a9fb98f48b
GO-2026-4441, bsc#1258048). even never returns (CVE-2025-47911, GO-2026-4440, bsc#1258047).
Egbert Eich2026-02-13 11:31:44 +00:00
5c5da86a40
Accepting request 1332454 from network:cluster
Ana Guerrero2026-02-11 17:49:26 +00:00
2de19b9281
- Fix HTML parser misimplementation of a part of the HTML specification for table related tags (CVE-2025-58190, GO-2026-4441, bsc#1258047). - Fix issue where the HTML parser takes a very long time or even never returns (CVE-2025-47911, GO-2026-4440, bsc#1258048).
Egbert Eich2026-02-11 11:28:03 +00:00
ae814856cf
Accepting request 1325744 from network:cluster
Ana Guerrero2026-01-07 15:02:24 +00:00
a68eefb93d
- Update to 1.4.3 * Corrected the mconfig -s option for statically building apptainer and starter binaries. * Resolved an issue where the Makefile generated by mconfig -b failed when the build directory was not a subdirectory of the Apptainer source code. * Fixed %files in definition files to correctly copy symlinks pointing above the destination directory but within the destination stage root filesystem. * Addressed a typo in nvliblist.conf ( libnvoptix.so.1 was corrected to libnvoptix.so). * Prevented timeouts during cleanup after building gocryptfs-encrypted SIF files. * Fixed a bug that prevented build with --passphrase or --pem-path (without --encrypt) from implying fakeroot. * Resolved a hang when copying files between build stages while using suid mode without user namespaces. * Fixed issues with running and building containers of different architectures than the host via binfmt_misc when using rootless fakeroot. * Corrected "target: no such file or directory" errors when extracting layers from certain OCI images that manipulate hard links across layers. * Fixed a crash when executing a privilege-encrypted container as root. * Improved documentation for the remote list command. * Removed the fakerootcallback functionality. * Updated the default pacman confURL for Bootstrap: arch container builds. * Updated bundled fuse programs to their latest releases.
Christian Goll2025-10-02 07:59:32 +00:00
4ec48735e0
- Add definition file for SLE 16 (SLE-16.def). - Remove definition files for SLE15 SP5 (SLE-15SP5.def) and SP6 (SLE-15SP6.def).
Christian Goll2025-10-02 07:57:00 +00:00
2614a0774d
Accepting request 1303080 from home:amanzini:branches:network:cluster
Christian Goll2025-09-08 09:44:42 +00:00
6606382c73
Accepting request 1283596 from network:cluster
Ana Guerrero2025-06-06 20:44:23 +00:00
a76a19153f
Reformatted changelog: * Fix the use of libsubid which had been broken by the revision applied in 1.4.0-rc.2. * Fix a bug introduced in 1.4.0 that caused arm64 to be mis-converted to arm64v8 and resulted in a failure when pulling OCI containers. * Fix user database lookup in master process preventing instance from starting correctly on systems using winbind. * Check for existence of /run/systemd/system when verifying cgroups can be used via systemd manager. * Add a clear error message if someone tries to use privileged network options while not using setuid mode. * Allow multi-arch oci-archive files that have a nested index with the manifest. This is the default format (both for Docker and OCI) when using nerdctl save. * Test if docker-archive is actually an oci-archive (since Docker version 25), and if it is oci then use the OCI parser to avoid bugs in the Docker parser. Save the daemon-daemon references to a temporary docker-archive, to benefit from the same improvements also for those references. Parse as oci-archive. * Add new build option --mksquashfs-args to pass additional arguments to the mksquashfs command when building SIF files. If a compression method other than gzip is selected, the SIF file might not work with older installations of Apptainer or Singularity, so an INFO message about that is printed. On the other hand, an INFO message that was printed (twice) when running an image with non-gzip compression has been removed. * If the mksquashfs version is new enough (version 4.6 in Leaep 16.0), then show a percentage progress bar (with ETA) during SIF creation in the default log level. If the mksquashfs version is older, then in verbose or debug log level show the
Egbert Eich2025-06-06 10:02:55 +00:00
d31ec6f7e2
Accepting request 1281891 from home:mslacken:pr
Egbert Eich2025-06-06 09:25:17 +00:00
173413e718
Accepting request 1254799 from network:cluster
Ana Guerrero2025-03-21 19:22:02 +00:00
6c62b3f789
Accepting request 1254798 from home:eeich:branches:network:cluster
Egbert Eich2025-03-20 17:01:09 +00:00
377260e709
Accepting request 1254788 from home:eeich:branches:network:cluster
Egbert Eich2025-03-20 16:33:41 +00:00
104912fd90
Accepting request 1254221 from network:cluster
Ana Guerrero2025-03-19 21:33:08 +00:00
b3034977bb
Accepting request 1254220 from home:eeich:branches:network:cluster
Egbert Eich2025-03-18 18:33:01 +00:00
a6564cbd0a
Accepting request 1241325 from network:cluster
Ana Guerrero2025-01-30 13:53:08 +00:00
4729590fb7
Accepting request 1241243 from home:eeich:branches:network:cluster
Egbert Eich2025-01-30 11:12:14 +00:00
c6d7fe8064
Accepting request 1237414 from network:cluster
Ana Guerrero2025-01-13 16:53:13 +00:00
ea2e12059d
Accepting request 1173630 from home:eeich:branches:network:cluster
Christian Goll2024-05-13 12:21:52 +00:00
e5ac1fc1cf
Accepting request 1173630 from home:eeich:branches:network:cluster
Christian Goll2024-05-13 12:21:52 +00:00
a8651ef236
Accepting request 1160483 from network:cluster
Ana Guerrero2024-03-22 14:20:22 +00:00
992031c060
Accepting request 1160483 from network:cluster
Ana Guerrero2024-03-22 14:20:22 +00:00
16c1bbbbc9
Accepting request 1160482 from home:eeich:branches:network:cluster
Egbert Eich2024-03-21 22:33:13 +00:00
f18065236f
Accepting request 1160482 from home:eeich:branches:network:cluster
Egbert Eich2024-03-21 22:33:13 +00:00
6e7ca168c8
- Make 'gocryptfs' an optional dependency.
Egbert Eich2024-03-21 18:12:10 +00:00
7778f0340b
- Make 'gocryptfs' an optional dependency.
Egbert Eich2024-03-21 18:12:10 +00:00
764f839d6f
are primarily used for the --overlay feature), restoring of the security risk. image driver will be used instead. would enable a user to theoretically bypass the limits via ptrace() because the FUSE process runs as that user. one of the layers is a FUSE filesystem). In addition, if allow setuid-mount encrypted = no then the unprivileged gocryptfs format can still be used with the --underlay option, but it is deprecated their own, dedicated keyserver command. Run apptainer help keyserver for more information. been moved to their own, dedicated registry command. Run * The remote status command will now print the username, realname, and email of the logged-in user, if available.
Egbert Eich2024-03-21 16:29:10 +00:00
0c9bfa3614
are primarily used for the --overlay feature), restoring of the security risk. image driver will be used instead. would enable a user to theoretically bypass the limits via ptrace() because the FUSE process runs as that user. one of the layers is a FUSE filesystem). In addition, if allow setuid-mount encrypted = no then the unprivileged gocryptfs format can still be used with the --underlay option, but it is deprecated their own, dedicated keyserver command. Run apptainer help keyserver for more information. been moved to their own, dedicated registry command. Run * The remote status command will now print the username, realname, and email of the logged-in user, if available.
Egbert Eich2024-03-21 16:29:10 +00:00
fbe0c3103a
Accepting request 1159335 from home:mslacken:pr
Egbert Eich2024-03-21 16:19:42 +00:00
978ad90979
Accepting request 1159335 from home:mslacken:pr
Egbert Eich2024-03-21 16:19:42 +00:00
7ed58aadab
Accepting request 1157874 from network:cluster
Ana Guerrero2024-03-14 16:45:04 +00:00
4ecb972867
Accepting request 1157874 from network:cluster
Ana Guerrero2024-03-14 16:45:04 +00:00
62b21fe220
Accepting request 1157757 from home:eeich:branches:network:cluster
Christian Goll2024-03-14 08:00:10 +00:00
4000bd5a59
Accepting request 1157757 from home:eeich:branches:network:cluster
Christian Goll2024-03-14 08:00:10 +00:00
9a524b97e7
Accepting request 1143604 from network:cluster
Ana Guerrero2024-02-02 14:48:00 +00:00
da193ea6bf
Accepting request 1143604 from network:cluster
Ana Guerrero2024-02-02 14:48:00 +00:00
33caaa9a61
Accepting request 1143317 from home:eeich:branches:network:cluster
Egbert Eich2024-02-02 10:42:39 +00:00
c63dd1002e
Accepting request 1143317 from home:eeich:branches:network:cluster
Egbert Eich2024-02-02 10:42:39 +00:00
8cb96cf334
Accepting request 1143195 from network:cluster
Ana Guerrero2024-02-01 17:05:13 +00:00
9d22fa5c6a
Accepting request 1143195 from network:cluster
Ana Guerrero2024-02-01 17:05:13 +00:00
58d17c44a2
Accepting request 1143083 from home:eeich:branches:network:cluster
Christian Goll2024-02-01 07:37:58 +00:00
6985fd371d
Accepting request 1143083 from home:eeich:branches:network:cluster
Christian Goll2024-02-01 07:37:58 +00:00
77ae9ed67b
Accepting request 1120777 from network:cluster
Ana Guerrero2023-10-27 20:27:52 +00:00
8222967b55
Accepting request 1120777 from network:cluster
Ana Guerrero2023-10-27 20:27:52 +00:00