Commit Graph

1390 Commits

Author SHA1 Message Date
Sebastiaan van Stijn
fd550344b1 vendor: github.com/moby/go-archive v0.1.0
full diff: https://github.com/moby/go-archive/compare/21f3f3385ab7...v0.1.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-04-16 13:00:13 +02:00
Jonathan A. Sternberg
14623770e1 vendor: github.com/moby/buildkit v0.21.0-rc2
Signed-off-by: Jonathan A. Sternberg <jonathan.sternberg@docker.com>
2025-04-11 14:02:47 -05:00
Jonathan A. Sternberg
ae3a1ac602 vendor: github.com/moby/buildkit v0.21.0-rc1
Signed-off-by: Jonathan A. Sternberg <jonathan.sternberg@docker.com>
2025-04-09 14:37:09 -05:00
Derek McGowan
57a042b77c deprecate pkg/(chroot)archive for github.com/moby/go-archive
- pkg/archive: deprecate, and add aliases
  Keeping the tests in this commit; also moves various utilities
  into a _test.go file, as they were now only used in tests.
- pkg/chrootarchive: deprecate and add aliase
  deprecate pkg/archive and add aliases
  keeping the tests in this commit
- Add temporary exceptions for deprecation linting errors, because
  this commit is to verify everything works with the aliases.
- remove tests that depend on un-exported types

    === RUN   TestDisablePigz
    --- FAIL: TestDisablePigz (0.00s)
    panic: interface conversion: io.Reader is *archive.readCloserWrapper, not *archive.readCloserWrapper (types from different packages) [recovered]

- pkg/archive, pkg/chrootarchive: remove test files

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
Signed-off-by: Derek McGowan <derek@mcg.dev>
2025-04-08 10:56:58 -07:00
Akihiro Suda
e7ab601ab9 Merge pull request #49750 from thaJeztah/bump_go_cmp
vendor: github.com/google/go-cmp v0.7.0
2025-04-07 08:59:43 +01:00
Sebastiaan van Stijn
a91bcc677b vendor: github.com/klauspost/compress v1.18.0
full diff: https://github.com/klauspost/compress/compare/v1.17.11...v1.18.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-04-05 16:44:10 +02:00
Sebastiaan van Stijn
2c54f6f316 vendor: github.com/google/go-cmp v0.7.0
full diff: https://github.com/google/go-cmp/v0.6.0...v0.7.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-04-05 16:42:24 +02:00
Sebastiaan van Stijn
6422ff2804 deprecate pkg/atomicwriter, migrate to github.com/moby/sys/atomicwriter
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-04-04 23:07:00 +02:00
Derek McGowan
b5c99c0e95 Update moby/sys/user to version which includes mapping
Update idtools to use Mkdir funcs from moby sys/user package
Add deprecation exception to golanci until move off idtools is complete

Signed-off-by: Derek McGowan <derek@mcg.dev>
2025-04-04 08:22:05 -07:00
Sebastiaan van Stijn
072ea62fcc vendor: github.com/opencontainers/image-spec v1.1.1
full diff: https://github.com/opencontainers/image-spec/compare/v1.1.0...v1.1.1

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-03-26 10:01:40 +01:00
Akihiro Suda
ecb03c4cda Merge pull request #49691 from thaJeztah/bump_selinux
vendor: github.com/opencontainers/selinux v1.12.0
2025-03-24 20:18:38 +09:00
Sebastiaan van Stijn
4db84b197d switch to github.com/opencontainers/cgroups
The runc libcontainer/cgroups package was moved to a separate
module; switch our use of the runc module to use the new
location.

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-03-24 00:36:25 +01:00
Sebastiaan van Stijn
697956a8c7 vendor: github.com/opencontainers/selinux v1.12.0
This release removes deprecated functions from the `label` package,
and improves documentation and error reporting of `SetCreateKey`.

Relevant changes:

-label: remove deprecated stuff
-Improve SetKeyCreate error reporting

full diff: https://github.com/opencontainers/selinux/compare/v1.11.1...v1.12.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-03-24 00:30:46 +01:00
Akihiro Suda
c1cd4e5eb4 Merge pull request #49683 from thaJeztah/vendor_ebpf
vendor: github.com/cilium/ebpf v0.17.3
2025-03-24 08:27:46 +09:00
Sebastiaan van Stijn
34bc972519 vendor: github.com/golang-jwt/jwt/v5 v5.2.2
Fixes [GHSA-mh63-6h87-95cp] / [CVE-2025-30204]

full diff: https://github.com/golang-jwt/jwt/compare/v5.2.1...v5.2.2

[GHSA-mh63-6h87-95cp]: https://github.com/golang-jwt/jwt/security/advisories/GHSA-mh63-6h87-95cp
[CVE-2025-30204]: https://www.cve.org/CVERecord?id=CVE-2025-30204

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-03-23 17:34:42 +01:00
Sebastiaan van Stijn
daeb6fb0b7 vendor: github.com/cilium/ebpf v0.17.3
full diff: https://github.com/cilium/ebpf/compare/v0.16.0...v0.17.3

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-03-21 17:02:01 +01:00
Sebastiaan van Stijn
c1c5f16b8b vendor: github.com/opencontainers/runc v1.2.6
This is the sixth patch release in the 1.2.z series of runc.
It primarily fixes an issue with runc exec vs time namespace,
and a compatibility issue with older kernels.

* Fix a stall issue that would happen if setting `O_CLOEXEC` with
  `CloseExecFrom` failed.
* `runc` now properly handles joining time namespaces (such as with
  `runc exec`). Previously we would attempt to set the time offsets
  when joining, which would fail.
* Handle `EINTR` retries correctly for socket-related direct
  `golang.org/x/sys/unix` system calls.
* We no longer use `F_SEAL_FUTURE_WRITE` when sealing the runc binary, as it
  turns out this had some unfortunate bugs in older kernel versions and was
  never necessary in the first place.
* Remove `Fexecve` helper from `libcontainer/system`. Runc 1.2.1 removed
  runc-dmz, but we forgot to remove this helper added only for that.
* Use Go 1.23 for official builds, run CI with Go 1.24 and drop Ubuntu 20.04
  from CI. We need to drop Ubuntu 20.04 from CI because Github Actions
  announced it's already deprecated and it will be discontinued soon.

full diff: https://github.com/opencontainers/runc/compare/v1.2.5...v1.2.6

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-03-21 16:49:42 +01:00
Paweł Gronowski
fb3cce1988 vendor: github.com/containerd/containerd/v2 v2.0.4
full diff: https://github.com/containerd/containerd/v2/compare/v2.0.3...v2.0.4

Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com>
2025-03-17 19:05:57 +01:00
Akihiro Suda
55ff0062ca vendor: github.com/containernetworking/plugins v1.6.2
full diff: https://github.com/containernetworking/plugins/compare/v1.5.1...v1.6.2

Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
2025-03-10 10:15:36 +09:00
Akihiro Suda
a9c9d5bb25 Merge pull request #49465 from thaJeztah/vendor_runc_filepath_securejoin
vendor: github.com/opencontainers/runc v1.2.5, cyphar/filepath-securejoin v0.4.1
2025-03-06 09:34:23 +09:00
CrazyMax
65b460b9ef vendor: update buildkit to v0.20.1
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
2025-03-05 17:07:25 +01:00
Sebastiaan van Stijn
dbc9d56820 vendor: github.com/containerd/containerd v2.0.3
Relevant changes:

- Update remote content to break up writes to avoid grpc message size limits
- Move CDI device spec out of the OCI package
- Remove deprecated WithCDIDevices in oci spec opts

full diff: https://github.com/containerd/containerd/compare/v2.0.2...v2.0.3

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-02-28 22:11:49 +01:00
Paweł Gronowski
d67f035d31 vendor: github.com/moby/buildkit v0.20.0
full diff: https://github.com/moby/buildkit/compare/v0.20.0-rc3...v0.20.0

Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com>
2025-02-19 21:14:36 +01:00
Paweł Gronowski
cde9f0752e vendor: github.com/moby/buildkit v0.20.0-rc3
full diff: https://github.com/moby/buildkit/compare/v0.20.0-rc2...v0.20.0-rc3

Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com>
2025-02-18 21:47:59 +01:00
Sebastiaan van Stijn
47ca352b0d vendor: github.com/opencontainers/runc v1.2.5, cyphar/filepath-securejoin v0.4.1
Changes in runc code are not impacting code we use;

- libcontainer/utils.MkdirAllInRootOpen is not used
- libcontainer/utils.MkdirAllInRoot is not used

Similarly, while filepath-securejoin is imported, the functions using it
in runc (cgroups.FindCgroupMountpoint, are not used in our codebase, so
these changes don't affect our code; `tryDefaultPath` uses securejoin,
which is used by `FindCgroupMountpoint`, but not used in our codebase.

diffs:

- https://github.com/opencontainers/runc/compare/v1.2.4...v1.2.5
- https://github.com/cyphar/filepath-securejoin/compare/v0.3.5...v0.4.1

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-02-14 13:04:45 +01:00
Tonis Tiigi
707d8d80b9 vendor: update buildkit to v0.20.0-rc2
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2025-02-13 19:17:43 -08:00
Sebastiaan van Stijn
71e025c560 Merge pull request #49454 from thaJeztah/bump_dns
vendor: github.com/miekg/dns v1.1.61
2025-02-13 23:36:35 +01:00
Sebastiaan van Stijn
c53c553880 Merge pull request #49456 from thaJeztah/bump_netlink
vendor: github.com/vishvananda/netlink 655392bc778a
2025-02-13 20:45:07 +01:00
Tonis Tiigi
e364e28ec8 vendor: update buildkit to v0.20.0-rc1
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2025-02-12 11:00:04 -08:00
Sebastiaan van Stijn
d47eb241bf vendor: github.com/vishvananda/netlink 655392bc778a
full diff: 084abd93d3...655392bc77

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-02-12 16:14:20 +01:00
Sebastiaan van Stijn
c5b226e377 vendor: github.com/miekg/dns v1.1.61
not the latest-latest version, but v1.1.58 is used elsewhere, and I saw
some fixes in v1.1.59 and v1.1.60, and v1.1.61 was docs-only changes.

- Allow use of fs.FS for $INCLUDE and wrap errors
- Add NXT record
- Add ISDN record
- Fix counting of escape sequences when splitting TXT string
- IsDomainName: check for escape as last character
- Add a hook to catch invalid messages
- Fix possible out-of-bounds read in endingToTxtSlice

full diff: https://github.com/miekg/dns/compare/v1.1.57...v1.1.61

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-02-12 13:20:26 +01:00
Sebastiaan van Stijn
b570831cc3 Merge pull request #49450 from thaJeztah/bump_pflag
vendor: github.com/spf13/pflag v1.0.6
2025-02-11 17:49:21 +01:00
Sebastiaan van Stijn
e36fb45eec vendor: github.com/spf13/pflag v1.0.6
- Add exported functions to preserve pkg/flag compatibility
- Add IPNetSlice and unit tests

full diff: https://github.com/spf13/pflag/compare/v1.0.5...v1.0.6

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-02-11 15:45:03 +01:00
Sebastiaan van Stijn
66910da5a3 vendor: github.com/containerd/go-cni v1.1.12
full diff: https://github.com/containerd/go-cni/compare/v1.1.11...v1.1.12

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-02-11 15:36:12 +01:00
Tonis Tiigi
66e6a0b7a1 vendor: update buildkit to v0.19.0-rc3
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2025-01-17 14:43:39 -08:00
Derek McGowan
0aa8fe0bf9 Update to containerd v2.0.2, buildkit v0.19.0-rc2
Update buildkit version to commit which uses 2.0

Signed-off-by: Derek McGowan <derek@mcg.dev>
2025-01-15 14:09:30 +01:00
Sebastiaan van Stijn
f68eb9c3cb vendor: github.com/Microsoft/hcsshim v0.12.9
full diff: https://github.com/Microsoft/hcsshim/compare/v0.12.8...v0.12.9

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-01-14 20:21:15 +01:00
Sebastiaan van Stijn
488d6972b2 vendor: github.com/stretchr/testify v1.10.0
full diff: https://github.com/stretchr/testify/compare/v1.9.0...v1.10.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-01-14 20:21:15 +01:00
Sebastiaan van Stijn
adec695d36 vendor: github.com/fsnotify/fsnotify v1.7.0
full diff: https://github.com/fsnotify/fsnotify/compare/v1.6.0...v1.7.0

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-01-14 20:21:14 +01:00
Sebastiaan van Stijn
1ef5957089 vendor: github.com/vbatts/tar-split v0.11.6
full diff: https://github.com/vbatts/tar-split/compare/v0.11.5...v0.11.6

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-01-14 20:21:14 +01:00
Sebastiaan van Stijn
de86c46158 vendor: github.com/containernetworking/cni v1.2.3
full diff: https://github.com/containernetworking/cni/compare/v1.2.2...v1.2.3

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-01-14 20:21:14 +01:00
Sebastiaan van Stijn
6dd592bd49 vendor: github.com/containerd/go-cni v1.1.11
full diff: https://github.com/containerd/go-cni/compare/v1.1.10...v1.1.11

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-01-14 20:21:13 +01:00
Sebastiaan van Stijn
2ea97aec2d vendor: github.com/containerd/ttrpc v1.2.7
full diff: https://github.com/containerd/ttrpc/compare/v1.2.5...v1.2.7

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-01-14 20:21:13 +01:00
Sebastiaan van Stijn
f40b92272c vendor: github.com/AdamKorcz/go-118-fuzz-build v0.0.0-20231105174938-2b5cbb29f3e2
full diff: 8075edf89b...2b5cbb29f3

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-01-14 17:31:17 +01:00
Sebastiaan van Stijn
eb592fecad vendor: github.com/AdaLogics/go-fuzz-headers v0.0.0-20240806141605-e8a1dd7889d6
full diff: e8a1dd7889...e8a1dd7889

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-01-14 17:31:16 +01:00
Sebastiaan van Stijn
2b7e859c49 Merge pull request #49276 from thaJeztah/vendor_otel
vendor: otel v0.56.0 / v1.31.0
2025-01-14 17:30:14 +01:00
Sebastiaan van Stijn
04b03cfc0a Merge pull request #49278 from thaJeztah/vendor_pty_v1.1.24
vendor: github.com/creack/pty v1.1.24
2025-01-14 15:26:28 +01:00
Sebastiaan van Stijn
48e6b4e8f7 vendor: otel v0.56.0 / v1.31.0
Reverts otel workaround, added in cca7085464,
as it's no longer needed:

    === Failed
    === FAIL: cmd/dockerd TestOtelMeterLeak (0.64s)
        daemon_test.go:303: Allocations: 3
        daemon_test.go:307: Allocations count decreased. OTEL leak workaround is no longer needed!

We're keeping the test for now, so that we can check for possible
regressions in the OTel dependencies.

Co-authored-by: Derek McGowan <derek@mcg.dev>
Signed-off-by: Derek McGowan <derek@mcg.dev>
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-01-14 15:01:34 +01:00
Sebastiaan van Stijn
d60f164e21 vendor: github.com/creack/pty v1.1.24
full diff: https://github.com/creack/pty/compare/v1.1.21...v1.1.24

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-01-14 13:47:01 +01:00
Sebastiaan van Stijn
a78b84c212 vendor: github.com/aws/aws-sdk-go-v2 v1.30.3
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2025-01-14 13:35:34 +01:00