Skip to content

chore(deps): update runc-containerd-minor to v2.3.1-ubuntu24.04u2 - autoclosed#8652

Closed
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/runc-containerd-minor
Closed

chore(deps): update runc-containerd-minor to v2.3.1-ubuntu24.04u2 - autoclosed#8652
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/runc-containerd-minor

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Jun 5, 2026

This PR contains the following updates:

Package Update Change
moby-containerd minor 2.2.4-ubuntu24.04u22.3.1-ubuntu24.04u2

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Copilot AI review requested due to automatic review settings June 5, 2026 22:17
@renovate renovate Bot added the renovate This pull request was created by renovate label Jun 5, 2026
@renovate renovate Bot requested a review from a team June 5, 2026 22:17
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@github-actions github-actions Bot added the components This pull request updates cached components on Linux or Windows VHDs label Jun 5, 2026
@djsly
Copy link
Copy Markdown
Collaborator

djsly commented Jun 6, 2026

Linux Gate Detective RCA — build 166961552

Status: CIS regression on Ubuntu 24.04 gen2 containerd; now correlated with a second matching failure shape on PR #8294
Failure: build2404gen2containerd failed CIS baseline comparison: rule 6.1.4.1 pass→fail
Run: https://msazure.visualstudio.com/CloudNativeCompute/_build/results?buildId=166961552

RCA: The first failing step is Test, Scan, and Cleanup via vhdbuilder/packer/test/run-test.shvhdbuilder/packer/vhd-scanning.sh, where CIS scan output is compared against the checked-in Ubuntu 24.04 baseline. The regression signature was:

CIS regressions detected: 1
Regression details (rule_id|baseline->current): 6.1.4.1|pass->fail

Rule 6.1.4.1 is "Ensure access to all logfiles has been configured". It scans /var/log and fails if any regular logfile has non-compliant mode/owner/group. The original suspect was the Ubuntu 24.04u2 runc/containerd package bump leaving a new or changed logfile footprint, but the same CIS rule has now shown up on PR #8294 as well, so this looks more like Ubuntu 24.04 baseline/product drift than a uniquely PR-local failure.

Confidence: MEDIUM-HIGH

Next action: compare cis-regressions.txt and the offending /var/log file list between this run and PR #8294 before merging; then either update the baseline/remediation if expected, or fix the package/logfile permissions if unexpected.

@djsly
Copy link
Copy Markdown
Collaborator

djsly commented Jun 6, 2026

AgentBaker Linux PR gate — CIS regression

  • Run: 166961552 (partiallySucceeded)
  • Failed job/task: build2404gen2containerdTest, Scan, and Cleanup
  • Signature: CIS regressions detected: 1 — rule 6.1.4.1 pass→fail (Ubuntu 24.04 L1: Ensure access to all logfiles has been configured). Only 24.04 gen2 SKU regressed; 12 other SKUs and E2E green.

Likely cause (high confidence, change-caused): the runc/containerd bump in parts/common/components.json (v2.3.1-ubuntu24.04u2) deposits a file under /var/log with mode/owner/group outside the CIS allow-list (commonly mode > 0640 or group ∉ {adm,syslog,utmp,systemd-journal}). PR is the only delta; vhdbuilder/packer/cis/baselines/ubuntu/24.04.txt is unchanged.

Strongest alternative (less likely): baseline staleness for 24.04 — ruled lower because only the targeted SKU regressed in a 13-SKU matrix and the baseline file is unchanged. (Note: a second renovate PR has since hit the same rule — see #8294 — so the baseline-drift hypothesis is now stronger; please coordinate.)

Recommended next action: download cis-regressions.txt from the failed job — it names the exact /var/log path and observed vs expected perms. Then either chmod/chown in the install step (vhdbuilder/packer/install-dependencies.sh), update the 24.04 baseline if intentional, or push back upstream. Owner: PR author / NodeSIG-dev renovate-gate triage.

Posted by Clawpilot AgentBaker gate detective.

@renovate renovate Bot changed the title chore(deps): update runc-containerd-minor to v2.3.1-ubuntu24.04u2 chore(deps): update runc-containerd-minor to v2.3.1-ubuntu24.04u2 - autoclosed Jun 7, 2026
@renovate renovate Bot closed this Jun 7, 2026
@renovate renovate Bot deleted the renovate/runc-containerd-minor branch June 7, 2026 04:38
@renovate renovate Bot changed the title chore(deps): update runc-containerd-minor to v2.3.1-ubuntu24.04u2 - autoclosed chore(deps): update runc-containerd-minor to v2.3.1-ubuntu24.04u2 Jun 7, 2026
@renovate renovate Bot reopened this Jun 7, 2026
@renovate renovate Bot force-pushed the renovate/runc-containerd-minor branch 2 times, most recently from 0e81029 to 9b8f765 Compare June 7, 2026 13:55
@renovate renovate Bot changed the title chore(deps): update runc-containerd-minor to v2.3.1-ubuntu24.04u2 chore(deps): update runc-containerd-minor to v2.3.1-ubuntu24.04u2 - autoclosed Jun 8, 2026
@renovate renovate Bot closed this Jun 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

components This pull request updates cached components on Linux or Windows VHDs renovate This pull request was created by renovate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants