[Bug 1535058] Re: applications close instantly when launched from the launcher or dash

2016-01-21 Thread Serge Hallyn
@ted,

could you restart cgmanager with --debug, then show the debug output?

(Assuming you're on systemd,  add --debug to the cmdline in
/lib/systemd/system/cgmanager.service, restart it, start an app, then
show output of journalctl -u cgmanager)

I suspect libpam-cgm will need to create the cgroup with same path that
systemd used for the name=systemd cgroup.

That, or (if this is the exact problem) upstart needs to not assume that
all cgroups are the same path.


** Also affects: cgmanager (Ubuntu)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1535058

Title:
  applications close instantly when launched from the launcher or dash

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cgmanager/+bug/1535058/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1536280] Re: domain shutdown fails for libvirt/lxc

2016-01-20 Thread Serge Hallyn
marking as affecting kernel given the description.


** Also affects: linux (Ubuntu)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to libvirt in Ubuntu.
https://bugs.launchpad.net/bugs/1536280

Title:
  domain shutdown fails for libvirt/lxc

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1536280/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1536280] Re: domain shutdown fails for libvirt/lxc

2016-01-20 Thread Serge Hallyn
marking as affecting kernel given the description.


** Also affects: linux (Ubuntu)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1536280

Title:
  domain shutdown fails for libvirt/lxc

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1536280/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


Re: [Bug 1536331] [NEW] Precise to Trusty live migration failing

2016-01-20 Thread Serge Hallyn
Thanks for reporting this bug - I will work on reproducing later today.

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to qemu in Ubuntu.
https://bugs.launchpad.net/bugs/1536331

Title:
  Precise to Trusty live migration failing

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/qemu/+bug/1536331/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


Re: [Bug 1536331] [NEW] Precise to Trusty live migration failing

2016-01-20 Thread Serge Hallyn
Thanks for reporting this bug - I will work on reproducing later today.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1536331

Title:
  Precise to Trusty live migration failing

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/qemu/+bug/1536331/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1529079] Re: Can't start virtual machines after upgrade to Xenial

2016-01-19 Thread Serge Hallyn
I'm also curious why the launchpad janitor marked this bug confirmed.
If anyone else can reproduce this issue, please comment here.
Otherwise, I do not want it marked confirmed until someone truly
independently reproduces it.


** Changed in: libvirt (Ubuntu)
   Status: Confirmed => Incomplete

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1529079

Title:
  Can't start virtual machines after upgrade to Xenial

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1529079/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1529079] Re: Can't start virtual machines after upgrade to Xenial

2016-01-19 Thread Serge Hallyn
I still cannot reproduce this at all, even when starting VMs from virt-
manager.

Are you still able to reproduce this?  (I'm wondering whether perhaps
there was a temporary bad state of systemd and libvirt being out of sync
some magical way)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1529079

Title:
  Can't start virtual machines after upgrade to Xenial

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1529079/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


Re: [Bug 1529079] Re: Can't start virtual machines after upgrade to Xenial

2016-01-19 Thread Serge Hallyn
Quoting RussianNeuroMancer (1529...@bugs.launchpad.net):
> > I still cannot reproduce this at all, even when starting VMs from 
> > virt-manager.
> Well, for fresh install this is not reproducible for me too. And 15.10-16.04
> upgrade may not be actual trigger - both testing systems get upgraded for a

And it is still reproducible after reboot after the upgrade, right?

> long time, Kubuntu from 11.04 as I remember. So there is may be something
> ancient that showed up just now. Or not so ancient - maybe some
> upstart->systemd upgrade issue. I have no idea actually what it may be. How I
> can help here find what's going on?
> 
> > Are you still able to reproduce this? (I'm wondering whether perhaps there 
> > was a temporary bad state of systemd and libvirt being out of sync some 
> > magical way)
> Still reproducible on my testing Kubuntu 16.04 setup. I can try Ubuntu Server 
> 15.10->16.04 upgrade once again, if necessary. Is it needed if issue still 
> reproducible on updated Kubuntu 16.04?

I'll try the upgrade too.  Thanks for the hint.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1529079

Title:
  Can't start virtual machines after upgrade to Xenial

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1529079/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1534090] Re: 'call to get_tasks_recursive failed' errors from su

2016-01-18 Thread Serge Hallyn
@tkedwards,

Could you please show your cgmanager version?

dpkg -l | grep cgmanager

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1534090

Title:
  'call to get_tasks_recursive failed' errors from su

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cgmanager/+bug/1534090/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


Re: [Bug 1533833] Re: unprivileged lxc containers won't start, need to put sessions into "pids" cgroup controller

2016-01-18 Thread Serge Hallyn
Thanks - Martin - tested that with the mainline kernel, and it did indeed
give me a pids cgroup:

ubuntu@pitti:~$ cat /proc/self/cgroup
11:hugetlb:/user.slice/user-1000.slice/session-2.scope
10:blkio:/user.slice/user-1000.slice/session-2.scope
9:devices:/user.slice/user-1000.slice/session-2.scope
8:pids:/user.slice/user-1000.slice/session-2.scope
7:memory:/user.slice/user-1000.slice/session-2.scope
6:perf_event:/user.slice/user-1000.slice/session-2.scope
5:cpuset:/user.slice/user-1000.slice/session-2.scope
4:net_cls,net_prio:/user.slice/user-1000.slice/session-2.scope
3:freezer:/user.slice/user-1000.slice/session-2.scope
2:cpu,cpuacct:/user.slice/user-1000.slice/session-2.scope
1:name=systemd:/user.slice/user-1000.slice/session-2.scope

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to lxc in Ubuntu.
https://bugs.launchpad.net/bugs/1533833

Title:
  unprivileged lxc containers won't start, need to put sessions into
  "pids"  cgroup controller

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1533833/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


Re: [Bug 1533833] Re: unprivileged lxc containers won't start, need to put sessions into "pids" cgroup controller

2016-01-18 Thread Serge Hallyn
Thanks - Martin - tested that with the mainline kernel, and it did indeed
give me a pids cgroup:

ubuntu@pitti:~$ cat /proc/self/cgroup
11:hugetlb:/user.slice/user-1000.slice/session-2.scope
10:blkio:/user.slice/user-1000.slice/session-2.scope
9:devices:/user.slice/user-1000.slice/session-2.scope
8:pids:/user.slice/user-1000.slice/session-2.scope
7:memory:/user.slice/user-1000.slice/session-2.scope
6:perf_event:/user.slice/user-1000.slice/session-2.scope
5:cpuset:/user.slice/user-1000.slice/session-2.scope
4:net_cls,net_prio:/user.slice/user-1000.slice/session-2.scope
3:freezer:/user.slice/user-1000.slice/session-2.scope
2:cpu,cpuacct:/user.slice/user-1000.slice/session-2.scope
1:name=systemd:/user.slice/user-1000.slice/session-2.scope

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1533833

Title:
  unprivileged lxc containers won't start, need to put sessions into
  "pids"  cgroup controller

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1533833/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1534090] Re: 'call to get_tasks_recursive failed' errors from su

2016-01-18 Thread Serge Hallyn
Confirmed it happens for me with the lxd-git-master ppa.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1534090

Title:
  'call to get_tasks_recursive failed' errors from su

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cgmanager/+bug/1534090/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1534090] Re: 'call to get_tasks_recursive failed' errors from su

2016-01-18 Thread Serge Hallyn
I'll remove all those error messages printed to stderr in pam/cgmanager.c.  If 
cgmanager
were going to last I would take the time to pass the errors back up to log them 
to syslog,
but it's just not worth it.


** Changed in: cgmanager (Ubuntu)
   Importance: Undecided => Medium

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1534090

Title:
  'call to get_tasks_recursive failed' errors from su

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cgmanager/+bug/1534090/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


Re: [Bug 1534090] Re: 'call to get_tasks_recursive failed' errors from su

2016-01-18 Thread Serge Hallyn
Yup that'll get the update.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1534090

Title:
  'call to get_tasks_recursive failed' errors from su

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cgmanager/+bug/1534090/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1534090] Re: 'call to get_tasks_recursive failed' errors from su

2016-01-18 Thread Serge Hallyn
Trusty doesn't have libpam-cgm.  Do you mean in ppas?


** Also affects: cgmanager (Ubuntu Wily)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1534090

Title:
  'call to get_tasks_recursive failed' errors from su

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cgmanager/+bug/1534090/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1534090] Re: 'call to get_tasks_recursive failed' errors from su

2016-01-18 Thread Serge Hallyn
Trusty doesn't have libpam-cgm.  Do you mean in ppas?


** Also affects: cgmanager (Ubuntu Wily)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to cgmanager in Ubuntu.
https://bugs.launchpad.net/bugs/1534090

Title:
  'call to get_tasks_recursive failed' errors from su

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cgmanager/+bug/1534090/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1535494] [NEW] Fix numa_node_to_cpus patch

2016-01-18 Thread Serge Hallyn
Public bug reported:

In bug 1358835 we applied a fix to supress a warning.  The patch is different
from upstream (and appears wrong).

In particular,

+   if (numa_bitmask_isbitset(numa_nodes_ptr, node)) {

becomes

+   if (f) {

Switch to a straight cherrypick of the upstream patch.

** Affects: numactl (Ubuntu)
 Importance: Medium
 Status: Triaged

** Affects: numactl (Ubuntu Trusty)
 Importance: Undecided
 Status: New

** Affects: numactl (Ubuntu Vivid)
 Importance: Undecided
 Status: New

** Changed in: numactl (Ubuntu)
   Importance: Undecided => Medium

** Changed in: numactl (Ubuntu)
   Status: New => Triaged

** Also affects: numactl (Ubuntu Vivid)
   Importance: Undecided
   Status: New

** Also affects: numactl (Ubuntu Trusty)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to numactl in Ubuntu.
https://bugs.launchpad.net/bugs/1535494

Title:
  Fix numa_node_to_cpus patch

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/numactl/+bug/1535494/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1535494] [NEW] Fix numa_node_to_cpus patch

2016-01-18 Thread Serge Hallyn
Public bug reported:

In bug 1358835 we applied a fix to supress a warning.  The patch is different
from upstream (and appears wrong).

In particular,

+   if (numa_bitmask_isbitset(numa_nodes_ptr, node)) {

becomes

+   if (f) {

Switch to a straight cherrypick of the upstream patch.

** Affects: numactl (Ubuntu)
 Importance: Medium
 Status: Triaged

** Affects: numactl (Ubuntu Trusty)
 Importance: Undecided
 Status: New

** Affects: numactl (Ubuntu Vivid)
 Importance: Undecided
 Status: New

** Changed in: numactl (Ubuntu)
   Importance: Undecided => Medium

** Changed in: numactl (Ubuntu)
   Status: New => Triaged

** Also affects: numactl (Ubuntu Vivid)
   Importance: Undecided
   Status: New

** Also affects: numactl (Ubuntu Trusty)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1535494

Title:
  Fix numa_node_to_cpus patch

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/numactl/+bug/1535494/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1358835] Re: numa_node_of_cpu() returns warning when cpu_index > 79

2016-01-18 Thread Serge Hallyn
The patch in our package has the upstream patch except for one apparent
error - it checks for

if (f)

instead of

if (numa_bitmask_isbitset(numa_nodes_ptr, node)) {

I think it will be easiest to open a new bug to fix that.  I'll note the
new bug# here.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1358835

Title:
  numa_node_of_cpu() returns warning  when cpu_index > 79

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/numactl/+bug/1358835/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1358835] Re: numa_node_of_cpu() returns warning when cpu_index > 79

2016-01-18 Thread Serge Hallyn
The patch in our package has the upstream patch except for one apparent
error - it checks for

if (f)

instead of

if (numa_bitmask_isbitset(numa_nodes_ptr, node)) {

I think it will be easiest to open a new bug to fix that.  I'll note the
new bug# here.

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to numactl in Ubuntu.
https://bugs.launchpad.net/bugs/1358835

Title:
  numa_node_of_cpu() returns warning  when cpu_index > 79

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/numactl/+bug/1358835/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1358835] Re: numa_node_of_cpu() returns warning when cpu_index > 79

2016-01-18 Thread Serge Hallyn
Opened bug 1535494

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to numactl in Ubuntu.
https://bugs.launchpad.net/bugs/1358835

Title:
  numa_node_of_cpu() returns warning  when cpu_index > 79

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/numactl/+bug/1358835/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1358835] Re: numa_node_of_cpu() returns warning when cpu_index > 79

2016-01-18 Thread Serge Hallyn
Opened bug 1535494

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1358835

Title:
  numa_node_of_cpu() returns warning  when cpu_index > 79

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/numactl/+bug/1358835/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1100976] Re: raring iso not booting in kvm

2016-01-18 Thread Serge Hallyn
Hi,

Can you show the result of doing

sudo kvm-ok
groups
and
kvm -vnc :1


** Changed in: qemu (Ubuntu)
   Status: Confirmed => Incomplete

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1100976

Title:
  raring iso not booting in kvm

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/qemu/+bug/1100976/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1122245] Re: booting from a cloud image hangs until virsh console is used

2016-01-18 Thread Serge Hallyn
Given the affected releases are all EOL, I will mark this bug invalid.
If anyone still sees this happen, please re-open.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1122245

Title:
  booting from a cloud image hangs until virsh console is used

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1122245/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1100976] Re: raring iso not booting in kvm

2016-01-18 Thread Serge Hallyn
Hi,

Can you show the result of doing

sudo kvm-ok
groups
and
kvm -vnc :1


** Changed in: qemu (Ubuntu)
   Status: Confirmed => Incomplete

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to qemu in Ubuntu.
https://bugs.launchpad.net/bugs/1100976

Title:
  raring iso not booting in kvm

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/qemu/+bug/1100976/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1535063] Re: package libvirt-bin 1.2.16-2ubuntu11.15.10.2 failed to install/upgrade: le sous-processus script post-installation installé a retourné une erreur de sortie d'état 1

2016-01-18 Thread Serge Hallyn
Thanks for reporting this bug.

janv. 17 12:37:51 hostname libvirtd[22974]: Unable to initialize audit layer: 
Permission non accordée
janv. 17 12:37:51 hostname libvirtd[22974]: cannot connect to netlink socket 
with protocol 0: Permission non accordée

Can you show what happens when you type

sudo libvirtd -v

on the command line?

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1535063

Title:
  package libvirt-bin 1.2.16-2ubuntu11.15.10.2 failed to
  install/upgrade: le sous-processus script post-installation installé a
  retourné une erreur de sortie d'état 1

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1535063/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 1533839] Re: vms shutting down on libvirt upgrade

2016-01-15 Thread Serge Hallyn
** Also affects: init-system-helpers (Ubuntu)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1533839

Title:
  vms shutting down on libvirt upgrade

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/init-system-helpers/+bug/1533839/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1533839] Re: vms shutting down on libvirt upgrade

2016-01-15 Thread Serge Hallyn
** Also affects: init-system-helpers (Ubuntu)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to init-system-helpers in Ubuntu.
https://bugs.launchpad.net/bugs/1533839

Title:
  vms shutting down on libvirt upgrade

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/init-system-helpers/+bug/1533839/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1432644] Re: VM permanently tries to read /dev/shm/lttng-ust-wait-5

2016-01-15 Thread Serge Hallyn
The bug was fixed in vivid (and later).  Which libvirt version are you
using?

It sounds like we need to SRU this to trusty.

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to ceph in Ubuntu.
https://bugs.launchpad.net/bugs/1432644

Title:
  VM permanently tries to read /dev/shm/lttng-ust-wait-5

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ceph/+bug/1432644/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1432644] Re: VM permanently tries to read /dev/shm/lttng-ust-wait-5

2016-01-15 Thread Serge Hallyn
The bug was fixed in vivid (and later).  Which libvirt version are you
using?

It sounds like we need to SRU this to trusty.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1432644

Title:
  VM permanently tries to read /dev/shm/lttng-ust-wait-5

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/ceph/+bug/1432644/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1534487] Re: cgroup change failed (freezer) when using sudo

2016-01-15 Thread Serge Hallyn
(If the bug ends up being only the warning message, than it is fix
released and low priority.  If there is a problem affect lxc startup,
then it is high priority)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1534487

Title:
  cgroup change failed (freezer) when using sudo

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cgmanager/+bug/1534487/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1534487] Re: cgroup change failed (freezer) when using sudo

2016-01-15 Thread Serge Hallyn
(If the bug ends up being only the warning message, than it is fix
released and low priority.  If there is a problem affect lxc startup,
then it is high priority)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1534487

Title:
  cgroup change failed (freezer) when using sudo

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cgmanager/+bug/1534487/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1534487] Re: cgroup change failed (freezer) when using sudo

2016-01-15 Thread Serge Hallyn
(Firing up a vm to reproduce)

The error message has been fixed in 0.39-2ubuntu4 uploaded today to
xenial.

Can you show your /proc/self/cgroup output?  Mine shows

ubuntu@beret:~$ cat /proc/self/cgroup
11:blkio:/user.slice
10:hugetlb:/
9:memory:/user.slice
8:cpu,cpuacct:/user.slice
7:perf_event:/
6:freezer:/user/ubuntu/0
5:cpuset:/
4:net_cls,net_prio:/user.slice
3:pids:/user.slice/user-1000.slice/session-2.scope
2:devices:/user.slice
1:name=systemd:/user.slice/user-1000.slice/session-2.scope

which is correct.  Systemd gave me a name=systemd cgroup, and libpam-cgm
gave me freezer.


** Changed in: cgmanager (Ubuntu)
   Status: New => Incomplete

** Changed in: cgmanager (Ubuntu)
   Importance: Undecided => High

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1534487

Title:
  cgroup change failed (freezer) when using sudo

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cgmanager/+bug/1534487/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1533839] Re: vms shutting down on libvirt upgrade

2016-01-15 Thread Serge Hallyn
Indeed, the following debdiff to init-system-helpers fixes it for me
(with the exception that I used quilt and it's a native package, so
don't use the debdiff verbatim) :

diff -Nru init-system-helpers-1.24ubuntu2/debian/changelog 
init-system-helpers-1.24ubuntu2x1/debian/changelog
--- init-system-helpers-1.24ubuntu2/debian/changelog2015-11-18 
12:27:05.0 +
+++ init-system-helpers-1.24ubuntu2x1/debian/changelog  2016-01-16 
00:43:32.0 +
@@ -1,3 +1,9 @@
+init-system-helpers (1.24ubuntu2x1) xenial; urgency=medium
+
+  * fix inverted use of -r flag to dh_systemd_start
+
+ -- Serge Hallyn <serge.hal...@ubuntu.com>  Sat, 16 Jan 2016 00:42:51 +
+
 init-system-helpers (1.24ubuntu2) xenial; urgency=medium
 
   * Add Breaks/Replaces on upstart to cover move of
diff -Nru 
init-system-helpers-1.24ubuntu2/patches/fix-systemd-restart-on-upgrade.patch 
init-system-helpers-1.24ubuntu2x1/patches/fix-systemd-restart-on-upgrade.patch
--- 
init-system-helpers-1.24ubuntu2/patches/fix-systemd-restart-on-upgrade.patch
1970-01-01 00:00:00.0 +
+++ 
init-system-helpers-1.24ubuntu2x1/patches/fix-systemd-restart-on-upgrade.patch  
2016-01-16 00:42:50.0 +
@@ -0,0 +1,13 @@
+Index: init-system-helpers-1.24ubuntu2/script/dh_systemd_start
+===
+--- init-system-helpers-1.24ubuntu2.orig/script/dh_systemd_start
 init-system-helpers-1.24ubuntu2/script/dh_systemd_start
+@@ -205,7 +205,7 @@ foreach my $package (@{$dh{DOPACKAGES}})
+ 
+   $sd_autoscript->("postrm", "postrm-systemd-reload-only");
+ 
+-  if ($dh{R_FLAG} || $dh{RESTART_AFTER_UPGRADE}) {
++  if (!$dh{R_FLAG} || $dh{RESTART_AFTER_UPGRADE}) {
+   # stop service only on remove
+   $sd_autoscript->("prerm", "prerm-systemd-restart");
+   } elsif (!$dh{NO_START}) {
diff -Nru init-system-helpers-1.24ubuntu2/patches/series 
init-system-helpers-1.24ubuntu2x1/patches/series
--- init-system-helpers-1.24ubuntu2/patches/series  1970-01-01 
00:00:00.0 +
+++ init-system-helpers-1.24ubuntu2x1/patches/series2016-01-16 
00:42:06.0 +
@@ -0,0 +1 @@
+fix-systemd-restart-on-upgrade.patch


** Changed in: init-system-helpers (Ubuntu)
   Importance: Undecided => High

** Also affects: libvirt (Ubuntu Wily)
   Importance: Undecided
   Status: New

** Also affects: init-system-helpers (Ubuntu Wily)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1533839

Title:
  vms shutting down on libvirt upgrade

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/init-system-helpers/+bug/1533839/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1533839] Re: vms shutting down on libvirt upgrade

2016-01-15 Thread Serge Hallyn
Indeed, the following debdiff to init-system-helpers fixes it for me
(with the exception that I used quilt and it's a native package, so
don't use the debdiff verbatim) :

diff -Nru init-system-helpers-1.24ubuntu2/debian/changelog 
init-system-helpers-1.24ubuntu2x1/debian/changelog
--- init-system-helpers-1.24ubuntu2/debian/changelog2015-11-18 
12:27:05.0 +
+++ init-system-helpers-1.24ubuntu2x1/debian/changelog  2016-01-16 
00:43:32.0 +
@@ -1,3 +1,9 @@
+init-system-helpers (1.24ubuntu2x1) xenial; urgency=medium
+
+  * fix inverted use of -r flag to dh_systemd_start
+
+ -- Serge Hallyn <serge.hal...@ubuntu.com>  Sat, 16 Jan 2016 00:42:51 +
+
 init-system-helpers (1.24ubuntu2) xenial; urgency=medium
 
   * Add Breaks/Replaces on upstart to cover move of
diff -Nru 
init-system-helpers-1.24ubuntu2/patches/fix-systemd-restart-on-upgrade.patch 
init-system-helpers-1.24ubuntu2x1/patches/fix-systemd-restart-on-upgrade.patch
--- 
init-system-helpers-1.24ubuntu2/patches/fix-systemd-restart-on-upgrade.patch
1970-01-01 00:00:00.0 +
+++ 
init-system-helpers-1.24ubuntu2x1/patches/fix-systemd-restart-on-upgrade.patch  
2016-01-16 00:42:50.0 +
@@ -0,0 +1,13 @@
+Index: init-system-helpers-1.24ubuntu2/script/dh_systemd_start
+===
+--- init-system-helpers-1.24ubuntu2.orig/script/dh_systemd_start
 init-system-helpers-1.24ubuntu2/script/dh_systemd_start
+@@ -205,7 +205,7 @@ foreach my $package (@{$dh{DOPACKAGES}})
+ 
+   $sd_autoscript->("postrm", "postrm-systemd-reload-only");
+ 
+-  if ($dh{R_FLAG} || $dh{RESTART_AFTER_UPGRADE}) {
++  if (!$dh{R_FLAG} || $dh{RESTART_AFTER_UPGRADE}) {
+   # stop service only on remove
+   $sd_autoscript->("prerm", "prerm-systemd-restart");
+   } elsif (!$dh{NO_START}) {
diff -Nru init-system-helpers-1.24ubuntu2/patches/series 
init-system-helpers-1.24ubuntu2x1/patches/series
--- init-system-helpers-1.24ubuntu2/patches/series  1970-01-01 
00:00:00.0 +
+++ init-system-helpers-1.24ubuntu2x1/patches/series2016-01-16 
00:42:06.0 +
@@ -0,0 +1 @@
+fix-systemd-restart-on-upgrade.patch


** Changed in: init-system-helpers (Ubuntu)
   Importance: Undecided => High

** Also affects: libvirt (Ubuntu Wily)
   Importance: Undecided
   Status: New

** Also affects: init-system-helpers (Ubuntu Wily)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to init-system-helpers in Ubuntu.
https://bugs.launchpad.net/bugs/1533839

Title:
  vms shutting down on libvirt upgrade

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/init-system-helpers/+bug/1533839/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


Re: [Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-14 Thread Serge Hallyn
> Something I'm still not sure about is what would happen if you made a
> symlink, bind mount, etc. in upperdir with the same name as an unrelated
> file in lowerdir. This is worth checking out.

just tried a symlink and it didn't seem to affect the host directory
(/opt/cisco) which was symlinked to /tmp/upper/cisco in the container to
begin with.

> > It looks like no, since
> > 
> > root@w1:/tmp# mount -t overlay -o 
> > lowerdir=lower,upperdir=upper,workdir=workdir overlay /mnt
> > root@w1:/tmp# ls /mnt
> > cisco
> > root@w1:/tmp# rmdir /mnt/cisco
> > rmdir: failed to remove ‘/mnt/cisco’: Read-only file system
> > root@w1:/tmp# mv /mnt/cisco /mnt/c2
> > mv: cannot move ‘/mnt/cisco’ to ‘/mnt/c2’: Read-only file system
> > 
> > (here w1 is a unpriv container with /hostopt a bind mount of /opt on the
> > host;  cisco a directory both in host's /opt and in /tmp/lowerdir)
> 
> I think I'm missing something here. I don't know why your mount is
> read-only.

Because a directory in workdir is owned by uid -1 (root on the host).

> But even if it wasn't, cisco is in lowerdir and thus should
> never be modified or removed in any case. Removing it in /mnt should (I

Right, but I was trying to use workdir as a vector to make changes to
something in the host's opt.  Not lowerdir.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531747

Title:
  overlay: mkdir fails if directory exists in lowerdir in a user
  namespace

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1531747/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 1533839] Re: vms shutting down on libvirt upgrade

2016-01-13 Thread Serge Hallyn
Thanks for submitting this bug.

Reproduce here.


** Changed in: libvirt (Ubuntu)
   Importance: Undecided => High

** Changed in: libvirt (Ubuntu)
   Importance: High => Critical

** Changed in: libvirt (Ubuntu)
   Status: New => Triaged

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1533839

Title:
  vms shutting down on libvirt upgrade

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1533839/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1533833] Re: unprivileged lxc containers won't start

2016-01-13 Thread Serge Hallyn
systemd should be updated to know about the pids cgroup


** Also affects: lxc (Ubuntu Wily)
   Importance: Undecided
   Status: New

** Also affects: systemd (Ubuntu Wily)
   Importance: Undecided
   Status: New

** Changed in: lxc (Ubuntu)
   Status: Confirmed => Fix Released

** Changed in: systemd (Ubuntu)
   Status: New => Fix Released

** Changed in: lxc (Ubuntu Wily)
   Importance: Undecided => Medium

** Changed in: systemd (Ubuntu)
   Importance: Undecided => Medium

** Changed in: systemd (Ubuntu Wily)
   Importance: Undecided => Medium

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to lxc in Ubuntu.
https://bugs.launchpad.net/bugs/1533833

Title:
  unprivileged lxc containers won't start

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1533833/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1533833] Re: unprivileged lxc containers won't start

2016-01-13 Thread Serge Hallyn
(Note this should be properly handled in xenial, but needs fixing in
wily)

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to lxc in Ubuntu.
https://bugs.launchpad.net/bugs/1533833

Title:
  unprivileged lxc containers won't start

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1533833/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1533839] Re: vms shutting down on libvirt upgrade

2016-01-13 Thread Serge Hallyn
prior versions are doing it for me to.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1533839

Title:
  vms shutting down on libvirt upgrade

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1533839/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1533839] Re: vms shutting down on libvirt upgrade

2016-01-13 Thread Serge Hallyn
libvirt-bin.service has

Before=libvirt-guests.service

and libvirt-guests.service has

After=network.target libvirt-bin.service time-sync.target systemd-
machined.target

Does that sabotage the --no-restart-on-upgrade?

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1533839

Title:
  vms shutting down on libvirt upgrade

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1533839/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1533839] Re: vms shutting down on libvirt upgrade

2016-01-13 Thread Serge Hallyn
lv2 login: systemd-journald.service: Got notification message from PID 318 
(WATCHDOG=1)
Accepted new private connection.
Got message type=method_call sender=n/a destination=org.freedesktop.systemd1 
object=/org/freedesktop/systemd1 interface=org.freedesktop.systemd1.Manager 
member=StopUnit cookie=1 reply_cookie=0 error=n/a
libvirt-guests.service: Trying to enqueue job 
libvirt-guests.service/stop/replace
libvirt-guests.service: Installed new job libvirt-guests.service/stop as 343
libvirt-guests.service: Enqueued job libvirt-guests.service/stop as 343
Sent message type=method_return sender=n/a destination=n/a object=n/a 
interface=n/a member=n/a cookie=1 reply_cookie=1 error=n/a
Sent message type=signal sender=n/a destination=n/a 
object=/org/freedesktop/systemd1 interface=org.freedesktop.systemd1.Manager 
member=JobNew cookie=2 reply_cookie=0 error=n/a
Sent message type=signal sender=n/a destination=n/a 
object=/org/freedesktop/systemd1 interface=org.freedesktop.systemd1.Manager 
member=JobNew cookie=249 reply_cookie=0 error=n/a
Got message type=method_call sender=n/a destination=org.freedesktop.systemd1 
object=/org/freedesktop/systemd1 interface=org.freedesktop.systemd1.Manager 
member=GetUnit cookie=2 reply_cookie=0 error=n/a
Sent message type=method_return sender=n/a destination=n/a object=n/a 
interface=n/a member=n/a cookie=3 reply_cookie=2 error=n/a
libvirt-guests.service: About to execute: /usr/lib/libvirt/libvirt-stop-guests
libvirt-guests.service: Forked /usr/lib/libvirt/libvirt-stop-guests as 1264
libvirt-guests.service: Changed exited -> stop[   88.071982] 
libvirt-stop-guests[1264]: libvirt-guests.service: Executing: 
/usr/lib/libvirt/libvirt-stop-guests

Sent message type=signal sender=n/a destination=n/a 
object=/org/freedesktop/systemd1/unit/libvirt_2dguests_2eservice 
interface=org.freedesktop.DBus.Properties member=PropertiesChanged cookie=4 
reply_cookie=0 error=n/a
Sent message type=signal sender=n/a destination=n/a 
object=/org/freedesktop/systemd1/unit/libvirt_2dguests_2eservice 
interface=org.freedesktop.DBus.Properties member=PropertiesChanged cookie=5 
reply_cookie=0 error=n/a
Sent message type=signal sender=n/a destination=n/a 
object=/org/freedesktop/systemd1/unit/libvirt_2dguests_2eservice 
interface=org.freedesktop.DBus.Properties member=PropertiesChanged cookie=250 
reply_cookie=0 error=n/a
Sent message type=signal sender=n/a destination=n/a 
object=/org/freedesktop/systemd1/unit/libvirt_2dguests_2eservice 
interface=org.freedesktop.DBus.Properties member=PropertiesChanged cookie=251 
reply_cookie=0 error=n/a
Sent message type=signal sender=n/a destination=n/a 
object=/org/freedesktop/systemd1/job/343 
interface=org.freedesktop.DBus.Properties member=PropertiesChanged cookie=6 
reply_cookie=0 error=n/a
Sent message type=signal sender=n/a destination=n/a 
object=/org/freedesktop/systemd1/job/343 
interface=org.freedesktop.DBus.Properties member=PropertiesChanged cookie=252 
reply_cookie=0 error=n/a
systemd-logind.service: Got notification message from PID 721 (WATCHDOG=1)
Got message type=method_call sender=n/a destination=org.freedesktop.systemd1 
object=/org/freedesktop/systemd1/unit/libvirt_2dguests_2eservice 
interface=org.freedesktop.DBus.Properties member=Get cookie=3 reply_cookie=0 
error=n/a
Sent message type=method_return sender=n/a destination=n/a object=n/a 
interface=n/a member=n/a cookie=7 reply_cookie=3 error=n/a
systemd-timesyncd.service: Got notification message from PID 457 (WATCHDOG=1)


but debian/rules installs libvirt-guests as --no-restart-on-upgrade.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1533839

Title:
  vms shutting down on libvirt upgrade

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1533839/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1533833] Re: unprivileged lxc containers won't start

2016-01-13 Thread Serge Hallyn
systemd should be updated to know about the pids cgroup


** Also affects: lxc (Ubuntu Wily)
   Importance: Undecided
   Status: New

** Also affects: systemd (Ubuntu Wily)
   Importance: Undecided
   Status: New

** Changed in: lxc (Ubuntu)
   Status: Confirmed => Fix Released

** Changed in: systemd (Ubuntu)
   Status: New => Fix Released

** Changed in: lxc (Ubuntu Wily)
   Importance: Undecided => Medium

** Changed in: systemd (Ubuntu)
   Importance: Undecided => Medium

** Changed in: systemd (Ubuntu Wily)
   Importance: Undecided => Medium

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1533833

Title:
  unprivileged lxc containers won't start

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1533833/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1533833] Re: unprivileged lxc containers won't start

2016-01-13 Thread Serge Hallyn
(Note this should be properly handled in xenial, but needs fixing in
wily)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1533833

Title:
  unprivileged lxc containers won't start

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1533833/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1533833] Re: unprivileged lxc containers won't start

2016-01-13 Thread Serge Hallyn
You're using a newer kernel which provides the 'pids' cgroup.  Systemd doesn't
know about that one and so doesn't create a cgroup for you that you own.  Lxc
in turn (in wily) doesn't yet know how to handle that.

You can work around this several ways.  The simplest is to do

sudo cgm create pids user
sudo cgm chown pids user $(id -u) $(id -g)
cgm movepid pids user $$

before you start the container.


** Also affects: systemd (Ubuntu)
   Importance: Undecided
   Status: New

** Changed in: lxc (Ubuntu)
   Importance: Undecided => Medium

** Changed in: lxc (Ubuntu)
   Status: New => Confirmed

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1533833

Title:
  unprivileged lxc containers won't start

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1533833/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1533833] Re: unprivileged lxc containers won't start

2016-01-13 Thread Serge Hallyn
You're using a newer kernel which provides the 'pids' cgroup.  Systemd doesn't
know about that one and so doesn't create a cgroup for you that you own.  Lxc
in turn (in wily) doesn't yet know how to handle that.

You can work around this several ways.  The simplest is to do

sudo cgm create pids user
sudo cgm chown pids user $(id -u) $(id -g)
cgm movepid pids user $$

before you start the container.


** Also affects: systemd (Ubuntu)
   Importance: Undecided
   Status: New

** Changed in: lxc (Ubuntu)
   Importance: Undecided => Medium

** Changed in: lxc (Ubuntu)
   Status: New => Confirmed

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to lxc in Ubuntu.
https://bugs.launchpad.net/bugs/1533833

Title:
  unprivileged lxc containers won't start

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1533833/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-13 Thread Serge Hallyn
Does it require the workdir to be empty?

I.e. is there a way (symlink, bind mount, something else) that a user
could use a dir they own which has a child which they don't own?

It looks like no, since

root@w1:/tmp# mount -t overlay -o lowerdir=lower,upperdir=upper,workdir=workdir 
overlay /mnt
root@w1:/tmp# ls /mnt
cisco
root@w1:/tmp# rmdir /mnt/cisco
rmdir: failed to remove ‘/mnt/cisco’: Read-only file system
root@w1:/tmp# mv /mnt/cisco /mnt/c2
mv: cannot move ‘/mnt/cisco’ to ‘/mnt/c2’: Read-only file system

(here w1 is a unpriv container with /hostopt a bind mount of /opt on the
host;  cisco a directory both in host's /opt and in /tmp/lowerdir)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531747

Title:
  overlay: mkdir fails if directory exists in lowerdir in a user
  namespace

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1531747/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 1531833] Re: package libvirt-bin 1.2.16-2ubuntu11.15.10.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2016-01-12 Thread Serge Hallyn
Thanks - it looks like libvirt is upset about something relating to
locales.  What do

dpkg -l | grep language-pack

env | grep LANG

sudo env | grep LANG

show?

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531833

Title:
  package libvirt-bin 1.2.16-2ubuntu11.15.10.1 failed to
  install/upgrade: subprocess installed post-installation script
  returned error exit status 1

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1531833/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1483071] Re: Error creating new VM with OVMF

2016-01-12 Thread Serge Hallyn
** Also affects: libvirt (Ubuntu Trusty)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1483071

Title:
  Error creating new VM with OVMF

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1483071/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1483071] Re: Error creating new VM with OVMF

2016-01-12 Thread Serge Hallyn
** Also affects: libvirt (Ubuntu Trusty)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to libvirt in Ubuntu.
https://bugs.launchpad.net/bugs/1483071

Title:
  Error creating new VM with OVMF

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1483071/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


Re: [Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-12 Thread Serge Hallyn
Quoting Seth Forshee (seth.forshee...@canonical.com):
> I don't know why #2 is that much grosser than what's there now. It's

I didn't mean gross as in eeuw, I meant not fine-grained enough.

Because the capability will apply to inode permissions checks,
and we only want it to be used for the check authorizing the
writing of the trusted.overlay.opaque xattr.

> already only taking the cap for setting the xattr, and taking
> CAP_SYS_ADMIN in init_user_ns seems to be what it's really wanting to do

Maybe - that's what I'm not sure about.  As you said earlier, in the
upstream code only an admin can do the actual mount.  The fact that an
unpriv user can create the mount may change assumptions about the
underlying fs's.

> there. The difference now though is that before that capability would
> have been required to do the mount and now it isn't.

Right.

> If we were to use ns_capable, which namespace do we use?

I don't know.  We're almost better off shipping a new version of
vfs_xattr() which is only for use by kernel writers.

If we had your patch we could maybe check against the sb->user_ns?

> current_user_ns? Then that check becomes worthless because any user can
> make a new namespace to bypass it. If we had the s_user_ns patches it

Quit saying in the next paragraph what I say in reply to the previous!

> might make sense to use that, but that probably doesn't solve the
> problem anyway since the lower mount was probably mounted in
> init_user_ns.

Good point, hadn't thought of that.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531747

Title:
  overlay: mkdir fails if directory exists in lowerdir in a user
  namespace

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1531747/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


Re: [Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-12 Thread Serge Hallyn
in ovl_clear_empty(), the opaque bit is set on the dir in workingdir

in ovl_create_over_whiteout() (the case we're currently looking at) it is
also being set in the working dir.

in ovl_rename2(), it is set in two places, on the upper dentries for
both the old and new.

So it is never set on the lowerdir, at least.

I'm still looking, but it may be safe to say that all needed inode
checks are already done before we call ovl_set_opaque() so that we
can indeed just use prepare_kernel_cred(NULL) instead of prepare_cred().

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531747

Title:
  overlay: mkdir fails if directory exists in lowerdir in a user
  namespace

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1531747/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1531833] Re: package libvirt-bin 1.2.16-2ubuntu11.15.10.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2016-01-12 Thread Serge Hallyn
Anything more from

sudo journalctl -u libvirt-bin

How about

sudo strace -f /usr/sbin/libvirtd -v

for pete's sake.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531833

Title:
  package libvirt-bin 1.2.16-2ubuntu11.15.10.1 failed to
  install/upgrade: subprocess installed post-installation script
  returned error exit status 1

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1531833/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1483071] Re: Error creating new VM with OVMF

2016-01-11 Thread Serge Hallyn
** Description changed:

+ =
+ SRU Justification
+ Impact: cannot start VMs with UEFI
+ Test case:
+ Regression potential: virt-aa-helper is modified to add the nvram files to 
the allowed list, there should be no regressions.
+ =
+ 
  When I'm trying to create new VM through virt-manager with OVMF firmware
  instead of BIOS an error appears:
  
  Failed to complete an installation: «internal error: cannot load
  AppArmor profile «libvirt-0dc7297d-a474-47ed-88b0-026f1d6ae2a4»»
  
  Traceback (most recent call last):
    File "/usr/share/virt-manager/virtManager/asyncjob.py", line 89, in 
cb_wrapper
  callback(asyncjob, *args, **kwargs)
    File "/usr/share/virt-manager/virtManager/create.py", line 1873, in 
do_install
  guest.start_install(meter=meter)
    File "/usr/share/virt-manager/virtinst/guest.py", line 414, in start_install
  noboot)
    File "/usr/share/virt-manager/virtinst/guest.py", line 478, in _create_guest
  dom = self.conn.createLinux(start_xml or final_xml, 0)
    File "/usr/lib/python2.7/dist-packages/libvirt.py", line 3497, in 
createLinux
  if ret is None:raise libvirtError('virDomainCreateLinux() failed', 
conn=self)
  libvirtError: internal error: cannot load AppArmor profile 
«libvirt-0dc7297d-a474-47ed-88b0-026f1d6ae2a4»
  
  There is an appropriate lines at the end of /etc/libvirt/qemu.conf:
  
  nvram = [ 
"/usr/share/OVMF/OVMF_CODE-pure-efi.fd:/usr/share/OVMF/OVMF_VARS-pure-efi.fd",
    
"/usr/share/OVMF/OVMF_CODE-with-csm.fd:/usr/share/OVMF/OVMF_VARS-with-csm.fd" ]
  
  Surely those files are present in /usr/share/OVMF/.
  
  Kbuntu 15.10 Wily
  Linux 4.2RC6 x86_64
  virt-manager 1.2.1
  libvirt 1.2.16
  qemu 2.3

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1483071

Title:
  Error creating new VM with OVMF

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1483071/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-11 Thread Serge Hallyn
#2 is probably a bit too gross - we really only need the cap for the setting
of the OVL_XATTR_OPAQUE xattr in ovl_set_opaque.  So we could simply override
creds again there.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531747

Title:
  overlay: mkdir fails if directory exists in lowerdir in a user
  namespace

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1531747/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1529319] Re: VM constantly tries to access /run/shm/lttng-ust-wait-5

2016-01-11 Thread Serge Hallyn
@mnaser,

We need a simple testcase in the Description for SRU.  do you know the
minimal set of things needed to make this happen?  Are you running an
unmodified ceph, or ceph from a particular ppa which re-enables lttng?


** Description changed:

+ =
+ SRU Justification
+ Impact: log is flooded by apparmor access denials
+ Fix: silence the denials using an explicity 'deny' rule in apparmor policy
+ Test case: XXX
+ Regression potential: we already had an explicit deny rule for this, but the 
path at which shm is mounted has changed.
+ =
+ 
  This seems like a regression of the following bug
  
  https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1432644
  
  It seems that the path is now /run/shm/lttng-ust-wait-5 which results in
  a flood of the following
  
  Dec 26 04:47:44 compute-4-ca-ymq-2 kernel: [1751079.003742] audit:
  type=1400 audit(1451105264.249:80133): apparmor="DENIED"
  operation="open" profile="libvirt-5923eded-8cbd-4257-a4c6-a8f4c2cf06cb"
  name="/run/shm/lttng-ust-wait-5" pid=5018 comm="qemu-system-x86"
  requested_mask="r" denied_mask="r" fsuid=108 ouid=107
  
  The fix would be similar

** Also affects: libvirt (Ubuntu Wily)
   Importance: Undecided
   Status: New

** Changed in: libvirt (Ubuntu Wily)
   Importance: Undecided => High

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1529319

Title:
  VM constantly tries to access /run/shm/lttng-ust-wait-5

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1529319/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1529319] Re: VM constantly tries to access /run/shm/lttng-ust-wait-5

2016-01-11 Thread Serge Hallyn
@mnaser,

We need a simple testcase in the Description for SRU.  do you know the
minimal set of things needed to make this happen?  Are you running an
unmodified ceph, or ceph from a particular ppa which re-enables lttng?


** Description changed:

+ =
+ SRU Justification
+ Impact: log is flooded by apparmor access denials
+ Fix: silence the denials using an explicity 'deny' rule in apparmor policy
+ Test case: XXX
+ Regression potential: we already had an explicit deny rule for this, but the 
path at which shm is mounted has changed.
+ =
+ 
  This seems like a regression of the following bug
  
  https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1432644
  
  It seems that the path is now /run/shm/lttng-ust-wait-5 which results in
  a flood of the following
  
  Dec 26 04:47:44 compute-4-ca-ymq-2 kernel: [1751079.003742] audit:
  type=1400 audit(1451105264.249:80133): apparmor="DENIED"
  operation="open" profile="libvirt-5923eded-8cbd-4257-a4c6-a8f4c2cf06cb"
  name="/run/shm/lttng-ust-wait-5" pid=5018 comm="qemu-system-x86"
  requested_mask="r" denied_mask="r" fsuid=108 ouid=107
  
  The fix would be similar

** Also affects: libvirt (Ubuntu Wily)
   Importance: Undecided
   Status: New

** Changed in: libvirt (Ubuntu Wily)
   Importance: Undecided => High

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to libvirt in Ubuntu.
https://bugs.launchpad.net/bugs/1529319

Title:
  VM constantly tries to access /run/shm/lttng-ust-wait-5

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1529319/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1517539] Re: Libvirt KVM can not create snapshot (with qemu-guest-agent)

2016-01-11 Thread Serge Hallyn
** Description changed:

+ ===
+ SRU Justification
+ Impact: snapshotting vms fails
+ Test case: install qemu-ga and use the snapshot-create-as command below
+ Regression potential: We broaden the types of sockets which virt-aa-helper 
allows to include vhostuser.  There should be no regressions.
+ ===
+ 
  When I try to create a snapshot of a running virtual machine using the
  following command:
  
  virsh snapshot-create-as --quiesce --domain dns sn1 --diskspec
  hda,file=/home/alank/vm/dns-sn1.qcow2 --disk-only --atomic
  
  I receive the following error message: "error: internal error: cannot
  update AppArmor profile 'libvirt-ffa7fd3a-e521-46e4-83b0-b982fe75773d'"
  
  I'm not sure if this is a libvirt issue or an AppArmor issue.
  
  ProblemType: Bug
  DistroRelease: Ubuntu 15.10
  Package: libvirt-bin 1.2.16-2ubuntu11 [modified: 
usr/lib/libvirt/libvirt-stop-guests]
  ProcVersionSignature: Ubuntu 4.2.0-18.22-generic 4.2.3
  Uname: Linux 4.2.0-18-generic x86_64
  ApportVersion: 2.19.1-0ubuntu5
  Architecture: amd64
  Date: Wed Nov 18 08:11:26 2015
  InstallationDate: Installed on 2015-11-09 (8 days ago)
  InstallationMedia: Xubuntu 15.10 "Wily Werewolf" - Release amd64 (20151021)
  ProcEnviron:
-  TERM=xterm-256color
-  PATH=(custom, no user)
-  XDG_RUNTIME_DIR=
-  LANG=en_US.UTF-8
-  SHELL=/bin/bash
+  TERM=xterm-256color
+  PATH=(custom, no user)
+  XDG_RUNTIME_DIR=
+  LANG=en_US.UTF-8
+  SHELL=/bin/bash
  SourcePackage: libvirt
  UpgradeStatus: No upgrade log present (probably fresh install)
  modified.conffile..etc.init.libvirt.bin.conf: [modified]
  modified.conffile..etc.libvirt.qemu.conf: [inaccessible: [Errno 13] 
Permission denied: '/etc/libvirt/qemu.conf']
  modified.conffile..etc.libvirt.qemu.networks.default.xml: [inaccessible: 
[Errno 13] Permission denied: '/etc/libvirt/qemu/networks/default.xml']
  mtime.conffile..etc.init.libvirt.bin.conf: 2015-11-11T07:35:24.679827

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1517539

Title:
  Libvirt KVM can not create snapshot (with qemu-guest-agent)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1517539/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 1524737] Re: systemd presents hugetblfs at /dev/hugepages

2016-01-11 Thread Serge Hallyn
** Description changed:

+ ==
+ SRU Justification
+ Impact: libvirt unable to grant access to hugepages
+ Fix: add an apparmor rule to allow libvirt to access hugepages at the path 
which systemd uses
+ Test case: boot a vm with hugepages enabled.
+ Regression potential:  We already have an allow rule for the old hugepages 
mount path, we are only allowing access to the path which systemd uses.  So 
there should be no regressions.
+ ==
+ 
  If a system is configured to allocate hugepages on boot, systemd will
  automatically present a hugetblfs at /dev/hugepages
  
  This is not compatible with the current apparmor profile which expects
  presentation at /var/run/hugepages.
  
  ProblemType: Bug
  DistroRelease: Ubuntu 16.04
  Package: libvirt-bin 1.2.21-2ubuntu1
  ProcVersionSignature: Ubuntu 4.3.0-2.11-generic 4.3.0
  Uname: Linux 4.3.0-2-generic x86_64
  NonfreeKernelModules: zfs zunicode zcommon znvpair zavl
  ApportVersion: 2.19.2-0ubuntu9
  Architecture: amd64
  CurrentDesktop: Unity
  Date: Thu Dec 10 11:16:28 2015
  EcryptfsInUse: Yes
  InstallationDate: Installed on 2014-11-25 (379 days ago)
  InstallationMedia: Ubuntu 15.04 "Vivid Vervet" - Alpha amd64 (20141124)
  SourcePackage: libvirt
  UpgradeStatus: Upgraded to xenial on 2015-11-02 (38 days ago)
  modified.conffile..etc.libvirt.qemu.conf: [inaccessible: [Errno 13] 
Permission denied: '/etc/libvirt/qemu.conf']
  modified.conffile..etc.libvirt.qemu.networks.default.xml: [inaccessible: 
[Errno 13] Permission denied: '/etc/libvirt/qemu/networks/default.xml']

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1524737

Title:
  systemd presents hugetblfs at /dev/hugepages

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1524737/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1531833] Re: package libvirt-bin 1.2.16-2ubuntu11.15.10.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2016-01-11 Thread Serge Hallyn
Ok, I don't know why that won't give us the error output we're looking
for.

What happens when you just do

sudo /usr/sbin/libvirtd

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531833

Title:
  package libvirt-bin 1.2.16-2ubuntu11.15.10.1 failed to
  install/upgrade: subprocess installed post-installation script
  returned error exit status 1

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1531833/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-11 Thread Serge Hallyn
hat may not be ok for the ovl_rename2 case.

What we want is for inode permissions to be checked, but only the
bit in xattr_permission() checking for trusted.* to accept ns_capable.

We could special-case that in xattr_permission(), but that's not
particularly nice.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531747

Title:
  overlay: mkdir fails if directory exists in lowerdir in a user
  namespace

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1531747/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


Re: [Bug 1531833] Re: package libvirt-bin 1.2.16-2ubuntu11.15.10.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2016-01-11 Thread Serge Hallyn
Do you get more if you add '-v' ?

Also try setting

log_level = 1

in /etc/libvirt/libvirtd.conf

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531833

Title:
  package libvirt-bin 1.2.16-2ubuntu11.15.10.1 failed to
  install/upgrade: subprocess installed post-installation script
  returned error exit status 1

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1531833/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1532314] Re: Buffer overflow in cgmanager

2016-01-11 Thread Serge Hallyn
Can you show 'ls /proc/$(pidof cgmanager)/fd' at a few times?

This is something we've run into with normal operation in go, but since
cgmanager is not threaded it should not have so many open fds.

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to lxc in Ubuntu.
https://bugs.launchpad.net/bugs/1532314

Title:
  Buffer overflow in cgmanager

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1532314/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1532314] Re: Buffer overflow in cgmanager

2016-01-11 Thread Serge Hallyn
Can you show 'ls /proc/$(pidof cgmanager)/fd' at a few times?

This is something we've run into with normal operation in go, but since
cgmanager is not threaded it should not have so many open fds.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1532314

Title:
  Buffer overflow in cgmanager

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1532314/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


Re: [Bug 1532125] Re: lxc-clone: Use btrfs backing store if original container does

2016-01-11 Thread Serge Hallyn
Ok, so this is working as expected.  But I guess there is really zero
advantage to having a copy-clone on btrfs, so I think it's worth
changing.

 status confirmed
 importance medium


** Changed in: lxc (Ubuntu)
   Importance: Undecided => Medium

** Changed in: lxc (Ubuntu)
   Status: New => Confirmed

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1532125

Title:
  lxc-clone: Use btrfs backing store if original container does

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1532125/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


Re: [Bug 1532125] Re: lxc-clone: Use btrfs backing store if original container does

2016-01-11 Thread Serge Hallyn
Ok, so this is working as expected.  But I guess there is really zero
advantage to having a copy-clone on btrfs, so I think it's worth
changing.

 status confirmed
 importance medium


** Changed in: lxc (Ubuntu)
   Importance: Undecided => Medium

** Changed in: lxc (Ubuntu)
   Status: New => Confirmed

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to lxc in Ubuntu.
https://bugs.launchpad.net/bugs/1532125

Title:
  lxc-clone: Use btrfs backing store if original container does

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1532125/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1524737] Re: systemd presents hugetblfs at /dev/hugepages

2016-01-11 Thread Serge Hallyn
** Also affects: libvirt (Ubuntu Wily)
   Importance: Undecided
   Status: New

** Also affects: libvirt (Ubuntu Vivid)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to libvirt in Ubuntu.
https://bugs.launchpad.net/bugs/1524737

Title:
  systemd presents hugetblfs at /dev/hugepages

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1524737/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1532007] Re: libvirt's apparmor policy prevents starting domain with hugepage-backed memory store

2016-01-11 Thread Serge Hallyn
*** This bug is a duplicate of bug 1524737 ***
https://bugs.launchpad.net/bugs/1524737

** This bug has been marked a duplicate of bug 1524737
   systemd presents hugetblfs at /dev/hugepages

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1532007

Title:
  libvirt's apparmor policy prevents starting domain with hugepage-
  backed memory store

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1532007/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1529319] Re: VM constantly tries to access /run/shm/lttng-ust-wait-5

2016-01-11 Thread Serge Hallyn
Hi,

Looking through the history of bug 1432644, AFAICS it was never "fixed",
it was worked around.

Ceph was built without support for lttng.  The libvirt patch was only to
*silence* the denial for attempted access to lttng, not to grant the
access.

Are you asking only to update the explit denial to keep your logs
cleaner?  If so that's trivial as you say.

@sage-newdream, @jamespage, @jdstrand - is there any news on properly
supporting lttng support built into ceph for libvirt?

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1529319

Title:
  VM constantly tries to access /run/shm/lttng-ust-wait-5

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1529319/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1531564] Re: missing apparmor rule to read /sys/module/vhost/parameters/max_mem_regions

2016-01-11 Thread Serge Hallyn
Thanks for submitting this bug.  The fix is being pushed in the next
version.


** Changed in: libvirt (Ubuntu)
   Importance: Undecided => Medium

** Changed in: libvirt (Ubuntu)
   Status: New => In Progress

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531564

Title:
  missing apparmor rule to read
  /sys/module/vhost/parameters/max_mem_regions

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1531564/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1531833] Re: package libvirt-bin 1.2.16-2ubuntu11.15.10.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2016-01-11 Thread Serge Hallyn
** Changed in: libvirt (Ubuntu)
   Importance: Undecided => High

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531833

Title:
  package libvirt-bin 1.2.16-2ubuntu11.15.10.1 failed to
  install/upgrade: subprocess installed post-installation script
  returned error exit status 1

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1531833/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1517539] Re: Libvirt KVM can not create snapshot (with qemu-guest-agent)

2016-01-11 Thread Serge Hallyn
Thanks.

This patch is in xenial's source.  I'll mark this to be SRUd to wily.


** Also affects: libvirt (Ubuntu Wily)
   Importance: Undecided
   Status: New

** Changed in: libvirt (Ubuntu)
   Status: Confirmed => Fix Released

** Changed in: libvirt (Ubuntu Wily)
   Importance: Undecided => High

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1517539

Title:
  Libvirt KVM can not create snapshot (with qemu-guest-agent)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1517539/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1517539] Re: Libvirt KVM can not create snapshot (with qemu-guest-agent)

2016-01-11 Thread Serge Hallyn
Thanks.

This patch is in xenial's source.  I'll mark this to be SRUd to wily.


** Also affects: libvirt (Ubuntu Wily)
   Importance: Undecided
   Status: New

** Changed in: libvirt (Ubuntu)
   Status: Confirmed => Fix Released

** Changed in: libvirt (Ubuntu Wily)
   Importance: Undecided => High

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to libvirt in Ubuntu.
https://bugs.launchpad.net/bugs/1517539

Title:
  Libvirt KVM can not create snapshot (with qemu-guest-agent)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1517539/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1483071] Re: Error creating new VM with OVMF

2016-01-11 Thread Serge Hallyn
The patch to fix this should be 91fdcefa7f145c1c39acc8e9a44fbfbf11568e54
upstream.  It is in the xenial package.  So I'm marking this fix
released and SRUing for wily.

Do we need this SRU'd to trusty too?


** Also affects: libvirt (Ubuntu Wily)
   Importance: Undecided
   Status: New

** Changed in: libvirt (Ubuntu Wily)
   Importance: Undecided => High

** Changed in: libvirt (Ubuntu)
   Status: Confirmed => Fix Released

** Changed in: libvirt (Ubuntu)
   Importance: Medium => High

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to libvirt in Ubuntu.
https://bugs.launchpad.net/bugs/1483071

Title:
  Error creating new VM with OVMF

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1483071/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


Re: [Bug 1532314] Re: Buffer overflow in cgmanager

2016-01-11 Thread Serge Hallyn
What were the fds?  (ls -l)

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1532314

Title:
  Buffer overflow in cgmanager

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1532314/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


Re: [Bug 1532314] Re: Buffer overflow in cgmanager

2016-01-11 Thread Serge Hallyn
What were the fds?  (ls -l)

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to lxc in Ubuntu.
https://bugs.launchpad.net/bugs/1532314

Title:
  Buffer overflow in cgmanager

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1532314/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1483071] Re: Error creating new VM with OVMF

2016-01-11 Thread Serge Hallyn
The patch to fix this should be 91fdcefa7f145c1c39acc8e9a44fbfbf11568e54
upstream.  It is in the xenial package.  So I'm marking this fix
released and SRUing for wily.

Do we need this SRU'd to trusty too?


** Also affects: libvirt (Ubuntu Wily)
   Importance: Undecided
   Status: New

** Changed in: libvirt (Ubuntu Wily)
   Importance: Undecided => High

** Changed in: libvirt (Ubuntu)
   Status: Confirmed => Fix Released

** Changed in: libvirt (Ubuntu)
   Importance: Medium => High

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1483071

Title:
  Error creating new VM with OVMF

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1483071/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1532007] Re: libvirt's apparmor policy prevents starting domain with hugepage-backed memory store

2016-01-11 Thread Serge Hallyn
*** This bug is a duplicate of bug 1524737 ***
https://bugs.launchpad.net/bugs/1524737

** This bug has been marked a duplicate of bug 1524737
   systemd presents hugetblfs at /dev/hugepages

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to libvirt in Ubuntu.
https://bugs.launchpad.net/bugs/1532007

Title:
  libvirt's apparmor policy prevents starting domain with hugepage-
  backed memory store

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1532007/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1524737] Re: systemd presents hugetblfs at /dev/hugepages

2016-01-11 Thread Serge Hallyn
** Also affects: libvirt (Ubuntu Wily)
   Importance: Undecided
   Status: New

** Also affects: libvirt (Ubuntu Vivid)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1524737

Title:
  systemd presents hugetblfs at /dev/hugepages

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1524737/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1393842] Re: libvirt does not grant qemu-guest-agent channel perms

2016-01-11 Thread Serge Hallyn
@rahul

ping?

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1393842

Title:
  libvirt does not grant qemu-guest-agent channel perms

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1393842/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1531833] Re: package libvirt-bin 1.2.16-2ubuntu11.15.10.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2016-01-11 Thread Serge Hallyn
Hi,

could you please show the output of both:

sudo journalctl -xe

and

sudo systemctl status libvirt-bin.service -l

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531833

Title:
  package libvirt-bin 1.2.16-2ubuntu11.15.10.1 failed to
  install/upgrade: subprocess installed post-installation script
  returned error exit status 1

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1531833/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1529319] Re: VM constantly tries to access /run/shm/lttng-ust-wait-5

2016-01-11 Thread Serge Hallyn
Thanks - I'll push that fix to xenial and SRU to wily.

Where else do you need it?


** Changed in: libvirt (Ubuntu)
   Importance: Undecided => High

** Changed in: libvirt (Ubuntu)
   Status: New => In Progress

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1529319

Title:
  VM constantly tries to access /run/shm/lttng-ust-wait-5

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1529319/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


Re: [Bug 1532125] [NEW] lxc-clone: Use btrfs backing store if original container does

2016-01-08 Thread Serge Hallyn
If you do

lxc-clone -s -o adt-xenial -n x1

does that snapshot the way you want?

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1532125

Title:
  lxc-clone: Use btrfs backing store if original container does

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1532125/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


Re: [Bug 1532125] [NEW] lxc-clone: Use btrfs backing store if original container does

2016-01-08 Thread Serge Hallyn
If you do

lxc-clone -s -o adt-xenial -n x1

does that snapshot the way you want?

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to lxc in Ubuntu.
https://bugs.launchpad.net/bugs/1532125

Title:
  lxc-clone: Use btrfs backing store if original container does

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1532125/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Blueprint servercloud-x-server-core] General server work for Xenial

2016-01-08 Thread Serge Hallyn
Blueprint changed by Serge Hallyn:

Work items changed:
  Work items for ubuntu-15.11:
- [serge-hallyn] etckeeper: TODO
+ [serge-hallyn] etckeeper: DONE
  [paelzer] NIS merge: DONE
  
  Work items for ubuntu-15.12:
  [raharper] : tgt merge (bug 1524982): DONE
  [racb] nagios-plugins/monitoring-plugins merge and cleanup: DONE
  [kick-d] exim4 merge: DONE
  
  Work items for ubuntu-16.01:
  [raharper] strongswan merge and cleanup (=4days): INPROGRESS
  [nacc] logwatch merge and cleanup: INPROGRESS
  [smoser] openiscsi merge: TODO
  [kick-d] amavisd-new merge: INPROGRESS
  [kick-d] freeipmi merge and cleanup (=3days): INPROGRESS
  
  Work items:
  [smoser] systemd-boot tag ~ubuntu-server package review and fixes: TODO
  puppet merge and cleanup: TODO
  [paelzer] DPDK MIR: INPROGRESS
  [paelzer] DPDK upstream work: TODO
  [racb] MySQL cleanup and move to 5.7 (=14days): TODO
  NTP merge, cleanup and PPS support: TODO
  Tomcat updates and cleanup (=14days): TODO
  mail-stack-delivery deprecation plan: TODO
  [tdaitx] squid3 merge (=4days): INPROGRESS
  dovecot merge (doko: done in wily, update to 2.2.2x would be good): TODO
  [louis-bouchard] nut merge: INPROGRESS
  [arges] libvirt merge (bug 1519433) : INPROGRESS
  [serge-hallyn] enable numa in qemu (=2days): TODO
  unbound merge: TODO
  [nacc] Consider php7.0 for Xenial: INPROGRESS
  HTTP/2 related work (=5days): TODO

-- 
General server work for Xenial
https://blueprints.launchpad.net/ubuntu/+spec/servercloud-x-server-core

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1532314] Re: Buffer overflow in cgmanager

2016-01-08 Thread Serge Hallyn
Hm, sadly the trace isn't very informative:

Core was generated by `/sbin/cgmanager -m name=systemd'.
Program terminated with signal SIGABRT, Aborted.
#0  0x7fade2d7a267 in __GI_raise (sig=sig@entry=6) at 
../sysdeps/unix/sysv/linux/raise.c:55
55  ../sysdeps/unix/sysv/linux/raise.c: No such file or directory.
(gdb) where
#0  0x7fade2d7a267 in __GI_raise (sig=sig@entry=6) at 
../sysdeps/unix/sysv/linux/raise.c:55
#1  0x7fade2d7beca in __GI_abort () at abort.c:89
#2  0x7fade2dbdc53 in __libc_message (do_abort=do_abort@entry=2, 
fmt=fmt@entry=0x7fade2ed3dad "*** %s ***: %s terminated\n") at 
../sysdeps/posix/libc_fatal.c:175
#3  0x7fade2e5de8c in __GI___fortify_fail (msg=, 
msg@entry=0x7fade2ed3d44 "buffer overflow detected") at fortify_fail.c:38
#4  0x7fade2e5be80 in __GI___chk_fail () at chk_fail.c:28
#5  0x7fade2e5ddd7 in __fdelt_chk (d=) at fdelt_chk.c:25
#6  0x7fade356e970 in nih_io_select_fds () from 
/lib/x86_64-linux-gnu/libnih.so.1
#7  0x7fade3572f79 in nih_main_loop () from 
/lib/x86_64-linux-gnu/libnih.so.1
#8  0x56043364a145 in ?? ()
#9  0x7fade2d65a40 in __libc_start_main (main=0x560433649ef0, argc=3, 
argv=0x7ffe4e46dda8, init=, fini=, 
rtld_fini=, stack_end=0x7ffe4e46dd98) at libc-start.c:289
#10 0x56043364a3d9 in ?? ()

How often does this happen?  Can you trigger it in a particular way?
Are you able to do

cgm listcontrollers
cgm getvalue memory . memory.limit_in_bytes
cgm listchildren memory .
cgm create memory x1

without any crashes?


** Changed in: lxc (Ubuntu)
   Importance: Undecided => High

** Changed in: lxc (Ubuntu)
   Status: New => Incomplete

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to lxc in Ubuntu.
https://bugs.launchpad.net/bugs/1532314

Title:
  Buffer overflow in cgmanager

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1532314/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1532314] Re: Buffer overflow in cgmanager

2016-01-08 Thread Serge Hallyn
Hm, sadly the trace isn't very informative:

Core was generated by `/sbin/cgmanager -m name=systemd'.
Program terminated with signal SIGABRT, Aborted.
#0  0x7fade2d7a267 in __GI_raise (sig=sig@entry=6) at 
../sysdeps/unix/sysv/linux/raise.c:55
55  ../sysdeps/unix/sysv/linux/raise.c: No such file or directory.
(gdb) where
#0  0x7fade2d7a267 in __GI_raise (sig=sig@entry=6) at 
../sysdeps/unix/sysv/linux/raise.c:55
#1  0x7fade2d7beca in __GI_abort () at abort.c:89
#2  0x7fade2dbdc53 in __libc_message (do_abort=do_abort@entry=2, 
fmt=fmt@entry=0x7fade2ed3dad "*** %s ***: %s terminated\n") at 
../sysdeps/posix/libc_fatal.c:175
#3  0x7fade2e5de8c in __GI___fortify_fail (msg=, 
msg@entry=0x7fade2ed3d44 "buffer overflow detected") at fortify_fail.c:38
#4  0x7fade2e5be80 in __GI___chk_fail () at chk_fail.c:28
#5  0x7fade2e5ddd7 in __fdelt_chk (d=) at fdelt_chk.c:25
#6  0x7fade356e970 in nih_io_select_fds () from 
/lib/x86_64-linux-gnu/libnih.so.1
#7  0x7fade3572f79 in nih_main_loop () from 
/lib/x86_64-linux-gnu/libnih.so.1
#8  0x56043364a145 in ?? ()
#9  0x7fade2d65a40 in __libc_start_main (main=0x560433649ef0, argc=3, 
argv=0x7ffe4e46dda8, init=, fini=, 
rtld_fini=, stack_end=0x7ffe4e46dd98) at libc-start.c:289
#10 0x56043364a3d9 in ?? ()

How often does this happen?  Can you trigger it in a particular way?
Are you able to do

cgm listcontrollers
cgm getvalue memory . memory.limit_in_bytes
cgm listchildren memory .
cgm create memory x1

without any crashes?


** Changed in: lxc (Ubuntu)
   Importance: Undecided => High

** Changed in: lxc (Ubuntu)
   Status: New => Incomplete

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1532314

Title:
  Buffer overflow in cgmanager

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1532314/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-08 Thread Serge Hallyn
Ok, I see.  At one point we had a special case to allow the overlay code
to write trusted.* xattrs for creating whiteouts.

However that is gone.  Therefore when overlayfs v1 (mount -t overlayfs)
is mounted, root in a user namespace also is not able to rm a file which
exists in the lower fs.

Some ways to fix this:

1. Add a special case in fs/xattr.c to allow the overlay code to create the 
trusted.overlay xattrs
2. In ovl_create_or_link(), target the override cred at init_user_ns.  Since we 
don't do that, the capabilities we are adding do not grant 
"capable(CAP_SYS_ADMIN)", only ns_capable.
3. Find another way to do this without requiring the trusted.overlay xattr.  It 
isn't needed for files so I don't know what the complications are, which 
require it to be done for directories.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531747

Title:
  overlay: mkdir fails if directory exists in lowerdir in a user
  namespace

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1531747/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-08 Thread Serge Hallyn
The type of the underlaying file does not matter, only the type of the
replacing object.

So if you

touch $t/dev; rm $t/dev; touch $t/dev
mkdir $t/dev; rmdir $t/ev; touch $t/dev

those succeed, while

touch $t/dev; rm $t/dev; mkdir $t/dev
mkdir $t/dev; rm $t/dev; mkdir $t/dev


both fail.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531747

Title:
  overlay: mkdir fails if directory exists in lowerdir in a user
  namespace

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1531747/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-08 Thread Serge Hallyn
In ovl_create_over_whiteout(), the ovl_set_opaque() in the S_ISDIR()
block failed.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531747

Title:
  overlay: mkdir fails if directory exists in lowerdir in a user
  namespace

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1531747/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1285850] Re: interuppting lxc-clone can destroy source container

2016-01-07 Thread Serge Hallyn
Should also need fix in trusty-backports

The fix will come in 1.1.6.


** Also affects: lxc (Ubuntu Wily)
   Importance: Undecided
   Status: New

** Also affects: lxc (Ubuntu Xenial)
   Importance: Undecided
   Status: New

** Also affects: lxc (Ubuntu Vivid)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to lxc in Ubuntu.
https://bugs.launchpad.net/bugs/1285850

Title:
  interuppting lxc-clone can destroy source container

To manage notifications about this bug go to:
https://bugs.launchpad.net/lxc/+bug/1285850/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1285850] Re: interuppting lxc-clone can destroy source container

2016-01-07 Thread Serge Hallyn
Should also need fix in trusty-backports

The fix will come in 1.1.6.


** Also affects: lxc (Ubuntu Wily)
   Importance: Undecided
   Status: New

** Also affects: lxc (Ubuntu Xenial)
   Importance: Undecided
   Status: New

** Also affects: lxc (Ubuntu Vivid)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1285850

Title:
  interuppting lxc-clone can destroy source container

To manage notifications about this bug go to:
https://bugs.launchpad.net/lxc/+bug/1285850/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1285850] Re: interuppting lxc-clone can destroy source container

2016-01-07 Thread Serge Hallyn
This was fixed by commit 5eea90e8505d9f336bb28379d8575be159fdd2e1, it
was github issue http://github.com/lxc/lxc/issues/694.

It needs to be SRUd somewhat urgently.


** Also affects: lxc (Ubuntu)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to lxc in Ubuntu.
https://bugs.launchpad.net/bugs/1285850

Title:
  interuppting lxc-clone can destroy source container

To manage notifications about this bug go to:
https://bugs.launchpad.net/lxc/+bug/1285850/+subscriptions

-- 
Ubuntu-server-bugs mailing list
Ubuntu-server-bugs@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs


[Bug 1285850] Re: interuppting lxc-clone can destroy source container

2016-01-07 Thread Serge Hallyn
This was fixed by commit 5eea90e8505d9f336bb28379d8575be159fdd2e1, it
was github issue http://github.com/lxc/lxc/issues/694.

It needs to be SRUd somewhat urgently.


** Also affects: lxc (Ubuntu)
   Importance: Undecided
   Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1285850

Title:
  interuppting lxc-clone can destroy source container

To manage notifications about this bug go to:
https://bugs.launchpad.net/lxc/+bug/1285850/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1531747] [NEW] overlay: mkdir fails if directory exists in lowerdir

2016-01-07 Thread Serge Hallyn
Public bug reported:

If a directory exists in the lowerdir but not in the mounted
overlay, then mkdir of the directory in the target dir results
in a mysterious -EPERM.  I've seen this both in wily kernel
(4.2.0-22-generic #27-Ubuntu) and in a hand-built xenial
master-next (with unrelated patches added).

=
#!/bin/sh -ex
dir=`mktemp -d`
cleanup() {
umount -l $dir/t
rm -rf $dir
}

trap cleanup EXIT

echo "dir is $dir"
mkdir -p $dir/l $dir/u $dir/w $dir/t
mkdir $dir/l/dev
mount -t overlay -o lowerdir=$dir/l,upperdir=$dir/u,workdir=$dir/w o $dir/t
stat $dir/t/dev
rmdir $dir/t/dev
mkdir $dir/t/dev
echo $?
echo "mkdir should have succeeded"
=

** Affects: linux (Ubuntu)
 Importance: Undecided
 Status: Incomplete

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531747

Title:
  overlay: mkdir fails if directory exists in lowerdir

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1531747/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


[Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir

2016-01-07 Thread Serge Hallyn
summary  overlay: mkdir in user namespace fails if directory exists in
lowerdir"


** Description changed:

  If a directory exists in the lowerdir but not in the mounted
  overlay, then mkdir of the directory in the target dir results
  in a mysterious -EPERM.  I've seen this both in wily kernel
  (4.2.0-22-generic #27-Ubuntu) and in a hand-built xenial
  master-next (with unrelated patches added).
  
  =
  #!/bin/sh -ex
  dir=`mktemp -d`
  cleanup() {
-   umount -l $dir/t
-   rm -rf $dir
+  umount -l $dir/t
+  rm -rf $dir
  }
  
  trap cleanup EXIT
  
  echo "dir is $dir"
  mkdir -p $dir/l $dir/u $dir/w $dir/t
  mkdir $dir/l/dev
  mount -t overlay -o lowerdir=$dir/l,upperdir=$dir/u,workdir=$dir/w o $dir/t
  stat $dir/t/dev
  rmdir $dir/t/dev
  mkdir $dir/t/dev
  echo $?
  echo "mkdir should have succeeded"
  =
+ 
+ The above will work on the host, but fail in a user namespace, i.e
+ in a regular lxd container.

** Summary changed:

- overlay: mkdir fails if directory exists in lowerdir
+ overlay: mkdir fails if directory exists in lowerdir in a user namespace

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531747

Title:
  overlay: mkdir fails if directory exists in lowerdir in a user
  namespace

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1531747/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

[Bug 1342083] Re: "Failed to create chardev" due to apparmor DENIED execute of "/usr/lib/pt_chown"

2016-01-07 Thread Serge Hallyn
I failed to reproduce the original problem, but the -proposed packages
pass the qa regression tests in lp:qa-regression-tests.


** Tags removed: verification-needed
** Tags added: verification-done

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1342083

Title:
  "Failed to create chardev" due to apparmor DENIED execute of
  "/usr/lib/pt_chown"

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1342083/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


Re: [Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-07 Thread Serge Hallyn
Quoting Joseph Salisbury (joseph.salisb...@canonical.com):
> Can you see if this bug also happens with the latest mainline kernel?  It can 
> be downloaded from:

That is not an option, because the mainline kernel doesn't support unprivileged
overlayfs mounting which is where this happens.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531747

Title:
  overlay: mkdir fails if directory exists in lowerdir in a user
  namespace

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1531747/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


Re: [Bug 1529079] Re: Can't start virtual machines after upgrade to Xenial

2016-01-07 Thread Serge Hallyn
Quoting RussianNeuroMancer (1529...@bugs.launchpad.net):
> I have systemd installed. 
> I mean, I can add systemd package as affected package again?

Yes I think that's fair, though it's more likely a bug in libvirt's
use of systemd-machined.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1529079

Title:
  Can't start virtual machines after upgrade to Xenial

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/libvirt/+bug/1529079/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


Re: [Bug 1531191] Re: qemu-kvm-init script called with undefined $KVM_HUGEPAGES

2016-01-06 Thread Serge Hallyn
Gah.  Thank you.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1531191

Title:
  qemu-kvm-init script called with undefined $KVM_HUGEPAGES

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/qemu/+bug/1531191/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs


<    4   5   6   7   8   9   10   11   12   13   >