Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

bubblewrap-0.11.2-1.1 RPM for riscv64

From OpenSuSE Ports Tumbleweed for riscv64

Name: bubblewrap Distribution: openSUSE Tumbleweed
Version: 0.11.2 Vendor: openSUSE
Release: 1.1 Build date: Wed Apr 29 18:20:45 2026
Group: Productivity/Security Build host: reproducible
Size: 113554 Source RPM: bubblewrap-0.11.2-1.1.src.rpm
Packager: https://bugs.opensuse.org
Url: https://github.com/containers/bubblewrap
Summary: Core execution tool for unprivileged containers
Bubblewrap (/usr/bin/bwrap) is a core execution engine for unprivileged
containers that works as a setuid binary on kernels without
user namespaces.

Provides

Requires

License

LGPL-2.0-or-later

Changelog

* Wed Apr 29 2026 Michael Gorse <mgorse@suse.com>
  - Update to version 0.11.2 (bsc#1262113):
    * In setuid mode, don't run the low-privileged parts of the setup
      as dumpable, as that allows it to be ptraced which can lead to
      problems.  This is CVE-2026-41163.
    * New build option `-Dsupport_setuid`, which if set to false
      (which is the default) disables the support for setuid.
      Binaries built with this will refuse to run if made setuid.
* Wed Apr 22 2026 Antonio Larrosa <alarrosa@suse.com>
  - Really drop the nobwrap.helper script as intended on Sep 29 2025.
* Mon Mar 23 2026 Dirk Müller <dmueller@suse.com>
  - update to 0.11.1:
    * Reset disposition of `SIGCHLD`, restoring normal subprocess
      management if bwrap was run from a process that was ignoring
      that signal, such as Erlang or volumeicon
    * Don't ignore `--userns 0`, `--userns2 0` or `--pidns 0` if
      used
    * Note that using a fd number ≥ 3 for these purposes is still
    * preferred, to avoid confusion with the stdin, stdout, stderr
    * that will be inherited by the command inside the container.
    * Fix grammar in an error message
    * Fix a broken link in the documentation
    * Enable user namespaces in Github Actions configuration,
      fixing a CI regression with newer Ubuntu
    * Clarify comments
* Mon Sep 29 2025 Dominique Leuenberger <dimstar@opensuse.org>
  - Drop the nobwrap.helper again: glycin could find a solution to
    detect it running in a CI/BuildEnvironment and it disarms
    bubblewrap in this case, making this wrapper obsolete
* Wed Sep 10 2025 Dominique Leuenberger <dimstar@opensuse.org>
  - Add a samplehelper to documentation that could be used by OBS
    packages to avoid bubblewrap: nobwrap.helper
* Sun Nov 17 2024 Sebastian Wagner <sebix@sebix.at>
  - fix shebang in demos/flatpak-run.sh
* Fri Nov 01 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - update to 0.11.0:
    * New --overlay, --tmp-overlay, --ro-overlay and --overlay-src
      options allow creation of overlay mounts. This feature is not
      available when bubblewrap is installed setuid.
    * New --level-prefix option produces output that can be parsed
      by tools like logger --prio-prefix and
      systemd-cat --level-prefix=1
    * bug fixes and developer visible changes
  - add upstream signing key and validate source signature
* Wed Aug 14 2024 Bjørn Lie <bjorn.lie@gmail.com>
  - Update to version v0.10.0:
    * New features: Add the --[ro-]bind-fd option, which can be used
      to mount a filesystem represented by a file descriptor without
      time-of-check/time-of-use attacks. This is needed when
      resolving security issue in Flatpak.
      (CVE-2024-42472, bsc#1229157)
    * Other changes: Fix some confusing syntax in SetupOpFlag (no
      functional change).
* Tue Apr 02 2024 Wolfgang Frisch <wolfgang.frisch@suse.com>
  - update to v0.9.0:
    * Build system changed to Meson from Autotools
    * Add --argv0
      https://github.com/containers/bubblewrap/issues/91
    * --symlink is now idempotent, meaning it succeeds if the symlink already
      exists and already has the desired target
    * Clarify security considerations in documentation
    * Clarify documentation for --cap-add
    * Report a better error message if mount(2) fails with ENOSPC
    * Fix a double-close on error reading from --args, --seccomp or
    - -add-seccomp-fd argument
    * Improve memory allocation behaviour
* Mon Mar 27 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - update to v0.8.0:
    * Add --disable-userns option to prevent the sandbox from
      creating its own nested user namespace
    * Add --assert-userns-disabled option to check that an existing
      userns was created with --disable-userns
    * Give a clearer error message if the kernel doesn't have
      CONFIG_SECCOMP and CONFIG_SECCOMP_FILTER

Files

/usr/bin/bwrap
/usr/share/bash-completion
/usr/share/bash-completion/completions
/usr/share/bash-completion/completions/bwrap
/usr/share/doc/packages/bubblewrap
/usr/share/doc/packages/bubblewrap/README.md
/usr/share/doc/packages/bubblewrap/demos
/usr/share/doc/packages/bubblewrap/demos/bubblewrap-shell.sh
/usr/share/doc/packages/bubblewrap/demos/flatpak-run.sh
/usr/share/doc/packages/bubblewrap/demos/flatpak.bpf
/usr/share/doc/packages/bubblewrap/demos/userns-block-fd.py
/usr/share/licenses/bubblewrap
/usr/share/licenses/bubblewrap/COPYING
/usr/share/man/man1/bwrap.1.gz


Generated by rpm2html 1.8.1

Fabrice Bellet, Sun Aug 2 03:56:04 2026