From patchwork Wed Feb 10 23:52:01 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Christian Stewart X-Patchwork-Id: 1439274 Return-Path: X-Original-To: incoming-buildroot@patchwork.ozlabs.org Delivered-To: patchwork-incoming-buildroot@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=busybox.net (client-ip=140.211.166.136; helo=smtp3.osuosl.org; envelope-from=buildroot-bounces@busybox.net; receiver=) Received: from smtp3.osuosl.org (smtp3.osuosl.org [140.211.166.136]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4Dbc4l6w4hz9s1l for ; Thu, 11 Feb 2021 10:52:23 +1100 (AEDT) Received: from localhost (localhost [127.0.0.1]) by smtp3.osuosl.org (Postfix) with ESMTP id 0877C6F5E3 for ; Wed, 10 Feb 2021 23:52:22 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from smtp3.osuosl.org ([127.0.0.1]) by localhost (smtp3.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EkiGfwIiL3SB for ; Wed, 10 Feb 2021 23:52:20 +0000 (UTC) Received: by smtp3.osuosl.org (Postfix, from userid 1001) id 485D46F664; Wed, 10 Feb 2021 23:52:20 +0000 (UTC) Received: from ash.osuosl.org (ash.osuosl.org [140.211.166.34]) by smtp3.osuosl.org (Postfix) with ESMTP id DD8DE6F511; Wed, 10 Feb 2021 23:52:11 +0000 (UTC) X-Original-To: buildroot@lists.busybox.net Delivered-To: buildroot@osuosl.org Received: from smtp3.osuosl.org (smtp3.osuosl.org [140.211.166.136]) by ash.osuosl.org (Postfix) with ESMTP id C383D1BF37B for ; Wed, 10 Feb 2021 23:52:09 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by smtp3.osuosl.org (Postfix) with ESMTP id BFDAC6F4D0 for ; Wed, 10 Feb 2021 23:52:09 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from smtp3.osuosl.org ([127.0.0.1]) by localhost (smtp3.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RccovnhIEw_q for ; Wed, 10 Feb 2021 23:52:09 +0000 (UTC) Received: by smtp3.osuosl.org (Postfix, from userid 1001) id 09D3C6F516; Wed, 10 Feb 2021 23:52:09 +0000 (UTC) X-Greylist: domain auto-whitelisted by SQLgrey-1.8.0 Received: from mail-pj1-f50.google.com (mail-pj1-f50.google.com [209.85.216.50]) by smtp3.osuosl.org (Postfix) with ESMTPS id 7BB996F4D0 for ; Wed, 10 Feb 2021 23:52:07 +0000 (UTC) Received: by mail-pj1-f50.google.com with SMTP id cv23so2112037pjb.5 for ; Wed, 10 Feb 2021 15:52:07 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=q9JnB8amvwgzFf6ww8tEpJEaSH3sqA+ezA9zmHdayeo=; b=YBKs7UxYI79donmSpBCsF1HcPEZHQL2t+WeKQRb3GjNeWZldxR+xWObdIzwnVbp/3r pfJHb5QyfL4PbgLtVYjeXollCuTcLVS83+FLsrngg+Q5ZsgRNlfdZ/LufyLm8wmyfG6q xHViPtEM/4FEbkTMOYeL9Pfty9vj2102fV0rZoVLWfD92s942qNyycgOygL5fNoaL6ns WelA11sMzMEJq5z5PHP1azDpYqxmi8uYYs6ebZIr/2uACNggMvThJol0KMlxhzXWFHkb oipUyxujm611TMaQfy0POZMq+dEI8ubalX8NrptbV/e4ABFvuTIG8OXoGl+MOO8Qk8Ok +wFw== X-Gm-Message-State: AOAM532A8iXvNHuYCRAjSH1Zvrd5SYi2kVW2QRuE39UTEOdUzNGu3wXh JXcE+nOku4l2blps5W6nG0ceX3kWpvPkNA== X-Google-Smtp-Source: ABdhPJyPR7TqkaDG/80T5gBD9/+AfZeUqAZATpkMslt8aUSGPlK4GNGwstsD4RJc62l6xti/lPdpAA== X-Received: by 2002:a17:902:ce83:b029:de:6b3c:fcd2 with SMTP id f3-20020a170902ce83b02900de6b3cfcd2mr5265664plg.67.1613001126655; Wed, 10 Feb 2021 15:52:06 -0800 (PST) Received: from localhost.localdomain (ip70-191-80-27.sb.sd.cox.net. [70.191.80.27]) by smtp.gmail.com with ESMTPSA id q196sm3536754pfc.162.2021.02.10.15.52.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 10 Feb 2021 15:52:06 -0800 (PST) From: Christian Stewart To: buildroot@buildroot.org Date: Wed, 10 Feb 2021 15:52:01 -0800 Message-Id: <20210210235203.2819535-1-christian@paral.in> X-Mailer: git-send-email 2.30.0 MIME-Version: 1.0 Subject: [Buildroot] [PATCH v1 1/3] package/runc: bump to version 1.0.0-rc93 X-BeenThere: buildroot@busybox.net X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussion and development of buildroot List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Michael Baudino , Christian Stewart , Anisse Astier , Thomas Petazzoni Errors-To: buildroot-bounces@busybox.net Sender: "buildroot" https://github.com/opencontainers/runc/releases/tag/v1.0.0-rc93 Signed-off-by: Christian Stewart --- package/runc/runc.hash | 2 +- package/runc/runc.mk | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/package/runc/runc.hash b/package/runc/runc.hash index d792947d5f..afe396368d 100644 --- a/package/runc/runc.hash +++ b/package/runc/runc.hash @@ -1,3 +1,3 @@ # Locally computed -sha256 28378df983a3c586ed3ec8c76a774a9b10f36a0c323590a284b801cce95cc61f runc-1.0.0-rc92.tar.gz +sha256 e42456078d2f76c925cdd656e4f423b918525d8188521de05e893b6bb473a6f8 runc-1.0.0-rc93.tar.gz sha256 552a739c3b25792263f731542238b92f6f8d07e9a488eae27e6c4690038a8243 LICENSE diff --git a/package/runc/runc.mk b/package/runc/runc.mk index c0de2783e4..ba2ab3081a 100644 --- a/package/runc/runc.mk +++ b/package/runc/runc.mk @@ -10,7 +10,7 @@ RUNC_LICENSE = Apache-2.0 RUNC_LICENSE_FILES = LICENSE RUNC_CPE_ID_VENDOR = linuxfoundation RUNC_CPE_ID_VERSION = 1.0.0 -RUNC_CPE_ID_UPDATE = rc92 +RUNC_CPE_ID_UPDATE = rc93 RUNC_LDFLAGS = -X main.version=$(RUNC_VERSION) RUNC_TAGS = cgo static_build From patchwork Wed Feb 10 23:52:02 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Christian Stewart X-Patchwork-Id: 1439273 Return-Path: X-Original-To: incoming-buildroot@patchwork.ozlabs.org Delivered-To: patchwork-incoming-buildroot@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=busybox.net (client-ip=140.211.166.138; helo=whitealder.osuosl.org; envelope-from=buildroot-bounces@busybox.net; receiver=) Received: from whitealder.osuosl.org (smtp1.osuosl.org [140.211.166.138]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4Dbc4f1q6tz9s1l for ; Thu, 11 Feb 2021 10:52:18 +1100 (AEDT) Received: from localhost (localhost [127.0.0.1]) by whitealder.osuosl.org (Postfix) with ESMTP id 096B687222; Wed, 10 Feb 2021 23:52:14 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from whitealder.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SR8JWgms782N; Wed, 10 Feb 2021 23:52:10 +0000 (UTC) Received: from ash.osuosl.org (ash.osuosl.org [140.211.166.34]) by whitealder.osuosl.org (Postfix) with ESMTP id B9F8A87221; Wed, 10 Feb 2021 23:52:10 +0000 (UTC) X-Original-To: buildroot@lists.busybox.net Delivered-To: buildroot@osuosl.org Received: from hemlock.osuosl.org (smtp2.osuosl.org [140.211.166.133]) by ash.osuosl.org (Postfix) with ESMTP id 07DF61BF37B for ; Wed, 10 Feb 2021 23:52:09 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by hemlock.osuosl.org (Postfix) with ESMTP id 04D6687514 for ; Wed, 10 Feb 2021 23:52:09 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from hemlock.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id p-0hRBjsrOlS for ; Wed, 10 Feb 2021 23:52:08 +0000 (UTC) X-Greylist: domain auto-whitelisted by SQLgrey-1.7.6 Received: from mail-pf1-f174.google.com (mail-pf1-f174.google.com [209.85.210.174]) by hemlock.osuosl.org (Postfix) with ESMTPS id 7B5E287462 for ; Wed, 10 Feb 2021 23:52:08 +0000 (UTC) Received: by mail-pf1-f174.google.com with SMTP id 18so2410062pfz.3 for ; Wed, 10 Feb 2021 15:52:08 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=6LBos3MwaoycMW4e3hPM8A6f4p9jPdsn2///oY3D9GQ=; b=tung5KVEK8tTmpOG3hmWybxWI8/DGvUzP3OSndcpXwLZuylvE88TlKDRchpl5a1xg5 mVm7oWbuDTcuWTSjoFO7Ak7JeIz9wN6kYkghZTBHz8xAB2k6l045dwfhgImu5jQ+8tMF uoTyRk83szTdWvYBUSkhY4ZT8OZ6UWBA7jm1sbb9ULa2REH3nykEJSTeVWO0r9InIpxk 2w4rib7x/OCpTPUqRwu5AKdrsrTf2z2jIxDFPB7evaNyc7WKmwWeZen4RifvjnrYlk+r zDi4Xd1hGa0PTZxu0wPfnNyI/YRIJEseipHAxKFE3KOA5owcYxQ5YIq9FLnpiSQRRHKB 5OSw== X-Gm-Message-State: AOAM531UKjy5NyPVJVW1SWde9WqFrewX6nag+iJbArcP/kcVNfbg949I 4ubH9o45ewcZX7z0XIszg3crbEE/wYoSnw== X-Google-Smtp-Source: ABdhPJyDM4JoyD1ddgCsAKzgbY6uusSnL+fEUTE+jA1odYyQpWnZOBS969Pq3ANaxSpGgUlz2E6FUA== X-Received: by 2002:a63:fe13:: with SMTP id p19mr5442386pgh.119.1613001127867; Wed, 10 Feb 2021 15:52:07 -0800 (PST) Received: from localhost.localdomain (ip70-191-80-27.sb.sd.cox.net. [70.191.80.27]) by smtp.gmail.com with ESMTPSA id q196sm3536754pfc.162.2021.02.10.15.52.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 10 Feb 2021 15:52:07 -0800 (PST) From: Christian Stewart To: buildroot@buildroot.org Date: Wed, 10 Feb 2021 15:52:02 -0800 Message-Id: <20210210235203.2819535-2-christian@paral.in> X-Mailer: git-send-email 2.30.0 In-Reply-To: <20210210235203.2819535-1-christian@paral.in> References: <20210210235203.2819535-1-christian@paral.in> MIME-Version: 1.0 Subject: [Buildroot] [PATCH v1 2/3] package/docker-engine: security bump to version 20.10.3 X-BeenThere: buildroot@busybox.net X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussion and development of buildroot List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Michael Baudino , Christian Stewart , Anisse Astier , Thomas Petazzoni Errors-To: buildroot-bounces@busybox.net Sender: "buildroot" Security fixes: - CVE-2021-21285 Prevent an invalid image from crashing docker daemon - CVE-2021-21284 Lock down file permissions to prevent remapped root from accessing docker state - Ensure AppArmor and SELinux profiles are applied when building with BuildKit Signed-off-by: Christian Stewart --- package/docker-engine/docker-engine.hash | 2 +- package/docker-engine/docker-engine.mk | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/package/docker-engine/docker-engine.hash b/package/docker-engine/docker-engine.hash index 2519ddaecd..69ebd113ea 100644 --- a/package/docker-engine/docker-engine.hash +++ b/package/docker-engine/docker-engine.hash @@ -1,3 +1,3 @@ # Locally calculated -sha256 f0fda46a82bf8f624eb349370358891d3bc65ef3e320675226f17dba8f62566d docker-engine-20.10.1.tar.gz +sha256 62bb03f197b8a064da568e62639f6834f91c8cfc9273126a978847becc214c31 docker-engine-20.10.3.tar.gz sha256 7c87873291f289713ac5df48b1f2010eb6963752bbd6b530416ab99fc37914a8 LICENSE diff --git a/package/docker-engine/docker-engine.mk b/package/docker-engine/docker-engine.mk index 058960119a..bbc97af8b5 100644 --- a/package/docker-engine/docker-engine.mk +++ b/package/docker-engine/docker-engine.mk @@ -4,7 +4,7 @@ # ################################################################################ -DOCKER_ENGINE_VERSION = 20.10.1 +DOCKER_ENGINE_VERSION = 20.10.3 DOCKER_ENGINE_SITE = $(call github,moby,moby,v$(DOCKER_ENGINE_VERSION)) DOCKER_ENGINE_LICENSE = Apache-2.0 From patchwork Wed Feb 10 23:52:03 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Christian Stewart X-Patchwork-Id: 1439275 Return-Path: X-Original-To: incoming-buildroot@patchwork.ozlabs.org Delivered-To: patchwork-incoming-buildroot@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=busybox.net (client-ip=140.211.166.137; helo=fraxinus.osuosl.org; envelope-from=buildroot-bounces@busybox.net; receiver=) Received: from fraxinus.osuosl.org (smtp4.osuosl.org [140.211.166.137]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4Dbc4t6ppNz9sS8 for ; Thu, 11 Feb 2021 10:52:30 +1100 (AEDT) Received: from localhost (localhost [127.0.0.1]) by fraxinus.osuosl.org (Postfix) with ESMTP id D9F2086ACC; Wed, 10 Feb 2021 23:52:28 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from fraxinus.osuosl.org ([127.0.0.1]) by localhost (.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id a8l_5gVb8Dqo; Wed, 10 Feb 2021 23:52:28 +0000 (UTC) Received: from ash.osuosl.org (ash.osuosl.org [140.211.166.34]) by fraxinus.osuosl.org (Postfix) with ESMTP id 54A8586C25; Wed, 10 Feb 2021 23:52:28 +0000 (UTC) X-Original-To: buildroot@lists.busybox.net Delivered-To: buildroot@osuosl.org Received: from smtp3.osuosl.org (smtp3.osuosl.org [140.211.166.136]) by ash.osuosl.org (Postfix) with ESMTP id 311801BF37B for ; Wed, 10 Feb 2021 23:52:14 +0000 (UTC) Received: from localhost (localhost [127.0.0.1]) by smtp3.osuosl.org (Postfix) with ESMTP id 252916F54B for ; Wed, 10 Feb 2021 23:52:14 +0000 (UTC) X-Virus-Scanned: amavisd-new at osuosl.org Received: from smtp3.osuosl.org ([127.0.0.1]) by localhost (smtp3.osuosl.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0kOdPCHuhjRI for ; Wed, 10 Feb 2021 23:52:13 +0000 (UTC) Received: by smtp3.osuosl.org (Postfix, from userid 1001) id 3415E6F516; Wed, 10 Feb 2021 23:52:13 +0000 (UTC) X-Greylist: domain auto-whitelisted by SQLgrey-1.8.0 Received: from mail-pg1-f180.google.com (mail-pg1-f180.google.com [209.85.215.180]) by smtp3.osuosl.org (Postfix) with ESMTPS id 1B1466F516 for ; Wed, 10 Feb 2021 23:52:12 +0000 (UTC) Received: by mail-pg1-f180.google.com with SMTP id t25so2369418pga.2 for ; Wed, 10 Feb 2021 15:52:12 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=x+y4h7AhcGIMzaYNk38Oq0oofe0ITuTeWYA9aOCQ/8A=; b=HcPDnijZpfuP3vdipTlrkvNadttq6UxsI13ZDLe6+EQ5YdNfFF5mZscCfyuUN6KaIR w5fLbBC9Kp4yyeB27vlGTLAtYLT0DFLr6/DMuS7+hqe18Hgr+eOxZZzdHUxzjwnAMLRF G1X9TvEVmFBkN/SCoBQNVGAOjUlSWyEneH+ohFgaox8B1sJxXjxxcspUnmQwWi2+HSGV Htcdf8AeuK8zUDrT3ql1IY+FGponx3hUx085fBa/kaDFRt9DAKh2cGiAXfbBKZ4y4H6X gLDUbJNjdMYHhW+PUDt459OjvYBTCsubaGeaV7czdutFRt+ReYDdsFJ7ZgMABlp7o8wb ht1w== X-Gm-Message-State: AOAM5320+qgW5c6Q1FJ6G6nzodZf3iGH9WMEE4RTPstUboly023UDvel wtafF8QwoxPvcCNOlGM1xDrcbPVOf0WipQ== X-Google-Smtp-Source: ABdhPJwWe7YvJJLnHOzjD4BhX/2Wb8Xur85WGdVvC6BnwVVHucs/8S8/JheQkTM0IYqs/OLmmvJDeQ== X-Received: by 2002:a65:50c3:: with SMTP id s3mr5235316pgp.269.1613001131374; Wed, 10 Feb 2021 15:52:11 -0800 (PST) Received: from localhost.localdomain (ip70-191-80-27.sb.sd.cox.net. [70.191.80.27]) by smtp.gmail.com with ESMTPSA id q196sm3536754pfc.162.2021.02.10.15.52.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 10 Feb 2021 15:52:11 -0800 (PST) From: Christian Stewart To: buildroot@buildroot.org Date: Wed, 10 Feb 2021 15:52:03 -0800 Message-Id: <20210210235203.2819535-3-christian@paral.in> X-Mailer: git-send-email 2.30.0 In-Reply-To: <20210210235203.2819535-1-christian@paral.in> References: <20210210235203.2819535-1-christian@paral.in> MIME-Version: 1.0 Subject: [Buildroot] [PATCH v1 3/3] package/docker-cli: bump to version 20.10.3 X-BeenThere: buildroot@busybox.net X-Mailman-Version: 2.1.29 Precedence: list List-Id: Discussion and development of buildroot List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Michael Baudino , Christian Stewart , Anisse Astier , Thomas Petazzoni Errors-To: buildroot-bounces@busybox.net Sender: "buildroot" Client fixes: - Check contexts before importing them to reduce risk of extracted files escaping context store Signed-off-by: Christian Stewart --- package/docker-cli/docker-cli.hash | 2 +- package/docker-cli/docker-cli.mk | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/package/docker-cli/docker-cli.hash b/package/docker-cli/docker-cli.hash index cf5e80825f..95b15b539b 100644 --- a/package/docker-cli/docker-cli.hash +++ b/package/docker-cli/docker-cli.hash @@ -1,3 +1,3 @@ # Locally calculated -sha256 4ee7cc9c3f6287ca834166aaa1a945790c54d9a8345a1b449a193d9c739f2a7d docker-cli-20.10.1.tar.gz +sha256 aafba3765d9013cb75810b4f4334525f0e74e82ef073b4df9e8b524f3794e60a docker-cli-20.10.3.tar.gz sha256 2d81ea060825006fc8f3fe28aa5dc0ffeb80faf325b612c955229157b8c10dc0 LICENSE diff --git a/package/docker-cli/docker-cli.mk b/package/docker-cli/docker-cli.mk index 0d1ec02ad7..d90c3b7d10 100644 --- a/package/docker-cli/docker-cli.mk +++ b/package/docker-cli/docker-cli.mk @@ -4,7 +4,7 @@ # ################################################################################ -DOCKER_CLI_VERSION = 20.10.1 +DOCKER_CLI_VERSION = 20.10.3 DOCKER_CLI_SITE = $(call github,docker,cli,v$(DOCKER_CLI_VERSION)) DOCKER_CLI_LICENSE = Apache-2.0