[Touch-packages] [Bug 1969905] Re: lxc-test-no-new-privs in ubuntu_lxc failed on F-s390x zVM (lxc 1:4.0.12-0ubuntu1~20.04.1 )

2022-04-22 Thread Christian Brauner
And that only fails on s390x? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1969905 Title: lxc-test-no-new-privs in ubuntu_lxc failed on F-s390x zVM (lxc

[Touch-packages] [Bug 1959013] Re: systemd test_exec_umask_namespace fails in privileged container

2022-01-25 Thread Christian Brauner
Are the tests run with security.nesting=true set? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to systemd in Ubuntu. https://bugs.launchpad.net/bugs/1959013 Title: systemd test_exec_umask_namespace fails in privileged

[Touch-packages] [Bug 1943441] Re: lxc: lxc-test-parse-config-file failure

2021-09-13 Thread Christian Brauner
This was caused by a recent change to how we handle selinux and apparmor config options when LXC is compiled without support. I've sent https://github.com/lxc/lxc/pull/3969 specific to stable-4.0. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages,

[Touch-packages] [Bug 1943441] Re: lxc: lxc-test-parse-config-file failure

2021-09-13 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: New => Confirmed ** Changed in: lxc (Ubuntu) Status: Confirmed => In Progress -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu.

[Touch-packages] [Bug 1938771] Re: lxc-test-rootfs test regression with 4.0.10-0ubuntu3

2021-08-03 Thread Christian Brauner
** Changed in: lxc (Ubuntu Impish) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1938771 Title: lxc-test-rootfs test regression

[Touch-packages] [Bug 1938771] Re: lxc-test-rootfs test regression with 4.0.10-0ubuntu3

2021-08-03 Thread Christian Brauner
Also added tests around rootfs mount options. ** Changed in: lxc (Ubuntu Impish) Status: Confirmed => In Progress -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1938771

[Touch-packages] [Bug 1938771] Re: lxc-test-rootfs test regression with 4.0.10-0ubuntu3

2021-08-03 Thread Christian Brauner
Thanks for reporting this. I've fixed this in: https://github.com/lxc/lxc/pull/3921 ** Changed in: lxc (Ubuntu Impish) Status: New => Confirmed ** Changed in: lxc (Ubuntu Impish) Assignee: (unassigned) => Christian Brauner (cbrauner) -- You received this bug notification b

[Touch-packages] [Bug 1776381] Re: lxc-test-api-reboot will hang with autopkgtest

2021-07-15 Thread Christian Brauner
Hm, what is the LXC version used here? Is it the one in Bionic? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1776381 Title: lxc-test-api-reboot will hang with autopkgtest

[Touch-packages] [Bug 1931064] Re: lxc autotest failure with kernel >= 5.13

2021-06-07 Thread Christian Brauner
I'm currently treating this as an upstream kernel regression reported here https://lore.kernel.org/regressions/20210607142245.eikvyeacqwwu6dn3@wittgenstein We should wait whether a simple revert will be acceptable or whether anything else is needed from LXC specifically. -- You received this

Re: [Touch-packages] [Bug 1931064] [NEW] lxc autotest failure with kernel >= 5.13

2021-06-07 Thread Christian Brauner
On Mon, Jun 07, 2021 at 05:14:50AM -, Andrea Righi wrote: > Public bug reported: > > The lxc autotest is failing with the following error(s) on the latest > kernel linux-unstable 5.13: > > FAIL: lxc-tests: lxc-test-apparmor (1s) > --- > failed - opened /sys/kernel/uevent_helper > --- > PASS:

[Touch-packages] [Bug 1917601] Re: lxc 1:4.0.4-0ubuntu3 ADT test failure with linux 5.8.0-45.51

2021-03-03 Thread Christian Brauner
This is with 4.0.4 and the bug is fixed in 4.0.6 which it seems hasn't made it into Groovy yet (but is released). I'm not sure what Stéphane's timeline is there. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu.

[Touch-packages] [Bug 1884024] Re: lxc-test-device-add-remove from ubuntu_lxc failed on B-5.4

2021-01-11 Thread Christian Brauner
This has been fixed a long while ago: commit 920cbb00268ce50d1306daebb74871f66583a46c Author: Christian Brauner Date: Mon Nov 18 15:08:22 2019 +0100 tests: use /dev/loop-control instead of /dev/network_latency BugLink: https://bugs.launchpad.net/bugs/1848587 The latter device

[Touch-packages] [Bug 1888705] Re: lxc ftbfs against libselinux 3.1

2020-09-10 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1888705 Title: lxc ftbfs against libselinux 3.1 Status

[Touch-packages] [Bug 1888705] Re: lxc ftbfs against libselinux 3.1

2020-07-25 Thread Christian Brauner
https://github.com/lxc/lxc/pull/3498 ** Changed in: lxc (Ubuntu) Status: New => In Progress -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1888705 Title: lxc ftbfs

[Touch-packages] [Bug 1886790] Re: lxc 3.0.3-0ubuntu1~18.04.1 ADT test failure with 5.4 kernels in Bionic

2020-07-08 Thread Christian Brauner
This is a bug we fixed in our stable-3.0 branch and is fixed in the Ubuntu lxc 3.0.4 packages. See https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1848587 and specifically this commit: commit 11fc6882f7bfd40fbcda6a3a7f7c1bca50df3f2b Author: Christian Brauner Date: Mon Nov 18 15:08:22 2019

[Touch-packages] [Bug 1884635] Re: lxc 1:4.0.2-0ubuntu1 ADT test failure with linux-5.8 5.8.0-1.2

2020-06-25 Thread Christian Brauner
** Changed in: linux (Ubuntu) Status: Incomplete => Confirmed ** Changed in: linux (Ubuntu) Status: Confirmed => In Progress ** Changed in: linux (Ubuntu) Assignee: (unassigned) => Christian Brauner (cbrauner) -- You received this bug notification because you are

[Touch-packages] [Bug 1884635] Re: lxc 1:4.0.2-0ubuntu1 ADT test failure with linux-5.8 5.8.0-1.2

2020-06-24 Thread Christian Brauner
** Also affects: linux (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1884635 Title: lxc 1:4.0.2-0ubuntu1 ADT test

[Touch-packages] [Bug 1884635] Re: lxc 1:4.0.2-0ubuntu1 ADT test failure with linux-5.8 5.8.0-1.2

2020-06-24 Thread Christian Brauner
This is a regression in overlayfs for the 5.8 kernel. The same test works fine on an earlier kernel with the same lxc version. ** Changed in: lxc (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is

[Touch-packages] [Bug 1869661] Re: lxc 3.23 (?) breaks nested lxd with snaps

2020-03-30 Thread Christian Brauner
I think that's already fixed in the edge snap but we haven't yet rolled that out to stable. Can you test with edge? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1869661

[Touch-packages] [Bug 1857046] Re: lxc 3.0.4-0ubuntu2 ADT test failure with linux 5.5.0-2.3

2020-03-26 Thread Christian Brauner
No, but might have been an allocation error which we fixed in the meantime. The error can only come from: ENOMEM The kernel could not allocate a free page to copy filenames or data into. That's the only reason mount() can fail with ENOMEM from just glancing at the manpage. I'll take another

[Touch-packages] [Bug 1858799] Re: lxc ADT test failure on Bionic with linux-raspi2-5.3 arm64

2020-01-08 Thread Christian Brauner
This might be caused by changes to busybox since this looks like it's testing liblxc-3.0.4. In any case, I believe that the following commit in the stable-3.0 tree would fix it: https://github.com/lxc/lxc/commit/3daa49d845b153dfb2012b61dba763cbc6e11374 -- You received this bug notification

Re: [Touch-packages] [Bug 1850667] Re: cgroup v2 is not fully supported yet, proceeding with partial confinement

2019-12-15 Thread Christian Brauner
On Mon, Dec 09, 2019 at 08:41:18PM -, Ryutaroh Matsumoto wrote: > https://github.com/lxc/lxc/issues/3221 Another LXC-container-doesn't > -start-at-all type issue also observed on Ubuntu Eoan with > systemd.unified_cgroup_hierarchy as well as Fedora 31. That seems specific to LXC stable-3.0

[Touch-packages] [Bug 1855513] Re: log file

2019-12-07 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1855513 Title: log file Status in lxc package in Ubuntu: Invalid

[Touch-packages] [Bug 1850667] Re: cgroup v2 is not fully supported yet, proceeding with partial confinement

2019-12-05 Thread Christian Brauner
https://github.com/lxc/lxc/issues/3198#issuecomment-562064091 -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1850667 Title: cgroup v2 is not fully supported yet, proceeding

[Touch-packages] [Bug 1848587] Re: lxc 3.0.4-0ubuntu1 ADT test failure with linux 5.4.0-1.2

2019-11-19 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1848587 Title: lxc 3.0.4-0ubuntu1 ADT test failure with

[Touch-packages] [Bug 1848587] Re: lxc 3.0.4-0ubuntu1 ADT test failure with linux 5.4.0-1.2

2019-11-18 Thread Christian Brauner
Sorry, mail got lost. Here's a fix: https://github.com/lxc/lxc/pull/3187 ** Changed in: lxc (Ubuntu) Status: Confirmed => In Progress -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu.

Re: [Touch-packages] [Bug 1848587] [NEW] lxc 3.0.4-0ubuntu1 ADT test failure with linux 5.4.0-1.2

2019-10-18 Thread Christian Brauner
Is this a flake or consistently reproducible? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1848587 Title: lxc 3.0.4-0ubuntu1 ADT test failure with linux 5.4.0-1.2 Status

[Touch-packages] [Bug 1831258] Re: journalctl --list-boots does not recognize boots in a container

2019-06-20 Thread Christian Brauner
** Also affects: lxc (Ubuntu) Importance: Undecided Status: New ** Changed in: systemd (Ubuntu Bionic) Status: In Progress => Invalid ** Changed in: systemd (Ubuntu Eoan) Status: In Progress => Invalid ** Changed in: lxc (Ubuntu Bionic) Status: New => Incomplete

[Touch-packages] [Bug 1831258] Re: journalctl --list-boots does not recognize boots in a container

2019-06-05 Thread Christian Brauner
Fix here: https://github.com/lxc/lxc/pull/3034 ** Changed in: lxd (Ubuntu Bionic) Status: New => In Progress ** Changed in: lxd (Ubuntu Eoan) Status: New => In Progress ** Changed in: systemd (Ubuntu Bionic) Status: Invalid => In Progress ** Changed in: systemd (Ubuntu

[Touch-packages] [Bug 1831258] Re: journalctl --list-boots does not recognize boots in a container

2019-06-04 Thread Christian Brauner
Several people tried to namespace this but this is really tied to a physical machine so it's kinda tricky to fake. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to systemd in Ubuntu. https://bugs.launchpad.net/bugs/1831258

[Touch-packages] [Bug 1825155] Re: lxc-start crashed with SIGSEGV in cgfsng_payload_create()

2019-04-19 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: Confirmed => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1825155 Title: lxc-start crashed with SIGSEGV in

[Touch-packages] [Bug 1824812] Re: apparmor does not start in Disco LXD containers

2019-04-15 Thread Christian Brauner
Okay, I have a fix for the shiftfs side I think. Attached here. ** Patch added: "UBUNTU: SAUCE: shiftfs: use correct llseek method for" https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1824812/+attachment/5256074/+files/0001-UBUNTU-SAUCE-shiftfs-use-correct-llseek-method-for-d.patch --

[Touch-packages] [Bug 1799032] [NEW] Update to libcap 2.26

2018-10-21 Thread Christian Brauner
Public bug reported: Hey everyone, We recently pushed support for ambient capabilities and namespaces filesystem capabilities to libcap2 [1]. Together with Andrew Morgan, Serge Hallyn and I have released a version 2.26 of libcap2. Note that libcap2 has moved to a new location [2] The 2.26

[Touch-packages] [Bug 1734410] Re: systemd: handle undelegated cgroup2 hierarchy

2018-10-08 Thread Christian Brauner
If the systemd version doesn't support hybrid cgroup layout on xenial then fine but I thought it did. But please make sure that Xenial doesn't have anything mounted on /sys/fs/cgroup/unified. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is

[Touch-packages] [Bug 1791958] Re: iptables-restore is missing -w option

2018-09-11 Thread Christian Brauner
** Changed in: iptables (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to iptables in Ubuntu. https://bugs.launchpad.net/bugs/1791958 Title: iptables-restore is missing -w option

[Touch-packages] [Bug 1783591] Re: lxc-user-nic allows unprivileged users to open arbitrary files

2018-08-30 Thread Christian Brauner
If you think that you have found an actual security bug please file it as a new one to follow best security practices. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1783591

Re: [Touch-packages] [Bug 1783591] Re: lxc-user-nic allows unprivileged users to open arbitrary files

2018-08-30 Thread Christian Brauner
On Thu, Aug 30, 2018 at 08:02:56PM -, Salvatore Bonaccorso wrote: > One can still test existence of files with those patches, but I guess > this was explicitly not part of the fixes? Is there a reproducer? Yes, the open() can fail and we will report back to the user that the open() failed but

[Touch-packages] [Bug 1783591] Re: lxc-user-nic allows unprivileged users to open arbitrary files

2018-08-06 Thread Christian Brauner
New version to apply cleanly to master. ** Patch added: "0001-CVE-2018-6556-verify-netns-fd-in-lxc-user-nic-master.patch" https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1783591/+attachment/5172186/+files/0001-CVE-2018-6556-verify-netns-fd-in-lxc-user-nic-master.patch -- You received

[Touch-packages] [Bug 1780227] Re: locking sockets broken due to missing AppArmor socket mediation patches

2018-07-27 Thread Christian Brauner
On Fri, Jul 27, 2018, 21:21 Stéphane Graber wrote: > Ok, thanks for the update. I've now updated the bug once again to move > all the tasks over to the kernel. Can you attach the kernel patch here > when you can, I'm sure some of the subscribers may want to test this > ahead of the Ubuntu kernel

[Touch-packages] [Bug 1575779] Re: hostnamectl fails under lxd unpriv container

2018-07-24 Thread Christian Brauner
** Changed in: apparmor (Ubuntu) Status: Fix Committed => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apparmor in Ubuntu. https://bugs.launchpad.net/bugs/1575779 Title: hostnamectl fails under lxd

[Touch-packages] [Bug 1783305] Re: apparmor DENIED when a systemd unit with DynamicUsers=yes is launched in a lxd container

2018-07-24 Thread Christian Brauner
*** This bug is a duplicate of bug 1780227 *** https://bugs.launchpad.net/bugs/1780227 This is an AppArmor bug that I reported and which is tracked here: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1780227 So please close here in favor of that bug. Christian ** Changed in: lxd

[Touch-packages] [Bug 1646462] Re: lxc-create cannot setgid

2018-07-12 Thread Christian Brauner
What's your LXC version? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1646462 Title: lxc-create cannot setgid Status in lxc: Unknown Status in lxc package in Ubuntu:

[Touch-packages] [Bug 1575779] Re: hostnamectl fails under lxd unpriv container

2018-07-05 Thread Christian Brauner
So, the good news is that this is all fixed upstream starting with 4.17 with the socket mediation patchset that got merged a short while ago. The bad news is that we need to get this patchset backported and it is quite large:

[Touch-packages] [Bug 1575779] Re: hostnamectl fails under lxd unpriv container

2018-07-04 Thread Christian Brauner
Hey, so we're seeing an instance of this issue and the problem is that a lock is taken on an fd instead of a path. This should be legal and we urgently need a fix for this since this is starting to break all systemd services running in a container that use PrivateUsers= and anything else that hits

Re: [Touch-packages] [Bug 1776381] Re: lxc-test-api-reboot will hang with autopkgtest

2018-06-14 Thread Christian Brauner
On Thu, Jun 14, 2018 at 04:19:39AM -, Po-Hsu Lin wrote: > Is there anything that I can do for debugging this? Hm, you could try manually creating a busybox container and trying to: - shut it down - reboot it with lxc-stop Christian -- You received this bug notification because you are a

Re: [Touch-packages] [Bug 1776381] Re: lxc-test-api-reboot will hang with autopkgtest

2018-06-12 Thread Christian Brauner
On Tue, Jun 12, 2018 at 8:39 AM, Po-Hsu Lin wrote: > If you leave it there for a long period, it will time out in the end: > make[1]: Leaving directory '/tmp/autopkgtest.ZiY11u/build.Nic/src' > FAIL: lxc-tests: lxc-test-api-reboot (9845s) The API reboot tests will hang indefinitely if the

Re: [Touch-packages] [Bug 1776381] Re: lxc-test-api-reboot will hang with autopkgtest

2018-06-12 Thread Christian Brauner
On Tue, Jun 12, 2018 at 12:46 PM, Free Ekanayaka wrote: > It might be a duplicate of https://github.com/lxc/lxd/issues/4485 (which > is fixed in 3.0.1, now in -proposed I believe). This is a LXC integration test that is failing, not a LXD one. :) > > We'd need to see the logs of the LXD daemon

[Touch-packages] [Bug 1755250] Re: backport statx syscall whitelist fix

2018-06-06 Thread Christian Brauner
This is indeed pretty important for some use-cases so we should try to come up with a reasonable solution. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to libseccomp in Ubuntu. https://bugs.launchpad.net/bugs/1755250 Title:

[Touch-packages] [Bug 1770481] Re: core: fall back to bind-mounts for PrivateDevices= execution environments

2018-05-11 Thread Christian Brauner
We just had a short discussion on systemd and for systemd 229 on 16.04 we also need: 9e5f825280192be429cc79153235d12778427fae : https://github.com/systemd/systemd/commit/9e5f825280192be429cc79153235d12778427fae -- You received this bug notification because you are a member of Ubuntu Touch

[Touch-packages] [Bug 1770481] [NEW] core: fall back to bind-mounts for PrivateDevices= execution environments

2018-05-10 Thread Christian Brauner
Public bug reported: Hey, Currently any service that has PrivateDevices=true set will fail to start in unprivileged containers since mknod is not possible and in privileged containers that drop CAP_MKNOD. I pushed a patch to systemd upstream that solves this problem and makes PrivateDevices

[Touch-packages] [Bug 1635382] Re: PrivateNetwork=yes (hostnamed, localed) does not work in lxd

2018-05-08 Thread Christian Brauner
What? That's totally possible. Simply try unshare -n inside an unprivileged container as root. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to systemd in Ubuntu. https://bugs.launchpad.net/bugs/1635382 Title:

[Touch-packages] [Bug 1758380] Re: unpriveleged containers no longer could start due to start.c: lxc_spawn: 1555 Failed initializing cgroup support

2018-03-23 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: New => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1758380 Title: unpriveleged containers no longer could start

[Touch-packages] [Bug 1757470] Re: apport autopkgtests broken (valgrind error) LXC regression?

2018-03-21 Thread Christian Brauner
Can we get some logs for the LXC containers that created and fail? Otherwise this is very much a black box. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apport in Ubuntu. https://bugs.launchpad.net/bugs/1757470 Title:

[Touch-packages] [Bug 1734410] Re: systemd: handle undelegated cgroup2 hierarchy

2018-03-21 Thread Christian Brauner
Sorry for the brevity before. I tested this with systemd 23{5,6} inside xenial and artful containers which is really the only case where it matters. A systemd with my patch applied would happily: 1. skip over undelegated /sys/fs/cgroup/unified mountpoints

[Touch-packages] [Bug 1734410] Re: systemd: handle undelegated cgroup2 hierarchy

2018-03-20 Thread Christian Brauner
** Tags removed: verification-needed verification-needed-artful ** Tags added: verification-done-artful -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to systemd in Ubuntu. https://bugs.launchpad.net/bugs/1734410 Title:

[Touch-packages] [Bug 1751780] Re: lxc-snapshot crashes when removing non-existing snapshot

2018-02-26 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: Confirmed => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1751780 Title: lxc-snapshot crashes when removing

[Touch-packages] [Bug 1751780] Re: lxc-snapshot crashes when removing non-existing snapshot

2018-02-26 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: New => Won't Fix ** Changed in: lxc (Ubuntu) Status: Won't Fix => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu.

Re: [Touch-packages] [Bug 1750654] [NEW] "lxc-create -B best" fails on non-btrfs/zfs system

2018-02-21 Thread Christian Brauner
On Tue, Feb 20, 2018 at 08:43:41PM -, Martin Pitt wrote: > Public bug reported: > > As per documentation, the `-B best` option should automatically select > the best backingstore, falling back all the way to dir. > > But apparently it doesn't, at least not in artful's 2.1.0-0ubuntu1: Hm, is

Re: [Touch-packages] [Bug 1729357] Re: unprivileged user can drop supplementary groups

2018-02-15 Thread Christian Brauner
On Thu, Feb 15, 2018 at 11:29:03AM -, Aleksa Sarai wrote: > I've just sent a request for a CVE. I'm working on the patch now. My I assume the CVE will at least be correctly attributed to Craig. Christian -- You received this bug notification because you are a member of Ubuntu Touch seeded

[Touch-packages] [Bug 1553097] Re: lxc-attach does not output stderr any more if stdout is redirected

2018-02-09 Thread Christian Brauner
** No longer affects: autopkgtest (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1553097 Title: lxc-attach does not output stderr any more if stdout is redirected

[Touch-packages] [Bug 1567037] Re: lxc-attach crashed with SIGSEGV in get_pty_on_host()

2018-02-09 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1567037 Title: lxc-attach crashed with SIGSEGV in

[Touch-packages] [Bug 1690125] Re: hybrid control goup mode breaks lxc adt tests

2018-02-09 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: In Progress => Fix Released ** No longer affects: lxc -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1690125 Title: hybrid control

[Touch-packages] [Bug 1734410] [NEW] systemd: handle undelegated cgroup2 hierarchy

2017-11-24 Thread Christian Brauner
Public bug reported: Hey everyone, Current systemd versions all fail when the unified cgroup hierarchy is not-writable. This is especially problematic in containers where the systemd administrator might decide to not delegate the unified hierarchy or when running with a liblxc driver that

[Touch-packages] [Bug 1734409] [NEW] systemd-sysctl: exit gracefully on EPERM/EACCESS

2017-11-24 Thread Christian Brauner
Public bug reported: Hi everyone, systemd-sysctl in systemd versions prior to 232 will exit with FAILED when not being able to apply kernel variables. In containers it should simply move on and exit with SUCCESS. Upstream systemd carries appropriate patches for this already. The relevant commits

[Touch-packages] [Bug 1692111] Re: Unable to configure raw.id_map with multiple entries

2017-09-06 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1692111 Title: Unable to configure raw.id_map with

[Touch-packages] [Bug 1713726] Re: lxc 2.0.8-0ubuntu6 ADT test failure with linux 4.13.0-7.8

2017-08-29 Thread Christian Brauner
Has the `/etc/init/` directory and associated files been removed from artful I remember @xnox removing old init scripts. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1713726

[Touch-packages] [Bug 1690125] Re: hybrid control goup mode breaks lxc adt tests

2017-07-27 Thread Christian Brauner
Hey everyone, Uust as an fyi: I sent a branch https://github.com/lxc/lxc/pull/1713 which is now merged that makes LXC handle the hybrid cgroup case provided the cgroup v2 mount does not bind any controllers (Which is the current default). It will be included in the next LXC release. Thanks!

Re: [Touch-packages] [Bug 1699919] Re: lxc copy between hosts preserves original uid/gid

2017-06-23 Thread Christian Brauner
On Fri, Jun 23, 2017 at 10:19:46AM -, PshemK wrote: > The thing is - it didn't get remapped. Now I have two containers mapping > to the same range, both live: > > pshemk@ii:~$ lxc list > +-+-+-+--++---+ > | NAME | STATE |

[Touch-packages] [Bug 1699919] Re: lxc copy between hosts preserves original uid/gid

2017-06-23 Thread Christian Brauner
Hi, I'm not sure what the problem here is. LXD will copy the filesystem mapped and will remap on demand if there's another sub{g,u}id range allocated for LXD on the new host. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

Re: [Touch-packages] [Bug 1699903] Re: lxc-sshd won't start with 2.0.8

2017-06-22 Thread Christian Brauner
On Thu, Jun 22, 2017 at 11:11:59PM -, Miroslav Los wrote: > Our actual templates are based on the lxc-sshd template example that > comes with lxc-templates. There, basically all the lxc is is bind-mounts > for necessary paths from the host, obviously read-only: The /dev bind-mount is

[Touch-packages] [Bug 1699903] Re: lxc-sshd won't start with 2.0.8

2017-06-22 Thread Christian Brauner
Hi Miroslav, Yes, we've been hardening the console handling code quite a bit prior to this release. It seems that you are on a read-only file system which prevents LXC from removing the underlying "/dev/console" file that already exists. LXC wants to remove this file since it wants to prevent

[Touch-packages] [Bug 1699759] Re: LXC Alpine template broken on ppc64le

2017-06-22 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: New => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1699759 Title: LXC Alpine template broken on ppc64le Status in

[Touch-packages] [Bug 1692111] Re: Unable to configure raw.id_map with multiple entries

2017-06-01 Thread Christian Brauner
** Changed in: lxd (Ubuntu) Status: In Progress => Fix Committed ** Also affects: lxc (Ubuntu) Importance: Undecided Status: New ** Changed in: lxc (Ubuntu) Status: New => Fix Committed ** Changed in: lxc (Ubuntu) Assignee: (unassigned) => Christia

[Touch-packages] [Bug 1690822] Re: GPU device in lxc profile ignored?

2017-05-18 Thread Christian Brauner
On Thu, May 18, 2017 at 08:09:05AM -, Konstantinos Tsakalozos wrote: > I can confirm that "ls -al /dev/dri/" within the lxc container shows the > devices you expect. However, "lxc config show xen2" shows the devices > section being empty. This isn't a bug at all. :) You're adding a device to

[Touch-packages] [Bug 1690822] Re: GPU device in lxc profile ignored?

2017-05-16 Thread Christian Brauner
I've used your exact profile now: https://paste.ubuntu.com/24586449/ -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1690822 Title: GPU device in lxc profile ignored? Status

[Touch-packages] [Bug 1690822] Re: GPU device in lxc profile ignored?

2017-05-16 Thread Christian Brauner
chb@conventiont|~ > lxc profile show dummy config: security.nesting: "true" security.privileged: "true" description: "" devices: gpu: type: gpu name: dummy used_by: - /1.0/containers/alp1 - /1.0/containers/alpgpu -- You received this bug notification because you are a member of Ubuntu

[Touch-packages] [Bug 1690822] Re: GPU device in lxc profile ignored?

2017-05-15 Thread Christian Brauner
I couldn't reproduce this behavior locally. - We'd need the logs for the daemon and the corresponding containers in question from /var/log/lxd/*, please. - Please also show cat /proc/1/mountinfo from inside one of those containers that doesn't mount the gpu device. -- You received this bug

[Touch-packages] [Bug 1654676] Re: lxc-user-nic does not ensure that target netns is caller-owned

2017-05-12 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Assignee: (unassigned) => Christian Brauner (cbrauner) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1654676 Title: lxc-user-nic d

[Touch-packages] [Bug 1686036] Re: strange behavior after restore snapshot

2017-04-28 Thread Christian Brauner
LXD 2.13 doesn't include my fix https://github.com/lxc/lxd/commit/6c6af18b4ab4720c802a61fa932179562446a4df yet. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1686036 Title:

[Touch-packages] [Bug 1686036] Re: strange behavior after restore snapshot

2017-04-27 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1686036 Title: strange behavior after restore snapshot

[Touch-packages] [Bug 1686036] Re: strange behavior after restore snapshot

2017-04-26 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Importance: Undecided => High -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1686036 Title: strange behavior after restore snapshot Status in

[Touch-packages] [Bug 1686036] Re: strange behavior after restore snapshot

2017-04-26 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: New => In Progress ** Changed in: lxc (Ubuntu) Assignee: (unassigned) => Christian Brauner (cbrauner) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu.

Re: [Touch-packages] [Bug 1686361] Re: systemd does not respect nofile ulimit when running in container

2017-04-26 Thread Christian Brauner
Would be good if we could also SRU that to Xenial as well since this is likely what users will be using most of the time as image in their container. Adding stgraber to this thread. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is

[Touch-packages] [Bug 1686361] [NEW] systemd does not respect nofile ulimit when running in container

2017-04-26 Thread Christian Brauner
Public bug reported: When systemd currently starts in a container that has RLIMIT_NOFILE set to e.g. 10 systemd will lower it to 65536 since this value is hard-coded into systemd. I've pushed a patch to systemd upstream that will try to set the nofile limit to the allowed kernel maximum. If

[Touch-packages] [Bug 1686036] Re: strange behavior after restore snapshot

2017-04-25 Thread Christian Brauner
Reproducible. Can you please open this bug on github. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1686036 Title: strange behavior after restore snapshot Status in lxc

[Touch-packages] [Bug 1686036] Re: strange behavior after restore snapshot

2017-04-25 Thread Christian Brauner
This is very likely not a LXD bug. I suspect this is https://github.com/zfsonlinux/zfs/issues/5796 again which I reported to ZFS upstream. I'll ping them about this again tomorrow and if I don't hear back will take a look at this myself. ** Bug watch added: Github Issue Tracker for ZFS #5796

[Touch-packages] [Bug 1684481] Re: KVM guest execution start apparmor blocks on /dev/ptmx now (regression?)

2017-04-22 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: In Progress => Fix Committed ** Changed in: lxc (Ubuntu) Assignee: (unassigned) => Christian Brauner (cbrauner) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to ap

[Touch-packages] [Bug 1684481] Re: KVM guest execution start apparmor blocks on /dev/ptmx now (regression?)

2017-04-21 Thread Christian Brauner
Hi John, hi Christian, Sent a branch to lxc that should fix this issue: https://github.com/lxc/lxc/pull/1519 ** Changed in: lxc (Ubuntu) Status: Triaged => In Progress -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

[Touch-packages] [Bug 1668049] Re: lxd cannot shutdown container

2017-02-26 Thread Christian Brauner
Note, that since a while LXC is sending SIGRTMIN+3 to systemd. So unless systemd has changed it's shutdown/halt signal again LXC should send the right signal. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to systemd in Ubuntu.

Re: [Touch-packages] [Bug 1641236] Re: Confined processes inside container cannot fully access host pty device passed in by lxc exec

2017-01-31 Thread Christian Brauner
On Tue, Jan 31, 2017 at 11:34:43AM +0100, Christian Brauner wrote: > I've reproduced this on a fresh standard xenial instance with LXD > 2.0.8 and also on a xenial instance with a patched glibc that reports > ENODEV on ttyname{_r}() on a pty fd that does not exist: &g

Re: [Touch-packages] [Bug 1641236] Re: Confined processes inside container cannot fully access host pty device passed in by lxc exec

2017-01-31 Thread Christian Brauner
I've reproduced this on a fresh standard xenial instance with LXD 2.0.8 and also on a xenial instance with a patched glibc that reports ENODEV on ttyname{_r}() on a pty fd that does not exist: root@x:~# ./enodev_on_pty_in_different_namespace ttyname(): The pty device might exist in a different

[Touch-packages] [Bug 1657437] Re: Unprivileged containers run by non-root fail to start if trying to bind-mount a directory that contains a mounted ecryptfs

2017-01-18 Thread Christian Brauner
Hi, this is not a bug. What you want is to recursively bind-mount: lxc.mount.entry = /home home none rbind,create=dir 0 0 Christian -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu.

Re: [Touch-packages] [Bug 1646462] Re: lxc container download error (possibly HSTS related)

2017-01-09 Thread Christian Brauner
Hi, Have you tried again after a while. I don't think that this is related to the uid/gid mappings. In order for the download template to work you should have a default lxc config for your unprivileged user configured which would list the uid/gid mapping you want to use, e.g. # Container

[Touch-packages] [Bug 1653725] Re: lxc-android-config not starting on ubuntu-touch/staging/* xenial-based images after lxc upgrade

2017-01-04 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1653725 Title: lxc-android-config not starting on

[Touch-packages] [Bug 1653725] Re: lxc-android-config not starting on ubuntu-touch/staging/* xenial-based images after lxc upgrade

2017-01-04 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: New => In Progress -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1653725 Title: lxc-android-config not starting on

[Touch-packages] [Bug 1649582] Re: lxc-start fails to start a unprivileged container - cgroup permissions

2016-12-16 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1649582 Title: lxc-start fails to start a unprivileged container -

Re: [Touch-packages] [Bug 1649582] Re: lxc-start fails to start a unprivileged container - cgroup permissions

2016-12-16 Thread Christian Brauner
Right, the cpuset bug is gone which was your main problem. Now the only thing left to do should be: chmod +x /home/sneetsher/.local Please try again and report back. :) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in

Re: [Touch-packages] [Bug 1649582] Re: lxc-start fails to start a unprivileged container - cgroup permissions

2016-12-16 Thread Christian Brauner
Ok, I think I may have clue. You're using lxcfs in version 2.0.4. This version of lxcfs does not handle uninitialized cpuset hierarchies which can happen when systemd does not allocate a per-user cgroup in the cpuset controller. I fixed this in lxcfs 2.0.5 by reimplementing the cgroup handling

Re: [Touch-packages] [Bug 1649582] Re: lxc-start fails to start a unprivileged container - cgroup permissions

2016-12-15 Thread Christian Brauner
Please attach the container config file and show or attache the output of the following commands: - grep cgroup /proc/1/mountinfo - cat /proc/self/cgroup - ls -al /sys/fs/cgroup - lxcfs --version Thanks! -- You received this bug notification because you are a member of Ubuntu Touch seeded

[Touch-packages] [Bug 1623143] Re: Linux container does not take same cpu configuration as kernet's hosts

2016-12-13 Thread Christian Brauner
** Changed in: lxc (Ubuntu) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1623143 Title: Linux container does not take same cpu

  1   2   >