Thursday, 2022-03-03

kata-irc-bot<fidencio> @eric.ernst, @samuel.ortiz, @wllenyj, @bergwolf, @steven, @archana.m.shinde, about the containerd version used for the "-rc0" and how it impacts the CC branch :thread:  Folks, I *think* the containerd version could be bumped to its 1.6.1 release (currently on 1.6.0-beta4) before we cut "-rc0".  However, doing this bump *might* after the CC branch as it did in the past, so it'd be good to sync with folks working there (and that's the13:55
kata-irc-botreason I'm CC'ing here Wang Lei and Steve Horseman). What's the best way to proceed with this?  Wang, would you have some time to try to rebase the current work on 1.6.1 and, if that goes well, then we can go ahead and try to bump that on the `main` side?  Archana, Eric, Samuel, Tao, any idea / opinion, strong or not, on this?13:55
kata-irc-bot<fidencio> Folks, I *think* the containerd version could be bumped to its 1.6.1 release (currently on 1.6.0-beta4) before we cut "-rc0".  However, doing this bump *might* after the CC branch as it did in the past, so it'd be good to sync with folks working there (and that's the reason I'm CC'ing here Wang Lei and Steve Horseman). What's the best way to proceed with this?  Wang, would you have some time to try to rebase the current work on 1.6.113:56
kata-irc-botand, if that goes well, then we can go ahead and try to bump that on the `main` side?  Archana, Eric, Samuel, Tao, any idea / opinion, strong or not, on this?13:56
kata-irc-bot<samuel.ortiz> Thanks for taking that initiative @fidencio I agree it would be good to sync and use the same version for main and CC.13:59
kata-irc-bot<wllenyj> Has 1.6.1 released? Ok, I will do it soon14:14
kata-irc-bot<fidencio> It was released Yesterda / Today. :slightly_smiling_face:14:22
kata-irc-bot<eric.ernst> [offtopic] Woa, beta feature in GitHub for "File Tree" when reviewing PRs is super helpful, especially with some of the larger PRs we currently have.15:54
kata-irc-bot<fidencio> I have opened https://github.com/kata-containers/kata-containers/pull/3822 and set the label to `do-not-merge` , as a way to see if the bump goes smooth on our side.  Once @wllenyj has his rebased sorted out, this PR can then be reviewed and merged.16:51
kata-irc-bot<wllenyj> I have make a pr https://github.com/confidential-containers/containerd/pull/319:23
kata-irc-bot<zkaiser> Hook is found ^^21:28
kata-irc-bot<zkaiser> ```Mar 03 13:08:23 r750-206 kata[1784272]: time="2022-03-03T13:08:23.566327155-08:00" level=debug msg="reading guest console" console-protocol=unix console-url=/run/vc/vm/test-kata/console.sock name=containerd-shim-v2 pid=1784272 sandbox=test-kata source=virtcontainers subsystem=sandbox vmconsole="{\"msg\":\"receive createcontainer, spec: Spec { version: \\\"1.0.2-dev\\\", process: Some(Process { terminal: true, console_size: None, user:21:28
kata-irc-botUser { uid: 0, gid: 0, additional_gids: [], username: \\\"\\\" }, args: [\\\"printenv\\\"], env: [\\\"PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin\\\", \\\"NVIDIA_DRIVER_CAPABILITIES=compute,utility\\\", \\\"TERM=xterm\\\"], cwd: \\\"/\\\", capabilities: Some(LinuxCapabilities { bounding: [\\\"CAP_CHOWN\\\", \\\"CAP_DAC_OVERRIDE\\\", \\\"CAP_FSETID\\\", \\\"CAP_FOWNER\\\", \\\"CAP_MKNOD\\\", \\\"CAP_NET_RAW\\\",21:28
kata-irc-bot\\\"CAP_SETGID\\\", \\\"CAP_SETUID\\\", \\\"CAP_SETFCAP\\\", \\\"CAP_SETPCAP\\\", \\\"CAP_NET_BIND_SERVICE\\\", \\\"CAP_SYS_CHROOT\\\", \\\"CAP_KILL\\\", \\\"CAP_AUDIT_WRITE\\\"], effective: [\\\"CAP_CHOWN\\\", \\\"CAP_DAC_OVERRIDE\\\", \\\"CAP_FSETID\\\", \\\"CAP_FOWNER\\\", \\\"CAP_MKNOD\\\", \\\"CAP_NET_RAW\\\", \\\"CAP_SETGID\\\", \\\"CAP_SETUID\\\", \\\"CAP_SETFCAP\\\", \\\"CAP_SETPCAP\\\", \\\"CAP_NET_BIND_SERVICE\\\",21:28
kata-irc-bot\\\"CAP_SYS_CHROOT\\\", \\\"CAP_KILL\\\", \\\"CAP_AUDIT_WRITE\\\"], inheritable: [\\\"CAP_CHOWN\\\", \\\"CAP_DAC_OVERRIDE\\\", \\\"CAP_FSETID\\\", \\\"CAP_FOWNER\\\", \\\"CAP_MKNOD\\\", \\\"CAP_NET_RAW\\\", \\\"CAP_SETGID\\\", \\\"CAP_SETUID\\\", \\\"CAP_SETFCAP\\\", \\\"CAP_SETPCAP\\\", \\\"CAP_NET_BIND_SERVICE\\\", \\\"CAP_SYS_CHROOT\\\", \\\"CAP_KILL\\\", \\\"CAP_AUDIT_WRITE\\\"], permitted: [\\\"CAP_CHOWN\\\", \\\"CAP_DAC_OVERRIDE\\\",21:28
kata-irc-bot\\\"CAP_FSETID\\\", \\\"CAP_FOWNER\\\", \\\"CAP_MKNOD\\\", \\\"CAP_NET_RAW\\\", \\\"CAP_SETGID\\\", \\\"CAP_SETUID\\\", \\\"CAP_SETFCAP\\\", \\\"CAP_SETPCAP\\\", \\\"CAP_NET_BIND_SERVICE\\\", \\\"CAP_SYS_CHROOT\\\", \\\"CAP_KILL\\\", \\\"CAP_AUDIT_WRITE\\\"], ambient: [] }), rlimits: [PosixRlimit { type: \\\"RLIMIT_NOFILE\\\", hard: 1024, soft: 1024 }], no_new_privileges: true, apparmor_profile: \\\"\\\", oom_score_adj: Some(0), selinux_label:21:28
kata-irc-bot\\\"\\\" }), root: Some(Root { path: \\\"/run/kata-containers/shared/containers/test-kata/rootfs\\\", readonly: false }), hostname: \\\"\\\", mounts: [Mount { destination: \\\"/proc\\\", type: \\\"proc\\\", source: \\\"proc\\\", options: [\\\"nosuid\\\", \\\"noexec\\\", \\\"nodev\\\"] }, Mount { destination: \\\"/dev\\\", type: \\\"tmpfs\\\", source: \\\"tmpfs\\\", options: [\\\"nosuid\\\", \\\"strictatime\\\", \\\"mode=755\\\",21:28
kata-irc-bot\\\"size=65536k\\\"] }, Mount { destination: \\\"/dev/pts\\\", type: \\\"devpts\\\", source: \\\"devpts\\\", options: [\\\"nosuid\\\", \\\"noexec\\\", \\\"newinstance\\\", \\\"ptmxmode=0666\\\", \\\"mode=0620\\\", \\\"gid=5\\\"] }, Mount { destination: \\\"/dev/shm\\\", type: \\\"bind\\\", source: \\\"/run/kata-containers/sandbox/shm\\\", options: [\\\"rbind\\\"] }, Mount { destination: \\\"/dev/mqueue\\\", type: \\\"mqueue\\\", source:21:28
kata-irc-bot\\\"mqueue\\\", options: [\\\"nosuid\\\", \\\"noexec\\\", \\\"nodev\\\"] }, Mount { destination: \\\"/sys\\\", type: \\\"sysfs\\\", source: \\\"sysfs\\\", options: [\\\"nosuid\\\", \\\"noexec\\\", \\\"nodev\\\", \\\"ro\\\"] }, Mount { destination: \\\"/run\\\", type: \\\"tmpfs\\\", source: \\\"tmpfs\\\", options: [\\\"nosuid\\\", \\\"strictatime\\\", \\\"mode=755\\\", \\\"size=65536k\\\"] }], hooks: None, annotations: {}, linux: Some(Linux {21:28
kata-irc-botuid_mappings: [], gid_mappings: [], sysctl: {}, resources: Some(LinuxResources { devices: [], memory: None, cpu: None, pids: None, block_io: None, hugepage_limits: [], network: None, rdma: {} }), cgroups_path: \\\"/default/test-kata\\\", namespaces: [LinuxNamespace { type: \\\"ipc\\\", path: \\\"\\\" }, LinuxNamespace { type: \\\"uts\\\", path: \\\"\\\" }, LinuxNamespace { type: \\\"mount\\\", path: \\\"\\\" }], devices: [], seccomp: None,21:28
kata-irc-botrootfs_propagation: \\\"\\\", masked_paths: [\\\"/proc/acpi\\\", \\\"/proc/asound\\\", \\\"/proc/kcore\\\", \\\"/proc/keys\\\", \\\"/proc/latency_stats\\\", \\\"/proc/timer_list\\\", \\\"/proc/timer_stats\\\", \\\"/proc/sched_debug\\\", \\\"/sys/firmware\\\", \\\"/proc/scsi\\\"], readonly_paths: [\\\"/proc/bus\\\", \\\"/proc/fs\\\", \\\"/proc/irq\\\", \\\"/proc/sys\\\", \\\"/proc/sysrq-trigger\\\"], mount_label: \\\"\\\", intel_rdt: None }),21:28
kata-irc-botsolaris: None, windows: None, vm: None }\",\"level\":\"INFO\",\"ts\":\"2022-03-03T21:08:23.557717312+00:00\",\"name\":\"kata-agent\",\"source\":\"agent\",\"subsystem\":\"rpc\",\"pid\":\"82\",\"version\":\"0.1.0\"}"``` But the container spec is missing the prestart hook section. Did I miss something to enable?21:28
kata-irc-bot<zkaiser> ```$ kata-runtime version kata-runtime  : 2.3.2    commit   : 1af292c9e693e9bc8e8324a9eb860dad45306fb5    OCI specs: 1.0.2-dev``` 21:29

Generated by irclog2html.py 2.17.3 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!