[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Update golang-github-appc-cni to 1.0 (was Re: singularity-container: CVE-2021-33622)



On 2/18/22 10:54 PM, Andreas Tille wrote:
Hi Shengjing,

Am Sat, Feb 19, 2022 at 12:44:39AM +0800 schrieb Shengjing Zhu:
I think you can build singularity in experiment for now to see if
there are other failures.

I've bumped Build-Depends: golang-github-appc-cni-dev (>= 1.0.1~) [1]
but when doing so Salsa-CI does not produce helpful logs any more.
Thus I've moved the resulting build log to:

    https://people.debian.org/~tille/singularity-container/singularity-container_3.9.4+ds1-1_amd64.build

I pushed a couple of commits that gets it building and tests passing. However, it chokes at
fixperms which has been propagated in d/rules

| make[1]: Entering directory '/home/nilesh/packages/singularity/singularity-container'
| dh_fixperms
| chown -c root.root debian/singularity-container/usr/lib/*/singularity/bin/*
| chown: changing ownership of 'debian/singularity-container/usr/lib/x86_64-linux-gnu/singularity/bin/starter': Operation not permitted
| chown: changing ownership of 'debian/singularity-container/usr/lib/x86_64-linux-gnu/singularity/bin/starter-suid': Operation not permitted

I am not really sure why this is done, but since this is more package related and has not got much to do with golang-land, I leave
this onto you to carry fwd.
Hope that helped.

Regards,
Nilesh

Attachment: OpenPGP_signature
Description: OpenPGP digital signature


Reply to: