← Back to team overview

kernel-packages team mailing list archive

[Bug 1543367] Re: nested unprileged container fails to start at mounting /proc


Ok, this is happening because lxc, for privileged containers, bind-
mounts /proc/sys and /proc/sys/net onto themselves.  This prevents later
unprivileged mounting of /proc.

You received this bug notification because you are a member of Kernel
Packages, which is subscribed to linux in Ubuntu.

  nested unprileged container fails to start at mounting /proc

Status in linux package in Ubuntu:
Status in lxc package in Ubuntu:

Bug description:
  Create a trusty or xenial host.  Probably use ubuntu-lxc/daily ppa to
  work around other bugs.

  Create a privileged container (again either trusty or xenial will do),
  and install ubuntu-lxc/daily ppa there.

  Create an unprivileged container in that container.  It will fail at
  mounting proc using safe_mount.  At this point it is mounting proc
  onto /proc/self/fd/14 flags 14.

        lxc-start 20160208234209.189 ERROR    lxc_utils -
  utils.c:safe_mount:1695 - Operation not permitted - Failed to mount
  proc onto /usr/lib/x86_64-linux-gnu/lxc/proc

To manage notifications about this bug go to: