Mailinglist Archive: opensuse-bugs (2150 mails)

< Previous Next >
[Bug 872373] New: opensuse still no lxc user-namespace
  • From: bugzilla_noreply@xxxxxxxxxx
  • Date: Mon, 7 Apr 2014 14:52:05 +0000
  • Message-id: <bug-872373-21960@http.bugzilla.novell.com/>

https://bugzilla.novell.com/show_bug.cgi?id=872373

https://bugzilla.novell.com/show_bug.cgi?id=872373#c0


Summary: opensuse still no lxc user-namespace
Classification: openSUSE
Product: openSUSE 13.1
Version: Final
Platform: x86-64
OS/Version: openSUSE 13.1
Status: NEW
Severity: Normal
Priority: P5 - None
Component: Other
AssignedTo: bnc-team-screening@xxxxxxxxxxxxxxxxxxxxxx
ReportedBy: aotto1968@xxxxxxxxxxx
QAContact: qa-bugs@xxxxxxx
Found By: ---
Blocker: ---


User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML,
like Gecko) Chrome/33.0.1750.152 Safari/537.36

I'm checking lxc after opensuse 13-1 upgrade

1) I'm still missing user-namespace support

linux02:~ # uname -a
Linux linux02 3.11.10-7-desktop #1 SMP PREEMPT Mon Feb 3 09:41:24 UTC 2014
(750023e) x86_64 x86_64 x86_64 GNU/Linux

linux02:~ # lxc-checkconfig
--- Namespaces ---
Namespaces: enabled
Utsname namespace: enabled
Ipc namespace: enabled
Pid namespace: enabled
User namespace: missing
Network namespace: enabled
Multiple /dev/pts instances: enabled

--- Control groups ---
Cgroup: enabled
Cgroup clone_children flag: enabled
Cgroup device: enabled
Cgroup sched: enabled
Cgroup cpu account: enabled
Cgroup memory controller: enabled
Cgroup cpuset: enabled

--- Misc ---
Veth pair device: enabled
Macvlan: enabled
Vlan: enabled
File capabilities: enabled

Note : Before booting a new kernel, you can check its configuration
usage : CONFIG=/path/to/config /usr/bin/lxc-checkconfig

2) in a lxc-container I see the mounts from the paranet-host

nhi2:~ # df -h
df: ‘/run/user/1000/gvfs’: No such file or directory
df: ‘/var/run/user/1000/gvfs’: No such file or directory
df: ‘/backup/linux02-2’: No such file or directory
df: ‘/backup/windows01-2’: No such file or directory
df: ‘/backup/windows01-1’: No such file or directory
df: ‘/backup/nhi2-1’: No such file or directory
df: ‘/backup/portal-1’: No such file or directory
df: ‘/backup/linux02-1’: No such file or directory
Filesystem Size Used Avail Use% Mounted on
/dev/sda2 20G 5.4G 14G 29% /
devtmpfs 16G 228K 16G 1% /dev
tmpfs 16G 0 16G 0% /dev/shm
tmpfs 16G 5.1M 16G 1% /run
tmpfs 16G 0 16G 0% /sys/fs/cgroup
tmpfs 16G 5.1M 16G 1% /var/run
tmpfs 16G 5.1M 16G 1% /var/lock
/dev/lxc/lxc_nhi2 20G 5.4G 14G 29% /
devtmpfs 16G 228K 16G 1% /dev
/dev/dm-4 200G 758M 198G 1% /backup/data
tmpfs 16G 0 16G 0% /dev/shm
tmpfs 16G 5.1M 16G 1% /run
tmpfs 16G 0 16G 0% /sys/fs/cgroup
tmpfs 16G 5.1M 16G 1% /var/lock
tmpfs 10G 1.2G 8.9G 12% /build

my config is:
linux02:/var/lib/lxc # cat nhi2/config
lxc.utsname = nhi2

#basic
lxc.tty = 4
lxc.pts = 1024
lxc.rootfs = /dev/lxc/lxc_nhi2
lxc.mount.entry=/dev/backup-1/nhi2 /dev/lxc/lxc_nhi2/backup/data btrfs
nofail,defaults,noatime,noexec 0 0
#lxc.mount.auto=cgroup-full:mixed proc:mixed sys
lxc.cap.drop = sys_module mac_admin mac_override mknod
lxc.autodev=1
lxc.haltsignal = SIGRTMIN+3
lxc.start.auto=1

# When using LXC with apparmor, uncomment the next line to run unconfined:
#lxc.aa_profile = unconfined

#network
lxc.network.type = veth
lxc.network.flags = up
lxc.network.link = br0
lxc.network.hwaddr = 00:60:2F:5A:F6:84
lxc.network.ipv4 = 0.0.0.0
lxc.network.name = lxc_nhi2
lxc.network.veth.pair = lxc_nhi2

lxc.cgroup.devices.deny = a
# /dev/null and zero
lxc.cgroup.devices.allow = c 1:3 rwm
lxc.cgroup.devices.allow = c 1:5 rwm
# consoles
lxc.cgroup.devices.allow = c 5:1 rwm
lxc.cgroup.devices.allow = c 5:0 rwm
lxc.cgroup.devices.allow = c 4:0 rwm
lxc.cgroup.devices.allow = c 4:1 rwm
# /dev/{,u}random
lxc.cgroup.devices.allow = c 1:9 rwm
lxc.cgroup.devices.allow = c 1:8 rwm
lxc.cgroup.devices.allow = c 136:* rwm
lxc.cgroup.devices.allow = c 5:2 rwm
# rtc
lxc.cgroup.devices.allow = c 254:0 rwm

Reproducible: Always

Steps to Reproduce:
1. after upgrade I expect a complete lxc solution
2.
3.
Actual Results:
see above

Expected Results:
df without parant data and user-namespace enabled

--
Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.
< Previous Next >