diff --git a/acl/SPECS/containerd2/CVE-2026-37236.patch b/acl/SPECS/containerd2/CVE-2026-37236.patch new file mode 100644 index 00000000000..13fac36ef39 --- /dev/null +++ b/acl/SPECS/containerd2/CVE-2026-37236.patch @@ -0,0 +1,56 @@ +From aa41752dc2dee0ba84d5d521dc9db78120f2b777 Mon Sep 17 00:00:00 2001 +From: AllSpark +Date: Tue, 8 Sep 2026 16:42:52 +0000 +Subject: [PATCH] Add WithDisableHTTPMethodOverride ServeMux option + +Signed-off-by: Azure Linux Security Servicing Account +Upstream-reference: AI Backport of https://github.com/grpc-ecosystem/grpc-gateway/commit/72123cd4f32545f6e1376873f412dcdcbcf29acc.patch +--- + .../grpc-gateway/v2/runtime/mux.go | 16 +++++++++++++++- + 1 file changed, 15 insertions(+), 1 deletion(-) + +diff --git a/vendor/github.com/grpc-ecosystem/grpc-gateway/v2/runtime/mux.go b/vendor/github.com/grpc-ecosystem/grpc-gateway/v2/runtime/mux.go +index 19255ec..4b36cb0 100644 +--- a/vendor/github.com/grpc-ecosystem/grpc-gateway/v2/runtime/mux.go ++++ b/vendor/github.com/grpc-ecosystem/grpc-gateway/v2/runtime/mux.go +@@ -71,7 +71,8 @@ type ServeMux struct { + streamErrorHandler StreamErrorHandlerFunc + routingErrorHandler RoutingErrorHandlerFunc + disablePathLengthFallback bool ++ disableHTTPMethodOverride bool + unescapingMode UnescapingMode + writeContentLength bool + disableChunkedEncoding bool + } +@@ -259,6 +260,19 @@ func WithDisablePathLengthFallback() ServeMuxOption { + } + } + ++// WithDisableHTTPMethodOverride returns a ServeMuxOption that disables the ++// X-HTTP-Method-Override header handling. ++// ++// When this option is used, the mux will no longer allow POST requests with ++// the X-HTTP-Method-Override header to override the HTTP method. The path ++// length fallback (POST with application/x-www-form-urlencoded falling back ++// to a matching GET handler) is not affected by this option. ++func WithDisableHTTPMethodOverride() ServeMuxOption { ++ return func(serveMux *ServeMux) { ++ serveMux.disableHTTPMethodOverride = true ++ } ++} ++ + // WithWriteContentLength returns a ServeMuxOption to enable writing content length on non-streaming responses + func WithWriteContentLength() ServeMuxOption { + return func(serveMux *ServeMux) { +@@ -386,7 +400,7 @@ func (s *ServeMux) ServeHTTP(w http.ResponseWriter, r *http.Request) { + path = r.URL.RawPath + } + +- if override := r.Header.Get("X-HTTP-Method-Override"); override != "" && s.isPathLengthFallback(r) { ++ if override := r.Header.Get("X-HTTP-Method-Override"); override != "" && !s.disableHTTPMethodOverride && s.isPathLengthFallback(r) { + if err := r.ParseForm(); err != nil { + _, outboundMarshaler := MarshalerForRequest(s, r) + sterr := status.Error(codes.InvalidArgument, err.Error()) +-- +2.45.4 + diff --git a/acl/SPECS/containerd2/CVE-2026-56852.patch b/acl/SPECS/containerd2/CVE-2026-56852.patch new file mode 100644 index 00000000000..3c15faaa442 --- /dev/null +++ b/acl/SPECS/containerd2/CVE-2026-56852.patch @@ -0,0 +1,167 @@ +From 2a1a9cb1b8f98a13dd94f4165925ec862e8fd452 Mon Sep 17 00:00:00 2001 +From: Damien Neil +Date: Wed, 15 Apr 2026 01:46:24 +0000 +Subject: [PATCH] unicode/norm: avoid infinite loop on invalid input + +Upstream-reference: https://github.com/golang/text/commit/5ae8e578e495731553eddba11b2d0e86c91a00ce.patch +--- + .../x/text/unicode/norm/forminfo.go | 9 ++++++++- + vendor/golang.org/x/text/unicode/norm/iter.go | 8 ++------ + .../x/text/unicode/norm/normalize.go | 20 +++++++++---------- + 3 files changed, 20 insertions(+), 17 deletions(-) + +diff --git a/vendor/golang.org/x/text/unicode/norm/forminfo.go b/vendor/golang.org/x/text/unicode/norm/forminfo.go +index f3a234e..b3cf5d9 100644 +--- a/vendor/golang.org/x/text/unicode/norm/forminfo.go ++++ b/vendor/golang.org/x/text/unicode/norm/forminfo.go +@@ -121,8 +121,12 @@ func (p Properties) BoundaryAfter() bool { + // + // When all 6 bits are zero, the character is inert, meaning it is never + // influenced by normalization. ++// ++// We set flags to 0x80 (high bit 7 unused in quick check data) to indicate an invalid rune. + type qcInfo uint8 + ++func (p Properties) isInvalid() bool { return p.flags == 0x80 } ++ + func (p Properties) isYesC() bool { return p.flags&0x10 == 0 } + func (p Properties) isYesD() bool { return p.flags&0x4 == 0 } + +@@ -247,6 +251,9 @@ func (f Form) PropertiesString(s string) Properties { + // to a Properties. See the comment at the top of the file + // for more information on the format. + func compInfo(v uint16, sz int) Properties { ++ if sz == 0 { ++ return Properties{flags: 0x80, size: 1} ++ } + if v == 0 { + return Properties{size: uint8(sz)} + } else if v >= 0x8000 { +@@ -254,7 +261,7 @@ func compInfo(v uint16, sz int) Properties { + size: uint8(sz), + ccc: uint8(v), + tccc: uint8(v), +- flags: qcInfo(v >> 8), ++ flags: qcInfo(v>>8) & 0x3f, + } + if p.ccc > 0 || p.combinesBackward() { + p.nLead = uint8(p.flags & 0x3) +diff --git a/vendor/golang.org/x/text/unicode/norm/iter.go b/vendor/golang.org/x/text/unicode/norm/iter.go +index 417c6b2..3cc0592 100644 +--- a/vendor/golang.org/x/text/unicode/norm/iter.go ++++ b/vendor/golang.org/x/text/unicode/norm/iter.go +@@ -376,16 +376,12 @@ func nextComposed(i *Iter) []byte { + goto doNorm + } + prevCC = i.info.tccc +- sz := int(i.info.size) +- if sz == 0 { +- sz = 1 // illegal rune: copy byte-by-byte +- } +- p := outp + sz ++ p := outp + int(i.info.size) + if p > len(i.buf) { + break + } + outp = p +- i.p += sz ++ i.p += int(i.info.size) + if i.p >= i.rb.nsrc { + i.setDone() + break +diff --git a/vendor/golang.org/x/text/unicode/norm/normalize.go b/vendor/golang.org/x/text/unicode/norm/normalize.go +index 4747ad0..60b1511 100644 +--- a/vendor/golang.org/x/text/unicode/norm/normalize.go ++++ b/vendor/golang.org/x/text/unicode/norm/normalize.go +@@ -148,7 +148,7 @@ func (f Form) IsNormalString(s string) bool { + // patched buffer and whether the decomposition is still in progress. + func patchTail(rb *reorderBuffer) bool { + info, p := lastRuneStart(&rb.f, rb.out) +- if p == -1 || info.size == 0 { ++ if p == -1 || info.isInvalid() { + return true + } + end := p + int(info.size) +@@ -225,7 +225,7 @@ func doAppend(rb *reorderBuffer, out []byte, p int) []byte { + } + fd := &rb.f + if doMerge { +- var info Properties ++ info := Properties{flags: 0x80, size: 1} // invalid rune + if p < n { + info = fd.info(src, p) + if !info.BoundaryBefore() || info.nLeadingNonStarters() > 0 { +@@ -235,7 +235,7 @@ func doAppend(rb *reorderBuffer, out []byte, p int) []byte { + p = decomposeSegment(rb, p, true) + } + } +- if info.size == 0 { ++ if info.isInvalid() { + rb.doFlush() + // Append incomplete UTF-8 encoding. + return src.appendSlice(rb.out, p, n) +@@ -314,7 +314,7 @@ func (f *formInfo) quickSpan(src input, i, end int, atEOF bool) (n int, ok bool) + continue + } + info := f.info(src, i) +- if info.size == 0 { ++ if info.isInvalid() { + if atEOF { + // include incomplete runes + return n, true +@@ -379,7 +379,7 @@ func (f Form) firstBoundary(src input, nsrc int) int { + // CGJ insertion points correctly. Luckily it doesn't have to. + for { + info := fd.info(src, i) +- if info.size == 0 { ++ if info.isInvalid() { + return -1 + } + if s := ss.next(info); s != ssSuccess { +@@ -424,7 +424,7 @@ func (f Form) nextBoundary(src input, nsrc int, atEOF bool) int { + } + fd := formTable[f] + info := fd.info(src, 0) +- if info.size == 0 { ++ if info.isInvalid() { + if atEOF { + return 1 + } +@@ -435,7 +435,7 @@ func (f Form) nextBoundary(src input, nsrc int, atEOF bool) int { + + for i := int(info.size); i < nsrc; i += int(info.size) { + info = fd.info(src, i) +- if info.size == 0 { ++ if info.isInvalid() { + if atEOF { + return i + } +@@ -465,7 +465,7 @@ func lastBoundary(fd *formInfo, b []byte) int { + if p == -1 { + return -1 + } +- if info.size == 0 { // ends with incomplete rune ++ if info.isInvalid() { // ends with incomplete rune + if p == 0 { // starts with incomplete rune + return -1 + } +@@ -504,7 +504,7 @@ func lastBoundary(fd *formInfo, b []byte) int { + func decomposeSegment(rb *reorderBuffer, sp int, atEOF bool) int { + // Force one character to be consumed. + info := rb.f.info(rb.src, sp) +- if info.size == 0 { ++ if info.isInvalid() { + return 0 + } + if s := rb.ss.next(info); s == ssStarter { +@@ -528,7 +528,7 @@ func decomposeSegment(rb *reorderBuffer, sp int, atEOF bool) int { + break + } + info = rb.f.info(rb.src, sp) +- if info.size == 0 { ++ if info.isInvalid() { + if !atEOF { + return int(iShortSrc) + } +-- +2.52.0 diff --git a/acl/SPECS/containerd2/containerd.service b/acl/SPECS/containerd2/containerd.service new file mode 100644 index 00000000000..06b501178b9 --- /dev/null +++ b/acl/SPECS/containerd2/containerd.service @@ -0,0 +1,15 @@ +[Unit] +Description=containerd container runtime +Documentation=https://containerd.io +After=network.target + +[Service] +ExecStartPre=/sbin/modprobe overlay +ExecStart=/usr/bin/containerd +Restart=always +Delegate=yes +KillMode=process +OOMScoreAdjust=-999 + +[Install] +WantedBy=multi-user.target diff --git a/acl/SPECS/containerd2/containerd.toml b/acl/SPECS/containerd2/containerd.toml new file mode 100644 index 00000000000..422716a3c33 --- /dev/null +++ b/acl/SPECS/containerd2/containerd.toml @@ -0,0 +1,9 @@ +version = 2 +[plugins] + [plugins."io.containerd.grpc.v1.cri"] + [plugins."io.containerd.grpc.v1.cri".containerd] + [plugins."io.containerd.grpc.v1.cri".containerd.runtimes] + [plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc] + runtime_type = "io.containerd.runc.v2" + [plugins."io.containerd.grpc.v1.cri".containerd.runtimes.runc.options] + SystemdCgroup = true \ No newline at end of file diff --git a/acl/SPECS/containerd2/containerd2.signatures.json b/acl/SPECS/containerd2/containerd2.signatures.json new file mode 100644 index 00000000000..514830951fe --- /dev/null +++ b/acl/SPECS/containerd2/containerd2.signatures.json @@ -0,0 +1,7 @@ +{ + "Signatures": { + "containerd.service": "a07bfcf412669b06673190b0779f48e652c9adcf1758289e849a00802804eec8", + "containerd.toml": "5b3821236f09b4c858e0e098bbe1400f4dbbb47d360e39d21c61858b088c2896", + "containerd-2.3.4.tar.gz": "175bbf57d637c987fa742f846b43b1b8ba2c61af6a9eaec619c625e4a8a19b69" + } +} diff --git a/acl/SPECS/containerd2/containerd2.spec b/acl/SPECS/containerd2/containerd2.spec new file mode 100644 index 00000000000..f5c67c459ef --- /dev/null +++ b/acl/SPECS/containerd2/containerd2.spec @@ -0,0 +1,232 @@ +%global debug_package %{nil} +%define upstream_name containerd +%define commit_hash db8809540e1a7a9da5d518876894933ff55692ab + +Summary: Industry-standard container runtime +Name: %{upstream_name}2 +Version: 2.3.4 +Release: 2%{?dist} +License: ASL 2.0 +Group: Tools/Container +URL: https://www.containerd.io +Vendor: Microsoft Corporation +Distribution: Azure Linux + +Source0: https://github.com/containerd/containerd/archive/v%{version}.tar.gz#/%{upstream_name}-%{version}.tar.gz +Source1: containerd.service +Source2: containerd.toml + +Patch0: multi-snapshotters-support.patch +Patch1: tardev-support.patch +Patch2: fix-TestCgroupNamespace-cgroupv1.patch +Patch3: CVE-2026-56852.patch +Patch4: CVE-2026-37236.patch +Patch5: fix-wrapped-enotsup-selinux-relabel.patch + +%{?systemd_requires} + +# Temporarily stay on Go 1.26 until the Go 1.27 ML-KEM backend is fixed. +BuildRequires: (golang < 1.27 with golang >= 1.26.7) +BuildRequires: go-md2man +BuildRequires: make +BuildRequires: systemd-rpm-macros + +Requires: runc >= 1.2.2 + +# This package replaces the old name of containerd +Provides: containerd = %{version}-%{release} +Obsoletes: containerd < %{version}-%{release} + +# This package replaces the old name of moby-containerd +Provides: moby-containerd = %{version}-%{release} +Obsoletes: moby-containerd < %{version}-%{release} + +# This package replaces moby-containerd-cc +Provides: moby-containerd-cc = %{version}-%{release} +Obsoletes: moby-containerd-cc < %{version}-%{release} + +%description +containerd is an industry-standard container runtime with an emphasis on +simplicity, robustness and portability. It is available as a daemon for Linux +and Windows, which can manage the complete container lifecycle of its host +system: image transfer and storage, container execution and supervision, +low-level storage and network attachments, etc. + +containerd is designed to be embedded into a larger system, rather than being +used directly by developers or end-users. + +%prep +%autosetup -p1 -n %{upstream_name}-%{version} + +%build +export BUILDTAGS="-mod=vendor" +# Go 1.26 requires this experiment for cgo-less OpenSSL systemcrypto. +export GOEXPERIMENT=ms_nocgo_opensslcrypto +make VERSION="%{version}" REVISION="%{commit_hash}" binaries man + +%check +export BUILDTAGS="-mod=vendor" +export GOEXPERIMENT=ms_nocgo_opensslcrypto +make VERSION="%{version}" REVISION="%{commit_hash}" test + +%install +make VERSION="%{version}" REVISION="%{commit_hash}" DESTDIR="%{buildroot}" PREFIX="/usr" install install-man + +mkdir -p %{buildroot}/%{_unitdir} +install -D -p -m 0644 %{SOURCE1} %{buildroot}%{_unitdir}/containerd.service +install -D -p -m 0644 %{SOURCE2} %{buildroot}%{_sysconfdir}/containerd/config.toml +install -vdm 755 %{buildroot}/opt/containerd/{bin,lib} + +%post +%systemd_post containerd.service + +if [ $1 -eq 1 ]; then # Package install + systemctl enable containerd.service > /dev/null 2>&1 || : + systemctl start containerd.service > /dev/null 2>&1 || : +fi + +%preun +%systemd_preun containerd.service + +%postun +%systemd_postun_with_restart containerd.service + +%files +%license LICENSE NOTICE +%{_bindir}/* +%{_mandir}/* +%config(noreplace) %{_unitdir}/containerd.service +%config(noreplace) %{_sysconfdir}/containerd/config.toml +%dir /opt/containerd +%dir /opt/containerd/bin +%dir /opt/containerd/lib + +%changelog +* Fri Sep 18 2026 Nan Liu - 2.3.4-2 +- Tolerate wrapped ENOTSUP errors from SELinux mount relabeling + +* Wed Sep 09 2026 Nan Liu - 2.3.4-1 +- Upgrade to 2.3.4 +- Remove CVE patches fixed upstream +- Rebase multi-snapshotter support and CVE-2026-56852 patches + +* Tue Sep 08 2026 Azure Linux Security Servicing Account - 2.2.4-9 +- Patch for CVE-2026-37236 + +* Thu Sep 03 2026 Aadhar Agarwal - 2.2.4-8 +- Temporarily build with Microsoft Go 1.26 to avoid the Go 1.27 systemcrypto + ML-KEM panic on OpenSSL 3.3. +- Restore GOEXPERIMENT=ms_nocgo_opensslcrypto for the Go 1.26 cgo-less OpenSSL + backend. + +* Wed Sep 02 2026 Muhammad Falak R Wani - 2.2.4-7 +- Drop 'GOEXPERIMENT=ms_nocgo_opensslcrypto', removed in Go 1.27. Systemcrypto is + now selected automatically and supports CGO_ENABLED=0 on Linux. + +* Mon Jul 27 2026 Azure Linux Security Servicing Account - 2.2.4-6 +- Patch for CVE-2026-56852 + +* Thu Jul 09 2026 Aadhar Agarwal - 2.2.4-5 +- Remove 'BuildRequires: golang < 1.25' and set GOEXPERIMENT=ms_nocgo_opensslcrypto + to build with the default Go toolchain, resolving Go stdlib CVE-2026-25679, + CVE-2026-27139, CVE-2026-33811, CVE-2026-39836 (was built on Go 1.24.13). + +* Fri Jun 19 2026 Azure Linux Security Servicing Account - 2.2.4-4 +- Patch for CVE-2026-42502, CVE-2026-25681, CVE-2026-25680 + +* Tue Jun 16 2026 Henry Beberman - 2.2.4-3 +- Patch for CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262 + +* Sat May 30 2026 Jon Slobodzian - 2.2.4-2 +- Resolve merge from fasttrack, bring patches for CVE-2026-42506, CVE-2026-39821, CVE-2026-27136 forward to 2.2.4 version of containerd2. + +* Fri May 29 2026 Aadhar Agarwal - 2.2.4-1 +- Upgrade to 2.2.4 +- Pulls in CVE-2026-46680 fix (PR #13448 / 0a8f65bef) +- Remove CVE-2026-34986.patch (in v2.2.4: go-jose/v4 v4.1.4, PR #13292 / 4413816ce) +- Remove CVE-2026-35469.patch (in v2.2.3: spdystream v0.5.1 / 31bd34a06) +- Remove fix-credential-leak-in-cri-errors.patch (in v2.2.2: PR #12491 / cb3ae2119) +- Retain CVE-2026-39882.patch (otel v1.35.0 lacks PR #8108) +- Retain CVE-2026-33814.patch (x/net v0.47.0 lacks 1e71bd86e) +- Add fix-TestCgroupNamespace-cgroupv1.patch (PR #13240; allows %check on cgroup-v1 build hosts) +- Regenerate multi-snapshotters-support.patch against v2.2.4 (upstream absorbed runtimeHandler plumbing in v2.2.3) + +* Fri May 29 2026 Azure Linux Security Servicing Account - 2.1.6-5 +- Patch for CVE-2026-33814 + +* Thu May 28 2026 Azure Linux Security Servicing Account - 2.1.6-4 +- Patch for CVE-2026-39882 + +* Wed May 27 2026 Azure Linux Security Servicing Account - 2.1.6-3 +- Patch for CVE-2026-42506, CVE-2026-39821, CVE-2026-27136 + +* Fri Apr 24 2026 Jyoti Kanase - 2.1.6-2 +- Modify CVE-2026-35469 patch for 2.1.6 +- Patch for CVE-2026-34986 + +* Fri Apr 17 2026 Jyoti Kanase - 2.1.6-1 +- Upgrade to 2.1.6 +- Remove CVE patches fixed in upstream: CVE-2024-25621, CVE-2024-40635, + CVE-2024-45338, CVE-2025-22872, CVE-2025-27144, CVE-2025-47291, + CVE-2025-47911, CVE-2025-58190, CVE-2025-64329 +- Modify fix-credential-leak-in-cri-errors patch to keep only 2/2 not yet merged in upstream +- Rebase multi-snapshotters-support patch for 2.1.6 + +* Tue Apr 07 2026 Kanishk Bansal - 2.0.0-19 +- Patch CVE-2026-35469 + +* Thu Feb 12 2026 Azure Linux Security Servicing Account - 2.0.0-18 +- Patch for CVE-2025-58190, CVE-2025-47911 + +* Wed Jan 21 2026 Aadhar Agarwal - 2.0.0-17 +- Backport fix for credential leak in CRI error logs + +* Mon Nov 24 2025 Azure Linux Security Servicing Account - 2.0.0-16 +- Patch for CVE-2025-64329 + +* Tue Nov 11 2025 Azure Linux Security Servicing Account - 2.0.0-15 +- Patch for CVE-2024-25621 + +* Sun Aug 31 2025 Andrew Phelps - 2.0.0-14 +- Set BR for golang to < 1.25 + +* Mon Jul 21 2025 Saul Paredes - 2.0.0-13 +- Add "Provides/Obsoletes:" to shift all installs of moby-containerd-cc to containerd2 + +* Tue Jun 10 2025 Mitch Zhu - 2.0.0-12 +- Add updated tardev-snapshotter support patch + +* Tue Jun 10 2025 Mitch Zhu - 2.0.0-11 +- Add updated multi-snapshotters-support patch + +* Fri May 30 2025 Durga Jagadeesh Palli - 2.0.0-10 +- Patch CVE-2025-47291 + +* Thu May 22 2025 Aninda Pradhan - 2.0.0-9 +- Patch CVE-2025-22872 + +* Wed Apr 09 2025 Aadhar Agarwal - 2.0.0-8 +- Fix CVE-2024-40635 + +* Tue Apr 01 2025 Nan Liu - 2.0.0-7 +- Remove the tardev-snapshotter patch for Kata CC support. + +* Fri Mar 21 2025 Dallas Delaney - 2.0.0-6 +- Fix CVE-2025-27144 + +* Mon Mar 03 2025 Nan Liu - 2.0.0-5 +- Add "Provides/Obsoletes:" to shift all installs of containerd and moby-containerd to containerd2 + +* Mon Feb 03 2025 Mitch Zhu - 2.0.0-4 +- Fix ptest in tardev-snapshotter support patch + +* Sun Jan 26 2025 Mitch Zhu - 2.0.0-3 +- Added patch to support tardev-snapshotter for Kata CC. + +* Thu Jan 23 2025 Kavya Sree Kaitepalli - 2.0.0-2 +- Fix CVE-2024-45338 by an unstream patch + +* Wed Dec 11 2024 Nan Liu - 2.0.0-1 +- Created a standalone package for containerd 2.0.0 +- Initial CBL-Mariner import from Azure +- Initial version and License verified diff --git a/acl/SPECS/containerd2/fix-TestCgroupNamespace-cgroupv1.patch b/acl/SPECS/containerd2/fix-TestCgroupNamespace-cgroupv1.patch new file mode 100644 index 00000000000..17640b62ce6 --- /dev/null +++ b/acl/SPECS/containerd2/fix-TestCgroupNamespace-cgroupv1.patch @@ -0,0 +1,77 @@ +From 970b5d46bc30b5aafe16c4fbb245500f885cc9cd Mon Sep 17 00:00:00 2001 +From: Arjun Yogidas +Date: Thu, 16 Apr 2026 18:24:24 +0000 +Subject: [PATCH] Fix TestCgroupNamespace failure on cgroups v1 hosts + +Signed-off-by: Arjun Yogidas +--- + .../cri/server/container_create_linux_test.go | 31 +++++++++++++++++-- + 1 file changed, 28 insertions(+), 3 deletions(-) + +diff --git a/internal/cri/server/container_create_linux_test.go b/internal/cri/server/container_create_linux_test.go +index 8151be9a47c40..f376ee04535e2 100644 +--- a/internal/cri/server/container_create_linux_test.go ++++ b/internal/cri/server/container_create_linux_test.go +@@ -487,6 +487,8 @@ func TestPrivilegedBindMount(t *testing.T) { + } + } + ++// TestCgroupNamespace verifies that a cgroup namespace is only assigned to ++// non-privileged containers on cgroupv2 hosts. + func TestCgroupNamespace(t *testing.T) { + testPid := uint32(1234) + c := newTestCRIService() +@@ -498,27 +500,50 @@ func TestCgroupNamespace(t *testing.T) { + tests := []struct { + desc string + privileged bool ++ requireCgroupV2 bool + expectCgroupNamespace bool + }{ + { +- desc: "non-privileged container should get cgroup namespace", ++ desc: "cgroupv2: non-privileged container should get cgroup namespace", + privileged: false, ++ requireCgroupV2: true, + expectCgroupNamespace: true, + }, + { +- desc: "privileged container should not get cgroup namespace", ++ desc: "cgroupv2: privileged container should not get cgroup namespace", + privileged: true, ++ requireCgroupV2: true, ++ expectCgroupNamespace: false, ++ }, ++ { ++ desc: "cgroupv1: non-privileged container should not get cgroup namespace", ++ privileged: false, ++ requireCgroupV2: false, ++ expectCgroupNamespace: false, ++ }, ++ { ++ desc: "cgroupv1: privileged container should not get cgroup namespace", ++ privileged: true, ++ requireCgroupV2: false, + expectCgroupNamespace: false, + }, + } + + for _, tt := range tests { + t.Run(tt.desc, func(t *testing.T) { ++ // Skip if the host's cgroup mode doesn't match what the test case requires. ++ if tt.requireCgroupV2 && !isUnifiedCgroupsMode() { ++ t.Skip("requires cgroups v2") ++ } ++ if !tt.requireCgroupV2 && isUnifiedCgroupsMode() { ++ t.Skip("requires cgroups v1") ++ } ++ + containerConfig.Linux.SecurityContext.Privileged = tt.privileged + sandboxConfig.Linux.SecurityContext.Privileged = tt.privileged + + spec, err := c.buildContainerSpec(currentPlatform, t.Name(), testSandboxID, testPid, "", testContainerName, testImageName, containerConfig, sandboxConfig, imageConfig, nil, ociRuntime, nil) +- assert.NoError(t, err) ++ require.NoError(t, err) + + hasCgroupNS := false + for _, ns := range spec.Linux.Namespaces { diff --git a/acl/SPECS/containerd2/fix-wrapped-enotsup-selinux-relabel.patch b/acl/SPECS/containerd2/fix-wrapped-enotsup-selinux-relabel.patch new file mode 100644 index 00000000000..6d0efc47b95 --- /dev/null +++ b/acl/SPECS/containerd2/fix-wrapped-enotsup-selinux-relabel.patch @@ -0,0 +1,18 @@ +From: Nan Liu +Date: Fri, 18 Sep 2026 00:00:00 +0000 +Subject: [PATCH] cri: tolerate wrapped ENOTSUP from SELinux relabel + +label.Relabel can return a PathError wrapping ENOTSUP. Use errors.Is so the +existing unsupported-filesystem tolerance also handles wrapped errors. +--- + internal/cri/opts/spec_linux_opts.go | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/internal/cri/opts/spec_linux_opts.go b/internal/cri/opts/spec_linux_opts.go +--- a/internal/cri/opts/spec_linux_opts.go ++++ b/internal/cri/opts/spec_linux_opts.go +@@ -205,2 +205,2 @@ +- ENOTSUP := syscall.Errno(0x5f) // Linux specific error code, this branch will not execute on non Linux platforms. +- if err := label.Relabel(src, mountLabel, false); err != nil && err != ENOTSUP { ++ if err := label.Relabel(src, mountLabel, false); err != nil && ++ !errors.Is(err, syscall.ENOTSUP) { diff --git a/acl/SPECS/containerd2/multi-snapshotters-support.patch b/acl/SPECS/containerd2/multi-snapshotters-support.patch new file mode 100644 index 00000000000..51b48167b93 --- /dev/null +++ b/acl/SPECS/containerd2/multi-snapshotters-support.patch @@ -0,0 +1,222 @@ +From 52b80f75572e3f3aca08a1feac59e3a5f9cfe2c5 Mon Sep 17 00:00:00 2001 +From: Mitch Zhu +Date: Thu, 22 May 2025 23:55:57 +0000 +Subject: [PATCH] Add multi-snapshotter support + +Upstream v2.2.3+ already adopted the runtimeHandler parameter for +snapshotterFromPodSandboxConfig and the local snapshotter variable in +sandbox_run.go (with a different code path that resolves snapshotter via +RuntimeSnapshotter(ociRuntime)); the only Azure Linux additions retained +here are: + - Plumbing a snapshotter override through CRIImageService.PullImage so + sandbox_run can request an image be pulled into a specific snapshotter. + - The Snapshotters set on the in-memory Image so ensureImageExists can + avoid pulling when the image is already present in the desired + snapshotter. +--- + integration/image_pull_timeout_test.go | 6 +++--- + internal/cri/server/container_status_test.go | 2 +- + internal/cri/server/images/image_pull.go | 12 +++++++----- + internal/cri/server/sandbox_run.go | 12 +++++++----- + internal/cri/server/service.go | 2 +- + internal/cri/store/image/image.go | 29 ++++++++++++++++++++++------ + 6 files changed, 42 insertions(+), 21 deletions(-) + +diff --git a/integration/image_pull_timeout_test.go b/integration/image_pull_timeout_test.go +index fc90953..aa4d2ba 100644 +--- a/integration/image_pull_timeout_test.go ++++ b/integration/image_pull_timeout_test.go +@@ -93,7 +93,7 @@ func testCRIImagePullTimeoutBySlowCommitWriter(t *testing.T, useLocal bool) { + + ctx := namespaces.WithNamespace(logtest.WithT(context.Background(), t), k8sNamespace) + +- _, err = criService.PullImage(ctx, pullProgressTestImageName, nil, nil, "") ++ _, err = criService.PullImage(ctx, pullProgressTestImageName, nil, nil, "", "") + assert.NoError(t, err) + } + +@@ -220,7 +220,7 @@ func testCRIImagePullTimeoutByHoldingContentOpenWriter(t *testing.T, useLocal bo + go func() { + defer close(errCh) + +- _, err := criService.PullImage(ctx, pullProgressTestImageName, nil, nil, "") ++ _, err := criService.PullImage(ctx, pullProgressTestImageName, nil, nil, "", "") + errCh <- err + }() + +@@ -316,7 +316,7 @@ func testCRIImagePullTimeoutByNoDataTransferred(t *testing.T, useLocal bool) { + dctx, _, err := cli.WithLease(ctx) + assert.NoError(t, err) + +- _, err = criService.PullImage(dctx, fmt.Sprintf("%s/%s", mirrorURL.Host, "containerd/volume-ownership:2.1"), nil, nil, "") ++ _, err = criService.PullImage(dctx, fmt.Sprintf("%s/%s", mirrorURL.Host, "containerd/volume-ownership:2.1"), nil, nil, "", "") + + assert.Equal(t, context.Canceled, errors.Unwrap(err), "[%v] expected canceled error, but got (%v)", idx, err) + assert.True(t, mirrorSrv.limiter.clearHitCircuitBreaker(), "[%v] expected to hit circuit breaker", idx) +diff --git a/internal/cri/server/container_status_test.go b/internal/cri/server/container_status_test.go +index a35dda2..4824529 100644 +--- a/internal/cri/server/container_status_test.go ++++ b/internal/cri/server/container_status_test.go +@@ -388,7 +388,7 @@ func (s *fakeImageService) Config() criconfig.ImageConfig { + return criconfig.ImageConfig{} + } + +-func (s *fakeImageService) PullImage(context.Context, string, func(string) (string, string, error), *runtime.PodSandboxConfig, string) (string, error) { ++func (s *fakeImageService) PullImage(context.Context, string, func(string) (string, string, error), *runtime.PodSandboxConfig, string, string) (string, error) { + return "", errors.New("not implemented") + } + +diff --git a/internal/cri/server/images/image_pull.go b/internal/cri/server/images/image_pull.go +index 5889f6f..ec3cdf7 100644 +--- a/internal/cri/server/images/image_pull.go ++++ b/internal/cri/server/images/image_pull.go +@@ -113,14 +113,14 @@ func (c *GRPCCRIImageService) PullImage(ctx context.Context, r *runtime.PullImag + return ParseAuth(hostauth, host) + } + +- ref, err := c.CRIImageService.PullImage(ctx, imageRef, credentials, r.SandboxConfig, r.GetImage().GetRuntimeHandler()) ++ ref, err := c.CRIImageService.PullImage(ctx, imageRef, credentials, r.SandboxConfig, r.GetImage().GetRuntimeHandler(), "") + if err != nil { + return nil, err + } + return &runtime.PullImageResponse{ImageRef: ref}, nil + } + +-func (c *CRIImageService) PullImage(ctx context.Context, name string, credentials func(string) (string, string, error), sandboxConfig *runtime.PodSandboxConfig, runtimeHandler string) (_ string, err error) { ++func (c *CRIImageService) PullImage(ctx context.Context, name string, credentials func(string) (string, string, error), sandboxConfig *runtime.PodSandboxConfig, runtimeHandler, snapshotter string) (_ string, err error) { + span := tracing.SpanFromContext(ctx) + defer func() { + // TODO: add domain label for imagePulls metrics, and we may need to provide a mechanism +@@ -165,9 +165,11 @@ func (c *CRIImageService) PullImage(ctx context.Context, name string, credential + return "", fmt.Errorf("failed to parse image_pull_progress_timeout %q: %w", c.config.ImagePullProgressTimeout, err) + } + +- snapshotter, err := c.snapshotterFromPodSandboxConfig(ctx, ref, sandboxConfig, runtimeHandler) +- if err != nil { +- return "", err ++ if snapshotter == "" { ++ snapshotter, err = c.snapshotterFromPodSandboxConfig(ctx, ref, sandboxConfig, runtimeHandler) ++ if err != nil { ++ return "", err ++ } + } + + span.SetAttributes( +diff --git a/internal/cri/server/sandbox_run.go b/internal/cri/server/sandbox_run.go +index 8d3a12b..9d81a79 100644 +--- a/internal/cri/server/sandbox_run.go ++++ b/internal/cri/server/sandbox_run.go +@@ -292,7 +292,7 @@ func (c *criService) RunPodSandbox(ctx context.Context, r *runtime.RunPodSandbox + // containers anyway, the CRI layer will pre-pull the pause container to guarantee + // it exists (even though it's counter to the purpose of the sandbox API). This may + // be removed/deprecated in the distant future, if we decide to remove pause containers. +- if err := c.ensurePauseImageExists(ctx, r.GetConfig(), r.GetRuntimeHandler()); err != nil { ++ if err := c.ensurePauseImageExists(ctx, r.GetConfig(), r.GetRuntimeHandler(), c.ImageService.RuntimeSnapshotter(ctx, ociRuntime)); err != nil { + return nil, err + } + +@@ -406,7 +406,7 @@ func (c *criService) RunPodSandbox(ctx context.Context, r *runtime.RunPodSandbox + return &runtime.RunPodSandboxResponse{PodSandboxId: id}, nil + } + +-func (c *criService) ensurePauseImageExists(ctx context.Context, config *runtime.PodSandboxConfig, runtimeHandler string) error { ++func (c *criService) ensurePauseImageExists(ctx context.Context, config *runtime.PodSandboxConfig, runtimeHandler, snapshotter string) error { + imageConfig := c.ImageService.Config() + + ref := criconfig.DefaultSandboxImage +@@ -415,14 +415,16 @@ func (c *criService) ensurePauseImageExists(ctx context.Context, config *runtime + ref = img + } + +- _, err := c.ImageService.LocalResolve(ref) ++ image, err := c.ImageService.LocalResolve(ref) + if err == nil { +- return nil ++ if _, ok := image.Snapshotters[snapshotter]; ok || len(image.Snapshotters) == 0 { ++ return nil ++ } + } else if !errdefs.IsNotFound(err) { + return fmt.Errorf("failed to get image %q: %w", ref, err) + } + +- _, err = c.ImageService.PullImage(ctx, ref, nil, config, runtimeHandler) ++ _, err = c.ImageService.PullImage(ctx, ref, nil, config, runtimeHandler, snapshotter) + if err != nil { + return fmt.Errorf("failed to pull image %q: %w", ref, err) + } +diff --git a/internal/cri/server/service.go b/internal/cri/server/service.go +index ba462a5..f1ad127 100644 +--- a/internal/cri/server/service.go ++++ b/internal/cri/server/service.go +@@ -101,7 +101,7 @@ type RuntimeService interface { + type ImageService interface { + RuntimeSnapshotter(ctx context.Context, ociRuntime criconfig.Runtime) string + +- PullImage(ctx context.Context, name string, credentials func(string) (string, string, error), sandboxConfig *runtime.PodSandboxConfig, runtimeHandler string) (string, error) ++ PullImage(ctx context.Context, name string, credentials func(string) (string, string, error), sandboxConfig *runtime.PodSandboxConfig, runtimeHandler, snapshotter string) (string, error) + UpdateImage(ctx context.Context, r string) error + + CheckImages(ctx context.Context) error +diff --git a/internal/cri/store/image/image.go b/internal/cri/store/image/image.go +index 5d20c12..2773c92 100644 +--- a/internal/cri/store/image/image.go ++++ b/internal/cri/store/image/image.go +@@ -20,6 +20,7 @@ import ( + "context" + "encoding/json" + "fmt" ++ "strings" + "sync" + + "github.com/containerd/containerd/v2/core/content" +@@ -53,6 +54,8 @@ type Image struct { + ImageSpec imagespec.Image + // Pinned image to prevent it from garbage collection + Pinned bool ++ // Snapshotters is a map whose keys are snapshotters for which this image has a snapshot. ++ Snapshotters map[string]struct{} + } + + // Getter is used to get images but does not make changes +@@ -170,6 +173,19 @@ func (s *Store) getImage(ctx context.Context, i images.Image) (*Image, error) { + return nil, fmt.Errorf("read image config from content store: %w", err) + } + ++ info, err := s.provider.Info(ctx, desc.Digest) ++ if err != nil { ++ return nil, fmt.Errorf("get content store config info: %w", err) ++ } ++ ++ snapshotters := make(map[string]struct{}) ++ for label := range info.Labels { ++ const prefix = "containerd.io/gc.ref.snapshot." ++ if strings.HasPrefix(label, prefix) { ++ snapshotters[label[len(prefix):]] = struct{}{} ++ } ++ } ++ + var spec imagespec.Image + if err := json.Unmarshal(blob, &spec); err != nil { + return nil, fmt.Errorf("unmarshal image config %s: %w", blob, err) +@@ -178,12 +194,13 @@ func (s *Store) getImage(ctx context.Context, i images.Image) (*Image, error) { + pinned := i.Labels[labels.PinnedImageLabelKey] == labels.PinnedImageLabelValue + + return &Image{ +- ID: id, +- References: []string{i.Name}, +- ChainID: chainID.String(), +- Size: size, +- ImageSpec: spec, +- Pinned: pinned, ++ ID: id, ++ References: []string{i.Name}, ++ ChainID: chainID.String(), ++ Size: size, ++ ImageSpec: spec, ++ Pinned: pinned, ++ Snapshotters: snapshotters, + }, nil + + } +-- +2.52.0 diff --git a/acl/SPECS/containerd2/tardev-support.patch b/acl/SPECS/containerd2/tardev-support.patch new file mode 100644 index 00000000000..5ab03ccd53e --- /dev/null +++ b/acl/SPECS/containerd2/tardev-support.patch @@ -0,0 +1,38 @@ +From b11c8fadd114d1c75480fcfb600587351e1789bc Mon Sep 17 00:00:00 2001 +From: Mitch Zhu +Date: Tue, 27 May 2025 21:19:31 +0000 +Subject: [PATCH] tardev-snapshotter support patch + +--- + client/image.go | 8 +++++++- + 1 file changed, 7 insertions(+), 1 deletion(-) + +diff --git a/client/image.go b/client/image.go +index 355bcba..54b5890 100644 +--- a/client/image.go ++++ b/client/image.go +@@ -31,6 +31,7 @@ import ( + "github.com/containerd/containerd/v2/internal/kmutex" + "github.com/containerd/containerd/v2/pkg/labels" + "github.com/containerd/containerd/v2/pkg/rootfs" ++ "github.com/containerd/containerd/v2/pkg/snapshotters" + "github.com/containerd/errdefs" + "github.com/containerd/platforms" + "github.com/opencontainers/go-digest" +@@ -333,7 +334,12 @@ func (i *image) Unpack(ctx context.Context, snapshotterName string, opts ...Unpa + } + + for _, layer := range layers { +- unpacked, err = rootfs.ApplyLayerWithOpts(ctx, layer, chain, sn, a, config.SnapshotOpts, config.ApplyOpts) ++ snOpts := append(config.SnapshotOpts, snapshots.WithLabels(map[string]string{ ++ snapshotters.TargetLayerDigestLabel: layer.Blob.Digest.String(), ++ snapshotters.TargetManifestDigestLabel: i.Target().Digest.String(), ++ snapshotters.TargetRefLabel: i.Name(), ++ })) ++ unpacked, err = rootfs.ApplyLayerWithOpts(ctx, layer, chain, sn, a, snOpts, config.ApplyOpts) + if err != nil { + return fmt.Errorf("apply layer error for %q: %w", i.Name(), err) + } +-- +2.34.1 + diff --git a/acl/SPECS/runc/runc.signatures.json b/acl/SPECS/runc/runc.signatures.json new file mode 100644 index 00000000000..ef544cd957d --- /dev/null +++ b/acl/SPECS/runc/runc.signatures.json @@ -0,0 +1,5 @@ +{ + "Signatures": { + "runc-1.4.3.tar.gz": "e0a89f9e883ce93e740d14bb105b25c665f7d7beade4cfd0714fcafb38855d35" + } +} diff --git a/acl/SPECS/runc/runc.spec b/acl/SPECS/runc/runc.spec new file mode 100644 index 00000000000..9ffd73adb6f --- /dev/null +++ b/acl/SPECS/runc/runc.spec @@ -0,0 +1,166 @@ +%define commit_hash bb14dabeb7185bb72c8c86735d090dcb20f36587 +Summary: CLI tool for spawning and running containers per OCI spec. +Name: runc +# update "commit_hash" above when upgrading version +Version: 1.4.3 +Release: 1%{?dist} +License: ASL 2.0 +Vendor: Microsoft Corporation +Distribution: Azure Linux +Group: Tools/Container +URL: https://github.com/opencontainers/runc +Source0: https://github.com/opencontainers/runc/archive/v%{version}.tar.gz#/%{name}-%{version}.tar.gz +BuildRequires: git +BuildRequires: go-md2man +BuildRequires: golang < 1.25 +BuildRequires: libseccomp-devel +BuildRequires: make +Requires: glibc +Requires: libgcc +Requires: libseccomp +Provides: moby-runc = %{version}-%{release} + +%description +runc is a CLI tool for spawning and running containers according to the OCI specification. Containers are started as a child process of runC and can be embedded into various other systems without having to run a daemon. + +%prep +%autosetup -p1 -n runc-%{version} + +%build +export CGO_ENABLED=1 +make %{?_smp_mflags} BUILDTAGS="seccomp" COMMIT="%{commit_hash}" man runc + +%check +unshare -m --propagation unchanged sh <<'EOF' +if ! mountpoint -q /sys/fs/cgroup; then + if mount -t cgroup2 none /sys/fs/cgroup; then + trap 'umount -l /sys/fs/cgroup' EXIT + fi +fi +go test -tags "seccomp cgo" -timeout 10m \ + $(go list ./... | grep -vE '/libcontainer/(integration|nsenter)$') +EOF + +%install +make install DESTDIR=%{buildroot} PREFIX=%{_prefix} BINDIR=%{_bindir} +make install-man DESTDIR=%{buildroot} PREFIX=%{_prefix} + +%files +%license LICENSE NOTICE +%{_bindir}/runc +%{_mandir}/* + +%changelog +* Thu Sep 03 2026 Nan Liu - 1.4.3-1 +- Upgrade to 1.4.3 + +* Wed Jul 01 2026 CBL-Mariner Servicing Account - 1.3.6-1 +- Auto-upgrade to 1.3.6 - for CVE-2026-41579 + +* Fri May 15 2026 Sumit Jena - 1.3.3-2 +- Fixed ptests failure + +* Wed Nov 05 2025 Nan Liu - 1.3.3-1 +- Upgrade to 1.3.3 +- BR golang < 1.25 + +* Mon Nov 25 2024 Nan Liu - 1.2.2-1 +- Bump version to 1.2.2 +- Remove the golang version constraint + +* Tue Oct 15 2024 Muhammad Falak - 1.1.12-2 +- Pin golang version to <= 1.22 + +* Mon Feb 05 2024 Henry Beberman - 1.1.12-1 +- Bump version to 1.1.12 +- Drop cgroups cpuset patch because it's included upstream now +- Rename spec and package to runc instead of moby-runc + +* Mon Oct 16 2023 CBL-Mariner Servicing Account - 1.1.9-3 +- Bump release to rebuild with go 1.20.10 + +* Tue Oct 10 2023 Dan Streetman - 1.1.9-2 +- Bump release to rebuild with updated version of Go. + +* Tue Aug 15 2023 Muhammad Falak - 1.1.9-1 +- Bump version to 1.1.9 + +* Mon Aug 07 2023 CBL-Mariner Servicing Account - 1.1.5-4 +- Bump release to rebuild with go 1.19.12 + +* Thu Jul 13 2023 CBL-Mariner Servicing Account - 1.1.5-3 +- Bump release to rebuild with go 1.19.11 + +* Thu Jun 15 2023 CBL-Mariner Servicing Account - 1.1.5-2 +- Bump release to rebuild with go 1.19.10 + +* Mon Apr 10 2023 CBL-Mariner Servicing Account - 1.1.5-1 +- Auto-upgrade to 1.1.5 - to fix CVE-2023-28642, CVE-2023-27561, CVE-2023-25809 + +* Wed Apr 05 2023 CBL-Mariner Servicing Account - 1.1.2-11 +- Bump release to rebuild with go 1.19.8 + +* Tue Mar 28 2023 CBL-Mariner Servicing Account - 1.1.2-10 +- Bump release to rebuild with go 1.19.7 + +* Wed Mar 15 2023 CBL-Mariner Servicing Account - 1.1.2-9 +- Bump release to rebuild with go 1.19.6 + +* Fri Feb 03 2023 Vince Perri - 1.1.2-8 +- Add 0001-cgroups-cpuset-fix-byte-order-while-parsing-cpuset-r.patch + +* Fri Feb 03 2023 CBL-Mariner Servicing Account - 1.1.2-7 +- Bump release to rebuild with go 1.19.5 + +* Wed Jan 18 2023 CBL-Mariner Servicing Account - 1.1.2-6 +- Bump release to rebuild with go 1.19.4 + +* Fri Dec 16 2022 Daniel McIlvaney - 1.1.2-5 +- Bump release to rebuild with go 1.18.8 with patch for CVE-2022-41717 + +* Tue Nov 01 2022 Olivia Crain - 1.1.2-4 +- Bump release to rebuild with go 1.18.8 + +* Mon Aug 22 2022 Olivia Crain - 1.1.2-3 +- Bump release to rebuild against Go 1.18.5 + +* Tue Jun 14 2022 Muhammad Falak - 1.1.2-2 +- Bump release to rebuild with golang 1.18.3 + +* Thu Jun 02 2022 Nicolas Guibourge 1.1.2-1 +- Upgrade to 1.1.2 to fix CVE-2022-29162. + +* Fri Jan 28 2022 Nicolas Guibourge 1.1.0-1 +- Upgrade to 1.1.0. +- Use code from upstream instead of Azure fork. +- License verified. + +* Tue Jun 08 2021 Henry Beberman 1.0.0~rc95+azure-2 +- Increment release to force republishing using golang 1.15.13. + +* Wed May 19 2021 Andrew Phelps 1.0.0~rc95+azure-1 +- Update to version 1.0.0~rc95+azure to fix CVE-2021-30465 + +* Thu May 13 2021 Andrew Phelps 1.0.0~rc94+azure-1 +- Update to version 1.0.0~rc94+azure + +* Mon Apr 26 2021 Nicolas Guibourge 1.0.0~rc10+azure-6 +- Increment release to force republishing using golang 1.15.11. + +* Thu Dec 10 2020 Andrew Phelps 1.0.0~rc10+azure-5 +- Increment release to force republishing using golang 1.15. + +* Wed May 20 2020 Joe Schmitt 1.0.0~rc10+azure-4 +- Remove reliance on existing GOPATH environment variable. + +* Sat May 09 2020 Nick Samson 1.0.0~rc10+azure-3 +- Added %%license line automatically + +* Fri May 01 2020 Emre Girgin 1.0.0~rc10+azure-2 +- Renaming go to golang + +* Fri Apr 03 2020 Mohan Datla 1.0.0~rc10+azure-1 +- Initial CBL-Mariner import from Azure. + +* Thu Jan 23 2020 Brian Goff +- Initial version diff --git a/acl/packages.yaml b/acl/packages.yaml index bd6fb20543b..7729744cf71 100644 --- a/acl/packages.yaml +++ b/acl/packages.yaml @@ -29,5 +29,7 @@ packages: # --- ACL-patched system packages ---------------------------------------- - bootengine # Flatcar bootengine (glob-based firstboot addon removal for UAPI UKI naming) + - containerd2 # Pre-merge validation of Azure Linux container runtime changes - microcode_ctl # CPU microcode updater (Fedora import) + - runc # Pre-merge validation of Azure Linux container runtime changes - selinux-policy # SELinux reference policy (ACL-specific modules)