6 Commits

Author SHA1 Message Date
Vanient
e12947bfb5 containerd:Use fs.RootPath when mounting volumes
fix CVE-2022-23648

Signed-off-by: Vanient <xiadanni1@huawei.com>
(cherry picked from commit 1c20efac8910ccd8180a341eca90db76442b8fef)
2022-04-26 20:49:12 +08:00
xiadanni
c5a97831ab containerd:reduce permissions for bundle dir to fix CVE-2021-41103
upstream:
6886c6a2ec
v1 runtime: reduce permissions for bundle dir

7c621e1fcc
btrfs: reduce permissions on plugin directories

Signed-off-by: xiadanni <xiadanni1@huawei.com>
(cherry picked from commit b4bc26bf252f387c3b26ace2ee20972a67530388)
2021-11-06 17:40:34 +08:00
xiadanni
666217db33 containerd: sync bugfix and bump version
Signed-off-by: xiadanni <xiadanni1@huawei.com>

Conflicts:
	containerd.spec
2021-03-05 11:16:23 +08:00
xiadanni
155deff118 containerd: update patches
0059-containerd-add-GO_GCFLAGS-to-containerd-shim-making.patch
0060-containerd-do-not-disable-cgo-in-containerd-shim-mak.patch
0061-containerd-check-if-bundle-exists-before-create-bund.patch
0062-containerd-use-path-based-socket-for-shims.patch
0063-containerd-kill-init-directly-if-runtime-kill-failed.patch

Signed-off-by: xiadanni <xiadanni1@huawei.com>
2020-11-25 20:05:42 +08:00
Grooooot
3a981f1909 containerd:add patches
Signed-off-by: Grooooot <isula@huawei.com>
2020-03-05 15:54:34 +08:00
Grooooot
7b8aa4184d first commit 2019-12-30 12:24:38 +08:00