]> git.ipfire.org Git - thirdparty/lxc.git/log
thirdparty/lxc.git
8 years agoalpine: Fix installing extra packages 1240/head
roedie [Tue, 18 Oct 2016 14:55:16 +0000 (16:55 +0200)] 
alpine: Fix installing extra packages
Signed-off-by: Sander Klein <github@roedie.nl>
8 years agoMerge pull request #1234 from brauner/2016-10-14/better_errors_for_lxc_start
Serge Hallyn [Tue, 18 Oct 2016 14:49:29 +0000 (09:49 -0500)] 
Merge pull request #1234 from brauner/2016-10-14/better_errors_for_lxc_start

tools: better error reporting for lxc-start

8 years agotools: better error reporting for lxc-start 1234/head
Christian Brauner [Fri, 14 Oct 2016 13:27:24 +0000 (15:27 +0200)] 
tools: better error reporting for lxc-start

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agoMerge pull request #1233 from brauner/2016-10-14/allow_overlay
Stéphane Graber [Fri, 14 Oct 2016 16:31:18 +0000 (12:31 -0400)] 
Merge pull request #1233 from brauner/2016-10-14/allow_overlay

tools: make overlay a valid backend for lxc-copy

8 years agoMerge pull request #1235 from Dean4Devil/master
Stéphane Graber [Fri, 14 Oct 2016 16:30:42 +0000 (12:30 -0400)] 
Merge pull request #1235 from Dean4Devil/master

Add voidlinux distribution

8 years agoAdd voidlinux distribution 1235/head
Gregor Reitzenstein [Fri, 14 Oct 2016 11:06:29 +0000 (13:06 +0200)] 
Add voidlinux distribution

Signed-off-by: Gregor Reitzenstein <dean4devil@paranoidlabs.org>
8 years agotools: make overlay valid backend 1233/head
Christian Brauner [Fri, 14 Oct 2016 12:20:41 +0000 (14:20 +0200)] 
tools: make overlay valid backend

So far, users could only create overlay snapshots by specifying -B overlayfs
and not with -B overlay. This adds support for -B overlay.

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agotools: fix coding style in lxc_attach
Christian Brauner [Fri, 14 Oct 2016 12:20:16 +0000 (14:20 +0200)] 
tools: fix coding style in lxc_attach

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agoMerge pull request #1232 from Cypresslin/fix-s390x-download
Christian Brauner [Fri, 14 Oct 2016 09:05:01 +0000 (11:05 +0200)] 
Merge pull request #1232 from Cypresslin/fix-s390x-download

tests: fix image download for s390x

8 years agotests: fix image download for s390x 1232/head
Po-Hsu Lin [Fri, 14 Oct 2016 08:17:30 +0000 (16:17 +0800)] 
tests: fix image download for s390x

Make release selection more flexible.
Update the KNOWN_RELEAES list, add yakkety and remove vivid.

Signed-off-by: Po-Hsu Lin <po-hsu.lin@canonical.com>
8 years agoMerge pull request #1230 from Jafaral/master
Stéphane Graber [Thu, 13 Oct 2016 23:57:30 +0000 (19:57 -0400)] 
Merge pull request #1230 from Jafaral/master

Drop leftover references to lxc_strerror().

8 years agoDrop leftover references to lxc_strerror(). 1230/head
Jafar Al-Gharaibeh [Thu, 13 Oct 2016 23:35:29 +0000 (18:35 -0500)] 
Drop leftover references to lxc_strerror().

lxc_strerror() was dropped long time ago, in 2009 to be exact.

Related commit:
https://github.com/lxc/lxc/commit/7cee8789514fb42d6a48d50b904e24284f5526e3

Signed-off-by: Jafar Al-Gharaibeh <to.jafar@gmail.com>
8 years agoMerge pull request #1229 from stgraber/master
Serge Hallyn [Thu, 13 Oct 2016 19:15:44 +0000 (14:15 -0500)] 
Merge pull request #1229 from stgraber/master

archlinux: Fix resolving

8 years agoarchlinux: Fix resolving 1229/head
Stéphane Graber [Thu, 13 Oct 2016 19:02:56 +0000 (15:02 -0400)] 
archlinux: Fix resolving

Signed-off-by: Stéphane Graber <stgraber@ubuntu.com>
8 years agoMerge pull request #1228 from stgraber/master
Serge Hallyn [Thu, 13 Oct 2016 18:38:35 +0000 (13:38 -0500)] 
Merge pull request #1228 from stgraber/master

archlinux: Do DHCP on eth0

8 years agoarchlinux: Do DHCP on eth0 1228/head
Stéphane Graber [Thu, 13 Oct 2016 18:32:03 +0000 (14:32 -0400)] 
archlinux: Do DHCP on eth0

Signed-off-by: Stéphane Graber <stgraber@ubuntu.com>
8 years agoMerge pull request #1226 from jirutka/alpine-shm
Christian Brauner [Wed, 12 Oct 2016 11:49:32 +0000 (13:49 +0200)] 
Merge pull request #1226 from jirutka/alpine-shm

lxc-alpine: mount /dev/shm as tmpfs

8 years agolxc-alpine: mount /dev/shm as tmpfs 1226/head
Jakub Jirutka [Wed, 12 Oct 2016 11:32:18 +0000 (13:32 +0200)] 
lxc-alpine: mount /dev/shm as tmpfs

Signed-off-by: Jakub Jirutka <jakub@jirutka.cz>
8 years agoMerge pull request #1225 from jiazhang0/master
Christian Brauner [Wed, 12 Oct 2016 09:49:57 +0000 (11:49 +0200)] 
Merge pull request #1225 from jiazhang0/master

log: sanity check the returned value from snprintf()

8 years agolog: sanity check the returned value from snprintf() 1225/head
Lans Zhang [Mon, 10 Oct 2016 13:49:55 +0000 (21:49 +0800)] 
log: sanity check the returned value from snprintf()

The returned value from snprintf() should be checked carefully.

This bug can be leveraged to execute arbitrary code through carefully
constructing the payload, e.g,

lxc-freeze -n `python -c "print 'AAAAAAAA' + 'B'*959"` -P PADPAD -o /tmp/log

This command running on Ubuntu 14.04 (x86-64) can cause a segment fault.

Signed-off-by: Lans Zhang <jia.zhang@windriver.com>
8 years agoMerge pull request #1224 from evgeni/python-utf8
Christian Brauner [Sat, 8 Oct 2016 17:18:17 +0000 (19:18 +0200)] 
Merge pull request #1224 from evgeni/python-utf8

mark the python examples as having utf-8 encoding

8 years agomark the python examples as having utf-8 encoding 1224/head
Evgeni Golov [Sat, 8 Oct 2016 16:29:30 +0000 (18:29 +0200)] 
mark the python examples as having utf-8 encoding

this allows running them also under Python2, which otherwise
would choke on Stéphane's name and error out with
 SyntaxError: Non-ASCII character '\xc3' in file …

Signed-off-by: Evgeni Golov <evgeni@debian.org>
8 years agoMerge pull request #1223 from evgeni/unit-doc
Christian Brauner [Sat, 8 Oct 2016 13:02:03 +0000 (15:02 +0200)] 
Merge pull request #1223 from evgeni/unit-doc

add Documentation entries to lxc and lxc@ units

8 years agoadd Documentation entries to lxc and lxc@ units 1223/head
Evgeni Golov [Sat, 8 Oct 2016 12:08:21 +0000 (14:08 +0200)] 
add Documentation entries to lxc and lxc@ units

Signed-off-by: Evgeni Golov <evgeni@debian.org>
8 years agoMerge pull request #1171 from brauner/2016-09-06/detect_ramfs_rootfs
Serge Hallyn [Thu, 6 Oct 2016 13:34:16 +0000 (08:34 -0500)] 
Merge pull request #1171 from brauner/2016-09-06/detect_ramfs_rootfs

improve detect_ramfs_rootfs() and add test

8 years agoMerge pull request #1217 from brauner/2016-09-29/lxc_checkconfig
Stéphane Graber [Wed, 5 Oct 2016 08:16:51 +0000 (04:16 -0400)] 
Merge pull request #1217 from brauner/2016-09-29/lxc_checkconfig

tools: lxc-checkconfig conditionalize devpts check

8 years agoMerge pull request #1221 from stgraber/master
Christian Brauner [Tue, 4 Oct 2016 17:12:55 +0000 (19:12 +0200)] 
Merge pull request #1221 from stgraber/master

Define LXC_DEVEL to detect development releases

8 years agoDefine LXC_DEVEL to detect development releases 1221/head
Stéphane Graber [Tue, 4 Oct 2016 16:31:29 +0000 (18:31 +0200)] 
Define LXC_DEVEL to detect development releases

This can be used by downstreams to improve their "feature" checks.

Signed-off-by: Stéphane Graber <stgraber@ubuntu.com>
8 years agotools: lxc-checkconfig conditionalize devpts check 1217/head
Christian Brauner [Thu, 29 Sep 2016 08:44:09 +0000 (10:44 +0200)] 
tools: lxc-checkconfig conditionalize devpts check

Only check for DEVPTS_MULTIPLE_INSTANCES on kernels < 4.7.

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agoMerge pull request #1214 from roman-mueller/fix_centos_spelling
Christian Brauner [Wed, 28 Sep 2016 09:15:53 +0000 (11:15 +0200)] 
Merge pull request #1214 from roman-mueller/fix_centos_spelling

Fix spelling of CentOS in the templates

8 years agoFix spelling of CentOS in the templates 1214/head
Roman Mueller [Wed, 28 Sep 2016 08:03:39 +0000 (10:03 +0200)] 
Fix spelling of CentOS in the templates

Signed-off-by: Roman Mueller <roman.mueller@gmail.com>
8 years agotests: add test for detect_ramfs_rootfs() 1171/head
Christian Brauner [Tue, 6 Sep 2016 12:51:01 +0000 (14:51 +0200)] 
tests: add test for detect_ramfs_rootfs()

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agoutils: make detect_ramfs_rootfs() return bool
Christian Brauner [Tue, 6 Sep 2016 11:49:13 +0000 (13:49 +0200)] 
utils: make detect_ramfs_rootfs() return bool

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agoMerge pull request #1212 from brauner/2016-09-26/fix_lxc_deslashify
Stéphane Graber [Tue, 27 Sep 2016 00:38:37 +0000 (20:38 -0400)] 
Merge pull request #1212 from brauner/2016-09-26/fix_lxc_deslashify

utils: lxc_deslashify() free memory

8 years agoutils: lxc_deslashify() free memory 1212/head
Christian Brauner [Mon, 26 Sep 2016 20:05:54 +0000 (22:05 +0200)] 
utils: lxc_deslashify() free memory

Make sure we always free any memory that was allocated by the call to
lxc_normalize_path().

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agoMerge pull request #1209 from brauner/2016-09-25/lxc_deslashify
Stéphane Graber [Mon, 26 Sep 2016 20:00:40 +0000 (16:00 -0400)] 
Merge pull request #1209 from brauner/2016-09-25/lxc_deslashify

2016 09 25/lxc deslashify

8 years agoMerge pull request #1210 from d4s/altlinux-fix
Christian Brauner [Mon, 26 Sep 2016 18:42:50 +0000 (20:42 +0200)] 
Merge pull request #1210 from d4s/altlinux-fix

Fix for ALTLinux container creation in all branches

8 years agoFix for ALTLinux container creation in all branches 1210/head
Denis Pynkin [Mon, 26 Sep 2016 17:49:47 +0000 (20:49 +0300)] 
Fix for ALTLinux container creation in all branches

Use 'apt-conf' virtual package for ALTLinux default packages set

Signed-off-by: Denis Pynkin <denis_pynkin@epam.com>
8 years agotests: add unit tests for lxc_deslashify() 1209/head
Christian Brauner [Sun, 25 Sep 2016 21:57:43 +0000 (23:57 +0200)] 
tests: add unit tests for lxc_deslashify()

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agotools: lxc_deslashify() handle special cases
Christian Brauner [Sun, 25 Sep 2016 21:57:13 +0000 (23:57 +0200)] 
tools: lxc_deslashify() handle special cases

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agoMerge pull request #1207 from brauner/2016-09-25/fix_lxc_string_split
Stéphane Graber [Sun, 25 Sep 2016 18:45:22 +0000 (14:45 -0400)] 
Merge pull request #1207 from brauner/2016-09-25/fix_lxc_string_split

utils: fix lxc_string_split()

8 years agoutils: fix lxc_string_split() 1207/head
Christian Brauner [Sun, 25 Sep 2016 14:51:24 +0000 (16:51 +0200)] 
utils: fix lxc_string_split()

Make sure we don't return uninitialized memory.

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agoMerge pull request #1206 from cwoac/master
Christian Brauner [Sun, 25 Sep 2016 09:22:21 +0000 (11:22 +0200)] 
Merge pull request #1206 from cwoac/master

Fix null derefence if attach is called without access to any tty

8 years agoFix null derefence if attach is called without access to any tty 1206/head
Oliver Matthews [Sun, 25 Sep 2016 08:37:43 +0000 (09:37 +0100)] 
Fix null derefence if attach is called without access to any tty

Signed-off-by: Oliver Matthews <oliver@codersoffortune.net>
8 years agoMerge pull request #1204 from tych0/close-tty-on-restore
Christian Brauner [Wed, 21 Sep 2016 22:08:14 +0000 (00:08 +0200)] 
Merge pull request #1204 from tych0/close-tty-on-restore

c/r: detatch from controlling tty on restore

8 years agoc/r: detatch from controlling tty on restore 1204/head
Tycho Andersen [Wed, 21 Sep 2016 21:45:49 +0000 (21:45 +0000)] 
c/r: detatch from controlling tty on restore

Signed-off-by: Tycho Andersen <tycho.andersen@canonical.com>
8 years agoMerge pull request #1201 from brauner/2016-09-21/lxc_ls_no_spaces
Stéphane Graber [Wed, 21 Sep 2016 19:34:34 +0000 (15:34 -0400)] 
Merge pull request #1201 from brauner/2016-09-21/lxc_ls_no_spaces

tools: do not add trailing spaces on lxc-ls -1

8 years agoMerge pull request #1202 from brauner/2016-09-21/lxc_attach_no_new_priv_fix
Stéphane Graber [Wed, 21 Sep 2016 19:33:45 +0000 (15:33 -0400)] 
Merge pull request #1202 from brauner/2016-09-21/lxc_attach_no_new_priv_fix

tools: fix lxc-attach regression with -s USER

8 years agoMerge pull request #1203 from brauner/2016-09-21/retrieve_mtu_from_bridge
Stéphane Graber [Wed, 21 Sep 2016 19:32:00 +0000 (15:32 -0400)] 
Merge pull request #1203 from brauner/2016-09-21/retrieve_mtu_from_bridge

2016 09 21/retrieve mtu from bridge

8 years agoconf: try to retrieve mtu from veth 1203/head
Christian Brauner [Wed, 21 Sep 2016 19:07:24 +0000 (21:07 +0200)] 
conf: try to retrieve mtu from veth

When the mtu cannot be retrieved from netdev->link try from veth device.

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agoconf: retrieve mtu from netdev->link
Christian Brauner [Wed, 21 Sep 2016 18:56:03 +0000 (20:56 +0200)] 
conf: retrieve mtu from netdev->link

When mtu is not set, try to retrieve mtu from netdev->link.

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agotools: fix lxc-attach regression with -s USER 1202/head
Christian Brauner [Wed, 21 Sep 2016 11:02:08 +0000 (13:02 +0200)] 
tools: fix lxc-attach regression with -s USER

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agotools: do not add trailing spaces on lxc-ls -1 1201/head
Christian Brauner [Wed, 21 Sep 2016 07:15:14 +0000 (09:15 +0200)] 
tools: do not add trailing spaces on lxc-ls -1

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agoMerge pull request #1197 from ysbnim/master
Christian Brauner [Tue, 20 Sep 2016 09:35:53 +0000 (11:35 +0200)] 
Merge pull request #1197 from ysbnim/master

Update Korean manuals

8 years agodoc: Add lxc.no_new_privs to Korean lxc.container.conf(5) 1197/head
Sungbae Yoo [Tue, 20 Sep 2016 09:10:33 +0000 (18:10 +0900)] 
doc: Add lxc.no_new_privs to Korean lxc.container.conf(5)

Update for commit 222ddc

Signed-off-by: Sungbae Yoo <sungbae.yoo@samsung.com>
8 years agoMerge pull request #1194 from tych0/cgroup-root-on-dump
Stéphane Graber [Sat, 17 Sep 2016 03:20:10 +0000 (23:20 -0400)] 
Merge pull request #1194 from tych0/cgroup-root-on-dump

Cgroup root on dump

8 years agoc/r: check that cgroup_num_hierarchies > 0 1194/head
Tycho Andersen [Sat, 17 Sep 2016 02:26:31 +0000 (20:26 -0600)] 
c/r: check that cgroup_num_hierarchies > 0

Otherwise in the error case, we end up subtracting two from the
static_args, which would lead to a segfault :)

Signed-off-by: Tycho Andersen <tycho.andersen@canonical.com>
8 years agocgroup: drop cgroup_canonical_path
Tycho Andersen [Wed, 14 Sep 2016 14:58:38 +0000 (14:58 +0000)] 
cgroup: drop cgroup_canonical_path

This is almost never the right thing to use, and we don't use it any more
anyway.

Signed-off-by: Tycho Andersen <tycho.andersen@canonical.com>
8 years agocgroup: get rid of weird hack in cgfsng_escape
Tycho Andersen [Wed, 14 Sep 2016 14:53:21 +0000 (14:53 +0000)] 
cgroup: get rid of weird hack in cgfsng_escape

We initialized cgfsng in a strange way inside of its implementation of
escape so we could use it during checkpoint. Instead, the previous patch
does a hacky initialization in criu.c, and we can get rid of the hacks
elsewhere :)

Signed-off-by: Tycho Andersen <tycho.andersen@canonical.com>
8 years agoc/r: pass --cgroup-roots on checkpoint
Tycho Andersen [Wed, 14 Sep 2016 14:47:38 +0000 (14:47 +0000)] 
c/r: pass --cgroup-roots on checkpoint

CRIU has added support for passing --cgroup-root on dump, which we should
use (see the criu commit 07d259f365f224b32914de26ea0fd59fc6db0001 for
details). Note that we don't have to do any version checking or anything,
because CRIU just ignored --cgroup-root on checkpoint before, so passing it
is safe, and will result in correct behavior when a sufficient version of
CRIU is present.

Signed-off-by: Tycho Andersen <tycho.andersen@canonical.com>
8 years agoutils: add lxc_deslashify
Tycho Andersen [Wed, 14 Sep 2016 14:46:47 +0000 (14:46 +0000)] 
utils: add lxc_deslashify

Signed-off-by: Tycho Andersen <tycho.andersen@canonical.com>
8 years agocgroup: add new functions for interacting with hierachies
Tycho Andersen [Wed, 14 Sep 2016 14:38:46 +0000 (14:38 +0000)] 
cgroup: add new functions for interacting with hierachies

N.B. that these are only implemented in cgfsng, but,

15:28:28    tych0 | do we still use cgfs anywhere? or the cgm backend?
15:29:19 stgraber | not anywhere we care about

...I think that's okay.

Signed-off-by: Tycho Andersen <tycho.andersen@canonical.com>
8 years agoc/r: fix typo in comment
Tycho Andersen [Mon, 12 Sep 2016 18:04:18 +0000 (18:04 +0000)] 
c/r: fix typo in comment

Signed-off-by: Tycho Andersen <tycho.andersen@canonical.com>
8 years agoMerge pull request #1193 from hallyn/2016-09-16/thierry
Stéphane Graber [Fri, 16 Sep 2016 17:35:42 +0000 (13:35 -0400)] 
Merge pull request #1193 from hallyn/2016-09-16/thierry

lxc-create -t debian fails on ppc64el arch

8 years agolxc-create -t debian fails on ppc64el arch 1193/head
Thierry Fauck [Fri, 16 Sep 2016 13:34:41 +0000 (08:34 -0500)] 
lxc-create -t debian fails on ppc64el arch

Template catches arch from uname -m, but for ppc64el system, arch reports ppc64le
which doesn't match image repo.

Signed-off-by: Thierry Fauck <tfauck@free.fr>
Signed-off-by: Serge Hallyn <serge@hallyn.com>
8 years agoMerge pull request #1192 from tenforward/japanese
Christian Brauner [Fri, 16 Sep 2016 07:18:45 +0000 (09:18 +0200)] 
Merge pull request #1192 from tenforward/japanese

doc: Add lxc.no_new_privs to Japanese lxc.container.conf(5)

8 years agodoc: Add lxc.no_new_privs to Japanese lxc.container.conf(5) 1192/head
KATOH Yasufumi [Fri, 16 Sep 2016 06:56:45 +0000 (15:56 +0900)] 
doc: Add lxc.no_new_privs to Japanese lxc.container.conf(5)

Update for commit 222ddc

Signed-off-by: KATOH Yasufumi <karma@jazz.email.ne.jp>
8 years agoMerge pull request #1166 from brauner/2016-09-02/no_new_privileges
Serge Hallyn [Fri, 16 Sep 2016 01:35:21 +0000 (20:35 -0500)] 
Merge pull request #1166 from brauner/2016-09-02/no_new_privileges

implement PR_SET_NO_NEW_PRIVS in liblxc

8 years agoMerge pull request #1187 from lpirl/master
Stéphane Graber [Wed, 14 Sep 2016 17:02:43 +0000 (13:02 -0400)] 
Merge pull request #1187 from lpirl/master

make rsync deal with sparse files efficiently

8 years agomake rsync deal with sparse files efficiently 1187/head
Lukas Pirl [Wed, 14 Sep 2016 15:40:16 +0000 (17:40 +0200)] 
make rsync deal with sparse files efficiently

Signed-off-by: Lukas Pirl <git@lukas-pirl.de>
8 years agoMerge pull request #1185 from tych0/free-valid-opts-if-necessary
Christian Brauner [Tue, 13 Sep 2016 23:16:57 +0000 (01:16 +0200)] 
Merge pull request #1185 from tych0/free-valid-opts-if-necessary

c/r: free valid_opts if necessary

8 years agoc/r: free valid_opts if necessary 1185/head
Tycho Andersen [Tue, 13 Sep 2016 22:42:20 +0000 (16:42 -0600)] 
c/r: free valid_opts if necessary

2cb80427bc468f7647309c3eca66cfc9afa85b61 introduced a malloc without a
matching free.

Signed-off-by: Tycho Andersen <tycho.andersen@canonical.com>
8 years agoMerge pull request #1184 from brauner/2016-09-13/zfs_fixes
Stéphane Graber [Tue, 13 Sep 2016 16:23:44 +0000 (12:23 -0400)] 
Merge pull request #1184 from brauner/2016-09-13/zfs_fixes

lxczfs: small fixes

8 years agolxczfs: small fixes 1184/head
Christian Brauner [Tue, 13 Sep 2016 15:18:23 +0000 (17:18 +0200)] 
lxczfs: small fixes

- We expect destroy to fail in zfs_clone() so try to silence it so users are
  not irritated when they create zfs snapshots.
- Add -r recursive to zfs_destroy(). This code is only hit when a) the
  container has no snapshots or b) the user calls destroy with snapshots. So
  this should be safe. Without -r snapshots will remain.

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agoMerge pull request #1177 from tych0/zero-smaller-migrate-struct
Christian Brauner [Thu, 8 Sep 2016 18:52:52 +0000 (20:52 +0200)] 
Merge pull request #1177 from tych0/zero-smaller-migrate-struct

c/r: zero a smaller than known migrate_opts struct

8 years agoc/r: zero a smaller than known migrate_opts struct 1177/head
Tycho Andersen [Thu, 8 Sep 2016 15:14:42 +0000 (09:14 -0600)] 
c/r: zero a smaller than known migrate_opts struct

Signed-off-by: Tycho Andersen <tycho.andersen@canonical.com>
8 years agoMerge pull request #1173 from melato/alpine-cron-v2
Christian Brauner [Tue, 6 Sep 2016 14:15:44 +0000 (16:15 +0200)] 
Merge pull request #1173 from melato/alpine-cron-v2

templates: use correct cron version in alpine template

8 years agotemplates: use correct cron version in alpine template 1173/head
Alex Athanasopoulos [Tue, 6 Sep 2016 14:09:55 +0000 (17:09 +0300)] 
templates: use correct cron version in alpine template

Signed-off-by: Alex Athanasopoulos <alex@melato.org>
8 years agotests: add test for PR_SET_NO_NEW_PRIVS 1166/head
Christian Brauner [Sat, 3 Sep 2016 11:59:47 +0000 (13:59 +0200)] 
tests: add test for PR_SET_NO_NEW_PRIVS

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agoattach, start: declare PR_{S,G}PR_GET_NO_NEW_PRIVS
Christian Brauner [Sat, 3 Sep 2016 13:19:27 +0000 (15:19 +0200)] 
attach, start: declare PR_{S,G}PR_GET_NO_NEW_PRIVS

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agodoc: add lxc.no_new_privs to lxc.container.conf
Christian Brauner [Sat, 3 Sep 2016 06:00:20 +0000 (08:00 +0200)] 
doc: add lxc.no_new_privs to lxc.container.conf

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agoattach: use PR_SET_NO_NEW_PRIVS
Christian Brauner [Fri, 2 Sep 2016 16:56:48 +0000 (18:56 +0200)] 
attach: use PR_SET_NO_NEW_PRIVS

- When we detect that the container, we want to attach to, has been stared with
  PR_SET_NO_NEW_PRIVS we attach with PR_SET_NO_NEW_PRIVS as well. (We might
  relax this restriction later but let's be strict for now.)
- When LXC_ATTACH_NO_NEW_PRIVS is set in the flags passed to
  lxc_attach()/attach_child_main() then we set PR_SET_NO_NEW_PRIVS irrespective
  of whether the container was started with PR_SET_NO_NEW_PRIVS or not.
- Set no_new_privs before lsm and seccomp. We probably don't want attach() to
  be able to change the lsm or seccomp policy if the container was started with
  PR_SET_NO_NEW_PRIVS enabled.

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agoattach: call lxc_container_new() earlier
Christian Brauner [Fri, 2 Sep 2016 16:39:11 +0000 (18:39 +0200)] 
attach: call lxc_container_new() earlier

We will reuse the newly initialized container for PR_SET_NO_NEW_PRIVS.

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agoattach_options: add LXC_ATTACH_NO_NEW_PRIVS
Christian Brauner [Fri, 2 Sep 2016 16:17:11 +0000 (18:17 +0200)] 
attach_options: add LXC_ATTACH_NO_NEW_PRIVS

Add a flag for PR_SET_NO_NEW_PRIVS. It is off by default.

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agostart: set PR_SET_NO_NEW_PRIVS when requested
Christian Brauner [Thu, 1 Sep 2016 23:40:39 +0000 (01:40 +0200)] 
start: set PR_SET_NO_NEW_PRIVS when requested

Set no_new_privs after setting the lsm label. If we do set it before we aren't
allowed to change the label anymore.

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agoconf, confile: add option for PR_SET_NO_NEW_PRIVS
Christian Brauner [Thu, 1 Sep 2016 23:30:59 +0000 (01:30 +0200)] 
conf, confile: add option for PR_SET_NO_NEW_PRIVS

Signed-off-by: Christian Brauner <christian.brauner@canonical.com>
8 years agoMerge pull request #1168 from jerome-pouiller/master
Christian Brauner [Mon, 5 Sep 2016 18:01:18 +0000 (20:01 +0200)] 
Merge pull request #1168 from jerome-pouiller/master

configure: add --disable-werror

8 years agoMerge pull request #1169 from brauner/2016-09-04/fix_syslog
Stéphane Graber [Mon, 5 Sep 2016 16:51:57 +0000 (12:51 -0400)] 
Merge pull request #1169 from brauner/2016-09-04/fix_syslog

syslog tweaks

8 years agoMerge pull request #1167 from brauner/2016-09-03/fix_log_name
Stéphane Graber [Mon, 5 Sep 2016 16:48:25 +0000 (12:48 -0400)] 
Merge pull request #1167 from brauner/2016-09-03/fix_log_name

console: use correct log name

8 years agotests: add lxc.syslog tests to get_item 1169/head
Christian Brauner [Sun, 4 Sep 2016 22:24:24 +0000 (00:24 +0200)] 
tests: add lxc.syslog tests to get_item

Signed-off-by: Christian Brauner <christian.brauner@mailbox.org>
8 years agotests: fix get_item tests
Christian Brauner [Sun, 4 Sep 2016 22:01:51 +0000 (00:01 +0200)] 
tests: fix get_item tests

Signed-off-by: Christian Brauner <christian.brauner@mailbox.org>
8 years agosyslog: simplify and model after lxc log functions
Christian Brauner [Sun, 4 Sep 2016 19:16:12 +0000 (21:16 +0200)] 
syslog: simplify and model after lxc log functions

- add lxc_syslog_priority_to_string()
- add lxc_syslog_priority_to_int()
- remove syslog_facility struct
- add lxc.syslog to lxc_getconfig struct
- adapt config_syslog() callback

Signed-off-by: Christian Brauner <christian.brauner@mailbox.org>
8 years agoconfigure: add --disable-werror 1168/head
Jérôme Pouiller [Sun, 4 Sep 2016 07:35:44 +0000 (09:35 +0200)] 
configure: add --disable-werror

-Werror may break builds on some scenarios with trivialities
(especially during developments).

Signed-off-by: Jérôme Pouiller <jezz@sysmic.org>
8 years agoconsole: use correct log name 1167/head
Christian Brauner [Sat, 3 Sep 2016 18:05:54 +0000 (20:05 +0200)] 
console: use correct log name

lxc_console is used with lxc_console.c

Signed-off-by: Christian Brauner <christian.brauner@mailbox.org>
8 years agoMerge pull request #1163 from mabes/fix-libetc-dir
Christian Brauner [Thu, 1 Sep 2016 15:00:16 +0000 (17:00 +0200)] 
Merge pull request #1163 from mabes/fix-libetc-dir

templates: remove creation of bogus directory in Debian templates

8 years agotemplates: remove creation of bogus directory 1163/head
Maxime BESSON [Thu, 1 Sep 2016 14:09:37 +0000 (16:09 +0200)] 
templates: remove creation of bogus directory

An incorrect quoting introduced in bf39edb caused a /{lib,etc} folder to
appear in Debian templates

The very next line :
    mkdir -p "${rootfs}/etc/systemd/system/getty.target.wants

makes creating ${rootfs}/etc/systemd/system/ unnecessary in the first
place

Signed-off-by: Maxime Besson <maxime.besson@smile.fr>
8 years agoMerge pull request #1162 from brauner/2016-08-31/remove_halt_symlink
Stéphane Graber [Wed, 31 Aug 2016 22:29:32 +0000 (18:29 -0400)] 
Merge pull request #1162 from brauner/2016-08-31/remove_halt_symlink

templates: rm halt.target -> sigpwr.target symlink

8 years agotemplates: rm halt.target -> sigpwr.target symlink 1162/head
Christian Brauner [Wed, 31 Aug 2016 21:53:50 +0000 (23:53 +0200)] 
templates: rm halt.target -> sigpwr.target symlink

Given commit 330ae3d350e060e5702a0e5ef5d0faeeeea8df6e:

    lxccontainer: detect if we should send SIGRTMIN+3

    This is required by systemd to cleanly shutdown. Other init systems should not
    have SIGRTMIN+3 in the blocked signals set.

we should stop symlinking halt.target to sigpwr.target for systemd.

Signed-off-by: Christian Brauner <cbrauner@suse.de>
8 years agoMerge pull request #1157 from evgeni/doxygen-no-full-path-names
Christian Brauner [Sat, 27 Aug 2016 10:21:29 +0000 (12:21 +0200)] 
Merge pull request #1157 from evgeni/doxygen-no-full-path-names

set FULL_PATH_NAMES=NO in doc/api/Doxyfile

8 years agoset FULL_PATH_NAMES=NO in doc/api/Doxyfile 1157/head
Evgeni Golov [Sat, 27 Aug 2016 10:14:53 +0000 (12:14 +0200)] 
set FULL_PATH_NAMES=NO in doc/api/Doxyfile

otherwise the generated docs have the full build path in them
and nonbody cares that the files were built in
 /build/lxc-_BVY2u/lxc-2.0.4/src/lxc/

Signed-off-by: Evgeni Golov <evgeni@debian.org>