• Bug#258038: util-vserver: vproc security util for 1.9.x vserver patch m

    From Ola Lundqvist@1:229/2 to Kilian Krause on Wed Aug 18 08:50:06 2004
    From: [email protected]

    Hello

    On Wed, Jul 07, 2004 at 12:02:37PM +0200, Kilian Krause wrote:
    Package: util-vserver
    Version: 0.30-1
    Severity: normal

    This is basically a follow-up bug for #253307. The vproc tool is needed
    for the stable tools when running a 2.6 kernel (and consequently the
    1.9.x vserver patch). The util-vserver 0.30.190 have vprocunhide which
    is already setting good defaults. Either of vproc or vprocunhide should
    be included in util-vserver as kernel 2.6 is not uncommon anymore.
    Thanks.

    I have now been in contact with people on the vserver list and will
    try to backport setattr from util-vserver so that it works with
    util-vserver.

    Is vprocunhide a standalone program?

    I have not used util-vserver under 2.6 kernel yet so you have to
    give me some input.

    vproc will not work with 2.6 when the compatibility layer is off
    (according to people on the list) so I will not include that tool.

    Regards,

    // Ola

    -- System Information:
    Debian Release: testing/unstable
    APT prefers unstable
    APT policy: (990, 'unstable'), (500, 'testing'), (1, 'experimental') Architecture: i386 (i686)
    Kernel: Linux 2.6.7-vs1.9.1.10
    Locale: LANG=de_DE.UTF-8@euro, LC_CTYPE=de_DE.UTF-8@euro

    Versions of packages util-vserver depends on:
    ii libc6 2.3.2.ds1-13 GNU C Library: Shared libraries an
    ii libgcc1 1:3.4.0-2 GCC support library
    ii libstdc++5 1:3.3.4-2 The GNU Standard C++ Library v3

    -- no debconf information


    --
    --------------------- Ola Lundqvist ---------------------------
    / [email protected] Annebergsslingan 37 \
    | [email protected] 654 65 KARLSTAD |
    | +46 (0)54-10 14 30 +46 (0)70-332 1551 |
    | http://www.opal.dhs.org UIN/icq: 4912500 |
    \ gpg/f.p.: 7090 A92B 18FE 7994 0C36 4FE4 18A1 B1CF 0FE5 3DD9 /
    ---------------------------------------------------------------


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • From Kilian Krause@1:229/2 to All on Wed Aug 18 09:10:09 2004
    From: [email protected]

    Hi Ola,

    Is vprocunhide a standalone program?

    that i do not know. I have only used the vproc tool with the script i
    supplied in the bugreport already. Basically that's the vprocunhide
    calls from util-vserver 0.30.190 or so. About current dependencies you
    might wanna ask Enrico Scholz who is maintainer of the util-vserver
    tools upstream and can give you more insight. Yet, taking his word from
    some weeks ago, the new util-vserver alpha is becoming mature. So just
    go ahead and ask him which of the tools make sense to be backported and
    which are still beta or alpha quality.

    I have not used util-vserver under 2.6 kernel yet so you have to
    give me some input.

    You can also try the 1.3 patch under 2.4. That one has the same
    proc-security according to what Herbert had told me so far (yet i have
    always gone for 2.6 so i can't tell for sure).

    vproc will not work with 2.6 when the compatibility layer is off
    (according to people on the list) so I will not include that tool.

    Well, here it did work pretty nicely. So that may be a feature of the
    1.9.2 patches and later. I had tried with the 1.9.1.10 and there was no
    problem except for some warnings that didn't stop the effect from taking
    place.

    Yet i haven't looked that much into vserver lately, so i can't tell
    what's the status with latest patches around (and Herbert is moving
    quickly ;)). I'd suggest to ask Enrico. He'll for sure be able to tell
    exact details what's needed to make the stable tools work with
    development kernel patches.

    --
    Best regards,
    Kilian

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.5 (GNU/Linux)

    iD8DBQBBIv0Jvdkzt4X+wX8RAkcMAJwO46/xlSUCvWb+DuXLGktjESEI6QCfQ850 4+NN/gfvAfjg7nv58qH6OSg=
    =NX2d
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • From Ola Lundqvist@1:229/2 to Kilian Krause on Wed Aug 18 10:00:17 2004
    From: [email protected]

    Hello

    On Wed, Aug 18, 2004 at 08:54:01AM +0200, Kilian Krause wrote:
    Hi Ola,

    Is vprocunhide a standalone program?

    that i do not know. I have only used the vproc tool with the script i supplied in the bugreport already. Basically that's the vprocunhide
    calls from util-vserver 0.30.190 or so. About current dependencies you
    might wanna ask Enrico Scholz who is maintainer of the util-vserver
    tools upstream and can give you more insight. Yet, taking his word from
    some weeks ago, the new util-vserver alpha is becoming mature. So just
    go ahead and ask him which of the tools make sense to be backported and
    which are still beta or alpha quality.

    I'll do.

    I have not used util-vserver under 2.6 kernel yet so you have to
    give me some input.

    You can also try the 1.3 patch under 2.4. That one has the same
    proc-security according to what Herbert had told me so far (yet i have
    always gone for 2.6 so i can't tell for sure).

    vproc will not work with 2.6 when the compatibility layer is off
    (according to people on the list) so I will not include that tool.

    Well, here it did work pretty nicely. So that may be a feature of the
    1.9.2 patches and later. I had tried with the 1.9.1.10 and there was no problem except for some warnings that didn't stop the effect from taking place.

    Yet i haven't looked that much into vserver lately, so i can't tell
    what's the status with latest patches around (and Herbert is moving
    quickly ;)). I'd suggest to ask Enrico. He'll for sure be able to tell
    exact details what's needed to make the stable tools work with
    development kernel patches.

    Best regards,

    // Ola

    --
    Best regards,
    Kilian



    --
    --------------------- Ola Lundqvist ---------------------------
    / [email protected] Annebergsslingan 37 \
    | [email protected] 654 65 KARLSTAD |
    | +46 (0)54-10 14 30 +46 (0)70-332 1551 |
    | http://www.opal.dhs.org UIN/icq: 4912500 |
    \ gpg/f.p.: 7090 A92B 18FE 7994 0C36 4FE4 18A1 B1CF 0FE5 3DD9 /
    ---------------------------------------------------------------


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)