commit lxc.3935 for openSUSE:13.2:Update
Hello community, here is the log from the commit of package lxc.3935 for openSUSE:13.2:Update checked in at 2015-07-30 11:15:18 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:13.2:Update/lxc.3935 (Old) and /work/SRC/openSUSE:13.2:Update/.lxc.3935.new (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Package is "lxc.3935" Changes: -------- New Changes file: --- /dev/null 2015-07-22 21:25:44.928025004 +0200 +++ /work/SRC/openSUSE:13.2:Update/.lxc.3935.new/lxc.changes 2015-07-30 11:15:19.000000000 +0200 @@ -0,0 +1,549 @@ +------------------------------------------------------------------- +Thu Jul 23 09:23:19 UTC 2015 - jslaby@suse.com + +- Added CVE-2015-1331-lxclock-use-run-lxc-lock-rather-than-r.patch + (bnc#938522) +- Added CVE-2015-1334-Don-t-use-the-container-s-proc-during-.patch + (bnc#938523) + +------------------------------------------------------------------- +Sat Sep 27 05:12:44 UTC 2014 - opensuse_buildservice@ojkastl.de + +- update to 1.0.6, which includes the following changes/fixes: + rootfs_is_blockdev: don't run if no rootfs is specified + confile: sanity-check netdev->type before setting netdev->priv elements + Fix typo in previous patch + Remove mention of mountcgroups in ubuntu.common config + remove mountcgroup hook entirely + Add SIGPWR support to lxc_init + Sysvinit script fixes + unprivileged containers: use next available nic name if unspecified + fix typo in btrfs error msg + apparmor: Allow slave bind mounts + provide an example SELinux policy for older releases + print a helpful message if creating unpriv container with no idmap + use non-thread-safe getpwuid and getpwgid for android + btrfs: support recursive subvolume deletion (v2) + fix '--log-priority' --> '--logpriority' in main + Fix a file descriptor leak in the daemonization + Fix a file descriptor leak in the monitord spawn + Ensure /dev/pts directory exists on pts setup + Do not allow snapshots of LVM backed containers + add lxc.console.logpath + coverity: don't use newname after null check + coverity: malloc the right size for btrs_node tree + introduce --with-distro=raspbian + cgmanager get/set: clean up child (v2) + Add extra debugging + Fix typo in the previous commit... + do_mount_entry: add nexec, nosuid, nodev, rdonly flags if needed at remount + command socket: use hash if needed + monitor: fix sockname calculation for long lxcpaths + show additional info if btrfs subvolume deletion fails (issue #315) + ignore SIGKILL (CTRL-C) and SIGQUIT (CTRL-\) - issue #313 + chmod container dir to 0770 (v2) + build: Fix support for split build and source dirs + mount_entry: use statvfs + lxc_mount_auto_mounts: honor existing nodev etc at remounts + statvfs: do nothing if statvfs does not exist (android/bionic) + Prevent compiler warning by initializing ifindex + build: don't remove configuration template on clean + build: Make setup.py run from srcdir to avoid distutils errors + handle hashed command socket names (v2) + lxc-cgm: fix issue with nested chowning + Report container exit status to monitord + support use of 'all' containers when cgmanager supports it + log: fix quiet mode + Fix build error(ISO C90 specs violation) in lxc.c + lxc_map_ids: don't do bogus chekc for newgidmap + lxc_map_ids: add a comment + clean autodev dir on container exit + As discussed on ML, do not clean autodev dir on reboot + Fix build failure due to slightly different rmdir + Fix presentation of IPv6 addresses and gateway + + lxc-start: Add -F (foreground) option + + all: Discontinue the use of in-line comments (stable) + all: Include hostname in DHCP requests + all: Switch from arch command to uname -m + altlinux: bugfixes + archlinux: Properly set default locale in /etc/locale.conf + centos template: prevent mingetty from calling vhangup(2) + download: Have wget retry 3 times + download: Make --keyserver actually work + gentoo: keep original uid/gid of files/dirs when installing + gentoo: Use portageq to determine portage distdir + plamo: keep original uid/gid of files/dirs when installing + plamo: bugfix template + ssh: send hostname to dhcp server + ubuntu: don't check for $rootfs/run/shm + ubuntu: add help string + + lxc-test-{unpriv,usernic.in}: make sure to chgrp as well + lxc-test-unpriv: test lxc-clone -s + tests: Call sync before testing a shutdown + tests: Copy the download cache when available [v2] + Fix the unprivileged tests cgroup management + + doc: Mention that veth.pair is ignored for unpriv + doc: Add mention that veth.pair is ignored for unpriv in Japanese man + doc: Add -F option to Japanese lxc-start(1) + doc: Update the description of SELinux in Japanese lxc.container.conf(5) + doc: Add 'zfs' to the parameter of -B option in lxc-create(1) + doc: add lxc.console.logpath to Japanese lxc.container.conf(5) + doc: language correction + doc: Fix Japanese translation of lxc.container.conf(5) + doc: Add destroy option to lxc-snapshot(1) + doc: Add description about ignoring lxc.cgroup.use when using cgmanager +- delete: 0002-lxc-autostart-helper-working-even-if-action-is-not-a.patch +- delete: 0003-lxc-autostart-helper-working-even-if-var-lock-subsys.patch + +------------------------------------------------------------------- +Fri Aug 15 14:43:35 UTC 2014 - opensuse_buildservice@ojkastl.de + +- third patch to get lxc-autostart-helper to work on openSUSE + * 0003-lxc-autostart-helper-working-even-if-var-lock-subsys.patch + +------------------------------------------------------------------- +Fri Aug 15 13:04:48 UTC 2014 - opensuse_buildservice@ojkastl.de + +- added another patch to ensure correct operation of lxc.service systemd-unit + * 0002-lxc-autostart-helper-working-even-if-action-is-not-a.patch + +------------------------------------------------------------------- +Thu Aug 14 19:26:33 UTC 2014 - opensuse_buildservice@ojkastl.de + +- added patch to ensure correct operation of lxc.service systemd-unit + * 0001-systemd-Ensure-action-is-defined.patch + +------------------------------------------------------------------- +Wed Aug 6 19:38:55 UTC 2014 - opensuse_buildservice@ojkastl.de + +- update to 1.0.5 + * seccomp profile + * core: Fix unprivileged containers to work with recent kernels. + * core: Fix building with -Werror=maybe-uninitialized. + * core: seccomp: Don't fail on unresolvable syscalls. + * core: lxc-init: Don't force dropping capabilities. + * core: configure: Split -lcap and -lselinux out of LIBS. + * core: configure: Fix expansion of libexecdir. + * core: seccomp: Support 'all' arch sections. + * core: seccomp: Fix 32-bit rules. + * core: seccomp: Enable a default filter for all templates. + * core: Fix corruption in write_config. + * core: attach: Fix querying for the current personality. + * core: cgmanager: Have cgm_set and cgm_get use absolute paths when possible. + * core: cgmanager: Make sure @value is null-terminated in cgm_get. + * core: optimization of signal filtering/parsing code. + * core: apparmor: Allow hugetlbfs by default (similar to tmpfs and restricted by the hugetlb cgroup controller). + * core: Fix find_fstype_cb to ignore blank lines and comments. + * lxc-autostart: Actually respect -P when passed. + * lxc-attach: Fix typo in usage. + * lxc-start: propagate the container exit code. + * lxc-stop: Fix incorrect timeout handling. + * lxc-device: Support --version. + * lxc-ls: Support --version. + * lxc-start-ephemeral: Support --version. + * tests: Avoid the download template when possible. + * tests: Don't fail when HOME isn't defined. + * tests: apparmor: Always end messages with a newline. + * tests: Clarify error message and fix return codes. + * tests: lxc-test-ubuntu doesn't actually need bind9-host. + * lxc-debian: standardize formatting. + * lxc-debian: fix formatting. + * python3: Fix attach_wait and threads. + +------------------------------------------------------------------- +Fri Jun 13 19:33:04 UTC 2014 - opensuse_buildservice@ojkastl.de + +- fixed the build errors + +------------------------------------------------------------------- +Fri Jun 13 18:24:48 UTC 2014 - opensuse_buildservice@ojkastl.de + +- update to 1.0.4; disable lua and excluded lxc-top, as lua-dependencies are not available + +------------------------------------------------------------------- +Sat May 17 18:57:22 UTC 2014 - opensuse_buildservice@ojkastl.de + +- added --enable-lua to compile lxc with lua support (for lxc-top) + +------------------------------------------------------------------- +Sat May 17 13:14:01 UTC 2014 - opensuse_buildservice@ojkastl.de + +- added "Requires: lua", as lxc-top needs it + +------------------------------------------------------------------- +Mon May 5 13:08:04 UTC 2014 - opensuse_buildservice@ojkastl.de + +- added file /usr/sbin/rxlcx that links to /usr/sbin/service + +------------------------------------------------------------------- +Mon May 5 10:14:06 UTC 2014 - opensuse_buildservice@ojkastl.de + +- upgrade to version 1.0.3 +- deleted patch patch_bash_completion.d_lxc.patch, as it is included upstream already +- added file /usr/sbin/init.lxc + +------------------------------------------------------------------- +Sun Mar 2 09:06:57 UTC 2014 - opensuse_buildservice@ojkastl.de + +- patch now including headers and signoff + +------------------------------------------------------------------- +Sun Mar 2 08:57:35 UTC 2014 - opensuse_buildservice@ojkastl.de + +- updated sources to 1.0.0 ++++ 352 more lines (skipped) ++++ between /dev/null ++++ and /work/SRC/openSUSE:13.2:Update/.lxc.3935.new/lxc.changes New: ---- 0001-systemd-Ensure-action-is-defined.patch CVE-2015-1331-lxclock-use-run-lxc-lock-rather-than-r.patch CVE-2015-1334-Don-t-use-the-container-s-proc-during-.patch README.SUSE lxc-1.0.6.tar.gz lxc-createconfig.in lxc.changes lxc.spec ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ lxc.spec ++++++ # # spec file for package lxc # # Copyright (c) 2014 SUSE LINUX Products GmbH, Nuernberg, Germany. # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed # upon. The license for this file, and modifications and additions to the # file, is the same license as for the pristine package itself (unless the # license for the pristine package is not an Open Source License, in which # case the license is the MIT License). An "Open Source License" is a # license that conforms to the Open Source Definition (Version 1.9) # published by the Open Source Initiative. # Please submit bugfixes or comments via http://bugs.opensuse.org/ # Name: lxc Version: 1.0.6 Release: 0 Url: http://linuxcontainers.org/ Summary: Userspace tools for the Linux kernel containers License: LGPL-2.1+ Group: System/Management Source: http://linuxcontainers.org/downloads/%{name}-%{version}.tar.gz Source1: README.SUSE Source2: lxc-createconfig.in Patch1: 0001-systemd-Ensure-action-is-defined.patch Patch2: CVE-2015-1331-lxclock-use-run-lxc-lock-rather-than-r.patch Patch3: CVE-2015-1334-Don-t-use-the-container-s-proc-during-.patch BuildRoot: %{_tmppath}/%{name}-%{version}-build BuildRequires: docbook-utils BuildRequires: docbook2x BuildRequires: libapparmor-devel BuildRequires: libcap-devel %ifarch %ix86 x86_64 BuildRequires: libseccomp-devel %endif BuildRequires: libxslt BuildRequires: linux-glibc-devel BuildRequires: lsb-release BuildRequires: pkg-config BuildRequires: python3-devel %if 0%{?suse_version} >= 1210 BuildRequires: systemd %endif Requires: /sbin/setcap Requires: rsync %{?systemd_requires} # needed to create openSUSE containers using template Recommends: build %description It provides commands to create and manage containers. It contains a full featured container with the isolation/virtualization of the pids, the ipc, the utsname, the mount points, /proc, /sys, the network and it takes into account the control groups. It is very light, flexible, and provides a set of tools around the container like the monitoring with asynchronous events notification, or the freeze of the container. This package is useful to create Virtual Private Server, or to run isolated applications like bash or sshd. %package devel Summary: Development library for lxc License: LGPL-2.1 Group: Development/Libraries/C and C++ Requires: %name = %version %description devel Lxc header files and library needed for development of containers. %prep %setup -q %patch1 -p1 %patch2 -p1 %patch3 -p1 %build chmod 755 configure %configure --disable-examples --with-init-script=systemd %__make %{?_smp_mflags} %__cp %{SOURCE1} . %__rm -rf .doc %__mkdir_p .doc/examples %__cp doc/examples/*.conf .doc/examples %install %makeinstall install -d -m 755 %{buildroot}/var/lib/lxc find %buildroot -type f -name '*.la' -delete chmod u-s %{buildroot}/usr/lib/lxc/lxc-user-nic ./config.status --file=%{buildroot}%{_bindir}/lxc-createconfig:%{S:2} chmod a+x %{buildroot}%{_bindir}/lxc-createconfig ln -s /usr/sbin/service %{buildroot}%{_sbindir}/rc%name %clean %__rm -rf %buildroot %pre %service_add_pre lxc.service %post /sbin/ldconfig %service_add_post lxc.service %preun %service_del_preun lxc.service %postun /sbin/ldconfig %service_del_postun lxc.service %files %defattr(-,root,root) %doc AUTHORS MAINTAINERS COPYING README doc/FAQ.txt %doc README.SUSE %doc .doc/examples %dir %{_sysconfdir}/%{name}/ %config %{_sysconfdir}/%{name}/default.conf %{_libdir}/lib%{name}.so.* %{_libexecdir}/%name %{_libdir}/%name %{_datadir}/%name %dir /var/lib/lxc %{_bindir}/%{name}-* %exclude %{_bindir}/%{name}-top %{_sbindir}/init.lxc %{_sbindir}/rclxc %{_mandir}/man[^3]/* %_unitdir/%{name}.service %python3_sitearch/%{name}/ %python3_sitearch/_%{name}* %dir %{_sysconfdir}/apparmor.d %dir %{_sysconfdir}/apparmor.d/abstractions %dir %{_sysconfdir}/apparmor.d/abstractions/lxc %config %{_sysconfdir}/apparmor.d/abstractions/lxc/container-base %config %{_sysconfdir}/apparmor.d/abstractions/lxc/start-container %config %{_sysconfdir}/apparmor.d/lxc-containers %dir %{_sysconfdir}/apparmor.d/lxc %config %{_sysconfdir}/apparmor.d/lxc/lxc-default %config %{_sysconfdir}/apparmor.d/lxc/lxc-default-with-mounting %config %{_sysconfdir}/apparmor.d/lxc/lxc-default-with-nesting %config %{_sysconfdir}/apparmor.d/usr.bin.lxc-start %config %{_sysconfdir}/bash_completion.d/%{name} %files devel %defattr(-,root,root) %{_includedir}/%name %{_libdir}/lib%{name}.so %{_libdir}/pkgconfig/%{name}.pc %changelog ++++++ 0001-systemd-Ensure-action-is-defined.patch ++++++
From 82dddfc2d3c26db922f105111a439e43f5ce7172 Mon Sep 17 00:00:00 2001 From: Martin Pitt
Date: Thu, 31 Jul 2014 08:53:54 +0200 Subject: [PATCH 1/2] systemd: Ensure action() is defined
If /etc/rc.d/init.d/functions is not present or does not define an action()
function, provide a simple fallback using "echo".
Signed-off-by: Martin Pitt
participants (1)
-
root@hilbert.suse.de