moby--moby/pkg/archive
Eric Mountain 2a0c446866
Use v2 capabilities in layer archives
When building images in a user-namespaced container, v3 capabilities are
stored including the root UID of the creator of the user-namespace.

This UID does not make sense outside the build environment however. If
the image is run in a non-user-namespaced runtime, or if a user-namespaced
runtime uses a different UID, the capabilities requested by the effective
bit will not be honoured by `execve(2)` due to this mismatch.

Instead, we convert v3 capabilities to v2, dropping the root UID on the
fly.

Signed-off-by: Eric Mountain <eric.mountain@datadoghq.com>
(cherry picked from commit 95eb490780)
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
2021-05-05 21:46:31 +09:00
..
testdata
README.md
archive.go Use v2 capabilities in layer archives 2021-05-05 21:46:31 +09:00
archive_linux.go archive: do not use overlayWhiteoutConverter for UserNS 2021-04-01 19:00:42 +09:00
archive_linux_test.go archive: do not use overlayWhiteoutConverter for UserNS 2021-04-01 19:00:42 +09:00
archive_other.go archive: do not use overlayWhiteoutConverter for UserNS 2021-04-01 19:00:42 +09:00
archive_test.go archive: avoid creating parent dirs for XGlobalHeader 2021-02-17 21:12:55 +01:00
archive_unix.go
archive_unix_test.go pkg/archive: TestUntarParentPathPermissions requires root 2021-03-01 22:05:09 +01:00
archive_windows.go
archive_windows_test.go
changes.go
changes_linux.go
changes_other.go
changes_posix_test.go
changes_test.go
changes_unix.go
changes_windows.go
copy.go
copy_unix.go
copy_unix_test.go
copy_windows.go
diff.go
diff_test.go
example_changes.go
time_linux.go
time_unsupported.go
utils_test.go
whiteouts.go
wrap.go
wrap_test.go

README.md

This code provides helper functions for dealing with archive files.