github-actions[bot] commented on code in PR #68352:
URL: https://github.com/apache/doris/pull/68352#discussion_r4110858214


##########
docker/runtime/base-image/Dockerfile_base:
##########
@@ -26,15 +26,23 @@ FROM ubuntu:22.04
 
 ARG TARGETARCH
 
+# Kernel-header and -dev packages are deliberately absent. 
linux-tools-realtime pulls
+# linux-tools-common, and libperl-dev/python2-dev pull linux-libc-dev + 
libc6-dev; all three
+# are built from the `linux`/`glibc` source packages, so every kernel CVE 
Ubuntu tracks is
+# reported against this image even though the packages ship only UAPI headers 
and perf wrapper
+# scripts - the vulnerable code runs in the host kernel, which an image cannot 
patch. They also
+# carry CVEs with no fixed version, so they can never be cleared by an apt 
upgrade. perf and the
+# BCC tools they provided are host-kernel-coupled and need --privileged plus a 
matching kernel
+# to be useful anyway; run them from a debug sidecar sharing the target's 
namespaces instead.

Review Comment:
   [P1] Preserve or retire the built-in BE flamegraph path. The BE still 
exposes `/pprof/profile?type=flamegraph`, and its handler executes `perf 
--version`, `perf record`, and `perf script` from the BE container's own 
`PATH`. Removing `linux-tools` plus this symlink makes that advertised endpoint 
deterministically return `NotSupported`; a sidecar cannot satisfy an exec 
performed inside this container. Please either keep a usable `perf` in the 
BE/debug image path, or update the handler/UI and operator workflow in the same 
change so the unavailable mode is not offered.



##########
docker/runtime/be/Dockerfile:
##########
@@ -26,7 +26,7 @@
 # get the binary from doris github and utar into resource, update the 
directory as apache-`version(example:2.0.1)`-bin-`architecture(amd64/arm64)` 
mode.
 
 # choose a base image
-FROM apache/doris:base-6.0
+FROM apache/doris:base-6.1

Review Comment:
   [P1] Publish the new base before switching every runtime image. As of this 
exact head, Docker Hub returns manifest-unknown/404 for 
`apache/doris:base-6.1`, and `docker/runtime/docker-build.sh` builds the 
modified base only as `apache/doris:base-latest` before attempting these 
hard-coded component Dockerfiles. A clean FE/BE/MS image build therefore stops 
at `FROM`. Please publish and verify the amd64+arm64 `base-6.1` manifest first 
(as was done for `base-6.0`), or make the base reference overridable and have 
the helper build/tag the exact image it consumes.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to