openeuler-ci-bot
839bcaf379
!373 [sync] PR-367: docker:fix CVE-2024-36623
...
From: @openeuler-sync-bot
Reviewed-by: @zhangsong234
Signed-off-by: @zhangsong234
2024-12-09 01:40:22 +00:00
zhongjiawei
a8c246882a
docker: fix CVE-2024-36623
...
(cherry picked from commit ee4cd41ad7780dce0066782c24a09b6673df10f8)
2024-12-06 14:50:25 +08:00
openeuler-ci-bot
27bf889df7
!365 [sync] PR-359: docker:fix missing lock in ensurelayer
...
From: @openeuler-sync-bot
Reviewed-by: @zhangsong234
Signed-off-by: @zhangsong234
2024-12-02 08:58:20 +00:00
zhongjiawei
f071dc8b46
docker:fix missing lock in ensurelayer
...
(cherry picked from commit 811fea11922b9da55ebd901c65d7fff82328cf36)
2024-12-02 16:03:44 +08:00
openeuler-ci-bot
d83c0c8c3d
!342 [sync] PR-337: docker:try to reconnect when containerd grpc return unexpected EOF
...
From: @openeuler-sync-bot
Reviewed-by: @zhangsong234
Signed-off-by: @zhangsong234
2024-08-31 09:01:11 +00:00
zhongjiawei
c0c85b6b52
docker:try to reconnect when containerd grpc return unexpected EOF
...
(cherry picked from commit bb19128a08aa2355d23555925a14a3733d173b64)
2024-08-31 11:43:24 +08:00
openeuler-ci-bot
cd8980480c
!334 [sync] PR-330: docker:add clone3 seccomp whitelist for arm64
...
From: @openeuler-sync-bot
Reviewed-by: @zhangsong234
Signed-off-by: @zhangsong234
2024-08-02 09:53:07 +00:00
zhongjiawei
23ae7fa8b1
docker:add clone3 seccomp whitelist for arm64
...
(cherry picked from commit 36446e9c94c779506c0d37b582a8b4330afeaaa1)
2024-08-02 17:31:13 +08:00
openeuler-ci-bot
0369f34a1b
!327 [sync] PR-323: docker:fix CVE-2024-41110
...
From: @openeuler-sync-bot
Reviewed-by: @zhangsong234
Signed-off-by: @zhangsong234
2024-07-27 01:30:09 +00:00
zhongjiawei
06987830bf
docker:fix CVE-2024-41110
...
(cherry picked from commit e6ebcc95f414d60dd04019b0deab87cb56760c7f)
2024-07-26 17:32:00 +08:00
openeuler-ci-bot
3ff5bfae95
!322 docker: Ignore SIGURG on Linux
...
From: @jackchan8
Reviewed-by: @zhangsong234
Signed-off-by: @zhangsong234
2024-07-16 01:34:21 +00:00
chenjiankun
97fea0296e
docker: Ignore SIGURG on Linux
...
fix #IA9T8K
2024-07-15 18:00:51 +08:00
openeuler-ci-bot
f3ac464a6e
!314 docker:modify runc rpm package name to runc
...
From: @zhong-jiawei-1
Reviewed-by: @zhangsong234
Signed-off-by: @zhangsong234
2024-06-14 06:24:01 +00:00
zhongjiawei
3fa184fafd
docker:modify runc rpm package name to runc
2024-06-13 16:34:54 +08:00
openeuler-ci-bot
630b06c475
!308 [sync] PR-303: backport: fix CVE-2024-32473
...
From: @openeuler-sync-bot
Reviewed-by: @zhangsong234
Signed-off-by: @zhangsong234
2024-05-08 13:13:07 +00:00
chenjiankun
99f5ab96c6
backport: fix CVE-2024-32473
...
fix #I9HX2H
(cherry picked from commit 29ff8159f389c51ebfe76fa3926ce722a65b7ba8)
2024-05-08 17:10:28 +08:00
openeuler-ci-bot
48894ea24f
!295 [sync] PR-294: docker: fix CVE-2024-29018
...
From: @openeuler-sync-bot
Reviewed-by: @zhangsong234
Signed-off-by: @zhangsong234
2024-04-12 11:32:33 +00:00
chenjiankun
d4dc011fd2
docker: fix CVE-2024-29018
...
fix #I9A82U
(cherry picked from commit 035844ebe4186c26e0da07fa35e52e968cde9836)
2024-04-12 17:05:37 +08:00
openeuler-ci-bot
4cb0d67c6e
!283 [sync] PR-281: backport: fix CVE-2024-24557
...
From: @openeuler-sync-bot
Reviewed-by: @zhangsong234
Signed-off-by: @zhangsong234
2024-03-19 11:29:41 +00:00
chenjiankun
af72c1a944
backport: fix CVE-2024-24557
...
fix #I90KVB
(cherry picked from commit 23c0890e05c6872627e34a03538443d7ef2dc6b1)
2024-03-19 17:25:23 +08:00
openeuler-ci-bot
51173e60bd
!277 [sync] PR-274: docker: sync patches from upstream
...
From: @openeuler-sync-bot
Reviewed-by: @zhangsong234
Signed-off-by: @zhangsong234
2024-01-09 06:22:34 +00:00
chenjiankun
c00617e26a
docker: sync patches from upstream
...
Sync patches from upstream, including:
b033961a82
2a8341f252
cae76642b6
f43f820a8c
b1d05350ec
7a24e475b3
f89fd3df7d
76e4260141
b92585a470
(cherry picked from commit 964354b6885aa28a3668ccab6cf0c458206df30b)
2024-01-08 15:46:01 +08:00
openeuler-ci-bot
b5f00e5985
!266 [sync] PR-262: docker:add delay after freeze
...
From: @openeuler-sync-bot
Reviewed-by: @duguhaotian
Signed-off-by: @duguhaotian
2023-10-12 12:33:37 +00:00
zhongjiawei
937754a249
docker:add delay after freeze
...
(cherry picked from commit 2e48b57e25c721804c926c73370c33d3e769bc94)
2023-10-12 17:19:29 +08:00
openeuler-ci-bot
b89d862077
!257 [sync] PR-255: docker: fix COPY --from should preserve ownership
...
From: @openeuler-sync-bot
Reviewed-by: @duguhaotian
Signed-off-by: @duguhaotian
2023-10-09 11:47:18 +00:00
Lu Jingxiao
0b26f41390
docker: fix COPY --from should preserve ownership
...
Fixes: #I86H6B
Signed-off-by: Lu Jingxiao <lujingxiao@huawei.com>
(cherry picked from commit 84fd54726a663f603700e4b565b065a62c268449)
2023-10-09 18:58:59 +08:00
openeuler-ci-bot
17fe0e8e71
!252 [sync] PR-249: 修复docker pull和restart dockerd并发操作,/var/lib/docker/devicemapper/mnt/目录资源残留问题
...
From: @openeuler-sync-bot
Reviewed-by: @duguhaotian
Signed-off-by: @duguhaotian
2023-08-29 02:51:53 +00:00
flyflyflypeng
1dceeb1c20
docker: remove useless mount point dir
...
fix #I7UQ2Y
Signed-off-by: flyflyflypeng <jiangpengfei9@huawei.com>
(cherry picked from commit e5190694496f1b5fccb7b70e982fdf3fadb6e3cb)
2023-08-28 15:14:00 +08:00
openeuler-ci-bot
b53043d34f
!240 docker: define a dummy hostname to use for local connections
...
From: @jackchan8
Reviewed-by: @duguhaotian
Signed-off-by: @duguhaotian
2023-08-03 02:26:30 +00:00
chenjiankun
cd7070aebb
docker: define a dummy hostname to use for local connections
...
For local communications (npipe://, unix://), the hostname is not used,
but we need valid and meaningful hostname.
The current code used the client's `addr` as hostname in some cases, which
could contain the path for the unix-socket (`/var/run/docker.sock`), which
gets rejected by go1.20.6 and go1.19.11 because of a security fix for
[CVE-2023-29406 ][1], which was implemented in https://go.dev/issue/60374 .
Prior versions go Go would clean the host header, and strip slashes in the
process, but go1.20.6 and go1.19.11 no longer do, and reject the host
header.
This patch introduces a `DummyHost` const, and uses this dummy host for
cases where we don't need an actual hostname.
2023-08-02 16:30:20 +08:00
openeuler-ci-bot
1b1985ecc6
!234 [sync] PR-233: docker: sync patches from master
...
From: @openeuler-sync-bot
Reviewed-by: @duguhaotian
Signed-off-by: @duguhaotian
2023-07-13 06:41:08 +00:00
chenjiankun
f69d70d2e2
docker: sync patches from master
...
(cherry picked from commit faa68fcbfa7bc543cdf70f004b82eed8431c7c77)
2023-07-13 11:26:08 +08:00
openeuler-ci-bot
1d0f48e769
!229 docker:remove invalid libcgroup dependencies
...
From: @zhong-jiawei-1
Reviewed-by: @zhangsong234, @duguhaotian
Signed-off-by: @duguhaotian
2023-07-12 04:00:06 +00:00
zhongjiawei
1beb1da2de
docker:remove invalid libcgroup dependencies
2023-07-12 11:39:01 +08:00
openeuler-ci-bot
d0e04590e6
!217 docker:thinpool full because docker daemon restart when docker pull
...
From: @zhong-jiawei-1
Reviewed-by: @zhangsong234, @duguhaotian
Signed-off-by: @duguhaotian
2023-06-09 04:01:58 +00:00
zhongjiawei
a4edd1edf4
docker:thinpool full because docker daemon restart when docker pull
2023-06-09 11:06:25 +08:00
openeuler-ci-bot
f366ec1425
!207 [sync] PR-205: docker:fix CVE-2023-28840 CVE-2023-28841 CVE-2023-28842
...
From: @openeuler-sync-bot
Reviewed-by: @zhangsong234, @duguhaotian
Signed-off-by: @duguhaotian
2023-04-06 12:31:54 +00:00
zhongjiawei
7a60984014
docker:fix CVE-2023-28840 CVE-2023-28841 CVE-2023-28842
...
(cherry picked from commit f021f5c385bf7dd11a892a128888f5998f754b24)
2023-04-06 20:00:21 +08:00
openeuler-ci-bot
2aa7dd8759
!200 [sync] PR-198: docker:backport upstream patches
...
From: @openeuler-sync-bot
Reviewed-by: @zhangsong234, @duguhaotian
Signed-off-by: @duguhaotian
2023-03-30 06:10:01 +00:00
zhongjiawei
cf3b5bbff6
docker:sync some patches
...
(cherry picked from commit 5004ebff5b6cd0eeff1a8edaf8f59dea0f348021)
2023-03-30 10:02:42 +08:00
openeuler-ci-bot
d6c7ceaf25
!189 [sync] PR-186: docker:try http for docker manifest insecure
...
From: @openeuler-sync-bot
Reviewed-by: @zhangsong234, @duguhaotian
Signed-off-by: @duguhaotian
2023-03-16 07:12:37 +00:00
zhongjiawei
9c2234772a
docker: try http for docker manifest insecure
...
(cherry picked from commit ff3bcc697b172784a8dacd637576cd932801399a)
2023-03-16 14:27:21 +08:00
openeuler-ci-bot
e3c5b359c0
!182 [sync] PR-181: docker: fix container missing after restarting dockerd twice
...
From: @openeuler-sync-bot
Reviewed-by: @duguhaotian
Signed-off-by: @duguhaotian
2023-03-15 02:51:07 +00:00
JackChan8
2f5e04a8aa
docker: fix container missing after restarting dockerd twice
...
fix #I6MJ4X
(cherry picked from commit 5ecf0ca3e74f004180222c8ec9ea3e240bf96d15)
2023-03-15 10:03:30 +08:00
openeuler-ci-bot
4eb3292100
!177 [sync] PR-176: docker stats: fix 'panic: close of closed channel'
...
From: @openeuler-sync-bot
Reviewed-by: @duguhaotian
Signed-off-by: @duguhaotian
2023-03-10 09:24:25 +00:00
Song Zhang
725d53a12b
docker stats: fix 'panic: close of closed channel'
...
bugfix: https://gitee.com/src-openeuler/docker/issues/I6LNNW?from=project-issue
Signed-off-by: Song Zhang <zhangsong34@huawei.com>
(cherry picked from commit 8ed0a65d0b666a1f05e3b9c2e0f906859a1c4acb)
2023-03-10 16:39:45 +08:00
openeuler-ci-bot
42eaf1976e
!172 [sync] PR-170: docker: set freezer.state to Thawed to increase freeze chances
...
From: @openeuler-sync-bot
Reviewed-by: @duguhaotian
Signed-off-by: @duguhaotian
2023-02-17 09:38:46 +00:00
chenjiankun
8eacb70a4e
docker: set freezer.state to Thawed to increase freeze chances
...
docker pause/unpause with parallel docker exec can lead to freezing
state, set freezer.state to Thawed to increase freeze chances
(cherry picked from commit b78a50c378d2ccef2254cf694991f4d52eec1fe9)
2023-02-17 16:52:06 +08:00
openeuler-ci-bot
6cac8f8bc6
!164 [sync] PR-160: docker:do not stop health check before sending signal
...
From: @openeuler-sync-bot
Reviewed-by: @duguhaotian
Signed-off-by: @duguhaotian
2022-12-01 12:29:18 +00:00
zhongjiawei
748628a918
docker:do not stop health check before sending signal
...
(cherry picked from commit 365eb0b1969d296e7e6894af9f913b3e24f81c21)
2022-12-01 16:28:49 +08:00