[Kernel-packages] [Bug 1728109] [NEW] nbd ( + lvm thin pool?) fragile

2017-10-27 Thread Serge Hallyn
Public bug reported: I've been trying this on several platforms - 16.04 physical host 16.04 VMware 17.04 vmware The script pasted below creates a virtual disk, writes a partition table, creates an fs and some thin pools, then verifies that writes happened as expected. On 16.04 physical host it

[Kernel-packages] [Bug 1728109] Re: nbd ( + lvm thin pool?) fragile

2017-10-27 Thread Serge Hallyn
apport information ** Tags added: apport-collected zesty ** Description changed: I've been trying this on several platforms - 16.04 physical host 16.04 VMware 17.04 vmware The script pasted below creates a virtual disk, writes a partition table, creates an fs and some thin pool

[Kernel-packages] [Bug 1728109] CRDA.txt

2017-10-27 Thread Serge Hallyn
apport information ** Attachment added: "CRDA.txt" https://bugs.launchpad.net/bugs/1728109/+attachment/4998182/+files/CRDA.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1728109 Ti

[Kernel-packages] [Bug 1728109] CurrentDmesg.txt

2017-10-27 Thread Serge Hallyn
apport information ** Attachment added: "CurrentDmesg.txt" https://bugs.launchpad.net/bugs/1728109/+attachment/4998183/+files/CurrentDmesg.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net

[Kernel-packages] [Bug 1728109] Lspci.txt

2017-10-27 Thread Serge Hallyn
apport information ** Attachment added: "Lspci.txt" https://bugs.launchpad.net/bugs/1728109/+attachment/4998185/+files/Lspci.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1728109

[Kernel-packages] [Bug 1728109] JournalErrors.txt

2017-10-27 Thread Serge Hallyn
apport information ** Attachment added: "JournalErrors.txt" https://bugs.launchpad.net/bugs/1728109/+attachment/4998184/+files/JournalErrors.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.n

[Kernel-packages] [Bug 1728109] ProcEnviron.txt

2017-10-27 Thread Serge Hallyn
apport information ** Attachment added: "ProcEnviron.txt" https://bugs.launchpad.net/bugs/1728109/+attachment/4998189/+files/ProcEnviron.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/b

[Kernel-packages] [Bug 1728109] ProcCpuinfo.txt

2017-10-27 Thread Serge Hallyn
apport information ** Attachment added: "ProcCpuinfo.txt" https://bugs.launchpad.net/bugs/1728109/+attachment/4998187/+files/ProcCpuinfo.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/b

[Kernel-packages] [Bug 1728109] Lsusb.txt

2017-10-27 Thread Serge Hallyn
apport information ** Attachment added: "Lsusb.txt" https://bugs.launchpad.net/bugs/1728109/+attachment/4998186/+files/Lsusb.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1728109

[Kernel-packages] [Bug 1728109] ProcCpuinfoMinimal.txt

2017-10-27 Thread Serge Hallyn
apport information ** Attachment added: "ProcCpuinfoMinimal.txt" https://bugs.launchpad.net/bugs/1728109/+attachment/4998188/+files/ProcCpuinfoMinimal.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.l

[Kernel-packages] [Bug 1728109] ProcInterrupts.txt

2017-10-27 Thread Serge Hallyn
apport information ** Attachment added: "ProcInterrupts.txt" https://bugs.launchpad.net/bugs/1728109/+attachment/4998190/+files/ProcInterrupts.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad

[Kernel-packages] [Bug 1728109] PulseList.txt

2017-10-27 Thread Serge Hallyn
apport information ** Attachment added: "PulseList.txt" https://bugs.launchpad.net/bugs/1728109/+attachment/4998192/+files/PulseList.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/

[Kernel-packages] [Bug 1728109] ProcModules.txt

2017-10-27 Thread Serge Hallyn
apport information ** Attachment added: "ProcModules.txt" https://bugs.launchpad.net/bugs/1728109/+attachment/4998191/+files/ProcModules.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/b

[Kernel-packages] [Bug 1728109] WifiSyslog.txt

2017-10-27 Thread Serge Hallyn
apport information ** Attachment added: "WifiSyslog.txt" https://bugs.launchpad.net/bugs/1728109/+attachment/4998194/+files/WifiSyslog.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bug

[Kernel-packages] [Bug 1728109] UdevDb.txt

2017-10-27 Thread Serge Hallyn
apport information ** Attachment added: "UdevDb.txt" https://bugs.launchpad.net/bugs/1728109/+attachment/4998193/+files/UdevDb.txt -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1728109

[Kernel-packages] [Bug 1728109] Re: nbd ( + lvm thin pool?) fragile

2017-10-27 Thread Serge Hallyn
http://pastebin.com/raw/YPGG6usG is the reproduction script. In virtualbox it actually passes. Maybe this really is a problem with the disk driver for vmware? ** Description changed: I've been trying this on several platforms - 16.04 physical host 16.04 VMware 17.04 vmware The

[Kernel-packages] [Bug 1728109] Re: nbd ( + lvm thin pool?) fragile

2017-10-27 Thread Serge Hallyn
Well, actually on virtualbox it's touch-and-go. ** Changed in: linux (Ubuntu) Status: Incomplete => Confirmed -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1728109 Title: nbd (

[Kernel-packages] [Bug 1728109] Re: nbd ( + lvm thin pool?) fragile

2017-10-27 Thread Serge Hallyn
*** This bug is a duplicate of bug 1628336 *** https://bugs.launchpad.net/bugs/1628336 ** This bug has been marked a duplicate of bug 1628336 mount-image-callback cannot mount partitioned disk image -- You received this bug notification because you are a member of Kernel Packages, which i

[Kernel-packages] [Bug 882147] Re: overlayfs does not implement inotify interfaces correctly

2017-09-07 Thread Serge Hallyn
Nope, tail -f is still broken at least in 4.12. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/882147 Title: overlayfs does not implement inotify interfaces correctly Status in coreutil

[Kernel-packages] [Bug 882147] Re: overlayfs does not implement inotify interfaces correctly

2017-09-07 Thread Serge Hallyn
I've seen reports that this is fixed in 4.10? -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/882147 Title: overlayfs does not implement inotify interfaces correctly Status in coreutils

[Kernel-packages] [Bug 1551854] Re: LXD bootstrap issues on xenial

2016-03-04 Thread Serge Hallyn
@sforshee - are you saying that removing the debugfs line from /usr/share/lxc/config/ubuntu-common.conf fixes this for you? -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1551854 Title:

[Kernel-packages] [Bug 1551854] Re: LXD bootstrap issues on xenial

2016-03-04 Thread Serge Hallyn
@sforshee, Because in the past mountall would fail if we didn't. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1551854 Title: LXD bootstrap issues on xenial Status in linux package in

[Kernel-packages] [Bug 1551854] Re: LXD bootstrap issues on xenial

2016-03-04 Thread Serge Hallyn
Note - I am not actively looking at this bug as I've not managed to reproduce it. Hopefully the kernel team has it under control, please shout if I'm needed. If using juju first is a prerequisite to reproducing this, I can try that, but my impression from previous reports has been that this is no

[Kernel-packages] [Bug 1543367] Re: nested unprileged container fails to start at mounting /proc

2016-03-04 Thread Serge Hallyn
Upstream kernel still fails: lxc-start 20160304193125.498 ERRORlxc_conf - conf.c:lxc_mount_auto_mounts:742 - Operation not permitted - error mounting proc on /usr/lib/x86_64-linux-gnu/lxc/proc flags 14 lxc-start: conf.c: lxc_mount_auto_mounts: 742 Operation not permitted - error mount

[Kernel-packages] [Bug 1543367] Re: nested unprileged container fails to start at mounting /proc

2016-03-04 Thread Serge Hallyn
Current wily kernel is giving me the same behavior. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1543367 Title: nested unprileged container fails to start at mounting /proc Status in

[Kernel-packages] [Bug 1543367] Re: nested unprileged container fails to start at mounting /proc

2016-03-04 Thread Serge Hallyn
Simplest way to reproduce: sudo systemctl stop proc-sys-fs-binfmt_misc.automount # (just to be sure) unshare -mpf mount --make-rslave / mount -t proc proc /proc lxc-usernsexec # mount -t proc proc /proc # permission denied, regardless what -o options may pass. -- You received this bug notificat

[Kernel-packages] [Bug 1543367] Re: nested unprileged container fails to start at mounting /proc

2016-03-04 Thread Serge Hallyn
Sorry, testcase in #8 is invalid, bc lxc-usernsexec doesn't create a new pid namespace, so mount is denied because we do not own our pidns->userns. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.ne

[Kernel-packages] [Bug 1543367] Re: nested unprileged container fails to start at mounting /proc

2016-03-04 Thread Serge Hallyn
Ok, this is happening because lxc, for privileged containers, bind- mounts /proc/sys and /proc/sys/net onto themselves. This prevents later unprivileged mounting of /proc. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. h

[Kernel-packages] [Bug 1543367] Re: nested unprileged container fails to start at mounting /proc

2016-03-06 Thread Serge Hallyn
Sorry, I had forgotten my own workaround for this. ** Changed in: linux (Ubuntu) Status: Confirmed => Won't Fix ** Changed in: lxc (Ubuntu) Status: Triaged => Fix Released ** Changed in: linux (Ubuntu) Status: Won't Fix => Invalid -- You received this bug notification beca

[Kernel-packages] [Bug 1558897] Re: guest vm hangs

2016-03-22 Thread Serge Hallyn
** Also affects: linux (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1558897 Title: guest vm hangs Status in linux package in Ubunt

[Kernel-packages] [Bug 1563887] Re: qemu-system-ppc64 freezes on starting image on ppc64le

2016-04-02 Thread Serge Hallyn
Hm - I can boot a wily cloud image, just not a xenial one. ** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in: qemu (Ubuntu) Status: Incomplete => Confirmed -- You received this bug notification because you are a member of Kernel Packages, which is

[Kernel-packages] [Bug 1563887] Re: qemu-system-ppc64 freezes on starting image on ppc64le

2016-04-03 Thread Serge Hallyn
Result of doing qemu-system-ppc64 -m 1024 -vnc :1 -net nic -net user,net=10.0.0.0/8,host=10.0.0.1,hostfwd=tcp::-:22 -machine pseries -drive file=xenial-server-cloudimg-ppc64el-disk1.img,if=virtio -drive file=my-seed.img,if=virtio ** Attachment added: "crash.png" https://bugs.launchpad.ne

[Kernel-packages] [Bug 1563887] Re: qemu-system-ppc64 freezes on starting image on ppc64le

2016-04-04 Thread Serge Hallyn
Actually the clou dimages have a 4.2 kernel. When I use a xenial beta2 iso which has 4.4.0-15-generic #31, it boots fine. I can install, and I can boot the installed image (with same kernel) just fine. -- You received this bug notification because you are a member of Kernel Packages, which is

[Kernel-packages] [Bug 1563887] Re: qemu-system-ppc64 freezes on starting image on ppc64le

2016-04-04 Thread Serge Hallyn
4.4.0-16 also works. ** Also affects: livecd-rootfs (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1563887 Title: qemu-system-ppc64

Re: [Kernel-packages] [Bug 1563887] Re: qemu-system-ppc64 freezes on starting image on ppc64le

2016-04-05 Thread Serge Hallyn
If you can reproduce this with the ppc64 xenial iso or a rootfs installed from that, using 4.4 kernel, please let us know. Otherwise, I think the fix will be for cloud images to be updated with a 4.4 kernel. -- You received this bug notification because you are a member of Kernel Packages, which

[Kernel-packages] [Bug 1563887] Re: qemu-system-ppc64 freezes on starting image on ppc64le

2016-04-06 Thread Serge Hallyn
Ok so if I'm following this right there are two issues: 1. the bug reporter is using a powervm partition. KVM cannot be used there. This is not a KVM bug. 2. the xenial cloud images have an outdated 4.2 kernel which doesn't boot in kvm on powernv. A workaround is to use the isos which do boot.

[Kernel-packages] [Bug 1563887] Re: qemu-system-ppc64 freezes on starting image on ppc64le

2016-04-06 Thread Serge Hallyn
@leftyfb - what exactly is IBM asking to verify? Whether kvm works under powervm? Did smoser's info help? -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1563887 Title: qemu-system-ppc6

[Kernel-packages] [Bug 1546775] [NEW] Please pull cgroup namespaces

2016-02-17 Thread Serge Hallyn
Public bug reported: Cgroup namespaces are a new kernel feature which allows virtualizing a container's /proc/self/cgroups and the root of future cgroupfs mounts, to make the container appear as though it is in the / cgroup. This is one of the pieces needed to be able to run, for instance, docker

[Kernel-packages] [Bug 1539349] Re: sleep from invalid context in aa_move_mount

2016-02-18 Thread Serge Hallyn
I get no warnings with 4.2.0-29-generic #34-Ubuntu -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1539349 Title: sleep from invalid context in aa_move_mount Status in linux package in

[Kernel-packages] [Bug 1539349] Re: sleep from invalid context in aa_move_mount

2016-02-18 Thread Serge Hallyn
Wait, that's not a valid test is it. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1539349 Title: sleep from invalid context in aa_move_mount Status in linux package in Ubuntu: Fix R

[Kernel-packages] [Bug 1539349] Re: sleep from invalid context in aa_move_mount

2016-02-18 Thread Serge Hallyn
Well, that's wily-proposed, so +1 ** Tags removed: verification-needed-wily ** Tags added: verification-done -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1539349 Title: sleep from inv

[Kernel-packages] [Bug 1551854] Re: LXD bootstrap issues on xenial

2016-03-01 Thread Serge Hallyn
marking confirmed because two people have reported it, but I cannot reproduce it yet. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1551854 Title: LXD bootstrap issues on xenial Statu

[Kernel-packages] [Bug 1551854] Re: LXD bootstrap issues on xenial

2016-03-01 Thread Serge Hallyn
I'm on the same kernel Linux sl 4.4.0-8-generic #23-Ubuntu SMP Wed Feb 24 20:45:30 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux and also have the tracefs mounted 0 ✓ serge@sl ~ $ grep debug /proc/self/mountinfo 74 19 0:7 / /sys/kernel/debug rw,relatime shared:26 - debugfs debugfs rw 44 74 0:9 / /sys/

[Kernel-packages] [Bug 1551854] Re: LXD bootstrap issues on xenial

2016-03-01 Thread Serge Hallyn
Also cannot reproduce in a clean VM, so I have to assume juju is tweaking something. Can you show output of 'lxc config show ' where is the container which fails? -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://b

[Kernel-packages] [Bug 1392176] Re: mounts cgroups unconditionally which causes undesired effects with cpu hotplug

2016-01-26 Thread Serge Hallyn
** Changed in: cgmanager (Ubuntu) Status: Confirmed => Fix Released ** Changed in: systemd (Ubuntu) Status: Incomplete => Fix Released ** Changed in: linux (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Kernel Pa

[Kernel-packages] [Bug 1539349] [NEW] sleep from invalid context in aa_move_mount

2016-01-28 Thread Serge Hallyn
Public bug reported: In xenial master-next, when I cp /bin/mount /home/ubuntu/mount, define the following policy: #include /home/ubuntu/mount { #include #include capability, network, mount, /** mkrwixr, } And then run the following script under sudo from ~/ubuntu: #!/bin/sh app

[Kernel-packages] [Bug 1543367] [NEW] nested unprileged container fails to start at mounting /proc

2016-02-08 Thread Serge Hallyn
Public bug reported: Create a trusty or xenial host. Probably use ubuntu-lxc/daily ppa to work around other bugs. Create a privileged container (again either trusty or xenial will do), and install ubuntu-lxc/daily ppa there. Create an unprivileged container in that container. It will fail at m

[Kernel-packages] [Bug 1543367] Re: nested unprileged container fails to start at mounting /proc

2016-02-08 Thread Serge Hallyn
I'm quite certain this is not an apparmor issue, since leaving everything unconfined does not help. It could be something we're doing wrong in lxc, but I'm not sure what. It could be something inherent in mounting onto an open fd. -- You received this bug notification because you are a member o

[Kernel-packages] [Bug 1543367] Re: nested unprileged container fails to start at mounting /proc

2016-02-08 Thread Serge Hallyn
Note that an unprivileged user on the host is able to do these mounts. Unprivileged users inside a privileged container cannot. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1543367 Titl

Re: [Kernel-packages] [Bug 1543367] Re: nested unprileged container fails to start at mounting /proc

2016-02-09 Thread Serge Hallyn
It's not something I regularly do, as I normally nest inside unprivileged lxd containers. So I can't say whether it is a regression. I did revert to an older trusty kernel and have the same behavior. I'm going to need to write a script to make this more easily reproducible, but I won't have time

[Kernel-packages] [Bug 1512185] Re: qemu-nbd on ARM64 deadlock? Stuck in rt_sigtimedwait([BUS ALRM IO], ..) and futex(0x7f749ec230, FUTEX_WAIT, ...)

2016-02-09 Thread Serge Hallyn
** Changed in: qemu (Ubuntu) Status: Confirmed => Incomplete ** Changed in: qemu (Ubuntu) Importance: Undecided => Medium ** Changed in: linux-meta-lts-vivid (Ubuntu) Status: Confirmed => Invalid -- You received this bug notification because you are a member of Kernel Packages,

[Kernel-packages] [Bug 1530617] Re: FUSE in wily image with upstart installed causes chaos

2016-01-05 Thread Serge Hallyn
(Where the last prompt comes from the lxc-attach having been killed) stopping lxcfs on the host prevents this from happening. I don't think lxcfs is to blame, though but rather fuse. ** Also affects: linux (Ubuntu) Importance: Undecided Status: New -- You received this bug notificat

[Kernel-packages] [Bug 1530617] Re: FUSE in wily image with upstart installed causes chaos

2016-01-05 Thread Serge Hallyn
An strace of the attach shows: 15047 read(0, 15047 +++ killed by SIGKILL +++ 15033 <... wait4 resumed> [{WIFSIGNALED(s) && WTERMSIG(s) == SIGKILL}], 0, NULL) = 15047 15033 --- SIGCHLD {si_signo=SIGCHLD, si_code=CLD_KILLED, si_pid=15047, si_uid=0, si_status=SIGKILL, si_utime=2, si_stime=1} ---

[Kernel-packages] [Bug 1392176] Re: mounts cgroups unconditionally which causes undesired effects with cpu hotplug

2016-01-06 Thread Serge Hallyn
No - this being moot does not apply to wily. Actually the xenial work has been delayed so it does not *yet* apply there either. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1392176 Titl

[Kernel-packages] [Bug 1392176] Re: mounts cgroups unconditionally which causes undesired effects with cpu hotplug

2016-01-06 Thread Serge Hallyn
@Sqxm - thanks for that input. For what it's worth you should be able to use ppa:serge-hallyn/systemd in xenial to get cpusets not created by default. Unfortunately I need to make some more changes (in particular to use the systemd-created cgroups when they exist) before pushing this to the archi

Re: [Kernel-packages] [Bug 1530617] Re: FUSE in wily image with upstart installed causes chaos

2016-01-06 Thread Serge Hallyn
Quoting Shimin (shi...@databricks.com): > Thanks for looking into it. Are there any downsides to disabling udev in > the container (by removing /etc/init/udev.conf for example) if we don't > need the container to be notified of new devices? hi, no this should have no downsides. You can just echo

[Kernel-packages] [Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir

2016-01-07 Thread Serge Hallyn
summary overlay: mkdir in user namespace fails if directory exists in lowerdir" ** Description changed: If a directory exists in the lowerdir but not in the mounted overlay, then mkdir of the directory in the target dir results in a mysterious -EPERM. I've seen this both in wily kernel

Re: [Kernel-packages] [Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-07 Thread Serge Hallyn
Quoting Joseph Salisbury (joseph.salisb...@canonical.com): > Can you see if this bug also happens with the latest mainline kernel? It can > be downloaded from: That is not an option, because the mainline kernel doesn't support unprivileged overlayfs mounting which is where this happens. -- You

[Kernel-packages] [Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-08 Thread Serge Hallyn
In ovl_create_over_whiteout(), the ovl_set_opaque() in the S_ISDIR() block failed. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1531747 Title: overlay: mkdir fails if directory exists

[Kernel-packages] [Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-08 Thread Serge Hallyn
The type of the underlaying file does not matter, only the type of the replacing object. So if you touch $t/dev; rm $t/dev; touch $t/dev mkdir $t/dev; rmdir $t/ev; touch $t/dev those succeed, while touch $t/dev; rm $t/dev; mkdir $t/dev mkdir $t/dev; rm $t/dev; mkdir $t/dev both fail. -- You

[Kernel-packages] [Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-08 Thread Serge Hallyn
Ok, I see. At one point we had a special case to allow the overlay code to write trusted.* xattrs for creating whiteouts. However that is gone. Therefore when overlayfs v1 (mount -t overlayfs) is mounted, root in a user namespace also is not able to rm a file which exists in the lower fs. Some

[Kernel-packages] [Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-11 Thread Serge Hallyn
#2 is probably a bit too gross - we really only need the cap for the setting of the OVL_XATTR_OPAQUE xattr in ovl_set_opaque. So we could simply override creds again there. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu.

[Kernel-packages] [Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-11 Thread Serge Hallyn
hat may not be ok for the ovl_rename2 case. What we want is for inode permissions to be checked, but only the bit in xattr_permission() checking for trusted.* to accept ns_capable. We could special-case that in xattr_permission(), but that's not particularly nice. -- You received this bug notif

Re: [Kernel-packages] [Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-12 Thread Serge Hallyn
Quoting Seth Forshee (seth.forshee...@canonical.com): > I don't know why #2 is that much grosser than what's there now. It's I didn't mean gross as in eeuw, I meant not fine-grained enough. Because the capability will apply to inode permissions checks, and we only want it to be used for the check

Re: [Kernel-packages] [Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-12 Thread Serge Hallyn
in ovl_clear_empty(), the opaque bit is set on the dir in workingdir in ovl_create_over_whiteout() (the case we're currently looking at) it is also being set in the working dir. in ovl_rename2(), it is set in two places, on the upper dentries for both the old and new. So it is never set on the l

[Kernel-packages] [Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-13 Thread Serge Hallyn
Does it require the workdir to be empty? I.e. is there a way (symlink, bind mount, something else) that a user could use a dir they own which has a child which they don't own? It looks like no, since root@w1:/tmp# mount -t overlay -o lowerdir=lower,upperdir=upper,workdir=workdir overlay /mnt ro

Re: [Kernel-packages] [Bug 1531747] Re: overlay: mkdir fails if directory exists in lowerdir in a user namespace

2016-01-14 Thread Serge Hallyn
> Something I'm still not sure about is what would happen if you made a > symlink, bind mount, etc. in upperdir with the same name as an unrelated > file in lowerdir. This is worth checking out. just tried a symlink and it didn't seem to affect the host directory (/opt/cisco) which was symlinked t

[Kernel-packages] [Bug 1536280] Re: domain shutdown fails for libvirt/lxc

2016-01-20 Thread Serge Hallyn
marking as affecting kernel given the description. ** Also affects: linux (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1536280 Titl

[Kernel-packages] [Bug 1567159] Re: Ubuntu 15.10: After hot plug vcpu, kvm_arch->use_master_clock will never be true.

2016-04-07 Thread Serge Hallyn
Thanks for reporting this bug. The 'kvm' package shouldn't really exist. The bug you're referring to is in the kernel kvm code, so I'm marking it as affecting the kernel. (If it were in the userspace qemu package, then the 'qemu' package would be the right bug target). ** Package changed: kvm (Ubu

[Kernel-packages] [Bug 1567167] Re: Ubuntu 15.10: tsc_offset is error for hot-plugged vcpu.

2016-04-07 Thread Serge Hallyn
Thanks for reporting this bug. The 'kvm' package shouldn't really exist. The bug you're referring to is in the kernel kvm code, so I'm marking it as affecting the kernel. (If it were in the userspace qemu package, then the 'qemu' package would be the right bug target). ** Package changed: kvm (

[Kernel-packages] [Bug 1446906] Re: lxc container with postfix, permission denied on mailq

2016-04-12 Thread Serge Hallyn
** Changed in: lxc (Ubuntu Xenial) Status: Confirmed => Invalid ** No longer affects: lxc (Ubuntu Vivid) ** No longer affects: lxc (Ubuntu Wily) -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchp

[Kernel-packages] [Bug 1325560] Re: kvm vm loses network connectivity under "enough" load

2014-06-03 Thread Serge Hallyn
Thanks - both of those seem to suggest there is a bug in the virtio driver in the guest kernel. Are the guests in both cases on the same release and same kernel? ** Also affects: linux (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a

[Kernel-packages] [Bug 1325560] Re: kvm virtio netdevs lose network connectivity under "enough" load

2014-06-06 Thread Serge Hallyn
** Summary changed: - kvm vm loses network connectivity under "enough" load + kvm virtio netdevs lose network connectivity under "enough" load ** Changed in: linux (Ubuntu) Importance: Undecided => High -- You received this bug notification because you are a member of Kernel Packages, which

Re: [Kernel-packages] [Bug 1218959] Re: KVM virbr# no longer forwards multicast traffic by default (U12.04)

2014-05-06 Thread Serge Hallyn
There has also been some concern about the propriety of the proposed fix (when a newer kernel with the upstream fixes should appear), in addition to lack of verifiaction - so please go ahead and supersede this if you haven't already. -- You received this bug notification because you are a member

Re: [Kernel-packages] [Bug 1322067] Re: 3.15.0-1.x breaks lxc-attach for unprivileged containers

2014-05-22 Thread Serge Hallyn
Unfortunaty the check is not a simple uid comparison, because when I use lxc-usernsexec to cat the file using the uid of root in the container, I still get EPERM. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bug

[Kernel-packages] [Bug 1322067] Re: 3.15.0-1.x breaks lxc-attach for unprivileged containers

2014-05-22 Thread Serge Hallyn
Expanding on comment #4: Otherwise we could work around it more easily in lxc. As it is, if we can't cleanly/safely allow it in the kernel, we may need to ask a new lxc command interface query to get the container's personality. -- You received this bug notification because you are a member of K

Re: [Kernel-packages] [Bug 1322067] Re: 3.15.0-1.x breaks lxc-attach for unprivileged containers

2014-05-22 Thread Serge Hallyn
Oh, yeah, I forgot we had that. That sounds good. Far preferable to having to tweak/relax the kernel constraints on reading that file. -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/13220

[Kernel-packages] [Bug 1285708] Re: FreeBSD Guest crash on boot due to xsave instruction issue

2014-06-16 Thread Serge Hallyn
Thanks for reporting this bug. Given the lkml.org fix, I assume this is in fact a kernel bug, so assigning it as such. This is presumably fix-released in utopic, but SRU-able to precise and trusty's backport kernels. I'm not clearn on how that process works, so leaving it like this. ** Also aff

[Kernel-packages] [Bug 1308341] Re: Multiple CPUs causes blue screen on Windows guest (14.04 regression)

2014-06-18 Thread Serge Hallyn
Thanks, given that info it seems clear to be a kernel and not a qemu bug. ** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** No longer affects: virt-manager (Ubuntu) -- You received this bug notification because you are a member of Kernel Packages, which is subscribe

[Kernel-packages] [Bug 1308341] Re: Multiple CPUs causes blue screen on Windows guest (14.04 regression)

2014-06-18 Thread Serge Hallyn
(Removed the task against virt-manager since hyperv is apparently *not* a safe workaround in all cases) -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1308341 Title: Multiple CPUs causes

[Kernel-packages] [Bug 1307473] Re: guest hang due to missing clock interrupt

2014-06-25 Thread Serge Hallyn
Thanks, the soft lockup message in that dmesg may be helpful. Marking as affecting the kernel. ** Also affects: linux (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. h

[Kernel-packages] [Bug 907188] Re: Asus EB1007 can't wake up from suspend when suspended using pm-suspend

2014-04-09 Thread Serge Hallyn
** Changed in: pm-utils (Ubuntu) Status: New => Invalid ** Changed in: linux (Ubuntu) Status: Incomplete => Invalid -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/907188 Tit

[Kernel-packages] [Bug 1218959] Re: KVM virbr# no longer forwards multicast traffic by default (U12.04)

2014-04-11 Thread Serge Hallyn
** Also affects: linux (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1218959 Title: KVM virbr# no longer forwards multicast traffic

[Kernel-packages] [Bug 1218959] Re: KVM virbr# no longer forwards multicast traffic by default (U12.04)

2014-04-11 Thread Serge Hallyn
I had thought that we'd need a udev rule to work around this, but looking over the fedora bug in more detail it looks like cherrypicking the two patches mentioned in comment 31 ( https://bugzilla.redhat.com/show_bug.cgi?id=880035#c31 ) should do it. Can those who are suffering from this bug please

[Kernel-packages] [Bug 1218959] Re: KVM virbr# no longer forwards multicast traffic by default (U12.04)

2014-04-14 Thread Serge Hallyn
** Description changed: A recent kernel update (Apr 2013) has made it's way to U12.04.2 LTS (approx June-Aug 2013) and has stopped the (default) behaviour of automatically forwarding multicast traffic over virbr#. Some updates the bridge subsystem now, by default, disable multicast traffi

[Kernel-packages] [Bug 1307829] Re: network namespace error

2014-04-15 Thread Serge Hallyn
** Also affects: linux (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/1307829 Title: network namespace error Status in “iproute” pac

[Kernel-packages] [Bug 1307829] Re: network namespace error

2014-04-15 Thread Serge Hallyn
So the particular files /var/run/netns/whatzit are bind-mounted /proc/self/ns/net files from a task which no longer exists, which are pinning the netns. Interestingly, if I reproduce this by hand by doing term 1: lxc-unshare -s NETWORK -- /bin/bash term 2: mkdir /var/run/netns/z; mount --bind /p

[Kernel-packages] [Bug 1307829] Re: network namespace error

2014-04-15 Thread Serge Hallyn
Ok I see the problem but am not sure what to do about it. iproute makes /var/run/netns MS_SHARED. When a container starts up, it umounts everything. So the netns bind mounts are being umounted on the host. Ideally it woudl be as simple as marking /var/run/netns MS_SLAVE before spawnign the cont

[Kernel-packages] [Bug 1309586] [NEW] enable CONFIG_MEMCG_KMEM

2014-04-18 Thread Serge Hallyn
Public bug reported: CONFIG_MEMCG_KMEM is disabled in the trusty kernel. It's the recommended way to prevent forkbombs, so if there's not a good reason to have it disabled, it would be great if that could be changed. ** Affects: linux (Ubuntu) Importance: Undecided Assignee: Tim Gardne

[Kernel-packages] [Bug 1157914] Re: time never catches up to reality after VM sleep

2014-03-11 Thread Serge Hallyn
Thanks, Barry. So IIUC this has nothing to do with qemu, so I'm switching it to linux. Is it safe to assume that other VMs - other Ubuntu releases, or other distros, or windows, do not have this behavior? ** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in:

[Kernel-packages] [Bug 1282730] Re: Suspend takes very long, more than 20mins

2014-03-12 Thread Serge Hallyn
Thanks for reporting this bug. Just to be clear - is the laptop in fact 'suspending' or 'hibernating'? Do you have this same problem if you remove the custom configuration for hybrid suspend? ** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in: pm-utils (Ub

[Kernel-packages] [Bug 997711] Re: on resume no login screen

2014-03-12 Thread Serge Hallyn
** Also affects: linux (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/997711 Title: on resume no login screen Status in “linux” pack

[Kernel-packages] [Bug 1293549] Re: Filesystem mount from lxc template causes filesystem permission breakages

2014-03-17 Thread Serge Hallyn
Thanks, that is a great reproducer. Note that doing rm -rf /etc/ssl/private mkdir /etc/ssl/private works around this, and explains why this *may* in fact be on purpose. If you only do sudo chown ubuntu:ubuntu /etc/ssl/private then the underlying directory is still owned by root and n

[Kernel-packages] [Bug 1293549] Re: Filesystem mount from lxc template causes filesystem permission breakages

2014-03-17 Thread Serge Hallyn
@Tim, is rmdir/mkdir an acceptable workaround for juju (ie can we lower priority of the bug) or will that not be doable? ** Changed in: lxc Status: New => Confirmed ** Changed in: linux (Ubuntu) Status: Incomplete => Confirmed ** Changed in: linux (Ubuntu) Importance: Undecided

[Kernel-packages] [Bug 629117] Re: Suspend failing on Dell Latitude E4310

2014-03-20 Thread Serge Hallyn
** Changed in: linux (Ubuntu) Status: Incomplete => Invalid -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux in Ubuntu. https://bugs.launchpad.net/bugs/629117 Title: Suspend failing on Dell Latitude E4310 Status in The Dell

[Kernel-packages] [Bug 575180] Re: PM: resume of drv:battery dev:PNP0C0A:00 complete after 59348.072 msecs

2014-03-20 Thread Serge Hallyn
Please reply if this is still an issue on a supported release. ** Changed in: pm-utils (Ubuntu) Status: New => Invalid ** Changed in: linux (Ubuntu) Status: Incomplete => Invalid -- You received this bug notification because you are a member of Kernel Packages, which is subscribe

[Kernel-packages] [Bug 293844] Re: rt2500pci wireless interface not functional after suspend/resume

2014-03-20 Thread Serge Hallyn
** Changed in: linux (Ubuntu) Status: Incomplete => Invalid ** Changed in: linux-backports-modules-2.6.27 (Ubuntu) Status: New => Invalid ** Changed in: pm-utils (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Kernel Package

[Kernel-packages] [Bug 1226855] Re: Cannot use open-iscsi inside LXC container

2014-03-21 Thread Serge Hallyn
** Changed in: lxc (Ubuntu) Importance: Undecided => Wishlist ** Also affects: linux (Ubuntu) Importance: Undecided Status: New ** Changed in: linux (Ubuntu) Importance: Undecided => Wishlist -- You received this bug notification because you are a member of Kernel Packages, whic

Re: [Kernel-packages] [Bug 1263738] Re: login console 0 in user namespace container is not configured right

2014-01-13 Thread Serge Hallyn
Quoting Seth Forshee (seth.forshee...@canonical.com): > I tried the kernel patch from the mailing list, but that doesn't fix the > problem. It does fix permissions for most /proc/pid/* files in setuid > processes, but the console problems remain. That's interesting! Thanks for testing. -- You r

Re: [Kernel-packages] [Bug 1263738] Re: login console 0 in user namespace container is not configured right

2014-01-14 Thread Serge Hallyn
Quoting Seth Forshee (seth.forshee...@canonical.com): > stderr actually is mapped to a pty. The problem seems to be that getty > can't set /dev/console as its controlling terminal because it's already > the controlling tty for init, which is in a different process group. > Thus getty ends up with n

  1   2   3   4   >