[FFe] Import version 1.0-rc93

Bug #1919182 reported by Lucas Kanashiro
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
runc (Ubuntu)
Fix Released
Medium
Unassigned

Bug Description

This new upstream release contains an important fix to address LP #1916485. runc now has special handling for seccomp profiles to avoid making new syscalls unusable for glibc. Backporting this single fix would be painful because upstream also updated some of the vendorized deps in the same git commit:

https://github.com/opencontainers/runc/commit/7a8d7162f9d72f20d83eaa36aeb5426deecd58f2

To stay on the safe side and also bring in some improvements made by upstream, we decided the best way to fix this issue is importing this new release. Below you can fine the upstream release notes:

https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc93

And here the diff between version 1.0-rc92 which we already have in Hirsute and this new version:

https://github.com/opencontainers/runc/compare/v1.0.0-rc92...v1.0.0-rc93

I already have this package (almost) ready in this PPA:

https://launchpad.net/~lucaskanashiro/+archive/ubuntu/docker-20.10/+packages

And I can confirm it is working well along with containerd and docker.io in Hirsute. All the DEP-8 tests are passing and also my manual smoke tests, for instance basic features like pulling images from remote registries and running them locally, binding containers to some host port, and building your own image locally.

Revision history for this message
Iain Lane (laney) wrote :

Sounds good, thanks for confirming about the testing you've done. That's what I like to see.

Please go ahead.

Changed in runc (Ubuntu):
status: New → Confirmed
importance: Undecided → Medium
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package runc - 1.0.0~rc93-0ubuntu1

---------------
runc (1.0.0~rc93-0ubuntu1) hirsute; urgency=medium

  * New upstream release (LP: #1919182).
    - runc now has special handling for seccomp profiles to avoid making new
      syscalls unusable for glibc (LP: #1916485).
  * Remove patch addressing a bug fixed by upstream:
    - debian/patches/test--fix_TestGetAdditionalGroups.patch
  * Refresh patch:
    - debian/patches/test--skip-fs-related-cgroups-test.patch
  * Backport upstream patch to fix patchpbf test on armhf:
    - debian/patches/fix-patchpbf-test-on-32-bit.patch

 -- Lucas Kanashiro <email address hidden> Tue, 10 Mar 2021 09:30:36 -0300

Changed in runc (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.