-
Tue Oct 13 2015 Thomas Tanaka <thomas.tanaka@oracle.com> - 1.0.7-2.0.12
- [Orabug 22011867] ol6 ct shutdown script remounts /dev/pts/* devices as
ro on host system.
-
Wed Sep 30 2015 Thomas Tanaka <thomas.tanaka@oracle.com> - 1.0.7-2.0.11
- [Orabug 21842483] failed to create directory '/RUN/LXC/LOCK//CONTAINER/OL7.1/SNAPS'
- CVE-2015-1335: Protect container mounts against symlinks.
- Fixed build failure on OL6.
-
Thu Sep 17 2015 Thomas Tanaka <thomas.tanaka@oracle.com> - 1.0.7-2.0.10
- [Orabug 21684132] Support for abrupt reboot.
-
Thu Aug 13 2015 Thomas Tanaka <thomas.tanaka@oracle.com> - 1.0.7-2.0.8
- [Orabug 21603129] mount /proc/sys/kernel/msgmni as r/w in container
- [Orabug 21418260] using OL6/7 OVM templates to create container
- Includes the lxc-lib dependency when upgrading LXC.
-
Thu Jul 30 2015 Thomas Tanaka <thomas.tanaka@oracle.com> - 1.0.7-2.0.7
- [Orabug 21533491] CVE-2015-1334: Don't use the container's /proc during
attach
-
Wed Jul 29 2015 Thomas Tanaka <thomas.tanaka@oracle.com> - 1.0.7-2.0.6
- [Orabug 21526922] CVE-2015-1331: LXCLOCK: USE /RUN/LXC/LOCK RATHER THAN
/RUN/LOCK/LXC
-
Mon Jun 22 2015 Thomas Tanaka <thomas.tanaka@oracle.com> - 1.0.7-2.0.5
- [Orabug 21267882] Make some of the global parameters as read-only inside
the container.
-
Mon Jun 15 2015 Thomas Tanaka <thomas.tanaka@oracle.com> - 1.0.7-2.0.4
- [Orabug 21233392] Oracle Linux Container enhancement. We are introducing
3 enhancements (introducing --privileged flag for lxc-oracle, new
configuration file for more privileged lxc use case and dynamic RT
management script).
-
Tue Feb 10 2015 Dwight Engen <dwight.engen@oracle.com> - 1.0.7-2.0.3
- [Orabug 20465908] Go ahead and backport upstream commit 18aa217b.
The symlink workaround was too hackish. With this change, the lock
file names in /run/lock/lxc/container change from <name> to .<name>
but snapshots need <name> to now be a directory so we remove any
old lock files that might be there in %post.
-
Wed Feb 04 2015 Dwight Engen <dwight.engen@oracle.com> - 1.0.7-2.0.2
- [Orabug 20465908] Introduce a workaround for creating btrfs snapshots
by symlinking /containersnaps to a dir in /container. Snapshots will
thus be created in the same btrfs. The real fix is upstream commit
18aa217b, but that is too invasive to backport to 1.0.x.