[release/2.2] overlay: disable "rebase" capability when running in UserNS#13393
Merged
fuweid merged 1 commit intoMay 13, 2026
Conversation
Fix issue 13388 ``` [...] May 12 16:57:23 kind-control-plane kubelet[257]: failed to extract layer (application/vnd.docker.image.rootfs .diff.tar sha256:6f1cdceb6a3146f0ccb986521156bef8a422cdbb0863396f7f751f575ba308f4) to overlayfs as "extract-920875437 -7QPF sha256:31e64620332e54e3e4fb246d8325ed2c9f1c2cc64a95f0bb23b4b7e82834c95a": failed to mount /var/lib/containerd/t mpmounts/containerd-mount2180142388: mount source: "overlay", target: "/var/lib/containerd/tmpmounts/containerd-mount 2180142388", fstype: overlay, flags: 0, data: "upperdir=/var/lib/containerd/io.containerd.snapshotter.v1.overlayfs/sn apshots/279/fs", err: invalid argument [...] ``` This was a regression introduced in PR 13115. Signed-off-by: Akihiro Suda <[email protected]>
AkihiroSuda
approved these changes
May 13, 2026
fuweid
approved these changes
May 13, 2026
antoine-gaillard
added a commit
to DataDog/containerd
that referenced
this pull request
Jun 18, 2026
containerd 2.2.4 Welcome to the v2.2.4 release of containerd! The fourth patch release for containerd 2.2 contains various fixes and updates including security patches. * **containerd** * [**CVE-2026-46680**](GHSA-fqw6-gf59-qr4w) * **go-jose** * [**CVE-2026-34986**](GHSA-78h2-9frx-2jm8) * Use mount manager during image volume processing to support snapshotters that require writable block volumes (e.g., EROFS) ([containerd#13242](containerd#13242)) * Fix handling of out-of-range USER values in OCI spec to avoid unexpected username/group lookups ([containerd#13448](containerd#13448)) * Apply hardening to block AF_ALG in default socket policy ([containerd#13408](containerd#13408)) * Fix bugs in sandbox service affecting sandbox creation configuration and event publishing ([containerd#13266](containerd#13266)) * Set AppArmor abi conditionally to support versions < 3.0 ([containerd#13275](containerd#13275)) * Disable overlay "rebase" capability when running in a user namespace to fix layer extraction failures ([containerd#13393](containerd#13393)) * Support both "volatile" and "fsync=volatile" mount options for volatile snapshotter ([containerd#13296](containerd#13296)) Please try out the release binaries and report any issues at https://github.com/containerd/containerd/issues. * Wei Fu * Akihiro Suda * Chris Henzie * Paweł Gronowski * Samuel Karp * Brian Goff * Champ-Goblem * Chris Chang * LEI WANG * Phil Estes * William Myers <details><summary>21 commits</summary> <p> * oci: return explicit error for out-of-range USER values ([containerd#13448](containerd#13448)) * [`d20c6267b`](containerd@d20c626) oci: return explicit error for out-of-range USER values * seccomp: Block AF_ALG in default socket policy ([containerd#13408](containerd#13408)) * [`db34dc4b4`](containerd@db34dc4) seccomp: Block AF_ALG in default socket policy * [`214b141ee`](containerd@214b141) seccomp: Document socket rule scope and socketcall limitation * update Go to 1.25.10, 1.26.3 ([containerd#13375](containerd#13375)) * [`c2b1856fa`](containerd@c2b1856) update Go to 1.25.10, 1.26.3 * overlay: disable "rebase" capability when running in UserNS ([containerd#13393](containerd#13393)) * [`63874d262`](containerd@63874d2) overlay: disable "rebase" capability when running in UserNS * Support both styles of volatile mount option ([containerd#13296](containerd#13296)) * [`2c7d48acf`](containerd@2c7d48a) Support both styles of volatile mount option * Bump go-jose/go-jose to v4.1.4 to fix GHSA-78h2-9frx-2jm8 ([containerd#13292](containerd#13292)) * [`80311db63`](containerd@80311db) chore: update go-jose for CVE-2026-34986 * sandbox: forward Create fields, fix event topics ([containerd#13266](containerd#13266)) * [`caa29a741`](containerd@caa29a7) sandbox: forward Create fields, fix event topics * apparmor: Set abi conditionally ([containerd#13275](containerd#13275)) * [`5ab0a1206`](containerd@5ab0a12) apparmor: Set abi conditionally * Parameterize K8s version in node-e2e workflow ([containerd#13247](containerd#13247)) * [`f9c34f7b1`](containerd@f9c34f7) Parameterize K8s version in node-e2e workflow * cri: use mount manager when image has volumes ([containerd#13242](containerd#13242)) * [`39dc2a475`](containerd@39dc2a4) cri: use mount manager when image has volumes </p> </details> * **github.com/go-jose/go-jose/v4** v4.1.3 -> v4.1.4 Previous release can be found at [v2.2.3](https://github.com/containerd/containerd/releases/tag/v2.2.3) * `containerd-<VERSION>-<OS>-<ARCH>.tar.gz`: ✅Recommended. Dynamically linked with glibc 2.35 (Ubuntu 22.04). * `containerd-static-<VERSION>-<OS>-<ARCH>.tar.gz`: Statically linked. Expected to be used on Linux distributions that do not use glibc >= 2.35. Not position-independent. In addition to containerd, typically you will have to install [runc](https://github.com/opencontainers/runc/releases) and [CNI plugins](https://github.com/containernetworking/plugins/releases) from their official sites too. See also the [Getting Started](https://github.com/containerd/containerd/blob/main/docs/getting-started.md) documentation. # -----BEGIN PGP SIGNATURE----- # # iQIzBAABCgAdFiEEkQwoYI0z3eaJwDKQmXxaPNMWfLUFAmoORmgACgkQmXxaPNMW # fLXIaRAA0LYh6aG+LwnQ5Pon4edFxO5BqqdrhhABoted1N57HAMDr84uICZiwV4u # BkL8sR2HXLhx4ogc64VsFxmcVQk55fKgYk/H6bJyaAzmrle/dHmKVlNqjSCN2WlR # lJ2UYlNJcmCdztLLoTFU/XUFdXXjG+ylBAQIqn80DEuwu9CZidAMkdqbsIIwGiF9 # U2jBs8F9HiGy/aiOWJI3wjh7p/B9DemXoyCuqHiyxAe8H1YcYkV5Whqx3U+tJ1mB # cytMsY0pJDDPkAtRUknWboaG6ZH2gqV5VYycm5K6sY6AZDU9dovWJ63GcowmFTrc # v0wv9dOgj52xZl0or2Cp6AsWrGgW2FbZWw/m14sB/8QWreoL5zdYhKZ2XJl/dkl1 # WbZm+cSkS4f6qevsBR96eXXLMdJ9Dka0RHlHavsxhPa4iZB1zUIpluj+nIVr8BSq # dk2gg74t4DSg7w6LDRYWlSOH86vevPX5lFRAV9AzvWuV+CgtSN9WAlkTBXu+4kp2 # JvY+VMj33hmgkjCFuc3zPv3n2lVce3YWxjsJFlG3WFoH+5cLHNbWupljg+E6DXFk # 2tNVaevvuq2h5gPYq2He/lhoimIMpKU7uR+FWiXbQMwQ8CF7K8bkx0tgEJsyuBcY # uKJTXrle8KWun2fE/sVEbcP/s6Zv7UmiS87lYns7UrLCXISPcSI= # =XaDj # -----END PGP SIGNATURE----- # gpg: Signature made mer. 20 mai 2026 19:40:24 EDT # gpg: using RSA key 910C28608D33DDE689C03290997C5A3CD3167CB5 # gpg: Can't check signature: No public key
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This is an automated cherry-pick of #13389
/assign AkihiroSuda