[1.5] deps: update to libpathrs v0.2.6 - #5449
Merged
Merged
Conversation
cyphar
force-pushed
the
1.5-libpathrs-0.2.6
branch
from
September 7, 2026 04:11
2b77cb1 to
1853b52
Compare
AkihiroSuda
approved these changes
Sep 7, 2026
cyphar
force-pushed
the
1.5-libpathrs-0.2.6
branch
from
September 7, 2026 04:21
1853b52 to
18d498c
Compare
The primary change in this release for runc is that libpathrs's behaviour when the cached ProcfsHandle fd is closed from underneath it is now more graceful (previously this would cause panics on the error path). This is a bit of an unusual program state, but it is something we do in runc before we exec the user binary. Commit 1056e68 ("libct: don't reset selinux labels on init error path") eliminated one cause of such panics, but this should completely resolve the issue. It also includes some key fixes when building with Clang or when distributions re-generate the libpathrs <pathrs.h> header as part of their build process which go-pathrs then consumes. Signed-off-by: Aleksa Sarai <cyphar@cyphar.com> (cherry picked from commit 5456b42) Signed-off-by: Aleksa Sarai <cyphar@cyphar.com>
cyphar
marked this pull request as draft
September 7, 2026 04:21
cyphar
force-pushed
the
1.5-libpathrs-0.2.6
branch
from
September 7, 2026 04:21
18d498c to
c93d41b
Compare
AkihiroSuda
added a commit
to AkihiroSuda/buildkit_poc
that referenced
this pull request
Sep 8, 2026
runc 1.5 depends on libpathrs, so build and install it before compiling runc statically. This requires several adjustments for cross-compilation: - Install cargo/rust for the build (native) arch via apk; only the target libraries go through xx-apk, otherwise the toolchain cannot run. - Pass --rust-target to install.sh, since xx-cargo builds into target/<triple>/release rather than target/release. - Install into the xx sysroot (DESTDIR) so xx's cross pkg-config finds pathrs.pc, and --disable-dynamic since the static build only needs the .a (Alpine's BusyBox install also lacks the -T flag used for the .so). - Set RISCV64_TARGET_ARCH=riscv64 for the libpathrs build. Alpine's rustc knows riscv64-alpine-linux-musl, while xx-cargo defaults to the rustup-style riscv64gc-alpine-linux-musl, for which there is no target specification. - Sync go-pathrs to v0.2.6 in runc's vendor tree. runc 1.5.1 vendors v0.2.5, which does not compile with clang: CGo resolves the PATHRS_PROC_* constants to unsigned values that overflow int64. Fixing that is the only change in v0.2.6, so copying the single affected file out of the libpathrs checkout is equivalent to the module bump. This can be dropped once runc vendors v0.2.6 (opencontainers/runc#5449). Note that patching the vendor tree makes runc report itself as -dirty. - Skip libpathrs on s390x. rustix's linux_raw backend declares __fsword_t as u32 there while its fstatfs magic constants are u64, so libpathrs 0.2.6 does not compile for s390x-musl at all. Verified by building the runc stage for all six linux platforms. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
AkihiroSuda
added a commit
to AkihiroSuda/buildkit_poc
that referenced
this pull request
Sep 8, 2026
runc 1.5 depends on libpathrs, so build and install it before compiling runc statically. This requires several adjustments for cross-compilation: - Install cargo/rust for the build (native) arch via apk; only the target libraries go through xx-apk, otherwise the toolchain cannot run. - Pass --rust-target to install.sh, since xx-cargo builds into target/<triple>/release rather than target/release. - Install into the xx sysroot (DESTDIR) so xx's cross pkg-config finds pathrs.pc, and --disable-dynamic since the static build only needs the .a (Alpine's BusyBox install also lacks the -T flag used for the .so). - Set RISCV64_TARGET_ARCH=riscv64 for the libpathrs build. Alpine's rustc knows riscv64-alpine-linux-musl, while xx-cargo defaults to the rustup-style riscv64gc-alpine-linux-musl, for which there is no target specification. - Sync go-pathrs to v0.2.6 in runc's vendor tree. runc 1.5.1 vendors v0.2.5, which does not compile with clang: CGo resolves the PATHRS_PROC_* constants to unsigned values that overflow int64. Fixing that is the only change in v0.2.6, so copying the single affected file out of the libpathrs checkout is equivalent to the module bump. This can be dropped once runc vendors v0.2.6 (opencontainers/runc#5449). Note that patching the vendor tree makes runc report itself as -dirty. - Skip libpathrs on s390x. rustix's linux_raw backend declares __fsword_t as u32 there while its fstatfs magic constants are u64, so libpathrs 0.2.6 does not compile for s390x-musl at all. Verified by building the runc stage for all six linux platforms. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
AkihiroSuda
added a commit
to AkihiroSuda/buildkit_poc
that referenced
this pull request
Sep 8, 2026
runc 1.5 depends on libpathrs, so build and install it before compiling runc statically. This requires several adjustments for cross-compilation: - Install cargo/rust for the build (native) arch via apk; only the target libraries go through xx-apk, otherwise the toolchain cannot run. - Pass --rust-target to install.sh, since xx-cargo builds into target/<triple>/release rather than target/release. - Install into the xx sysroot (DESTDIR) so xx's cross pkg-config finds pathrs.pc, and --disable-dynamic since the static build only needs the .a (Alpine's BusyBox install also lacks the -T flag used for the .so). - Set RISCV64_TARGET_ARCH=riscv64 for the libpathrs build. Alpine's rustc knows riscv64-alpine-linux-musl, while xx-cargo defaults to the rustup-style riscv64gc-alpine-linux-musl, for which there is no target specification. - Sync go-pathrs to v0.2.6 in runc's vendor tree. runc 1.5.1 vendors v0.2.5, which does not compile with clang: CGo resolves the PATHRS_PROC_* constants to unsigned values that overflow int64. Fixing that is the only change in v0.2.6, so copying the single affected file out of the libpathrs checkout is equivalent to the module bump. This can be dropped once runc vendors v0.2.6 (opencontainers/runc#5449). Note that patching the vendor tree makes runc report itself as -dirty. - Skip libpathrs on s390x. rustix's linux_raw backend declares __fsword_t as u32 there while its fstatfs magic constants are u64, so libpathrs 0.2.6 does not compile for s390x-musl at all. Verified by building the runc stage for all six linux platforms. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
kolyshkin
approved these changes
Sep 8, 2026
Contributor
|
guess it's no longer a draft since #5448 is merged so marking as such and merging now |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backport of #5448
The primary change in this release for runc is that libpathrs's
behaviour when the cached ProcfsHandle fd is closed from underneath it
is now more graceful (previously this would cause panics on the error
path). This is a bit of an unusual program state, but it is something we
do in runc before we exec the user binary. Commit 1056e68 ("libct:
don't reset selinux labels on init error path") eliminated one cause of
such panics, but this should completely resolve the issue.
It also includes some key fixes when building with Clang or when
distributions re-generate the libpathrs <pathrs.h> header as part of
their build process which go-pathrs then consumes.
This independently fixes #5438.
Signed-off-by: Aleksa Sarai cyphar@cyphar.com