Commit Graph

956 Commits

Author SHA1 Message Date
dependabot[bot]
cd9113b9d5 build(deps): bump the codeql-actions group with 3 updates
Bumps the codeql-actions group with 3 updates: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/analyze](https://github.com/github/codeql-action) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.37.3 to 4.37.4
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](e4fba868fa...f205ea1c33)

Updates `github/codeql-action/analyze` from 4.37.3 to 4.37.4
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](e4fba868fa...f205ea1c33)

Updates `github/codeql-action/upload-sarif` from 4.37.3 to 4.37.4
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](e4fba868fa...f205ea1c33)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.37.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-07 23:26:33 +00:00
dependabot[bot]
406c8dc44a build(deps): bump the codeql-actions group with 3 updates
Bumps the codeql-actions group with 3 updates: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/analyze](https://github.com/github/codeql-action) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.37.2 to 4.37.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](e0647621c2...e4fba868fa)

Updates `github/codeql-action/analyze` from 4.37.2 to 4.37.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](e0647621c2...e4fba868fa)

Updates `github/codeql-action/upload-sarif` from 4.37.2 to 4.37.3
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](e0647621c2...e4fba868fa)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.37.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-31 23:26:40 +00:00
Samuel Karp
56bc534e7e Merge pull request #13871 from samuelkarp/remove_deprecated_checkpoint_restore
cri: remove restore in CreateContainer
2026-07-31 15:50:29 +00:00
Samuel Karp
91be73ba62 cri: remove restore in CreateContainer
Remove support for restoring checkpoint data during CreateContainer,
which was previously deprecated in v2.3.

Assisted-by: Antigravity
Signed-off-by: Samuel Karp <samuelkarp@google.com>
2026-07-29 09:32:24 -07:00
Samuel Karp
565606decf workflows/stale: exempt priority and status labels
Exclude priority/*, status/accepted, status/needs-major-release, and
status/roadmapped labels from being marked as stale and closed.

Assisted-by: Antigravity
Signed-off-by: Samuel Karp <samuelkarp@google.com>
2026-07-28 11:29:53 -07:00
dependabot[bot]
ef89efe0d0 build(deps): bump the codeql-actions group with 3 updates
Bumps the codeql-actions group with 3 updates: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/analyze](https://github.com/github/codeql-action) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.36.2 to 4.37.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](8aad20d150...e0647621c2)

Updates `github/codeql-action/analyze` from 4.36.2 to 4.37.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](8aad20d150...e0647621c2)

Updates `github/codeql-action/upload-sarif` from 4.37.0 to 4.37.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](99df26d4f1...e0647621c2)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codeql-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: codeql-actions
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.37.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: codeql-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-28 00:15:56 +00:00
Samuel Karp
e8e0b8b356 Merge pull request #13847 from thaJeztah/dependabot_group
ci: dependabot: group docker/* and codeql action updates
2026-07-27 23:39:28 +00:00
Sebastiaan van Stijn
069df6c325 ci: dependabot: group docker/* and codeql action updates
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-07-25 01:34:25 +02:00
dependabot[bot]
4fa23707c8 build(deps): bump actions/checkout from 7.0.0 to 7.0.1
Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](9c091bb21b...3d3c42e5aa)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 7.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-24 23:24:34 +00:00
Maksym Pavlenko
5c620e984f Fix NET/network CI failure on Windows
Signed-off-by: Maksym Pavlenko <pavlenko.maksym@gmail.com>
2026-07-21 21:00:34 -07:00
Akihiro Suda
4b730651ee Merge pull request #13688 from containerd/dependabot/github_actions/actions/attest-build-provenance-4.1.1
build(deps): bump actions/attest-build-provenance from 4.1.0 to 4.1.1
2026-07-20 20:54:55 +00:00
Maksym Pavlenko
0ed30a42b9 Merge pull request #13810 from containerd/dependabot/github_actions/github/codeql-action/upload-sarif-4.37.0
build(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.0
2026-07-19 06:06:54 +00:00
Maksym Pavlenko
956be807ee Merge pull request #13765 from containerd/dependabot/github_actions/docker/setup-buildx-action-4.2.0
build(deps): bump docker/setup-buildx-action from 4.1.0 to 4.2.0
2026-07-19 01:57:53 +00:00
Maksym Pavlenko
9a2d8419eb Merge pull request #13772 from containerd/dependabot/github_actions/docker/login-action-4.4.0
build(deps): bump docker/login-action from 4.2.0 to 4.4.0
2026-07-19 01:57:39 +00:00
dependabot[bot]
a4b1e9a44b build(deps): bump actions/stale from 10.3.0 to 10.4.0
Bumps [actions/stale](https://github.com/actions/stale) from 10.3.0 to 10.4.0.
- [Release notes](https://github.com/actions/stale/releases)
- [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md)
- [Commits](eb5cf3af3a...1e223db275)

---
updated-dependencies:
- dependency-name: actions/stale
  dependency-version: 10.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-17 23:27:04 +00:00
dependabot[bot]
624c8e85bd build(deps): bump github/codeql-action/upload-sarif
Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 4.36.2 to 4.37.0.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](8aad20d150...99df26d4f1)

---
updated-dependencies:
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.37.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-17 23:26:20 +00:00
Samuel Karp
4796c7b9d2 Merge pull request #13748 from mxpv/dev
Run CI against dev branches
2026-07-16 17:15:38 +00:00
Samuel Karp
1ab181cb64 Merge pull request #13780 from mxpv/stale
Raise stale bot limits
2026-07-15 08:04:44 +00:00
Maksym Pavlenko
12f6a4d585 Raise stale bot limits
Signed-off-by: Maksym Pavlenko <pavlenko.maksym@gmail.com>
2026-07-12 17:18:23 -07:00
dependabot[bot]
a9bb893ecb build(deps): bump docker/login-action from 4.2.0 to 4.4.0
Bumps [docker/login-action](https://github.com/docker/login-action) from 4.2.0 to 4.4.0.
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](650006c6eb...af1e73f918)

---
updated-dependencies:
- dependency-name: docker/login-action
  dependency-version: 4.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-10 23:25:37 +00:00
dependabot[bot]
51355849a7 build(deps): bump docker/setup-buildx-action from 4.1.0 to 4.2.0
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 4.1.0 to 4.2.0.
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](d7f5e7f509...bb05f3f551)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-10 23:22:41 +00:00
Maksym Pavlenko
6c438b0479 Run CI against dev branches
Signed-off-by: Maksym Pavlenko <pavlenko.maksym@gmail.com>
2026-07-09 10:20:18 -07:00
Akihiro Suda
a42b09aaa6 CI: migrate Vagrant to Lima
Vagrant is no longer well maintained: e.g., its apt repository does not
provide packages for Ubuntu 26.04 (hashicorp/vagrant#13811), and recent
Fedora boxes are no longer published to HashiCorp's registry, so the CI
had to download the box file manually from Fedora mirrors.

The test scripts in the Vagrantfile were split out to script/vm/*.sh .
The scripts depend on neither Vagrant nor Lima, and can be used with
other VM environments too.

Assisted-by: Claude Fable 5 <noreply@anthropic.com>
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
2026-07-08 21:09:27 +09:00
Samuel Karp
cb66686cbb Merge pull request #13664 from samuelkarp/criu-check-fail-fast
Disable checkpoint restore codepath when CRIU is not installed
2026-07-08 06:10:01 +00:00
Chris Henzie
2b017f12b5 Update go to 1.26.5
Includes security fixes to the crypto/tls and os packages.

Assisted-by: Antigravity
Signed-off-by: Chris Henzie <chrishenzie@gmail.com>
2026-07-07 14:34:38 -07:00
徐晓伟
48c841fe2d feat: add loong64 (LoongArch) build support
Add loong64 (LoongArch) architecture support to the build system and CI:

- Makefile.linux: add loong64 to architectures that don't use -buildmode=pie
  (consistent with other non-amd64 architectures like mips, ppc64)
- ci.yml: add linux/loong64 to crossbuild matrix with CGO_ENABLED=0
- RELEASES.md: add linux/loong64 as Tier 3 (Build-verified) platform

The linux/loong64 release build and nightly build entries are intentionally
excluded — the cross-compilation toolchain is not yet available in Ubuntu 22.04
apt repositories (no crossbuild-essential-loong64 package). The crossbuild CI
check uses CGO_ENABLED=0. Nightly and release builds will be re-enabled once
the upstream tonistiigi/xx base image provides the loong64 cross-compilation
toolchain.

Go has supported GOARCH=loong64 as a first-class port since Go 1.21.
The seccomp default profile already includes loong64 support (contrib/seccomp).

Tracked by: https://github.com/containerd/containerd/issues/13641

Signed-off-by: 徐晓伟 <xuxiaowei@xuxiaowei.com.cn>
2026-07-07 01:43:14 +08:00
Phil Estes
072dbf625f Merge pull request #13687 from containerd/dependabot/github_actions/actions/cache-6.1.0
build(deps): bump actions/cache from 5.0.5 to 6.1.0
2026-07-06 14:47:39 +00:00
Maksym Pavlenko
4f9bae6776 Update stale PR policy
Signed-off-by: Maksym Pavlenko <pavlenko.maksym@gmail.com>
2026-07-02 15:44:54 -07:00
dependabot[bot]
ee7e56cac7 build(deps): bump actions/cache from 5.0.5 to 6.1.0
Bumps [actions/cache](https://github.com/actions/cache) from 5.0.5 to 6.1.0.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](27d5ce7f10...55cc834586)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-02 13:27:21 -04:00
Samuel Karp
84112c78c1 ci: pin fog-json to resolve gem conflict
Vagrant 2.4.x bundles an embedded Ruby 3.3.0 runtime that loads the
default specification json-2.7.2 during initialization. When installing
vagrant-libvirt, RubyGems resolves the newly released fog-json 1.4.0,
which requires json (~> 2.19). Because json-2.7.2 is already active in
memory when Vagrant starts up, RubyGems raises a Gem::ConflictError.

To avoid this conflict, pin fog-json to version 1.2.0 before installing
vagrant-libvirt. Since CI caches /root/.vagrant.d across runs, also
uninstall fog-json first to remove any conflicting version left in cache
by a previous job.

Assisted-by: Antigravity
Signed-off-by: Samuel Karp <samuelkarp@google.com>
2026-07-01 23:19:06 -07:00
Samuel Karp
81350a5d9a github/workflows: install criu in node-e2e
The Kubernetes E2E CI workflow was failing on tests requiring container
checkpointing because criu was not installed on the GitHub Actions
runner.

Add a step to install criu via ppa:criu/ppa before building and
installing containerd, matching the existing setup in ci.yml.

Assisted-by: Antigravity
Signed-off-by: Samuel Karp <samuelkarp@google.com>
2026-06-30 12:47:52 -07:00
Samuel Karp
06495733b2 cri: add enable_criu configuration option
Add a new `enable_criu` configuration option under CRI plugin runtime
settings. When set to false, any checkpoint or restore request will fail
fast with an error indicating that CRIU support is disabled by
configuration. `enable_criu` currently defaults to true.

Add an integration test script to verify that setting `enable_criu` to
false in containerd configuration successfully disables checkpoint and
restore operations and fails fast.

Assisted-by: Antigravity
Signed-off-by: Samuel Karp <samuelkarp@google.com>
2026-06-30 12:47:48 -07:00
dependabot[bot]
43866c6a3f build(deps): bump actions/attest-build-provenance from 4.1.0 to 4.1.1
Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 4.1.0 to 4.1.1.
- [Release notes](https://github.com/actions/attest-build-provenance/releases)
- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md)
- [Commits](a2bbfa2537...0f67c3f485)

---
updated-dependencies:
- dependency-name: actions/attest-build-provenance
  dependency-version: 4.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-29 23:22:59 +00:00
Sebastiaan van Stijn
0f18307820 gha: quote some values
Quote values to address CoPilot review comments

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-06-26 18:53:38 +02:00
Sebastiaan van Stijn
0274924d74 gha: remove uses of "read-all" permissions
"read-all" is overly permissive as a default. Change it to contents: read
to align with other defaults.

Note that this does not actually impact the workflows, because the defaults
are overwritten in the actual check.

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-06-26 18:53:37 +02:00
Sebastiaan van Stijn
072a34d648 gha: suppress zizmor warning for intentionally un-pinned workflows
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-06-26 18:53:37 +02:00
Sebastiaan van Stijn
9f0bb640ce gha: apply zizmor fixes
Results of automated fixes using;

    zizmor --fix=all --min-severity medium .

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-06-26 18:53:36 +02:00
Sebastiaan van Stijn
8722c46313 gha: buf-breaking: pin actions by sha
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2026-06-26 18:49:57 +02:00
dependabot[bot]
38aaa269c7 build(deps): bump actions/checkout from 6 to 7
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Commits](https://github.com/actions/checkout/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-23 17:22:48 +00:00
dependabot[bot]
d568ae9cb5 build(deps): bump softprops/action-gh-release from 3.0.0 to 3.0.1
Bumps [softprops/action-gh-release](https://github.com/softprops/action-gh-release) from 3.0.0 to 3.0.1.
- [Release notes](https://github.com/softprops/action-gh-release/releases)
- [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md)
- [Commits](b430933298...718ea10b13)

---
updated-dependencies:
- dependency-name: softprops/action-gh-release
  dependency-version: 3.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-22 23:23:04 +00:00
Akhil Mohan
3c37ceee46 update go to 1.26.4
go1.26.4 includes security fixes to the crypto/x509, mime, and
net/textproto packages, as well as bug fixes to the compiler, the
runtime, the go fix command, and the crypto/fips140 package

Signed-off-by: Akhil Mohan <akhilerm@gmail.com>
2026-06-11 20:37:57 +05:30
Akihiro Suda
01f6f189a5 Merge pull request #13516 from estesp/setup-go-node20-fix
Update to current setup-go version
2026-06-11 13:42:26 +00:00
Akihiro Suda
f58cda1274 Merge pull request #13555 from containerd/dependabot/github_actions/github/codeql-action-4.36.2
build(deps): bump github/codeql-action from 4.36.0 to 4.36.2
2026-06-11 23:22:47 +09:00
Samuel Karp
2454191ea6 Merge pull request #13562 from chrishenzie/fix-erofs-dmverity-tests
Configure udevd children-max for root-test
2026-06-10 02:32:14 +00:00
Chris Henzie
4adafdf7e1 Configure udevd children-max for root-test
GHA runners occasionally experience I/O constraints during root-test
test execution. While concurrent tests rapidly allocate loopback
devices, background udev probing stalls. This quickly exhausts
systemd-udevd's default worker pool ceiling (20 children max), stalling
netlink uevent processing so device-mapper device nodes are never
created for subsequent dm-verity test execution.

Logging cgroups v2 pids.peak telemetry confirmed peak in-flight udev
workers accumulate to 325 during test execution. Raising the
children-max limit to 500 provides comfortable buffer room so udevd
freely spawns worker processes without entering event lockup or causing
test timeouts.

Assisted-by: Antigravity
Signed-off-by: Chris Henzie <chrishenzie@gmail.com>
2026-06-09 17:59:56 -07:00
Samuel Karp
a769b7aea1 Merge pull request #13503 from lauralorenz/fuzz-upload-failures
Upload crash artifacts from go test -fuzz when failed
2026-06-09 18:03:29 +00:00
dependabot[bot]
dfb00c4770 build(deps): bump github/codeql-action from 4.36.0 to 4.36.2
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.0 to 4.36.2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](7211b7c807...8aad20d150)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.36.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-08 23:23:19 +00:00
Samuel Karp
af60379ff6 Merge pull request #13434 from lauralorenz/workflow-updates-bash-interpolation
Use intermediate env variables for bash script runners in github workflows
2026-06-04 18:59:36 +00:00
Akihiro Suda
e37dfad050 CI: update Fedora to 44
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
2026-06-03 20:35:09 +09:00
Phil Estes
80b3fe5c78 Update to current setup-go version
Update the setup-go version in our private action yml to
1) be pinned by hash (with comment to version string)
2) remove cache disable that was fixed 3 years ago

Signed-off-by: Phil Estes <estesp@amazon.com>
2026-06-02 13:20:20 -04:00