Skip to content

src/cmd/linuxkit: update buildkit to v0.31.1 - #4222

Merged
deitch merged 2 commits into
linuxkit:masterfrom
eriknordmark:buildkit-0.31.1
Sep 22, 2026
Merged

deitch merged 2 commits into
linuxkit:masterfrom
eriknordmark:buildkit-0.31.1

Conversation

@eriknordmark

Copy link
Copy Markdown
Contributor

buildkit removed the deprecated SolveOpt.LocalDirs field in v0.30.0, which
is what currently holds linuxkit at v0.29.0: linuxkit pkg build passes the
package directory as the Dockerfile and build-context local mounts through
that field.

The first commit switches those to SolveOpt.LocalMounts, wrapping each path
in an fsutil filesystem the same way buildkit itself did for LocalDirs
entries before dropping them. It builds unchanged against the currently
pinned v0.29.0, where both fields still exist.

The second commit moves the pin to v0.31.1, which carries two low-severity
security fixes (GHSA-7236-3392-c5c6, a custom frontend bypassing
Seccomp/AppArmor restrictions, and GHSA-72x6-4j93-7w86, a runtime DoS via
unbounded group parsing). go mod tidy brings a matching round of transitive
updates and raises the go directive to 1.25.9; it also retires the vendored
golang.org/x/net/context copy, unused since gcp moved to the standard
library context.

Verified at the branch tip: go build ./..., go vet ./..., go test ./...
and golangci-lint run (v2.11.4, matching CI) are all clean, with master
linted as a control. The first commit was separately built and vetted on its
own against v0.29.0, so both commits compile.

Motivation is downstream: lf-edge/eve vendors pkglib in two tool modules and
is pinned below buildkit 0.27 and 0.30 by the ConfigFile and LocalDirs
removals respectively. The first was fixed in #4214; this finishes the job so
EVE can re-pin linuxkit and take the buildkit security updates.

@eriknordmark

Copy link
Copy Markdown
Contributor Author

@deitch if/when #4217 is done, take a look at this one to enable the update of buildkit and they do the update in the second commit.

eriknordmark and others added 2 commits September 8, 2026 20:39
Package builds hand buildkit the package directory as the Dockerfile and
build-context local mounts. They were passed as plain paths through the
deprecated SolveOpt.LocalDirs field, which buildkit removed in v0.30.0 in
favour of SolveOpt.LocalMounts. Wrap each path in an fsutil filesystem and
pass it as a local mount instead, which is what buildkit did internally for
LocalDirs entries before dropping the field.

No behaviour change against the currently pinned buildkit v0.29.0, where
both fields exist; this only removes the barrier to moving past v0.29.0.

Signed-off-by: eriknordmark <erik@zededa.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Moves the vendored buildkit client from v0.29.0 to v0.31.1, which carries
the two low-severity fixes in that patch release (GHSA-7236-3392-c5c6, a
custom frontend bypassing Seccomp/AppArmor restrictions, and
GHSA-72x6-4j93-7w86, a runtime DoS via unbounded group parsing). Anything
past v0.29.0 needs SolveOpt.LocalMounts, which the preceding commit
switched to.

go mod tidy pulls a matching round of transitive updates -- docker/cli,
go-containerregistry, containerd, sigstore and the OpenTelemetry set are
the visible ones -- and raises the go directive to 1.25.9. It also retires
the vendored golang.org/x/net/context copy, unused since gcp moved to the
standard library context.

Signed-off-by: eriknordmark <erik@zededa.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@eriknordmark

Copy link
Copy Markdown
Contributor Author

@deitch this is my last known update to the dependencies for linuxkit.

@deitch

deitch commented Sep 20, 2026

Copy link
Copy Markdown
Collaborator

Aw, but we will miss your updates!

@eriknordmark

Copy link
Copy Markdown
Contributor Author

Aw, but we will miss your updates!

I said "known" and since the future is unknowable ... ;-)
Is this good to merge @deitch ?

@deitch
deitch merged commit 40ad998 into linuxkit:master Sep 22, 2026
25 checks passed
rene pushed a commit to lf-edge/eve that referenced this pull request Sep 23, 2026
EVE builds linuxkit from this commit, so the pin decides which buildkit and
containerd the package and image builds run through. Moving from 3bf33c3a1 to
current master takes buildkit v0.26.3 to v0.31.1
(linuxkit/linuxkit#4222) and containerd to v2.2.4
(CVE-2026-46680). Both are build-host libraries rather than content shipped in
an EVE image.

Package content hashes are unchanged -- all 48 pkg/ targets report identical
show-tag values under binaries built from the old and the new commit -- so no
FROM lfedge/eve-* reference moves.

Signed-off-by: eriknordmark <erik@zededa.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants