]> git.proxmox.com Git - lxc.git/log
lxc.git
2 years agoupdate patches for lxc-4.0.11
Wolfgang Bumiller [Thu, 2 Dec 2021 09:32:22 +0000 (10:32 +0100)]
update patches for lxc-4.0.11

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
2 years agoupdate to lxc-4.0.11
Wolfgang Bumiller [Thu, 2 Dec 2021 09:12:40 +0000 (10:12 +0100)]
update to lxc-4.0.11

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
2 years agobump version to 4.0.9-4
Thomas Lamprecht [Tue, 20 Jul 2021 15:28:18 +0000 (17:28 +0200)]
bump version to 4.0.9-4

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
2 years agopatches: update series file with latest patches
Stoiko Ivanov [Tue, 20 Jul 2021 15:09:09 +0000 (17:09 +0200)]
patches: update series file with latest patches

Signed-off-by: Stoiko Ivanov <s.ivanov@proxmox.com>
2 years agobump version to 4.0.9-3
Thomas Lamprecht [Tue, 20 Jul 2021 11:35:24 +0000 (13:35 +0200)]
bump version to 4.0.9-3

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
2 years agoadd patches for cgroup handling in non-unified cgroup setups
Stoiko Ivanov [Tue, 20 Jul 2021 10:52:00 +0000 (12:52 +0200)]
add patches for cgroup handling in non-unified cgroup setups

I opened a PR at lxc-upstream with these changes [0].

Testing in my hybrid layout environment fixes the issue with
priviledged container reported in the forum.
(Note that the issue also occurs with unprivileged container, if they
have a `lxc.cgroup.devices.(allow|deny)` entry (which they don't in
our default config)

[0] https://github.com/lxc/lxc/pull/3911

Signed-off-by: Stoiko Ivanov <s.ivanov@proxmox.com>
2 years agobump version to 4.0.9-2
Wolfgang Bumiller [Mon, 5 Jul 2021 07:54:55 +0000 (09:54 +0200)]
bump version to 4.0.9-2

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
2 years agoadd patch to include userns.conf.d/
Wolfgang Bumiller [Mon, 5 Jul 2021 07:04:43 +0000 (09:04 +0200)]
add patch to include userns.conf.d/

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
2 years agobuildsys: change upload dist to bullseye
Thomas Lamprecht [Tue, 8 Jun 2021 07:38:38 +0000 (09:38 +0200)]
buildsys: change upload dist to bullseye

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
3 years agobump version to 4.0.9-1
Thomas Lamprecht [Wed, 12 May 2021 17:25:01 +0000 (19:25 +0200)]
bump version to 4.0.9-1

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
3 years agolxc-pve: adapt to new file locations
Thomas Lamprecht [Wed, 12 May 2021 17:24:38 +0000 (19:24 +0200)]
lxc-pve: adapt to new file locations

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
3 years agod/control: drop pve-libseccomp2.4-dev in favor of debians now new enough one
Thomas Lamprecht [Wed, 12 May 2021 17:24:00 +0000 (19:24 +0200)]
d/control: drop pve-libseccomp2.4-dev in favor of debians now new enough one

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
3 years agod/control: bump debhelper compat to >= 12
Thomas Lamprecht [Wed, 12 May 2021 17:22:18 +0000 (19:22 +0200)]
d/control: bump debhelper compat to >= 12

where the previously deprecated passing of fail-missing to dh_install
got an real error, so adapt to that and use the new dh_missing
debhelper.

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
3 years agoimport LXC 4.0.9 and update patches
Thomas Lamprecht [Wed, 12 May 2021 17:21:45 +0000 (19:21 +0200)]
import LXC 4.0.9 and update patches

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
3 years agobump version to 4.0.6-2
Thomas Lamprecht [Tue, 9 Feb 2021 06:53:53 +0000 (07:53 +0100)]
bump version to 4.0.6-2

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
3 years agoupdate to current stable-4.0
Thomas Lamprecht [Tue, 9 Feb 2021 06:49:18 +0000 (07:49 +0100)]
update to current stable-4.0

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
3 years agobump version to 4.0.6-1
Wolfgang Bumiller [Mon, 25 Jan 2021 10:27:03 +0000 (11:27 +0100)]
bump version to 4.0.6-1

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
3 years agoupdate to lxc-4.0.6
Wolfgang Bumiller [Mon, 25 Jan 2021 10:26:30 +0000 (11:26 +0100)]
update to lxc-4.0.6

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
3 years agobump version to 4.0.3-1
Wolfgang Bumiller [Fri, 31 Jul 2020 09:09:21 +0000 (11:09 +0200)]
bump version to 4.0.3-1

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
3 years agorebase on lxc-4.0.3 tag
Wolfgang Bumiller [Fri, 31 Jul 2020 09:07:51 +0000 (11:07 +0200)]
rebase on lxc-4.0.3 tag

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
3 years agomerge fix for busy-looping on cgroup events
Wolfgang Bumiller [Thu, 30 Jul 2020 13:08:35 +0000 (15:08 +0200)]
merge fix for busy-looping on cgroup events

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
3 years agoapparmor: add rule for allowing remount of boot_id
Stoiko Ivanov [Wed, 22 Jul 2020 11:05:05 +0000 (13:05 +0200)]
apparmor: add rule for allowing remount of boot_id

commit 863845075d3f77d27c91bd9f47d2f8ddc4867bd5 in upstream only partially
fixes the apparmor deny for mounting boot_id (used for example for identifying
different boots with `journalctl`) inside the container.

Tested by editing the profile and replacing it disregarding the cache:
`apparmor_parser -W -T -r /etc/apparmor.d/usr.bin.lxc-start`

Signed-off-by: Stoiko Ivanov <s.ivanov@proxmox.com>
Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
3 years agoupdate lxc to include fixes for cgroupv2 setups
Stoiko Ivanov [Wed, 22 Jul 2020 11:05:04 +0000 (13:05 +0200)]
update lxc to include fixes for cgroupv2 setups

This commit fast-forwards 7 commits from upstream/master. The first commit
(partially) fixes a missing apparmor rule for /proc/sys/kernel/random/boot_id)

The last commit fixes running containers in pure cgroupv2 environments (by
premounting cgroup2).

It contains one other fix for a netlink bug, which I haven't seen in our
support channels, thus assume limited potential for regressions.

Signed-off-by: Stoiko Ivanov <s.ivanov@proxmox.com>
Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agobump version to 4.0.2-1
Wolfgang Bumiller [Mon, 20 Apr 2020 09:49:32 +0000 (11:49 +0200)]
bump version to 4.0.2-1

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agobump version to 4.0.0-2
Wolfgang Bumiller [Tue, 7 Apr 2020 08:53:57 +0000 (10:53 +0200)]
bump version to 4.0.0-2

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agoupdate to current master: devices cgroup isolation fixes
Wolfgang Bumiller [Tue, 7 Apr 2020 07:07:08 +0000 (09:07 +0200)]
update to current master: devices cgroup isolation fixes

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agobump version to 4.0.0-1
Wolfgang Bumiller [Fri, 27 Mar 2020 08:59:10 +0000 (09:59 +0100)]
bump version to 4.0.0-1

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agopve-container is going to 3.1-1, update Breaks
Wolfgang Bumiller [Mon, 6 Apr 2020 12:23:59 +0000 (14:23 +0200)]
pve-container is going to 3.1-1, update Breaks

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agoBreaks: pve-container (<= 3.0-24)
Wolfgang Bumiller [Mon, 6 Apr 2020 09:19:21 +0000 (11:19 +0200)]
Breaks: pve-container (<= 3.0-24)

We dropped some configuration aptches with lxc-4 which
pve-container needs to account for when writing a
container's /var/lib/lxc/$vmid/config file, so lxc-4 should
not be used with an older pve-container package.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agoupdate to master / lxc-4.0.0+fixes
Wolfgang Bumiller [Fri, 27 Mar 2020 08:56:36 +0000 (09:56 +0100)]
update to master / lxc-4.0.0+fixes

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agopostinst fixup
Wolfgang Bumiller [Thu, 2 Apr 2020 13:24:08 +0000 (15:24 +0200)]
postinst fixup

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agopostinst: reload/restart lxc.service later
Fabian Grünbichler [Wed, 6 Nov 2019 10:08:54 +0000 (11:08 +0100)]
postinst: reload/restart lxc.service later

since the debhelper-generated default enabling should come before we
attempt to start/reload/restart it.

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
4 years agopostinst: ignore lxc.service reload errors
Fabian Grünbichler [Wed, 6 Nov 2019 10:08:53 +0000 (11:08 +0100)]
postinst: ignore lxc.service reload errors

otherwise this could fail posinst execution (and thus package
installation!) on systems coming from plain Debian, or where lxc.service
is masked.

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
4 years agobump version to 3.2.1-1
Wolfgang Bumiller [Wed, 23 Oct 2019 09:05:22 +0000 (11:05 +0200)]
bump version to 3.2.1-1

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agobuild with pve-libseccomp2.4
Wolfgang Bumiller [Wed, 23 Oct 2019 08:59:06 +0000 (10:59 +0200)]
build with pve-libseccomp2.4

To allow syscall interception.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agoupdate to current master
Wolfgang Bumiller [Wed, 23 Oct 2019 08:58:14 +0000 (10:58 +0200)]
update to current master

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agobump version to 3.1.0-65
Wolfgang Bumiller [Tue, 3 Sep 2019 12:09:09 +0000 (14:09 +0200)]
bump version to 3.1.0-65

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agoupdate apparmor patch
Wolfgang Bumiller [Tue, 3 Sep 2019 12:07:44 +0000 (14:07 +0200)]
update apparmor patch

the previous patch removed some required lines from the
nesting profile part, this brings it closer to lxd plus the
additional read-only-bind-remount rule generation

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agobump version to 3.1.0-64
Wolfgang Bumiller [Tue, 13 Aug 2019 12:02:55 +0000 (14:02 +0200)]
bump version to 3.1.0-64

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agomerge fix for 'getent' in lxc-attach
Wolfgang Bumiller [Tue, 13 Aug 2019 12:18:47 +0000 (14:18 +0200)]
merge fix for 'getent' in lxc-attach

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agofix issues with shell detection on attach
Wolfgang Bumiller [Tue, 13 Aug 2019 12:01:27 +0000 (14:01 +0200)]
fix issues with shell detection on attach

Merge: attach: always use getent

Commit message:
In debian buster, some libnss plugins (if installed) can
cause getpwent to segfault instead of erroring out cleanly.
To avoid this, stick to always using getent.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agobump version to 3.1.0-63
Wolfgang Bumiller [Fri, 9 Aug 2019 09:48:30 +0000 (11:48 +0200)]
bump version to 3.1.0-63

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agomerge new apparmor profile update
Wolfgang Bumiller [Fri, 9 Aug 2019 08:49:43 +0000 (10:49 +0200)]
merge new apparmor profile update

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agobump version to 3.1.0-62
Wolfgang Bumiller [Mon, 5 Aug 2019 07:23:41 +0000 (09:23 +0200)]
bump version to 3.1.0-62

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agoupdate apparmor profile
Wolfgang Bumiller [Fri, 2 Aug 2019 11:01:30 +0000 (13:01 +0200)]
update apparmor profile

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agofixup
Wolfgang Bumiller [Thu, 11 Jul 2019 10:14:18 +0000 (12:14 +0200)]
fixup

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agobump version to 3.1.0-61
Wolfgang Bumiller [Thu, 11 Jul 2019 10:13:23 +0000 (12:13 +0200)]
bump version to 3.1.0-61

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agobump compat to 11, fix reloading of lxc.service
Wolfgang Bumiller [Thu, 11 Jul 2019 10:11:27 +0000 (12:11 +0200)]
bump compat to 11, fix reloading of lxc.service

Add a patch to add an ExecReload for lxc.service, and use
the new dh_installsystemd instead of the old
dh_systemd_start.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
4 years agod/rules: whitespace fixup
Wolfgang Bumiller [Wed, 3 Jul 2019 14:29:32 +0000 (16:29 +0200)]
d/rules: whitespace fixup

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agobuildsys: switch upload dist over to buster
Thomas Lamprecht [Wed, 22 May 2019 10:34:31 +0000 (12:34 +0200)]
buildsys: switch upload dist over to buster

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
5 years agobump version to 3.1.0-60
Thomas Lamprecht [Wed, 22 May 2019 10:30:23 +0000 (12:30 +0200)]
bump version to 3.1.0-60

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
5 years agobump debian compat level to 10
Thomas Lamprecht [Wed, 22 May 2019 10:28:27 +0000 (12:28 +0200)]
bump debian compat level to 10

This allows to remove a few dependencies and flags from dh which are
now implied or obsolete

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
5 years agobuildsys: use dpkg-dev makefile helpers for pkg info
Thomas Lamprecht [Wed, 22 May 2019 10:28:08 +0000 (12:28 +0200)]
buildsys: use dpkg-dev makefile helpers for pkg info

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
5 years agobump version to 3.1.0-3
Wolfgang Bumiller [Tue, 12 Feb 2019 07:07:15 +0000 (08:07 +0100)]
bump version to 3.1.0-3

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agomerge fix for CVE-2019-5736
Wolfgang Bumiller [Tue, 12 Feb 2019 07:07:07 +0000 (08:07 +0100)]
merge fix for CVE-2019-5736

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agobump version to 3.1.0-2
Wolfgang Bumiller [Thu, 17 Jan 2019 08:24:16 +0000 (09:24 +0100)]
bump version to 3.1.0-2

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agomerge 2 fixups:
Wolfgang Bumiller [Thu, 17 Jan 2019 08:22:01 +0000 (09:22 +0100)]
merge 2 fixups:

* Revert "conf: remove extra MS_BIND with sysfs:mixed"
    This should let privileged Ubuntu 14.04 containers boot
    again.

* conf: use SYSERROR on lxc_write_to_file errors
    Slightly more useful error output in a specific error
    case.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agobuildsys: use dpkg-parsechangelog
Wolfgang Bumiller [Thu, 17 Jan 2019 08:32:04 +0000 (09:32 +0100)]
buildsys: use dpkg-parsechangelog

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agoupdate to lxc-3.1.0
Wolfgang Bumiller [Wed, 2 Jan 2019 08:40:29 +0000 (09:40 +0100)]
update to lxc-3.1.0

The default cgroup pattern was switched from lxc/%n to
lxc.payload/%n, so add a ./configure option to revert this
change as PVE expects containers in lxc/%n.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agobump version to 3.0.2+pve1-5
Wolfgang Bumiller [Mon, 19 Nov 2018 11:16:52 +0000 (12:16 +0100)]
bump version to 3.0.2+pve1-5

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agoRevert "d/control: bump compat to 10"
Wolfgang Bumiller [Mon, 19 Nov 2018 11:29:35 +0000 (12:29 +0100)]
Revert "d/control: bump compat to 10"

The new dh_systemd_start parameter behavior is stupid.
Might be less so with compat 11 later on...

This reverts commit 4d672101f14f9e5358b8b79bd11c3d9b783af482.

5 years agofix typo in package description
Oguz Bektas [Tue, 20 Nov 2018 09:11:11 +0000 (10:11 +0100)]
fix typo in package description

Signed-off-by: Oguz Bektas <o.bektas@proxmox.com>
5 years agobump version to 3.0.2+pve1-4
Wolfgang Bumiller [Fri, 16 Nov 2018 11:13:16 +0000 (12:13 +0100)]
bump version to 3.0.2+pve1-4

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agoapparmor: allow various ro,remount,bind mounts
Wolfgang Bumiller [Thu, 15 Nov 2018 11:21:56 +0000 (12:21 +0100)]
apparmor: allow various ro,remount,bind mounts

Required to enable new systemd sandboxing mechanisms.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agod/control: add missing build-dependencies
Wolfgang Bumiller [Thu, 8 Nov 2018 09:01:39 +0000 (10:01 +0100)]
d/control: add missing build-dependencies

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agod/control: set Source package to lxc-pve
Wolfgang Bumiller [Wed, 7 Nov 2018 16:06:35 +0000 (17:06 +0100)]
d/control: set Source package to lxc-pve

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agod/control: bump compat to 10
Wolfgang Bumiller [Wed, 7 Nov 2018 16:04:28 +0000 (17:04 +0100)]
d/control: bump compat to 10

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agobuildsys: split deb target into deb and src
Wolfgang Bumiller [Wed, 7 Nov 2018 16:01:47 +0000 (17:01 +0100)]
buildsys: split deb target into deb and src

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agobump version to 3.0.2+pve1-3
Wolfgang Bumiller [Thu, 11 Oct 2018 09:52:30 +0000 (11:52 +0200)]
bump version to 3.0.2+pve1-3

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agofixup patch names namespace separation patch
Wolfgang Bumiller [Thu, 11 Oct 2018 09:48:58 +0000 (11:48 +0200)]
fixup patch names namespace separation patch

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agoAdd debian/SOURCE to docs to install
Rhonda D'Vine [Thu, 6 Sep 2018 07:22:35 +0000 (09:22 +0200)]
Add debian/SOURCE to docs to install

The lxc packages were missing the SOURCE file in the docs.

Signed-off-by: Rhonda D'Vine <rhonda@proxmox.com>
5 years agoremove some non-default lxc.cap.drop entries
Wolfgang Bumiller [Tue, 4 Sep 2018 13:00:12 +0000 (15:00 +0200)]
remove some non-default lxc.cap.drop entries

This really shouldn't be that much distro specific...

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agobump version to 3.0.2+pve1-2
Wolfgang Bumiller [Tue, 4 Sep 2018 12:51:22 +0000 (14:51 +0200)]
bump version to 3.0.2+pve1-2

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agoremove .gitignore as it contains only 1 entry
Wolfgang Bumiller [Mon, 27 Aug 2018 09:49:29 +0000 (11:49 +0200)]
remove .gitignore as it contains only 1 entry

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agobuildsys: remove update-template-configs target
Wolfgang Bumiller [Mon, 27 Aug 2018 09:48:08 +0000 (11:48 +0200)]
buildsys: remove update-template-configs target

Most of them aren't needed and we want to try to get rid of
these distro-specific configuration files in the long run.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agoconfig: opensuse.common: unset lxc.tty.dir key
Thomas Lamprecht [Thu, 23 Aug 2018 11:51:03 +0000 (13:51 +0200)]
config: opensuse.common: unset lxc.tty.dir key

not needed for *suse containers and results in cases where we get two
agetty processes when using xterm.js/noVNC (e.g., one on /dev/tty1
and one on /dev/lxc/tty1)

Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
5 years agobump version to 3.0.2+pve1-1
Wolfgang Bumiller [Mon, 20 Aug 2018 09:51:46 +0000 (11:51 +0200)]
bump version to 3.0.2+pve1-1

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
5 years agobump version to 3.0.1+pve2-1
Fabian Grünbichler [Tue, 7 Aug 2018 09:41:44 +0000 (11:41 +0200)]
bump version to 3.0.1+pve2-1

5 years agocherry-pick CVE-2018-6556 fix
Fabian Grünbichler [Tue, 7 Aug 2018 09:39:50 +0000 (11:39 +0200)]
cherry-pick CVE-2018-6556 fix

from upstream's stable-3.0 branch

5 years agobump version to 3.0.1+pve1-1
Wolfgang Bumiller [Thu, 19 Jul 2018 09:33:35 +0000 (11:33 +0200)]
bump version to 3.0.1+pve1-1

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agobump version to 3.0.0-3
Wolfgang Bumiller [Wed, 2 May 2018 08:50:37 +0000 (10:50 +0200)]
bump version to 3.0.0-3

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agomerge upstream bugfixes:
Wolfgang Bumiller [Wed, 2 May 2018 08:43:05 +0000 (10:43 +0200)]
merge upstream bugfixes:

  * fix some memory leaks
  * fix temp file creation
  * fix rootfs pinning with NFS
  * drop supplementary groups on attach
  * fix gid=5 mount option on /dev/pts

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agobump version to 3.0.0-2
Wolfgang Bumiller [Fri, 30 Mar 2018 08:20:02 +0000 (10:20 +0200)]
bump version to 3.0.0-2

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoinstall lxc-template configs again
Wolfgang Bumiller [Fri, 30 Mar 2018 08:17:26 +0000 (10:17 +0200)]
install lxc-template configs again

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoupdate configs from lxc-templates
Wolfgang Bumiller [Fri, 30 Mar 2018 08:16:54 +0000 (10:16 +0200)]
update configs from lxc-templates

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agobuildsys: GITVERSION fixup
Wolfgang Bumiller [Fri, 30 Mar 2018 07:50:10 +0000 (09:50 +0200)]
buildsys: GITVERSION fixup

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agobump version to 3.0.0-1
Wolfgang Bumiller [Wed, 28 Mar 2018 11:53:28 +0000 (13:53 +0200)]
bump version to 3.0.0-1

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agobump version to 2.1.1-3
Fabian Grünbichler [Mon, 5 Mar 2018 11:34:06 +0000 (12:34 +0100)]
bump version to 2.1.1-3

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
6 years agoreplace AA's feature-set with custom one
Fabian Grünbichler [Mon, 5 Mar 2018 11:34:05 +0000 (12:34 +0100)]
replace AA's feature-set with custom one

Debian's apparmor package introduced feature-set pinning in Debian
Stretch 9.4 to prevent problems with AA profiles packaged in Debian
Stretch which target Debian Stretch's 4.9 based kernel.

Since our LXC profiles rely on features not included in this feature
set, we need to replace the pinned feature-set with our own.

The features file is not a conf-file, so it is possible to just
dpkg-divert it on installation/upgrades.

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
6 years agoadd AA feature set for 4.13.13-6-pve
Fabian Grünbichler [Mon, 5 Mar 2018 11:34:04 +0000 (12:34 +0100)]
add AA feature set for 4.13.13-6-pve

copied from /etc/apparmor.d/cache/.features with disabled
feature-pinning to obtain kernel feature set

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
6 years agobump version to 2.1.1-2
Wolfgang Bumiller [Fri, 24 Nov 2017 12:48:07 +0000 (13:48 +0100)]
bump version to 2.1.1-2

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agomerge lxc-console improvements from stable branch
Wolfgang Bumiller [Fri, 24 Nov 2017 12:46:51 +0000 (13:46 +0100)]
merge lxc-console improvements from stable branch

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agobuildsys: cleanup & dbgsym package switch
Wolfgang Bumiller [Mon, 20 Nov 2017 13:15:37 +0000 (14:15 +0100)]
buildsys: cleanup & dbgsym package switch

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agobump version to 2.1.1-1
Wolfgang Bumiller [Mon, 20 Nov 2017 10:14:38 +0000 (11:14 +0100)]
bump version to 2.1.1-1

And switch to using submodules.

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agoremove old README
Wolfgang Bumiller [Mon, 20 Nov 2017 10:15:06 +0000 (11:15 +0100)]
remove old README

Signed-off-by: Wolfgang Bumiller <w.bumiller@proxmox.com>
6 years agobuild: reformat debian/control
Fabian Grünbichler [Wed, 4 Oct 2017 09:05:33 +0000 (11:05 +0200)]
build: reformat debian/control

using wrap-and-sort -abt

6 years agobump version to 2.1.0-2
Wolfgang Bumiller [Tue, 19 Sep 2017 08:06:43 +0000 (10:06 +0200)]
bump version to 2.1.0-2

6 years agoupdate cgroup namespace separation patches
Wolfgang Bumiller [Tue, 19 Sep 2017 08:04:57 +0000 (10:04 +0200)]
update cgroup namespace separation patches

6 years agobump version to 2.1.0-1
Wolfgang Bumiller [Wed, 6 Sep 2017 08:45:32 +0000 (10:45 +0200)]
bump version to 2.1.0-1

6 years agoupdate to lxc-2.1.0
Wolfgang Bumiller [Wed, 6 Sep 2017 08:43:45 +0000 (10:43 +0200)]
update to lxc-2.1.0