github opencontainers/runc v1.6.0-rc.1
runc v1.6.0-rc.1 -- "Lo bueno, si breve, dos veces bueno."

pre-release2 hours ago

This is the first release candidate of the upcoming runc 1.6.0 release.
It contains a couple of new features, but is mostly made up of various
cleanups (such as the removal of many deprecated APIs) and improvements.

This version includes all of the patches backported to runc v1.5.2.

Users are strongly encouraged to test our release candidates so we can
fix issues before the general release.

libcontainer API

  • configs.ToCPUSet now returns a unix.CPUSetDynamic instead of a
    *unix.CPUSet, and the Initial/Final fields of configs.CPUAffinity and
    the Nodes field of configs.LinuxMemoryPolicy have changed type
    accordingly. This lifts the previous 1024 CPUs/nodes limit. (#5343)
  • The deprecated libcontainer/devices package has been removed. Use
    github.com/moby/sys/devices instead. (#5142, #5223, #5495)
  • The deprecated RecvFile, SendFile, and SendRawFd functions have been
    removed from libcontainer/utils. (#5227, #5231, #5495)

Removed

  • The deprecated EXTRA_BUILDTAGS make variable has been removed, and setting
    it is now an error. Use RUNC_BUILDTAGS instead. (#5171, #5198, #5511)

Fixed

  • The poststart hooks are now executed after starting the user-specified
    process, fixing a runtime-spec conformance issue. (#4347, #5186)
  • process.user.umask is now honored for a container which does not have its
    own mount namespace. Previously it was silently ignored, and not even the
    default umask of 022 was set. (#5479)
  • When an AppArmor profile is not loaded, runc now says so explicitly and
    names the profile, instead of returning a confusing no such file or directory error about a procfs file. (#5438, #5441)

Changed

  • runc now requires Go 1.26+ to build. (#5413)
  • The runc binary is now built with the urfave_cli_no_template build tag,
    which, together with removing the reflect-based logging of CRIU options,
    re-enables the linker's dead code elimination of exported methods. As a
    result, the runc binary shrunk by about 2 MB (15%) on amd64. (#5486, #5506)
  • The cpuAffinity and NUMA memoryPolicy settings are no longer limited
    to 1024 CPUs/nodes, as runc now uses a dynamically-sized CPU mask. (#5343)
  • A container configuration which asks for a read-only rootfs
    (root.readonly), a read-only tmpfs mount, or a read-only /dev, but does
    not have its own mount namespace, is now refused. Previously such a
    container was silently started with those filesystems left writable, since
    making them read-only requires a remount, which is only possible in a
    private mount namespace. This is consistent with how maskedPaths and
    readonlyPaths, which have the same requirement, were already treated.
    (#5371, #5479)
  • Switched from urfave/cli v1 (which is in maintenance mode) to v3. The
    command-line syntax is intended to remain the same, but the help output
    looks different. Please report any regressions in command-line parsing.
    The urfave_cli_no_docs build tag is no longer used. (#5184)
  • runc start now waits for the container's init process using poll(2) and
    pidfd (where available), instead of a goroutine with a 100ms polling
    timeout. (#5251, #5271)
  • runc no longer sets up a signal forwarder for detached containers, as
    there is nothing to forward the signals to. (#4661)

Static Linking Notices

The runc binaries distributed with this release are statically linked with
the following GNU LGPL-2.1 licensed libraries, with runc acting
as a "work that uses the Library":

Similarly, the runc binaries distributed with this release are also
statically linked with the following MPLv2 licensed libraries,
with runc acting as a "Larger Work":

The versions of these libraries were not modified from their upstream versions,
but in order to comply with their corresponding licenses, we have attached the
complete source code for those libraries which (when combined with the attached
runc source code) may be used to exercise your rights under their respective
licenses.

However, we strongly suggest that you make use of your distribution's packages
or download them from the authoritative upstream sources, especially since
these libraries are related to the security of your containers.


Thanks to the following contributors who made this release possible:

Signed-off-by: Kir Kolyshkin kolyshkin@gmail.com

Don't miss a new runc release

NewReleases is sending notifications on new releases.