Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package inspektor-gadget for 
openSUSE:Factory checked in at 2026-10-02 23:03:34
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/inspektor-gadget (Old)
 and      /work/SRC/openSUSE:Factory/.inspektor-gadget.new.1631729 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "inspektor-gadget"

Fri Oct  2 23:03:34 2026 rev:40 rq:1381989 version:0.56.2

Changes:
--------
--- /work/SRC/openSUSE:Factory/inspektor-gadget/inspektor-gadget.changes        
2026-09-28 10:48:54.703134236 +0200
+++ 
/work/SRC/openSUSE:Factory/.inspektor-gadget.new.1631729/inspektor-gadget.changes
   2026-10-02 23:04:16.343624844 +0200
@@ -1,0 +2,8 @@
+Fri Oct 02 04:52:31 UTC 2026 - Johannes Kastl 
<[email protected]>
+
+- Update to version 0.56.2:
+  * Bugfixes
+    - [BACKPORT] container-collection: Bound the owner reference
+      enrichment loop. in #5816
+
+-------------------------------------------------------------------

Old:
----
  inspektor-gadget-0.56.1.obscpio

New:
----
  inspektor-gadget-0.56.2.obscpio

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ inspektor-gadget.spec ++++++
--- /var/tmp/diff_new_pack.VbUrAi/_old  2026-10-02 23:04:18.248704580 +0200
+++ /var/tmp/diff_new_pack.VbUrAi/_new  2026-10-02 23:04:18.252704747 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           inspektor-gadget
-Version:        0.56.1
+Version:        0.56.2
 Release:        0
 Summary:        A eBPF tool and systems inspection framework
 License:        Apache-2.0

++++++ _service ++++++
--- /var/tmp/diff_new_pack.VbUrAi/_old  2026-10-02 23:04:18.344708598 +0200
+++ /var/tmp/diff_new_pack.VbUrAi/_new  2026-10-02 23:04:18.354709017 +0200
@@ -3,7 +3,7 @@
     <param 
name="url">https://github.com/inspektor-gadget/inspektor-gadget.git</param>
     <param name="scm">git</param>
     <param name="exclude">.git</param>
-    <param name="revision">refs/tags/v0.56.1</param>
+    <param name="revision">refs/tags/v0.56.2</param>
     <param name="versionformat">@PARENT_TAG@</param>
     <param name="versionrewrite-pattern">v(.*)</param>
     <param name="changesgenerate">enable</param>

++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.VbUrAi/_old  2026-10-02 23:04:18.416711612 +0200
+++ /var/tmp/diff_new_pack.VbUrAi/_new  2026-10-02 23:04:18.426712030 +0200
@@ -3,6 +3,6 @@
                 <param 
name="url">https://github.com/inspektor-gadget/inspektor-gadget</param>
               <param 
name="changesrevision">7a314380ff61534ea70df9fb086505f958b2dff9</param></service><service
 name="tar_scm">
                 <param 
name="url">https://github.com/inspektor-gadget/inspektor-gadget.git</param>
-              <param 
name="changesrevision">815346241cb6727badef69b4db6ead6cf29eff2b</param></service></servicedata>
+              <param 
name="changesrevision">9e8cca605d7923b9e8db281bf9e3c6617089aa8d</param></service></servicedata>
 (No newline at EOF)
 

++++++ inspektor-gadget-0.56.1.obscpio -> inspektor-gadget-0.56.2.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/inspektor-gadget-0.56.1/pkg/container-collection/containers.go 
new/inspektor-gadget-0.56.2/pkg/container-collection/containers.go
--- old/inspektor-gadget-0.56.1/pkg/container-collection/containers.go  
2026-09-25 10:16:17.000000000 +0200
+++ new/inspektor-gadget-0.56.2/pkg/container-collection/containers.go  
2026-10-01 14:42:30.000000000 +0200
@@ -147,6 +147,12 @@
        return c.K8s.ownerReference, nil
 }
 
+// maxOwnerReferenceDepth caps how many owner-reference hops the enricher will
+// follow before giving up. Legitimate Kubernetes controller chains are shallow
+// (Pod -> ReplicaSet -> Deployment, Pod -> Job -> CronJob: depth 3); this cap
+// is a defensive backstop paired with the visited-set cycle check below.
+const maxOwnerReferenceDepth = 8
+
 func ownerReferenceEnrichment(
        dynamicClient dynamic.Interface,
        container *Container,
@@ -159,10 +165,24 @@
 
        var highestOwnerRef *metav1.OwnerReference
 
+       // Kubernetes tolerates cycles in metadata.ownerReferences (the garbage
+       // collector declines to delete them rather than rejecting them at
+       // admission), so an unprivileged namespaced user can craft a cyclic
+       // ownership graph. Without a visited set this loop walks the graph as
+       // if it were a tree and never terminates, hammering the apiserver and
+       // wedging the caller (the container-hook FAN_ACCESS_PERM permission
+       // response is deferred until AddContainer returns).
+       type visitedKey struct {
+               namespace, kind, name string
+       }
+       visited := map[visitedKey]struct{}{
+               {resNamespace, resKind, resName}: {},
+       }
+
        // Iterate until we reach the highest level of reference with one of the
        // expected resource kind. Take into account that if this logic is 
changed,
        // the gadget cluster role needs to be updated accordingly.
-       for {
+       for depth := 0; depth < maxOwnerReferenceDepth; depth++ {
                if len(ownerReferences) == 0 {
                        var err error
                        ownerReferences, err = getOwnerReferences(dynamicClient,
@@ -190,6 +210,15 @@
                resKind = strings.ToLower(ownerRef.Kind) + "s"
                resName = ownerRef.Name
                ownerReferences = nil
+
+               next := visitedKey{resNamespace, resKind, resName}
+               if _, seen := visited[next]; seen {
+                       // Cycle in ownerReferences; stop walking and keep the 
last
+                       // valid owner we saw. Returning an error would just 
make the
+                       // caller log and continue, dropping the partial 
enrichment.
+                       break
+               }
+               visited[next] = struct{}{}
        }
 
        // Update container's owner reference (If any)

++++++ inspektor-gadget.obsinfo ++++++
--- /var/tmp/diff_new_pack.VbUrAi/_old  2026-10-02 23:04:22.191869619 +0200
+++ /var/tmp/diff_new_pack.VbUrAi/_new  2026-10-02 23:04:22.203870121 +0200
@@ -1,5 +1,5 @@
 name: inspektor-gadget
-version: 0.56.1
-mtime: 1790324177
-commit: 815346241cb6727badef69b4db6ead6cf29eff2b
+version: 0.56.2
+mtime: 1790858550
+commit: 9e8cca605d7923b9e8db281bf9e3c6617089aa8d
 

++++++ vendor.tar.gz ++++++
/work/SRC/openSUSE:Factory/inspektor-gadget/vendor.tar.gz 
/work/SRC/openSUSE:Factory/.inspektor-gadget.new.1631729/vendor.tar.gz differ: 
char 134, line 3

Reply via email to