This is an automated email from the ASF dual-hosted git repository.
MuhammadTahaNaveed pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/age.git
The following commit(s) were added to refs/heads/master by this push:
new 9be6efc1 Pin Docker Hub BuildKit image to v0.30.0 (#2523)
9be6efc1 is described below
commit 9be6efc15478ba0d672415d62149bfd4d7bb6915
Author: John Gemignani <[email protected]>
AuthorDate: Thu Aug 20 02:21:43 2026 -0700
Pin Docker Hub BuildKit image to v0.30.0 (#2523)
Commit 8f16cf51 pinned the docker-container buildx driver to
moby/buildkit:v0.31.2 to dodge the runc masked-path regression, but that
release bundles runc 1.3.6, which already contains the maskDir() change.
Every RUN step still fails during container init:
can't mask dir "/proc/acpi": mount src=tmpfs, dst=/proc/acpi,
flags=MS_RDONLY, data=nr_blocks=1,nr_inodes=1: invalid argument
maskDir() mounts masked paths with nr_inodes=1, which the Docker Hub build
host's Ubuntu 20.04 5.4 kernel rejects with EINVAL
(opencontainers/runc#5348).
Bundled runc by BuildKit release:
v0.30.0 runc 1.3.5 unaffected
v0.31.0 - v0.31.2 runc 1.3.6 affected
v0.32.0 - v0.32.2 runc 1.4.3 affected
v0.32.2 is the newest BuildKit release, so no version ships the fix yet.
Pin to v0.30.0, the last release predating maskDir(). Drop the pin once
BuildKit ships runc >= 1.4.4.
Verified locally: a multi-arch (linux/amd64, linux/arm64) build of this
Dockerfile with moby/buildkit:v0.30.0 completes, and both image variants
create a graph and run Cypher queries.
---
docker/hooks/build | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/docker/hooks/build b/docker/hooks/build
index 68b9acda..cc1d0340 100644
--- a/docker/hooks/build
+++ b/docker/hooks/build
@@ -1,7 +1,12 @@
#!/bin/bash
-# Pinned: buildx-stable-1 ships runc 1.4.3, which fails masked-path setup on
the build host (runc#5348).
+# Pinned: every BuildKit >= v0.31.0 bundles a runc whose maskDir() mounts
masked paths
+# with "nr_blocks=1,nr_inodes=1", which the Docker Hub build host's Ubuntu
20.04 5.4
+# kernel rejects with EINVAL, failing every RUN step in container init
(runc#5348).
+# v0.31.x ships runc 1.3.6 and v0.32.x ships runc 1.4.3, both affected;
v0.30.0 ships
+# runc 1.3.5, the last release before maskDir(). Drop the pin once BuildKit
ships
+# runc >= 1.4.4 (note runc 1.5.0 predates the backport and is also affected).
docker buildx create --name multiarch --use --platform
linux/amd64,linux/arm64/v8 \
- --driver-opt image=moby/buildkit:v0.31.2
+ --driver-opt image=moby/buildkit:v0.30.0
docker buildx build ../ -t $IMAGE_NAME -f Dockerfile --platform
linux/amd64,linux/arm64/v8 --push