Comments

37 Comments
karma

Seems to be working fine, no regressions I can see.

Tested, works fine locally

karma

Works here

BZ#1919391 CVE-2021-20206 containernetworking-cni: Arbitrary path injection via type field in CNI configuration
BZ#1925399 CVE-2021-20206 containernetworking-plugins: containernetworking-cni: Arbitrary path injection via type field in CNI configuration [fedora-all]
BZ#1926796 CVE-2021-20206 buildah: containernetworking-cni: Arbitrary path injection via type field in CNI configuration [fedora-all]
BZ#1926801 CVE-2021-20206 podman: containernetworking-cni: Arbitrary path injection via type field in CNI configuration [fedora-all]
karma

LGTM here

karma

Working fine locally

karma

Rootless seems to be working, no issues

karma

Seems to be working fine

karma

Seems fine, works as expected

karma

Launches containers fine over here

karma

Seems to work - nothing obviously wrong

User Icon mheon commented & provided feedback on crun-0.10-1.fc31 5 years ago
karma

Confirmed that this resolves Podman issues

Seems functional on my system, no obvious regressions

karma

No obvious conmon-related issues during brief testing

Podman networking working fine over here

BZ#1715758 CVE-2019-9946 containernetworking-plugins: kubernetes: Incorrect rule injection in CNI portmap plugin [fedora-all]

Podman seems fine, alleviates our AVCs

Working here

Looks good over here - the bug with 0.12.1 should be gone, everything else seems functional

BZ#1641800 Podman does not attach to container when uid is too long
BZ#1648668 podman assumes sbin in path
BZ#1657263 error setting up OCI Hooks: open /usr/share/containers/oci/hooks.d: no such file or directory

SELinux looks correct again. Spot-check on everything else looks good.

BZ#1638847 Privileged containers running as container_t instead of spc_t

Works locally with no apparent issues

SELinux issues appear to have been separate (container-selinux probably). This seems to work locally.