2024-09-13 16:13:54 +02:00
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Jul 31 04:58:15 UTC 2024 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
[NOTE: This update was only ever released in SLES and Leap.]
|
|
|
|
|
|
|
|
|
|
- Update to Docker 25.0.6-ce. See upstream changelog online at
|
|
|
|
|
<https://docs.docker.com/engine/release-notes/25.0/#2506>
|
|
|
|
|
- This update includes a fix for CVE-2024-41110. bsc#1228324
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
* 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
|
|
|
|
|
* 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
* 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
|
|
|
|
|
* 0006-bsc1221916-update-to-patched-buildkit-version-to-fix.patch
|
|
|
|
|
* 0007-bsc1214855-volume-use-AtomicWriteFile-to-save-volume.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Jun 24 08:15:24 UTC 2024 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
* 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
|
|
|
|
|
* 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
* 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
|
|
|
|
|
- Fix BuildKit's symlink resolution logic to correctly handle non-lexical
|
|
|
|
|
symlinks. Backport of <https://github.com/moby/buildkit/pull/4896> and
|
|
|
|
|
<https://github.com/moby/buildkit/pull/5060>. bsc#1221916
|
|
|
|
|
+ 0006-bsc1221916-update-to-patched-buildkit-version-to-fix.patch
|
|
|
|
|
- Write volume options atomically so sudden system crashes won't result in
|
|
|
|
|
future Docker starts failing due to empty files. Backport of
|
|
|
|
|
<https://github.com/moby/moby/pull/48034>. bsc#1214855
|
|
|
|
|
+ 0007-bsc1214855-volume-use-AtomicWriteFile-to-save-volume.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Mar 25 12:34:56 UTC 2024 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
[NOTE: This update was only ever released in SLES and Leap.]
|
|
|
|
|
|
|
|
|
|
- Update to Docker 25.0.5-ce. See upstream changelog online at
|
|
|
|
|
<https://docs.docker.com/engine/release-notes/25.0/#2505> bsc#1223409
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
* 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
|
|
|
|
|
* 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
* 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
|
|
|
|
|
* cli-0001-docs-include-required-tools-in-source-tree.patch
|
|
|
|
|
- Remove upstreamed patches:
|
|
|
|
|
- 0007-daemon-overlay2-remove-world-writable-permission-fro.patch
|
|
|
|
|
- Update --add-runtime to point to correct binary path.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Mar 8 07:46:11 UTC 2024 - Dan Čermák <dcermak@suse.com>
|
|
|
|
|
|
|
|
|
|
[NOTE: This update was only ever released in SLES and Leap.]
|
|
|
|
|
|
|
|
|
|
- Add patch to fix bsc#1220339
|
|
|
|
|
* 0007-daemon-overlay2-remove-world-writable-permission-fro.patch
|
|
|
|
|
|
|
|
|
|
- rebase patches:
|
|
|
|
|
* 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
* 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
|
|
|
|
|
* 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
* 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
|
|
|
|
|
* 0006-Vendor-in-latest-buildkit-v0.11-branch-including-CVE.patch
|
|
|
|
|
|
2024-05-03 12:09:28 +02:00
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Feb 22 14:13:42 UTC 2024 - Thorsten Kukuk <kukuk@suse.com>
|
|
|
|
|
|
|
|
|
|
- Allow to disable apparmor support (ALP supports only SELinux)
|
|
|
|
|
|
2024-09-13 16:13:54 +02:00
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Feb 17 12:56:22 UTC 2024 - Danish Prakash <danish.prakash@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 25.0.3-ce. See upstream changelog online at
|
|
|
|
|
<https://docs.docker.com/engine/release-notes/25.0/#2503>
|
|
|
|
|
- Fixes:
|
|
|
|
|
* bsc#1219267 - CVE-2024-23651
|
|
|
|
|
* bsc#1219268 - CVE-2024-23652
|
|
|
|
|
* bsc#1219438 - CVE-2024-23653
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
* 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
|
|
|
|
|
* 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
* 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
|
|
|
|
|
* cli-0001-docs-include-required-tools-in-source-tree.patch
|
|
|
|
|
- Remove upstreamed patches:
|
|
|
|
|
- 0006-Vendor-in-latest-buildkit-v0.11-branch-including-CVE.patch
|
|
|
|
|
|
2024-05-03 12:09:28 +02:00
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Feb 14 08:40:36 UTC 2024 - Dan Čermák <dcermak@suse.com>
|
|
|
|
|
|
|
|
|
|
- Vendor latest buildkit v0.11:
|
|
|
|
|
Add patch 0006-Vendor-in-latest-buildkit-v0.11-branch-including-CVE.patch that
|
|
|
|
|
vendors in the latest v0.11 buildkit branch including bugfixes for the following:
|
|
|
|
|
* bsc#1219438: CVE-2024-23653
|
|
|
|
|
* bsc#1219268: CVE-2024-23652
|
|
|
|
|
* bsc#1219267: CVE-2024-23651
|
|
|
|
|
|
|
|
|
|
- rebase patches:
|
|
|
|
|
* 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
* 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
|
|
|
|
|
* 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
* 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
|
|
|
|
|
|
|
|
|
|
- switch from %patchN to %patch -PN syntax
|
|
|
|
|
- remove unused rpmlint filters and add filters to silence pointless bash & zsh
|
|
|
|
|
completion warnings
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Oct 27 21:14:37 UTC 2023 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
2024-09-13 16:13:54 +02:00
|
|
|
|
- Update to Docker 24.0.7-ce. See upstream changelog online at
|
2024-05-03 12:09:28 +02:00
|
|
|
|
<https://docs.docker.com/engine/release-notes/24.0/#2407>. bsc#1217513
|
|
|
|
|
* Deny containers access to /sys/devices/virtual/powercap by default.
|
|
|
|
|
- CVE-2020-8694 bsc#1170415
|
2024-09-13 16:13:54 +02:00
|
|
|
|
- CVE-2020-8695 bsc#1170446
|
|
|
|
|
- CVE-2020-12912 bsc#1178760
|
2024-05-03 12:09:28 +02:00
|
|
|
|
- Rebase patches:
|
|
|
|
|
* 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
* 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
|
|
|
|
|
* 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
* 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
|
|
|
|
|
* cli-0001-docs-include-required-tools-in-source-tree.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Oct 11 10:32:43 UTC 2023 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Add a patch to fix apparmor on SLE-12, reverting the upstream removal of
|
|
|
|
|
version-specific templating for the default apparmor profile. bsc#1213500
|
|
|
|
|
+ 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
* 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
|
|
|
|
|
* 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Sep 14 01:46:30 UTC 2023 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
2024-09-13 16:13:54 +02:00
|
|
|
|
- Update to Docker 24.0.6-ce. See upstream changelog online at
|
2024-05-03 12:09:28 +02:00
|
|
|
|
<https://docs.docker.com/engine/release-notes/24.0/#2406>. bsc#1215323
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
* 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
|
|
|
|
|
* 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
* cli-0001-docs-include-required-tools-in-source-tree.patch
|
|
|
|
|
- Switch from disabledrun to manualrun in _service.
|
|
|
|
|
- Add a docker.socket unit file, but with socket activation effectively
|
|
|
|
|
disabled to ensure that Docker will always run even if you start the socket
|
|
|
|
|
individually. Users should probably just ignore this unit file. bsc#1210141
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Jul 25 19:40:25 UTC 2023 - Dirk Müller <dmueller@suse.com>
|
|
|
|
|
|
2024-09-13 16:13:54 +02:00
|
|
|
|
- Update to Docker 24.0.5-ce. See upstream changelog online at
|
2024-05-03 12:09:28 +02:00
|
|
|
|
<https://docs.docker.com/engine/release-notes/24.0/#2405>. bsc#1213229
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Jul 7 21:29:05 UTC 2023 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 24.0.4-ce. See upstream changelog online at
|
|
|
|
|
<https://docs.docker.com/engine/release-notes/24.0/#2404>. bsc#1213500
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Jul 7 02:35:02 UTC 2023 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 24.0.3-ce. See upstream changelog online at
|
|
|
|
|
<https://docs.docker.com/engine/release-notes/24.0/#2403>. bsc#1213120
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* cli-0001-docs-include-required-tools-in-source-tree.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Jun 29 10:07:13 UTC 2023 - Danish Prakash <danish.prakash@suse.com>
|
|
|
|
|
|
|
|
|
|
- Recommend docker-rootless-extras instead of Require(ing) it, given
|
|
|
|
|
it's an additional functionality and not inherently required for
|
|
|
|
|
docker to function.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Jun 20 15:28:13 UTC 2023 - Danish Prakash <danish.prakash@suse.com>
|
|
|
|
|
|
|
|
|
|
- Add docker-rootless-extras subpackage
|
|
|
|
|
(https://docs.docker.com/engine/security/rootless)
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Jun 14 13:02:01 UTC 2023 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 24.0.2-ce. See upstream changelog online at
|
|
|
|
|
<https://docs.docker.com/engine/release-notes/24.0/#2402>. bsc#1212368
|
|
|
|
|
* Includes the upstreamed fix for the mount table pollution issue.
|
|
|
|
|
bsc#1210797
|
|
|
|
|
- Add Recommends for docker-buildx, and add /usr/lib/docker/cli-plugins as
|
|
|
|
|
being provided by this package.
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
* 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
|
|
|
|
|
* 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
* cli-0001-docs-include-required-tools-in-source-tree.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Sun May 21 02:31:35 UTC 2023 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 23.0.6-ce. See upstream changelog online at
|
|
|
|
|
<https://docs.docker.com/engine/release-notes/23.0/#2306>. bsc#1211578
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* cli-0001-docs-include-required-tools-in-source-tree.patch
|
|
|
|
|
- Re-unify packaging for SLE-12 and SLE-15.
|
|
|
|
|
- Add patch to fix build on SLE-12 by switching back to libbtrfs-devel headers
|
|
|
|
|
(the uapi headers in SLE-12 are too old).
|
|
|
|
|
+ 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
|
|
|
|
|
- Re-numbered patches:
|
|
|
|
|
- 0003-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
+ 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch`
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Apr 27 14:09:05 UTC 2023 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 23.0.5-ce. See upstream changelog online at
|
|
|
|
|
<https://docs.docker.com/engine/release-notes/23.0/#2305>.
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* cli-0001-docs-include-required-tools-in-source-tree.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Apr 26 00:31:54 UTC 2023 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 23.0.4-ce. See upstream changelog online at
|
|
|
|
|
<https://docs.docker.com/engine/release-notes/23.0/#2304>. bsc#1208074
|
|
|
|
|
- Fixes:
|
|
|
|
|
* bsc#1214107 - CVE-2023-28840
|
|
|
|
|
* bsc#1214108 - CVE-2023-28841
|
|
|
|
|
* bsc#1214109 - CVE-2023-28842
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
* 0003-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
- Renumbered patches:
|
|
|
|
|
- 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
- Remove upstreamed patches:
|
|
|
|
|
- 0005-bsc1183855-btrfs-Do-not-disable-quota-on-cleanup.patch
|
|
|
|
|
- 0006-bsc1193930-vendor-update-golang.org-x-crypto.patch
|
|
|
|
|
- 0007-bsc1200022-fifo.Close-prevent-possible-panic-if-fifo.patch
|
|
|
|
|
- Backport <https://github.com/docker/cli/pull/4228> to allow man pages to be
|
|
|
|
|
built without internet access in OBS.
|
|
|
|
|
+ cli-0001-docs-include-required-tools-in-source-tree.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Feb 1 14:33:19 UTC 2023 - Dirk Müller <dmueller@suse.com>
|
|
|
|
|
|
|
|
|
|
- update to 20.10.23-ce.
|
|
|
|
|
* see upstream changelog at https://docs.docker.com/engine/release-notes/#201023
|
|
|
|
|
|
|
|
|
|
- drop kubic flavor as kubic is EOL. this removes:
|
|
|
|
|
kubelet.env docker-kubic-service.conf 0003-PRIVATE-REGISTRY-add-private-registry-mirror-support.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Dec 6 11:49:32 UTC 2022 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 20.10.21-ce. See upstream changelog online at
|
|
|
|
|
<https://docs.docker.com/engine/release-notes/#201021>. bsc#1206065
|
|
|
|
|
bsc#1205375 CVE-2022-36109
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
* 0003-PRIVATE-REGISTRY-add-private-registry-mirror-support.patch
|
|
|
|
|
* 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
* 0005-bsc1183855-btrfs-Do-not-disable-quota-on-cleanup.patch
|
|
|
|
|
* 0006-bsc1193930-vendor-update-golang.org-x-crypto.patch
|
|
|
|
|
* 0007-bsc1200022-fifo.Close-prevent-possible-panic-if-fifo.patch
|
|
|
|
|
- The PRIVATE-REGISTRY patch will now output a warning if it is being used (in
|
|
|
|
|
preparation for removing the feature). This feature was never meant to be
|
|
|
|
|
used by users directly (and is only available in the -kubic/CaaSP version of
|
|
|
|
|
the package anyway) and thus should not affect any users.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Oct 24 09:45:20 UTC 2022 - Dan Čermák <dcermak@suse.com>
|
|
|
|
|
|
|
|
|
|
- Fix wrong After: in docker.service, fixes bsc#1188447
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Sep 29 08:40:35 UTC 2022 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Add apparmor-parser as a Recommends to make sure that most users will end up
|
|
|
|
|
with it installed even if they are primarily running SELinux.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Sep 29 07:27:03 UTC 2022 - Fabian Vogt <fvogt@suse.com>
|
|
|
|
|
|
|
|
|
|
- Fix syntax of boolean dependency
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Jul 28 07:42:33 UTC 2022 - Frederic Crozat <fcrozat@suse.com>
|
|
|
|
|
|
|
|
|
|
- Allow to install container-selinux instead of apparmor-parser.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Sun Jul 17 17:06:01 UTC 2022 - Callum Farmer <gmbr3@opensuse.org>
|
|
|
|
|
|
|
|
|
|
- Change to using systemd-sysusers
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Jun 29 12:19:55 UTC 2022 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Backport <https://github.com/containerd/fifo/pull/32> to fix a crash-on-start
|
|
|
|
|
issue with dockerd. bsc#1200022
|
|
|
|
|
+ 0007-bsc1200022-fifo.Close-prevent-possible-panic-if-fifo.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Jun 7 07:18:41 UTC 2022 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 20.10.17-ce. See upstream changelog online at
|
|
|
|
|
<https://docs.docker.com/engine/release-notes/#201017>. bsc#1200145
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
* 0003-PRIVATE-REGISTRY-add-private-registry-mirror-support.patch
|
|
|
|
|
* 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
* 0005-bsc1183855-btrfs-Do-not-disable-quota-on-cleanup.patch
|
|
|
|
|
* 0006-bsc1193930-vendor-update-golang.org-x-crypto.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Apr 29 02:51:43 UTC 2022 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Add patch to update golang.org/x/crypto for CVE-2021-43565 and CVE-2022-27191.
|
|
|
|
|
bsc#1193930 bsc#1197284
|
|
|
|
|
* 0006-bsc1193930-vendor-update-golang.org-x-crypto.patch
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
* 0003-PRIVATE-REGISTRY-add-private-registry-mirror-support.patch
|
|
|
|
|
* 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
* 0005-bsc1183855-btrfs-Do-not-disable-quota-on-cleanup.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Apr 14 04:09:58 UTC 2022 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 20.10.14-ce. See upstream changelog online at
|
|
|
|
|
<https://docs.docker.com/engine/release-notes/#201014>. bsc#1197517
|
|
|
|
|
CVE-2022-24769
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Jan 17 07:23:01 UTC 2022 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 20.10.12-ce. See upstream changelog online at
|
|
|
|
|
<https://docs.docker.com/engine/release-notes/#201012>.
|
|
|
|
|
- Remove CHANGELOG.md. It hasn't been maintained since 2017, and all of the
|
|
|
|
|
changelogs are currently only available online.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Nov 18 08:35:37 UTC 2021 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 20.10.11-ce. See upstream changelog online at
|
|
|
|
|
<https://docs.docker.com/engine/release-notes/#201011>. bsc#1192814
|
|
|
|
|
bsc#1193273 CVE-2021-41190
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
* 0003-PRIVATE-REGISTRY-add-private-registry-mirror-support.patch
|
|
|
|
|
* 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
* 0005-bsc1183855-btrfs-Do-not-disable-quota-on-cleanup.patch
|
|
|
|
|
- Remove upstreamed patches:
|
|
|
|
|
- 0006-bsc1190670-seccomp-add-support-for-clone3-syscall-in.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Oct 6 02:51:16 UTC 2021 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 20.10.9-ce. See upstream changelog online at
|
|
|
|
|
<https://docs.docker.com/engine/release-notes/#20109>. bsc#1191355
|
|
|
|
|
CVE-2021-41089 bsc#1191015 CVE-2021-41091 bsc#1191434
|
|
|
|
|
CVE-2021-41092 bsc#1191334 CVE-2021-41103 bsc#1191121
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
* 0003-PRIVATE-REGISTRY-add-private-registry-mirror-support.patch
|
|
|
|
|
* 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
* 0005-bsc1183855-btrfs-Do-not-disable-quota-on-cleanup.patch
|
|
|
|
|
* 0006-bsc1190670-seccomp-add-support-for-clone3-syscall-in.patch
|
|
|
|
|
- Switch to Go 1.16.x compiler, in line with upstream.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Sep 20 23:59:05 UTC 2021 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Add patch to return ENOSYS for clone3 to avoid breaking glibc again.
|
|
|
|
|
bsc#1190670
|
|
|
|
|
+ 0006-bsc1190670-seccomp-add-support-for-clone3-syscall-in.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon May 3 13:24:55 UTC 2021 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Add shell requires for the *-completion subpackages.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Apr 15 05:23:20 UTC 2021 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 20.10.6-ce. See upstream changelog online at
|
|
|
|
|
<https://docs.docker.com/engine/release-notes/#20106>. bsc#1184768
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
* 0003-PRIVATE-REGISTRY-add-private-registry-mirror-support.patch
|
|
|
|
|
* 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
- Backport upstream fix <https://github.com/moby/moby/pull/42273> for btrfs
|
|
|
|
|
quotas being removed by Docker regularly. bsc#1183855 bsc#1175081
|
|
|
|
|
+ 0005-bsc1183855-btrfs-Do-not-disable-quota-on-cleanup.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Mar 3 00:49:58 UTC 2021 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 20.10.5-ce. See upstream changelog online at
|
|
|
|
|
<https://docs.docker.com/engine/release-notes/#20105>. bsc#1182947
|
|
|
|
|
- Update runc dependency to 1.0.0~rc93.
|
|
|
|
|
- Remove upstreamed patches:
|
|
|
|
|
- cli-0001-Rename-bin-md2man-to-bin-go-md2man.patch
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
* 0003-PRIVATE-REGISTRY-add-private-registry-mirror-support.patch
|
|
|
|
|
* 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
- Switch version to use -ce suffix rather than _ce to avoid confusing other
|
|
|
|
|
tools. boo#1182476
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Sun Feb 14 06:33:16 UTC 2021 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
[NOTE: This update was only ever released in SLES and Leap.]
|
|
|
|
|
|
|
|
|
|
- It turns out the boo#1178801 libnetwork patch is also broken on Leap, so drop
|
|
|
|
|
the patch entirely. bsc#1180401 bsc#1182168
|
|
|
|
|
- boo1178801-0001-Add-docker-interfaces-to-firewalld-docker-zone.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Feb 10 07:40:36 UTC 2021 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Fix incorrect cast in SUSE secrets patches causing warnings on SLES.
|
|
|
|
|
* 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Sat Feb 6 12:36:42 UTC 2021 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
[NOTE: This update was only ever released in SLES and Leap.]
|
|
|
|
|
|
|
|
|
|
- Update Docker to 19.03.15-ce. See upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md. This update includes fixes for
|
|
|
|
|
bsc#1181732 (CVE-2021-21284) and bsc#1181730 (CVE-2021-21285).
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* bsc1073877-0001-apparmor-clobber-docker-default-profile-on-start.patch
|
|
|
|
|
- Only apply the boo#1178801 libnetwork patch to handle firewalld on openSUSE.
|
|
|
|
|
It appears that SLES doesn't like the patch. bsc#1180401
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Feb 2 13:06:17 UTC 2021 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 20.10.3-ce. See upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md. Fixes bsc#1181732
|
|
|
|
|
(CVE-2021-21284) and bsc#1181730 (CVE-2021-21285).
|
|
|
|
|
- Rebase patches on top of 20.10.3-ce.
|
|
|
|
|
- 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
+ 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
- 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
+ 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
- 0004-PRIVATE-REGISTRY-add-private-registry-mirror-support.patch
|
|
|
|
|
+ 0003-PRIVATE-REGISTRY-add-private-registry-mirror-support.patch
|
|
|
|
|
- 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
+ 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Feb 2 05:28:01 UTC 2021 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Drop docker-runc, docker-test and docker-libnetwork packages. We now just use
|
|
|
|
|
the upstream runc package (it's stable enough and Docker no longer pins git
|
|
|
|
|
versions). docker-libnetwork is so unstable that it doesn't have any
|
|
|
|
|
versioning scheme and so it really doesn't make sense to maintain the project
|
|
|
|
|
as a separate package. bsc#1181641 bsc#1181677
|
|
|
|
|
- Remove no-longer-needed patch for packaging now that we've dropped
|
|
|
|
|
docker-runc and docker-libnetwork.
|
|
|
|
|
- 0001-PACKAGING-revert-Remove-docker-prefix-for-containerd.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Jan 29 22:55:48 UTC 2021 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 20.10.2-ce. See upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md. bsc#1181594
|
|
|
|
|
- Remove upstreamed patches:
|
|
|
|
|
- bsc1122469-0001-apparmor-allow-readby-and-tracedby.patch
|
|
|
|
|
- boo1178801-0001-Add-docker-interfaces-to-firewalld-docker-zone.patch
|
|
|
|
|
- Add patches to fix build:
|
|
|
|
|
+ cli-0001-Rename-bin-md2man-to-bin-go-md2man.patch
|
|
|
|
|
- Since upstream has changed their source repo (again) we have to rebase all of
|
|
|
|
|
our patches. While doing this, I've collapsed all patches into one branch
|
|
|
|
|
per-release and thus all the patches are now just one series:
|
|
|
|
|
- packaging-0001-revert-Remove-docker-prefix-for-containerd-and-runc-.patch
|
|
|
|
|
+ 0001-PACKAGING-revert-Remove-docker-prefix-for-containerd.patch
|
|
|
|
|
- secrets-0001-daemon-allow-directory-creation-in-run-secrets.patch
|
|
|
|
|
+ 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
|
|
|
|
|
- secrets-0002-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
+ 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
- private-registry-0001-Add-private-registry-mirror-support.patch
|
|
|
|
|
+ 0004-PRIVATE-REGISTRY-add-private-registry-mirror-support.patch
|
|
|
|
|
- bsc1073877-0001-apparmor-clobber-docker-default-profile-on-start.patch
|
|
|
|
|
+ 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Jan 29 11:54:53 UTC 2021 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Re-apply secrets fix for bsc#1065609 which appears to have been lost after it
|
|
|
|
|
was fixed.
|
|
|
|
|
* secrets-0001-daemon-allow-directory-creation-in-run-secrets.patch
|
|
|
|
|
* secrets-0002-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Dec 23 06:40:46 UTC 2020 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Add Conflicts and Provides for kubic flavour of docker-fish-completion.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Dec 21 07:06:53 UTC 2020 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 19.03.14-ce. See upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md. CVE-2020-15257 bsc#1180243
|
|
|
|
|
|
|
|
|
|
https://github.com/docker/docker-ce/releases/tag/v19.03.14
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Dec 14 13:45:56 UTC 2020 - Robert Munteanu <rombert@apache.org>
|
|
|
|
|
|
|
|
|
|
- Enable fish-completion
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Nov 12 18:36:26 UTC 2020 - Michał Rostecki <mrostecki@suse.com>
|
|
|
|
|
|
|
|
|
|
- Add a patch which makes Docker compatible with firewalld with
|
|
|
|
|
nftables backend. Backport of https://github.com/moby/libnetwork/pull/2548
|
|
|
|
|
(boo#1178801, SLE-16460)
|
|
|
|
|
* boo1178801-0001-Add-docker-interfaces-to-firewalld-docker-zone.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Sep 18 08:20:04 UTC 2020 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 19.03.13-ce. See upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md. bsc#1176708
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Aug 3 16:58:07 UTC 2020 - Callum Farmer <callumjfarmer13@gmail.com>
|
|
|
|
|
|
|
|
|
|
- Fixes for %_libexecdir changing to /usr/libexec (bsc#1174075)
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Jun 30 23:00:00 UTC 2020 - Dominique Leuenberger <dimstar@opensuse.org>
|
|
|
|
|
|
|
|
|
|
- Emergency fix: %requires_eq does not work with provide symbols,
|
|
|
|
|
only effective package names. Convert back to regular Requires.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Jun 25 21:54:46 UTC 2020 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 19.03.12-ce. See upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md.
|
|
|
|
|
- Use Go 1.13 instead of Go 1.14 because Go 1.14 can cause all sorts of
|
|
|
|
|
spurrious errors due to Go returning -EINTR from I/O syscalls much more often
|
|
|
|
|
(due to Go 1.14's pre-emptive goroutine support).
|
|
|
|
|
- bsc1172377-0001-unexport-testcase.Cleanup-to-fix-Go-1.14.patch
|
|
|
|
|
- Add BuildRequires for all -git dependencies so that we catch missing
|
|
|
|
|
dependencies much more quickly.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Jun 2 08:37:06 UTC 2020 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 19.03.11-ce. See upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md. bsc#1172377 CVE-2020-13401
|
|
|
|
|
- Backport https://github.com/gotestyourself/gotest.tools/pull/169 so that we
|
|
|
|
|
can build Docker with Go 1.14 (upstream uses Go 1.13).
|
|
|
|
|
+ bsc1172377-0001-unexport-testcase.Cleanup-to-fix-Go-1.14.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Dec 19 15:42:26 UTC 2019 - Dominique Leuenberger <dimstar@opensuse.org>
|
|
|
|
|
|
|
|
|
|
- BuildRequire pkgconfig(libsystemd) instead of systemd-devel:
|
|
|
|
|
Allow OBS to shortcut through the -mini flavors.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Dec 12 13:27:21 UTC 2019 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Add backport of https://github.com/docker/docker/pull/39121. bsc#1122469
|
|
|
|
|
+ bsc1122469-0001-apparmor-allow-readby-and-tracedby.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Dec 11 23:55:40 UTC 2019 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Support older SLE systems which don't have "usermod -w -v".
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Nov 18 04:46:31 UTC 2019 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 19.03.5-ce. See upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md. bsc#1158590 bsc#1157330
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Sat Oct 19 11:21:03 UTC 2019 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 19.03.4-ce. See upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Oct 8 21:47:56 UTC 2019 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Drop containerd.service workaround (we've released enough versions without
|
|
|
|
|
containerd.service -- there's no need to support package upgrades that old).
|
|
|
|
|
- Update to Docker 19.03.3-ce. See upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md. bsc#1153367
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Oct 1 23:54:25 UTC 2019 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 19.03.2-ce. See upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md. bsc#1150397
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Sun Sep 22 17:41:56 UTC 2019 - Chris Coutinho <chrisbcoutinho@gmail.com>
|
|
|
|
|
|
|
|
|
|
- Fix zsh-completion (docker -> _docker)
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Jul 30 05:14:44 UTC 2019 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Fix default installation such that --userns-remap=default works properly
|
|
|
|
|
(this appears to be an upstream regression, where --userns-remap=default
|
|
|
|
|
doesn't auto-create the group and results in an error on-start). boo#1143349
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Jul 26 12:49:18 UTC 2019 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 19.03.1-ce. See upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md. CVE-2019-14271
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Jul 22 22:13:30 UTC 2019 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 19.03.0-ce. See upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md. bsc#1142413
|
|
|
|
|
- Remove upstreamed patches:
|
|
|
|
|
- bsc1001161-0001-oci-include-the-domainname-in-kernel.domainname.patch
|
|
|
|
|
- bsc1001161-0002-cli-add-a-separate-domainname-flag.patch
|
|
|
|
|
- bsc1047218-0001-man-obey-SOURCE_DATE_EPOCH-when-generating-man-pages.patch
|
|
|
|
|
- bsc1128746-0001-integration-cli-don-t-build-test-images-if-they-alre.patch
|
|
|
|
|
- Rebase pacthes:
|
|
|
|
|
* bsc1073877-0001-apparmor-clobber-docker-default-profile-on-start.patch
|
|
|
|
|
* packaging-0001-revert-Remove-docker-prefix-for-containerd-and-runc-.patch
|
|
|
|
|
* private-registry-0001-Add-private-registry-mirror-support.patch
|
|
|
|
|
* secrets-0001-daemon-allow-directory-creation-in-run-secrets.patch
|
|
|
|
|
* secrets-0002-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Jul 17 23:15:33 UTC 2019 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Move bash-completion to correct location.
|
|
|
|
|
- Update to Docker 18.09.8-ce. See upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md.
|
|
|
|
|
* Includes fixes for CVE-2019-13509 bsc#1142160.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Jun 28 01:21:19 UTC 2019 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 18.09.7-ce. See upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md. bsc#1139649
|
|
|
|
|
- Remove upstreamed patches:
|
|
|
|
|
- CVE-2018-15664.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Jun 27 07:12:57 UTC 2019 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Use %config(noreplace) for /etc/docker/daemon.json. bsc#1138920
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Jun 7 08:36:17 UTC 2019 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Add patch for CVE-2018-15664. bsc#1096726
|
|
|
|
|
+ CVE-2018-15664.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon May 6 18:25:14 UTC 2019 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 18.09.6-ce see upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md.
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* bsc1128746-0001-integration-cli-don-t-build-test-images-if-they-alre.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri May 3 14:02:46 UTC 2019 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 18.09.5-ce see upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md. bsc#1128376 boo#1134068
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* bsc1001161-0001-oci-include-the-domainname-in-kernel.domainname.patch
|
|
|
|
|
* bsc1001161-0002-cli-add-a-separate-domainname-flag.patch
|
|
|
|
|
* bsc1047218-0001-man-obey-SOURCE_DATE_EPOCH-when-generating-man-pages.patch
|
|
|
|
|
* bsc1128746-0001-integration-cli-don-t-build-test-images-if-they-alre.patch
|
|
|
|
|
* packaging-0001-revert-Remove-docker-prefix-for-containerd-and-runc-.patch
|
|
|
|
|
* private-registry-0001-Add-private-registry-mirror-support.patch
|
|
|
|
|
* secrets-0001-daemon-allow-directory-creation-in-run-secrets.patch
|
|
|
|
|
* secrets-0002-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
- Updated patch name:
|
|
|
|
|
+ bsc1073877-0001-apparmor-clobber-docker-default-profile-on-start.patch
|
|
|
|
|
- bsc1073877-0002-apparmor-clobber-docker-default-profile-on-start.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Mar 22 09:19:28 UTC 2019 - Sascha Grunert <sgrunert@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 18.09.3-ce. See upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Sun Mar 10 21:12:09 UTC 2019 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- docker-test: improvements to test packaging (we don't need to ship around the
|
|
|
|
|
entire source tree, and we also need to build the born-again integration/
|
|
|
|
|
tests which contain a suite-per-directory). We also need a new patch which
|
|
|
|
|
fixes the handling of *-test images. bsc#1128746
|
|
|
|
|
+ bsc1128746-0001-integration-cli-don-t-build-test-images-if-they-alre.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Feb 26 09:39:57 UTC 2019 - Michal Jura <mjura@suse.com>
|
|
|
|
|
|
|
|
|
|
- Move daemon.json file to /etc/docker directory, bsc#1114832
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Sat Feb 9 13:54:03 UTC 2019 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update shell completion to use Group: System/Shells.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Feb 6 14:37:43 UTC 2019 - Michal Jura <mjura@suse.com>
|
|
|
|
|
|
|
|
|
|
- Add daemon.json file with rotation logs cofiguration, bsc#1114832
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Feb 5 11:24:02 UTC 2019 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update to Docker 18.09.1-ce. See upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md. bsc#1124308
|
|
|
|
|
* Includes fix for CVE-2018-10892 bsc#1100331.
|
|
|
|
|
* Includes fix for CVE-2018-20699 bsc#1121768.
|
|
|
|
|
- Remove upstreamed patches.
|
|
|
|
|
- bsc1073877-0001-apparmor-allow-receiving-of-signals-from-docker-kill.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Jan 11 09:57:32 UTC 2019 - Sascha Grunert <sgrunert@suse.com>
|
|
|
|
|
|
|
|
|
|
- Disable leap based builds for kubic flavor. bsc#1121412
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Dec 19 19:28:47 UTC 2018 - clee@suse.com
|
|
|
|
|
|
|
|
|
|
- Update go requirements to >= go1.10.6 to fix
|
|
|
|
|
* bsc#1118897 CVE-2018-16873
|
|
|
|
|
go#29230 cmd/go: remote command execution during "go get -u"
|
|
|
|
|
* bsc#1118898 CVE-2018-16874
|
|
|
|
|
go#29231 cmd/go: directory traversal in "go get" via curly braces in import paths
|
|
|
|
|
* bsc#1118899 CVE-2018-16875
|
|
|
|
|
go#29233 crypto/x509: CPU denial of service
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Dec 18 10:10:06 UTC 2018 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Handle build breakage due to missing 'export GOPATH' (caused by resolution of
|
|
|
|
|
boo#1119634). I believe Docker is one of the only packages with this problem.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Dec 3 16:14:22 UTC 2018 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Add backports of https://github.com/docker/docker/pull/37302 and
|
|
|
|
|
https://github.com/docker/cli/pull/1130, which allow for users to explicitly
|
|
|
|
|
specify the NIS domainname of a container. bsc#1001161
|
|
|
|
|
+ bsc1001161-0001-oci-include-the-domainname-in-kernel.domainname.patch
|
|
|
|
|
+ bsc1001161-0002-cli-add-a-separate-domainname-flag.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Nov 29 09:41:11 UTC 2018 - Aleksa Sarai <asarai@suse.com>
|
|
|
|
|
|
|
|
|
|
- Update docker.service to match upstream and avoid rlimit problems.
|
|
|
|
|
bsc#1112980
|
|
|
|
|
- Upgrade to Docker 18.09.0-ce. See upstream changelog in the packaged
|
|
|
|
|
/usr/share/doc/packages/docker/CHANGELOG.md. boo#1115464 bsc#1118990
|
|
|
|
|
- Add revert of an upstream patch to fix docker-* handling.
|
|
|
|
|
+ packaging-0001-revert-Remove-docker-prefix-for-containerd-and-runc-.patch
|
|
|
|
|
- Rebase patches:
|
|
|
|
|
* bsc1047218-0001-man-obey-SOURCE_DATE_EPOCH-when-generating-man-pages.patch
|
|
|
|
|
* bsc1073877-0001-apparmor-allow-receiving-of-signals-from-docker-kill.patch
|
|
|
|
|
* bsc1073877-0002-apparmor-clobber-docker-default-profile-on-start.patch
|
|
|
|
|
* private-registry-0001-Add-private-registry-mirror-support.patch
|
|
|
|
|
* secrets-0001-daemon-allow-directory-creation-in-run-secrets.patch
|
|
|
|
|
* secrets-0002-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
- Remove upstreamed patches:
|
|
|
|
|
- bsc1100727-0001-build-add-buildmode-pie.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Oct 8 06:41:21 UTC 2018 - Valentin Rothberg <vrothberg@suse.com>
|
|
|
|
|
|
|
|
|
|
- Reduce the disk footprint by recommending git-core instead of
|
|
|
|
|
hard requiring it.
|
|
|
|
|
bsc#1108038
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Sep 4 08:32:43 UTC 2018 - rbrown@suse.com
|
|
|
|
|
|
|
|
|
|
- ExcludeArch i586 for entire docker-kubic flavour
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Sep 4 07:32:47 UTC 2018 - rbrown@suse.com
|
|
|
|
|
|
|
|
|
|
- ExcludeArch i586 for docker-kubic-kubeadm-criconfig subpackage
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Aug 24 08:17:41 UTC 2018 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Add patch to make package reproducible, which is a backport of
|
|
|
|
|
https://github.com/docker/cli/pull/1306. boo#1047218
|
|
|
|
|
+ bsc1047218-0001-man-obey-SOURCE_DATE_EPOCH-when-generating-man-pages.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Aug 22 09:54:57 UTC 2018 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Upgrade to docker-ce v18.06.1-ce. bsc#1102522 bsc#1113313
|
|
|
|
|
Upstream changelog:
|
|
|
|
|
https://github.com/docker/docker-ce/releases/tag/v18.06.1-ce
|
|
|
|
|
- Remove patches that were merged upstream:
|
|
|
|
|
- bsc1102522-0001-18.06-disable-containerd-CRI-plugin.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Aug 21 09:50:01 UTC 2018 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Add a backport of https://github.com/docker/engine/pull/29 for the 18.06.0-ce
|
|
|
|
|
upgrade. This is a potential security issue (the CRI plugin was enabled by
|
|
|
|
|
default, which listens on a TCP port bound to 0.0.0.0) that will be fixed
|
|
|
|
|
upstream in the 18.06.1-ce upgrade. bsc#1102522
|
|
|
|
|
+ bsc1102522-0001-18.06-disable-containerd-CRI-plugin.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Aug 21 09:39:57 UTC 2018 - rbrown@suse.com
|
|
|
|
|
|
|
|
|
|
- Kubic: Make crio default, docker as alternative runtime
|
|
|
|
|
(boo#1104821)
|
|
|
|
|
- Provide kubernetes CRI config with docker-kubic-kubeadm-criconfig
|
|
|
|
|
subpackage
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Aug 16 02:00:31 UTC 2018 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Merge -kubic packages back into the main Virtualization:containers packages.
|
|
|
|
|
This is done using _multibuild to add a "kubic" flavour, which is then used
|
|
|
|
|
to conditionally compile patches and other kubic-specific features.
|
|
|
|
|
bsc#1105000
|
|
|
|
|
- Rework docker-rpmlintrc with the new _multibuild setup.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Aug 1 09:40:59 UTC 2018 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Enable seccomp support on SLE12, since libseccomp is now a new enough vintage
|
|
|
|
|
to work with Docker and containerd. fate#325877
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Jul 31 09:48:16 UTC 2018 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Upgrade to docker-ce v18.06.0-ce. bsc#1102522
|
|
|
|
|
- Remove systemd-service dependency on containerd, which is now being started
|
|
|
|
|
by dockerd to align with upstream defaults.
|
|
|
|
|
- Removed the following patches as they are merged upstream:
|
|
|
|
|
- bsc1021227-0001-pkg-devmapper-dynamically-load-dm_task_deferred_remo.patch
|
|
|
|
|
- bsc1055676-0001-daemon-oci-obey-CL_UNPRIVILEGED-for-user-namespaced-.patch
|
|
|
|
|
- Rebased the following patches:
|
|
|
|
|
* bsc1073877-0001-apparmor-allow-receiving-of-signals-from-docker-kill.patch
|
|
|
|
|
* bsc1073877-0002-apparmor-clobber-docker-default-profile-on-start.patch
|
|
|
|
|
* bsc1100727-0001-build-add-buildmode-pie.patch
|
|
|
|
|
* secrets-0001-daemon-allow-directory-creation-in-run-secrets.patch
|
|
|
|
|
* secrets-0002-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Jul 30 09:44:47 UTC 2018 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Build the client binary with -buildmode=pie to fix issues on POWER.
|
|
|
|
|
bsc#1100727
|
|
|
|
|
+ bsc1100727-0001-build-add-buildmode-pie.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Jun 29 08:35:56 UTC 2018 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Update the AppArmor patchset again to fix a separate issue where changed
|
|
|
|
|
AppArmor profiles don't actually get applied on Docker daemon reboot.
|
|
|
|
|
bsc#1099277
|
|
|
|
|
* bsc1073877-0001-apparmor-allow-receiving-of-signals-from-docker-kill.patch
|
|
|
|
|
+ bsc1073877-0002-apparmor-clobber-docker-default-profile-on-start.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Jun 5 11:24:35 UTC 2018 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Update to AppArmor patch so that signal mediation also works for signals
|
|
|
|
|
between in-container processes. bsc#1073877
|
|
|
|
|
* bsc1073877-0001-apparmor-allow-receiving-of-signals-from-docker-kill.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Jun 5 08:41:07 UTC 2018 - dcassany@suse.com
|
|
|
|
|
|
|
|
|
|
- Make use of %license macro
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Jun 5 06:38:40 UTC 2018 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Remove 'go test' from %check section, as it has only ever caused us problems
|
|
|
|
|
and hasn't (as far as I remember) ever caught a release-blocking issue. Smoke
|
|
|
|
|
testing has been far more useful. boo#1095817
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue May 29 08:10:48 UTC 2018 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Update secrets patch to not log incorrect warnings when attempting to inject
|
|
|
|
|
non-existent host files. bsc#1065609
|
|
|
|
|
* secrets-0001-daemon-allow-directory-creation-in-run-secrets.patch
|
|
|
|
|
* secrets-0002-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed May 16 10:12:56 UTC 2018 - jmassaguerpla@suse.com
|
|
|
|
|
|
|
|
|
|
- Review Obsoletes to fix bsc#1080978
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Apr 12 12:49:25 UTC 2018 - fcastelli@suse.com
|
|
|
|
|
|
|
|
|
|
- Put docker under the podruntime slice. This the recommended
|
|
|
|
|
deployment to allow fine resource control on Kubernetes.
|
|
|
|
|
bsc#1086185
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Apr 10 09:25:43 UTC 2018 - mmeister@suse.com
|
|
|
|
|
|
|
|
|
|
- Add patch to handle AppArmor changes that make 'docker kill' stop working.
|
|
|
|
|
bsc#1073877 boo#1089732
|
|
|
|
|
+ bsc1073877-0001-apparmor-allow-receiving-of-signals-from-docker-kill.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Apr 6 04:21:28 UTC 2018 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Fix manpage generation breaking ppc64le builds due to a missing
|
|
|
|
|
-buildemode=pie.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Apr 4 12:27:29 UTC 2018 - vrothberg@suse.com
|
|
|
|
|
|
|
|
|
|
- Compile and install all manpages.
|
|
|
|
|
bsc#1085117
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Mar 27 10:13:41 UTC 2018 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Add requirement for catatonit, which provides a docker-init implementation.
|
|
|
|
|
fate#324652 bsc#1085380
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Mar 8 13:14:54 UTC 2018 - vrothberg@suse.com
|
|
|
|
|
|
|
|
|
|
- Fix private-registry-0001-Add-private-registry-mirror-support.patch to
|
|
|
|
|
deal corretly with TLS configs of 3rd party registries.
|
|
|
|
|
fix bsc#1084533
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Feb 13 10:45:58 UTC 2018 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Update patches to be sourced from https://github.com/suse/docker-ce (which
|
|
|
|
|
are based on the upstream docker/docker-ce repo). The reason for this change
|
|
|
|
|
(though it is functionally identical to the old patches) is so that public
|
|
|
|
|
patch maintenance is much simpler.
|
|
|
|
|
* bsc1021227-0001-pkg-devmapper-dynamically-load-dm_task_deferred_remo.patch
|
|
|
|
|
* bsc1055676-0001-daemon-oci-obey-CL_UNPRIVILEGED-for-user-namespaced-.patch
|
|
|
|
|
* private-registry-0001-Add-private-registry-mirror-support.patch
|
|
|
|
|
* secrets-0001-daemon-allow-directory-creation-in-run-secrets.patch
|
|
|
|
|
* secrets-0002-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Feb 12 10:52:33 UTC 2018 - rbrown@suse.com
|
|
|
|
|
|
|
|
|
|
- Add ${version} to equivalent non-kubic package provides
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Feb 8 12:34:51 UTC 2018 - rbrown@suse.com
|
|
|
|
|
|
|
|
|
|
- Add Provides for equivalent non-kubic packages
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Jan 30 12:27:44 UTC 2018 - vrothberg@suse.com
|
|
|
|
|
|
|
|
|
|
- Disable all tests for docker/client and docker/pkg/discovery. The unit tests
|
|
|
|
|
of those packages broke reproducibly the builds in IBS.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Jan 29 14:39:02 UTC 2018 - vrothberg@suse.com
|
|
|
|
|
|
|
|
|
|
- Disable flaky tests github.com/docker/docker/pkg/discovery/kv.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Jan 26 07:15:53 UTC 2018 - vrothberg@suse.com
|
|
|
|
|
|
|
|
|
|
- Add patch to support mirroring of private/non-upstream registries. As soon as
|
|
|
|
|
the upstream PR (https://github.com/moby/moby/pull/34319) is merged, this
|
|
|
|
|
patch will be replaced by the backported one from upstream.
|
|
|
|
|
+ private-registry-0001-Add-private-registry-mirror-support.patch
|
|
|
|
|
fix bsc#1074971
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Jan 19 14:12:32 UTC 2018 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Add Obsoletes: docker-image-migrator, as the tool is no longer needed and
|
|
|
|
|
we've pretty much removed it from everywhere except the containers module.
|
|
|
|
|
bsc#1069758
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Jan 19 07:48:10 UTC 2018 - vrothberg@suse.com
|
|
|
|
|
|
|
|
|
|
- Remove requirement on bridge-utils, which has been replaced by libnetwork in
|
|
|
|
|
Docker. bsc#1072798
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Dec 18 12:32:35 UTC 2017 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Update to Docker v17.09.1_ce (bsc#1069758). Upstream changelog:
|
|
|
|
|
https://github.com/docker/docker-ce/releases/tag/v17.09.1-ce
|
|
|
|
|
- Removed patches (merged upstream):
|
|
|
|
|
- bsc1045628-0001-devicemapper-remove-container-rootfs-mountPath-after.patch
|
|
|
|
|
- bsc1066210-0001-vendor-update-to-github.com-vbatts-tar-split-v0.10.2.patch
|
|
|
|
|
- bsc1066801-0001-oci-add-proc-scsi-to-masked-paths.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Dec 18 12:32:35 UTC 2017 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Update to Docker v17.09.0_ce. Upstream changelog:
|
|
|
|
|
https://github.com/docker/docker-ce/releases/tag/v17.09.0-ce
|
|
|
|
|
- Rebased patches:
|
|
|
|
|
* bsc1021227-0001-pkg-devmapper-dynamically-load-dm_task_deferred_remo.patch
|
|
|
|
|
* bsc1045628-0001-devicemapper-remove-container-rootfs-mountPath-after.patch
|
|
|
|
|
* bsc1055676-0001-daemon-oci-obey-CL_UNPRIVILEGED-for-user-namespaced-.patch
|
|
|
|
|
* secrets-0001-daemon-allow-directory-creation-in-run-secrets.patch
|
|
|
|
|
* secrets-0002-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
- Removed patches (merged upstream):
|
|
|
|
|
- bsc1064781-0001-Allow-to-override-build-date.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Dec 5 10:58:07 UTC 2017 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Add a patch to dynamically probe whether libdevmapper supports
|
|
|
|
|
dm_task_deferred_remove. This is necessary because we build the containers
|
|
|
|
|
module on a SLE12 base, but later SLE versions have libdevmapper support.
|
|
|
|
|
This should not affect openSUSE, as all openSUSE versions have a new enough
|
|
|
|
|
libdevmapper. Backport of https://github.com/moby/moby/pull/35518.
|
|
|
|
|
bsc#1021227 bsc#1029320 bsc#1058173
|
|
|
|
|
+ bsc1021227-0001-pkg-devmapper-dynamically-load-dm_task_deferred_remo.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Dec 4 12:22:29 UTC 2017 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Fix up the ordering of tests in docker.spec. This is to keep things easier to
|
|
|
|
|
backport into the SLE package.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Nov 30 10:15:20 UTC 2017 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Include secrets fix to handle "old" containers that have orphaned secret
|
|
|
|
|
data. It's not clear why Docker caches these secrets, but fix the problem by
|
|
|
|
|
trashing the references manually. bsc#1057743
|
|
|
|
|
* secrets-0002-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Thu Nov 23 13:48:08 UTC 2017 - rbrown@suse.com
|
|
|
|
|
|
|
|
|
|
- Replace references to /var/adm/fillup-templates with new
|
|
|
|
|
%_fillupdir macro (boo#1069468)
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Nov 14 22:39:56 UTC 2017 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Remove migration code for the v1.9.x -> v1.10.x migration. This has been
|
|
|
|
|
around for a while, and we no longer support migrating from such an old
|
|
|
|
|
version "nicely". Docker still has migration code that will run on
|
|
|
|
|
first-boot, we are merely removing all of the "nice" warnings which tell
|
|
|
|
|
users how to avoid issues during an upgrade that ocurred more than a year
|
|
|
|
|
ago.
|
|
|
|
|
- Drop un-needed files:
|
|
|
|
|
- docker-plugin-message.txt
|
|
|
|
|
- docker-update-message.txt
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Nov 7 16:47:01 UTC 2017 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Add a backport of https://github.com/moby/moby/pull/35424, which fixes a
|
|
|
|
|
security issue where a maliciously crafted image could be used to crash a
|
|
|
|
|
Docker daemon. bsc#1066210 CVE-2017-14992
|
|
|
|
|
+ bsc1066210-0001-vendor-update-to-github.com-vbatts-tar-split-v0.10.2.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Nov 7 09:00:31 UTC 2017 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Add a backport of https://github.com/moby/moby/pull/35399, which fixes a
|
|
|
|
|
security issue where a Docker container (with a disabled AppArmor profile)
|
|
|
|
|
could write to /proc/scsi/... and subsequently DoS the host. bsc#1066801
|
|
|
|
|
CVE-2017-16539
|
|
|
|
|
+ bsc1066801-0001-oci-add-proc-scsi-to-masked-paths.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Tue Oct 24 06:50:29 UTC 2017 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Correctly set `docker version` information, including the version, git
|
|
|
|
|
commit, and SOURCE_DATE_EPOCH (requires a backport). This should
|
|
|
|
|
*effectively* make Docker builds reproducible, with minimal cost. boo#1064781
|
|
|
|
|
+ bsc1064781-0001-Allow-to-override-build-date.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Oct 16 11:06:22 UTC 2017 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Add backport of https://github.com/moby/moby/pull/35205. This used to be
|
|
|
|
|
fixed in docker-runc, but we're moving it here after upstream discussion.
|
|
|
|
|
bsc#1055676
|
|
|
|
|
+ bsc1055676-0001-daemon-oci-obey-CL_UNPRIVILEGED-for-user-namespaced-.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Oct 9 11:36:59 UTC 2017 - asarai@suse.com
|
|
|
|
|
|
|
|
|
|
- Update to Docker v17.07.0_ce. Upstream changelog:
|
|
|
|
|
https://github.com/docker/docker-ce/releases/tag/v17.06.0-ce
|
|
|
|
|
https://github.com/docker/docker-ce/releases/tag/v17.07.0-ce
|
|
|
|
|
- Removed no-longer needed patches.
|
|
|
|
|
- bsc1037436-0001-client-check-tty-before-creating-exec-job.patch
|
|
|
|
|
- bsc1037607-0001-apparmor-make-pkg-aaparser-work-on-read-only-root.patch
|
|
|
|
|
- integration-cli-fix-TestInfoEnsureSucceeds.patch
|
|
|
|
|
- Added backport of https://github.com/moby/moby/pull/34573. bsc#1045628
|
|
|
|
|
+ bsc1045628-0001-devicemapper-remove-container-rootfs-mountPath-after.patch
|
|
|
|
|
- Rewrite secrets patches to correctly handle directories in a way that doesn't
|
|
|
|
|
cause errors when starting new containers.
|
|
|
|
|
* secrets-0001-daemon-allow-directory-creation-in-run-secrets.patch
|
|
|
|
|
* secrets-0002-SUSE-implement-SUSE-container-secrets.patch
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Mon Oct 2 08:12:17 UTC 2017 - vrothberg@suse.com
|
|
|
|
|
|
|
|
|
|
- Fix bsc#1059011
|
|
|
|
|
|
|
|
|
|
The systemd service helper script used a timeout of 60 seconds to
|
|
|
|
|
start the daemon, which is insufficient in cases where the daemon
|
|
|
|
|
takes longer to start. Instead, set the service type from 'simple' to
|
|
|
|
|
'notify' and remove the now superfluous helper script.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Wed Sep 27 15:04:19 UTC 2017 - jmassaguerpla@suse.com
|
|
|
|
|
|
|
|
|
|
- fix bsc#1057743: Add a Requires: fix_bsc_1057743 which is provided by the
|
|
|
|
|
newer version of docker-libnetwork. This is necessary because of a versioning
|
|
|
|
|
bug we found in bsc#1057743.
|
|
|
|
|
|
|
|
|
|
-------------------------------------------------------------------
|
|
|
|
|
Fri Sep 15 15:32:49 UTC 2017 - jmassaguerpla@suse.com
|
|
|
|
|
|
|
|
|
|
- fix /var/adm/update-message/docker file name to be
|
|
|
|
|
/var/adm/update-message/docker-%{version}-%{release}
|
|
|
|
|
|
|
|
|