lxc-container-default-with-nesting is too lax

Bug #1299944 reported by Serge Hallyn
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
lxc (Ubuntu)
Fix Released
High
Stéphane Graber

Bug Description

Before cgmanager, lxc-container-default-with-nesting needed to allow the container to mount fstype=cgroup. This is no longer needed and is not safe, therefore should no longer be allowed.

description: updated
Changed in lxc (Ubuntu):
status: New → Triaged
importance: Undecided → High
Revision history for this message
Serge Hallyn (serge-hallyn) wrote :

Verified that simply removing the line:

# mount fstype=cgroup -> /sys/fs/cgroup/**,

stops cgroup-lite from mounting the cgroupfs, while cgmanager continues to work.

I'm going to assign this to stgraber just to get his opinion on whether he still needs cgroups mountable in some cases for cgroup-lite to work, or not. (For instance, libvirt won't currently work without that)

Changed in lxc (Ubuntu):
assignee: nobody → Stéphane Graber (stgraber)
Revision history for this message
Stéphane Graber (stgraber) wrote :

I absolutely agree we should be getting rid of this from the profile ASAP.

Revision history for this message
Serge Hallyn (serge-hallyn) wrote : Re: [Bug 1299944] Re: lxc-container-default-with-nesting is too lax

Quoting Stéphane Graber (<email address hidden>):
> I absolutely agree we should be getting rid of this from the profile
> ASAP.

Would you call this a bug or a feature? (Shall I seek FFE?)

Revision history for this message
Stéphane Graber (stgraber) wrote :

Security improvement, I don't think we need a FFe, just send a patch upstream and I'll get it in 1.0.3 along with the other apparmor updates.

Changed in lxc (Ubuntu):
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.