Commit Graph

  • df931afd90 Accepting request 1302771 from Virtualization:containers factory Ana Guerrero 2025-09-05 19:42:22 +00:00
  • f8f5090fcb Fix SUSEConnect+buildx changelog entry. Aleksa Sarai 2025-09-04 15:40:43 +00:00
  • 1571af50e2 - Update to docker-buildx v0.28.0. Upstream changelog: <https://github.com/docker/buildx/releases/tag/v0.28.0> - Update to Docker 28.4.0-ce. See upstream changelog online at <https://docs.docker.com/engine/release-notes/28/#2840> - Rebased patches: * 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch * 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch * cli-0001-openSUSE-point-users-to-docker-buildx-package.patch * cli-0002-SECRETS-SUSE-default-to-DOCKER_BUILDKIT-0-for-docker.patch Aleksa Sarai 2025-09-04 15:30:45 +00:00
  • 92ad80cecc Accepting request 1302148 from Virtualization:containers Ana Guerrero 2025-09-01 15:16:51 +00:00
  • 533ef8e35e - Update warnings and errors related to "docker buildx ..." so that they reference our openSUSE docker-buildx packages. + cli-0001-openSUSE-point-users-to-docker-buildx-package.patch Aleksa Sarai 2025-09-01 06:21:40 +00:00
  • b430a54521 - Enable building docker-buildx for SLE systems with SUSEConnect secret injection enabled (i.e., SLE15 and earlier). PED-12534 PED-8905 bsc#1247594 As docker-buildx does not support our SUSEConnect secret injection (and some users depend "docker build" working transparently), patch the docker CLI so that "docker build" will no longer automatically call "docker buildx build", effectively making DOCKER_BUILDKIT=0 the default configuration. Users can manually use "docker buildx ..." commands or set DOCKER_BUILDKIT=1 in order to opt-in to using docker-buildx. Aleksa Sarai 2025-09-01 06:00:17 +00:00
  • 22f297a04a Accepting request 1297919 from Virtualization:containers Dominique Leuenberger 2025-08-06 16:41:23 +00:00
  • 1dc8abd5ca Accepting request 1296345 from Virtualization:containers Dominique Leuenberger 2025-07-30 09:42:08 +00:00
  • 8209c912ee Accepting request 1296528 from home:cyphar:docker devel Aleksa Sarai 2025-07-30 09:36:22 +00:00
  • 924b24592b - Update to Docker 28.3.3-ce. See upstream changelog online at <https://docs.docker.com/engine/release-notes/28/#2833> CVE-2025-54388 Aleksa Sarai 2025-07-29 14:52:57 +00:00
  • cff1a2c48d Accepting request 1295197 from Virtualization:containers Dominique Leuenberger 2025-07-24 16:34:40 +00:00
  • a81b7b9cba - Update to docker-buildx v0.26.1. Upstream changelog: <https://github.com/docker/buildx/releases/tag/v0.26.1> Aleksa Sarai 2025-07-23 04:33:16 +00:00
  • 3177dadb1d Accepting request 1294744 from Virtualization:containers slfo-main slfo-1.2 Ana Guerrero 2025-07-21 18:00:26 +00:00
  • a9817d2f90 Add bsc#1246556 reference. Aleksa Sarai 2025-07-21 06:09:47 +00:00
  • 323e2d4ca9 Accepting request 1293990 from Virtualization:containers Ana Guerrero 2025-07-18 13:57:38 +00:00
  • 487c67f1de - Update to Go 1.24 for builds, to match upstream. Aleksa Sarai 2025-07-17 04:34:00 +00:00
  • 406a71b522 Accepting request 1293103 from Virtualization:containers Ana Guerrero 2025-07-15 14:42:02 +00:00
  • ddbb0cf9b0 - Update to Docker 28.3.2-ce. See upstream changelog online at <https://docs.docker.com/engine/release-notes/28/#2832> Dirk Mueller 2025-07-14 10:23:10 +00:00
  • d7c9b3e5f2 Accepting request 1290059 from Virtualization:containers Ana Guerrero 2025-07-06 14:59:38 +00:00
  • 8beeee3eda - Update to Docker 28.3.1-ce. See upstream changelog online at <https://docs.docker.com/engine/release-notes/28/#2831> Aleksa Sarai 2025-07-03 02:34:03 +00:00
  • 4f26a3a4f8 Accepting request 1288579 from Virtualization:containers Ana Guerrero 2025-06-26 12:05:40 +00:00
  • 7944c3c06a - Update to Docker 28.3.0-ce. See upstream changelog online at <https://docs.docker.com/engine/release-notes/28/#2830> - Rebase patches: * 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch * 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch Aleksa Sarai 2025-06-25 15:46:10 +00:00
  • 02b514011a Accepting request 1287937 from Virtualization:containers Ana Guerrero 2025-06-24 18:46:07 +00:00
  • e65290c603 Fix SUSEConnect patch build. Aleksa Sarai 2025-06-23 13:07:50 +00:00
  • 4f0ef3de34 [ This update is a no-op, only needed to work around unfortunate automated packaging script behaviour on SLES. ] Aleksa Sarai 2025-06-23 12:56:51 +00:00
  • ed61589e0d Accepting request 1283419 from Virtualization:containers Ana Guerrero 2025-06-10 06:57:46 +00:00
  • cc421e65c3 fix pkg/errors import Aleksa Sarai 2025-06-05 16:36:19 +00:00
  • e827a6b7ca Improve patchset changes. Aleksa Sarai 2025-06-05 16:34:25 +00:00
  • 1f58d49808 - Do not try to inject SUSEConnect secrets when in Rootless Docker mode, as Docker does not have permission to access the host zypper credentials in this mode (and unprivileged users cannot disable the feature using /etc/docker/suse-secrets-enable.) bsc#1240150 Aleksa Sarai 2025-06-05 16:19:52 +00:00
  • cb1fadaa4b - Always clear SUSEConnect suse_* secrets when starting containers regardless of whether the daemon was built with SUSEConnect support. Not doing this causes containers from SUSEConnect-enabled daemons to fail to start when running with SUSEConnect-disabled (i.e. upstream) daemons. Aleksa Sarai 2025-06-04 06:14:23 +00:00
  • 69630be04c Accepting request 1281542 from Virtualization:containers Ana Guerrero 2025-06-02 19:59:08 +00:00
  • 37241ca5cc - Update to Docker 28.2.2-ce. See upstream changelog online at <https://github.com/moby/moby/releases/tag/v28.2.2> - Rebase patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch Aleksa Sarai 2025-05-30 17:59:48 +00:00
  • 3f2382a8b2 - Update to Docker 28.2.1-ce. See upstream changelog online at <https://docs.docker.com/engine/release-notes/28/#2820> bsc#1243833 - Rebase patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch - Update to docker-buildx v0.24.0. Upstream changelog: <https://github.com/docker/buildx/releases/tag/v0.24.0> Aleksa Sarai 2025-05-30 09:46:29 +00:00
  • 8371f55e1e Accepting request 1273868 from Virtualization:containers Dominique Leuenberger 2025-05-02 12:56:14 +00:00
  • ba29e28bc2 - Update to Docker 28.1.1-ce. See upstream changelog online at <https://docs.docker.com/engine/release-notes/28/#2811> bsc#1242114 Includes upstream fixes: - CVE-2025-22872 bsc#1241830 - Remove long-outdated build handling for deprecated and unsupported devicemapper and AUFS storage drivers. AUFS was removed in v24, and devicemapper was removed in v25. <https://docs.docker.com/engine/deprecated/#aufs-storage-driver> - Rebase patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch - Remove upstreamed patches: - 0006-CVE-2025-22868-vendor-jws-split-token-into-fixed-num.patch - 0007-CVE-2025-22869-vendor-ssh-limit-the-size-of-the-inte.patch - cli-0001-docs-include-required-tools-in-source-tree.patch - Update to docker-buildx v0.23.0. Upstream changelog: <https://github.com/docker/buildx/releases/tag/v0.23.0> Aleksa Sarai 2025-05-01 17:17:53 +00:00
  • d1bd3c357c Accepting request 1268264 from Virtualization:containers Ana Guerrero 2025-04-11 14:45:32 +00:00
  • 212e67e0d3 - Update to docker-buildx v0.22.0. Upstream changelog: <https://github.com/docker/buildx/releases/tag/v0.22.0> * Includes fixes for CVE-2025-0495. bsc#1239765 - Disable transparent SUSEConnect support for SLE-16. PED-12534 When this patchset was first added in 2013 (and rewritten over the years), there was no upstream way to easily provide SLE customers with a way to build container images based on SLE using the host subscription. However, with docker-buildx you can now define secrets for builds (this is not entirely transparent, but we can easily document this new requirement for SLE-16). Users should use RUN --mount=type=secret,id=SCCcredentials zypper -n ... in their Dockerfiles, and docker buildx build --secret id=SCCcredentials,src=/etc/zypp/credentials.d/SCCcredentials,type=file . when doing their builds. - Now that the only blocker for docker-buildx support was removed for SLE-16, enable docker-buildx for SLE-16 as well. PED-8905 Aleksa Sarai 2025-04-10 03:37:01 +00:00
  • cffd8cbd08 - Don't use the new container-selinux conditional requires on SLE-12, as the RPM version there doesn't support it. Arguably the change itself is a bit suspect but we can fix that later. bsc#1237367 Aleksa Sarai 2025-03-26 02:43:19 +00:00
  • 836cda6985 - Add backport for golang.org/x/oauth2 CVE-2025-22868 fix. bsc#1239185 + 0006-CVE-2025-22868-vendor-jws-split-token-into-fixed-num.patch - Add backport for golang.org/x/crypto CVE-2025-22869 fix. bsc#1239322 + 0007-CVE-2025-22869-vendor-ssh-limit-the-size-of-the-inte.patch - Refresh patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch - Add backport for golang.org/x/oauth2 CVE-2025-22868 fix. bsc#1239185 + 0006-CVE-2025-22868-vendor-jws-split-token-into-fixed-num.patch - Add backport for golang.org/x/crypto CVE-2025-22869 fix. bsc#1239322 + 0007-CVE-2025-22869-vendor-ssh-limit-the-size-of-the-inte.patch - Refresh patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch Aleksa Sarai 2025-03-25 04:21:54 +00:00
  • 2d61de33db Accepting request 1254953 from Virtualization:containers Ana Guerrero 2025-03-21 19:21:51 +00:00
  • 2ca7ac0f0f - Make container-selinux requirement conditional on selinux-policy (bsc#1237367) Dan Čermák 2025-03-21 09:06:19 +00:00
  • efef872286 Accepting request 1246830 from Virtualization:containers Ana Guerrero 2025-02-20 15:27:07 +00:00
  • f02cd51b7d Accepting request 1246829 from home:cyphar:docker Aleksa Sarai 2025-02-19 04:52:58 +00:00
  • 93f33fbbcb Accepting request 1231895 from Virtualization:containers Ana Guerrero 2024-12-18 19:09:12 +00:00
  • 22827cbc1b - Update to Docker 27.4.1-ce. See upstream changelog online at <https://docs.docker.com/engine/release-notes/27/#2741> - Rebase patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch * cli-0001-docs-include-required-tools-in-source-tree.patch Aleksa Sarai 2024-12-18 13:03:50 +00:00
  • d69d01a8db Add bsc#1234089 CVE-2024-29018 reference. Aleksa Sarai 2024-12-18 06:26:28 +00:00
  • ae8b5fe738 - Update to docker-buildx 0.19.3. See upstream changelog online at <https://github.com/docker/buildx/releases/tag/v0.19.3> Aleksa Sarai 2024-12-17 13:26:18 +00:00
  • f9cd741afc - Update to Docker 27.4.0-ce. See upstream changelog online at <https://docs.docker.com/engine/release-notes/27/#274> - Rebase patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch * cli-0001-docs-include-required-tools-in-source-tree.patch - Remove upstreamed patches: - 0006-bsc1221916-update-to-patched-buildkit-version-to-fix.patch - 0007-bsc1214855-volume-use-AtomicWriteFile-to-save-volume.patch Aleksa Sarai 2024-12-16 07:04:37 +00:00
  • 598ab51442 Accepting request 1230151 from Virtualization:containers Ana Guerrero 2024-12-13 21:32:49 +00:00
  • bdc26590fb Accepting request 1230148 from home:cyphar:docker Aleksa Sarai 2024-12-11 15:36:12 +00:00
  • 9a4f7f6039 Accepting request 1230066 from home:cyphar:docker Aleksa Sarai 2024-12-11 10:51:14 +00:00
  • 2ddb1de5c3 Accepting request 1228305 from Virtualization:containers Ana Guerrero 2024-12-05 16:05:19 +00:00
  • a78dff7569 - Disable docker-buildx builds for SLES. It turns out that build containers with docker-buildx don't currently get the SUSE secrets mounts applied, meaning that container-suseconnect doesn't work when building images. bsc#1233819 Aleksa Sarai 2024-11-27 12:52:26 +00:00
  • 09f45a6980 Accepting request 1224334 from Virtualization:containers Ana Guerrero 2024-11-15 14:38:04 +00:00
  • fb27775c7c Add bsc#1232999 reference. Aleksa Sarai 2024-11-15 01:07:11 +00:00
  • e3eecc4a34 Format specfile. Aleksa Sarai 2024-11-15 00:48:16 +00:00
  • 6a719b3954 - Remove DOCKER_NETWORK_OPTS from docker.service. This was removed from sysconfig a long time ago, and apparently this causes issues with systemd in some cases. Aleksa Sarai 2024-11-15 00:13:38 +00:00
  • 2b22e66486 Accepting request 1219984 from Virtualization:containers Dominique Leuenberger 2024-11-01 20:47:08 +00:00
  • 91c73e108b osc copypac from project:Virtualization:containers package:docker revision:413, using keep-link Aleksa Sarai 2024-11-01 00:04:14 +00:00
  • c30a8d1a08 Accepting request 1219449 from Virtualization:containers Dominique Leuenberger 2024-10-31 15:09:11 +00:00
  • 6246803744 - fix build for SLE12+ Dirk Mueller 2024-10-22 13:49:02 +00:00
  • bd70f4dc19 Accepting request 1208742 from Virtualization:containers Ana Guerrero 2024-10-20 08:13:04 +00:00
  • 245fad9603 - Further merge docker and docker-stable specfiles to minimise the differences. The main thing is that we now include both halves of the Conflicts/Provides/Obsoletes dance in both specfiles. Aleksa Sarai 2024-10-18 00:34:51 +00:00
  • c4b3c605db Accepting request 1208252 from Virtualization:containers Ana Guerrero 2024-10-16 21:36:50 +00:00
  • 590d71b04d - Update to docker-buildx v0.17.1 to match standalone docker-buildx package we are replacing. See upstream changelog online at <https://github.com/docker/buildx/releases/tag/v0.17.1> Aleksa Sarai 2024-10-16 05:42:35 +00:00
  • 81aaf8950a - Allow users to disable SUSE secrets support by setting DOCKER_SUSE_SECRETS_ENABLE=0 in /etc/sysconfig/docker. bsc#1231348 - Mark docker-buildx as required since classic "docker build" has been deprecated since Docker 23.0. bsc#1230331 - Import docker-buildx v0.16.2 as a subpackage. Previously this was a separate package, but with docker-stable it will be necessary to maintain the packages together and it makes more sense to have them live in the same OBS package. bsc#1230333 - Make some minor name macro updates to help with the docker-stable package fork. Aleksa Sarai 2024-10-15 05:59:40 +00:00
  • da5612206c Accepting request 1201947 from Virtualization:containers Ana Guerrero 2024-09-30 13:34:54 +00:00
  • 84b4bc3b21 fix Ana Guerrero 2024-09-19 07:05:47 +00:00
  • d6005dc22f - Add %{_sysconfdir}/audit/rules.d to filelist Dirk Mueller 2024-09-18 15:50:40 +00:00
  • 069b069692 Accepting request 1199307 from Virtualization:containers Ana Guerrero 2024-09-10 19:13:23 +00:00
  • 4e5c898b67 Add bsc#1230294 reference. Aleksa Sarai 2024-09-07 04:01:38 +00:00
  • 903c5fa2d7 Accepting request 1199007 from Virtualization:containers Ana Guerrero 2024-09-06 15:18:09 +00:00
  • bab2de8fff Add CVE references. Aleksa Sarai 2024-09-05 14:28:46 +00:00
  • 3480afa22e Accepting request 1190568 from Virtualization:containers Dominique Leuenberger 2024-08-01 20:03:42 +00:00
  • 2b14743f6e Accepting request 1190567 from home:cyphar:docker Aleksa Sarai 2024-07-31 05:49:49 +00:00
  • 5a65005d4a Accepting request 1182989 from Virtualization:containers Ana Guerrero 2024-06-24 18:50:54 +00:00
  • c4e850f70c Accepting request 1182985 from home:cyphar:docker Aleksa Sarai 2024-06-24 09:33:37 +00:00
  • 78fb6443aa Accepting request 1170269 from Virtualization:containers Ana Guerrero 2024-04-26 21:26:43 +00:00
  • 06460be95f Accepting request 1170268 from home:cyphar:docker Aleksa Sarai 2024-04-26 09:49:08 +00:00
  • b3cb6fc020 Accepting request 1170079 from home:cyphar:docker Aleksa Sarai 2024-04-24 21:20:41 +00:00
  • f84318c1f3 Accepting request 1151209 from Virtualization:containers Ana Guerrero 2024-02-27 21:44:10 +00:00
  • 6245febf22 Accepting request 1149534 from home:kukuk:no-utmp Dan Čermák 2024-02-26 11:16:23 +00:00
  • af5f657805 Accepting request 1147713 from Virtualization:containers Ana Guerrero 2024-02-21 16:52:04 +00:00
  • febbaafee6 Accepting request 1147637 from home:danishprakash:branches:Virtualization:containers Dan Čermák 2024-02-20 08:51:39 +00:00
  • 6b492dc520 Accepting request 1146862 from Virtualization:containers Ana Guerrero 2024-02-16 20:41:33 +00:00
  • 4406dfe326 Accepting request 1146719 from home:dancermak:branches:Virtualization:containers Danish Prakash 2024-02-15 14:06:27 +00:00
  • 347a50b30a Accepting request 1129616 from Virtualization:containers Ana Guerrero 2023-11-28 21:18:26 +00:00
  • e62df9de4c Accepting request 1129615 from home:cyphar:docker Aleksa Sarai 2023-11-28 13:41:42 +00:00
  • 8ee02a0b77 Accepting request 1129485 from home:cyphar:docker Aleksa Sarai 2023-11-28 09:55:45 +00:00
  • c749fd4874 Accepting request 1120880 from Virtualization:containers Ana Guerrero 2023-10-29 18:39:44 +00:00
  • 67d760b1ca Accepting request 1120879 from home:cyphar:docker Aleksa Sarai 2023-10-28 06:06:16 +00:00
  • 987d43aae5 Accepting request 1116896 from Virtualization:containers Ana Guerrero 2023-10-12 21:39:14 +00:00
  • 47539840b4 Accepting request 1116895 from home:cyphar:docker Aleksa Sarai 2023-10-11 10:44:20 +00:00
  • 335d5bc74a Accepting request 1111025 from Virtualization:containers Ana Guerrero 2023-09-14 14:25:08 +00:00
  • f28071cbb5 - Update to Docker 24.0.6-ce. See upstream changelong online at <https://docs.docker.com/engine/release-notes/24.0/#2406>. bsc#1215323 - Rebase patches: * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch * cli-0001-docs-include-required-tools-in-source-tree.patch - Switch from disabledrun to manualrun in _service. - Add a docker.socket unit file, but with socket activation effectively disabled to ensure that Docker will always run even if you start the socket individually. Users should probably just ignore this unit file. bsc#1210141 Aleksa Sarai 2023-09-14 06:38:15 +00:00
  • f362c288b1 Accepting request 1109451 from Virtualization:containers Ana Guerrero 2023-09-07 19:12:57 +00:00
  • aa4eb4b1c7 Accepting request 1108556 from home:msmeissn:branches:Virtualization:containers Dirk Mueller 2023-09-07 08:03:44 +00:00
  • f19c554f4c Accepting request 1100698 from Virtualization:containers Ana Guerrero 2023-07-26 11:22:05 +00:00
  • b00fbb945c - update to Docker 24.0.5-ce. See upstream changelong online at <https://docs.docker.com/engine/release-notes/24.0/#2405>. bsc#1213229 Dirk Mueller 2023-07-25 19:41:47 +00:00
  • 0550e1511e Accepting request 1099610 from Virtualization:containers Ana Guerrero 2023-07-24 16:25:00 +00:00