Copilot commented on code in PR #2523:
URL: https://github.com/apache/age/pull/2523#discussion_r3815119004


##########
docker/hooks/build:
##########
@@ -1,7 +1,12 @@
 #!/bin/bash
 
-# Pinned: buildx-stable-1 ships runc 1.4.3, which fails masked-path setup on 
the build host (runc#5348).
+# Pinned: every BuildKit >= v0.31.0 bundles a runc whose maskDir() mounts 
masked paths
+# with "nr_blocks=1,nr_inodes=1", which the Docker Hub build host's Ubuntu 
20.04 5.4
+# kernel rejects with EINVAL, failing every RUN step in container init 
(runc#5348).
+# v0.31.x ships runc 1.3.6 and v0.32.x ships runc 1.4.3, both affected; 
v0.30.0 ships
+# runc 1.3.5, the last release before maskDir(). Drop the pin once BuildKit 
ships
+# runc >= 1.4.4 (note runc 1.5.0 predates the backport and is also affected).

Review Comment:
   The comment references `runc#5348` and also makes a specific claim about 
`runc 1.5.0` being affected. Since this is a Docker-hook script likely read 
outside GitHub context, please replace `runc#5348` with a fully qualified link 
(or include the full `opencontainers/runc` reference) and consider adding a 
link/reference for the `runc 1.5.0` note to keep this pinned-version rationale 
verifiable over time.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to