Brian Goff [Thu, 30 May 2019 21:55:52 +0000 (14:55 -0700)]
Add chroot for tar packing operations
Previously only unpack operations were supported with chroot.
This adds chroot support for packing operations.
This prevents potential breakouts when copying data from a container.
Signed-off-by: Brian Goff <cpuguy83@gmail.com>
Origin: upstream, https://github.com/moby/moby/pull/39292
Gbp-Pq: Name cve-2018-15664-02-add-chroot-for-tar-packing-operations.patch
Brian Goff [Thu, 30 May 2019 18:15:09 +0000 (11:15 -0700)]
Pass root to chroot to for chroot Untar
This is useful for preventing CVE-2018-15664 where a malicious container
process can take advantage of a race on symlink resolution/sanitization.
Before this change chrootarchive would chroot to the destination
directory which is attacker controlled. With this patch we always chroot
to the container's root which is not attacker controlled.
Signed-off-by: Brian Goff <cpuguy83@gmail.com>
Origin: upstream, https://github.com/moby/moby/pull/39292
Gbp-Pq: Name cve-2018-15664-01-pass-root-to-chroot-to-for-chroot-untar.patch
[ Dmitry Smirnov ]
* rules: no longer disable Go cache to prevent FTBFS with Go 1.12.
[ Felix Geyer ]
* Cherry-pick upstream commits to fix test failures with golang >= 1.11.6-1+deb10u1
* Add upstream patch for CVE-2019-14271
* Fix build failure with gogo/protobuf >= 1.2