File _patchinfo of Package patchinfo.4666

<patchinfo incident="4666">
  <issue id="964546" tracker="bnc">devel:languages:go: Standard library missing __.PKGDEF headers</issue>
  <issue id="1028639" tracker="bnc">docker: conditional filtering not supported on libseccomp for leap42.1</issue>
  <issue id="1028638" tracker="bnc">docker: conditional filtering not supported on libseccomp for sle12 or sle12sp1</issue>
  <issue id="953182" tracker="bnc">docker manual page not available on SLES 12 SP1 / Containers Module on POWER</issue>
  <issue id="996303" tracker="bnc">update go to 1.7</issue>
  <issue id="1026827" tracker="bnc">systemd TasksMax default throttles docker</issue>
  <issue id="1034063" tracker="bnc">Containers cannot resolve DNS if docker host uses 127.0.0.1 as resolver</issue>
  <issue id="1032769" tracker="bnc">containerd spurious messages filling journal in SLE 12 SP2 with docker 1.12.6</issue>
  <issue id="1028113" tracker="bnc">runc: make sure to ignore cgroup v2 mountpoints</issue>
  <issue id="1034053" tracker="bnc">update docker to v17.04.0-ce</issue>
  <issue id="1030702" tracker="bnc">docker fails to start containers: error creating secret</issue>
  <issue id="1032644" tracker="bnc">docker requires lvm2, but we don't use/need/support that</issue>
  <issue id="1037436" tracker="bnc">docker exec -i leaks exec IDs</issue>
  <issue id="1038493" tracker="bnc">Feature: Allow installing multiple go compiler versions</issue>
  <issue id="1037607" tracker="bnc">The image from April 28th is broken: docker fails to run containers</issue>
  <issue id="1032287" tracker="bnc">Missing Docker systemd configuration</issue>
  <issue id="1038476" tracker="bnc">"zypper in docker" fails with "docker: command not found"</issue>
  <issue id="1040618" tracker="bnc">CVE-2017-8932: go: Elliptic curves carry propagation issue in x86-64 P-256</issue>
  <issue id="2017-8932" tracker="cve"/>
  <category>recommended</category>
  <rating>moderate</rating>
  <packager>jordimassaguerpla</packager>
  <description>
This update for Containerd, Docker and RunC provides several fixes and enhancements.

Containerd:

- Update containerd to the version needed for docker-v17.04.0-ce. (bsc#1034053) 
- Fix spurious messages filling journal. (bsc#1032769)
- Set TasksMax=infinity to make sure runC doesn't start failing randomly.

Docker:

- Update to version 17.04.0-ce. (bsc#1034053)
- Fix execids leaks due to bad error handling. (bsc#1037436)
- Make Apparmor's pkg/aaparser work on read-only root. (bsc#1037607)
- Improve Docker's systemd configuration. (bsc#1032287)
- Check if the docker binary is available before attempting to use it. (bsc#1038476)
- Build man pages for all architectures. (bsc#953182)
- Fix DNS resolution when Docker host uses 127.0.0.1 as resolver. (bsc#1034063)
- Enable Delegate=yes, since systemd will safely ignore lvalues it doesn't understand.
- Update SUSE secrets patch to handle bsc#1030702.
- Change lvm2 from Requires to Recommends: Docker usually uses a default storage driver,
  when it's not configured explicitly. This default driver then depends on the underlying
  system and gets chosen during installation. (bsc#1032644)
- Disable libseccomp for Leap 42.1, SLE 12 and 12-SP1, because docker needs a higher version.
  Otherwise, we get the error "conditional filtering requires libseccomp version &gt;= 2.2.1.
  (bsc#1028639, bsc#1028638)
- Add a backport of fix to AppArmor lazy loading docker-exec case.
- Fix systemd TasksMax default which could throttle docker. (bsc#1026827)
- Enable pkcs11

For a comprehensive list of changes please refer to /usr/share/doc/packages/docker/CHANGELOG.md

RunC:

- Update version to the one required by docker-17.04.0-ce. (bsc#1034053) 
- Make sure to ignore cgroup v2 mountpoints. (bsc#1028113)
</description>
  <summary>Recommended update for Docker, RunC, Containerd</summary>
  <message>Updating docker will restart the docker service, which may stop some of your docker containers. Do you want to proceed with the update?</message>
</patchinfo>
openSUSE Build Service is sponsored by