[Bug 1204069] Re: lxc dhcp fails

2013-10-26 Thread Ross Patterson
I can confirm that on an up-to-date Saucy system, a brand new container with the ubuntu template network doesn't work. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1204069 Title: lxc

[Bug 1244713] Re: invalid syntax for check_ssh plugin

2013-10-26 Thread cyco
Please be so kind and merge 1.4.16-3 from Debian, which fixes this issue (beside some small other once): nagios-plugins (1.4.16-3) unstable; urgency=medium * Fixed check_squid* command definitions * Add double threshold to check_smtp (LP: #318703) - 12_check_smtp_double_threshold.dpatch

[Bug 318703] Re: nagios check_smtp expects integer instead of double

2013-10-26 Thread cyco
This is fixed in version 1.5 of nagios-plugins ** Changed in: nagios-plugins Importance: Unknown = Undecided ** Changed in: nagios-plugins Status: Unknown = New ** Changed in: nagios-plugins Remote watch: SourceForge.net Tracker #2555775 = None ** Changed in: nagios-plugins

[Bug 1244635] Re: setuid executables in a container may compromise security on the host

2013-10-26 Thread Andrea Corbellini
I also don't feel that this is a high priority bug since, so far, we do not recommend allowing unprivileged users to use containers. Agreed. Especially because (currently) it's fairly easy to escape from LXC when you have root access to the container. I don't believe it would be a serious loss

[Bug 1244713] Re: invalid syntax for check_ssh plugin

2013-10-26 Thread Bug Watch Updater
** Changed in: nagios-plugins (Debian) Status: Unknown = Fix Released -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to nagios-plugins in Ubuntu. https://bugs.launchpad.net/bugs/1244713 Title: invalid syntax for check_ssh

[Bug 918543] Re: vbox build fails with NameMapper.NotFound: cannot find 'mac'

2013-10-26 Thread Launchpad Bug Tracker
Status changed to 'Confirmed' because the bug affects multiple users. ** Changed in: vm-builder (Ubuntu) Status: New = Confirmed -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to vm-builder in Ubuntu.

[Bug 1244713] Re: invalid syntax for check_ssh plugin

2013-10-26 Thread Tom Worley
Wow, that was quick, good job guys =) Thanks, Tom -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to nagios-plugins in Ubuntu. https://bugs.launchpad.net/bugs/1244713 Title: invalid syntax for check_ssh plugin To manage notifications

[Bug 1234880] Re: HP ilo4 consoles default to autodetect protocol, which doesn't work

2013-10-26 Thread MaaS Lander
** Changed in: maas Status: Triaged = Fix Committed -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to maas in Ubuntu. https://bugs.launchpad.net/bugs/1234880 Title: HP ilo4 consoles default to autodetect protocol, which doesn't

[Bug 1244635] Re: setuid executables in a container may compromise security on the host

2013-10-26 Thread Stéphane Graber
For those users, getting back to the old way would be a chmod away and I asked Serge to make sure permissions would only be changed once and not with every update, so it should be a one time thing. As for security, while we don't currently say LXC is secure on Ubuntu, we're not aware of any way

[Bug 1234880] Re: HP ilo4 consoles default to autodetect protocol, which doesn't work

2013-10-26 Thread Andres Rodriguez
** Branch linked: lp:~andreserl/maas/fix_ipmi_lp1234880_1.4 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to maas in Ubuntu. https://bugs.launchpad.net/bugs/1234880 Title: HP ilo4 consoles default to autodetect protocol, which

Re: [Bug 1204069] Re: lxc dhcp fails

2013-10-26 Thread Serge Hallyn
Quoting Ross Patterson (m...@rpatterson.net): I can confirm that on an up-to-date Saucy system, a brand new container with the ubuntu template network doesn't work. Did you make sure that the brand new container was created with a flushed cache? (Either rm -rf /var/cache/lxc/* or add '-- -F'

[Bug 1244635] Re: setuid executables in a container may compromise security on the host

2013-10-26 Thread Andrea Corbellini
Hi Stéphane, I can see at least three ways of escaping. The first is using LXC through libvirt. I see that there's an Apparmor profile for usr.bin.lxc-start, but AFAIK libvirt does not use lxc-start. Also, libvirt does not load the lxc-containers profile (AFAIK). This is proven by the fact that

[Bug 1245043] Re: package squid3 3.3.8-1ubuntu3 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error exit status 1

2013-10-26 Thread Apport retracing service
*** This bug is a duplicate of bug 1241957 *** https://bugs.launchpad.net/bugs/1241957 Thank you for taking the time to report this crash and helping to make this software better. This particular crash has already been reported and is a duplicate of bug #1241957, so is being marked as such.

[Bug 1245043] [NEW] package squid3 3.3.8-1ubuntu3 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error exit status 1

2013-10-26 Thread Olaf
*** This bug is a duplicate of bug 1241957 *** https://bugs.launchpad.net/bugs/1241957 Public bug reported: I did do-dist-upgrade and this is what it showed me. ProblemType: Package DistroRelease: Ubuntu 13.10 Package: squid3 3.3.8-1ubuntu3 ProcVersionSignature: Ubuntu 3.8.0-32.47-generic

[Bug 1244635] Re: setuid executables in a container may compromise security on the host

2013-10-26 Thread Stéphane Graber
Right, libvirt-lxc isn't LXC (even though they sort of stole the name) and is indeed completely unsafe... As for the rest, I'm happy to report that you misread the apparmor profile and that we thought of and blocked all of those from the beginning as is shown below: root@lxc-dev:/# echo abc

[Bug 1244635] Re: setuid executables in a container may compromise security on the host

2013-10-26 Thread Andrea Corbellini
Good news. However I must say that the documentation on LXC does not say that libvirt is less secure than the official LXC: https://help.ubuntu.com/13.10/serverguide/lxc.html#lxc-libvirt So either libvirt should ship with an Apparmor profile for LXC, or a warning should be added to the relevant

[Bug 1231182] Re: kpartx-boot: Typo in package description: availible

2013-10-26 Thread Hans Joachim Desserud
** Branch linked: lp:~hjd/ubuntu/trusty/multipath-tools/bug1231182 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to multipath-tools in Ubuntu. https://bugs.launchpad.net/bugs/1231182 Title: kpartx-boot: Typo in package description:

[Bug 1231182] Re: kpartx-boot: Typo in package description: availible

2013-10-26 Thread Hans Joachim Desserud
Thanks for taking your time to report this issue and help making Ubuntu better. I have created a patch for this and submitted it for review. ** Changed in: multipath-tools (Ubuntu) Status: New = In Progress ** Changed in: multipath-tools (Ubuntu) Assignee: (unassigned) = Hans

[Bug 1228649] Re: noVNC doesn't work when offloaded to port 80 or 443

2013-10-26 Thread John Dewey
This should be backported for 12.04, since most should be running LTS. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to nova in Ubuntu. https://bugs.launchpad.net/bugs/1228649 Title: noVNC doesn't work when offloaded to port 80 or