Bug 2503794

Summary: buildah: FTBFS in Fedora rawhide/f45
Product: [Fedora] Fedora Reporter: Fedora Release Engineering <releng>
Component: buildahAssignee: Lokesh Mandvekar <lsm5>
Status: CLOSED RAWHIDE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: rawhideCC: amurdaca, debarshir, dwalsh, go-sig, jnovy, lsm5, nsella, pehunt, pholzing, tsweeney
Target Milestone: ---Keywords: Reopened
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-08-04 17:55:59 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2433833    
Attachments:
Description Flags
build.log
none
root.log
none
state.log none

Description Fedora Release Engineering 2026-07-21 18:01:22 UTC
buildah failed to build from source in Fedora rawhide/f45

https://koji.fedoraproject.org/koji/taskinfo?taskID=147843318


For details on the mass rebuild see:

https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
Please fix buildah at your earliest convenience and set the bug's status to
ASSIGNED when you start fixing it. If the bug remains in NEW state for 8 weeks,
buildah will be orphaned. Before branching of Fedora 46,
buildah will be retired, if it still fails to build.

For more details on the FTBFS policy, please visit:
https://docs.fedoraproject.org/en-US/fesco/Fails_to_build_from_source_Fails_to_install/

Comment 1 Fedora Release Engineering 2026-07-21 18:01:29 UTC
Created attachment 2149571 [details]
build.log

file build.log too big, will only attach last 32768 bytes

Comment 2 Fedora Release Engineering 2026-07-21 18:01:35 UTC
Created attachment 2149572 [details]
root.log

file root.log too big, will only attach last 32768 bytes

Comment 3 Fedora Release Engineering 2026-07-21 18:01:38 UTC
Created attachment 2149573 [details]
state.log

Comment 4 Lokesh Mandvekar 2026-07-21 19:40:50 UTC
podman is not affected by CVE-2025-47914.

The vulnerability affects golang.org/x/crypto/ssh/agent and was fixed in v0.45.0. podman currently uses golang.org/x/crypto v0.54.0, which includes the fix.

Comment 5 Lokesh Mandvekar 2026-07-21 19:41:40 UTC
(In reply to Lokesh Mandvekar from comment #4)
> podman is not affected by CVE-2025-47914.
> 
> The vulnerability affects golang.org/x/crypto/ssh/agent and was fixed in
> v0.45.0. podman currently uses golang.org/x/crypto v0.54.0, which includes
> the fix.

ugh, pasted on the wrong bz. My bad.

Comment 6 Lokesh Mandvekar 2026-08-04 17:55:59 UTC
Fixed in buildah-1.45.0-2.fc45 (FEDORA-2026-06e3d92054)