This update for conmon, libcontainers-common, libseccomp, podman fixes the following issues:
podman was updated to 3.4.4.
Security issues fixed:
fix CVE-2021-41190 [bsc#1193273], opencontainers: OCI manifest and index parsing confusion
fix CVE-2021-4024 [bsc#1193166], podman machine spawns gvproxy with port binded to all IPs
fix CVE-2021-20199 [bsc#1181640], Remote traffic to rootless containers is seen as orginating from localhost
Add: Provides: podman:/usr/bin/podman-remote subpackage for a clearer upgrade path from podman < 3.1.2
Update to version 3.4.4:
Bugfixes
Update to version 3.4.3:
Security
Features
Bugfixes
API
Update to version 3.4.2:
Update to version 3.4.1:
Bugfixes
API
Update to version 3.4.0:
Features
Changes
Bugfixes
API
Update to version 3.3.1:
Bugfixes
API
Update to version 3.3.0:
Switch to crun (bsc#1188914)
Update to version 3.2.3:
Update to version 3.2.2:
Update to version 3.2.1:
Update to version 3.2.0:
--allstale release...make nixpkgs-- into en dashimages/get--full-path option for conmonmake nixpkgsmake nixpkgs--userns=keep-id sets user in configregistries.conf for aliasesrequire.NoErrorUpdate to version 3.1.2:
Split podman-remote into a subpackage
Add missing scriptlets for systemd units
Escape macros in comments
Drop some obsolete workarounds, including %{go_nostrip}
Update to version 3.1.1:
--userns=keep-id sets user in configUpdate to version 3.1.0:
registries.conf for aliasesRequire systemd 241 or newer due to podman dependency go-systemd v22, otherwise build will fail with unknown C name errors
Create docker subpackage to allow replacing docker with corresponding aliases to podman.
Update to v3.0.1
Changes from v3.0.0
Update to v2.2.1
Update to v2.2.0
The Compat Create endpoint for Container has received a major refactor to share more code with the Libpod Create endpoint, and should be significantly more stable.
A Compat endpoint for exporting multiple images at once, GET /images/get, has been added (#7950).
The Compat Network Connect and Network Disconnect endpoints have been added.
Endpoints that deal with image registries now support a X-Registry-Config header to specify registry authentication configuration.
The Compat Create endpoint for images now properly supports specifying images by digest.
The Libpod Build endpoint for images now supports an httpproxy query parameter which, if set to true, will forward the server's HTTP proxy settings into the build container for RUN instructions.
The Libpod Untag endpoint for images will now remove all tags for the given image if no repository and tag are specified for removal.
Fixed a bug where the Ping endpoint misspelled a header name (Libpod-Buildha-Version instead of Libpod-Buildah-Version).
Fixed a bug where the Ping endpoint sent an extra newline at the end of its response where Docker did not.
Fixed a bug where the Compat Logs endpoint for containers did not send a newline character after each log line.
Fixed a bug where the Compat Logs endpoint for containers would mangle line endings to change newline characters to add a preceding carriage return (#7942).
Fixed a bug where the Compat Inspect endpoint for Containers did not properly list the container's stop signal (#7917).
Fixed a bug where the Compat Inspect endpoint for Containers formatted the container's create time incorrectly (#7860).
Fixed a bug where the Compat Inspect endpoint for Containers did not include the container's Path, Args, and Restart Count.
Fixed a bug where the Compat Inspect endpoint for Containers prefixed added and dropped capabilities with CAP_ (Docker does not do so).
Fixed a bug where the Compat Info endpoint for the Engine did not include configured registries.
Fixed a bug where the server could panic if a client closed a connection midway through an image pull (#7896).
Fixed a bug where the Compat Create endpoint for volumes returned an error when a volume with the same name already existed, instead of succeeding with a 201 code (#7740).
Fixed a bug where a client disconnecting from the Libpod or Compat events endpoints could result in the server using 100% CPU (#7946).
Fixed a bug where the 'no such image' error message sent by the Compat Inspect endpoint for Images returned a 404 status code with an error that was improperly formatted for Docker compatibility.
Fixed a bug where the Compat Create endpoint for networks did not properly set a default for the driver parameter if it was not provided by the client.
Fixed a bug where the Compat Inspect endpoint for images did not populate the RootFS field of the response.
Fixed a bug where the Compat Inspect endpoint for images would omit the ParentId field if the image had no parent, and the Created field if the image did not have a creation time.
Fixed a bug where the Compat Remove endpoint for Networks did not support the Force query parameter.
add dependency to timezone package or podman fails to build a
Correct invalid use of %{_libexecdir} to ensure files should be in /usr/lib SELinux support [jsc#SMO-15]
libseccomp was updated to release 2.5.3:
Update to release 2.5.2
update to 2.5.1:
Update to release 2.5.0
Update to release 2.4.3
Update to release 2.4.2
conmon was updated to version 2.0.30:
Update to version 2.0.29:
Update to version 2.0.27:
Update to version 2.0.26:
Update to version 2.0.22:
Update to version 2.0.21:
/nix folderlibcontainers-common was updated to include:
CVEs fixed: CVE-2020-14370,CVE-2020-15157,CVE-2021-20199,CVE-2021-20291,CVE-2021-3602
{
"binaries": [
{
"conmon": "2.0.30-150300.8.3.1",
"libcontainers-common": "20210626-150300.8.3.1",
"libseccomp-devel": "2.5.3-150300.10.5.1",
"libseccomp-tools": "2.5.3-150300.10.5.1",
"libseccomp2": "2.5.3-150300.10.5.1",
"libseccomp2-32bit": "2.5.3-150300.10.5.1",
"podman": "3.4.4-150300.9.3.2",
"podman-cni-config": "3.4.4-150300.9.3.2"
}
]
}
{
"binaries": [
{
"conmon": "2.0.30-150300.8.3.1",
"libcontainers-common": "20210626-150300.8.3.1",
"libseccomp-devel": "2.5.3-150300.10.5.1",
"libseccomp-tools": "2.5.3-150300.10.5.1",
"libseccomp2": "2.5.3-150300.10.5.1",
"libseccomp2-32bit": "2.5.3-150300.10.5.1",
"podman": "3.4.4-150300.9.3.2",
"podman-cni-config": "3.4.4-150300.9.3.2"
}
]
}
{
"binaries": [
{
"conmon": "2.0.30-150300.8.3.1",
"libcontainers-common": "20210626-150300.8.3.1",
"libseccomp-devel": "2.5.3-150300.10.5.1",
"libseccomp-tools": "2.5.3-150300.10.5.1",
"libseccomp2": "2.5.3-150300.10.5.1",
"libseccomp2-32bit": "2.5.3-150300.10.5.1",
"podman": "3.4.4-150300.9.3.2",
"podman-cni-config": "3.4.4-150300.9.3.2"
}
]
}
{
"binaries": [
{
"conmon": "2.0.30-150300.8.3.1",
"libcontainers-common": "20210626-150300.8.3.1",
"libseccomp-devel": "2.5.3-150300.10.5.1",
"libseccomp-tools": "2.5.3-150300.10.5.1",
"libseccomp2": "2.5.3-150300.10.5.1",
"libseccomp2-32bit": "2.5.3-150300.10.5.1",
"podman": "3.4.4-150300.9.3.2",
"podman-cni-config": "3.4.4-150300.9.3.2"
}
]
}