Bug#1105773: unblock: passt/0.0~git20250503.587980c-2

2025-05-14 Thread Stefano Brivio
leave the flow table in an inconsistent state, which would typically cause unexpected termination on a subsequent flow creation. Further, we also need to close the socket corresponding to the failed UDP flow, otherwise we'll (resource-wise) leak a file descriptor. Author: Stefano Brivio

Bug#1100135: [pkg-apparmor] Bug#1100135: Conflict between Podman Profile and Pasta profile breaks rootless network shutdown

2025-03-15 Thread Stefano Brivio
On Thu, 13 Mar 2025 18:18:28 +0100 intrigeri wrote: > Hi, > > Stefano Brivio (2025-03-13): > > Actually, if you need something quick, you don't really need a > > complete/real profile for Podman. You can just add to the current stub > > (untested, but I'm fa

Bug#1100135: [pkg-apparmor] Bug#1100135: Conflict between Podman Profile and Pasta profile breaks rootless network shutdown

2025-03-13 Thread Stefano Brivio
On Thu, 13 Mar 2025 10:51:07 +0100 intrigeri wrote: > Control: reassign -1 passt > > Hi, > > Stefano Brivio (2025-03-12): > > On Wed, 12 Mar 2025 14:41:14 +0100 > > intrigeri wrote: > > Thanks for fixing the address, yes, I didn't get the original rep

Bug#1100135: [pkg-apparmor] Bug#1100135: Conflict between Podman Profile and Pasta profile breaks rootless network shutdown

2025-03-12 Thread Stefano Brivio
Hi intrigeri, On Wed, 12 Mar 2025 14:41:14 +0100 intrigeri wrote: > Hi Sam, Stefano, others, > > (almost fully quoting because the Sam's original report Cc'ed > pa...@packages.debian.org, while I believe he meant to write to > pa...@packages.debian.org) Thanks for fixing the address, yes, I di

Bug#1086844: passt: apparmor profile breaks passt in libguestfs

2025-01-02 Thread Stefano Brivio
On Thu, 2 Jan 2025 09:52:38 + "Richard W.M. Jones" wrote: > On Wed, Nov 27, 2024 at 11:15:24AM +0100, Stefano Brivio wrote: > > Control: reassign 1086844 guestfs-tools > > > > So, I went ahead and submitted a proposal for a very loose initial > &g

Bug#1086844: passt: apparmor profile breaks passt in libguestfs

2024-11-28 Thread Stefano Brivio
On Thu, 28 Nov 2024 10:46:35 + "Richard W.M. Jones" wrote: > On Wed, Nov 27, 2024 at 10:39:18PM +0100, Hilko Bengen wrote: > > > > Rich, do you think the AppArmor policy should be part of the upstream > > source distribution? > > I don't really have an opinion on it. For SELinux policies

Bug#1086844: passt: apparmor profile breaks passt in libguestfs

2024-11-27 Thread Stefano Brivio
Control: reassign 1086844 guestfs-tools So, I went ahead and submitted a proposal for a very loose initial AppArmor profile for guestfs-tools: https://salsa.debian.org/libvirt-team/guestfs-tools/-/merge_requests/1 I checked functionality of several tools, with and without passt, as root and as

Bug#1086844: passt: apparmor profile breaks passt in libguestfs

2024-11-20 Thread Stefano Brivio
On Tue, 12 Nov 2024 15:10:38 + "Richard W.M. Jones" wrote: > On Tue, Nov 12, 2024 at 03:29:11PM +0100, Stefano Brivio wrote: > > On Tue, 12 Nov 2024 13:52:43 + > > "Richard W.M. Jones" wrote: > > > https://issues.redhat.com/browse/RH

Bug#1086844: passt: apparmor profile breaks passt in libguestfs

2024-11-12 Thread Stefano Brivio
On Tue, 12 Nov 2024 13:52:43 + "Richard W.M. Jones" wrote: > On Tue, Nov 12, 2024 at 02:22:19PM +0100, Stefano Brivio wrote: > > On Tue, 12 Nov 2024 13:08:00 + > > "Richard W.M. Jones" wrote: > > > > > Do you know where the apparmor p

Bug#1086844: passt: apparmor profile breaks passt in libguestfs

2024-11-12 Thread Stefano Brivio
On Tue, 12 Nov 2024 13:08:00 + "Richard W.M. Jones" wrote: > Do you know where the apparmor profile is shipped right now? Could it > be in libvirt (src/security/apparmor)? Yes, but that's the one for libvirt components themselves, and used on Debian without changes from upstream. I don't th

Bug#1086844: passt: apparmor profile breaks passt in libguestfs

2024-11-06 Thread Stefano Brivio
Hi, On Wed, 06 Nov 2024 15:00:13 + Tomas Janousek wrote: > Package: passt > Version: 0.0~git20241030.ee7d0b6-1 > Severity: normal > X-Debbugs-Cc: t...@nomi.cz > > Dear Maintainer, > > I just tried to run virt-sysprep on a system with passt installed (as a > recommended dep of podman) and

Bug#1078981: podman: Networking unavailable in rootles environment using pasta on i686

2024-08-20 Thread Stefano Brivio
On Tue, 20 Aug 2024 15:41:24 +0300 Faidon Liambotis wrote: > Nice. To debug i386 for the purposes of this bug, given there is no > cloud image, I used debvm (apt install debvm), and debvm-create & > debvm-run specifically. (Also thanks to Reinhard for reminding me of > it). Perhaps you would find

Bug#1078981: podman: Networking unavailable in rootles environment using pasta on i686

2024-08-20 Thread Stefano Brivio
On Mon, 19 Aug 2024 16:04:25 +0300 Faidon Liambotis wrote: > On Sun, Aug 18, 2024 at 10:00:57PM +0200, Stefano Brivio wrote: > > Thanks Uroš for reporting and Faidon for the analysis! > > Thanks for the quick response! > > > > In this case, there is a comment that

Bug#1078981: podman: Networking unavailable in rootles environment using pasta on i686

2024-08-18 Thread Stefano Brivio
Thanks Uroš for reporting and Faidon for the analysis! On Sun, 18 Aug 2024 21:15:23 +0300 Faidon Liambotis wrote: > On Sun, Aug 18, 2024 at 04:47:39PM +0200, Uroš Knupleš wrote: > > [...] > > > Interestingly, this kernel message pops up every time an container > > is brought up as an non-root

Bug#1061678: passt: apparmor denies access to /run/user/$UID/libvirt/qemu/run/passt/

2024-01-31 Thread Stefano Brivio
reassign 1061678 libvirt On Mon, 29 Jan 2024 14:03:38 +0100 Stefano Brivio wrote: > [...] > > Then, in libvirtd's policy, specific rules cover the paths for socket > and PID files as needed by libvirtd itself. To solve this, we need a > change in libvirtd's p

Bug#1061678: passt: apparmor denies access to /run/user/$UID/libvirt/qemu/run/passt/

2024-01-29 Thread Stefano Brivio
Andi, thanks for reporting this. Andrea, On Sun, 28 Jan 2024 17:16:38 +0100 "Andreas B. Mundt" wrote: > Package: passt > Version: 0.0~git20231230.f091893-1 > Severity: normal > Tags: upstream > X-Debbugs-Cc: a...@debian.org > > Hi, > > I tried to run a VM using libvirt with user mode networki

Bug#1032968: unblock: passt/0.0~git20230309.7c7625d-1

2023-03-16 Thread Stefano Brivio
On Thu, 16 Mar 2023 16:22:33 +0100 Paul Gevers wrote: > Hi Stefano, > > On 14-03-2023 22:44, Stefano Brivio wrote: > > - full slirp4netns(1) compatibility not granted > > I've never heard of this before, what does that mean for the user? pasta(1) is supposed to pro

Bug#1022886: ITP: passt -- Unprivileged user-mode network connectivity for virtual machines and containers

2022-10-27 Thread Stefano Brivio
Package: wnpp Severity: wishlist Owner: Stefano Brivio X-Debbugs-Cc: debian-de...@lists.debian.org * Package name: passt Version : 0.0~git20221026.f212044 Upstream Author : Stefano Brivio * URL : https://passt.top/ * License : AGPL-3.0-or-later AND BSD-3

Bug#1010498: RFP: passt -- Unprivileged user-mode network connectivity for virtual machines and containers

2022-05-02 Thread Stefano Brivio
Sorry, wrong link, it's actually: https://passt.top/passt/tree/contrib/debian

Bug#1010498: RFP: passt -- Unprivileged user-mode network connectivity for virtual machines and containers

2022-05-02 Thread Stefano Brivio
Package: wnpp Severity: wishlist * Package name: passt Version : 0+git-32210fb64f7d Upstream Author : Stefano Brivio * URL : https://passt.top/ * License : AGPL-3.0-or-later AND BSD-3-Clause Programming Lang: C Description : user-mode networking