LXC development for Precise
Several items should be worked on during this cycle:
provide a default bridge and lxc.conf
proper reboot
containerized syslog
userns vfs
apparmor support
ARM support
tests in qa-regression-tests
allow mknod in the container by default (and potential udev problems)
Update mountall to not require our current /lib/init/fstab hack
Community requests?
Blueprint information
- Status:
- Complete
- Approver:
- Dave Walker
- Priority:
- High
- Drafter:
- Ubuntu Server
- Direction:
- Needs approval
- Assignee:
- Serge Hallyn
- Definition:
- Approved
- Series goal:
- Accepted for precise
- Implementation:
- Implemented
- Milestone target:
- ubuntu-12.04-beta-1
- Started by
- Dave Walker
- Completed by
- Serge Hallyn
Whiteboard
Status: Started
NOTE: (jdstrand) jjohansen's work items are being tracked as part ot security-
Work Items:
[serge-hallyn] LXC init script to create default bridge if enabled in /etc/default/lxc: DONE
[daniel-lezcano] Get patchset accepted into kernel so kernel can send reboot signal to container : DONE
[serge-hallyn] Change userspace lxc to not need to watch utmp for reboot: DONE
[serge-hallyn] queue ubuntu package delta for upstream on github: DONE
[stgraber] Make sure we can build in a working LXC container for arm on x86 (need new apt): DONE
[stgraber] Allow mknod in the default Ubuntu template for precise: DONE
[stgraber] modprobe should not work in a container ( check libvirt ): DONE
[stgraber] make mountall not mount certain things when inside a container: DONE
[stgraber] Move lxc-is-container (as generic is-container) into upstart: DONE
[stgraber] Move lxc consoles into upstart: DONE
[serge-hallyn] Add apparmor profile: DONE
[serge-hallyn] When mount controls are in kernel, use them in apparmor profile (thanks, stgraber): DONE
[serge-hallyn] Submit merge proposal to add lxc section to the Ubuntu Server Guide: DONE
[serge-hallyn] Update simple templates to work: DONE
[serge-hallyn] Update fedora template to work: DONE
[serge-hallyn] Update lxc-create/etc manpages: DONE
[serge-hallyn] Keep pushing on the patchset for userns vfs patches: POSTPONED
[serge-hallyn] Update opensuse template to work (requires zypper packaged): POSTPONED
[smoser] open bug for libvirt to check capsys-module, capmac*: POSTPONED
Questions/Comments:
Would we be able to get some documentation of what we can expect (and not expect) from a security aspect this cycle soon? -- Daviey
See wiki.ubuntu.
Thanks.
Work Items
Dependency tree
* Blueprints in grey have been implemented.