/srv/irclogs.ubuntu.com/2018/02/19/#ubuntu-kernel.txt

=== himcesjf_ is now known as him-cesjf
=== zyga_ is now known as zyga
hallynjsalisbury: https://wiki.ubuntu.com/Kernel/   points to https://wiki.ubuntu.com/Kernel/Release , which does not exist19:38
hallynhm, lxd network under hwe kernel on xenial seems busted?19:54
hallynmaybe i messed up something else, still comparing...19:54
hallynjjohansen: running linux-generic-hwe-16.04 on a xenial host.  it doesn't have the apparmor stacking fix?20:27
hallynis there a scheduled release of thatkernel with that fix?20:28
hallyndo i have to wait until august?20:32
hallynoh should i use -edge?20:34
* hallyn tries20:36
hallynprolly living on the edge at this point20:37
hallynno even that doesn't fix it.20:54
hallynjjohansen: stgraber: do you know of a list that woudl show which kernels for xenial would have the apparmor ns fix ? 20:55
hallynlooking for that plus namespaced filecaps (else i'd just stick with 4.4)20:55
hallyni'm surprised hwe-16.04-edge doesn't work20:55
stgraberoh right, you're hitting the broken ns support because of empty label thing again20:55
hallynright.  is that fix only going into artful and bionic?20:56
stgraberit should go everywhere once it finally lands...20:58
stgraberwant the ugly workaround until then?20:58
stgraberecho lxd-$(hostname) > /root/ns20:59
stgrabermount --bind /root/ns /sys/kernel/security/apparmor/.ns_name20:59
stgrabersystemctl restart apparmor20:59
stgraberhallyn: ^ I said it's ugly :)20:59
TJ-wow! thanks stgraber I have been wondering about that one as well21:03
hallynstgraber: I'm wondering when "whenit finally lands" will be :)21:07
hallynhm, what would be the easiest way to automated that.21:08
hallyni guess a systemd service in the images :(21:08
hallynthanks stgraber i guess i'll go that route :)21:09
jjohansenhallyn: hrmmm, I'll have to dig, I did send the fix to the kt22:30
hallynjjohansen: thx, here's hoping it goes in soon :)22:38
hallynfor now i've just updated the lxd images to add a startup job with stgraber's fix22:38
jjohansenhallyn: it seems to have been dropped, probably in one of the many rebases during the whole spectre/meltdown mess22:46
jjohansenI will resend22:46
hallyncool, thanks22:48

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!