/srv/irclogs.ubuntu.com/2017/12/27/#ubuntu-devel.txt

JackFrostA wild Faux!00:00
JackFrostHello.00:00
FauxHello.00:01
JackFrost(I'm Unit193.)00:01
FauxI guessed, from the whois.00:01
tsimonq2JackFrost: I thought you were a GCI student, to be honest. Heh.00:08
stgraberjjohansen: hmm, if the check isn't ns_capable() then it would always fail inside an unprivileged container00:25
stgraberjjohansen: and would always succeed inside a privileged container (as we don't drop whatever caps it's looking for)00:26
stgraberjjohansen: unless it's an unpriv container which is spawned through a binary that's got an fscap added, then indeed the sysctl would block that :)00:26
jjohansenright, but seccomp uses its own mechanism, and so do some of the other users00:38
jjohansenof ebpf00:38
JackFrostA code browser would be useful enough as it is, such that one doesn't have to download the package just to check something quickly.00:39
jjohansenwhich actually is concerning in that, we need to check these as well and the sysctl mitigation may not be sufficient00:39
stgraberyeah, at least seccomp should be fine as it's not full on ebpf, it's a much more restricted subset of bpf00:40
stgraberI have no idea what iptables and others do00:40
stgraberbut since they don't have a long lasting process to attach the program to, they clearly have some other mechanism to deal with this00:41
stgraberso long as we don't break seccomp with this (and lool's testing suggests we aren't), we should be fine00:41
stgraberand since it's a sysctl, someone can always flip it back if it's critical for their operation00:41
stgraberthough not sure how that'd play with livepatch :)00:41
wxlypwong: just got a new HP Envy and it appears to have an Insyde BIOS, so potentially liable to the whole intel_spi bug. Is there any way I can help with testing that won't necessarily brick my device (forever)? :)00:44
jjohansenright, the sysctl looks like it isn't going to break too much, so it works as a mitigation until we can get the larger change out00:45
jjohansenwe just wanted you to be aware we were flipping it as LXD was one of the places where we figured problems might surface00:46
stgraberyep, thanks for the heads up00:52
ypwongwxl, i am afraid not... yet01:32
wxlypwong: ok, well i dedicate my machine to the cause, should you need a tester :)01:32
ypwongwxl, that's great! Thanks for the offer. Will loop you in when we have something reliable to be tested :)01:33
wxlsounds good :)01:34
tsimonq2ypwong: I know it may be a lot to ask right now given the holidays (Happy Holidays, btw!) but is there a timeline at all? (If not, what's the current status of getting that fixed?)01:36
ypwongtsimonq2, although it's holiday but Mika from Intel and I have been trying out to recover the bios from ubuntu, we have something that works sometimes but since it doesn't work always we are afraid there will be risks in breaking other things.01:43
tsimonq2ypwong: Alright01:45
tsimonq2ypwong: Keep us updated, and many thanks to everyone that's been involved in dealing with this!01:45
wxl+101:45
tsimonq2s/dealing with this/getting this solved/01:46
wxlypwong: is there a definitive way i can determine whether or not this particular insyde bios is affected? from what i read in the bug report, it wasn't entirely clear that it was a problem with the BIOS manufacturer or the chip manufacturer.04:42
ypwongwxl, yeah, we are also not sure yet, i just starting talking to insyde to find out more04:42
wxlypwong: ok. i'll leave you alone some more XD04:43
ypwong:)04:49
=== capadesu_ is now known as capadesu
=== capadesu is now known as capadesu_
=== capadesu_ is now known as capadesu
Fraciao20:18
Fra!list20:18
ubottuFra: No warez here! This is not a file sharing channel (or network); read the channel topic. If you're looking for information about me, type « /msg ubottu !bot ». If you're looking for a channel, see « /msg ubottu !alis ».20:18

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!