This is the first release candidate of the upcoming runc 1.6.0 release.
It contains a couple of new features, but is mostly made up of various
cleanups (such as the removal of many deprecated APIs) and improvements.
This version includes all of the patches backported to runc v1.5.2.
Users are strongly encouraged to test our release candidates so we can
fix issues before the general release.
libcontainer API
configs.ToCPUSetnow returns aunix.CPUSetDynamicinstead of a
*unix.CPUSet, and theInitial/Finalfields ofconfigs.CPUAffinityand
theNodesfield ofconfigs.LinuxMemoryPolicyhave changed type
accordingly. This lifts the previous 1024 CPUs/nodes limit. (#5343)- The deprecated
libcontainer/devicespackage has been removed. Use
github.com/moby/sys/devicesinstead. (#5142, #5223, #5495) - The deprecated
RecvFile,SendFile, andSendRawFdfunctions have been
removed fromlibcontainer/utils. (#5227, #5231, #5495)
Removed
- The deprecated
EXTRA_BUILDTAGSmake variable has been removed, and setting
it is now an error. UseRUNC_BUILDTAGSinstead. (#5171, #5198, #5511)
Fixed
- The poststart hooks are now executed after starting the user-specified
process, fixing a runtime-spec conformance issue. (#4347, #5186) process.user.umaskis now honored for a container which does not have its
own mount namespace. Previously it was silently ignored, and not even the
default umask of 022 was set. (#5479)- When an AppArmor profile is not loaded, runc now says so explicitly and
names the profile, instead of returning a confusingno such file or directoryerror about a procfs file. (#5438, #5441)
Changed
- runc now requires Go 1.26+ to build. (#5413)
- The runc binary is now built with the
urfave_cli_no_templatebuild tag,
which, together with removing the reflect-based logging of CRIU options,
re-enables the linker's dead code elimination of exported methods. As a
result, the runc binary shrunk by about 2 MB (15%) on amd64. (#5486, #5506) - The
cpuAffinityand NUMAmemoryPolicysettings are no longer limited
to 1024 CPUs/nodes, as runc now uses a dynamically-sized CPU mask. (#5343) - A container configuration which asks for a read-only rootfs
(root.readonly), a read-only tmpfs mount, or a read-only/dev, but does
not have its own mount namespace, is now refused. Previously such a
container was silently started with those filesystems left writable, since
making them read-only requires a remount, which is only possible in a
private mount namespace. This is consistent with howmaskedPathsand
readonlyPaths, which have the same requirement, were already treated.
(#5371, #5479) - Switched from urfave/cli v1 (which is in maintenance mode) to v3. The
command-line syntax is intended to remain the same, but the help output
looks different. Please report any regressions in command-line parsing.
Theurfave_cli_no_docsbuild tag is no longer used. (#5184) runc startnow waits for the container's init process using poll(2) and
pidfd (where available), instead of a goroutine with a 100ms polling
timeout. (#5251, #5271)- runc no longer sets up a signal forwarder for detached containers, as
there is nothing to forward the signals to. (#4661)
Static Linking Notices
The runc binaries distributed with this release are statically linked with
the following GNU LGPL-2.1 licensed libraries, with runc acting
as a "work that uses the Library":
Similarly, the runc binaries distributed with this release are also
statically linked with the following MPLv2 licensed libraries,
with runc acting as a "Larger Work":
The versions of these libraries were not modified from their upstream versions,
but in order to comply with their corresponding licenses, we have attached the
complete source code for those libraries which (when combined with the attached
runc source code) may be used to exercise your rights under their respective
licenses.
However, we strongly suggest that you make use of your distribution's packages
or download them from the authoritative upstream sources, especially since
these libraries are related to the security of your containers.
Thanks to the following contributors who made this release possible:
- Akihiro Suda akihiro.suda.cz@hco.ntt.co.jp
- Aleksa Sarai cyphar@cyphar.com
- Erik Sjölund erik.sjolund@gmail.com
- Kir Kolyshkin kolyshkin@gmail.com
- Li Fu Bang lifubang@acmcoder.com
- Mohammed Aminu Futa mohammedfuta2000@gmail.com
- ningmingxiao ning.mingxiao@zte.com.cn
- Patrick Stoeckle patrick.stoeckle@siemens.com
- RedMakeUp girafeeblue@gmail.com
- Ricardo Branco rbranco@suse.de
- Rodrigo Campos rodrigo@sdfg.com.ar
- sean xujihui1985@gmail.com
- Sebastiaan van Stijn github@gone.nl
- Timothy Durward timothy.a.durward@gmail.com
Signed-off-by: Kir Kolyshkin kolyshkin@gmail.com