[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#812207: linux: AUFS can hang up; Please update to v20160111 or later



Ben -

Thanks for queueing these. I've been trying to figure out the process from this point forward, though, and wondering if you can help educate me. Looking at http://metadata.ftp-master.debian.org/changelogs/main/l/linux/?C=M;O=A, it looks like there has been at least (4.3.5-1) unstable and (4.4.1-1~exp1) experimental builds since the patches were queued, but I don't think I saw the aufs patches in those changelogs. I also haven't yet seen any builds beyond those, and those are both lower urgency, it looks like.

If these were queued for a security update, is there a deadline timer before they go out for jessie-security and wheezy-backports, or does it just mean they're on a security train that goes out with the next CVE?

Thanks.

...Zach

On Tue, Jan 26, 2016 at 9:53 AM, Ben Hutchings <ben@decadent.org.uk> wrote:
Control: tag -1 - moreinfo
Control: tag -1 pending

On Tue, 2016-01-26 at 07:37 -0800, Zachary Loafman wrote:
> On Mon, Jan 25, 2016 at 5:36 PM, Ben Hutchings <ben@decadent.org.uk> wrote:
>
> > > Although I didn't test for 3.16.7, I think merging this commit is
> > enough:
> > https://github.com/sfjro/aufs4-linux/commit/f60d586b7b8cae42bacc603d192810db85278d3c
> >
> > That and the previous commit appear to be sufficient, though they
> > needed some minor changes.  Please can you test whether the attached
> > patches work, following the procedure at
> > <
> > https://kernel-handbook.alioth.debian.org/ch-common-tasks.html#s-common-official
> > > .
> >
>
> I tested these patches on Jessie and they seem to work. Methodology: I spun
> up an 3.16.7-ckt20-1+deb8u3 image in GCE, made sure
> https://hub.docker.com/r/akihirosuda/test18180/ failed as expected. I built
> a 3.16.7-ckt20-1+deb8u3 kernel with those patches quilted in and ran the
> same image:
>
> zml@jessie:~$ sudo docker run -it --rm akihirosuda/test18180
> [INFO] Checking whether hitting docker#18180.
> ....................................................................................................
> [INFO] OK. not hitting docker#18180.
> [INFO] Checking whether sendfile(2) is killable.
> [INFO] If the container hangs up here, you are still facing the bug
> that linux@296291cd tried to fix.
> /test.sh: line 22:  3308 Killed                  /sendfile-test
> zml@jessie:~$
>
> I think we're golden. (Container is not hung, both the original bug
> and the new bug are fixed.)

Thanks, I've queued these up for inclusion in the next security update.

Ben.

--
Ben Hutchings
Q.  Which is the greater problem in the world today, ignorance or apathy?
A.  I don't know and I couldn't care less.


Reply to: