Skip to content

runc 1.1.7 -- "Ночевала тучка золотая на груди утеса-великана."

Compare
Choose a tag to compare
@cyphar cyphar released this 27 Apr 09:40
· 1063 commits to main since this release
v1.1.7
860f061

This is the seventh patch release in the 1.1.z release of runc, and is
the last planned release of the 1.1.z series. It contains a fix for
cgroup device rules with systemd when handling device rules for devices
that don't exist (though for devices whose drivers don't correctly
register themselves in the kernel -- such as the NVIDIA devices -- the
full fix only works with systemd v240+).

  • When used with systemd v240+, systemd cgroup drivers no longer skip
    DeviceAllow rules if the device does not exist (a regression introduced
    in runc 1.1.3). This fix also reverts the workaround added in runc 1.1.5,
    removing an extra warning emitted by runc run/start. (#3845, #3708, #3671)
  • The source code now has a new file, runc.keyring, which contains the keys
    used to sign runc releases. (#3838)

Static Linking Notices

The runc binary distributed with this release are statically linked with
the following GNU LGPL-2.1 licensed libraries, with runc acting
as a "work that uses the Library":

The versions of these libraries were not modified from their upstream versions,
but in order to comply with the LGPL-2.1 (§6(a)), we have attached the
complete source code for those libraries which (when combined with the attached
runc source code) may be used to exercise your rights under the LGPL-2.1.

However we strongly suggest that you make use of your distribution's packages
or download them from the authoritative upstream sources, especially since
these libraries are related to the security of your containers.


Thanks to all of the contributors who made this release possible:

Signed-off-by: Aleksa Sarai cyphar@cyphar.com