This is an automated email from the ASF dual-hosted git repository.
jrgemignani pushed a commit to branch release/PG18/1.8.0
in repository https://gitbox.apache.org/repos/asf/age.git
The following commit(s) were added to refs/heads/release/PG18/1.8.0 by this
push:
new b570cf7c Pin Docker Hub BuildKit image to v0.30.0 (#2523) (#2531)
b570cf7c is described below
commit b570cf7c1486863f77c14e9c0e07b0e9bfd01bf4
Author: John Gemignani <[email protected]>
AuthorDate: Thu Aug 20 08:25:41 2026 -0700
Pin Docker Hub BuildKit image to v0.30.0 (#2523) (#2531)
NOTE: This is needed to allow Docker Hub builds for both latest and
release/PG18/1.8.0 to build and is outside of the release.
Commit 8f16cf51 pinned the docker-container buildx driver to
moby/buildkit:v0.31.2 to dodge the runc masked-path regression, but that
release bundles runc 1.3.6, which already contains the maskDir() change.
Every RUN step still fails during container init:
can't mask dir "/proc/acpi": mount src=tmpfs, dst=/proc/acpi,
flags=MS_RDONLY, data=nr_blocks=1,nr_inodes=1: invalid argument
maskDir() mounts masked paths with nr_inodes=1, which the Docker Hub build
host's Ubuntu 20.04 5.4 kernel rejects with EINVAL
(opencontainers/runc#5348).
Bundled runc by BuildKit release:
v0.30.0 runc 1.3.5 unaffected
v0.31.0 - v0.31.2 runc 1.3.6 affected
v0.32.0 - v0.32.2 runc 1.4.3 affected
v0.32.2 is the newest BuildKit release, so no version ships the fix yet.
Pin to v0.30.0, the last release predating maskDir(). Drop the pin once
BuildKit ships runc >= 1.4.4.
Verified locally: a multi-arch (linux/amd64, linux/arm64) build of this
Dockerfile with moby/buildkit:v0.30.0 completes, and both image variants
create a graph and run Cypher queries.
---
docker/hooks/build | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/docker/hooks/build b/docker/hooks/build
index bd347d90..cc1d0340 100644
--- a/docker/hooks/build
+++ b/docker/hooks/build
@@ -1,4 +1,12 @@
#!/bin/bash
-docker buildx create --name multiarch --use --platform
linux/amd64,linux/arm64/v8
-docker buildx build ../ -t $IMAGE_NAME -f Dockerfile --platform
linux/amd64,linux/arm64/v8 --push
\ No newline at end of file
+# Pinned: every BuildKit >= v0.31.0 bundles a runc whose maskDir() mounts
masked paths
+# with "nr_blocks=1,nr_inodes=1", which the Docker Hub build host's Ubuntu
20.04 5.4
+# kernel rejects with EINVAL, failing every RUN step in container init
(runc#5348).
+# v0.31.x ships runc 1.3.6 and v0.32.x ships runc 1.4.3, both affected;
v0.30.0 ships
+# runc 1.3.5, the last release before maskDir(). Drop the pin once BuildKit
ships
+# runc >= 1.4.4 (note runc 1.5.0 predates the backport and is also affected).
+docker buildx create --name multiarch --use --platform
linux/amd64,linux/arm64/v8 \
+ --driver-opt image=moby/buildkit:v0.30.0
+
+docker buildx build ../ -t $IMAGE_NAME -f Dockerfile --platform
linux/amd64,linux/arm64/v8 --push