CI: podman 6.1.2 breaks runner action copy (path escapes from parent) #300
Labels
No labels
audit-work
bug
docs
general-admin
major-upgrade
needs-vps-sync
new-service
on-hold
outside-work
post-podman
renovate
upstream
vps
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
mysticalsoap/docker#300
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Every
validaterun since the 2026-09-20 host upgrade fails in the checkout step before anything runs:Cause. The upgrade took podman 6.1.1 -> 6.1.2 on the CI runner host. 6.1.2 vendors buildah 1.45.1, whose copier fix for CVE-2026-79705 refuses tar entries that cross an absolute symlink. forgejo-runner copies each action into the job container as a tar rooted at
/with entries undervar/run/act/..., and/var/run -> /runis absolute innode:22-bookworm. The act path is hardcoded in the runner, no config knob. Upstream: containers/podman#29805 (open, 2026-09-19); Docker had the same regression in 29.5.1 and fixed it in 29.5.2 by resolving in-container symlinks first (moby/moby#52655).Not a fix.
node:22-alpinehas a relative../runsymlink and copies fine, but ships no git, sofetch-depth: 0for gitleaks would not work.Workaround. Pin podman at 6.1.1 (
pacman -Ufrom the cache,IgnorePkg = podman) until podman ships the symlink-resolution fix, then drop the pin.Pinned: podman downgraded to 6.1.1 from the pacman cache,
IgnorePkg = podmanin /etc/pacman.conf. Dispatched validate run 320 on trunk: checkout, all 12 stacks, gitleaks green. Unpin when containers/podman#29805 is fixed and released. No alerting on failed runs by choice; catch by dispatching a run after host upgrades.