27 Commits

Author SHA1 Message Date
dongyuzhen
15e7d5a038 fix CVE-2024-40635 2025-03-19 15:06:01 +08:00
zhongjiawei
9aaa26c0db containerd:modify make options 2024-06-12 11:30:55 +08:00
zhongjiawei
87383d05a2 containerd:enable make cri 2024-04-23 19:19:58 +08:00
zhongjiawei
5d3c6499ce containerd:modify Makefile for go build options 2024-04-07 09:57:43 +08:00
zhongjiawei
bacfecc5bb containerd:remove stw gc sweep set for arm64 2024-03-22 14:23:22 +08:00
zhongjiawei
7f3cac2599 containerd:disable Transparent HugePage for shim process if SHIM_DISABLE_THP is set 2024-02-23 15:00:46 +08:00
zhongjiawei
31cc3dd36c containerd:fix mission closed fifo 2023-12-21 14:54:46 +08:00
zhongjiawei
a90d673203 containerd:update vendor net/http package to fix CVE-2023-39325 2023-11-08 10:47:20 +08:00
zhongjiawei
8aba0d5156 containerd:fix some bugs after version upgrade 2023-10-19 10:19:33 +08:00
zhongjiawei
bf91571d1f containerd:symc some patches 2023-09-19 14:43:01 +08:00
zhongjiawei
4a1d8da417 containerd:add patch for 1.6.22
Signed-off-by: zhongjiawei <zhongjiawei1@huawei.com>
2023-09-08 15:52:11 +08:00
vegbir
982bc6258b upgrade to contained 1.6.22
Signed-off-by: vegbir <yangjiaqi16@huawei.com>
2023-08-02 08:23:32 +00:00
peppaJoeng
7c4eacd6ac upgrade to contained 1.6.21
Signed-off-by: vegbir <yangjiaqi16@huawei.com>
2023-07-21 08:11:52 +00:00
zhongjiawei
ca79c58f4e containerd:fix CVE-2023-25153 and CVE-2023-25173 2023-02-27 16:52:55 +08:00
zhongjiawei
a2c40b0650 containerd:fix k8s build fail without import context
(cherry picked from commit cf1b0bc6ef5c80f78b1012246cd312b4dfa1c9a4)
2022-12-15 16:59:57 +08:00
zhongjiawei
3ca4395efe containerd:Fix goroutine leak in Exec
(cherry picked from commit 9fc75e44814de33a73f690764c2de4c7e9495efc)
2022-12-13 19:03:09 +08:00
zhongjiawei
371b59a846 containerd: fix version number wrong
(cherry picked from commit 6bbb86302fbc7c085c3f63d7e9cdd41570101549)
2022-11-16 14:30:59 +08:00
zhongjiawei
d49c9d0693 containerd: bugfix and add CGO security build option
(cherry picked from commit eb136438cf63fae5754c31920a6bf8afaeded135)
2022-09-22 19:38:32 +08:00
zhongjiawei
8bbd2f34fd containerd: Limit the response size of ExecSync
fix CVE-2022-31030

Signed-off-by: zhongjiawei <zhongjiawei1@huawei.com>
(cherry picked from commit 0436d058b39572dfa0d0a267b0518fd8a793dc49)
2022-07-04 17:24:32 +08:00
zhangsong234
5cff214452 containerd:put get pid lock after set process exited to avoid deadlock
Signed-off-by: zhangsong234 <zhangsong34@huawei.com>
2022-06-22 14:47:29 +08:00
duyiwei
49ca531746 containerd:Use fs.RootPath when mounting volumes 2022-05-23 10:34:51 +08:00
songyanting
19583b7229 containerd: update patches
0069-containerd-add-check-in-spec.patch
0070-containerd-kill-container-init-process-if-runc-start.patch
0071-containerd-fix-containerd-shim-residual-when-kill-co.patch
0072-containerd-fix-deadlock-on-commit-error.patch
0073-containerd-backport-upstream-patches.patch
0074-containerd-fix-exec-event-missing-due-to-pid-reuse.patch
0075-containerd-fix-dm-left-when-pause-contaienr-and-kill-shim.patch
0076-containerd-fix-start-container-failed-with-id-exists.patch
0077-containerd-drop-opt-package.patch
0078-containerd-bump-containerd-ttrpc-699c4e40d1.patch
0079-containerd-fix-race-access-for-mobySubcribed.patch
0080-containerd-improve-log-for-debugging.patch
0081-containerd-reduce-permissions-for-bundle-di.patch
0082-containerd-fix-publish-command-wait-block-for.patch
0083-containerd-optimize-cgo-compile-options.patch

Signed-off-by:songyanting <songyanting@huawei.com>
2022-01-26 20:03:57 +08:00
xiadanni
9c4ff3a46f containerd: compile option compliance
Signed-off-by: xiadanni <xiadanni1@huawei.com>
2021-03-18 10:42:53 +08:00
xiadanni
349a80d77f sync patches
1. check task list to avoid unnecessary cleanup.
2. fix dead loop
3. cleanup dangling shim by brand new context
4. fix potential panic for task in unknown state

Signed-off-by: xiadanni <xiadanni1@huawei.com>
2021-03-18 10:20:49 +08:00
xiadanni
dccab1cbca containerd: update patches
0059-containerd-add-GO_GCFLAGS-to-containerd-shim-making.patch
0060-containerd-do-not-disable-cgo-in-containerd-shim-mak.patch
0061-containerd-check-if-bundle-exists-before-create-bund.patch
0062-containerd-use-path-based-socket-for-shims.patch
0063-containerd-kill-init-directly-if-runtime-kill-failed.patch

Signed-off-by: xiadanni <xiadanni1@huawei.com>
2020-11-25 11:08:13 +08:00
xiadanni
9de0263d1f containerd: fix SOURCE0 addr
Signed-off-by: xiadanni <xiadanni1@huawei.com>
2020-09-14 14:58:02 +08:00
liuzekun
bada571c96 containerd: use git-commit to store commit ID
Signed-off-by: liuzekun <liuzekun@huawei.com>
2020-06-15 04:54:01 -04:00