Commit Graph

131 Commits

Author SHA256 Message Date
Aleksa Sarai
58623da251 Accepting request 733834 from home:cyphar:containers:maint
Add reference to bsc#1152308.

OBS-URL: https://build.opensuse.org/request/show/733834
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=80
2019-09-28 11:41:04 +00:00
Aleksa Sarai
3def4f837a Fix From: line for CVE-2019-16884.
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=79
2019-09-27 20:22:13 +00:00
Aleksa Sarai
b326742dd0 Accepting request 733753 from home:cyphar:containers:maint
Add /proc/self/fd protections to CVE-2019-16884.patch.

OBS-URL: https://build.opensuse.org/request/show/733753
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=78
2019-09-27 20:18:17 +00:00
Aleksa Sarai
0bdfb449d1 Accepting request 733530 from home:cyphar:containers:maint
Fix CVE patch.

OBS-URL: https://build.opensuse.org/request/show/733530
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=77
2019-09-27 03:17:22 +00:00
Aleksa Sarai
f3a10f34bd Accepting request 733478 from home:cyphar:containers:maint
- Add backported fix for CVE-2019-16884.
  + CVE-2019-16884.patch
- Add runc-rpmlintrc to drop runc-test rpmlint warnings.

OBS-URL: https://build.opensuse.org/request/show/733478
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=76
2019-09-26 15:15:16 +00:00
Dominique Leuenberger
c1c85d71d9 Accepting request 699413 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/699413
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=23
2019-05-02 17:14:41 +00:00
Aleksa Sarai
48d20bc916 Accepting request 699412 from home:cyphar:runc
- Upgrade to runc v1.0.0~rc8. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc8
- Includes upstreamed patches for regressions (bsc#1131314 bsc#1131553).
- Remove upstreamed patches:
  - CVE-2019-5736.patch

OBS-URL: https://build.opensuse.org/request/show/699412
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=74
2019-04-29 12:05:18 +00:00
Stephan Kulow
5f213fa519 Accepting request 674113 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/674113
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=22
2019-02-24 16:03:54 +00:00
Aleksa Sarai
ba0b485e9f Accepting request 674111 from home:cyphar:cve-2019-5736
- Add fix for CVE-2019-5736 (effectively copying /proc/self/exe during re-exec
  to avoid write attacks to the host runc binary). bsc#1121967
  + CVE-2019-5736.patch

OBS-URL: https://build.opensuse.org/request/show/674111
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=72
2019-02-12 14:09:26 +00:00
Dominique Leuenberger
6de3818d6e Accepting request 660263 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/660263
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=21
2018-12-26 23:25:07 +00:00
Aleksa Sarai
d568e44ecc Accepting request 660132 from home:clee:branches:Virtualization:containers
- Update go requirements to >= go1.10 to fix
  * bsc#1118897 CVE-2018-16873
    go#29230 cmd/go: remote command execution during "go get -u"
  * bsc#1118898 CVE-2018-16874
    go#29231 cmd/go: directory traversal in "go get" via curly braces in import paths
  * bsc#1118899 CVE-2018-16875
    go#29233 crypto/x509: CPU denial of service

OBS-URL: https://build.opensuse.org/request/show/660132
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=70
2018-12-20 11:15:05 +00:00
Aleksa Sarai
34ced09c11 Accepting request 657727 from home:dorf:branches:Virtualization:containers
- Require golang = 1.10.

OBS-URL: https://build.opensuse.org/request/show/657727
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=69
2018-12-13 07:54:13 +00:00
Dominique Leuenberger
c3baf55d81 Accepting request 652640 from Virtualization:containers
- Upgrade to runc v1.0.0~rc6. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc6

OBS-URL: https://build.opensuse.org/request/show/652640
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=20
2018-12-05 08:37:06 +00:00
Aleksa Sarai
801ddcf199 [ DO NOT FORWARD TO FACTORY! ]
- Upgrade to Docker 18.09.0-ce. See upstream changelog in the packaged
  /usr/share/doc/packages/docker/CHANGELOG.md
- Add revert of an upstream patch to fix docker-* handling.
  + packaging-0001-revert-Remove-docker-prefix-for-containerd-and-runc-.patch
- Rebase patches:
  * bsc1047218-0001-man-obey-SOURCE_DATE_EPOCH-when-generating-man-pages.patch
  * bsc1073877-0001-apparmor-allow-receiving-of-signals-from-docker-kill.patch
  * bsc1073877-0002-apparmor-clobber-docker-default-profile-on-start.patch
  * private-registry-0001-Add-private-registry-mirror-support.patch
  * secrets-0001-daemon-allow-directory-creation-in-run-secrets.patch
  * secrets-0002-SUSE-implement-SUSE-container-secrets.patch
- Remove upstreamed patches:
  - bsc1100727-0001-build-add-buildmode-pie.patch

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=67
2018-11-29 15:15:50 +00:00
Dominique Leuenberger
09bb5bc8ae Accepting request 645770 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/645770
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=19
2018-11-06 14:29:02 +00:00
Aleksa Sarai
101116b685 Accepting request 645753 from home:vrothberg:branches:Virtualization:containers
- Create a symlink in /usr/bin/runc to enable rootless Podman and Buildah.

OBS-URL: https://build.opensuse.org/request/show/645753
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=65
2018-10-31 15:30:13 +00:00
Yuchen Lin
f21ff0aaba Accepting request 616570 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/616570
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=18
2018-06-22 11:15:38 +00:00
Jordi Massaguer
bb31ae7e18 Accepting request 616531 from home:dcassany:branches:Virtualization:containers
- Make use of %license macro

OBS-URL: https://build.opensuse.org/request/show/616531
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=63
2018-06-13 15:25:29 +00:00
Dominique Leuenberger
f7453cc11e Accepting request 614156 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/614156
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=17
2018-06-08 21:09:53 +00:00
Valentin Rothberg
ce055b46c7 Accepting request 614149 from home:cyphar:containers:remove_check_section
- Remove 'go test' from %check section, as it has only ever caused us problems
  and hasn't (as far as I remember) ever caught a release-blocking issue. Smoke
  testing has been far more useful. boo#1095817

OBS-URL: https://build.opensuse.org/request/show/614149
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=61
2018-06-05 07:46:42 +00:00
Dominique Leuenberger
ef801e1c09 Accepting request 580741 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/580741
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=16
2018-03-01 11:03:37 +00:00
Aleksa Sarai
bbfd719f9c Accepting request 580739 from home:cyphar:containers:runc_rc5
- Upgrade to runc v1.0.0~rc5. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc5
- Remove patch now merged upstream.
  - bsc1053532-0001-makefile-drop-usage-of-install.patch

OBS-URL: https://build.opensuse.org/request/show/580739
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=59
2018-02-27 17:41:09 +00:00
Dominique Leuenberger
017bcd5c0c Accepting request 517695 from Virtualization:containers
1

OBS-URL: https://build.opensuse.org/request/show/517695
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=15
2017-08-24 16:22:28 +00:00
Aleksa Sarai
4a233a5c6e Accepting request 517286 from home:cyphar:containers:runc_use_signed_archive
- Use .tar.xz provided by upstream, as well as include the keyring to allow
  full provenance of the source.

OBS-URL: https://build.opensuse.org/request/show/517286
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=57
2017-08-19 13:24:20 +00:00
Dominique Leuenberger
2916c4fb6f Accepting request 517265 from Virtualization:containers
- Use the upstream Makefile, to ensure that we always include the version
  information in runc. This was confusing users (and Docker). bsc#1053532
- Add a backported patch to fix a Makefile bug.
  https://github.com/opencontainers/runc/pull/1555
  + bsc1053532-0001-makefile-drop-usage-of-install.patch
- Update to runc v1.0.0-rc4.
- Use -buildmode=pie for tests and binary build. bsc#1048046 bsc#1051429
- Cleanup seccomp builds similar to bsc#1028638

OBS-URL: https://build.opensuse.org/request/show/517265
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=14
2017-08-17 09:44:20 +00:00
Aleksa Sarai
74ea12c88b Accepting request 517264 from home:cyphar:containers:bsc1053532
- Use the upstream Makefile, to ensure that we always include the version and
  commit information in runc. This was confusing users (and Docker).
  bsc#1053532
- Add a backported patch to fix a Makefile bug. This also includes some other
  changes to make the docker-runc.spec mirror the newer runc.

OBS-URL: https://build.opensuse.org/request/show/517264
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=55
2017-08-16 19:16:32 +00:00
Aleksa Sarai
d38ef74d50 Accepting request 516116 from home:cyphar:containers:runc_update_rc4
- Update to runc v1.0.0-rc4. Upstream changelog:
	+ runc now supports v1.0.0 of the OCI runtime specification. #1527
	+ Rootless containers support has been released. The current state of
	  this feature is that it only supports single-{uid,gid} mappings as an
	  unprivileged user, and cgroups are completely unsupported. Work is
	  being done to improve this. #774
	+ Rather than relying on CRIU version nnumbers, actually check if the
	  system supports pre-dumping. #1371
	+ Allow the PIDs cgroup limit to be updated. #1423
	+ Add support for checkpoint/restore of containers with orphaned PTYs
	  (which is effectively all containers with terminal=true). #1355
	+ Permit prestart hooks to modify the cgroup configuration of a
	  container. #1239
	+ Add support for a wide variety of mount options. #1460
	+ Expose memory.use_hierarchy in MemoryStats. #1378
	* Fix incorrect handling of systems without the freezer cgroup. #1387
	* Many, many changes to switch away from Go's "syscall" stdlib to
	  "golang.org/x/sys/unix". #1394 #1398 #1442 #1464 #1467 #1470 #1474
	  #1478 #1491 #1482 #1504 #1519 #1530
	* Set cgroup resources when restoring a container. #1399
	* Switch back to using /sbin as the installation directory. #1406
	* Remove the arbitrary container ID length restriction. #1435
	* Make container force deletion ignore non-existent containers. #1451
	* Improve handling of arbitrary cgroup mount locations when populating
	  cpuset. #1372
	* Make the SaneTerminal interface public. #1479
	* Fix cases where runc would report a container to be in a "Running"
	  state if the init was a zombie or dead. #1489
	* Do not set supplementary groups for numeric users. #1450
	* Fix various issues with the "owner" field in runc-list. #1516
	* Many other miscellaneous fixes, some of which were made by first-time
	  contributors. Thanks, and welcome to the project! #1406 #1400 #1365
	  #1396 #1402 #1414 #1412 #1408 #1418 #1425 #1428 #1436 #1433 #1438
	  #1410 #1447 #1388 #1484 #1481 #1496 #1245 #1524 #1534 #1526 #1533
	- Remove any semblance of non-Linux support. #1502
	- We no longer use shfmt for testing. #1510

OBS-URL: https://build.opensuse.org/request/show/516116
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=54
2017-08-11 13:51:29 +00:00
Aleksa Sarai
438ec77e8c - Use -buildmode=pie for tests and binary build. bsc#1048046 bsc#1051429
This also includes some various improvements to the packaging of runc,
containerd and docker-runc.

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=53
2017-08-11 12:10:02 +00:00
Dominique Leuenberger
27a574379a Accepting request 509158 from Virtualization:containers
1

OBS-URL: https://build.opensuse.org/request/show/509158
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=13
2017-07-30 09:22:54 +00:00
Thomas Hipp
030004095c Accepting request 508797 from home:thipp:branches:Virtualization:containers
- switch to opencontainers/runc master branch
- remove CVE-2016-9962.patch 
- stop providing docker-runc

OBS-URL: https://build.opensuse.org/request/show/508797
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=51
2017-07-10 11:39:32 +00:00
Dominique Leuenberger
dcbdbcdd9e Accepting request 494718 from Virtualization:containers
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/494718
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=12
2017-05-20 08:13:19 +00:00
Jordi Massaguer
e9cd9305f4 OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=49 2017-05-04 19:02:51 +00:00
Jordi Massaguer
8d8fed71b3 Accepting request 492509 from home:jordimassaguerpla:branch:V:c:fix_golang_req
- fix golang requirement to 1.7

OBS-URL: https://build.opensuse.org/request/show/492509
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=48
2017-05-04 18:33:34 +00:00
Jordi Massaguer
02fcbee273 Accepting request 491891 from home:jengelh:branches:Virtualization:containers
- Substitute %__-type macro indirections

OBS-URL: https://build.opensuse.org/request/show/491891
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=47
2017-04-28 16:29:38 +00:00
Jordi Massaguer
871ab3a54c OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=46 2017-04-20 10:54:06 +00:00
Jordi Massaguer
dd30b50950 OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=45 2017-04-20 10:25:40 +00:00
Yuchen Lin
e1aa70800a Accepting request 487329 from Virtualization:containers
1

OBS-URL: https://build.opensuse.org/request/show/487329
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=11
2017-04-17 08:26:20 +00:00
Jordi Massaguer
3f88467bef Accepting request 487318 from home:cyphar:containers
Fix up the ignore cgroupv2 patch so it is easier to track.

OBS-URL: https://build.opensuse.org/request/show/487318
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=43
2017-04-11 12:14:17 +00:00
Jordi Massaguer
c6ef2832c5 fix changelog
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=42
2017-04-11 11:03:16 +00:00
Aleksa Sarai
b0463e5979 Accepting request 487271 from home:jordimassaguerpla:branch:V:c:runc:ignore_cgroup_v2_mountpoints
- fix bsc#1028113 - runc: make sure to ignore cgroup v2 mountpoints

OBS-URL: https://build.opensuse.org/request/show/487271
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=41
2017-04-11 09:56:51 +00:00
Dominique Leuenberger
df1e6f7536 Accepting request 478794 from Virtualization:containers
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/478794
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=10
2017-03-12 19:05:55 +00:00
Aleksa Sarai
b55f5ac831 Accepting request 461897 from home:jordimassaguerpla:branch:Vc:update_docker_1_13
- update to docker-1.13.0 requirement

OBS-URL: https://build.opensuse.org/request/show/461897
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=39
2017-03-05 03:07:20 +00:00
Dominique Leuenberger
acca8538c6 Accepting request 450531 from Virtualization:containers
(forwarded request 450530 from jordimassaguerpla)

OBS-URL: https://build.opensuse.org/request/show/450531
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=9
2017-01-23 10:36:50 +00:00
Jordi Massaguer
0de2bc6731 Accepting request 450530 from home:jordimassaguerpla:branch:Vc:runc:fix_CVE_name
OBS-URL: https://build.opensuse.org/request/show/450530
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=37
2017-01-16 15:08:31 +00:00
Aleksa Sarai
6c28b7232c OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=36 2017-01-13 17:01:54 +00:00
Dominique Leuenberger
d116931e46 Accepting request 447965 from Virtualization:containers
- update runc to the version used in docker 1.12.5 (bsc#1016307).
  This fixes bsc#1015661 

- For the moment, we have to switch to using Docker's fork of runC. This *will*
  be solved properly by creating a new package purely for Docker's runC fork,
  because it's quite silly to tie OCI project releases to Docker's vendoring
  scheme. Once this is fixed, this package will be switch to being purely-OCI.

- add the /usr/bin/docker-run symlink to partially fix bsc#1015661

  fix bsc#1009961
- update to 02f8fa7 because that is the needed version for docker 1.12.1 (bsc#1004490)
  it fails to build

OBS-URL: https://build.opensuse.org/request/show/447965
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=8
2017-01-10 09:44:31 +00:00
Aleksa Sarai
4199169c81 Accepting request 447963 from home:jordimassaguerpla:branch:Vc:fix_runc_symlink
OBS-URL: https://build.opensuse.org/request/show/447963
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=34
2016-12-28 10:08:10 +00:00
Aleksa Sarai
88553395ee Accepting request 447318 from home:jordimassaguerpla:branch:V:c:fix_runc_symlink
- add symlink to docker-runc in the post section, as this is how it
  has been already fixed for some client. fixes bsc#1015661

OBS-URL: https://build.opensuse.org/request/show/447318
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=33
2016-12-21 16:38:17 +00:00
Jordi Massaguer
020aaf5db9 fix version
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=32
2016-12-19 17:41:49 +00:00
Aleksa Sarai
9547577941 OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=31 2016-12-19 14:01:37 +00:00