Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package docker for openSUSE:Factory checked 
in at 2026-09-12 21:15:38
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/docker (Old)
 and      /work/SRC/openSUSE:Factory/.docker.new.1265 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "docker"

Sat Sep 12 21:15:38 2026 rev:187 rq:1377394 version:unknown

Changes:
--------
--- /work/SRC/openSUSE:Factory/docker/docker.changes    2026-06-29 
17:30:41.994730355 +0200
+++ /work/SRC/openSUSE:Factory/.docker.new.1265/docker.changes  2026-09-12 
21:16:18.331858376 +0200
@@ -1,0 +2,42 @@
+Thu Sep  3 06:30:01 UTC 2026 - Madhankumar Chellamuthu 
<[email protected]>
+
+- Ship the SELinux CIL policies from contrib/selinux/, loading
+  docker-af-alg-deny.cil (mitigates CVE-2026-31431) via semodule
+  when SELinux is enabled (bsc#1278193).
+
+-------------------------------------------------------------------
+Tue Aug 11 09:27:20 UTC 2026 - Madhankumar Chellamuthu 
<[email protected]>
+
+- Update to Docker 29.7.2. See upstream changelog online at
+  <https://docs.docker.com/engine/release-notes/29/#2972>
+- Update to buildx 0.36.1. See upstream changelog online at
+  <https://github.com/docker/buildx/releases/tag/v0.36.1>
+- Rebased patches:
+  * 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch
+  * 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
+  * 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch
+  * 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
+  * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
+    (renamed from 
0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch)
+  * cli-0001-openSUSE-point-users-to-docker-buildx-package.patch
+  * cli-0002-SECRETS-SUSE-default-to-DOCKER_BUILDKIT-0-for-docker.patch
+- Remove patches now fixed upstream:
+  - 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
+    (bsc#1099277, superseded by upstream commit 528a806141 "daemon:
+    Always reload AppArmor profile at daemon startup", which fixes
+    the same root cause: the daemon no longer skips reinstalling the
+    docker-default profile on upgrade)
+  - 0007-CVE-2026-39984-Ensure-correct-certificate-is-used-fo.patch
+    (bsc#1262346, CVE-2026-39984 fixed upstream via vendored
+    sigstore/timestamp-authority v2.1.2)
+  - 0008-CVE-2026-33814-http2-prevent-hanging-Transport-due-t.patch
+    (bsc#1265782, CVE-2026-33814 fixed upstream via vendored
+    golang.org/x/net v0.57.0)
+  - 0009-CVE-2026-39821-idna-update-from-x-text-fix-ToUnicode.patch
+    (bsc#1266625, CVE-2026-39821 fixed upstream via vendored
+    golang.org/x/net v0.57.0)
+  - 0010-CVE-2026-41567-daemon-Decompress-archives-before-ent.patch
+    (bsc#1267827, CVE-2026-41567 fixed upstream directly in moby/moby
+    via commit 2022313ffe)
+
+-------------------------------------------------------------------

Old:
----
  0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
  0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
  0007-CVE-2026-39984-Ensure-correct-certificate-is-used-fo.patch
  0008-CVE-2026-33814-http2-prevent-hanging-Transport-due-t.patch
  0009-CVE-2026-39821-idna-update-from-x-text-fix-ToUnicode.patch
  0010-CVE-2026-41567-daemon-Decompress-archives-before-ent.patch
  docker-29.4.0_ce_daa0cb7f23.tar.xz
  docker-buildx-0.33.0.tar.xz
  docker-cli-29.4.0_ce.tar.xz

New:
----
  0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
  docker-29.7.2_ce_6a43e3d5af.tar.xz
  docker-buildx-0.36.1.tar.xz
  docker-cli-29.7.2_ce.tar.xz

----------(Old B)----------
  Old:- Remove patches now fixed upstream:
  - 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
    (bsc#1099277, superseded by upstream commit 528a806141 "daemon:
  Old:  * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
    (renamed from 
0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch)
  * cli-0001-openSUSE-point-users-to-docker-buildx-package.patch
  Old:    docker-default profile on upgrade)
  - 0007-CVE-2026-39984-Ensure-correct-certificate-is-used-fo.patch
    (bsc#1262346, CVE-2026-39984 fixed upstream via vendored
  Old:    sigstore/timestamp-authority v2.1.2)
  - 0008-CVE-2026-33814-http2-prevent-hanging-Transport-due-t.patch
    (bsc#1265782, CVE-2026-33814 fixed upstream via vendored
  Old:    golang.org/x/net v0.57.0)
  - 0009-CVE-2026-39821-idna-update-from-x-text-fix-ToUnicode.patch
    (bsc#1266625, CVE-2026-39821 fixed upstream via vendored
  Old:    golang.org/x/net v0.57.0)
  - 0010-CVE-2026-41567-daemon-Decompress-archives-before-ent.patch
    (bsc#1267827, CVE-2026-41567 fixed upstream directly in moby/moby
----------(Old E)----------

----------(New B)----------
  New:  * 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
  * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
    (renamed from 
0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch)
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ docker.spec ++++++
--- /var/tmp/diff_new_pack.w6wWAV/_old  2026-09-12 21:16:19.387902295 +0200
+++ /var/tmp/diff_new_pack.w6wWAV/_new  2026-09-12 21:16:19.388902337 +0200
@@ -1,7 +1,7 @@
 #
 # spec file for package docker
 #
-# Copyright (c) 2024 SUSE LLC
+# Copyright (c) 2026 SUSE LLC and contributors
 #
 # All modifications and additions to the file contributed by third parties
 # remain the property of their copyright owners, unless otherwise agreed
@@ -53,8 +53,8 @@
 %endif
 
 # MANUAL: This needs to be updated with every docker update.
-%define docker_real_version 29.4.0
-%define docker_git_version daa0cb7f23
+%define docker_real_version 29.7.2
+%define docker_git_version 6a43e3d5af
 %define docker_version %{docker_real_version}_ce
 # This "nice version" is so that docker --version gives a result that can be
 # parsed by other people. boo#1182476
@@ -62,7 +62,7 @@
 
 %if %{with buildx}
 # MANUAL: This needs to be updated with every docker-buildx update.
-%define buildx_version 0.33.0
+%define buildx_version 0.36.1
 %endif
 
 # Used when generating the "build" information for Docker version. The value of
@@ -70,7 +70,7 @@
 # helpfully injects into our build environment from the changelog). If you want
 # to generate a new git_commit_epoch, use this:
 #  $ date --date="$(git show --format=fuller --date=iso $COMMIT_ID | grep -oP 
'(?<=^CommitDate: ).*')" '+%s'
-%define git_commit_epoch 1775550724
+%define git_commit_epoch 1785954267
 
 Name:           docker%{flavour}
 Version:        %{docker_version}
@@ -108,14 +108,8 @@
 Patch902:       
cli-0002-SECRETS-SUSE-default-to-DOCKER_BUILDKIT-0-for-docker.patch
 # UPSTREAM: Revert of upstream patch to keep SLE-12 build working.
 Patch200:       0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
-# UPSTREAM: Backport of <https://github.com/moby/moby/pull/41954>.
-Patch201:       0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
 # UPSTREAM: Revert of upstream patches to make apparmor work on SLE 12.
-Patch202:       0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
-Patch203:       0007-CVE-2026-39984-Ensure-correct-certificate-is-used-fo.patch
-Patch204:       0008-CVE-2026-33814-http2-prevent-hanging-Transport-due-t.patch
-Patch205:       0009-CVE-2026-39821-idna-update-from-x-text-fix-ToUnicode.patch
-Patch206:       0010-CVE-2026-41567-daemon-Decompress-archives-before-ent.patch
+Patch201:       0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
 BuildRequires:  audit
 BuildRequires:  bash-completion
 BuildRequires:  ca-certificates
@@ -134,8 +128,8 @@
 BuildRequires:  sysuser-tools
 BuildRequires:  zsh
 BuildRequires:  golang(API) >= 1.25
-BuildRequires:  pkgconfig(libsystemd)
 BuildRequires:  pkgconfig(libnftables)
+BuildRequires:  pkgconfig(libsystemd)
 %if %{with apparmor}
 %if 0%{?suse_version} >= 1500
 # This conditional only works on rpm>=4.13, which SLE 12 doesn't have. But we
@@ -390,18 +384,8 @@
 # Patches to build on SLE-12.
 %patch -P200 -p1
 %endif
-# bsc#1099277
-%patch -P201 -p1
 # Solves apparmor issues on SLE-12, but okay for newer SLE versions too.
-%patch -P202 -p1
-# bsc#1262346
-%patch -P203 -p1
-# bsc#1265782
-%patch -P204 -p1
-# bsc#1266625
-%patch -P205 -p1
-# bsc#1267827
-%patch -P206 -p1
+%patch -P201 -p1
 
 %build
 %sysusers_generate_pre %{SOURCE160} %{name} docker.conf
@@ -529,6 +513,12 @@
 # audit rules
 install -D -m0640 %{SOURCE140} 
%{buildroot}%{_sysconfdir}/audit/rules.d/docker.rules
 
+# SELinux policies. docker-af-alg-deny.cil denies AF_ALG sockets in
+# container domains (mitigates CVE-2026-31431); docker_client.cil is an
+# optional udica template for confining docker CLI clients. bsc#1278193
+install -d -m0755 %{buildroot}%{_datadir}/docker/selinux
+install -p -m0644 %{docker_builddir}/contrib/selinux/*.cil 
%{buildroot}%{_datadir}/docker/selinux/
+
 # sysconfig file
 install -D -m0644 %{SOURCE120} %{buildroot}%{_fillupdir}/sysconfig.docker
 
@@ -580,12 +570,21 @@
 %post
 %service_add_post docker.service docker.socket
 %{fillup_only -n docker}
+# Load the AF_ALG deny policy when SELinux is enabled. This may fail on
+# systems with SELinux userspace < 3.6, or without container-selinux's
+# container_domain attribute, so keep installation non-fatal. bsc#1278193
+if command -v semodule >/dev/null 2>&1 && selinuxenabled 2>/dev/null; then
+       semodule -i %{_datadir}/docker/selinux/docker-af-alg-deny.cil 
2>/dev/null || :
+fi
 
 %preun
 %service_del_preun docker.service docker.socket
 
 %postun
 %service_del_postun docker.service docker.socket
+if [ "$1" -eq 0 ] && command -v semodule >/dev/null 2>&1; then
+       semodule -r docker-af-alg-deny 2>/dev/null || :
+fi
 
 %files
 %defattr(-,root,root)
@@ -621,6 +620,10 @@
 %config %{_sysconfdir}/audit/rules.d/docker.rules
 %{_udevrulesdir}/80-docker.rules
 
+%dir %{_datadir}/docker
+%dir %{_datadir}/docker/selinux
+%{_datadir}/docker/selinux/*.cil
+
 %{_mandir}/man*/*%{ext_man}
 
 %if %{with buildx}

++++++ 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch ++++++
--- /var/tmp/diff_new_pack.w6wWAV/_old  2026-09-12 21:16:19.414903418 +0200
+++ /var/tmp/diff_new_pack.w6wWAV/_new  2026-09-12 21:16:19.417903543 +0200
@@ -1,7 +1,7 @@
-From 39cfc6ab1ba937f3c59a31536ee34ff43f362306 Mon Sep 17 00:00:00 2001
+From 6584c9aab47883bfc04c00b7f41afcad334a0762 Mon Sep 17 00:00:00 2001
 From: Aleksa Sarai <[email protected]>
 Date: Wed, 4 Jun 2025 15:01:37 +1000
-Subject: [PATCH 1/6] SECRETS: SUSE: always clear our internal secrets
+Subject: [PATCH 1/5] SECRETS: SUSE: always clear our internal secrets
 
 In the future SUSEConnect support patch, we will add swarm secrets with
 the ID suse_* containing credentials pertinent to SUSEConnect.
@@ -24,6 +24,8 @@
 
 SUSE-Bugs: bsc#1244035 bsc#1057743
 Signed-off-by: Aleksa Sarai <[email protected]>
+Signed-off-by: rcmadhankumar <[email protected]>
+(cherry picked from commit 39cfc6ab1ba937f3c59a31536ee34ff43f362306)
 ---
  daemon/start.go        | 10 ++++++++++
  daemon/suse_secrets.go | 44 ++++++++++++++++++++++++++++++++++++++++++
@@ -102,6 +104,6 @@
 +      c.SecretReferences = without
 +}
 -- 
-2.53.0
+2.54.0
 
 

++++++ 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch ++++++
--- /var/tmp/diff_new_pack.w6wWAV/_old  2026-09-12 21:16:19.430904083 +0200
+++ /var/tmp/diff_new_pack.w6wWAV/_new  2026-09-12 21:16:19.433904208 +0200
@@ -1,7 +1,7 @@
-From e6936c41e4dbb1fe2ef072a5b4a31c9399785fbe Mon Sep 17 00:00:00 2001
+From 8e746c9bcf00c0921a52d49bb4ced3c855c4eb4c Mon Sep 17 00:00:00 2001
 From: Aleksa Sarai <[email protected]>
 Date: Wed, 8 Mar 2017 12:41:54 +1100
-Subject: [PATCH 2/6] SECRETS: daemon: allow directory creation in /run/secrets
+Subject: [PATCH 2/5] SECRETS: daemon: allow directory creation in /run/secrets
 
 Since FileMode can have the directory bit set, allow a SecretStore
 implementation to return secrets that are actually directories. This is
@@ -9,12 +9,14 @@
 
 Signed-off-by: Antonio Murdaca <[email protected]>
 Signed-off-by: Aleksa Sarai <[email protected]>
+Signed-off-by: rcmadhankumar <[email protected]>
+(cherry picked from commit e6936c41e4dbb1fe2ef072a5b4a31c9399785fbe)
 ---
  daemon/container_operations_unix.go | 23 ++++++++++++++++++++---
  1 file changed, 20 insertions(+), 3 deletions(-)
 
 diff --git a/daemon/container_operations_unix.go 
b/daemon/container_operations_unix.go
-index 146025ff89..2d76615341 100644
+index a41a4cbb5c..65db764fc5 100644
 --- a/daemon/container_operations_unix.go
 +++ b/daemon/container_operations_unix.go
 @@ -3,6 +3,7 @@
@@ -25,7 +27,7 @@
        "context"
        "fmt"
        "os"
-@@ -22,6 +23,7 @@ import (
+@@ -23,6 +24,7 @@
        "github.com/moby/moby/v2/daemon/network"
        "github.com/moby/moby/v2/errdefs"
        "github.com/moby/moby/v2/pkg/process"
@@ -33,7 +35,7 @@
        "github.com/moby/sys/mount"
        "github.com/moby/sys/user"
        "github.com/opencontainers/selinux/go-selinux/label"
-@@ -329,9 +331,6 @@ func (daemon *Daemon) setupSecretDir(ctr 
*container.Container) (setupErr error)
+@@ -330,9 +332,6 @@ func (daemon *Daemon) setupSecretDir(ctr 
*container.Container) (setupErr error)
                if err != nil {
                        return errors.Wrap(err, "unable to get secret from 
secret store")
                }
@@ -43,7 +45,7 @@
  
                uid, err := strconv.Atoi(s.File.UID)
                if err != nil {
-@@ -342,6 +341,24 @@ func (daemon *Daemon) setupSecretDir(ctr 
*container.Container) (setupErr error)
+@@ -343,6 +342,24 @@ func (daemon *Daemon) setupSecretDir(ctr 
*container.Container) (setupErr error)
                        return err
                }
  
@@ -69,6 +71,6 @@
                        return errors.Wrap(err, "error setting ownership for 
secret")
                }
 -- 
-2.53.0
+2.54.0
 
 

++++++ 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch ++++++
--- /var/tmp/diff_new_pack.w6wWAV/_old  2026-09-12 21:16:19.445904707 +0200
+++ /var/tmp/diff_new_pack.w6wWAV/_new  2026-09-12 21:16:19.449904874 +0200
@@ -1,7 +1,7 @@
-From 65a6fc5f7829a14c83e559d9129ed080c1f12baf Mon Sep 17 00:00:00 2001
+From 9816d94bbd456d0a47b29d4c73860b1437a96cc9 Mon Sep 17 00:00:00 2001
 From: Aleksa Sarai <[email protected]>
 Date: Wed, 8 Mar 2017 11:43:29 +1100
-Subject: [PATCH 3/6] SECRETS: SUSE: implement SUSE container secrets
+Subject: [PATCH 3/5] SECRETS: SUSE: implement SUSE container secrets
 
 This allows for us to pass in host credentials to a container, allowing
 for SUSEConnect to work with containers.
@@ -16,6 +16,8 @@
 
 SUSE-Bugs: bsc#1065609 bsc#1057743 bsc#1055676 bsc#1030702 bsc#1231348 
bsc#1240150
 Signed-off-by: Aleksa Sarai <[email protected]>
+Signed-off-by: rcmadhankumar <[email protected]>
+(cherry picked from commit 65a6fc5f7829a14c83e559d9129ed080c1f12baf)
 ---
  daemon/start.go        |   5 +
  daemon/suse_secrets.go | 439 +++++++++++++++++++++++++++++++++++++++++
@@ -501,6 +503,6 @@
 +      return nil
 +}
 -- 
-2.53.0
+2.54.0
 
 

++++++ 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch ++++++
--- /var/tmp/diff_new_pack.w6wWAV/_old  2026-09-12 21:16:19.460905331 +0200
+++ /var/tmp/diff_new_pack.w6wWAV/_new  2026-09-12 21:16:19.463905456 +0200
@@ -1,7 +1,7 @@
-From 294173206a84069de026c3975cd9f70e5c0cb501 Mon Sep 17 00:00:00 2001
+From c012c8bf7ba29dd00b010cd45636ba902dfe0b4e Mon Sep 17 00:00:00 2001
 From: Aleksa Sarai <[email protected]>
 Date: Mon, 22 May 2023 15:44:54 +1000
-Subject: [PATCH 4/6] BUILD: SLE12: revert "graphdriver/btrfs: use kernel UAPI
+Subject: [PATCH 4/5] BUILD: SLE12: revert "graphdriver/btrfs: use kernel UAPI
  headers"
 
 This reverts commit 3208dcabdc8997340b255f5b880fef4e3f54580d.
@@ -11,15 +11,17 @@
 for SLE-12.
 
 Signed-off-by: Aleksa Sarai <[email protected]>
+Signed-off-by: rcmadhankumar <[email protected]>
+(cherry picked from commit 294173206a84069de026c3975cd9f70e5c0cb501)
 ---
  daemon/graphdriver/btrfs/btrfs.go | 13 ++++---------
  1 file changed, 4 insertions(+), 9 deletions(-)
 
 diff --git a/daemon/graphdriver/btrfs/btrfs.go 
b/daemon/graphdriver/btrfs/btrfs.go
-index 5f6ead6c7e..ab45a3cec1 100644
+index 35cf7d1104..fff51e3794 100644
 --- a/daemon/graphdriver/btrfs/btrfs.go
 +++ b/daemon/graphdriver/btrfs/btrfs.go
-@@ -4,17 +4,12 @@ package btrfs
+@@ -4,17 +4,12 @@
  
  /*
  #include <stdlib.h>
@@ -42,6 +44,6 @@
  static void set_name_btrfs_ioctl_vol_args_v2(struct btrfs_ioctl_vol_args_v2* 
btrfs_struct, const char* value) {
      snprintf(btrfs_struct->name, BTRFS_SUBVOL_NAME_MAX, "%s", value);
 -- 
-2.53.0
+2.54.0
 
 

++++++ 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch -> 
0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch ++++++
--- 
/work/SRC/openSUSE:Factory/docker/0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
   2026-05-13 17:21:00.215439186 +0200
+++ 
/work/SRC/openSUSE:Factory/.docker.new.1265/0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
 2026-09-12 21:16:16.842796448 +0200
@@ -1,7 +1,7 @@
-From e1e27add6a799e8973e7b3777ec3187ebd86c523 Mon Sep 17 00:00:00 2001
+From cfc9eee8433d1d064bafebff1be64b1296263ed1 Mon Sep 17 00:00:00 2001
 From: Aleksa Sarai <[email protected]>
 Date: Wed, 11 Oct 2023 21:19:12 +1100
-Subject: [PATCH 6/6] SLE12: revert "apparmor: remove version-conditionals from
+Subject: [PATCH 5/5] SLE12: revert "apparmor: remove version-conditionals from
  template"
 
 This reverts the following commits:
@@ -16,20 +16,22 @@
 apparmor_parser version is quite old.
 
 Signed-off-by: Aleksa Sarai <[email protected]>
+Signed-off-by: rcmadhankumar <[email protected]>
+(cherry picked from commit e1e27add6a799e8973e7b3777ec3187ebd86c523)
 ---
  contrib/apparmor/main.go                      | 16 +++-
  contrib/apparmor/template.go                  | 16 ++++
  pkg/aaparser/aaparser.go                      | 86 +++++++++++++++++++
- .../moby/profiles/apparmor/apparmor.go        | 16 +++-
+ .../moby/profiles/apparmor/apparmor.go        | 10 +++
  .../moby/profiles/apparmor/template.go        |  4 +
- 5 files changed, 134 insertions(+), 4 deletions(-)
+ 5 files changed, 130 insertions(+), 2 deletions(-)
  create mode 100644 pkg/aaparser/aaparser.go
 
 diff --git a/contrib/apparmor/main.go b/contrib/apparmor/main.go
 index 899d8378ed..13caa8245e 100644
 --- a/contrib/apparmor/main.go
 +++ b/contrib/apparmor/main.go
-@@ -6,9 +6,13 @@ import (
+@@ -6,9 +6,13 @@
        "os"
        "path"
        "text/template"
@@ -72,7 +74,7 @@
 index 58afcbe845..e6d0b6d37c 100644
 --- a/contrib/apparmor/template.go
 +++ b/contrib/apparmor/template.go
-@@ -20,9 +20,11 @@ profile /usr/bin/docker (attach_disconnected, complain) {
+@@ -20,9 +20,11 @@
  
    umount,
    pivot_root,
@@ -84,7 +86,7 @@
    network,
    capability,
    owner /** rw,
-@@ -45,10 +47,12 @@ profile /usr/bin/docker (attach_disconnected, complain) {
+@@ -45,10 +47,12 @@
    /etc/ld.so.cache r,
    /etc/passwd r,
  
@@ -97,7 +99,7 @@
  
    /usr/lib/** rm,
    /lib/** rm,
-@@ -69,9 +73,11 @@ profile /usr/bin/docker (attach_disconnected, complain) {
+@@ -69,9 +73,11 @@
    /sbin/zfs rCx,
    /sbin/apparmor_parser rCx,
  
@@ -109,7 +111,7 @@
  
    profile /bin/cat (complain) {
      /etc/ld.so.cache r,
-@@ -93,8 +99,10 @@ profile /usr/bin/docker (attach_disconnected, complain) {
+@@ -93,8 +99,10 @@
      /dev/null rw,
      /bin/ps mr,
  
@@ -120,7 +122,7 @@
  
      # Quiet dac_override denials
      deny capability dac_override,
-@@ -112,11 +120,15 @@ profile /usr/bin/docker (attach_disconnected, complain) {
+@@ -112,11 +120,15 @@
      /proc/tty/drivers r,
    }
    profile /sbin/iptables (complain) {
@@ -136,7 +138,7 @@
      capability sys_admin,
      capability dac_override,
  
-@@ -135,7 +147,9 @@ profile /usr/bin/docker (attach_disconnected, complain) {
+@@ -135,7 +147,9 @@
      /proc/[0-9]*/mounts rw,
    }
    profile /sbin/modprobe /bin/kmod (complain) {
@@ -146,7 +148,7 @@
      capability sys_module,
      /etc/ld.so.cache r,
      /lib/** rm,
-@@ -149,7 +163,9 @@ profile /usr/bin/docker (attach_disconnected, complain) {
+@@ -149,7 +163,9 @@
    }
    # xz works via pipes, so we do not need access to the filesystem.
    profile /usr/bin/xz (complain) {
@@ -249,36 +251,28 @@
 +      return numericVersion, nil
 +}
 diff --git a/vendor/github.com/moby/profiles/apparmor/apparmor.go 
b/vendor/github.com/moby/profiles/apparmor/apparmor.go
-index 445eed64e9..060a482289 100644
+index 244ae70fb2..af79e08980 100644
 --- a/vendor/github.com/moby/profiles/apparmor/apparmor.go
 +++ b/vendor/github.com/moby/profiles/apparmor/apparmor.go
-@@ -11,10 +11,14 @@ import (
-       "path"
+@@ -16,6 +16,8 @@
+       "path/filepath"
        "strings"
        "text/template"
 +
 +      "github.com/moby/moby/v2/pkg/aaparser"
  )
  
--// profileDirectory is the file store for apparmor profiles and macros.
--const profileDirectory = "/etc/apparmor.d"
-+var (
-+      // profileDirectory is the file store for apparmor profiles and macros.
-+      profileDirectory = "/etc/apparmor.d"
-+)
- 
- // profileData holds information about the given profile for generation.
- type profileData struct {
-@@ -26,6 +30,8 @@ type profileData struct {
+ // profileDirectory is the file store for AppArmor profiles and macros.
+@@ -33,6 +35,8 @@ type profileData struct {
        Imports []string
-       // InnerImports defines the apparmor functions to import in the profile.
+       // InnerImports defines the AppArmor functions to import in the profile.
        InnerImports []string
 +      // Version is the {major, minor, patch} version of apparmor_parser as a 
single number.
 +      Version int
  }
  
- // generateDefault creates an apparmor profile from ProfileData.
-@@ -45,6 +51,12 @@ func (p *profileData) generateDefault(out io.Writer) error {
+ // generate creates an AppArmor profile from ProfileData.
+@@ -61,6 +65,12 @@ func generate(p *profileData, out io.Writer, macroExistsFn 
func(string) bool) er
                p.InnerImports = append(p.InnerImports, "#include 
<abstractions/base>")
        }
  
@@ -292,10 +286,10 @@
  }
  
 diff --git a/vendor/github.com/moby/profiles/apparmor/template.go 
b/vendor/github.com/moby/profiles/apparmor/template.go
-index 2ebcc218a7..682425f71e 100644
+index 4694a6c6e1..181b6cdbd5 100644
 --- a/vendor/github.com/moby/profiles/apparmor/template.go
 +++ b/vendor/github.com/moby/profiles/apparmor/template.go
-@@ -22,6 +22,7 @@ profile {{.Name}} 
flags=(attach_disconnected,mediate_deleted) {
+@@ -37,6 +37,7 @@
    capability,
    file,
    umount,
@@ -303,24 +297,25 @@
    # Host (privileged) processes may send signals to container processes.
    signal (receive) peer=unconfined,
    # runc may send signals to container processes (for "docker stop").
-@@ -32,6 +33,7 @@ profile {{.Name}} 
flags=(attach_disconnected,mediate_deleted) {
-   signal (receive) peer={{.DaemonProfile}},
+@@ -47,6 +48,7 @@
+   signal (receive) peer="{{.DaemonProfile}}",
    # Container processes may send signals amongst themselves.
-   signal (send,receive) peer={{.Name}},
+   signal (send,receive) peer="{{.Name}}",
 +{{end}}
  
    deny @{PROC}/* w,   # deny write for all files directly in /proc (not in a 
subdir)
    # deny write to files not in /proc/<number>/** or /proc/sys/**
-@@ -52,7 +54,9 @@ profile {{.Name}} 
flags=(attach_disconnected,mediate_deleted) {
+@@ -67,8 +69,10 @@
    deny /sys/devices/virtual/powercap/** rwklx,
    deny /sys/kernel/security/** rwklx,
  
 +{{if ge .Version 208095}}
-   # suppress ptrace denials when using 'docker ps' or using 'ps' inside a 
container
-   ptrace (trace,read,tracedby,readby) peer={{.Name}},
+   # allow processes within the container to trace each other,
+   # provided all other LSM and yama setting allow it.
+   ptrace (trace,tracedby,read,readby) peer="{{.Name}}",
 +{{end}}
  }
  `
 -- 
-2.53.0
+2.54.0
 

++++++ _service ++++++
--- /var/tmp/diff_new_pack.w6wWAV/_old  2026-09-12 21:16:19.529908201 +0200
+++ /var/tmp/diff_new_pack.w6wWAV/_new  2026-09-12 21:16:19.532908326 +0200
@@ -3,24 +3,24 @@
     <param name="url">https://github.com/moby/moby.git</param>
     <param name="scm">git</param>
     <param name="exclude">.git</param>
-    <param name="versionformat">29.4.0_ce_%h</param>
-    <param name="revision">docker-v29.4.0</param>
+    <param name="versionformat">29.7.2_ce_%h</param>
+    <param name="revision">docker-v29.7.2</param>
     <param name="filename">docker</param>
   </service>
   <service name="tar_scm" mode="manual">
     <param name="url">https://github.com/docker/cli.git</param>
     <param name="scm">git</param>
     <param name="exclude">.git</param>
-    <param name="versionformat">29.4.0_ce</param>
-    <param name="revision">v29.4.0</param>
+    <param name="versionformat">29.7.2_ce</param>
+    <param name="revision">v29.7.2</param>
     <param name="filename">docker-cli</param>
   </service>
   <service name="tar_scm" mode="manual">
     <param name="url">https://github.com/docker/buildx.git</param>
     <param name="scm">git</param>
     <param name="exclude">.git</param>
-    <param name="versionformat">0.33.0</param>
-    <param name="revision">v0.33.0</param>
+    <param name="versionformat">0.36.1</param>
+    <param name="revision">v0.36.1</param>
     <param name="filename">docker-buildx</param>
   </service>
   <service name="recompress" mode="manual">

++++++ cli-0001-openSUSE-point-users-to-docker-buildx-package.patch ++++++
--- /var/tmp/diff_new_pack.w6wWAV/_old  2026-09-12 21:16:19.547908949 +0200
+++ /var/tmp/diff_new_pack.w6wWAV/_new  2026-09-12 21:16:19.550909074 +0200
@@ -1,4 +1,4 @@
-From b9da04f83eeadb027d5f3a85186b9ada3c7723d2 Mon Sep 17 00:00:00 2001
+From 1b069c6dbffdd1124bbb56ced41c4c3803cb4d75 Mon Sep 17 00:00:00 2001
 From: Aleksa Sarai <[email protected]>
 Date: Mon, 1 Sep 2025 16:05:24 +1000
 Subject: [PATCH 1/2] openSUSE: point users to docker-buildx package
@@ -8,12 +8,14 @@
 need to install the "docker-buildx" package.
 
 Signed-off-by: Aleksa Sarai <[email protected]>
+Signed-off-by: rcmadhankumar <[email protected]>
+(cherry picked from commit b9da04f83eeadb027d5f3a85186b9ada3c7723d2)
 ---
  cmd/docker/builder.go | 6 +++---
  1 file changed, 3 insertions(+), 3 deletions(-)
 
 diff --git a/cmd/docker/builder.go b/cmd/docker/builder.go
-index d6d74919b..3fc465f86 100644
+index d6d74919bc..3fc465f860 100644
 --- a/cmd/docker/builder.go
 +++ b/cmd/docker/builder.go
 @@ -20,7 +20,7 @@

++++++ cli-0002-SECRETS-SUSE-default-to-DOCKER_BUILDKIT-0-for-docker.patch 
++++++
--- /var/tmp/diff_new_pack.w6wWAV/_old  2026-09-12 21:16:19.563909615 +0200
+++ /var/tmp/diff_new_pack.w6wWAV/_new  2026-09-12 21:16:19.567909781 +0200
@@ -1,4 +1,4 @@
-From d22fb5cb9087645b95df94038766e5b91564db66 Mon Sep 17 00:00:00 2001
+From e07c6ec89513797d39cc972570dfd0fd87e7f82a Mon Sep 17 00:00:00 2001
 From: Aleksa Sarai <[email protected]>
 Date: Fri, 15 Aug 2025 19:55:53 +1000
 Subject: [PATCH 2/2] SECRETS: SUSE: default to DOCKER_BUILDKIT=0 for "docker
@@ -29,12 +29,14 @@
 SUSE-Bug: https://jira.suse.com/browse/PED-8905
 SUSE-Bug: https://bugzilla.suse.com/show_bug.cgi?id=1247594
 Signed-off-by: Aleksa Sarai <[email protected]>
+Signed-off-by: rcmadhankumar <[email protected]>
+(cherry picked from commit d22fb5cb9087645b95df94038766e5b91564db66)
 ---
  cmd/docker/builder.go | 28 +++++++++++++++++++++++-----
  1 file changed, 23 insertions(+), 5 deletions(-)
 
 diff --git a/cmd/docker/builder.go b/cmd/docker/builder.go
-index 3fc465f86..60f2a8e9a 100644
+index 3fc465f860..60f2a8e9a4 100644
 --- a/cmd/docker/builder.go
 +++ b/cmd/docker/builder.go
 @@ -23,9 +23,19 @@

++++++ docker-29.4.0_ce_daa0cb7f23.tar.xz -> docker-29.7.2_ce_6a43e3d5af.tar.xz 
++++++
/work/SRC/openSUSE:Factory/docker/docker-29.4.0_ce_daa0cb7f23.tar.xz 
/work/SRC/openSUSE:Factory/.docker.new.1265/docker-29.7.2_ce_6a43e3d5af.tar.xz 
differ: char 15, line 1

++++++ docker-buildx-0.33.0.tar.xz -> docker-buildx-0.36.1.tar.xz ++++++
/work/SRC/openSUSE:Factory/docker/docker-buildx-0.33.0.tar.xz 
/work/SRC/openSUSE:Factory/.docker.new.1265/docker-buildx-0.36.1.tar.xz differ: 
char 15, line 1

++++++ docker-cli-29.4.0_ce.tar.xz -> docker-cli-29.7.2_ce.tar.xz ++++++
++++ 116070 lines of diff (skipped)

Reply via email to