Skip to content

[1.5] deps: update to libpathrs v0.2.6 - #5449

Merged
kolyshkin merged 1 commit into
opencontainers:release-1.5from
cyphar:1.5-libpathrs-0.2.6
Sep 8, 2026
Merged

kolyshkin merged 1 commit into
opencontainers:release-1.5from
cyphar:1.5-libpathrs-0.2.6

Conversation

@cyphar

@cyphar cyphar commented Sep 7, 2026 •

Copy link
Copy Markdown
Member

Backport of #5448


The primary change in this release for runc is that libpathrs's
behaviour when the cached ProcfsHandle fd is closed from underneath it
is now more graceful (previously this would cause panics on the error
path). This is a bit of an unusual program state, but it is something we
do in runc before we exec the user binary. Commit 1056e68 ("libct:
don't reset selinux labels on init error path") eliminated one cause of
such panics, but this should completely resolve the issue.

It also includes some key fixes when building with Clang or when
distributions re-generate the libpathrs <pathrs.h> header as part of
their build process which go-pathrs then consumes.

This independently fixes #5438.

Signed-off-by: Aleksa Sarai cyphar@cyphar.com

@cyphar cyphar added this to the 1.5.2 milestone Sep 7, 2026
@cyphar cyphar added the backport/1.5-pr A backport PR to release-1.5 label Sep 7, 2026
@cyphar
cyphar force-pushed the 1.5-libpathrs-0.2.6 branch from 2b77cb1 to 1853b52 Compare September 7, 2026 04:11
@cyphar
cyphar force-pushed the 1.5-libpathrs-0.2.6 branch from 1853b52 to 18d498c Compare September 7, 2026 04:21
The primary change in this release for runc is that libpathrs's
behaviour when the cached ProcfsHandle fd is closed from underneath it
is now more graceful (previously this would cause panics on the error
path). This is a bit of an unusual program state, but it is something we
do in runc before we exec the user binary. Commit 1056e68 ("libct:
don't reset selinux labels on init error path") eliminated one cause of
such panics, but this should completely resolve the issue.

It also includes some key fixes when building with Clang or when
distributions re-generate the libpathrs <pathrs.h> header as part of
their build process which go-pathrs then consumes.

Signed-off-by: Aleksa Sarai <cyphar@cyphar.com>
(cherry picked from commit 5456b42)
Signed-off-by: Aleksa Sarai <cyphar@cyphar.com>
@cyphar
cyphar marked this pull request as draft September 7, 2026 04:21
@cyphar
cyphar force-pushed the 1.5-libpathrs-0.2.6 branch from 18d498c to c93d41b Compare September 7, 2026 04:21
AkihiroSuda added a commit to AkihiroSuda/buildkit_poc that referenced this pull request Sep 8, 2026
runc 1.5 depends on libpathrs, so build and install it before compiling
runc statically. This requires several adjustments for cross-compilation:

- Install cargo/rust for the build (native) arch via apk; only the target
  libraries go through xx-apk, otherwise the toolchain cannot run.
- Pass --rust-target to install.sh, since xx-cargo builds into
  target/<triple>/release rather than target/release.
- Install into the xx sysroot (DESTDIR) so xx's cross pkg-config finds
  pathrs.pc, and --disable-dynamic since the static build only needs the .a
  (Alpine's BusyBox install also lacks the -T flag used for the .so).
- Set RISCV64_TARGET_ARCH=riscv64 for the libpathrs build. Alpine's rustc
  knows riscv64-alpine-linux-musl, while xx-cargo defaults to the
  rustup-style riscv64gc-alpine-linux-musl, for which there is no target
  specification.
- Sync go-pathrs to v0.2.6 in runc's vendor tree. runc 1.5.1 vendors
  v0.2.5, which does not compile with clang: CGo resolves the
  PATHRS_PROC_* constants to unsigned values that overflow int64. Fixing
  that is the only change in v0.2.6, so copying the single affected file
  out of the libpathrs checkout is equivalent to the module bump. This can
  be dropped once runc vendors v0.2.6 (opencontainers/runc#5449). Note
  that patching the vendor tree makes runc report itself as -dirty.
- Skip libpathrs on s390x. rustix's linux_raw backend declares __fsword_t
  as u32 there while its fstatfs magic constants are u64, so libpathrs
  0.2.6 does not compile for s390x-musl at all.

Verified by building the runc stage for all six linux platforms.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
AkihiroSuda added a commit to AkihiroSuda/buildkit_poc that referenced this pull request Sep 8, 2026
runc 1.5 depends on libpathrs, so build and install it before compiling
runc statically. This requires several adjustments for cross-compilation:

- Install cargo/rust for the build (native) arch via apk; only the target
  libraries go through xx-apk, otherwise the toolchain cannot run.
- Pass --rust-target to install.sh, since xx-cargo builds into
  target/<triple>/release rather than target/release.
- Install into the xx sysroot (DESTDIR) so xx's cross pkg-config finds
  pathrs.pc, and --disable-dynamic since the static build only needs the .a
  (Alpine's BusyBox install also lacks the -T flag used for the .so).
- Set RISCV64_TARGET_ARCH=riscv64 for the libpathrs build. Alpine's rustc
  knows riscv64-alpine-linux-musl, while xx-cargo defaults to the
  rustup-style riscv64gc-alpine-linux-musl, for which there is no target
  specification.
- Sync go-pathrs to v0.2.6 in runc's vendor tree. runc 1.5.1 vendors
  v0.2.5, which does not compile with clang: CGo resolves the
  PATHRS_PROC_* constants to unsigned values that overflow int64. Fixing
  that is the only change in v0.2.6, so copying the single affected file
  out of the libpathrs checkout is equivalent to the module bump. This can
  be dropped once runc vendors v0.2.6 (opencontainers/runc#5449). Note
  that patching the vendor tree makes runc report itself as -dirty.
- Skip libpathrs on s390x. rustix's linux_raw backend declares __fsword_t
  as u32 there while its fstatfs magic constants are u64, so libpathrs
  0.2.6 does not compile for s390x-musl at all.

Verified by building the runc stage for all six linux platforms.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
AkihiroSuda added a commit to AkihiroSuda/buildkit_poc that referenced this pull request Sep 8, 2026
runc 1.5 depends on libpathrs, so build and install it before compiling
runc statically. This requires several adjustments for cross-compilation:

- Install cargo/rust for the build (native) arch via apk; only the target
  libraries go through xx-apk, otherwise the toolchain cannot run.
- Pass --rust-target to install.sh, since xx-cargo builds into
  target/<triple>/release rather than target/release.
- Install into the xx sysroot (DESTDIR) so xx's cross pkg-config finds
  pathrs.pc, and --disable-dynamic since the static build only needs the .a
  (Alpine's BusyBox install also lacks the -T flag used for the .so).
- Set RISCV64_TARGET_ARCH=riscv64 for the libpathrs build. Alpine's rustc
  knows riscv64-alpine-linux-musl, while xx-cargo defaults to the
  rustup-style riscv64gc-alpine-linux-musl, for which there is no target
  specification.
- Sync go-pathrs to v0.2.6 in runc's vendor tree. runc 1.5.1 vendors
  v0.2.5, which does not compile with clang: CGo resolves the
  PATHRS_PROC_* constants to unsigned values that overflow int64. Fixing
  that is the only change in v0.2.6, so copying the single affected file
  out of the libpathrs checkout is equivalent to the module bump. This can
  be dropped once runc vendors v0.2.6 (opencontainers/runc#5449). Note
  that patching the vendor tree makes runc report itself as -dirty.
- Skip libpathrs on s390x. rustix's linux_raw backend declares __fsword_t
  as u32 there while its fstatfs magic constants are u64, so libpathrs
  0.2.6 does not compile for s390x-musl at all.

Verified by building the runc stage for all six linux platforms.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
@kolyshkin

Copy link
Copy Markdown
Contributor

guess it's no longer a draft since #5448 is merged so marking as such and merging now

@kolyshkin
kolyshkin marked this pull request as ready for review September 8, 2026 18:07
@kolyshkin
kolyshkin merged commit 0901417 into opencontainers:release-1.5 Sep 8, 2026
56 checks passed
@cyphar
cyphar deleted the 1.5-libpathrs-0.2.6 branch September 9, 2026 08:52
@kolyshkin kolyshkin mentioned this pull request Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport/1.5-pr A backport PR to release-1.5

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants