Commit Graph

182 Commits

Author SHA256 Message Date
Aleksa Sarai
9c821cca87 Accepting request 735404 from home:cyphar:containers:maint
- Upgrade to runc v1.0.0~rc9. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc9
- Remove upstreamed patches:
  - CVE-2019-16884.patch

OBS-URL: https://build.opensuse.org/request/show/735404
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=81
2019-10-05 11:52:50 +00:00
Aleksa Sarai
2606526c7c Accepting request 733834 from home:cyphar:containers:maint
Add reference to bsc#1152308.

OBS-URL: https://build.opensuse.org/request/show/733834
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=80
2019-09-28 11:41:04 +00:00
Aleksa Sarai
c2791cd3be Fix From: line for CVE-2019-16884.
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=79
2019-09-27 20:22:13 +00:00
Aleksa Sarai
53bd0f1302 Accepting request 733753 from home:cyphar:containers:maint
Add /proc/self/fd protections to CVE-2019-16884.patch.

OBS-URL: https://build.opensuse.org/request/show/733753
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=78
2019-09-27 20:18:17 +00:00
Aleksa Sarai
c0cf07af42 Accepting request 733530 from home:cyphar:containers:maint
Fix CVE patch.

OBS-URL: https://build.opensuse.org/request/show/733530
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=77
2019-09-27 03:17:22 +00:00
Aleksa Sarai
1a94d9d340 Accepting request 733478 from home:cyphar:containers:maint
- Add backported fix for CVE-2019-16884.
  + CVE-2019-16884.patch
- Add runc-rpmlintrc to drop runc-test rpmlint warnings.

OBS-URL: https://build.opensuse.org/request/show/733478
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=76
2019-09-26 15:15:16 +00:00
Dominique Leuenberger
0eb4f05040 Accepting request 699413 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/699413
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=23
2019-05-02 17:14:41 +00:00
Aleksa Sarai
67c52ee2aa Accepting request 699412 from home:cyphar:runc
- Upgrade to runc v1.0.0~rc8. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc8
- Includes upstreamed patches for regressions (bsc#1131314 bsc#1131553).
- Remove upstreamed patches:
  - CVE-2019-5736.patch

OBS-URL: https://build.opensuse.org/request/show/699412
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=74
2019-04-29 12:05:18 +00:00
Stephan Kulow
c5c186118b Accepting request 674113 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/674113
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=22
2019-02-24 16:03:54 +00:00
Aleksa Sarai
68bddaf3ee Accepting request 674111 from home:cyphar:cve-2019-5736
- Add fix for CVE-2019-5736 (effectively copying /proc/self/exe during re-exec
  to avoid write attacks to the host runc binary). bsc#1121967
  + CVE-2019-5736.patch

OBS-URL: https://build.opensuse.org/request/show/674111
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=72
2019-02-12 14:09:26 +00:00
Dominique Leuenberger
c07367038d Accepting request 660263 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/660263
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=21
2018-12-26 23:25:07 +00:00
Aleksa Sarai
337c2c14cc Accepting request 660132 from home:clee:branches:Virtualization:containers
- Update go requirements to >= go1.10 to fix
  * bsc#1118897 CVE-2018-16873
    go#29230 cmd/go: remote command execution during "go get -u"
  * bsc#1118898 CVE-2018-16874
    go#29231 cmd/go: directory traversal in "go get" via curly braces in import paths
  * bsc#1118899 CVE-2018-16875
    go#29233 crypto/x509: CPU denial of service

OBS-URL: https://build.opensuse.org/request/show/660132
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=70
2018-12-20 11:15:05 +00:00
Aleksa Sarai
588a1df835 Accepting request 657727 from home:dorf:branches:Virtualization:containers
- Require golang = 1.10.

OBS-URL: https://build.opensuse.org/request/show/657727
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=69
2018-12-13 07:54:13 +00:00
Dominique Leuenberger
f03667ed33 Accepting request 652640 from Virtualization:containers
- Upgrade to runc v1.0.0~rc6. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc6

OBS-URL: https://build.opensuse.org/request/show/652640
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=20
2018-12-05 08:37:06 +00:00
Aleksa Sarai
adc9380f22 [ DO NOT FORWARD TO FACTORY! ]
- Upgrade to Docker 18.09.0-ce. See upstream changelog in the packaged
  /usr/share/doc/packages/docker/CHANGELOG.md
- Add revert of an upstream patch to fix docker-* handling.
  + packaging-0001-revert-Remove-docker-prefix-for-containerd-and-runc-.patch
- Rebase patches:
  * bsc1047218-0001-man-obey-SOURCE_DATE_EPOCH-when-generating-man-pages.patch
  * bsc1073877-0001-apparmor-allow-receiving-of-signals-from-docker-kill.patch
  * bsc1073877-0002-apparmor-clobber-docker-default-profile-on-start.patch
  * private-registry-0001-Add-private-registry-mirror-support.patch
  * secrets-0001-daemon-allow-directory-creation-in-run-secrets.patch
  * secrets-0002-SUSE-implement-SUSE-container-secrets.patch
- Remove upstreamed patches:
  - bsc1100727-0001-build-add-buildmode-pie.patch

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=67
2018-11-29 15:15:50 +00:00
Dominique Leuenberger
1928689ce0 Accepting request 645770 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/645770
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=19
2018-11-06 14:29:02 +00:00
Aleksa Sarai
5b02da5652 Accepting request 645753 from home:vrothberg:branches:Virtualization:containers
- Create a symlink in /usr/bin/runc to enable rootless Podman and Buildah.

OBS-URL: https://build.opensuse.org/request/show/645753
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=65
2018-10-31 15:30:13 +00:00
Yuchen Lin
8cfedf9e90 Accepting request 616570 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/616570
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=18
2018-06-22 11:15:38 +00:00
Jordi Massaguer
8c87813fbf Accepting request 616531 from home:dcassany:branches:Virtualization:containers
- Make use of %license macro

OBS-URL: https://build.opensuse.org/request/show/616531
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=63
2018-06-13 15:25:29 +00:00
Dominique Leuenberger
b0b522efd7 Accepting request 614156 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/614156
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=17
2018-06-08 21:09:53 +00:00
Valentin Rothberg
28fa6fa85c Accepting request 614149 from home:cyphar:containers:remove_check_section
- Remove 'go test' from %check section, as it has only ever caused us problems
  and hasn't (as far as I remember) ever caught a release-blocking issue. Smoke
  testing has been far more useful. boo#1095817

OBS-URL: https://build.opensuse.org/request/show/614149
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=61
2018-06-05 07:46:42 +00:00
Dominique Leuenberger
39fd35b355 Accepting request 580741 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/580741
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=16
2018-03-01 11:03:37 +00:00
Aleksa Sarai
5b9cf0431f Accepting request 580739 from home:cyphar:containers:runc_rc5
- Upgrade to runc v1.0.0~rc5. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc5
- Remove patch now merged upstream.
  - bsc1053532-0001-makefile-drop-usage-of-install.patch

OBS-URL: https://build.opensuse.org/request/show/580739
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=59
2018-02-27 17:41:09 +00:00
Dominique Leuenberger
145736efd2 Accepting request 517695 from Virtualization:containers
1

OBS-URL: https://build.opensuse.org/request/show/517695
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=15
2017-08-24 16:22:28 +00:00
Aleksa Sarai
a670c86507 Accepting request 517286 from home:cyphar:containers:runc_use_signed_archive
- Use .tar.xz provided by upstream, as well as include the keyring to allow
  full provenance of the source.

OBS-URL: https://build.opensuse.org/request/show/517286
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=57
2017-08-19 13:24:20 +00:00
Dominique Leuenberger
7a344dfd11 Accepting request 517265 from Virtualization:containers
- Use the upstream Makefile, to ensure that we always include the version
  information in runc. This was confusing users (and Docker). bsc#1053532
- Add a backported patch to fix a Makefile bug.
  https://github.com/opencontainers/runc/pull/1555
  + bsc1053532-0001-makefile-drop-usage-of-install.patch
- Update to runc v1.0.0-rc4.
- Use -buildmode=pie for tests and binary build. bsc#1048046 bsc#1051429
- Cleanup seccomp builds similar to bsc#1028638

OBS-URL: https://build.opensuse.org/request/show/517265
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=14
2017-08-17 09:44:20 +00:00
Aleksa Sarai
9676cebf63 Accepting request 517264 from home:cyphar:containers:bsc1053532
- Use the upstream Makefile, to ensure that we always include the version and
  commit information in runc. This was confusing users (and Docker).
  bsc#1053532
- Add a backported patch to fix a Makefile bug. This also includes some other
  changes to make the docker-runc.spec mirror the newer runc.

OBS-URL: https://build.opensuse.org/request/show/517264
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=55
2017-08-16 19:16:32 +00:00
Aleksa Sarai
f50f0c9beb Accepting request 516116 from home:cyphar:containers:runc_update_rc4
- Update to runc v1.0.0-rc4. Upstream changelog:
	+ runc now supports v1.0.0 of the OCI runtime specification. #1527
	+ Rootless containers support has been released. The current state of
	  this feature is that it only supports single-{uid,gid} mappings as an
	  unprivileged user, and cgroups are completely unsupported. Work is
	  being done to improve this. #774
	+ Rather than relying on CRIU version nnumbers, actually check if the
	  system supports pre-dumping. #1371
	+ Allow the PIDs cgroup limit to be updated. #1423
	+ Add support for checkpoint/restore of containers with orphaned PTYs
	  (which is effectively all containers with terminal=true). #1355
	+ Permit prestart hooks to modify the cgroup configuration of a
	  container. #1239
	+ Add support for a wide variety of mount options. #1460
	+ Expose memory.use_hierarchy in MemoryStats. #1378
	* Fix incorrect handling of systems without the freezer cgroup. #1387
	* Many, many changes to switch away from Go's "syscall" stdlib to
	  "golang.org/x/sys/unix". #1394 #1398 #1442 #1464 #1467 #1470 #1474
	  #1478 #1491 #1482 #1504 #1519 #1530
	* Set cgroup resources when restoring a container. #1399
	* Switch back to using /sbin as the installation directory. #1406
	* Remove the arbitrary container ID length restriction. #1435
	* Make container force deletion ignore non-existent containers. #1451
	* Improve handling of arbitrary cgroup mount locations when populating
	  cpuset. #1372
	* Make the SaneTerminal interface public. #1479
	* Fix cases where runc would report a container to be in a "Running"
	  state if the init was a zombie or dead. #1489
	* Do not set supplementary groups for numeric users. #1450
	* Fix various issues with the "owner" field in runc-list. #1516
	* Many other miscellaneous fixes, some of which were made by first-time
	  contributors. Thanks, and welcome to the project! #1406 #1400 #1365
	  #1396 #1402 #1414 #1412 #1408 #1418 #1425 #1428 #1436 #1433 #1438
	  #1410 #1447 #1388 #1484 #1481 #1496 #1245 #1524 #1534 #1526 #1533
	- Remove any semblance of non-Linux support. #1502
	- We no longer use shfmt for testing. #1510

OBS-URL: https://build.opensuse.org/request/show/516116
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=54
2017-08-11 13:51:29 +00:00
Aleksa Sarai
ce95522847 - Use -buildmode=pie for tests and binary build. bsc#1048046 bsc#1051429
This also includes some various improvements to the packaging of runc,
containerd and docker-runc.

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=53
2017-08-11 12:10:02 +00:00
Dominique Leuenberger
95b584f280 Accepting request 509158 from Virtualization:containers
1

OBS-URL: https://build.opensuse.org/request/show/509158
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=13
2017-07-30 09:22:54 +00:00
Thomas Hipp
c311eecf47 Accepting request 508797 from home:thipp:branches:Virtualization:containers
- switch to opencontainers/runc master branch
- remove CVE-2016-9962.patch 
- stop providing docker-runc

OBS-URL: https://build.opensuse.org/request/show/508797
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=51
2017-07-10 11:39:32 +00:00
Dominique Leuenberger
c08cc4e6bb Accepting request 494718 from Virtualization:containers
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/494718
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=12
2017-05-20 08:13:19 +00:00
Jordi Massaguer
105b3cf4bc OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=49 2017-05-04 19:02:51 +00:00
Jordi Massaguer
b8321caca6 Accepting request 492509 from home:jordimassaguerpla:branch:V:c:fix_golang_req
- fix golang requirement to 1.7

OBS-URL: https://build.opensuse.org/request/show/492509
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=48
2017-05-04 18:33:34 +00:00
Jordi Massaguer
b03a9ad55f Accepting request 491891 from home:jengelh:branches:Virtualization:containers
- Substitute %__-type macro indirections

OBS-URL: https://build.opensuse.org/request/show/491891
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=47
2017-04-28 16:29:38 +00:00
Jordi Massaguer
c6750aa1a1 OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=46 2017-04-20 10:54:06 +00:00
Jordi Massaguer
f4e0799fbb OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=45 2017-04-20 10:25:40 +00:00
Yuchen Lin
98d4194e22 Accepting request 487329 from Virtualization:containers
1

OBS-URL: https://build.opensuse.org/request/show/487329
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=11
2017-04-17 08:26:20 +00:00
Jordi Massaguer
6d3438c47b Accepting request 487318 from home:cyphar:containers
Fix up the ignore cgroupv2 patch so it is easier to track.

OBS-URL: https://build.opensuse.org/request/show/487318
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=43
2017-04-11 12:14:17 +00:00
Jordi Massaguer
faf305337d fix changelog
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=42
2017-04-11 11:03:16 +00:00
Aleksa Sarai
6b0d36eb61 Accepting request 487271 from home:jordimassaguerpla:branch:V:c:runc:ignore_cgroup_v2_mountpoints
- fix bsc#1028113 - runc: make sure to ignore cgroup v2 mountpoints

OBS-URL: https://build.opensuse.org/request/show/487271
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=41
2017-04-11 09:56:51 +00:00
Dominique Leuenberger
2fc0db0acd Accepting request 478794 from Virtualization:containers
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/478794
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=10
2017-03-12 19:05:55 +00:00
Aleksa Sarai
c57749596d Accepting request 461897 from home:jordimassaguerpla:branch:Vc:update_docker_1_13
- update to docker-1.13.0 requirement

OBS-URL: https://build.opensuse.org/request/show/461897
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=39
2017-03-05 03:07:20 +00:00
Dominique Leuenberger
161e459806 Accepting request 450531 from Virtualization:containers
(forwarded request 450530 from jordimassaguerpla)

OBS-URL: https://build.opensuse.org/request/show/450531
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=9
2017-01-23 10:36:50 +00:00
Jordi Massaguer
f0fbd369e5 Accepting request 450530 from home:jordimassaguerpla:branch:Vc:runc:fix_CVE_name
OBS-URL: https://build.opensuse.org/request/show/450530
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=37
2017-01-16 15:08:31 +00:00
Aleksa Sarai
03232f8a36 OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=36 2017-01-13 17:01:54 +00:00
Dominique Leuenberger
5a0827b682 Accepting request 447965 from Virtualization:containers
- update runc to the version used in docker 1.12.5 (bsc#1016307).
  This fixes bsc#1015661 

- For the moment, we have to switch to using Docker's fork of runC. This *will*
  be solved properly by creating a new package purely for Docker's runC fork,
  because it's quite silly to tie OCI project releases to Docker's vendoring
  scheme. Once this is fixed, this package will be switch to being purely-OCI.

- add the /usr/bin/docker-run symlink to partially fix bsc#1015661

  fix bsc#1009961
- update to 02f8fa7 because that is the needed version for docker 1.12.1 (bsc#1004490)
  it fails to build

OBS-URL: https://build.opensuse.org/request/show/447965
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=8
2017-01-10 09:44:31 +00:00
Aleksa Sarai
24bfdba743 Accepting request 447963 from home:jordimassaguerpla:branch:Vc:fix_runc_symlink
OBS-URL: https://build.opensuse.org/request/show/447963
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=34
2016-12-28 10:08:10 +00:00
Aleksa Sarai
eb1aad3421 Accepting request 447318 from home:jordimassaguerpla:branch:V:c:fix_runc_symlink
- add symlink to docker-runc in the post section, as this is how it
  has been already fixed for some client. fixes bsc#1015661

OBS-URL: https://build.opensuse.org/request/show/447318
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=33
2016-12-21 16:38:17 +00:00
Jordi Massaguer
118b9cd3a0 fix version
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=32
2016-12-19 17:41:49 +00:00