Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package docker for openSUSE:Factory checked in at 2026-09-12 21:15:38 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/docker (Old) and /work/SRC/openSUSE:Factory/.docker.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "docker" Sat Sep 12 21:15:38 2026 rev:187 rq:1377394 version:unknown Changes: -------- --- /work/SRC/openSUSE:Factory/docker/docker.changes 2026-06-29 17:30:41.994730355 +0200 +++ /work/SRC/openSUSE:Factory/.docker.new.1265/docker.changes 2026-09-12 21:16:18.331858376 +0200 @@ -1,0 +2,42 @@ +Thu Sep 3 06:30:01 UTC 2026 - Madhankumar Chellamuthu <[email protected]> + +- Ship the SELinux CIL policies from contrib/selinux/, loading + docker-af-alg-deny.cil (mitigates CVE-2026-31431) via semodule + when SELinux is enabled (bsc#1278193). + +------------------------------------------------------------------- +Tue Aug 11 09:27:20 UTC 2026 - Madhankumar Chellamuthu <[email protected]> + +- Update to Docker 29.7.2. See upstream changelog online at + <https://docs.docker.com/engine/release-notes/29/#2972> +- Update to buildx 0.36.1. See upstream changelog online at + <https://github.com/docker/buildx/releases/tag/v0.36.1> +- Rebased patches: + * 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch + * 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch + * 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch + * 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch + * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch + (renamed from 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch) + * cli-0001-openSUSE-point-users-to-docker-buildx-package.patch + * cli-0002-SECRETS-SUSE-default-to-DOCKER_BUILDKIT-0-for-docker.patch +- Remove patches now fixed upstream: + - 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch + (bsc#1099277, superseded by upstream commit 528a806141 "daemon: + Always reload AppArmor profile at daemon startup", which fixes + the same root cause: the daemon no longer skips reinstalling the + docker-default profile on upgrade) + - 0007-CVE-2026-39984-Ensure-correct-certificate-is-used-fo.patch + (bsc#1262346, CVE-2026-39984 fixed upstream via vendored + sigstore/timestamp-authority v2.1.2) + - 0008-CVE-2026-33814-http2-prevent-hanging-Transport-due-t.patch + (bsc#1265782, CVE-2026-33814 fixed upstream via vendored + golang.org/x/net v0.57.0) + - 0009-CVE-2026-39821-idna-update-from-x-text-fix-ToUnicode.patch + (bsc#1266625, CVE-2026-39821 fixed upstream via vendored + golang.org/x/net v0.57.0) + - 0010-CVE-2026-41567-daemon-Decompress-archives-before-ent.patch + (bsc#1267827, CVE-2026-41567 fixed upstream directly in moby/moby + via commit 2022313ffe) + +------------------------------------------------------------------- Old: ---- 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch 0007-CVE-2026-39984-Ensure-correct-certificate-is-used-fo.patch 0008-CVE-2026-33814-http2-prevent-hanging-Transport-due-t.patch 0009-CVE-2026-39821-idna-update-from-x-text-fix-ToUnicode.patch 0010-CVE-2026-41567-daemon-Decompress-archives-before-ent.patch docker-29.4.0_ce_daa0cb7f23.tar.xz docker-buildx-0.33.0.tar.xz docker-cli-29.4.0_ce.tar.xz New: ---- 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch docker-29.7.2_ce_6a43e3d5af.tar.xz docker-buildx-0.36.1.tar.xz docker-cli-29.7.2_ce.tar.xz ----------(Old B)---------- Old:- Remove patches now fixed upstream: - 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch (bsc#1099277, superseded by upstream commit 528a806141 "daemon: Old: * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch (renamed from 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch) * cli-0001-openSUSE-point-users-to-docker-buildx-package.patch Old: docker-default profile on upgrade) - 0007-CVE-2026-39984-Ensure-correct-certificate-is-used-fo.patch (bsc#1262346, CVE-2026-39984 fixed upstream via vendored Old: sigstore/timestamp-authority v2.1.2) - 0008-CVE-2026-33814-http2-prevent-hanging-Transport-due-t.patch (bsc#1265782, CVE-2026-33814 fixed upstream via vendored Old: golang.org/x/net v0.57.0) - 0009-CVE-2026-39821-idna-update-from-x-text-fix-ToUnicode.patch (bsc#1266625, CVE-2026-39821 fixed upstream via vendored Old: golang.org/x/net v0.57.0) - 0010-CVE-2026-41567-daemon-Decompress-archives-before-ent.patch (bsc#1267827, CVE-2026-41567 fixed upstream directly in moby/moby ----------(Old E)---------- ----------(New B)---------- New: * 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch (renamed from 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch) ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ docker.spec ++++++ --- /var/tmp/diff_new_pack.w6wWAV/_old 2026-09-12 21:16:19.387902295 +0200 +++ /var/tmp/diff_new_pack.w6wWAV/_new 2026-09-12 21:16:19.388902337 +0200 @@ -1,7 +1,7 @@ # # spec file for package docker # -# Copyright (c) 2024 SUSE LLC +# Copyright (c) 2026 SUSE LLC and contributors # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -53,8 +53,8 @@ %endif # MANUAL: This needs to be updated with every docker update. -%define docker_real_version 29.4.0 -%define docker_git_version daa0cb7f23 +%define docker_real_version 29.7.2 +%define docker_git_version 6a43e3d5af %define docker_version %{docker_real_version}_ce # This "nice version" is so that docker --version gives a result that can be # parsed by other people. boo#1182476 @@ -62,7 +62,7 @@ %if %{with buildx} # MANUAL: This needs to be updated with every docker-buildx update. -%define buildx_version 0.33.0 +%define buildx_version 0.36.1 %endif # Used when generating the "build" information for Docker version. The value of @@ -70,7 +70,7 @@ # helpfully injects into our build environment from the changelog). If you want # to generate a new git_commit_epoch, use this: # $ date --date="$(git show --format=fuller --date=iso $COMMIT_ID | grep -oP '(?<=^CommitDate: ).*')" '+%s' -%define git_commit_epoch 1775550724 +%define git_commit_epoch 1785954267 Name: docker%{flavour} Version: %{docker_version} @@ -108,14 +108,8 @@ Patch902: cli-0002-SECRETS-SUSE-default-to-DOCKER_BUILDKIT-0-for-docker.patch # UPSTREAM: Revert of upstream patch to keep SLE-12 build working. Patch200: 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch -# UPSTREAM: Backport of <https://github.com/moby/moby/pull/41954>. -Patch201: 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch # UPSTREAM: Revert of upstream patches to make apparmor work on SLE 12. -Patch202: 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch -Patch203: 0007-CVE-2026-39984-Ensure-correct-certificate-is-used-fo.patch -Patch204: 0008-CVE-2026-33814-http2-prevent-hanging-Transport-due-t.patch -Patch205: 0009-CVE-2026-39821-idna-update-from-x-text-fix-ToUnicode.patch -Patch206: 0010-CVE-2026-41567-daemon-Decompress-archives-before-ent.patch +Patch201: 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch BuildRequires: audit BuildRequires: bash-completion BuildRequires: ca-certificates @@ -134,8 +128,8 @@ BuildRequires: sysuser-tools BuildRequires: zsh BuildRequires: golang(API) >= 1.25 -BuildRequires: pkgconfig(libsystemd) BuildRequires: pkgconfig(libnftables) +BuildRequires: pkgconfig(libsystemd) %if %{with apparmor} %if 0%{?suse_version} >= 1500 # This conditional only works on rpm>=4.13, which SLE 12 doesn't have. But we @@ -390,18 +384,8 @@ # Patches to build on SLE-12. %patch -P200 -p1 %endif -# bsc#1099277 -%patch -P201 -p1 # Solves apparmor issues on SLE-12, but okay for newer SLE versions too. -%patch -P202 -p1 -# bsc#1262346 -%patch -P203 -p1 -# bsc#1265782 -%patch -P204 -p1 -# bsc#1266625 -%patch -P205 -p1 -# bsc#1267827 -%patch -P206 -p1 +%patch -P201 -p1 %build %sysusers_generate_pre %{SOURCE160} %{name} docker.conf @@ -529,6 +513,12 @@ # audit rules install -D -m0640 %{SOURCE140} %{buildroot}%{_sysconfdir}/audit/rules.d/docker.rules +# SELinux policies. docker-af-alg-deny.cil denies AF_ALG sockets in +# container domains (mitigates CVE-2026-31431); docker_client.cil is an +# optional udica template for confining docker CLI clients. bsc#1278193 +install -d -m0755 %{buildroot}%{_datadir}/docker/selinux +install -p -m0644 %{docker_builddir}/contrib/selinux/*.cil %{buildroot}%{_datadir}/docker/selinux/ + # sysconfig file install -D -m0644 %{SOURCE120} %{buildroot}%{_fillupdir}/sysconfig.docker @@ -580,12 +570,21 @@ %post %service_add_post docker.service docker.socket %{fillup_only -n docker} +# Load the AF_ALG deny policy when SELinux is enabled. This may fail on +# systems with SELinux userspace < 3.6, or without container-selinux's +# container_domain attribute, so keep installation non-fatal. bsc#1278193 +if command -v semodule >/dev/null 2>&1 && selinuxenabled 2>/dev/null; then + semodule -i %{_datadir}/docker/selinux/docker-af-alg-deny.cil 2>/dev/null || : +fi %preun %service_del_preun docker.service docker.socket %postun %service_del_postun docker.service docker.socket +if [ "$1" -eq 0 ] && command -v semodule >/dev/null 2>&1; then + semodule -r docker-af-alg-deny 2>/dev/null || : +fi %files %defattr(-,root,root) @@ -621,6 +620,10 @@ %config %{_sysconfdir}/audit/rules.d/docker.rules %{_udevrulesdir}/80-docker.rules +%dir %{_datadir}/docker +%dir %{_datadir}/docker/selinux +%{_datadir}/docker/selinux/*.cil + %{_mandir}/man*/*%{ext_man} %if %{with buildx} ++++++ 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch ++++++ --- /var/tmp/diff_new_pack.w6wWAV/_old 2026-09-12 21:16:19.414903418 +0200 +++ /var/tmp/diff_new_pack.w6wWAV/_new 2026-09-12 21:16:19.417903543 +0200 @@ -1,7 +1,7 @@ -From 39cfc6ab1ba937f3c59a31536ee34ff43f362306 Mon Sep 17 00:00:00 2001 +From 6584c9aab47883bfc04c00b7f41afcad334a0762 Mon Sep 17 00:00:00 2001 From: Aleksa Sarai <[email protected]> Date: Wed, 4 Jun 2025 15:01:37 +1000 -Subject: [PATCH 1/6] SECRETS: SUSE: always clear our internal secrets +Subject: [PATCH 1/5] SECRETS: SUSE: always clear our internal secrets In the future SUSEConnect support patch, we will add swarm secrets with the ID suse_* containing credentials pertinent to SUSEConnect. @@ -24,6 +24,8 @@ SUSE-Bugs: bsc#1244035 bsc#1057743 Signed-off-by: Aleksa Sarai <[email protected]> +Signed-off-by: rcmadhankumar <[email protected]> +(cherry picked from commit 39cfc6ab1ba937f3c59a31536ee34ff43f362306) --- daemon/start.go | 10 ++++++++++ daemon/suse_secrets.go | 44 ++++++++++++++++++++++++++++++++++++++++++ @@ -102,6 +104,6 @@ + c.SecretReferences = without +} -- -2.53.0 +2.54.0 ++++++ 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch ++++++ --- /var/tmp/diff_new_pack.w6wWAV/_old 2026-09-12 21:16:19.430904083 +0200 +++ /var/tmp/diff_new_pack.w6wWAV/_new 2026-09-12 21:16:19.433904208 +0200 @@ -1,7 +1,7 @@ -From e6936c41e4dbb1fe2ef072a5b4a31c9399785fbe Mon Sep 17 00:00:00 2001 +From 8e746c9bcf00c0921a52d49bb4ced3c855c4eb4c Mon Sep 17 00:00:00 2001 From: Aleksa Sarai <[email protected]> Date: Wed, 8 Mar 2017 12:41:54 +1100 -Subject: [PATCH 2/6] SECRETS: daemon: allow directory creation in /run/secrets +Subject: [PATCH 2/5] SECRETS: daemon: allow directory creation in /run/secrets Since FileMode can have the directory bit set, allow a SecretStore implementation to return secrets that are actually directories. This is @@ -9,12 +9,14 @@ Signed-off-by: Antonio Murdaca <[email protected]> Signed-off-by: Aleksa Sarai <[email protected]> +Signed-off-by: rcmadhankumar <[email protected]> +(cherry picked from commit e6936c41e4dbb1fe2ef072a5b4a31c9399785fbe) --- daemon/container_operations_unix.go | 23 ++++++++++++++++++++--- 1 file changed, 20 insertions(+), 3 deletions(-) diff --git a/daemon/container_operations_unix.go b/daemon/container_operations_unix.go -index 146025ff89..2d76615341 100644 +index a41a4cbb5c..65db764fc5 100644 --- a/daemon/container_operations_unix.go +++ b/daemon/container_operations_unix.go @@ -3,6 +3,7 @@ @@ -25,7 +27,7 @@ "context" "fmt" "os" -@@ -22,6 +23,7 @@ import ( +@@ -23,6 +24,7 @@ "github.com/moby/moby/v2/daemon/network" "github.com/moby/moby/v2/errdefs" "github.com/moby/moby/v2/pkg/process" @@ -33,7 +35,7 @@ "github.com/moby/sys/mount" "github.com/moby/sys/user" "github.com/opencontainers/selinux/go-selinux/label" -@@ -329,9 +331,6 @@ func (daemon *Daemon) setupSecretDir(ctr *container.Container) (setupErr error) +@@ -330,9 +332,6 @@ func (daemon *Daemon) setupSecretDir(ctr *container.Container) (setupErr error) if err != nil { return errors.Wrap(err, "unable to get secret from secret store") } @@ -43,7 +45,7 @@ uid, err := strconv.Atoi(s.File.UID) if err != nil { -@@ -342,6 +341,24 @@ func (daemon *Daemon) setupSecretDir(ctr *container.Container) (setupErr error) +@@ -343,6 +342,24 @@ func (daemon *Daemon) setupSecretDir(ctr *container.Container) (setupErr error) return err } @@ -69,6 +71,6 @@ return errors.Wrap(err, "error setting ownership for secret") } -- -2.53.0 +2.54.0 ++++++ 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch ++++++ --- /var/tmp/diff_new_pack.w6wWAV/_old 2026-09-12 21:16:19.445904707 +0200 +++ /var/tmp/diff_new_pack.w6wWAV/_new 2026-09-12 21:16:19.449904874 +0200 @@ -1,7 +1,7 @@ -From 65a6fc5f7829a14c83e559d9129ed080c1f12baf Mon Sep 17 00:00:00 2001 +From 9816d94bbd456d0a47b29d4c73860b1437a96cc9 Mon Sep 17 00:00:00 2001 From: Aleksa Sarai <[email protected]> Date: Wed, 8 Mar 2017 11:43:29 +1100 -Subject: [PATCH 3/6] SECRETS: SUSE: implement SUSE container secrets +Subject: [PATCH 3/5] SECRETS: SUSE: implement SUSE container secrets This allows for us to pass in host credentials to a container, allowing for SUSEConnect to work with containers. @@ -16,6 +16,8 @@ SUSE-Bugs: bsc#1065609 bsc#1057743 bsc#1055676 bsc#1030702 bsc#1231348 bsc#1240150 Signed-off-by: Aleksa Sarai <[email protected]> +Signed-off-by: rcmadhankumar <[email protected]> +(cherry picked from commit 65a6fc5f7829a14c83e559d9129ed080c1f12baf) --- daemon/start.go | 5 + daemon/suse_secrets.go | 439 +++++++++++++++++++++++++++++++++++++++++ @@ -501,6 +503,6 @@ + return nil +} -- -2.53.0 +2.54.0 ++++++ 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch ++++++ --- /var/tmp/diff_new_pack.w6wWAV/_old 2026-09-12 21:16:19.460905331 +0200 +++ /var/tmp/diff_new_pack.w6wWAV/_new 2026-09-12 21:16:19.463905456 +0200 @@ -1,7 +1,7 @@ -From 294173206a84069de026c3975cd9f70e5c0cb501 Mon Sep 17 00:00:00 2001 +From c012c8bf7ba29dd00b010cd45636ba902dfe0b4e Mon Sep 17 00:00:00 2001 From: Aleksa Sarai <[email protected]> Date: Mon, 22 May 2023 15:44:54 +1000 -Subject: [PATCH 4/6] BUILD: SLE12: revert "graphdriver/btrfs: use kernel UAPI +Subject: [PATCH 4/5] BUILD: SLE12: revert "graphdriver/btrfs: use kernel UAPI headers" This reverts commit 3208dcabdc8997340b255f5b880fef4e3f54580d. @@ -11,15 +11,17 @@ for SLE-12. Signed-off-by: Aleksa Sarai <[email protected]> +Signed-off-by: rcmadhankumar <[email protected]> +(cherry picked from commit 294173206a84069de026c3975cd9f70e5c0cb501) --- daemon/graphdriver/btrfs/btrfs.go | 13 ++++--------- 1 file changed, 4 insertions(+), 9 deletions(-) diff --git a/daemon/graphdriver/btrfs/btrfs.go b/daemon/graphdriver/btrfs/btrfs.go -index 5f6ead6c7e..ab45a3cec1 100644 +index 35cf7d1104..fff51e3794 100644 --- a/daemon/graphdriver/btrfs/btrfs.go +++ b/daemon/graphdriver/btrfs/btrfs.go -@@ -4,17 +4,12 @@ package btrfs +@@ -4,17 +4,12 @@ /* #include <stdlib.h> @@ -42,6 +44,6 @@ static void set_name_btrfs_ioctl_vol_args_v2(struct btrfs_ioctl_vol_args_v2* btrfs_struct, const char* value) { snprintf(btrfs_struct->name, BTRFS_SUBVOL_NAME_MAX, "%s", value); -- -2.53.0 +2.54.0 ++++++ 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch -> 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch ++++++ --- /work/SRC/openSUSE:Factory/docker/0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch 2026-05-13 17:21:00.215439186 +0200 +++ /work/SRC/openSUSE:Factory/.docker.new.1265/0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch 2026-09-12 21:16:16.842796448 +0200 @@ -1,7 +1,7 @@ -From e1e27add6a799e8973e7b3777ec3187ebd86c523 Mon Sep 17 00:00:00 2001 +From cfc9eee8433d1d064bafebff1be64b1296263ed1 Mon Sep 17 00:00:00 2001 From: Aleksa Sarai <[email protected]> Date: Wed, 11 Oct 2023 21:19:12 +1100 -Subject: [PATCH 6/6] SLE12: revert "apparmor: remove version-conditionals from +Subject: [PATCH 5/5] SLE12: revert "apparmor: remove version-conditionals from template" This reverts the following commits: @@ -16,20 +16,22 @@ apparmor_parser version is quite old. Signed-off-by: Aleksa Sarai <[email protected]> +Signed-off-by: rcmadhankumar <[email protected]> +(cherry picked from commit e1e27add6a799e8973e7b3777ec3187ebd86c523) --- contrib/apparmor/main.go | 16 +++- contrib/apparmor/template.go | 16 ++++ pkg/aaparser/aaparser.go | 86 +++++++++++++++++++ - .../moby/profiles/apparmor/apparmor.go | 16 +++- + .../moby/profiles/apparmor/apparmor.go | 10 +++ .../moby/profiles/apparmor/template.go | 4 + - 5 files changed, 134 insertions(+), 4 deletions(-) + 5 files changed, 130 insertions(+), 2 deletions(-) create mode 100644 pkg/aaparser/aaparser.go diff --git a/contrib/apparmor/main.go b/contrib/apparmor/main.go index 899d8378ed..13caa8245e 100644 --- a/contrib/apparmor/main.go +++ b/contrib/apparmor/main.go -@@ -6,9 +6,13 @@ import ( +@@ -6,9 +6,13 @@ "os" "path" "text/template" @@ -72,7 +74,7 @@ index 58afcbe845..e6d0b6d37c 100644 --- a/contrib/apparmor/template.go +++ b/contrib/apparmor/template.go -@@ -20,9 +20,11 @@ profile /usr/bin/docker (attach_disconnected, complain) { +@@ -20,9 +20,11 @@ umount, pivot_root, @@ -84,7 +86,7 @@ network, capability, owner /** rw, -@@ -45,10 +47,12 @@ profile /usr/bin/docker (attach_disconnected, complain) { +@@ -45,10 +47,12 @@ /etc/ld.so.cache r, /etc/passwd r, @@ -97,7 +99,7 @@ /usr/lib/** rm, /lib/** rm, -@@ -69,9 +73,11 @@ profile /usr/bin/docker (attach_disconnected, complain) { +@@ -69,9 +73,11 @@ /sbin/zfs rCx, /sbin/apparmor_parser rCx, @@ -109,7 +111,7 @@ profile /bin/cat (complain) { /etc/ld.so.cache r, -@@ -93,8 +99,10 @@ profile /usr/bin/docker (attach_disconnected, complain) { +@@ -93,8 +99,10 @@ /dev/null rw, /bin/ps mr, @@ -120,7 +122,7 @@ # Quiet dac_override denials deny capability dac_override, -@@ -112,11 +120,15 @@ profile /usr/bin/docker (attach_disconnected, complain) { +@@ -112,11 +120,15 @@ /proc/tty/drivers r, } profile /sbin/iptables (complain) { @@ -136,7 +138,7 @@ capability sys_admin, capability dac_override, -@@ -135,7 +147,9 @@ profile /usr/bin/docker (attach_disconnected, complain) { +@@ -135,7 +147,9 @@ /proc/[0-9]*/mounts rw, } profile /sbin/modprobe /bin/kmod (complain) { @@ -146,7 +148,7 @@ capability sys_module, /etc/ld.so.cache r, /lib/** rm, -@@ -149,7 +163,9 @@ profile /usr/bin/docker (attach_disconnected, complain) { +@@ -149,7 +163,9 @@ } # xz works via pipes, so we do not need access to the filesystem. profile /usr/bin/xz (complain) { @@ -249,36 +251,28 @@ + return numericVersion, nil +} diff --git a/vendor/github.com/moby/profiles/apparmor/apparmor.go b/vendor/github.com/moby/profiles/apparmor/apparmor.go -index 445eed64e9..060a482289 100644 +index 244ae70fb2..af79e08980 100644 --- a/vendor/github.com/moby/profiles/apparmor/apparmor.go +++ b/vendor/github.com/moby/profiles/apparmor/apparmor.go -@@ -11,10 +11,14 @@ import ( - "path" +@@ -16,6 +16,8 @@ + "path/filepath" "strings" "text/template" + + "github.com/moby/moby/v2/pkg/aaparser" ) --// profileDirectory is the file store for apparmor profiles and macros. --const profileDirectory = "/etc/apparmor.d" -+var ( -+ // profileDirectory is the file store for apparmor profiles and macros. -+ profileDirectory = "/etc/apparmor.d" -+) - - // profileData holds information about the given profile for generation. - type profileData struct { -@@ -26,6 +30,8 @@ type profileData struct { + // profileDirectory is the file store for AppArmor profiles and macros. +@@ -33,6 +35,8 @@ type profileData struct { Imports []string - // InnerImports defines the apparmor functions to import in the profile. + // InnerImports defines the AppArmor functions to import in the profile. InnerImports []string + // Version is the {major, minor, patch} version of apparmor_parser as a single number. + Version int } - // generateDefault creates an apparmor profile from ProfileData. -@@ -45,6 +51,12 @@ func (p *profileData) generateDefault(out io.Writer) error { + // generate creates an AppArmor profile from ProfileData. +@@ -61,6 +65,12 @@ func generate(p *profileData, out io.Writer, macroExistsFn func(string) bool) er p.InnerImports = append(p.InnerImports, "#include <abstractions/base>") } @@ -292,10 +286,10 @@ } diff --git a/vendor/github.com/moby/profiles/apparmor/template.go b/vendor/github.com/moby/profiles/apparmor/template.go -index 2ebcc218a7..682425f71e 100644 +index 4694a6c6e1..181b6cdbd5 100644 --- a/vendor/github.com/moby/profiles/apparmor/template.go +++ b/vendor/github.com/moby/profiles/apparmor/template.go -@@ -22,6 +22,7 @@ profile {{.Name}} flags=(attach_disconnected,mediate_deleted) { +@@ -37,6 +37,7 @@ capability, file, umount, @@ -303,24 +297,25 @@ # Host (privileged) processes may send signals to container processes. signal (receive) peer=unconfined, # runc may send signals to container processes (for "docker stop"). -@@ -32,6 +33,7 @@ profile {{.Name}} flags=(attach_disconnected,mediate_deleted) { - signal (receive) peer={{.DaemonProfile}}, +@@ -47,6 +48,7 @@ + signal (receive) peer="{{.DaemonProfile}}", # Container processes may send signals amongst themselves. - signal (send,receive) peer={{.Name}}, + signal (send,receive) peer="{{.Name}}", +{{end}} deny @{PROC}/* w, # deny write for all files directly in /proc (not in a subdir) # deny write to files not in /proc/<number>/** or /proc/sys/** -@@ -52,7 +54,9 @@ profile {{.Name}} flags=(attach_disconnected,mediate_deleted) { +@@ -67,8 +69,10 @@ deny /sys/devices/virtual/powercap/** rwklx, deny /sys/kernel/security/** rwklx, +{{if ge .Version 208095}} - # suppress ptrace denials when using 'docker ps' or using 'ps' inside a container - ptrace (trace,read,tracedby,readby) peer={{.Name}}, + # allow processes within the container to trace each other, + # provided all other LSM and yama setting allow it. + ptrace (trace,tracedby,read,readby) peer="{{.Name}}", +{{end}} } ` -- -2.53.0 +2.54.0 ++++++ _service ++++++ --- /var/tmp/diff_new_pack.w6wWAV/_old 2026-09-12 21:16:19.529908201 +0200 +++ /var/tmp/diff_new_pack.w6wWAV/_new 2026-09-12 21:16:19.532908326 +0200 @@ -3,24 +3,24 @@ <param name="url">https://github.com/moby/moby.git</param> <param name="scm">git</param> <param name="exclude">.git</param> - <param name="versionformat">29.4.0_ce_%h</param> - <param name="revision">docker-v29.4.0</param> + <param name="versionformat">29.7.2_ce_%h</param> + <param name="revision">docker-v29.7.2</param> <param name="filename">docker</param> </service> <service name="tar_scm" mode="manual"> <param name="url">https://github.com/docker/cli.git</param> <param name="scm">git</param> <param name="exclude">.git</param> - <param name="versionformat">29.4.0_ce</param> - <param name="revision">v29.4.0</param> + <param name="versionformat">29.7.2_ce</param> + <param name="revision">v29.7.2</param> <param name="filename">docker-cli</param> </service> <service name="tar_scm" mode="manual"> <param name="url">https://github.com/docker/buildx.git</param> <param name="scm">git</param> <param name="exclude">.git</param> - <param name="versionformat">0.33.0</param> - <param name="revision">v0.33.0</param> + <param name="versionformat">0.36.1</param> + <param name="revision">v0.36.1</param> <param name="filename">docker-buildx</param> </service> <service name="recompress" mode="manual"> ++++++ cli-0001-openSUSE-point-users-to-docker-buildx-package.patch ++++++ --- /var/tmp/diff_new_pack.w6wWAV/_old 2026-09-12 21:16:19.547908949 +0200 +++ /var/tmp/diff_new_pack.w6wWAV/_new 2026-09-12 21:16:19.550909074 +0200 @@ -1,4 +1,4 @@ -From b9da04f83eeadb027d5f3a85186b9ada3c7723d2 Mon Sep 17 00:00:00 2001 +From 1b069c6dbffdd1124bbb56ced41c4c3803cb4d75 Mon Sep 17 00:00:00 2001 From: Aleksa Sarai <[email protected]> Date: Mon, 1 Sep 2025 16:05:24 +1000 Subject: [PATCH 1/2] openSUSE: point users to docker-buildx package @@ -8,12 +8,14 @@ need to install the "docker-buildx" package. Signed-off-by: Aleksa Sarai <[email protected]> +Signed-off-by: rcmadhankumar <[email protected]> +(cherry picked from commit b9da04f83eeadb027d5f3a85186b9ada3c7723d2) --- cmd/docker/builder.go | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/cmd/docker/builder.go b/cmd/docker/builder.go -index d6d74919b..3fc465f86 100644 +index d6d74919bc..3fc465f860 100644 --- a/cmd/docker/builder.go +++ b/cmd/docker/builder.go @@ -20,7 +20,7 @@ ++++++ cli-0002-SECRETS-SUSE-default-to-DOCKER_BUILDKIT-0-for-docker.patch ++++++ --- /var/tmp/diff_new_pack.w6wWAV/_old 2026-09-12 21:16:19.563909615 +0200 +++ /var/tmp/diff_new_pack.w6wWAV/_new 2026-09-12 21:16:19.567909781 +0200 @@ -1,4 +1,4 @@ -From d22fb5cb9087645b95df94038766e5b91564db66 Mon Sep 17 00:00:00 2001 +From e07c6ec89513797d39cc972570dfd0fd87e7f82a Mon Sep 17 00:00:00 2001 From: Aleksa Sarai <[email protected]> Date: Fri, 15 Aug 2025 19:55:53 +1000 Subject: [PATCH 2/2] SECRETS: SUSE: default to DOCKER_BUILDKIT=0 for "docker @@ -29,12 +29,14 @@ SUSE-Bug: https://jira.suse.com/browse/PED-8905 SUSE-Bug: https://bugzilla.suse.com/show_bug.cgi?id=1247594 Signed-off-by: Aleksa Sarai <[email protected]> +Signed-off-by: rcmadhankumar <[email protected]> +(cherry picked from commit d22fb5cb9087645b95df94038766e5b91564db66) --- cmd/docker/builder.go | 28 +++++++++++++++++++++++----- 1 file changed, 23 insertions(+), 5 deletions(-) diff --git a/cmd/docker/builder.go b/cmd/docker/builder.go -index 3fc465f86..60f2a8e9a 100644 +index 3fc465f860..60f2a8e9a4 100644 --- a/cmd/docker/builder.go +++ b/cmd/docker/builder.go @@ -23,9 +23,19 @@ ++++++ docker-29.4.0_ce_daa0cb7f23.tar.xz -> docker-29.7.2_ce_6a43e3d5af.tar.xz ++++++ /work/SRC/openSUSE:Factory/docker/docker-29.4.0_ce_daa0cb7f23.tar.xz /work/SRC/openSUSE:Factory/.docker.new.1265/docker-29.7.2_ce_6a43e3d5af.tar.xz differ: char 15, line 1 ++++++ docker-buildx-0.33.0.tar.xz -> docker-buildx-0.36.1.tar.xz ++++++ /work/SRC/openSUSE:Factory/docker/docker-buildx-0.33.0.tar.xz /work/SRC/openSUSE:Factory/.docker.new.1265/docker-buildx-0.36.1.tar.xz differ: char 15, line 1 ++++++ docker-cli-29.4.0_ce.tar.xz -> docker-cli-29.7.2_ce.tar.xz ++++++ ++++ 116070 lines of diff (skipped)
