Skip to content

Add container runtime specs for ACL validation - #81

Merged
Jiri Appl (jiria) merged 1 commit into
aclmainfrom
liunan/containerd_patch
Sep 24, 2026
Merged

Jiri Appl (jiria) merged 1 commit into
aclmainfrom
liunan/containerd_patch

Conversation

@liunan-ms

Copy link
Copy Markdown

Summary

Import containerd2 and runc RPM definitions for ACL builds, including the SELinux relabel fix, and register both packages in acl/packages.yaml.

Change Log

  • Import containerd2 and runc
  • Tolerate wrapped ENOTSUP errors from SELinux mount relabeling

Type of Change

  • Image build change (base image, sysexts, OEM images)
  • Package/SPEC update
  • CI/automation change
  • SDK/toolchain update
  • Configuration change
  • Documentation update
  • Bug fix

Does this affect the image build?

  • Yes
  • No

Associated Issues

Test Methodology

  • Test details:

Merge Checklist

All applicable boxes should be checked before merging

  • Image builds successfully with this change (or image build is not affected)
  • Any updated packages/SPECs build successfully
  • Relevant kola tests pass
  • All package sources are available
  • Source files have up-to-date hashes/manifests
  • Documentation has been updated to match any changes
  • Ready to merge

Import containerd2 and runc RPM definitions for ACL builds, including the SELinux relabel fix, and register both packages in acl/packages.yaml.
@liunan-ms
Nan Liu (liunan-ms) requested a review from a team as a code owner September 24, 2026 16:38
Copilot AI lite review requested due to automatic review settings September 24, 2026 16:38

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Fix the %check pipeline so go list ./... failures cannot be masked.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

Adds containerd2 and runc RPM definitions, runtime configuration, patches, signatures, and ACL package registration.

Changes:

  • Adds container runtime package specifications and source signatures.
  • Includes compatibility, snapshotter, cgroup, SELinux, and CVE patches.
  • Registers both packages in acl/packages.yaml.
  • Review finding: runc.spec may mask go list failures in %check.
File Description
acl/​SPECS/​runc/​runc.spec Defines the runc RPM build.
acl/​SPECS/​runc/​runc.signatures.json Verifies the runc source archive.
acl/​SPECS/​containerd2/​tardev-support.patch Adds containerd tar device support.
acl/​SPECS/​containerd2/​multi-snapshotters-support.patch Adds multi-snapshotter support.
acl/​SPECS/​containerd2/​fix-wrapped-enotsup-selinux-relabel.patch Handles wrapped SELinux relabel errors.
acl/​SPECS/​containerd2/​fix-TestCgroupNamespace-cgroupv1.patch Fixes the cgroup v1 namespace test.
acl/​SPECS/​containerd2/​CVE-2026-56852.patch Applies a containerd security fix.
acl/​SPECS/​containerd2/​CVE-2026-37236.patch Applies a containerd security fix.
acl/​SPECS/​containerd2/​containerd2.spec Defines the containerd2 RPM build.
acl/​SPECS/​containerd2/​containerd2.signatures.json Verifies containerd source archives.
acl/​SPECS/​containerd2/​containerd.toml Configures the container runtime.
acl/​SPECS/​containerd2/​containerd.service Provides the systemd service unit.
acl/​packages.yaml Registers containerd2 and runc for ACL builds.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread acl/SPECS/runc/runc.spec
@jiria
Jiri Appl (jiria) merged commit c2d4e9d into aclmain Sep 24, 2026
25 of 27 checks passed
@jiria
Jiri Appl (jiria) deleted the liunan/containerd_patch branch September 24, 2026 21:15

This branch was successfully deployed

1 active deployment
development — 87dbbc8f Deployed Sep 24, 2026 by liunan-ms via Check if we need to update the SDK #50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants