[Bug 1452601] Re: vivid container's networking.service fails on boot with signal=PIPE

2015-11-04 Thread Serge Hallyn
Thanks, what about sudo brctl show sudo ifconfig -a sudo journalctl -u lxc-net sudo systemd-detect-virt -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1452601 Title: vivid container's

[Bug 1452601] Re: vivid container's networking.service fails on boot with signal=PIPE

2015-11-04 Thread Serge Hallyn
Thanks, what about sudo brctl show sudo ifconfig -a sudo journalctl -u lxc-net sudo systemd-detect-virt -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1452601 Title: vivid container's

[Bug 1480440] Re: libvirt does not wait for guests to shut down

2015-11-04 Thread Serge Hallyn
Hi, I'd really prefer to avoid the potential breakage by trying to backport this with 2months left to EOL. So I'm going to mark this wontfix for vivid. If you reall need this, please reply here. Please remember you can work around this by using upstart, or you can upgrade to wily which has the

[Bug 1480440] Re: libvirt does not wait for guests to shut down

2015-11-04 Thread Serge Hallyn
Hi, I'd really prefer to avoid the potential breakage by trying to backport this with 2months left to EOL. So I'm going to mark this wontfix for vivid. If you reall need this, please reply here. Please remember you can work around this by using upstart, or you can upgrade to wily which has the

[Bug 1511830] Re: apparmor denies VM startup when image is network mounted

2015-11-04 Thread Serge Hallyn
** Also affects: libvirt (Ubuntu Trusty) Importance: Undecided Status: New ** Also affects: libvirt (Ubuntu Wily) Importance: Undecided Status: New ** Also affects: libvirt (Ubuntu Vivid) Importance: Undecided Status: New -- You received this bug notification

[Bug 1510720] Re: vm-builder doesn't support ppc64el

2015-11-04 Thread Serge Hallyn
Actually, it seems that python-vm-builder *is* available in wily on power8. ubuntu@diamond:~$ apt-cache show python-vm-builder Package: python-vm-builder Priority: extra Section: universe/utils Installed-Size: 4248 Maintainer: Serge Hallyn <serge.hal...@ubuntu.com> Architecture: all Sour

[Bug 1511830] Re: apparmor denies VM startup when image is network mounted

2015-11-04 Thread Serge Hallyn
** Description changed: + = + SRU Justification + Impact: cannot start vms on nfs mounted disk images + Testcase: set up libvirt managed nfs mount, try to start a vm on it. + Fix: add 'network ipv6' permission to virt-aa-helper's apparmor policy. +

[Bug 1510720] Re: vm-builder doesn't support ppc64el

2015-11-04 Thread Serge Hallyn
Actually, it seems that python-vm-builder *is* available in wily on power8. ubuntu@diamond:~$ apt-cache show python-vm-builder Package: python-vm-builder Priority: extra Section: universe/utils Installed-Size: 4248 Maintainer: Serge Hallyn <serge.hal...@ubuntu.com> Architecture: all Sour

[Bug 1511830] Re: apparmor denies VM startup when image is network mounted

2015-11-04 Thread Serge Hallyn
** Also affects: libvirt (Ubuntu Trusty) Importance: Undecided Status: New ** Also affects: libvirt (Ubuntu Wily) Importance: Undecided Status: New ** Also affects: libvirt (Ubuntu Vivid) Importance: Undecided Status: New -- You received this bug notification

[Bug 1511830] Re: apparmor denies VM startup when image is network mounted

2015-11-04 Thread Serge Hallyn
** Changed in: libvirt (Ubuntu) Importance: Undecided => High ** Changed in: libvirt (Ubuntu Trusty) Importance: Undecided => High ** Changed in: libvirt (Ubuntu Vivid) Importance: Undecided => High ** Changed in: libvirt (Ubuntu Wily) Importance: Undecided => High -- You received

[Bug 235562] Re: Add ability to build Debian virtual machines

2015-11-03 Thread Serge Hallyn
** Changed in: vm-builder (Ubuntu) Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to vm-builder in Ubuntu. https://bugs.launchpad.net/bugs/235562 Title: Add ability to build Debian virtual

[Bug 235562] Re: Add ability to build Debian virtual machines

2015-11-03 Thread Serge Hallyn
** Changed in: vm-builder (Ubuntu) Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/235562 Title: Add ability to build Debian virtual machines To manage

[Bug 1497420] Re: systemd 226 (moving pid 1 into /init.scope cgroup) breaks lxc-attach

2015-11-03 Thread Serge Hallyn
Yup, we need https://github.com/lxc/lxc/commit/f348e47c93568b4f0c371cf5df1c98d4e816a86c in the packages. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1497420 Title: systemd 226

[Bug 1497420] Re: systemd 226 (moving pid 1 into /init.scope cgroup) breaks lxc-attach

2015-11-03 Thread Serge Hallyn
Yup, we need https://github.com/lxc/lxc/commit/f348e47c93568b4f0c371cf5df1c98d4e816a86c in the packages. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1497420 Title: systemd 226 (moving pid 1

[Bug 1452601] Re: vivid container's networking.service fails on boot with signal=PIPE

2015-11-03 Thread Serge Hallyn
@Kevin, could you please give some more details? In particular, release of both host and container, where exactly it fails, and the relevant journalctl output. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1452601] Re: vivid container's networking.service fails on boot with signal=PIPE

2015-11-03 Thread Serge Hallyn
@Kevin, could you please give some more details? In particular, release of both host and container, where exactly it fails, and the relevant journalctl output. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to lxc in Ubuntu.

[Bug 1475749] Re: usermod --add-subuids fails for users not in /etc/passwd

2015-11-03 Thread Serge Hallyn
** Changed in: shadow (Ubuntu Vivid) Status: Fix Committed => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1475749 Title: usermod --add-subuids fails for users not in /etc/passwd

[Bug 1475749] Re: usermod --add-subuids fails for users not in /etc/passwd

2015-11-03 Thread Serge Hallyn
(sorry, i msread the bug history) ** Changed in: shadow (Ubuntu Vivid) Status: Confirmed => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1475749 Title: usermod --add-subuids

[Bug 1475749] Re: usermod --add-subuids fails for users not in /etc/passwd

2015-11-03 Thread Serge Hallyn
The test case in the Description passed cleanly for me (and failed without -proposed) ** Tags removed: verification-needed ** Tags added: verification-done -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

Re: [Bug 1294200] Re: test linked against nih-dbus-tool-generated libraryis not thread-safe

2015-11-03 Thread Serge Hallyn
I don't know. libnih is still a nice library and it would be nice if it could be fixed. Certainly the lxcfs bug should be marked invalid since we no longer use it. Perhaps lxc eventually, but not yet. -- You received this bug notification because you are a member of Ubuntu Server Team, which

Re: [Bug 1294200] Re: test linked against nih-dbus-tool-generated libraryis not thread-safe

2015-11-03 Thread Serge Hallyn
I don't know. libnih is still a nice library and it would be nice if it could be fixed. Certainly the lxcfs bug should be marked invalid since we no longer use it. Perhaps lxc eventually, but not yet. -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1511830] Re: apparmor denies VM startup when image is network mounted

2015-11-02 Thread Serge Hallyn
Thanks for reporting this bug. Can you show the xml for the libvirt managed nfs storage and for the VM? The virt-aa-helper policy has # needed for when disk is on a network filesystem network inet, Which I suspect should prevent this from happening, so I will target this at apparmor. **

[Bug 1511830] Re: apparmor denies VM startup when image is network mounted

2015-11-02 Thread Serge Hallyn
Thanks for reporting this bug. Can you show the xml for the libvirt managed nfs storage and for the VM? The virt-aa-helper policy has # needed for when disk is on a network filesystem network inet, Which I suspect should prevent this from happening, so I will target this at apparmor. **

[Bug 1511993] Re: when trying to install the lxd package, lxc fails to install

2015-11-02 Thread Serge Hallyn
Oct 31 18:12:17 majid-top lxc-net[6891]: iptables v1.4.21: can't initialize iptables table `nat': Table does not exist (do you need to insmod?) Oct 31 18:12:17 majid-top lxc-net[6891]: Perhaps iptables or your kernel needs to be upgraded. Oct 31 18:12:17 majid-top lxc-net[6891]: Failed to setup

[Bug 1511875] Re: Can't upgrade from 15.10 Wily to 16.04 Xenial in LXC container

2015-11-02 Thread Serge Hallyn
** Attachment added: "/var/log/dist-upgrade/apt.log file" https://bugs.launchpad.net/ubuntu/+source/ubuntu-release-upgrader/+bug/1511875/+attachment/4511345/+files/apt.log -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1510720] Re: vm-builder doesn't support ppc64el

2015-11-02 Thread Serge Hallyn
This appears to be fixed now in xenial. I think a simple no-change rebuild in any release will enable it in power8. Please comment here with any release where you do need it. ** Changed in: vm-builder (Ubuntu) Importance: Undecided => Medium ** Changed in: vm-builder (Ubuntu)

[Bug 1505339] Re: Creation external snapshot, apparmor problem

2015-11-02 Thread Serge Hallyn
*** This bug is a duplicate of bug 1004606 *** https://bugs.launchpad.net/bugs/1004606 ** This bug has been marked a duplicate of bug 1004606 virsh create-snapshot fails to create external snapshot (blockdev-snapshot-sync fails in json monitor) -- You received this bug notification

[Bug 1511875] Re: Can't upgrade from 15.10 Wily to 16.04 Xenial in LXC container

2015-11-02 Thread Serge Hallyn
It does this in an unprivileged (true root) as well as a apparmor- unconfined container. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1511875 Title: Can't upgrade from 15.10 Wily to 16.04 Xenial

[Bug 1506378] Re: libvirt-bin configuration after installatioin fails

2015-11-02 Thread Serge Hallyn
(marking 'invalid' meaning 'cannot reproduce any more') -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1506378 Title: libvirt-bin configuration after installatioin fails To manage notifications

[Bug 1506378] Re: libvirt-bin configuration after installatioin fails

2015-11-02 Thread Serge Hallyn
Thanks for the update. ** Changed in: libvirt (Ubuntu) Status: Incomplete => Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1506378 Title: libvirt-bin configuration after

[Bug 1506378] Re: libvirt-bin configuration after installatioin fails

2015-11-02 Thread Serge Hallyn
Thanks for the update. ** Changed in: libvirt (Ubuntu) Status: Incomplete => Invalid -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libvirt in Ubuntu. https://bugs.launchpad.net/bugs/1506378 Title: libvirt-bin configuration

[Bug 1511993] Re: when trying to install the lxd package, lxc fails to install

2015-11-02 Thread Serge Hallyn
Oct 31 18:12:17 majid-top lxc-net[6891]: iptables v1.4.21: can't initialize iptables table `nat': Table does not exist (do you need to insmod?) Oct 31 18:12:17 majid-top lxc-net[6891]: Perhaps iptables or your kernel needs to be upgraded. Oct 31 18:12:17 majid-top lxc-net[6891]: Failed to setup

[Bug 1510720] Re: vm-builder doesn't support ppc64el

2015-11-02 Thread Serge Hallyn
This appears to be fixed now in xenial. I think a simple no-change rebuild in any release will enable it in power8. Please comment here with any release where you do need it. ** Changed in: vm-builder (Ubuntu) Importance: Undecided => Medium ** Changed in: vm-builder (Ubuntu)

[Bug 1511875] Re: Can't upgrade from 15.10 Wily to 16.04 Xenial in LXC container

2015-11-02 Thread Serge Hallyn
** Attachment added: "/var/log/dist-upgrade/apt.log file" https://bugs.launchpad.net/ubuntu/+source/ubuntu-release-upgrader/+bug/1511875/+attachment/4511345/+files/apt.log -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to lxc in

[Bug 1511875] Re: Can't upgrade from 15.10 Wily to 16.04 Xenial in LXC container

2015-11-02 Thread Serge Hallyn
same thing happens with vivid->wily upgrade. ** Changed in: ubuntu-release-upgrader (Ubuntu) Status: New => Confirmed ** Changed in: lxc (Ubuntu) Status: New => Triaged ** Changed in: lxc (Ubuntu) Importance: Undecided => High ** Changed in: ubuntu-release-upgrader (Ubuntu)

[Bug 1511875] Re: Can't upgrade from 15.10 Wily to 16.04 Xenial in LXC container

2015-11-02 Thread Serge Hallyn
same thing happens with vivid->wily upgrade. ** Changed in: ubuntu-release-upgrader (Ubuntu) Status: New => Confirmed ** Changed in: lxc (Ubuntu) Status: New => Triaged ** Changed in: lxc (Ubuntu) Importance: Undecided => High ** Changed in: ubuntu-release-upgrader (Ubuntu)

[Bug 1511875] Re: Can't upgrade from 15.10 Wily to 16.04 Xenial in LXC container

2015-11-02 Thread Serge Hallyn
It does this in an unprivileged (true root) as well as a apparmor- unconfined container. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1511875 Title: Can't upgrade from 15.10 Wily to

[Bug 1504496] Re: package lxc 1.1.4-0ubuntu0.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2015-10-30 Thread Serge Hallyn
Actually the most telling sign in the logs here is Oct 09 11:56:42 quelbo lxc-net[23366]: lxc-net is already running If someone can reproduce this again, please attach the same information Nick had assigned in addition to 'ifconfig -a' and 'systemctl -u lxc- net' output. ** Changed in: lxc

[Bug 1504496] Re: package lxc 1.1.4-0ubuntu0.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2015-10-30 Thread Serge Hallyn
(marking incomplete as we need more information to debug, but we've lost the reproducer) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1504496 Title: package lxc 1.1.4-0ubuntu0.1 failed to

[Bug 1504496] Re: package lxc 1.1.4-0ubuntu0.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2015-10-30 Thread Serge Hallyn
fwiw i don't think this is bug 1490110 because the signature is different - there is complaint about the sysv job not being there. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1504496

[Bug 1504496] Re: package lxc 1.1.4-0ubuntu0.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2015-10-30 Thread Serge Hallyn
Actually the most telling sign in the logs here is Oct 09 11:56:42 quelbo lxc-net[23366]: lxc-net is already running If someone can reproduce this again, please attach the same information Nick had assigned in addition to 'ifconfig -a' and 'systemctl -u lxc- net' output. ** Changed in: lxc

[Bug 1504496] Re: package lxc 1.1.4-0ubuntu0.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2015-10-30 Thread Serge Hallyn
(marking incomplete as we need more information to debug, but we've lost the reproducer) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1504496 Title: package lxc 1.1.4-0ubuntu0.1

[Bug 1504496] Re: package lxc 1.1.4-0ubuntu0.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2015-10-30 Thread Serge Hallyn
fwiw i don't think this is bug 1490110 because the signature is different - there is complaint about the sysv job not being there. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1504496 Title:

[Bug 517067] Re: Using virtio for block devices makes disks and partitions disappear in KVM/QEMU (using vmbuilder and libvirt)

2015-10-30 Thread Serge Hallyn
** Changed in: vm-builder (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/517067 Title: Using virtio for block devices makes disks and partitions

[Bug 517067] Re: Using virtio for block devices makes disks and partitions disappear in KVM/QEMU (using vmbuilder and libvirt)

2015-10-30 Thread Serge Hallyn
** Changed in: vm-builder (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to vm-builder in Ubuntu. https://bugs.launchpad.net/bugs/517067 Title: Using virtio for block devices makes

[Bug 1481295] Re: virt-manager after upgrade: Error polling connection 'qemu:///system': internal error: could not get interface XML description: File operation failed - Failed to read (null)

2015-10-30 Thread Serge Hallyn
Ok, thanks. so ncftool dumpxml actually stil works, but virsh iface-dumpxml fails. It is fixed in x (i can now test that :), so we just need to SRU that patch to t,v,w. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to netcf in Ubuntu.

[Bug 1481295] Re: virt-manager after upgrade: Error polling connection 'qemu:///system': internal error: could not get interface XML description: File operation failed - Failed to read (null)

2015-10-30 Thread Serge Hallyn
Ok, thanks. so ncftool dumpxml actually stil works, but virsh iface-dumpxml fails. It is fixed in x (i can now test that :), so we just need to SRU that patch to t,v,w. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1481295] Re: virt-manager after upgrade: Error polling connection 'qemu:///system': internal error: could not get interface XML description: File operation failed - Failed to read (null)

2015-10-30 Thread Serge Hallyn
Actually trusty is not affected ** Also affects: virt-manager (Ubuntu Vivid) Importance: Undecided Status: New ** Also affects: netcf (Ubuntu Vivid) Importance: Undecided Status: New ** Changed in: netcf (Ubuntu Vivid) Importance: Undecided => High ** Changed in:

[Bug 1481295] Re: virt-manager after upgrade: Error polling connection 'qemu:///system': internal error: could not get interface XML description: File operation failed - Failed to read (null)

2015-10-30 Thread Serge Hallyn
Actually trusty is not affected ** Also affects: virt-manager (Ubuntu Vivid) Importance: Undecided Status: New ** Also affects: netcf (Ubuntu Vivid) Importance: Undecided Status: New ** Changed in: netcf (Ubuntu Vivid) Importance: Undecided => High ** Changed in:

[Bug 1481295] Re: virt-manager after upgrade: Error polling connection 'qemu:///system': internal error: could not get interface XML description: File operation failed - Failed to read (null)

2015-10-29 Thread Serge Hallyn
@ferdez, are you able to provide the information requested in comment #7? -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to netcf in Ubuntu. https://bugs.launchpad.net/bugs/1481295 Title: virt-manager after upgrade: Error polling

[Bug 1481295] Re: virt-manager after upgrade: Error polling connection 'qemu:///system': internal error: could not get interface XML description: File operation failed - Failed to read (null)

2015-10-29 Thread Serge Hallyn
@ferdez, are you able to provide the information requested in comment #7? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1481295 Title: virt-manager after upgrade: Error polling connection

[Bug 1384532] Re: Unable to set AppArmor profile for /usr/bin/kvm-spice

2015-10-29 Thread Serge Hallyn
@xianghui, will you be able to provide the information requested in comment #19? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1384532 Title: Unable to set AppArmor profile for /usr/bin/kvm-spice

Re: [Bug 1510720] [NEW] vm-builder doesn't support ppc64el

2015-10-29 Thread Serge Hallyn
Quoting Stewart Smith (stew...@linux.vnet.ibm.com): > Serge Hallyn <1510...@bugs.launchpad.net> writes: > > Which package are you trying to use? > > gitian-builder - an attempt to work on repeatable builds for OpenPower > firmware (and having it all run on ppc64el rat

[Bug 1481295] Re: virt-manager after upgrade: Error polling connection 'qemu:///system': internal error: could not get interface XML description: File operation failed - Failed to read (null)

2015-10-29 Thread Serge Hallyn
D'oh, that makes sense. I'll try again with that - thanks. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to netcf in Ubuntu. https://bugs.launchpad.net/bugs/1481295 Title: virt-manager after upgrade: Error polling connection

[Bug 1481295] Re: virt-manager after upgrade: Error polling connection 'qemu:///system': internal error: could not get interface XML description: File operation failed - Failed to read (null)

2015-10-29 Thread Serge Hallyn
D'oh, that makes sense. I'll try again with that - thanks. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1481295 Title: virt-manager after upgrade: Error polling connection 'qemu:///system':

Re: [Bug 1510720] [NEW] vm-builder doesn't support ppc64el

2015-10-29 Thread Serge Hallyn
Quoting Stewart Smith (stew...@linux.vnet.ibm.com): > Serge Hallyn <1510...@bugs.launchpad.net> writes: > > Which package are you trying to use? > > gitian-builder - an attempt to work on repeatable builds for OpenPower > firmware (and having it all run on ppc64el rat

Re: [Bug 1510720] [NEW] vm-builder doesn't support ppc64el

2015-10-29 Thread Serge Hallyn
Ok, I just built a package on power8 switching Architecture:all to any. I don't see any reason not to push with that change. There are some other changes in the bzr tree and one I'm still reviewing, I'll upload to xenial in a bit. I assume you'll need this SRU'd - which releases do you need this

Re: [Bug 1510720] [NEW] vm-builder doesn't support ppc64el

2015-10-29 Thread Serge Hallyn
Ok, I just built a package on power8 switching Architecture:all to any. I don't see any reason not to push with that change. There are some other changes in the bzr tree and one I'm still reviewing, I'll upload to xenial in a bit. I assume you'll need this SRU'd - which releases do you need this

[Bug 1504781] Re: lxc-test-ubuntu hangs forever in trusty-proposed with Linux 3.13.0-66: AppArmor denies /dev/ptmx mounting

2015-10-28 Thread Serge Hallyn
** Also affects: linux (Ubuntu Precise) Importance: Undecided Status: New ** Also affects: lxc (Ubuntu Precise) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to lxc in Ubuntu.

[Bug 1504781] Re: lxc-test-ubuntu hangs forever in trusty-proposed with Linux 3.13.0-66: AppArmor denies /dev/ptmx mounting

2015-10-28 Thread Serge Hallyn
** Also affects: linux (Ubuntu Precise) Importance: Undecided Status: New ** Also affects: lxc (Ubuntu Precise) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1509752] Re: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-28 Thread Serge Hallyn
** Also affects: lxc (Ubuntu Trusty) Importance: Undecided Status: New ** Changed in: lxc (Ubuntu Trusty) Importance: Undecided => High ** Changed in: lxc (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu

[Bug 1509752] Re: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-28 Thread Serge Hallyn
** Also affects: lxc (Ubuntu Trusty) Importance: Undecided Status: New ** Changed in: lxc (Ubuntu Trusty) Importance: Undecided => High ** Changed in: lxc (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu

Re: [Bug 1510720] [NEW] vm-builder doesn't support ppc64el

2015-10-28 Thread Serge Hallyn
Which package are you trying to use? We could change this for xenial (although a new attempt to drop vm-builder fromthe archive would serve us better) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to vm-builder in Ubuntu.

[Bug 1504781] Re: lxc-test-ubuntu hangs forever in trusty-proposed with Linux 3.13.0-66: AppArmor denies /dev/ptmx mounting

2015-10-28 Thread Serge Hallyn
** Description changed: + == + SRU Justification: + Impact: containers fail to start! + Regression potential: we only add a copy of an existing apparmor allow rule + with a different syntax (no trailing /), leaving the old one for

[Bug 1504781] Re: lxc-test-ubuntu hangs forever in trusty-proposed with Linux 3.13.0-66: AppArmor denies /dev/ptmx mounting

2015-10-28 Thread Serge Hallyn
** Description changed: + == + SRU Justification: + Impact: containers fail to start! + Regression potential: we only add a copy of an existing apparmor allow rule + with a different syntax (no trailing /), leaving the old one for

Re: [Bug 1510720] [NEW] vm-builder doesn't support ppc64el

2015-10-28 Thread Serge Hallyn
Which package are you trying to use? We could change this for xenial (although a new attempt to drop vm-builder fromthe archive would serve us better) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1509752] Re: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-28 Thread Serge Hallyn
Yup, switching in the upstream fix works - will upload that in a bit. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1509752 Title: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch To

[Bug 1509752] Re: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-28 Thread Serge Hallyn
Yup, switching in the upstream fix works - will upload that in a bit. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to lxc in Ubuntu. https://bugs.launchpad.net/bugs/1509752 Title: Bug in ensure_not_symlink() from

[Bug 1509752] Re: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-28 Thread Serge Hallyn
No, sadly one testcase - lxc-test-unpriv - still fails: Oct 28 15:33:49 lxct1 kernel: [ 2659.417204] type=1400 audit(1446046429.177:52): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="/usr/bin/lxc-start"

[Bug 1509752] Re: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-28 Thread Serge Hallyn
No, sadly one testcase - lxc-test-unpriv - still fails: Oct 28 15:33:49 lxct1 kernel: [ 2659.417204] type=1400 audit(1446046429.177:52): apparmor="DENIED" operation="mount" info="failed flags match" error=-13 profile="/usr/bin/lxc-start"

[Bug 1509752] Re: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-28 Thread Serge Hallyn
** Description changed: - This bug/limitation is present in lxc from 1.0.7-0ubuntu0.5 through - 1.0.7-0ubuntu0.9 (or anything that incorporates - 0003-CVE-2015-1335.patch). Basically, the limitation is obvious when - using recursive bind mounts because ensure_not_symlink() only checks the - last

[Bug 1509752] Re: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-28 Thread Serge Hallyn
** Description changed: - This bug/limitation is present in lxc from 1.0.7-0ubuntu0.5 through - 1.0.7-0ubuntu0.9 (or anything that incorporates - 0003-CVE-2015-1335.patch). Basically, the limitation is obvious when - using recursive bind mounts because ensure_not_symlink() only checks the - last

[Bug 1509752] Re: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-28 Thread Serge Hallyn
(invalid would probably be a better status for the development release, but i dont' want to scare the SRU team :) Uploaded a workaround for this bug. Using the upstream fix sadly is still broken by apparmor+overlayfs bugs. -- You received this bug notification because you are a member of

[Bug 1509752] Re: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-28 Thread Serge Hallyn
(invalid would probably be a better status for the development release, but i dont' want to scare the SRU team :) Uploaded a workaround for this bug. Using the upstream fix sadly is still broken by apparmor+overlayfs bugs. -- You received this bug notification because you are a member of

[Bug 1504781] Re: lxc-test-ubuntu hangs forever in trusty-proposed with Linux 3.13.0-66: AppArmor denies /dev/ptmx mounting

2015-10-27 Thread Serge Hallyn
@stefan-huehner - sorry, I'm losing track. is what you are asking for just a lxc update to precise-proposed with the new apparmor allow rule that jj suggested? If so, in comment #33 I was trying to encourage a debdiff to be posted by someone who could best test it. I'll then sponsor it into the

[Bug 235562] Re: Add ability to build Debian virtual machines

2015-10-27 Thread Serge Hallyn
Thanks, I've merged this upstream. I may push a new version to xenial in a few days. ** Changed in: vmbuilder Status: Invalid => Fix Released ** No longer affects: ubuntu-vm-builder (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1481295] Re: virt-manager after upgrade: Error polling connection 'qemu:///system': internal error: could not get interface XML description: File operation failed - Failed to read (null)

2015-10-27 Thread Serge Hallyn
** Changed in: netcf (Ubuntu Xenial) Status: Triaged => Fix Released ** Changed in: virt-manager (Ubuntu Xenial) Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1481295] Re: virt-manager after upgrade: Error polling connection 'qemu:///system': internal error: could not get interface XML description: File operation failed - Failed to read (null)

2015-10-27 Thread Serge Hallyn
** Changed in: netcf (Ubuntu Xenial) Status: Triaged => Fix Released ** Changed in: virt-manager (Ubuntu Xenial) Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to netcf in Ubuntu.

Re: [Bug 1509752] [NEW] Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-27 Thread Serge Hallyn
Thanks - haven't tested, but it certainly makes sense. status: confirmed importance: high ** Changed in: lxc (Ubuntu) Importance: Undecided => High ** Changed in: lxc (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs,

Re: [Bug 1509752] [NEW] Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-27 Thread Serge Hallyn
Thanks - haven't tested, but it certainly makes sense. status: confirmed importance: high ** Changed in: lxc (Ubuntu) Importance: Undecided => High ** Changed in: lxc (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Server

[Bug 235562] Re: Add ability to build Debian virtual machines

2015-10-27 Thread Serge Hallyn
Thanks, I've merged this upstream. I may push a new version to xenial in a few days. ** Changed in: vmbuilder Status: Invalid => Fix Released ** No longer affects: ubuntu-vm-builder (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Server Team, which is

[Bug 1481295] Re: virt-manager after upgrade: Error polling connection 'qemu:///system': internal error: could not get interface XML description: File operation failed - Failed to read (null)

2015-10-27 Thread Serge Hallyn
I'm trying to come up with a brief test case to SRU this to wily, but i don't seem to get an error when I do: sudo ifconfig eth0:0 192.168.99.1 up sudo ncftool list sudo ncftool dumpxml eth0:0 Or, at least, no different results than with the patch applied. Can you show ifconfig -a output for

[Bug 1481295] Re: virt-manager after upgrade: Error polling connection 'qemu:///system': internal error: could not get interface XML description: File operation failed - Failed to read (null)

2015-10-27 Thread Serge Hallyn
I'm trying to come up with a brief test case to SRU this to wily, but i don't seem to get an error when I do: sudo ifconfig eth0:0 192.168.99.1 up sudo ncftool list sudo ncftool dumpxml eth0:0 Or, at least, no different results than with the patch applied. Can you show ifconfig -a output for

[Bug 1472369] Re: lxcbr0 missing after starting lxc-net.service

2015-10-27 Thread Serge Hallyn
*** This bug is a duplicate of bug 1468611 *** https://bugs.launchpad.net/bugs/1468611 @paugnu which ubuntu release are you on and what is your dnsmasq version? (dpkg -l dnsmasq) Do you have bind installed? Does creating /etc/dnsmasq.conf fix without having to clear out /etc/dnsmasq.d/lxc

[Bug 1472369] Re: lxcbr0 missing after starting lxc-net.service

2015-10-27 Thread Serge Hallyn
*** This bug is a duplicate of bug 1468611 *** https://bugs.launchpad.net/bugs/1468611 @paugnu which ubuntu release are you on and what is your dnsmasq version? (dpkg -l dnsmasq) Do you have bind installed? Does creating /etc/dnsmasq.conf fix without having to clear out /etc/dnsmasq.d/lxc

[Bug 1509752] Re: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-27 Thread Serge Hallyn
Apparently the kernel is now fixed so that we should be able to use the upstream fix. I'm going to try to get that into the trusty package rather than keep tweakng this separate patch. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1509752] Re: Bug in ensure_not_symlink() from 0003-CVE-2015-1335.patch

2015-10-27 Thread Serge Hallyn
Apparently the kernel is now fixed so that we should be able to use the upstream fix. I'm going to try to get that into the trusty package rather than keep tweakng this separate patch. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to

[Bug 1504781] Re: lxc-test-ubuntu hangs forever in trusty-proposed with Linux 3.13.0-66: AppArmor denies /dev/ptmx mounting

2015-10-27 Thread Serge Hallyn
@stefan-huehner - sorry, I'm losing track. is what you are asking for just a lxc update to precise-proposed with the new apparmor allow rule that jj suggested? If so, in comment #33 I was trying to encourage a debdiff to be posted by someone who could best test it. I'll then sponsor it into the

[Bug 1384532] Re: Unable to set AppArmor profile for /usr/bin/kvm-spice

2015-10-26 Thread Serge Hallyn
Hi, so I'm getting the feeling that we ought to turn this bug into one for enhancing the transparancy of errors. Too many errors are mis-reported by this line. For your particular case, could we try an experiment? Please install strace on the compute host, and edit /usr/bin/kvm-spice to read:

[Bug 1498162] Re: unable to make backup link of `./usr/sbin/uuidd' before installing new version: Operation not permitted

2015-10-26 Thread Serge Hallyn
It's the setuid and setgid bits with user namespace. ** Also affects: linux (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1498162 Title: unable

[Bug 1498162] Re: unable to make backup link of `./usr/sbin/uuidd' before installing new version: Operation not permitted

2015-10-26 Thread Serge Hallyn
You can work around this by doing echo 0 | sudo tee -a /proc/sys/fs/protected_hardlinks on the host. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1498162 Title: unable to make backup link of

Re: [Bug 1509414] Re: pre-installed lxc in cloud image produces broken lxc (and later lxd) containers

2015-10-25 Thread Serge Hallyn
Quoting Stéphane Graber (stgra...@stgraber.org): > I agree, the stage 2 fix for this issue concerns me with regard to > regressing current use cases. > > As much as I'd like to get rid of the rest of this issue (any user of > 10.0.4.0/24 behind a router looses connectivity to that subnet), we

Re: [Bug 1509414] Re: pre-installed lxc in cloud image produces broken lxc (and later lxd) containers

2015-10-25 Thread Serge Hallyn
Quoting Stéphane Graber (stgra...@stgraber.org): > I agree, the stage 2 fix for this issue concerns me with regard to > regressing current use cases. > > As much as I'd like to get rid of the rest of this issue (any user of > 10.0.4.0/24 behind a router looses connectivity to that subnet), we

[Bug 1509414] Re: pre-installed lxc in cloud image produces broken lxc (and later lxd) containers

2015-10-24 Thread Serge Hallyn
New image works for me in lxc: lxcbr0Link encap:Ethernet HWaddr 76:79:3e:90:1c:88 inet addr:10.0.4.1 Bcast:0.0.0.0 Mask:255.255.255.0 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to lxc in Ubuntu.

[Bug 1509414] Re: pre-installed lxc in cloud image produces broken lxc (and later lxd) containers

2015-10-24 Thread Serge Hallyn
New image works for me in lxc: lxcbr0Link encap:Ethernet HWaddr 76:79:3e:90:1c:88 inet addr:10.0.4.1 Bcast:0.0.0.0 Mask:255.255.255.0 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1509414

[Bug 1509414] Re: pre-installed lxc in cloud image produces broken lxc (and later lxd) containers

2015-10-24 Thread Serge Hallyn
I was able to For stage two, at least with systemd, I changed /lib/systemd/system/lxd-startup.service to: [Unit] Description=Container hypervisor based on LXC - boot time check After=cgmanager.service lxd-unix.socket Requires=cgmanager.service lxd-unix.socket [Service] Type=oneshot

[Bug 1509414] Re: pre-installed lxc in cloud image produces broken lxc (and later lxd) containers

2015-10-24 Thread Serge Hallyn
I was able to For stage two, at least with systemd, I changed /lib/systemd/system/lxd-startup.service to: [Unit] Description=Container hypervisor based on LXC - boot time check After=cgmanager.service lxd-unix.socket Requires=cgmanager.service lxd-unix.socket [Service] Type=oneshot

Re: [Bug 235562] Re: Add ability to build Debian virtual machines

2015-10-24 Thread Serge Hallyn
Quoting Joseph Bisch (josephbi...@gmail.com): > I just tried filling out the contributor agreement (so far I am the sole > author of the changes), but I'm not sure what to put for the project > contact and it is required. Do I put you, Serge? Uh, I'm really not sure. Putting me down sounds

Re: [Bug 235562] Re: Add ability to build Debian virtual machines

2015-10-24 Thread Serge Hallyn
Quoting Joseph Bisch (josephbi...@gmail.com): > I just tried filling out the contributor agreement (so far I am the sole > author of the changes), but I'm not sure what to put for the project > contact and it is required. Do I put you, Serge? Uh, I'm really not sure. Putting me down sounds

[Bug 1509414] Re: pre-installed lxc in cloud image produces broken lxc (and later lxd) containers

2015-10-24 Thread Serge Hallyn
This lxc debdiff (not appropriate upstream lxc) and a pull request against lxd-pkg-ubuntu (https://github.com/lxc/lxd-pkg-ubuntu/pull/7) combined should implement stage 2 of the fix. Note I've tested these when separately implemented by hand, but have not built packages with this

<    7   8   9   10   11   12   13   14   15   16   >