Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #72249 > unrolled thread

Bug#990140: upgrade-reports: lxc-attach does not start with apparmor problem after ugrade to 10.10

Started byPaul Gevers <elbrus@debian.org>
First post2021-06-21 19:10 +0200
Last post2021-06-21 20:20 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.debian.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Bug#990140: upgrade-reports: lxc-attach does not start with apparmor problem after ugrade to 10.10 Paul Gevers <elbrus@debian.org> - 2021-06-21 19:10 +0200
    Bug#990140: upgrade-reports: lxc-attach does not start with apparmor problem after ugrade to 10.10 Bernd Breuer <b.breuer@gmx.de> - 2021-06-21 20:20 +0200

#72249 — Bug#990140: upgrade-reports: lxc-attach does not start with apparmor problem after ugrade to 10.10

FromPaul Gevers <elbrus@debian.org>
Date2021-06-21 19:10 +0200
SubjectBug#990140: upgrade-reports: lxc-attach does not start with apparmor problem after ugrade to 10.10
Message-ID<CsvAS-7fS-7@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Hi Bernd,

Thanks for your report.

On 21-06-2021 18:04, Bernd Breuer wrote:
> after the recent upgrade to Buster 10.10 (including a kernel upgrade) the command 'lxc-attach' (out of the Linux Container (lxc) set of commands), typed in like
> 
> "sudo lxc-attach <container-name>"
> 
> stopped working with the error message
> 
> "lxc-attach: <container-name>: lsm/lsm.c: lsm_process_label_set_at: 174 Operation not permitted - Failed to set AppArmor label "unconfined"
> 
> The conainer itself is starting, but apparmor related config lines like
> 
> "lxc.apparmor.profile = unconfined"
> 
> produce the above mentioned error, also on another machine after the
> same packages upgrade.
> 
> I expect lxc-attach to provide me a root shell in the running lxc-container like  it was the case before the recent upgrade.

As we didn't upgrade lxc during the point release, this *may* be caused
by the updated Linux kernel. What happens if you reboot using the
previous kernel?

Paul

[toc] | [next] | [standalone]


#72252

FromBernd Breuer <b.breuer@gmx.de>
Date2021-06-21 20:20 +0200
Message-ID<CswGB-7RR-1@gated-at.bofh.it>
In reply to#72249
Hi Paul,

thanks for your immediate response.

Your assumption is right, booting into kernel 4.19.0-16 causes
lxc-attach to behave as expected, no more apparmor related errors.

Cheers Bernd


Am 21.06.21 um 19:06 schrieb Paul Gevers:
> Hi Bernd,
>
> Thanks for your report.
>
> On 21-06-2021 18:04, Bernd Breuer wrote:
>> after the recent upgrade to Buster 10.10 (including a kernel upgrade) the command 'lxc-attach' (out of the Linux Container (lxc) set of commands), typed in like
>>
>> "sudo lxc-attach <container-name>"
>>
>> stopped working with the error message
>>
>> "lxc-attach: <container-name>: lsm/lsm.c: lsm_process_label_set_at: 174 Operation not permitted - Failed to set AppArmor label "unconfined"
>>
>> The conainer itself is starting, but apparmor related config lines like
>>
>> "lxc.apparmor.profile = unconfined"
>>
>> produce the above mentioned error, also on another machine after the
>> same packages upgrade.
>>
>> I expect lxc-attach to provide me a root shell in the running lxc-container like  it was the case before the recent upgrade.
> As we didn't upgrade lxc during the point release, this *may* be caused
> by the updated Linux kernel. What happens if you reboot using the
> previous kernel?
>
> Paul
>

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web