]> git.ipfire.org Git - thirdparty/lxc.git/log
thirdparty/lxc.git
6 years agoutils: Fix wrong integer of a function parameter. 3113/head
Julio Faracco [Sat, 3 Aug 2019 05:16:13 +0000 (02:16 -0300)] 
utils: Fix wrong integer of a function parameter.

If SSL is enabled, utils will include function `do_sha1_hash()` to
generate a sha1 encrypted buffer. Last function argument of
`EVP_DigestFinal_ex()` requires a `unsigned int` but the current
parameter is an `integer` type.

See error:
utils.c:350:38: error: passing 'int *' to parameter of type 'unsigned int *' converts between pointers to integer types with different sign
      [-Werror,-Wpointer-sign]
        EVP_DigestFinal_ex(mdctx, md_value, md_len);
                                            ^~~~~~
/usr/include/openssl/evp.h:549:49: note: passing argument to parameter 's' here
                                  unsigned int *s);

Signed-off-by: Julio Faracco <jcfaracco@gmail.com>
6 years agoMerge pull request #3107 from tomponline/tp-wlan-detach
Christian Brauner [Mon, 29 Jul 2019 16:10:46 +0000 (12:10 -0400)] 
Merge pull request #3107 from tomponline/tp-wlan-detach

lxccontainer: do_lxcapi_detach_interface to support detaching wlan devs

6 years agolxccontainer: do_lxcapi_detach_interface to support detaching wlan devices 3107/head
Thomas Parrott [Fri, 26 Jul 2019 15:14:18 +0000 (16:14 +0100)] 
lxccontainer: do_lxcapi_detach_interface to support detaching wlan devices

Signed-off-by: Thomas Parrott <thomas.parrott@canonical.com>
6 years agoMerge pull request #3109 from brauner/2019-07-28/bugfixes
Stéphane Graber [Mon, 29 Jul 2019 03:43:24 +0000 (23:43 -0400)] 
Merge pull request #3109 from brauner/2019-07-28/bugfixes

cgroups: initialize cpuset properly

6 years agocgroups: initialize cpuset properly 3109/head
Christian Brauner [Sun, 28 Jul 2019 21:13:26 +0000 (23:13 +0200)] 
cgroups: initialize cpuset properly

Closes #3108.
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agoMerge pull request #3102 from brauner/2019-07-22/bugfixes
Wolfgang Bumiller [Sun, 28 Jul 2019 17:07:21 +0000 (19:07 +0200)] 
Merge pull request #3102 from brauner/2019-07-22/bugfixes

tree-wide: initialize all auto-cleanup variables

6 years agoMerge pull request #3106 from brauner/2019-07-25/bugfixes
Stéphane Graber [Fri, 26 Jul 2019 13:36:24 +0000 (09:36 -0400)] 
Merge pull request #3106 from brauner/2019-07-25/bugfixes

network: restore ability to move nl80211 devices

6 years agonetwork: restore ability to move nl80211 devices 3106/head
Christian Brauner [Fri, 26 Jul 2019 06:20:02 +0000 (08:20 +0200)] 
network: restore ability to move nl80211 devices

Closes #3105.
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agoMerge pull request #3103 from tych0/info-on-enosys
Christian Brauner [Tue, 23 Jul 2019 15:48:12 +0000 (17:48 +0200)] 
Merge pull request #3103 from tych0/info-on-enosys

pidfds: don't print a scary warning on ENOSYS

6 years agopidfds: don't print a scary warning on ENOSYS 3103/head
Tycho Andersen [Tue, 23 Jul 2019 15:40:14 +0000 (09:40 -0600)] 
pidfds: don't print a scary warning on ENOSYS

Most kernels don't have this functionality yet, and so the warning is
printed a lot. Our people are scared of warnings, so let's make it INFO
instead in this case.

Signed-off-by: Tycho Andersen <tycho@tycho.ws>
6 years agotree-wide: initialize all auto-cleanup variables 3102/head
Christian Brauner [Tue, 23 Jul 2019 14:41:46 +0000 (16:41 +0200)] 
tree-wide: initialize all auto-cleanup variables

Closes: #3101.
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agoRe-enable devel flag
Stéphane Graber [Mon, 22 Jul 2019 22:42:42 +0000 (18:42 -0400)] 
Re-enable devel flag

Signed-off-by: Stéphane Graber <stgraber@ubuntu.com>
6 years agoRelease LXC 3.2.1 lxc-3.2.1
Stéphane Graber [Mon, 22 Jul 2019 22:32:29 +0000 (18:32 -0400)] 
Release LXC 3.2.1

Signed-off-by: Stéphane Graber <stgraber@ubuntu.com>
6 years agoRelease LXC 3.2.0 lxc-3.2.0
Stéphane Graber [Mon, 22 Jul 2019 22:24:40 +0000 (18:24 -0400)] 
Release LXC 3.2.0

Signed-off-by: Stéphane Graber <stgraber@ubuntu.com>
6 years agolxc-download: Pre-release bump of compat
Stéphane Graber [Mon, 22 Jul 2019 22:23:48 +0000 (18:23 -0400)] 
lxc-download: Pre-release bump of compat

Signed-off-by: Stéphane Graber <stgraber@ubuntu.com>
6 years agoMerge pull request #3092 from Blub/seccomp-mem-rdwr
Christian Brauner [Tue, 16 Jul 2019 13:17:11 +0000 (15:17 +0200)] 
Merge pull request #3092 from Blub/seccomp-mem-rdwr

seccomp: open memfd read-write

6 years agoseccomp: open memfd read-write 3092/head
Wolfgang Bumiller [Tue, 16 Jul 2019 09:22:50 +0000 (11:22 +0200)] 
seccomp: open memfd read-write

Makes it easier to implement syscalls which need to write to
a buffer passed by user space as a pointer.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoMerge pull request #2921 from tomponline/tp-2019-03-26/routedveth
Christian Brauner [Thu, 11 Jul 2019 12:41:00 +0000 (14:41 +0200)] 
Merge pull request #2921 from tomponline/tp-2019-03-26/routedveth

Adds veth router mode

6 years agodoc: Documents the lxc.net.[i].veth.mode option 2921/head
tomponline [Wed, 3 Apr 2019 11:57:32 +0000 (11:57 +0000)] 
doc: Documents the lxc.net.[i].veth.mode option

Signed-off-by: Thomas Parrott <thomas.parrott@canonical.com>
6 years agonetwork: Adds veth router mode static routes and proxy entries
Thomas Parrott [Fri, 5 Jul 2019 13:46:19 +0000 (14:46 +0100)] 
network: Adds veth router mode static routes and proxy entries

Signed-off-by: Thomas Parrott <thomas.parrott@canonical.com>
6 years agonetwork: Adds mode param (bridge, router) to veth network setting
Thomas Parrott [Fri, 5 Jul 2019 13:46:49 +0000 (14:46 +0100)] 
network: Adds mode param (bridge, router) to veth network setting

Defaulting to bridge mode.

Signed-off-by: Thomas Parrott <thomas.parrott@canonical.com>
6 years agolxc/log: Adds error_log_errno macro
Thomas Parrott [Tue, 21 May 2019 16:25:52 +0000 (17:25 +0100)] 
lxc/log: Adds error_log_errno macro

Suggested usage:

return error_log_errno(err, "Failed: %s", "some error");

It sets errno to the value of err, then calls SYSERROR with the format and remaining args.

It always returns -1.

Suggested-by: Christian Brauner <christian.brauner@ubuntu.com>
Signed-off-by: Thomas Parrott <thomas.parrott@canonical.com>
6 years agoMerge pull request #3090 from Rachid-Koucha/patch-3
Christian Brauner [Thu, 11 Jul 2019 10:10:28 +0000 (12:10 +0200)] 
Merge pull request #3090 from Rachid-Koucha/patch-3

Suppress hardcoded table sizes

6 years agoSuppress hardcoded table sizes 3090/head
Rachid Koucha [Thu, 11 Jul 2019 08:01:36 +0000 (10:01 +0200)] 
Suppress hardcoded table sizes

. Use sizeof() instead of hardcoded values
. snprintf(..., size, ""...) is in error if the return code is >= size (not sufficient to set only ">")

Signed-off-by: Rachid Koucha <rachid.koucha@gmail.com>
6 years agoMerge pull request #3089 from Rachid-Koucha/patch-2
Christian Brauner [Thu, 11 Jul 2019 07:57:34 +0000 (09:57 +0200)] 
Merge pull request #3089 from Rachid-Koucha/patch-2

Typo fix

6 years agoTypo fix 3089/head
Rachid Koucha [Thu, 11 Jul 2019 07:42:05 +0000 (09:42 +0200)] 
Typo fix

Fixed a typo in error message

Signed-off-by: Rachid Koucha <rachid.koucha@gmail.com>
6 years agoMerge pull request #3088 from tenforward/japanese
Christian Brauner [Thu, 11 Jul 2019 06:28:11 +0000 (08:28 +0200)] 
Merge pull request #3088 from tenforward/japanese

doc: Add lxc.comp.notify.cookie to Japanese lxc.container.conf(5)

6 years agodoc: Add lxc.comp.notify.cookie to Japanese lxc.container.conf(5) 3088/head
KATOH Yasufumi [Thu, 11 Jul 2019 06:22:08 +0000 (15:22 +0900)] 
doc: Add lxc.comp.notify.cookie to Japanese lxc.container.conf(5)

update for commit 214008e

Signed-off-by: KATOH Yasufumi <karma@jazz.email.ne.jp>
6 years agoMerge pull request #3087 from brauner/master
Stéphane Graber [Wed, 10 Jul 2019 14:53:45 +0000 (10:53 -0400)] 
Merge pull request #3087 from brauner/master

cgroup: check for non-empty conf

6 years agocgroup: check for non-empty conf 3087/head
Christian Brauner [Wed, 10 Jul 2019 14:34:29 +0000 (16:34 +0200)] 
cgroup: check for non-empty conf

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agoMerge pull request #3086 from brauner/2019-07-09/seccomp_fixes
Stéphane Graber [Tue, 9 Jul 2019 19:15:41 +0000 (15:15 -0400)] 
Merge pull request #3086 from brauner/2019-07-09/seccomp_fixes

seccomp: coding style

6 years agoseccomp: coding style 3086/head
Christian Brauner [Tue, 9 Jul 2019 19:08:20 +0000 (21:08 +0200)] 
seccomp: coding style

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agoMerge pull request #3080 from Blub/seccomp-notify-api
Christian Brauner [Tue, 9 Jul 2019 15:50:44 +0000 (17:50 +0200)] 
Merge pull request #3080 from Blub/seccomp-notify-api

Seccomp notify api update

6 years agoaf_unix: remove unused variable 3080/head
Christian Brauner [Tue, 9 Jul 2019 15:19:29 +0000 (17:19 +0200)] 
af_unix: remove unused variable

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agoseccomp: send caller pidfd along with proxied requests
Wolfgang Bumiller [Tue, 9 Jul 2019 10:18:43 +0000 (12:18 +0200)] 
seccomp: send caller pidfd along with proxied requests

On the one hand this should close the race between the
process exiting until the proxy reads the request.
On the other hand it'll help the proxy quickly access info
from /proc (such as ./cwd, ./ns/mnt, ...)

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoseccomp: recvmsg with MSG_TRUNC
Wolfgang Bumiller [Mon, 8 Jul 2019 16:00:20 +0000 (18:00 +0200)] 
seccomp: recvmsg with MSG_TRUNC

We only read the message without the cookie. For now assert
that the sender also didn't try to send more by letting
`recvmsg()` return the original size of the packet if it was
longer.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agodoc: document lxc.seccomp.notify.cookie
Wolfgang Bumiller [Fri, 5 Jul 2019 17:21:34 +0000 (19:21 +0200)] 
doc: document lxc.seccomp.notify.cookie

and fix a minor typo

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoseccomp: defer reconnecting to the proxy
Wolfgang Bumiller [Fri, 5 Jul 2019 09:36:07 +0000 (11:36 +0200)] 
seccomp: defer reconnecting to the proxy

With the previous commit we now attempt to reconnect to the
proxy in the beginning of the notify handler if we had no
connection.
If the connection fails later on, we now don't really need
to immediately try to reconnect if we send a default
response anyway (particularly if the recv() fails). (This
also gives the proxy more time, for instance if it was just
restarted.)

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoseccomp: keep retrying to reconnect to proxy
Wolfgang Bumiller [Fri, 5 Jul 2019 09:30:24 +0000 (11:30 +0200)] 
seccomp: keep retrying to reconnect to proxy

If a syscall happens after we already failed to communicate
with the proxy, proxy_fd was -1.
Before the previous commit we'd then be stuck in the state
where there was no proxy registered. With the previous
commit we'd send a default reply and only then try to
reconnect.
Improve this even further by trying to reconnect right at
the start.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoseccomp: send default response when there's no proxy
Wolfgang Bumiller [Fri, 5 Jul 2019 09:22:34 +0000 (11:22 +0200)] 
seccomp: send default response when there's no proxy

Particularly, when there's no proxy registered (iow. none
configured but the seccomp profile still had a 'notify'
rule), we don't want to leave them hanging.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoseccomp: retry connecting to the proxy once
Wolfgang Bumiller [Fri, 5 Jul 2019 08:41:19 +0000 (10:41 +0200)] 
seccomp: retry connecting to the proxy once

If the first sendmsg() fails, try to reconnect once before
failing. Otherwise if a proxy restarts while no syscall
happens, the next syscall always fails with ENOSYS.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoseccomp: don't ignore syscalls when there's no proxy
Wolfgang Bumiller [Fri, 5 Jul 2019 07:44:17 +0000 (09:44 +0200)] 
seccomp: don't ignore syscalls when there's no proxy

The container process would just hang.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoseccomp: remove reconnect-loop
Wolfgang Bumiller [Fri, 5 Jul 2019 07:40:04 +0000 (09:40 +0200)] 
seccomp: remove reconnect-loop

When we fail to send a message, we send a default seccomp
response and try to reconnect to the proxy. It doesn't
really make much sense to retry to send the request over the
new connection as the syscall has already been answered. The
same goes for receiving the response - after reconnecting to
the proxy, we're a new client to a potentially new proxy
process, so awaiting a response without having sent a
request doesn't make all too much sense either.

In the future we should probably have a timeout or retry
count for the entire proxy _transaction_ before sending a
response to seccomp at all (and probably handle requests
asynchronously).

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoseccomp: use SOCK_SEQPACKET for the notify proxy
Wolfgang Bumiller [Fri, 5 Jul 2019 07:31:09 +0000 (09:31 +0200)] 
seccomp: use SOCK_SEQPACKET for the notify proxy

The seccomp notify API has a few variables: The struct sizes
are queried at runtime, and we now also have a user
configured cookie.
This means that with a SOCK_STREAM connection the proxy
needs to carefully read() the right amount of data based on
the contents of our proxy message struct to avoid ending up
in the middle of a packet.
While for now this may not be too tragic, since we currently
only ever send a single packet and then wait for the
response, we may at some point want to be able to handle
multiple processes simultaneously, hence it makes sense to
switch to a packet based connection.

So switch to using SOCK_SEQPACKET which is packet based,
(and also guarantees ordering). The `MSG_PEEK` flag can be
used with `recvmsg()` to figure out a packet's size on the
other end, and usually the size *should* not change after
that for an existing connection from a running container.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoseccomp: assert that __reserved is 0 in notify responses
Wolfgang Bumiller [Fri, 5 Jul 2019 10:55:48 +0000 (12:55 +0200)] 
seccomp: assert that __reserved is 0 in notify responses

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoseccomp: update notify api
Wolfgang Bumiller [Fri, 5 Jul 2019 07:22:11 +0000 (09:22 +0200)] 
seccomp: update notify api

The previous API doesn't reflect the fact that
`seccomp_notif` and `seccomp_notif_resp` are allocatd
dynamically with sizes figured out at runtime.

We now query the sizes via the seccomp(2) syscall and change
`struct seccomp_notify_proxy_msg` to contain the sizes
instead of the data, with the data following afterwards.

Additionally it did not provide a convenient way to identify
the container the message originated from, for which we now
include a cookie configured via `lxc.seccomp.notify.cookie`.

Since we currently always send exactly one request and await
the response immediately, verify the `id` in the client's
response.

Finally, the proxy message's "version" field is removed, and
we reserve 64 bits in its place.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoconf: add lxc.seccomp.notify.cookie
Wolfgang Bumiller [Wed, 3 Jul 2019 15:30:49 +0000 (17:30 +0200)] 
conf: add lxc.seccomp.notify.cookie

This is an arbitrary string to to be included in proxied
seccomp notification messages.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agofile_utils: add lxc_recvmsg_nointr_iov
Wolfgang Bumiller [Thu, 4 Jul 2019 12:25:02 +0000 (14:25 +0200)] 
file_utils: add lxc_recvmsg_nointr_iov

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoaf_unix: add lxc_unix_connect_type
Wolfgang Bumiller [Thu, 4 Jul 2019 12:34:01 +0000 (14:34 +0200)] 
af_unix: add lxc_unix_connect_type

we want to use SOCK_SEQPACKET and in the future perhaps
SOCK_DATAGRAM as well

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoaf_unix: add lxc_abstract_unix_recv_fds_iov()
Christian Brauner [Tue, 9 Jul 2019 10:17:42 +0000 (12:17 +0200)] 
af_unix: add lxc_abstract_unix_recv_fds_iov()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agoaf_unix: add lxc_abstract_unix_send_fds_iov
Wolfgang Bumiller [Thu, 4 Jul 2019 07:17:04 +0000 (09:17 +0200)] 
af_unix: add lxc_abstract_unix_send_fds_iov

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoMerge pull request #3085 from Blub/pidfd_send_signal-fixup
Christian Brauner [Mon, 8 Jul 2019 21:33:58 +0000 (23:33 +0200)] 
Merge pull request #3085 from Blub/pidfd_send_signal-fixup

pidf_send_signal: fix return value

6 years agopidf_send_signal: fix return value 3085/head
Wolfgang Bumiller [Mon, 8 Jul 2019 16:10:35 +0000 (18:10 +0200)] 
pidf_send_signal: fix return value

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoMerge pull request #3083 from brauner/2019-07-07/mount_api
Stéphane Graber [Sun, 7 Jul 2019 16:39:49 +0000 (12:39 -0400)] 
Merge pull request #3083 from brauner/2019-07-07/mount_api

lxccontainer: properly cleanup on mount injection failure

6 years agolxccontainer: properly cleanup on mount injection failure 3083/head
Christian Brauner [Sun, 7 Jul 2019 16:00:27 +0000 (18:00 +0200)] 
lxccontainer: properly cleanup on mount injection failure

Closes: #3082
Reported-by: Stéphane Graber <stgraber@ubuntu.com>
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agoMerge pull request #3081 from brauner/2019-07-05/network_unification_fixes
Christian Brauner [Fri, 5 Jul 2019 09:44:45 +0000 (11:44 +0200)] 
Merge pull request #3081 from brauner/2019-07-05/network_unification_fixes

start: call lxc_find_gateway_addresses early

6 years agostart: call lxc_find_gateway_addresses early 3081/head
Thomas Parrott [Thu, 4 Jul 2019 21:38:23 +0000 (22:38 +0100)] 
start: call lxc_find_gateway_addresses early

This restores the lxc.net.x.ipv4.gateway = auto and
lxc.net.x.ipv6.gateway = auto functionality.

When the child is created the parent and child have different views of
struct lxc_handler since - obviously - virtual memory is duplicated. So any
changes to done by the parent that the child should see need to be IPCed to it.
For any non-actual device creation stuff this does not make much sense. This
includes finding gateway addresses. Move it back prior to clone().

Fixes #3078

Signed-off-by: Thomas Parrott <thomas.parrott@canonical.com>
[christian.brauner@ubuntu.com: non-functional changes and update commit message]
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agoMerge pull request #3077 from brauner/2019-07-03/network_fixes
Stéphane Graber [Wed, 3 Jul 2019 22:13:20 +0000 (18:13 -0400)] 
Merge pull request #3077 from brauner/2019-07-03/network_fixes

network: simplify lxc_network_move_created_netdev_priv()

6 years agonetwork: simplify lxc_network_move_created_netdev_priv() 3077/head
Christian Brauner [Wed, 3 Jul 2019 21:55:57 +0000 (23:55 +0200)] 
network: simplify lxc_network_move_created_netdev_priv()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agoMerge pull request #3076 from brauner/2019-07-03/network_fixes
Stéphane Graber [Wed, 3 Jul 2019 21:43:54 +0000 (17:43 -0400)] 
Merge pull request #3076 from brauner/2019-07-03/network_fixes

network: fixes after unifying network creation

6 years agonetwork: send names for all non-trivial network types 3076/head
Christian Brauner [Wed, 3 Jul 2019 21:17:05 +0000 (23:17 +0200)] 
network: send names for all non-trivial network types

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agonetwork: record created_name for instantiate_phys()
Christian Brauner [Wed, 3 Jul 2019 19:48:20 +0000 (21:48 +0200)] 
network: record created_name for instantiate_phys()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agonetwork: simplify instantiate_phys()
Christian Brauner [Wed, 3 Jul 2019 19:46:37 +0000 (21:46 +0200)] 
network: simplify instantiate_phys()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agonetwork: record created_name for instantiate_vlan()
Christian Brauner [Wed, 3 Jul 2019 19:44:52 +0000 (21:44 +0200)] 
network: record created_name for instantiate_vlan()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agonetwork: simplify instantiate_vlan()
Christian Brauner [Wed, 3 Jul 2019 19:44:19 +0000 (21:44 +0200)] 
network: simplify instantiate_vlan()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agonetwork: record created_name for instantiate_ipvlan()
Christian Brauner [Wed, 3 Jul 2019 19:43:19 +0000 (21:43 +0200)] 
network: record created_name for instantiate_ipvlan()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agonetwork: simplify instantiate_ipvlan()
Christian Brauner [Wed, 3 Jul 2019 19:42:18 +0000 (21:42 +0200)] 
network: simplify instantiate_ipvlan()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agonetwork: stash created_name in instantiate_macvlan()
Christian Brauner [Wed, 3 Jul 2019 19:39:54 +0000 (21:39 +0200)] 
network: stash created_name in instantiate_macvlan()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agonetwork: simplify instantiate_macvlan()
Christian Brauner [Wed, 3 Jul 2019 19:39:24 +0000 (21:39 +0200)] 
network: simplify instantiate_macvlan()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agonetwork: s/loDev/loop_device/g
Christian Brauner [Wed, 3 Jul 2019 19:37:37 +0000 (21:37 +0200)] 
network: s/loDev/loop_device/g

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agoMerge pull request #3075 from brauner/2019-07-03/cgroups
Stéphane Graber [Wed, 3 Jul 2019 16:23:50 +0000 (12:23 -0400)] 
Merge pull request #3075 from brauner/2019-07-03/cgroups

cgroups: hande cpuset initialization race

6 years agocgroups: hande cpuset initialization race 3075/head
Christian Brauner [Wed, 3 Jul 2019 15:57:48 +0000 (17:57 +0200)] 
cgroups: hande cpuset initialization race

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agoMerge pull request #3074 from brauner/2019-07-03/fix_phys_network_creation
Stéphane Graber [Wed, 3 Jul 2019 15:44:25 +0000 (11:44 -0400)] 
Merge pull request #3074 from brauner/2019-07-03/fix_phys_network_creation

network: remove faulty restriction

6 years agonetwork: remove faulty restriction 3074/head
Christian Brauner [Wed, 3 Jul 2019 13:13:46 +0000 (15:13 +0200)] 
network: remove faulty restriction

Reported-by: Thomas Parrott <thomas.parrott@canonical.com>
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agoMerge pull request #3069 from brauner/2019-07-01/network_creation
Stéphane Graber [Tue, 2 Jul 2019 15:46:55 +0000 (11:46 -0400)] 
Merge pull request #3069 from brauner/2019-07-01/network_creation

start: unify network creation

6 years agostart: expose LXC_PID to network hooks too 3069/head
Christian Brauner [Tue, 2 Jul 2019 10:57:12 +0000 (12:57 +0200)] 
start: expose LXC_PID to network hooks too

Closes #3066.
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agostart: unify and simplify network creation
Christian Brauner [Mon, 1 Jul 2019 15:55:16 +0000 (17:55 +0200)] 
start: unify and simplify network creation

Make sure that network creation happens at the same time for containers started
by privileged and unprivileged users. The only reason we didn't do this so far
was to avoid sending network device ifindices around in the privileged case.

Link: https://github.com/lxc/lxc/issues/3066
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agoMerge pull request #3064 from brauner/2019-06-27/cleanup_macros
Stéphane Graber [Tue, 2 Jul 2019 02:06:23 +0000 (22:06 -0400)] 
Merge pull request #3064 from brauner/2019-06-27/cleanup_macros

bugfixes

6 years agoMerge pull request #3059 from brauner/2019-06-21/seccomp_notify
Stéphane Graber [Tue, 2 Jul 2019 02:04:20 +0000 (22:04 -0400)] 
Merge pull request #3059 from brauner/2019-06-21/seccomp_notify

lxccontainer: rework seccomp notify api function

6 years agoMerge pull request #3067 from Rachid-Koucha/patch-1
Christian Brauner [Sun, 30 Jun 2019 16:13:30 +0000 (18:13 +0200)] 
Merge pull request #3067 from Rachid-Koucha/patch-1

Move code/variable in smaller scope

6 years agoMove code/variable in smaller scope 3067/head
Rachid Koucha [Sat, 29 Jun 2019 21:21:14 +0000 (23:21 +0200)] 
Move code/variable in smaller scope

In start.c, do not fill path[] table if not necessary

Signed-off-by: Rachid Koucha <rachid.koucha@gmail.com>
6 years agoMerge pull request #3065 from lifeng68/fix_memory_leak
Christian Brauner [Fri, 28 Jun 2019 09:53:52 +0000 (11:53 +0200)] 
Merge pull request #3065 from lifeng68/fix_memory_leak

fix memory leak in do_storage_create

6 years agofix memory leak in do_storage_create 3065/head
LiFeng [Fri, 28 Jun 2019 03:49:08 +0000 (23:49 -0400)] 
fix memory leak in do_storage_create

Signed-off-by: LiFeng <lifeng68@huawei.com>
6 years agocgroups: move variable into tighter scope 3064/head
Christian Brauner [Thu, 27 Jun 2019 12:48:34 +0000 (14:48 +0200)] 
cgroups: move variable into tighter scope

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agocgroups: correctly order variables
Christian Brauner [Thu, 27 Jun 2019 12:46:47 +0000 (14:46 +0200)] 
cgroups: correctly order variables

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agocgroups: move variable into tighter scope
Christian Brauner [Thu, 27 Jun 2019 12:45:36 +0000 (14:45 +0200)] 
cgroups: move variable into tighter scope

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agocgroups: simplify cgfsng_nrtasks()
Christian Brauner [Thu, 27 Jun 2019 12:43:36 +0000 (14:43 +0200)] 
cgroups: simplify cgfsng_nrtasks()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agocgroups: move variable into tighter scope
Christian Brauner [Thu, 27 Jun 2019 12:43:09 +0000 (14:43 +0200)] 
cgroups: move variable into tighter scope

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agocgroups: move variable into tighter scope
Christian Brauner [Thu, 27 Jun 2019 12:27:58 +0000 (14:27 +0200)] 
cgroups: move variable into tighter scope

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agocgroups: use __do_free in cgfsng_attach()
Christian Brauner [Thu, 27 Jun 2019 12:27:39 +0000 (14:27 +0200)] 
cgroups: use __do_free in cgfsng_attach()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agocgroups: simplify cgfsng_setup_limits()
Christian Brauner [Thu, 27 Jun 2019 12:26:38 +0000 (14:26 +0200)] 
cgroups: simplify cgfsng_setup_limits()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agocgroups: move variables into tighter scope
Christian Brauner [Thu, 27 Jun 2019 12:26:14 +0000 (14:26 +0200)] 
cgroups: move variables into tighter scope

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agocgroups: use __do_free
Christian Brauner [Thu, 27 Jun 2019 12:25:53 +0000 (14:25 +0200)] 
cgroups: use __do_free

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agoMerge pull request #3063 from lifeng68/fix_memory_leak
Christian Brauner [Thu, 27 Jun 2019 07:40:55 +0000 (09:40 +0200)] 
Merge pull request #3063 from lifeng68/fix_memory_leak

cgfsng: fix memory leak in lxc_cpumask_to_cpulist

6 years agocgfsng: fix memory leak in lxc_cpumask_to_cpulist 3063/head
LiFeng [Thu, 27 Jun 2019 03:54:27 +0000 (23:54 -0400)] 
cgfsng: fix memory leak in lxc_cpumask_to_cpulist

Signed-off-by: LiFeng <lifeng68@huawei.com>
6 years agolxccontainer: rework seccomp notify api function 3059/head
Christian Brauner [Fri, 21 Jun 2019 10:59:36 +0000 (12:59 +0200)] 
lxccontainer: rework seccomp notify api function

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agoMerge pull request #3056 from brauner/2019-06-20/cpuset
Stéphane Graber [Thu, 20 Jun 2019 17:54:12 +0000 (13:54 -0400)] 
Merge pull request #3056 from brauner/2019-06-20/cpuset

cgfsng: write cpuset.mems of correct ancestor

6 years agocgfsng: write cpuset.mems of correct ancestor 3056/head
Christian Brauner [Thu, 20 Jun 2019 17:37:09 +0000 (19:37 +0200)] 
cgfsng: write cpuset.mems of correct ancestor

Reported-by: Free Ekanayaka <free.ekanayaka@canonical.com>
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
6 years agoMerge pull request #3052 from tanyifeng/fd_leak
Christian Brauner [Thu, 20 Jun 2019 09:33:41 +0000 (11:33 +0200)] 
Merge pull request #3052 from tanyifeng/fd_leak

parse.c: fix fd leak from memfd_create

6 years agoparse.c: fix fd leak from memfd_create 3052/head
t00416110 [Thu, 20 Jun 2019 20:26:59 +0000 (16:26 -0400)] 
parse.c: fix fd leak from memfd_create

Signed-off-by: t00416110 <tanyifeng1@huawei.com>