[pull] main from containerd:main - #56
Merged
Merged
Conversation
Image config labels are copied onto the container by both the CRI plugin (BuildLabels) and the client's WithImageConfigLabels option used by `ctr run`. Labels in the containerd.io/* namespace are interpreted by containerd itself and labels in the io.cri-containerd* namespace are interpreted by the CRI plugin. An image config is not a trusted source for labels in either namespace. Skip labels in both reserved namespaces when copying labels from an image config to a container, and warn about each label skipped: an image that tries to set them may be attempting to alter containerd behavior. Oversized image labels are already skipped this way by the CRI plugin. Labels set explicitly by clients, for example via `ctr run --label` or in the CRI request, are unaffected. Verified with the CRI plugin and with `ctr run` against an image whose config carries labels like these: the labels are no longer present on the created container and a warning is logged for each. Assisted-by: Claude Code Signed-off-by: Ben Cressey <ben@cressey.org> Signed-off-by: Samuel Karp <samuelkarp@google.com>
awaitPipeReady retried only when DialPipe returned os.IsNotExist or context.DeadlineExceeded, but winio.DialPipe converts the per-attempt deadline into winio.ErrTimeout before returning. A pipe in state 1 (ListenPipe called, Accept not yet called) causes DialPipe to block for the full per-attempt timeout and return winio.ErrTimeout, which the old check treated as a fatal error instead of retrying. Also guard windows.ERROR_PIPE_BUSY explicitly to match the error checks in containerd/nerdbox#218. Adds a regression test that forces the state-1 to state-2 transition race by delaying Accept past the 1-second per-attempt timeout. Signed-off-by: Esteban Ginez <esteban.ginez@docker.com>
…ithub/codeql-action-4.36.2 build(deps): bump github/codeql-action from 4.36.0 to 4.36.2
Update to current setup-go version
go1.26.4 includes security fixes to the crypto/x509, mime, and net/textproto packages, as well as bug fixes to the compiler, the runtime, the go fix command, and the crypto/fips140 package Signed-off-by: Akhil Mohan <akhilerm@gmail.com>
update go to 1.26.4
Most content proxy operations normalize remote RPC errors before returning them, including stream receive errors from Walk and write errors from the remote writer. remoteReaderAt.ReadAt was an outlier and returned raw status errors from Read and Recv. Callers that use content.ReadBlob through the proxy can then fail errdefs checks, such as treating concurrent content deletion as NotFound. Convert non-EOF read stream errors with errgrpc.ToNative so ReaderAt matches the rest of the content proxy while preserving io.EOF. Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com>
Some proxy stream setup and receive paths still returned raw RPC status errors while neighboring proxy methods normalized them with errgrpc.ToNative. This made errdefs checks depend on which proxy API surfaced the same remote failure. Normalize event subscription setup and receive errors, and streaming stream creation errors, while preserving io.EOF for completed receive streams. Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com>
TestImagesCreateUpdateDelete asserts that an image's updatedat is strictly after its createdat. Both timestamps are stamped via time.Now().UTC(), which strips the monotonic reading, so the comparison falls back to the wall clock. On platforms with coarse timer resolution (e.g. Windows, which advances system time at the ~15.6ms tick), the Create and Update calls can land in the same tick and produce identical timestamps, making the strict After() check fail intermittently. Wait for the wall clock to advance past the creation timestamp before updating so the assertion stays meaningful without depending on clock resolution. On fine-resolution clocks the loop runs zero iterations. Signed-off-by: Austin Vazquez <austin.vazquez@docker.com>
Allow the last host to retry on transient network errors to incrase the likelihood of the operation succeeding and help reduce flaky tests. Signed-off-by: Derek McGowan <derek@mcg.dev>
release notes: https://github.com/opencontainers/runc/releases/tag/v1.4.3 full diff: opencontainers/runc@v1.4.2...v1.4.3 Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
resolver: retry on transient network errors
…g-x-b1834abdb7 build(deps): bump the golang-x group with 3 updates
golang.org/x/crypto v0.52.0 contains various security updates; those
do NOT impact containerd, but may show up as vulnerability in scanners;
=== Symbol Results ===
No vulnerabilities found.
=== Package Results ===
No other vulnerabilities found.
=== Module Results ===
Vulnerability #1: GO-2026-5033
Invoking pathological inputs can lead to client panic in
golang.org/x/crypto/ssh/agent
More info: https://pkg.go.dev/vuln/GO-2026-5033
Module: golang.org/x/crypto
Found in: golang.org/x/crypto@v0.51.0
Fixed in: golang.org/x/crypto@v0.52.0
Vulnerability #2: GO-2026-5023
Invoking VerifiedPublicKeyCallback permissions skip enforcement in
golang.org/x/crypto/ssh
More info: https://pkg.go.dev/vuln/GO-2026-5023
Module: golang.org/x/crypto
Found in: golang.org/x/crypto@v0.51.0
Fixed in: golang.org/x/crypto@v0.52.0
Vulnerability #3: GO-2026-5021
Invoking auth bypass via unenforced @Revoked status in
golang.org/x/crypto/ssh/knownhosts
More info: https://pkg.go.dev/vuln/GO-2026-5021
Module: golang.org/x/crypto
Found in: golang.org/x/crypto@v0.51.0
Fixed in: golang.org/x/crypto@v0.52.0
Vulnerability #4: GO-2026-5020
Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh
More info: https://pkg.go.dev/vuln/GO-2026-5020
Module: golang.org/x/crypto
Found in: golang.org/x/crypto@v0.51.0
Fixed in: golang.org/x/crypto@v0.52.0
Vulnerability #5: GO-2026-5019
Invoking bypass of FIDO/U2F security keys physical interaction in
golang.org/x/crypto/ssh
More info: https://pkg.go.dev/vuln/GO-2026-5019
Module: golang.org/x/crypto
Found in: golang.org/x/crypto@v0.51.0
Fixed in: golang.org/x/crypto@v0.52.0
Vulnerability #6: GO-2026-5018
Invoking pathological RSA/DSA parameters may cause DoS in
golang.org/x/crypto/ssh
More info: https://pkg.go.dev/vuln/GO-2026-5018
Module: golang.org/x/crypto
Found in: golang.org/x/crypto@v0.51.0
Fixed in: golang.org/x/crypto@v0.52.0
Vulnerability #7: GO-2026-5017
Invoking client can cause server deadlock on unexpected responses in
golang.org/x/crypto/ssh
More info: https://pkg.go.dev/vuln/GO-2026-5017
Module: golang.org/x/crypto
Found in: golang.org/x/crypto@v0.51.0
Fixed in: golang.org/x/crypto@v0.52.0
Vulnerability #8: GO-2026-5016
Invoking memory leak when rejecting channels can lead to DoS in
golang.org/x/crypto/ssh
More info: https://pkg.go.dev/vuln/GO-2026-5016
Module: golang.org/x/crypto
Found in: golang.org/x/crypto@v0.51.0
Fixed in: golang.org/x/crypto@v0.52.0
Vulnerability #9: GO-2026-5015
Invoking server panic during CheckHostKey/Authenticate in
golang.org/x/crypto/ssh
More info: https://pkg.go.dev/vuln/GO-2026-5015
Module: golang.org/x/crypto
Found in: golang.org/x/crypto@v0.51.0
Fixed in: golang.org/x/crypto@v0.52.0
Vulnerability #10: GO-2026-5014
Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh
More info: https://pkg.go.dev/vuln/GO-2026-5014
Module: golang.org/x/crypto
Found in: golang.org/x/crypto@v0.51.0
Fixed in: golang.org/x/crypto@v0.52.0
Vulnerability #11: GO-2026-5013
Invoking byte arithmetic causes underflow and panic in
golang.org/x/crypto/ssh
More info: https://pkg.go.dev/vuln/GO-2026-5013
Module: golang.org/x/crypto
Found in: golang.org/x/crypto@v0.51.0
Fixed in: golang.org/x/crypto@v0.52.0
Vulnerability #12: GO-2026-5006
Invoking agent constraints dropped when forwarding keys in
golang.org/x/crypto/ssh/agent
More info: https://pkg.go.dev/vuln/GO-2026-5006
Module: golang.org/x/crypto
Found in: golang.org/x/crypto@v0.51.0
Fixed in: golang.org/x/crypto@v0.52.0
Vulnerability #13: GO-2026-5005
Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent
More info: https://pkg.go.dev/vuln/GO-2026-5005
Module: golang.org/x/crypto
Found in: golang.org/x/crypto@v0.51.0
Fixed in: golang.org/x/crypto@v0.52.0
Your code is affected by 0 vulnerabilities.
This scan also found 0 vulnerabilities in packages you import and 13
vulnerabilities in modules you require, but your code doesn't appear to call
these vulnerabilities.
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
core/proxy: Convert stream proxy errors to native errdefs
Replace the stdlib compress/gzip decoder with klauspost's inflate. Also see #13559 Signed-off-by: Dr. Jan-Philip Gehrcke <jgehrcke@nvidia.com>
update runc binary to v1.4.3
The CRI checkpoint restore path unpacked checkpoint archive/OCI image content directly into the container's persistent state directory and read files such as container.log back from it with a symlink-following copy. Checkpoint content is externally provided, so make restore more defensive about what it unpacks and how it reads those files back. Behavior changes: - Only unpack regular files and directories from the checkpoint archive. - Unpack checkpoint content into a dedicated <state>/ctrd-restore subdirectory created fresh rather than into the state dir itself, so checkpoint content cannot collide with containerd's own files (e.g. the "status" blob). Restore and cleanup operate on that subdir; cleanup is now a single RemoveAll of it. Signed-off-by: Brian Goff <cpuguy83@gmail.com>
vendor: golang.org/x/crypto v0.53.0
…s-awaitpipeready-bails-on fix(shim/windows): retry on winio.ErrTimeout in awaitPipeReady
Signed-off-by: Maksym Pavlenko <pavlenko.maksym@gmail.com>
Signed-off-by: Maksym Pavlenko <pavlenko.maksym@gmail.com>
Signed-off-by: Maksym Pavlenko <pavlenko.maksym@gmail.com>
Signed-off-by: s3onghyun <s3onghyun.hong@gmail.com>
CRImportCheckpoint built the combined environment (image env followed by the CRI container env) into a local slice, then re-appended that slice to imageConfig.Env, duplicating every image environment variable on the restored container. Assign the combined slice directly instead. Fixes #13611 Signed-off-by: Aman Raj <aman.yug@gmail.com>
Use ScrubLogs by default on Windows
mounts() moved `first` to the merged fsmeta mount's index whenever mountFsMeta matched, collapsing the overlay's lowerdir range to the fsmeta alone and dropping any plain lowers already appended above it. When fsmerge was added, fsmeta was only ever written for the top parent of the chain being prepared, so the loop matched at i == 0, where first already equalled the fsmeta's index and the reassignment was a no-op. It only mattered once the fsmeta could sit below the top parent, i.e. a chain extending an already-merged sub-chain. The snapshotter no longer generates fsmeta itself, so today this only affects externally supplied fsmeta files. first only marks the start of the lowerdir range, so it must stay at the first lower's index. Signed-off-by: Derek McGowan <derek@mcg.dev>
The oomWatchers.Stop method stopped the watcher but never removed it from the watchers map. Because Add is the only writer and nothing ever deletes from the map, *watcher entries accumulated for the lifetime of the shim process. This resulted in an unbounded memory leak. Furthermore, this prevented the same container ID from ever being watched again if it was re-created, silently dropping OOM monitoring. This commit modifies Stop to delete(ows.watchers, cid), ensuring the watcher is released and the container ID is freed. Signed-off-by: Harshal Patel <106813066+HarshalPatel1972@users.noreply.github.com>
ci: dependabot: group docker/* and codeql action updates
Bumps [github.com/klauspost/compress](https://github.com/klauspost/compress) from 1.19.0 to 1.19.1. - [Release notes](https://github.com/klauspost/compress/releases) - [Commits](klauspost/compress@v1.19.0...v1.19.1) --- updated-dependencies: - dependency-name: github.com/klauspost/compress dependency-version: 1.19.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/containerd/imgcrypt/v2](https://github.com/containerd/imgcrypt) from 2.0.2 to 2.0.3. - [Release notes](https://github.com/containerd/imgcrypt/releases) - [Changelog](https://github.com/containerd/imgcrypt/blob/main/CHANGES) - [Commits](containerd/imgcrypt@v2.0.2...v2.0.3) --- updated-dependencies: - dependency-name: github.com/containerd/imgcrypt/v2 dependency-version: 2.0.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/prometheus/client_golang](https://github.com/prometheus/client_golang) from 1.23.2 to 1.24.0. - [Release notes](https://github.com/prometheus/client_golang/releases) - [Changelog](https://github.com/prometheus/client_golang/blob/v1.24.0/CHANGELOG.md) - [Commits](prometheus/client_golang@v1.23.2...v1.24.0) --- updated-dependencies: - dependency-name: github.com/prometheus/client_golang dependency-version: 1.24.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps the codeql-actions group with 3 updates: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/analyze](https://github.com/github/codeql-action) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action). Updates `github/codeql-action/init` from 4.36.2 to 4.37.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@8aad20d...e064762) Updates `github/codeql-action/analyze` from 4.36.2 to 4.37.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@8aad20d...e064762) Updates `github/codeql-action/upload-sarif` from 4.37.0 to 4.37.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@99df26d...e064762) --- updated-dependencies: - dependency-name: github/codeql-action/init dependency-version: 4.37.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: codeql-actions - dependency-name: github/codeql-action/analyze dependency-version: 4.37.2 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: codeql-actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.37.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: codeql-actions ... Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Derek McGowan <derek@mcg.dev>
…odeql-actions-d0435be077 build(deps): bump the codeql-actions group with 3 updates
Assisted-by: Antigravity Signed-off-by: Samuel Karp <samuelkarp@google.com>
…b.com/prometheus/client_golang-1.24.0 build(deps): bump github.com/prometheus/client_golang from 1.23.2 to 1.24.0
…b.com/klauspost/compress-1.19.1 build(deps): bump github.com/klauspost/compress from 1.19.0 to 1.19.1
internal/oom: Fix memory leak by removing watcher from map on Stop
cri: deprecate restore in CreateContainer
Exclude priority/*, status/accepted, status/needs-major-release, and status/roadmapped labels from being marked as stale and closed. Assisted-by: Antigravity Signed-off-by: Samuel Karp <samuelkarp@google.com>
workflows/stale: exempt priority and status labels
…b.com/containerd/imgcrypt/v2-2.0.3 build(deps): bump github.com/containerd/imgcrypt/v2 from 2.0.2 to 2.0.3
Remove support for restoring checkpoint data during CreateContainer, which was previously deprecated in v2.3. Assisted-by: Antigravity Signed-off-by: Samuel Karp <samuelkarp@google.com>
Add proof-of-concept (PoC) execution requirements against a running daemon to the triage guide and threat model. Assisted-by: Antigravity Signed-off-by: Samuel Karp <samuelkarp@google.com>
snapshots/erofs: keep lowers stacked above a merged fsmeta
docs/security: update security report triage criteria
integration: build the whiteout-test image locally
…t_restore cri: remove restore in CreateContainer
Prepare release notes for v2.4.0-beta.0
ctr resolves named users and groups for run and task exec in the client process. Since EROFS fsview support moved behind registration, the ctr application does not link the handler and falls back to a temporary host mount. Register the handler with the ctr application so EROFS snapshots can be inspected directly. Non-EROFS mounts continue through the existing handlers unchanged. Signed-off-by: Chris Ayoub <cayoub@openai.com>
ctr: register EROFS fsview
When collectContainerMetrics fails for a single container, the goroutine was returning nil which exited the loop entirely. The sandbox metrics, including pod-level network metrics and any successfully collected container metrics, were never appended to the response. Replace return nil with continue so that individual container failures only skip that container. Signed-off-by: Damien Grisonnet <dgrisonn@redhat.com>
cri: skip failed container instead of dropping entire sandbox metrics
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
See Commits and Changes for more details.
Created by
pull[bot]
Can you help keep this open source service alive? 💖 Please sponsor : )