runc (1.0.0~rc6+dfsg1-3) unstable; urgency=medium
authorShengjing Zhu <zhsj@debian.org>
Sun, 10 Mar 2019 09:51:44 +0000 (09:51 +0000)
committerShengjing Zhu <zhsj@debian.org>
Sun, 10 Mar 2019 09:51:44 +0000 (09:51 +0000)
commitcb81dadc54ff552c857288a3d9dcc57eca4ddbfb
treeba061562a2ee8de4c0d07cced1e1e6e73468f29c
parent85d24da38094071683916dc5d4b54ee9d322bd36
parentf918038b73c4180a0dd5c1b5d0d7647434c4c9dc
runc (1.0.0~rc6+dfsg1-3) unstable; urgency=medium

  * Team upload.

  [ Shengjing Zhu ]
  * Improve patch for CVE-2019-5736 based on upstream commits.
    Now the patch includes following commits:
    + 2d4a37b nsenter: cloned_binary: userspace copy fallback if sendfile fails
    + 16612d7 nsenter: cloned_binary: try to ro-bind /proc/self/exe before
              copying
    + af9da0a nsenter: cloned_binary: use the runc statedir for O_TMPFILE
    + 2429d59 nsenter: cloned_binary: expand and add pre-3.11 fallbacks
    + 5b775bf nsenter: cloned_binary: detect and handle short copies
    + bb7d8b1 nsexec (CVE-2019-5736): avoid parsing environ
    + 0a8e411 nsenter: clone /proc/self/exe to avoid exposing host binary to
              container

  [ Arnaud Rebillout ]
  * Add version and gitcommit to the ldflags (Closes: #909644)
    Note that we fill the git commit with something that is NOT a git commit
    at all, instead we use it as a placeholder for the debian version. The
    debian version is a relevant information for the user, and it's nice to
    be able to show it, some way or another.

[dgit import unpatched runc 1.0.0~rc6+dfsg1-3]
21 files changed:
debian/changelog
debian/clean
debian/compat
debian/control
debian/copyright
debian/gbp.conf
debian/gitlab-ci.yml
debian/golang-github-opencontainers-runc-dev.install
debian/patches/CVE-2019-5736.patch
debian/patches/series
debian/patches/test--fix_TestGetAdditionalGroups.patch
debian/patches/test--skip-Hugetlb.patch
debian/patches/test--skip_TestFactoryNewTmpfs.patch
debian/rules
debian/runc.docs
debian/runc.install
debian/runc.lintian-overrides
debian/runc.manpages
debian/source/format
debian/source/lintian-overrides
debian/watch