src/cmd/linuxkit: update buildkit to v0.31.1 - #4222
Merged
Merged
Conversation
Contributor
Author
This was referenced Sep 3, 2026
build(deps): bump github.com/moby/buildkit from 0.29.0 to 0.31.1 in /tools/get-deps
lf-edge/eve#6426
Closed
Package builds hand buildkit the package directory as the Dockerfile and build-context local mounts. They were passed as plain paths through the deprecated SolveOpt.LocalDirs field, which buildkit removed in v0.30.0 in favour of SolveOpt.LocalMounts. Wrap each path in an fsutil filesystem and pass it as a local mount instead, which is what buildkit did internally for LocalDirs entries before dropping the field. No behaviour change against the currently pinned buildkit v0.29.0, where both fields exist; this only removes the barrier to moving past v0.29.0. Signed-off-by: eriknordmark <erik@zededa.com> Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Moves the vendored buildkit client from v0.29.0 to v0.31.1, which carries the two low-severity fixes in that patch release (GHSA-7236-3392-c5c6, a custom frontend bypassing Seccomp/AppArmor restrictions, and GHSA-72x6-4j93-7w86, a runtime DoS via unbounded group parsing). Anything past v0.29.0 needs SolveOpt.LocalMounts, which the preceding commit switched to. go mod tidy pulls a matching round of transitive updates -- docker/cli, go-containerregistry, containerd, sigstore and the OpenTelemetry set are the visible ones -- and raises the go directive to 1.25.9. It also retires the vendored golang.org/x/net/context copy, unused since gcp moved to the standard library context. Signed-off-by: eriknordmark <erik@zededa.com> Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
eriknordmark
force-pushed
the
buildkit-0.31.1
branch
from
September 8, 2026 18:40
ac32dfe to
b3cc8c0
Compare
Contributor
Author
|
@deitch this is my last known update to the dependencies for linuxkit. |
4 of 7 tasks
Collaborator
|
Aw, but we will miss your updates! |
deitch
approved these changes
Sep 20, 2026
Contributor
Author
I said "known" and since the future is unknowable ... ;-) |
This was referenced Sep 22, 2026
rene
pushed a commit
to lf-edge/eve
that referenced
this pull request
Sep 23, 2026
EVE builds linuxkit from this commit, so the pin decides which buildkit and containerd the package and image builds run through. Moving from 3bf33c3a1 to current master takes buildkit v0.26.3 to v0.31.1 (linuxkit/linuxkit#4222) and containerd to v2.2.4 (CVE-2026-46680). Both are build-host libraries rather than content shipped in an EVE image. Package content hashes are unchanged -- all 48 pkg/ targets report identical show-tag values under binaries built from the old and the new commit -- so no FROM lfedge/eve-* reference moves. Signed-off-by: eriknordmark <erik@zededa.com> Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
buildkit removed the deprecated
SolveOpt.LocalDirsfield in v0.30.0, whichis what currently holds linuxkit at v0.29.0:
linuxkit pkg buildpasses thepackage directory as the Dockerfile and build-context local mounts through
that field.
The first commit switches those to
SolveOpt.LocalMounts, wrapping each pathin an fsutil filesystem the same way buildkit itself did for
LocalDirsentries before dropping them. It builds unchanged against the currently
pinned v0.29.0, where both fields still exist.
The second commit moves the pin to v0.31.1, which carries two low-severity
security fixes (GHSA-7236-3392-c5c6, a custom frontend bypassing
Seccomp/AppArmor restrictions, and GHSA-72x6-4j93-7w86, a runtime DoS via
unbounded group parsing).
go mod tidybrings a matching round of transitiveupdates and raises the go directive to 1.25.9; it also retires the vendored
golang.org/x/net/contextcopy, unused since gcp moved to the standardlibrary context.
Verified at the branch tip:
go build ./...,go vet ./...,go test ./...and
golangci-lint run(v2.11.4, matching CI) are all clean, with masterlinted as a control. The first commit was separately built and vetted on its
own against v0.29.0, so both commits compile.
Motivation is downstream: lf-edge/eve vendors
pkglibin two tool modules andis pinned below buildkit 0.27 and 0.30 by the
ConfigFileandLocalDirsremovals respectively. The first was fixed in #4214; this finishes the job so
EVE can re-pin linuxkit and take the buildkit security updates.