[pkg-go] Bug#1034871: podman: "sudo podman system reset" can delete current working directory

Jan Hendrik Farr debian at jfarr.cc
Wed Apr 26 11:45:06 BST 2023

Package: podman
Version: 4.3.1+ds1-6+b2
Severity: normal
Tags: newcomer
X-Debbugs-Cc: debian at jfarr.cc

Dear Maintainer,

if /etc/containers/storage.conf does not include the runRoot variable, then
running "sudo podman system reset" will delete the current working directory.
This is already fixed in upstream, I hope this can be backported and included
in Debian 12.

upstream issue: https://github.com/containers/podman/issues/18349
upstream fix: https://github.com/containers/storage/pull/1510

Including this fix in Debian 12 has a really low chance of affecting other
packages, but if this fix is not included there will inevitably be more people
like me that accidentally remove their home directory.

With kind regards

-- System Information:
Debian Release: 12.0
  APT prefers testing-security
  APT policy: (500, 'testing-security'), (500, 'testing')
Architecture: amd64 (x86_64)

Kernel: Linux 6.2.11 (SMP w/4 CPU threads; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages podman depends on:
ii  conmon                           2.1.6+ds1-1
ii  crun                             1.8.1-1+b1
ii  golang-github-containers-common  0.50.1+ds1-4
ii  libc6                            2.36-9
ii  libdevmapper1.02.1               2:1.02.185-2
ii  libgpgme11                       1.18.0-3+b1
ii  libseccomp2                      2.5.4-1+b3
ii  libsubid4                        1:4.13+dfsg1-1+b1
ii  runc                             1.1.5+ds1-1+b1

Versions of packages podman recommends:
ii  buildah            1.28.2+ds1-1+b2
ii  catatonit          0.1.7-1+b1
ii  dbus-user-session  1.14.6-1
ii  fuse-overlayfs     1.10-1
ii  slirp4netns        1.2.0-1
ii  tini               0.19.0-1
ii  uidmap             1:4.13+dfsg1-1+b1

Versions of packages podman suggests:
pn  containers-storage  <none>
pn  docker-compose      <none>
ii  iptables            1.8.9-2

-- no debconf information

More information about the Pkg-go-maintainers mailing list