Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package inspektor-gadget for openSUSE:Factory checked in at 2026-10-02 23:03:34 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/inspektor-gadget (Old) and /work/SRC/openSUSE:Factory/.inspektor-gadget.new.1631729 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "inspektor-gadget" Fri Oct 2 23:03:34 2026 rev:40 rq:1381989 version:0.56.2 Changes: -------- --- /work/SRC/openSUSE:Factory/inspektor-gadget/inspektor-gadget.changes 2026-09-28 10:48:54.703134236 +0200 +++ /work/SRC/openSUSE:Factory/.inspektor-gadget.new.1631729/inspektor-gadget.changes 2026-10-02 23:04:16.343624844 +0200 @@ -1,0 +2,8 @@ +Fri Oct 02 04:52:31 UTC 2026 - Johannes Kastl <[email protected]> + +- Update to version 0.56.2: + * Bugfixes + - [BACKPORT] container-collection: Bound the owner reference + enrichment loop. in #5816 + +------------------------------------------------------------------- Old: ---- inspektor-gadget-0.56.1.obscpio New: ---- inspektor-gadget-0.56.2.obscpio ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ inspektor-gadget.spec ++++++ --- /var/tmp/diff_new_pack.VbUrAi/_old 2026-10-02 23:04:18.248704580 +0200 +++ /var/tmp/diff_new_pack.VbUrAi/_new 2026-10-02 23:04:18.252704747 +0200 @@ -17,7 +17,7 @@ Name: inspektor-gadget -Version: 0.56.1 +Version: 0.56.2 Release: 0 Summary: A eBPF tool and systems inspection framework License: Apache-2.0 ++++++ _service ++++++ --- /var/tmp/diff_new_pack.VbUrAi/_old 2026-10-02 23:04:18.344708598 +0200 +++ /var/tmp/diff_new_pack.VbUrAi/_new 2026-10-02 23:04:18.354709017 +0200 @@ -3,7 +3,7 @@ <param name="url">https://github.com/inspektor-gadget/inspektor-gadget.git</param> <param name="scm">git</param> <param name="exclude">.git</param> - <param name="revision">refs/tags/v0.56.1</param> + <param name="revision">refs/tags/v0.56.2</param> <param name="versionformat">@PARENT_TAG@</param> <param name="versionrewrite-pattern">v(.*)</param> <param name="changesgenerate">enable</param> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.VbUrAi/_old 2026-10-02 23:04:18.416711612 +0200 +++ /var/tmp/diff_new_pack.VbUrAi/_new 2026-10-02 23:04:18.426712030 +0200 @@ -3,6 +3,6 @@ <param name="url">https://github.com/inspektor-gadget/inspektor-gadget</param> <param name="changesrevision">7a314380ff61534ea70df9fb086505f958b2dff9</param></service><service name="tar_scm"> <param name="url">https://github.com/inspektor-gadget/inspektor-gadget.git</param> - <param name="changesrevision">815346241cb6727badef69b4db6ead6cf29eff2b</param></service></servicedata> + <param name="changesrevision">9e8cca605d7923b9e8db281bf9e3c6617089aa8d</param></service></servicedata> (No newline at EOF) ++++++ inspektor-gadget-0.56.1.obscpio -> inspektor-gadget-0.56.2.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/inspektor-gadget-0.56.1/pkg/container-collection/containers.go new/inspektor-gadget-0.56.2/pkg/container-collection/containers.go --- old/inspektor-gadget-0.56.1/pkg/container-collection/containers.go 2026-09-25 10:16:17.000000000 +0200 +++ new/inspektor-gadget-0.56.2/pkg/container-collection/containers.go 2026-10-01 14:42:30.000000000 +0200 @@ -147,6 +147,12 @@ return c.K8s.ownerReference, nil } +// maxOwnerReferenceDepth caps how many owner-reference hops the enricher will +// follow before giving up. Legitimate Kubernetes controller chains are shallow +// (Pod -> ReplicaSet -> Deployment, Pod -> Job -> CronJob: depth 3); this cap +// is a defensive backstop paired with the visited-set cycle check below. +const maxOwnerReferenceDepth = 8 + func ownerReferenceEnrichment( dynamicClient dynamic.Interface, container *Container, @@ -159,10 +165,24 @@ var highestOwnerRef *metav1.OwnerReference + // Kubernetes tolerates cycles in metadata.ownerReferences (the garbage + // collector declines to delete them rather than rejecting them at + // admission), so an unprivileged namespaced user can craft a cyclic + // ownership graph. Without a visited set this loop walks the graph as + // if it were a tree and never terminates, hammering the apiserver and + // wedging the caller (the container-hook FAN_ACCESS_PERM permission + // response is deferred until AddContainer returns). + type visitedKey struct { + namespace, kind, name string + } + visited := map[visitedKey]struct{}{ + {resNamespace, resKind, resName}: {}, + } + // Iterate until we reach the highest level of reference with one of the // expected resource kind. Take into account that if this logic is changed, // the gadget cluster role needs to be updated accordingly. - for { + for depth := 0; depth < maxOwnerReferenceDepth; depth++ { if len(ownerReferences) == 0 { var err error ownerReferences, err = getOwnerReferences(dynamicClient, @@ -190,6 +210,15 @@ resKind = strings.ToLower(ownerRef.Kind) + "s" resName = ownerRef.Name ownerReferences = nil + + next := visitedKey{resNamespace, resKind, resName} + if _, seen := visited[next]; seen { + // Cycle in ownerReferences; stop walking and keep the last + // valid owner we saw. Returning an error would just make the + // caller log and continue, dropping the partial enrichment. + break + } + visited[next] = struct{}{} } // Update container's owner reference (If any) ++++++ inspektor-gadget.obsinfo ++++++ --- /var/tmp/diff_new_pack.VbUrAi/_old 2026-10-02 23:04:22.191869619 +0200 +++ /var/tmp/diff_new_pack.VbUrAi/_new 2026-10-02 23:04:22.203870121 +0200 @@ -1,5 +1,5 @@ name: inspektor-gadget -version: 0.56.1 -mtime: 1790324177 -commit: 815346241cb6727badef69b4db6ead6cf29eff2b +version: 0.56.2 +mtime: 1790858550 +commit: 9e8cca605d7923b9e8db281bf9e3c6617089aa8d ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/inspektor-gadget/vendor.tar.gz /work/SRC/openSUSE:Factory/.inspektor-gadget.new.1631729/vendor.tar.gz differ: char 134, line 3
