Some little direction with what i think are cgroup/appamour issues with LXC

James Crook

Well-Known Member
Jul 28, 2017
146
4
58
Long story short, our demo box (LXC is privilaged) is failing to start some services with
Failed to reset devices.list: Operation not permitted

This has started since we did updates to the hosts, but as it's a demo container it wasn't caught till now.

I'm looking for a bit of help with figuring out how much permissions i need to give it, through appamour (rather than lxc.apparmor.profile: unconfined) and cgroups (rather than lxc.cgroup.devices.allow: a)

I'm suspecting cgroup as i think there were changes in the kernel to cgroup v2 (i'm a little bit behind on my podcasts)

Just want pointing in the right direction for tools i can or commands i can run to figure out what the container is asking for.
 
Last edited:
do you actually experience any issues? those log lines are normal and usually benign..
 
please post the full journal of such a start attempt..
 
the reason why the services don't start is definitely something else, you have to debug the individual services themselves (e.g., check what command(s) get started, try to start them manually with more verbosity and look for errors).

e.g. I see a service crashing on startup:
Code:
 43 Jul 24 10:37:29 intralan3cx systemd[1]: Starting 3CX Event Notification Manager...
[..]
117 Jul 24 10:37:29 intralan3cx systemd[1]: 3CXEventNotificationManager.service: Main process exited, code=killed, status=11/SEGV
118 Jul 24 10:37:29 intralan3cx systemd[1]: Failed to start 3CX Event Notification Manager.
119 Jul 24 10:37:29 intralan3cx systemd[1]: 3CXEventNotificationManager.service: Unit entered failed state.
120 Jul 24 10:37:29 intralan3cx systemd[1]: 3CXEventNotificationManager.service: Failed with result 'signal'.

and another one timing out on startup:
Code:
[..]
174 Jul 24 10:39:32 intralan3cx systemd[1]: 3CXPhoneSystemMC01.service: Start operation timed out. Terminating.
175 Jul 24 10:39:32 intralan3cx systemd[1]: Failed to start 3CX PhoneSystem 01 Management Console.
176 Jul 24 10:39:32 intralan3cx systemd[1]: 3CXPhoneSystemMC01.service: Unit entered failed state.
177 Jul 24 10:39:32 intralan3cx systemd[1]: 3CXPhoneSystemMC01.service: Failed with result 'timeout'.
 
  • Like
Reactions: James Crook
the reason why the services don't start is definitely something else, you have to debug the individual services themselves (e.g., check what command(s) get started, try to start them manually with more verbosity and look for errors).

e.g. I see a service crashing on startup:
Code:
43 Jul 24 10:37:29 intralan3cx systemd[1]: Starting 3CX Event Notification Manager...
[..]
117 Jul 24 10:37:29 intralan3cx systemd[1]: 3CXEventNotificationManager.service: Main process exited, code=killed, status=11/SEGV
118 Jul 24 10:37:29 intralan3cx systemd[1]: Failed to start 3CX Event Notification Manager.
119 Jul 24 10:37:29 intralan3cx systemd[1]: 3CXEventNotificationManager.service: Unit entered failed state.
120 Jul 24 10:37:29 intralan3cx systemd[1]: 3CXEventNotificationManager.service: Failed with result 'signal'.

and another one timing out on startup:
Code:
[..]
174 Jul 24 10:39:32 intralan3cx systemd[1]: 3CXPhoneSystemMC01.service: Start operation timed out. Terminating.
175 Jul 24 10:39:32 intralan3cx systemd[1]: Failed to start 3CX PhoneSystem 01 Management Console.
176 Jul 24 10:39:32 intralan3cx systemd[1]: 3CXPhoneSystemMC01.service: Unit entered failed state.
177 Jul 24 10:39:32 intralan3cx systemd[1]: 3CXPhoneSystemMC01.service: Failed with result 'timeout'.

I was afraid of that, as i suspect they are closed source programs.

Many thanks for this, i'll change angle.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!