Commit Graph

3574 Commits

Author SHA1 Message Date
Stéphane Graber
dfb5edcac0 lxc-net: Use iproute and relative paths everywhere (V2)
V2 changes:
 - Keep using /var/lib for the lease file, but making it respect localstatedir
 - Don't pass an empty --conf-file as that confuses dnsmasq when
   /etc/dnsmasq.conf doesn't exist or isn't readable.

Signed-off-by: Stéphane Graber <stgraber@ubuntu.com>
Acked-by: Serge E. Hallyn <serge.hallyn@ubuntu.com>
2015-06-29 13:36:55 -04:00
Arjun Sreedharan
57354986d6 lxc_monitor: fix memory leak on @fds and close fds
also label and consolidate error conditions for
better readability

Signed-off-by: Arjun Sreedharan <arjun024@gmail.com>
Acked-by: Serge E. Hallyn <serge.hallyn@ubuntu.com>
2015-06-29 09:58:43 -05:00
Serge Hallyn
d791668b9a lxc_user_nic: free_groupnames: fix
lxc_user_nic was segfaulting:
lxc-user-nic[9761]: segfault at 29 ip 00007f3fb2346872 sp 00007ffdd17b2dd0 error 4 in libc-2.21.so[7f3fb22c2000+1c0000

This patch fixes it.

Signed-off-by: Serge Hallyn <serge.hallyn@ubuntu.com>
2015-06-24 13:07:05 -05:00
Serge Hallyn
2c7a50081b Merge pull request #517 from hkjolhede/master
Added support for groups in lxc-usernet
2015-06-23 16:10:26 -05:00
Henrik Kjölhede
680836fa52 Make sure to cleanup and exit with an error if malloc fails in append_alloted
Signed-off-by: Henrik Kjölhede <hkjolhede@gmail.com>
2015-06-21 11:13:01 +02:00
Stéphane Graber
16fc3582a4 Merge pull request #572 from fanyeren/patch-9
Update centos.common.conf.in
2015-06-18 04:05:56 +02:00
有张纸
28468a67cb Update centos.common.conf.in
systemd services like logind and journald need CAP_SETFCAP CAP_SETPCAP
2015-06-17 14:56:08 +08:00
Stéphane Graber
ccb17e9f8a Merge pull request #569 from LenzGr/master
use `hostname` for DHCP_HOSTNAME in ifcfg-eth0
2015-06-16 16:24:29 +02:00
Lenz Grimmer
7e1a946f61 use hostname for DHCP_HOSTNAME in ifcfg-eth0
Updated centos/fedora/oracle templates to use `hostname` for DHCP_HOSTNAME in
/etc/sysconfig/network/ifcfg-eth0, so the container's host name is propagated
to the host's DHCP server (e.g. dnsmasq, which also acts as the DNS server).
This resolves lxc/lxd#756

Signed-off-by: Lenz Grimmer <lenz@grimmer.com>
2015-06-16 14:00:49 +02:00
Stéphane Graber
60978799df Merge pull request #564 from devurandom/fix/gentoo-systemd-caps
Adopt capability (lxc.cap.drop) documentation from other distros in Gentoo config, drop setpcap and sys_nice
2015-06-15 16:47:27 +02:00
Dennis Schridde
00ec0cc72c Adopt capability drop explanations from other distros on Gentoo, drop setpcap,sys_nice caps
Documents setpcap,sys_admin,sys_resources as breaking systemd, but does not drop them from lxc.cap.drop, as the default init system on Gentoo is OpenRC, thus stuff breaking systemd can be blocked anyway.

This also drops setpcap and sys_nice caps, as these are also dropped in other non-systemd distros.

Most of the explanatory blurb was copied from other distros' configs.

See-Also: https://bugs.gentoo.org/show_bug.cgi?id=551792

Signed-Off-By: Dennis Schridde <devurandom@gmx.net>
2015-06-13 09:56:31 +02:00
Serge Hallyn
13353dc420 daemonized start: exit children on failure, don't return
When starting a daemonized container, only the original parent
thread should return to the caller.  The first forked child
immediately exits after forking, but the grandparent child
was in some places returning on error - causing a second instance
of the calling function.

Signed-off-by: Serge Hallyn <serge.hallyn@ubuntu.com>
Acked-by: Tycho Andersen <tycho.andersen@canonical.com>
2015-06-12 16:11:53 -05:00
Stéphane Graber
2badf64b39 Merge pull request #567 from ysbnim/jap_manual_patch
Translate untranslated section titles in Japanese man pages
2015-06-12 06:48:31 +02:00
Stéphane Graber
dbf21ae6dc Merge pull request #558 from cloudnull/template-cache-var
Added container-cache option to templates
2015-06-12 06:43:21 +02:00
Sungbae Yoo
51fded061a doc: Translate untranslated section titles in Japanese man pages
Signed-off-by: Sungbae Yoo <sungbae.yoo@samsung.com>
2015-06-12 10:29:58 +09:00
Kevin Carter
6dc6f80bfd Added container-cache option to templates
This change adds in the container-cache option within the mainline
default lxc templates. The pupose here is to allow a template to
pull from a location that may not be `@LOCALSTATEDIR@/cache/lxc`

Signed-off-by: Kevin Carter <kevin.carter@rackspace.com>
2015-06-11 11:21:17 -05:00
Stéphane Graber
3814bc62d1 Merge pull request #563 from devurandom/fix/gentoo-mount-create-dir
Fix creation of dev/mqueue and dev/shm on Gentoo
2015-06-11 15:27:01 +02:00
Dennis Schridde
bc19636d58 Fix creation of dev/mqueue and dev/shm on Gentoo
The dev/mqueue and dev/shm directories do not exist when using lxc.autodev, thus they have to be created upon mount.

Signed-off-by: Dennis Schridde <devurandom@gmx.net>
2015-06-11 15:21:19 +02:00
Sungbae Yoo
2b371b262f doc: Add Korean man pages
Signed-off-by: Sungbae Yoo <sungbae.yoo@samsung.com>
2015-06-11 20:08:58 +09:00
Stéphane Graber
963abb4688 Merge pull request #560 from fanyeren/patch-8
Update lxc-oracle.in fix a bug
2015-06-11 05:34:55 -04:00
有张纸
761fbd510c Update lxc-oracle.in 2015-06-11 12:50:50 +08:00
Tycho Andersen
69aeabac1a uniformly nullify std fds
In various places throughout the code, we want to "nullify" the std fds,
opening them to /dev/null or zero or so. Instead, let's unify this code and do
it in such a way that Coverity (probably) won't complain.

v2: use /dev/null for stdin as well
v3: add a comment about use of C's short circuiting
v4: axe comment, check errors on dup2, s/quiet/need_null_stdfds

Reported-by: Coverity
Signed-off-by: Tycho Andersen <tycho.andersen@canonical.com>
Signed-off-by: Serge Hallyn <serge.hallyn@ubuntu.com>
2015-06-10 23:04:51 -05:00
Tycho Andersen
5b72de5fd3 move utils.h #endif to end of file
Signed-off-by: Tycho Andersen <tycho.andersen@canonical.com>
Signed-off-by: Serge Hallyn <serge.hallyn@ubuntu.com>
2015-06-10 23:04:47 -05:00
Tycho Andersen
bd9e78f570 c/r: remove unused variable mnts
Reported-by: Coverity
Signed-off-by: Tycho Andersen <tycho.andersen@canonical.com>
Signed-off-by: Serge Hallyn <serge.hallyn@ubuntu.com>
2015-06-10 23:04:45 -05:00
Tycho Andersen
3158ab5b9e c/r: use fclose instead of close
We're leaking the FILE* here while closing the underlying fd; let's just
close the file and thus close both.

Reported-by: Coverity
Signed-off-by: Tycho Andersen <tycho.andersen@canonical.com>
Signed-off-by: Serge Hallyn <serge.hallyn@ubuntu.com>
2015-06-10 23:04:43 -05:00
Sungbae Yoo
89dfc30230 config: miscellaneous signals for lxc.*signal
Signed-off-by: Sungbae Yoo <sungbae.yoo@samsung.com>
2015-06-10 17:58:36 +09:00
Henrik Kjölhede
21002b3950 Fixed memory checks and faulty loop in get_alloted according to comments
Signed-off-by: Henrik Kjölhede <hkjolhede@gmail.com>
2015-06-09 22:25:16 +02:00
Stéphane Graber
2a5da24387 Merge pull request #557 from dangowrt/fix-build-on-ppc
fix build on mpc85xx
2015-06-09 07:21:33 -04:00
Daniel Golle
f58ad87a3f fix build on mpc85xx
Initialize ret to 0 so compiler no longer complains about
monitor.c: In function 'lxc_monitor_open':
monitor.c:212:5: error: 'ret' may be used uninitialized in this function [-Werror=maybe-uninitialized]

https://github.com/openwrt/packages/issues/1356

Signed-off-by: Daniel Golle <daniel@makrotopia.org>
2015-06-09 12:58:12 +02:00
Laurence Rowe
da0e298c67 Wait on correct container name
Signed-off-by: Laurence Rowe <l@lrowe.co.uk>
2015-06-08 14:43:24 -07:00
Serge Hallyn
d9b32b0900 coverity: don't risk exec()ing NULL
Signed-off-by: Serge Hallyn <serge.hallyn@ubuntu.com>
2015-06-08 10:37:55 -05:00
Serge Hallyn
17d252a822 coverity: fix use-after-free in cgmanager.
Signed-off-by: Serge Hallyn <serge.hallyn@ubuntu.com>
2015-06-08 10:33:22 -05:00
Henrik Kjölhede
1940bff4d2 Updated the documentation
Signed-off-by: Henrik Kjölhede <hkjolhede@gmail.com>
2015-06-04 22:22:54 +02:00
Stéphane Graber
212bc24189
Fix bdev.h
Signed-off-by: Stéphane Graber <stgraber@ubuntu.com>
2015-06-03 21:45:23 -04:00
Stéphane Graber
c2af52cf52
Revert bdev.h to the way it was
Instead of re-defining MS_ options all over the place, just revert the
last change to bdev.h so we have all the defines in there again.

Signed-off-by: Stéphane Graber <stgraber@ubuntu.com>
2015-06-03 19:37:59 -04:00
Stéphane Graber
54c0610037
Define MS_RELATIME for Android
Signed-off-by: Stéphane Graber <stgraber@ubuntu.com>
2015-06-03 17:08:11 -04:00
Stéphane Graber
c37ebdc49a
Define MS_REC and MS_SLAVE for Android in bdev.c
Signed-off-by: Stéphane Graber <stgraber@ubuntu.com>
2015-06-03 15:07:08 -04:00
Henrik Kjölhede
dc6bb7539b Fixed an error
Signed-off-by: Henrik Kjölhede <hkjolhede@gmail.com>
2015-06-03 20:43:59 +02:00
Henrik Kjölhede
905f8792e5 Indentation fix
Signed-off-by: Henrik Kjölhede <hkjolhede@gmail.com>
2015-06-03 20:40:46 +02:00
Serge Hallyn
a70a69e8a0 don't dereference a NULL c->lxc_conf
Commit 37cf711b added a destroy hook, but when it checks
at destroy time whether that hook exists, it assumes that
c->lxc_conf is good.  In fact lxc_conf can be NULL, so check
for that.

Signed-off-by: Serge Hallyn <serge.hallyn@ubuntu.com>
Acked-by: Stéphane Graber <stgraber@ubuntu.com>
2015-06-03 14:09:51 -04:00
Tycho Andersen
755fa45300 don't hardcode the path to criu when checking versions
We use the right path when actually execing criu to checkpoint and restore, but
when checking versions we didn't. Let's use the right path.

Reported-by: Dietmar Maurer <dietmar@proxmox.com>
Signed-off-by: Tycho Andersen <tycho.andersen@canonical.com>
Acked-by: Stéphane Graber <stgraber@ubuntu.com>
2015-06-03 10:37:30 -04:00
Serge Hallyn
a041127564 detect whether cgmanager_list_controllers is available
and don't use it if not. This fixes failure to build with older
cgmanager.

Signed-off-by: Serge Hallyn <serge.hallyn@ubuntu.com>
Acked-by: Stéphane Graber <stgraber@ubuntu.com>
2015-06-03 10:37:27 -04:00
Henrik Kjölhede
af59ff2eed Changed parsing of allotments. Now parses top-to-bottom regardless of user or group
Signed-off-by: Henrik Kjölhede <hkjolhede@gmail.com>
2015-06-03 15:22:46 +02:00
Serge Hallyn
454ec0abc7 api_start: always close fds 0-2 when daemonized
commit 507cee3618 moved the close and re-open of fds 0-2 into
do_start.  But this means that the lxc monitor itself keeps the
caller's fds 0-2 open, which is wrong for daemonized containers.

Closes #548

Reported-by: Mathieu Le Marec - Pasquet <kiorky@cryptelium.net>
Signed-off-by: Serge Hallyn <serge.hallyn@ubuntu.com>
Acked-by: Stéphane Graber <stgraber@ubuntu.com>
2015-06-02 19:05:37 -04:00
Serge Hallyn
27be573155 cgmanager: attach: never use 'all' controller
We were using 'all' controller if current was in all the
same cgroup.  That doesn't suffice.  We'd have to check
the target.  At that point we may as well just attach
controller by controller.

An optimization to consider is to check the /proc/initpid/cgroup
for all identical controllers.  Let's start by just getting it
right.

Signed-off-by: Serge Hallyn <serge.hallyn@ubuntu.com>
Acked-by: Stéphane Graber <stgraber@ubuntu.com>
2015-06-02 19:05:22 -04:00
KATOH Yasufumi
de0dc53307 doc: Add the description of lxc.hook.destroy in Japanese lxc.container.conf(5)
Update for commit 37cf711

Signed-off-by: KATOH Yasufumi <karma@jazz.email.ne.jp>
Acked-by: Stéphane Graber <stgraber@ubuntu.com>
2015-06-02 19:05:20 -04:00
Tycho Andersen
59c2d40689 c/r: remember to clean up pidfile
When restoring, we didn't clean up the pidfile that criu uses to pass us the
init pid on error or success; let's do that.

Signed-off-by: Tycho Andersen <tycho.andersen@canonical.com>
Acked-by: Serge E. Hallyn <serge.hallyn@ubuntu.com>
2015-06-02 19:04:23 -04:00
Stéphane Graber
d24095e46a Fix ABI compatibility
Until we bump the SONAME to liblxc2, only symbol additions and struct
member additions are allowed.

Adding struct members in the middle of the struct breaks backward
compatibility.

This commit makes it clear when struct members were added and moves a
few members that were added in the middle of the 1.0 struct to the end
of it.

Note that unfortunately that means we're breaking backward compatibility
between LXC 1.1.0 and the state after this commit, given 1.1 is
reasonably new, this is the least damaging way of fixing the problem.

Signed-off-by: Stéphane Graber <stgraber@ubuntu.com>
Acked-by: Serge E. Hallyn <serge.hallyn@ubuntu.com>
2015-06-02 19:04:20 -04:00
Dwight Schauer
75d87a4b80 The yum in Centos 5.11 does not know about '--releasever', which is used by: lxc-create ... -- release=VERSION
The release version only needs to be set in the outer bootstrap, not the inner one.
With this change an lxc-create bootstrap of CentOS 5.11 completes enough to be usable.
CentOS 5.11 containers can be created, started, stopped, and networking works.
Signed-off-by: Dwight Schauer <das@teegra.net>
2015-06-01 23:41:09 -05:00
Henrik Kjölhede
1b7eaf072c Added check against negative malloc and cleaned up comments
Signed-off-by: Henrik Kjölhede <hkjolhede@gmail.com>
2015-06-01 10:04:46 +02:00