Bump github.com/opencontainers/runc from 1.0.3 to 1.1.2
Bumps github.com/opencontainers/runc from 1.0.3 to 1.1.2.
Release notes
Sourced from github.com/opencontainers/runc's releases.
runc 1.1 -- "A plan depends as much upon execution as it does upon concept."
This release only contains very minor changes from v1.1.0-rc.1 and is the first release of the 1.1.y release series of runc. We do not plan to make any new releases of the 1.0.y release series of runc, so users are strongly encouraged to update to 1.1.0.
Changed:
- libcontainer will now refuse to build without the nsenter package being correctly compiled (specifically this requires CGO to be enabled). This should avoid folks accidentally creating broken runc binaries (and incorrectly importing our internal libraries into their projects). (#3331)
Static Linking Notices
The
runcbinary distributed with this release are statically linked with the following GNU LGPL-2.1 licensed libraries, withruncacting as a "work that uses the Library":The versions of these libraries were not modified from their upstream versions, but in order to comply with the LGPL-2.1 (§6(a)), we have attached the complete source code for those libraries which (when combined with the attached runc source code) may be used to exercise your rights under the LGPL-2.1.
However we strongly suggest that you make use of your distribution's packages or download them from the authoritative upstream sources, especially since these libraries are related to the security of your containers.
Thanks to the following people who made this release possible:
- Akihiro Suda [email protected]
- Aleksa Sarai [email protected]
- Kir Kolyshkin [email protected]
Signed-off-by: Aleksa Sarai [email protected]
runc 1.1-rc1 -- "He who controls the spice controls the universe."
This release is the first release candidate for the next minor release following runc 1.0. It contains all of the bugfixes included in runc 1.0 patch releases (up to and including 1.0.3).
A fair few new features have been added, and several features have been deprecated (with plans for removal in runc 1.2). At the moment we only plan to do a single release candidate for runc 1.1, and once 1.1.0 is released we will not continue updating the 1.0.z runc branch.
... (truncated)
Changelog
Sourced from github.com/opencontainers/runc's changelog.
[1.1.2] - 2022-05-06
I should think I’m going to be a perpetual student.
Security
- A bug was found in runc where runc exec --cap executed processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment. For more information, see GHSA-f3fp-gc8g-vw66 and CVE-2022-29162.
Changed
runc specno longer sets any inheritable capabilities in the created example OCI spec (config.json) file.[1.1.1] - 2022-03-28
Violence is the last refuge of the incompetent.
Added
- CI is now also run on centos-stream-9. (#3436)
Fixed
runc run/startcan now run a container with read-only/devin OCI spec, rather than error out. (#3355)runc execnow ensures that--cgroupargument is a sub-cgroup. (#3403)- libcontainer systemd v2 manager no longer errors out if one of the files listed in
/sys/kernel/cgroup/delegatedo not exist in container's cgroup. (#3387, #3404)- Loose OCI spec validation to avoid bogus "Intel RDT is not supported" error. (#3406)
- libcontainer/cgroups no longer panics in cgroup v1 managers if
statof/sys/fs/cgroup/unifiedreturns an error other than ENOENT. (#3435)[1.1.0] - 2022-01-14
A plan depends as much upon execution as it does upon concept.
Changed
- libcontainer will now refuse to build without the nsenter package being correctly compiled (specifically this requires CGO to be enabled). This should avoid folks accidentally creating broken runc binaries (and incorrectly importing our internal libraries into their projects). (#3331)
[1.1.0-rc.1] - 2021-12-14
... (truncated)
Commits
a916309VERSION: release 1.1.2364ec0frunc: do not set inheritable capabilities5854665merge branch 'pr-3439' into release-1.18959e37VERSION: back to development52de29dVERSION: release 1.1.12636e1cCHANGELOG.md: add 1.1.1 release notesae28db1Merge pull request #3436 from kolyshkin/1.1-add-centos-stream-9036cc34CI/cirrus: add centos-stream-9c653632Merge pull request #3438 from kolyshkin/1.1-fix-badgesdb95315README.md: add cirrus-ci badge- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)@dependabot use these labelswill set the current labels as the default for future PRs for this repo and language@dependabot use these reviewerswill set the current reviewers as the default for future PRs for this repo and language@dependabot use these assigneeswill set the current assignees as the default for future PRs for this repo and language@dependabot use this milestonewill set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.