From james.page at ubuntu.com Mon Oct 2 14:44:57 2017 From: james.page at ubuntu.com (James Page) Date: Mon, 02 Oct 2017 14:44:57 -0000 Subject: [Bug 1708305] Re: Realtime feature mlockall: Cannot allocate memory References: <150171241072.13811.9640168220127189659.malonedeb@soybean.canonical.com> Message-ID: <150695549739.20308.17057529458772484772.malone@soybean.canonical.com> This bug was fixed in the package libvirt - 1.3.1-1ubuntu10.14~cloud0 --------------- libvirt (1.3.1-1ubuntu10.14~cloud0) trusty-mitaka; urgency=medium . * New update for the Ubuntu Cloud Archive. . libvirt (1.3.1-1ubuntu10.14) xenial; urgency=medium . * d/p/bug-1708305-qemu-Fix-memory-locking-limit-calculation.patch: Remove memlock limit when using . (LP: #1708305). ** Changed in: cloud-archive/mitaka Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libvirt in Ubuntu. https://bugs.launchpad.net/bugs/1708305 Title: Realtime feature mlockall: Cannot allocate memory To manage notifications about this bug go to: https://bugs.launchpad.net/cloud-archive/+bug/1708305/+subscriptions From james.page at ubuntu.com Mon Oct 2 14:46:03 2017 From: james.page at ubuntu.com (James Page) Date: Mon, 02 Oct 2017 14:46:03 -0000 Subject: [Bug 1708305] Re: Realtime feature mlockall: Cannot allocate memory References: <150171241072.13811.9640168220127189659.malonedeb@soybean.canonical.com> Message-ID: <150695556345.12103.1247375791402306389.malone@wampee.canonical.com> This bug was fixed in the package libvirt - 2.5.0-3ubuntu5.5~cloud0 --------------- libvirt (2.5.0-3ubuntu5.5~cloud0) xenial-ocata; urgency=medium . * New update for the Ubuntu Cloud Archive. . libvirt (2.5.0-3ubuntu5.5) zesty; urgency=medium . * d/p/bug-1708305-qemu-Fix-memory-locking-limit-calculation.patch: Remove memlock limit when using . (LP: #1708305). ** Changed in: cloud-archive/ocata Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libvirt in Ubuntu. https://bugs.launchpad.net/bugs/1708305 Title: Realtime feature mlockall: Cannot allocate memory To manage notifications about this bug go to: https://bugs.launchpad.net/cloud-archive/+bug/1708305/+subscriptions From andreas at canonical.com Tue Oct 3 12:25:25 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Tue, 03 Oct 2017 12:25:25 -0000 Subject: [Bug 1720957] Re: package winbind 2:4.5.8+dfsg-0ubuntu0.17.04.7 failed to install/upgrade: il sottoprocesso installato script di post-installation ha restituito lo stato di errore 1 References: <150701483817.2038.7074483387960630176.malonedeb@chaenomeles.canonical.com> Message-ID: <150703352525.20154.6124505870009487278.malone@soybean.canonical.com> Thanks for filing this bug in Ubuntu. Unfortunately the logs just confirm that winbind failed to start, but do not have a reason. Could you please attach the following files: /etc/samba/smb.conf /var/log/samba/log* (there are multiple files starting with "log", please pack them together in a tarball or zip file) Another question: the computer where this happened, is it attached to the network via ethernet or just wifi? In other words, does the network only become available once you login? Thanks ** Changed in: samba (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to samba in Ubuntu. https://bugs.launchpad.net/bugs/1720957 Title: package winbind 2:4.5.8+dfsg-0ubuntu0.17.04.7 failed to install/upgrade: il sottoprocesso installato script di post- installation ha restituito lo stato di errore 1 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1720957/+subscriptions From andreas at canonical.com Tue Oct 3 12:48:55 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Tue, 03 Oct 2017 12:48:55 -0000 Subject: [Bug 1720174] Re: package samba-dbg 2:4.3.11+dfsg-0ubuntu0.16.04.11 failed to install/upgrade: problemas de dependencias - se deja sin configurar References: <150661415750.22699.8267130328469862022.malonedeb@chaenomeles.canonical.com> Message-ID: <150703493579.21028.14249455830518667034.malone@soybean.canonical.com> Thanks for filing this bug in Ubuntu. Turns out you have an invalid configuration setting in your /etc/samba/smb.conf file: [www] path = /var/www comment = red guest ok = red <---- The "guest ok" parameter is a boolean type, meaning it takes only yes or no values. You have it set to a username instead. Once you change that setting and save the file, run these commands to fix your system: sudo apt update sudo apt -f install Thanks! ** Changed in: samba (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to samba in Ubuntu. https://bugs.launchpad.net/bugs/1720174 Title: package samba-dbg 2:4.3.11+dfsg-0ubuntu0.16.04.11 failed to install/upgrade: problemas de dependencias - se deja sin configurar To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1720174/+subscriptions From james.page at ubuntu.com Wed Oct 4 08:28:56 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 04 Oct 2017 08:28:56 -0000 Subject: [Bug 1720887] Re: Default settings for virtlogd results in "too many open files" errors References: <150698084992.12103.18309269881595236533.malonedeb@wampee.canonical.com> Message-ID: <150710573700.12531.2602686810433406287.malone@wampee.canonical.com> @freyes Yes definitely! ** Changed in: charm-nova-compute Status: New => Invalid ** Changed in: libvirt (Ubuntu) Status: New => Triaged ** Changed in: libvirt (Ubuntu) Importance: Undecided => High -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libvirt in Ubuntu. https://bugs.launchpad.net/bugs/1720887 Title: Default settings for virtlogd results in "too many open files" errors To manage notifications about this bug go to: https://bugs.launchpad.net/charm-nova-compute/+bug/1720887/+subscriptions From andreas at canonical.com Wed Oct 4 14:03:52 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Wed, 04 Oct 2017 14:03:52 -0000 Subject: [Bug 1719034] Re: 'ubuntu-advantage status': output formatting? References: <150611822999.5782.16779362953866446391.malonedeb@soybean.canonical.com> Message-ID: <150712583216.20789.2308250213276559028.malone@soybean.canonical.com> When a service is enabled, the output contains more information. Where should we indent that? Example: ubuntu at 87-69:~$ ubuntu-advantage status livepatch: enabled kernel: 4.4.0-96.119-generic fully-patched: true version: "" esm: disabled (not available) fips: disabled ** Bug watch added: github.com/CanonicalLtd/ubuntu-advantage-script/issues #69 https://github.com/CanonicalLtd/ubuntu-advantage-script/issues/69 ** Also affects: ubuntu-advantage-script via https://github.com/CanonicalLtd/ubuntu-advantage-script/issues/69 Importance: Unknown Status: Unknown ** Changed in: ubuntu-advantage-tools (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719034 Title: 'ubuntu-advantage status': output formatting? To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu-advantage-script/+bug/1719034/+subscriptions From andreas at canonical.com Wed Oct 4 14:16:07 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Wed, 04 Oct 2017 14:16:07 -0000 Subject: [Bug 1658273] Re: Failed to preset unit: Unit file /etc/systemd/system/samba-ad-dc.service is masked. References: <20170121051744.20288.84588.malonedeb@wampee.canonical.com> Message-ID: <150712656704.12665.12530531417715103259.malone@wampee.canonical.com> @aleandrodasilva, which error is the same? We have established that the "Failed to preset unit" messages are harmless. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1658273 Title: Failed to preset unit: Unit file /etc/systemd/system/samba-ad- dc.service is masked. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1658273/+subscriptions From andreas at canonical.com Wed Oct 4 14:29:05 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Wed, 04 Oct 2017 14:29:05 -0000 Subject: [Bug 1719034] Re: 'ubuntu-advantage status': output formatting? References: <150611822999.5782.16779362953866446391.malonedeb@soybean.canonical.com> Message-ID: <150712734532.1760.17443450565887895286.malone@chaenomeles.canonical.com> Livepatch is the only status output that is multi-line for now, I think we can leave the indentation on those extra lines as is. It would look like this after aligning the enabled/disabled bits: ubuntu at 87-69:~$ ubuntu-advantage status livepatch: enabled kernel: 4.4.0-1002.2-fips fully-patched: true version: "" esm: disabled (not available) fips: enabled I'll work on the rest of your suggestions and see what it looks like. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719034 Title: 'ubuntu-advantage status': output formatting? To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu-advantage-script/+bug/1719034/+subscriptions From andreas at canonical.com Wed Oct 4 14:52:50 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Wed, 04 Oct 2017 14:52:50 -0000 Subject: [Bug 1721272] [NEW] Rename 'ubuntu-advantage' script to 'advantage' Message-ID: <150712877071.13102.6148654257305099225.malonedeb@wampee.canonical.com> Public bug reported: It was requested that the main script in the package be renamed from 'ubuntu-advantage' to just 'advantage'. ** Affects: ubuntu-advantage-tools (Ubuntu) Importance: High Assignee: Andreas Hasenack (ahasenack) Status: In Progress ** Summary changed: - Update ubuntu-advantage-tools to version 11 which renames the script + Rename 'ubuntu-advantage' script to 'advantage' -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1721272 Title: Rename 'ubuntu-advantage' script to 'advantage' To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+subscriptions From andreas at canonical.com Wed Oct 4 21:08:56 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Wed, 04 Oct 2017 21:08:56 -0000 Subject: [Bug 1684295] Re: sssd fails with 'Exiting the SSSD. Could not restart critical service [tpad]. References: <20170419212018.12328.98123.malonedeb@soybean.canonical.com> Message-ID: <150715133651.12410.16627653201460038826.malone@wampee.canonical.com> Continuing on this bug is fine, thanks for getting back to us with a simplified configuration file. I reopened the bug so that it will be picked up again. ** Changed in: sssd (Ubuntu) Status: Expired => New -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to sssd in Ubuntu. https://bugs.launchpad.net/bugs/1684295 Title: sssd fails with 'Exiting the SSSD. Could not restart critical service [tpad]. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/sssd/+bug/1684295/+subscriptions From james.page at ubuntu.com Thu Oct 5 13:40:03 2017 From: james.page at ubuntu.com (James Page) Date: Thu, 05 Oct 2017 13:40:03 -0000 Subject: [Bug 1715254] Re: nova-novncproxy process gets wedged, requiring kill -HUP References: <150465233858.18943.6161632660361862640.malonedeb@chaenomeles.canonical.com> Message-ID: <150721080372.21485.6160561838605882484.launchpad@gac.canonical.com> ** Also affects: nova (Ubuntu) Importance: Undecided Status: New ** Also affects: websockify (Ubuntu) Importance: Undecided Status: New ** Changed in: charm-nova-cloud-controller Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to websockify in Ubuntu. https://bugs.launchpad.net/bugs/1715254 Title: nova-novncproxy process gets wedged, requiring kill -HUP To manage notifications about this bug go to: https://bugs.launchpad.net/charm-nova-cloud-controller/+bug/1715254/+subscriptions From andreas at canonical.com Thu Oct 5 14:32:14 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Thu, 05 Oct 2017 14:32:14 -0000 Subject: [Bug 1721272] Re: Rename 'ubuntu-advantage' script to 'advantage' References: <150712877071.13102.6148654257305099225.malonedeb@wampee.canonical.com> Message-ID: <150721393442.8209.6665645286600122139.malone@wampee.canonical.com> v11 ** Attachment added: "ubuntu-advantage-tools_11.tar.xz" https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+attachment/4962874/+files/ubuntu-advantage-tools_11.tar.xz -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1721272 Title: Rename 'ubuntu-advantage' script to 'advantage' To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+subscriptions From andreas at canonical.com Thu Oct 5 14:32:34 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Thu, 05 Oct 2017 14:32:34 -0000 Subject: [Bug 1721272] Re: Rename 'ubuntu-advantage' script to 'advantage' References: <150712877071.13102.6148654257305099225.malonedeb@wampee.canonical.com> Message-ID: <150721395505.15394.11022654360656946685.malone@soybean.canonical.com> debdiff (annoying to see because of the rename) ** Patch added: "ubuntu-advantage-tools.debdiff" https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+attachment/4962875/+files/ubuntu-advantage-tools.debdiff ** Description changed: It was requested that the main script in the package be renamed from 'ubuntu-advantage' to just 'advantage'. + + v10..v11 diff on github: https://github.com/CanonicalLtd/ubuntu- + advantage-script/compare/v10...v11 ** Description changed: It was requested that the main script in the package be renamed from 'ubuntu-advantage' to just 'advantage'. - v10..v11 diff on github: https://github.com/CanonicalLtd/ubuntu- - advantage-script/compare/v10...v11 + v10..v11 diff on github: https://github.com/CanonicalLtd/ubuntu-advantage-script/compare/v10...v11 + The above is a more sensible view of the changes as it takes into account the rename in a smart way. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1721272 Title: Rename 'ubuntu-advantage' script to 'advantage' To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+subscriptions From andreas at canonical.com Thu Oct 5 14:48:06 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Thu, 05 Oct 2017 14:48:06 -0000 Subject: [Bug 1721272] Re: [FFe] Rename 'ubuntu-advantage' script to 'advantage' References: <150712877071.13102.6148654257305099225.malonedeb@wampee.canonical.com> Message-ID: <150721488699.7817.16760577688262219617.launchpad@wampee.canonical.com> ** Summary changed: - Rename 'ubuntu-advantage' script to 'advantage' + [FFe] Rename 'ubuntu-advantage' script to 'advantage' -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1721272 Title: [FFe] Rename 'ubuntu-advantage' script to 'advantage' To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+subscriptions From andreas at canonical.com Thu Oct 5 14:53:47 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Thu, 05 Oct 2017 14:53:47 -0000 Subject: [Bug 1721272] Re: [FFe] Rename 'ubuntu-advantage' script to 'advantage' References: <150712877071.13102.6148654257305099225.malonedeb@wampee.canonical.com> Message-ID: <150721522755.21899.3240177568813340393.launchpad@gac.canonical.com> ** Description changed: It was requested that the main script in the package be renamed from 'ubuntu-advantage' to just 'advantage'. - v10..v11 diff on github: https://github.com/CanonicalLtd/ubuntu-advantage-script/compare/v10...v11 - The above is a more sensible view of the changes as it takes into account the rename in a smart way. + Symlinks for the binary and its manpage are provided so that the old + names still work. + + Documentation and tests were updated. + + There was also a small text change in the FIPS output: + https://github.com/CanonicalLtd/ubuntu-advantage- + script/commit/0e62b45c93fde61cbf6f7cdaa4c62638dac425bf + + Full diff on github: https://github.com/CanonicalLtd/ubuntu-advantage-script/compare/v10...v11 + The above is a more sensible view of all changes as it takes into account the rename in a smart way. + + Upstream has Travis CI in place. Link to the last run on this code: + https://travis-ci.org/CanonicalLtd/ubuntu-advantage- + script/builds/283297628 + + Note that ubuntu-advantage-tools is meant for LTS releases only, but we + need it in all of them for upcoming SRU processes. ** Description changed: - It was requested that the main script in the package be renamed from - 'ubuntu-advantage' to just 'advantage'. + High level changes + ================== + It was requested that the main script in the package be renamed from 'ubuntu-advantage' to just 'advantage'. Symlinks for the binary and its manpage are provided so that the old names still work. Documentation and tests were updated. - There was also a small text change in the FIPS output: - https://github.com/CanonicalLtd/ubuntu-advantage- - script/commit/0e62b45c93fde61cbf6f7cdaa4c62638dac425bf + + Diff + ==== + There was also a small text change in the FIPS output: https://github.com/CanonicalLtd/ubuntu-advantage-script/commit/0e62b45c93fde61cbf6f7cdaa4c62638dac425bf Full diff on github: https://github.com/CanonicalLtd/ubuntu-advantage-script/compare/v10...v11 The above is a more sensible view of all changes as it takes into account the rename in a smart way. - Upstream has Travis CI in place. Link to the last run on this code: - https://travis-ci.org/CanonicalLtd/ubuntu-advantage- - script/builds/283297628 - Note that ubuntu-advantage-tools is meant for LTS releases only, but we - need it in all of them for upcoming SRU processes. + CI/Testing + ========== + Upstream has Travis CI in place. Link to the last run on this code: https://travis-ci.org/CanonicalLtd/ubuntu-advantage-script/builds/283297628 + + + Builds + ====== + Daily PPA: https://launchpad.net/~ahasenack/+archive/ubuntu/ubuntu-advantage-tools-devel + + + Misc + ==== + Note that ubuntu-advantage-tools is meant for LTS releases only, but we need it in all of them for upcoming SRU processes. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1721272 Title: [FFe] Rename 'ubuntu-advantage' script to 'advantage' To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+subscriptions From andreas at canonical.com Thu Oct 5 15:13:17 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Thu, 05 Oct 2017 15:13:17 -0000 Subject: [Bug 1721272] Re: [FFe] Rename 'ubuntu-advantage' script to 'advantage' References: <150712877071.13102.6148654257305099225.malonedeb@wampee.canonical.com> Message-ID: <150721639835.1654.9719994352696285494.launchpad@chaenomeles.canonical.com> ** Description changed: High level changes ================== It was requested that the main script in the package be renamed from 'ubuntu-advantage' to just 'advantage'. Symlinks for the binary and its manpage are provided so that the old names still work. Documentation and tests were updated. - Diff ==== There was also a small text change in the FIPS output: https://github.com/CanonicalLtd/ubuntu-advantage-script/commit/0e62b45c93fde61cbf6f7cdaa4c62638dac425bf Full diff on github: https://github.com/CanonicalLtd/ubuntu-advantage-script/compare/v10...v11 The above is a more sensible view of all changes as it takes into account the rename in a smart way. - CI/Testing ========== Upstream has Travis CI in place. Link to the last run on this code: https://travis-ci.org/CanonicalLtd/ubuntu-advantage-script/builds/283297628 - Builds ====== Daily PPA: https://launchpad.net/~ahasenack/+archive/ubuntu/ubuntu-advantage-tools-devel + Source build on artful with proposed enabled: + http://pastebin.ubuntu.com/25680205/ + Misc ==== Note that ubuntu-advantage-tools is meant for LTS releases only, but we need it in all of them for upcoming SRU processes. ** Description changed: High level changes ================== It was requested that the main script in the package be renamed from 'ubuntu-advantage' to just 'advantage'. Symlinks for the binary and its manpage are provided so that the old names still work. Documentation and tests were updated. Diff ==== There was also a small text change in the FIPS output: https://github.com/CanonicalLtd/ubuntu-advantage-script/commit/0e62b45c93fde61cbf6f7cdaa4c62638dac425bf Full diff on github: https://github.com/CanonicalLtd/ubuntu-advantage-script/compare/v10...v11 The above is a more sensible view of all changes as it takes into account the rename in a smart way. CI/Testing ========== Upstream has Travis CI in place. Link to the last run on this code: https://travis-ci.org/CanonicalLtd/ubuntu-advantage-script/builds/283297628 Builds ====== Daily PPA: https://launchpad.net/~ahasenack/+archive/ubuntu/ubuntu-advantage-tools-devel Source build on artful with proposed enabled: http://pastebin.ubuntu.com/25680205/ + Binary build on artful with proposed enabled: + http://pastebin.ubuntu.com/25680210/ + Misc ==== Note that ubuntu-advantage-tools is meant for LTS releases only, but we need it in all of them for upcoming SRU processes. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1721272 Title: [FFe] Rename 'ubuntu-advantage' script to 'advantage' To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+subscriptions From andreas at canonical.com Thu Oct 5 17:56:04 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Thu, 05 Oct 2017 17:56:04 -0000 Subject: [Bug 1721272] Re: [FFe] Rename 'ubuntu-advantage' script to 'advantage' References: <150712877071.13102.6148654257305099225.malonedeb@wampee.canonical.com> Message-ID: <150722616518.7489.6570908671708064288.launchpad@wampee.canonical.com> ** Description changed: High level changes ================== It was requested that the main script in the package be renamed from 'ubuntu-advantage' to just 'advantage'. Symlinks for the binary and its manpage are provided so that the old names still work. Documentation and tests were updated. Diff ==== There was also a small text change in the FIPS output: https://github.com/CanonicalLtd/ubuntu-advantage-script/commit/0e62b45c93fde61cbf6f7cdaa4c62638dac425bf Full diff on github: https://github.com/CanonicalLtd/ubuntu-advantage-script/compare/v10...v11 The above is a more sensible view of all changes as it takes into account the rename in a smart way. CI/Testing ========== Upstream has Travis CI in place. Link to the last run on this code: https://travis-ci.org/CanonicalLtd/ubuntu-advantage-script/builds/283297628 Builds ====== Daily PPA: https://launchpad.net/~ahasenack/+archive/ubuntu/ubuntu-advantage-tools-devel Source build on artful with proposed enabled: http://pastebin.ubuntu.com/25680205/ Binary build on artful with proposed enabled: http://pastebin.ubuntu.com/25680210/ + Upgrading + ========= + http://pastebin.ubuntu.com/25681014/ shows the upgrade from 10 to 11 and that both names ("ubuntu-advantage" and the new "advantage") can be used. + + Misc ==== Note that ubuntu-advantage-tools is meant for LTS releases only, but we need it in all of them for upcoming SRU processes. ** Description changed: High level changes ================== It was requested that the main script in the package be renamed from 'ubuntu-advantage' to just 'advantage'. Symlinks for the binary and its manpage are provided so that the old names still work. Documentation and tests were updated. Diff ==== There was also a small text change in the FIPS output: https://github.com/CanonicalLtd/ubuntu-advantage-script/commit/0e62b45c93fde61cbf6f7cdaa4c62638dac425bf - Full diff on github: https://github.com/CanonicalLtd/ubuntu-advantage-script/compare/v10...v11 + There is no i18n for this package. + + Full diff of all changes on github: https://github.com/CanonicalLtd/ubuntu-advantage-script/compare/v10...v11 The above is a more sensible view of all changes as it takes into account the rename in a smart way. CI/Testing ========== Upstream has Travis CI in place. Link to the last run on this code: https://travis-ci.org/CanonicalLtd/ubuntu-advantage-script/builds/283297628 Builds ====== Daily PPA: https://launchpad.net/~ahasenack/+archive/ubuntu/ubuntu-advantage-tools-devel Source build on artful with proposed enabled: http://pastebin.ubuntu.com/25680205/ Binary build on artful with proposed enabled: http://pastebin.ubuntu.com/25680210/ - Upgrading ========= http://pastebin.ubuntu.com/25681014/ shows the upgrade from 10 to 11 and that both names ("ubuntu-advantage" and the new "advantage") can be used. - Misc ==== Note that ubuntu-advantage-tools is meant for LTS releases only, but we need it in all of them for upcoming SRU processes. ** Description changed: High level changes ================== It was requested that the main script in the package be renamed from 'ubuntu-advantage' to just 'advantage'. Symlinks for the binary and its manpage are provided so that the old names still work. Documentation and tests were updated. Diff ==== There was also a small text change in the FIPS output: https://github.com/CanonicalLtd/ubuntu-advantage-script/commit/0e62b45c93fde61cbf6f7cdaa4c62638dac425bf There is no i18n for this package. Full diff of all changes on github: https://github.com/CanonicalLtd/ubuntu-advantage-script/compare/v10...v11 - The above is a more sensible view of all changes as it takes into account the rename in a smart way. + The above is a more sensible view of all changes as it takes into account the rename in a smart way, but a debdiff is also attached to this bug. CI/Testing ========== Upstream has Travis CI in place. Link to the last run on this code: https://travis-ci.org/CanonicalLtd/ubuntu-advantage-script/builds/283297628 Builds ====== Daily PPA: https://launchpad.net/~ahasenack/+archive/ubuntu/ubuntu-advantage-tools-devel Source build on artful with proposed enabled: http://pastebin.ubuntu.com/25680205/ Binary build on artful with proposed enabled: http://pastebin.ubuntu.com/25680210/ Upgrading ========= http://pastebin.ubuntu.com/25681014/ shows the upgrade from 10 to 11 and that both names ("ubuntu-advantage" and the new "advantage") can be used. Misc ==== Note that ubuntu-advantage-tools is meant for LTS releases only, but we need it in all of them for upcoming SRU processes. ** Description changed: High level changes ================== It was requested that the main script in the package be renamed from 'ubuntu-advantage' to just 'advantage'. Symlinks for the binary and its manpage are provided so that the old names still work. Documentation and tests were updated. Diff ==== There was also a small text change in the FIPS output: https://github.com/CanonicalLtd/ubuntu-advantage-script/commit/0e62b45c93fde61cbf6f7cdaa4c62638dac425bf There is no i18n for this package. Full diff of all changes on github: https://github.com/CanonicalLtd/ubuntu-advantage-script/compare/v10...v11 The above is a more sensible view of all changes as it takes into account the rename in a smart way, but a debdiff is also attached to this bug. CI/Testing ========== Upstream has Travis CI in place. Link to the last run on this code: https://travis-ci.org/CanonicalLtd/ubuntu-advantage-script/builds/283297628 + To run the tests manually: + - sudo apt install tox + - cd ubuntu-advantage-tools-11 + - sed -i 's/py35/py36/' tox.ini + - tox + Here is a run: http://pastebin.ubuntu.com/25681058/ + Builds ====== Daily PPA: https://launchpad.net/~ahasenack/+archive/ubuntu/ubuntu-advantage-tools-devel Source build on artful with proposed enabled: http://pastebin.ubuntu.com/25680205/ Binary build on artful with proposed enabled: http://pastebin.ubuntu.com/25680210/ Upgrading ========= http://pastebin.ubuntu.com/25681014/ shows the upgrade from 10 to 11 and that both names ("ubuntu-advantage" and the new "advantage") can be used. Misc ==== Note that ubuntu-advantage-tools is meant for LTS releases only, but we need it in all of them for upcoming SRU processes. ** Description changed: High level changes ================== It was requested that the main script in the package be renamed from 'ubuntu-advantage' to just 'advantage'. Symlinks for the binary and its manpage are provided so that the old names still work. Documentation and tests were updated. Diff ==== There was also a small text change in the FIPS output: https://github.com/CanonicalLtd/ubuntu-advantage-script/commit/0e62b45c93fde61cbf6f7cdaa4c62638dac425bf There is no i18n for this package. Full diff of all changes on github: https://github.com/CanonicalLtd/ubuntu-advantage-script/compare/v10...v11 The above is a more sensible view of all changes as it takes into account the rename in a smart way, but a debdiff is also attached to this bug. CI/Testing ========== Upstream has Travis CI in place. Link to the last run on this code: https://travis-ci.org/CanonicalLtd/ubuntu-advantage-script/builds/283297628 - To run the tests manually: + To run the tests manually on artful: - sudo apt install tox + - tar xJf ubuntu-advantage-tools_11.tar.xz - cd ubuntu-advantage-tools-11 - sed -i 's/py35/py36/' tox.ini - tox Here is a run: http://pastebin.ubuntu.com/25681058/ Builds ====== Daily PPA: https://launchpad.net/~ahasenack/+archive/ubuntu/ubuntu-advantage-tools-devel Source build on artful with proposed enabled: http://pastebin.ubuntu.com/25680205/ Binary build on artful with proposed enabled: http://pastebin.ubuntu.com/25680210/ Upgrading ========= http://pastebin.ubuntu.com/25681014/ shows the upgrade from 10 to 11 and that both names ("ubuntu-advantage" and the new "advantage") can be used. Misc ==== Note that ubuntu-advantage-tools is meant for LTS releases only, but we need it in all of them for upcoming SRU processes. ** Changed in: ubuntu-advantage-tools (Ubuntu) Status: In Progress => New ** Changed in: ubuntu-advantage-tools (Ubuntu) Assignee: Andreas Hasenack (ahasenack) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1721272 Title: [FFe] Rename 'ubuntu-advantage' script to 'advantage' To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+subscriptions From andreas at canonical.com Thu Oct 5 18:16:40 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Thu, 05 Oct 2017 18:16:40 -0000 Subject: [Bug 1721272] Re: [FFe] Rename 'ubuntu-advantage' script to 'advantage' References: <150712877071.13102.6148654257305099225.malonedeb@wampee.canonical.com> Message-ID: <150722740133.7626.17105337685572362295.launchpad@wampee.canonical.com> ** Description changed: High level changes ================== - It was requested that the main script in the package be renamed from 'ubuntu-advantage' to just 'advantage'. + Mark S. requested that the main script in the package be renamed from 'ubuntu-advantage' to just 'advantage'. Symlinks for the binary and its manpage are provided so that the old names still work. Documentation and tests were updated. Diff ==== There was also a small text change in the FIPS output: https://github.com/CanonicalLtd/ubuntu-advantage-script/commit/0e62b45c93fde61cbf6f7cdaa4c62638dac425bf There is no i18n for this package. Full diff of all changes on github: https://github.com/CanonicalLtd/ubuntu-advantage-script/compare/v10...v11 The above is a more sensible view of all changes as it takes into account the rename in a smart way, but a debdiff is also attached to this bug. CI/Testing ========== Upstream has Travis CI in place. Link to the last run on this code: https://travis-ci.org/CanonicalLtd/ubuntu-advantage-script/builds/283297628 To run the tests manually on artful: - sudo apt install tox - tar xJf ubuntu-advantage-tools_11.tar.xz - cd ubuntu-advantage-tools-11 - sed -i 's/py35/py36/' tox.ini - tox Here is a run: http://pastebin.ubuntu.com/25681058/ Builds ====== Daily PPA: https://launchpad.net/~ahasenack/+archive/ubuntu/ubuntu-advantage-tools-devel Source build on artful with proposed enabled: http://pastebin.ubuntu.com/25680205/ Binary build on artful with proposed enabled: http://pastebin.ubuntu.com/25680210/ Upgrading ========= http://pastebin.ubuntu.com/25681014/ shows the upgrade from 10 to 11 and that both names ("ubuntu-advantage" and the new "advantage") can be used. Misc ==== Note that ubuntu-advantage-tools is meant for LTS releases only, but we need it in all of them for upcoming SRU processes. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1721272 Title: [FFe] Rename 'ubuntu-advantage' script to 'advantage' To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+subscriptions From andreas at canonical.com Thu Oct 5 18:35:59 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Thu, 05 Oct 2017 18:35:59 -0000 Subject: [Bug 1721272] Re: [FFe] Main script should be called 'advantage' References: <150712877071.13102.6148654257305099225.malonedeb@wampee.canonical.com> Message-ID: <150722855945.21936.13745653163979224990.launchpad@gac.canonical.com> ** Summary changed: - [FFe] Rename 'ubuntu-advantage' script to 'advantage' + [FFe] Main script should be called 'advantage' ** Description changed: High level changes ================== - Mark S. requested that the main script in the package be renamed from 'ubuntu-advantage' to just 'advantage'. + Mark S. requested that the main script in the package be called 'advantage'. Symlinks for the binary and its manpage are provided so that the old - names still work. + 'ubuntu-advantage' name still works. Documentation and tests were updated. Diff ==== There was also a small text change in the FIPS output: https://github.com/CanonicalLtd/ubuntu-advantage-script/commit/0e62b45c93fde61cbf6f7cdaa4c62638dac425bf There is no i18n for this package. Full diff of all changes on github: https://github.com/CanonicalLtd/ubuntu-advantage-script/compare/v10...v11 The above is a more sensible view of all changes as it takes into account the rename in a smart way, but a debdiff is also attached to this bug. CI/Testing ========== Upstream has Travis CI in place. Link to the last run on this code: https://travis-ci.org/CanonicalLtd/ubuntu-advantage-script/builds/283297628 To run the tests manually on artful: - sudo apt install tox - tar xJf ubuntu-advantage-tools_11.tar.xz - cd ubuntu-advantage-tools-11 - sed -i 's/py35/py36/' tox.ini - tox Here is a run: http://pastebin.ubuntu.com/25681058/ Builds ====== Daily PPA: https://launchpad.net/~ahasenack/+archive/ubuntu/ubuntu-advantage-tools-devel Source build on artful with proposed enabled: http://pastebin.ubuntu.com/25680205/ Binary build on artful with proposed enabled: http://pastebin.ubuntu.com/25680210/ Upgrading ========= http://pastebin.ubuntu.com/25681014/ shows the upgrade from 10 to 11 and that both names ("ubuntu-advantage" and the new "advantage") can be used. Misc ==== Note that ubuntu-advantage-tools is meant for LTS releases only, but we need it in all of them for upcoming SRU processes. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1721272 Title: [FFe] Main script should be called 'advantage' To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+subscriptions From andreas at canonical.com Fri Oct 6 13:06:26 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Fri, 06 Oct 2017 13:06:26 -0000 Subject: [Bug 1721750] Re: package libwind0-heimdal:amd64 7.1.0+dfsg-9ubuntu1.1 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting configuration References: <150728684232.21485.1918422802740630800.malonedeb@gac.canonical.com> Message-ID: <150729518607.15993.3108927708842475547.malone@soybean.canonical.com> Thanks for filing this bug in Ubuntu. Could you please try the following: sudo apt update sudo apt install --reinstall libwind0-heimdal:amd64 sudo apt -f install ** Changed in: heimdal (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to heimdal in Ubuntu. https://bugs.launchpad.net/bugs/1721750 Title: package libwind0-heimdal:amd64 7.1.0+dfsg-9ubuntu1.1 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting configuration To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/heimdal/+bug/1721750/+subscriptions From andreas at canonical.com Fri Oct 6 19:38:14 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Fri, 06 Oct 2017 19:38:14 -0000 Subject: [Bug 1721859] Re: package libnss-winbind:i386 2:4.3.11+dfsg-0ubuntu0.16.04.11 failed to install/upgrade: problemas de dependencias - se deja sin configurar References: <150731814789.7885.9874061362158662913.malonedeb@wampee.canonical.com> Message-ID: <150731869480.1322.6227340318687122940.malone@chaenomeles.canonical.com> *** This bug is a duplicate of bug 1720174 *** https://bugs.launchpad.net/bugs/1720174 You reported this about a week ago. Please see https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1720174/comments/2 for the solution in that bug. ** This bug has been marked a duplicate of bug 1720174 package samba-dbg 2:4.3.11+dfsg-0ubuntu0.16.04.11 failed to install/upgrade: problemas de dependencias - se deja sin configurar -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to samba in Ubuntu. https://bugs.launchpad.net/bugs/1721859 Title: package libnss-winbind:i386 2:4.3.11+dfsg-0ubuntu0.16.04.11 failed to install/upgrade: problemas de dependencias - se deja sin configurar To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1721859/+subscriptions From andreas at canonical.com Wed Oct 11 16:29:36 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Wed, 11 Oct 2017 16:29:36 -0000 Subject: [Bug 1722831] Re: package samba 2:4.3.11+dfsg-0ubuntu0.16.04.11 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1 References: <150773401354.15282.7759805161096760495.malonedeb@soybean.canonical.com> Message-ID: <150773937694.8245.12136169988863560378.malone@wampee.canonical.com> Thanks for filing this bug in Ubuntu. The attached logs show that the samba services failed to start, but not why. Could you please attach the following files to this bug: /etc/samba/smb.conf /var/log/samba/log* <-- all files that start with "log" in the /var/log/samba directory It's possible that a configuration option that was valid in a previous version is now invalid, I'll mark this bug as incomplete until you attach those files. Thanks! ** Changed in: samba (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to samba in Ubuntu. https://bugs.launchpad.net/bugs/1722831 Title: package samba 2:4.3.11+dfsg-0ubuntu0.16.04.11 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1722831/+subscriptions From nish.aravamudan at canonical.com Thu Oct 12 19:30:23 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Thu, 12 Oct 2017 19:30:23 -0000 Subject: [Bug 1722808] Re: update to 2.10.1 point release References: <150772902909.1466.5268045072203974620.malonedeb@chaenomeles.canonical.com> Message-ID: <150783662404.15571.9789323559119971121.malone@soybean.canonical.com> @paelzer, should this be assigned to you? Not sure if there is an explicit request here for someone else to pick this up? -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to qemu in Ubuntu. https://bugs.launchpad.net/bugs/1722808 Title: update to 2.10.1 point release To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/qemu/+bug/1722808/+subscriptions From nish.aravamudan at canonical.com Thu Oct 12 19:32:14 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Thu, 12 Oct 2017 19:32:14 -0000 Subject: [Bug 1720126] Re: [ip link] Message truncated error for large number of passthrough VFs References: <150660088961.29180.1650947608023209442.malonedeb@gac.canonical.com> Message-ID: <150783673450.1429.10327198855311934554.launchpad@chaenomeles.canonical.com> ** Also affects: iproute2 (Ubuntu Xenial) Importance: Undecided Status: New ** Also affects: iproute2 (Ubuntu Zesty) Importance: Undecided Status: New ** Changed in: iproute2 (Ubuntu) Status: Confirmed => Fix Released ** Changed in: iproute2 (Ubuntu Xenial) Status: New => Confirmed ** Changed in: iproute2 (Ubuntu Zesty) Status: New => Fix Released ** Changed in: iproute2 (Ubuntu Xenial) Importance: Undecided => High ** Changed in: iproute2 (Ubuntu) Importance: High => Undecided ** Also affects: iproute2 (Ubuntu Trusty) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1720126 Title: [ip link] Message truncated error for large number of passthrough VFs To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/iproute2/+bug/1720126/+subscriptions From nish.aravamudan at canonical.com Thu Oct 12 19:43:11 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Thu, 12 Oct 2017 19:43:11 -0000 Subject: [Bug 1719671] Re: [SRU][xenial] include fips enablement into ubuntu-advantage References: <150644034167.6129.8221946942865677369.malonedeb@soybean.canonical.com> Message-ID: <150783739120.1214.1981032075234690398.malone@chaenomeles.canonical.com> @j-latten: It's unclear to me if this is actually intended for all releases (based upon the nominated tasks by Manoj and Andreas) or just Xenial (based upon the bug description). Can you clarify? -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719671 Title: [SRU][xenial] include fips enablement into ubuntu-advantage To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+subscriptions From nish.aravamudan at canonical.com Thu Oct 12 19:48:29 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Thu, 12 Oct 2017 19:48:29 -0000 Subject: [Bug 1721546] Re: max open files limit prevents max_connections over 214 on systemd References: <150721058709.15196.16089744505018496083.malonedeb@soybean.canonical.com> Message-ID: <150783770929.22119.1465690249701172623.malone@gac.canonical.com> Should this be fixed in Debian? Or at least reported there? So that it does not add to the delta? And is the underlying proposed fix to add the Service LimitNOFILE change to the default mysql service file? -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to mysql-5.7 in Ubuntu. Matching subscriptions: main https://bugs.launchpad.net/bugs/1721546 Title: max open files limit prevents max_connections over 214 on systemd To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/mysql-5.7/+bug/1721546/+subscriptions From nish.aravamudan at canonical.com Thu Oct 12 19:53:08 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Thu, 12 Oct 2017 19:53:08 -0000 Subject: [Bug 1720126] Re: [ip link] Message truncated error for large number of passthrough VFs References: <150660088961.29180.1650947608023209442.malonedeb@gac.canonical.com> Message-ID: <150783798826.15858.14154509740810956625.malone@soybean.canonical.com> @jangutter: I'm not sure why you built from source? I assume you actually tested the version in 17.04 and it worked. The proper solution is to backport the Debian change to xenial and trusty, most likely. A git repository that can be used with `git-ubuntu` (sudo snap install --classic git-ubuntu`) is available here: https://code.launchpad.net/~usd-import- team/ubuntu/+source/iproute2/+git/iproute2 Feel free to propose MPs against ubuntu/xenial-devel and ubuntu/trusty- devel, or I can do it if you'd prefer. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1720126 Title: [ip link] Message truncated error for large number of passthrough VFs To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/iproute2/+bug/1720126/+subscriptions From nish.aravamudan at canonical.com Thu Oct 12 20:06:33 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Thu, 12 Oct 2017 20:06:33 -0000 Subject: [Bug 1719671] Re: [SRU][xenial] include fips enablement into ubuntu-advantage References: <150644034167.6129.8221946942865677369.malonedeb@soybean.canonical.com> Message-ID: <150783879385.16068.18247807295807259467.malone@soybean.canonical.com> After chatting on IRC, this was fixed in Artful in LP: #1718291. ** Changed in: ubuntu-advantage-tools (Ubuntu) Status: New => Fix Released ** Also affects: ubuntu-advantage-tools (Ubuntu Xenial) Importance: Undecided Status: New ** Also affects: ubuntu-advantage-tools (Ubuntu Zesty) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719671 Title: [SRU][xenial] include fips enablement into ubuntu-advantage To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+subscriptions From nish.aravamudan at canonical.com Thu Oct 12 20:41:05 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Thu, 12 Oct 2017 20:41:05 -0000 Subject: [Bug 1721468] Re: Free invalid pointer crash in vnc References: <150719011072.13203.5552998352120576113.malonedeb@wampee.canonical.com> Message-ID: <150784086563.7779.12925956527886429609.malone@wampee.canonical.com> @berrange, if so, can @peter-sabaini verify that it is fixed in 17.04 (2.8 based) and Artful (2.10 based). ** Changed in: qemu (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to qemu in Ubuntu. https://bugs.launchpad.net/bugs/1721468 Title: Free invalid pointer crash in vnc To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/qemu/+bug/1721468/+subscriptions From andreas at canonical.com Fri Oct 13 12:50:49 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Fri, 13 Oct 2017 12:50:49 -0000 Subject: [Bug 1722831] Re: package samba 2:4.3.11+dfsg-0ubuntu0.16.04.11 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1 References: <150773401354.15282.7759805161096760495.malonedeb@soybean.canonical.com> Message-ID: <150789904984.21936.152145029115213460.malone@gac.canonical.com> Sorry, your attachment seems to be a screenshot of something (for some reason I can't open it), but I need the files I requested in comment #2 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to samba in Ubuntu. https://bugs.launchpad.net/bugs/1722831 Title: package samba 2:4.3.11+dfsg-0ubuntu0.16.04.11 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1722831/+subscriptions From andreas at canonical.com Fri Oct 13 12:45:02 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Fri, 13 Oct 2017 12:45:02 -0000 Subject: [Bug 1721272] Re: [FFe] Main script should be called 'advantage' References: <150712877071.13102.6148654257305099225.malonedeb@wampee.canonical.com> Message-ID: <150789870260.1171.3277010865676184945.malone@chaenomeles.canonical.com> Ok, so I will: - revert this change we have here in the bug - make /usr/bin/ua -> /usr/bin/ubuntu-advantage - make /usr/share/man/man1/ua.1 -> /usr/share/man/man1/ubuntu-advantage.1 - change contents of ubuntu-advantage.1 to also refer to the short name "ua" - change README.md to also refer to the script as "ua" - let unit tests keep using the name ubuntu-advantage - maybe change ubuntu-advantage (the script) to use $0 instead of its name in the help output -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1721272 Title: [FFe] Main script should be called 'advantage' To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+subscriptions From andreas at canonical.com Fri Oct 13 12:46:10 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Fri, 13 Oct 2017 12:46:10 -0000 Subject: [Bug 1721272] Re: [FFe] Main script should be called 'advantage' References: <150712877071.13102.6148654257305099225.malonedeb@wampee.canonical.com> Message-ID: <150789877079.21970.1754700140244859875.malone@gac.canonical.com> I also believe the window for a FFe is over and this will become a normal SRU for Artful now. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1721272 Title: [FFe] Main script should be called 'advantage' To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+subscriptions From andreas at canonical.com Fri Oct 13 17:26:55 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Fri, 13 Oct 2017 17:26:55 -0000 Subject: [Bug 1721272] Re: [FFe] Create 'ua' symlink pointing at 'ubuntu-advantage' References: <150712877071.13102.6148654257305099225.malonedeb@wampee.canonical.com> Message-ID: <150791561565.8007.14909618569355990635.launchpad@wampee.canonical.com> ** Summary changed: - [FFe] Main script should be called 'advantage' + [FFe] Create 'ua' symlink pointing at 'ubuntu-advantage' ** Description changed: High level changes ================== - Mark S. requested that the main script in the package be called 'advantage'. - - Symlinks for the binary and its manpage are provided so that the old - 'ubuntu-advantage' name still works. + We want to add a short alias named 'ua' to the ubuntu-advantage script. + This can be easily accomplished by creating a 'ua' symlink pointing at the 'ubuntu-advantage' script. Likewise for its manpage. Documentation and tests were updated. Diff ==== There was also a small text change in the FIPS output: https://github.com/CanonicalLtd/ubuntu-advantage-script/commit/0e62b45c93fde61cbf6f7cdaa4c62638dac425bf There is no i18n for this package. Full diff of all changes on github: https://github.com/CanonicalLtd/ubuntu-advantage-script/compare/v10...v11 The above is a more sensible view of all changes as it takes into account the rename in a smart way, but a debdiff is also attached to this bug. CI/Testing ========== Upstream has Travis CI in place. Link to the last run on this code: https://travis-ci.org/CanonicalLtd/ubuntu-advantage-script/builds/283297628 To run the tests manually on artful: - sudo apt install tox - tar xJf ubuntu-advantage-tools_11.tar.xz - cd ubuntu-advantage-tools-11 - sed -i 's/py35/py36/' tox.ini - tox Here is a run: http://pastebin.ubuntu.com/25681058/ Builds ====== Daily PPA: https://launchpad.net/~ahasenack/+archive/ubuntu/ubuntu-advantage-tools-devel Source build on artful with proposed enabled: http://pastebin.ubuntu.com/25680205/ Binary build on artful with proposed enabled: http://pastebin.ubuntu.com/25680210/ Upgrading ========= http://pastebin.ubuntu.com/25681014/ shows the upgrade from 10 to 11 and that both names ("ubuntu-advantage" and the new "advantage") can be used. Misc ==== Note that ubuntu-advantage-tools is meant for LTS releases only, but we need it in all of them for upcoming SRU processes. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1721272 Title: [FFe] Create 'ua' symlink pointing at 'ubuntu-advantage' To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+subscriptions From andreas at canonical.com Fri Oct 13 18:17:01 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Fri, 13 Oct 2017 18:17:01 -0000 Subject: [Bug 1721272] Re: [FFe] Create 'ua' symlink pointing at 'ubuntu-advantage' References: <150712877071.13102.6148654257305099225.malonedeb@wampee.canonical.com> Message-ID: <150791862213.1581.5728000958671842087.launchpad@chaenomeles.canonical.com> ** Description changed: High level changes ================== We want to add a short alias named 'ua' to the ubuntu-advantage script. This can be easily accomplished by creating a 'ua' symlink pointing at the 'ubuntu-advantage' script. Likewise for its manpage. Documentation and tests were updated. Diff ==== There was also a small text change in the FIPS output: https://github.com/CanonicalLtd/ubuntu-advantage-script/commit/0e62b45c93fde61cbf6f7cdaa4c62638dac425bf There is no i18n for this package. - Full diff of all changes on github: https://github.com/CanonicalLtd/ubuntu-advantage-script/compare/v10...v11 - The above is a more sensible view of all changes as it takes into account the rename in a smart way, but a debdiff is also attached to this bug. + Full diff of all changes on github: https://github.com/CanonicalLtd + /ubuntu-advantage-script/compare/v10...v12 + CI/Testing ========== - Upstream has Travis CI in place. Link to the last run on this code: https://travis-ci.org/CanonicalLtd/ubuntu-advantage-script/builds/283297628 + Upstream has Travis CI in place. Link to the last run on this code: https://travis-ci.org/CanonicalLtd/ubuntu-advantage-script/builds/287672916 To run the tests manually on artful: - sudo apt install tox - tar xJf ubuntu-advantage-tools_11.tar.xz - cd ubuntu-advantage-tools-11 - sed -i 's/py35/py36/' tox.ini - tox Here is a run: http://pastebin.ubuntu.com/25681058/ Builds ====== Daily PPA: https://launchpad.net/~ahasenack/+archive/ubuntu/ubuntu-advantage-tools-devel Source build on artful with proposed enabled: http://pastebin.ubuntu.com/25680205/ Binary build on artful with proposed enabled: http://pastebin.ubuntu.com/25680210/ Upgrading ========= http://pastebin.ubuntu.com/25681014/ shows the upgrade from 10 to 11 and that both names ("ubuntu-advantage" and the new "advantage") can be used. Misc ==== Note that ubuntu-advantage-tools is meant for LTS releases only, but we need it in all of them for upcoming SRU processes. ** Description changed: High level changes ================== We want to add a short alias named 'ua' to the ubuntu-advantage script. This can be easily accomplished by creating a 'ua' symlink pointing at the 'ubuntu-advantage' script. Likewise for its manpage. Documentation and tests were updated. Diff ==== There was also a small text change in the FIPS output: https://github.com/CanonicalLtd/ubuntu-advantage-script/commit/0e62b45c93fde61cbf6f7cdaa4c62638dac425bf There is no i18n for this package. Full diff of all changes on github: https://github.com/CanonicalLtd /ubuntu-advantage-script/compare/v10...v12 - CI/Testing ========== Upstream has Travis CI in place. Link to the last run on this code: https://travis-ci.org/CanonicalLtd/ubuntu-advantage-script/builds/287672916 To run the tests manually on artful: - sudo apt install tox - - tar xJf ubuntu-advantage-tools_11.tar.xz - - cd ubuntu-advantage-tools-11 + - tar xJf ubuntu-advantage-tools_12.tar.xz + - cd ubuntu-advantage-tools-12 - sed -i 's/py35/py36/' tox.ini - tox - Here is a run: http://pastebin.ubuntu.com/25681058/ + Here is a run: http://xxxxxxx Builds ====== Daily PPA: https://launchpad.net/~ahasenack/+archive/ubuntu/ubuntu-advantage-tools-devel - Source build on artful with proposed enabled: - http://pastebin.ubuntu.com/25680205/ + Source build on artful with proposed enabled: http://xxxxx Binary build on artful with proposed enabled: - http://pastebin.ubuntu.com/25680210/ + http://xxxxx Upgrading ========= - http://pastebin.ubuntu.com/25681014/ shows the upgrade from 10 to 11 and that both names ("ubuntu-advantage" and the new "advantage") can be used. + http://xxxxx/ shows the upgrade from 10 to 12 and that both names ("ubuntu-advantage" and the new "ua") can be used. Misc ==== Note that ubuntu-advantage-tools is meant for LTS releases only, but we need it in all of them for upcoming SRU processes. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1721272 Title: [FFe] Create 'ua' symlink pointing at 'ubuntu-advantage' To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+subscriptions From andreas at canonical.com Fri Oct 13 18:44:33 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Fri, 13 Oct 2017 18:44:33 -0000 Subject: [Bug 1721272] Re: [FFe] Create 'ua' symlink pointing at 'ubuntu-advantage' References: <150712877071.13102.6148654257305099225.malonedeb@wampee.canonical.com> Message-ID: <150792027362.21637.3618390972674360547.malone@gac.canonical.com> v12 ** Description changed: High level changes ================== We want to add a short alias named 'ua' to the ubuntu-advantage script. This can be easily accomplished by creating a 'ua' symlink pointing at the 'ubuntu-advantage' script. Likewise for its manpage. Documentation and tests were updated. Diff ==== There was also a small text change in the FIPS output: https://github.com/CanonicalLtd/ubuntu-advantage-script/commit/0e62b45c93fde61cbf6f7cdaa4c62638dac425bf There is no i18n for this package. Full diff of all changes on github: https://github.com/CanonicalLtd /ubuntu-advantage-script/compare/v10...v12 CI/Testing ========== Upstream has Travis CI in place. Link to the last run on this code: https://travis-ci.org/CanonicalLtd/ubuntu-advantage-script/builds/287672916 To run the tests manually on artful: - sudo apt install tox - tar xJf ubuntu-advantage-tools_12.tar.xz - cd ubuntu-advantage-tools-12 - sed -i 's/py35/py36/' tox.ini - tox Here is a run: http://xxxxxxx Builds ====== Daily PPA: https://launchpad.net/~ahasenack/+archive/ubuntu/ubuntu-advantage-tools-devel - Source build on artful with proposed enabled: http://xxxxx + Source build on artful with proposed enabled: + http://pastebin.ubuntu.com/25733640/ Binary build on artful with proposed enabled: - http://xxxxx + http://pastebin.ubuntu.com/25733649/ Upgrading ========= http://xxxxx/ shows the upgrade from 10 to 12 and that both names ("ubuntu-advantage" and the new "ua") can be used. Misc ==== Note that ubuntu-advantage-tools is meant for LTS releases only, but we need it in all of them for upcoming SRU processes. ** Description changed: High level changes ================== We want to add a short alias named 'ua' to the ubuntu-advantage script. This can be easily accomplished by creating a 'ua' symlink pointing at the 'ubuntu-advantage' script. Likewise for its manpage. Documentation and tests were updated. Diff ==== There was also a small text change in the FIPS output: https://github.com/CanonicalLtd/ubuntu-advantage-script/commit/0e62b45c93fde61cbf6f7cdaa4c62638dac425bf There is no i18n for this package. Full diff of all changes on github: https://github.com/CanonicalLtd /ubuntu-advantage-script/compare/v10...v12 CI/Testing ========== Upstream has Travis CI in place. Link to the last run on this code: https://travis-ci.org/CanonicalLtd/ubuntu-advantage-script/builds/287672916 To run the tests manually on artful: - sudo apt install tox - tar xJf ubuntu-advantage-tools_12.tar.xz - cd ubuntu-advantage-tools-12 - sed -i 's/py35/py36/' tox.ini - tox Here is a run: http://xxxxxxx Builds ====== Daily PPA: https://launchpad.net/~ahasenack/+archive/ubuntu/ubuntu-advantage-tools-devel Source build on artful with proposed enabled: http://pastebin.ubuntu.com/25733640/ Binary build on artful with proposed enabled: http://pastebin.ubuntu.com/25733649/ Upgrading ========= - http://xxxxx/ shows the upgrade from 10 to 12 and that both names ("ubuntu-advantage" and the new "ua") can be used. + http://pastebin.ubuntu.com/25733666/ shows the upgrade from 10 to 12 and that both names ("ubuntu-advantage" and the new "ua") can be used in v12. Misc ==== Note that ubuntu-advantage-tools is meant for LTS releases only, but we need it in all of them for upcoming SRU processes. ** Description changed: High level changes ================== We want to add a short alias named 'ua' to the ubuntu-advantage script. This can be easily accomplished by creating a 'ua' symlink pointing at the 'ubuntu-advantage' script. Likewise for its manpage. Documentation and tests were updated. Diff ==== There was also a small text change in the FIPS output: https://github.com/CanonicalLtd/ubuntu-advantage-script/commit/0e62b45c93fde61cbf6f7cdaa4c62638dac425bf There is no i18n for this package. Full diff of all changes on github: https://github.com/CanonicalLtd /ubuntu-advantage-script/compare/v10...v12 CI/Testing ========== Upstream has Travis CI in place. Link to the last run on this code: https://travis-ci.org/CanonicalLtd/ubuntu-advantage-script/builds/287672916 To run the tests manually on artful: - sudo apt install tox - tar xJf ubuntu-advantage-tools_12.tar.xz - cd ubuntu-advantage-tools-12 - sed -i 's/py35/py36/' tox.ini - tox - Here is a run: http://xxxxxxx + Here is a run: http://pastebin.ubuntu.com/25733673/ Builds ====== Daily PPA: https://launchpad.net/~ahasenack/+archive/ubuntu/ubuntu-advantage-tools-devel Source build on artful with proposed enabled: http://pastebin.ubuntu.com/25733640/ Binary build on artful with proposed enabled: http://pastebin.ubuntu.com/25733649/ Upgrading ========= http://pastebin.ubuntu.com/25733666/ shows the upgrade from 10 to 12 and that both names ("ubuntu-advantage" and the new "ua") can be used in v12. Misc ==== Note that ubuntu-advantage-tools is meant for LTS releases only, but we need it in all of them for upcoming SRU processes. ** Patch removed: "ubuntu-advantage-tools.debdiff" https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+attachment/4962875/+files/ubuntu-advantage-tools.debdiff ** Attachment removed: "ubuntu-advantage-tools_11.tar.xz" https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+attachment/4962874/+files/ubuntu-advantage-tools_11.tar.xz ** Attachment added: "ubuntu-advantage-tools_12.tar.xz" https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+attachment/4970289/+files/ubuntu-advantage-tools_12.tar.xz -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1721272 Title: [FFe] Create 'ua' symlink pointing at 'ubuntu-advantage' To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+subscriptions From andreas at canonical.com Fri Oct 13 18:46:07 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Fri, 13 Oct 2017 18:46:07 -0000 Subject: [Bug 1721272] Re: [FFe] Create 'ua' symlink pointing at 'ubuntu-advantage' References: <150712877071.13102.6148654257305099225.malonedeb@wampee.canonical.com> Message-ID: <150792036781.796.14403894790383922149.malone@chaenomeles.canonical.com> v10-v12 debdiff ** Patch added: "v10-v12.debdiff" https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+attachment/4970290/+files/v10-v12.debdiff -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1721272 Title: [FFe] Create 'ua' symlink pointing at 'ubuntu-advantage' To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+subscriptions From andreas at canonical.com Fri Oct 13 18:47:48 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Fri, 13 Oct 2017 18:47:48 -0000 Subject: [Bug 1721272] Re: [FFe] Create 'ua' symlink pointing at 'ubuntu-advantage' References: <150712877071.13102.6148654257305099225.malonedeb@wampee.canonical.com> Message-ID: <150792046831.8049.5379020997393436284.malone@wampee.canonical.com> Let's try an FFe again, maybe there is time. If not, we will SRU after. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1721272 Title: [FFe] Create 'ua' symlink pointing at 'ubuntu-advantage' To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1721272/+subscriptions From nish.aravamudan at canonical.com Fri Oct 13 19:41:08 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Fri, 13 Oct 2017 19:41:08 -0000 Subject: [Bug 1721607] Re: please update to latest upstream release 7.0.24 References: <150722582934.21676.5660673599872685581.malonedeb@gac.canonical.com> Message-ID: <150792366881.21899.18294263269355127608.malone@gac.canonical.com> Thank Tyler :) Steven, a) The patched version from Ondrej's repo is not an official, nor supported version, it's irrelevant to this discussion. b) If you can provide the CVEs that Tyler asked for, then a security update will occur. c) We do have an MRE for PHP7.0 (probably also for PHP7.1 by the same logic) and I plan on submitting an update to the latest PHP7.0 upstream in the next week or two. But that will only be present in -updates, not -security unless b) is addressed. Sorry for the delay on my end in replying to this bug. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to php7.0 in Ubuntu. https://bugs.launchpad.net/bugs/1721607 Title: please update to latest upstream release 7.0.24 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/php7.0/+bug/1721607/+subscriptions From andreas at canonical.com Fri Oct 13 20:02:04 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Fri, 13 Oct 2017 20:02:04 -0000 Subject: [Bug 1723391] Re: package samba 2:4.3.11+dfsg-0ubuntu0.16.04.11 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1 References: <150789155272.1249.15118852527734503898.malonedeb@chaenomeles.canonical.com> Message-ID: <150792492470.1654.16322012301457611196.malone@chaenomeles.canonical.com> Thanks for filing this bug in Ubuntu. The samba services failed to start, but the attached logs don't tell why. Could you please attach: - /var/log/samba/log*: files in /var/log/samba that start with "log" - /etc/samba/smb.conf: your configuration file. It might have an invalid option and that could be what is preventing samba from starting correctly. Thanks! ** Changed in: samba (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to samba in Ubuntu. https://bugs.launchpad.net/bugs/1723391 Title: package samba 2:4.3.11+dfsg-0ubuntu0.16.04.11 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1723391/+subscriptions From andreas at canonical.com Fri Oct 13 20:35:14 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Fri, 13 Oct 2017 20:35:14 -0000 Subject: [Bug 1722936] Re: sssd hbac rule applicaton for AD users is inconsistent References: <150775828838.15858.3324948959773563229.malonedeb@soybean.canonical.com> Message-ID: <150792691503.843.14345855153697144888.malone@chaenomeles.canonical.com> Thanks for filing this bug in Ubuntu. It looks like you are familiar with Ubuntu/Debian development. Do you think you would be able to make a merge proposal against this git branch for xenial? https://code.launchpad.net/~usd-import- team/ubuntu/+source/sssd/+git/sssd/+ref/ubuntu/xenial-devel If you are familiar with git and Ubuntu development, you can use our git workflow and the git-ubuntu helper tool. Something like this, on a fresh xenial VM to show the setup steps: $ sudo snap install git-ubuntu --classic $ mkdir -p git/packages $ cd git/packages $ git ubuntu clone sssd $ cd sssd $ git checkout -b xenial-sssd-hbac-rule-1722936 pkg/ubuntu/xenial-devel code away $ git ubuntu submit More information about this tool can be found in this blog post: https://naccblog.wordpress.com/2017/08/01/git-ubuntu-clone/ ** Changed in: sssd (Ubuntu) Status: New => Triaged ** Changed in: sssd (Ubuntu) Importance: Undecided => Low ** Tags added: bitesize -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to sssd in Ubuntu. https://bugs.launchpad.net/bugs/1722936 Title: sssd hbac rule applicaton for AD users is inconsistent To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/sssd/+bug/1722936/+subscriptions From andreas at canonical.com Fri Oct 13 21:37:23 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Fri, 13 Oct 2017 21:37:23 -0000 Subject: [Bug 1723350] Re: sssd offline on boot, stays offline forever (artful) References: <150788228031.15993.1646269907378018652.malonedeb@soybean.canonical.com> Message-ID: <150793064344.1614.3125399507271398027.malone@chaenomeles.canonical.com> I can confirm this is happening after a reboot, and that a simple USR2 signal fixes it, but I wonder why sssd doesn't get itself back into online mode on its own in this case. For example, I tried the following: - login via kerberos using pam_sss while it was online - got my ticket - kdestroy, logout - in another terminal, bring down the network on this client workstation - try go login again - login failed, and sssd log showed: (Fri Oct 13 21:23:15 2017) [sssd[pam]] [sss_dp_get_reply] (0x0010): The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Offline] I then brought the network back up, and after a while (a minute or less), login was working again using krb5. This shows sssd recovered from the induced "outage". The systemd unit file we are using in ubuntu comes straight from upstream. (some searching) Found these upstream tickets: https://pagure.io/SSSD/sssd/issue/3467 https://pagure.io/SSSD/sssd/issue/3294 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to sssd in Ubuntu. https://bugs.launchpad.net/bugs/1723350 Title: sssd offline on boot, stays offline forever (artful) To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/sssd/+bug/1723350/+subscriptions From andreas at canonical.com Fri Oct 13 21:45:39 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Fri, 13 Oct 2017 21:45:39 -0000 Subject: [Bug 1723350] Re: sssd offline on boot, stays offline forever (artful) References: <150788228031.15993.1646269907378018652.malonedeb@soybean.canonical.com> Message-ID: <150793114031.21602.18268046728470456199.launchpad@gac.canonical.com> ** Changed in: sssd (Ubuntu) Status: Confirmed => Triaged ** Changed in: sssd (Ubuntu) Importance: Undecided => Medium -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to sssd in Ubuntu. https://bugs.launchpad.net/bugs/1723350 Title: sssd offline on boot, stays offline forever (artful) To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/sssd/+bug/1723350/+subscriptions From nish.aravamudan at canonical.com Mon Oct 16 21:45:09 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Mon, 16 Oct 2017 21:45:09 -0000 Subject: [Bug 1720029] Re: Backport "Re-enable SSL support by default. Compatibility with older versions has been fixed." to zesty. References: <150655329889.30760.8085397682327061822.malonedeb@wampee.canonical.com> Message-ID: <150819030959.22673.14865044230958139923.malone@wampee.canonical.com> Hello and thank you again for the report. I am looking at the fix, and the NEWS and changelog files say: + The bug that caused the SSL support between NRPE 2.x and 3.x not + to work has been fixed. What bug? Where was it fixed? Will updating just nagios-nrpe break existing 17.04 installs? -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to nagios-nrpe in Ubuntu. https://bugs.launchpad.net/bugs/1720029 Title: Backport "Re-enable SSL support by default. Compatibility with older versions has been fixed." to zesty. To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nagios-nrpe/+bug/1720029/+subscriptions From corey.bryant at canonical.com Wed Oct 18 15:28:05 2017 From: corey.bryant at canonical.com (Corey Bryant) Date: Wed, 18 Oct 2017 15:28:05 -0000 Subject: [Bug 1719196] Re: [arm64 ocata] newly created instances are unable to raise network interfaces References: <150626680089.6094.17724106932405637799.malonedeb@soybean.canonical.com> Message-ID: <150834048548.17029.4509843003376585930.launchpad@gac.canonical.com> ** Also affects: cloud-archive Importance: Undecided Status: New ** Also affects: cloud-archive/pike Importance: Undecided Status: New ** Also affects: cloud-archive/ocata Importance: Undecided Status: New ** No longer affects: cloud-archive/pike ** Changed in: cloud-archive/ocata Status: New => Triaged ** Changed in: cloud-archive/ocata Importance: Undecided => High ** Changed in: cloud-archive Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libvirt in Ubuntu. https://bugs.launchpad.net/bugs/1719196 Title: [arm64 ocata] newly created instances are unable to raise network interfaces To manage notifications about this bug go to: https://bugs.launchpad.net/cloud-archive/+bug/1719196/+subscriptions From andreas at canonical.com Wed Oct 18 20:25:02 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Wed, 18 Oct 2017 20:25:02 -0000 Subject: [Bug 1719671] Re: [SRU][xenial] include recent version containing fips and livepatch References: <150644034167.6129.8221946942865677369.malonedeb@soybean.canonical.com> Message-ID: <150835830223.1285.11985805729876476006.malone@soybean.canonical.com> I'm updating the SRU template with livepatch bits, since livepatch is also included in this update. ** Summary changed: - [SRU][xenial] include recent version containing fips + [SRU][xenial] include recent version containing fips and livepatch ** Description changed: [IMPACT] - Most recent version of ubuntu-advantage-tool on github includes fips enablement. The fips enablement will allow customers to easily install and configure Canonical's FIPS certified modules on xenial + Most recent version of ubuntu-advantage-tool on github includes fips and livepatch enablement. The fips enablement will allow customers to easily install and configure Canonical's FIPS certified modules on xenial, whereas livepatch allows customers to patch the kernel without a reboot. + + This SRU will cover both new features. Note: FIPS certified modules are only available for xenial. On other releases the tool will not install and configure fips. when "ubuntu-advantage enable-fips " is issued from commandline,  - configure the private PPA where the FIPS modules are located  - install the FIPS modules from this PPA to the local machine from where the script is run  - configure the bootloader to enable fips Upon successful completion of these steps, the customer then gets a message stating to reboot the machine to complete the fips enablement process. Without the script, customers must perform the steps manually. [FIX] Add enable-fips to advantage script. See debdiff below. [TEST] A test package is available: and it was tested by me on S390, PPC64EL and AMD64 architectures. [REGRESSION POTENTIAL] The patch adds a new features to ubuntu-advantage-tool in Xenial to enable fips. Current functionality was not altered. [FIPS TESTCASES] - These testcases assume you have installed ubuntu-advantage-tools with the proposed changes. + These testcases assume you have installed ubuntu-advantage-tools with the proposed changes. XENIAL 1. Collect status before enabling fips - type on commandline, - ubuntu-advantage status + type on commandline, +     ubuntu-advantage status expect, - livepatch: disabled +     livepatch: disabled - esm: disabled (not available) +     esm: disabled (not available) - fips: disabled +     fips: disabled 2. Enable fips Note: This will require a token or credentials to fips Private PPA, in the form xxx:xxx - type on commandline, - sudo ubuntu-advantage enable-fips xxx:xxx + type on commandline, +     sudo ubuntu-advantage enable-fips xxx:xxx expect, - [sudo] password for ubuntu: - Running apt-get update... OK - Ubuntu FIPS PPA repository enabled. - Installing FIPS packages (this may take a while)... OK - Configuring FIPS... - Updating grub to enable fips... OK - Successfully configured FIPS. PLEASE REBOOT to complete FIPS enablement. +     [sudo] password for ubuntu: +     Running apt-get update... OK +     Ubuntu FIPS PPA repository enabled. +     Installing FIPS packages (this may take a while)... OK +     Configuring FIPS... +     Updating grub to enable fips... OK +     Successfully configured FIPS. PLEASE REBOOT to complete FIPS enablement. type on commandline, - sudo reboot +     sudo reboot 3. Log back into system after reboot type on commandline, - ubuntu-advantage status +     ubuntu-advantage status expect, - livepatch: disabled +     livepatch: disabled - esm: disabled (not available) +     esm: disabled (not available) - fips: enabled - +     fips: enabled 4. verify fips kernel "4.4.0-1002-fips" has been installed type on commandline, - uname -a +     uname -a expect, - Linux xenialguest 4.4.0-1002-fips #2-Ubuntu SMP Thu Apr 27 19:37:46 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux - +     Linux xenialguest 4.4.0-1002-fips #2-Ubuntu SMP Thu Apr 27 19:37:46 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux ZESTY (Note that FIPS is not supported on zesty.) 1. Collect status before enabling fips type on commandline, - ubuntu-advantage status +     ubuntu-advantage status expect, - livepatch: disabled (not available) +     livepatch: disabled (not available) - esm: disabled (not available) +     esm: disabled (not available) - fips: disabled (not available) +     fips: disabled (not available) 2. Ensure that fips cannot be enabled on Zesty. Note: This will require a token or credentials to fips Private PPA, in the form xxx:xxx type on commandline, - sudo ubuntu-advantage enable-fips xxx:xxx +     sudo ubuntu-advantage enable-fips xxx:xxx expect, - Sorry, but Canonical FIPS 140-2 Modules is not supported on zesty +     Sorry, but Canonical FIPS 140-2 Modules is not supported on zesty 3. Check that kernel is not fips kernel (4.4.0-1002-fips) type on commandline, - uname -a +     uname -a expect: - Linux ubuntu-zesty 4.10.0-19-generic #21-Ubuntu SMP Thu Apr 6 17:04:57 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux +     Linux ubuntu-zesty 4.10.0-19-generic #21-Ubuntu SMP Thu Apr 6 17:04:57 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux ** Description changed: [IMPACT] Most recent version of ubuntu-advantage-tool on github includes fips and livepatch enablement. The fips enablement will allow customers to easily install and configure Canonical's FIPS certified modules on xenial, whereas livepatch allows customers to patch the kernel without a reboot. This SRU will cover both new features. - Note: FIPS certified modules are only available for xenial. On other - releases the tool will not install and configure fips. + Note: FIPS certified modules and livepatch are only available for + xenial. On other releases the tool will not install and configure fips + or livepatch. when "ubuntu-advantage enable-fips " is issued from commandline,  - configure the private PPA where the FIPS modules are located  - install the FIPS modules from this PPA to the local machine from where the script is run  - configure the bootloader to enable fips Upon successful completion of these steps, the customer then gets a message stating to reboot the machine to complete the fips enablement process. Without the script, customers must perform the steps manually. [FIX] Add enable-fips to advantage script. See debdiff below. [TEST] A test package is available: and it was tested by me on S390, PPC64EL and AMD64 architectures. [REGRESSION POTENTIAL] The patch adds a new features to ubuntu-advantage-tool in Xenial to enable fips. Current functionality was not altered. [FIPS TESTCASES] These testcases assume you have installed ubuntu-advantage-tools with the proposed changes. XENIAL 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable fips Note: This will require a token or credentials to fips Private PPA, in the form xxx:xxx type on commandline,     sudo ubuntu-advantage enable-fips xxx:xxx expect,     [sudo] password for ubuntu:     Running apt-get update... OK     Ubuntu FIPS PPA repository enabled.     Installing FIPS packages (this may take a while)... OK     Configuring FIPS...     Updating grub to enable fips... OK     Successfully configured FIPS. PLEASE REBOOT to complete FIPS enablement. type on commandline,     sudo reboot 3. Log back into system after reboot type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: enabled 4. verify fips kernel "4.4.0-1002-fips" has been installed type on commandline,     uname -a expect,     Linux xenialguest 4.4.0-1002-fips #2-Ubuntu SMP Thu Apr 27 19:37:46 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux ZESTY (Note that FIPS is not supported on zesty.) 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled (not available)     esm: disabled (not available)     fips: disabled (not available) 2. Ensure that fips cannot be enabled on Zesty. Note: This will require a token or credentials to fips Private PPA, in the form xxx:xxx type on commandline,     sudo ubuntu-advantage enable-fips xxx:xxx expect,     Sorry, but Canonical FIPS 140-2 Modules is not supported on zesty 3. Check that kernel is not fips kernel (4.4.0-1002-fips) type on commandline,     uname -a expect:     Linux ubuntu-zesty 4.10.0-19-generic #21-Ubuntu SMP Thu Apr 6 17:04:57 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux ** Description changed: [IMPACT] Most recent version of ubuntu-advantage-tool on github includes fips and livepatch enablement. The fips enablement will allow customers to easily install and configure Canonical's FIPS certified modules on xenial, whereas livepatch allows customers to patch the kernel without a reboot. This SRU will cover both new features. Note: FIPS certified modules and livepatch are only available for xenial. On other releases the tool will not install and configure fips or livepatch. + [FIPS DESCRIPTION] when "ubuntu-advantage enable-fips " is issued from commandline,  - configure the private PPA where the FIPS modules are located  - install the FIPS modules from this PPA to the local machine from where the script is run  - configure the bootloader to enable fips Upon successful completion of these steps, the customer then gets a message stating to reboot the machine to complete the fips enablement process. Without the script, customers must perform the steps manually. + [LIVEPATCH DESCRIPTION] + TBW + [FIX] Add enable-fips to advantage script. See debdiff below. [TEST] A test package is available: and it was tested by me on S390, PPC64EL and AMD64 architectures. [REGRESSION POTENTIAL] - The patch adds a new features to ubuntu-advantage-tool in Xenial to enable fips. Current functionality was not altered. + The patch adds a new features to ubuntu-advantage-tool in Xenial to enable fips and livepatch. Current functionality was not altered. [FIPS TESTCASES] These testcases assume you have installed ubuntu-advantage-tools with the proposed changes. XENIAL 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable fips Note: This will require a token or credentials to fips Private PPA, in the form xxx:xxx type on commandline,     sudo ubuntu-advantage enable-fips xxx:xxx expect,     [sudo] password for ubuntu:     Running apt-get update... OK     Ubuntu FIPS PPA repository enabled.     Installing FIPS packages (this may take a while)... OK     Configuring FIPS...     Updating grub to enable fips... OK     Successfully configured FIPS. PLEASE REBOOT to complete FIPS enablement. type on commandline,     sudo reboot 3. Log back into system after reboot type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: enabled 4. verify fips kernel "4.4.0-1002-fips" has been installed type on commandline,     uname -a expect,     Linux xenialguest 4.4.0-1002-fips #2-Ubuntu SMP Thu Apr 27 19:37:46 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux ZESTY (Note that FIPS is not supported on zesty.) 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled (not available)     esm: disabled (not available)     fips: disabled (not available) 2. Ensure that fips cannot be enabled on Zesty. Note: This will require a token or credentials to fips Private PPA, in the form xxx:xxx type on commandline,     sudo ubuntu-advantage enable-fips xxx:xxx expect,     Sorry, but Canonical FIPS 140-2 Modules is not supported on zesty 3. Check that kernel is not fips kernel (4.4.0-1002-fips) type on commandline,     uname -a expect:     Linux ubuntu-zesty 4.10.0-19-generic #21-Ubuntu SMP Thu Apr 6 17:04:57 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719671 Title: [SRU][xenial] include recent version containing fips and livepatch To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+subscriptions From nish.aravamudan at canonical.com Wed Oct 18 22:14:00 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Wed, 18 Oct 2017 22:14:00 -0000 Subject: [Bug 1720126] Re: [ip link] Message truncated error for large number of passthrough VFs References: <150660088961.29180.1650947608023209442.malonedeb@gac.canonical.com> <150823057740.16957.14805499658503497087.malone@gac.canonical.com> Message-ID: <20171018221400.ijld4jrjopbo42yl@pitfall> On 17.10.2017 [08:56:17 -0000], Jan Gutter wrote: > @nacc I built from source to verify that the one-liner is directly > responsible for fixing and breaking the issue (inherent paranoia). I did > test with the binaries and they worked. Ah ok, yeah -- I guess that's reasonable, and is a good preemptive test, but given that it needs to be backported to a different release, feels a bit like busywork (the same time could have been spent building it for xenial :) > Apologies, I'm unfamiliar with the Ubuntu SRU process as you can > probably see. What exactly is an "MP" and how would one go about to > propose one? MP = Merge Proposal. Roughly like GitHub's Pull Requests (PR), except less formal with Git (bzr I think is somewhat more first-class in Launchpad). > I'm aware of the need of testing bugfixes like these, I'm not familiar > with your release pipeline, however. http://www.justgohome.co.uk/blog/2017/07/developing-ubuntu-using- git.html may help a bit. Roughly: $ sudo snap install --classic git-ubuntu $ git ubuntu clone iproute2 $ cd iproute2 $ ... make and commit changes $ git ubuntu submit Now, the issue is that middle bit, where you have to know a bit about source packaging. That is, simply cherry-picking the upstream/Debian fix is not quite right, as you need to change it into a Quilt patch and then insert a changelog entry. We are currently developing a fix for that so you can just do a $ git ubuntu remote add debian $ git cherry-pick 72b365e83 $ git ubuntu build-source And it should spit out a commit that has the quiltify'd and changelogify'd result that you can use as a base or to submit. Feel free to find me on IRC if you want some more pointers. In the meanwhile, I'll try and look at Monique's debdiffs this week. -Nish -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1720126 Title: [ip link] Message truncated error for large number of passthrough VFs To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/iproute2/+bug/1720126/+subscriptions From nish.aravamudan at canonical.com Wed Oct 18 22:58:52 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Wed, 18 Oct 2017 22:58:52 -0000 Subject: [Bug 1720126] Re: [ip link] Message truncated error for large number of passthrough VFs References: <150660088961.29180.1650947608023209442.malonedeb@gac.canonical.com> Message-ID: <150836753304.900.7942526741087663507.malone@soybean.canonical.com> @mvandenberg, Couple of nits in your debdiffs. 1) changelogs are targetting UNRELEASED, please update to xenial and trusty respectively. 2) Is there a reason your fix is different than the fix upstream/Debian? Does Debian need your version instead? 3) Please use appropriate DEP3 headers (dpkg-source --commit creates a template patch with them): http://dep.debian.net/deps/dep3/, especially Origin (not Origin/Author). 4) The actual author appears to be Phil Sutter, not Jan Gutter, although Jan authored the patch in this bug. Consider using dep3changelog once you have a quilt patch to generate the changelog in the standard format (with an attribution to Phil or Jan as you decide). 5) The trusty version number seems off, it should be 3.12.0-2ubuntu1.1. Please take a look at https://wiki.ubuntu.com/SecurityTeam/UpdatePreparation#Update_the_packaging. Can you fix these up and reupload the debdiffs? Thanks, Nish -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1720126 Title: [ip link] Message truncated error for large number of passthrough VFs To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/iproute2/+bug/1720126/+subscriptions From james.page at ubuntu.com Thu Oct 19 10:54:07 2017 From: james.page at ubuntu.com (James Page) Date: Thu, 19 Oct 2017 10:54:07 -0000 Subject: [Bug 968722] Re: /usr/sbin missing some wrappers for plugins/env References: <20120329233526.9664.55081.malonedeb@soybean.canonical.com> Message-ID: <150841044812.16814.837872078291159257.launchpad@gac.canonical.com> ** Changed in: rabbitmq-server (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to rabbitmq-server in Ubuntu. https://bugs.launchpad.net/bugs/968722 Title: /usr/sbin missing some wrappers for plugins/env To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/rabbitmq-server/+bug/968722/+subscriptions From james.page at ubuntu.com Thu Oct 19 10:57:37 2017 From: james.page at ubuntu.com (James Page) Date: Thu, 19 Oct 2017 10:57:37 -0000 Subject: [Bug 1710077] Re: please sync or merge 6.32-1 References: <150243422363.19681.18354654722420599170.malonedeb@chaenomeles.canonical.com> Message-ID: <150841065776.17635.10806014845798095042.launchpad@gac.canonical.com> ** Changed in: ipset (Ubuntu) Status: New => Triaged ** Changed in: ipset (Ubuntu) Importance: Undecided => Medium ** Changed in: ipset (Ubuntu) Milestone: None => ubuntu-18.04 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1710077 Title: please sync or merge 6.32-1 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ipset/+bug/1710077/+subscriptions From james.page at ubuntu.com Thu Oct 19 11:05:56 2017 From: james.page at ubuntu.com (James Page) Date: Thu, 19 Oct 2017 11:05:56 -0000 Subject: [Bug 1679386] Re: Missing dep8 tests References: <20170403222533.crwiqvquhm3gwzsh@x1> Message-ID: <150841115737.17635.4718293276131605401.launchpad@gac.canonical.com> ** Changed in: rabbitmq-server (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to rabbitmq-server in Ubuntu. https://bugs.launchpad.net/bugs/1679386 Title: Missing dep8 tests To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/rabbitmq-server/+bug/1679386/+subscriptions From nish.aravamudan at canonical.com Thu Oct 19 16:51:02 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Thu, 19 Oct 2017 16:51:02 -0000 Subject: [Bug 1724896] [NEW] [MRE] Please update to latest upstream release 7.0.24 Message-ID: <150843186244.22717.2377421836783947337.malonedeb@wampee.canonical.com> Public bug reported: There have been a number of microreleases of PHP 7.0 upstream since the last update to Xenial (which corresponded to the last update in Zesty). As it has been a few months, it feels appropriate to provide another MRE update to php7.0. A number of critical security and bug-fixes are present in each 7.0.x. Rather than backporting individual patches (e.g., Bug # 1569509), I believe it makes significantly more sense to follow the upstream 7.0.x. Upstream PHP is demonstrating an improved approach of bugfixes only in 7.0.x: - 7.0.24: http://php.net/ChangeLog-7.php The upstream CI is at: https://travis-ci.org/php/php-src and is run regularly. Our php7.0 source package has autopkgtests for the 4 SAPIs, mod-php, cgi, fpm and cli. We have also updated the packing to run the source tests during the build itself. I do not believe there is a firm statement from upstream on API/ABI stability, but the general approach seems to be a BC-break would result in 7.1.0 (which is present in Artful, and is why the Artful task is invalid). ** Affects: php7.0 (Ubuntu) Importance: Undecided Status: Invalid ** Affects: php7.0 (Ubuntu Trusty) Importance: Undecided Assignee: Nish Aravamudan (nacc) Status: In Progress ** Affects: php7.0 (Ubuntu Xenial) Importance: Undecided Assignee: Nish Aravamudan (nacc) Status: In Progress ** Also affects: php7.0 (Ubuntu Trusty) Importance: Undecided Status: New ** Also affects: php7.0 (Ubuntu Xenial) Importance: Undecided Status: New ** Changed in: php7.0 (Ubuntu) Status: New => Invalid ** Changed in: php7.0 (Ubuntu Trusty) Status: New => In Progress ** Changed in: php7.0 (Ubuntu Xenial) Status: New => In Progress ** Changed in: php7.0 (Ubuntu Trusty) Assignee: (unassigned) => Nish Aravamudan (nacc) ** Changed in: php7.0 (Ubuntu Xenial) Assignee: (unassigned) => Nish Aravamudan (nacc) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to php7.0 in Ubuntu. https://bugs.launchpad.net/bugs/1724896 Title: [MRE] Please update to latest upstream release 7.0.24 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/php7.0/+bug/1724896/+subscriptions From nish.aravamudan at canonical.com Thu Oct 19 17:06:24 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Thu, 19 Oct 2017 17:06:24 -0000 Subject: [Bug 1724902] [NEW] [MRE] Please update to latest upstream release 7.1.10 Message-ID: <150843278427.22876.454055092021011278.malonedeb@wampee.canonical.com> Public bug reported: There have been a number of microreleases of PHP 7.1 upstream since the last update to Artful. As it has been a few months, it feels appropriate to provide a MRE update to php7.1. A number of critical security and bug-fixes are present in each 7.1.x. Rather than backporting individual patches, I believe it makes significantly more sense to follow the upstream 7.1.x. Upstream PHP is demonstrating an improved approach of bugfixes only in 7.1.x:  - 7.1.10: http://php.net/ChangeLog-7.php The upstream CI is at: https://travis-ci.org/php/php-src and is run regularly. Our php7.0 source package has autopkgtests for the 4 SAPIs, mod-php, cgi, fpm and cli. We have also updated the packaging to run the source tests during the build itself. I do not believe there is a firm statement from upstream on API/ABI stability, but the general approach seems to be a BC-break would result in 7.2.0. ** Affects: php7.1 (Ubuntu) Importance: Undecided Assignee: Nish Aravamudan (nacc) Status: In Progress ** Affects: php7.1 (Ubuntu Artful) Importance: Undecided Assignee: Nish Aravamudan (nacc) Status: In Progress ** Affects: php7.1 (Ubuntu Bb-series) Importance: Undecided Assignee: Nish Aravamudan (nacc) Status: In Progress ** Also affects: php7.1 (Ubuntu Bb-series) Importance: Undecided Status: New ** Also affects: php7.1 (Ubuntu Artful) Importance: Undecided Status: New ** Description changed: There have been a number of microreleases of PHP 7.1 upstream since the last update to Artful. As it has been a few months, it feels appropriate to provide a MRE update to php7.1. A number of critical security and bug-fixes are present in each 7.1.x. Rather than backporting individual patches, I believe it makes significantly more sense to follow the upstream 7.1.x. Upstream PHP is demonstrating an improved approach of bugfixes only in 7.1.x: - - 7.1.10: http://php.net/ChangeLog-7.php +  - 7.1.10: http://php.net/ChangeLog-7.php The upstream CI is at: https://travis-ci.org/php/php-src and is run regularly. Our php7.0 source package has autopkgtests for the 4 SAPIs, mod-php, cgi, fpm and cli. We have also updated the packaging to run the source tests during the build itself. I do not believe there is a firm statement from upstream on API/ABI stability, but the general approach seems to be a BC-break would result - in 7.2.0 (which will probably be present in BB once released, which is - why there is no BB task). + in 7.2.0. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to php7.1 in Ubuntu. https://bugs.launchpad.net/bugs/1724902 Title: [MRE] Please update to latest upstream release 7.1.10 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/php7.1/+bug/1724902/+subscriptions From nish.aravamudan at canonical.com Thu Oct 19 17:13:27 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Thu, 19 Oct 2017 17:13:27 -0000 Subject: [Bug 1724902] Re: [MRE] Please update to latest upstream release 7.1.10 References: <150843278427.22876.454055092021011278.malonedeb@wampee.canonical.com> Message-ID: <150843320814.1709.7548513285894992481.launchpad@soybean.canonical.com> ** Changed in: php7.1 (Ubuntu Artful) Assignee: (unassigned) => Nish Aravamudan (nacc) ** Changed in: php7.1 (Ubuntu Bb-series) Assignee: (unassigned) => Nish Aravamudan (nacc) ** Changed in: php7.1 (Ubuntu Bb-series) Status: New => In Progress ** Changed in: php7.1 (Ubuntu Artful) Status: New => In Progress ** Changed in: php7.1 (Ubuntu Bb-series) Status: In Progress => Invalid -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to php7.1 in Ubuntu. https://bugs.launchpad.net/bugs/1724902 Title: [MRE] Please update to latest upstream release 7.1.10 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/php7.1/+bug/1724902/+subscriptions From corey.bryant at canonical.com Thu Oct 19 17:20:59 2017 From: corey.bryant at canonical.com (Corey Bryant) Date: Thu, 19 Oct 2017 17:20:59 -0000 Subject: [Bug 1720397] Re: qemu-kvm doesnt restart after node reboot References: <150669833185.21053.13738921475958605908.malonedeb@chaenomeles.canonical.com> Message-ID: <150843365972.13685.5076797702659784303.malone@chaenomeles.canonical.com> Hello Ernie, or anyone else affected, Accepted qemu into pike-proposed. The package will build now and be available in the Ubuntu Cloud Archive in a few hours, and then in the -proposed repository. Please help us by testing this new package. To enable the -proposed repository: sudo add-apt-repository cloud-archive:pike-proposed sudo apt-get update Your feedback will aid us getting this update out to other Ubuntu users. If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested, and change the tag from verification-pike-needed to verification-pike-done. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-pike-failed. In either case, details of your testing will help us make a better decision. Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance! ** Also affects: cloud-archive/ocata Importance: Undecided Status: New ** Also affects: cloud-archive/pike Importance: Undecided Status: New ** Changed in: cloud-archive/ocata Status: New => Triaged ** Changed in: cloud-archive/pike Status: New => Triaged ** Changed in: cloud-archive/ocata Importance: Undecided => High ** Changed in: cloud-archive/pike Importance: Undecided => High ** Changed in: cloud-archive/pike Status: Triaged => Fix Committed ** Tags added: verification-pike-needed -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to qemu in Ubuntu. https://bugs.launchpad.net/bugs/1720397 Title: qemu-kvm doesnt restart after node reboot To manage notifications about this bug go to: https://bugs.launchpad.net/cloud-archive/+bug/1720397/+subscriptions From corey.bryant at canonical.com Thu Oct 19 17:23:02 2017 From: corey.bryant at canonical.com (Corey Bryant) Date: Thu, 19 Oct 2017 17:23:02 -0000 Subject: [Bug 1720397] Please test proposed package References: <150669833185.21053.13738921475958605908.malonedeb@chaenomeles.canonical.com> Message-ID: <150843378217.1041.2999975209897735915.malone@soybean.canonical.com> Hello Ernie, or anyone else affected, Accepted qemu into ocata-proposed. The package will build now and be available in the Ubuntu Cloud Archive in a few hours, and then in the -proposed repository. Please help us by testing this new package. To enable the -proposed repository: sudo add-apt-repository cloud-archive:ocata-proposed sudo apt-get update Your feedback will aid us getting this update out to other Ubuntu users. If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested, and change the tag from verification-ocata-needed to verification-ocata-done. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-ocata-failed. In either case, details of your testing will help us make a better decision. Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance! ** Changed in: cloud-archive/ocata Status: Triaged => Fix Committed ** Tags added: verification-ocata-needed -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to qemu in Ubuntu. https://bugs.launchpad.net/bugs/1720397 Title: qemu-kvm doesnt restart after node reboot To manage notifications about this bug go to: https://bugs.launchpad.net/cloud-archive/+bug/1720397/+subscriptions From nish.aravamudan at canonical.com Thu Oct 19 17:35:18 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Thu, 19 Oct 2017 17:35:18 -0000 Subject: [Bug 1724902] Re: [MRE] Please update to latest upstream release 7.1.10 References: <150843278427.22876.454055092021011278.malonedeb@wampee.canonical.com> Message-ID: <150843451903.14228.7616001502721323084.malone@chaenomeles.canonical.com> I will probably SRU this ahead of BB opening, which will imply we'll need a copy-forward for BB. ** Changed in: php7.1 (Ubuntu Bb-series) Status: Invalid => In Progress -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to php7.1 in Ubuntu. https://bugs.launchpad.net/bugs/1724902 Title: [MRE] Please update to latest upstream release 7.1.10 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/php7.1/+bug/1724902/+subscriptions From corey.bryant at canonical.com Thu Oct 19 18:19:05 2017 From: corey.bryant at canonical.com (Corey Bryant) Date: Thu, 19 Oct 2017 18:19:05 -0000 Subject: [Bug 1718668] Re: Libvirt FTBFS in Artful on x86 References: <150599963491.29596.1144297357269709061.malonedeb@gac.canonical.com> Message-ID: <150843714547.858.10749880417899782427.malone@soybean.canonical.com> Hello ChristianEhrhardt, or anyone else affected, Accepted libvirt into pike-proposed. The package will build now and be available in the Ubuntu Cloud Archive in a few hours, and then in the -proposed repository. Please help us by testing this new package. To enable the -proposed repository: sudo add-apt-repository cloud-archive:pike-proposed sudo apt-get update Your feedback will aid us getting this update out to other Ubuntu users. If this package fixes the bug for you, please add a comment to this bug, mentioning the version of the package you tested, and change the tag from verification-pike-needed to verification-pike-done. If it does not fix the bug for you, please add a comment stating that, and change the tag to verification-pike-failed. In either case, details of your testing will help us make a better decision. Further information regarding the verification process can be found at https://wiki.ubuntu.com/QATeam/PerformingSRUVerification . Thank you in advance! ** Also affects: cloud-archive Importance: Undecided Status: New ** Also affects: cloud-archive/pike Importance: Undecided Status: New ** Changed in: cloud-archive/pike Status: New => Triaged ** Changed in: cloud-archive/pike Importance: Undecided => Critical ** Changed in: cloud-archive/pike Importance: Critical => High ** Changed in: cloud-archive/pike Importance: High => Medium ** Changed in: cloud-archive/pike Status: Triaged => Fix Committed ** Tags added: verification-pike-needed -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libvirt in Ubuntu. https://bugs.launchpad.net/bugs/1718668 Title: Libvirt FTBFS in Artful on x86 To manage notifications about this bug go to: https://bugs.launchpad.net/cloud-archive/+bug/1718668/+subscriptions From andreas at canonical.com Thu Oct 19 20:47:57 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Thu, 19 Oct 2017 20:47:57 -0000 Subject: [Bug 1719671] Re: [SRU][xenial] include recent version containing fips and livepatch References: <150644034167.6129.8221946942865677369.malonedeb@soybean.canonical.com> Message-ID: <150844607872.13874.10595591599463963522.launchpad@chaenomeles.canonical.com> ** Description changed: + ** description still being worked on, not done yet ** + + [IMPACT] - Most recent version of ubuntu-advantage-tool on github includes fips and livepatch enablement. The fips enablement will allow customers to easily install and configure Canonical's FIPS certified modules on xenial, whereas livepatch allows customers to patch the kernel without a reboot. + Most recent version of ubuntu-advantage-tool on github includes fips and livepatch enablement. The fips enablement will allow customers to easily install and configure Canonical's FIPS certified modules on xenial, whereas livepatch allows xenial and trusty customers to patch the running kernel without a reboot. This SRU will cover both new features. - Note: FIPS certified modules and livepatch are only available for - xenial. On other releases the tool will not install and configure fips - or livepatch. + In addition to the new features themselves, a new "status" command was + added that will give a short summary about the available modules and + their status, at a glance. + + Note: FIPS certified modules are only available for xenial. Livepatch is + supported on xenial and trusty. The tool will refuse to enable either + service on an unsupported ubuntu release. + + Without this updated package, customers of those services have to enable + them manually by following a series of steps. [FIPS DESCRIPTION] - when "ubuntu-advantage enable-fips " is issued from commandline, + When "ubuntu-advantage enable-fips " is issued from commandline,  - configure the private PPA where the FIPS modules are located  - install the FIPS modules from this PPA to the local machine from where the script is run  - configure the bootloader to enable fips Upon successful completion of these steps, the customer then gets a message stating to reboot the machine to complete the fips enablement process. Without the script, customers must perform the steps manually. [LIVEPATCH DESCRIPTION] - TBW + Livepatch allows customers to apply kernel patches to a running system without rebooting it. + + The current instructions live in http://ubuntu.com/livepatch and boil down to: + - install snapd if it's not installed already. On trusty this means a new kernel as well. + - install the canonical-livepatch snap + - obtain a livepatch token from Canonical + - run the enable command with the given token + + The ubuntu-advantage-tools package simplifies this process by just + requesting the token and performing all the other steps on behalf of the + user. It also conveniently checks the running kernel and instructs the + user to reboot into a newer kernel if needed to finish the installation + (this is the case when running trusty). [FIX] - Add enable-fips to advantage script. See debdiff below. - - [TEST] - A test package is available: and it was tested by me on S390, PPC64EL and AMD64 architectures. - - [REGRESSION POTENTIAL] - The patch adds a new features to ubuntu-advantage-tool in Xenial to enable fips and livepatch. Current functionality was not altered. + Add fips and livepatch support to the ubuntu-adadvantage-tools package. + See debdiff below. [FIPS TESTCASES] - These testcases assume you have installed ubuntu-advantage-tools with the proposed changes. + These testcases assume you have installed ubuntu-advantage-tools with the proposed changes. Prior to the upload they were performed on S390, PPC64EL and AMD64 architectures. XENIAL + 0. Install the new package to add fips support. 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable fips Note: This will require a token or credentials to fips Private PPA, in the form xxx:xxx type on commandline,     sudo ubuntu-advantage enable-fips xxx:xxx expect,     [sudo] password for ubuntu:     Running apt-get update... OK     Ubuntu FIPS PPA repository enabled.     Installing FIPS packages (this may take a while)... OK     Configuring FIPS...     Updating grub to enable fips... OK -     Successfully configured FIPS. PLEASE REBOOT to complete FIPS enablement. +     Successfully configured FIPS. Please reboot into the FIPS kernel to enable it. type on commandline,     sudo reboot 3. Log back into system after reboot type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: enabled 4. verify fips kernel "4.4.0-1002-fips" has been installed type on commandline,     uname -a expect,     Linux xenialguest 4.4.0-1002-fips #2-Ubuntu SMP Thu Apr 27 19:37:46 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux ZESTY (Note that FIPS is not supported on zesty.) 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled (not available)     esm: disabled (not available)     fips: disabled (not available) 2. Ensure that fips cannot be enabled on Zesty. - Note: This will require a token or credentials to fips Private PPA, in - the form xxx:xxx + You can use a dummy set of credentials like user:secret as the token: type on commandline, -     sudo ubuntu-advantage enable-fips xxx:xxx +     sudo ubuntu-advantage enable-fips user:secret expect,     Sorry, but Canonical FIPS 140-2 Modules is not supported on zesty 3. Check that kernel is not fips kernel (4.4.0-1002-fips) type on commandline,     uname -a expect:     Linux ubuntu-zesty 4.10.0-19-generic #21-Ubuntu SMP Thu Apr 6 17:04:57 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux + + + [REGRESSION POTENTIAL] + The current ubuntu-advantage-tools package in trusty, xenial and zesty is basically a NOOP because the only service it supports is ESM, which is only available for precise. + This update adds two new features to the package: FIPS (xenial only) and Livepatch (trusty and xenial), essentially making the package useful in trusty and xenial. For zesty there is no change, as none of these products are available for non-LTS releases. + + + [OTHER INFO] + The way this package was made available in all the ubuntu releases where it is now was via a "pocket copy". That's why it has the exact same version in trusty, xenial and zesty. Currently artful has version 10 (a version 12 just missed the feature freeze), so in order for upgrades between releases to work, we adopted the backports versioning scheme, by appending the ubuntu release code with a tilda ("~") to the version. + Another point is that even though ubuntu-advantage-tools is "just" a shell script, it is unit tested with python3, and these tests (and lint runs) gate merges in the upstream github repository at github.com/CanonicalLtd/ubuntu-advantage-script/ -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719671 Title: [SRU][xenial] include recent version containing fips and livepatch To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+subscriptions From nish.aravamudan at canonical.com Thu Oct 19 23:10:08 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Thu, 19 Oct 2017 23:10:08 -0000 Subject: [Bug 1720126] Re: [ip link] Message truncated error for large number of passthrough VFs References: <150660088961.29180.1650947608023209442.malonedeb@gac.canonical.com> <150840571982.16994.9637394054493855669.malone@gac.canonical.com> Message-ID: <20171019231008.qxw34evun5pq5f4h@pitfall> On 19.10.2017 [09:35:19 -0000], Jan Gutter wrote: > @nacc > > Thanks so much for the explanation. I also found > https://wiki.ubuntu.com/ServerTeam/KnowledgeBase#Merge_Proposals_and_Reviewing > that details a bit more of the internal processes. As relative outsiders > to the Ubuntu process, I'd appreciate it very much if you could handle > that part for Monique's patches. I can be on hand to answer technical > questions if required. And to be clear, the MP based workflow for the Git trees is brand new and experimental :) I'm happy to integrate the updated debdiffs (I'll reply to those comments directly). > Regarding the buffer size choice, it's very arbitrary as Phil said. I'm > pretty sure we came to the same conclusion independently (libvirt and > libnl had very similar issues) and the workaround is obvious. 32k seems > to work for 64 VF's (our test case), but breaks with 128 VF's. Not a lot > of machines can handle 128 concurrent VF's. I typed 64k "just because". > libvirt+libnl allow message peeking. However, iproute2 uses netlink > directly. So, implementing a similar idea would require an entirely new > receive codepath with all the fun of finding out where new exception > paths occur: something to be done on tip and not suitable for backport > without thorough vetting. Absolutely. My concern is the upstream code is at 32k as is Artful. I'm hesitant to backport something different (64k) to X and T without also ensuring Artful gets it (and BB when it opens), and presumably also fixing it upstream. So I see two routes forward: 1) File an upstream issue to request they bump to 64k, as you note 32k is insufficient for 128 VFs. Link to that issue in this bug and we'll fix AA, X and T with the suggested change (presuming upstream acks it). 2) Backport the upstream change as-is to X and T (AA already has the necessary fix). This will be faster, of course, but does mean the 128 VF case is broken. Given that it is less likely to be hit in the field, perhaps that is ok -- and in the meanwhile, upstream can work on a proper fix which, when available, we can backport accordingly (or decide at that point, in any case). I prefer 2), because I do not like diverging from upstream (or at least not without an upstream bug report). If you and Monique are ok with 2), I can update the debdiffs before sponsoring them. > I'm sure it'll save a lot of time once the kinks have been worked out of > the automation, backports are quite the double-edged sword. Definitely :) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1720126 Title: [ip link] Message truncated error for large number of passthrough VFs To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/iproute2/+bug/1720126/+subscriptions From nish.aravamudan at canonical.com Thu Oct 19 23:31:51 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Thu, 19 Oct 2017 23:31:51 -0000 Subject: [Bug 1724902] Re: [MRE] Please update to latest upstream release 7.1.10 References: <150843278427.22876.454055092021011278.malonedeb@wampee.canonical.com> Message-ID: <150845591228.14099.1801727030607935148.launchpad@chaenomeles.canonical.com> ** Description changed: There have been a number of microreleases of PHP 7.1 upstream since the last update to Artful. As it has been a few months, it feels appropriate to provide a MRE update to php7.1. A number of critical security and bug-fixes are present in each 7.1.x. Rather than backporting individual patches, I believe it makes significantly more sense to follow the upstream 7.1.x. Upstream PHP is demonstrating an improved approach of bugfixes only in 7.1.x:  - 7.1.10: http://php.net/ChangeLog-7.php The upstream CI is at: https://travis-ci.org/php/php-src and is run regularly. - Our php7.0 source package has autopkgtests for the 4 SAPIs, mod-php, + Our php7.1 source package has autopkgtests for the 4 SAPIs, mod-php, cgi, fpm and cli. We have also updated the packaging to run the source tests during the build itself. I do not believe there is a firm statement from upstream on API/ABI stability, but the general approach seems to be a BC-break would result in 7.2.0. + + We already had an MRE for php7.0 in X and Y, and this is the + corresponding source package in AA. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to php7.1 in Ubuntu. https://bugs.launchpad.net/bugs/1724902 Title: [MRE] Please update to latest upstream release 7.1.10 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/php7.1/+bug/1724902/+subscriptions From nish.aravamudan at canonical.com Thu Oct 19 23:59:24 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Thu, 19 Oct 2017 23:59:24 -0000 Subject: [Bug 1720126] Re: [ip link] Message truncated error for large number of passthrough VFs References: <150660088961.29180.1650947608023209442.malonedeb@gac.canonical.com> Message-ID: <150845756489.1041.5728850714558515674.malone@soybean.canonical.com> I have set up two MPs with the adjustments (it looks like Monique's latest debdiffs followed path 2) from my previous comment already) to the DEP3 headers that I think make the most sense. Please take a look at them and if you approve the changes I will upload them. I note also there are a number of statically sized buffers in the iproute2 code -- is there any concern about other buffers overflowing? -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1720126 Title: [ip link] Message truncated error for large number of passthrough VFs To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/iproute2/+bug/1720126/+subscriptions From james.page at ubuntu.com Fri Oct 20 11:33:52 2017 From: james.page at ubuntu.com (James Page) Date: Fri, 20 Oct 2017 11:33:52 -0000 Subject: [Bug 1659648] Re: Instance hung on first start, but works after being killed and restarted References: <20170126201457.8713.53457.malonedeb@gac.canonical.com> Message-ID: <150849923441.13542.7108398094784014692.launchpad@chaenomeles.canonical.com> ** Changed in: nova (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to qemu in Ubuntu. https://bugs.launchpad.net/bugs/1659648 Title: Instance hung on first start, but works after being killed and restarted To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/nova/+bug/1659648/+subscriptions From james.page at ubuntu.com Fri Oct 20 11:41:37 2017 From: james.page at ubuntu.com (James Page) Date: Fri, 20 Oct 2017 11:41:37 -0000 Subject: [Bug 1694159] Re: Complete libvirt migration to Debian style packaging (dependencies, conffiles) References: <149600204082.22694.9364201033396633719.malonedeb@wampee.canonical.com> Message-ID: <150849969874.16994.8539239625898203137.launchpad@gac.canonical.com> ** Changed in: nova (Ubuntu) Status: Confirmed => Triaged ** Changed in: nova (Ubuntu) Importance: High => Medium ** Changed in: nova (Ubuntu) Milestone: None => ubuntu-18.04 ** Changed in: nova (Ubuntu) Assignee: James Page (james-page) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1694159 Title: Complete libvirt migration to Debian style packaging (dependencies, conffiles) To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu-release-notes/+bug/1694159/+subscriptions From james.page at ubuntu.com Fri Oct 20 11:39:59 2017 From: james.page at ubuntu.com (James Page) Date: Fri, 20 Oct 2017 11:39:59 -0000 Subject: [Bug 1398999] Re: Block migrate with attached volumes copies volumes to themselves References: <20141203220446.31673.18630.malonedeb@chaenomeles.canonical.com> Message-ID: <150849960296.13320.7509625053781693631.launchpad@chaenomeles.canonical.com> ** Changed in: libvirt (Ubuntu Vivid) Status: Confirmed => Won't Fix ** Changed in: nova (Ubuntu Trusty) Importance: High => Medium -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libvirt in Ubuntu. https://bugs.launchpad.net/bugs/1398999 Title: Block migrate with attached volumes copies volumes to themselves To manage notifications about this bug go to: https://bugs.launchpad.net/nova/+bug/1398999/+subscriptions From nish.aravamudan at canonical.com Fri Oct 20 15:24:00 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Fri, 20 Oct 2017 15:24:00 -0000 Subject: [Bug 1720126] Re: [ip link] Message truncated error for large number of passthrough VFs References: <150660088961.29180.1650947608023209442.malonedeb@gac.canonical.com> <150848334033.22525.5830432248457768522.malone@wampee.canonical.com> Message-ID: <20171020152400.ysvviwtgzsgxn7ro@pitfall> On 20.10.2017 [07:09:00 -0000], Jan Gutter wrote: > I concur with option 2), unnecessary deviation will just cause > confusion. Thank you for confirming that! > Regarding the other buffer sizes, the last time I looked they were > mostly OK. The issue reared its head in this particular case because the > netlink message that previously had a pretty constant per-netdev > response size suddenly had the ability to balloon with "no warning". A > number of workarounds exist (i.e. you have to explicitly ask for the VF > info), but, in this case we actually want the VF info and iproute2 was > just unprepared for the size of it. Ok, that's good to hear. > I guess the core issue is that it's entirely possible for the kernel to > add extra netlink attributes to any query response, iproute2 makes the > assumption that the queries it's making is not necessarily going to > explode with gigabytes of new annotations and 16k will easily fit any > current real-world system. A pragmatic approach would probably be to > handle the "Message Truncated" path with a dynamically sized buffer as > an exceptional case. Yep, I can see how iproute2 itself has to move in lockstep with the kernel, which also means older iproute2 that can run on newer kernels needs periodic updates like this one. > Any fix in iproute2 that "properly" addresses this issue has to be > carefully vetted. Who knows how many inherent races will get exposed if > the ip command doubles in execution time. Yep :) I'm fine with eventually doubling the buffer again statically if that is the conclusion upstream reaches. My guess is that is the simplest solution. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1720126 Title: [ip link] Message truncated error for large number of passthrough VFs To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/iproute2/+bug/1720126/+subscriptions From nish.aravamudan at canonical.com Fri Oct 20 15:24:37 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Fri, 20 Oct 2017 15:24:37 -0000 Subject: [Bug 1720126] Re: [ip link] Message truncated error for large number of passthrough VFs References: <150660088961.29180.1650947608023209442.malonedeb@gac.canonical.com> <150848389555.1634.3980708111906706424.malone@soybean.canonical.com> Message-ID: <20171020152437.w2y6tlmivjrfhfgj@pitfall> On 20.10.2017 [07:18:15 -0000], Jan Gutter wrote: > I had a look at the two proposals and could not spot any obvious > mistakes: > > - the correct upstream git commit has been cherry-picked > - I don't have any objections to attribution or log messages > > Thanks again for shepherding this one through! You're welcome, I'll upload them both today. Thank you and Monique for filing the SRU template properly! -Nish -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1720126 Title: [ip link] Message truncated error for large number of passthrough VFs To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/iproute2/+bug/1720126/+subscriptions From nish.aravamudan at canonical.com Fri Oct 20 17:17:00 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Fri, 20 Oct 2017 17:17:00 -0000 Subject: [Bug 1720126] Re: [ip link] Message truncated error for large number of passthrough VFs References: <150660088961.29180.1650947608023209442.malonedeb@gac.canonical.com> <150848389555.1634.3980708111906706424.malone@soybean.canonical.com> <20171020152437.w2y6tlmivjrfhfgj@pitfall> Message-ID: <20171020171700.npd4mi5uwa7gyp3o@pitfall> On 20.10.2017 [08:24:37 -0700], Nish Aravamudan wrote: > On 20.10.2017 [07:18:15 -0000], Jan Gutter wrote: > > I had a look at the two proposals and could not spot any obvious > > mistakes: > > > > - the correct upstream git commit has been cherry-picked > > - I don't have any objections to attribution or log messages > > > > Thanks again for shepherding this one through! > > You're welcome, I'll upload them both today. > > Thank you and Monique for filing the SRU template properly! I have sponsored both packages. They will need to be approved by an SRU team member (probably next week) before they appear in {trusty,xenial}-proposed and then they will need testing as built in proposed, with a minimum bake time of 7 days in proposed. Thank you and Monique for your contribution to Ubuntu! -Nish -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1720126 Title: [ip link] Message truncated error for large number of passthrough VFs To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/iproute2/+bug/1720126/+subscriptions From andreas at canonical.com Fri Oct 20 18:45:15 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Fri, 20 Oct 2017 18:45:15 -0000 Subject: [Bug 1719671] Re: [SRU] include recent version containing fips and livepatch References: <150644034167.6129.8221946942865677369.malonedeb@soybean.canonical.com> Message-ID: <150852511651.18401.1407046712008788224.launchpad@chaenomeles.canonical.com> ** Summary changed: - [SRU][xenial] include recent version containing fips and livepatch + [SRU] include recent version containing fips and livepatch -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719671 Title: [SRU] include recent version containing fips and livepatch To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+subscriptions From andreas at canonical.com Fri Oct 20 19:52:27 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Fri, 20 Oct 2017 19:52:27 -0000 Subject: [Bug 1719671] Re: [SRU] include recent version containing fips and livepatch References: <150644034167.6129.8221946942865677369.malonedeb@soybean.canonical.com> Message-ID: <150852914828.17385.17110477570049986408.launchpad@gac.canonical.com> ** Description changed: ** description still being worked on, not done yet ** - [IMPACT] Most recent version of ubuntu-advantage-tool on github includes fips and livepatch enablement. The fips enablement will allow customers to easily install and configure Canonical's FIPS certified modules on xenial, whereas livepatch allows xenial and trusty customers to patch the running kernel without a reboot. This SRU will cover both new features. In addition to the new features themselves, a new "status" command was added that will give a short summary about the available modules and their status, at a glance. Note: FIPS certified modules are only available for xenial. Livepatch is supported on xenial and trusty. The tool will refuse to enable either service on an unsupported ubuntu release. Without this updated package, customers of those services have to enable them manually by following a series of steps. [FIPS DESCRIPTION] When "ubuntu-advantage enable-fips " is issued from commandline,  - configure the private PPA where the FIPS modules are located  - install the FIPS modules from this PPA to the local machine from where the script is run  - configure the bootloader to enable fips Upon successful completion of these steps, the customer then gets a message stating to reboot the machine to complete the fips enablement process. Without the script, customers must perform the steps manually. [LIVEPATCH DESCRIPTION] Livepatch allows customers to apply kernel patches to a running system without rebooting it. The current instructions live in http://ubuntu.com/livepatch and boil down to: - install snapd if it's not installed already. On trusty this means a new kernel as well. - install the canonical-livepatch snap - obtain a livepatch token from Canonical - run the enable command with the given token The ubuntu-advantage-tools package simplifies this process by just requesting the token and performing all the other steps on behalf of the user. It also conveniently checks the running kernel and instructs the user to reboot into a newer kernel if needed to finish the installation (this is the case when running trusty). [FIX] Add fips and livepatch support to the ubuntu-adadvantage-tools package. See debdiff below. + [LIVEPATCH TESTCASES] + + XENIAL + 0. Install the new ubuntu-advantage-tools package to add livepatch support. + + 1. Collect status before enabling livepatch + + type on commandline, +     ubuntu-advantage status + + expect, +     livepatch: disabled + +     esm: disabled (not available) + +     fips: disabled + + 2. Enable livepatch + + visit https://ubuntu.com/livepatch and obtain a token + + type on commandline, +     sudo ubuntu-advantage enable-livepatch + + expect, + Installing the canonical-livepatch snap. + This may take a few minutes depending on your bandwidth. + 2017-10-20T19:39:41Z INFO Waiting for restart... + canonical-livepatch 7.24 from 'canonical' installed + Enabling Livepatch with the given token, stand by... + Successfully enabled device. Using machine-token: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx + Use "canonical-livepatch status" to verify current patch status. + + 3. Verify livepatch status + + type on commandline, + ubuntu-advantage status + + expect an output like the following, + + livepatch: enabled + client-version: "7.23" + architecture: x86_64 + cpu-model: Intel Core Processor (Skylake) + last-check: 2017-10-20T19:39:54.451499227Z + boot-time: 2017-10-20T19:28:09Z + uptime: 15m30s + status: + - kernel: 4.4.0-97.120-generic + running: true + livepatch: + checkState: checked + patchState: nothing-to-apply + version: "" + fixes: "" + + esm: disabled (not available) + + fips: disabled + + [FIPS TESTCASES] These testcases assume you have installed ubuntu-advantage-tools with the proposed changes. Prior to the upload they were performed on S390, PPC64EL and AMD64 architectures. XENIAL - 0. Install the new package to add fips support. + 0. Install the new ubuntu-advantage-tools package to add fips support. 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable fips Note: This will require a token or credentials to fips Private PPA, in the form xxx:xxx type on commandline,     sudo ubuntu-advantage enable-fips xxx:xxx expect,     [sudo] password for ubuntu:     Running apt-get update... OK     Ubuntu FIPS PPA repository enabled.     Installing FIPS packages (this may take a while)... OK     Configuring FIPS...     Updating grub to enable fips... OK     Successfully configured FIPS. Please reboot into the FIPS kernel to enable it. type on commandline,     sudo reboot 3. Log back into system after reboot type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: enabled 4. verify fips kernel "4.4.0-1002-fips" has been installed type on commandline,     uname -a expect,     Linux xenialguest 4.4.0-1002-fips #2-Ubuntu SMP Thu Apr 27 19:37:46 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux ZESTY (Note that FIPS is not supported on zesty.) 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled (not available)     esm: disabled (not available)     fips: disabled (not available) 2. Ensure that fips cannot be enabled on Zesty. You can use a dummy set of credentials like user:secret as the token: type on commandline,     sudo ubuntu-advantage enable-fips user:secret expect,     Sorry, but Canonical FIPS 140-2 Modules is not supported on zesty - 3. Check that kernel is not fips kernel (4.4.0-1002-fips) - - type on commandline, -     uname -a - - expect: -     Linux ubuntu-zesty 4.10.0-19-generic #21-Ubuntu SMP Thu Apr 6 17:04:57 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux - [REGRESSION POTENTIAL] The current ubuntu-advantage-tools package in trusty, xenial and zesty is basically a NOOP because the only service it supports is ESM, which is only available for precise. This update adds two new features to the package: FIPS (xenial only) and Livepatch (trusty and xenial), essentially making the package useful in trusty and xenial. For zesty there is no change, as none of these products are available for non-LTS releases. - [OTHER INFO] The way this package was made available in all the ubuntu releases where it is now was via a "pocket copy". That's why it has the exact same version in trusty, xenial and zesty. Currently artful has version 10 (a version 12 just missed the feature freeze), so in order for upgrades between releases to work, we adopted the backports versioning scheme, by appending the ubuntu release code with a tilda ("~") to the version. Another point is that even though ubuntu-advantage-tools is "just" a shell script, it is unit tested with python3, and these tests (and lint runs) gate merges in the upstream github repository at github.com/CanonicalLtd/ubuntu-advantage-script/ -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719671 Title: [SRU] include recent version containing fips and livepatch To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+subscriptions From james.page at ubuntu.com Mon Oct 23 14:09:03 2017 From: james.page at ubuntu.com (James Page) Date: Mon, 23 Oct 2017 14:09:03 -0000 Subject: [Bug 1096002] Re: Multipath does not work with EMC 5300 Storage References: <20130104103959.20840.25344.malonedeb@chaenomeles.canonical.com> Message-ID: <150876774343.18471.8229890649803354024.malone@chaenomeles.canonical.com> Reassigning to the Linux package as that's where this driver resides (libiscsi is a pure userspace implementation of the iSCSI client protocol). ** Package changed: libiscsi (Ubuntu) => linux (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libiscsi in Ubuntu. https://bugs.launchpad.net/bugs/1096002 Title: Multipath does not work with EMC 5300 Storage To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1096002/+subscriptions From james.page at ubuntu.com Mon Oct 23 14:20:33 2017 From: james.page at ubuntu.com (James Page) Date: Mon, 23 Oct 2017 14:20:33 -0000 Subject: [Bug 1691109] Re: qemu-kvm not working as nested inside ESX 6.0 References: <149494197837.9319.2077559864368104737.malonedeb@wampee.canonical.com> Message-ID: <150876843331.17096.6494971266454703470.malone@gac.canonical.com> @paelzer No we don't - sorry. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to qemu in Ubuntu. https://bugs.launchpad.net/bugs/1691109 Title: qemu-kvm not working as nested inside ESX 6.0 To manage notifications about this bug go to: https://bugs.launchpad.net/cloud-archive/+bug/1691109/+subscriptions From andreas at canonical.com Mon Oct 23 17:54:19 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Mon, 23 Oct 2017 17:54:19 -0000 Subject: [Bug 1719671] Re: [SRU] include recent version containing fips and livepatch References: <150644034167.6129.8221946942865677369.malonedeb@soybean.canonical.com> Message-ID: <150878125999.17619.7530302679816658663.launchpad@chaenomeles.canonical.com> ** Description changed: ** description still being worked on, not done yet ** [IMPACT] Most recent version of ubuntu-advantage-tool on github includes fips and livepatch enablement. The fips enablement will allow customers to easily install and configure Canonical's FIPS certified modules on xenial, whereas livepatch allows xenial and trusty customers to patch the running kernel without a reboot. This SRU will cover both new features. In addition to the new features themselves, a new "status" command was added that will give a short summary about the available modules and their status, at a glance. Note: FIPS certified modules are only available for xenial. Livepatch is supported on xenial and trusty. The tool will refuse to enable either service on an unsupported ubuntu release. Without this updated package, customers of those services have to enable them manually by following a series of steps. [FIPS DESCRIPTION] When "ubuntu-advantage enable-fips " is issued from commandline,  - configure the private PPA where the FIPS modules are located  - install the FIPS modules from this PPA to the local machine from where the script is run  - configure the bootloader to enable fips Upon successful completion of these steps, the customer then gets a message stating to reboot the machine to complete the fips enablement process. Without the script, customers must perform the steps manually. [LIVEPATCH DESCRIPTION] Livepatch allows customers to apply kernel patches to a running system without rebooting it. The current instructions live in http://ubuntu.com/livepatch and boil down to: - install snapd if it's not installed already. On trusty this means a new kernel as well. - install the canonical-livepatch snap - obtain a livepatch token from Canonical - run the enable command with the given token The ubuntu-advantage-tools package simplifies this process by just requesting the token and performing all the other steps on behalf of the user. It also conveniently checks the running kernel and instructs the user to reboot into a newer kernel if needed to finish the installation (this is the case when running trusty). [FIX] Add fips and livepatch support to the ubuntu-adadvantage-tools package. See debdiff below. [LIVEPATCH TESTCASES] + ZESTY + 0. Install the new ubuntu-advantage-tools package to add livepatch support. + + 1. Collect status before enabling livepatch + + type on commandline: + ubuntu-advantage status + + expect the livepatch service to be unavailable: + livepatch: disabled (not available) + + esm: disabled (not available) + + fips: disabled (not available) + + 2. Ensure that livepatch cannot be enabled on Zesty. + You can use a dummy set of credentials like "foobar" as the token: + + type on commandline, +     sudo ubuntu-advantage enable-livepatch foobar + + expect, + Sorry, but Canonical Livepatch is not supported on zesty + + + TRUSTY + 0. Install the new ubuntu-advantage-tools package to add livepatch support. + + 1. Collect status before enabling livepatch + + type on commandline: + ubuntu-advantage status + + expect: + livepatch: disabled + + esm: disabled (not available) + + fips: disabled (not available) + + 2. Enable livepatch + + visit https://ubuntu.com/livepatch and obtain a token + + type on commandline, +     sudo ubuntu-advantage enable-livepatch + + You may be required to install a newer kernel. In that case, expect the + following output: + Installing missing dependency snapd... OK + Installing the canonical-livepatch snap. + This may take a few minutes depending on your bandwidth. + canonical-livepatch 7.24 from 'canonical' installed + + Your currently running kernel (3.13.0-133-generic) is too old to + support snaps. Version 4.4.0 or higher is needed. + + Please reboot your system into a supported kernel version + and run the following command one more time to complete the + installation: + + sudo ubuntu-advantage enable-livepatch + + Once you reboot and re-run the specified command, expect: + Enabling Livepatch with the given token, stand by... + Successfully enabled device. Using machine-token: + Use "canonical-livepatch status" to verify current patch status. + + + 3. Verify livepatch status + + type on commandline, +     ubuntu-advantage status + + expect an output like the following, + livepatch: enabled + client-version: "7.23" + architecture: x86_64 + cpu-model: Intel Core Processor (Skylake) + last-check: 2017-10-23T15:10:45.640938255Z + boot-time: 2017-10-23T15:10:13Z + uptime: 1m19s + status: + - kernel: 4.4.0-97.120~14.04.1-generic + running: true + livepatch: + checkState: checked + patchState: nothing-to-apply + version: "" + fixes: "" + + esm: disabled (not available) + + fips: disabled (not available) + + XENIAL 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable livepatch visit https://ubuntu.com/livepatch and obtain a token type on commandline,     sudo ubuntu-advantage enable-livepatch expect, - Installing the canonical-livepatch snap. - This may take a few minutes depending on your bandwidth. - 2017-10-20T19:39:41Z INFO Waiting for restart... - canonical-livepatch 7.24 from 'canonical' installed - Enabling Livepatch with the given token, stand by... - Successfully enabled device. Using machine-token: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx - Use "canonical-livepatch status" to verify current patch status. +     Installing the canonical-livepatch snap. +     This may take a few minutes depending on your bandwidth. +     2017-10-20T19:39:41Z INFO Waiting for restart... +     canonical-livepatch 7.24 from 'canonical' installed +     Enabling Livepatch with the given token, stand by... +     Successfully enabled device. Using machine-token: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx +     Use "canonical-livepatch status" to verify current patch status. 3. Verify livepatch status type on commandline, - ubuntu-advantage status +     ubuntu-advantage status expect an output like the following, - livepatch: enabled - client-version: "7.23" - architecture: x86_64 - cpu-model: Intel Core Processor (Skylake) - last-check: 2017-10-20T19:39:54.451499227Z - boot-time: 2017-10-20T19:28:09Z - uptime: 15m30s - status: - - kernel: 4.4.0-97.120-generic - running: true - livepatch: - checkState: checked - patchState: nothing-to-apply - version: "" - fixes: "" - - esm: disabled (not available) - - fips: disabled - +     livepatch: enabled +       client-version: "7.23" +       architecture: x86_64 +       cpu-model: Intel Core Processor (Skylake) +       last-check: 2017-10-20T19:39:54.451499227Z +       boot-time: 2017-10-20T19:28:09Z +       uptime: 15m30s +       status: +       - kernel: 4.4.0-97.120-generic +         running: true +         livepatch: +           checkState: checked +           patchState: nothing-to-apply +           version: "" +           fixes: "" + +     esm: disabled (not available) + +     fips: disabled [FIPS TESTCASES] These testcases assume you have installed ubuntu-advantage-tools with the proposed changes. Prior to the upload they were performed on S390, PPC64EL and AMD64 architectures. XENIAL 0. Install the new ubuntu-advantage-tools package to add fips support. 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable fips Note: This will require a token or credentials to fips Private PPA, in the form xxx:xxx type on commandline,     sudo ubuntu-advantage enable-fips xxx:xxx expect,     [sudo] password for ubuntu:     Running apt-get update... OK     Ubuntu FIPS PPA repository enabled.     Installing FIPS packages (this may take a while)... OK     Configuring FIPS...     Updating grub to enable fips... OK     Successfully configured FIPS. Please reboot into the FIPS kernel to enable it. type on commandline,     sudo reboot 3. Log back into system after reboot type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: enabled 4. verify fips kernel "4.4.0-1002-fips" has been installed type on commandline,     uname -a expect,     Linux xenialguest 4.4.0-1002-fips #2-Ubuntu SMP Thu Apr 27 19:37:46 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux ZESTY (Note that FIPS is not supported on zesty.) 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled (not available)     esm: disabled (not available)     fips: disabled (not available) 2. Ensure that fips cannot be enabled on Zesty. You can use a dummy set of credentials like user:secret as the token: type on commandline,     sudo ubuntu-advantage enable-fips user:secret expect,     Sorry, but Canonical FIPS 140-2 Modules is not supported on zesty + TRUSTY + (Note that FIPS is not supported on trusty.) + + 1. Collect status before enabling fips + + type on commandline, +     ubuntu-advantage status + + expect, + livepatch: disabled + + esm: disabled (not available) + + fips: disabled (not available) + + 2. Ensure that fips cannot be enabled on trusty. + You can use a dummy set of credentials like user:secret as the token: + + type on commandline, +     sudo ubuntu-advantage enable-fips user:secret + + expect, +     Sorry, but Canonical FIPS 140-2 Modules is not supported on trusty + [REGRESSION POTENTIAL] The current ubuntu-advantage-tools package in trusty, xenial and zesty is basically a NOOP because the only service it supports is ESM, which is only available for precise. This update adds two new features to the package: FIPS (xenial only) and Livepatch (trusty and xenial), essentially making the package useful in trusty and xenial. For zesty there is no change, as none of these products are available for non-LTS releases. [OTHER INFO] The way this package was made available in all the ubuntu releases where it is now was via a "pocket copy". That's why it has the exact same version in trusty, xenial and zesty. Currently artful has version 10 (a version 12 just missed the feature freeze), so in order for upgrades between releases to work, we adopted the backports versioning scheme, by appending the ubuntu release code with a tilda ("~") to the version. Another point is that even though ubuntu-advantage-tools is "just" a shell script, it is unit tested with python3, and these tests (and lint runs) gate merges in the upstream github repository at github.com/CanonicalLtd/ubuntu-advantage-script/ ** Description changed: ** description still being worked on, not done yet ** [IMPACT] Most recent version of ubuntu-advantage-tool on github includes fips and livepatch enablement. The fips enablement will allow customers to easily install and configure Canonical's FIPS certified modules on xenial, whereas livepatch allows xenial and trusty customers to patch the running kernel without a reboot. This SRU will cover both new features. In addition to the new features themselves, a new "status" command was added that will give a short summary about the available modules and their status, at a glance. Note: FIPS certified modules are only available for xenial. Livepatch is supported on xenial and trusty. The tool will refuse to enable either service on an unsupported ubuntu release. Without this updated package, customers of those services have to enable them manually by following a series of steps. [FIPS DESCRIPTION] When "ubuntu-advantage enable-fips " is issued from commandline,  - configure the private PPA where the FIPS modules are located  - install the FIPS modules from this PPA to the local machine from where the script is run  - configure the bootloader to enable fips Upon successful completion of these steps, the customer then gets a message stating to reboot the machine to complete the fips enablement process. Without the script, customers must perform the steps manually. [LIVEPATCH DESCRIPTION] Livepatch allows customers to apply kernel patches to a running system without rebooting it. The current instructions live in http://ubuntu.com/livepatch and boil down to: - install snapd if it's not installed already. On trusty this means a new kernel as well. - install the canonical-livepatch snap - obtain a livepatch token from Canonical - run the enable command with the given token The ubuntu-advantage-tools package simplifies this process by just requesting the token and performing all the other steps on behalf of the user. It also conveniently checks the running kernel and instructs the user to reboot into a newer kernel if needed to finish the installation (this is the case when running trusty). [FIX] Add fips and livepatch support to the ubuntu-adadvantage-tools package. See debdiff below. [LIVEPATCH TESTCASES] - - ZESTY - 0. Install the new ubuntu-advantage-tools package to add livepatch support. - - 1. Collect status before enabling livepatch - - type on commandline: - ubuntu-advantage status - - expect the livepatch service to be unavailable: - livepatch: disabled (not available) - - esm: disabled (not available) - - fips: disabled (not available) - - 2. Ensure that livepatch cannot be enabled on Zesty. - You can use a dummy set of credentials like "foobar" as the token: - - type on commandline, -     sudo ubuntu-advantage enable-livepatch foobar - - expect, - Sorry, but Canonical Livepatch is not supported on zesty - TRUSTY 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline: ubuntu-advantage status expect: livepatch: disabled esm: disabled (not available) fips: disabled (not available) 2. Enable livepatch visit https://ubuntu.com/livepatch and obtain a token type on commandline,     sudo ubuntu-advantage enable-livepatch You may be required to install a newer kernel. In that case, expect the following output: Installing missing dependency snapd... OK Installing the canonical-livepatch snap. This may take a few minutes depending on your bandwidth. canonical-livepatch 7.24 from 'canonical' installed Your currently running kernel (3.13.0-133-generic) is too old to support snaps. Version 4.4.0 or higher is needed. Please reboot your system into a supported kernel version and run the following command one more time to complete the installation: sudo ubuntu-advantage enable-livepatch Once you reboot and re-run the specified command, expect: Enabling Livepatch with the given token, stand by... Successfully enabled device. Using machine-token: Use "canonical-livepatch status" to verify current patch status. 3. Verify livepatch status type on commandline,     ubuntu-advantage status expect an output like the following, livepatch: enabled client-version: "7.23" architecture: x86_64 cpu-model: Intel Core Processor (Skylake) last-check: 2017-10-23T15:10:45.640938255Z boot-time: 2017-10-23T15:10:13Z uptime: 1m19s status: - kernel: 4.4.0-97.120~14.04.1-generic running: true livepatch: checkState: checked patchState: nothing-to-apply version: "" fixes: "" esm: disabled (not available) fips: disabled (not available) XENIAL 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable livepatch visit https://ubuntu.com/livepatch and obtain a token type on commandline,     sudo ubuntu-advantage enable-livepatch expect,     Installing the canonical-livepatch snap.     This may take a few minutes depending on your bandwidth.     2017-10-20T19:39:41Z INFO Waiting for restart...     canonical-livepatch 7.24 from 'canonical' installed     Enabling Livepatch with the given token, stand by...     Successfully enabled device. Using machine-token: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx     Use "canonical-livepatch status" to verify current patch status. 3. Verify livepatch status type on commandline,     ubuntu-advantage status expect an output like the following,     livepatch: enabled       client-version: "7.23"       architecture: x86_64       cpu-model: Intel Core Processor (Skylake)       last-check: 2017-10-20T19:39:54.451499227Z       boot-time: 2017-10-20T19:28:09Z       uptime: 15m30s       status:       - kernel: 4.4.0-97.120-generic         running: true         livepatch:           checkState: checked           patchState: nothing-to-apply           version: ""           fixes: ""     esm: disabled (not available)     fips: disabled + ZESTY + 0. Install the new ubuntu-advantage-tools package to add livepatch support. + + 1. Collect status before enabling livepatch + + type on commandline: + ubuntu-advantage status + + expect the livepatch service to be unavailable: + livepatch: disabled (not available) + + esm: disabled (not available) + + fips: disabled (not available) + + 2. Ensure that livepatch cannot be enabled on Zesty. + You can use a dummy set of credentials like "foobar" as the token: + + type on commandline, +     sudo ubuntu-advantage enable-livepatch foobar + + expect, + Sorry, but Canonical Livepatch is not supported on zesty + + [FIPS TESTCASES] These testcases assume you have installed ubuntu-advantage-tools with the proposed changes. Prior to the upload they were performed on S390, PPC64EL and AMD64 architectures. + + TRUSTY + (Note that FIPS is not supported on trusty.) + + 1. Collect status before enabling fips + + type on commandline, +     ubuntu-advantage status + + expect, + livepatch: disabled + + esm: disabled (not available) + + fips: disabled (not available) + + 2. Ensure that fips cannot be enabled on trusty. + You can use a dummy set of credentials like user:secret as the token: + + type on commandline, +     sudo ubuntu-advantage enable-fips user:secret + + expect, +     Sorry, but Canonical FIPS 140-2 Modules is not supported on trusty + + XENIAL 0. Install the new ubuntu-advantage-tools package to add fips support. 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable fips Note: This will require a token or credentials to fips Private PPA, in the form xxx:xxx type on commandline,     sudo ubuntu-advantage enable-fips xxx:xxx expect,     [sudo] password for ubuntu:     Running apt-get update... OK     Ubuntu FIPS PPA repository enabled.     Installing FIPS packages (this may take a while)... OK     Configuring FIPS...     Updating grub to enable fips... OK     Successfully configured FIPS. Please reboot into the FIPS kernel to enable it. type on commandline,     sudo reboot 3. Log back into system after reboot type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: enabled 4. verify fips kernel "4.4.0-1002-fips" has been installed type on commandline,     uname -a expect,     Linux xenialguest 4.4.0-1002-fips #2-Ubuntu SMP Thu Apr 27 19:37:46 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux ZESTY (Note that FIPS is not supported on zesty.) 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled (not available)     esm: disabled (not available)     fips: disabled (not available) 2. Ensure that fips cannot be enabled on Zesty. You can use a dummy set of credentials like user:secret as the token: type on commandline,     sudo ubuntu-advantage enable-fips user:secret expect,     Sorry, but Canonical FIPS 140-2 Modules is not supported on zesty - TRUSTY - (Note that FIPS is not supported on trusty.) - - 1. Collect status before enabling fips - - type on commandline, -     ubuntu-advantage status - - expect, - livepatch: disabled - - esm: disabled (not available) - - fips: disabled (not available) - - 2. Ensure that fips cannot be enabled on trusty. - You can use a dummy set of credentials like user:secret as the token: - - type on commandline, -     sudo ubuntu-advantage enable-fips user:secret - - expect, -     Sorry, but Canonical FIPS 140-2 Modules is not supported on trusty - - [REGRESSION POTENTIAL] The current ubuntu-advantage-tools package in trusty, xenial and zesty is basically a NOOP because the only service it supports is ESM, which is only available for precise. This update adds two new features to the package: FIPS (xenial only) and Livepatch (trusty and xenial), essentially making the package useful in trusty and xenial. For zesty there is no change, as none of these products are available for non-LTS releases. [OTHER INFO] The way this package was made available in all the ubuntu releases where it is now was via a "pocket copy". That's why it has the exact same version in trusty, xenial and zesty. Currently artful has version 10 (a version 12 just missed the feature freeze), so in order for upgrades between releases to work, we adopted the backports versioning scheme, by appending the ubuntu release code with a tilda ("~") to the version. Another point is that even though ubuntu-advantage-tools is "just" a shell script, it is unit tested with python3, and these tests (and lint runs) gate merges in the upstream github repository at github.com/CanonicalLtd/ubuntu-advantage-script/ -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719671 Title: [SRU] include recent version containing fips and livepatch To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+subscriptions From andreas at canonical.com Mon Oct 23 18:30:41 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Mon, 23 Oct 2017 18:30:41 -0000 Subject: [Bug 1719671] Re: [SRU] include recent version containing fips and livepatch References: <150644034167.6129.8221946942865677369.malonedeb@soybean.canonical.com> Message-ID: <150878344173.17030.6836305628962673085.launchpad@gac.canonical.com> ** Changed in: ubuntu-advantage-tools (Ubuntu Trusty) Status: New => In Progress ** Changed in: ubuntu-advantage-tools (Ubuntu Xenial) Status: New => In Progress ** Changed in: ubuntu-advantage-tools (Ubuntu Zesty) Status: New => In Progress ** Changed in: ubuntu-advantage-tools (Ubuntu Trusty) Assignee: (unassigned) => Andreas Hasenack (ahasenack) ** Changed in: ubuntu-advantage-tools (Ubuntu Xenial) Assignee: (unassigned) => Andreas Hasenack (ahasenack) ** Changed in: ubuntu-advantage-tools (Ubuntu Zesty) Assignee: (unassigned) => Andreas Hasenack (ahasenack) -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719671 Title: [SRU] include recent version containing fips and livepatch To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+subscriptions From andreas at canonical.com Mon Oct 23 18:41:08 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Mon, 23 Oct 2017 18:41:08 -0000 Subject: [Bug 1719671] Re: [SRU] include recent version containing fips and livepatch References: <150644034167.6129.8221946942865677369.malonedeb@soybean.canonical.com> Message-ID: <150878406934.27794.5856372163331621725.launchpad@soybean.canonical.com> ** Description changed: ** description still being worked on, not done yet ** + + This bug has some history that may be confusing if the comments are read + linearly. Basically it started out as a Feature Freeze Exception, that's + why we have build logs and unit test runs attached. + + Also, the "rename" that is mentioned elsewhere did not happen with this + package: the ubuntu-advantage name was kept, no new aliases were added. + This will happen in a later SRU, with a later version of the package. + + + For the SRU, what we need is: + * new tarball + * new debdiff, but note that binary file changes won't be shown in the debdiff [IMPACT] Most recent version of ubuntu-advantage-tool on github includes fips and livepatch enablement. The fips enablement will allow customers to easily install and configure Canonical's FIPS certified modules on xenial, whereas livepatch allows xenial and trusty customers to patch the running kernel without a reboot. This SRU will cover both new features. In addition to the new features themselves, a new "status" command was added that will give a short summary about the available modules and their status, at a glance. Note: FIPS certified modules are only available for xenial. Livepatch is supported on xenial and trusty. The tool will refuse to enable either service on an unsupported ubuntu release. Without this updated package, customers of those services have to enable them manually by following a series of steps. [FIPS DESCRIPTION] When "ubuntu-advantage enable-fips " is issued from commandline,  - configure the private PPA where the FIPS modules are located  - install the FIPS modules from this PPA to the local machine from where the script is run  - configure the bootloader to enable fips Upon successful completion of these steps, the customer then gets a message stating to reboot the machine to complete the fips enablement process. Without the script, customers must perform the steps manually. [LIVEPATCH DESCRIPTION] Livepatch allows customers to apply kernel patches to a running system without rebooting it. The current instructions live in http://ubuntu.com/livepatch and boil down to: - install snapd if it's not installed already. On trusty this means a new kernel as well. - install the canonical-livepatch snap - obtain a livepatch token from Canonical - run the enable command with the given token The ubuntu-advantage-tools package simplifies this process by just requesting the token and performing all the other steps on behalf of the user. It also conveniently checks the running kernel and instructs the user to reboot into a newer kernel if needed to finish the installation (this is the case when running trusty). [FIX] Add fips and livepatch support to the ubuntu-adadvantage-tools package. See debdiff below. [LIVEPATCH TESTCASES] TRUSTY 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline: - ubuntu-advantage status +     ubuntu-advantage status expect: livepatch: disabled esm: disabled (not available) fips: disabled (not available) 2. Enable livepatch visit https://ubuntu.com/livepatch and obtain a token type on commandline,     sudo ubuntu-advantage enable-livepatch You may be required to install a newer kernel. In that case, expect the following output: - Installing missing dependency snapd... OK - Installing the canonical-livepatch snap. - This may take a few minutes depending on your bandwidth. - canonical-livepatch 7.24 from 'canonical' installed - - Your currently running kernel (3.13.0-133-generic) is too old to - support snaps. Version 4.4.0 or higher is needed. - - Please reboot your system into a supported kernel version - and run the following command one more time to complete the - installation: - - sudo ubuntu-advantage enable-livepatch +  Installing missing dependency snapd... OK +  Installing the canonical-livepatch snap. +  This may take a few minutes depending on your bandwidth. +  canonical-livepatch 7.24 from 'canonical' installed + +  Your currently running kernel (3.13.0-133-generic) is too old to +  support snaps. Version 4.4.0 or higher is needed. + +  Please reboot your system into a supported kernel version +  and run the following command one more time to complete the +  installation: + +  sudo ubuntu-advantage enable-livepatch Once you reboot and re-run the specified command, expect: - Enabling Livepatch with the given token, stand by... - Successfully enabled device. Using machine-token: - Use "canonical-livepatch status" to verify current patch status. - +  Enabling Livepatch with the given token, stand by... +  Successfully enabled device. Using machine-token: +  Use "canonical-livepatch status" to verify current patch status. 3. Verify livepatch status type on commandline,     ubuntu-advantage status expect an output like the following, - livepatch: enabled - client-version: "7.23" - architecture: x86_64 - cpu-model: Intel Core Processor (Skylake) - last-check: 2017-10-23T15:10:45.640938255Z - boot-time: 2017-10-23T15:10:13Z - uptime: 1m19s - status: - - kernel: 4.4.0-97.120~14.04.1-generic - running: true - livepatch: - checkState: checked - patchState: nothing-to-apply - version: "" - fixes: "" - - esm: disabled (not available) - - fips: disabled (not available) - +  livepatch: enabled +    client-version: "7.23" +    architecture: x86_64 +    cpu-model: Intel Core Processor (Skylake) +    last-check: 2017-10-23T15:10:45.640938255Z +    boot-time: 2017-10-23T15:10:13Z +    uptime: 1m19s +    status: +    - kernel: 4.4.0-97.120~14.04.1-generic +      running: true +      livepatch: +        checkState: checked +        patchState: nothing-to-apply +        version: "" +        fixes: "" + +  esm: disabled (not available) + +  fips: disabled (not available) XENIAL 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable livepatch visit https://ubuntu.com/livepatch and obtain a token type on commandline,     sudo ubuntu-advantage enable-livepatch expect,     Installing the canonical-livepatch snap.     This may take a few minutes depending on your bandwidth.     2017-10-20T19:39:41Z INFO Waiting for restart...     canonical-livepatch 7.24 from 'canonical' installed     Enabling Livepatch with the given token, stand by...     Successfully enabled device. Using machine-token: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx     Use "canonical-livepatch status" to verify current patch status. 3. Verify livepatch status type on commandline,     ubuntu-advantage status expect an output like the following,     livepatch: enabled       client-version: "7.23"       architecture: x86_64       cpu-model: Intel Core Processor (Skylake)       last-check: 2017-10-20T19:39:54.451499227Z       boot-time: 2017-10-20T19:28:09Z       uptime: 15m30s       status:       - kernel: 4.4.0-97.120-generic         running: true         livepatch:           checkState: checked           patchState: nothing-to-apply           version: ""           fixes: ""     esm: disabled (not available)     fips: disabled ZESTY 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline: - ubuntu-advantage status +     ubuntu-advantage status expect the livepatch service to be unavailable: livepatch: disabled (not available) esm: disabled (not available) fips: disabled (not available) 2. Ensure that livepatch cannot be enabled on Zesty. You can use a dummy set of credentials like "foobar" as the token: type on commandline,     sudo ubuntu-advantage enable-livepatch foobar expect, - Sorry, but Canonical Livepatch is not supported on zesty - +     Sorry, but Canonical Livepatch is not supported on zesty [FIPS TESTCASES] These testcases assume you have installed ubuntu-advantage-tools with the proposed changes. Prior to the upload they were performed on S390, PPC64EL and AMD64 architectures. TRUSTY (Note that FIPS is not supported on trusty.) 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect, - livepatch: disabled - - esm: disabled (not available) - - fips: disabled (not available) +  livepatch: disabled + +  esm: disabled (not available) + +  fips: disabled (not available) 2. Ensure that fips cannot be enabled on trusty. You can use a dummy set of credentials like user:secret as the token: type on commandline,     sudo ubuntu-advantage enable-fips user:secret expect,     Sorry, but Canonical FIPS 140-2 Modules is not supported on trusty - - XENIAL 0. Install the new ubuntu-advantage-tools package to add fips support. 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable fips Note: This will require a token or credentials to fips Private PPA, in the form xxx:xxx type on commandline,     sudo ubuntu-advantage enable-fips xxx:xxx expect,     [sudo] password for ubuntu:     Running apt-get update... OK     Ubuntu FIPS PPA repository enabled.     Installing FIPS packages (this may take a while)... OK     Configuring FIPS...     Updating grub to enable fips... OK     Successfully configured FIPS. Please reboot into the FIPS kernel to enable it. type on commandline,     sudo reboot 3. Log back into system after reboot type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: enabled 4. verify fips kernel "4.4.0-1002-fips" has been installed type on commandline,     uname -a expect,     Linux xenialguest 4.4.0-1002-fips #2-Ubuntu SMP Thu Apr 27 19:37:46 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux ZESTY (Note that FIPS is not supported on zesty.) 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled (not available)     esm: disabled (not available)     fips: disabled (not available) 2. Ensure that fips cannot be enabled on Zesty. You can use a dummy set of credentials like user:secret as the token: type on commandline,     sudo ubuntu-advantage enable-fips user:secret expect,     Sorry, but Canonical FIPS 140-2 Modules is not supported on zesty [REGRESSION POTENTIAL] The current ubuntu-advantage-tools package in trusty, xenial and zesty is basically a NOOP because the only service it supports is ESM, which is only available for precise. This update adds two new features to the package: FIPS (xenial only) and Livepatch (trusty and xenial), essentially making the package useful in trusty and xenial. For zesty there is no change, as none of these products are available for non-LTS releases. [OTHER INFO] The way this package was made available in all the ubuntu releases where it is now was via a "pocket copy". That's why it has the exact same version in trusty, xenial and zesty. Currently artful has version 10 (a version 12 just missed the feature freeze), so in order for upgrades between releases to work, we adopted the backports versioning scheme, by appending the ubuntu release code with a tilda ("~") to the version. Another point is that even though ubuntu-advantage-tools is "just" a shell script, it is unit tested with python3, and these tests (and lint runs) gate merges in the upstream github repository at github.com/CanonicalLtd/ubuntu-advantage-script/ -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719671 Title: [SRU] include recent version containing fips and livepatch To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+subscriptions From andreas at canonical.com Mon Oct 23 19:27:50 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Mon, 23 Oct 2017 19:27:50 -0000 Subject: [Bug 1719671] Re: [SRU] include recent version containing fips and livepatch References: <150644034167.6129.8221946942865677369.malonedeb@soybean.canonical.com> Message-ID: <150878687087.17869.17993823194644738003.malone@wampee.canonical.com> trusty tarball ** Attachment removed: "ubuntu-advantage-tools_10~ubuntu0.16.04.1.tar.xz" https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+attachment/4973827/+files/ubuntu-advantage-tools_10~ubuntu0.16.04.1.tar.xz ** Attachment removed: "ubuntu-advantage-tools_10~ubuntu0.17.04.1.tar.xz" https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+attachment/4973837/+files/ubuntu-advantage-tools_10~ubuntu0.17.04.1.tar.xz ** Attachment added: "ubuntu-advantage-tools_10~ubuntu0.14.04.1.tar.xz" https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+attachment/4989104/+files/ubuntu-advantage-tools_10~ubuntu0.14.04.1.tar.xz -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719671 Title: [SRU] include recent version containing fips and livepatch To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+subscriptions From andreas at canonical.com Mon Oct 23 19:28:09 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Mon, 23 Oct 2017 19:28:09 -0000 Subject: [Bug 1719671] Re: [SRU] include recent version containing fips and livepatch References: <150644034167.6129.8221946942865677369.malonedeb@soybean.canonical.com> Message-ID: <150878689003.18102.11538575119999768564.malone@chaenomeles.canonical.com> xenial tarball ** Attachment added: "ubuntu-advantage-tools_10~ubuntu0.16.04.1.tar.xz" https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+attachment/4989105/+files/ubuntu-advantage-tools_10~ubuntu0.16.04.1.tar.xz -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719671 Title: [SRU] include recent version containing fips and livepatch To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+subscriptions From andreas at canonical.com Mon Oct 23 19:28:30 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Mon, 23 Oct 2017 19:28:30 -0000 Subject: [Bug 1719671] Re: [SRU] include recent version containing fips and livepatch References: <150644034167.6129.8221946942865677369.malonedeb@soybean.canonical.com> Message-ID: <150878691076.17385.2525627164988403168.malone@gac.canonical.com> zesty tarball ** Attachment added: "ubuntu-advantage-tools_10~ubuntu0.17.04.1.tar.xz" https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+attachment/4989106/+files/ubuntu-advantage-tools_10~ubuntu0.17.04.1.tar.xz ** Patch removed: "v2v10-zesty.debdiff" https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+attachment/4973833/+files/v2v10-zesty.debdiff ** Patch removed: "v2v10.xenial.debdiff" https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+attachment/4973809/+files/v2v10-xenial.debdiff -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719671 Title: [SRU] include recent version containing fips and livepatch To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+subscriptions From andreas at canonical.com Mon Oct 23 19:31:22 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Mon, 23 Oct 2017 19:31:22 -0000 Subject: [Bug 1719671] Re: [SRU] include recent version containing fips and livepatch References: <150644034167.6129.8221946942865677369.malonedeb@soybean.canonical.com> Message-ID: <150878708296.17603.7790503927168449727.malone@gac.canonical.com> trusty debdiff ** Patch added: "trusty-v2v10.debdiff" https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+attachment/4989120/+files/trusty-v2v10.debdiff -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719671 Title: [SRU] include recent version containing fips and livepatch To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+subscriptions From andreas at canonical.com Mon Oct 23 19:31:45 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Mon, 23 Oct 2017 19:31:45 -0000 Subject: [Bug 1719671] Re: [SRU] include recent version containing fips and livepatch References: <150644034167.6129.8221946942865677369.malonedeb@soybean.canonical.com> Message-ID: <150878710597.17686.9059460200540426938.malone@wampee.canonical.com> xenial debdiff ** Patch added: "xenial-v2v10.debdiff" https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+attachment/4989121/+files/xenial-v2v10.debdiff -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719671 Title: [SRU] include recent version containing fips and livepatch To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+subscriptions From andreas at canonical.com Mon Oct 23 19:32:17 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Mon, 23 Oct 2017 19:32:17 -0000 Subject: [Bug 1719671] Re: [SRU] include recent version containing fips and livepatch References: <150644034167.6129.8221946942865677369.malonedeb@soybean.canonical.com> Message-ID: <150878713744.27683.15781695845429488248.malone@soybean.canonical.com> zesty debdiff ** Patch added: "zesty-v2v10.debdiff" https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+attachment/4989122/+files/zesty-v2v10.debdiff ** Description changed: ** description still being worked on, not done yet ** This bug has some history that may be confusing if the comments are read linearly. Basically it started out as a Feature Freeze Exception, that's why we have build logs and unit test runs attached. Also, the "rename" that is mentioned elsewhere did not happen with this package: the ubuntu-advantage name was kept, no new aliases were added. This will happen in a later SRU, with a later version of the package. - - For the SRU, what we need is: - * new tarball - * new debdiff, but note that binary file changes won't be shown in the debdiff + I uploaded new tarballs and debdiff with these changes from what was here before, just in case you the reader have looked at this before: + * tarball with correct directory entry. The previous one had "v10" instead of "10" as the base version + * updated most recent changelog entry, just saying this is a backport of version 10. No need to say it has fips support, which neglected to mention the livepatch support. All that is in the previous d/changelog entries + [IMPACT] Most recent version of ubuntu-advantage-tool on github includes fips and livepatch enablement. The fips enablement will allow customers to easily install and configure Canonical's FIPS certified modules on xenial, whereas livepatch allows xenial and trusty customers to patch the running kernel without a reboot. This SRU will cover both new features. In addition to the new features themselves, a new "status" command was added that will give a short summary about the available modules and their status, at a glance. Note: FIPS certified modules are only available for xenial. Livepatch is supported on xenial and trusty. The tool will refuse to enable either service on an unsupported ubuntu release. Without this updated package, customers of those services have to enable them manually by following a series of steps. [FIPS DESCRIPTION] When "ubuntu-advantage enable-fips " is issued from commandline,  - configure the private PPA where the FIPS modules are located  - install the FIPS modules from this PPA to the local machine from where the script is run  - configure the bootloader to enable fips Upon successful completion of these steps, the customer then gets a message stating to reboot the machine to complete the fips enablement process. Without the script, customers must perform the steps manually. [LIVEPATCH DESCRIPTION] Livepatch allows customers to apply kernel patches to a running system without rebooting it. The current instructions live in http://ubuntu.com/livepatch and boil down to: - install snapd if it's not installed already. On trusty this means a new kernel as well. - install the canonical-livepatch snap - obtain a livepatch token from Canonical - run the enable command with the given token The ubuntu-advantage-tools package simplifies this process by just requesting the token and performing all the other steps on behalf of the user. It also conveniently checks the running kernel and instructs the user to reboot into a newer kernel if needed to finish the installation (this is the case when running trusty). [FIX] Add fips and livepatch support to the ubuntu-adadvantage-tools package. See debdiff below. [LIVEPATCH TESTCASES] TRUSTY 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline:     ubuntu-advantage status expect: livepatch: disabled esm: disabled (not available) fips: disabled (not available) 2. Enable livepatch visit https://ubuntu.com/livepatch and obtain a token type on commandline,     sudo ubuntu-advantage enable-livepatch You may be required to install a newer kernel. In that case, expect the following output:  Installing missing dependency snapd... OK  Installing the canonical-livepatch snap.  This may take a few minutes depending on your bandwidth.  canonical-livepatch 7.24 from 'canonical' installed  Your currently running kernel (3.13.0-133-generic) is too old to  support snaps. Version 4.4.0 or higher is needed.  Please reboot your system into a supported kernel version  and run the following command one more time to complete the  installation:  sudo ubuntu-advantage enable-livepatch Once you reboot and re-run the specified command, expect:  Enabling Livepatch with the given token, stand by...  Successfully enabled device. Using machine-token:  Use "canonical-livepatch status" to verify current patch status. 3. Verify livepatch status type on commandline,     ubuntu-advantage status expect an output like the following,  livepatch: enabled    client-version: "7.23"    architecture: x86_64    cpu-model: Intel Core Processor (Skylake)    last-check: 2017-10-23T15:10:45.640938255Z    boot-time: 2017-10-23T15:10:13Z    uptime: 1m19s    status:    - kernel: 4.4.0-97.120~14.04.1-generic      running: true      livepatch:        checkState: checked        patchState: nothing-to-apply        version: ""        fixes: ""  esm: disabled (not available)  fips: disabled (not available) XENIAL 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable livepatch visit https://ubuntu.com/livepatch and obtain a token type on commandline,     sudo ubuntu-advantage enable-livepatch expect,     Installing the canonical-livepatch snap.     This may take a few minutes depending on your bandwidth.     2017-10-20T19:39:41Z INFO Waiting for restart...     canonical-livepatch 7.24 from 'canonical' installed     Enabling Livepatch with the given token, stand by...     Successfully enabled device. Using machine-token: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx     Use "canonical-livepatch status" to verify current patch status. 3. Verify livepatch status type on commandline,     ubuntu-advantage status expect an output like the following,     livepatch: enabled       client-version: "7.23"       architecture: x86_64       cpu-model: Intel Core Processor (Skylake)       last-check: 2017-10-20T19:39:54.451499227Z       boot-time: 2017-10-20T19:28:09Z       uptime: 15m30s       status:       - kernel: 4.4.0-97.120-generic         running: true         livepatch:           checkState: checked           patchState: nothing-to-apply           version: ""           fixes: ""     esm: disabled (not available)     fips: disabled ZESTY 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline:     ubuntu-advantage status expect the livepatch service to be unavailable: livepatch: disabled (not available) esm: disabled (not available) fips: disabled (not available) 2. Ensure that livepatch cannot be enabled on Zesty. You can use a dummy set of credentials like "foobar" as the token: type on commandline,     sudo ubuntu-advantage enable-livepatch foobar expect,     Sorry, but Canonical Livepatch is not supported on zesty [FIPS TESTCASES] These testcases assume you have installed ubuntu-advantage-tools with the proposed changes. Prior to the upload they were performed on S390, PPC64EL and AMD64 architectures. TRUSTY (Note that FIPS is not supported on trusty.) 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,  livepatch: disabled  esm: disabled (not available)  fips: disabled (not available) 2. Ensure that fips cannot be enabled on trusty. You can use a dummy set of credentials like user:secret as the token: type on commandline,     sudo ubuntu-advantage enable-fips user:secret expect,     Sorry, but Canonical FIPS 140-2 Modules is not supported on trusty XENIAL 0. Install the new ubuntu-advantage-tools package to add fips support. 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable fips Note: This will require a token or credentials to fips Private PPA, in the form xxx:xxx type on commandline,     sudo ubuntu-advantage enable-fips xxx:xxx expect,     [sudo] password for ubuntu:     Running apt-get update... OK     Ubuntu FIPS PPA repository enabled.     Installing FIPS packages (this may take a while)... OK     Configuring FIPS...     Updating grub to enable fips... OK     Successfully configured FIPS. Please reboot into the FIPS kernel to enable it. type on commandline,     sudo reboot 3. Log back into system after reboot type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: enabled 4. verify fips kernel "4.4.0-1002-fips" has been installed type on commandline,     uname -a expect,     Linux xenialguest 4.4.0-1002-fips #2-Ubuntu SMP Thu Apr 27 19:37:46 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux ZESTY (Note that FIPS is not supported on zesty.) 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled (not available)     esm: disabled (not available)     fips: disabled (not available) 2. Ensure that fips cannot be enabled on Zesty. You can use a dummy set of credentials like user:secret as the token: type on commandline,     sudo ubuntu-advantage enable-fips user:secret expect,     Sorry, but Canonical FIPS 140-2 Modules is not supported on zesty [REGRESSION POTENTIAL] The current ubuntu-advantage-tools package in trusty, xenial and zesty is basically a NOOP because the only service it supports is ESM, which is only available for precise. This update adds two new features to the package: FIPS (xenial only) and Livepatch (trusty and xenial), essentially making the package useful in trusty and xenial. For zesty there is no change, as none of these products are available for non-LTS releases. [OTHER INFO] The way this package was made available in all the ubuntu releases where it is now was via a "pocket copy". That's why it has the exact same version in trusty, xenial and zesty. Currently artful has version 10 (a version 12 just missed the feature freeze), so in order for upgrades between releases to work, we adopted the backports versioning scheme, by appending the ubuntu release code with a tilda ("~") to the version. Another point is that even though ubuntu-advantage-tools is "just" a shell script, it is unit tested with python3, and these tests (and lint runs) gate merges in the upstream github repository at github.com/CanonicalLtd/ubuntu-advantage-script/ -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719671 Title: [SRU] include recent version containing fips and livepatch To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+subscriptions From andreas at canonical.com Mon Oct 23 20:17:43 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Mon, 23 Oct 2017 20:17:43 -0000 Subject: [Bug 1726231] Re: package samba 2:4.5.8+dfsg-0ubuntu0.17.04.7 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1 References: <150873250668.27608.13111073853539426755.malonedeb@soybean.canonical.com> Message-ID: <150878986433.17022.13369749767369094518.malone@wampee.canonical.com> Thanks for filing this bug in Ubuntu. The logs indeed indicate that one of the samba service, "smbd", is failing to start, but do not state why. To help determine why it's failing, could you please attach the following to this bug: - /etc/samba/smb.conf - /var/log/samba/log* <--- files that start with the "log" word. You can put them together in a zip file or tarball. If you want you can also run the testparm utility: it will inspect your samba configuration file (/etc/samba/smb.conf) looking for common mistakes and report to you what it finds. Thanks! ** Changed in: samba (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to samba in Ubuntu. https://bugs.launchpad.net/bugs/1726231 Title: package samba 2:4.5.8+dfsg-0ubuntu0.17.04.7 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1726231/+subscriptions From andreas at canonical.com Mon Oct 23 20:21:12 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Mon, 23 Oct 2017 20:21:12 -0000 Subject: [Bug 1725980] Re: package libheimntlm0-heimdal:i386 1.7~git20150920+dfsg-4ubuntu1.16.04.1 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting configuration References: <150867326154.17490.16052633904329646594.malonedeb@gac.canonical.com> Message-ID: <150879007296.18137.3957530638952298726.malone@chaenomeles.canonical.com> Thanks for filing this bug in Ubuntu. Could you please try these commands and see if they help solve the problem: sudo apt update sudo apt install --reinstall libheimntlm0-heimdal:i386 sudo apt -f install Please let us know how it goes. Thanks! -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to heimdal in Ubuntu. https://bugs.launchpad.net/bugs/1725980 Title: package libheimntlm0-heimdal:i386 1.7~git20150920+dfsg- 4ubuntu1.16.04.1 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting configuration To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/heimdal/+bug/1725980/+subscriptions From andreas at canonical.com Mon Oct 23 20:26:16 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Mon, 23 Oct 2017 20:26:16 -0000 Subject: [Bug 1719671] Re: [SRU] include recent version containing fips and livepatch References: <150644034167.6129.8221946942865677369.malonedeb@soybean.canonical.com> Message-ID: <150879037772.17574.15792463386290803070.launchpad@wampee.canonical.com> ** Description changed: This bug has some history that may be confusing from the comments. Basically it started out as a Feature Freeze Exception, that's why we have build logs, git logs and unit test runs attached. Also, the "rename" that is mentioned elsewhere did not happen with this package: the ubuntu-advantage name was kept, no new aliases were added. This will happen in a later SRU, with a later version of the package. I uploaded new tarballs and debdiff with these changes from what was here before, just in case you, the reader, have looked at the previous description: * tarball with correct directory entry. The previous one had "v10" instead of "10" as the base version * updated most recent changelog entry, just saying this is a backport of version 10. No need to say it has fips support, which neglected to mention the livepatch support. All that is in the previous d/changelog entries + + PPA with built packages for t, x and z: + https://launchpad.net/~ahasenack/+archive/ubuntu/ua-tools-sru-1719671 + (ppa:ahasenack/ua-tools-sru-1719671 - no ~ppaN suffix, sorry) [IMPACT] Most recent version of ubuntu-advantage-tool on github includes fips and livepatch enablement. The fips enablement will allow customers to easily install and configure Canonical's FIPS certified modules on xenial, whereas livepatch allows xenial and trusty customers to patch the running kernel without a reboot. This SRU will cover both new features. In addition to the new features themselves, a new "status" command was added that will give a short summary about the available modules and their status, at a glance. Note: FIPS certified modules are only available for xenial. Livepatch is supported on xenial and trusty. The tool will refuse to enable either service on an unsupported ubuntu release. Without this updated package, customers of those services have to enable them manually by following a series of steps. [FIPS DESCRIPTION] When "ubuntu-advantage enable-fips " is issued from commandline,  - configure the private PPA where the FIPS modules are located  - install the FIPS modules from this PPA to the local machine from where the script is run  - configure the bootloader to enable fips Upon successful completion of these steps, the customer then gets a message stating to reboot the machine to complete the fips enablement process. Without the script, customers must perform the steps manually. [LIVEPATCH DESCRIPTION] Livepatch allows customers to apply kernel patches to a running system without rebooting it. The current instructions live in http://ubuntu.com/livepatch and boil down to: - install snapd if it's not installed already. On trusty this means a new kernel as well. - install the canonical-livepatch snap - obtain a livepatch token from Canonical - run the enable command with the given token The ubuntu-advantage-tools package simplifies this process by just requesting the token and performing all the other steps on behalf of the user. It also conveniently checks the running kernel and instructs the user to reboot into a newer kernel if needed to finish the installation (this is the case when running trusty). [FIX] Add fips and livepatch support to the ubuntu-adadvantage-tools package. See debdiff below. [LIVEPATCH TESTCASES] TRUSTY 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline:     ubuntu-advantage status expect: livepatch: disabled esm: disabled (not available) fips: disabled (not available) 2. Enable livepatch visit https://ubuntu.com/livepatch and obtain a token type on commandline,     sudo ubuntu-advantage enable-livepatch You may be required to install a newer kernel. In that case, expect the following output:  Installing missing dependency snapd... OK  Installing the canonical-livepatch snap.  This may take a few minutes depending on your bandwidth.  canonical-livepatch 7.24 from 'canonical' installed  Your currently running kernel (3.13.0-133-generic) is too old to  support snaps. Version 4.4.0 or higher is needed.  Please reboot your system into a supported kernel version  and run the following command one more time to complete the  installation:  sudo ubuntu-advantage enable-livepatch Once you reboot and re-run the specified command, expect:  Enabling Livepatch with the given token, stand by...  Successfully enabled device. Using machine-token:  Use "canonical-livepatch status" to verify current patch status. 3. Verify livepatch status type on commandline,     ubuntu-advantage status expect an output like the following,  livepatch: enabled    client-version: "7.23"    architecture: x86_64    cpu-model: Intel Core Processor (Skylake)    last-check: 2017-10-23T15:10:45.640938255Z    boot-time: 2017-10-23T15:10:13Z    uptime: 1m19s    status:    - kernel: 4.4.0-97.120~14.04.1-generic      running: true      livepatch:        checkState: checked        patchState: nothing-to-apply        version: ""        fixes: ""  esm: disabled (not available)  fips: disabled (not available) XENIAL 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable livepatch visit https://ubuntu.com/livepatch and obtain a token type on commandline,     sudo ubuntu-advantage enable-livepatch expect,     Installing the canonical-livepatch snap.     This may take a few minutes depending on your bandwidth.     2017-10-20T19:39:41Z INFO Waiting for restart...     canonical-livepatch 7.24 from 'canonical' installed     Enabling Livepatch with the given token, stand by...     Successfully enabled device. Using machine-token: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx     Use "canonical-livepatch status" to verify current patch status. 3. Verify livepatch status type on commandline,     ubuntu-advantage status expect an output like the following,     livepatch: enabled       client-version: "7.23"       architecture: x86_64       cpu-model: Intel Core Processor (Skylake)       last-check: 2017-10-20T19:39:54.451499227Z       boot-time: 2017-10-20T19:28:09Z       uptime: 15m30s       status:       - kernel: 4.4.0-97.120-generic         running: true         livepatch:           checkState: checked           patchState: nothing-to-apply           version: ""           fixes: ""     esm: disabled (not available)     fips: disabled ZESTY 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline:     ubuntu-advantage status expect the livepatch service to be unavailable: livepatch: disabled (not available) esm: disabled (not available) fips: disabled (not available) 2. Ensure that livepatch cannot be enabled on Zesty. You can use a dummy set of credentials like "foobar" as the token: type on commandline,     sudo ubuntu-advantage enable-livepatch foobar expect,     Sorry, but Canonical Livepatch is not supported on zesty [FIPS TESTCASES] These testcases assume you have installed ubuntu-advantage-tools with the proposed changes. Prior to the upload they were performed on S390, PPC64EL and AMD64 architectures. TRUSTY (Note that FIPS is not supported on trusty.) 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,  livepatch: disabled  esm: disabled (not available)  fips: disabled (not available) 2. Ensure that fips cannot be enabled on trusty. You can use a dummy set of credentials like user:secret as the token: type on commandline,     sudo ubuntu-advantage enable-fips user:secret expect,     Sorry, but Canonical FIPS 140-2 Modules is not supported on trusty XENIAL 0. Install the new ubuntu-advantage-tools package to add fips support. 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable fips Note: This will require a token or credentials to fips Private PPA, in the form xxx:xxx type on commandline,     sudo ubuntu-advantage enable-fips xxx:xxx expect,     [sudo] password for ubuntu:     Running apt-get update... OK     Ubuntu FIPS PPA repository enabled.     Installing FIPS packages (this may take a while)... OK     Configuring FIPS...     Updating grub to enable fips... OK     Successfully configured FIPS. Please reboot into the FIPS kernel to enable it. type on commandline,     sudo reboot 3. Log back into system after reboot type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: enabled 4. verify fips kernel "4.4.0-1002-fips" has been installed type on commandline,     uname -a expect,     Linux xenialguest 4.4.0-1002-fips #2-Ubuntu SMP Thu Apr 27 19:37:46 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux ZESTY (Note that FIPS is not supported on zesty.) 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled (not available)     esm: disabled (not available)     fips: disabled (not available) 2. Ensure that fips cannot be enabled on Zesty. You can use a dummy set of credentials like user:secret as the token: type on commandline,     sudo ubuntu-advantage enable-fips user:secret expect,     Sorry, but Canonical FIPS 140-2 Modules is not supported on zesty [REGRESSION POTENTIAL] The current ubuntu-advantage-tools package in trusty, xenial and zesty is basically a NOOP because the only service it supports is ESM, which is only available for precise. This update adds two new features to the package: FIPS (xenial only) and Livepatch (trusty and xenial), essentially making the package useful in trusty and xenial. For zesty there is no change, as none of these products are available for non-LTS releases. [OTHER INFO] The way this package was made available in all the ubuntu releases where it is now was via a "pocket copy". That's why it has the exact same version in trusty, xenial and zesty. Currently artful has version 10 (a version 12 just missed the feature freeze), so in order for upgrades between releases to work, we adopted the backports versioning scheme, by appending the ubuntu release code with a tilda ("~") to the version. Another point is that even though ubuntu-advantage-tools is "just" a shell script, it is unit tested with python3, and these tests (and lint runs) gate merges in the upstream github repository at github.com/CanonicalLtd/ubuntu-advantage-script/. The tests do not necessarily run on each ubuntu release because of the version of python that is available in each. A clean run without any changes can be obtained in xenial and higher. Trusty needs a newer python3 (3.5 at a minimum). -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719671 Title: [SRU] include recent version containing fips and livepatch To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+subscriptions From nish.aravamudan at canonical.com Mon Oct 23 20:52:39 2017 From: nish.aravamudan at canonical.com (Nish Aravamudan) Date: Mon, 23 Oct 2017 20:52:39 -0000 Subject: [Bug 1721607] Re: please update to latest upstream release 7.0.24 References: <150722582934.21676.5660673599872685581.malonedeb@gac.canonical.com> Message-ID: <150879195999.17926.15039537731601668363.malone@chaenomeles.canonical.com> Just an FYI that I have uploaded an update to php7.0 for x and z and php7.1 for aa (which should get copied to bb, but bb will end up with 7.2 before release), but not as a security update. It will go through the normal SRU process before being available. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to php7.0 in Ubuntu. https://bugs.launchpad.net/bugs/1721607 Title: please update to latest upstream release 7.0.24 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/php7.0/+bug/1721607/+subscriptions From andreas at canonical.com Mon Oct 23 20:10:13 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Mon, 23 Oct 2017 20:10:13 -0000 Subject: [Bug 1719671] Re: [SRU] include recent version containing fips and livepatch References: <150644034167.6129.8221946942865677369.malonedeb@soybean.canonical.com> Message-ID: <150878941405.27939.1408448120606602134.launchpad@soybean.canonical.com> ** Description changed: ** description still being worked on, not done yet ** - This bug has some history that may be confusing if the comments are read - linearly. Basically it started out as a Feature Freeze Exception, that's - why we have build logs and unit test runs attached. + This bug has some history that may be confusing from the comments. + Basically it started out as a Feature Freeze Exception, that's why we + have build logs, git logs and unit test runs attached. Also, the "rename" that is mentioned elsewhere did not happen with this package: the ubuntu-advantage name was kept, no new aliases were added. This will happen in a later SRU, with a later version of the package. - I uploaded new tarballs and debdiff with these changes from what was here before, just in case you the reader have looked at this before: + I uploaded new tarballs and debdiff with these changes from what was here before, just in case you, the reader, have looked at the previous description: * tarball with correct directory entry. The previous one had "v10" instead of "10" as the base version * updated most recent changelog entry, just saying this is a backport of version 10. No need to say it has fips support, which neglected to mention the livepatch support. All that is in the previous d/changelog entries - [IMPACT] Most recent version of ubuntu-advantage-tool on github includes fips and livepatch enablement. The fips enablement will allow customers to easily install and configure Canonical's FIPS certified modules on xenial, whereas livepatch allows xenial and trusty customers to patch the running kernel without a reboot. This SRU will cover both new features. In addition to the new features themselves, a new "status" command was added that will give a short summary about the available modules and their status, at a glance. Note: FIPS certified modules are only available for xenial. Livepatch is supported on xenial and trusty. The tool will refuse to enable either service on an unsupported ubuntu release. Without this updated package, customers of those services have to enable them manually by following a series of steps. [FIPS DESCRIPTION] When "ubuntu-advantage enable-fips " is issued from commandline,  - configure the private PPA where the FIPS modules are located  - install the FIPS modules from this PPA to the local machine from where the script is run  - configure the bootloader to enable fips Upon successful completion of these steps, the customer then gets a message stating to reboot the machine to complete the fips enablement process. Without the script, customers must perform the steps manually. [LIVEPATCH DESCRIPTION] Livepatch allows customers to apply kernel patches to a running system without rebooting it. The current instructions live in http://ubuntu.com/livepatch and boil down to: - install snapd if it's not installed already. On trusty this means a new kernel as well. - install the canonical-livepatch snap - obtain a livepatch token from Canonical - run the enable command with the given token The ubuntu-advantage-tools package simplifies this process by just requesting the token and performing all the other steps on behalf of the user. It also conveniently checks the running kernel and instructs the user to reboot into a newer kernel if needed to finish the installation (this is the case when running trusty). [FIX] Add fips and livepatch support to the ubuntu-adadvantage-tools package. See debdiff below. [LIVEPATCH TESTCASES] TRUSTY 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline:     ubuntu-advantage status expect: livepatch: disabled esm: disabled (not available) fips: disabled (not available) 2. Enable livepatch visit https://ubuntu.com/livepatch and obtain a token type on commandline,     sudo ubuntu-advantage enable-livepatch You may be required to install a newer kernel. In that case, expect the following output:  Installing missing dependency snapd... OK  Installing the canonical-livepatch snap.  This may take a few minutes depending on your bandwidth.  canonical-livepatch 7.24 from 'canonical' installed  Your currently running kernel (3.13.0-133-generic) is too old to  support snaps. Version 4.4.0 or higher is needed.  Please reboot your system into a supported kernel version  and run the following command one more time to complete the  installation:  sudo ubuntu-advantage enable-livepatch Once you reboot and re-run the specified command, expect:  Enabling Livepatch with the given token, stand by...  Successfully enabled device. Using machine-token:  Use "canonical-livepatch status" to verify current patch status. 3. Verify livepatch status type on commandline,     ubuntu-advantage status expect an output like the following,  livepatch: enabled    client-version: "7.23"    architecture: x86_64    cpu-model: Intel Core Processor (Skylake)    last-check: 2017-10-23T15:10:45.640938255Z    boot-time: 2017-10-23T15:10:13Z    uptime: 1m19s    status:    - kernel: 4.4.0-97.120~14.04.1-generic      running: true      livepatch:        checkState: checked        patchState: nothing-to-apply        version: ""        fixes: ""  esm: disabled (not available)  fips: disabled (not available) XENIAL 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable livepatch visit https://ubuntu.com/livepatch and obtain a token type on commandline,     sudo ubuntu-advantage enable-livepatch expect,     Installing the canonical-livepatch snap.     This may take a few minutes depending on your bandwidth.     2017-10-20T19:39:41Z INFO Waiting for restart...     canonical-livepatch 7.24 from 'canonical' installed     Enabling Livepatch with the given token, stand by...     Successfully enabled device. Using machine-token: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx     Use "canonical-livepatch status" to verify current patch status. 3. Verify livepatch status type on commandline,     ubuntu-advantage status expect an output like the following,     livepatch: enabled       client-version: "7.23"       architecture: x86_64       cpu-model: Intel Core Processor (Skylake)       last-check: 2017-10-20T19:39:54.451499227Z       boot-time: 2017-10-20T19:28:09Z       uptime: 15m30s       status:       - kernel: 4.4.0-97.120-generic         running: true         livepatch:           checkState: checked           patchState: nothing-to-apply           version: ""           fixes: ""     esm: disabled (not available)     fips: disabled ZESTY 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline:     ubuntu-advantage status expect the livepatch service to be unavailable: livepatch: disabled (not available) esm: disabled (not available) fips: disabled (not available) 2. Ensure that livepatch cannot be enabled on Zesty. You can use a dummy set of credentials like "foobar" as the token: type on commandline,     sudo ubuntu-advantage enable-livepatch foobar expect,     Sorry, but Canonical Livepatch is not supported on zesty [FIPS TESTCASES] These testcases assume you have installed ubuntu-advantage-tools with the proposed changes. Prior to the upload they were performed on S390, PPC64EL and AMD64 architectures. TRUSTY (Note that FIPS is not supported on trusty.) 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,  livepatch: disabled  esm: disabled (not available)  fips: disabled (not available) 2. Ensure that fips cannot be enabled on trusty. You can use a dummy set of credentials like user:secret as the token: type on commandline,     sudo ubuntu-advantage enable-fips user:secret expect,     Sorry, but Canonical FIPS 140-2 Modules is not supported on trusty XENIAL 0. Install the new ubuntu-advantage-tools package to add fips support. 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable fips Note: This will require a token or credentials to fips Private PPA, in the form xxx:xxx type on commandline,     sudo ubuntu-advantage enable-fips xxx:xxx expect,     [sudo] password for ubuntu:     Running apt-get update... OK     Ubuntu FIPS PPA repository enabled.     Installing FIPS packages (this may take a while)... OK     Configuring FIPS...     Updating grub to enable fips... OK     Successfully configured FIPS. Please reboot into the FIPS kernel to enable it. type on commandline,     sudo reboot 3. Log back into system after reboot type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: enabled 4. verify fips kernel "4.4.0-1002-fips" has been installed type on commandline,     uname -a expect,     Linux xenialguest 4.4.0-1002-fips #2-Ubuntu SMP Thu Apr 27 19:37:46 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux ZESTY (Note that FIPS is not supported on zesty.) 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled (not available)     esm: disabled (not available)     fips: disabled (not available) 2. Ensure that fips cannot be enabled on Zesty. You can use a dummy set of credentials like user:secret as the token: type on commandline,     sudo ubuntu-advantage enable-fips user:secret expect,     Sorry, but Canonical FIPS 140-2 Modules is not supported on zesty [REGRESSION POTENTIAL] The current ubuntu-advantage-tools package in trusty, xenial and zesty is basically a NOOP because the only service it supports is ESM, which is only available for precise. This update adds two new features to the package: FIPS (xenial only) and Livepatch (trusty and xenial), essentially making the package useful in trusty and xenial. For zesty there is no change, as none of these products are available for non-LTS releases. [OTHER INFO] The way this package was made available in all the ubuntu releases where it is now was via a "pocket copy". That's why it has the exact same version in trusty, xenial and zesty. Currently artful has version 10 (a version 12 just missed the feature freeze), so in order for upgrades between releases to work, we adopted the backports versioning scheme, by appending the ubuntu release code with a tilda ("~") to the version. Another point is that even though ubuntu-advantage-tools is "just" a shell script, it is unit tested with python3, and these tests (and lint runs) gate merges in the upstream github repository at github.com/CanonicalLtd/ubuntu-advantage-script/ ** Description changed: ** description still being worked on, not done yet ** This bug has some history that may be confusing from the comments. Basically it started out as a Feature Freeze Exception, that's why we have build logs, git logs and unit test runs attached. Also, the "rename" that is mentioned elsewhere did not happen with this package: the ubuntu-advantage name was kept, no new aliases were added. This will happen in a later SRU, with a later version of the package. I uploaded new tarballs and debdiff with these changes from what was here before, just in case you, the reader, have looked at the previous description: * tarball with correct directory entry. The previous one had "v10" instead of "10" as the base version * updated most recent changelog entry, just saying this is a backport of version 10. No need to say it has fips support, which neglected to mention the livepatch support. All that is in the previous d/changelog entries [IMPACT] Most recent version of ubuntu-advantage-tool on github includes fips and livepatch enablement. The fips enablement will allow customers to easily install and configure Canonical's FIPS certified modules on xenial, whereas livepatch allows xenial and trusty customers to patch the running kernel without a reboot. This SRU will cover both new features. In addition to the new features themselves, a new "status" command was added that will give a short summary about the available modules and their status, at a glance. Note: FIPS certified modules are only available for xenial. Livepatch is supported on xenial and trusty. The tool will refuse to enable either service on an unsupported ubuntu release. Without this updated package, customers of those services have to enable them manually by following a series of steps. [FIPS DESCRIPTION] When "ubuntu-advantage enable-fips " is issued from commandline,  - configure the private PPA where the FIPS modules are located  - install the FIPS modules from this PPA to the local machine from where the script is run  - configure the bootloader to enable fips Upon successful completion of these steps, the customer then gets a message stating to reboot the machine to complete the fips enablement process. Without the script, customers must perform the steps manually. [LIVEPATCH DESCRIPTION] Livepatch allows customers to apply kernel patches to a running system without rebooting it. The current instructions live in http://ubuntu.com/livepatch and boil down to: - install snapd if it's not installed already. On trusty this means a new kernel as well. - install the canonical-livepatch snap - obtain a livepatch token from Canonical - run the enable command with the given token The ubuntu-advantage-tools package simplifies this process by just requesting the token and performing all the other steps on behalf of the user. It also conveniently checks the running kernel and instructs the user to reboot into a newer kernel if needed to finish the installation (this is the case when running trusty). [FIX] Add fips and livepatch support to the ubuntu-adadvantage-tools package. See debdiff below. [LIVEPATCH TESTCASES] TRUSTY 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline:     ubuntu-advantage status expect: livepatch: disabled esm: disabled (not available) fips: disabled (not available) 2. Enable livepatch visit https://ubuntu.com/livepatch and obtain a token type on commandline,     sudo ubuntu-advantage enable-livepatch You may be required to install a newer kernel. In that case, expect the following output:  Installing missing dependency snapd... OK  Installing the canonical-livepatch snap.  This may take a few minutes depending on your bandwidth.  canonical-livepatch 7.24 from 'canonical' installed  Your currently running kernel (3.13.0-133-generic) is too old to  support snaps. Version 4.4.0 or higher is needed.  Please reboot your system into a supported kernel version  and run the following command one more time to complete the  installation:  sudo ubuntu-advantage enable-livepatch Once you reboot and re-run the specified command, expect:  Enabling Livepatch with the given token, stand by...  Successfully enabled device. Using machine-token:  Use "canonical-livepatch status" to verify current patch status. 3. Verify livepatch status type on commandline,     ubuntu-advantage status expect an output like the following,  livepatch: enabled    client-version: "7.23"    architecture: x86_64    cpu-model: Intel Core Processor (Skylake)    last-check: 2017-10-23T15:10:45.640938255Z    boot-time: 2017-10-23T15:10:13Z    uptime: 1m19s    status:    - kernel: 4.4.0-97.120~14.04.1-generic      running: true      livepatch:        checkState: checked        patchState: nothing-to-apply        version: ""        fixes: ""  esm: disabled (not available)  fips: disabled (not available) XENIAL 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable livepatch visit https://ubuntu.com/livepatch and obtain a token type on commandline,     sudo ubuntu-advantage enable-livepatch expect,     Installing the canonical-livepatch snap.     This may take a few minutes depending on your bandwidth.     2017-10-20T19:39:41Z INFO Waiting for restart...     canonical-livepatch 7.24 from 'canonical' installed     Enabling Livepatch with the given token, stand by...     Successfully enabled device. Using machine-token: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx     Use "canonical-livepatch status" to verify current patch status. 3. Verify livepatch status type on commandline,     ubuntu-advantage status expect an output like the following,     livepatch: enabled       client-version: "7.23"       architecture: x86_64       cpu-model: Intel Core Processor (Skylake)       last-check: 2017-10-20T19:39:54.451499227Z       boot-time: 2017-10-20T19:28:09Z       uptime: 15m30s       status:       - kernel: 4.4.0-97.120-generic         running: true         livepatch:           checkState: checked           patchState: nothing-to-apply           version: ""           fixes: ""     esm: disabled (not available)     fips: disabled ZESTY 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline:     ubuntu-advantage status expect the livepatch service to be unavailable: livepatch: disabled (not available) esm: disabled (not available) fips: disabled (not available) 2. Ensure that livepatch cannot be enabled on Zesty. You can use a dummy set of credentials like "foobar" as the token: type on commandline,     sudo ubuntu-advantage enable-livepatch foobar expect,     Sorry, but Canonical Livepatch is not supported on zesty [FIPS TESTCASES] These testcases assume you have installed ubuntu-advantage-tools with the proposed changes. Prior to the upload they were performed on S390, PPC64EL and AMD64 architectures. TRUSTY (Note that FIPS is not supported on trusty.) 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,  livepatch: disabled  esm: disabled (not available)  fips: disabled (not available) 2. Ensure that fips cannot be enabled on trusty. You can use a dummy set of credentials like user:secret as the token: type on commandline,     sudo ubuntu-advantage enable-fips user:secret expect,     Sorry, but Canonical FIPS 140-2 Modules is not supported on trusty XENIAL 0. Install the new ubuntu-advantage-tools package to add fips support. 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable fips Note: This will require a token or credentials to fips Private PPA, in the form xxx:xxx type on commandline,     sudo ubuntu-advantage enable-fips xxx:xxx expect,     [sudo] password for ubuntu:     Running apt-get update... OK     Ubuntu FIPS PPA repository enabled.     Installing FIPS packages (this may take a while)... OK     Configuring FIPS...     Updating grub to enable fips... OK     Successfully configured FIPS. Please reboot into the FIPS kernel to enable it. type on commandline,     sudo reboot 3. Log back into system after reboot type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: enabled 4. verify fips kernel "4.4.0-1002-fips" has been installed type on commandline,     uname -a expect,     Linux xenialguest 4.4.0-1002-fips #2-Ubuntu SMP Thu Apr 27 19:37:46 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux ZESTY (Note that FIPS is not supported on zesty.) 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled (not available)     esm: disabled (not available)     fips: disabled (not available) 2. Ensure that fips cannot be enabled on Zesty. You can use a dummy set of credentials like user:secret as the token: type on commandline,     sudo ubuntu-advantage enable-fips user:secret expect,     Sorry, but Canonical FIPS 140-2 Modules is not supported on zesty [REGRESSION POTENTIAL] The current ubuntu-advantage-tools package in trusty, xenial and zesty is basically a NOOP because the only service it supports is ESM, which is only available for precise. This update adds two new features to the package: FIPS (xenial only) and Livepatch (trusty and xenial), essentially making the package useful in trusty and xenial. For zesty there is no change, as none of these products are available for non-LTS releases. [OTHER INFO] The way this package was made available in all the ubuntu releases where it is now was via a "pocket copy". That's why it has the exact same version in trusty, xenial and zesty. Currently artful has version 10 (a version 12 just missed the feature freeze), so in order for upgrades between releases to work, we adopted the backports versioning scheme, by appending the ubuntu release code with a tilda ("~") to the version. - Another point is that even though ubuntu-advantage-tools is "just" a shell script, it is unit tested with python3, and these tests (and lint runs) gate merges in the upstream github repository at github.com/CanonicalLtd/ubuntu-advantage-script/ + Another point is that even though ubuntu-advantage-tools is "just" a shell script, it is unit tested with python3, and these tests (and lint runs) gate merges in the upstream github repository at github.com/CanonicalLtd/ubuntu-advantage-script/. The tests do not necessarily run on each ubuntu release because of the version of python that is available in each. A clean run without any changes can be obtained in xenial and higher. Trusty needs a newer python3 (3.5 at a minimum). ** Description changed: - ** description still being worked on, not done yet ** - This bug has some history that may be confusing from the comments. Basically it started out as a Feature Freeze Exception, that's why we have build logs, git logs and unit test runs attached. Also, the "rename" that is mentioned elsewhere did not happen with this package: the ubuntu-advantage name was kept, no new aliases were added. This will happen in a later SRU, with a later version of the package. I uploaded new tarballs and debdiff with these changes from what was here before, just in case you, the reader, have looked at the previous description: * tarball with correct directory entry. The previous one had "v10" instead of "10" as the base version * updated most recent changelog entry, just saying this is a backport of version 10. No need to say it has fips support, which neglected to mention the livepatch support. All that is in the previous d/changelog entries [IMPACT] Most recent version of ubuntu-advantage-tool on github includes fips and livepatch enablement. The fips enablement will allow customers to easily install and configure Canonical's FIPS certified modules on xenial, whereas livepatch allows xenial and trusty customers to patch the running kernel without a reboot. This SRU will cover both new features. In addition to the new features themselves, a new "status" command was added that will give a short summary about the available modules and their status, at a glance. Note: FIPS certified modules are only available for xenial. Livepatch is supported on xenial and trusty. The tool will refuse to enable either service on an unsupported ubuntu release. Without this updated package, customers of those services have to enable them manually by following a series of steps. [FIPS DESCRIPTION] When "ubuntu-advantage enable-fips " is issued from commandline,  - configure the private PPA where the FIPS modules are located  - install the FIPS modules from this PPA to the local machine from where the script is run  - configure the bootloader to enable fips Upon successful completion of these steps, the customer then gets a message stating to reboot the machine to complete the fips enablement process. Without the script, customers must perform the steps manually. [LIVEPATCH DESCRIPTION] Livepatch allows customers to apply kernel patches to a running system without rebooting it. The current instructions live in http://ubuntu.com/livepatch and boil down to: - install snapd if it's not installed already. On trusty this means a new kernel as well. - install the canonical-livepatch snap - obtain a livepatch token from Canonical - run the enable command with the given token The ubuntu-advantage-tools package simplifies this process by just requesting the token and performing all the other steps on behalf of the user. It also conveniently checks the running kernel and instructs the user to reboot into a newer kernel if needed to finish the installation (this is the case when running trusty). [FIX] Add fips and livepatch support to the ubuntu-adadvantage-tools package. See debdiff below. [LIVEPATCH TESTCASES] TRUSTY 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline:     ubuntu-advantage status expect: livepatch: disabled esm: disabled (not available) fips: disabled (not available) 2. Enable livepatch visit https://ubuntu.com/livepatch and obtain a token type on commandline,     sudo ubuntu-advantage enable-livepatch You may be required to install a newer kernel. In that case, expect the following output:  Installing missing dependency snapd... OK  Installing the canonical-livepatch snap.  This may take a few minutes depending on your bandwidth.  canonical-livepatch 7.24 from 'canonical' installed  Your currently running kernel (3.13.0-133-generic) is too old to  support snaps. Version 4.4.0 or higher is needed.  Please reboot your system into a supported kernel version  and run the following command one more time to complete the  installation:  sudo ubuntu-advantage enable-livepatch Once you reboot and re-run the specified command, expect:  Enabling Livepatch with the given token, stand by...  Successfully enabled device. Using machine-token:  Use "canonical-livepatch status" to verify current patch status. 3. Verify livepatch status type on commandline,     ubuntu-advantage status expect an output like the following,  livepatch: enabled    client-version: "7.23"    architecture: x86_64    cpu-model: Intel Core Processor (Skylake)    last-check: 2017-10-23T15:10:45.640938255Z    boot-time: 2017-10-23T15:10:13Z    uptime: 1m19s    status:    - kernel: 4.4.0-97.120~14.04.1-generic      running: true      livepatch:        checkState: checked        patchState: nothing-to-apply        version: ""        fixes: ""  esm: disabled (not available)  fips: disabled (not available) XENIAL 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable livepatch visit https://ubuntu.com/livepatch and obtain a token type on commandline,     sudo ubuntu-advantage enable-livepatch expect,     Installing the canonical-livepatch snap.     This may take a few minutes depending on your bandwidth.     2017-10-20T19:39:41Z INFO Waiting for restart...     canonical-livepatch 7.24 from 'canonical' installed     Enabling Livepatch with the given token, stand by...     Successfully enabled device. Using machine-token: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx     Use "canonical-livepatch status" to verify current patch status. 3. Verify livepatch status type on commandline,     ubuntu-advantage status expect an output like the following,     livepatch: enabled       client-version: "7.23"       architecture: x86_64       cpu-model: Intel Core Processor (Skylake)       last-check: 2017-10-20T19:39:54.451499227Z       boot-time: 2017-10-20T19:28:09Z       uptime: 15m30s       status:       - kernel: 4.4.0-97.120-generic         running: true         livepatch:           checkState: checked           patchState: nothing-to-apply           version: ""           fixes: ""     esm: disabled (not available)     fips: disabled ZESTY 0. Install the new ubuntu-advantage-tools package to add livepatch support. 1. Collect status before enabling livepatch type on commandline:     ubuntu-advantage status expect the livepatch service to be unavailable: livepatch: disabled (not available) esm: disabled (not available) fips: disabled (not available) 2. Ensure that livepatch cannot be enabled on Zesty. You can use a dummy set of credentials like "foobar" as the token: type on commandline,     sudo ubuntu-advantage enable-livepatch foobar expect,     Sorry, but Canonical Livepatch is not supported on zesty [FIPS TESTCASES] These testcases assume you have installed ubuntu-advantage-tools with the proposed changes. Prior to the upload they were performed on S390, PPC64EL and AMD64 architectures. TRUSTY (Note that FIPS is not supported on trusty.) 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,  livepatch: disabled  esm: disabled (not available)  fips: disabled (not available) 2. Ensure that fips cannot be enabled on trusty. You can use a dummy set of credentials like user:secret as the token: type on commandline,     sudo ubuntu-advantage enable-fips user:secret expect,     Sorry, but Canonical FIPS 140-2 Modules is not supported on trusty XENIAL 0. Install the new ubuntu-advantage-tools package to add fips support. 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: disabled 2. Enable fips Note: This will require a token or credentials to fips Private PPA, in the form xxx:xxx type on commandline,     sudo ubuntu-advantage enable-fips xxx:xxx expect,     [sudo] password for ubuntu:     Running apt-get update... OK     Ubuntu FIPS PPA repository enabled.     Installing FIPS packages (this may take a while)... OK     Configuring FIPS...     Updating grub to enable fips... OK     Successfully configured FIPS. Please reboot into the FIPS kernel to enable it. type on commandline,     sudo reboot 3. Log back into system after reboot type on commandline,     ubuntu-advantage status expect,     livepatch: disabled     esm: disabled (not available)     fips: enabled 4. verify fips kernel "4.4.0-1002-fips" has been installed type on commandline,     uname -a expect,     Linux xenialguest 4.4.0-1002-fips #2-Ubuntu SMP Thu Apr 27 19:37:46 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux ZESTY (Note that FIPS is not supported on zesty.) 1. Collect status before enabling fips type on commandline,     ubuntu-advantage status expect,     livepatch: disabled (not available)     esm: disabled (not available)     fips: disabled (not available) 2. Ensure that fips cannot be enabled on Zesty. You can use a dummy set of credentials like user:secret as the token: type on commandline,     sudo ubuntu-advantage enable-fips user:secret expect,     Sorry, but Canonical FIPS 140-2 Modules is not supported on zesty [REGRESSION POTENTIAL] The current ubuntu-advantage-tools package in trusty, xenial and zesty is basically a NOOP because the only service it supports is ESM, which is only available for precise. This update adds two new features to the package: FIPS (xenial only) and Livepatch (trusty and xenial), essentially making the package useful in trusty and xenial. For zesty there is no change, as none of these products are available for non-LTS releases. [OTHER INFO] The way this package was made available in all the ubuntu releases where it is now was via a "pocket copy". That's why it has the exact same version in trusty, xenial and zesty. Currently artful has version 10 (a version 12 just missed the feature freeze), so in order for upgrades between releases to work, we adopted the backports versioning scheme, by appending the ubuntu release code with a tilda ("~") to the version. Another point is that even though ubuntu-advantage-tools is "just" a shell script, it is unit tested with python3, and these tests (and lint runs) gate merges in the upstream github repository at github.com/CanonicalLtd/ubuntu-advantage-script/. The tests do not necessarily run on each ubuntu release because of the version of python that is available in each. A clean run without any changes can be obtained in xenial and higher. Trusty needs a newer python3 (3.5 at a minimum). -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to ubuntu-advantage-tools in Ubuntu. https://bugs.launchpad.net/bugs/1719671 Title: [SRU] include recent version containing fips and livepatch To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/1719671/+subscriptions From james.page at ubuntu.com Tue Oct 24 09:05:43 2017 From: james.page at ubuntu.com (James Page) Date: Tue, 24 Oct 2017 09:05:43 -0000 Subject: [Bug 1558311] Re: package rabbitmq-server 3.5.4-1 failed to install/upgrade: rabbit@controller: * unable to connect to epmd (port 4369) on controller: address (cannot connect to host/port) current node details: - node name: 'rabbitmq-cli-25717@controller' - home dir: /var/lib/rabbitmq - cookie hash: XHLruNjMVi9RPYDcOuJiAQ==subprocess installed post-installation script returned error exit status 1 References: <20160316230847.18531.70372.malonedeb@wampee.canonical.com> Message-ID: <150883594366.17802.13081154286240696801.malone@chaenomeles.canonical.com> erlang/rmq is notoriously brittle if the hostname being used ('controller') does not forward and reverse resolve on the host its running on (and all other hosts that you might want to cluster it with). Please check this is the case: sudo nslookup controller Marking 'Incomplete'; if the hostname controller does not forward/reverse lookup between hostname and IP OK then please fix that and mark this bug as Invalid; otherwise please comment and set back to 'New'. ** Changed in: rabbitmq-server (Ubuntu) Status: New => Incomplete ** Changed in: rabbitmq-server (Ubuntu) Importance: Undecided => Low -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to rabbitmq-server in Ubuntu. https://bugs.launchpad.net/bugs/1558311 Title: package rabbitmq-server 3.5.4-1 failed to install/upgrade: rabbit at controller: * unable to connect to epmd (port 4369) on controller: address (cannot connect to host/port) current node details: - node name: 'rabbitmq-cli-25717 at controller' - home dir: /var/lib/rabbitmq - cookie hash: XHLruNjMVi9RPYDcOuJiAQ==subprocess installed post-installation script returned error exit status 1 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/rabbitmq-server/+bug/1558311/+subscriptions From james.page at ubuntu.com Tue Oct 24 09:10:57 2017 From: james.page at ubuntu.com (James Page) Date: Tue, 24 Oct 2017 09:10:57 -0000 Subject: [Bug 1434395] Re: Rabbitmq fails to start epmd daemon References: <20150320063112.14196.55155.malonedeb@wampee.canonical.com> Message-ID: <150883625814.17363.13801579605234698870.malone@wampee.canonical.com> Hi Trusty shipped with RMQ 3.2.4-1ubuntu0.1 - I see you have 3.3.5-1 installed which I can't find in any currently supported Ubuntu release, or the Ubuntu Cloud Archive pockets for Ubuntu Trusty. I'm not able to reproduce this issue on either trusty or xenial package versions. Please could you comment on the question in #1. I'm going to mark this as Incomplete for now - please confirm whether you still see this issue on a rabbitmq-server package version actually provided by Ubuntu. Thanks! ** Changed in: rabbitmq-server (Ubuntu) Status: New => Incomplete ** Changed in: rabbitmq-server (Ubuntu) Importance: Undecided => Low -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to rabbitmq-server in Ubuntu. https://bugs.launchpad.net/bugs/1434395 Title: Rabbitmq fails to start epmd daemon To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/rabbitmq-server/+bug/1434395/+subscriptions From james.page at ubuntu.com Tue Oct 24 09:18:52 2017 From: james.page at ubuntu.com (James Page) Date: Tue, 24 Oct 2017 09:18:52 -0000 Subject: [Bug 1513853] Re: RabbitMQ connection going down consistently with scale config References: <20151106142501.32089.83179.malonedeb@wampee.canonical.com> Message-ID: <150883673295.27641.1079892112701868186.malone@soybean.canonical.com> I appreciate that this is an older bug, but if you could provide details on which Ubuntu release and which version of the rabbitmq-server package you see this issue that would be helpful. Marking 'Incomplete' and 'Low' for now. Please set back to 'New' when the information requested has been provided, or mark 'Invalid' if you no longer see this issue (as you've moved to a newer Ubuntu or OpenStack release version). ** Changed in: rabbitmq-server (Ubuntu) Status: New => Incomplete ** Changed in: rabbitmq-server (Ubuntu) Importance: Undecided => Low -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to rabbitmq-server in Ubuntu. https://bugs.launchpad.net/bugs/1513853 Title: RabbitMQ connection going down consistently with scale config To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/rabbitmq-server/+bug/1513853/+subscriptions From james.page at ubuntu.com Tue Oct 24 09:16:54 2017 From: james.page at ubuntu.com (James Page) Date: Tue, 24 Oct 2017 09:16:54 -0000 Subject: [Bug 1496409] Re: Race condition in mnesia_locker after node down References: <20150916140328.19915.39291.malonedeb@soybean.canonical.com> Message-ID: <150883661411.18032.12515548438316644625.malone@chaenomeles.canonical.com> Jorge Have you seen this issue in Xenial or later releases of the RabbitMQ server package? Xenial included a 3.5.x series rabbitmq which should contain the fixes referenced. Note that we also provide this version of RMQ for trusty uses via the Icehouse Ubuntu Cloud Archive. ** Changed in: rabbitmq-server (Ubuntu) Status: New => Triaged ** Changed in: rabbitmq-server (Ubuntu) Importance: Undecided => Medium ** Changed in: rabbitmq-server (Ubuntu) Importance: Medium => Low -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to rabbitmq-server in Ubuntu. https://bugs.launchpad.net/bugs/1496409 Title: Race condition in mnesia_locker after node down To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/rabbitmq-server/+bug/1496409/+subscriptions From andreas at canonical.com Tue Oct 24 11:30:02 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Tue, 24 Oct 2017 11:30:02 -0000 Subject: [Bug 1726720] Re: package samba 2:4.6.7+dfsg-1ubuntu3 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1 References: <150882828019.28343.11431008366342619413.malonedeb@soybean.canonical.com> Message-ID: <150884460273.28414.7616381096135886209.malone@soybean.canonical.com> Thanks for filing this bug in Ubuntu. The Samba nmbd service indeed failed to start, but the attached logs don't indicate why. Could you please attach all the files that start with "log" in the directory /var/log/samba? Also, what is the current status of the samba services after you finished this upgrade: sudo systemctl status nmbd.service smbd.service Thanks! ** Changed in: samba (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to samba in Ubuntu. https://bugs.launchpad.net/bugs/1726720 Title: package samba 2:4.6.7+dfsg-1ubuntu3 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1726720/+subscriptions From andreas at canonical.com Tue Oct 24 13:12:14 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Tue, 24 Oct 2017 13:12:14 -0000 Subject: =?utf-8?q?=5BBug_1718984=5D_Re=3A_package_samba_2=3A4=2E5=2E8+dfsg?= =?utf-8?q?-0ubuntu0=2E17=2E04=2E7_failed_to_install/upgrade=3A_el_subproces?= =?utf-8?q?o_instalado_el_script_post-installation_devolvi=C3=B3_el_c=C3=B3d?= =?utf-8?q?igo_de_salida_de_error_1?= References: <150610089505.21888.1778716702653418075.malonedeb@chaenomeles.canonical.com> Message-ID: <150885073497.17253.12684622149642835005.malone@wampee.canonical.com> Thanks for filing this bug in Ubuntu. The logs confirm that the nmbd service failed to start, but are not clear as to why. Could you please attach the following files to this bug to help diagnose the problem: - /etc/samba/smb.conf - all files inside /var/log/samba that start with "log". You can put these in a tarball or zip archive. Thanks! ** Changed in: samba (Ubuntu) Status: Confirmed => Incomplete -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to samba in Ubuntu. https://bugs.launchpad.net/bugs/1718984 Title: package samba 2:4.5.8+dfsg-0ubuntu0.17.04.7 failed to install/upgrade: el subproceso instalado el script post-installation devolvió el código de salida de error 1 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1718984/+subscriptions From corey.bryant at canonical.com Tue Oct 24 16:11:01 2017 From: corey.bryant at canonical.com (Corey Bryant) Date: Tue, 24 Oct 2017 16:11:01 -0000 Subject: [Bug 1720397] Re: qemu-kvm doesnt restart after node reboot References: <150669833185.21053.13738921475958605908.malonedeb@chaenomeles.canonical.com> Message-ID: <150886146192.18032.3372403721125052860.malone@chaenomeles.canonical.com> OpenStack regression tests have passed successfully for xenial-pike- proposed with this package. pike-proposed with next charms: ====== Totals ====== Ran: 102 tests in 1904.7099 sec. - Passed: 93 - Skipped: 9 - Expected Fail: 0 - Unexpected Success: 0 - Failed: 0 Sum of execute time for each test: 794.0835 sec. pike-proposed with stable charms: ====== Totals ====== Ran: 102 tests in 1976.6895 sec. - Passed: 93 - Skipped: 9 - Expected Fail: 0 - Unexpected Success: 0 - Failed: 0 Sum of execute time for each test: 854.3158 sec. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to qemu in Ubuntu. https://bugs.launchpad.net/bugs/1720397 Title: qemu-kvm doesnt restart after node reboot To manage notifications about this bug go to: https://bugs.launchpad.net/cloud-archive/+bug/1720397/+subscriptions From andreas at canonical.com Tue Oct 24 17:41:33 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Tue, 24 Oct 2017 17:41:33 -0000 Subject: =?utf-8?q?=5BBug_1726905=5D_Re=3A_package_samba_2=3A4=2E3=2E11+dfs?= =?utf-8?q?g-0ubuntu0=2E16=2E04=2E11_failed_to_install/upgrade=3A_el_subproc?= =?utf-8?q?eso_instalado_el_script_post-installation_devolvi=C3=B3_el_c?= =?utf-8?q?=C3=B3digo_de_salida_de_error_1?= References: <150885788844.27573.15419875761878989455.malonedeb@soybean.canonical.com> Message-ID: <150886689332.17764.7380844357689879143.malone@chaenomeles.canonical.com> Thanks for filing this bug in Ubuntu. You have a configuration syntax error in /etc/samba/smb.conf: [www] path = /var/www comment = red guest ok = red <--- The "guest ok" parameter takes a boolean value, that is, either yes or no: $ testparm ./smb.conf Load smb config files from ./smb.conf rlimit_max: increasing rlimit_max (1024) to minimum Windows limit (16384) WARNING: The "syslog" option is deprecated Processing section "[printers]" Processing section "[print$]" Processing section "[Red]" Processing section "[www]" set_variable_helper(red): value is not boolean! Error loading services. Fix that in your /etc/samba/smb.conf and then run the following: sudo apt update sudo apt -f install I'll mark this bug as invalid because of that. If the above doesn't fix your problem, then please reopen the bug with a comment saying what happened. Thanks ** Changed in: samba (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to samba in Ubuntu. https://bugs.launchpad.net/bugs/1726905 Title: package samba 2:4.3.11+dfsg-0ubuntu0.16.04.11 failed to install/upgrade: el subproceso instalado el script post-installation devolvió el código de salida de error 1 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1726905/+subscriptions From andreas at canonical.com Tue Oct 24 17:53:54 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Tue, 24 Oct 2017 17:53:54 -0000 Subject: [Bug 1725980] Re: package libheimntlm0-heimdal:i386 1.7~git20150920+dfsg-4ubuntu1.16.04.1 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting configuration References: <150867326154.17490.16052633904329646594.malonedeb@gac.canonical.com> Message-ID: <150886763572.17490.12968828079028695540.launchpad@gac.canonical.com> ** Changed in: heimdal (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to heimdal in Ubuntu. https://bugs.launchpad.net/bugs/1725980 Title: package libheimntlm0-heimdal:i386 1.7~git20150920+dfsg- 4ubuntu1.16.04.1 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting configuration To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/heimdal/+bug/1725980/+subscriptions From andreas at canonical.com Tue Oct 24 18:35:54 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Tue, 24 Oct 2017 18:35:54 -0000 Subject: [Bug 1726595] Re: Running Matlab (R) from ssh session with X forwarding doesn't work anymore in 17.10 References: <150879317231.27683.16119704591861460296.malonedeb@soybean.canonical.com> Message-ID: <150887015452.27466.6628628102504582780.malone@soybean.canonical.com> Are you using Wayland? If yes, can you try with plain Xorg? To switch to xorg, logout, and on the login screen, after clicking on your name, you will see a small gear icon. Click that to select xorg, and then continue with the login. ** Changed in: openssh (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to openssh in Ubuntu. https://bugs.launchpad.net/bugs/1726595 Title: Running Matlab (R) from ssh session with X forwarding doesn't work anymore in 17.10 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/1726595/+subscriptions From andreas at canonical.com Tue Oct 24 20:00:43 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Tue, 24 Oct 2017 20:00:43 -0000 Subject: [Bug 1726595] Re: Running Matlab (R) from ssh session with X forwarding doesn't work anymore in 17.10 References: <150879317231.27683.16119704591861460296.malonedeb@soybean.canonical.com> Message-ID: <150887524378.17926.9410182675850273214.malone@chaenomeles.canonical.com> I meant in the ssh localhost test case that you showed. But still, even in the remote case, the "X server" would be your local machine and the X api calls from matlab would be routed to your local X server (wayland or xorg) through the ssh connection. So, just to clarify, matlab works on your localhost when ssh is not used? I.e., just opening a terminal and running "matlab" followed by the plot command? And if you repeat the above but first do a "ssh -X localhost", i.e., the DISPLAY variable is something other than just ":0", then it doesn't work? Both scenarios above stay the same regardless if you are using wayland or xorg in Ubuntu Artful? -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to openssh in Ubuntu. https://bugs.launchpad.net/bugs/1726595 Title: Running Matlab (R) from ssh session with X forwarding doesn't work anymore in 17.10 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/1726595/+subscriptions From james.page at ubuntu.com Wed Oct 25 07:57:43 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 25 Oct 2017 07:57:43 -0000 Subject: [Bug 1727063] Re: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage References: <150887824680.17498.17769190132626371447.malonedeb@wampee.canonical.com> Message-ID: <150891826383.17328.12685525335606541733.malone@wampee.canonical.com> Hmm https://github.com/ClusterLabs/pacemaker/commit/fc11a4651b971bd3b9dfc15b8b5c538c7ee9ab75 #diff-06baf804b1f5edee72fb63df4b884b7c -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to pacemaker in Ubuntu. https://bugs.launchpad.net/bugs/1727063 Title: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage To manage notifications about this bug go to: https://bugs.launchpad.net/charm-hacluster/+bug/1727063/+subscriptions From james.page at ubuntu.com Wed Oct 25 07:58:35 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 25 Oct 2017 07:58:35 -0000 Subject: [Bug 1727063] Re: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage References: <150887824680.17498.17769190132626371447.malonedeb@wampee.canonical.com> Message-ID: <150891831581.18511.9298468952274839875.malone@chaenomeles.canonical.com> And https://github.com/ClusterLabs/pacemaker/pull/656 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to pacemaker in Ubuntu. https://bugs.launchpad.net/bugs/1727063 Title: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage To manage notifications about this bug go to: https://bugs.launchpad.net/charm-hacluster/+bug/1727063/+subscriptions From james.page at ubuntu.com Wed Oct 25 08:11:10 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 25 Oct 2017 08:11:10 -0000 Subject: [Bug 1727063] Re: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage References: <150887824680.17498.17769190132626371447.malonedeb@wampee.canonical.com> Message-ID: <150891907095.28011.14412770924347313809.malone@soybean.canonical.com> Other related bugs - bug 1322899 and bug 1052449 ** Changed in: pacemaker (Ubuntu) Status: Confirmed => Triaged ** Changed in: pacemaker (Ubuntu) Importance: Undecided => High ** Changed in: pacemaker (Ubuntu) Importance: High => Critical ** Also affects: pacemaker (Ubuntu Artful) Importance: Undecided Status: New ** Also affects: pacemaker (Ubuntu Xenial) Importance: Undecided Status: New ** Also affects: pacemaker (Ubuntu Bionic) Importance: Critical Status: Triaged ** Also affects: pacemaker (Ubuntu Zesty) Importance: Undecided Status: New ** Changed in: pacemaker (Ubuntu Zesty) Importance: Undecided => Critical ** Changed in: pacemaker (Ubuntu Artful) Importance: Undecided => Critical ** Changed in: pacemaker (Ubuntu Xenial) Status: New => Triaged ** Changed in: pacemaker (Ubuntu Zesty) Status: New => Triaged ** Changed in: pacemaker (Ubuntu Xenial) Importance: Undecided => Critical ** Changed in: pacemaker (Ubuntu Artful) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to pacemaker in Ubuntu. https://bugs.launchpad.net/bugs/1727063 Title: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage To manage notifications about this bug go to: https://bugs.launchpad.net/charm-hacluster/+bug/1727063/+subscriptions From james.page at ubuntu.com Wed Oct 25 08:18:36 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 25 Oct 2017 08:18:36 -0000 Subject: [Bug 1727063] Re: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage References: <150887824680.17498.17769190132626371447.malonedeb@wampee.canonical.com> Message-ID: <150891951663.17220.1022518050855039567.malone@wampee.canonical.com> I think this is a packaging/upstream bug which I appear to have had a go at before (see #4); however I've not seen this specific symptom before. ** Changed in: charm-hacluster Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to pacemaker in Ubuntu. https://bugs.launchpad.net/bugs/1727063 Title: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage To manage notifications about this bug go to: https://bugs.launchpad.net/charm-hacluster/+bug/1727063/+subscriptions From james.page at ubuntu.com Wed Oct 25 08:22:29 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 25 Oct 2017 08:22:29 -0000 Subject: [Bug 1727063] Re: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage References: <150887824680.17498.17769190132626371447.malonedeb@wampee.canonical.com> Message-ID: <150891974941.17686.12541972136830630980.malone@wampee.canonical.com> Marking charm bug task as invalid - its doing the right things, however the package does not declare default start/stop levels so its all foobar. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to pacemaker in Ubuntu. https://bugs.launchpad.net/bugs/1727063 Title: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage To manage notifications about this bug go to: https://bugs.launchpad.net/charm-hacluster/+bug/1727063/+subscriptions From james.page at ubuntu.com Wed Oct 25 08:27:37 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 25 Oct 2017 08:27:37 -0000 Subject: [Bug 1322899] Re: pacemaker init script links aren't created on upgrade References: <20140524194253.25586.27315.malonedeb@chaenomeles.canonical.com> Message-ID: <150892005718.17640.3693366445224793395.malone@gac.canonical.com> See related bug 1727063 ** Changed in: pacemaker (Ubuntu) Status: Confirmed => Triaged -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to pacemaker in Ubuntu. https://bugs.launchpad.net/bugs/1322899 Title: pacemaker init script links aren't created on upgrade To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/pacemaker/+bug/1322899/+subscriptions From james.page at ubuntu.com Wed Oct 25 08:27:58 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 25 Oct 2017 08:27:58 -0000 Subject: [Bug 1052449] Re: corosync hangs due to missing pacemaker shutdown scripts References: <20120918114650.18946.40820.malonedeb@soybean.canonical.com> Message-ID: <150892007820.17181.4766021462165623021.malone@wampee.canonical.com> See related bug 1727063 ** Changed in: pacemaker (Ubuntu) Status: Confirmed => Triaged ** Changed in: pacemaker (Ubuntu) Importance: Undecided => High -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to pacemaker in Ubuntu. https://bugs.launchpad.net/bugs/1052449 Title: corosync hangs due to missing pacemaker shutdown scripts To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/pacemaker/+bug/1052449/+subscriptions From james.page at ubuntu.com Wed Oct 25 08:35:38 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 25 Oct 2017 08:35:38 -0000 Subject: [Bug 1727063] Re: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage References: <150887824680.17498.17769190132626371447.malonedeb@wampee.canonical.com> Message-ID: <150892053860.27641.17683812815110330892.malone@soybean.canonical.com> Hmmm - however pacemaker at xenial ships with a native systemd unit; so I'm baffled as to the behaviour of the package upgrade. ** Description changed: - We have found on our openstack charm-hacluster implementations that the - pacemaker .deb packaging along with the upstream pacemaker configuration - result in pacemaker stopping but not starting upon package upgrade - (while attended or unattended). + [Impact] + upgrades of the pacemaker package don't restart pacemaker after the package upgrade, resulting in down HA clusters. + + [Test Case] + sudo apt install pacemaker + sudo systemctl start pacemaker + sudo dpkg-reconfigure pacemaker + + pacemaker daemons will not be restarted. + + [Regression Potential] + TBC as not quite sure where the fix for this is. + + [Original Bug Report] + We have found on our openstack charm-hacluster implementations that the pacemaker .deb packaging along with the upstream pacemaker configuration result in pacemaker stopping but not starting upon package upgrade (while attended or unattended). This was seen on three separate Xenial clouds. Both Mitaka and Ocata. The package upgrade today was to pacemaker 1.1.14-2ubuntu1.2. It appears that pacemaker.prerm stops the service using "invoke-rc.d pacemaker stop" and then the pacemaker.postinst attempts to start the service, but silently fails due to policy denial. It appears the policy check fails because /etc/rcX.d/S*pacemaker does not exist because /etc/init.d/pacemaker has no Default-Start or Default-Stop entries in the LSB init headers. (or rather, they are blank.) I have not checked whether this affects trusty environments. I'd suggest on systems that use systemd, the pacemaker.postinst script should check if the service is enabled and start it with systemctl commands rather than using the cross-platform compatible invoke-rc.d wrappers. Or upstream pacemaker should get default start/stop entries. Our default runlevel on cloud init built images appears to be 5 (graphical), so at least 5 should be present in /etc/init.d/pacemaker LSB init headers under Default-Start:. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to pacemaker in Ubuntu. https://bugs.launchpad.net/bugs/1727063 Title: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage To manage notifications about this bug go to: https://bugs.launchpad.net/charm-hacluster/+bug/1727063/+subscriptions From james.page at ubuntu.com Wed Oct 25 08:44:39 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 25 Oct 2017 08:44:39 -0000 Subject: [Bug 1727063] Re: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage References: <150887824680.17498.17769190132626371447.malonedeb@wampee.canonical.com> Message-ID: <150892108018.17455.12493274633007980481.malone@gac.canonical.com> This issue can be fixed by re-adding the required Start/Stop bits to the LSB header; however the behaviour of update-rc.d when native systemd unit files are in use looks odd to me. Raising an init-system-helpers bug task for foundations team input on this. ** Also affects: init-system-helpers (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to pacemaker in Ubuntu. https://bugs.launchpad.net/bugs/1727063 Title: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage To manage notifications about this bug go to: https://bugs.launchpad.net/charm-hacluster/+bug/1727063/+subscriptions From james.page at ubuntu.com Wed Oct 25 08:57:12 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 25 Oct 2017 08:57:12 -0000 Subject: [Bug 1727063] Re: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage References: <150887824680.17498.17769190132626371447.malonedeb@wampee.canonical.com> Message-ID: <150892183272.27540.5623339837433781933.malone@soybean.canonical.com> Actually this only impacts Xenial; Debian carried a patch from: pacemaker (1.1.15~rc3-1) unstable; urgency=medium [ Christoph Berg ] * [23ee108] libcrmservice3.symbols: Exclude systemd symbol on non-linux * [41dea05] Fix time formatting on x32 * [533c5cc] Fix FTBFS on GNU Hurd [ Arturo Borrero Gonzalez ] * [698053d] d/tests/control: add isolation-container restriction [ Ferenc Wágner ] * [065159d] New patch Enable-the-init-scripts-on-multi-user-runlevels.patch * [7a5008b] New patch Make-the-asciidoc-documentation-reproducible.patch * [08a4162] New patch Add-remote_fs-dependencies-to-the-init-scripts.patch * [7a65d2c] New upstream release (1.1.15~rc1) * [dd9f5f4] Remove upstreamed patches, refresh the rest * [0cdd116] Update symbol files * [3de7a21] New patch Add-documentation-URIs-to-the-service-files.patch * [9faaa02] Move documentation generators into Build-Depends-Indep * [9362a46] Move documentation into /usr/share/doc/pacemaker * [64c0e84] Move misc documentation files into the pacemaker-doc package * [837e74d] New patch Read-default-files-in-pacemaker.service.patch * [72fef80] New upstream release (1.1.15~rc2) * [69ee575] Remove patch included in 1.1.15~rc2 * [46dce98] Also add documentation URI to our version of crm_mon.service * [8c25aff] New patch to avoid using WIFCONTINUED entirely * [a28e0ae] New upstream release (1.1.15~rc3) * [a8976fe] Remove freshly upstreamed patches, refresh the rest -- Ferenc Wágner Sat, 28 May 2016 22:28:49 +0200 Which re-enables the default runlevels. ** Changed in: pacemaker (Ubuntu Bionic) Status: Triaged => Fix Released ** Changed in: pacemaker (Ubuntu Artful) Status: Triaged => Fix Released ** Changed in: pacemaker (Ubuntu Zesty) Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to init-system-helpers in Ubuntu. https://bugs.launchpad.net/bugs/1727063 Title: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage To manage notifications about this bug go to: https://bugs.launchpad.net/charm-hacluster/+bug/1727063/+subscriptions From james.page at ubuntu.com Wed Oct 25 09:05:30 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 25 Oct 2017 09:05:30 -0000 Subject: [Bug 1727063] Re: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage References: <150887824680.17498.17769190132626371447.malonedeb@wampee.canonical.com> Message-ID: <150892233022.17721.2936569812891476677.malone@wampee.canonical.com> Proposed update for xenial ** Patch added: "pacemaker.debdiff" https://bugs.launchpad.net/ubuntu/zesty/+source/pacemaker/+bug/1727063/+attachment/4993845/+files/pacemaker.debdiff -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to pacemaker in Ubuntu. https://bugs.launchpad.net/bugs/1727063 Title: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage To manage notifications about this bug go to: https://bugs.launchpad.net/charm-hacluster/+bug/1727063/+subscriptions From james.page at ubuntu.com Wed Oct 25 09:10:46 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 25 Oct 2017 09:10:46 -0000 Subject: [Bug 1727063] Re: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage References: <150887824680.17498.17769190132626371447.malonedeb@wampee.canonical.com> Message-ID: <150892264627.17764.9746188965381052991.malone@chaenomeles.canonical.com> Doing some testing via: https://launchpad.net/~ci-train-ppa-service/+archive/ubuntu/3010 before upload to xenial-proposed; not that the act of fixing this problem will in itself cause the pacemaker daemons to be started on upgrade. However it won't be auto-applied on a default install (unlike the security update that caused the original issue). -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to pacemaker in Ubuntu. https://bugs.launchpad.net/bugs/1727063 Title: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage To manage notifications about this bug go to: https://bugs.launchpad.net/charm-hacluster/+bug/1727063/+subscriptions From james.page at ubuntu.com Wed Oct 25 09:52:47 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 25 Oct 2017 09:52:47 -0000 Subject: [Bug 1727063] Re: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage References: <150887824680.17498.17769190132626371447.malonedeb@wampee.canonical.com> Message-ID: <150892516765.27683.5767476059907693595.malone@soybean.canonical.com> Tested OK (pacemaker was restarted after upgrade) Uploaded to unapproved queue for SRU Team review - I'd suggest we fasttrack this ASAP into -updates and -security to catch auto updates for those systems not already updated. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to pacemaker in Ubuntu. https://bugs.launchpad.net/bugs/1727063 Title: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage To manage notifications about this bug go to: https://bugs.launchpad.net/charm-hacluster/+bug/1727063/+subscriptions From james.page at ubuntu.com Wed Oct 25 10:04:27 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 25 Oct 2017 10:04:27 -0000 Subject: [Bug 1727063] Re: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage References: <150887824680.17498.17769190132626371447.malonedeb@wampee.canonical.com> Message-ID: <150892586857.27899.13097243076625722472.launchpad@soybean.canonical.com> ** Description changed: [Impact] upgrades of the pacemaker package don't restart pacemaker after the package upgrade, resulting in down HA clusters. [Test Case] sudo apt install pacemaker sudo systemctl start pacemaker sudo dpkg-reconfigure pacemaker pacemaker daemons will not be restarted. [Regression Potential] - TBC as not quite sure where the fix for this is. + Minimal, earlier and later versions provide the defaults in the lsb header. [Original Bug Report] We have found on our openstack charm-hacluster implementations that the pacemaker .deb packaging along with the upstream pacemaker configuration result in pacemaker stopping but not starting upon package upgrade (while attended or unattended). This was seen on three separate Xenial clouds. Both Mitaka and Ocata. The package upgrade today was to pacemaker 1.1.14-2ubuntu1.2. It appears that pacemaker.prerm stops the service using "invoke-rc.d pacemaker stop" and then the pacemaker.postinst attempts to start the service, but silently fails due to policy denial. It appears the policy check fails because /etc/rcX.d/S*pacemaker does not exist because /etc/init.d/pacemaker has no Default-Start or Default-Stop entries in the LSB init headers. (or rather, they are blank.) I have not checked whether this affects trusty environments. I'd suggest on systems that use systemd, the pacemaker.postinst script should check if the service is enabled and start it with systemctl commands rather than using the cross-platform compatible invoke-rc.d wrappers. Or upstream pacemaker should get default start/stop entries. Our default runlevel on cloud init built images appears to be 5 (graphical), so at least 5 should be present in /etc/init.d/pacemaker LSB init headers under Default-Start:. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to init-system-helpers in Ubuntu. https://bugs.launchpad.net/bugs/1727063 Title: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage To manage notifications about this bug go to: https://bugs.launchpad.net/charm-hacluster/+bug/1727063/+subscriptions From james.page at ubuntu.com Wed Oct 25 10:18:06 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 25 Oct 2017 10:18:06 -0000 Subject: [Bug 1727063] Re: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage References: <150887824680.17498.17769190132626371447.malonedeb@wampee.canonical.com> Message-ID: <150892668683.28298.12662640494703687215.malone@soybean.canonical.com> Updates building in: https://launchpad.net/~ubuntu-security-proposed/+archive/ubuntu/ppa -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to pacemaker in Ubuntu. https://bugs.launchpad.net/bugs/1727063 Title: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage To manage notifications about this bug go to: https://bugs.launchpad.net/charm-hacluster/+bug/1727063/+subscriptions From james.page at ubuntu.com Wed Oct 25 10:26:35 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 25 Oct 2017 10:26:35 -0000 Subject: [Bug 1727063] Re: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage References: <150887824680.17498.17769190132626371447.malonedeb@wampee.canonical.com> Message-ID: <150892719583.28263.4862932068948361329.malone@soybean.canonical.com> Testing from security-proposed PPA: Broken install (dpkg-reconfigure pacemaker already run, daemons stopped): Packages updated and pacemaker daemon restarted by postinst: OK Running install (pacemaker daemons running prior to pkg upgrade): Packages update, pacemaker daemon stop prior to unpack and restarted by postinst: OK >From my perspective the update looks good - but would appreciate a second pair of eyes on this one. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to pacemaker in Ubuntu. https://bugs.launchpad.net/bugs/1727063 Title: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage To manage notifications about this bug go to: https://bugs.launchpad.net/charm-hacluster/+bug/1727063/+subscriptions From james.page at ubuntu.com Wed Oct 25 10:31:02 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 25 Oct 2017 10:31:02 -0000 Subject: [Bug 1727063] Re: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage References: <150887824680.17498.17769190132626371447.malonedeb@wampee.canonical.com> Message-ID: <150892746217.28109.12554775972838368150.malone@soybean.canonical.com> Also tested proposed fix on a three unit gnocchi HA deployment; all pacemaker updates applied and restarted pacemaker postinst as desired. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to pacemaker in Ubuntu. https://bugs.launchpad.net/bugs/1727063 Title: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage To manage notifications about this bug go to: https://bugs.launchpad.net/charm-hacluster/+bug/1727063/+subscriptions From james.page at ubuntu.com Wed Oct 25 10:56:38 2017 From: james.page at ubuntu.com (James Page) Date: Wed, 25 Oct 2017 10:56:38 -0000 Subject: [Bug 1727063] Re: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage References: <150887824680.17498.17769190132626371447.malonedeb@wampee.canonical.com> Message-ID: <150892899841.17574.14926831851906187217.malone@wampee.canonical.com> Also validated that the update fixes an existing machine with the 1.2 update on it (with pacemaker services not running). Pacemaker started after the update. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to pacemaker in Ubuntu. https://bugs.launchpad.net/bugs/1727063 Title: Pacemaker package upgrades stop but fail to start pacemaker resulting in HA outage To manage notifications about this bug go to: https://bugs.launchpad.net/charm-hacluster/+bug/1727063/+subscriptions From andreas at canonical.com Wed Oct 25 12:30:00 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Wed, 25 Oct 2017 12:30:00 -0000 Subject: [Bug 1726595] Re: Running Matlab (R) from ssh session with X forwarding doesn't work anymore in 17.10 References: <150879317231.27683.16119704591861460296.malonedeb@soybean.canonical.com> Message-ID: <150893460045.18436.15322380937991436871.malone@chaenomeles.canonical.com> Most curious. It would be of tremendous help if you could find another application that behaves like that, one that is opensource and part of the ubuntu archive preferably. DISPLAY being set to, for example, localhost:10.0, is indicating that the X alls are going through ssh in that particular case. It's setup by the -X parameter. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to openssh in Ubuntu. https://bugs.launchpad.net/bugs/1726595 Title: Running Matlab (R) from ssh session with X forwarding doesn't work anymore in 17.10 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/1726595/+subscriptions From andreas at canonical.com Wed Oct 25 14:41:56 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Wed, 25 Oct 2017 14:41:56 -0000 Subject: [Bug 1726595] Re: Running Matlab (R) from ssh session with X forwarding doesn't work anymore in 17.10 References: <150879317231.27683.16119704591861460296.malonedeb@soybean.canonical.com> <150894110202.17463.17861974732205753755.malone@wampee.canonical.com> Message-ID: Ah, Java, I hadn't realised that. I have a couple a I can try too with ssh -X. On Oct 25, 2017 12:31, "thomas duriez" <1726595 at bugs.launchpad.net> wrote: > I will try. For the moment I double boot 16.04 because I need to have it > working, but I can run tests on spare time. Because I couldn't find > problems when not running the java machine of Matlab I will focus on > applications relying heavily on java. If you have any suggestion it > would help. Thanks again for your time. > > -- > You received this bug notification because you are subscribed to the bug > report. > https://bugs.launchpad.net/bugs/1726595 > > Title: > Running Matlab (R) from ssh session with X forwarding doesn't work > anymore in 17.10 > > To manage notifications about this bug go to: > https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/ > 1726595/+subscriptions > -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to openssh in Ubuntu. https://bugs.launchpad.net/bugs/1726595 Title: Running Matlab (R) from ssh session with X forwarding doesn't work anymore in 17.10 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/1726595/+subscriptions From corey.bryant at canonical.com Wed Oct 25 18:40:41 2017 From: corey.bryant at canonical.com (Corey Bryant) Date: Wed, 25 Oct 2017 18:40:41 -0000 Subject: [Bug 1720397] Update Released References: <150669833185.21053.13738921475958605908.malonedeb@chaenomeles.canonical.com> Message-ID: <150895684207.18248.10455963824626173437.malone@chaenomeles.canonical.com> The verification of the Stable Release Update for qemu has completed successfully and the package has now been released to -updates. In the event that you encounter a regression using the package from -updates please report a new bug using ubuntu-bug and tag the bug report regression-update so we can easily find any regressions. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to qemu in Ubuntu. https://bugs.launchpad.net/bugs/1720397 Title: qemu-kvm doesnt restart after node reboot To manage notifications about this bug go to: https://bugs.launchpad.net/cloud-archive/+bug/1720397/+subscriptions From corey.bryant at canonical.com Wed Oct 25 18:40:44 2017 From: corey.bryant at canonical.com (Corey Bryant) Date: Wed, 25 Oct 2017 18:40:44 -0000 Subject: [Bug 1720397] Re: qemu-kvm doesnt restart after node reboot References: <150669833185.21053.13738921475958605908.malonedeb@chaenomeles.canonical.com> Message-ID: <150895684496.17076.12427739026625952593.malone@wampee.canonical.com> This bug was fixed in the package qemu - 1:2.10+dfsg-0ubuntu3~cloud0 --------------- qemu (1:2.10+dfsg-0ubuntu3~cloud0) xenial-pike; urgency=medium . * New update for the Ubuntu Cloud Archive. . qemu (1:2.10+dfsg-0ubuntu3) artful; urgency=medium . * fix enablement of qemu-kvm service (LP: #1720397) - rename d/qemu-kvm.service to d/qemu-system-common.qemu-kvm.service - d/rules: add proper enablement debhelper calls - d/qemu-system-common.install: install covered by dh_installinit ** Changed in: cloud-archive/pike Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to qemu in Ubuntu. https://bugs.launchpad.net/bugs/1720397 Title: qemu-kvm doesnt restart after node reboot To manage notifications about this bug go to: https://bugs.launchpad.net/cloud-archive/+bug/1720397/+subscriptions From corey.bryant at canonical.com Wed Oct 25 18:38:33 2017 From: corey.bryant at canonical.com (Corey Bryant) Date: Wed, 25 Oct 2017 18:38:33 -0000 Subject: [Bug 1718668] Re: Libvirt FTBFS in Artful on x86 References: <150599963491.29596.1144297357269709061.malonedeb@gac.canonical.com> Message-ID: <150895671332.17463.2071377899401825642.malone@wampee.canonical.com> This bug was fixed in the package libvirt - 3.6.0-1ubuntu5~cloud0 --------------- libvirt (3.6.0-1ubuntu5~cloud0) xenial-pike; urgency=medium . * New update for the Ubuntu Cloud Archive. . libvirt (3.6.0-1ubuntu5) artful; urgency=medium . * d/p/u/gnulib-getopt-posix-Fix-build-failure-when-using-ac_cv_head.patch: fix FTBFS with glibc 2.26 (LP: #1718668) ** Changed in: cloud-archive/pike Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libvirt in Ubuntu. https://bugs.launchpad.net/bugs/1718668 Title: Libvirt FTBFS in Artful on x86 To manage notifications about this bug go to: https://bugs.launchpad.net/cloud-archive/+bug/1718668/+subscriptions From corey.bryant at canonical.com Wed Oct 25 18:56:58 2017 From: corey.bryant at canonical.com (Corey Bryant) Date: Wed, 25 Oct 2017 18:56:58 -0000 Subject: [Bug 1720397] Re: qemu-kvm doesnt restart after node reboot References: <150669833185.21053.13738921475958605908.malonedeb@chaenomeles.canonical.com> Message-ID: <150895781834.18511.12728896682053542636.malone@chaenomeles.canonical.com> Regression testing with OpenStack tempest for Ocata has completed successfully. xenial-ocata proposed stable charms: ====== Totals ====== Ran: 102 tests in 1742.1837 sec. - Passed: 93 - Skipped: 9 - Expected Fail: 0 - Unexpected Success: 0 - Failed: 0 Sum of execute time for each test: 856.3288 sec. xenial-ocata proposed dev charms: ====== Totals ====== Ran: 102 tests in 1987.3271 sec. - Passed: 93 - Skipped: 9 - Expected Fail: 0 - Unexpected Success: 0 - Failed: 0 Sum of execute time for each test: 1008.6304 sec. zesty-ocata proposed stable charms: ====== Totals ====== Ran: 102 tests in 1604.2247 sec. - Passed: 93 - Skipped: 9 - Expected Fail: 0 - Unexpected Success: 0 - Failed: 0 Sum of execute time for each test: 843.3645 sec. zesty-ocata proposed dev charms: ====== Totals ====== Ran: 102 tests in 1579.9423 sec. - Passed: 93 - Skipped: 9 - Expected Fail: 0 - Unexpected Success: 0 - Failed: 0 Sum of execute time for each test: 867.0801 sec. -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to qemu in Ubuntu. https://bugs.launchpad.net/bugs/1720397 Title: qemu-kvm doesnt restart after node reboot To manage notifications about this bug go to: https://bugs.launchpad.net/cloud-archive/+bug/1720397/+subscriptions From corey.bryant at canonical.com Thu Oct 26 19:00:46 2017 From: corey.bryant at canonical.com (Corey Bryant) Date: Thu, 26 Oct 2017 19:00:46 -0000 Subject: [Bug 1726804] Re: rules for images on attach-device not containing lock permission References: <150884171868.18353.2181453992737847445.malonedeb@chaenomeles.canonical.com> Message-ID: <150904444676.9399.12955937171574434970.launchpad@wampee.canonical.com> ** Also affects: cloud-archive/pike Importance: Undecided Status: New ** Changed in: cloud-archive/pike Status: New => Triaged ** Changed in: cloud-archive Status: New => Triaged ** Changed in: cloud-archive/pike Importance: Undecided => Critical ** Changed in: cloud-archive Importance: Undecided => Critical ** Also affects: cloud-archive/queens Importance: Critical Status: Triaged -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libvirt in Ubuntu. https://bugs.launchpad.net/bugs/1726804 Title: rules for images on attach-device not containing lock permission To manage notifications about this bug go to: https://bugs.launchpad.net/cloud-archive/+bug/1726804/+subscriptions From corey.bryant at canonical.com Thu Oct 26 19:28:46 2017 From: corey.bryant at canonical.com (Corey Bryant) Date: Thu, 26 Oct 2017 19:28:46 -0000 Subject: [Bug 1715254] Re: nova-novncproxy process gets wedged, requiring kill -HUP References: <150465233858.18943.6161632660361862640.malonedeb@chaenomeles.canonical.com> Message-ID: <150904612696.20092.4149619152687269216.malone@soybean.canonical.com> Thanks for the patches Seyeong. Assuming those fix the problem this only affects websockify < 0.8.0, which are releases prior to Yakkety/Newton. ** Also affects: cloud-archive/kilo Importance: Undecided Status: New ** Also affects: cloud-archive/icehouse Importance: Undecided Status: New ** Also affects: cloud-archive/mitaka Importance: Undecided Status: New ** Changed in: cloud-archive/kilo Status: New => Triaged ** Changed in: cloud-archive/icehouse Status: New => Triaged ** Changed in: cloud-archive/icehouse Importance: Undecided => Medium ** Changed in: cloud-archive/kilo Importance: Undecided => Medium ** Changed in: cloud-archive/mitaka Importance: Undecided => Medium ** Changed in: cloud-archive Status: New => Invalid ** Changed in: cloud-archive/mitaka Status: New => Triaged ** Also affects: websockify (Ubuntu Trusty) Importance: Undecided Status: New ** Also affects: websockify (Ubuntu Xenial) Importance: Undecided Status: New ** Changed in: websockify (Ubuntu Trusty) Status: New => Triaged ** Changed in: websockify (Ubuntu Xenial) Status: New => Triaged ** Changed in: websockify (Ubuntu Trusty) Importance: Undecided => Medium ** Changed in: websockify (Ubuntu Xenial) Importance: Undecided => Medium ** Changed in: websockify (Ubuntu Trusty) Assignee: (unassigned) => Seyeong Kim (xtrusia) ** Changed in: websockify (Ubuntu Xenial) Assignee: (unassigned) => Seyeong Kim (xtrusia) ** Changed in: websockify (Ubuntu) Status: Confirmed => Invalid ** Changed in: websockify (Ubuntu) Assignee: Seyeong Kim (xtrusia) => (unassigned) ** Changed in: websockify (Ubuntu) Importance: Medium => Undecided -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to websockify in Ubuntu. https://bugs.launchpad.net/bugs/1715254 Title: nova-novncproxy process gets wedged, requiring kill -HUP To manage notifications about this bug go to: https://bugs.launchpad.net/charm-nova-cloud-controller/+bug/1715254/+subscriptions From andreas at canonical.com Thu Oct 26 20:13:45 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Thu, 26 Oct 2017 20:13:45 -0000 Subject: [Bug 1727688] Re: package samba 2:4.3.11+dfsg-0ubuntu0.16.04.11 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1 References: <150901592273.17022.6499593252421173625.malonedeb@wampee.canonical.com> Message-ID: <150904882519.3948.3140098213985471807.malone@gac.canonical.com> Thanks for filing this bug in Ubuntu. The smbd service from Samba indeed failed to start, but the logs don't tell us why. Could you please attach the following to this bug report: - /etc/samba/smb.conf - /var/log/samba/log*, i.e., all files in /var/log/samba that start with "log" Thanks! ** Changed in: samba (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to samba in Ubuntu. https://bugs.launchpad.net/bugs/1727688 Title: package samba 2:4.3.11+dfsg-0ubuntu0.16.04.11 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1727688/+subscriptions From andreas at canonical.com Thu Oct 26 20:34:27 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Thu, 26 Oct 2017 20:34:27 -0000 Subject: [Bug 1726595] Re: Running Matlab (R) from ssh session with X forwarding doesn't work anymore in 17.10 References: <150879317231.27683.16119704591861460296.malonedeb@soybean.canonical.com> Message-ID: <150905006753.9276.5085487735918557302.malone@wampee.canonical.com> Interesting: Exception in thread "AWT-EventQueue-1" com.jogamp.opengl.GLException: Caught GLException: AWT-EventQueue-1: createImpl ARB n/a but required, profile > GL2 requested (OpenGL >= 3.1). Requested: GLProfile[GL3bc/GL3bc.sw], current: 3.0 (Compat profile, compat[ES2], FBO, software) - 3.0 Mesa 17.2.2 So something to do with opengl over remote X11 connections. I'll switch the bug over to wayland, and maybe add a xorg task ** Package changed: openssh (Ubuntu) => wayland (Ubuntu) ** Changed in: wayland (Ubuntu) Status: Incomplete => New -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to openssh in Ubuntu. https://bugs.launchpad.net/bugs/1726595 Title: Running Matlab (R) from ssh session with X forwarding doesn't work anymore in 17.10 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/wayland/+bug/1726595/+subscriptions From andreas at canonical.com Fri Oct 27 12:26:31 2017 From: andreas at canonical.com (Andreas Hasenack) Date: Fri, 27 Oct 2017 12:26:31 -0000 Subject: [Bug 1423498] Re: FTP upload causes squid hang References: <20150219102539.20724.23398.malonedeb@wampee.canonical.com> Message-ID: <150910719129.8592.4250418779169312789.malone@wampee.canonical.com> Trusty verification Confirming the problem with 3.3.8-1ubuntu6.9 Version table: *** 3.3.8-1ubuntu6.9 0 500 http://br.archive.ubuntu.com/ubuntu/ trusty-updates/main amd64 Packages ubuntu at trusty-squid-ftp-upload-1423498:~$ echo -e "ubuntu\nubuntu" | sudo passwd ubuntu Enter new UNIX password: Retype new UNIX password: passwd: password updated successfully ubuntu at trusty-squid-ftp-upload-1423498:~$ truncate -s 0 /tmp/zero ubuntu at trusty-squid-ftp-upload-1423498:~$ ftp_proxy=http://localhost:3128/ curl --upload-file /tmp/zero ftp://ubuntu:ubuntu at localhost/ % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0 curl: (52) Empty reply from server ubuntu at trusty-squid-ftp-upload-1423498:~$ sudo grep assertion /var/log/squid3/cache.log 2017/10/27 12:21:38| assertion failed: Server.cc:244: "r->body_pipe != NULL" Installing the package from proposed: Version table: *** 3.3.8-1ubuntu6.10 0 500 http://br.archive.ubuntu.com/ubuntu/ trusty-proposed/main amd64 Packages ubuntu at trusty-squid-ftp-upload-1423498:~$ ftp_proxy=http://localhost:3128/ curl --upload-file /tmp/zero ftp://ubuntu:ubuntu at localhost/ % Total % Received % Xferd Average Speed Time Time Time Current Dload Upload Total Spent Left Speed 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0 FTP PUT Successful.