Skip to content

Update bundled browser image runtime dependencies - #446

Merged
sjmiller609 merged 2 commits into
mainfrom
hypeship/bump-image-security-deps
Oct 10, 2026
Merged

sjmiller609 merged 2 commits into
mainfrom
hypeship/bump-image-security-deps

Conversation

@sjmiller609

@sjmiller609 sjmiller609 commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Upgrade bundled Docker tooling from 29.1.3 to 29.8.2 in headful and headless images.
  • Replace Docker's bundled containerd 2.3.6 (which still embeds gRPC 1.80.0) with containerd 2.4.1. Download only the daemon and runc shim, verifying pinned SHA-256 hashes for amd64 and arm64.
  • Pin the headful Neko base to the published 3.0.8-v1.6.2 release, including the crypto/network updates and compatible native builder from Restore compatible Neko release image builds neko#27.
  • Leave API dependencies unchanged: main already resolves x/crypto v0.54.0, x/net v0.57.0, and gRPC v1.82.1.

Verification

  • API build and race-enabled unit suite passed (excluding browser e2e).
  • Built the Docker tooling stage and verified both containerd archive checksums.
  • Inspected copied Go binaries: containerd/shim use gRPC v1.83.2 and x/net v0.58.0; dockerd uses gRPC v1.83.2, x/crypto v0.57.0, and x/net v0.59.0; runc uses x/net v0.55.0.
  • Validated the existing daemon.json with the new dockerd.
  • Started Docker 29.8.2 with containerd 2.4.1 in an isolated privileged container and successfully ran a BusyBox container.
  • Full browser image builds, browser e2e, and native arm64 execution were not run locally.

Published base verification

  • Neko v3.0.8-v1.6.2 was successfully built and published for amd64, arm64, and arm/v7: https://github.com/kernel/neko/actions/runs/37966960969.
  • Pulled each published architecture by digest and inspected its Neko binary: all embed x/crypto v0.54.0 and x/net v0.57.0.
  • Booted the published amd64 base: Neko, Xorg, and PulseAudio are RUNNING; health succeeds and the web client returns HTTP 200.
  • Both headful and headless image builds, race-enabled server unit tests, browser e2e, live-view, and launcher checks pass on the updated pin: https://github.com/kernel/kernel-images/actions/runs/37973078200. The first e2e attempt failed the executor-tab cleanup assertion; the complete rerun passed without code changes. No production browser image was deployed.

Note

Medium Risk
Changes privileged in-image Docker/containerd runtime versions used when WITHDOCKER is enabled; mis-versioned or incompatible binaries could break nested container startup despite checksum pinning.

Overview
Upgrades the Docker-in-Docker stage in both chromium headful and headless images from docker:29.1.3-dind to 29.8.2-dind, and during that stage runs a new shared/docker/update-containerd.sh script that downloads containerd 2.4.1 static binaries (daemon + containerd-shim-runc-v2) with pinned SHA-256 checks for amd64/arm64, installing them over Docker’s bundled containerd to pick up a newer embedded gRPC stack.

The headful image also pins the Neko base from 3.0.8-v1.6.0 to 3.0.8-v1.6.1; the final images still copy the same Docker binaries from the docker stage into /usr/local/bin.

Reviewed by Cursor Bugbot for commit 14b7267. Bugbot is set up for automated code reviews on this repo. Configure here.

@sjmiller609
sjmiller609 marked this pull request as ready for review October 9, 2026 16:02
Comment thread shared/docker/update-containerd.sh

@hiroTamada hiroTamada left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

what’s the production use case for Docker inside browser VMs? is something using it today, or is it bundled for future use?

@sjmiller609
sjmiller609 merged commit 70d2dba into main Oct 10, 2026
15 of 16 checks passed
@sjmiller609
sjmiller609 deleted the hypeship/bump-image-security-deps branch October 10, 2026 13:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants