SHA256
1
0
forked from pool/runc

192 Commits

Author SHA256 Message Date
Aleksa Sarai
bf26614547 runc: update to v1.3.4
- Update to runc v1.3.4. Upstream changelog is available from
  <https://github.com/opencontainers/runc/releases/tag/v1.3.4>. bsc#1254362

Signed-off-by: Aleksa Sarai <cyphar@cyphar.com>
2025-12-02 05:49:42 +11:00
Aleksa Sarai
e1bf8599a4 runc: update to v1.3.3
- Update to runc v1.3.3. Upstream changelog is available from
  <https://github.com/opencontainers/runc/releases/tag/v1.3.3>. bsc#1252232
  * CVE-2025-31133
  * CVE-2025-52565
  * CVE-2025-52881
- Remove upstreamed patches for bsc#1252232:
  - 2025-11-05-CVEs.patch

SUSE-Bugs: https://bugzilla.suse.com/show_bug.cgi?id=1252232
Signed-off-by: Aleksa Sarai <cyphar@cyphar.com>
2025-11-06 02:29:19 +11:00
024faa61ab Sync changes to SLFO-1.2 branch 2025-08-20 13:08:41 +02:00
1eba63e985 Accepting request 1273510 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1273510
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=72
2025-05-01 13:22:25 +00:00
dd8cfc76ef - Update to runc v1.3.0. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.3.0>

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=182
2025-04-29 19:32:44 +00:00
1d995bf294 Accepting request 1268306 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1268306
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=71
2025-04-11 14:45:33 +00:00
323f8f7c45 Fix v1.1.13 link reference.
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=180
2025-04-10 08:23:25 +00:00
cf8e4a842a Add 0004-bsc1214960-nsenter-cloned_binary-remove-bindfd-logic.patch reference.
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=179
2025-04-10 04:13:56 +00:00
a412680656 - Update to runc v1.2.6. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.2.6>.

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=178
2025-04-10 03:54:33 +00:00
12e513aafd Accepting request 1245781 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1245781
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=70
2025-02-16 21:37:07 +00:00
2d682ad444 - Update to runc v1.2.5. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.2.5>.

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=176
2025-02-14 05:01:18 +00:00
043e645b71 Accepting request 1235492 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1235492
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=69
2025-01-09 14:04:54 +00:00
5ae709f712 - Update runc.keyring to match upstream.
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=174
2025-01-07 06:35:28 +00:00
09900039d8 - Update to runc v1.2.4. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.2.4>.

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=173
2025-01-07 06:32:47 +00:00
8bdc03b7b4 Accepting request 1229979 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1229979
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=68
2024-12-13 21:30:36 +00:00
84da435103 Accepting request 1229978 from home:cyphar:docker
- Update to runc v1.2.3. Upstream changelog is available from
  <https://github.com/opencontainers/runc/releases/tag/v1.2.3>.

OBS-URL: https://build.opensuse.org/request/show/1229978
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=171
2024-12-11 02:05:04 +00:00
c8280a39b3 Accepting request 1224554 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1224554
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=67
2024-11-17 15:39:34 +00:00
6924b85142 - Update to runc v1.2.2. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.2.2>.

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=169
2024-11-16 07:04:45 +00:00
a811cce773 Accepting request 1220123 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1220123
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=66
2024-11-03 06:17:07 +00:00
156dfe7e9d - Update to runc v1.2.1. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.2.1>.

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=167
2024-11-02 00:28:41 +00:00
c27b0c3b43 - build without manpages on SLE12
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=166
2024-10-29 13:29:26 +00:00
f39156d2f7 Accepting request 1216988 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1216988
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=65
2024-10-23 19:08:42 +00:00
c56b5f514a - Update to runc v1.2.0. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.2.0>.

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=164
2024-10-22 09:15:32 +00:00
936c90f147 Accepting request 1198393 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1198393
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=64
2024-09-04 11:22:06 +00:00
67e60adac6 Accepting request 1187033 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1187033
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=63
2024-07-31 11:28:07 +00:00
313d2c4984 Accepting request 1187032 from home:cyphar:docker
- Update to runc v1.2.0~rc2. Upstream changelog is available from
  <https://github.com/opencontainers/runc/releases/tag/v1.2.0-rc.2>.
- Re-allow Go 1.22 builds for >= 1.22.4.

OBS-URL: https://build.opensuse.org/request/show/1187032
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=160
2024-07-12 08:43:39 +00:00
45e4adb561 Accepting request 1165426 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1165426
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=62
2024-04-05 18:25:29 +00:00
2d98556bab Accepting request 1165425 from home:cyphar:docker
- Update to runc v1.2.0~rc1. Upstream changelog is available from
  <https://github.com/opencontainers/runc/releases/tag/v1.2.0-rc.1>.
- Remove upstreamed patches.
  - 0001-bsc1221050-libct-seccomp-patchbpf-rm-duplicated-code.patch
  - 0002-bsc1221050-seccomp-patchbpf-rename-nativeArch-linuxA.patch
  - 0003-bsc1221050-seccomp-patchbpf-always-include-native-ar.patch

OBS-URL: https://build.opensuse.org/request/show/1165425
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=158
2024-04-05 06:50:38 +00:00
3f45a3d3f3 Accepting request 1159949 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1159949
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=61
2024-03-22 14:17:59 +00:00
904cbe4ac7 Accepting request 1159948 from home:cyphar:docker
- Add upstream patch <https://github.com/opencontainers/runc/pull/4219> to
  properly fix -ENOSYS stub on ppc64le. bsc#1192051 bsc#1221050
  + 0001-bsc1221050-libct-seccomp-patchbpf-rm-duplicated-code.patch
  + 0002-bsc1221050-seccomp-patchbpf-rename-nativeArch-linuxA.patch
  + 0003-bsc1221050-seccomp-patchbpf-always-include-native-ar.patch

OBS-URL: https://build.opensuse.org/request/show/1159948
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=156
2024-03-21 03:51:32 +00:00
a336e7eb11 Accepting request 1143139 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1143139
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=60
2024-02-01 17:04:09 +00:00
1888581cd1 Accepting request 1143138 from home:cyphar:docker
- Update to runc v1.1.12. Upstream changelog is available from
  <https://github.com/opencontainers/runc/releases/tag/v1.1.12>. bsc#1218894

  * This release fixes a container breakout vulnerability (CVE-2024-21626). For
    more details, see the upstream security advisory:
    <https://github.com/opencontainers/runc/security/advisories/GHSA-xr7r-f8xq-vfvv>
  * Remove upstreamed patches:
    - CVE-2024-21626.patch
  * Update runc.keyring to match upstream changes.

OBS-URL: https://build.opensuse.org/request/show/1143138
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=154
2024-01-31 20:38:35 +00:00
1a42b5979e Accepting request 1136047 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1136047
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=59
2024-01-04 14:56:37 +00:00
74ec7c7074 Accepting request 1136046 from home:cyphar:docker
- Update to runc v1.1.11. Upstream changelog is available from
  <https://github.com/opencontainers/runc/releases/tag/v1.1.11>.

OBS-URL: https://build.opensuse.org/request/show/1136046
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=152
2024-01-02 03:04:06 +00:00
44754697d1 Accepting request 1123912 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1123912
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=58
2023-11-07 20:25:34 +00:00
4bed41fd2c Accepting request 1121545 from home:cyphar:docker
- Update to runc v1.1.10. Upstream changelog is available from
  <https://github.com/opencontainers/runc/releases/tag/v1.1.10>.

OBS-URL: https://build.opensuse.org/request/show/1121545
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=150
2023-11-07 10:34:07 +00:00
77dc7ea28d Accepting request 1110965 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1110965
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=57
2023-09-14 14:25:05 +00:00
2608422848 Accepting request 1109204 from home:danishprakash:branches:Virtualization:containers
Update to runc v1.1.9

OBS-URL: https://build.opensuse.org/request/show/1109204
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=148
2023-09-14 01:52:09 +00:00
00cbac1625 Accepting request 1099532 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1099532
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=56
2023-07-25 09:23:38 +00:00
fe29cfaec4 Accepting request 1099531 from home:cyphar:docker
- Update to runc v1.1.8. Upstream changelog is available from
  <https://github.com/opencontainers/runc/releases/tag/v1.1.8>.

OBS-URL: https://build.opensuse.org/request/show/1099531
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=146
2023-07-19 14:09:53 +00:00
cdedb08921 Accepting request 1083239 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1083239
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=55
2023-04-28 14:22:37 +00:00
b2d3afeb60 Accepting request 1083238 from home:cyphar:docker
- Update to runc v1.1.7. Upstream changelog is available from
  <https://github.com/opencontainers/runc/releases/tag/v1.1.7>.
- Update runc.keyring to upstream version.

OBS-URL: https://build.opensuse.org/request/show/1083238
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=144
2023-04-27 09:57:52 +00:00
d38f3d56df Accepting request 1079877 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1079877
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=54
2023-04-17 15:41:13 +00:00
6023ea5248 Accepting request 1079875 from home:cyphar:docker
Fix bugzilla references for /dev/null issues bsc#1168481 and bsc#1207004.

OBS-URL: https://build.opensuse.org/request/show/1079875
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=142
2023-04-17 09:46:28 +00:00
c08e860fac Accepting request 1078554 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1078554
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=53
2023-04-13 12:09:51 +00:00
5ec848c759 Accepting request 1078553 from home:cyphar:docker
- Update to runc v1.1.6. Upstream changelog is available from
  <https://github.com/opencontainers/runc/releases/tag/v1.1.6>.

OBS-URL: https://build.opensuse.org/request/show/1078553
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=140
2023-04-12 04:25:25 +00:00
6a71307c5e Accepting request 1075228 from Virtualization:containers
- Update to runc v1.1.5. Upstream changelog is available from
  <https://github.com/opencontainers/runc/releases/tag/v1.1.5>.

  Includes fixes for the following CVEs:
   - CVE-2023-25809 bsc#1209884
   - CVE-2023-27561 bsc#1208962
   - CVE-2023-28642 bsc#1209888

  * Fix the inability to use `/dev/null` when inside a container.
  * Fix changing the ownership of host's `/dev/null` caused by fd redirection
    (a regression in 1.1.1). bsc#1168481
  * Fix rare runc exec/enter unshare error on older kernels.
  * nsexec: Check for errors in `write_log()`.

- Drop version-specific Go requirement.

OBS-URL: https://build.opensuse.org/request/show/1075228
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=52
2023-03-30 20:50:49 +00:00
7a1dc570e6 Accepting request 1075227 from home:cyphar:docker
Add bsc references for CVEs.
   - CVE-2023-25809 bsc#1209884
   - CVE-2023-27561 bsc#1208962
   - CVE-2023-28642 bsc#1209888

OBS-URL: https://build.opensuse.org/request/show/1075227
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=138
2023-03-29 13:06:28 +00:00
b6fd9f1914 Accepting request 1075138 from home:cyphar:docker
- Drop version-specific Go requirement.

OBS-URL: https://build.opensuse.org/request/show/1075138
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=137
2023-03-29 07:14:02 +00:00
d39f70955b Accepting request 1075135 from home:cyphar:docker
- Update to runc v1.1.5. Upstream changelog is available from
  <https://github.com/opencontainers/runc/releases/tag/v1.1.5>.
  CVE-2023-25809 CVE-2023-27561 CVE-2023-28642

  * Fix the inability to use `/dev/null` when inside a container.
  * Fix changing the ownership of host's `/dev/null` caused by fd redirection
    (a regression in 1.1.1). bsc#1168481
  * Fix rare runc exec/enter unshare error on older kernels.
  * nsexec: Check for errors in `write_log()`.

OBS-URL: https://build.opensuse.org/request/show/1075135
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=136
2023-03-29 07:12:21 +00:00
b005b543cf Accepting request 1005074 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1005074
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=51
2022-09-21 12:39:40 +00:00
2440658faa Accepting request 1005073 from home:cyphar:docker
Add bugzilla reference bsc#1202021

OBS-URL: https://build.opensuse.org/request/show/1005073
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=134
2022-09-21 00:34:33 +00:00
ba9556dac3 Accepting request 1000884 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/1000884
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=50
2022-09-03 21:18:41 +00:00
64bb0cbc3a Accepting request 1000448 from home:favogt:branches:Virtualization:containers
- Update to runc v1.1.4. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.1.4.
  * Fix mounting via wrong proc fd. When the user and mount namespaces are
    used, and the bind mount is followed by the cgroup mount in the spec,
    the cgroup was mounted using the bind mount's mount fd.
  * Switch kill() in libcontainer/nsenter to sane_kill().
  * Fix "permission denied" error from runc run on noexec fs.
  * Fix failed exec after systemctl daemon-reload. Due to a regression
    in v1.1.3, the DeviceAllow=char-pts rwm rule was no longer added and
    was causing an error open /dev/pts/0: operation not permitted: unknown when systemd was reloaded.
    (boo#1202821)

OBS-URL: https://build.opensuse.org/request/show/1000448
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=132
2022-09-02 12:28:01 +00:00
0de189a64c Accepting request 983321 from Virtualization:containers
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/983321
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=49
2022-06-17 19:19:01 +00:00
96f151fd47 Accepting request 981402 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/981402
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=48
2022-06-10 13:57:15 +00:00
d2a02458e0 Accepting request 982018 from home:cyphar:docker
Fix bsc#1193436 reference.

OBS-URL: https://build.opensuse.org/request/show/982018
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=129
2022-06-10 09:28:15 +00:00
683f0a36dd Accepting request 981401 from home:cyphar:docker
- Update to runc v1.1.3. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.1.3.
  (Includes a fix for bsc#1200088.)

  * Our seccomp `-ENOSYS` stub now correctly handles multiplexed syscalls on
    s390 and s390x. This solves the issue where syscalls the host kernel did not
    support would return `-EPERM` despite the existence of the `-ENOSYS` stub
    code (this was due to how s390x does syscall multiplexing).
  * Retry on dbus disconnect logic in libcontainer/cgroups/systemd now works as
    intended; this fix does not affect runc binary itself but is important for
    libcontainer users such as Kubernetes.
  * Inability to compile with recent clang due to an issue with duplicate
    constants in libseccomp-golang.
  * When using systemd cgroup driver, skip adding device paths that don't exist,
    to stop systemd from emitting warnings about those paths.
  * Socket activation was failing when more than 3 sockets were used.
  * Various CI fixes.
  * Allow to bind mount /proc/sys/kernel/ns_last_pid to inside container.
  * runc static binaries are now linked against libseccomp v2.5.4.
- Remove upstreamed patches:
  - bsc1192051-0001-seccomp-enosys-always-return-ENOSYS-for-setup-2-on-s390x.patch

OBS-URL: https://build.opensuse.org/request/show/981401
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=128
2022-06-09 00:28:16 +00:00
d7c9cff73a Accepting request 978577 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/978577
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=47
2022-05-24 18:30:41 +00:00
bb89a115f8 Accepting request 978576 from home:cyphar:docker
Fix CVE references.

OBS-URL: https://build.opensuse.org/request/show/978576
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=126
2022-05-23 03:24:41 +00:00
456c3f8a79 Accepting request 978574 from home:cyphar:docker
- Backport <https://github.com/opencontainers/runc/pull/3474> to fix issues
  with newer syscalls (namely faccessat2) on older kernels on s390(x) caused by
  that platform's syscall multiplexing semantics. bsc#1192051 bsc#1199565
  + bsc1192051-0001-seccomp-enosys-always-return-ENOSYS-for-setup-2-on-s390x.patch
- Add ExcludeArch for s390 (not s390x) since we've never supported it.

OBS-URL: https://build.opensuse.org/request/show/978574
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=125
2022-05-23 03:15:57 +00:00
6ea6b466e6 Accepting request 976495 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/976495
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=46
2022-05-14 20:52:06 +00:00
2f40aa19ad Accepting request 976494 from home:cyphar:docker
- Update to runc v1.1.2. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.1.2.
  CVE-2022-24769

 * A bug was found in runc where runc exec --cap executed processes with
   non-empty inheritable Linux process capabilities, creating an atypical Linux
   environment. For more information, see [GHSA-f3fp-gc8g-vw66][] and
   CVE-2022-29162.
 * `runc spec` no longer sets any inheritable capabilities in the created
   example OCI spec (`config.json`) file.

OBS-URL: https://build.opensuse.org/request/show/976494
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=123
2022-05-11 23:03:17 +00:00
7345490bc2 Accepting request 965512 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/965512
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=45
2022-04-02 16:20:10 +00:00
c5a72d81b3 Accepting request 965511 from home:cyphar:docker
- Update to runc v1.1.1. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.1.1.

  * runc run/start can now run a container with read-only /dev in OCI spec,
    rather than error out. (#3355)
  * runc exec now ensures that --cgroup argument is a sub-cgroup. (#3403)
    libcontainer systemd v2 manager no longer errors out if one of the files
    listed in /sys/kernel/cgroup/delegate do not exist in container's
    cgroup. (#3387, #3404)
  * Loosen OCI spec validation to avoid bogus "Intel RDT is not supported"
    error. (#3406)
  * libcontainer/cgroups no longer panics in cgroup v1 managers if stat
    of /sys/fs/cgroup/unified returns an error other than ENOENT. (#3435)

OBS-URL: https://build.opensuse.org/request/show/965511
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=121
2022-03-29 03:37:10 +00:00
4bf6c57201 Accepting request 947076 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/947076
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=44
2022-01-21 00:24:53 +00:00
52be9a93b9 Accepting request 947075 from home:cyphar:docker
- Update to runc v1.1.0. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.1.0.

  - libcontainer will now refuse to build without the nsenter package being
    correctly compiled (specifically this requires CGO to be enabled). This
    should avoid folks accidentally creating broken runc binaries (and
    incorrectly importing our internal libraries into their projects). (#3331)

OBS-URL: https://build.opensuse.org/request/show/947075
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=120
2022-01-17 22:51:56 +00:00
560bb768a1 Accepting request 940369 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/940369
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=43
2021-12-16 20:18:43 +00:00
81f99db1b9 Accepting request 940368 from home:cyphar:docker
- Update to runc v1.1.0~rc1. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.1.0-rc.1.

  + Add support for RDMA cgroup added in Linux 4.11.
  * runc exec now produces exit code of 255 when the exec failed.
    This may help in distinguishing between runc exec failures
    (such as invalid options, non-running container or non-existent
    binary etc.) and failures of the command being executed.
  + runc run: new --keep option to skip removal exited containers artefacts.
    This might be useful to check the state (e.g. of cgroup controllers) after
    the container hasexited.
  + seccomp: add support for SCMP_ACT_KILL_PROCESS and SCMP_ACT_KILL_THREAD
    (the latter is just an alias for SCMP_ACT_KILL).
  + seccomp: add support for SCMP_ACT_NOTIFY (seccomp actions). This allows
    users to create sophisticated seccomp filters where syscalls can be
    efficiently emulated by privileged processes on the host.
  + checkpoint/restore: add an option (--lsm-mount-context) to set
    a different LSM mount context on restore.
  + intelrdt: support ClosID parameter.
  + runc exec --cgroup: an option to specify a (non-top) in-container cgroup
    to use for the process being executed.
  + cgroup v1 controllers now support hybrid hierarchy (i.e. when on a cgroup v1
    machine a cgroup2 filesystem is mounted to /sys/fs/cgroup/unified, runc
    run/exec now adds the container to the appropriate cgroup under it).
  + sysctl: allow slashes in sysctl names, to better match sysctl(8)'s
    behaviour.
  + mounts: add support for bind-mounts which are inaccessible after switching
    the user namespace. Note that this does not permit the container any
    additional access to the host filesystem, it simply allows containers to
    have bind-mounts configured for paths the user can access but have
    restrictive access control settings for other users.
  + Add support for recursive mount attributes using mount_setattr(2). These
    have the same names as the proposed mount(8) options -- just prepend r
    to the option name (such as rro).
  + Add runc features subcommand to allow runc users to detect what features
    runc has been built with. This includes critical information such as
    supported mount flags, hook names, and so on. Note that the output of this
    command is subject to change and will not be considered stable until runc
    1.2 at the earliest. The runtime-spec specification for this feature is
    being developed in opencontainers/runtime-spec#1130.
  * system: improve performance of /proc/$pid/stat parsing.
  * cgroup2: when /sys/fs/cgroup is configured as a read-write mount, change
    the ownership of certain cgroup control files (as per
    /sys/kernel/cgroup/delegate) to allow for proper deferral to the container
    process.
  * runc checkpoint/restore: fixed for containers with an external bind mount
    which destination is a symlink.
  * cgroup: improve openat2 handling for cgroup directory handle hardening.
    runc delete -f now succeeds (rather than timing out) on a paused
    container.
  * runc run/start/exec now refuses a frozen cgroup (paused container in case of
    exec). Users can disable this using --ignore-paused.
- Update version data embedded in binary to correctly include the git commit of
  the release.
- Drop runc-rpmlintrc because we don't have runc-test anymore.

OBS-URL: https://build.opensuse.org/request/show/940368
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=119
2021-12-14 05:24:53 +00:00
001b38a108 Accepting request 935875 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/935875
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=42
2021-12-08 21:08:27 +00:00
f76f27fb03 Accepting request 935874 from home:cyphar:docker
- Update to runc v1.0.3. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.3. CVE-2021-43784

  * A potential vulnerability was discovered in runc (related to an internal
    usage of netlink), however upon further investigation we discovered that
    while this bug was exploitable on the master branch of runc, no released
    version of runc could be exploited using this bug. The exploit required
    being able to create a netlink attribute with a length that would overflow a
    uint16 but this was not possible in any released version of runc. For more
    information see GHSA-v95c-p5hm-xq8f and CVE-2021-43784.

    Due to an abundance of caution we decided to do an emergency release with
    this fix, but to reiterate we do not believe this vulnerability was
    possible to exploit. Thanks to Felix Wilhelm from Google Project Zero for
    discovering and reporting this vulnerability so quickly.
  * Fixed inability to start a container with read-write bind mount of a
    read-only fuse host mount.
  * Fixed inability to start when read-only /dev in set in spec.
  * Fixed not removing sub-cgroups upon container delete, when rootless cgroup
    v2 is used with older systemd.
  * Fixed returning error from GetStats when hugetlb is unsupported (which
    causes excessive logging for kubernetes).

OBS-URL: https://build.opensuse.org/request/show/935874
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=118
2021-12-06 04:44:55 +00:00
b553e39996 Accepting request 913732 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/913732
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=41
2021-08-24 08:53:55 +00:00
cf1a13f90d Accepting request 913731 from home:cyphar:docker
- Update to runc v1.0.2. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.2

  * Fixed a failure to set CPU quota period in some cases on cgroup v1.
  * Fixed the inability to start a container with the "adding seccomp filter
    rule for syscall ..." error, caused by redundant seccomp rules (i.e. those
    that has action equal to the default one). Such redundant rules are now
    skipped.
  * Made release builds reproducible from now on.
  * Fixed a rare debug log race in runc init, which can result in occasional
    harmful "failed to decode ..." errors from runc run or exec.
  * Fixed the check in cgroup v1 systemd manager if a container needs to be
    frozen before Set, and add a setting to skip such freeze unconditionally.
    The previous fix for that issue, done in runc 1.0.1, was not working.

OBS-URL: https://build.opensuse.org/request/show/913731
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=117
2021-08-23 09:40:05 +00:00
9065981863 Accepting request 907286 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/907286
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=40
2021-07-20 13:38:40 +00:00
bb50268589 Accepting request 907285 from home:cyphar:docker
- Update to runc v1.0.1. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.1

  * Fixed occasional runc exec/run failure ("interrupted system call") on an
    Azure volume.
  * Fixed "unable to find groups ... token too long" error with /etc/group
    containing lines longer than 64K characters.
  * cgroup/systemd/v1: fix leaving cgroup frozen after Set if a parent cgroup is
    frozen. This is a regression in 1.0.0, not affecting runc itself but some
    of libcontainer users (e.g Kubernetes).
  * cgroupv2: bpf: Ignore inaccessible existing programs in case of
    permission error when handling replacement of existing bpf cgroup
    programs. This fixes a regression in 1.0.0, where some SELinux
    policies would block runc from being able to run entirely.
  * cgroup/systemd/v2: don't freeze cgroup on Set.
  * cgroup/systemd/v1: avoid unnecessary freeze on Set.

- Remove upstreamed patches:
  + boo1187704-0001-cgroupv2-ebpf-ignore-inaccessible-existing-programs.patch

OBS-URL: https://build.opensuse.org/request/show/907285
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=116
2021-07-20 09:40:45 +00:00
19a7cb9c53 Accepting request 903381 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/903381
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=39
2021-07-02 11:26:39 +00:00
5eef441a29 Accepting request 903380 from home:cyphar:docker
Cherry-pick patch correctly so it applies cleanly...

OBS-URL: https://build.opensuse.org/request/show/903380
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=115
2021-07-01 10:36:06 +00:00
608f0629ac Accepting request 903342 from home:cyphar:docker
- Backport <https://github.com/opencontainers/runc/pull/3055> to fix issues
  with runc under openSUSE MicroOS's SELinux policy. boo#1187704
  + boo1187704-0001-cgroupv2-ebpf-ignore-inaccessible-existing-programs.patch

OBS-URL: https://build.opensuse.org/request/show/903342
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=114
2021-07-01 06:17:25 +00:00
9e55180025 Accepting request 901272 from home:cyphar:docker
- Update to runc v1.0.0. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.0

  ! The usage of relative paths for mountpoints will now produce a warning
    (such configurations are outside of the spec, and in future runc will
    produce an error when given such configurations).

  * cgroupv2: devices: rework the filter generation to produce consistent
    results with cgroupv1, and always clobber any existing eBPF
    program(s) to fix runc update and avoid leaking eBPF programs
    (resulting in errors when managing containers).
  * cgroupv2: correctly convert "number of IOs" statistics in a
    cgroupv1-compatible way.
  * cgroupv2: support larger than 32-bit IO statistics on 32-bit architectures.
  * cgroupv2: wait for freeze to finish before returning from the freezing
    code, optimize the method for checking whether a cgroup is frozen.
  * cgroups/systemd: fixed "retry on dbus disconnect" logic introduced in rc94
  * cgroups/systemd: fixed returning "unit already exists" error from a systemd
    cgroup manager (regression in rc94)

  + cgroupv2: support SkipDevices with systemd driver
  + cgroup/systemd: return, not ignore, stop unit error from Destroy
  + Make "runc --version" output sane even when built with go get or
    otherwise outside of our build scripts.
  + cgroups: set SkipDevices during runc update (so we don't modify
    cgroups at all during runc update).
  + cgroup1: blkio: support BFQ weights.
  + cgroupv2: set per-device io weights if BFQ IO scheduler is available.

OBS-URL: https://build.opensuse.org/request/show/901272
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=113
2021-06-22 06:34:42 +00:00
c49fe8659d Accepting request 894286 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/894286
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=38
2021-05-20 17:23:42 +00:00
c92ebea2d0 Accepting request 894285 from home:cyphar:docker
- Update to runc v1.0.0~rc95. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc95

  This release of runc contains a fix for CVE-2021-30465, and users are
  strongly recommended to update (especially if you are providing
  semi-limited access to spawn containers to untrusted users). bsc#1185405

OBS-URL: https://build.opensuse.org/request/show/894285
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=111
2021-05-19 10:09:39 +00:00
a69f721202 Accepting request 892392 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/892392
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=37
2021-05-15 21:15:28 +00:00
e359b5cff1 Accepting request 892389 from home:cyphar:docker
- Update to runc v1.0.0~rc94. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc94
  Breaking Changes:
  * cgroupv1: kernel memory limits are now always ignored, as kmemcg has
    been effectively deprecated by the kernel. Users should make use of regular
    memory cgroup controls.
  Regression Fixes:
  * seccomp: fix 32-bit compilation errors
  * runc init: fix a hang caused by deadlock in seccomp/ebpf loading code
  * runc start: fix "chdir to cwd: permission denied" for some setups
- Remove upstreamed patches:
  - 0001-cloned_binary-switch-from-error-to-warning-for-SYS_m.patch

OBS-URL: https://build.opensuse.org/request/show/892389
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=109
2021-05-12 08:08:56 +00:00
11034395b8 Accepting request 888385 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/888385
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=36
2021-04-27 19:34:09 +00:00
88d4373f4e Accepting request 888384 from home:cyphar:docker
- Backport patch to fix build on SLE-12 ppc64le.
  + 0001-cloned_binary-switch-from-error-to-warning-for-SYS_m.patch

OBS-URL: https://build.opensuse.org/request/show/888384
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=107
2021-04-26 08:00:58 +00:00
136b10cf94 Accepting request 886967 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/886967
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=35
2021-04-21 18:58:57 +00:00
0146fb1293 Accepting request 886957 from home:cyphar:docker
Add new BZ reference.

OBS-URL: https://build.opensuse.org/request/show/886957
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=105
2021-04-20 10:41:16 +00:00
Richard Brown
85c53b9d4c Accepting request 876335 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/876335
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=34
2021-03-03 17:34:50 +00:00
894e8e2368 Accepting request 876332 from home:cyphar:docker
Add BZ reference.

OBS-URL: https://build.opensuse.org/request/show/876332
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=103
2021-03-03 03:06:45 +00:00
d64a9eb6c9 Accepting request 869059 from Virtualization:containers
- Update to runc v1.0.0~rc93. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc93
  * Cgroupv2 support is no longer considered experimental.
  * Mountinfo parsing code has been reworked significantly.
  * Special ENOSYS handling for seccomp profiles to avoid making new
	syscalls unusable for glibc.
  * Various rootless containers improvements.
  * The "selinux" and "apparmor" buildtags have been removed, and now all runc
    builds will have SELinux and AppArmor support enabled.
- Update to handle the docker-runc removal. bsc#1181677
- Modernise go building for runc now that it has go.mod.

OBS-URL: https://build.opensuse.org/request/show/869059
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=33
2021-02-04 19:22:53 +00:00
f530b9f9ff Accepting request 869056 from home:cyphar:docker
runc 1.0.0-rc93 update.

OBS-URL: https://build.opensuse.org/request/show/869056
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=101
2021-02-04 00:26:20 +00:00
c589d24124 - Update to Docker 20.10.3-ce. See upstream changelog in the packaged
/usr/share/doc/packages/docker/CHANGELOG.md. CVE-2021-21285 CVE-2021-21284
- Drop docker-runc, docker-test and docker-libnetwork packages. We now just use
  the upstream runc package (it's stable enough and Docker no longer pins git
  versions). docker-libnetwork is so unstable that it doesn't have any
  versioning scheme and so it really doesn't make sense to maintain the project
  as a separate package. bsc#1181641 bsc#1181677

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=100
2021-02-02 22:19:53 +00:00
1e1da9e0a2 Accepting request 830453 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/830453
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=32
2020-08-31 14:47:44 +00:00
4aca013630 Accepting request 830206 from home:rhafer:branches:Virtualization:containers
- Upgrade to runc v1.0.0~rc92 (bsc#1175821). Upstream changelog is
  available from https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc92
  * Updates to CRIU support.
  * Improvements to cgroupfs performance and correctness.

OBS-URL: https://build.opensuse.org/request/show/830206
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=98
2020-08-29 09:35:30 +00:00
c4e0835c2e Accepting request 818193 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/818193
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=31
2020-07-06 14:14:00 +00:00
7b244a9844 Accepting request 818188 from home:cyphar:docker
- Upgrade to runc v1.0.0~rc91. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc91

  * This release of runc has experimental support for cgroupv2-only systems.

- Remove upstreamed patches:
  - bsc1149954-0001-sd-notify-do-not-hang-when-NOTIFY_SOCKET-is-used-wit.patch
  - bsc1168481-0001-cgroup-devices-major-cleanups-and-minimal-transition.patch

OBS-URL: https://build.opensuse.org/request/show/818188
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=96
2020-07-02 01:50:30 +00:00
74c0f964de Accepting request 804891 from Virtualization:containers
- Backport https://github.com/opencontainers/runc/pull/2391 to help fix
  bsc#1168481.
  + bsc1168481-0001-cgroup-devices-major-cleanups-and-minimal-transition.patch

OBS-URL: https://build.opensuse.org/request/show/804891
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=30
2020-05-14 21:22:28 +00:00
923e7ff863 Accepting request 804873 from home:cyphar:docker
- Backport https://github.com/opencontainers/runc/pull/2391 to help fix
  bsc#1168481.
  + bsc1168481-0001-cgroup-devices-major-cleanups-and-minimal-transition.patch

OBS-URL: https://build.opensuse.org/request/show/804873
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=94
2020-05-13 07:16:34 +00:00
8c654ae3d8 Accepting request 793810 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/793810
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=29
2020-04-15 17:53:41 +00:00
b91f4ecce0 Accepting request 793807 from home:rhafer:branches:Virtualization:containers
- Renamed patch:
  0001-sd-notify-do-not-hang-when-NOTIFY_SOCKET-is-used-wit.patch
  to
  bsc1149954-0001-sd-notify-do-not-hang-when-NOTIFY_SOCKET-is-used-wit.patch

- Added fix for bsc#1149954
  * 0001-sd-notify-do-not-hang-when-NOTIFY_SOCKET-is-used-wit.patch
    (cherry pick of https://github.com/opencontainers/runc/pull/1807)

OBS-URL: https://build.opensuse.org/request/show/793807
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=92
2020-04-14 10:22:21 +00:00
9aab460be0 Accepting request 769817 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/769817
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=28
2020-02-06 12:19:01 +00:00
c8dec0e6fa Accepting request 766566 from home:iznogood:branches:Virtualization:containers
- Change packagewide go version to be greater or equal to 1.10.

OBS-URL: https://build.opensuse.org/request/show/766566
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=90
2020-02-04 02:30:22 +00:00
e71fb241d7 Accepting request 766725 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/766725
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=27
2020-01-30 08:30:55 +00:00
9a57dbdc64 Accepting request 766724 from home:cyphar:docker
runc 1.0.0-rc10 update

OBS-URL: https://build.opensuse.org/request/show/766724
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=88
2020-01-24 03:07:47 +00:00
0e18ab7717 Accepting request 765105 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/765105
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=26
2020-01-23 15:07:57 +00:00
8a0d82c468 Accepting request 765103 from home:cyphar:docker
- Update CVE-2019-19921 patch to match upstream PR.
  * CVE-2019-19921.patch

OBS-URL: https://build.opensuse.org/request/show/765103
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=86
2020-01-17 03:34:42 +00:00
fc1984a25f Accepting request 764685 from Virtualization:containers
CVE-2019-19921

OBS-URL: https://build.opensuse.org/request/show/764685
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=25
2020-01-16 17:19:36 +00:00
8fefd473fa Accepting request 764682 from home:cyphar:docker
Add bug reference for CVE-2019-19921.

OBS-URL: https://build.opensuse.org/request/show/764682
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=84
2020-01-15 14:07:23 +00:00
01dc9f6ec0 Accepting request 764148 from home:cyphar:docker
- Add backported fix for CVE-2019-19921.
  + CVE-2019-19921.patch

OBS-URL: https://build.opensuse.org/request/show/764148
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=83
2020-01-14 04:49:43 +00:00
5a2b279580 Accepting request 735405 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/735405
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=24
2019-10-10 09:50:05 +00:00
9c821cca87 Accepting request 735404 from home:cyphar:containers:maint
- Upgrade to runc v1.0.0~rc9. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc9
- Remove upstreamed patches:
  - CVE-2019-16884.patch

OBS-URL: https://build.opensuse.org/request/show/735404
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=81
2019-10-05 11:52:50 +00:00
2606526c7c Accepting request 733834 from home:cyphar:containers:maint
Add reference to bsc#1152308.

OBS-URL: https://build.opensuse.org/request/show/733834
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=80
2019-09-28 11:41:04 +00:00
c2791cd3be Fix From: line for CVE-2019-16884.
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=79
2019-09-27 20:22:13 +00:00
53bd0f1302 Accepting request 733753 from home:cyphar:containers:maint
Add /proc/self/fd protections to CVE-2019-16884.patch.

OBS-URL: https://build.opensuse.org/request/show/733753
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=78
2019-09-27 20:18:17 +00:00
c0cf07af42 Accepting request 733530 from home:cyphar:containers:maint
Fix CVE patch.

OBS-URL: https://build.opensuse.org/request/show/733530
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=77
2019-09-27 03:17:22 +00:00
1a94d9d340 Accepting request 733478 from home:cyphar:containers:maint
- Add backported fix for CVE-2019-16884.
  + CVE-2019-16884.patch
- Add runc-rpmlintrc to drop runc-test rpmlint warnings.

OBS-URL: https://build.opensuse.org/request/show/733478
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=76
2019-09-26 15:15:16 +00:00
0eb4f05040 Accepting request 699413 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/699413
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=23
2019-05-02 17:14:41 +00:00
67c52ee2aa Accepting request 699412 from home:cyphar:runc
- Upgrade to runc v1.0.0~rc8. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc8
- Includes upstreamed patches for regressions (bsc#1131314 bsc#1131553).
- Remove upstreamed patches:
  - CVE-2019-5736.patch

OBS-URL: https://build.opensuse.org/request/show/699412
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=74
2019-04-29 12:05:18 +00:00
Stephan Kulow
c5c186118b Accepting request 674113 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/674113
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=22
2019-02-24 16:03:54 +00:00
68bddaf3ee Accepting request 674111 from home:cyphar:cve-2019-5736
- Add fix for CVE-2019-5736 (effectively copying /proc/self/exe during re-exec
  to avoid write attacks to the host runc binary). bsc#1121967
  + CVE-2019-5736.patch

OBS-URL: https://build.opensuse.org/request/show/674111
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=72
2019-02-12 14:09:26 +00:00
c07367038d Accepting request 660263 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/660263
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=21
2018-12-26 23:25:07 +00:00
337c2c14cc Accepting request 660132 from home:clee:branches:Virtualization:containers
- Update go requirements to >= go1.10 to fix
  * bsc#1118897 CVE-2018-16873
    go#29230 cmd/go: remote command execution during "go get -u"
  * bsc#1118898 CVE-2018-16874
    go#29231 cmd/go: directory traversal in "go get" via curly braces in import paths
  * bsc#1118899 CVE-2018-16875
    go#29233 crypto/x509: CPU denial of service

OBS-URL: https://build.opensuse.org/request/show/660132
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=70
2018-12-20 11:15:05 +00:00
588a1df835 Accepting request 657727 from home:dorf:branches:Virtualization:containers
- Require golang = 1.10.

OBS-URL: https://build.opensuse.org/request/show/657727
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=69
2018-12-13 07:54:13 +00:00
f03667ed33 Accepting request 652640 from Virtualization:containers
- Upgrade to runc v1.0.0~rc6. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc6

OBS-URL: https://build.opensuse.org/request/show/652640
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=20
2018-12-05 08:37:06 +00:00
adc9380f22 [ DO NOT FORWARD TO FACTORY! ]
- Upgrade to Docker 18.09.0-ce. See upstream changelog in the packaged
  /usr/share/doc/packages/docker/CHANGELOG.md
- Add revert of an upstream patch to fix docker-* handling.
  + packaging-0001-revert-Remove-docker-prefix-for-containerd-and-runc-.patch
- Rebase patches:
  * bsc1047218-0001-man-obey-SOURCE_DATE_EPOCH-when-generating-man-pages.patch
  * bsc1073877-0001-apparmor-allow-receiving-of-signals-from-docker-kill.patch
  * bsc1073877-0002-apparmor-clobber-docker-default-profile-on-start.patch
  * private-registry-0001-Add-private-registry-mirror-support.patch
  * secrets-0001-daemon-allow-directory-creation-in-run-secrets.patch
  * secrets-0002-SUSE-implement-SUSE-container-secrets.patch
- Remove upstreamed patches:
  - bsc1100727-0001-build-add-buildmode-pie.patch

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=67
2018-11-29 15:15:50 +00:00
1928689ce0 Accepting request 645770 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/645770
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=19
2018-11-06 14:29:02 +00:00
5b02da5652 Accepting request 645753 from home:vrothberg:branches:Virtualization:containers
- Create a symlink in /usr/bin/runc to enable rootless Podman and Buildah.

OBS-URL: https://build.opensuse.org/request/show/645753
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=65
2018-10-31 15:30:13 +00:00
8cfedf9e90 Accepting request 616570 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/616570
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=18
2018-06-22 11:15:38 +00:00
8c87813fbf Accepting request 616531 from home:dcassany:branches:Virtualization:containers
- Make use of %license macro

OBS-URL: https://build.opensuse.org/request/show/616531
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=63
2018-06-13 15:25:29 +00:00
b0b522efd7 Accepting request 614156 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/614156
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=17
2018-06-08 21:09:53 +00:00
Valentin Rothberg
28fa6fa85c Accepting request 614149 from home:cyphar:containers:remove_check_section
- Remove 'go test' from %check section, as it has only ever caused us problems
  and hasn't (as far as I remember) ever caught a release-blocking issue. Smoke
  testing has been far more useful. boo#1095817

OBS-URL: https://build.opensuse.org/request/show/614149
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=61
2018-06-05 07:46:42 +00:00
39fd35b355 Accepting request 580741 from Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/580741
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=16
2018-03-01 11:03:37 +00:00
5b9cf0431f Accepting request 580739 from home:cyphar:containers:runc_rc5
- Upgrade to runc v1.0.0~rc5. Upstream changelog is available from
  https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc5
- Remove patch now merged upstream.
  - bsc1053532-0001-makefile-drop-usage-of-install.patch

OBS-URL: https://build.opensuse.org/request/show/580739
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=59
2018-02-27 17:41:09 +00:00
145736efd2 Accepting request 517695 from Virtualization:containers
1

OBS-URL: https://build.opensuse.org/request/show/517695
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=15
2017-08-24 16:22:28 +00:00
a670c86507 Accepting request 517286 from home:cyphar:containers:runc_use_signed_archive
- Use .tar.xz provided by upstream, as well as include the keyring to allow
  full provenance of the source.

OBS-URL: https://build.opensuse.org/request/show/517286
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=57
2017-08-19 13:24:20 +00:00
7a344dfd11 Accepting request 517265 from Virtualization:containers
- Use the upstream Makefile, to ensure that we always include the version
  information in runc. This was confusing users (and Docker). bsc#1053532
- Add a backported patch to fix a Makefile bug.
  https://github.com/opencontainers/runc/pull/1555
  + bsc1053532-0001-makefile-drop-usage-of-install.patch
- Update to runc v1.0.0-rc4.
- Use -buildmode=pie for tests and binary build. bsc#1048046 bsc#1051429
- Cleanup seccomp builds similar to bsc#1028638

OBS-URL: https://build.opensuse.org/request/show/517265
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=14
2017-08-17 09:44:20 +00:00
9676cebf63 Accepting request 517264 from home:cyphar:containers:bsc1053532
- Use the upstream Makefile, to ensure that we always include the version and
  commit information in runc. This was confusing users (and Docker).
  bsc#1053532
- Add a backported patch to fix a Makefile bug. This also includes some other
  changes to make the docker-runc.spec mirror the newer runc.

OBS-URL: https://build.opensuse.org/request/show/517264
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=55
2017-08-16 19:16:32 +00:00
f50f0c9beb Accepting request 516116 from home:cyphar:containers:runc_update_rc4
- Update to runc v1.0.0-rc4. Upstream changelog:
	+ runc now supports v1.0.0 of the OCI runtime specification. #1527
	+ Rootless containers support has been released. The current state of
	  this feature is that it only supports single-{uid,gid} mappings as an
	  unprivileged user, and cgroups are completely unsupported. Work is
	  being done to improve this. #774
	+ Rather than relying on CRIU version nnumbers, actually check if the
	  system supports pre-dumping. #1371
	+ Allow the PIDs cgroup limit to be updated. #1423
	+ Add support for checkpoint/restore of containers with orphaned PTYs
	  (which is effectively all containers with terminal=true). #1355
	+ Permit prestart hooks to modify the cgroup configuration of a
	  container. #1239
	+ Add support for a wide variety of mount options. #1460
	+ Expose memory.use_hierarchy in MemoryStats. #1378
	* Fix incorrect handling of systems without the freezer cgroup. #1387
	* Many, many changes to switch away from Go's "syscall" stdlib to
	  "golang.org/x/sys/unix". #1394 #1398 #1442 #1464 #1467 #1470 #1474
	  #1478 #1491 #1482 #1504 #1519 #1530
	* Set cgroup resources when restoring a container. #1399
	* Switch back to using /sbin as the installation directory. #1406
	* Remove the arbitrary container ID length restriction. #1435
	* Make container force deletion ignore non-existent containers. #1451
	* Improve handling of arbitrary cgroup mount locations when populating
	  cpuset. #1372
	* Make the SaneTerminal interface public. #1479
	* Fix cases where runc would report a container to be in a "Running"
	  state if the init was a zombie or dead. #1489
	* Do not set supplementary groups for numeric users. #1450
	* Fix various issues with the "owner" field in runc-list. #1516
	* Many other miscellaneous fixes, some of which were made by first-time
	  contributors. Thanks, and welcome to the project! #1406 #1400 #1365
	  #1396 #1402 #1414 #1412 #1408 #1418 #1425 #1428 #1436 #1433 #1438
	  #1410 #1447 #1388 #1484 #1481 #1496 #1245 #1524 #1534 #1526 #1533
	- Remove any semblance of non-Linux support. #1502
	- We no longer use shfmt for testing. #1510

OBS-URL: https://build.opensuse.org/request/show/516116
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=54
2017-08-11 13:51:29 +00:00
ce95522847 - Use -buildmode=pie for tests and binary build. bsc#1048046 bsc#1051429
This also includes some various improvements to the packaging of runc,
containerd and docker-runc.

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=53
2017-08-11 12:10:02 +00:00
95b584f280 Accepting request 509158 from Virtualization:containers
1

OBS-URL: https://build.opensuse.org/request/show/509158
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=13
2017-07-30 09:22:54 +00:00
Thomas Hipp
c311eecf47 Accepting request 508797 from home:thipp:branches:Virtualization:containers
- switch to opencontainers/runc master branch
- remove CVE-2016-9962.patch 
- stop providing docker-runc

OBS-URL: https://build.opensuse.org/request/show/508797
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=51
2017-07-10 11:39:32 +00:00
c08cc4e6bb Accepting request 494718 from Virtualization:containers
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/494718
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=12
2017-05-20 08:13:19 +00:00
105b3cf4bc OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=49 2017-05-04 19:02:51 +00:00
b8321caca6 Accepting request 492509 from home:jordimassaguerpla:branch:V:c:fix_golang_req
- fix golang requirement to 1.7

OBS-URL: https://build.opensuse.org/request/show/492509
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=48
2017-05-04 18:33:34 +00:00
b03a9ad55f Accepting request 491891 from home:jengelh:branches:Virtualization:containers
- Substitute %__-type macro indirections

OBS-URL: https://build.opensuse.org/request/show/491891
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=47
2017-04-28 16:29:38 +00:00
c6750aa1a1 OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=46 2017-04-20 10:54:06 +00:00
f4e0799fbb OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=45 2017-04-20 10:25:40 +00:00
98d4194e22 Accepting request 487329 from Virtualization:containers
1

OBS-URL: https://build.opensuse.org/request/show/487329
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=11
2017-04-17 08:26:20 +00:00
6d3438c47b Accepting request 487318 from home:cyphar:containers
Fix up the ignore cgroupv2 patch so it is easier to track.

OBS-URL: https://build.opensuse.org/request/show/487318
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=43
2017-04-11 12:14:17 +00:00
faf305337d fix changelog
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=42
2017-04-11 11:03:16 +00:00
6b0d36eb61 Accepting request 487271 from home:jordimassaguerpla:branch:V:c:runc:ignore_cgroup_v2_mountpoints
- fix bsc#1028113 - runc: make sure to ignore cgroup v2 mountpoints

OBS-URL: https://build.opensuse.org/request/show/487271
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=41
2017-04-11 09:56:51 +00:00
2fc0db0acd Accepting request 478794 from Virtualization:containers
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/478794
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=10
2017-03-12 19:05:55 +00:00
c57749596d Accepting request 461897 from home:jordimassaguerpla:branch:Vc:update_docker_1_13
- update to docker-1.13.0 requirement

OBS-URL: https://build.opensuse.org/request/show/461897
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=39
2017-03-05 03:07:20 +00:00
161e459806 Accepting request 450531 from Virtualization:containers
(forwarded request 450530 from jordimassaguerpla)

OBS-URL: https://build.opensuse.org/request/show/450531
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=9
2017-01-23 10:36:50 +00:00
f0fbd369e5 Accepting request 450530 from home:jordimassaguerpla:branch:Vc:runc:fix_CVE_name
OBS-URL: https://build.opensuse.org/request/show/450530
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=37
2017-01-16 15:08:31 +00:00
03232f8a36 OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=36 2017-01-13 17:01:54 +00:00
5a0827b682 Accepting request 447965 from Virtualization:containers
- update runc to the version used in docker 1.12.5 (bsc#1016307).
  This fixes bsc#1015661 

- For the moment, we have to switch to using Docker's fork of runC. This *will*
  be solved properly by creating a new package purely for Docker's runC fork,
  because it's quite silly to tie OCI project releases to Docker's vendoring
  scheme. Once this is fixed, this package will be switch to being purely-OCI.

- add the /usr/bin/docker-run symlink to partially fix bsc#1015661

  fix bsc#1009961
- update to 02f8fa7 because that is the needed version for docker 1.12.1 (bsc#1004490)
  it fails to build

OBS-URL: https://build.opensuse.org/request/show/447965
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=8
2017-01-10 09:44:31 +00:00
24bfdba743 Accepting request 447963 from home:jordimassaguerpla:branch:Vc:fix_runc_symlink
OBS-URL: https://build.opensuse.org/request/show/447963
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=34
2016-12-28 10:08:10 +00:00
eb1aad3421 Accepting request 447318 from home:jordimassaguerpla:branch:V:c:fix_runc_symlink
- add symlink to docker-runc in the post section, as this is how it
  has been already fixed for some client. fixes bsc#1015661

OBS-URL: https://build.opensuse.org/request/show/447318
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=33
2016-12-21 16:38:17 +00:00
118b9cd3a0 fix version
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=32
2016-12-19 17:41:49 +00:00
4c6313f08e OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=31 2016-12-19 14:01:37 +00:00
e10db47282 Accepting request 446750 from home:jordimassaguerpla:branch:Vc:runc_symlink_docker_runc
- add the /usr/bin/docker-run symlink to partially fix bsc#1015661

OBS-URL: https://build.opensuse.org/request/show/446750
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=30
2016-12-19 08:39:07 +00:00
0500cba636 Accepting request 441850 from Virtualization:containers
1

OBS-URL: https://build.opensuse.org/request/show/441850
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=7
2016-11-24 20:26:04 +00:00
23bd349d7b Accepting request 441846 from home:jordimassaguerpla:branch:Vc:fix_runc_and_containerd_versioning
- fix version by adding a revision "counter" so that it will always
  increase
  fix bsc#1009961

OBS-URL: https://build.opensuse.org/request/show/441846
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=28
2016-11-24 12:49:13 +00:00
83eec669cd Accepting request 437086 from Virtualization:containers
update to docker-1.12.2

OBS-URL: https://build.opensuse.org/request/show/437086
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=6
2016-10-26 11:29:17 +00:00
1ebe653ab7 OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=27 2016-10-24 10:56:10 +00:00
fbe3aed76a Accepting request 429838 from Virtualization:containers
1

OBS-URL: https://build.opensuse.org/request/show/429838
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=5
2016-09-30 13:31:55 +00:00
de54266a52 Accepting request 429757 from home:jengelh:branches:Virtualization:containers
- Run fdupes.

OBS-URL: https://build.opensuse.org/request/show/429757
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=25
2016-09-23 14:37:04 +00:00
628d2347f9 Accepting request 428676 from Virtualization:containers
1

OBS-URL: https://build.opensuse.org/request/show/428676
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=4
2016-09-21 16:49:18 +00:00
b7d6e6faa6 Accepting request 428672 from home:jordimassaguerpla:branch:V:c:fix_go_arches_def
- fix go_arches definition: use global instead of define, otherwise
  it fails to build

OBS-URL: https://build.opensuse.org/request/show/428672
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=23
2016-09-19 12:08:36 +00:00
c9c9a9be7e Accepting request 422801 from home:cyphar:branches:Virtualization:containers
Removes the docker-runc symlink, since that's been fixed as part of sr#422714

OBS-URL: https://build.opensuse.org/request/show/422801
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=22
2016-08-26 10:03:29 +00:00
Christian Brauner
939f8c5c0e Accepting request 422238 from home:jordimassaguerpla:branch:Vc:symlink_runc
- Create a symlink /usr/sbin/docker-runc -> /usr/sbin/docker
  Docker expects this symlink to exist

OBS-URL: https://build.opensuse.org/request/show/422238
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=21
2016-08-25 17:13:43 +00:00
Christian Brauner
241b17da12 Accepting request 422163 from home:jordimassaguerpla:branch:Vc:gcc_fails_with_GOPATH_empty
- Remove GOPATH at the end of the GOPATH assignment
  cause GOPATH is empty and if we do that, we get the path ""
  appended, which causes gcc6-go to complain

OBS-URL: https://build.opensuse.org/request/show/422163
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=20
2016-08-25 16:01:03 +00:00
Christian Brauner
87f4726724 Accepting request 421922 from home:jordimassaguerpla:branch:V:c:fix_go_arches_definition
fix the go_arches definition

OBS-URL: https://build.opensuse.org/request/show/421922
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=19
2016-08-25 13:46:46 +00:00
Christian Brauner
d2d654dc53 Accepting request 421771 from home:jordimassaguerpla:branch:Vc:add_version_unconverted_back
add version_unconverted back

OBS-URL: https://build.opensuse.org/request/show/421771
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=18
2016-08-24 15:03:48 +00:00
Christian Brauner
2179b88ce1 Accepting request 421574 from home:jordimassaguerpla:branch:V:c:add_go_arches_in_prjconf
- add go_arches in project configuration: this way, we can use the
  same spec file but decide in the project configuration if to
  use gc-go or gcc-go for some archs.

OBS-URL: https://build.opensuse.org/request/show/421574
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=17
2016-08-24 12:34:21 +00:00
Christian Brauner
a8cdc9e7c2 Accepting request 421318 from Virtualization:containers:1.12-RC
- use gcc6-go instead of gcc5-go (bsc#988408) 
- build ppc64le with gc-go because this version builds with gc-go 1.6

- bump git commit id to the one required by docker v1.12.0 (bsc#995058)
- run unit tests during package build
- remove seccomp-use-pkg-config.patch
  The patch is now upstream.
- remove GO_BUILD_FLAGS macro and substitute with BUILDFLAGS env variable to
  allow for easier string appending.
- only run unit test on architectures that provide the go list and go test tools

OBS-URL: https://build.opensuse.org/request/show/421318
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=16
2016-08-23 15:12:47 +00:00
160ef62d41 Accepting request 419732 from Virtualization:containers
1

OBS-URL: https://build.opensuse.org/request/show/419732
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=3
2016-08-18 07:18:07 +00:00
4112781916 Accepting request 419728 from home:chbrauner:branches:Virtualization:containers
OBS-URL: https://build.opensuse.org/request/show/419728
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=14
2016-08-17 10:45:55 +00:00
ad8992e528 Accepting request 415383 from Virtualization:containers
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/415383
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=2
2016-07-29 22:27:41 +00:00
2f5fe34871 update changelog with fate#
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=12
2016-07-20 08:35:48 +00:00
c681e5e813 add bug number for docker 1.11.2
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=11
2016-07-19 15:34:55 +00:00
81e42fa4f7 Accepting request 392078 from Virtualization:containers
This is necessary for the Docker 1.11.1 update, in which the daemon has been
split into multiple components.

runC is also a useful package unto itself (it allows people to just run
containers without needing any of the complicated functionality that Docker
provides).

OBS-URL: https://build.opensuse.org/request/show/392078
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/runc?expand=0&rev=1
2016-05-04 06:19:55 +00:00
c3a7dc71d7 * Remove empty %postun and %post sections.
* Update to runC 0.1.1. Changelog from upstream:
  This release includes a bug fix for adding the selinux mount label in the specification.

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=9
2016-04-29 09:35:10 +00:00
4af6b62b5f * Don't use gcc-go for aarch64, since gc has grown support for it and is more
stable.

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=8
2016-04-19 10:00:18 +00:00
a16035cb0e * Disable seccomp entirely for aarch64 builds, since it is not provided on all
SUSE platforms.

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=7
2016-04-15 10:47:01 +00:00
ffc5144079 * Update to runC 0.1.0. Changelog from upstream:
This release updates runc to the OCI runtime specification v0.5.0 and includes
  various fixes and features.

  Features:
  + cgroups: pid limits and stats
  + cgroups: kmem stats
  + systemd cgroup support
  + libcontainer specconv package
  + no pivot root option
  + numeric ids are treated as uid/gid
  + hook improvements

  Bug Fixes:
  * log flushing
  * atomic pid file creation
  * init error recovery
  * seccomp logging removed
  * delete container on aborted start
  * /dev bind mount handling

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=6
2016-04-13 12:11:46 +00:00
ff3f9b9234 * Install to /usr/sbin. https://github.com/opencontainers/runc/pull/702
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=5
2016-03-30 14:18:58 +00:00
723532a2f2 * Added runC man pages.
* Recommended criu, since it's required for the checkpoint and restore
  functionality.

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=4
2016-03-27 15:19:30 +00:00
b67aa431ac * Small updates to method of compilation to better match Makefile.
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=3
2016-03-27 10:15:05 +00:00
45aa94d4dc * Make compilation work on gcc-go only systems (ppc and s390).
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=2
2016-03-21 12:15:39 +00:00
3ecd3b8405 * initial import of runC 0.0.9
* add patch seccomp-use-pkg-config.patch which allows us to build runC, since
  they assume that the seccomp.h file lives at /usr/include/seccomp.h.

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/runc?expand=0&rev=1
2016-03-21 08:36:29 +00:00
11 changed files with 146 additions and 71 deletions

View File

@@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:3f6fed97bf5db1d4eac43b622a62379e07f3f73dd1c3e5ee5c0f82a1c960e1f7
size 1603252

View File

@@ -1,17 +0,0 @@
-----BEGIN PGP SIGNATURE-----
iQJEBAABCAAuFiEEXzbGxhtUYBJKdfWmnhiqJn3bjbQFAmYNM/MQHGFzYXJhaUBz
dXNlLmNvbQAKCRCeGKomfduNtLTvEACihuWRg3CBLJuZFnV5YMkgYO1nhNfcY0TX
BJWqrjleSkyhrWWNeGPmCLGvCLzQtk+pQzC8T2lN3/y4VNIsdSUrGrMP6uSh3uKu
TF/IMBL5HJmowv+6RYcKb0kq9ta1lFR8LL63o7hn45xu5ZsnQGwEz+nI4IbrYRjr
zPyYD5GQgkjFzBeHUb5BcbGNgZ62XTyyhZgUH8D/2+X9B/xqK6RKZ+dEVD4rU/nj
rQafX4GHg+20OsmUj5AoE+nXkP98YyM33Nh9RQKNdDwS/OZ8lh24BtN4635VRINA
EsCLKZKAb9Eu0Wqs/b0k8RsWblNEg/fDPvTg8bBJI6tIldVa8K4mqk6tOYL1zZzD
33F5lhpNdstajFZuehXDHDqhDAQmJ0GAHDFeGZo7Am7wTmxSNNZ0gpo1zcWl9Y/D
xW12H/oYtMwaj3MrtmlN+Os3V4pm16FgFM6LuPAR79FrXpu1l30D1wkVvQsp5pkD
XaUxLw6kYzt5Z/PB13L7QccxojRDJtFCDf2n4DLHJWI/qFe57qYCwD0TP/gIDkOA
HE4t7UU6lygPwIbc+0Zc5S7zOI3/CBgq1IWoMiZamAEs3FzPwt4jC3Czq9zemHPU
7gyjR5rTVTJu9OOCVhyegxqD2fOxMOEKITAHrKIN+qnQkXAQ5gXeY4mHWr02tkkW
7rsh+eQR2A==
=io9I
-----END PGP SIGNATURE-----

View File

@@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:293b7271196a7284a1cca1865e8e210d9c153054b0d0c04f3a69f28ca517723d
size 1607920

View File

@@ -1,11 +0,0 @@
-----BEGIN PGP SIGNATURE-----
iQEzBAABCAAdFiEEwkKM11cg+s3PdrbqF95ey3WhEA4FAmZ8WH4ACgkQF95ey3Wh
EA6mMwf/Zh+RldJEoFjye87UFK9OhNMZCwIKqYS4mKNRdgCfdzYq/ZGbvczwGbQQ
tUpD7UFfHlIegc1qJkOi20LtyzoE+H3bChacjn5N0hpfbfJ/NUPMgoBFxpcPS8Bp
xdyKrA4L6RwvoS6APxAfzqFoXkZ0lADxa/x46NBgxHMCXkGwofY6n/G+2ztgYEyn
hg10kG2olFK7nbmCms3xdxi2AEQ5V35SwyCtZrSnVlm/9rGtZZro8eiF4MXMYr9N
Cj/9oWy+F4ATzkQI1FoqtE5K8uhD76qFtKfJ67SuVGZhHaqLUPSuMjlF6Qlu+ziA
0YH6gwvKpvtFSejEM2l9UKYazASJMA==
=tl7E
-----END PGP SIGNATURE-----

View File

@@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:837185e9041c795187eb0f775af8d0b76869e98376bad7cf5f3249a2c636e794
size 1609672

View File

@@ -1,7 +0,0 @@
-----BEGIN PGP SIGNATURE-----
iHUEABYKAB0WIQS2TklVsp+j1GPyqQYol/rSt+lEbwUCZtZoygAKCRAol/rSt+lE
bx7WAP0SyVg+qUJHACE0IkVAxaBzqVjNFVhdLY5ieF9h4LE0KgEA5Aa2n1k22JMX
0774jwpF778ieaNR3L6sf/hKjAXTmwM=
=6S7t
-----END PGP SIGNATURE-----

BIN
runc-1.3.4.tar.xz LFS Normal file

Binary file not shown.

8
runc-1.3.4.tar.xz.asc Normal file
View File

@@ -0,0 +1,8 @@
-----BEGIN PGP SIGNATURE-----
iJEEABYKADkWIQS2TklVsp+j1GPyqQYol/rSt+lEbwUCaSjevxsUgAAAAAAEAA5t
YW51MiwyLjUrMS4xMSwyLDIACgkQKJf60rfpRG8DqgEAgQBUL0dOg31PIjBq03oW
5dLKfrM4KQS4tDfj36Ol7y0A/jmlAoMzn32VfL2UnEh1DUBHFDxhiXvNEA3lNf0O
G3gC
=Q/Xl
-----END PGP SIGNATURE-----

View File

@@ -1,9 +1,115 @@
-------------------------------------------------------------------
Fri Nov 28 00:20:13 UTC 2025 - Aleksa Sarai <asarai@suse.com>
- Update to runc v1.3.4. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.3.4>. bsc#1254362
-------------------------------------------------------------------
Wed Nov 5 10:05:32 UTC 2025 - Aleksa Sarai <asarai@suse.com>
- Update to runc v1.3.3. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.3.3>. bsc#1252232
* CVE-2025-31133
* CVE-2025-52565
* CVE-2025-52881
- Remove upstreamed patches for bsc#1252232:
- 2025-11-05-CVEs.patch
-------------------------------------------------------------------
Thu Oct 16 02:16:12 UTC 2025 - Aleksa Sarai <asarai@suse.com>
[ This update was only released for SLE 12 and 15. ]
- Backport patches for three CVEs. All three vulnerabilities ultimately allow
(through different methods) for full container breakouts by bypassing runc's
restrictions for writing to arbitrary /proc files. bsc#1252232
* CVE-2025-31133
* CVE-2025-52565
* CVE-2025-52881
+ 2025-11-05-CVEs.patch
-------------------------------------------------------------------
Fri Oct 10 14:10:23 UTC 2025 - Aleksa Sarai <asarai@suse.com>
[ This update was only released for SLE 12 and 15. ]
- Update to runc v1.2.7. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.2.7>.
-------------------------------------------------------------------
Sat Oct 4 05:01:50 UTC 2025 - Aleksa Sarai <asarai@suse.com>
- Update to runc v1.3.2. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.3.2> bsc#1252110
- Includes an important fix for the CPUSet translation for cgroupv2.
-------------------------------------------------------------------
Thu Sep 4 15:29:15 UTC 2025 - Aleksa Sarai <asarai@suse.com>
- Update to runc v1.3.1. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.3.1>
- Fix runc 1.3.x builds on SLE-12 by enabling --std=gnu11.
-------------------------------------------------------------------
Tue Apr 29 15:23:32 UTC 2025 - Aleksa Sarai <asarai@suse.com>
- Update to runc v1.3.0. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.3.0>
-------------------------------------------------------------------
Thu Apr 10 03:52:03 UTC 2025 - Aleksa Sarai <asarai@suse.com>
- Update to runc v1.2.6. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.2.6>.
-------------------------------------------------------------------
Fri Feb 14 01:31:56 UTC 2025 - Aleksa Sarai <asarai@suse.com>
- Update to runc v1.2.5. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.2.5>.
-------------------------------------------------------------------
Tue Jan 7 06:31:57 UTC 2025 - Aleksa Sarai <asarai@suse.com>
- Update to runc v1.2.4. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.2.4>.
- Update runc.keyring to match upstream.
-------------------------------------------------------------------
Wed Dec 11 02:01:52 UTC 2024 - Aleksa Sarai <asarai@suse.com>
- Update to runc v1.2.3. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.2.3>.
-------------------------------------------------------------------
Sat Nov 16 01:55:06 UTC 2024 - Aleksa Sarai <asarai@suse.com>
- Update to runc v1.2.2. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.2.2>.
-------------------------------------------------------------------
Fri Nov 1 22:26:11 UTC 2024 - Aleksa Sarai <asarai@suse.com>
- Update to runc v1.2.1. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.2.1>.
-------------------------------------------------------------------
Mon Oct 21 22:42:50 UTC 2024 - Aleksa Sarai <asarai@suse.com>
- Update to runc v1.2.0. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.2.0>.
- Remove upstreamed patches.
- 0001-bsc1221050-libct-seccomp-patchbpf-rm-duplicated-code.patch
- 0002-bsc1221050-seccomp-patchbpf-rename-nativeArch-linuxA.patch
- 0003-bsc1221050-seccomp-patchbpf-always-include-native-ar.patch
- 0004-bsc1214960-nsenter-cloned_binary-remove-bindfd-logic.patch
-------------------------------------------------------------------
Tue Sep 3 02:01:16 UTC 2024 - Aleksa Sarai <asarai@suse.com>
- Update to runc v1.2.0~rc3. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.2.0-rc.3>.
Includes the patch for CVE-2024-45310.
Includes the patch for CVE-2024-45310. bsc#1230092
-------------------------------------------------------------------
Tue Sep 3 01:57:20 UTC 2024 - Aleksa Sarai <asarai@suse.com>
@@ -12,7 +118,7 @@ Tue Sep 3 01:57:20 UTC 2024 - Aleksa Sarai <asarai@suse.com>
- Update to runc v1.1.14. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.1.14>.
Includes the patch for CVE-2024-45310.
Includes the patch for CVE-2024-45310. bsc#1230092
- Rebase patches:
* 0001-bsc1221050-libct-seccomp-patchbpf-rm-duplicated-code.patch
@@ -26,7 +132,7 @@ Mon Jul 22 13:08:06 UTC 2024 - Aleksa Sarai <asarai@suse.com>
[ This was only ever released for SLES and Leap. ]
- Update to runc v1.1.13. Upstream changelog is available from
<https://github.com/opencontainers/runc/releases/tag/v1.1.12>.
<https://github.com/opencontainers/runc/releases/tag/v1.1.13>.
- Rebase patches:
* 0001-bsc1221050-libct-seccomp-patchbpf-rm-duplicated-code.patch
* 0002-bsc1221050-seccomp-patchbpf-rename-nativeArch-linuxA.patch

View File

@@ -122,10 +122,10 @@ lxxclgJYU604APsFzpoLD0oUlfMn5Fh75ftkKPrwiHpTj4rRU6oIQu1/Bg==
=Ab7w
-----END PGP PUBLIC KEY BLOCK-----
pub rsa2048 2020-04-28 [SC] [expires: 2025-04-18]
pub rsa2048 2020-04-28 [SC] [expires: 2028-04-18]
C2428CD75720FACDCF76B6EA17DE5ECB75A1100E
uid [ultimate] Kir Kolyshkin <kolyshkin@gmail.com>
sub rsa2048 2020-04-28 [E] [expires: 2025-04-18]
sub rsa2048 2020-04-28 [E] [expires: 2028-04-18]
-----BEGIN PGP PUBLIC KEY BLOCK-----
Comment: github=kolyshkin
@@ -137,26 +137,26 @@ ppTSiCl8/x/gKoXiJ+7MyvOZozUavkVHdim1NKCzwD014VOB8RXz+heUjS+HDXY9
SbTL4jCsN/x0bq+ZNp4lunihVY5WqX+BGLcx7xPnJ0Rp9Ju1mAhKrbKUmOG3rkWu
DIJuVP8HQfCoffsBLUKQ0V4fh18kfq1bo3JvABEBAAG0I0tpciBLb2x5c2hraW4g
PGtvbHlzaGtpbkBnbWFpbC5jb20+iQFUBBMBCAA+AhsDBQsJCAcCBhUKCQgLAgQW
AgMBAh4BAheAFiEEwkKM11cg+s3PdrbqF95ey3WhEA4FAmRAbOgFCQlaGGoACgkQ
F95ey3WhEA6dRQf+P+OHI3QiZu3TnrNBTsf+V8HhFBWKqafrjKbIE1A5HOHzcK2F
t2afYG+MZQILwSuCQOObgr3o7hGlqkwMwGtHt5nqG6/Z0bmkowG4JJmYIg9FhvQW
JEm/7lSBtxvFkw05H90UlzCM7AigD+PrLs96Zb0+FqdzEDWTMJeU7yYUFRNbXEu3
wqpOZpHlYCJGKzFJBbGxYphlmljexRlWdZPwACKg7lBsVkM8JDPGxmmEe7/5tXPt
Oa1yS13SleLv4muHH3KO3cgJGqBfY/XIExZUQUF0GdL0yppBDbn0oZ/wvRuibCR0
1P7rW88csSjAjhNjja4v/zWleSIpyWVi8IvYLLkBDQReqLt+AQgAtKUDLyUFxQ9k
AgMBAh4BAheAFiEEwkKM11cg+s3PdrbqF95ey3WhEA4FAmdcs+gFCQ7+0bIACgkQ
F95ey3WhEA6rRwf8CxnbLB/uqPZfmmiTzTk7luWaIo6YxtnNz3bn2rTByEo+rBgO
gbgtKaV4REYeKhtbdstkMTX3zr+zlqwuqaPaag/Cz20HLkD04bI+JCPoRH/dPadd
3nOdbdRfdWZeDDSFKjVunVpXlLxwvZ1WaaYKCfF06U3F7/z7MTAuKHrHTG9SrNPJ
UPJTy63dNnuiPpVNNtOyftLGEGgD1JH2tcosVEwEpAlXpIpJy4Lad9ajaRVoYNtT
qZr26sRFYNOQqWgl25QM8LyLFyYry9HfEXkbilW0OpkAkUvv0yAe97UPZ0beP8D+
d5rMbZps6Ph1TtosdE/Gx8xWs7ALNDmXyCI/F7kBDQReqLt+AQgAtKUDLyUFxQ9k
p8OwI/MsPTLLoYfjilJaXnmtzQjGYFrEuU3lt7omRUBldNChkjGghEukGTq0RD7Z
s6Qv5PM5dtOypPJM0lmz2j7seun3AfDV44h/bjOFwTUjab3Nr9fQ52qESmRS03ik
6+5YNwq2D/+2kHVJ2vkUoo6KvioA1vPU311oW/Yfky8dLS5NguikE3to6YElWW38
oqFUVdMScCbf9a6CPXSQEz/rH4TgAhwyTo6oegv+8L/szGFy5ToNGiA0D45HcFDc
yXs1d+b3bYRuGfC1l/z+WZWwbeHt1fKEQ8pCLDLRre5y0hPRHeN2CG4U7iyI5B5h
8LITPcZ66wARAQABiQE8BBgBCAAmAhsMFiEEwkKM11cg+s3PdrbqF95ey3WhEA4F
AmRAbRQFCQlaGJYACgkQF95ey3WhEA7vywf9FFTeRgNji8ZIPMM2vIlns+CMkP5R
uXakU6Q0O6Wmbb/ULOkobTqJ/Jcze8OuembuU3V6MiOQKgUIDrN7itjnJPQBneKT
iqJdPK8KOiGIzqa0aRekvOu2nCz9n87Bf48pviH922yfs8gXYRCUnSV/i7/p+N8r
5Fy7dJen5SXksN2/rUCEgU9FD17l2uMAoQbRqZg74/GwSDLnhrZ9eMrbPnguSQF4
S1NPMeS7+G/gPN9Ze9qFmOF2p57cmEa+8mriZCYY3BcUBOiMOV5HSBKJwqA2M8au
2dAKmFWb/G+K/dgBdkAulQ/BfCpwgFmmgJ5dAeaS3y8Xd86aBE0/eLCrhQ==
=GkpD
AmdctAIFCQ7+0bIACgkQF95ey3WhEA7PDggAlZxK7mCYThh7Z75mWftIaT3ms5jR
cuQcCQYy2Z7qCaNxJtRklhsaAwpO0NQdNdQEfVXlNYLXRuFDq+hemhZKMu4lzQbZ
3atm5swWcB8+9q+aCMP5nppwUXxCxHdhp4VxIYEv+wNjTF/6Fxu66fYPQPDKVacS
H9NLjHsVoDFSi9rvtAy/Bs2aVn0hZkwpxzHJNVPnNcMAEnYXfM+kXu3761J61FAr
o8zT9XXXnUYRuxHRAsrpa3atQj7jDHvFlcc3VfPmUFPs0aLRy19/44xRE1FZOSur
f7jJ1HOKSJA9zx0xWaURRTRkMTIVuMnQKZofxC96GavBDVTtZlgLzeWVnQ==
=eHgH
-----END PGP PUBLIC KEY BLOCK-----
pub rsa3072 2019-07-25 [SC] [expires: 2025-07-27]

View File

@@ -1,7 +1,7 @@
#
# spec file for package runc
#
# Copyright (c) 2024 SUSE LLC
# Copyright (c) 2025 SUSE LLC and contributors
#
# All modifications and additions to the file contributed by third parties
# remain the property of their copyright owners, unless otherwise agreed
@@ -18,16 +18,14 @@
# MANUAL: Make sure you update this each time you update runc.
%define git_version 45471bc945571d57acef05e0795008d7f1d9baf5
%define git_short 45471bc94557
%define git_version d6d73eb8c60246978da649ffe75ce5c8bca8f856
%define git_short d6d73eb8c602
%define project github.com/opencontainers/runc
Name: runc
# RPM doesn't handle semver rc releases nicely, so for rc releases we need to
# do something different.
%define upstream_version 1.2.0-rc.3
Version: 1.2.0~rc3
Version: 1.3.4
%define upstream_version %{version}
Release: 0
Summary: Tool for spawning and running OCI containers
License: Apache-2.0
@@ -38,7 +36,7 @@ Source1: https://github.com/opencontainers/runc/releases/download/v%{upst
Source2: runc.keyring
BuildRequires: diffutils
BuildRequires: fdupes
BuildRequires: go >= 1.22.4
BuildRequires: go >= 1.23
BuildRequires: go-go-md2man
BuildRequires: libseccomp-devel
BuildRequires: libselinux-devel
@@ -70,6 +68,10 @@ and has grown to become a separate project entirely.
%autopatch -p1
%build
%if 0%{?sle_version} == 120000
# Fix nsenter builds on SLE12.
export CGO_CFLAGS="--std=gnu11"
%endif
# build runc
make BUILDTAGS="seccomp" COMMIT="%{git_describe}" runc
# build man pages