<p dir="ltr">Hi Igor</p>
<p dir="ltr">It does not matter really. Both ways will do.</p>
<p dir="ltr">However I have a question. As I understand the config is changed at creation or start. Should it be changed at upgrade time too to make sure the next start is safe? Or is it changed before it is a security hazard?</p>
<p dir="ltr">/Ola</p>
<p dir="ltr">Sent from a phone</p>
<div class="gmail_quote">Den 3 sep 2015 12:37 skrev &quot;Igor Bazhitov&quot; &lt;<a href="mailto:ibazhitov@odin.com">ibazhitov@odin.com</a>&gt;:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi, Ola.<br>
<br>
There are 4 patches in the original fix - 2 of them making various<br>
preparations and the other 2 do the actual fix. Do you need them ported<br>
to vzctl-4.8 as is, or as one big cumulative patch?<br>
<br>
WBR, Igor Bazhitov.<br>
<br>
01.09.2015 00:22, Ola Lundqvist writes:<br>
&gt; Privet Kir and Igor<br>
&gt;<br>
&gt; Sources and patches here:<br>
&gt; <a href="ftp://ftp.debian.org/debian/pool/main/v/vzctl/" rel="noreferrer" target="_blank">ftp://ftp.debian.org/debian/pool/main/v/vzctl/</a><br>
&gt;<br>
&gt; Source is named .orig.tar.gz<br>
&gt; and the patches are either in .diff.gz or packaged in .debian.tar.gz<br>
&gt;<br>
&gt; I think we should at least backport 4.8 (current stable) and then maybe<br>
&gt; oldstable 3.0.30. 3.0.24 is oldold stable so I guess you can skip that.<br>
&gt;<br>
&gt; Thanks in advance<br>
&gt;<br>
&gt; // Ola<br>
&gt;<br>
&gt; On Mon, Aug 31, 2015 at 11:17 PM, Kir Kolyshkin &lt;<a href="mailto:kir@odin.com">kir@odin.com</a><br>
&gt; &lt;mailto:<a href="mailto:kir@odin.com">kir@odin.com</a>&gt;&gt; wrote:<br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt;     On 08/31/2015 12:15 PM, Ola Lundqvist wrote:<br>
&gt;&gt;     I was. :-) Thanks!<br>
&gt;&gt;<br>
&gt;&gt;     Will look into this shortly. Will also look into backporting the fix.<br>
&gt;<br>
&gt;     Ola,<br>
&gt;<br>
&gt;     I think Igor (in Cc) will be able to provide the fix backported,<br>
&gt;     just let us know which version do you have in Debian (and a link<br>
&gt;     to sources, as I guess you have some patches in there, too).<br>
&gt;<br>
&gt;     Kir.<br>
&gt;<br>
&gt;<br>
&gt;&gt;<br>
&gt;&gt;     // Ola<br>
&gt;&gt;<br>
&gt;&gt;     On Mon, Aug 31, 2015 at 8:47 PM, Kir Kolyshkin &lt;<a href="mailto:kir@openvz.org">kir@openvz.org</a><br>
&gt;&gt;     &lt;mailto:<a href="mailto:kir@openvz.org">kir@openvz.org</a>&gt;&gt; wrote:<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;         On 08/26/2015 01:26 AM, Sergey Bronnikov wrote:<br>
&gt;&gt;<br>
&gt;&gt;             Hi<br>
&gt;&gt;<br>
&gt;&gt;             On 23:19 Tue 25 Aug , Ola Lundqvist wrote:<br>
&gt;&gt;<br>
&gt;&gt;                 Hi again<br>
&gt;&gt;<br>
&gt;&gt;                 Also I can not find where to download the software<br>
&gt;&gt;                 (neither binaries nor<br>
&gt;&gt;                 sources). Is it only available in git?<br>
&gt;&gt;<br>
&gt;&gt;             It is not so difficult to find sources.<br>
&gt;&gt;             We have one git repo for openvz sources -<br>
&gt;&gt;             <a href="http://src.openvz.org" rel="noreferrer" target="_blank">src.openvz.org</a> &lt;<a href="http://src.openvz.org" rel="noreferrer" target="_blank">http://src.openvz.org</a>&gt;.<br>
&gt;&gt;             vzctl sources are here<br>
&gt;&gt;             <a href="https://src.openvz.org/projects/OVZL/repos/vzctl/browse" rel="noreferrer" target="_blank">https://src.openvz.org/projects/OVZL/repos/vzctl/browse</a><br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;         Ola is probably asking about the source tarball. It&#39;s here:<br>
&gt;&gt;         <a href="http://download.openvz.org/utils/vzctl/4.9.4/src/vzctl-4.9.4.tar.bz2" rel="noreferrer" target="_blank">http://download.openvz.org/utils/vzctl/4.9.4/src/vzctl-4.9.4.tar.bz2</a><br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;                 Cheers<br>
&gt;&gt;<br>
&gt;&gt;                 // Ola<br>
&gt;&gt;<br>
&gt;&gt;                 On Tue, Aug 25, 2015 at 11:15 PM, Ola Lundqvist<br>
&gt;&gt;                 &lt;&lt;mailto:<a href="mailto:ola@inguza.com">ola@inguza.com</a>&gt;<a href="mailto:ola@inguza.com">ola@inguza.com</a><br>
&gt;&gt;                 &lt;mailto:<a href="mailto:ola@inguza.com">ola@inguza.com</a>&gt;&gt; wrote:<br>
&gt;&gt;<br>
&gt;&gt;                     Hi Sergey<br>
&gt;&gt;<br>
&gt;&gt;                     How serious should we consider this problem?<br>
&gt;&gt;                     Should I ask the Debian<br>
&gt;&gt;                     security team (Debian do not accept new revisions,<br>
&gt;&gt;                     just backports for<br>
&gt;&gt;                     security fixes to their stable releases) to<br>
&gt;&gt;                     backport this correction to the<br>
&gt;&gt;                     current vzctl stable package?<br>
&gt;&gt;<br>
&gt;&gt;                     In the meantime I&#39;ll build this 4.9.4 for debian<br>
&gt;&gt;                     unstable and also upload<br>
&gt;&gt;                     to the openvz download directory. First testing<br>
&gt;&gt;                     and then after a few days<br>
&gt;&gt;                     to the wheezy and jessie stable targets.<br>
&gt;&gt;<br>
&gt;&gt;                     Regards,<br>
&gt;&gt;<br>
&gt;&gt;                     // Ola<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;                     On Tue, Aug 25, 2015 at 2:32 PM, Sergey Bronnikov<br>
&gt;&gt;                     &lt;<a href="mailto:sergeyb@openvz.org">sergeyb@openvz.org</a> &lt;mailto:<a href="mailto:sergeyb@openvz.org">sergeyb@openvz.org</a>&gt;&gt;<br>
&gt;&gt;                     wrote:<br>
&gt;&gt;<br>
&gt;&gt;                         OpenVZ project has released a new vzctl update<br>
&gt;&gt;                         for legacy OpenVZ.<br>
&gt;&gt;                         Read below for more information. Everybody is<br>
&gt;&gt;                         advised to upgrade.<br>
&gt;&gt;<br>
&gt;&gt;                         Changes<br>
&gt;&gt;                         =======<br>
&gt;&gt;                         * store VE layout to VE config on start<br>
&gt;&gt;                         * store VE layout in VE config during create<br>
&gt;&gt;                         and convert<br>
&gt;&gt;<br>
&gt;&gt;                         See full changelog here:<br>
&gt;&gt;                         <a href="https://src.openvz.org/projects/OVZL/repos/vzctl/commits" rel="noreferrer" target="_blank">https://src.openvz.org/projects/OVZL/repos/vzctl/commits</a><br>
&gt;&gt;<br>
&gt;&gt;                         Download<br>
&gt;&gt;                         ========<br>
&gt;&gt;                         <a href="http://wiki.openvz.org/Download/vzctl/4.9.4" rel="noreferrer" target="_blank">http://wiki.openvz.org/Download/vzctl/4.9.4</a><br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;                         Thanks<br>
&gt;&gt;                         ======<br>
&gt;&gt;                         OpenVZ project would like to thank the<br>
&gt;&gt;                         RACK911LABS for discovering this<br>
&gt;&gt;                         bug and<br>
&gt;&gt;                         providing the attack scenario.<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;                         Bug reporting<br>
&gt;&gt;                         =============<br>
&gt;&gt;                         Please report all bugs found to<br>
&gt;&gt;                         &lt;<a href="https://bugs.openvz.org/" rel="noreferrer" target="_blank">https://bugs.openvz.org/</a>&gt;<a href="https://bugs.openvz.org/" rel="noreferrer" target="_blank">https://bugs.openvz.org/</a><br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;                         Other sources of info on updates<br>
&gt;&gt;                         ================================<br>
&gt;&gt;                         See <a href="http://planet.openvz.org/" rel="noreferrer" target="_blank">http://planet.openvz.org/</a> to view all the<br>
&gt;&gt;                         news (including updates)<br>
&gt;&gt;                         online.<br>
&gt;&gt;                         There you can also find RSS/Atom feed links.<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;                         Regards,<br>
&gt;&gt;                              OpenVZ team<br>
&gt;&gt;                         _______________________________________________<br>
&gt;&gt;                         Announce mailing list<br>
&gt;&gt;                         <a href="mailto:Announce@openvz.org">Announce@openvz.org</a> &lt;mailto:<a href="mailto:Announce@openvz.org">Announce@openvz.org</a>&gt;<br>
&gt;&gt;                         <a href="https://lists.openvz.org/mailman/listinfo/announce" rel="noreferrer" target="_blank">https://lists.openvz.org/mailman/listinfo/announce</a><br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;                     --<br>
&gt;&gt;                       --- Inguza Technology AB --- MSc in Information<br>
&gt;&gt;                     Technology ----<br>
&gt;&gt;                     /  <a href="mailto:ola@inguza.com">ola@inguza.com</a> &lt;mailto:<a href="mailto:ola@inguza.com">ola@inguza.com</a>&gt;<br>
&gt;&gt;                               Annebergsslingan 37        \<br>
&gt;&gt;                     |  <a href="mailto:opal@debian.org">opal@debian.org</a> &lt;mailto:<a href="mailto:opal@debian.org">opal@debian.org</a>&gt;<br>
&gt;&gt;                                654 65 KARLSTAD            |<br>
&gt;&gt;                     |  <a href="http://inguza.com/" rel="noreferrer" target="_blank">http://inguza.com/</a>                Mobile: +46<br>
&gt;&gt;                     (0)70-332 1551 &lt;tel:%2B46%20%280%2970-332%201551&gt; |<br>
&gt;&gt;                     \  gpg/f.p.: 7090 A92B 18FE 7994 0C36 4FE4 18A1<br>
&gt;&gt;                     B1CF 0FE5 3DD9  /<br>
&gt;&gt;<br>
&gt;&gt;                     ---------------------------------------------------------------<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;                 --<br>
&gt;&gt;                   --- Inguza Technology AB --- MSc in Information<br>
&gt;&gt;                 Technology ----<br>
&gt;&gt;                 /  <a href="mailto:ola@inguza.com">ola@inguza.com</a> &lt;mailto:<a href="mailto:ola@inguza.com">ola@inguza.com</a>&gt;<br>
&gt;&gt;                       Annebergsslingan 37        \<br>
&gt;&gt;                 |  <a href="mailto:opal@debian.org">opal@debian.org</a> &lt;mailto:<a href="mailto:opal@debian.org">opal@debian.org</a>&gt;<br>
&gt;&gt;                        654 65 KARLSTAD            |<br>
&gt;&gt;                 |  <a href="http://inguza.com/" rel="noreferrer" target="_blank">http://inguza.com/</a>                Mobile: +46<br>
&gt;&gt;                 (0)70-332 1551 &lt;tel:%2B46%20%280%2970-332%201551&gt; |<br>
&gt;&gt;                 \  gpg/f.p.: 7090 A92B 18FE 7994 0C36 4FE4 18A1 B1CF<br>
&gt;&gt;                 0FE5 3DD9  /<br>
&gt;&gt;<br>
&gt;&gt;                 ---------------------------------------------------------------<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;<br>
&gt;&gt;     --<br>
&gt;&gt;      --- Inguza Technology AB --- MSc in Information Technology ----<br>
&gt;&gt;     /  &lt;mailto:<a href="mailto:ola@inguza.com">ola@inguza.com</a>&gt;<a href="mailto:ola@inguza.com">ola@inguza.com</a> &lt;mailto:<a href="mailto:ola@inguza.com">ola@inguza.com</a>&gt;<br>
&gt;&gt;                      Annebergsslingan 37        \<br>
&gt;&gt;     |  &lt;mailto:<a href="mailto:opal@debian.org">opal@debian.org</a>&gt;<a href="mailto:opal@debian.org">opal@debian.org</a><br>
&gt;&gt;     &lt;mailto:<a href="mailto:opal@debian.org">opal@debian.org</a>&gt;                   654 65 KARLSTAD<br>
&gt;&gt;        |<br>
&gt;&gt;     |  &lt;<a href="http://inguza.com/" rel="noreferrer" target="_blank">http://inguza.com/</a>&gt;<a href="http://inguza.com/" rel="noreferrer" target="_blank">http://inguza.com/</a>                Mobile:<br>
&gt;&gt;     <a href="tel:%2B46%20%280%2970-332%201551" value="+46703321551">+46 (0)70-332 1551</a> &lt;tel:%2B46%20%280%2970-332%201551&gt; |<br>
&gt;&gt;     \  gpg/f.p.: 7090 A92B 18FE 7994 0C36 4FE4 18A1 B1CF 0FE5 3DD9  /<br>
&gt;&gt;      ---------------------------------------------------------------<br>
&gt;&gt;<br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt; --<br>
&gt;  --- Inguza Technology AB --- MSc in Information Technology ----<br>
&gt; /  <a href="mailto:ola@inguza.com">ola@inguza.com</a> &lt;mailto:<a href="mailto:ola@inguza.com">ola@inguza.com</a>&gt;<br>
&gt;  Annebergsslingan 37        \<br>
&gt; |  <a href="mailto:opal@debian.org">opal@debian.org</a> &lt;mailto:<a href="mailto:opal@debian.org">opal@debian.org</a>&gt;                   654 65<br>
&gt; KARLSTAD            |<br>
&gt; |  <a href="http://inguza.com/" rel="noreferrer" target="_blank">http://inguza.com/</a>                Mobile: <a href="tel:%2B46%20%280%2970-332%201551" value="+46703321551">+46 (0)70-332 1551</a> |<br>
&gt; \  gpg/f.p.: 7090 A92B 18FE 7994 0C36 4FE4 18A1 B1CF 0FE5 3DD9  /<br>
&gt;  ---------------------------------------------------------------<br>
&gt;<br>
<br>
</blockquote></div>