Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Backport runc exec/setns race fix (1.4.1+/1.4.3) to Azure Linux 4.0

Open Beginner friendly
#19,102 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
72/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
docker, linux

Research direction

Start with specs/r/runc/runc.spec on the 4.0 branch and compare its version and packaging details with the runc bump in PR #18777. Update the 4.0 package to runc 1.4.1 or later, ideally 1.4.3, and run the relevant package build and tests; done means the updated package builds for Azure Linux 4.0.

Written by the indexing model from the issue text.

Description

Summary

On Azure Linux 4.0 (Cloud Variant Beta), running Docker containers that are docker exec'd into shortly after container start (e.g. kind's docker exec --privileged <node> cat /kind/version during kind create cluster bootstrap) intermittently fails with:

OCI runtime exec failed: exec failed: unable to start container process: error starting setns process: exec: already started

This is the Docker/runc exec/setns race tracked upstream as moby/moby#52194, introduced in Docker/moby 29.2.1 (not present in 28.0.1). It is reported upstream to be fixed by runc 1.4.1+.

Environment

  • Azure Linux 4.0 (Cloud Variant Beta), VERSION_ID=4.0
  • moby-engine-29.2.1-5.azl4.x86_64 (also reproduces on -3.azl4; these are the only two builds currently in azurelinux-base, so tdnf downgrade moby-engine cannot reach an unaffected 28.x build)
  • runc-1.4.0-4.azl4.x86_64 (standalone package, confirmed via rpm -q --whatprovides /usr/bin/runc)
  • Reproduced with both kind v0.20.0 and a freshly-installed kind v0.33.0 — ruling out kind version as a factor

What I found in this repo

  • specs/r/runc/runc.spec on the 4.0 branch is still pinned to Version: 1.4.0, last touched 2026-08-19.
  • PR #18777 ("containerd2: upgrade to 2.3.4 and runc to 1.4.3") already merged this exact bump for Azure Linux 3.0 (3.0-dev label) on 2026-09-18, but no equivalent PR/backport exists yet targeting the 4.0 branch.
  • No existing open issue/PR in this repo mentions setns or this moby-engine 29.2.1 regression.

Request

Please backport the runc bump (1.4.0 → 1.4.1+, ideally matching the 1.4.3 used in #18777) to the Azure Linux 4.0 branch, since AZL4 currently ships a runc with this known exec/setns race and there's no supported in-repo mitigation available via tdnf (no older moby-engine build, no newer runc build).

Impact

Any workflow that does rapid docker exec right after container creation is affected, notably kind create cluster, which fails non-deterministically during kubeadm bootstrap with the error above.

Dominant language
Python
Stars
5.3k
Forks
708
Avg merge
3d 17h
Merged PRs (30d)
219

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from microsoft/azurelinux

All issues in microsoft/azurelinux

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.