=process the running bash kept running

Re: [systemd-devel] timers always run when time changes

2015-04-30 Thread Cameron Norman
synced? Cheers, -- Cameron Norman ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org http://lists.freedesktop.org/mailman/listinfo/systemd-devel

Re: [systemd-devel] SD_BUS_VTABLE_CAPABILITY

2015-04-16 Thread Cameron Norman
. If you could be so kind, could you summarize the other uses you have? And if you can, explain why using regular user/group credentials does not achieve the goal. Thank you, -- Cameron Norman ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org

Re: [systemd-devel] sshd.service fails on boot when primary listener is a bridge (br0) instead of real interface (eth0). What dependency is needed?

2015-04-12 Thread Cameron Norman
because the bridge is up at a later time than the ethernet device. -- Cameron Norman ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org http://lists.freedesktop.org/mailman/listinfo/systemd-devel

Re: [systemd-devel] [RFC 0/6] A network proxy management daemon, systemd-proxy-discoveryd

2015-04-12 Thread Cameron Norman
duktape is preferred? Smaller memory footprint? Thanks, -- Cameron Norman ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org http://lists.freedesktop.org/mailman/listinfo/systemd-devel

Re: [systemd-devel] [PATCH] Set the NOCOW flag for the journal via tmpfiles

2015-04-03 Thread Cameron Norman
but has failed libero.it's required tests for authentication. Best regards, -- Cameron Norman On 2015-03-21 12:56, Goffredo Baroncelli wrote: Hi all, these patches set reverts the commit 11689d2 journald: turn off COW for journal files on btrfs which enables *unconditionally* the NOCOW flag

Re: [systemd-devel] [RFC] activate on DBus signal

2015-03-23 Thread Cameron Norman
://bazaar.launchpad.net/~elementary-apps/capnet-assist/trunk/view/head:/90captive_portal_test Cheers, -- Cameron Norman ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org http://lists.freedesktop.org/mailman/listinfo/systemd-devel

[systemd-devel] is-enabled does not work

2015-03-20 Thread Cameron Norman
not work on the Debian systems? IIRC debian uses at as the service name. -- Cameron Norman ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org http://lists.freedesktop.org/mailman/listinfo/systemd-devel

Re: [systemd-devel] feature request: dlopen

2015-02-22 Thread Cameron Norman
that is an extra unused 600kb library, which is completely insignificant. And when it is significant you are usually in situation where you are compiling your own packages and can remove the systemd compile time option. -- Cameron Norman ___ systemd-devel

Re: [systemd-devel] [PATCH] timesyncd: tighten unit file

2015-01-27 Thread Cameron Norman
On Tue, Jan 27, 2015 at 1:16 PM, Lennart Poettering lenn...@poettering.net wrote: On Tue, 27.01.15 19:47, Topi Miettinen (toiwo...@gmail.com) wrote: I'm not sure. Shouldn't we then ship a SELinux policy file then? Would you be interested in AppArmor profile for timesyncd, I have one? Also, if

Re: [systemd-devel] [PATCH] timesyncd: tighten unit file

2015-01-27 Thread Cameron Norman
...@lists.ubuntu.com asking for a review. Lennart: if you really want to test the profile, you just need to spin up an OpenSuSE, Ubuntu, or Debian VM (on debian you need to install and enable apparmor, which takes a short while). Cheers, -- Cameron Norman

Re: [systemd-devel] logind vs CAP_SYS_ADMIN-lessness

2015-01-26 Thread Cameron Norman
On Mon, Jan 26, 2015 at 6:08 PM, Lennart Poettering lenn...@poettering.net wrote: On Fri, 23.01.15 19:35, Christian Seiler (christ...@iwakd.de) wrote: - I hope I didn't forget anything I spent quite some time to ensuer that systemd systems work out-of-the-box in container managers. Any

Re: [systemd-devel] networkd link file not setting MTU

2015-01-20 Thread Cameron Norman
and for future reference, is there any way to get udev to apply the link files without rebooting? E.g. possibly with a udevadm trigger command of some sort. Thank you, -- Cameron Norman ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org

Re: [systemd-devel] Questions regarding dbus started via systemd --user

2015-01-09 Thread Cameron Norman
On Fri, Jan 9, 2015 at 2:18 AM, Colin Guthrie gm...@colin.guthr.ie wrote: Cameron Norman wrote on 09/01/15 02:24: On Thu, Jan 8, 2015 at 9:42 AM, Dimitri John Ledkov dimitri.j.led...@intel.com wrote: On 8 January 2015 at 17:24, Simon McVittie simon.mcvit...@collabora.co.uk wrote: On 08/01/15

Re: [systemd-devel] Questions regarding dbus started via systemd --user

2015-01-08 Thread Cameron Norman
(not dconf, but something along the lines of a GUI shell or gnome-session/upstart) could use it instead of doing their own session instancing (like upstart does). Cheers, -- Cameron Norman ___ systemd-devel mailing list systemd-devel

Re: [systemd-devel] [PATCH] systemctl: print unit package in status

2014-12-18 Thread Cameron Norman
workstations and operate exclusively with YUM or DNF in short: don't make it another log-flood candidate The patch takes that into account: /* we frequently can't get the user bus, nor call PackageKit, so don't complain on error */ -- Cameron Norman

Re: [systemd-devel] systemd-cgroups-agent not working in containers

2014-11-27 Thread Cameron Norman
message with most relevant info) for reference: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=756076#75 Best regards, -- Cameron Norman ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org http://lists.freedesktop.org/mailman/listinfo

Re: [systemd-devel] Put user@.service cgroups into all controllers (user LXC)

2014-11-03 Thread Cameron Norman
is how the behavior they are relying on in cgmgr is not what systemd gives, and how that is causing problems with unpriveleged LXC containers. So no, I do not think so. Regards, -- Cameron Norman ___ systemd-devel mailing list systemd-devel

Re: [systemd-devel] Put user@.service cgroups into all controllers (user LXC)

2014-11-03 Thread Cameron Norman
On Mon, Nov 3, 2014 at 8:32 AM, Cameron Norman camerontnor...@gmail.com wrote: On Nov 3, 2014 8:21 AM, Jóhann B. Guðmundsson johan...@gmail.com wrote: On 11/03/2014 03:25 PM, Martin Pitt wrote: Hints are appreciated. Thanks! Assuming you have read [1] Is not the solution to this problem

Re: [systemd-devel] How to use cgroups within containers?

2014-10-17 Thread Cameron Norman
On Fri, Oct 17, 2014 at 2:37 PM, Richard Weinberger richard.weinber...@gmail.com wrote: ...fixing LXC devel mailinglist... :-\ On Fri, Oct 17, 2014 at 11:35 PM, Richard Weinberger richard.weinber...@gmail.com wrote: Dear systemd and container folks, at Plumbers the question raised how to

Re: [systemd-devel] [question] networkd: Any support for hooks?

2014-10-09 Thread Cameron Norman
El mié, 8 de oct 2014 a las 10:24 , Marcel Holtmann mar...@holtmann.org escribió: Hi Cameron, ifupdown [1], NetworkManager, and WICD all support hooks for when a network interface is configured or deconfigured (before and after these actions). Are there any plans to support something

Re: [systemd-devel] [question] networkd: Any support for hooks?

2014-10-08 Thread Cameron Norman
On Wed, Oct 8, 2014 at 2:26 PM, Lennart Poettering lenn...@poettering.net wrote: On Thu, 02.10.14 19:48, Cameron Norman (camerontnor...@gmail.com) wrote: On Wed, Oct 1, 2014 at 10:36 PM, Tom Gundersen t...@jklm.no wrote: Hi Cameron, On Thu, Oct 2, 2014 at 6:36 AM, Cameron Norman

Re: [systemd-devel] A way to better integrate rsyslog into systemd?

2014-10-04 Thread Cameron Norman
that cause sec issues (e.g. easier to overflow the logs by faking the PID / user then writing to the private socket directly)? Cheers, -- Cameron Norman ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org http://lists.freedesktop.org/mailman

Re: [systemd-devel] [question] networkd: Any support for hooks?

2014-10-02 Thread Cameron Norman
On Wed, Oct 1, 2014 at 10:36 PM, Tom Gundersen t...@jklm.no wrote: Hi Cameron, On Thu, Oct 2, 2014 at 6:36 AM, Cameron Norman camerontnor...@gmail.com wrote: ifupdown [1], NetworkManager, and WICD all support hooks for when a network interface is configured or deconfigured (before and after

[systemd-devel] [question] networkd: Any support for hooks?

2014-10-01 Thread Cameron Norman
developers feel about adding the feature (will not merge, or will accept patches, etc.) ? Thank you, [1] Debian's networking service, re-implemented a couple times elsewhere (busybox, and some other independent stuff) -- Cameron Norman ___ systemd-devel

Re: [systemd-devel] [ANNOUNCE] systemd 214

2014-06-11 Thread Cameron Norman
the documentation entirely would make it hard for people looking at old tmpfile configurations to understand what m does. Why not keep it in the docs, but clearly mark it as deprecated? Awesome release, -- Cameron Norman ___ systemd-devel mailing list systemd

Re: [systemd-devel] [PATCH] Add a network-pre.target to avoid firewall leaks

2014-06-08 Thread Cameron Norman
will already be configured. Hope that helps, -- Cameron Norman ___ systemd-devel mailing list systemd-devel@lists.freedesktop.org http://lists.freedesktop.org/mailman/listinfo/systemd-devel

Re: [systemd-devel] How to Restrict device in systemd?

2014-06-04 Thread Cameron Norman
El Tue, 3 de Jun 2014 a las 11:18 PM, Mohit Agrawal moagr...@redhat.com escribió: Hi, I want to block the device through the systemd cgroup so I have created a below unit file [Unit] Description=mydevblock [Service] DeviceAllow=/dev/zero ExecStart=/usr/bin/dd if=/dev/zero of=/root/file_1

Re: [systemd-devel] [PATCH v5 12/14] autoconf: xen: enable explicit preference option for xenstored preference

2014-06-04 Thread Cameron Norman
On Wed, Jun 4, 2014 at 5:31 PM, Luis R. Rodriguez mcg...@suse.com wrote: On Sun, Jun 01, 2014 at 08:15:47AM +0200, Lennart Poettering wrote: On Fri, 30.05.14 01:29, Luis R. Rodriguez (mcg...@suse.com) wrote: I'm cc'ing a few security folks as I'd appreciate review on the ideas here, in