/srv/irclogs.ubuntu.com/2014/08/15/#ubuntu-kernel.txt

=== cmagina_ is now known as cmagina
=== Mikee_C_afk is now known as Mikee_C
apwhallyn, bug 1357025, looks like we lost a patch on rebase to v3.16, i've repplied it and am dumping test kernels in the bug shortly12:51
ubot5bug 1357025 in linux (Ubuntu) "unprivileged overlayfs mounts no longer work in utopic" [Medium,Confirmed] https://launchpad.net/bugs/135702512:51
rtgapw, which one ?12:52
apwUBUNTU: SAUCE: Overlayfs: allow unprivileged mounts12:53
apwrtg, ^12:53
rtghmm, that isn't in my dropped file12:53
apwyou probababally just said "overlayfs is dropped" as a whole ?12:54
rtgapw, could be12:54
apwcollateral dammage from that, if the test existed (which it will soon) it owuld have been cought before it left CKT PPA but ... hey12:56
hallynapw: cool, thanks13:01
hallynapw: test case has been submitted to lxc upstream, it may make it into the utopic yet13:01
apwhallyn, ok there are test kernels up, if you could get them verified "soon" then we have an upload planned for today13:02
apwwhich i would like to see it in13:02
hallynwill do, thx13:05
hallynapw: fixed13:14
apwhallyn, thanks for the confirmation, confidence was high13:14
=== willcooke_ is now known as willcooke
=== hatch__ is now known as hatch
=== cyphermox__ is now known as cyphermox
dannfrtg: http://paste.ubuntu.com/8054904/16:14
dannfrtg: i'll update to those regex's - let me know if there's any other tests you'd like me to add16:15
rtgdannf, I've never used extended regex's. I may have to find a new book :)16:15
rtgdannf,  those look like sufficient tests16:17
dannfack. will send out a patch after a test build16:17
=== cmagina_ is now known as cmagina
=== Mikee_C is now known as Mikee_C_afk
=== cyphermox_ is now known as cyphermox
apwrtg, i sometimes wonder if we should just add .0 in the middle there for this purpose17:51
apwrtg, indeed i wonder what would happen if we just used like -Nr0.U and people rev'd r17:52
apwsomething to chew on17:52
rtgapw, so, what would that do for us (the distro) besides making the version even _more_ complicated ?18:18
rtgdannf, I just accidentally moderated your emails out of existence. maybe you should just subscribe ?18:43
dannfrtg: i'm on ubuntu-kernel18:44
dannfer kernel-team18:44
rtgdannf, this was the private list I moderated18:44
dannfoh - i assumed that was an organizational list 18:45
hallynsforshee: just to be sure, nothing you've done with fuse+userns would break if fuse mounts requred MS_DEV?20:13
hallynuh, MS_NODEV20:13
=== chiluk` is now known as chiluk
sforsheehallyn: I'm thinking that I required MS_NODEV for fuse+userns mounts, but I'd have to go back and look20:15
hallyncool, long as there's nothing wher eyou'd have needed NOT specifying MS_NODEV :)  (which would be ridiculous, i think)20:16
hallynthanks20:16
sforsheehallyn: yeah, I didn't set FS_USERNS_DEV_MOUNT which means that any userns mounts get NODEV20:16
hallynnot for long :)20:17
sforsheeare you referring to that cve fix?20:17
sforsheehallyn: either way, I think letting a userns+fuse mount contain devices would be a big problem20:19
hallynsforshee: i'm referring to a patch by Andy L. reverting part of Eric's patch20:21
hallyn(not sure if that's the cve fix you mean)20:22
sforsheehallyn: yeah, I'm talking about the one from eric. Do you have a link to the revert?20:22
hallynsforshee: http://lkml.org/lkml/2014/8/13/74620:23
sforsheehallyn: that's still okay then. Instead of an implicit NODEV the mount just fails.20:24
hallynright20:25
sforsheehallyn: does that impact our overlayfs support?20:27
hallynsforshee: hm.  it might20:27
hallynbut if it does then lxc should simply add the nodev option 20:28
hallynthe new lxc-test-unpriv extension should catch it if it does20:28
sforsheeright, something to look out for when we pick up that patch20:28
stgraberhmm, so the latest kernel security update for the 3.13 kernel breaks LXC22:45
stgraber(well, nested unprivileged containers specifically)22:46
hallynstgraber: http://lkml.org/lkml/2014/8/13/746 will be the patch to fix it22:48
hallyncan you test-build a kernel?22:48
hallynapw: I assume the quickest we could get http://lkml.org/lkml/2014/8/13/746 into a build is 3 weeks?22:49
stgraberwe obviously have two talks lined up at LinuxCon/Linux Security Summit next week which both demo nested unprivileged containers on Ubuntu... so looks like we'll need custom patched kernels or tweaked LXC which means people following those talks won't be able to reproduce what we show them...22:51
stgraberhallyn, apw: filed bug 135758823:22
ubot5bug 1357588 in linux (Ubuntu) "3.13.0-24 broke nested unprivileged LXC" [Undecided,New] https://launchpad.net/bugs/135758823:22
stgraberand tagged as a regression in an udpate23:22
stgraber*update23:23

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!