[Touch-packages] [Bug 2080069] Re: lxc-dev does not provide liblxc.a any more

2024-09-09 Thread Serge Hallyn
Thanks, Ryan. Looks good to me. Could you post a diff of the dpkg --contents of the built files? Looks like the same is true in the debian unstable package. I'd suggest we fix it here and then see whether debian is willing to take this patch. ** Changed in: lxc (Ubuntu) Status: New => C

[Touch-packages] [Bug 2080069] Re: lxc-dev does not provide liblxc.a any more

2024-09-09 Thread Serge Hallyn
** Changed in: lxc (Ubuntu) Status: Confirmed => Triaged ** Changed in: lxc (Ubuntu Noble) Status: Confirmed => Triaged -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/b

[Touch-packages] [Bug 2080069] Re: lxc-dev does not provide liblxc.a any more

2024-09-10 Thread Serge Hallyn
Sadly I forgot to add the bug number to the changelog, but the fixed package is in oracular. Thanks. ** Changed in: lxc (Ubuntu) Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in

[Touch-packages] [Bug 2012437] [NEW] Ship a static libsystemd.a

2023-03-21 Thread Serge Hallyn
Public bug reported: More and more things are requiring linking against libsystemd. In particular, because dbus is now linked against libsystemd, anything that wants to make a dbus client call needs it. By not shipping a static libsystemd.a, all such users are prevented from building statically.

[Touch-packages] [Bug 2039873] Re: liblxc-dev was built with LXC_DEVEL=1 in Ubuntu Jammy/Kinetic

2023-10-23 Thread Serge Hallyn
> Looking at the changelog, it appears that Serge simply pulled all changes following 5.0.1 from git, which he likely did mistakenly looking at the master branch rather than the stable-5.0 branch which wouldn't have had that particular change. That sounds like exactly what I would do. -- You rec

[Touch-packages] [Bug 1963834] Re: openssl 3.0 - SSL: UNSAFE_LEGACY_RENEGOTIATION_DISABLED]

2022-03-16 Thread Serge Hallyn
FWIW I'm seeing this with the openconnect-sso (https://github.com/vlaci/openconnect-sso) package on jammy. I just tried adding the following to my /etc/ssl/openssl.cfg: [ssl_configuration] client = client_tls_config [client_tls_config] Options = UnsafeLegacyServerConnect With no luck :( -- Yo

[Touch-packages] [Bug 1963834] Re: openssl 3.0 - SSL: UNSAFE_LEGACY_RENEGOTIATION_DISABLED]

2022-03-16 Thread Serge Hallyn
I tried also adding the following: [openssl_init] providers = provider_sect ssl_conf = ssl_configuration as I wasn't sure whether the [ssl_configuration] section would otherwise get used for anything, but that didn't seem to make a difference. The end of the file is [ssl_configuration] client =

[Touch-packages] [Bug 1963834] Re: openssl 3.0 - SSL: UNSAFE_LEGACY_RENEGOTIATION_DISABLED]

2022-03-16 Thread Serge Hallyn
Ok, I did get my case to work by creating ~/ssl.conf containing: openssl_conf = openssl_init [openssl_init] ssl_conf = ssl_sect [ssl_sect] system_default = system_default_sect [system_default_sect] Options = UnsafeLegacyRenegotiation And then did OPENSSL_CONF=~/ssl.conf do-my-command that wor

[Touch-packages] [Bug 1966590] Re: cups segfault when printing or editing printers

2022-03-27 Thread Serge Hallyn
This makes it impossible for me to print from my laptop :( -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1966590 Title: cups segfault when printing or editing printers Stat

[Touch-packages] [Bug 1966590] [NEW] cups segfault when printing or editing printers

2022-03-27 Thread Serge Hallyn
Public bug reported: Editing a printer in localhost:631, cups keeps segfaulting after (possibly related) access denied messages: [932068.059601] audit: type=1400 audit(1648388571.894:566): apparmor="DENIED" operation="connect" profile="/usr/bin/evince" name="/run/user/1000/at-spi/bus_0" pid=853

[Touch-packages] [Bug 1966590] Re: cups segfault when printing or editing printers

2022-03-27 Thread Serge Hallyn
The permission denied errors appear unrelated: after stopping apparmor and restarting cups, I still get: [932499.635684] cupsd[855122]: segfault at 0 ip 7f39be2ff98c sp 7ffc12737718 error 4 in libc.so.6[7f39be176000+195000] [932499.635695] Code: 1e fa 89 f8 31 d2 62 a1 fd 00 ef c0 09 f0

[Touch-packages] [Bug 1966590] Re: cups segfault when printing or editing printers

2022-03-27 Thread Serge Hallyn
(Forcibly downgrading to the impish packages restored ability to print.) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cups in Ubuntu. https://bugs.launchpad.net/bugs/1966590 Title: cups segfault when printing or editing

[Touch-packages] [Bug 1700814] Re: Default capability of cap_setfcap+i should be set on setcap

2022-05-20 Thread Serge Hallyn
** Changed in: libcap2 (Ubuntu) Assignee: Serge Hallyn (serge-hallyn) => Balint Reczey (rbalint) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to libcap2 in Ubuntu. https://bugs.launchpad.net/bugs/1700814 Ti

[Touch-packages] [Bug 1917187] Re: lxc cgroup2: containers unbootable

2022-02-27 Thread Serge Hallyn
FWIW this is affecting me on jammy too. I'll have to take a look at systemd sources. Adding: lxc.init.cmd = /sbin/init systemd.unified_cgroup_hierarchy to my config does not help, nor does bind mounting a /proc/filesystems without 'cgroup' (v1) in it. -- You received this bug notification bec

[Touch-packages] [Bug 1923262] Re: backup /etc/passwd- file should be mode 0600

2021-10-27 Thread Serge Hallyn
I appreciate you bringing this to our attention, but (as shadow upstream maintainer) I'm going to join John in saying this should be wontfix. Now if you want to change the subject to also making /etc/passwd 600, then as Alexander points out that may be doable and have merit. But just hiding the b

[Touch-packages] [Bug 1928309] Re: usermod change home directory no tilde

2021-10-27 Thread Serge Hallyn
Well that's just fascinating! :) This would be best reported at https://github.com/shadow- maint/shadow/issues. Would you mind opening an issue there? ** Changed in: shadow (Ubuntu) Status: New => Confirmed ** Changed in: shadow (Ubuntu) Importance: Undecided => Wishlist -- You rece

[Touch-packages] [Bug 1869267] Re: /etc/login.defs contains a non-ASCII character

2021-10-27 Thread Serge Hallyn
This is in the debian/login.defs file, and was replaced at least before bionic with a proper ascii ', so I'm targeting this to xenial. ** Changed in: shadow (Ubuntu) Status: New => Fix Released ** Also affects: shadow (Ubuntu Xenial) Importance: Undecided Status: New ** Changed

[Touch-packages] [Bug 1700814] Re: Default capability of cap_setfcap+i should be set on setcap

2022-10-18 Thread Serge Hallyn
> FWIW This used to be the default inside the libcap build tree, but the > problems with the container defaults (eventually fixed with > https://github.com/moby/moby/security/advisories/GHSA-2mm7-x5h6-5pvq Thanks for the links. For a moment I was worried that there was an issue with containers in

[Touch-packages] [Bug 1923232] [NEW] SRU of LXC 4.0.6 to focal (upstream bugfix release)

2021-04-09 Thread Serge Hallyn
built in -proposed are functional. ** Affects: lxc (Ubuntu) Importance: Undecided Status: New ** Affects: lxc (Ubuntu Bionic) Importance: High Assignee: Serge Hallyn (serge-hallyn) Status: New ** Affects: lxc (Ubuntu Focal) Importance: High Assignee

[Touch-packages] [Bug 1923232] Re: SRU of LXC 4.0.6 to focal (upstream bugfix release)

2021-04-09 Thread Serge Hallyn
** No longer affects: lxc (Ubuntu Bionic) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1923232 Title: SRU of LXC 4.0.6 to focal (upstream bugfix release) Status in lxc pack

[Touch-packages] [Bug 1923232] Re: SRU of LXC 4.0.6 to focal (upstream bugfix release)

2021-04-09 Thread Serge Hallyn
** Changed in: lxc (Ubuntu Focal) Status: New => In Progress -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1923232 Title: SRU of LXC 4.0.6 to focal (upstream bugfix re

[Touch-packages] [Bug 1729357] Re: unprivileged user can drop supplementary groups

2023-08-29 Thread Serge Hallyn
** Changed in: shadow (Ubuntu) Importance: Undecided => Low -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to shadow in Ubuntu. https://bugs.launchpad.net/bugs/1729357 Title: unprivileged user can drop supplementary groups

[Touch-packages] [Bug 1840375] Re: groupdel doesn't support extrausers

2019-08-31 Thread Serge Hallyn
Hi, can I interest anyone in pushing the extrausers patch as a PR to github.com/shadow-maint/shadow? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to shadow in Ubuntu. https://bugs.launchpad.net/bugs/1840375 Title: groupdel

Re: [Touch-packages] [Bug 1303649] Re: systemd-logind spins in cgmanager_ping_sync()

2018-03-24 Thread Serge Hallyn
Could you find the pid of cgmanager ( 353 below)‎ and do Strafe -f -p 353 -o trace.txt for maybe 5 seconds, ctrl-c it, and attach trace.txt here? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.la

[Touch-packages] [Bug 1704416] Re: CAP_AUDIT_READ is not supported on Xenial

2018-02-26 Thread Serge Hallyn
Sorry - if this is still an issue, please reply here. ** Changed in: libcap2 (Ubuntu) Assignee: (unassigned) => Serge Hallyn (serge-hallyn) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to libcap2 in Ubuntu. ht

[Touch-packages] [Bug 1700814] Re: Default capability of cap_setfcap+i should be set on setcap

2018-02-26 Thread Serge Hallyn
Assignee: (unassigned) => Serge Hallyn (serge-hallyn) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to libcap2 in Ubuntu. https://bugs.launchpad.net/bugs/1700814 Title: Default capability of cap_setfcap+i should be set on setc

[Touch-packages] [Bug 1303649] Re: systemd-logind spins in cgmanager_ping_sync()

2018-03-12 Thread Serge Hallyn
Hi, just to get this straight to narrow down scenarios to try to reproduce: 1. Dale with 16.04 you are *not* seeing this, right? You saw it with 14.04 with proposed enabled? 2. Marcelo, you are seeing this with 14.04.5 with proposed enabled? -- You received this bug notification because you a

[Touch-packages] [Bug 1729357] Re: unprivileged user can drop supplementary groups

2018-03-13 Thread Serge Hallyn
@stgraber @mdeslaur - I'd considered making a release for Ubuntu... but this is the negative acl thing... Your opinions appreciated. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to shadow in Ubuntu. https://bugs.launchpad.ne

[Touch-packages] [Bug 1782825] [NEW] missing symlink for library

2018-07-20 Thread Serge Hallyn
Public bug reported: On bionic, I needed to ln -s /lib/x86_64-linux-gnu/libdevmapper.so.1.02.1 /lib/x86_64-linux- gnu/libdevmapper.so.1.02 in order for some previously built programs (like skopeo) to continue to work. ** Affects: lvm2 (Ubuntu) Importance: Undecided Status: New --

Re: [Touch-packages] [Bug 1729357] Re: unprivileged user can drop supplementary groups

2018-01-15 Thread Serge Hallyn
This sounds acceptable to me. Issues or (even better) PRs against github.com/shadow-maint/shadow would be great :) Indeed the default should be the more permissible. (I won't accept patches which require changes to the container runtime.) On Mon, Jan 15, 2018 at 9:13 AM, Akihiro Suda wrote: >

[Touch-packages] [Bug 1668724] Re: fails to mount cgroupfs inside containers running on 16.04

2017-10-25 Thread Serge Hallyn
I'll still aim to push this for trusty and xenial. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cgroup-lite in Ubuntu. https://bugs.launchpad.net/bugs/1668724 Title: fails to mount cgroupfs inside containers running on 1

[Touch-packages] [Bug 1668724] Re: fails to mount cgroupfs inside containers running on 16.04

2017-10-25 Thread Serge Hallyn
Drat. I do think this should still be pushed. I don't know when I'll have time to do it though. Please keep it open. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to cgroup-lite in Ubuntu. https://bugs.launchpad.net/bugs/166

[Touch-packages] [Bug 1490110] Re: package lxc 1.1.3-0ubuntu1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 100

2015-10-21 Thread Serge Hallyn
Raising priority since as rbasak pointed out, all vivid cloud image updates to wily will hit this. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to apport in Ubuntu. https://bugs.launchpad.net/bugs/1490110 Title: package lxc

[Touch-packages] [Bug 1490110] Re: package lxc 1.1.3-0ubuntu1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 100

2015-10-21 Thread Serge Hallyn
SystemError: E:Sub-process /usr/bin/dpkg returned an error code (1) Error in sys.excepthook: Traceback (most recent call last): File "/usr/lib/python3/dist-packages/apport_python_hook.py", line 102, in apport_excepthook pr.add_proc_info(extraenv=['PYTHONPATH', 'PYTHONHOME']) File "/usr/lib

[Touch-packages] [Bug 1490110] Re: package lxc 1.1.3-0ubuntu1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 100

2015-10-21 Thread Serge Hallyn
I still think the bug is actually not in lxc. If I take a vivid cloud image, manually install the wily lxc packages with dpkg, that works. Then do-release-upgrade still fails. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

[Touch-packages] [Bug 1490110] Re: package lxc 1.1.3-0ubuntu1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 100

2015-10-21 Thread Serge Hallyn
The original complaint appears to be: dpkg: dependency problems prevent configuration of liblxc1: liblxc1 depends on libdbus-1-3 (>= 1.9.14); however: Version of libdbus-1-3:amd64 on system is 1.8.12-1ubuntu5. The libdbus version being installed is higher than that. Note that that dependency

[Touch-packages] [Bug 1508577] Re: [wily] installing juju-local on ARM64 failed. broken apt dependency

2015-10-21 Thread Serge Hallyn
Please show the results of "systemctl status lxc-net.service" and "journalctl -xe" -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1508577 Title: [wily] installing juju-local

[Touch-packages] [Bug 1490110] Re: package lxc 1.1.3-0ubuntu1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 100

2015-10-21 Thread Serge Hallyn
But even when pre-installing the newer dbus, it still fails with the invoke-rc.d failure. I can't explain that one, have no idea why it is trying to use the /etc/init.d script. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

Re: [Touch-packages] [Bug 1504781] Re: lxc-test-ubuntu hangs forever in trusty-proposed with Linux 3.13.0-66: AppArmor denies /dev/ptmx mounting

2015-10-22 Thread Serge Hallyn
Quoting Stratos Zolotas (str...@gmail.com): > Another one has asked but no reply yet. Is a fix for 12.04 going to be > released? The bug is still valid there. Which bug are you looking for? You're using a backport or ppa or custom built lxc and are looking for a kernel fix? -- You received this

[Touch-packages] [Bug 1508744] Re: Upgrade to Ubuntu 15.10 Broken: lxc-net.service fails on upgrade

2015-10-22 Thread Serge Hallyn
Please show the results of sudo systemctl status lxc-net.service sudo journalctl -u lxc-net sudo journalctl -xe ifconfig -a cat /etc/default/lxc-net ** Changed in: lxc (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seede

[Touch-packages] [Bug 1508577] Re: [wily] installing juju-local on ARM64 failed. broken apt dependency

2015-10-22 Thread Serge Hallyn
Sorry, could you please show the result of sudo journalctl -u lxc-net if that doesn't seem to show anything, then maybe do sudo systemctl start lxc-net sudo journalctl -u lxc-net -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed

[Touch-packages] [Bug 1508744] Re: Upgrade to Ubuntu 15.10 Broken: lxc-net.service fails on upgrade

2015-10-22 Thread Serge Hallyn
Was yours also on an upgrade from vivid to wily? Were you using the stock archive lxc packages? Any customizatoin of the lxc-net configuration? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.laun

[Touch-packages] [Bug 1504781] Re: lxc-test-ubuntu hangs forever in trusty-proposed with Linux 3.13.0-66: AppArmor denies /dev/ptmx mounting

2015-10-23 Thread Serge Hallyn
Judging by jjohansen's comment #8, I guess the shipped common configuration files in precise's lxc should be updated to include the new rule. Precise's lxc is in universe, community supported. Can you provide a proposed, tested debdiff and ping me? I'll sponsor it when ready if needed. -- You

[Touch-packages] [Bug 1509414] Re: lxc postinst script checks available interfaces, can choose

2015-10-23 Thread Serge Hallyn
Debdiff which works for me. I tested this by creating a cloud container, temporarily setting USE_LXC_BRIDGE=false, rebooting, building the package, setting USE_LXC_BRIDGE=true (leaving 10.0.3 as the lxcbr0 subnet), rebooting. lxcbr0 comes up with 10.0.4.1 as expected. A nested trusty container wo

[Touch-packages] [Bug 1509414] Re: lxc postinst script checks available interfaces, can choose

2015-10-23 Thread Serge Hallyn
I don't like disabling lxc-net, because it's simpler to tell a user to apt-get install lxd than to systemctl enable lxc-net or echo "USE_LXC_BRIDGE=true" | sudo tee -a /etc/default/lxc-net systemctl restart lxc-net -- You received this bug notification because you are a member of Ubuntu Touc

[Touch-packages] [Bug 1509414] Re: lxc postinst script checks available interfaces, can choose

2015-10-23 Thread Serge Hallyn
Updated debdiff, which 1. stops creation of /etc/default/lxc-net on package install 2. removes that file only if upgrading from the 1.0.4ubuntu4 version with an umodified /etc/default/lxc-net file ** Patch added: "lxcnet4.debdiff" https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1509414/+

[Touch-packages] [Bug 1509414] Re: pre-installed lxc in cloud image produces broken lxc (and later lxd) containers

2015-10-23 Thread Serge Hallyn
new patch. It upgrades a broken container fine, but lxc-net is not properly started until I manually call /usr/lib/x86_64-linux-gnu/lxc/lxc-net stop /usr/lib/x86_64-linux-gnu/lxc/lxc-net start or reboot ** Patch added: "lxcnet6.debdiff" https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/15

[Touch-packages] [Bug 1509414] Re: pre-installed lxc in cloud image produces broken lxc (and later lxd) containers

2015-10-23 Thread Serge Hallyn
Final proposed patch for now. Uploaded to ppa:serge-hallyn/lxc-natty for wily. Installing this on a fresh ubuntu-cloud wily container (i.e. a broken one) results in working lxcbr0 on new subnet. ** Patch added: "lxcnet8.debdiff" https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1509414/+att

[Touch-packages] [Bug 1509414] Re: pre-installed lxc in cloud image produces broken lxc (and later lxd) containers

2015-10-23 Thread Serge Hallyn
Handle one more corner case ** Patch added: "lxcnet9.debdiff" https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1509414/+attachment/4503630/+files/lxcnet9.debdiff -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ub

[Touch-packages] [Bug 1509414] Re: pre-installed lxc in cloud image produces broken lxc (and later lxd) containers

2015-10-23 Thread Serge Hallyn
** Patch added: "And one more to fix in vms" https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1509414/+attachment/4503681/+files/lxcneta.debdiff -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs

[Touch-packages] [Bug 1508577] Re: [wily] installing juju-local on ARM64 failed. broken apt dependency

2015-10-23 Thread Serge Hallyn
Ah, thanks for that info. ** Changed in: lxc (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1508577 Title: [wily] installing juju-lo

[Touch-packages] [Bug 1509414] Re: pre-installed lxc in cloud image produces broken lxc (and later lxd) containers

2015-10-24 Thread Serge Hallyn
New image works for me in lxc: lxcbr0Link encap:Ethernet HWaddr 76:79:3e:90:1c:88 inet addr:10.0.4.1 Bcast:0.0.0.0 Mask:255.255.255.0 -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.laun

[Touch-packages] [Bug 1509414] Re: pre-installed lxc in cloud image produces broken lxc (and later lxd) containers

2015-10-24 Thread Serge Hallyn
I was able to For stage two, at least with systemd, I changed /lib/systemd/system/lxd-startup.service to: [Unit] Description=Container hypervisor based on LXC - boot time check After=cgmanager.service lxd-unix.socket Requires=cgmanager.service lxd-unix.socket [Service] Type=oneshot ExecStart=/usr

[Touch-packages] [Bug 1509414] Re: pre-installed lxc in cloud image produces broken lxc (and later lxd) containers

2015-10-24 Thread Serge Hallyn
This lxc debdiff (not appropriate upstream lxc) and a pull request against lxd-pkg-ubuntu (https://github.com/lxc/lxd-pkg-ubuntu/pull/7) combined should implement stage 2 of the fix. Note I've tested these when separately implemented by hand, but have not built packages with this debdiff+pull-requ

Re: [Touch-packages] [Bug 1509414] Re: pre-installed lxc in cloud image produces broken lxc (and later lxd) containers

2015-10-25 Thread Serge Hallyn
Quoting Stéphane Graber (stgra...@stgraber.org): > I agree, the stage 2 fix for this issue concerns me with regard to > regressing current use cases. > > As much as I'd like to get rid of the rest of this issue (any user of > 10.0.4.0/24 behind a router looses connectivity to that subnet), we must

[Touch-packages] [Bug 1498162] Re: unable to make backup link of `./usr/sbin/uuidd' before installing new version: Operation not permitted

2015-10-26 Thread Serge Hallyn
It's the setuid and setgid bits with user namespace. ** Also affects: linux (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to util-linux in Ubuntu. https://bugs.launchpad.net

[Touch-packages] [Bug 1498162] Re: unable to make backup link of `./usr/sbin/uuidd' before installing new version: Operation not permitted

2015-10-26 Thread Serge Hallyn
You can work around this by doing echo 0 | sudo tee -a /proc/sys/fs/protected_hardlinks on the host. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to util-linux in Ubuntu. https://bugs.launchpad.net/bugs/1498162 Title: una

[Touch-packages] [Bug 1504781] Re: lxc-test-ubuntu hangs forever in trusty-proposed with Linux 3.13.0-66: AppArmor denies /dev/ptmx mounting

2015-10-27 Thread Serge Hallyn
@stefan-huehner - sorry, I'm losing track. is what you are asking for just a lxc update to precise-proposed with the new apparmor allow rule that jj suggested? If so, in comment #33 I was trying to encourage a debdiff to be posted by someone who could best test it. I'll then sponsor it into the

Re: [Touch-packages] [Bug 1509752] [NEW] Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-27 Thread Serge Hallyn
Thanks - haven't tested, but it certainly makes sense. status: confirmed importance: high ** Changed in: lxc (Ubuntu) Importance: Undecided => High ** Changed in: lxc (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch s

[Touch-packages] [Bug 1472369] Re: lxcbr0 missing after starting lxc-net.service

2015-10-27 Thread Serge Hallyn
*** This bug is a duplicate of bug 1468611 *** https://bugs.launchpad.net/bugs/1468611 @paugnu which ubuntu release are you on and what is your dnsmasq version? (dpkg -l dnsmasq) Do you have bind installed? Does creating /etc/dnsmasq.conf fix without having to clear out /etc/dnsmasq.d/lxc

[Touch-packages] [Bug 1509752] Re: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-27 Thread Serge Hallyn
Apparently the kernel is now fixed so that we should be able to use the upstream fix. I'm going to try to get that into the trusty package rather than keep tweakng this separate patch. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscr

[Touch-packages] [Bug 1504781] Re: lxc-test-ubuntu hangs forever in trusty-proposed with Linux 3.13.0-66: AppArmor denies /dev/ptmx mounting

2015-10-28 Thread Serge Hallyn
** Also affects: linux (Ubuntu Precise) Importance: Undecided Status: New ** Also affects: lxc (Ubuntu Precise) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubun

[Touch-packages] [Bug 1504781] Re: lxc-test-ubuntu hangs forever in trusty-proposed with Linux 3.13.0-66: AppArmor denies /dev/ptmx mounting

2015-10-28 Thread Serge Hallyn
** Description changed: + == + SRU Justification: + Impact: containers fail to start! + Regression potential: we only add a copy of an existing apparmor allow rule + with a different syntax (no trailing /), leaving the old one for o

[Touch-packages] [Bug 1509752] Re: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-28 Thread Serge Hallyn
Yup, switching in the upstream fix works - will upload that in a bit. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1509752 Title: Bug in ensure_not_symlink() from 0003-CVE-2

[Touch-packages] [Bug 1509752] Re: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-28 Thread Serge Hallyn
** Also affects: lxc (Ubuntu Trusty) Importance: Undecided Status: New ** Changed in: lxc (Ubuntu Trusty) Importance: Undecided => High ** Changed in: lxc (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Touc

[Touch-packages] [Bug 1509752] Re: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-28 Thread Serge Hallyn
No, sadly one testcase - lxc-test-unpriv - still fails: Oct 28 15:33:49 lxct1 kernel: [ 2659.417204] type=1400 audit(1446046429.177:52): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="/usr/bin/lxc-start" name="/home/lxcunpriv/.local/share/lxc/c1/rootfs/dev/consol

[Touch-packages] [Bug 1509752] Re: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-28 Thread Serge Hallyn
** Description changed: - This bug/limitation is present in lxc from 1.0.7-0ubuntu0.5 through - 1.0.7-0ubuntu0.9 (or anything that incorporates - 0003-CVE-2015-1335.patch). Basically, the limitation is obvious when - using recursive bind mounts because ensure_not_symlink() only checks the - last

[Touch-packages] [Bug 1509752] Re: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-28 Thread Serge Hallyn
(invalid would probably be a better status for the development release, but i dont' want to scare the SRU team :) Uploaded a workaround for this bug. Using the upstream fix sadly is still broken by apparmor+overlayfs bugs. -- You received this bug notification because you are a member of Ubuntu

[Touch-packages] [Bug 1504496] Re: package lxc 1.1.4-0ubuntu0.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2015-10-30 Thread Serge Hallyn
Actually the most telling sign in the logs here is Oct 09 11:56:42 quelbo lxc-net[23366]: lxc-net is already running If someone can reproduce this again, please attach the same information Nick had assigned in addition to 'ifconfig -a' and 'systemctl -u lxc- net' output. ** Changed in: lxc (Ubu

[Touch-packages] [Bug 1504496] Re: package lxc 1.1.4-0ubuntu0.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2015-10-30 Thread Serge Hallyn
(marking incomplete as we need more information to debug, but we've lost the reproducer) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1504496 Title: package lxc 1.1.4-0ubunt

[Touch-packages] [Bug 1504496] Re: package lxc 1.1.4-0ubuntu0.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2015-10-30 Thread Serge Hallyn
fwiw i don't think this is bug 1490110 because the signature is different - there is complaint about the sysv job not being there. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/

[Touch-packages] [Bug 1511830] Re: apparmor denies VM startup when image is network mounted

2015-11-02 Thread Serge Hallyn
Thanks for reporting this bug. Can you show the xml for the libvirt managed nfs storage and for the VM? The virt-aa-helper policy has # needed for when disk is on a network filesystem network inet, Which I suspect should prevent this from happening, so I will target this at apparmor. ** A

[Touch-packages] [Bug 1511875] Re: Can't upgrade from 15.10 Wily to 16.04 Xenial in LXC container

2015-11-02 Thread Serge Hallyn
same thing happens with vivid->wily upgrade. ** Changed in: ubuntu-release-upgrader (Ubuntu) Status: New => Confirmed ** Changed in: lxc (Ubuntu) Status: New => Triaged ** Changed in: lxc (Ubuntu) Importance: Undecided => High ** Changed in: ubuntu-release-upgrader (Ubuntu)

[Touch-packages] [Bug 1511875] Re: Can't upgrade from 15.10 Wily to 16.04 Xenial in LXC container

2015-11-02 Thread Serge Hallyn
It does this in an unprivileged (true root) as well as a apparmor- unconfined container. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1511875 Title: Can't upgrade from 15.10

[Touch-packages] [Bug 1511875] Re: Can't upgrade from 15.10 Wily to 16.04 Xenial in LXC container

2015-11-02 Thread Serge Hallyn
** Attachment added: "/var/log/dist-upgrade/apt.log file" https://bugs.launchpad.net/ubuntu/+source/ubuntu-release-upgrader/+bug/1511875/+attachment/4511345/+files/apt.log -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lx

[Touch-packages] [Bug 1511993] Re: when trying to install the lxd package, lxc fails to install

2015-11-02 Thread Serge Hallyn
Oct 31 18:12:17 majid-top lxc-net[6891]: iptables v1.4.21: can't initialize iptables table `nat': Table does not exist (do you need to insmod?) Oct 31 18:12:17 majid-top lxc-net[6891]: Perhaps iptables or your kernel needs to be upgraded. Oct 31 18:12:17 majid-top lxc-net[6891]: Failed to setup l

[Touch-packages] [Bug 1497420] Re: systemd 226 (moving pid 1 into /init.scope cgroup) breaks lxc-attach

2015-11-03 Thread Serge Hallyn
Yup, we need https://github.com/lxc/lxc/commit/f348e47c93568b4f0c371cf5df1c98d4e816a86c in the packages. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1497420 Title: system

[Touch-packages] [Bug 1475749] Re: usermod --add-subuids fails for users not in /etc/passwd

2015-11-03 Thread Serge Hallyn
** Changed in: shadow (Ubuntu Vivid) Status: Fix Committed => Confirmed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to shadow in Ubuntu. https://bugs.launchpad.net/bugs/1475749 Title: usermod --add-subuids fails for

[Touch-packages] [Bug 1452601] Re: vivid container's networking.service fails on boot with signal=PIPE

2015-11-03 Thread Serge Hallyn
@Kevin, could you please give some more details? In particular, release of both host and container, where exactly it fails, and the relevant journalctl output. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. h

[Touch-packages] [Bug 1475749] Re: usermod --add-subuids fails for users not in /etc/passwd

2015-11-03 Thread Serge Hallyn
(sorry, i msread the bug history) ** Changed in: shadow (Ubuntu Vivid) Status: Confirmed => Fix Committed -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to shadow in Ubuntu. https://bugs.launchpad.net/bugs/1475749 Title

[Touch-packages] [Bug 1475749] Re: usermod --add-subuids fails for users not in /etc/passwd

2015-11-03 Thread Serge Hallyn
The test case in the Description passed cleanly for me (and failed without -proposed) ** Tags removed: verification-needed ** Tags added: verification-done -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to shadow in Ubuntu. ht

Re: [Touch-packages] [Bug 1294200] Re: test linked against nih-dbus-tool-generated libraryis not thread-safe

2015-11-03 Thread Serge Hallyn
I don't know. libnih is still a nice library and it would be nice if it could be fixed. Certainly the lxcfs bug should be marked invalid since we no longer use it. Perhaps lxc eventually, but not yet. -- You received this bug notification because you are a member of Ubuntu Touch seeded package

[Touch-packages] [Bug 1452601] Re: vivid container's networking.service fails on boot with signal=PIPE

2015-11-04 Thread Serge Hallyn
Hi, you're actually geting EPERM, which means lxcbr0 exists. Please show the output of: sudo lxc-start -n escale_build -F -l trace -o /dev/stdout sudo brctl show sudo ifconfig -a sudo journalctl -u lxc-net sudo systemd-detect-virt -- You received this bug notification because you are a member

[Touch-packages] [Bug 1504781] Re: lxc-test-ubuntu hangs forever in trusty-proposed with Linux 3.13.0-66: AppArmor denies /dev/ptmx mounting

2015-11-04 Thread Serge Hallyn
Hi, The fix was uploaded last week for acceptance by the SRU team. It's waiting to be accepted into -proposed. Then it will need to be tested to be accepted into -updates. https://launchpad.net/ubuntu/precise/+queue?queue_state=1&queue_text=lxc -- You received this bug notification because yo

[Touch-packages] [Bug 1294200] Re: test linked against nih-dbus-tool-generated libraryis not thread-safe

2015-11-04 Thread Serge Hallyn
Ok. It was 'fix released' in cgmanager and lxc by working around it (not enabling threading). It is invalid in lxcfs in xenial because we have switched to glib and gdbus there. The libnih and dbus bugs are still open, though in dbus it is wontfix from upstream. Since dbus is wontfix, I think we

[Touch-packages] [Bug 1452601] Re: vivid container's networking.service fails on boot with signal=PIPE

2015-11-04 Thread Serge Hallyn
Thanks, what about sudo brctl show sudo ifconfig -a sudo journalctl -u lxc-net sudo systemd-detect-virt -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1452601 Title: vivid co

[Touch-packages] [Bug 1452601] Re: vivid container's networking.service fails on boot with signal=PIPE

2015-11-05 Thread Serge Hallyn
Ok, so the error msg is simply misleading - it says 'permission denied', but the bridge does not exist. Can you please show: sudo /usr/lib/x86_64-linux-gnu/lxc/lxc-net stop sudo /usr/lib/x86_64-linux-gnu/lxc/lxc-net start sudo brctl show and see if your container now starts? Please also paste /

[Touch-packages] [Bug 1452601] Re: vivid container's networking.service fails on boot with signal=PIPE

2015-11-05 Thread Serge Hallyn
You're still getting dnsmasq: failed to create listening socket for 10.0.3.1: Cannot assign requested address What does sudo netstat -lap| grep LISTEN show? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to l

Re: [Touch-packages] [Bug 1513698] [NEW] $HOME variable set incorrectly inside container

2015-11-05 Thread Serge Hallyn
Right, this is mentioned in the manpage. You can force environment to be cleared by passing --clear-env. Actually setting HOME to what a login shell would do would require lxc-attach to make assumptions about the container. However you can lxc-attach -n trusty-vimprobable --clear-env -- su - ro

[Touch-packages] [Bug 1452437] Re: 15.04 container does not get an IP address when started

2015-11-06 Thread Serge Hallyn
*** This bug is a duplicate of bug 1240757 *** https://bugs.launchpad.net/bugs/1240757 ** This bug is no longer a duplicate of bug 1452601 vivid container's networking.service fails on boot with signal=PIPE ** This bug has been marked a duplicate of bug 1240757 Bridge not created if bind

[Touch-packages] [Bug 1452601] Re: vivid container's networking.service fails on boot with signal=PIPE

2015-11-06 Thread Serge Hallyn
*** This bug is a duplicate of bug 1240757 *** https://bugs.launchpad.net/bugs/1240757 D'oh! thanks for that info. You are running bind9, which is causing the conflict. To work around this, you can tell bind9 to not listen on 10.0.3.1 - see https://bugs.launchpad.net/ubuntu/+source/lxc/+bug

[Touch-packages] [Bug 1451232] Re: container does not receive IP address after 15.04 upgrade

2015-11-06 Thread Serge Hallyn
*** This bug is a duplicate of bug 1240757 *** https://bugs.launchpad.net/bugs/1240757 ** This bug is no longer a duplicate of bug 1452601 vivid container's networking.service fails on boot with signal=PIPE ** This bug has been marked a duplicate of bug 1240757 Bridge not created if bind

Re: [Touch-packages] [Bug 1497420] Re: systemd 226 (moving pid 1 into /init.scope cgroup) breaks lxc-attach

2015-11-09 Thread Serge Hallyn
Hi Martin, thanks for that info. During a reboot, lxc deletes the container's cgroup, then recreates it. Is systemd expecting the cgroup it previously created to stick around? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to

Re: [Touch-packages] [Bug 1452601] Re: vivid container's networking.service fails on boot with signal=PIPE

2015-11-09 Thread Serge Hallyn
*** This bug is a duplicate of bug 1240757 *** https://bugs.launchpad.net/bugs/1240757 Quoting Kevin Dalley (1452...@bugs.launchpad.net): > *** This bug is a duplicate of bug 1240757 *** > https://bugs.launchpad.net/bugs/1240757 > > I have now added > > listen-on-v6 { none; }; > re

[Touch-packages] [Bug 1480411] Re: rm -r * fails to delete directories when using overlayfs in a user-namespace

2015-11-10 Thread Serge Hallyn
@oleg, yes, but it is not an lxc bug, there's nothing lxc can do about it. Stéphane un-marked it from lxc to make the lxc bug view more usable so we can use it rather than ignore it :) -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscr

[Touch-packages] [Bug 1514080] Re: lxc-templates lacks template for ubuntu core

2015-11-10 Thread Serge Hallyn
The download template (which is recommended) installs no ssh and no ubuntu password. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1514080 Title: lxc-templates lacks template

[Touch-packages] [Bug 1514690] Re: rebooting container with systemd >= 226 fails to create /lxc/adt-xenial/init.scope control group

2015-11-10 Thread Serge Hallyn
** Changed in: lxc (Ubuntu) Assignee: (unassigned) => Serge Hallyn (serge-hallyn) ** Changed in: lxc (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu.

[Touch-packages] [Bug 1514690] Re: rebooting container with systemd >= 226 fails to create /lxc/adt-xenial/init.scope control group

2015-11-10 Thread Serge Hallyn
Doh', it's because I had a total brainfart while writing that. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1514690 Title: rebooting container with systemd >= 226 fails to c

[Touch-packages] [Bug 1514690] Re: rebooting container with systemd >= 226 fails to create /lxc/adt-xenial/init.scope control group

2015-11-10 Thread Serge Hallyn
When I test this using cgfs-backed lxcfs, the mkdir of init.cgroup fails after setresuid(10, 10, 0). This is odd since doing it manually using sudo -u \#10 -g \#10 mkdir /sys/fs/cgroup/systemd/lxc/x1/x works fine. -- You received this bug notification because you are a member of

[Touch-packages] [Bug 1514690] Re: rebooting container with systemd >= 226 fails to create /lxc/adt-xenial/init.scope control group

2015-11-10 Thread Serge Hallyn
That was a red herring, actually. The cause of failure appears to be the next line. After fixing that so that the mkdir succeeds, it still fails on Failed to allocate manager object: No such file or directory -- You received this bug notification because you are a member of Ubuntu Touch seeded

  1   2   3   4   5   6   7   8   >