Thanks for verifying. What is happening is actually vaguely explained in the mountcgroup hook itself, and is an unfortunate side effect of a somewhat recent kernel change:
cd /sys/fs/cgroup/devices
sudo mkdir a
echo a | sudo tee -a a/devices.deny # succeeds
sudo mkdir -p b/c
echo a | sudo tee -a b/devices.deny # fails
If a devices cgroup has any child cgroups, then you can no longer make certain changes to it.
Marking this confirmed and changing the title to reflect that the comments in /usr/share/lxc/config/ubuntu.common.conf need to be changed.
Thanks for verifying. What is happening is actually vaguely explained in the mountcgroup hook itself, and is an unfortunate side effect of a somewhat recent kernel change:
cd /sys/fs/ cgroup/ devices
sudo mkdir a
echo a | sudo tee -a a/devices.deny # succeeds
sudo mkdir -p b/c
echo a | sudo tee -a b/devices.deny # fails
If a devices cgroup has any child cgroups, then you can no longer make certain changes to it.
Marking this confirmed and changing the title to reflect that the comments in /usr/share/ lxc/config/ ubuntu. common. conf need to be changed.