From: "Zac Medico" <zmedico@gentoo.org>
To: gentoo-commits@lists.gentoo.org
Subject: [gentoo-commits] repo/gentoo:master commit in: app-containers/podman/
Date: Wed, 27 Mar 2024 03:02:09 +0000 (UTC) [thread overview]
Message-ID: <1711508521.9569a2ffc816bb40837a3f0e0a872cf57f20bf3f.zmedico@gentoo> (raw)
commit: 9569a2ffc816bb40837a3f0e0a872cf57f20bf3f
Author: Rahil Bhimjiani <me <AT> rahil <DOT> rocks>
AuthorDate: Tue Mar 26 08:13:57 2024 +0000
Commit: Zac Medico <zmedico <AT> gentoo <DOT> org>
CommitDate: Wed Mar 27 03:02:01 2024 +0000
URL: https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=9569a2ff
app-containers/podman: 4.9.4 fixes CVE-2024-1753 and CVE-2024-24786
also backported some niceities from 5.x ebuild
* fix failed build with python-exec[-native-symlinks]
* improvments in init.d/podman, add podman-restart and
podman-clean-transient scripts, add podman-auto-update cronjob
Bug: https://bugs.gentoo.org/927500
Bug: https://bugs.gentoo.org/927501
Signed-off-by: Rahil Bhimjiani <me <AT> rahil.rocks>
From: https://github.com/gentoo/gentoo/pull/35929
Signed-off-by: Zac Medico <zmedico <AT> gentoo.org>
app-containers/podman/Manifest | 1 +
app-containers/podman/podman-4.9.4.ebuild | 156 ++++++++++++++++++++++++++++++
2 files changed, 157 insertions(+)
diff --git a/app-containers/podman/Manifest b/app-containers/podman/Manifest
index 1f1960306d0d..2e96132cac7e 100644
--- a/app-containers/podman/Manifest
+++ b/app-containers/podman/Manifest
@@ -1,2 +1,3 @@
DIST podman-4.9.3.tar.gz 21727849 BLAKE2B 9a67ba4266a8a0e20d165ba2bae00dcf146724ee976838d5e3310b094155ffa89bff526e8ae72864dc100d1e6878d5519d53581dc7e034982a4f2b364e4c8feb SHA512 395014bbe70923f1444d2f33440013a16e9c339b70be5e6a9c7026617a40795a1c0e410c08a52fba46b9f5e853d853ce4133db36167a3c5ace7d325f8b3a3327
+DIST podman-4.9.4.tar.gz 21733620 BLAKE2B 17d099c0a13fbbb77556742313c39995127fc97b4086ef3c2d74a92cc0a4f825a6c729dd099c6d4f4cd3d2ebfd470494babdeaa85a5653b327ea1a16fb5ea993 SHA512 7b52555789a1c214fcf26b0826bdda6cf0ccca588f87c0f15ac5e8358ddac625e17cafbe6a43de07cad964e1418b5ee0d2e38a5cb5dc6f6d4e638399749a7f7b
DIST podman-5.0.0.tar.gz 21861935 BLAKE2B 1ec7006f272f5da7f93929bc543cd8988d6f9596cb868e9561578ebef85d51cbd6baa4b66571872fc9748c639ca636ce27f6d90303707f04caa321c7b71db81a SHA512 8800d96d668cbc7a7ff85a09c71b3307a280c124513fd02fe478f415cf8db43ee47dc7e9c3b75046c6bda9f916937a2cc59887c2c4b26766c2f770abb87fd7ce
diff --git a/app-containers/podman/podman-4.9.4.ebuild b/app-containers/podman/podman-4.9.4.ebuild
new file mode 100644
index 000000000000..4505efe8f91d
--- /dev/null
+++ b/app-containers/podman/podman-4.9.4.ebuild
@@ -0,0 +1,156 @@
+# Copyright 1999-2024 Gentoo Authors
+# Distributed under the terms of the GNU General Public License v2
+
+EAPI=8
+
+PYTHON_COMPAT=( python3_{11,12} )
+
+inherit go-module python-any-r1 tmpfiles linux-info
+
+DESCRIPTION="A tool for managing OCI containers and pods with Docker-compatible CLI"
+HOMEPAGE="https://github.com/containers/podman/ https://podman.io/"
+
+if [[ ${PV} == 9999* ]]; then
+ inherit git-r3
+ EGIT_REPO_URI="https://github.com/containers/podman.git"
+else
+ SRC_URI="https://github.com/containers/podman/archive/v${PV/_rc/-rc}.tar.gz -> ${P}.tar.gz"
+ S="${WORKDIR}/${P/_rc/-rc}"
+ if [[ ${PV} != *rc* ]] ; then
+ KEYWORDS="~amd64 ~arm64 ~riscv"
+ fi
+fi
+
+# main pkg
+LICENSE="Apache-2.0"
+# deps
+LICENSE+=" BSD BSD-2 CC-BY-SA-4.0 ISC MIT MPL-2.0"
+SLOT="0"
+IUSE="apparmor btrfs cgroup-hybrid wrapper +fuse +init +rootless +seccomp selinux systemd"
+RESTRICT="test"
+
+RDEPEND="
+ app-crypt/gpgme:=
+ >=app-containers/conmon-2.0.0
+ >=app-containers/containers-common-0.56.0
+ dev-libs/libassuan:=
+ dev-libs/libgpg-error:=
+ sys-apps/shadow:=
+
+ apparmor? ( sys-libs/libapparmor )
+ btrfs? ( sys-fs/btrfs-progs )
+ cgroup-hybrid? ( >=app-containers/runc-1.0.0_rc6 )
+ !cgroup-hybrid? ( app-containers/crun )
+ wrapper? ( !app-containers/docker-cli )
+ fuse? ( sys-fs/fuse-overlayfs )
+ init? ( app-containers/catatonit )
+ rootless? ( app-containers/slirp4netns )
+ seccomp? ( sys-libs/libseccomp:= )
+ selinux? ( sec-policy/selinux-podman sys-libs/libselinux:= )
+ systemd? ( sys-apps/systemd:= )
+"
+DEPEND="${RDEPEND}"
+BDEPEND="
+ ${PYTHON_DEPS}
+ dev-go/go-md2man
+"
+
+PATCHES=(
+ "${FILESDIR}/seccomp-toggle-4.7.0.patch"
+)
+
+CONFIG_CHECK="
+ ~USER_NS
+"
+
+pkg_setup() {
+ use btrfs && CONFIG_CHECK+=" ~BTRFS_FS"
+ linux-info_pkg_setup
+ python-any-r1_pkg_setup
+}
+
+src_prepare() {
+ default
+
+ # assure necessary files are present
+ local file
+ for file in apparmor_tag btrfs_installed_tag btrfs_tag systemd_tag; do
+ [[ -f hack/"${file}".sh ]] || die
+ done
+
+ local feature
+ for feature in apparmor systemd; do
+ cat <<-EOF > hack/"${feature}"_tag.sh || die
+ #!/usr/bin/env bash
+ $(usex ${feature} "echo ${feature}" echo)
+ EOF
+ done
+
+ echo -e "#!/usr/bin/env bash\n echo" > hack/btrfs_installed_tag.sh || die
+ cat <<-EOF > hack/btrfs_tag.sh || die
+ #!/usr/bin/env bash
+ $(usex btrfs echo 'echo exclude_graphdriver_btrfs btrfs_noversion')
+ EOF
+}
+
+src_compile() {
+ export PREFIX="${EPREFIX}/usr"
+
+ # bug 906073
+ use elibc_musl && export CGO_CFLAGS="-D_LARGEFILE64_SOURCE"
+
+ # For non-live versions, prevent git operations which causes sandbox violations
+ # https://github.com/gentoo/gentoo/pull/33531#issuecomment-1786107493
+ [[ ${PV} != 9999* ]] && export COMMIT_NO="" GIT_COMMIT="" EPOCH_TEST_COMMIT=""
+
+ # BUILD_SECCOMP is used in the patch to toggle seccomp
+ emake BUILDFLAGS="-v -work -x" GOMD2MAN="go-md2man" BUILD_SECCOMP="$(usex seccomp)" all $(usev wrapper docker-docs)
+}
+
+src_install() {
+ emake DESTDIR="${D}" install install.completions $(usev wrapper install.docker-full)
+
+ insinto /etc/cni/net.d
+ doins cni/87-podman-bridge.conflist
+
+ if use !systemd; then
+ newconfd "${FILESDIR}"/podman-5.0.0_rc4.confd podman
+ newinitd "${FILESDIR}"/podman-5.0.0_rc4.initd podman
+
+ newinitd "${FILESDIR}"/podman-restart-5.0.0_rc4.initd podman-restart
+ newconfd "${FILESDIR}"/podman-restart-5.0.0_rc4.confd podman-restart
+
+ newinitd "${FILESDIR}"/podman-clean-transient-5.0.0_rc6.initd podman-clean-transient
+ newconfd "${FILESDIR}"/podman-clean-transient-5.0.0_rc6.confd podman-clean-transient
+
+ exeinto /etc/cron.daily
+ newexe "${FILESDIR}"/podman-auto-update-5.0.0.cron podman-auto-update
+
+ insinto /etc/logrotate.d
+ newins "${FILESDIR}/podman.logrotated" podman
+ fi
+
+ keepdir /var/lib/containers
+}
+
+pkg_preinst() {
+ PODMAN_ROOTLESS_UPGRADE=false
+ if use rootless; then
+ has_version 'app-containers/podman[rootless]' || PODMAN_ROOTLESS_UPGRADE=true
+ fi
+}
+
+pkg_postinst() {
+ tmpfiles_process podman.conf $(usev wrapper podman-docker.conf)
+
+ local want_newline=false
+ if [[ ${PODMAN_ROOTLESS_UPGRADE} == true ]] ; then
+ ${want_newline} && elog ""
+ elog "For rootless operation, you need to configure subuid/subgid"
+ elog "for user running podman. In case subuid/subgid has only been"
+ elog "configured for root, run:"
+ elog "usermod --add-subuids 1065536-1131071 <user>"
+ elog "usermod --add-subgids 1065536-1131071 <user>"
+ want_newline=true
+ fi
+}
next reply other threads:[~2024-03-27 3:02 UTC|newest]
Thread overview: 94+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-03-27 3:02 Zac Medico [this message]
-- strict thread matches above, loose matches on Subject: below --
2025-01-23 2:34 [gentoo-commits] repo/gentoo:master commit in: app-containers/podman/ Zac Medico
2025-01-10 13:18 Arthur Zamarin
2025-01-10 13:18 Arthur Zamarin
2024-11-26 22:09 Zac Medico
2024-11-26 3:17 Sam James
2024-11-26 2:56 Sam James
2024-11-13 23:23 Zac Medico
2024-10-31 3:56 Zac Medico
2024-10-24 19:53 Zac Medico
2024-10-16 2:12 Sam James
2024-10-11 21:59 Zac Medico
2024-08-22 8:55 WANG Xuerui
2024-08-22 8:55 WANG Xuerui
2024-06-13 19:10 Zac Medico
2024-05-26 23:31 Zac Medico
2024-05-12 20:49 Zac Medico
2024-04-18 4:12 Zac Medico
2024-04-18 4:12 Zac Medico
2024-04-01 16:06 Zac Medico
2024-03-31 23:51 Zac Medico
2024-03-31 19:07 Arthur Zamarin
2024-03-31 16:47 Jakov Smolić
2024-03-23 8:29 Sam James
2024-03-16 23:35 Zac Medico
2024-03-15 19:47 Sam James
2024-03-15 19:28 Sam James
2024-03-08 3:25 Zac Medico
2024-03-07 2:28 Zac Medico
2024-03-02 23:47 Andreas K. Hüttel
2024-02-28 9:12 Florian Schmaus
2024-02-15 5:15 Zac Medico
2024-02-10 5:04 Zac Medico
2024-02-10 4:15 Zac Medico
2024-02-08 3:17 Zac Medico
2024-02-02 6:37 Zac Medico
2024-01-08 8:13 Zac Medico
2024-01-04 10:02 Sam James
2024-01-04 10:02 Sam James
2024-01-03 18:19 Zac Medico
2024-01-03 18:19 Zac Medico
2023-12-18 5:36 Zac Medico
2023-12-18 5:36 Zac Medico
2023-12-06 6:35 Zac Medico
2023-12-06 6:35 Zac Medico
2023-11-28 5:32 Arthur Zamarin
2023-11-28 5:32 Arthur Zamarin
2023-11-28 3:16 Zac Medico
2023-11-22 5:21 Zac Medico
2023-11-02 2:13 Zac Medico
2023-10-31 17:19 Mike Gilbert
2023-10-06 3:58 Zac Medico
2023-09-27 15:00 Yixun Lan
2023-09-25 4:48 Sam James
2023-09-25 3:45 Zac Medico
2023-09-25 3:45 Zac Medico
2023-06-10 4:20 Sam James
2023-06-09 18:09 Arthur Zamarin
2023-05-09 5:16 Zac Medico
2023-03-22 1:20 Sam James
2023-02-18 1:15 Zac Medico
2023-01-06 22:34 Zac Medico
2023-01-06 22:23 Sam James
2023-01-06 20:03 Arthur Zamarin
2022-11-22 1:19 Zac Medico
2022-10-20 0:03 Zac Medico
2022-10-07 23:23 Zac Medico
2022-09-18 23:47 Zac Medico
2022-08-15 19:28 Sam James
2022-08-12 20:01 Zac Medico
2022-06-18 20:36 Zac Medico
2022-06-05 15:13 Zac Medico
2022-06-04 19:51 Jakov Smolić
2022-06-03 21:30 Jakov Smolić
2022-05-07 16:10 Zac Medico
2022-04-10 17:09 Zac Medico
2022-04-09 21:32 Jason Zaman
2022-04-09 19:47 Arthur Zamarin
2022-04-07 20:58 Jakov Smolić
2022-04-01 17:55 Zac Medico
2022-03-26 1:41 Zac Medico
2022-03-25 4:01 Zac Medico
2022-03-25 3:53 Zac Medico
2022-03-25 3:01 Zac Medico
2022-03-25 2:43 Zac Medico
2022-03-10 3:22 Yixun Lan
2022-03-05 18:56 Zac Medico
2022-02-25 9:25 Yixun Lan
2022-02-24 3:03 Zac Medico
2022-02-18 18:46 Zac Medico
2021-12-27 3:30 Zac Medico
2021-12-25 17:28 Arthur Zamarin
2021-12-25 1:00 Sam James
2021-12-24 22:34 Zac Medico
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1711508521.9569a2ffc816bb40837a3f0e0a872cf57f20bf3f.zmedico@gentoo \
--to=zmedico@gentoo.org \
--cc=gentoo-commits@lists.gentoo.org \
--cc=gentoo-dev@lists.gentoo.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox