Bug#916639: LXC AppArmor confinement breaks systemd v240

2019-02-24 Thread intrigeri
Hi, Pierre-Elliott Bécue: > Please review and comment: > - > https://salsa.debian.org/lxc-team/lxc/commit/1e8ca3640eec0b82297314d10435b68918907fc8 >(patch inclusion) > - > https://salsa.debian.org/lxc-team/lxc/commit/84df6216317542961bbad08a08e159f38e623de7 >(minimalist default.conf)

Bug#916639: LXC AppArmor confinement breaks systemd v240

2019-02-11 Thread Pierre-Elliott Bécue
Le dimanche 27 janvier 2019 à 19:47:59+0100, intrigeri a écrit : > Hi, > > Pierre-Elliott Bécue: > > We have to decide what solution I will implement. > > Right, thanks for following up. > > > I'm open to suggestions, although I'm considering the "disable > > apparmor profiles for lxc" solution

Bug#916639: LXC AppArmor confinement breaks systemd v240

2019-02-09 Thread Pierre-Elliott Bécue
Le dimanche 27 janvier 2019 à 19:47:59+0100, intrigeri a écrit : > Hi, > > Pierre-Elliott Bécue: > > We have to decide what solution I will implement. > > Right, thanks for following up. > > > I'm open to suggestions, although I'm considering the "disable > > apparmor profiles for lxc" solution

Bug#916639: LXC AppArmor confinement breaks systemd v240

2019-01-27 Thread intrigeri
Hi, Pierre-Elliott Bécue: > We have to decide what solution I will implement. Right, thanks for following up. > I'm open to suggestions, although I'm considering the "disable > apparmor profiles for lxc" solution for now. I think that disabling AppArmor by default for new LXC containers for Bus

Bug#916639: LXC AppArmor confinement breaks systemd v240

2019-01-27 Thread Pierre-Elliott Bécue
Le jeudi 17 janvier 2019 à 11:41:49+0100, Wolfgang Bumiller a écrit : > > > On January 13, 2019 at 11:40 AM intrigeri wrote: > > > > > > Hi Christian, > > > > Christian Brauner: > > > Did you backport the new config keys as well? > > > If so we can't carry that version upstream. > > > Since th

Bug#916639: LXC AppArmor confinement breaks systemd v240

2019-01-17 Thread Wolfgang Bumiller
> On January 13, 2019 at 11:40 AM intrigeri wrote: > > > Hi Christian, > > Christian Brauner: > > Did you backport the new config keys as well? > > If so we can't carry that version upstream. > > Since this would be a feature release. > > If you only backported the internal profile changes th

Bug#916639: LXC AppArmor confinement breaks systemd v240

2019-01-13 Thread intrigeri
Hi Christian, Christian Brauner: > Did you backport the new config keys as well? > If so we can't carry that version upstream. > Since this would be a feature release. > If you only backported the internal profile changes than we can > carry it upstream and you should send your patch. I've backpo

Bug#916639: LXC AppArmor confinement breaks systemd v240

2019-01-13 Thread intrigeri
Hi, Pierre-Elliott Bécue: > Hi, > Le 11/01/2019 à 16:02, Christian Brauner a écrit : >> Hm, unlikely. Can you carry a separate patch on top of 3.0.3 until >> we release 3.0.4? > Sure, if it is applicable on top of 3.0.3 I can do it. :) Note that I've already backported these patches and propose

Bug#916639: LXC AppArmor confinement breaks systemd v240

2019-01-13 Thread Christian Brauner
Did you backport the new config keys as well? If so we can't carry that version upstream. Since this would be a feature release. If you only backported the internal profile changes than we can carry it upstream and you should send your patch. Christian On January 13, 2019 12:19:43 PM GMT+02:00,

Bug#916639: LXC AppArmor confinement breaks systemd v240

2019-01-11 Thread Christian Brauner
On Fri, Jan 11, 2019 at 03:56:02PM +0100, Pierre-Elliott Bécue wrote: > Le 11/01/2019 à 15:01, Christian Brauner a écrit : > > On Fri, Jan 11, 2019 at 12:58:09AM +0100, Pierre-Elliott Bécue wrote: > >> Le dimanche 16 décembre 2018 à 20:22:05+0100, intrig...@debian.org a écrit  > >> : > >>> Package:

Bug#916639: LXC AppArmor confinement breaks systemd v240

2019-01-11 Thread Pierre-Elliott Bécue
Hi, Le 11/01/2019 à 16:02, Christian Brauner a écrit :> Hm, unlikely. Can you carry a separate patch on top of 3.0.3 until we > release 3.0.4? Sure, if it is applicable on top of 3.0.3 I can do it. :) -- PEB

Bug#916639: LXC AppArmor confinement breaks systemd v240

2019-01-11 Thread Pierre-Elliott Bécue
Le 11/01/2019 à 15:01, Christian Brauner a écrit : > On Fri, Jan 11, 2019 at 12:58:09AM +0100, Pierre-Elliott Bécue wrote: >> Le dimanche 16 décembre 2018 à 20:22:05+0100, intrig...@debian.org a écrit : >>> Package: lxc >>> Version: 1:3.0.3-1 >>> Severity: normal >>> Tags: patch >>> X-Debbugs-Cc: M

Bug#916639: LXC AppArmor confinement breaks systemd v240

2019-01-11 Thread Christian Brauner
On Fri, Jan 11, 2019 at 12:58:09AM +0100, Pierre-Elliott Bécue wrote: > Le dimanche 16 décembre 2018 à 20:22:05+0100, intrig...@debian.org a écrit : > > Package: lxc > > Version: 1:3.0.3-1 > > Severity: normal > > Tags: patch > > X-Debbugs-Cc: Michael Biebl , Wolfgang Bumiller > > > > User: pkg-a

Bug#916639: LXC AppArmor confinement breaks systemd v240

2019-01-10 Thread Pierre-Elliott Bécue
Le dimanche 16 décembre 2018 à 20:22:05+0100, intrig...@debian.org a écrit : > Package: lxc > Version: 1:3.0.3-1 > Severity: normal > Tags: patch > X-Debbugs-Cc: Michael Biebl , Wolfgang Bumiller > > User: pkg-apparmor-t...@lists.alioth.debian.org > Usertags: buggy-profile > > Hi, > > as discus

Bug#916639: LXC AppArmor confinement breaks systemd v240

2018-12-16 Thread intrigeri
Michael Biebl: > Fwiw, I agree with your assessment here. Thanks for your input. > That said, I guess #911806 could be closed now (with #916639 and #916644 > having been filed, thanks for that btw). I'm hereby closing it, then. I only kept it open in case _you_ still saw value in your original r

Bug#916639: LXC AppArmor confinement breaks systemd v240

2018-12-16 Thread Michael Biebl
Am 16.12.18 um 20:22 schrieb intrig...@debian.org: > If Buster is going to be released with LXC 3.0.x, IMO we need to > either apply these patches or disable AppArmor by default for new LXC > containers. Fwiw, I agree with your assessment here. If we can't get AppArmor/LXC fixed in time for buste

Bug#916639: LXC AppArmor confinement breaks systemd v240

2018-12-16 Thread intrigeri
Package: lxc Version: 1:3.0.3-1 Severity: normal Tags: patch X-Debbugs-Cc: Michael Biebl , Wolfgang Bumiller User: pkg-apparmor-t...@lists.alioth.debian.org Usertags: buggy-profile Hi, as discussed on https://bugs.debian.org/911806 the current LXC AppArmor support breaks systemd v240, which now