github-actions[bot] commented on code in PR #68352: URL: https://github.com/apache/doris/pull/68352#discussion_r4110858214
########## docker/runtime/base-image/Dockerfile_base: ########## @@ -26,15 +26,23 @@ FROM ubuntu:22.04 ARG TARGETARCH +# Kernel-header and -dev packages are deliberately absent. linux-tools-realtime pulls +# linux-tools-common, and libperl-dev/python2-dev pull linux-libc-dev + libc6-dev; all three +# are built from the `linux`/`glibc` source packages, so every kernel CVE Ubuntu tracks is +# reported against this image even though the packages ship only UAPI headers and perf wrapper +# scripts - the vulnerable code runs in the host kernel, which an image cannot patch. They also +# carry CVEs with no fixed version, so they can never be cleared by an apt upgrade. perf and the +# BCC tools they provided are host-kernel-coupled and need --privileged plus a matching kernel +# to be useful anyway; run them from a debug sidecar sharing the target's namespaces instead. Review Comment: [P1] Preserve or retire the built-in BE flamegraph path. The BE still exposes `/pprof/profile?type=flamegraph`, and its handler executes `perf --version`, `perf record`, and `perf script` from the BE container's own `PATH`. Removing `linux-tools` plus this symlink makes that advertised endpoint deterministically return `NotSupported`; a sidecar cannot satisfy an exec performed inside this container. Please either keep a usable `perf` in the BE/debug image path, or update the handler/UI and operator workflow in the same change so the unavailable mode is not offered. ########## docker/runtime/be/Dockerfile: ########## @@ -26,7 +26,7 @@ # get the binary from doris github and utar into resource, update the directory as apache-`version(example:2.0.1)`-bin-`architecture(amd64/arm64)` mode. # choose a base image -FROM apache/doris:base-6.0 +FROM apache/doris:base-6.1 Review Comment: [P1] Publish the new base before switching every runtime image. As of this exact head, Docker Hub returns manifest-unknown/404 for `apache/doris:base-6.1`, and `docker/runtime/docker-build.sh` builds the modified base only as `apache/doris:base-latest` before attempting these hard-coded component Dockerfiles. A clean FE/BE/MS image build therefore stops at `FROM`. Please publish and verify the amd64+arm64 `base-6.1` manifest first (as was done for `base-6.0`), or make the base reference overridable and have the helper build/tag the exact image it consumes. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
