CI: podman 6.1.2 breaks runner action copy (path escapes from parent) #300

Open
opened 2026-09-20 16:42:23 -04:00 by mysticalsoap · 1 comment
Owner

Every validate run since the 2026-09-20 host upgrade fails in the checkout step before anything runs:

copyDir: failed to copy content to container: Error response from daemon: statat var/run/act: path escapes from parent

Cause. The upgrade took podman 6.1.1 -> 6.1.2 on the CI runner host. 6.1.2 vendors buildah 1.45.1, whose copier fix for CVE-2026-79705 refuses tar entries that cross an absolute symlink. forgejo-runner copies each action into the job container as a tar rooted at / with entries under var/run/act/..., and /var/run -> /run is absolute in node:22-bookworm. The act path is hardcoded in the runner, no config knob. Upstream: containers/podman#29805 (open, 2026-09-19); Docker had the same regression in 29.5.1 and fixed it in 29.5.2 by resolving in-container symlinks first (moby/moby#52655).

Not a fix. node:22-alpine has a relative ../run symlink and copies fine, but ships no git, so fetch-depth: 0 for gitleaks would not work.

Workaround. Pin podman at 6.1.1 (pacman -U from the cache, IgnorePkg = podman) until podman ships the symlink-resolution fix, then drop the pin.

Every `validate` run since the 2026-09-20 host upgrade fails in the checkout step before anything runs: ``` copyDir: failed to copy content to container: Error response from daemon: statat var/run/act: path escapes from parent ``` **Cause.** The upgrade took podman 6.1.1 -> 6.1.2 on the CI runner host. 6.1.2 vendors buildah 1.45.1, whose copier fix for CVE-2026-79705 refuses tar entries that cross an absolute symlink. forgejo-runner copies each action into the job container as a tar rooted at `/` with entries under `var/run/act/...`, and `/var/run -> /run` is absolute in `node:22-bookworm`. The act path is hardcoded in the runner, no config knob. Upstream: containers/podman#29805 (open, 2026-09-19); Docker had the same regression in 29.5.1 and fixed it in 29.5.2 by resolving in-container symlinks first (moby/moby#52655). **Not a fix.** `node:22-alpine` has a relative `../run` symlink and copies fine, but ships no git, so `fetch-depth: 0` for gitleaks would not work. **Workaround.** Pin podman at 6.1.1 (`pacman -U` from the cache, `IgnorePkg = podman`) until podman ships the symlink-resolution fix, then drop the pin.
Author
Owner

Pinned: podman downgraded to 6.1.1 from the pacman cache, IgnorePkg = podman in /etc/pacman.conf. Dispatched validate run 320 on trunk: checkout, all 12 stacks, gitleaks green. Unpin when containers/podman#29805 is fixed and released. No alerting on failed runs by choice; catch by dispatching a run after host upgrades.

Pinned: podman downgraded to 6.1.1 from the pacman cache, `IgnorePkg = podman` in /etc/pacman.conf. Dispatched validate run 320 on trunk: checkout, all 12 stacks, gitleaks green. Unpin when containers/podman#29805 is fixed and released. No alerting on failed runs by choice; catch by dispatching a run after host upgrades.
Sign in to join this conversation.
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
mysticalsoap/docker#300
No description provided.