runc.git
6 years agoMerge runc (1.0.0~rc9+dfsg1-1+rpi1) import into refs/heads/workingbranch
Peter Michael Green [Tue, 15 Oct 2019 17:37:31 +0000 (18:37 +0100)]
Merge runc (1.0.0~rc9+dfsg1-1+rpi1) import into refs/heads/workingbranch

6 years agodisable test (requires root)
Dmitry Smirnov [Tue, 15 Oct 2019 17:37:31 +0000 (18:37 +0100)]
disable test (requires root)

Last-Update: 2018-06-15
Forwarded: not-needed

Gbp-Pq: Name test--skip_TestFactoryNewTmpfs.patch

6 years agodisabled unreliable tests due to random failures on [ppc64el, s390x].
Dmitry Smirnov [Tue, 15 Oct 2019 17:37:31 +0000 (18:37 +0100)]
disabled unreliable tests due to random failures on [ppc64el, s390x].

Last-Update: 2018-09-27
Forwarded: not-needed
Bug-Upstream: https://github.com/opencontainers/runc/issues/1822

Gbp-Pq: Name test--skip-Hugetlb.patch

6 years agofix FTBFS on i686
Dmitry Smirnov [Tue, 15 Oct 2019 17:37:31 +0000 (18:37 +0100)]
fix FTBFS on i686

Last-Update: 2018-06-16
Forwarded: https://github.com/opencontainers/runc/pull/1821
Bug-Upstream: https://github.com/opencontainers/runc/issues/941

src/github.com/opencontainers/runc/libcontainer/user/user_test.go:448:36: constant 2147483648 overflows int

Gbp-Pq: Name test--fix_TestGetAdditionalGroups.patch

6 years agorunc (1.0.0~rc9+dfsg1-1+rpi1) bullseye-staging; urgency=medium
Peter Michael Green [Tue, 15 Oct 2019 17:37:31 +0000 (18:37 +0100)]
runc (1.0.0~rc9+dfsg1-1+rpi1) bullseye-staging; urgency=medium

  * Disable testsuite.

[dgit import unpatched runc 1.0.0~rc9+dfsg1-1+rpi1]

6 years agoImport runc_1.0.0~rc9+dfsg1-1+rpi1.debian.tar.xz
Peter Michael Green [Tue, 15 Oct 2019 17:37:31 +0000 (18:37 +0100)]
Import runc_1.0.0~rc9+dfsg1-1+rpi1.debian.tar.xz

[dgit import tarball runc 1.0.0~rc9+dfsg1-1+rpi1 runc_1.0.0~rc9+dfsg1-1+rpi1.debian.tar.xz]

6 years agoMerge runc (1.0.0~rc9+dfsg1-1) import into refs/heads/workingbranch
Dmitry Smirnov [Wed, 9 Oct 2019 08:09:07 +0000 (09:09 +0100)]
Merge runc (1.0.0~rc9+dfsg1-1) import into refs/heads/workingbranch

6 years agoImport runc_1.0.0~rc9+dfsg1.orig.tar.xz
Dmitry Smirnov [Wed, 9 Oct 2019 08:09:07 +0000 (09:09 +0100)]
Import runc_1.0.0~rc9+dfsg1.orig.tar.xz

[dgit import orig runc_1.0.0~rc9+dfsg1.orig.tar.xz]

6 years agodisable test (requires root)
Dmitry Smirnov [Wed, 9 Oct 2019 08:09:07 +0000 (09:09 +0100)]
disable test (requires root)

Last-Update: 2018-06-15
Forwarded: not-needed

Gbp-Pq: Name test--skip_TestFactoryNewTmpfs.patch

6 years agodisabled unreliable tests due to random failures on [ppc64el, s390x].
Dmitry Smirnov [Wed, 9 Oct 2019 08:09:07 +0000 (09:09 +0100)]
disabled unreliable tests due to random failures on [ppc64el, s390x].

Last-Update: 2018-09-27
Forwarded: not-needed
Bug-Upstream: https://github.com/opencontainers/runc/issues/1822

Gbp-Pq: Name test--skip-Hugetlb.patch

6 years agofix FTBFS on i686
Dmitry Smirnov [Wed, 9 Oct 2019 08:09:07 +0000 (09:09 +0100)]
fix FTBFS on i686

Last-Update: 2018-06-16
Forwarded: https://github.com/opencontainers/runc/pull/1821
Bug-Upstream: https://github.com/opencontainers/runc/issues/941

src/github.com/opencontainers/runc/libcontainer/user/user_test.go:448:36: constant 2147483648 overflows int

Gbp-Pq: Name test--fix_TestGetAdditionalGroups.patch

6 years agorunc (1.0.0~rc9+dfsg1-1) unstable; urgency=medium
Dmitry Smirnov [Wed, 9 Oct 2019 08:09:07 +0000 (09:09 +0100)]
runc (1.0.0~rc9+dfsg1-1) unstable; urgency=medium

  * New upstream release.
    + fixed CVE-2019-16884.
  * Recommends += "criu" (Closes: #912821).
    Thanks, Qian Cai.
  * (Build-)Depends:
    = golang-github-docker-go-units-dev (>= 0.4.0~)
    = golang-github-opencontainers-selinux-dev (>= 1.3.0~)
    = golang-github-seccomp-libseccomp-golang-dev (>= 0.9.1~)
    = golang-gocapability-dev (>= 0.0+git20180916~)

[dgit import unpatched runc 1.0.0~rc9+dfsg1-1]

6 years agoImport runc_1.0.0~rc9+dfsg1-1.debian.tar.xz
Dmitry Smirnov [Wed, 9 Oct 2019 08:09:07 +0000 (09:09 +0100)]
Import runc_1.0.0~rc9+dfsg1-1.debian.tar.xz

[dgit import tarball runc 1.0.0~rc9+dfsg1-1 runc_1.0.0~rc9+dfsg1-1.debian.tar.xz]

6 years agoCVE-2019-5736
Shengjing Zhu [Sun, 10 Mar 2019 09:47:46 +0000 (17:47 +0800)]
CVE-2019-5736

Backport upstream patches for CVE-2019-5736

Include commits:
2d4a37b427167907ef2402586a8e8e2931a22490 nsenter: cloned_binary: userspace copy fallback if sendfile fails
16612d74de5f84977e50a9c8ead7f0e9e13b8628 nsenter: cloned_binary: try to ro-bind /proc/self/exe before copying
af9da0a45082783f6005b252488943b5ee2e2138 nsenter: cloned_binary: use the runc statedir for O_TMPFILE
2429d59352b81f6b9cc79b5ed26780c5fe6ba4ec nsenter: cloned_binary: expand and add pre-3.11 fallbacks
5b775bf297c47a6bc50e36da89d1ec74a6fa01dc nsenter: cloned_binary: detect and handle short copies
bb7d8b1f41f7bf0399204d54009d6da57c3cc775 nsexec (CVE-2019-5736): avoid parsing environ
0a8e4117e7f715d5fbeef398405813ce8e88558b nsenter: clone /proc/self/exe to avoid exposing host binary to container

Debian-Bug: https://bugs.debian.org/922050

Gbp-Pq: Name CVE-2019-5736.patch

6 years agodisable test (requires root)
Dmitry Smirnov [Sun, 10 Mar 2019 09:51:44 +0000 (09:51 +0000)]
disable test (requires root)

Last-Update: 2018-06-15
Forwarded: not-needed

Gbp-Pq: Name test--skip_TestFactoryNewTmpfs.patch

6 years agodisabled unreliable tests due to random failures on [ppc64el, s390x].
Dmitry Smirnov [Sun, 10 Mar 2019 09:51:44 +0000 (09:51 +0000)]
disabled unreliable tests due to random failures on [ppc64el, s390x].

Last-Update: 2018-09-27
Forwarded: not-needed
Bug-Upstream: https://github.com/opencontainers/runc/issues/1822

Gbp-Pq: Name test--skip-Hugetlb.patch

6 years agofix FTBFS on i686
Dmitry Smirnov [Sun, 10 Mar 2019 09:51:44 +0000 (09:51 +0000)]
fix FTBFS on i686

Last-Update: 2018-06-16
Forwarded: https://github.com/opencontainers/runc/pull/1821
Bug-Upstream: https://github.com/opencontainers/runc/issues/941

src/github.com/opencontainers/runc/libcontainer/user/user_test.go:448:36: constant 2147483648 overflows int

Gbp-Pq: Name test--fix_TestGetAdditionalGroups.patch

6 years agorunc (1.0.0~rc6+dfsg1-3) unstable; urgency=medium
Shengjing Zhu [Sun, 10 Mar 2019 09:51:44 +0000 (09:51 +0000)]
runc (1.0.0~rc6+dfsg1-3) unstable; urgency=medium

  * Team upload.

  [ Shengjing Zhu ]
  * Improve patch for CVE-2019-5736 based on upstream commits.
    Now the patch includes following commits:
    + 2d4a37b nsenter: cloned_binary: userspace copy fallback if sendfile fails
    + 16612d7 nsenter: cloned_binary: try to ro-bind /proc/self/exe before
              copying
    + af9da0a nsenter: cloned_binary: use the runc statedir for O_TMPFILE
    + 2429d59 nsenter: cloned_binary: expand and add pre-3.11 fallbacks
    + 5b775bf nsenter: cloned_binary: detect and handle short copies
    + bb7d8b1 nsexec (CVE-2019-5736): avoid parsing environ
    + 0a8e411 nsenter: clone /proc/self/exe to avoid exposing host binary to
              container

  [ Arnaud Rebillout ]
  * Add version and gitcommit to the ldflags (Closes: #909644)
    Note that we fill the git commit with something that is NOT a git commit
    at all, instead we use it as a placeholder for the debian version. The
    debian version is a relevant information for the user, and it's nice to
    be able to show it, some way or another.

[dgit import unpatched runc 1.0.0~rc6+dfsg1-3]

6 years agoImport runc_1.0.0~rc6+dfsg1-3.debian.tar.xz
Shengjing Zhu [Sun, 10 Mar 2019 09:51:44 +0000 (09:51 +0000)]
Import runc_1.0.0~rc6+dfsg1-3.debian.tar.xz

[dgit import tarball runc 1.0.0~rc6+dfsg1-3 runc_1.0.0~rc6+dfsg1-3.debian.tar.xz]

6 years agoImport runc_1.0.0~rc6+dfsg1.orig.tar.xz
Dmitry Smirnov [Thu, 24 Jan 2019 20:55:34 +0000 (20:55 +0000)]
Import runc_1.0.0~rc6+dfsg1.orig.tar.xz

[dgit import orig runc_1.0.0~rc6+dfsg1.orig.tar.xz]