Compare commits

..

1 commit

Author SHA1 Message Date
David Michael
dfd5e45f96 Add a runc patch for CVE-2019-5736 2019-02-10 18:49:23 -05:00
13 changed files with 649 additions and 1029 deletions

205
.gitignore vendored
View file

@ -1,202 +1,5 @@
# Ignore unpacked source directories
/moby-*/
/cli-*/
# Ignore fedpkg mockbuild artifacts
/results_*
/2d0083d657f82c47044c8d3948ba434b622fe2fd.tar.gz
/425e105d5a03fabd737a126ad93d62a9eeede87f.tar.gz
/894b81a4b802e4eb2a91d1ce216b8817763c29fb.tar.gz
/e7933d41e7b206756115aa9df5e0599fc5169742.tar.gz
/0ffa8257ec673ed6849b73b03fb01b0cac90fdb3.tar.gz
/a79d3687931697244b8e03485bf7b2042f8ec6b6.tar.gz
/a88b6319614de846458750ff882723479ca7b1a1.tar.gz
/ad0f5255060d36872be04de22f8731f38ef2d7b1.tar.gz
/fec3683b971d9c3ef73f284f176672c44b448662.tar.gz
/0dd43dd87fd530113bf44c9bba9ad8b20ce4637f.tar.gz
/7141c199a2edb2a90b778175f836f9dd2a22c95a.tar.gz
/264bffcb88c1b6b7471c04e3c6b3f301233a544b.tar.gz
/afacb8b7f0d8d4f9d2a8e8736e9c993e672b41f3.tar.gz
/bf2bd42abc0a3734f12b5ec724e571434e42c669.tar.gz
/2e24aed516bd5c836e11378bb457dd612aa868ed.tar.gz
/42e35e61f352e527082521280d5ea3761f0dee50.tar.gz
/4484c46d9d1a2d10b8fc662923ad586daeedb04f.tar.gz
/026aabaa659832804b01754aaadd2c0f420c68b6.tar.gz
/de40ad007797e0dcd8b7126f27bb87401d224240.tar.gz
/moby-v20.10.5.tar.gz
/cli-v20.10.5.tar.gz
/moby-v20.10.6.tar.gz
/cli-v20.10.6.tar.gz
/moby-v20.10.7.tar.gz
/cli-v20.10.7.tar.gz
/cli-v20.10.8.tar.gz
/moby-v20.10.8.tar.gz
/cli-v20.10.9.tar.gz
/moby-v20.10.9.tar.gz
/cli-v20.10.10.tar.gz
moby-v20.10.10.tar.gz
/cli-v20.10.11.tar.gz
/moby-v20.10.11.tar.gz
/cli-v20.10.12.tar.gz
/moby-v20.10.12.tar.gz
/cli-20.10.12.tar.gz
/moby-20.10.12.tar.gz
/tini-de40ad0.tar.gz
/cli-20.10.14.tar.gz
/moby-20.10.14.tar.gz
/cli-20.10.15.tar.gz
/moby-20.10.15.tar.gz
/cli-20.10.16.tar.gz
/moby-20.10.16.tar.gz
/cli-20.10.17.tar.gz
/moby-20.10.17.tar.gz
/cli-20.10.18.tar.gz
/moby-20.10.18.tar.gz
/cli-20.10.19.tar.gz
/moby-20.10.19.tar.gz
/cli-20.10.20.tar.gz
/moby-20.10.20.tar.gz
/cli-20.10.21.tar.gz
/moby-20.10.21.tar.gz
/cli-20.10.22.tar.gz
/moby-20.10.22.tar.gz
/moby-20.10.23.tar.gz
/cli-20.10.23.tar.gz
/moby-23.0.4.tar.gz
/cli-23.0.4.tar.gz
/tini-0b44d36.tar.gz
/cli-24.0.5.tar.gz
/moby-24.0.5.tar.gz
/moby-26.0.0.tar.gz
/moby-26.0.0-vendor.tar.bz2
/moby-26.0.1.tar.gz
/moby-26.0.1-vendor.tar.bz2
/moby-26.1.0.tar.gz
/moby-26.1.0-vendor.tar.bz2
/moby-26.1.4.tar.gz
/moby-26.1.4-vendor.tar.bz2
/moby-27.1.1.tar.gz
/cli-27.1.1.tar.gz
/moby-27.1.1-vendor.tar.bz2
/cli-27.1.1-vendor.tar.bz2
/moby-27.1.2.tar.gz
/cli-27.1.2.tar.gz
/moby-27.1.2-vendor.tar.bz2
/cli-27.1.2-vendor.tar.bz2
/cli-27.2.0.tar.gz
/cli-27.2.0-vendor.tar.bz2
/moby-27.2.0.tar.gz
/moby-27.2.0-vendor.tar.bz2
/cli-27.2.1.tar.gz
/cli-27.2.1-vendor.tar.bz2
/moby-27.2.1.tar.gz
/moby-27.2.1-vendor.tar.bz2
/cli-27.3.1.tar.gz
/cli-27.3.1-vendor.tar.bz2
/moby-27.3.1.tar.gz
/moby-27.3.1-vendor.tar.bz2
/moby-27.4.0-rc.4-vendor.tar.bz2
/moby-27.4.0-rc.4.tar.gz
/cli-27.4.0-rc.4.tar.gz
/cli-27.4.0-rc.4-vendor.tar.bz2
/cli-27.4.0.tar.gz
/cli-27.4.0-vendor.tar.bz2
/moby-27.4.0.tar.gz
/moby-27.4.0-vendor.tar.bz2
/cli-27.4.1.tar.gz
/cli-27.4.1-vendor.tar.bz2
/moby-27.4.1.tar.gz
/moby-27.4.1-vendor.tar.bz2
/cli-27.5.0.tar.gz
/cli-27.5.0-vendor.tar.bz2
/moby-27.5.0.tar.gz
/moby-27.5.0-vendor.tar.bz2
/cli-27.5.1.tar.gz
/cli-27.5.1-vendor.tar.bz2
/moby-27.5.1.tar.gz
/moby-27.5.1-vendor.tar.bz2
/cli-28.0.0.tar.gz
/cli-28.0.0-vendor.tar.bz2
/moby-28.0.0.tar.gz
/moby-28.0.0-vendor.tar.bz2
/cli-28.0.1.tar.gz
/cli-28.0.1-vendor.tar.bz2
/moby-28.0.1.tar.gz
/moby-28.0.1-vendor.tar.bz2
/cli-28.0.2-vendor.tar.bz2
/cli-28.0.2.tar.gz
/moby-28.0.2-vendor.tar.bz2
/moby-28.0.2.tar.gz
/moby-28.0.4.tar.gz
/moby-28.0.4-vendor.tar.bz2
/cli-28.0.4.tar.gz
/cli-28.0.4-vendor.tar.bz2
/cli-28.1.1.tar.gz
/cli-28.1.1-vendor.tar.bz2
/moby-28.1.1.tar.gz
/moby-28.1.1-vendor.tar.bz2
/cli-28.2.1.tar.gz
/cli-28.2.1-vendor.tar.bz2
/moby-28.2.1.tar.gz
/moby-28.2.1-vendor.tar.bz2
/cli-28.2.2-vendor.tar.bz2
/cli-28.2.2.tar.gz
/moby-28.2.2-vendor.tar.bz2
/moby-28.2.2.tar.gz
/cli-28.3.0-vendor.tar.bz2
/cli-28.3.0.tar.gz
/moby-28.3.0-vendor.tar.bz2
/moby-28.3.0.tar.gz
/cli-28.3.1.tar.gz
/cli-28.3.1-vendor.tar.bz2
/moby-28.3.1.tar.gz
/moby-28.3.1-vendor.tar.bz2
/cli-28.3.2.tar.gz
/cli-28.3.2-vendor.tar.bz2
/moby-28.3.2.tar.gz
/moby-28.3.2-vendor.tar.bz2
/cli-28.3.3.tar.gz
/cli-28.3.3-vendor.tar.bz2
/moby-28.3.3.tar.gz
/moby-28.3.3-vendor.tar.bz2
/cli-28.4.0.tar.gz
/cli-28.4.0-vendor.tar.bz2
/moby-28.4.0.tar.gz
/moby-28.4.0-vendor.tar.bz2
/cli-28.5.1.tar.gz
/cli-28.5.1-vendor.tar.bz2
/moby-28.5.1.tar.gz
/moby-28.5.1-vendor.tar.bz2
/cli-28.5.2-vendor.tar.bz2
/moby-28.5.2-vendor.tar.bz2
/cli-28.5.2.tar.gz
/moby-28.5.2.tar.gz
/cli-29.0.0-vendor.tar.bz2
/moby-docker-v29.0.0.tar.gz
/moby-docker-v29.0.0-vendor.tar.bz2
/cli-29.0.0.tar.gz
/cli-29.0.1-vendor.tar.bz2
/cli-29.0.1.tar.gz
/moby-docker-v29.0.1.tar.gz
/moby-docker-v29.0.1-vendor.tar.bz2
/cli-29.0.2.tar.gz
/cli-29.0.2-vendor.tar.bz2
/moby-docker-v29.0.2.tar.gz
/moby-docker-v29.0.2-vendor.tar.bz2
/moby-docker-v29.0.3.tar.gz
/moby-docker-v29.0.3-vendor.tar.bz2
/cli-29.0.3.tar.gz
/cli-29.0.3-vendor.tar.bz2
/cli-29.0.4.tar.gz
/cli-29.0.4-vendor.tar.bz2
/moby-docker-v29.0.4.tar.gz
/moby-docker-v29.0.4-vendor.tar.bz2
/cli-29.1.2-vendor.tar.bz2
/cli-29.1.2.tar.gz
/moby-docker-v29.1.2-vendor.tar.bz2
/moby-docker-v29.1.2.tar.gz
/cli-29.1.3-vendor.tar.bz2
/cli-29.1.3.tar.gz
/moby-docker-v29.1.3-vendor.tar.bz2
/moby-docker-v29.1.3.tar.gz
/cli-29.1.4.tar.gz
/cli-29.1.4-vendor.tar.bz2
/moby-docker-v29.1.4.tar.gz
/moby-docker-v29.1.4-vendor.tar.bz2

View file

@ -1,34 +0,0 @@
From 5b6aae1885d02aa0a1ab0846834b86d87c989b79 Mon Sep 17 00:00:00 2001
From: Maxwell G <maxwell@gtmx.me>
Date: Fri, 15 Mar 2024 00:28:34 +0000
Subject: [PATCH] systemd: adjust docker.service for downstream
For now, we just enable selinux support and hardcode the paths for
docker-proxy and docker-init.
For `--init-path`, we use the tini-static binary directly instead of
bundling tini in this package.
---
contrib/init/systemd/docker.service | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/contrib/init/systemd/docker.service b/contrib/init/systemd/docker.service
index d8c7867..e305616 100644
--- a/contrib/init/systemd/docker.service
+++ b/contrib/init/systemd/docker.service
@@ -10,7 +10,12 @@ Type=notify
# the default is not to use systemd for cgroups because the delegate issues still
# exists and systemd currently does not support the cgroup feature set required
# for containers run by docker
-ExecStart=/usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock
+ExecStart=/usr/bin/dockerd \
+ -H fd:// \
+ --containerd=/run/containerd/containerd.sock \
+ --selinux-enabled \
+ --userland-proxy-path /usr/bin/docker-proxy \
+ --init-path /usr/bin/tini-static
ExecReload=/bin/kill -s HUP $MAINPID
TimeoutStartSec=0
RestartSec=2
--
2.44.0

View file

@ -1,10 +0,0 @@
MIT License
Copyright (C) 2024 Maxwell G <maxwell@gtmx.me>
Copyright (C) Fedora Project Authors
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

View file

@ -1,33 +1,3 @@
# moby-engine
The moby-engine package
## Maintainer notes
Follow these steps to build this package.
1. Use your favorite git client to check out the repository if not already present.
```
fedpkg clone moby-engine
```
1. Update the `%version0` macro in `moby-engine.spec` to the target version
using your preferred text editor.
```
vim moby-engine.spec
```
1. Run `./mkvendor.sh` to download upstream source files and generate vendor archives.
```
./mkvendor.sh
```
1. Build and test the package locally.
```
# fedpkg mockbuild example
fedpkg --release rawhide mockbuild
```
The moby-engine package

277
changelog
View file

@ -1,277 +0,0 @@
* Thu Jul 18 2024 Fedora Release Engineering <releng@fedoraproject.org>
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Sun Feb 11 2024 Maxwell G <maxwell@gtmx.me> - 24.0.5-4
- Rebuild for golang 1.22.0
* Thu Jan 25 2024 Fedora Release Engineering <releng@fedoraproject.org>
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Jan 21 2024 Fedora Release Engineering <releng@fedoraproject.org>
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Wed Aug 23 2023 LuK1337 <priv.luk@gmail.com> - 24.0.5-1
- Update moby-engine to 24.0.5
* Thu Jul 20 2023 Fedora Release Engineering <releng@fedoraproject.org>
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Sun Jan 29 2023 John Ghatas <john@johnghatas.com>
- Update moby-engine to 23.0.4
* Sun Jan 29 2023 Sérgio Basto <sergio@serjux.com>
- Update moby-engine to 20.10.23
* Thu Jan 19 2023 Fedora Release Engineering <releng@fedoraproject.org>
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Sun Jan 01 2023 Sérgio Basto <sergio@serjux.com>
- Update moby-engine to 20.10.22
* Wed Dec 14 2022 Dan Čermák <dan.cermak@cgc-instruments.com> - 20.10.21-1
- Update to 20.10.21
- Fix build, use libnetwork from golang-github-docker-0:22.06.0~beta
* Thu Oct 20 2022 Jan Kuparinen <copperi@fedoraproject.org> - 20.10.20-1
- Update to 20.10.20.
- Mitigates CVE-2022-39253
* Tue Oct 18 2022 Jan Kuparinen <copperi@fedoraproject.org> - 20.10.19-1
- Update to 20.10.19.
* Sat Sep 10 2022 Maxwell G <gotmax@e.email> - 20.10.18-1
- Update to 20.10.18.
- Mitigates CVE-2022-36109 / GHSA-rc4r-wh2q-q6c4
* Tue Aug 30 2022 Luca BRUNO <lucab@lucabruno.net> - 20.10.17-8
- Move 'docker' group creation logic to a sysusers.d fragment
Resolves: rhbz#1745936
* Fri Aug 05 2022 Maxwell G <gotmax@e.email> - 20.10.17-7
- Migrate to SPDX license identifiers
- Generate debuginfo
- Specfile improvements
* Thu Jul 21 2022 Fedora Release Engineering <releng@fedoraproject.org>
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Tue Jul 19 2022 Maxwell G <gotmax@e.email> - 20.10.17-5
- Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in
golang
* Mon Jul 04 2022 Maxwell G <gotmax@e.email> - 20.10.17-4
- Only build on %%golang_arches (i.e. where golang is available).
* Sun Jun 19 2022 Maxwell G <gotmax@e.email> - 20.10.17-3
- Rebuilt for CVE-2022-1996, CVE-2022-24675, CVE-2022-28327, CVE-2022-27191,
CVE-2022-29526, CVE-2022-30629.
* Sat Jun 11 2022 Maxwell G <gotmax@e.email> - 20.10.17-2
- Rebuild for new golang-github-docker-libnetwork
* Fri Jun 10 2022 Maxwell G <gotmax@e.email> - 20.10.17-1
- Update to 20.10.17. Fixes rhbz#2095714.
* Fri May 13 2022 Maxwell G <gotmax@e.email> - 20.10.16-1
- Update to 20.10.16.
* Sat May 07 2022 Maxwell G <gotmax@e.email> - 20.10.15-1
- Update to 20.10.15 (rhbz#2082501).
- Fix BUILDTAGS (rhbz#2082924).
- Make non-binary subpackages noarch.
* Mon Apr 11 2022 Maxwell G <gotmax@e.email> - 20.10.14-1
- Update to 20.10.14. Fixes rhbz#2063052.
- Mitigate CVE-2022-24769.
* Mon Jan 31 2022 Maxwell G <gotmax@e.email> - 20.10.12-3
- Fixes FTBFS. Closes rhbz#2046748.
- Use %%gobuild instead of Makefile to build binaries
- Add explanatory comments.
- Normalize install commands
- Make compliant with SourceURL Guidelines
- Remove no longer necessary `ExcludeArch: ppc64`.
* Thu Jan 20 2022 Fedora Release Engineering <releng@fedoraproject.org> - 20.10.12-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Tue Jan 11 2022 Maxwell G <gotmax@e.email> - 20.10.12-1
- Update to 20.10.12. Fixes rhbz#2032534.
- Install zsh completions to the correct directory. Fixes rhbz#2038888.
* Mon Nov 22 2021 Olivier Lemasle <o.lemasle@gmail.com> - 20.10-11-1
- Update to upstream 20.10.11 (fixes rhbz#2024384)
- Mitigates CVE-2021-41190 (fixes rhbz#2024940)
* Fri Oct 29 2021 Maxwell G <gotmax@e.email> - 20.10.10-1
- Update to 20.10.10 (fixes rhbz#2015385)
- Update virtual provides
* Fri Oct 08 2021 Maxwell G <gotmax@e.email> - 20.10.9-1
- Update to 20.10.9 (fixes rhbz#2010508)
- Patch seccomp policy to fix clone3() issue (fixes rhbz#2011523 and rhbz#1988199)
* Sun Aug 15 2021 Olivier Lemasle <o.lemasle@gmail.com> - 20.10.8-1
- Update to upstream 20.10.8 (fixes rhbz#1990148)
- Fix seccomp support (fixes rhbz#1986092)
* Sun Aug 15 2021 Dusty Mabe <dusty@dustymabe.com> - 20.10.7-3
- Remove `Requires(post)` on firewalld-filesystem.
* Thu Jul 22 2021 Fedora Release Engineering <releng@fedoraproject.org> - 20.10.7-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Fri Jul 16 2021 Olivier Lemasle <o.lemasle@gmail.com> - 20.10.7-1
- Update to upstream 20.10.7 (fixes rhbz#1967390)
* Tue May 04 2021 Olivier Lemasle <o.lemasle@gmail.com> - 20.10.6-2
- Add conflict with podman-docker
* Tue Apr 20 2021 Olivier Lemasle <o.lemasle@gmail.com> - 20.10.6-1
- Update to upstream 20.10.6 (#1948605)
- Re-bundle moby dependencies to fix gRPC issues with Swarm
(https://github.com/coreos/fedora-coreos-tracker/issues/793)
* Sun Mar 14 2021 Olivier Lemasle <o.lemasle@gmail.com> - 20.10.5-1
- Update to latest upstream 20.10.5 - fixes #1903426
- Upstream brings compatibility with cgroups v2 - fixes #1746355
- Remove package moby-engine-vim (dockerfile.vim has been merged in upstream vim)
- Remove firewalld docker zone, since dockerd can now communicate with firewalld - fixes #1852680
- Build dockerd and docker-proxy from unbundled source packages
- Remove fixed storage-driver (cf. https://src.fedoraproject.org/rpms/moby-engine/pull-request/6)
* Tue Mar 02 2021 Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> - 19.03.13-3.ce.git4484c46
- Rebuilt for updated systemd-rpm-macros
See https://pagure.io/fesco/issue/2583.
* Tue Jan 26 2021 Fedora Release Engineering <releng@fedoraproject.org> - 19.03.13-2.ce.git4484c46
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
* Fri Oct 02 2020 Olivier Lemasle <o.lemasle@gmail.com> - 19.03.13-1.ce.git4484c46
- Update to upstream 19.03.13 (#1837641)
* Fri Oct 02 2020 Olivier Lemasle <o.lemasle@gmail.com> - 19.03.11-4.ce.git42e35e6
- Fix FTBFS: adapt to change to CMake builds (#1864160)
* Sat Aug 01 2020 Fedora Release Engineering <releng@fedoraproject.org> - 19.03.11-3.ce.git42e35e6
- Second attempt - Rebuilt for
https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Tue Jul 28 2020 Fedora Release Engineering <releng@fedoraproject.org> - 19.03.11-2.ce.git42e35e6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Sun Jun 07 2020 Olivier Lemasle <o.lemasle@gmail.com> - 19.03.11-1.ce.git42e35e6
- Update to upstream 19.03.11 to prevent CVE-2020-13401
* Thu May 07 2020 Olivier Lemasle <o.lemasle@gmail.com> - 19.03.8-2.ce.gitafacb8b
- Configure storage-driver explicitely (fixes #1832301)
- Add firewalld zone: trust interface docker0, as firewalld now uses nftables
by default and docker communicates with iptables (fixes #1817022)
* Mon Mar 16 2020 Olivier Lemasle <o.lemasle@gmail.com> - 19.03.8-1.ce.gitafacb8b
- Update to latest upstream release - Docker CE 19.03.8
- Prune unused BuildRequires
* Sun Mar 8 2020 Olivier Lemasle <o.lemasle@gmail.com> - 19.03.7-2.ce.git7141c19
- Add Conflicts with docker-ce-cli and Obsoletes docker-common
* Sat Mar 7 2020 Olivier Lemasle <o.lemasle@gmail.com> - 19.03.7-1.ce.git7141c19
- Update to latest upstream release - Docker CE 19.03.7
- Add Epoch: 2 to Obsoletes for docker and docker-latest
* Wed Jan 29 2020 Fedora Release Engineering <releng@fedoraproject.org> - 18.09.8-3.ce.git0dd43dd
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
* Thu Jul 25 2019 Fedora Release Engineering <releng@fedoraproject.org> - 18.09.8-2.ce.git0dd43dd
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Thu Jul 18 2019 Olivier Lemasle <o.lemasle@gmail.com> - 18.09.8-1.ce.git0dd43dd
- Update to latest upstream release - Docker CE 18.09.8
* Sat Jul 13 2019 Olivier Lemasle <o.lemasle@gmail.com> - 18.09.7-5.ce.git2d0083d
- Move docker-init and docker-proxy to /usr/libexec/docker
- Update moby-engine-nano summary to follow guidelines
* Sat Jul 13 2019 Olivier Lemasle <o.lemasle@gmail.com> - 18.09.7-4.ce.git2d0083d
- Add nofile ulimit to default docker daemon options (#1715254, #1708115)
* Fri Jul 12 2019 Olivier Lemasle <o.lemasle@gmail.com> - 18.09.7-3.ce.git2d0083d
- rebuilt
* Fri Jul 12 2019 Olivier Lemasle <o.lemasle@gmail.com> - 18.09.7-2.ce.git2d0083d
- Depend on packaged versions "runc" and "containerd" instead of building them.
* Thu Jun 27 2019 David Michael <dm0@redhat.com> - 18.09.7-1.ce.git2d0083d
- Update docker-ce to commit 2d0083d (version 18.09.7).
- Update runc to commit 425e105.
- Update containerd to commit 894b81a (1.2.6).
- Update docker-proxy to commit e7933d4.
* Tue May 14 2019 David Michael <dm0@redhat.com> - 18.09.6-1.ce.git481bc77
- Update docker-ce to commit 481bc77 (version 18.09.6).
- Update docker-proxy to commit 872f0a8.
- Obsolete and provide the docker and docker-latest packages. (#1700006)
* Thu Apr 11 2019 David Michael <dm0@redhat.com> - 18.09.5-1.ce.gite8ff056
- Update docker-ce to commit e8ff056 (version 18.09.5).
- Update docker-runc to commit 2b18fe1.
- Update docker-containerd to commit bb71b10 (version 1.2.5).
- Update docker-proxy to commit 4725f21.
- Report the correct engine version.
- Install symlinks to unprefixed runc/containerd program names.
* Thu Mar 28 2019 David Michael <dm0@redhat.com> - 18.06.3-2.ce.gitd7080c1
- Conflict with docker-common. (#1693397)
* Thu Feb 21 2019 David Michael <dm0@redhat.com> - 18.06.3-1.ce.gitd7080c1
- Update docker-ce to commit d7080c1 (version 18.06.3).
* Tue Feb 12 2019 David Michael <dm0@redhat.com> - 18.06.2-1.ce.git6d37f41
- Update docker-ce to commit 6d37f41 (version 18.06.2).
- Update docker-runc to commit a592beb.
* Mon Feb 11 2019 David Michael <dm0@redhat.com> - 18.06.1-3.ce.gite68fc7a
- Apply a runc patch for CVE-2019-5736.
* Fri Feb 01 2019 Fedora Release Engineering <releng@fedoraproject.org> - 18.06.1-2.ce.gite68fc7a
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Thu Nov 29 2018 David Michael <dm0@redhat.com> - 18.06.1-1.ce.gite68fc7a
- Update docker-ce to commit e68fc7a (version 18.06.1).
- Update docker-runc to commit 69663f0.
- Update docker-containerd to commit 468a545 (version 1.1.2).
- Update docker-proxy to commit 3ac297b.
- Backport a fix for mounting named volumes.
- Create a "docker" group for non-root Docker access.
- Support systemd socket-activation.
- Make runc and containerd commit IDs match their expected values.
- Preserve containerd debuginfo.
* Mon Nov 12 2018 Marcin Skarbek <rpm@skarbek.name> - 18.06.0-2.ce.git0ffa825
- add configuration file
- update service file
* Sat Aug 18 2018 Lokesh Mandvekar <lsm5@fedoraproject.org> - 18.06.0-1.ce.git0ffa825
- Resolves: #1539161 - first upload to Fedora
- built docker-ce commit 0ffa825
- built docker-runc commit ad0f5255
- built docker-containerd commit a88b631
- built docker-proxy commit a79d368
- built docker-init commit fec3683
* Tue Mar 20 2018 Lokesh Mandvekar <lsm5@fedoraproject.org> - 17.03.2-4.ce.gitf5ec1e2
- correct some rpmlint errors
* Wed Feb 21 2018 Lokesh Mandvekar <lsm5@fedoraproject.org> - 17.03.2-3.ce
- docker-* symlinks to moby-* (RE: gh PR 34226)
* Wed Feb 21 2018 Lokesh Mandvekar <lsm5@fedoraproject.org> - 17.03.2-2.ce
- rename binaries as per upstream gh PR 34226
* Fri Jan 26 2018 Lokesh Mandvekar <lsm5@fedoraproject.org> - 17.03.2-1
- initial build
- built moby commit f5ec1e2
- built cli commit 4b61f56
- built docker-runc commit 2d41c047
- built docker-containerd commit 3addd84
- built docker-proxy commit 7b2b1fe

View file

@ -1,28 +0,0 @@
[licensing]
detector = "trivy"
exclude_files = [
"vendor/go.opentelemetry.io/otel/get_main_pkgs.sh",
"vendor/go.opentelemetry.io/otel/verify_examples.sh",
"vendor/google.golang.org/grpc/regenerate.sh",
]
[[licensing.licenses]]
path = "vendor/github.com/google/shlex/COPYING"
sha256sum = "cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30"
expression = "Apache-2.0"
[[licensing.licenses]]
path = "vendor/github.com/moby/sys/symlink/LICENSE.APACHE"
sha256sum = "e6abacaae15d29c132fc8688f098a3b9c89088bc434ea33992261e19e34e6723"
expression = "Apache-2.0"
[[licensing.licenses]]
path = "vendor/github.com/moby/sys/symlink/LICENSE.BSD"
sha256sum = "81205fa54813e578a0d361c671c21ae35ca5b1b575f39e82f5cdab68b8539a1d"
expression = "BSD-3-Clause"
[archive]
pre_commands = [
# This project has a setup where go.mod and go.sum are not always present.
# We write those files manually.
["cp", "-p", "vendor.mod", "go.mod"],
["cp", "-p", "vendor.sum", "go.sum"],
]

View file

@ -1,56 +0,0 @@
[licensing]
detector = "trivy"
exclude_files = [
"vendor/go.opentelemetry.io/otel/get_main_pkgs.sh",
"vendor/go.opentelemetry.io/otel/verify_examples.sh",
"vendor/google.golang.org/grpc/regenerate.sh",
"LICENSE.macros",
]
[[licensing.licenses]]
path = "vendor/github.com/google/shlex/COPYING"
sha256sum = "cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30"
expression = "Apache-2.0"
[[licensing.licenses]]
path = "vendor/github.com/spdx/tools-golang/LICENSE.code"
sha256sum = "e914fb1f3927226e04b0438e0b541b3c6e3c65de4d64aa8f5cdaa803f05448fd"
expression = "Apache-2.0 OR GPL-2.0-or-later"
[[licensing.licenses]]
path = "internal/test/suite/testify.LICENSE"
sha256sum = "dad2b0b2cc2dbdbf95ad5d800ef7588956e74dc2479014829d42be295125c25d"
expression = "MIT"
[[licensing.licenses]]
path = "vendor/github.com/miekg/dns/COPYRIGHT"
sha256sum = "66550c0ad5ca7ec1e08683e5f872cc45c741f311eee3b8ee484206ecbf9c740d"
expression = "BSD-3-Clause"
[[licensing.licenses]]
path = "vendor/github.com/moby/sys/symlink/LICENSE.APACHE"
sha256sum = "e6abacaae15d29c132fc8688f098a3b9c89088bc434ea33992261e19e34e6723"
expression = "Apache-2.0"
[[licensing.licenses]]
path = "vendor/github.com/moby/sys/symlink/LICENSE.BSD"
sha256sum = "81205fa54813e578a0d361c671c21ae35ca5b1b575f39e82f5cdab68b8539a1d"
expression = "BSD-3-Clause"
[[licensing.licenses]]
path = "vendor/github.com/shibumi/go-pathspec/GO-LICENSE"
sha256sum = "dd26a7abddd02e2d0aba97805b31f248ef7835d9e10da289b22e3b8ab78b324d"
expression = "BSD-3-Clause"
[[licensing.licenses]]
path = "vendor/cyphar.com/go-pathrs/COPYING"
sha256sum = "3f3d9e0024b1921b067d6f7f88deb4a60cbe7a78e76c64e3f1d7fc3b779b9d04"
expression = "MPL-2.0"
[[licensing.licenses]]
path = "vendor/github.com/cyphar/filepath-securejoin/LICENSE.BSD"
sha256sum = "26be8a79415737dfe8edf1be62e71afeb8c770ed5a5605a06270d5701830f47c"
expression = "BSD-3-Clause"
[[licensing.licenses]]
path = "vendor/github.com/cyphar/filepath-securejoin/LICENSE.MPL-2.0"
sha256sum = "3f3d9e0024b1921b067d6f7f88deb4a60cbe7a78e76c64e3f1d7fc3b779b9d04"
expression = "BSD-3-Clause"
[[licensing.licenses]]
path = "vendor/go.yaml.in/yaml/v2/LICENSE.libyaml"
sha256sum = "a94710b55e03b5285f77d048c5ba61bb9d6ee04a06c0eb90e68821e11b0c707a"
expression = "MIT"
[archive]
[archive.dependency_overrides]
"github.com/moby/policy-helpers" = "v0.0.0-20251120141729-4dd138b40f3e"

View file

@ -1,5 +0,0 @@
# Copyright (C) 2024 Maxwell G <maxwell@gtmx.me>
# Copyright (C) Fedora Project Authors
# SPDX-License-Identifier: MIT
%moby_cli_plugins_dir %{_libexecdir}/docker/cli-plugins

View file

@ -1,41 +0,0 @@
#!/bin/bash
# Copyright (C) 2024 Maxwell G <maxwell@gtmx.me>
# SPDX-License-Identifier: MIT
set -euo pipefail
# Source0: %{gosource0}
# Source1: %{archivename0}-vendor.tar.bz2
# Source2: %{gosource2}
# Source3: %{archivename2}-vendor.tar.bz2
sources=()
while read -r source; do
filename="$(awk '{print $2}' <<< "${source}" | awk -F '/' '{print $NF}')"
sources+=( "${filename}" )
done < <(spectool --sources ./*.spec)
set -x
temp="$(mktemp -d)"
trap 'rm -rf $temp' EXIT
here="$(pwd)"
# Retrieve remote sources
spectool -g moby-engine.spec
# (re)create vendor archives
config="${here}/engine_go-vendor-tools.toml"
go_vendor_archive create --config "${config}" --idempotent \
--output "${sources[1]}" "${sources[0]}"
go_vendor_license --config "${config}" --path "moby-engine.spec" \
report expression --update-spec
config="${here}/cli_go-vendor-tools.toml"
go_vendor_archive create --config "${config}" --idempotent \
--output "${sources[3]}" "${sources[2]}"
mkdir -p "${temp}/cli"
cd "${temp}/cli"
tar xf "${here}/${sources[2]}"
cd ./*
tar xf "${here}/${sources[3]}"
expr="$(go_vendor_license --config "${config}" --path "." report expression)"
sed -i -E "s|(\%global cli_license).*|\1 ${expr}|" "${here}/moby-engine.spec"

View file

@ -0,0 +1,337 @@
From 2d069bb79260e594870ce3e7466477e54a0c5307 Mon Sep 17 00:00:00 2001
From: Aleksa Sarai <asarai@suse.de>
Date: Wed, 9 Jan 2019 13:40:01 +1100
Subject: [PATCH] nsenter: clone /proc/self/exe to avoid exposing host binary
to container
There are quite a few circumstances where /proc/self/exe pointing to a
pretty important container binary is a _bad_ thing, so to avoid this we
have to make a copy (preferably doing self-clean-up and not being
writeable).
We require memfd_create(2) -- though there is an O_TMPFILE fallback --
but we can always extend this to use a scratch MNT_DETACH overlayfs or
tmpfs. The main downside to this approach is no page-cache sharing for
the runc binary (which overlayfs would give us) but this is far less
complicated.
This is only done during nsenter so that it happens transparently to the
Go code, and any libcontainer users benefit from it. This also makes
ExtraFiles and --preserve-fds handling trivial (because we don't need to
worry about it).
Fixes: CVE-2019-5736
Co-developed-by: Christian Brauner <christian.brauner@ubuntu.com>
Signed-off-by: Aleksa Sarai <asarai@suse.de>
---
libcontainer/nsenter/cloned_binary.c | 268 +++++++++++++++++++++++++++
libcontainer/nsenter/nsexec.c | 11 ++
2 files changed, 279 insertions(+)
create mode 100644 libcontainer/nsenter/cloned_binary.c
diff --git a/libcontainer/nsenter/cloned_binary.c b/libcontainer/nsenter/cloned_binary.c
new file mode 100644
index 000000000000..c8a42c23f73f
--- /dev/null
+++ b/libcontainer/nsenter/cloned_binary.c
@@ -0,0 +1,268 @@
+/*
+ * Copyright (C) 2019 Aleksa Sarai <cyphar@cyphar.com>
+ * Copyright (C) 2019 SUSE LLC
+ *
+ * Licensed under the Apache License, Version 2.0 (the "License");
+ * you may not use this file except in compliance with the License.
+ * You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+
+#define _GNU_SOURCE
+#include <unistd.h>
+#include <stdio.h>
+#include <stdlib.h>
+#include <stdbool.h>
+#include <string.h>
+#include <limits.h>
+#include <fcntl.h>
+#include <errno.h>
+
+#include <sys/types.h>
+#include <sys/stat.h>
+#include <sys/vfs.h>
+#include <sys/mman.h>
+#include <sys/sendfile.h>
+#include <sys/syscall.h>
+
+/* Use our own wrapper for memfd_create. */
+#if !defined(SYS_memfd_create) && defined(__NR_memfd_create)
+# define SYS_memfd_create __NR_memfd_create
+#endif
+#ifdef SYS_memfd_create
+# define HAVE_MEMFD_CREATE
+/* memfd_create(2) flags -- copied from <linux/memfd.h>. */
+# ifndef MFD_CLOEXEC
+# define MFD_CLOEXEC 0x0001U
+# define MFD_ALLOW_SEALING 0x0002U
+# endif
+int memfd_create(const char *name, unsigned int flags)
+{
+ return syscall(SYS_memfd_create, name, flags);
+}
+#endif
+
+/* This comes directly from <linux/fcntl.h>. */
+#ifndef F_LINUX_SPECIFIC_BASE
+# define F_LINUX_SPECIFIC_BASE 1024
+#endif
+#ifndef F_ADD_SEALS
+# define F_ADD_SEALS (F_LINUX_SPECIFIC_BASE + 9)
+# define F_GET_SEALS (F_LINUX_SPECIFIC_BASE + 10)
+#endif
+#ifndef F_SEAL_SEAL
+# define F_SEAL_SEAL 0x0001 /* prevent further seals from being set */
+# define F_SEAL_SHRINK 0x0002 /* prevent file from shrinking */
+# define F_SEAL_GROW 0x0004 /* prevent file from growing */
+# define F_SEAL_WRITE 0x0008 /* prevent writes */
+#endif
+
+#define RUNC_SENDFILE_MAX 0x7FFFF000 /* sendfile(2) is limited to 2GB. */
+#ifdef HAVE_MEMFD_CREATE
+# define RUNC_MEMFD_COMMENT "runc_cloned:/proc/self/exe"
+# define RUNC_MEMFD_SEALS \
+ (F_SEAL_SEAL | F_SEAL_SHRINK | F_SEAL_GROW | F_SEAL_WRITE)
+#endif
+
+static void *must_realloc(void *ptr, size_t size)
+{
+ void *old = ptr;
+ do {
+ ptr = realloc(old, size);
+ } while(!ptr);
+ return ptr;
+}
+
+/*
+ * Verify whether we are currently in a self-cloned program (namely, is
+ * /proc/self/exe a memfd). F_GET_SEALS will only succeed for memfds (or rather
+ * for shmem files), and we want to be sure it's actually sealed.
+ */
+static int is_self_cloned(void)
+{
+ int fd, ret, is_cloned = 0;
+
+ fd = open("/proc/self/exe", O_RDONLY|O_CLOEXEC);
+ if (fd < 0)
+ return -ENOTRECOVERABLE;
+
+#ifdef HAVE_MEMFD_CREATE
+ ret = fcntl(fd, F_GET_SEALS);
+ is_cloned = (ret == RUNC_MEMFD_SEALS);
+#else
+ struct stat statbuf = {0};
+ ret = fstat(fd, &statbuf);
+ if (ret >= 0)
+ is_cloned = (statbuf.st_nlink == 0);
+#endif
+ close(fd);
+ return is_cloned;
+}
+
+/*
+ * Basic wrapper around mmap(2) that gives you the file length so you can
+ * safely treat it as an ordinary buffer. Only gives you read access.
+ */
+static char *read_file(char *path, size_t *length)
+{
+ int fd;
+ char buf[4096], *copy = NULL;
+
+ if (!length)
+ return NULL;
+
+ fd = open(path, O_RDONLY | O_CLOEXEC);
+ if (fd < 0)
+ return NULL;
+
+ *length = 0;
+ for (;;) {
+ int n;
+
+ n = read(fd, buf, sizeof(buf));
+ if (n < 0)
+ goto error;
+ if (!n)
+ break;
+
+ copy = must_realloc(copy, (*length + n) * sizeof(*copy));
+ memcpy(copy + *length, buf, n);
+ *length += n;
+ }
+ close(fd);
+ return copy;
+
+error:
+ close(fd);
+ free(copy);
+ return NULL;
+}
+
+/*
+ * A poor-man's version of "xargs -0". Basically parses a given block of
+ * NUL-delimited data, within the given length and adds a pointer to each entry
+ * to the array of pointers.
+ */
+static int parse_xargs(char *data, int data_length, char ***output)
+{
+ int num = 0;
+ char *cur = data;
+
+ if (!data || *output != NULL)
+ return -1;
+
+ while (cur < data + data_length) {
+ num++;
+ *output = must_realloc(*output, (num + 1) * sizeof(**output));
+ (*output)[num - 1] = cur;
+ cur += strlen(cur) + 1;
+ }
+ (*output)[num] = NULL;
+ return num;
+}
+
+/*
+ * "Parse" out argv and envp from /proc/self/cmdline and /proc/self/environ.
+ * This is necessary because we are running in a context where we don't have a
+ * main() that we can just get the arguments from.
+ */
+static int fetchve(char ***argv, char ***envp)
+{
+ char *cmdline = NULL, *environ = NULL;
+ size_t cmdline_size, environ_size;
+
+ cmdline = read_file("/proc/self/cmdline", &cmdline_size);
+ if (!cmdline)
+ goto error;
+ environ = read_file("/proc/self/environ", &environ_size);
+ if (!environ)
+ goto error;
+
+ if (parse_xargs(cmdline, cmdline_size, argv) <= 0)
+ goto error;
+ if (parse_xargs(environ, environ_size, envp) <= 0)
+ goto error;
+
+ return 0;
+
+error:
+ free(environ);
+ free(cmdline);
+ return -EINVAL;
+}
+
+static int clone_binary(void)
+{
+ int binfd, memfd;
+ ssize_t sent = 0;
+
+#ifdef HAVE_MEMFD_CREATE
+ memfd = memfd_create(RUNC_MEMFD_COMMENT, MFD_CLOEXEC | MFD_ALLOW_SEALING);
+#else
+ memfd = open("/tmp", O_TMPFILE | O_EXCL | O_RDWR | O_CLOEXEC, 0711);
+#endif
+ if (memfd < 0)
+ return -ENOTRECOVERABLE;
+
+ binfd = open("/proc/self/exe", O_RDONLY | O_CLOEXEC);
+ if (binfd < 0)
+ goto error;
+
+ sent = sendfile(memfd, binfd, NULL, RUNC_SENDFILE_MAX);
+ close(binfd);
+ if (sent < 0)
+ goto error;
+
+#ifdef HAVE_MEMFD_CREATE
+ int err = fcntl(memfd, F_ADD_SEALS, RUNC_MEMFD_SEALS);
+ if (err < 0)
+ goto error;
+#else
+ /* Need to re-open "memfd" as read-only to avoid execve(2) giving -EXTBUSY. */
+ int newfd;
+ char *fdpath = NULL;
+
+ if (asprintf(&fdpath, "/proc/self/fd/%d", memfd) < 0)
+ goto error;
+ newfd = open(fdpath, O_RDONLY | O_CLOEXEC);
+ free(fdpath);
+ if (newfd < 0)
+ goto error;
+
+ close(memfd);
+ memfd = newfd;
+#endif
+ return memfd;
+
+error:
+ close(memfd);
+ return -EIO;
+}
+
+int ensure_cloned_binary(void)
+{
+ int execfd;
+ char **argv = NULL, **envp = NULL;
+
+ /* Check that we're not self-cloned, and if we are then bail. */
+ int cloned = is_self_cloned();
+ if (cloned > 0 || cloned == -ENOTRECOVERABLE)
+ return cloned;
+
+ if (fetchve(&argv, &envp) < 0)
+ return -EINVAL;
+
+ execfd = clone_binary();
+ if (execfd < 0)
+ return -EIO;
+
+ fexecve(execfd, argv, envp);
+ return -ENOEXEC;
+}
diff --git a/libcontainer/nsenter/nsexec.c b/libcontainer/nsenter/nsexec.c
index 28269dfc027f..7750af35ea92 100644
--- a/libcontainer/nsenter/nsexec.c
+++ b/libcontainer/nsenter/nsexec.c
@@ -534,6 +534,9 @@ void join_namespaces(char *nslist)
free(namespaces);
}
+/* Defined in cloned_binary.c. */
+extern int ensure_cloned_binary(void);
+
void nsexec(void)
{
int pipenum;
@@ -549,6 +552,14 @@ void nsexec(void)
if (pipenum == -1)
return;
+ /*
+ * We need to re-exec if we are not in a cloned binary. This is necessary
+ * to ensure that containers won't be able to access the host binary
+ * through /proc/self/exe. See CVE-2019-5736.
+ */
+ if (ensure_cloned_binary() < 0)
+ bail("could not ensure we are a cloned binary");
+
/* Parse all of the netlink configuration. */
nl_parse(pipenum, &config);
--
2.20.1

View file

@ -1,2 +0,0 @@
#Type Name ID
g docker -

View file

@ -1,391 +1,353 @@
# This specfile is licensed under:
# SPDX-FileCopyrightText: Fedora Project Authors
# SPDX-FileCopyrightText: 2024 Maxwell G <maxwell@gtmx.me>
# SPDX-License-Identifier: MIT
# License Text: https://spdx.org/licenses/MIT.html
%global with_debug 0
# Generated by go2rpm 1.11.0
%bcond_without check
%if 0%{?with_debug}
%global _find_debuginfo_dwz_opts %{nil}
%global _dwz_low_mem_die_limit 0
%else
%global debug_package %{nil}
%endif
# https://github.com/moby/moby
%global goipath0 github.com/moby/moby
# For rc, beta, alpha releases substitute tilde (~) for dash (-)
# in version0. tag0 reverses the substitution
# e.g. global version0 27.4.0~rc.4
%global version0 29.1.4
%{lua:
local version0 = rpm.expand("%{version0}"):gsub("~", "-")
rpm.define("tag0 " .. "docker-v" .. version0)
rpm.define("distprefix0 %{nil}")
rpm.define("tag2 " .. "v" .. version0)
}
# binaries and unitfiles are currently called 'docker'
# to match with upstream supplied packages
%global origname docker
%global newname moby
%global service_name %{origname}
# https://github.com/docker/cli
%global goipath2 github.com/docker/cli
%global version2 %{version0}
# moby / docker-ce / cli
%global git_moby https://github.com/%{service_name}/%{service_name}-ce
%global commit_moby 0ffa8257ec673ed6849b73b03fb01b0cac90fdb3
%global shortcommit_moby %(c=%{commit_moby}; echo ${c:0:7})
%gometa -L -a -f
%global engine_dir ../%{topdir0}
%global cli_dir ../%{topdir2}
# docker-runc
%global git_runc https://github.com/opencontainers/runc
%global commit_runc ad0f5255060d36872be04de22f8731f38ef2d7b1
%global shortcommit_runc %(c=%{commit_runc}; echo ${c:0:7})
%global common_description %{expand:
# docker-containerd
%global git_containerd https://github.com/containerd/containerd
%global commit_containerd a88b6319614de846458750ff882723479ca7b1a1
%global shortcommit_containerd %(c=%{commit_containerd}; echo ${c:0:7})
# docker-proxy / libnetwork
%global git_libnetwork https://github.com/%{service_name}/libnetwork
%global commit_libnetwork a79d3687931697244b8e03485bf7b2042f8ec6b6
%global shortcommit_libnetwork %(c=%{commit_libnetwork}; echo ${c:0:7})
# tini
%global git_tini https://github.com/krallin/tini
%global commit_tini fec3683b971d9c3ef73f284f176672c44b448662
%global shortcommit_tini %(c=%{commit_tini}; echo ${c:0:7})
Name: %{newname}-engine
Version: 18.06.0
Release: 2.ce.git%{shortcommit_moby}%{?dist}
Summary: The open-source application container engine
License: ASL 2.0
# no golang / go-md2man for ppc64
ExcludeArch: ppc64
Source0: %{git_moby}/archive/%{commit_moby}.tar.gz
Source1: %{git_runc}/archive/%{commit_runc}.tar.gz
Source2: %{git_containerd}/archive/%{commit_containerd}.tar.gz
Source3: %{git_libnetwork}/archive/%{commit_libnetwork}.tar.gz
Source4: %{git_tini}/archive/%{commit_tini}.tar.gz
Patch1: %{name}-%{version}-CVE-2019-5736.patch
URL: https://www.%{origname}.com
BuildRequires: btrfs-progs-devel
BuildRequires: cmake
BuildRequires: dep
BuildRequires: device-mapper-devel
BuildRequires: git
BuildRequires: glibc-static
BuildRequires: %{?go_compiler:compiler(go-compiler)}%{!?go_compiler:golang >= 1.6.2}
BuildRequires: go-md2man
BuildRequires: gpgme-devel
BuildRequires: libassuan-devel
BuildRequires: libseccomp-static >= 2.3.0
BuildRequires: libtool-ltdl-devel
BuildRequires: make
BuildRequires: pkgconfig(audit)
BuildRequires: pkgconfig(systemd)
BuildRequires: sed
BuildRequires: sqlite-devel
# required packages on install
Requires: container-selinux
Requires: iptables
Requires: systemd
Requires: tar
Requires: xz
Requires: pigz
# Resolves: rhbz#1165615
Requires: device-mapper-libs >= 1.02.90-1
# conflicting packages
Conflicts: %{origname}
Conflicts: %{origname}-io
Conflicts: %{origname}-engine-cs
Conflicts: %{origname}-ce
Conflicts: %{origname}-ee
%description
Docker is an open source project to build, ship and run any application as a
lightweight container.
Docker containers are both hardware-agnostic and platform-agnostic. This means
they can run anywhere, from your laptop to the largest EC2 compute instance and
everything in between and they do not require you to use a particular
everything in between - and they don't require you to use a particular
language, framework or packaging system. That makes them great building blocks
for deploying and scaling web apps, databases, and backend services without
depending on a particular stack or provider.
}
Name: moby-engine
Version: %{version0}
Release: %autorelease
Summary: The open-source application container engine
%package fish-completion
Summary: Fish completion files for %{name}
Requires: %{name} = %{version}-%{release}
Requires: fish
Conflicts: %{service_name}-fish-completion
# Generated with go-vendor-tools
License: Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND ISC AND MIT AND MPL-2.0 AND (Apache-2.0 OR GPL-2.0-or-later)
URL: %{gourl}
# We create our own vendor tarballs instead of using the built-in directoies.
# This allows us to include the manpage build dependencies for docker-cli
# and make any of our own changes to the deps included as necessary.
Source0: %{gosource0}
Source1: %{archivename0}-vendor.tar.bz2
Source2: %{gosource2}
Source3: %{archivename2}-vendor.tar.bz2
Source100: moby-engine-systemd-sysusers.conf
Source101: macros.moby
Source102: LICENSE.macros
Source200: engine_go-vendor-tools.toml
Source201: cli_go-vendor-tools.toml
# Patches 0-999 are for moby/moby
Patch0: 0001-systemd-adjust-docker.service-for-downstream.patch
# Patches 1000+ are for docker/cli
# Patch1000:
BuildRequires: git-core
BuildRequires: go-vendor-tools
BuildRequires: make
BuildRequires: pkg-config
BuildRequires: systemd-devel
BuildRequires: /usr/bin/go-md2man
BuildRequires: nftables-devel
# docker.service depends on containerd
Requires: containerd
# The docker CLI is provided as a separate package
Requires: docker-cli = %{version}-%{release}
# moby-filesystem owns the libexecdir/docker directory
Requires: moby-filesystem = %{version}-%{release}
# tini-static is used as the docker-init binary
Requires: tini-static
# Other runtime packages (sorted)
Requires: container-selinux
Requires: iptables
Requires: libseccomp
Requires: nftables
Requires: pigz
Requires: systemd
Requires: tar
Requires: xz
# Provide docker name to help users who "dnf install docker"
Provides: docker = %{version}-%{release}
# Conflict with upstream packages
Conflicts: docker-ce
Conflicts: docker-ee
%description %{common_description}
%package nano
Summary: GNU nano syntax highlighting files for Moby
BuildArch: noarch
Requires: nano
Supplements: moby-engine
%description nano %{common_description}
%description fish-completion
This package installs %{summary}.
%package vim
Summary: Vim syntax highlighting files for %{name}
Requires: %{name} = %{version}-%{release}
Requires: vim
Conflicts: %{service_name}-vim
# We name this package docker-cli, as that's the name of the upstream project.
# moby-engine is github.com/moby/moby.
%package -n docker-cli
Version: %{forgeversion -z1}
Summary: The Docker CLI
# Generated with go-vendor-tools
%global cli_license Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND MIT
License: %{cli_license}
Requires: moby-filesystem = %{version}-%{release}
# Recommend main moby-engine package with the docker daemon
# We don't use a strict dependency, as it's possible to use the docker CLI with
# a different host.
Recommends: moby-engine
# docker buildx is the new supported way to run builds; docker build is deprecated.
Recommends: docker-buildx
%description vim
This package installs %{summary}.
# Conflict with older moby-engine versions
Conflicts: moby-engine < %{version}-%{release}
Conflicts: moby-engine > %{version}-%{release}
%package zsh-completion
Summary: Zsh completion files for %{name}
Requires: %{name} = %{version}-%{release}
Requires: zsh
Conflicts: %{service_name}-zsh-completion
# Conflict with upstream packages
Conflicts: docker-ce-cli
Conflicts: docker-ee-cli
# Conflict with podman-docker that also contains /usr/bin/docker
Conflicts: podman-docker
%description zsh-completion
This package installs %{summary}.
# Obsolete old separate shell completions packages
Obsoletes: moby-engine-fish-completion < 24.0.5-6
Obsoletes: moby-engine-zsh-completion < 24.0.5-6
%description -n docker-cli %{common_description}
This package provides the Docker CLI.
%package -n moby-filesystem
Summary: Filesystem package for the Moby/Docker stack
License: LicenseRef-Not-Copyrightable
BuildArch: noarch
%description -n moby-filesystem %{common_description}
This is the filesystem subpackage for the Moby/Docker stack.
%package -n moby-rpm-macros
Summary: RPM Macros for the Moby/Docker stack
License: MIT
BuildArch: noarch
%description -n moby-rpm-macros %{common_description}
This package provides RPM macros for the Moby/Docker stack.
%package nano
Summary: nano syntax highlighting files for Moby
Requires: %{name} = %{version}-%{release}
Requires: nano
%description nano
This package installs %{summary}.
%prep
%goprep -a -A
%autosetup -N -Sgit -n %{service_name}-ce-%{commit_moby}
# moby-engine
cd %{_builddir}/%{extractdir0}
# Unpack vendor archive
tar -xf %{S:1}
# Apply patches 0-1000
# Leave this here despite warnings so we can easily add and remove patches.
%autopatch -M999 -p1
cp -p %{S:100} %{S:101} %{S:102} .
# docker-cli
cd %{cli_dir}
# Unpack vendor archive
tar -xf %{S:3}
# Apply patches 1000+.
# Leave this here despite warnings so we can easily add and remove patches.
%autopatch -m1000 -p1
# See comment in go-vendor-tools.toml
rm -f man/go.mod
%generate_buildrequires
# moby-engine
%go_vendor_license_buildrequires -c %{S:200}
# docker-cli
%go_vendor_license_buildrequires -c %{S:201}
%build
export GO_LDFLAGS="" GO_BUILDTAGS="" CGO_ENABLED=1
%global gomodulesmode GO111MODULE=on
# moby-engine
cd %{engine_dir}
# DOCKER_DEBUG: Ensure that all debuginfo is preserved
BUILDFLAGS="%{gocompilerflags} -a -v" \
CGO_CFLAGS="%{build_cflags}" \
CGO_LDFLAGS="%{build_ldflags}" \
DOCKER_BUILDTAGS="rpm_crashback journald" \
DOCKER_GITCOMMIT=%{release} \
DOCKER_DEBUG=1 \
DOCKER_LDFLAGS=%{gobuild_ldflags_shescaped} \
LDFLAGS=%{gobuild_ldflags_shescaped} \
VERSION=%{version} \
GOPATH=%{gobuilddir} \
bash -x ./hack/make.sh dynbinary
# build man pages using Makefile in man subdirectory
pushd man
GO_MD2MAN=go-md2man %make_build all
# correct rpmlint errors for bash completion
pushd components/cli
sed -i '/env bash/d' contrib/completion/bash/docker
popd
# docker-cli
cd %{cli_dir}
%make_build dynbinary \
DISABLE_WARN_OUTSIDE_CONTAINER=1 \
GITCOMMIT=%{release} \
GO_BUILDTAGS="rpm_crashback" \
GO_LDFLAGS=%{gobuild_ldflags_shescaped} \
VERSION=%{version} \
dynbinary manpages
# untar runc
tar zxf %{SOURCE1}
# untar containerd
tar zxf %{SOURCE2}
# untar libnetwork
tar zxf %{SOURCE3}
# untar tini
tar zxf %{SOURCE4}
%patch1 -p1 -d runc-%{commit_runc}
%build
# build docker-runc
pushd runc-%{commit_runc}
mv vendor src
mkdir -p src/github.com/opencontainers
ln -s $(pwd) src/github.com/opencontainers/runc
sed -i 's/go build -i/go build/g' Makefile
GOPATH=$(pwd) make BUILDTAGS="seccomp selinux"
popd
# build docker-containerd
pushd containerd-%{commit_containerd}
mv vendor src
mkdir -p src/github.com/containerd
ln -s $(pwd) src/github.com/containerd/containerd
GOPATH=$(pwd) make
popd
# build docker-proxy / libnetwork
pushd libnetwork-%{commit_libnetwork}
mkdir -p src/github.com/%{service_name}
ln -s $(pwd) src/github.com/%{service_name}/libnetwork
export GOPATH=$(pwd)
LDFLAGS="-linkmode=external" %gobuild -o %{service_name}-proxy github.com/%{service_name}/libnetwork/cmd/proxy
popd
# build tini
pushd tini-%{commit_tini}
cmake .
make tini-static
popd
# build engine
pushd components/engine
mkdir _build
pushd _build
mkdir -p $(pwd)/src/github.com/%{service_name}
ln -s $(dirs +1 -l) src/github.com/%{service_name}/%{service_name}
ln -s $(dirs +1 -l) src/github.com/%{service_name}/%{service_name}
popd
export DOCKER_GITCOMMIT=%{shortcommit_moby}
export DOCKER_BUILDTAGS="seccomp selinux"
DOCKER_DEBUG=1 GOPATH=$(pwd)/_build:$(pwd)/vendor:%{gopath} bash -x hack/make.sh dynbinary
popd
# build cli
pushd components/cli
mkdir -p src/github.com/%{service_name}/cli
ln -s $(pwd)/* src/github.com/%{service_name}/cli
export GOPATH=%{gopath}:$(pwd)
make VERSION=$(cat VERSION) GITCOMMIT=%{shortcommit_moby} dynbinary # cli
./man/md2man-all.sh
pushd man/man1
popd
pushd man/man5
popd
popd
%install
# moby-engine
cd %{engine_dir}
# Install licenses
%go_vendor_license_install -c %{S:200}
# Install binaries
install -Dpm 0755 bundles/dynbinary*/* -t %{buildroot}%{_bindir}
# Install systemd configuration
install -Dpm 0644 contrib/init/systemd/* -t %{buildroot}%{_unitdir}
# Install sysusers config
install -Dpm 0644 moby-engine-systemd-sysusers.conf %{buildroot}%{_sysusersdir}/moby-engine.conf
install -Dpm 644 man/man8/*.8 -t %{buildroot}%{_mandir}/man8/
install -dp %{buildroot}%{_bindir}
install -dp %{buildroot}%{_libexecdir}/%{service_name}
# docker-cli
cd %{cli_dir}
# Install licenses
%go_vendor_license_install -c %{S:201}
# Install docker-cli
install -Dpm 0755 build/docker -t %{buildroot}%{_bindir}
# Install shell completions
install -Dpm 644 contrib/completion/bash/docker -t %{buildroot}%{bash_completions_dir}
install -Dpm 644 contrib/completion/zsh/_docker -t %{buildroot}%{zsh_completions_dir}
install -Dpm 644 contrib/completion/fish/docker.fish -t %{buildroot}%{fish_completions_dir}
# Install manpages
install -Dpm 644 man/man1/*.1 -t %{buildroot}%{_mandir}/man1/
install -Dpm 644 man/man5/*.5 -t %{buildroot}%{_mandir}/man5/
cd -
# install binary
install -p -m 755 components/cli/build/%{service_name} %{buildroot}%{_bindir}/%{service_name}
install -p -m 755 components/engine/bundles/latest/dynbinary-daemon/%{service_name}d %{buildroot}%{_bindir}/%{service_name}d
# moby-filesystem
mkdir -p %{buildroot}%{_libexecdir}/docker
mkdir %{buildroot}%{_libexecdir}/docker/cli-plugins
# install proxy
install -p -m 755 libnetwork-%{commit_libnetwork}/%{service_name}-proxy %{buildroot}%{_bindir}/%{service_name}-proxy
# moby-rpm-macros
install -Dpm 0644 macros.moby -t %{buildroot}%{_rpmmacrodir}
# install containerd
install -p -m 755 containerd-%{commit_containerd}/bin/containerd %{buildroot}%{_bindir}/%{service_name}-containerd
install -p -m 755 containerd-%{commit_containerd}/bin/containerd-shim %{buildroot}%{_bindir}/%{service_name}-containerd-shim
install -p -m 755 containerd-%{commit_containerd}/bin/ctr %{buildroot}%{_bindir}/%{service_name}-containerd-ctr
%check
export PATH="%{buildroot}%{_bindir}:${PATH}" TZ=utc
# install runc
install -p -m 755 runc-%{commit_runc}/runc %{buildroot}%{_bindir}/%{service_name}-runc
# moby-engine
cd %{engine_dir}
%go_vendor_license_check -c %{S:200}
# install tini
install -p -m 755 tini-%{commit_tini}/tini-static %{buildroot}%{_bindir}/%{service_name}-init
# docker-cli
cd %{cli_dir}
%go_vendor_license_check -c %{S:201} %{cli_license}
# install udev rules
install -dp %{buildroot}%{_prefix}/lib/udev/rules.d
install -p -m 644 components/engine/contrib/udev/80-%{service_name}.rules %{buildroot}%{_usr}/lib/udev/rules.d/80-%{service_name}.rules
%if %{with check}
# moby-engine
cd %{engine_dir}
# Manually skip specific tests
%global engine_ignores %{shrink:
%dnl assertion failed
-s "TestC8dSnapshotterWithUsernsRemap"
-s "TestSCTP4Proxy"
%dnl flaky test will fail on x86_64 - sometimes
-s "TestSCTP6Proxy"
%dnl Failed to enter netns: operation not permitted
%dnl -s "TestSCTP4ProxyNoListener"
%dnl -s "TestSCTP6ProxyNoListener"
%dnl possibly flaky test failing on ppc64le
%[ "%{_arch}" == "ppc64le" ? "-s TestSCTP6ProxyNoListener" : "" ]
%dnl network_proxy_linux_test.go:73: protocol not supported; fails in COPR rawhide
-s "TestIfaceAddrs"
%dnl failed to mount resolved path: operation not permitted
-s "TestJoinGoodSymlink"
-s "TestJoinWithSymlinkReplace"
-s "TestJoinCloseInvalidates"
%dnl Test timeout
-s "TestImageLoad"
%dnl doesn't provide the requested platform
-s "TestContentStoreForPull"
-s "TestManifestStore"
%dnl all with error is not nil: create tmp file
%[ "%{_arch}" == "s390x" ? "-s TestCloseRunningCommand" : "" ]
%dnl graphdriver tests require extra permissions
-t daemon/graphdriver
%dnl integration tests require a running docker daemon
-t integration
%dnl libnetwork tests cannot create netns in mock
-t daemon/libnetwork
%dnl integration-cli: we don't want to run integration tests or benchmarks
-d integration-cli
}
%gocheck2 -F %{engine_ignores}
# add init scripts
install -dp %{buildroot}/%{_unitdir}
install -p -m 644 components/packaging/rpm/systemd/%{service_name}.service %{buildroot}%{_unitdir}
# docker-cli
cd %{cli_dir}
%global cli_ignores %{shrink:
-s "TestInitializeFromClientHangs"
%dnl Needs network
-s "TestRunBuildFromGitHubSpecialCase"
%dnl Test is flaky
-s "TestConnectAndWait"
%dnl Test panics
-s "TestRunAttachTermination"
-s "TestRunPullTermination"
-s "TestUpgradePromptTermination"
}
%gocheck2 -F -t e2e %{cli_ignores}
%endif
# add bash, zsh, and fish completions
install -dp %{buildroot}%{_datadir}/bash-completion/completions
install -dp %{buildroot}%{_datadir}/zsh/vendor-completions
install -dp %{buildroot}%{_datadir}/fish/vendor_completions.d
install -p -m 644 components/cli/contrib/completion/bash/%{service_name} %{buildroot}%{_datadir}/bash-completion/completions/%{service_name}
install -p -m 644 components/cli/contrib/completion/zsh/_%{service_name} %{buildroot}%{_datadir}/zsh/vendor-completions/_%{service_name}
install -p -m 644 components/cli/contrib/completion/fish/%{service_name}.fish %{buildroot}%{_datadir}/fish/vendor_completions.d/%{service_name}.fish
# install manpages
install -dp %{buildroot}%{_mandir}/man{1,5,8}
install -p -m 644 components/cli/man/man1/*.1 %{buildroot}%{_mandir}/man1
install -p -m 644 components/cli/man/man5/*.5 %{buildroot}%{_mandir}/man5
install -p -m 644 components/cli/man/man8/*.8 %{buildroot}%{_mandir}/man8
# add vimfiles
install -dp %{buildroot}%{_datadir}/vim/vimfiles/doc
install -dp %{buildroot}%{_datadir}/vim/vimfiles/ftdetect
install -dp %{buildroot}%{_datadir}/vim/vimfiles/syntax
install -p -m 644 components/engine/contrib/syntax/vim/doc/%{service_name}file.txt %{buildroot}%{_datadir}/vim/vimfiles/doc/%{service_name}file.txt
install -p -m 644 components/engine/contrib/syntax/vim/ftdetect/%{service_name}file.vim %{buildroot}%{_datadir}/vim/vimfiles/ftdetect/%{service_name}file.vim
install -p -m 644 components/engine/contrib/syntax/vim/syntax/%{service_name}file.vim %{buildroot}%{_datadir}/vim/vimfiles/syntax/%{service_name}file.vim
# add nano files
install -dp %{buildroot}%{_datadir}/nano
install -p -m 644 components/engine/contrib/syntax/nano/Dockerfile.nanorc %{buildroot}%{_datadir}/nano/Dockerfile.nanorc
for cli_file in LICENSE MAINTAINERS NOTICE README.md; do
cp "components/cli/$cli_file" "$(pwd)/cli-$cli_file"
done
%post
%systemd_post docker.service docker.socket
%systemd_post %{service_name}
%preun
%systemd_preun docker.service docker.socket
%systemd_preun %{service_name}
%postun
%systemd_postun_with_restart docker.service
%systemd_postun_with_restart %{service_name}
%files
%license cli-LICENSE components/engine/LICENSE
%doc components/engine/{AUTHORS,CHANGELOG.md,CONTRIBUTING.md,MAINTAINERS,NOTICE,README.md}
%doc cli-MAINTAINERS cli-NOTICE cli-README.md
%{_bindir}/%{service_name}
%{_bindir}/%{service_name}d
%dir %{_libexecdir}/%{service_name}/
%{_bindir}/%{service_name}-containerd
%{_bindir}/%{service_name}-containerd-shim
%{_bindir}/%{service_name}-containerd-ctr
%{_bindir}/%{service_name}-proxy
%{_bindir}/%{service_name}-runc
%{_bindir}/%{service_name}-init
%{_usr}/lib/udev/rules.d/80-%{service_name}.rules
%{_unitdir}/%{service_name}.service
%{_datadir}/bash-completion/completions/%{service_name}
%{_mandir}/man1/*
%{_mandir}/man5/*
%{_mandir}/man8/*
%files -f %{engine_dir}/%{go_vendor_license_filelist}
%license %{engine_dir}/vendor/modules.txt
%doc %{engine_dir}/README.md
%{_bindir}/docker-proxy
%{_bindir}/dockerd
%{_sysusersdir}/moby-engine.conf
%{_unitdir}/docker.service
%{_unitdir}/docker.socket
%{_mandir}/man8/dockerd.8*
%files vim
%dir %{_datadir}/vim/vimfiles/{doc,ftdetect,syntax}
%{_datadir}/vim/vimfiles/doc/%{service_name}file.txt
%{_datadir}/vim/vimfiles/ftdetect/%{service_name}file.vim
%{_datadir}/vim/vimfiles/syntax/%{service_name}file.vim
%files zsh-completion
%dir %{_datadir}/zsh/vendor-completions/
%{_datadir}/zsh/vendor-completions/_%{service_name}
%files fish-completion
%dir %{_datadir}/fish/vendor_completions.d
%{_datadir}/fish/vendor_completions.d/%{service_name}.fish
%files nano
%license %{engine_dir}/AUTHORS
%license %{engine_dir}/LICENSE
%license %{engine_dir}/NOTICE
%files -n docker-cli -f %{cli_dir}/%{go_vendor_license_filelist}
%license %{cli_dir}/vendor/modules.txt
%doc %{cli_dir}/README.md
%{_bindir}/docker
%{_mandir}/man1/docker*.1*
%{_mandir}/man5/{Dockerfile,docker-config-json}.5*
%{bash_completions_dir}/docker
%{fish_completions_dir}/docker.fish
%{zsh_completions_dir}/_docker
%files -n moby-filesystem
%dir %{_libexecdir}/docker
%dir %{_libexecdir}/docker/cli-plugins
%files -n moby-rpm-macros
%license %{engine_dir}/LICENSE.macros
%{_rpmmacrodir}/macros.moby
%dir %{_datadir}/nano
%{_datadir}/nano/Dockerfile.nanorc
%changelog
%autochangelog
* Mon Feb 11 2019 David Michael <dm0@redhat.com> - 18.06.0-2.ce.git0ffa825
- Apply a runc patch for CVE-2019-5736.
* Sat Aug 18 2018 Lokesh Mandvekar <lsm5@fedoraproject.org> - 18.06.0-1.ce.git0ffa825
- Resolves: #1539161 - first upload to Fedora
- built docker-ce commit 0ffa825
- built docker-runc commit ad0f5255
- built docker-containerd commit a88b631
- built docker-proxy commit a79d368
- built docker-init commit fec3683
* Tue Mar 20 2018 Lokesh Mandvekar <lsm5@fedoraproject.org> - 17.03.2-4.ce.gitf5ec1e2
- correct some rpmlint errors
* Wed Feb 21 2018 Lokesh Mandvekar <lsm5@fedoraproject.org> - 17.03.2-3.ce
- docker-* symlinks to moby-* (RE: gh PR 34226)
* Wed Feb 21 2018 Lokesh Mandvekar <lsm5@fedoraproject.org> - 17.03.2-2.ce
- rename binaries as per upstream gh PR 34226
* Fri Jan 26 2018 Lokesh Mandvekar <lsm5@fedoraproject.org> - 17.03.2-1
- initial build
- built moby commit f5ec1e2
- built cli commit 4b61f56
- built docker-runc commit 2d41c047
- built docker-containerd commit 3addd84
- built docker-proxy commit 7b2b1fe

View file

@ -1,4 +1,5 @@
SHA512 (cli-29.1.4.tar.gz) = 517b3976e740aef1e40e7cc90d3792f3ef2a13fc3d5dd3e41126451bc938a43c37c1c7ff36de8b47aa7870d0c8dd4efa124639cf505626b339a87ffdb25c8a79
SHA512 (cli-29.1.4-vendor.tar.bz2) = 6147c6ad55e3c65c45afa3d9cc01cee7bc92da4d709cb4ccd91dfc97db8f6d459fb089f3cd02464b35ac5e78552f971c8c7a20870eab5ce9543d7d2e66347ac7
SHA512 (moby-docker-v29.1.4.tar.gz) = 53a46ddce7363c7cf74b07a928f195af6fd646524154170a90a5303ea39ad7d79980eff94568ed84c242a381c467b0613bd1f9344f6cdce89fba6a6f4e95defd
SHA512 (moby-docker-v29.1.4-vendor.tar.bz2) = 8ca3d92590f86cd24bba61356646ac20a5cecc6aab1fe23c110f7edb1d86734f8631360580bdb4ff250c373f1ae02b5c37ccbbc90380d5e9f7e9b95be575dbb4
SHA512 (0ffa8257ec673ed6849b73b03fb01b0cac90fdb3.tar.gz) = 4045d655548bb3d9cced82a7c27014a48343d91af47cd06a9128bfec40fe61c0688716246422128f963af9fa72eeab7c3d8e7c6ab0a2aac568a95edadc03b54a
SHA512 (a79d3687931697244b8e03485bf7b2042f8ec6b6.tar.gz) = df6e608ecf04e81f5df16e18677fe0a2dc3402eb7b74d5c718b240937ed2c9f6781988881147bb7f30914a2fdf0c1c93092b71d45405e534a8e83cc5b763da0a
SHA512 (a88b6319614de846458750ff882723479ca7b1a1.tar.gz) = 0e43133030c924c1c06979eaff52790fc74332e47aeaf0e6f3ce3f0a3abf5825288eab746bcfafe2aa14387f5cbd8b04a317a454596c12c6ab772e4f8d6cc25e
SHA512 (ad0f5255060d36872be04de22f8731f38ef2d7b1.tar.gz) = 93b2c9a063a5f403f38ee9da535464456a07ea103a24e15d51105af93887f7ac18073bf6c9be87d9612087d6f6e78f4ce141ad2bc2bcdc0c70c30dfe052f8d76
SHA512 (fec3683b971d9c3ef73f284f176672c44b448662.tar.gz) = ee46d21467f8bacb4e8be72f5dfcbb23c1964286e90b4b3d3bf67dbbf79a337968ac8a0042a8191e329a65398b20ea160aae3ae5ef20ee03ebae11c2083d7621