]> git.proxmox.com Git - mirror_lxc.git/log
mirror_lxc.git
2 years agolxccontainer: improve create_partial()
Christian Brauner [Tue, 18 Jan 2022 16:48:29 +0000 (17:48 +0100)]
lxccontainer: improve create_partial()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agolxccontainer: improve do_lxcapi_create()
Christian Brauner [Tue, 18 Jan 2022 16:25:07 +0000 (17:25 +0100)]
lxccontainer: improve do_lxcapi_create()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agolxccontainer: improve do_lxcapi_save_config()
Christian Brauner [Tue, 18 Jan 2022 15:57:47 +0000 (16:57 +0100)]
lxccontainer: improve do_lxcapi_save_config()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoconf: log termination status
Christian Brauner [Tue, 18 Jan 2022 15:26:58 +0000 (16:26 +0100)]
conf: log termination status

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoconf: improve userns_exec_mapped_root()
Christian Brauner [Tue, 18 Jan 2022 15:14:13 +0000 (16:14 +0100)]
conf: improve userns_exec_mapped_root()

As we do in all other places, first drop groups, then use
setres{g,u}id().

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoMerge pull request #4063 from simondeziel/gnupg
Stéphane Graber [Tue, 18 Jan 2022 15:00:27 +0000 (10:00 -0500)]
Merge pull request #4063 from simondeziel/gnupg

github: stop installing gnupg now that it's unused

2 years agogithub: stop installing gnupg now that it's unused
Simon Deziel [Tue, 18 Jan 2022 14:53:45 +0000 (09:53 -0500)]
github: stop installing gnupg now that it's unused

Signed-off-by: Simon Deziel <simon.deziel@canonical.com>
2 years agoMerge pull request #4062 from stgraber/master
Christian Brauner [Tue, 18 Jan 2022 14:24:41 +0000 (15:24 +0100)]
Merge pull request #4062 from stgraber/master

lxc-download: Rely on HTTPS only

2 years agolxc-download: Rely on HTTPS only
Stéphane Graber [Tue, 18 Jan 2022 02:15:53 +0000 (21:15 -0500)]
lxc-download: Rely on HTTPS only

GPG has been a major source of issues over the years with various
attacks on the key network as well as client side issues making it hard
to retrieve our keys.

Back when we introduced the image server, SSL certificates were still
expensive and annoying to setup, so not something we'd have expected
potential mirrors to setup for us. They were also issued for multiple
years, making a compromise of such a certificate quite problematic.

But things have changed since, we now have completely free, very easily
deployable SSL certificates everywhere with the majority of those being
shortlived and with good reporting of issued certificates.

With that, we can now deprecate the GPG validation, disable the fallback
to non-HTTPS download and rely on our indices being accurate because
they've been downloaded from a server with a valid certificate.

This puts LXC more in line with what LXD has done since the beginning
and should offer a more reliable user experience.

Signed-off-by: Stéphane Graber <stgraber@ubuntu.com>
2 years agoMerge pull request #4058 from brauner/2022-01-13.fixes
Stéphane Graber [Fri, 14 Jan 2022 23:03:58 +0000 (18:03 -0500)]
Merge pull request #4058 from brauner/2022-01-13.fixes

cgroups: improvements

2 years agoMerge pull request #4059 from DevinNorgarb/patch-1
Stéphane Graber [Fri, 14 Jan 2022 16:30:18 +0000 (11:30 -0500)]
Merge pull request #4059 from DevinNorgarb/patch-1

Update README.md: Fix broken link (403 Forbidden)

2 years agoUpdate README.md: Fix broken link (403 Forbidden)
Devin Norgarb [Fri, 14 Jan 2022 16:04:16 +0000 (18:04 +0200)]
Update README.md: Fix broken link (403 Forbidden)

Signed-off-by: Devin Norgarb dnorgarb@gmail.com
2 years agoattach: don't pointlessly call cgroup_init()
Christian Brauner [Thu, 13 Jan 2022 17:48:15 +0000 (18:48 +0100)]
attach: don't pointlessly call cgroup_init()

We can let attach detect that it is running on a cgroup layout without
writable cgroup hierarchies. In that case attach can finish early and
doesn't need to run the heavy-handed cgroup parsing code.

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agocommands: log command during file descriptor retrieval
Christian Brauner [Thu, 13 Jan 2022 16:42:17 +0000 (17:42 +0100)]
commands: log command during file descriptor retrieval

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoMerge pull request #4057 from Dmole/patch-2
Stéphane Graber [Wed, 12 Jan 2022 20:36:53 +0000 (15:36 -0500)]
Merge pull request #4057 from Dmole/patch-2

lxc-checkconfig.in: CONFIG_NF_NAT_IPV4

2 years agolxc-checkconfig.in: CONFIG_NF_NAT_IPV4 was removed from the kernel 2019-03-03
Tim [Wed, 12 Jan 2022 14:55:25 +0000 (09:55 -0500)]
lxc-checkconfig.in: CONFIG_NF_NAT_IPV4 was removed from the kernel 2019-03-03

Signed-off-by: Tim L <elatllat@gmail.com>
2 years agoMerge pull request #4054 from hallyn/2022-01-09/trivial
Stéphane Graber [Sun, 9 Jan 2022 22:16:17 +0000 (23:16 +0100)]
Merge pull request #4054 from hallyn/2022-01-09/trivial

(trivial) Fix error message, failure was connect not bind

2 years ago(trivial) Fix error message, failure was connect not bind
Serge Hallyn [Sun, 9 Jan 2022 16:16:02 +0000 (10:16 -0600)]
(trivial) Fix error message, failure was connect not bind

Signed-off-by: Serge Hallyn <serge@hallyn.com>
2 years agoMerge pull request #4053 from brauner/2022-01-07.fixes
Wolfgang Bumiller [Fri, 7 Jan 2022 13:19:10 +0000 (14:19 +0100)]
Merge pull request #4053 from brauner/2022-01-07.fixes

seccomp: close seccomp notifier fd in cleanup handler

2 years agoseccomp: close seccomp notifier fd in cleanup handler
Christian Brauner [Fri, 7 Jan 2022 12:42:33 +0000 (13:42 +0100)]
seccomp: close seccomp notifier fd in cleanup handler

Reported-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoMerge pull request #4047 from brauner/2021-12-10.fixes
Stéphane Graber [Fri, 10 Dec 2021 17:14:11 +0000 (12:14 -0500)]
Merge pull request #4047 from brauner/2021-12-10.fixes

seccomp: only guard seccomp notify behind HAVE_DECL_SECCOMP_NOTIFY_FD

2 years agoseccomp: only guard seccomp notify behind HAVE_DECL_SECCOMP_NOTIFY_FD
Christian Brauner [Fri, 10 Dec 2021 16:05:11 +0000 (17:05 +0100)]
seccomp: only guard seccomp notify behind HAVE_DECL_SECCOMP_NOTIFY_FD

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoMerge pull request #4043 from brauner/2021-12-06.fixes
Stéphane Graber [Wed, 8 Dec 2021 15:59:43 +0000 (10:59 -0500)]
Merge pull request #4043 from brauner/2021-12-06.fixes

api-extensions: don't advertise seccomp notify support if it's not co…

2 years agoapi-extensions: don't advertise seccomp notify support if it's not compiled in
Christian Brauner [Wed, 8 Dec 2021 09:41:59 +0000 (10:41 +0100)]
api-extensions: don't advertise seccomp notify support if it's not compiled in

Link: https://discuss.linuxcontainers.org/t/runtimeerror-failed-to-read-zi-bytes-from-dev-urandom
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoMerge pull request #4042 from Blub/2021-12-03/two-sysfs-instances-main
Christian Brauner [Fri, 3 Dec 2021 14:46:29 +0000 (15:46 +0100)]
Merge pull request #4042 from Blub/2021-12-03/two-sysfs-instances-main

use 2 sysfs instances for sys:mixed

2 years agouse 2 sysfs instances for sys:mixed
Wolfgang Bumiller [Fri, 3 Dec 2021 08:13:11 +0000 (09:13 +0100)]
use 2 sysfs instances for sys:mixed

In order to facilitate this, the default mount list's
'destination' may now be NULL to mean that the source should
be unmounted instead.

Here's what we need to do:

1) Ensure the first sysfs mount point is writable.
2) Mount a read-only sysfs on /sys
3) Bind devices/virtual/net *writably* into /sys

We use /proc/sys as a staging directory for the first sysfs
mount in read-write mode, then mount /sys r/o. Afterwards we
bind the r/w devices/virtual/net and unmount the staging
/proc/sys mount point.

The staging directory would not be required with the new
mount API, but this way we can support the old API and keep
the general workflow in the `default_mounts`.

Once we drop support for the old mount API, the
default_mounts table could just get a subdirectory field to
mount subdirectories directly.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
2 years agoRevert "api: ->save_config() doesn't need to create container dir"
Stéphane Graber [Tue, 30 Nov 2021 22:39:34 +0000 (17:39 -0500)]
Revert "api: ->save_config() doesn't need to create container dir"

This reverts commit 2fde07c3990fe09925699da5d9a1762eb279c497.

We need to investigate this in more detail but this commit is breaking
LXD, causing startup to fail with:

lxc foo 20211130202833.906 INFO     conf - conf.c:run_script_argv:336 - Executing script "/bin/mount -t shiftfs -o passthrough=3 "/lxc-ci/build/tmp.WemmpzWGYz/go/src/github.com/lxc/lxd/test/tmp.Cli/0To/containers/foo/rootfs" "/lxc-ci/build/tmp.WemmpzWGYz/go/src/github.com/lxc/lxd/test/tmp.Cli/0To/containers/foo/rootfs"" for container "foo"
lxc foo 20211130202833.912 ERROR    conf - conf.c:run_buffer:321 - Script exited with status 32
lxc foo 20211130202833.912 ERROR    conf - conf.c:lxc_setup_rootfs_prepare_root:3947 - Failed to run pre-mount hooks
lxc foo 20211130202833.912 ERROR    conf - conf.c:lxc_setup:4317 - Failed to setup rootfs
lxc foo 20211130202833.912 ERROR    start - start.c:do_start:1275 - Failed to setup container "foo"

Not entirely sure why we're seeing things blow up as the directory
definitely exists (and contains a valid rootfs) but this was caused by
today's liblxc update.

Signed-off-by: Stéphane Graber <stgraber@ubuntu.com>
2 years agoMerge pull request #4039 from tych0/config-no-container-dir
Christian Brauner [Mon, 29 Nov 2021 16:26:06 +0000 (17:26 +0100)]
Merge pull request #4039 from tych0/config-no-container-dir

api: ->save_config() doesn't need to create container dir

2 years agoMerge pull request #4040 from tych0/fix-cgroup-warning
Christian Brauner [Mon, 29 Nov 2021 16:25:45 +0000 (17:25 +0100)]
Merge pull request #4040 from tych0/fix-cgroup-warning

cgroups: fix compiler warning

2 years agoapi: ->save_config() doesn't need to create container dir
Tycho Andersen [Mon, 29 Nov 2021 13:23:17 +0000 (08:23 -0500)]
api: ->save_config() doesn't need to create container dir

If we're saving the config file to somewhere that's *not* the container
dir, we don't need to create the container dir. Let's not do this and
thus not require its parent to exist, which can be confusing, especially in
light of the sparse logging through these functions.

Signed-off-by: Tycho Andersen <tycho@tycho.pizza>
2 years agocgroups: fix compiler warning
Tycho Andersen [Mon, 29 Nov 2021 13:38:30 +0000 (08:38 -0500)]
cgroups: fix compiler warning

I get:

In file included from cgroups/cgfsng.c:42:
In function 'cpuset1_cpus_initialize',
    inlined from 'cpuset1_initialize' at cgroups/cgfsng.c:658:7,
    inlined from '__cgroup_tree_create.constprop' at cgroups/cgfsng.c:723:26:
./log.h:376:9: error: '%s' directive argument is null [-Werror=format-overflow=]
  376 |         LXC_ERROR(&locinfo, format, ##__VA_ARGS__);                     \
      |         ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
./log.h:457:17: note: in expansion of macro 'ERROR'
  457 |                 ERROR("%s - " format, ptr, ##__VA_ARGS__); \
      |                 ^~~~~
./log.h:491:17: note: in expansion of macro 'SYSERROR'
  491 |                 SYSERROR(format, ##__VA_ARGS__);              \
      |                 ^~~~~~~~
cgroups/cgfsng.c:585:24: note: in expansion of macro 'log_error_errno'
  585 |                 return log_error_errno(false, errno, "Failed to read file \"%s\"", fpath);
      |                        ^~~~~~~~~~~~~~~

it turns out here that fpath is not used, so let's get rid of it and just
render the dfd+pathname directly.

Signed-off-by: Tycho Andersen <tycho@tycho.pizza>
2 years agoMerge pull request #4035 from Blub/revert-vfork
Christian Brauner [Sat, 13 Nov 2021 22:24:12 +0000 (23:24 +0100)]
Merge pull request #4035 from Blub/revert-vfork

Revert "initutils: use vfork() in lxc_container_init()"

2 years agoRevert "initutils: use vfork() in lxc_container_init()"
Wolfgang Bumiller [Sat, 13 Nov 2021 17:20:13 +0000 (18:20 +0100)]
Revert "initutils: use vfork() in lxc_container_init()"

This reverts commit d65e5e492f740bbb50e3005f97420c3ddae3d595.

With vfork the child process modifies the parent's memory,
so the calls to `signal`, `fprintf` and regular `exit` may
be dangerous and might cause conflicting states in the
parent.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
2 years agoMerge pull request #4033 from brauner/2021-11-09.fixes
Stéphane Graber [Tue, 9 Nov 2021 14:48:37 +0000 (09:48 -0500)]
Merge pull request #4033 from brauner/2021-11-09.fixes

macro: ensure necessary io_uring flags are defined

2 years agomacro: ensure necessary io_uring flags are defined
Christian Brauner [Tue, 9 Nov 2021 13:01:35 +0000 (14:01 +0100)]
macro: ensure necessary io_uring flags are defined

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoMerge pull request #4032 from joanbm/master
Christian Brauner [Mon, 8 Nov 2021 18:41:47 +0000 (19:41 +0100)]
Merge pull request #4032 from joanbm/master

autotools: Avoid multiple liblxc.so with --enable-pam

2 years agoautotools: Avoid multiple liblxc.so with --enable-pam
Joan Bruguera [Sun, 7 Nov 2021 11:38:15 +0000 (12:38 +0100)]
autotools: Avoid multiple liblxc.so with --enable-pam

When installing LXC with the default options, a single non-symlink liblxc.so*
(e.g. liblxc.so.1.7.0) file is created:

```
    $ ./autogen.sh && ./configure && make && \
    rm -rf "$HOME/lxci" && make DESTDIR="$HOME/lxci" install && \
    stat -c%N "$HOME/lxci/usr/local/lib/liblxc.so"*
    [...]
    '/home/someone/lxci/usr/local/lib/liblxc.so' -> 'liblxc.so.1'
    '/home/someone/lxci/usr/local/lib/liblxc.so.1' -> 'liblxc.so.1.7.0'
    '/home/someone/lxci/usr/local/lib/liblxc.so.1.7.0'
```

However, when automake>=1.16.5, and the `--enable-pam` option is used, two
non-symlink liblxc.so* (e.g. liblxc.so.1.0.0 and liblxc.so.1.7.0) are
erroneously created:

```
    $ ./autogen.sh && ./configure --enable-pam && make && \
    rm -rf "$HOME/lxci" && make DESTDIR="$HOME/lxci" install && \
    stat -c%N "$HOME/lxci/usr/local/lib/liblxc.so"*
    [...]
    '/home/someone/lxci/usr/local/lib/liblxc.so' -> 'liblxc.so.1.0.0'
    '/home/someone/lxci/usr/local/lib/liblxc.so.1' -> 'liblxc.so.1.0.0'
    '/home/someone/lxci/usr/local/lib/liblxc.so.1.0.0'
    '/home/someone/lxci/usr/local/lib/liblxc.so.1.7.0'
```

This is due to infighting between libtool's and LXC's versioning:
libtool creates liblxc.so.1.0.0, then LXC's `install-exec-local` hook in
`Makefile.am` moves it to liblxc.so.1.7.0. However, with `--enable-pam`, the
`install-libLTLIBRARIES` target is re-triggered after `install-pamLTLIBRARIES`,
which will create liblxc.so.1.0.0 again.

The bigger problem here is that the install for the pam_cgfs library is done on
the `data` phase of the automake install process instead of the `exec` phase
(https://www.gnu.org/software/automake/manual/html_node/The-Two-Parts-of-Install.html),
which gives `install-libLTLIBRARIES` a chance to run again after the
`install-exec-local` / `install-exec-hook` targets have already run.

To fix this, we add an "exec_" prefix to the pam_cgfs library to make it run
during the `exec` phase (see link above). We also consolidate the various hooks
in the `install-exec-hook` target, which runs after the whole install, avoiding
needing to manually specify the dependencies like in `install-exec-local`.

Signed-off-by: Joan Bruguera <joanbrugueram@gmail.com>
2 years agoMerge pull request #4030 from brauner/2021-11-04.fixes
Stéphane Graber [Thu, 4 Nov 2021 15:28:03 +0000 (11:28 -0400)]
Merge pull request #4030 from brauner/2021-11-04.fixes

conf: lxc.proc.* and lxc.sysctl.* fixes and tests

2 years agobuild: refuse to compile with unsupported liburing version
Christian Brauner [Thu, 4 Nov 2021 14:45:58 +0000 (15:45 +0100)]
build: refuse to compile with unsupported liburing version

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agotests: add lxc.proc.* test
Christian Brauner [Thu, 4 Nov 2021 13:05:25 +0000 (14:05 +0100)]
tests: add lxc.proc.* test

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agotests: add lxc.sysctls.* test
Christian Brauner [Thu, 4 Nov 2021 10:59:08 +0000 (11:59 +0100)]
tests: add lxc.sysctls.* test

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agotest: improve logging helpers
Christian Brauner [Thu, 4 Nov 2021 11:13:02 +0000 (12:13 +0100)]
test: improve logging helpers

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoconf: improve logging setting sysctl and /proc/<pid>/ parameters
Christian Brauner [Thu, 4 Nov 2021 12:46:52 +0000 (13:46 +0100)]
conf: improve logging setting sysctl and /proc/<pid>/ parameters

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoconf: apply /proc/sys and /proc/<pid>/ parameters
Christian Brauner [Thu, 4 Nov 2021 10:26:00 +0000 (11:26 +0100)]
conf: apply /proc/sys and /proc/<pid>/ parameters

When porting to the new list type we added an accidental ! when checking
whether the list is empty.

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoMerge pull request #4028 from brauner/2021-11-02.fixes
Stéphane Graber [Tue, 2 Nov 2021 14:06:45 +0000 (10:06 -0400)]
Merge pull request #4028 from brauner/2021-11-02.fixes

start: fixes

2 years agotests: include config.h
Christian Brauner [Tue, 2 Nov 2021 10:06:33 +0000 (11:06 +0100)]
tests: include config.h

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agobuild: move _FILE_OFFSET_BITS to common option
Christian Brauner [Tue, 2 Nov 2021 09:57:24 +0000 (10:57 +0100)]
build: move _FILE_OFFSET_BITS to common option

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agostart: log signal name and number
Christian Brauner [Tue, 2 Nov 2021 09:48:52 +0000 (10:48 +0100)]
start: log signal name and number

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoprocess_utils: add signal_name() helper
Christian Brauner [Tue, 2 Nov 2021 09:42:09 +0000 (10:42 +0100)]
process_utils: add signal_name() helper

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoMerge pull request #4025 from brauner/2021-10-30.fixes
Stéphane Graber [Mon, 1 Nov 2021 14:33:51 +0000 (10:33 -0400)]
Merge pull request #4025 from brauner/2021-10-30.fixes

build: fixes

2 years agobuild: improve liburing support detection
Christian Brauner [Sat, 30 Oct 2021 15:45:50 +0000 (17:45 +0200)]
build: improve liburing support detection

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agomainloop: make ifdefs easier to follow
Christian Brauner [Sat, 30 Oct 2021 15:38:37 +0000 (17:38 +0200)]
mainloop: make ifdefs easier to follow

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoMerge pull request #4024 from simondeziel/no-which
Stéphane Graber [Thu, 28 Oct 2021 21:49:37 +0000 (17:49 -0400)]
Merge pull request #4024 from simondeziel/no-which

Replace remaining occurences of 'which' with 'command -v'

2 years agoReplace last occurence of 'which' with 'command -v'
Simon Deziel [Thu, 28 Oct 2021 17:09:48 +0000 (13:09 -0400)]
Replace last occurence of 'which' with 'command -v'

The later is builtin and POSIX compliant.

Signed-off-by: Simon Deziel <simon.deziel@canonical.com>
2 years agoMerge pull request #4021 from diederikdehaas/replace-which-in-tests-too
Stéphane Graber [Thu, 28 Oct 2021 19:32:01 +0000 (15:32 -0400)]
Merge pull request #4021 from diederikdehaas/replace-which-in-tests-too

Replace 'which' with 'command -v' in tests too

2 years agoMerge pull request #4023 from diederikdehaas/fix-SC2006
Stéphane Graber [Thu, 28 Oct 2021 19:31:53 +0000 (15:31 -0400)]
Merge pull request #4023 from diederikdehaas/fix-SC2006

Replace backticks with $() construct

2 years agoReplace deprecated backticks with $() construct
Diederik de Haas [Thu, 28 Oct 2021 17:30:05 +0000 (19:30 +0200)]
Replace deprecated backticks with $() construct

See https://github.com/koalaman/shellcheck/wiki/SC2006 for details.
Not only uses this the recommended construct, it also makes the code
more uniform as in many other places the $() construct was already used.

Signed-off-by: Diederik de Haas <didi.debian@cknow.org>
2 years agoMerge pull request #4020 from brauner/2021-10-28.fixes
Stéphane Graber [Thu, 28 Oct 2021 18:01:46 +0000 (14:01 -0400)]
Merge pull request #4020 from brauner/2021-10-28.fixes

build & mainloop: fixes

2 years agoMerge pull request #4018 from brauner/2021-10-28.fixes.2
Stéphane Graber [Thu, 28 Oct 2021 17:07:49 +0000 (13:07 -0400)]
Merge pull request #4018 from brauner/2021-10-28.fixes.2

confile: don't use path_simplify() on lxc.{execute,init}.cmd

2 years agoReplace 'which' with 'command -v' in tests too
Diederik de Haas [Thu, 28 Oct 2021 16:25:37 +0000 (18:25 +0200)]
Replace 'which' with 'command -v' in tests too

Forgot to modify and include the tests in previous PR, so do that now.

Signed-off-by: Diederik de Haas <didi.debian@cknow.org>
2 years agoMerge pull request #4019 from diederikdehaas/replace-which-with-command-v
Christian Brauner [Thu, 28 Oct 2021 16:06:17 +0000 (18:06 +0200)]
Merge pull request #4019 from diederikdehaas/replace-which-with-command-v

Replace 'which' with 'command -v'

2 years agostart: check event loop type before closing fd
Christian Brauner [Thu, 28 Oct 2021 15:39:42 +0000 (17:39 +0200)]
start: check event loop type before closing fd

Since this is a union we might otherwise stomp on io_uring mmap()ed
memory.

Fixes: #4016
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agomainloop: make sure that descr->ring is allocated
Christian Brauner [Thu, 28 Oct 2021 15:39:11 +0000 (17:39 +0200)]
mainloop: make sure that descr->ring is allocated

This is future proofing more than anything else.

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoReplace 'which' with 'command -v'
Diederik de Haas [Thu, 28 Oct 2021 15:27:08 +0000 (17:27 +0200)]
Replace 'which' with 'command -v'

The 'which' command is deprecated on Debian Sid as it is not POSIX
compliant and it's behavior is therefor not consistent, so replace it
with 'command -v' which is POSIX compliant.
See https://stackoverflow.com/a/677212 for details.

Also replaced a use of backticks (`) as that is deprecated as well.
See https://github.com/koalaman/shellcheck/wiki/SC2006 for details.

Signed-off-by: Diederik de Haas <didi.debian@cknow.org>
2 years agobuild: add io-uring-event-loop option
Christian Brauner [Thu, 28 Oct 2021 15:07:27 +0000 (17:07 +0200)]
build: add io-uring-event-loop option

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agobuild: add static libcap to output
Christian Brauner [Thu, 28 Oct 2021 15:07:14 +0000 (17:07 +0200)]
build: add static libcap to output

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoconfile: don't use path_simplify() on lxc.{execute,init}.cmd
Christian Brauner [Thu, 28 Oct 2021 14:53:14 +0000 (16:53 +0200)]
confile: don't use path_simplify() on lxc.{execute,init}.cmd

Fixes: #4015
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoMerge pull request #4013 from stgraber/master
Christian Brauner [Mon, 25 Oct 2021 13:11:06 +0000 (15:11 +0200)]
Merge pull request #4013 from stgraber/master

AUTHORS: Update to point to git history

2 years agoAUTHORS: Update to point to git history
Stéphane Graber [Mon, 25 Oct 2021 12:53:58 +0000 (08:53 -0400)]
AUTHORS: Update to point to git history

Signed-off-by: Stéphane Graber <stgraber@ubuntu.com>
2 years agoMerge pull request #4010 from brauner/2021-10-23.fixes
Stéphane Graber [Sun, 24 Oct 2021 05:41:36 +0000 (01:41 -0400)]
Merge pull request #4010 from brauner/2021-10-23.fixes

conf: handle kernels without or not using SMT

2 years agoconf: handle kernels without or not using SMT
Christian Brauner [Sat, 23 Oct 2021 17:15:24 +0000 (19:15 +0200)]
conf: handle kernels without or not using SMT

On kernel not enabling or not using SMT core scheduling will return with
ENODEV. Handle such kernels.

Link: https://github.com/lxc/lxd/issues/9419
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoMerge pull request #4008 from tenforward/japanese
Christian Brauner [Sat, 23 Oct 2021 08:29:06 +0000 (10:29 +0200)]
Merge pull request #4008 from tenforward/japanese

doc: Update Japanese lxc.container.conf(5) and common options

2 years agodoc: fix typo in English lxc.container.conf(5)
KATOH Yasufumi [Sat, 23 Oct 2021 06:26:26 +0000 (15:26 +0900)]
doc: fix typo in English lxc.container.conf(5)

Signed-off-by: KATOH Yasufumi <karma@jazz.email.ne.jp>
2 years agodoc: Add lxc.sched.core to Japanese lxc.container.conf(5)
KATOH Yasufumi [Sat, 23 Oct 2021 06:18:00 +0000 (15:18 +0900)]
doc: Add lxc.sched.core to Japanese lxc.container.conf(5)

Update for commit 09996a4

Signed-off-by: KATOH Yasufumi <karma@jazz.email.ne.jp>
2 years agodoc: add way to specify broadcast address to Japanese lxc.container.conf(5)
KATOH Yasufumi [Sat, 23 Oct 2021 05:53:58 +0000 (14:53 +0900)]
doc: add way to specify broadcast address to Japanese lxc.container.conf(5)

Update for commit 5686798

Signed-off-by: KATOH Yasufumi <karma@jazz.email.ne.jp>
2 years agodoc: add loglevels to ja and ko common options
KATOH Yasufumi [Sat, 23 Oct 2021 05:44:22 +0000 (14:44 +0900)]
doc: add loglevels to ja and ko common options

Update for commit 44b87e8

Signed-off-by: KATOH Yasufumi <karma@jazz.email.ne.jp>
2 years agoMerge pull request #4006 from coledishington/master
Christian Brauner [Fri, 22 Oct 2021 17:30:05 +0000 (19:30 +0200)]
Merge pull request #4006 from coledishington/master

Make number of rx and tx queues configurable for veths

2 years agoMake number of rx and tx queues configurable for veths
Cole Dishington [Mon, 18 Oct 2021 19:53:25 +0000 (08:53 +1300)]
Make number of rx and tx queues configurable for veths

Distribute traffic over cpu cores of container by configuring more
than 1 tx/rx queue.

Signed-off-by: Cole Dishington <Cole.Dishington@alliedtelesis.co.nz>
2 years agoMerge pull request #4005 from brauner/2021-10-21.fixes
Stéphane Graber [Thu, 21 Oct 2021 14:59:19 +0000 (10:59 -0400)]
Merge pull request #4005 from brauner/2021-10-21.fixes

conf: allow users to specify that they want a cgroup2 layout on a hybrid host

2 years agoconf: add cgroup2, cgroup2:ro, cgroup2:force, cgroup2:ro:force options
Christian Brauner [Thu, 21 Oct 2021 14:17:59 +0000 (16:17 +0200)]
conf: add cgroup2, cgroup2:ro, cgroup2:force, cgroup2:ro:force options

We keep running into situations where we want to pre-mount a pure
cgroup2 layout regardless of the layout of the host.

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoconf: make it more obvious how auto-mount flags are defined
Christian Brauner [Thu, 21 Oct 2021 13:44:58 +0000 (15:44 +0200)]
conf: make it more obvious how auto-mount flags are defined

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoMerge pull request #4004 from brauner/2021-10-20.fixes.2
Stéphane Graber [Wed, 20 Oct 2021 13:51:49 +0000 (09:51 -0400)]
Merge pull request #4004 from brauner/2021-10-20.fixes.2

criu: support restoring containers with pre-created veth devices

2 years agocriu: support restoring containers with pre-created veth devices
Christian Brauner [Wed, 20 Oct 2021 12:48:41 +0000 (14:48 +0200)]
criu: support restoring containers with pre-created veth devices

We did th CRIU and kernel work but for some reason we never did push the
LXC work.

Link: https://github.com/checkpoint-restore/criu/commit/cdb0d427020f0531f5a35146513c3a36b6eece11
      commit cdb0d427020f ("net: allow restoring of precreated veth devices")
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoMerge pull request #4003 from brauner/2021-10-19.fixes
Stéphane Graber [Tue, 19 Oct 2021 15:24:26 +0000 (11:24 -0400)]
Merge pull request #4003 from brauner/2021-10-19.fixes

conf: verify that rootfs is stable after setting up mounts

2 years agoconf: verify that rootfs is stable after setting up mounts
Christian Brauner [Tue, 19 Oct 2021 14:57:05 +0000 (16:57 +0200)]
conf: verify that rootfs is stable after setting up mounts

Apparently some users changed their rootfs via their lxc.mount.entry
entries. Let's not allow that as that can cause confusion during
container setup. So lets verify that the rootfs is stable after setup.

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoMerge pull request #4002 from xypron/riscv64
Stéphane Graber [Tue, 19 Oct 2021 14:58:23 +0000 (10:58 -0400)]
Merge pull request #4002 from xypron/riscv64

Riscv64

2 years agoREADME.md: mention RISC-V architecture
Heinrich Schuchardt [Tue, 19 Oct 2021 11:16:33 +0000 (13:16 +0200)]
README.md: mention RISC-V architecture

Signed-off-by: Heinrich Schuchardt <heinrich.schuchardt@canonical.com>
2 years agoAdd riscv64 to --arch parameter values
Heinrich Schuchardt [Tue, 19 Oct 2021 07:56:21 +0000 (09:56 +0200)]
Add riscv64 to --arch parameter values

lxc-attach uses an --arch parameter. 'riscv64' should be a usable value.

Signed-off-by: Heinrich Schuchardt <heinrich.schuchardt@canonical.com>
2 years agoMerge pull request #4000 from brauner/2021-10-18.fixes
Stéphane Graber [Mon, 18 Oct 2021 14:01:24 +0000 (10:01 -0400)]
Merge pull request #4000 from brauner/2021-10-18.fixes

conf: fixes

2 years agoconf: don't fail umount2()
Christian Brauner [Mon, 18 Oct 2021 10:07:37 +0000 (12:07 +0200)]
conf: don't fail umount2()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoconf: fix coding style
Christian Brauner [Mon, 18 Oct 2021 09:46:16 +0000 (11:46 +0200)]
conf: fix coding style

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoMerge pull request #3997 from brauner/2021-10-15.fixes
Stéphane Graber [Fri, 15 Oct 2021 13:19:47 +0000 (09:19 -0400)]
Merge pull request #3997 from brauner/2021-10-15.fixes

log: fixes

2 years agocaps: ensure \0-termination
Christian Brauner [Fri, 15 Oct 2021 09:29:27 +0000 (11:29 +0200)]
caps: ensure \0-termination

Fixes: Coverity 1492865
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoattach: improve error logging
Christian Brauner [Fri, 15 Oct 2021 08:06:48 +0000 (10:06 +0200)]
attach: improve error logging

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoaf_unix: replace log_error_errno()
Christian Brauner [Fri, 15 Oct 2021 07:59:28 +0000 (09:59 +0200)]
af_unix: replace log_error_errno()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoMerge pull request #3996 from tych0/fix-criu-log
Stéphane Graber [Thu, 14 Oct 2021 17:02:36 +0000 (13:02 -0400)]
Merge pull request #3996 from tych0/fix-criu-log

criu: fix error message

2 years agocriu: fix error message
Tycho Andersen [Thu, 14 Oct 2021 16:40:08 +0000 (10:40 -0600)]
criu: fix error message

as of 59d8a539d106 ("criu: massage exec_criu()") I see:

In file included from criu.c:22:
criu.c: In function 'exec_criu':
log.h:376:2: error: '%s' directive argument is null [-Werror=format-overflow=]
  376 |  LXC_ERROR(&locinfo, format, ##__VA_ARGS__);   \
      |  ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
log.h:457:3: note: in expansion of macro 'ERROR'
  457 |   ERROR("%s - " format, ptr, ##__VA_ARGS__); \
      |   ^~~~~
log.h:491:3: note: in expansion of macro 'SYSERROR'
  491 |   SYSERROR(format, ##__VA_ARGS__);              \
      |   ^~~~~~~~
criu.c:325:11: note: in expansion of macro 'log_error_errno'
  325 |    return log_error_errno(-ENOMEM, ENOMEM, "Failed to remove extraneous slashes from \"%s\"", tmp);
      |           ^~~~~~~~~~~~~~~

it looks like we should be logging the string that failed, vs. tmp here.

(my log was taken from stable-4.0, but the same issue exists on master it
seems.)

Signed-off-by: Tycho Andersen <tycho@tycho.pizza>
2 years agoMerge pull request #3995 from brauner/2021-10-13.fixes
Stéphane Graber [Thu, 14 Oct 2021 14:38:18 +0000 (10:38 -0400)]
Merge pull request #3995 from brauner/2021-10-13.fixes

tree-wide: capability tests and fixes

2 years agotest: fix nested capability tests
Christian Brauner [Thu, 14 Oct 2021 11:59:34 +0000 (13:59 +0200)]
test: fix nested capability tests

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
2 years agoattach: improve error logging for drop_capabilities()
Christian Brauner [Thu, 14 Oct 2021 09:52:06 +0000 (11:52 +0200)]
attach: improve error logging for drop_capabilities()

Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>