81 Commits

Author SHA1 Message Date
chenjiankun
cd7070aebb docker: define a dummy hostname to use for local connections
For local communications (npipe://, unix://), the hostname is not used,
but we need valid and meaningful hostname.

The current code used the client's `addr` as hostname in some cases, which
could contain the path for the unix-socket (`/var/run/docker.sock`), which
gets rejected by go1.20.6 and go1.19.11 because of a security fix for
[CVE-2023-29406 ][1], which was implemented in  https://go.dev/issue/60374.

Prior versions go Go would clean the host header, and strip slashes in the
process, but go1.20.6 and go1.19.11 no longer do, and reject the host
header.

This patch introduces a `DummyHost` const, and uses this dummy host for
cases where we don't need an actual hostname.
2023-08-02 16:30:20 +08:00
openeuler-ci-bot
1b1985ecc6
!234 [sync] PR-233: docker: sync patches from master
From: @openeuler-sync-bot 
Reviewed-by: @duguhaotian 
Signed-off-by: @duguhaotian
2023-07-13 06:41:08 +00:00
chenjiankun
f69d70d2e2 docker: sync patches from master
(cherry picked from commit faa68fcbfa7bc543cdf70f004b82eed8431c7c77)
2023-07-13 11:26:08 +08:00
openeuler-ci-bot
1d0f48e769
!229 docker:remove invalid libcgroup dependencies
From: @zhong-jiawei-1 
Reviewed-by: @zhangsong234, @duguhaotian 
Signed-off-by: @duguhaotian
2023-07-12 04:00:06 +00:00
zhongjiawei
1beb1da2de docker:remove invalid libcgroup dependencies 2023-07-12 11:39:01 +08:00
openeuler-ci-bot
d0e04590e6
!217 docker:thinpool full because docker daemon restart when docker pull
From: @zhong-jiawei-1 
Reviewed-by: @zhangsong234, @duguhaotian 
Signed-off-by: @duguhaotian
2023-06-09 04:01:58 +00:00
zhongjiawei
a4edd1edf4 docker:thinpool full because docker daemon restart when docker pull 2023-06-09 11:06:25 +08:00
openeuler-ci-bot
f366ec1425
!207 [sync] PR-205: docker:fix CVE-2023-28840 CVE-2023-28841 CVE-2023-28842
From: @openeuler-sync-bot 
Reviewed-by: @zhangsong234, @duguhaotian 
Signed-off-by: @duguhaotian
2023-04-06 12:31:54 +00:00
zhongjiawei
7a60984014 docker:fix CVE-2023-28840 CVE-2023-28841 CVE-2023-28842
(cherry picked from commit f021f5c385bf7dd11a892a128888f5998f754b24)
2023-04-06 20:00:21 +08:00
openeuler-ci-bot
2aa7dd8759
!200 [sync] PR-198: docker:backport upstream patches
From: @openeuler-sync-bot 
Reviewed-by: @zhangsong234, @duguhaotian 
Signed-off-by: @duguhaotian
2023-03-30 06:10:01 +00:00
zhongjiawei
cf3b5bbff6 docker:sync some patches
(cherry picked from commit 5004ebff5b6cd0eeff1a8edaf8f59dea0f348021)
2023-03-30 10:02:42 +08:00
openeuler-ci-bot
d6c7ceaf25
!189 [sync] PR-186: docker:try http for docker manifest insecure
From: @openeuler-sync-bot 
Reviewed-by: @zhangsong234, @duguhaotian 
Signed-off-by: @duguhaotian
2023-03-16 07:12:37 +00:00
zhongjiawei
9c2234772a docker: try http for docker manifest insecure
(cherry picked from commit ff3bcc697b172784a8dacd637576cd932801399a)
2023-03-16 14:27:21 +08:00
openeuler-ci-bot
e3c5b359c0
!182 [sync] PR-181: docker: fix container missing after restarting dockerd twice
From: @openeuler-sync-bot 
Reviewed-by: @duguhaotian 
Signed-off-by: @duguhaotian
2023-03-15 02:51:07 +00:00
JackChan8
2f5e04a8aa docker: fix container missing after restarting dockerd twice
fix #I6MJ4X

(cherry picked from commit 5ecf0ca3e74f004180222c8ec9ea3e240bf96d15)
2023-03-15 10:03:30 +08:00
openeuler-ci-bot
4eb3292100
!177 [sync] PR-176: docker stats: fix 'panic: close of closed channel'
From: @openeuler-sync-bot 
Reviewed-by: @duguhaotian 
Signed-off-by: @duguhaotian
2023-03-10 09:24:25 +00:00
Song Zhang
725d53a12b docker stats: fix 'panic: close of closed channel'
bugfix: https://gitee.com/src-openeuler/docker/issues/I6LNNW?from=project-issue

Signed-off-by: Song Zhang <zhangsong34@huawei.com>
(cherry picked from commit 8ed0a65d0b666a1f05e3b9c2e0f906859a1c4acb)
2023-03-10 16:39:45 +08:00
openeuler-ci-bot
42eaf1976e
!172 [sync] PR-170: docker: set freezer.state to Thawed to increase freeze chances
From: @openeuler-sync-bot 
Reviewed-by: @duguhaotian 
Signed-off-by: @duguhaotian
2023-02-17 09:38:46 +00:00
chenjiankun
8eacb70a4e docker: set freezer.state to Thawed to increase freeze chances
docker pause/unpause with parallel docker exec can lead to freezing
state, set freezer.state to Thawed to increase freeze chances

(cherry picked from commit b78a50c378d2ccef2254cf694991f4d52eec1fe9)
2023-02-17 16:52:06 +08:00
openeuler-ci-bot
6cac8f8bc6
!164 [sync] PR-160: docker:do not stop health check before sending signal
From: @openeuler-sync-bot 
Reviewed-by: @duguhaotian 
Signed-off-by: @duguhaotian
2022-12-01 12:29:18 +00:00
zhongjiawei
748628a918 docker:do not stop health check before sending signal
(cherry picked from commit 365eb0b1969d296e7e6894af9f913b3e24f81c21)
2022-12-01 16:28:49 +08:00
openeuler-ci-bot
4e8201a56d
!157 [sync] PR-154: docker: using VERSION-vendor to record version
From: @openeuler-sync-bot 
Reviewed-by: @duguhaotian 
Signed-off-by: @duguhaotian
2022-11-24 07:34:25 +00:00
chenjiankun
ec922e1fed docker: using VERSION-vendor to record version
(cherry picked from commit 3cc77fa02d5a0efb77b71d4f506b44f209329b1d)
2022-11-24 14:31:40 +08:00
openeuler-ci-bot
33724df909
!151 [sync] PR-148: docker: fix dockerd core when release network
From: @openeuler-sync-bot 
Reviewed-by: @duguhaotian 
Signed-off-by: @duguhaotian
2022-11-23 02:36:53 +00:00
chenjiankun
025a686650 docker: fix dockerd core when release network
fix #I627ON

(cherry picked from commit 07ce32f65f1a3d9d812fe0fbb0276353472c035d)
2022-11-22 20:40:56 +08:00
openeuler-ci-bot
b3ee12551d
!145 [sync] PR-142: docker: cleanup netns file when stop docker daemon
From: @openeuler-sync-bot 
Reviewed-by: @duguhaotian 
Signed-off-by: @duguhaotian
2022-11-22 12:37:25 +00:00
chenjiankun
6c95d358c2 docker: cleanup netns file when stop docker daemon
fix #I5W2XY

(cherry picked from commit 6a3861c8c1449da33e37ccbd0f8a9327394dff6b)
2022-11-22 16:36:27 +08:00
openeuler-ci-bot
dc16083004
!141 [sync] PR-139: docker: fix compile problem
From: @openeuler-sync-bot 
Reviewed-by: @duguhaotian 
Signed-off-by: @duguhaotian
2022-10-19 02:29:08 +00:00
chenjiankun
3adcb38631 docker: fix compile problem
(cherry picked from commit 0044b4982fe164af275802e9901040e9c588a2b2)
2022-10-19 09:56:49 +08:00
openeuler-ci-bot
5106a479a6
!135 [sync] PR-131: docker: add epoch for easy upgrade
From: @openeuler-sync-bot 
Reviewed-by: @duguhaotian 
Signed-off-by: @duguhaotian
2022-09-21 06:16:07 +00:00
chenjiankun
ffbd659b2d docker: add epoch for easy upgrade
(cherry picked from commit 7e4ff1bd426180bbdb05f55a57db9ec03034a257)
2022-09-21 11:29:00 +08:00
openeuler-ci-bot
37e7f70f10
!129 [sync] PR-125: docker: ensure layer digest folder removed if ls.driver.Remove fails
From: @openeuler-sync-bot 
Reviewed-by: @duguhaotian 
Signed-off-by: @duguhaotian
2022-09-16 06:51:20 +00:00
chenjiankun
d13823d8e0 docker: ensure layer digest folder removed if ls.driver.Remove fails
If image pull fails of context canceled, image layer will perform a
rollback operation. When image layer is released, the diff folder of layer
will be removed first, and then the digest folder will be removed.
If the diff folder fails to be removed, such as operation not permitted or
interrupted by others, both the digest folder and diff folder will remain
on the disk, this will cause image not be complete and not repairable.

So we should remove the digest folder first for image layers rollback
and ensure image can be re-pulled completely.

(cherry picked from commit 54c9d1260f3b7756794a8b8c13e0080831c29203)
2022-09-16 09:24:39 +08:00
openeuler-ci-bot
90947b1467
!123 docker: sync openEuler-22.03-LTS-Next with openEuler-22.03-LTS
From: @jackchan8 
Reviewed-by: @duguhaotian, @zhangsong234 
Signed-off-by: @duguhaotian
2022-09-15 08:44:58 +00:00
chenjiankun
7fed8d00d0 docker: sync openEuler-22.03-LTS-Next with openEuler-22.03-LTS 2022-09-15 16:58:10 +08:00
openeuler-ci-bot
e6a2315a4e !65 add GO111MODULE=off for build in golang 1.17.3
Merge pull request !65 from JackChan8/go_module_off
2021-12-28 08:28:51 +00:00
chenjiankun
d13f0e239e add GO111MODULE=off for build in golang 1.17.3 2021-12-28 10:23:13 +08:00
openeuler-ci-bot
d7b6ee7dd9 !59 docker:update seccomp whitelist to Linux 5.10 syscall list
From: @Vanient
Reviewed-by: 
Signed-off-by:
2021-09-27 02:06:06 +00:00
xiadanni
06a66dabde docker:update seccomp whitelist to Linux 5.10 syscall list
Signed-off-by: xiadanni <xiadanni1@huawei.com>
2021-09-26 05:49:25 +08:00
openeuler-ci-bot
8c7be812cf !56 docker:add clone3 to seccomp whitelist to fix curl failed in X86
From: @Vanient
Reviewed-by: @jianminw
Signed-off-by: @jianminw
2021-09-08 09:36:12 +00:00
xiadanni
7b18fd9382 docker:add clone3 to seccomp whitelist to fix curl failed in X86
After kernel upgrade to 5.10, clone3 is defined. But if clone3 is not
added to docker seccomp whitelist, clone3 calling will be rejected in
container, which causes some commands like curl returns error.

Signed-off-by: xiadanni <xiadanni1@huawei.com>
2021-09-08 13:00:11 +08:00
openeuler-ci-bot
704395add0 !55 Enable debuginfo
From: @jackchan8
Reviewed-by: @jing-rui,@duguhaotian
Signed-off-by: @duguhaotian
2021-09-06 08:36:33 +00:00
chenjiankun
6a44acb1d7 Enable debuginfo 2021-09-06 14:57:42 +08:00
openeuler-ci-bot
bf0cca49a9 !43 rollback if docker restart when doing BlkDiscard
From: @wangfengtu
Reviewed-by: @jing-rui,@caihaomin
Signed-off-by: @caihaomin
2021-04-02 14:03:37 +08:00
WangFengTu
82696f6e38 rollback if docker restart when doing BlkDiscard
Signed-off-by: WangFengTu <wangfengtu@huawei.com>
2021-04-01 16:25:19 +08:00
openeuler-ci-bot
41aa094cbe !38 docker:sync bugfix and fix CVE-2021-21284 2021-21285
From: @Vanient
Reviewed-by: @jing-rui,@caihaomin
Signed-off-by: @caihaomin
2021-03-19 11:18:09 +08:00
xiadanni
1bae2e5ea3 docker:sync bugfix and fix CVE-2021-21284 2021-21285
1.fix execCommands leak in health-check
2.check containerd pid before kill it
3.fix CVE-2021-21284
4.fix CVE-2021-21285

Change-Id: I2fe1dd40281f1786ecc63ff19d416b113710e611
Signed-off-by: xiadanni <xiadanni1@huawei.com>
2021-03-18 15:40:53 +08:00
openeuler-ci-bot
773302aeb3 !30 docker: remove go-md2man build require
From: @DCCooper
Reviewed-by: @jingxiaolu,@caihaomin
Signed-off-by: @caihaomin
2021-02-09 19:05:15 +08:00
DCCooper
0f204a4fd6 docker:remove go-md2man build require
Signed-off-by: DCCooper <1866858@gmail.com>
2021-02-09 18:51:03 +08:00
openeuler-ci-bot
791686bbfe !26 docker: sync bugfix
From: @jing-rui
Reviewed-by: @flyflyflypeng
Signed-off-by: @flyflyflypeng
2021-01-19 14:15:08 +08:00