<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>Univers Libre - lxc</title>
    <subtitle>Yet another sysadmin&#39;s personal blog</subtitle>
    <link rel="self" type="application/atom+xml" href="https://univers-libre.net/tags/lxc/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://univers-libre.net"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2014-01-21T21:02:08+00:00</updated>
    <id>https://univers-libre.net/tags/lxc/atom.xml</id>
    <entry xml:lang="en">
        <title>Ajout d&#39;une carte son à chaud dans un conteneur LXC</title>
        <published>2014-01-21T21:02:08+00:00</published>
        <updated>2014-01-21T21:02:08+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/lxc-ajout-carte-audio/"/>
        <id>https://univers-libre.net/posts/lxc-ajout-carte-audio/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/lxc-ajout-carte-audio/">&lt;p&gt;Voici un article express pour rajouter une carte son dans un conteneur LXC,
plus un aide-mémoire en fait, car c’est pas le genre de chose que je fais tous
les 4 matins.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Brancher la carte son à la machine hôte. Dans mon cas une carte USB, si
c’est en PCI, la procédure n’a que peu d’intérêt puisqu’il faudra dans tout
les cas redémarrer.&lt;/li&gt;
&lt;li&gt;le kernel doit la détecter et créer des fichiers spéciaux de type caractère
dans &lt;code&gt;/dev/snd&lt;/code&gt; :&lt;/li&gt;
&lt;/ol&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;```&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# ls -l /dev/snd/&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;total 0&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;drwxr-xr-x 2 root root       60 Jan 21 19:44 by-id&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;drwxr-xr-x 2 root root       60 Jan 21 19:44 by-path&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;crw-rw---T 1 root audio 116,  4 Jan 21 19:44 controlC0&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;crw-rw---T 1 root audio 116,  3 Jan 21 19:44 pcmC0D0c&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;crw-rw---T 1 root audio 116,  2 Jan 21 19:44 pcmC0D0p&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;crw------T 1 root root  116,  1 Dec 17 09:24 seq&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;crw-rw---T 1 root audio 116, 33 Dec 17 09:24 timer&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;```&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Notez le numéro majeur et mineur de chaque pseudo fichier (dans mon cas 116&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;et de 1 à 4 et 33).&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;3&quot;&gt;
&lt;li&gt;Ajoutez les autorisations nécessaires dans votre conf LXC pour le conteneur
en question :&lt;/li&gt;
&lt;/ol&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;```&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# /dev/snd/*&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;lxc.cgroup.devices.allow                = c 116:4 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;lxc.cgroup.devices.allow                = c 116:3 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;lxc.cgroup.devices.allow                = c 116:2 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;lxc.cgroup.devices.allow                = c 116:1 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;lxc.cgroup.devices.allow                = c 116:33 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;```&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Adaptez bien sûr avec les bons numéro majeurs et mineurs.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;4&quot;&gt;
&lt;li&gt;À ce stade, il faut redémarrer le conteneur pour que les nouveaux cgroups
s’appliquent. Comme j’avais pas envie de faire ça et que les cgroups
cesttropbien, On va appliquer les nouvelles règles à chaud via son pseudo
système de fichier :&lt;/li&gt;
&lt;/ol&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;```&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# cat &amp;gt;/sys/fs/cgroup/lxc/&amp;lt;nom du conteneur&amp;gt;/devices.allow&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;c 116:4 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;c 116:3 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;c 116:2 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;c 116:1 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;c 116:33 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;^D&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;```&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;5&quot;&gt;
&lt;li&gt;
&lt;p&gt;Maintenant, on peut créer manuellement les pseudo fichiers dans le conteneur :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# mkdir /dev/snd; cd /dev/snd&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# mknod controlC0 c 116 4&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# mknod pcmC0D0c c 116 3&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# mknod pcmC0D0p c 116 2&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# mknod seq c 116 1&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# mknod timer c 116 33&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# chgrp audio controlC0 pcm* timer&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# chmod 1660 controlC0 pcm* timer&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# chmod 600 seq&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Et ajoutez vous dans le groupe audio si besoin.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;6&quot;&gt;
&lt;li&gt;
&lt;p&gt;Installer alsa-utils puis :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;$ alsactl init&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Votre carte devrait à présent être détectée, vous pouvez vérifier que tout&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;fonctionne avec un `speaker-test`.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Et voila.&lt;/p&gt;
&lt;p&gt;Bon c’est pas tout ça, allons mettre à jour le kernel et rebooter :-).&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Archlinux dans un conteneur LXC et paquet filesystem</title>
        <published>2013-06-03T21:04:00+00:00</published>
        <updated>2013-06-03T21:04:00+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/archlinux-lxc-filesystem/"/>
        <id>https://univers-libre.net/posts/archlinux-lxc-filesystem/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/archlinux-lxc-filesystem/">&lt;p&gt;Parmis mes conteneurs LXC, il y en a un qui tourne sous Archlinux. Comme
j’avais un peu joué avec les &lt;code&gt;capabilities (7)&lt;/code&gt; du noyau, qu’on peut retirer
avec &lt;code&gt;lxc.cap.drop&lt;/code&gt; dans le fichier de conf du conteneur, mon &lt;em&gt;/sys/&lt;/em&gt; (entre
autre) est en lecture seule pour le système chrooté.&lt;br /&gt;
Par jouer il faut comprendre rajouter des &lt;code&gt;lxc.cap.drop&lt;/code&gt; sur des &lt;code&gt;capabilities&lt;/code&gt;
choisies au feeling, jusqu’à ce que ça ne marche plus. J’exagère mais c’était
un peu ça l’idée au final :-).&lt;/p&gt;
&lt;p&gt;Donc, comme mon &lt;em&gt;/sys/&lt;/em&gt; est en lecture seule, la mise à jour du paquet
&lt;em&gt;filesystem&lt;/em&gt; chie lamentablement dans la colle :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;error: cannot remove file &amp;#39;/sys/&amp;#39;: Read-only file system&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;error: could not commit transaction&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;error: failed to commit transaction (transaction aborted)&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Par flème, lorsque une mise à jour du paquet était disponible, je l’excluais
manuellement avec :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# pacman --ignore filesystem -Syu&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Puis vint le jour où la mise à jour d’un paquet demandait une version à jour du
paquet filesystem. Forcement, ça devait arriver un jour…&lt;/p&gt;
&lt;p&gt;Et c’est là qu’en cherchant un peu, j’ai découvert que dans la configuration de
&lt;code&gt;pacman&lt;/code&gt;, on peut lui dire d’empêcher un paquet de toucher à un fichier. Ça se
rapproche un peu du &lt;code&gt;dpkg-divert&lt;/code&gt; de Debian.&lt;/p&gt;
&lt;p&gt;Dans &lt;em&gt;/etc/pacman.conf&lt;/em&gt; :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;NoUpgrade    = sys/&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;NoExtract    = sys/&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;le répertoire &lt;em&gt;/sys/&lt;/em&gt; sera ignoré, et la mise à jour de &lt;em&gt;filesystem&lt;/em&gt; se fait
sans soucis !&lt;/p&gt;
&lt;p&gt;Pour plus de détails, voir &lt;code&gt;pacman.conf(5)&lt;/code&gt;.&lt;/p&gt;
</content>
        
    </entry>
</feed>
