1322525204 J * derjohn_mobi ~aj@88.128.13.88 1322526519 J * fisted_ ~fisted@xdsl-87-78-216-4.netcologne.de 1322526741 Q * fisted Ping timeout: 480 seconds 1322526885 Q * BenG Quit: I Leave 1322528921 J * qwerty1 ~werty@9YYAACXIL.tor-irc.dnsbl.oftc.net 1322534381 Q * thierryp Remote host closed the connection 1322541243 M * Bertl off to bed now ... have a good one everyone! 1322541250 N * Bertl Bertl_zZ 1322542300 J * thierryp ~thierry@home.parmentelat.net 1322544953 Q * thierryp Remote host closed the connection 1322548566 J * thierryp ~thierry@home.parmentelat.net 1322548578 Q * derjohn_mobi Ping timeout: 480 seconds 1322549737 J * aj__ ~aj@87.253.171.211 1322550810 J * ncopa ~ncopa@3.203.202.84.customer.cdi.no 1322550952 Q * thierryp Remote host closed the connection 1322552012 Q * qwerty1 Quit: No Ping reply in 300 seconds. 1322552031 J * qwerty1 ~werty@04ZAAADBX.tor-irc.dnsbl.oftc.net 1322552236 J * kir ~kir@swsoft-msk-nat.sw.ru 1322552831 J * ghislain ~AQUEOS@adsl2.aqueos.com 1322553578 Q * hparker Quit: Quit 1322554675 Q * Aiken Remote host closed the connection 1322554921 J * thierryp ~thierry@zankai.inria.fr 1322555650 J * hparker ~hparker@2001:470:1f0f:32c:beae:c5ff:fe01:b647 1322556843 P * kir Leaving. 1322557192 J * Aiken ~Aiken@2001:44b8:2168:1000:21f:d0ff:fed6:d63f 1322557528 J * _nono_ ~gomes@licencieux.ircam.fr 1322560588 Q * geb Ping timeout: 480 seconds 1322560970 J * geb ~geb@mars.gebura.eu.org 1322561567 Q * hparker Remote host closed the connection 1322561787 J * hparker ~hparker@2001:470:1f0f:32c:beae:c5ff:fe01:b647 1322562703 Q * mike_ Remote host closed the connection 1322566061 N * Bertl_zZ Bertl 1322566067 M * Bertl morning folks! 1322566118 M * pmjdebruijn mornin 1322567220 M * pmjdebruijn oh sweet you updated the 2.6.32.x tree 1322567340 M * Bertl yes, but I'm already one version behind :) 1322567391 M * Bertl (actually one extraversion step :) 1322567392 M * pmjdebruijn applies just fine 1322567398 A * pmjdebruijn just tested 1322567401 M * pmjdebruijn build ing now 1322567421 A * pmjdebruijn noticed you upped the vserver version as well 1322571800 Q * thierryp Remote host closed the connection 1322571874 J * clopez ~clopez@155.99.117.91.static.mundo-r.com 1322571892 M * clopez hello 1322571948 M * Bertl hi 1322571959 M * clopez I am making an lvm snapshoot of an XFS volume and something weird happens.... 1322571969 M * clopez when I mount the snapshoots I get many UIDs and GIDs with 2617245696 (overflow) 1322571992 M * clopez can be this related to the mount tag option that vserver uses? 1322572002 M * daniel_hozac if you mount it without -o tag, yes. 1322572008 M * Bertl definitely 1322572032 M * clopez oh... i see 1322572040 M * clopez mounting the snapshoot with tag works 1322572047 M * clopez thanks :) 1322572052 M * Bertl you're welcome! 1322572313 J * thierryp ~thierry@zankai.inria.fr 1322572575 J * fisted ~fisted@xdsl-87-78-212-77.netcologne.de 1322572731 Q * fisted_ Ping timeout: 480 seconds 1322573234 Q * Aiken Remote host closed the connection 1322576308 J * mike ~mike@no.phear.eu 1322577278 J * qwerty1_ ~werty@83TAABQI9.tor-irc.dnsbl.oftc.net 1322577406 Q * qwerty1 Quit: No Ping reply in 300 seconds. 1322578658 Q * thierryp Remote host closed the connection 1322578772 J * thierryp ~thierry@zankai.inria.fr 1322580020 Q * thierryp Remote host closed the connection 1322582659 M * ghislain i had weird quota issue with quota+tag, now i use without tag and feel better 1322582692 M * ghislain too bad i wanted to use both to limit /var just in case of overflow 1322582707 M * ghislain without need to have specific partition 1322582734 M * ghislain with btrfs i think we cen resize partition on the fly so it will help to solve this issue for me ^^ 1322582967 J * dowdle ~dowdle@scott.coe.montana.edu 1322584686 J * thierryp ~thierry@home.parmentelat.net 1322586411 J * bonbons ~bonbons@2001:960:7ab:0:f484:694e:28f9:3310 1322587529 Q * ncopa Quit: Leaving 1322587724 J * chrissbx ~chrissbx@69-196-180-202.dsl.teksavvy.com 1322587857 M * chrissbx Hello. Running my desktop in a vserver guest is a success so far, although I've ended up running Xorg inside the same guest. 1322587899 M * chrissbx But I've written a script to copy the world-readable parts of /sys, and have trimmed down caps and device nodes to the necessary, which might make it secure again: 1322587937 M * chrissbx The only capability I'm giving is SYS_RAWIO. 1322588020 M * chrissbx The only device nodes I'm giving are /dev/agpgart /dev/vga_arbiter /dev/cpu_dma_latency /dev/fb0 and (currently the whole of) /dev/input/ 1322588038 M * chrissbx (Actually not sure anymore whether cpu_dma_latency and fb0 are required.) 1322588065 M * chrissbx Do you see any way to break out of the guest with these? 1322588096 M * chrissbx (I've also given /dev/snd/) 1322588179 M * chrissbx Also, chromium won't work inside the guest, fails with "Failed to move to new PID namespace: Operation not permitted", I suppose that's because of its sandboxing. 1322588193 M * chrissbx Any way to solve this? 1322588218 Q * aj__ Ping timeout: 480 seconds 1322588226 M * daniel_hozac no. 1322588439 M * chrissbx To which question did you answer? :) 1322588491 M * chrissbx No way to break out, or no way to run chromium? 1322589650 Q * thierryp Remote host closed the connection 1322595783 J * Aiken ~Aiken@2001:44b8:2168:1000:21f:d0ff:fed6:d63f 1322595874 Q * clopez Ping timeout: 480 seconds 1322597561 J * qwerty1 ~werty@router-sun-nat-i.pilsfree.net 1322597680 Q * qwerty1_ Ping timeout: 480 seconds 1322598448 M * Bertl daniel_hozac: what does util-vserver need c++ for? 1322599220 J * hijacker_ ~hijacker@cable-84-43-136-96.mnet.bg 1322600941 Q * hijacker_ Quit: Leaving 1322601686 M * daniel_hozac Bertl: nothing that i am aware of... i know ensc had plans to rewrite parts in C++, but i don't think that happened. 1322601781 M * Bertl okay, just because: 1322601792 M * Bertl configure: error: in `/src/util-vserver-0.30.216-pre3002': 1322601792 M * Bertl configure: error: C++ compiler cannot create executables 1322601812 M * daniel_hozac yeah... 1322601995 M * daniel_hozac i'm not sure why it is required. i'll see if i can get rid of that. 1322602043 M * Bertl excellent! thanks! 1322602277 M * daniel_hozac yeah, nothing seems to require it. 1322602534 M * daniel_hozac 3004 should be g++ free 1322602555 M * daniel_hozac but i need to get some sleep, got a plane to catch in less than 6 hours :) 1322602560 M * daniel_hozac good night 1322604633 M * Bertl thanks and have a good night/sleep and journey 1322604652 Q * bonbons Quit: Leaving 1322608490 J * derjohn_mobi ~aj@88.128.131.98 1322609566 Q * fisted Read error: Connection reset by peer 1322610187 J * fisted ~fisted@xdsl-87-78-212-77.netcologne.de 1322610926 M * chrissbx Is there a way to make mount --bind work on a running vserver? 1322610941 M * chrissbx vnamespace mount .. only seems to work for devices. 1322610979 M * Bertl well, first, of course, you can do bind mounts in the proper namespace 1322611017 M * Bertl and secondly, if you want to be able to do bind mounts from inside the guest, just give the necessary ccaps 1322611047 M * chrissbx I don't need to do it inside; I just want to add a bind mount from the host into the guest. 1322611060 M * chrissbx Looking up what I tried. 1322611081 M * Bertl you cannot move bind mounts from the host to the guest 1322611104 M * Bertl but you can re-do the bind mount in the guest namespace (with vnamespace) 1322611143 M * chrissbx This is what I tried: vnamespace -e t3 mount --bind /mnt/f73a7f07-2f47-4e9a-ac2e-e7be22cfaee1/filme/ /var/lib/vservers/t3/mnt/f73a7f07-2f47-4e9a-ac2e-e7be22cfaee1/filme/ 1322611151 M * chrissbx mount: special device /mnt/f73a7f07-2f47-4e9a-ac2e-e7be22cfaee1/filme/ does not exist 1322611168 M * chrissbx But I now realize that probably the mount of that disk isn't visible in the t3 namespace. 1322611175 M * Bertl precisely 1322611198 M * chrissbx Ok.