1539587995 J * hijacker ~nikolay@external.oldum.net 1539588204 J * romster ~romster@158.140.215.184 1539589439 M * Ghislain hello there 1539589526 M * Guy- hi 1539589609 M * Ghislain fyi 4.9.133 seems ok, compile, boot, testfs testme.. 1539589630 M * Guy- they release a new 4.9.x every two days? 1539589640 M * Guy- I can't keep up 1539589668 M * Ghislain yes they do 1539589673 M * Ghislain i was testing the 1 1539589687 M * Ghislain 132 when i finished my internal test the 133 comes out 1539589704 M * Ghislain being tired of that i must admit 1539589775 M * Ghislain and each time there is major things concerned like specter optimisation or driver issue in a very used one, not to mention ext4 that has a fair share of patches 1539589828 M * Ghislain i heard newer kernel will have a kernel upgrade inline possibility 1539589835 M * Ghislain not the commercial one but a new one 1539589871 M * Ghislain that would help a lot but i guess this will also open security concerns 1539590946 M * AlexanderS Hi, this should fix the loopback virtualisation for netlink diag sockets: https://pastebin.com/raw/jHqecnBA 1539591165 M * Ghislain hi alexander, this is for the 127.X.Y.Z leak ? 1539591189 M * Ghislain if you find the udp one i will have to kiss you :p 1539591303 M * AlexanderS Isn't the udp socket leak fixed with: http://vserver.13thfloor.at/Experimental/delta-netlink-feat02.diff ? 1539591393 M * Ghislain no its not 1539591440 M * Ghislain you can see the udp sockets open of all guest from another guest 1539591452 M * Ghislain you cannot interact with it but you can see them 1539591483 M * Ghislain but not with netstat, you have to use ss (great name...serious) 1539591522 M * Ghislain i dont know what they drinked to name it like this 1539591528 M * Ghislain or perhaps they dont know history 1539591578 M * AlexanderS Are you sure the netlink diff does not fix it? I tested with this: https://pastebin.com/raw/YyBU8GUS and it seems to remove the udp sockets from the ss output. 1539591655 M * AlexanderS (This seems to be the same like the delta-netlink-feat02.diff but only for udp...) 1539591739 M * Ghislain i am launching the test right now but i us the patch http://vserver.13thfloor.at/Experimental/patch-4.9.113-vs2.3.9.7.diff of july 1539591800 M * Ghislain udp    UNCONN     0      0      127.159.46.1:domain                *:* 1539591802 M * AlexanderS I think the delta-netlink-feat02.diff is a patch on top of the default patch. 1539591865 M * Ghislain a complete patch is supposed to be the complete thing so i think not. bertl could tell us that :) 1539591978 M * AlexanderS Can you just test http://vserver.13thfloor.at/Experimental/delta-netlink-feat02.diff on top of the default patch? It just changes 4 files in net/. I think this will fix the udp socket leak. 1539592062 M * Ghislain fake news it changes 7 lines ! :p 1539592082 M * Ghislain oh no 8 ! 1539592093 M * Ghislain well i cannot now but i will try 1539592106 M * AlexanderS 9 lines in 4 files ;-) 1539592161 M * Ghislain well i wasnt counting the space one ;p 1539592197 M * Ghislain bertl told me he was truggling with this one so i dont think the old patch is enough 1539592231 M * Ghislain vserver bertl: any clues bertl ? :) 1539592241 M * AlexanderS If this is not enough I can look into it. But I need a test case. 1539593297 M * Ghislain simple, run 2 guest, launch bind/unbound in one of them. do ss -lu on the other, that will show you the socket 1539593322 M * Ghislain of the dns server in the other one 1539593505 M * AlexanderS This case should be fixed with the delta patch. 1539596396 M * Ghislain bertl did include it in the 4.4 one but not on the 4.9 one , so or he forgot, or this was an issue in 4.9 to do it like this 1539596408 M * Ghislain i am building a kernel to test 1539613132 M * Ghislain okay 1539613157 M * Ghislain so your patch + the feat, i have no more 127.X.Y.Z leaks or udp leaks 1539614177 M * AlexanderS Great. 1539614623 M * Ghislain will you post the patch on the maillign list ? 1539614633 M * Ghislain so bertl can catch it 1539617965 M * Bertl_oO no worries, he contacted me some time ago 1539617985 M * Bertl_oO but it would be nice to sum up what changes were tested on the ML :) 1539618161 M * Ghislain rapidly here i tested 4.9.133 + corrected the include in inet.c + used delta-netlink-feat02.diff + the patch from Alex 1539618209 M * Ghislain compile , boot , testme testfs ok, memory ok, udp do not leaks, 127.X.Y.Z do not leak (at least like we tested before 1539618221 M * Bertl_oO nice 1539618225 M * AlexanderS Any open issues? 1539618251 M * Ghislain for me the 2 leaks where the only thing i could see 1539618276 M * AlexanderS :-) 1539618277 M * Ghislain now there is the patch for 4.18 and we are good ;p 1539618305 M * Ghislain i heard the facepalm sound you made bertl ! :p 1539618666 M * Ghislain mail sent 1539618845 M * AlexanderS I would wait for 4.19, because that's the next LTS kernel ;-) 1539618869 M * Ghislain lol 1539619154 M * arekmx hi, was that 4.9 vserver network crash/cpu lockup issue found? 1539619240 M * Ghislain the lockup i got have been, the crash i had seems linked to stress-ng i have not found from where it comes, it just kill all the process but on the host it do not 1539619268 M * Ghislain it still does that with --all 1539619416 Q * hijacker Remote host closed the connection 1539619431 M * Bertl_oO AlexanderS: take your time ... drop me an e-mail when you finish a patch :) 1539619471 M * AlexanderS ;-) 1539619566 M * Ghislain he cannot or 4.20 will pop 1539625266 M * arekmx Ghislain: which fix for the crash? 1539625272 M * arekmx Ghislain: I mean lockup 1539627389 Q * FireEgl Quit: Leaving... 1539637000 J * fstd_ ~fstd@xdsl-87-78-62-11.netcologne.de 1539637447 Q * fstd Ping timeout: 480 seconds 1539639320 M * Ghislain the lock just went away as kernel incremented so i guess there was a regression somewhere 1539642452 J * fstd ~fstd@xdsl-85-197-42-148.netcologne.de 1539642693 Q * fstd_ Ping timeout: 480 seconds