Skip to content

Dockerfile: build runc 1.5 with libpathrs - #6908

Draft
AkihiroSuda wants to merge 3 commits into
moby:masterfrom
AkihiroSuda:runc-1.5
Draft

AkihiroSuda wants to merge 3 commits into
moby:masterfrom
AkihiroSuda:runc-1.5

Conversation

@AkihiroSuda

@AkihiroSuda AkihiroSuda commented Jun 29, 2026 •

Copy link
Copy Markdown
Member

runc 1.5 depends on libpathrs, so build and install it before compiling runc statically. This requires several adjustments for cross-compilation:

  • Install cargo/rust for the build (native) arch via apk; only the target libraries go through xx-apk, otherwise the toolchain cannot run.
  • Pass --rust-target to install.sh, since xx-cargo builds into target//release rather than target/release.
  • Install into the xx sysroot (DESTDIR) so xx's cross pkg-config finds pathrs.pc, and --disable-dynamic since the static build only needs the .a (Alpine's BusyBox install also lacks the -T flag used for the .so).

Comment thread Dockerfile Outdated
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
@github-actions github-actions Bot added the area/dependencies Pull requests that update a dependency file label Sep 7, 2026
Comment thread Dockerfile
# declares __fsword_t as u32 there while the fstatfs magic constants are u64.
# Build runc without libpathrs on s390x until that is fixed upstream.
if [ "$(xx-info arch)" = "s390x" ]; then
export RUNC_BUILDTAGS=-libpathrs

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread Dockerfile
# release, so sync the single affected file from the libpathrs checkout.
# Drop this once runc vendors go-pathrs v0.2.6 (opencontainers/runc#5449).
if grep -qx "# cyphar.com/go-pathrs v0.2.5" vendor/modules.txt; then
cp libpathrs/go-pathrs/internal/libpathrs/libpathrs_linux.go vendor/cyphar.com/go-pathrs/internal/libpathrs/

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AkihiroSuda and others added 2 commits September 8, 2026 16:05
The case differs depending on whether libpathrs is enabled in runc

Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
runc 1.5 depends on libpathrs, so build and install it before compiling
runc statically. This requires several adjustments for cross-compilation:

- Install cargo/rust for the build (native) arch via apk; only the target
  libraries go through xx-apk, otherwise the toolchain cannot run.
- Pass --rust-target to install.sh, since xx-cargo builds into
  target/<triple>/release rather than target/release.
- Install into the xx sysroot (DESTDIR) so xx's cross pkg-config finds
  pathrs.pc, and --disable-dynamic since the static build only needs the .a
  (Alpine's BusyBox install also lacks the -T flag used for the .so).
- Set RISCV64_TARGET_ARCH=riscv64 for the libpathrs build. Alpine's rustc
  knows riscv64-alpine-linux-musl, while xx-cargo defaults to the
  rustup-style riscv64gc-alpine-linux-musl, for which there is no target
  specification.
- Sync go-pathrs to v0.2.6 in runc's vendor tree. runc 1.5.1 vendors
  v0.2.5, which does not compile with clang: CGo resolves the
  PATHRS_PROC_* constants to unsigned values that overflow int64. Fixing
  that is the only change in v0.2.6, so copying the single affected file
  out of the libpathrs checkout is equivalent to the module bump. This can
  be dropped once runc vendors v0.2.6 (opencontainers/runc#5449). Note
  that patching the vendor tree makes runc report itself as -dirty.
- Skip libpathrs on s390x. rustix's linux_raw backend declares __fsword_t
  as u32 there while its fstatfs magic constants are u64, so libpathrs
  0.2.6 does not compile for s390x-musl at all.

Verified by building the runc stage for all six linux platforms.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/dependencies Pull requests that update a dependency file area/project area/testing area/worker

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant