<feed xmlns='http://www.w3.org/2005/Atom'>
<title>linux/meta-virtualization.git/recipes-containers/docker, branch container-cross-install</title>
<subtitle>Mirror of git.yoctoproject.org/meta-virtualization</subtitle>
<id>https://git.enea.com/cgit/linux/meta-virtualization.git/atom?h=container-cross-install</id>
<link rel='self' href='https://git.enea.com/cgit/linux/meta-virtualization.git/atom?h=container-cross-install'/>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-virtualization.git/'/>
<updated>2026-01-21T23:00:26+00:00</updated>
<entry>
<title>RFC: not for merge: docker-moby add -native variant</title>
<updated>2026-01-21T23:00:26+00:00</updated>
<author>
<name>Bruce Ashfield</name>
<email>bruce.ashfield@gmail.com</email>
</author>
<published>2024-05-14T02:34:59+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-virtualization.git/commit/?id=eda75fafe2bd38466662d4975bfeef18ee30610c'/>
<id>urn:sha1:eda75fafe2bd38466662d4975bfeef18ee30610c</id>
<content type='text'>
Signed-off-by: Bruce Ashfield &lt;bruce.ashfield@gmail.com&gt;
</content>
</entry>
<entry>
<title>docker-moby: update to docker-v29.0.0-rc.1</title>
<updated>2025-10-18T17:33:14+00:00</updated>
<author>
<name>Bruce Ashfield</name>
<email>bruce.ashfield@gmail.com</email>
</author>
<published>2025-10-17T16:01:59+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-virtualization.git/commit/?id=424f6c57016d8b2ff56e8ef9bbe2a980a3d2abc2'/>
<id>urn:sha1:424f6c57016d8b2ff56e8ef9bbe2a980a3d2abc2</id>
<content type='text'>
Along with the listed updates, we also update the cli, adjust our build
path (it is now under moby), refresh patches and explicitly export
trimpath to avoid QA warnings.

Bumping moby to version docker-v29.0.0-rc.1-54-gd1a720cb15, which comprises the following commits:

    5fa3c65682 client: Client.PluginList: add options-struct
    aa36c44ef9 api/types/volume: move `UpdateOptions` to `client.VolumeUpdateOptions`
    709336a2c3 api/types/network: EndpointSettings: make MacAddress "operational data"
    e84bbc09b1 integration/container: fix daemon min API version
    1caf3dd3b2 integration-cli: TestDockerCLIBuildSuite/TestBuildEmitsEvents: reduce logs
    acfe4e8613 gha: add support for docker-v* tags
    b87ed4512a integration/container: fix test using wrong daemon
    ecd7551310 daemon/server/router/container: fix back-filling of top-level network fields
    865cfe9a7f client: VolumesPrune: rewrite to use option structs and result
    b11d9d410f client: NetworksPrune: rewrite to use option structs and result
    0672a0f999 client: ImagesPrune: rewrite to use option structs and result
    91323b7a35 client: ContainersPrune: rewrite to use option structs and result
    d9a03a374f daemon: consolidate "log-level" and "log-format" options and flags
    4e6c955e78 daemon/command: configureDaemonLogs: don't panic
    06ff7d9cd4 daemon/config: add validateDaemonLogConfig function
    c73fe6d26e daemon/config: move daemon log-config to a separate struct
    a6cf5e19e8 daemon/command: remove placeholder
    c584855329 daemon/command: configureProxyEnv: accept smaller struct
    0a2ab376ff daemon/config: slight cleanup of Config struct
    69702bd821 fix minor linting issues
    3b075a79b9 api: remove image inspect `Parent`, `DockerVersion` from swagger docs
    d62a521c7d daemon: initialize volumes if nil on decode
    a65293c036 libnetwork/osl/kernel: ApplyOSTweaks: don't log errors if not found
    adb4269928 api/types/image: remove deprecated Summary.VirtualSize field
    2537eae6f3 api/types/container: remove support for config mac address
    e77f116c9c integration: remove some version-gates for API &lt; v1.44
    2c59be7011 daemon: raise default minimum API version to v1.44
    47fe719b33 api/types/build: remove deprecated BuildCache.Parent field
    36f1c830bb add back replace rules and re-vendor
    45caa74e3b api/types/sytem: remove deprecated DiskUsage.BuilderSize
    a5d9619093 api/docs: remove BuildCache.Parent field for API v1.42 and up
    e1722eb8d8 daemon/command: disable c8d snapshotter when userns remapping enabled
    1aa73144f2 update to go1.25.3
    5e9e261107 vendor: github.com/moby/moby/client v0.1.0-beta.2
    01a19e9d95 vendor: github.com/moby/moby/api v1.52.0-beta.2
    b1e57881c3 gha/labeler: disable sync-labels to preserve human-added labels
    3848b16bca Removed all occurrences of wrapError in libcontainerd/remote
    28018a51d8 update to go1.25.2
    39cf847787 api: regenerate with go-swagger v0.33.1
    b4c3b29245 Dockerfile: update to go-swagger v0.33.1 (for go1.25)
    bbdd24d145 api/templates: align with go-swagger v1.32.3
    b3f74e85aa Dockerfile: bump gotest.tools/gotestsum v1.13.0
    ac3960a44c api/types/container: omit `Config.OnBuild` when empty
    0ee0283c9d gha/labeler: Some more file-based rules
    15289ad2dc client: Filters: add Clone method
    a6206f2da9 dockerd-rootless: default MTU 65520 for slirp4netns
    7e63d2a81b dockerd-rootless.sh: if no slirp4netns, try pasta
    cfdb9068f0 client: ImagePullResponse: use sync.OnceValue
    3c44bd67b2 client: ImagePullResponse: don't panic without reader
    4210e4ad16 daemon/internal/netiputil: make "MaybeXXX" functions a function, not var
    4c6e571d38 api/pkg/stdcopy: move stdWriter to daemon/internal
    8cf0529a8c api/types/swarm: add documentation to clarify virtual IP address type
    c2812dc285 api: fix swarm network field from addr to prefix
    9912ccd7b3 Clean up bridge device on network create error
    e6bac8983b introduce ImagePullResponse to manage JSONMessage stream decoding
    7652f38c28 client: remove API-version compatibility for API &lt; v1.44
    7ea066c8d1 client: add Filters type
    778e5bfad3 api/types/filters: move to daemon/internal
    96b29f5a1f client: remove support for negotiating API version &lt; v1.44 (docker 25.0)
    ef5feb4992 vendor: golang.org/x/net v0.45.0
    3f75e2116f vendor: golang.org/x mod v0.28, net v0.44, text v0.29, crypto v0.42, tools v0.37
    6de0417884 vendor: golang.org/x/sync v0.17.0
    4bc628581d vendor: golang.org/x/sys v0.36.0
    9169ed2873 client: touch-up some godoc
    04318e0d86 client: update some tests using obsolete API versions
    ca9c5c6f7b vendor: github.com/moby/swarmkit/v2 v2.1.1
    1b1608f2cd hack: add patch to buildkit tests
    3c418bea4e vendor: update buildkit to v0.25.1
    0aed907a86 update to go1.24.8
    0cc04d0c5c Network restore, don't update config to match state
    b1e20b6a3a api/types/system: remove deprecated Commit.Expected field
    1a7d7cc015 builder: use proper percentage calculations for default gc policy
    dbcbe87d52 ci: fix cache for go modules
    f8d3c4e4a7 api/types/image: InspectResponse: remove deprecated Parent, DockerVersion
    1a81903854 api/types/image: InspectResponse: remove deprecated fields
    a8dd9c5025 daemon/pkg/plugin: stop propagating Plugin.Config.DockerVersion field
    1d3687aeee ci: update gha cache attributes
    a99b7947e1 daemon: stop propagating Image.DockerVersion field
    f6e1bf2808 Rework Go mod tidy/vendor checks
    45a728a13b image inspect: fix legacy fields for API &lt; v1.52 response
    fdd61821da use consistent alias for docker image spec
    c4fda95bea api/types/plugin: deprecate Config.DockerVersion field
    a9a1ac3c45 Dockerfile: update compose to v2.40.0
    94ab6a9c5e Dockerfile: update buildx to v0.29.1
    b9ac2cea0c Dockerfile: update cli to v28.5.0
    222a3fe94e integration-cli: remove deprecated buildImage utility
    bd8a99b400 api/types/image: InspectResponse: deprecate Parent, DockerVersion
    288b9f033b integration-cli: remove deprecated buildImageSuccessfully utility
    15bef6ff1a daemon/server: move GetImageOpts, ImageInspectOpts to imagebackend
    95e77d6861 daemon/images: minor linting fixes
    e204ba1dca daemon/internal/compat: add extra fields recursively, and don't replace
    50269e6e39 api/types/swarm: remove `PortConfigProtocol`
    ea76dbefeb api/types/swarm: deprecate PortConfigProtocol
    c646091d57 api: move container port type to network package
    038bfbfbd4 api: omit legacy fields from image inspect if not set
    f289cb2d7c api: docs: sync v1.52 yaml
    d6899ca5a5 api/types/registry: use netip types as appropriate
    fd4329a620 api/types/container: use netip types as appropriate
    d5c838dc5e internal: move sliceutil from daemon/internal
    a90adb6dc1 api/types/network: use netip types as appropriate
    ef31514a9f api/t/network: move IPAM validation to daemon
    4d6a2be79d api/t/network: validate EndpointIPAMConfig in daemon
    2da472b1a5 api/types/system: use netip types where appropriate
    cc082add87 api/types/swarm: use netip types as appropriate
    46ab36ae46 daemon/internal: move netiputil from libnetwork
    470f5b50a5 internal/sliceutil: map nil to nil
    df506c107e negociate content-type used by /events API
    0ad35e3ef0 Add existence check for go.mod and go.sum files
    cb3abacc52 api/types/container: add network port and port range types
    c46704a80f client/build_prune: Wrap result in a struct
    a35b3cd149 client/build_cancel: Add options struct
    3f3bbe4430 vendor: github.com/moby/buildkit v0.25.0
    9a32a7e0d1 daemon, client: remove version-gate for daemon-side AutoRemove
    af5988238a client: reduce uses of obsolete API versions in tests
    eafca64a6b daemon/server: implement image-inspect with "compat" package
    51cbd2ed16 api: swagger: remove VirtualSize fields for API &gt; v1.43
    a7edbe8e5f api: remove support for `KernelMemoryTCP`
    fb2f8115c8 api: deprecate `KernelMemoryTCP` support
    eff4f064a3 daemon/libnetwork/internal/kvstore: remove unused ErrBackendNotSupported
    1697aecbd5 daemon/libnetwork/internal/kvstore: remove unused BOLTDB and Backend type
    94bcf89412 Eliminate warning about endpoint count store delete
    08d014cac8 api/docs: remove email field from example auth
    344ab458a1 api/types/registry: remove deprecated AuthConfig.Email field
    3241d46525 client: Client.doRequest: adjust error matching for TLS1.3 handshake
    b8fbd0539e vendor: github.com/deckarep/golang-set/v2 v2.8.0
    178d697484 integration-cli: adjust TestHTTPSInfoRogueCert for TLS1.3 handshake
    efa077848f api/types/storage: define generic `Storage` type for container inspect
    77bf85647c contrib: add docker_client SELinux policy module to access socket in container
    b48fcf6cdb client/checkpoint_list: Wrap result in a struct
    646e068cf1 api/checkpoint: Don't return null if no checkpoints
    38fb0dd10c Add build tag "no_libnftables"
    062479f95c vendor: github.com/hashicorp/go-memdb v1.3.5
    3912ffacd6 integration/nw: TestEmptyPortBindingsBC use context
    e80e2908ba dockerversion: use t.Context() in tests
    aca0adfb97 daemon: use t.Context() in tests
    8905c3052b daemon/libnetwork: use t.Context() in tests
    01f9186d6d daemon/logger: use t.Context() in tests
    c1c9087404 daemon/containerd: use t.Context() in tests
    544f8f53ed daemon/builder: use t.Context() in tests
    415274d62a vendor: github.com/opencontainers/cgroups v0.0.5
    73ed41ef79 vendor: github.com/coreos/go-systemd/v22 v22.6.0
    0f393630f8 vendor: opencontainers/runtime-tools v0.9.1-0.20250523060157-0ea5ed0382a2
    6db6de2c20 Use libnftables in dynamically linked binary
    e8d3609031 hack: use custom ref for buildkit tests
    21d2d55500 vendor: update buildkit to v0.25.0-rc1
    de5e64b3bd Add option WithSetNsHandles for testutil SetupTestOSContextEx
    0fb46d08ad api: docs: remove deprecated BridgeNfIptables, BridgeNfIp6tables
    362d4d9538 testutil:SetupTestOSContext - don't leak namespaces, netlink handles
    a32a53ae01 daemon/containerd: pass custom metaHeaders to resolver
    2223b7f582 daemon/server/imagebackend: add PushOptions struct
    9d53093db6 daemon/server/imagebackend: add PullOptions struct
    cbafff64e4 project: mark 23.0 branch as unmaintained (EOL)
    5d22d9bec9 integration/service: rename var to prevent shadowing
    471f24bafc daemon/server/backend: CreateImageConfig: change "Pause" to "NoPause"
    bad3dfe9cb client: ContainerCommitOptions: change "Pause" to "NoPause"
    1135ab0283 Dockerfile: update xx to v1.7.0
    f5847040cc client: Client.negotiateAPIVersionPing: trim v-prefix before handling
    af3f971431 client: TestNegotiateAPIVersionAutomatic: gofumpt
    a8cb35f01a client: TestPingHeadFallback: check method, path, and fix example response
    87d1da50f0 test: migrate test api network get defaults and filter
    d9cdfd2887 client: remove unused Client.HTTPClient() method
    d4d93bf558 daemon/container: remove State.ExitCode() method
    ee4b7a8374 daemon/container: remove NewState() constructor
    d06f0d008d explicitly access Container.State.Health.Health
    0df791cb72 explicitly access Container.State instead of through embedded struct
    aa492314a1 ipams: Re-enable legacy remote plugins support
    41a6ad5def client: remove deprecated ImageListOptions.ContainerCount
    02c4bb6a0c daemon/config: More tests for DNS addresses
    f7ed1b84d2 client: ImageList: don't discard reference filter on API &lt; 1.25
    d60b4ea278 client: fix version-gate for readonly-recursive mounts validation on service
    0673d43663 client: remove "version" header for service create, update
    9fc12daf80 client: remove version-gate for "--force" on "volume remove"
    839c2709af client: WithMockClient: match version behavior of actual client
    8f8a2db52c client: rename validateAPIVersion to validateServiceSpecForAPIVersion
    0468dac252 client: Client.ContainerCreate: fix panic when passing a nil config
    6d0551e13a api/types/network: CreateRequest: remove deprecated CheckDuplicate field
    50ea842e17 client: separate exec methods to ExecAPIClient interface
    94309db0aa daemon/server: Server.makeHTTPHandler: pass Route as argument
    81506ad8b1 daemon/server/router: NewRoute: don't use un-keyed struct literal
    82e5d3064a client: ImageBuildResponse: remove OSType field
    5028ff1f40 integration-cli: remove startContainerGetOutput, runCommandWithOutput
    2a867f0c4d daemon/server/backend: remove ExecInspect, ExecProcessConfig alias
    ff21989215 api/types/container: move ExecInspect type to client
    c1be6ef5de api/docs: remove KernelMemory option from old API versions
    c5991341eb remove support for deprecated kernel memory limit
    20d8342a4b move endpoint API version constraints to API server
    b70c1a439d gha: add missing dependency to Windows workflows
    18b289f9df daemon/server: fix requests not logged with --log-level=trace
    839e46f97c client: remove support for API &lt; v1.22 filter format
    a83d91f427 API: /info: remove `SecurityOptions` re-formatting for API &lt; 1.25
    082b4e8d77 client: move ExecOptions to client
    6a642300f0 client: move ExecStartOptions, ExecAttachOptions to client
    c8c13fe058 API: /info: remove magic `&lt;unknown&gt;` values for API &lt; 1.39
    c600f62c25 api/docs: sync swagger and update changelog
    6084882b98 client: tidy go.mod
    2bb0443ae9 Release IPv6 address if unused due to sysctl setting
    252659278e Configure addresses before adding them to DNS or /etc/hosts
    18b8e369ae Split OS-specific code out of Sandbox.populateNetworkResources
    a8b9eff902 Don't set up DNS in Network.createEndpoint
    ddf10ee1cd Delay Endpoint config until the osSbox exists
    b043980e6f daemon/config: remove deprecated CommonConfig.CorsHeaders
    4c7deaf832 Windows containers: restore network name after reboot
    9129094b98 Windows containers: report HNS network name in inspect
    aa78f19066 ipvlan-l2: do not allocate a gateway address from IPAM
    468e3521b0 macvlan: do not allocate a gateway address from IPAM
    caae209d25 api/types/container: remove deprecated ExecOptions.Detach
    19edf44896 daemon/config: remove deprecated Config.
    fabe66322f builder/remotecontext: remove deprecated "Rel()" utility
    cf243b64aa daemon: fix build after revendoring api module
    c2c2b80e90 daemon: report IPAM status for Swarm networks
    b092c8ca64 api/t/container: drop NetworkSettingsBase
    fc1ff44bc2 api/t/container: drop DefaultNetworkSettings
    d5d3716705 daemon/i/compat: disable HTML encoding
    8efe6b0183 Add TestJoinError
    73413ea693 bridge_linux_test.go: gofumpt
    52c9cfd016 Use sbLeave to roll back on error from sbJoin
    53390f85dd Put clearNetworkResources() inline in its only caller
    916fa31ab5 Acquire Sandbox.joinLeaveMu for Endpoint force-Delete
    a9db1e9a26 Endpoint.sbLeave: don't load ep from store
    b192d06ec7 Remove network info from container when endpoint join fails
    1b74b3e1ce api/types/events: Message: remove deprecated Status, ID, and From fields
    5815eb82ee daemon/events: omit deprecated event fields on API &gt;= v1.52
    c4eb791dba daemon/events: remove tests for deprecated API fields
    33a05ac344 daemon/internal: add "compat" package for legacy responses
    3f86797d3f api,daemon: report IPAM status for network
    ee8abb845d d/libnetwork: move uint128 to its own package
    65ffac3dbf internal/iterutil: add Chain, Chain2 iterators
    ee24728b1e go.mod: replace client
    139b6464b5 api/docs: fix events example response
    f8925bac6f daemon: Do not default to c8d image store on Windows
    bdd0a2a970 gha: extract vm test to a separate workflow
    8c8324b37f Dockerfile.windows: remove deprecated 7Zip4Powershell
    9d2e74d43d gha: Add automatic PR labeling for modules
    705f26010e client/image_inspect: Unexport ImageInspectOptions
    67c8064bb3 client: remove ImageInspectWithAPIOpts function
    5303799297 go.mod: re-add replace github.com/moby/moby/api
    2f1015482f libnet/d/windows: ReleasePorts: use errors.Join
    fc86411353 libnet/d/windows: inline releasePort
    9efc1cc264 libnet/portmapper: rename, move PortMapper to portallocator
    4b230a4909 internal/testutils: merge with internal/testutil
    d3e45f8743 testutil: move back to internal
    af677b61a5 libnet/portmapper: clean up windows port mapper
    90f31c6c27 libnet/portmapper: remove dead field bridgeName
    f6e5b3afc5 libnet/portmapper: drop unused NewWithPortAllocator
    9e7de1b679 libnet/portmapper: remove unused field proxyPath
    f6c59f9779 libnet/portmapper: merge mapper.go &amp; mapper_windows.go
    b48442db4c libnet/portmapper: remove dead DeleteForwardingTableEntry
    32710d3e5e libnet/portmapper: remove dead AppendForwardingTableEntry
    eb2e296711 daemon: GetContainerStats: use errdefs for error-type handling
    97eceb266a errdefs: remove deprecated IsXXX utilities
    2d73fed24e update AUTHORS
    37de02378c Prepare release notes for v2.0.0-beta.0
    de4ae66d08 Update client vendor to use tag
    b5dde0234c add back replace
    1499623a9d go.mod: update client to v0.1.0-beta.0
    0525ae2aed api: image inspect: remove temporary backfill for Config fields
    d98a8c59ab testutil/daemon: fail gracefully if DEST is unset
    8995619b9d testutil/daemon: fix DOCKER_USERLANDPROXY env var
    b5035def03 Prepare release notes for client/v0.1.0-beta.0
    76964752d3 Update client api version to v1.52.0-beta
    a1e3a109ee api/docs: sync v1.52 docs with latest
    0fe1af95f3 api/docs: remove temporary "full" example for image config (v1.50, v1.51)
    7bfbb6e8ca api/swagger: remove temporary "full" example for image config
    2d1af4e4e4 api/types/build: move build options to client and backend
    5232d82c1b daemon/server/backend: move build options to buildbackend
    8b8a3cb14c api/types/image: move LoadResponse to client
    a8afc2c6fb api/types/checkpoint: move checkpoint options to client
    f1da80e8d3 contrib/check-config: check SCTP protocol option
    d904f3b625 Prepare api/1.52.0-beta releases
    4e30076e4d Add mailmap entry for Austin
    e656f39952 api/t/network: generate more structs from Swagger
    ea1c2530da api/t/network: generate Inspect, Summary structs
    26e335b647 api/types/build: move `CachePruneOptions` to client mod
    798abe8965 vendor: github.com/spf13/cobra v1.10.1
    02a50be1f9 vendor: github.com/spf13/pflag v1.0.10
    aaa9dd4e26 gha: skip "vm" checks if `ci/validate-only` label is set
    ccf1363680 api/docs: update v1.52 docs with current swagger
    c208f90796 api/templates: vendor structfield template
    57ce548341 client: move container options together with their users
    4d20b6fe56 api/types/container: move container options to client
    c441b2ef19 api/types/image: make `InspectResponse.GraphDriver` optional
    1a86389419 api/types/network: separate Summary from Inspect
    f8bd170b2a daemon: validate args in network.New*Filter
    ea1dfbda9e daemon: prune networks using network.Filter
    f0d10ae733 d/network: filter networks individually
    a4a90c2248 api: fix deprecation of "keep-storage" /build/prune query parameter
    e46a991dc5 api: remove unused DefaultVersion, MinSupportedAPIVersion consts
    30406d42e3 update to go1.24.7
    e2e9f36c5f api/types/system: move `SecurityOpt` type and `DecodeSecurityOptions` to client
    d47b0db4f9 vendor: update buildkit to v0.24.0
    ca97d071b7 fix: client vendor with config struct changes
    37d6a1909b libcontainerd/remote: wrapError: don't convert c8d errdefs error
    36303969b9 libcontainerd/remote: container.NewTask: move vars to where used
    f37094ad4f libnet/d/bridge: CreateEndpoint: use d.config directly
    ae24edfc0d libnet/d/bridge: merge configure into newDriver
    2436458227 libnet/d/bridge: Register: pass a Configuration struct
    386a3a6bba libnet/config: mv config_{unsupported,windows}.go
    18f2e61d08 libnet/config: rm config_freebsd.go
    e099f1e409 daemon: Daemon.ContainerExecStart: fix typo in log field
    6e512cc292 libnet/d/ipvlan: Register: remove unused config param
    459f4f431d libnet/d/macvlan: Register: remove unused config param
    43014a891b libnet/d/overlay: Register: remove unused config param
    18efa5513d libnet: makeDriverConfig: drop support for label-based config
    1470048e00 libnet: remove drivers_freebsd.go
    4ea085187a libnet/d/bridge: export Configuration
    7b75f355e5 daemon/srv/r/ctr: handlePortBindingsBC: fix warning
    fbad7b568d libcontainerd/remote: task.Exec: log warning on cleanup failure
    e67b3b0b90 libcontainerd/remote: task.Exec: rename processID -&gt; execID
    003e17ff5a libcontainerd/remote: task.Exec: preserve parent context during cleanup
    167b0e9ea6 libcontainerd/remote: task.Exec: make defer error-handling more explicit
    55c929c97f libcontainerd/remote: rename var that shadowed import
    023ae2e218 contrib: remove udev rules for hiding loopback devices
    0ca7ac3258 daemon: backfill empty PBs slices for backward compat
    4d2a293ff3 libnet/drvapi: make NetworkAllocate optional
    cbd04b6f08 libnet/cnmallocator: use a list of local netdrivers
    478d1fc8ba Bump go.mod minimum-go-version to 1.24
    269960a4c6 integration-cli: TestConcurrentPush: refactor to improve failure logs
    8031b077bc gha/arm64: Setup qemu
    ce338dec81 integration/internal: Print Buildkit logs
    27fca93b65 c8d/history: Fix non-native platforms
    ad830a47af integration/internal: Handle Buildkit in GetImageIDFromBody
    f66f555ad4 graphdriver/windows: Potential fix for access denied
    ea73c88d12 libnet/cnmallocator: rm drivers_darwin.go
    18b21a32a1 libnet/cnmallocator: rm drivers_unsupported.go
    60fa39d559 hack: temporarily use custom buildkit ref for testing
    5682f65cca hack/dind-systemd: collect firewalld logs
    03df89b84a hack/dind-systemd: enable firewalld debug logs
    77ce202515 vendor: update buildkit to v0.24.0-rc2
    3c83038936 hack: use heredocs in generate-swagger-api.sh
    854ec0a1ad d/libn/internal/addrset: add popcount methods
    b7c597ec35 api/t/ctr: deprecate DefaultNetworkSettings
    c9fdad2552 daemon: marshal legacy `registry.ServiceConfig` extra fields for compatability
    d0de293513 testutil/daemon: remove unused FindContainerIP
    80bb864fd6 api/t/ctr: deprecate NetworkSettingsBase
    16dc39136c api/t/ctr: deprecate NetworkSettingsBase.Bridge
    20b679b4a6 client: Extract clientConfig for opt applying
    9ddf9d87e7 client: Remove newMockClient
    7cd089edd9 client/volume_test: Use functional option to create mock client
    72e11d78d7 client/task_test: Use functional option to create mock client
    a1e304f76c client/system_test: Use functional option to create mock client
    407af72993 client/swarm_test: Use functional option to create mock client
    124bba478a client/service_test: Use functional option to create mock client
    98434a5ea4 client/secret_test: Use functional option to create mock client
    c99f2eaf34 client/request_test: Use functional option to create mock client
    8581a15c25 client/plugin_test: Use functional option to create mock client
    0b577c703a client/ping_test: Use functional option to create mock client
    d401228b43 client/options_test: Use functional option to create mock client
    643e94ebf5 client/node_test: Use functional option to create mock client
    5a82c3397e client/network_test: Use functional option to create mock client
    be76beee8f client/image_test: Use functional option to create mock client
    005a289703 client/distribution_test: Use functional option to create mock client
    bc1d436aa9 client/container_test: Use functional option to create mock client
    c70aac772e client/config_test: Use functional option to create mock client
    6452807fb4 client/client_test: Use functional option to create mock client
    a3d073e160 client/checkpoint_test: Use functional option to create mock client
    17396e5d94 client: Add WithMockClient opt
    09ecd74cf3 CI: add oraclelinux-8 for running tests with cgroup v1
    1570ca934d Dockerfile: install fuse-overlayfs
    e15c51a03d Makefile: propagate DOCKER_IGNORE_BR_NETFILTER_ERROR
    ed78637b9a nftables: iterate over rules
    9dc0c094e6 cmd/docker-proxy: set O_NONBLOCK unconditionally
    12897011fa vendor: github.com/ishidawataru/sctp v0.0.0-20250829011129-4b890084db30
    785ae9a0f9 Rework the interface to libnet/internal/nftables
    cf913f5b0a d/cluster: use lockedManagerAction in more places
    4b866fdcef d/cluster: add context param to lockedManagerAction
    8839f53175 d/libnet: TestUserChain: fix error matching for nonexistent chains
    fbde2bcb9a nftabler,nftablesdoc: stringify numerical dstnat prio
    a4949b669e iptablesdoc: remove -n from iptables -L invocations
    fc045ad139 libnet/pmapi: remove firewaller arg from Map/UnmapPorts
    9b1c4ad3b1 libnet/pm/routed: don't set up firewall rules directly
    9d9b05446c libnet/pm/nat: move back fw / proxy steps into the bridge driver
    268e636b2b libnet/pmapi: let portmappers specify NAT/fwding rules
    c6717f4387 libnetwork: provide endpoint name for IPAM drivers
    5349095cd1 vendor: github.com/docker/go-events 605354379745 (main)
    229a29649f vendor: github.com/moby/buildkit v0.24.0-rc1
    071e6472db Unmap IPv4 addresses loaded from store
    b721c4f4a8 daemon: minor touchups for backend system info response marshal
    60c6e57b82 hack/make/test-integration: disable firewalld integration
    1b4fcb8da7 api/types/network: move `CreateOptions` type to client module
    b0b7260c77 ImageCache.restoreCachedImage: rename var that shadowed import
    1e249cc309 api/types/network: move connect/disconnect options types to client module
    3003c5fe45 d/libnet: fix CreateOptionIPAM capitalization
    853aed171b api/types/image: move image option types to client
    33066cddb1 api/types/swarm: move `SecretListOptions` type to client
    33cdcd62f5 daemon: Daemon.getInspectData: also set Config
    fae54e03af api/types/container: merge InspectResponse and ContainerJSONBase
    c9a0c93b04 d/libnet: remove unused arg from CreateOptionIpam
    b85c91f1b8 fix vendor
    44972d7427 daemon: Daemon.getInspectData: inline struct-literals
    94d0b10503 api/types/swarm: move `ServiceInspectOptions` type to client
    a2291e5eac api/types/swarm: move `ServiceListOptions` type to client
    3b1e16594b api/types/swarm: move `ServiceUpdateOptions` type to client
    bb4125e89f api/types/swarm: move `ServiceCreateOptions` type to client
    4dcc7af116 api/types/swarm: move `UpdateFlags` type to client
    ad0fa5a872 api/types/swarm: move `TaskListOptions` type to client
    2718f953f0 api/types/swarm: move `NodeRemoveOptions` to client
    7d2b87e95f api/types/swarm: move `NodeListOptions` to client mod
    b1260cd493 api/types/swarm: move `ConfigListOptions` to client
    bdce1608c8 api: move authconfig package from types/registry to pkg
    ff0e644c88 daemon/cluster: use authconfig package for decoding
    9f1d8be252 docs/contributing: minor fixes
    dbe19a506e fluentd logger: add read timeout configuration.
    28ba0fcaae vendor: github.com/fluent/fluent-logger-golang v1.10.1
    3bcaf1c4da vendor: github.com/tinylib/msgp v1.3.0
    27b609b401 vendor: github.com/philhofer/fwd v1.2.0
    1d6c7663c4 d/libnet/i/nftables: move golden files into subdir
    28afa75c39 d/libnet: TestIptabler: move golden files into subdir
    ce4a331287 d/libnet: TestNftabler: move golden files into subdir
    c5e75cc485 daemon/containerd: remove convertError utility
    6fbea5f5c1 image delete: inline some variables, and touch-up TODOs
    7f8ce05f6e client: check for Digested reference instead of Canonical
    eed354379c api: docs: update v1.52 swagger with latest changes
    0de3d2ec51 Dockerfile: update rootlesskit to v2.3.5
    70d096313f vendor: github.com/rootless-containers/rootlesskit/v2 v2.3.5
    fe8516cf4b client: refactor `InspectOptions` to `NetworkInspectOptions`
    5eaed0366c api/types/network: move `InspectOptions` to client mod
    6084c6ae78 client: refactor `ListOptions` to `NetworkListOptions`
    d6aa6ae9bd api/types/network: move `ListOptions` to client
    d867f9f0f1 api/docs: update description for AuthConfig.Email field
    6cfff7e880 api/types/registry: update deprecation comment for AuthConfig.Email
    7aa50424e3 daemon: decouple daemon backend from client volume list options
    9fc6a1e437 api/types/volume: refactor volume options to prune report
    ee22a62dd5 client: refactor `ListOptions` to `VolumeListOptions`
    c48585f104 api/types/volume: move `ListOptions` to client mod
    56626a1222 api/types/system: move `DiskUsageOptions` to client mod
    4665aa11ce client: refactor `SearchOptions` to `ImageSearchOptions`
    40025bdf43 api/types/registry: move `SearchOptions` to client
    e8d0aba254 vendor: golang.org/x/sync v0.16.0
    60125b888c contrib: update dockerfiles to debian 13 "trixie"
    39d4dbea9c Dockerfile: update debian frozen image to trixie-slim
    15f92925f0 vendor: go.etcd.io/bbolt v1.4.3
    eb9774cbf9 client: rename `ListOptions` type to `EventsListOptions`
    d73dd4990c api/types/events: move `ListOptions` type to client
    db72cc28c7 Rename test helper function input parameters to not shadow client package
    f07d359043 client: rename `ResizeOptions` type to `ContainerResizeOptions`
    882fd68b1b api/types/container: move `ResizeOptions` type to client
    14262696d7 libnet/pa: OSAllocator: retry allocations
    201968cc03 libnet/pa: OSAllocator: listen after bind
    86ae7a56d2 daemon: Fix container restore with automatic driver selection
    555e3939c9 daemon: Fix forceful switch to containerd image store
    47bdbf5a4b client/pkg/jsonmessage: remove unused fields
    c4e82bab70 api/types/volume: move `DiskUsage` type internal to daemon backend
    0d61b55add api/types/image: move `DiskUsage` type internal to daemon backend
    566c44edfe api/types/container: move `DiskUsage` type internal to daemon backend
    d588092be2 api/types/build: move  internal to daemon backend
    eac4c43aaa integration/system: remove TestEventsBackwardsCompatible
    b0d9a90f45 integration/system: add TestEventsNonBlocking
    000f5e8d10 daemon: Daemon.ContainerStats: small cleanups
    f4ae01a38a daemon/server/router/system: getEvents: use event consts for filtering
    6b52a16f14 integration/network/bridge: add "generated" header to markdown docs
    48557f72f9 daemon/libnetwork: TestUserChain: rename golden files
    ff8364a39f hack/test/unit: use empty default values
    fbd3cdc007 fix vendor
    da2b1a2930 Fix image prune events for containerd backend
    b68ff62ab7 daemon/libnetwork/bitmap: add OnesCount method
    be7a769b69 Dockerfile: disable CGO for building utilities
    8de606beb1 Dockerfile: remove trailing slashes for GOBIN
    aa80ad2572 Copy the daemon/internal/timestamp package to internal client package
    812aa46d81 Move the api/types/time package to internal daemon package
    033ec8be44 daemon/router/image: initialize default authConfig
    f0c069ffc9 gha: Add conditional skip for jobs with 'ci/validate-only' label
    8013d80c24 hack/test/unit: run in the right module when TESTDIRS is used
    97587945ef .github/workflows: Add kind label validation to PR workflow
    d2e0895b9b daemon: deprecate env vars set by legacy links
    b13ea83488 api: bump github.com/google/go-cmp v0.7.0
    56c48e8708 d/libn/bitmap: tidy up constants, branchy math
    82ba7fef17 api/types/container: rename Port to PortMapping
    48038347d7 Match device driver on name and ignore capabilities
    2aba802ae6 daemon: don't strong-type filters
    a2aa7be724 vendor: go.etcd.io/bbolt v1.4.2
    1c34ff94bc client: consistently use defer for ensureReaderClosed
    f6b63e6013 client.sendRequest: clean-up logic for error-handling
    2a4f70309d client.doRequest: improve GoDoc to clarify behavior
    d69fde4c60 client: Client.Ping: improve error handling and fallback
    b2e6fd31cf Restore DOCKER_DRIVER environment variable for storage driver configuration.
    80294ddb60 client: make checkResponseErr a regular function
    423980614e daemon: use slices.Clone, maps.Collect in some places
    6505e8d605 daemon/libnetwork/types: rename StaticRoute.GetCopy to Copy
    1e11e64c9c daemon/libnetwork/types: remove TransportPort.Equal()
    561e14ea3f daemon/libnetwork/types: remove TransportPort.GetCopy()
    385297ee40 daemon/libnetwork/types: remove unused IsIPNetValid utility
    7960f742a2 daemon/libnetwork: Endpoint.CopyTo: use maps/slices.Clone
    a82a68a445 daemon/libnetwork: replace endpointJoinInfo.CopyTo with Copy()
    2d5100749d daemon/libnetwork: replace EndpointInterface.CopyTo with Copy()
    80452e5d4a daemon/libnetwork/types: PortBinding.Equal: use non-pointer receiver
    7d5312ab56 daemon/libnetwork/types: rename PortBinding.GetCopy to Copy and non-pointer
    e387dc977e daemon/libnetwork/types: cleanup GetIPNetCopy, GetIPNetCanonical
    68a94ecbb5 daemon/libnetwork/types: remove GetIPCopy; use slices.Clone
    115b801a3b daemon/libnetwork/types: remove GetMacCopy; use slices.Clone
    cfad3ed6b9 daemon/libnetwork: replace IpamInfo.CopyTo with IpamInfo.Copy()
    2f74f245b6 daemon/libnetwork: replace IpamConf.CopyTo with IpamConf.Copy()
    796a4ce952 daemon/libnet/drv/bridge: stubPortMapper.UnmapPorts: fix slices.Delete
    a4fbbc1570 Add context to restore and load containers
    85b79f83f4 Fix hardlink handling in containerd snapshot remap
    ead007f1f1 Use native snapshotter for integration tests and run
    99181f56ce Fix symlink evaluation to a directory that may not exist
    4816383c0b Add environment variable to define the threshold
    185ae7ec2c docs: api: Tweak type of ForceUpdate to uin64
    c8173c5c1f api: swagger: Tweak type of ForceUpdate to uint64
    0a89d98bad daemon/libnetwork/types: remove errdefs aliases
    892ebd2f17 daemon/libnet/drivers/windows: small cleanup in error-handling
    11094e27b0 api/types/network: modernize EndpointIPAMConfig.Copy, EndpointSettings.Copy
    b48df69b02 daemon: Daemon.ContainerInspect: move vars closer to where used
    582ee7ea57 daemon/builder/dockerfile: copyRunConfig: use slices/maps.Clone
    0ded8645b6 Fix custom runtimes handling on Windows
    aa6838ae54 vendor: go.uber.org/zap v1.27.0
    daf843b72f vendor: go.uber.org/multierr v1.11.0
    aa85a44139 vendor: github.com/google/btree v1.1.3
    fe32e4a999 vendor: github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8
    76fc74317a vendor: github.com/golang/gddo v0.0.0-20190904175337-72a348e765d2
    632fb0c89a Update graphdriver check logic to account for disabling of snapshotter
    b41babafaa Fix windows test graphdriver setting
    8700bca2bf Update migration test to use graphdriver env
    00463b9216 Fix containerd image count
    7f87cf9d8a Check for snapshotter plugin availability
    632de98f75 Enable containerd snapshotters by default
    9f5f4f5a42 Add containerd migration to daemon startup
    2fff6b442e check-config.sh: report IP forwarding sysctl state
    f71e86eed5 rootless: enable IP forwarding
    f802d8a08e When cleaning iptables rules, warn on filter-FORWARD DROP
    67ffa47090 nftables: don't enable IP forwarding
    7dfeee8460 Drop FirewallCleanerSetter interface
    200a75b34a Return concrete types from NewNftabler/NewIptabler
    050fbbccca chore: use errors.Join instead of github.com/hashicorp/go-multierror
    96f8c6395e chore: enable use-any rule from revive
    c6be4ad999 libnet/pa: don't set SO_REUSEADDR on UDP sockets
    3862a0875c check for net.ErrClosed instead of "use of closed network connection"
    9cae3fb167 docs/contributing: remove GIT_BRANCH image tag references
    04d95003fd Stabilize TestSaveAndLoadPlatform integration test.
    1f323d5035 client: README: add badges
    662154a940 api: README: add badges
    b4e353c02b README: add license and OpenSSF badge
    df3aea43aa remove references to "vendor.mod"
    98790830eb Deprecate api/types/strslice.StrSlice and remove its use
    b25b421f97 update to go1.24.6
    677c2a19d9 vendor: github.com/docker/go-connections v0.6.0
    50789e2bab testutil/fakestorage: inline go code and remove contrib/httpserver
    d49a354cb2 testutil/fakestorage: use local paths, fix port-mapping and optimize
    8be1b2372a Dockerfile: update containerd binary to v1.7.28
    b9b52d59b8 download-frozen-image-v2: Use curl -L
    359a881cea download-frozen-image-v2: handle 307 responses without decimal
    12c6345d3a libn/d/overlay: don't deref nil PeerRecord on error
    dcaf8893a0 windows: do not forgot IPAM configuration when re-creating networks
    0ad765c67d add back replace and vendor, tidy
    f5f984eec6 Dockerfile: update runc binary to v1.3.0
    234349d173 api/docs: sync v1.52 swagger with current version
    833dc69ad9 docs: improve the description of the `outputs` parameter for `/build` endpoint
    c145229828 update some fixtures in tests
    90c3d29bfb go.mod: tidy
    78ccee32b3 update various "doc" links in code
    d82f50557e Bump api version in client and main module to v1.52.0-alpha.1
    a0a7d9a3d7 Add release notes for client/v0.1.0-alpha.0
    32ec26be6c Update client and main module api version to latest alpha tag
    e30b8e3393 update golangci-lint settings
    57256a9b62 fix error-capitalization
    c13266d2c0 api/types: move plugin types to api/types/plugin
    c17d43ae67 api/types: move ErrorResponse to common/ErrorResponse
    15f78b752c daemon: make buildSandboxOptions, buildSandboxPlatformOptions more atomic
    77c2e3279d daemon/libnetwork: Sandbox.EnableService/DisableService slight cleanup
    bfce6556c4 client: use stdlib errors
    3fe93532e4 client: tidy go.mod
    3b14c5488f go.mod: github.com/containerd/containerd/v2 v2.1.4
    259eb259bc go.mod: dario.cat/mergo v1.0.2
    d8b622b315 go.mod: github.com/docker/go-events v0.0.0-20250114142523-c867878c5e32
    8e63b55146 go.mod: github.com/fernet/fernet-go v0.0.0-20240119011108-303da6aec611
    044234f847 api/docs: add v1.52 swagger
    59e8fe8479 Prepare release notes for v1.52.0
    dfac16c297 hack: Update cosmetic occurences of the old package name
    83267a0fda go.mod: github.com/docker/docker v28.3.3
    5b3e1a6425 go.mod: tidy
    0ae3cb000e validate/pkgimports: Fix package name
    22bd59010e hack: Fix dockerversion not being set correctly
    79148460b0 hack/make.ps1: Replace old package name with moby/v2
    2dcd8b8def golangci: Replace old package name with moby/v2
    cad3a5775b docs: fix URI fragment by changing it to the existing subheading
    778d8e3a26 libnet/d/bridge: handleFirewalldReloadNw: fix deadlock
    519adb26c3 libnet/d/bridge: driver: un-embed mutex
    752a3b302c api/pkg/stdcopy: add example
    26cf610e6e api/pkg/stdcopy: improve docs
    c010c84ade api/pkg/stdcopy: don't use iota for consts
    195a6bbb1e client: touch-up godoc
    e7c784c270 Dockerfile: add GO_SWAGGER_VERSION build-arg
    908895b9c3 api: update "interface{}" to "any"
    51bbc37f64 api/types/strslice: use slices.Equal
    dab42db691 contrib: remove editorconfig
    5fbbf040aa contrib: remove mac-install-bundle.sh
    5a40d4ed9f contrib: remove syntax (Dockerfile syntax) files
    62545ddf90 daemon/internal/image: remove image-spec markdown
    4cfc260a5f TESTING.md fix links to gotest.tools, and some touch-ups
    1205a15db1 libnetwork/types: define RouteType type
    6aab881534 libnetwork/types: make Protocol consts strong-typed
    ec5dbaf233 libnetwork/types: define IPFamily options using syscall.AF_XXX consts
    95eeb0b3b0 libnetwork/types: define IPFamily type for IP-family consts
    ee560a3b23 api/types: fix Plugin.Config.Interface.Types def'n
    2783f80ecf api/types: generate with latest go-swagger
    5365f08ae2 daemon/config: make DNSConfig.DNS a netip.Addr
    a43198845b daemon/pkg/registry: un-export ResolveAuthConfig
    5fbf680f5d daemon/pkg/registry: move newIndexInfo to search
    6a7f0008a3 daemon/pkg/registry: move searchRepositories to where it's used
    17d0ac56f3 daemon/pkg/registry: remove session; make searchRepositories a func
    0c73c459b4 daemon/pkg/registry: un-export GetAuthConfigKey
    eda6a499e3 router/distribution: fetchManifest; detach from distributionRouter
    aac2623115 integration/container: TestCheckpoint: inline containerExec util
    03991f4846 builder-next: puller.Snapshot: cleanup handling of v1 images
    0156a42200 daemon/libnetwork/resolvconf: remove unused code
    bbec7a5150 migrated test container API rename to docker/cli
    1e499bae79 daemon: consolidate platform-specific inspectExecProcessConfig
    49aa38e9e7 update links to swarmkit v2 docs
    c98e5cb60b update github links to moby/moby
    cf15d5bbc6 remove obsolete //go:build tags
    02b3f1cd99 integration: remove stray "distribution" directory
    297ea75204 check_config: add nftables modules to optional features
    83357620e2 Update unit test script for windows
    58c95cde9b Replace uses of code which requires 1.24+
    900a0516de Update hack/test/unit for go module
    1d571e619d Rename build package to moby v2 module
    65867642d3 Remove go module workarounds
    f74e5d48b3 Create github.com/moby/moby/v2 module
    a954a0f4a2 Remove profiles
    53bd828853 Remove libnetwork
    e55d294ea7 api/types/registry: add TODO/note about empty authConfigs
    8b68b977b1 Revert "api/types/registry: EncodeAuthConfig: use empty string for zero value"
    5bbf3af980 daemon: fix linting S1016 (staticcheck) false positive
    d58dc493fe replace direct uses of nat types for api/types/container aliases
    494677f93f api/types/container: add aliases for go-connections/nat types
    f3ba0b2dc2 client/pkg/jsonmessage: remove Stream interface
    19edf5c53c client/pkg/jsonmessage: remove DisplayJSONMessagesToStream
    fdaccdb233 pkg/jsonmessage: stop printing deprecated progressDetail, errorDetail
    94ac102e4b api: remove deprecated NoBaseImageSpecifier
    0d8ca8eefe Move pkg/jsonmessage to client/pkg/jsonmessage
    d00ecdc479 Move pkg/streamformatter to api/pkg/streamformatter
    66862e14d1 Move pkg/progress to api/pkg/progress
    1da417980c Move api/stdcopy to api/pkg/stdcopy
    ebef4a44fd Split streamformatter from jsonmessage
    5a144c40e2 pkg/streamformatter: reduce jsonmessage.JSONMessage dependency
    f4127d76c5 pkg/jsonmessage: move JSONProgress to api/types/jsonstream
    0515e1c991 pkg/jsonmessage: move JSONError to api/types/jsonstream
    9a52e474a3 pkg/jsonmessage: suppress unhandled errors
    02fcde0c18 Add separate const for daemon httputils to avoid jsonmessage import
    e257027903 pkg/jsonmessage: remove github.com/morikuni/aec dependency
    d7082848a6 tidy vendor.mod
    6c7e2909c2 api/types/filters: remove deprecated ToParamWithVersion
    5535e81a79 pkg/system: move to daemon/internal
    d94171bfaa pkg/system: make XattrError linux-only
    aa9de914ca pkg/system: remove unused ErrNotSupportedPlatform
    28b822d5b3 pkg/system: remove Lgetxattr, Lsetxattr stubs for non-Linux
    450ac30e4a pkg/system: LUtimesNano: remove stub for non-Linux
    03f44e6d14 pkg/system: MkdirAllWithACL: remove stubs and unused os.FileMode arg
    6f9e099fd3 pkg/system: remove deprecated IsAbs
    53a3085256 pkg/system: remove deprecated EscapeArgs
    1313b8caff pkg/fileutils: move ReadSymlinkedDirectory to daemon
    ae0a3d6918 pkg/fileutils: move ReadSymlinkedDirectory internal to daemon
    bae46854c5 pkg/fileutils: remove unused CopyFile utility
    46854ca5ab daemon/pkg/registry: remove copy of rootless.RunningWithRootlessKit
    f1c65c1dd6 daemon/pkg/registry: Service.Auth: remove unused statusMessage return
    f797ced96a daemon/pkg/registry: remove unused ParseRepositoryInfo, RepositoryInfo
    e30d541da0 daemon/pkg/registry: remove unused ReadCertsDirectory
    d80e16bb18 daemon/pkg/registry: remove unused ParseSearchIndexInfo
    4c1ab68c6c daemon/builder/remotecontext: remove detection of system.XattrError
    1dc53e8ec7 Update client go.mod
    03d7f47f31 Update api go.mod
    5bbb7182e7 Move logdriver to internal under daemon/logger
    d7cfe97984 Update logdriver to remove proto definitions
    f866621303 contrib/check-config: fix kernel version range check
    df8d45c7c9 contrib/check-config: fix MEMCG_SWAP
    ee24dcec3d Move swarm runtime plugin storage type to internal
    86190e7366 Move swarm runtime plugin spec to swarm types
    d761d9d358 pkg/rootless: move to daemon/internal
    17959aff2c remove pkg/stdcopy as it has moved to the api module
    c055c3e098 remove pkg/stringid as it has moved to the client module
    76e2ca1d41 pkg/stack: move to daemon/internal
    f78d595c96 runconfig: move to daemon/internal/runconfig
    75bc4c5292 daemon/server/router/container: request sysInfo from daemon / backend
    02867f9473 runconfig: rewrite ContainerDecoder to DecodeCreateRequest
    5e567a3856 daemon/server/httputils: remove ContainerDecoder interface
    ec3e83a7b5 api/types/container: move StateStatus, NewStateStatus internal again
    667cb4bec8 fix vendor
    26fda349b8 runconfig: remove exported errors
    969b293778 iptables: remove SCTP checksum rule
    e6298db297 cli/ is not in moby repo (anymore)
    83510a26b3 api/types: move backend types to daemon/server
    be27300c6e daemon/server/router/checkpoint: remove unused httputils.ContainerDecoder
    b448dc5575 daemon/server/router/container: postCommit: only decode Config
    6b4dfb0135 integration-cli: migrate TestPostContainersCreateShmSizeXXX to integration
    617326a40c testutil, integration-cli: fix minor linting issues
    da92ea2837 integration-cli/daemon: rewrite CheckActiveContainerCount with client
    6adbeff449 integration-cli: remove parseEventTime utility
    281a3f6c41 integration-cli: remove deprecaed inspectMountSourceField
    6124c00827 integration-cli: buildImageSuccessfully: don't wrap buildImage
    877529c62d integration-cli: remove deprecated inspectFieldWithError utility
    68480dc11d integration-cli: remove createTmpFile utility
    29a7d4039e integration-cli: remove deprecated inspectFieldMap utility
    d100fd6a77 integration/system: remove "hdr" utility
    97827e1a58 integration-cli: TestContainerAPIGetExport: fix minor linting issues
    f73aba83dc client: TestContainerStats: fix minor linting issues
    f67e6555bf api/types/container.StatsResponseReader: move to client
    4dda328af8 client: rename files for system-commands to their canonical name
    96a6884cb3 api/types: move DiskUsage types to api/types/system
    82c069c857 api/types/system: move DiskUsage, DiskUsageOptions to api/types/backend
    24aa86991c api/types: move PluginCreateOptions to client
    b93ad81898 api/types: move plugin client options into client
    44ae4cd2b7 api/types: move HijackedResponse into client
    f491b70aa4 integration-cli: remove "requirement" package
    ca1c5ee08f pkg/stringid: move to daemon, and provide copy in client
    0abcdb7405 Update golangci for lazyregexp
    6514282136 Move internal/testutils/networking to integration/internal/testutils/networking
    14eb2770b9 Move internal/unshare to daemon/internal/unshare
    28de87fb28 Move internal/unix_noeintr to daemon/internal/unix_noeintr
    5b913b3ea0 Move internal/sliceutil to daemon/internal/sliceutil
    20cc1a6203 Move internal/rootless to daemon/internal/rootless
    8042010175 Move internal/platform to daemon/internal/platform
    c3b0e0130a Move internal/otelutil to daemon/internal/otelutil
    b62b542c2e Move internal/opts to daemon/internal/opts
    713d7f5ed1 Move internal/nlwrap to daemon/libnetwork/nlwrap
    fd21e3b935 Move internal/multierror to daemon/internal/multierror
    baea1c5092 Move internal/ioutils to daemon/internal/ioutils
    50743e3f38 Move internal/containerfs to daemon/internal/containerfs
    ca9c4dffb7 Move internal/cleanups to daemon/internal/cleanups
    222b2b8b2f Move internal/lazyregexp to daemon/internal/lazyregexp
    9566272f30 Move pkg/tarsum to daemon/builder/remotecontext/internal/tarsum
    ca5d2348d0 Move pkg/idtools to daemon/internal/idtools
    7bfb804dbe Move registry to daemon/pkg/registry
    f1f83dae55 Move reference to daemon/internal/refstore
    c74ba95583 Move oci to daemon/pkg/oci
    f24455c90b Move image to daemon/internal/image
    1ff6011e04 Move distribution to daemon/internal/distribution
    fa9a3c383d Move layer to daemon/internal/layer
    3003c56c57 Delete TestRunDNSOptionsBasedOnHostResolvConf
    3205fcf6c7 pkg/stringid: TruncateID: touch-up doc
    6ed00d5044 registry: ConvertToHostname: use strings.Cut
    547a2db21d registry: TestNewIndexInfo: inline testIndexInfo (thelper)
    5ea78575e7 registry: fix assorted gocritic issues
    406ee2feb5 registry: translateV2AuthError: fix singleCaseSwitch (gocritic)
    ecb0354da5 registry: isCIDRMatch: fix captLocal (gocritic)
    1ceda96864 registry: serviceConfig.loadInsecureRegistries: fix ifElseChain (gocritic)
    d4e85443ff registry: remove deprecated RepositoryInfo.Class field
    cc2d564a9e registry: remove deprecated RepositoryInfo.Official field
    38453db513 contrib: remove gitdm
    0d9304c9e1 docs: remove old rootless placeholder
    a1f68bf5a6 overlay: Reload Ingress iptables rules in swarm mode
    8b208f1b95 libnetwork: split programIngress() and dependent functions on Add and Del functions
    50e6f4c4cb libnetwork: refactor ingress chain management for improved rule handling and initialization
    4f0485e45f libnetwork: add FlushChain methods for improved iptables management
    262c32565b libnetwork: refactor rule management to use Ensure method for Append and Insert operations
    19a8083866 libnetwork: refactor iptable functions to include table parameter for improved rule management
    c2e2e7fe24 libnetwork: extract plumpIngressProxy steps in a separate function
    51ed289b06 libnetwork: extract programIngressPorts steps in a separate functions
    752758ae77 libnetwork: extract creation/initiation of INGRESS-DOCKER chains in separate function
    07393071ad bridge: Reapply endpoint iptables rules on firewalld reload
    6d457d9695 bridge: Trigger firewalld reload during bridge integration tests
    f1a97bda3d api/types/container: remove deprecated Stats type
    4d5a7289a0 api: move docs to api module
    bdcf4e8c85 adjust minimum API-version for multiple platforms on save/load
    a401c0c046 runconfig: update fixtures for TestDecodeContainerConfig
    1378604cc3 integration-cli: remove tests for pre-docker 1.7 clients
    8d8bbefb90 client: remove deprecated CommonAPIClient interface
    728f0769e1 client: remove deprecated ImageInspectWithRaw
    2f200f9e05 client: remove deprecated IsErrNotFound helper
    5ed9891eed client: remove deprecated ErrorConnectionFailed helper
    a0fa5da2ab client: remove deprecated NewClient and NewEnvClient functions
    30322dd649 client: fix example, and update refs to old modules
    4859497098 pkg/stdcopy: fix missing alias for stdcopy.Systemerr
    01c7b4233c hack/validate: remove obsolete exception
    b91ebbde6d Refactor containerd platform matchers.
    fcc8209e12 Add support for multiple platforms in image export and loading.
    2303e6bff6 client: Client.doRequest: add special handling for DNS resolution errors
    67596f01e2 client: Client.doRequest: add special handling for "not found" errors
    462d0ff5aa client: Client.doRequest: simplify permission check and unwrap error
    7072acac79 client: Client.doRequest: preserve wrapped error
    3b4fbaacd7 client: Client.doRequest: use early return
    cf1695bef1 Add option --bridge-accept-fwmark
    2a342079c6 api/types/container: add missing type for exec-inspect response.
    a600da91f4 profiles/apparmor, seccomp: migrate to separate module
    30752f0780 Always allow access to routed endpoints
    4538a1de0a libnetwork: handle coalesced endpoint events
    e1a586a9a7 libnetwork/d/overlay: handle coalesced peer updates
    8340e109de libn/d/win/overlay: dedupe NetworkDB definitions
    c7b93702b9 libn/d/overlay: extract hashable address types
    844023f794 libnetwork/driverapi: make EventNotify optional
    69c3c56eba libn/networkdb: report prev value in update events
    34fb2486ef test: migrate test api client version old not supported
    cc9e6a13a2 api/types/swarm/runtime: remove module path for generating proto
    76c1afeb97 api/types/plugins/logdriver: remove module path for generating proto
    85ecf8c0f4 api: update references to old module name
    a17a2e8f3d api/stdcopy: touch-up godoc
    5b8ef1aff2 api: remove redundant //go:build lines
    260cc008f4 fix vendor
    4e246efcd1 libnet/d/bridge: mv portmapper to libnet/pms/{nat,routed}
    289ef96d8b libnet/d/bridge/i/rlkclient: move to libnet/i/rlkclient
    41cd92f6c0 libnet/portmapperapi: add PortMapper interface, registry
    afb231d027 libnet/d/bridge: add a new Hairpin config flag
    6f59a8e665 libnet/d/bridge: call setChildHostIP while binding
    43f384c452 libnet/d/bridge: connectivityConfiguration: use PortBindingReq type
    aa36cc5d25 libnet/d/bridge: move portBinding to portmapperapi
    429818f969 libnet/d/bridge: move portBindingReq to portmapperapi
    090c319f2e Don't allow the daemon to start with nftables and Swarm enabled
    26e487db78 testutil: Fix sense of hasFwBackendArg check
    6e7a2c830d Add Health attribute on the docker ps command
    c4f9616c4a client: cleanup encoding body and add test-coverage
    024414b47e integration: rename vars that shadowed import
    20d594fb79 deprecate pkg/stdcopy, move to api/stdcopy
    f651a5d5e9 registry: remove uses of lazyregexp
    b33b4bd290 internal/testutils/networking: rm uses of lazyregexp
    daa991c3d8 testutil/environment: don't use regex for string-matching error
    0dc3193b2b integration-cli: remove uses of lazyregexp
    6f9758047d fix: add create log stream awslog driver log option to validate list
    c47afd41c8 Create github.com/moby/moby/client module
    afd6487b2e Create github.com/moby/moby/api module
    135cea2a10 Update test-unit for client module
    7e708a5416 Update unit tests for api module
    0971099c5f Add options to vendor to add and remove replace
    eab076f217 Gocompat tests no longer needed with go modules
    c469e5ebab daemon/server: rename vars that shadowed imports
    61b19a494a oci: deprecate SetCapabilities
    b9196ed703 oci: fix godoc for SetCapabilities, TweakCapabilities
    5c683e8603 oci: sort defaultLinuxMaskedPaths
    0433def57d internal/platform: remove NumProcs() stub for Linux
    1a504f68fd Add nftables+firewalld tests to CI
    02d7a3026a Support nftables+firewalld
    d95dceb3b1 build: device entitlement support
    655dbe69d0 pkg/tailfile: rename vars that shadowed type
    a089c51160 pkg/idtools: remove deprecated functions and types
    3bc64b312e runconfig: decodeContainerConfig: fix godoc referencing wrong type
    ab5d348b77 integration-cli: remove uses of "runconfig"
    0c3185a835 daemon: killProcessDirectly: use "WithFields" for logging
    1cc42643ae hack/buildkit-ref: temporarily bump BuildKit to head of v0.23 branch
    18e463a082 api/types: remove deprecated RequestPrivilegeFunc type
    a3920ae6a0 api/types: remove deprecated IDResponse type
    3e5a06179e api/types: remove deprecated container-inspect types
    8347b05435 api/types: remove deprecated Container type
    f050df0329 api/types: remove deprecated ContainerState type
    7abeb4d5a4 api/types: remove deprecated container-networksettings types
    c5a2194b5d api/types: remove deprecated container Health types
    76bf0e2929 api/types: remove deprecated MountPoint
    207db8792e api/types: remove deprecated Port
    fa8177ba7a api/types: remove deprecated GraphDriverData
    836ec65d5f api/types: remove deprecated ImageInspect, RootFS
    7d3459e7fb api/types: remove deprecated SecretCreateResponse, SecretListOptions
    68744c8b05 api/types: remove deprecated ConfigCreateResponse, ConfigListOptions
    33f07ff3f4 api/types: remove deprecated NodeListOptions, NodeRemoveOptions
    f13796d2af api/types: remove deprecated TaskListOptions
    72b1e11264 api/types: remove deprecated ServiceCreateOptions
    3faead6fc1 api/types: remove deprecated ServiceUpdateOptions
    55ad118eaf api/types: remove deprecated ServiceListOptions, ServiceInspectOptions
    91558ae3f3 api/types: remove deprecated SwarmUnlockKeyResponse
    74fe646ac2 api/types: remove deprecated build-cache types
    3eac6e7888 api/types: remove deprecated BuildResult
    088cb2ffa6 api/types: remove deprecated build-related types
    1359046a36 pkg/process: call out that "Zombie" is only supported on Linux
    94618ac3ab pkg/process: separate exported funcs from implementation
    a88e13f4f9 client: fix datarace when accessing cli.Version field
    e6cdf24bcd windows: include labels when re-creating non-default nat networks
    d4e026fe20 Wait for container dependencies upon daemon start up
    39ab393274 Add daemon option --firewall-backend
    7b9bd987bf api: deprecate NoBaseImageSpecifier
    a632b8495b daemon: define default (and maximum) API version
    2b17ab0ec6 libnet/internal/resolvconf: fix naming of error (errname)
    aa757e591d libnet/internal/resolvconf: don't use rc.WriteFile in tests
    8d54d36bce libnet/internal/resolvconf: fix naming of error
    60a3a28a04 libnet/internal/resolvconf: minor optimizations
    f22a3dfdb7 libnet/internal/resolvconf: optimize Generate() without text/template
    0775ab6661 libnet/internal/resolvconf: add benchmark for Generate()
    41da5700a4 client: define default (and maximum) API version
    b54bde4376 Move testutils image load to integration internal
    b83f36877f Move internal/mod to daemon/internal/builder-next/worker/mod
    af86e80825 Move daemon/build to daemon/builder/backend
    7d48302134 Move builder to daemon/builder
    6ff9bea6a7 Move builder/builder-next to daemon/internal/builder-next
    3a447bc079 api/types/registry: EncodeAuthConfig: use empty string for zero value
    472e09ac47 api/types/registry: DecodeAuthConfig: add early returns and improve errors
    6865032baa api/types/registry: add BenchmarkDecodeAuthConfig
    c1b95c0ca2 ci/windows: Always run tests with c8d
    967daa627a integration: Skip TestRunMountImageMultipleTimes on Windows
    a615ec798d builder/remotecontext/git: fix linting issues
    6a8654a808 api: bump to 1.52
    ac5f464649 libnetwork/networkdb: improve quality of randomness
    5799deb853 libnetwork/networkdb: test quality of mRandomNodes
    d8730dc1d3 libnetwork/networkdb: add convergence test
    7771a38896 Remove integration test using daemon internals
    17d5f731f1 Move internal/safepath to daemon/volume/safepath
    7edd7c68b1 Move internal/mounttree to daemon/internal/mounttree
    daeaac0d3c Move internal/directory to daemon/internal/directory
    33d824b838 Move quota to daemon/internal/quota
    04f5276267 Move volume to daemon/volume
    fdd9ae3465 libnet/internal/resolvconf: use slices.Clone
    b1ce0c89f0 client: always send (empty) body on push
    50d2dafc7f libnet/portallocator: introduce OSAllocator
    14bd3451d8 client: ContainerExecAttach: update GoDoc links
    830e0d79f5 vendor: github.com/opencontainers/cgroups v0.0.4
    d66cf14a87 registry: replace pkg/homedir.GetConfigHome for os.UserConfigDir
    14d9be4978 daemon: Fix mounting same image multiple times with different destinations
    a28f031298 Fix libnetwork proto generation
    b1884b6bba Restore libnetwork/resolvconf
    3b5f7c2a29 Move internal/modprobe to daemon/libnetwork/internal/modprobe
    7f4713a364 Move internal/maputil to daemon/libnetwork/internal/maputil
    22ed8b1327 hack/make/test-docker-py: split test-exclusions to separate lines
    7a720df61f Move libnetwork to daemon/libnetwork
    f05652867d Move opts to daemon/pkg/opts
    fb2117987d Dockerfile: upgrade Delve to v1.25.0
    18438f3c13 Dockerfile: update compose to v2.38.2
    8c3e10a011 Dockerfile: update buildx to v0.25.0
    4dee288b51 Dockerfile: update cli to v28.3.2
    9bcb12aa48 daemon: ContainerExtractToDir: make AllowOverwriteDirWithFile opt-in
    fd8fec18cd integration/container: XFAIL flaky TestExecResize on Windows
    4a8d77c958 api/types/container: remove deprecated ContainerTopOKBody alias
    3d8d9c2bb3 api/types/container: remove deprecated ContainerUpdateOKBody alias
    f8a2550a22 pkg/system: deprecate IsAbs and move internal
    63bada41e5 pkg/system: deprecate EscapeArgs and move internal
    0fc1493654 pkg/system: remove EnableContainerdRuntime, ContainerdRuntimeSupported
    a327a9f341 integration-cli: fix flaky TestRestartStoppedContainer
    59d5743a43 testutil/daemon: Daemon.Stop() don't log when already stopped
    1c8b09ccf6 integration-cli: TestDockerNetworkHostModeUngracefulDaemonRestart start, not restart
    9e69fc567e testutil/daemon: remove string-matching for error
    cf41e9ac60 testutil/daemon: gofumpt
    d6c90dcb87 integration/container: fix flaky TestRemoveContainerWithVolume
    d30e61bff4 api/types/registry: add some tests for encoding/decoding authconfig
    c31368fffb Don't raise an error when stopping a stopped docker-proxy
    f6b3b257c8 implement test api images history integration test on dedicated file
    669163c416 remove test api images history integration cli test suite
    04dbcddd6a migrate test api images history integration cli test to integration test
    adad33b30e Fix expected results for nftablesdoc tests
    dde698a2e8 integration/container: add basic test for ContainerInspectWithRaw
    16ed75572f client: TestContainerInspectWithEmptyID test both inspect variants
    7f602d3b94 When switching between iptables/nftables, delete old rules
    a5e3f39770 integration/container: avoid ContainerInspectWithRaw with "size"
    88b67eb2fc integration/container: cleanup TestCreateWithCustomReadonlyPaths
    bd091c1a9d integration/container: cleanup TestCreateWithCustomMaskedPaths
    779052873d Add nftablesdoc
    ad579b8a1d daemon/container: remove deprecated IsValidStateString
    312eebde49 daemon/container: remove deprecated IsValidHealthString
    e9fb208e87 daemon/container: remove deprecated StateStatus, WaitCondition
    0d24798529 daemon/graphdriver: remove error or deprecated graphdriver-plugins
    7767525ccd daemon/graphdriver: remove deprecated GetDriver()
    1fe4a0a7ad daemon/graphdriver: remove redundant init()
    bd8f9c3c1b registry: remove deprecated APIEndpoint.AllowNondistributableArtifacts
    65d424e126 registry: remove deprecated APIEndpoint.Official
    7252c3c78d registry: remove deprecated APIEndpoint.TrimHostName
    11a18d3b00 api/types/registry: remove deprecated fields for non-distributable artifacts
    b3e513f80a registry: remove deprecated Service.ResolveRepository()
    5862b926f5 registry: remove deprecated SetCertsDir and unify CertsDir code
    924cd22d1d registry: remove deprecated HostCertsDir
    178416334f Run CI tests with nftables
    ea29dffaa5 daemon/server: remove compatibility with API v1.4 auth-config on push
    54e67d0054 daemon: AuthenticateToRegistry: remove statusMessage return
    e8396af484 nftabler: add per-port rules
    b677c1a671 Replace integration import test use of image type
    d90277372f libn/d/overlay: drop obsolete writeToStore comment
    30b9480107 Create legacy links during endpoint Join
    dd9e289b6e Don't pass sandbox options to ProgramExternalConnectivity
    4f7afb8ac9 Remove libnet's logic to track a driver's port mapping state
    89d3419093 libnetwork/d/overlay: fix logical race conditions
    843cd96725 libn/d/overlay: fix encryption race conditions
    a1d299749c libn/d/overlay: inline secMapWalk into only caller
    74713e1a7d libnetwork/d/overlay: un-embed mutexes
    a05080c26c libnet/d/bridge: split NATed and routed port mappings
    d229c1ba31 libnet/d/bridge: norm pb reqs before forming groups
    e2034267f6 nftabler: add per-endpoint rules
    b5bf89c315 libnet/d/bridge: pass SCTP sock to the proxy
    0a047e825c update to go1.24.5
    0ea28fede0 integration/networking: increase context timeout for attach
    c833bd598e vendor: github.com/ishidawataru/sctp v0.0.0-20250708014235-1989182a9425
    03a662b80e vendor: code.cloudfoundry.org/clock v1.37.0
    08bde5edfa libnetwork/networkdb: fix broadcast queue deadlocks
    aff444df86 libn/networkdb: make TestNetworkDBIslands not flaky
    1e1be54d3e libn/networkdb: prevent spurious rejoins in tests
    21d9109750 libn/networkdb: stop forging tombstone entries
    428dbe617a nftabler: add network level rules
    a55fede2d4 Pass context to nftables functions
    1c5d6d1ee3 Mark iptabler/nftabler golden results as generated
    ee6a6b061f daemon/pkg/plugin: remove dependency on legacy distribution package
    09689298e3 distribution: fix detection of v1 images and remove libtrust dependency
    ac9d5a6068 integration-cli: TestPullFailsWithAlteredLayer: use OCI manifest
    fd47ccef7b integration-cli: TestPullFailsWithAlteredManifest: use OCI manifest
    4e818970e2 integration-cli: TestPullManifestList: use OCI media-types
    f6ef56a0bc integration-cli: TestPullManifestList: rewrite using OCI types
    51d6687754 api: swagger: Tweak type of GwPriority to integer
    bfc0c7cff5 docs: api: Tweak type of GwPriority to integer
    557b5d60d3 layer: remove LogReleaseMetadata utility
    7d18f65eb2 distribution/xfer: improve test reporting
    291872e086 remove type conversions
    ade244f97d deprecate layer.CreateChainID for OCI identity
    10e9ab66f9 image/tarexport: inline validateManifest utility
    471f173170 image/tarexport: improve error messages for invalid archives
    033750cf80 image/tarexport: remove suport for loading v0/v1 images
    ebfafa1561 contrib: add Wireshark plugins for NetworkDB
    aae26b80fe Remove client buildkit dep
    e93e15afb0 Replace use of env test util with standard library call
    4754c15e2b Dockerfile: bump gotest.tools/gotestsum v1.12.3 (for go1.25)
    fa4f3c979f gha: remove GO_VERSION build-arg from builds
    136c0e591b image: RootFS.Clone: simplify
    aea776332b pkg/stack: suppress some unhandled errors
    e32d26cb59 libnet/diag: remove /stackdump endpoint
    a881e9e057 Remember port binding state in the bridge driver
    7ea50c14d6 Remote network driver: remember gateway state
    054738bce3 Pass gateway endpoint ids to ProgramExternalConnectivity
    07e5be0a18 image: remove special handling for legacy "layers+base" windows images
    5efd2286da vendor: update buildkit to v0.23.2
    e1b70074ec distribution/xfer: LayerDownloadManager.Download: remove initialRootFS arg
    173436c702 distribution/xfer: rename var that shadowed type
    0683bc6355 fix some inconsistency in import aliases
    d207ee97ff daemon/listeners: extract utility for DACL, and improve docs
    18dc570918 remove project dev "reports"
    93bbd21d82 rename codecov.yml to .codecov.yml
    ce3c8785dc restartmanager: move to daemon/internal
    256f96ef59 remove VENDORING.md
    717188201a contrib: remove mkimage-xxx scripts
    3f8630cb84 internal/usergroup: move to daemon/internal
    cbe6e31487 internal/usergroup: move windows consts to builder/dockerfile
    8dbe0f45a9 integration-cli: debug TestPushToCentralRegistryUnauthorized
    5fe253cd79 builder/dockerfile: BuildFromConfig: combine loops
    a30b63eafc integration-cli: remove uses of deprecated dockerCmdWithResult utility
    90f9ce14f1 Move libcontainerd to daemon/internal/libcontainerd
    3ee8c1e3a9 Move libcontainerd/types to daemon/internal/libcontainerd/types
    841a369b8f Move libcontainerd/supervisor to daemon/internal/libcontainerd/supervisor
    fe959261d3 Move libcontainerd/shimopts to daemon/internal/libcontainerd/shimopts
    4e8bd050bf Move libcontainerd/remote to daemon/internal/libcontainerd/remote
    dd1656e6bc Move libcontainerd/queue to daemon/internal/libcontainerd/queue
    6835f367e5 Move libcontainerd/local to daemon/internal/libcontainerd/local
    5419eb1efc Move container to daemon/container
    a02ba3c7df Move container/stream to daemon/internal/stream
    9d9cb00d50 Move container/stream/bytespipe to daemon/internal/stream/bytespipe
    3581b982f7 Move plugin to daemon/pkg/plugin
    1c700c876f Move plugin/v2 to daemon/pkg/plugin/v2
    f5ceed8719 Move plugin/executor/containerd to daemon/internal/plugin/executor/containerd
    0b2582dc8f Move internal/metrics to daemon/internal/metrics
    87238882e0 Move api/server to daemon/server
    3a6e3f85c6 Move api/server/backend/build to daemon/build
    79f802d46a Move api/server/httputils to daemon/server/httputils
    c7a87f0dee Move api/server/httpstatus to daemon/server/httpstatus
    d64bd2cceb Move api/server/middleware to daemon/server/middleware
    72a020fcd8 Move api/server/router to daemon/server/router
    f293628f55 Move api/server/router/volume to daemon/server/router/volume
    15c8007064 Move api/server/router/system to daemon/server/router/system
    45172bbf23 Move api/server/router/swarm to daemon/server/router/swarm
    f6ba5a5241 Move api/server/router/session to daemon/server/router/session
    3eb5fe0277 Move api/server/router/plugin to daemon/server/router/plugin
    baa58ddc6a Move api/server/router/network to daemon/server/router/network
    0cbb4ac8e6 Move api/server/router/image to daemon/server/router/image
    a063389af7 Move api/server/router/grpc to daemon/server/router/grpc
    9ff489863c Move api/server/router/distribution to daemon/server/router/distribution
    ced7798ed8 Move api/server/router/debug to daemon/server/router/debug
    3a9db5fbd6 Move api/server/router/container to daemon/server/router/container
    fcf3ff1b2f client: remove getDockerOS utility in favor of "Ostype" header
    d6136b660f Move api/server/router/checkpoint to daemon/server/router/checkpoint
    31b6886eb1 Move api/server/router/build to daemon/server/router/build
    1c0d381f4e client: client.tryImagePush: accept registry.RequestAuthConfig
    ca0afe91b9 client: client.tryImageCreate: accept registry.RequestAuthConfig
    79b4e18883 client: add staticAuth utility
    871543a8c5 client: Client.ServiceUpdate: don't manually construct header value
    a824db247f Add progress aux emitter to build backend
    374fa24a53 Add multierror function to api network
    0964fa01ba Remove dependency on testutil from client
    58404b0c28 Remove dependency on httputil for client hijack test
    e7289e7e02 hack: check windows resources are set in the binary
    44623fb856 cmd: use dockerfile to generate win event messages
    0ea20c9f72 cmd: fix winresources and move them out cli package
    6b8afec95b fix redefines-builtin-id from revive
    90ab64cbda fix increment-decrement from revive
    381d9d0723 fix use-errors-new from revive
    f0136d1dba fix superfluous-else from revive
    369c8f828e fix var-declaration from revive
    d72f219a11 gha/bin-image: update tags comment
    b40fe5cb8b pluginrpc-gen: align generator with generated
    f8fcc20c3b Update maintainer info for austinvazquez
    38b98bcf68 gha/bin-image: add major and minor version image tags
    057e35dd65 libnetwork/d/overlay: ref-count encryption params
    1c2b744ca2 libnetwork/d/overlay: properly model peer db
    59437f56f9 libnetwork/d/overlay: refactor peer db impl
    33139da522 Split part of dockerd main to command under daemon
    98047c5190 Move cmd/dockerd/trap to daemon/command/trap
    ea11b5f3fe Move cmd/dockerd/debug to daemon/command/debug
    53475e1adf integration/container: TestCreateByImageID: minor improvements
    fcf666f9b0 dockerfile: update govulncheck to v1.1.4
    8c067c5223 client: Client.addHeaders: remove special handling for api &lt; 1.25
    ef50844a0b docs: cut api docs for v1.51
    5a02e7f4e3 vendor: update buildkit to v0.23.1
    b466c35da1 Update containerd to v2.1.3
    7a12bbe5d3 libn/d/overlay: delete FDB entry from AF_BRIDGE
    1d8545d60c daemon/config: Validate: add missing validation for registry mirrors
    307c18598d registry: ValidateMirror: improve validation for missing schemes
    a90da2edc3 vendor: github.com/opencontainers/cgroups v0.0.3
    a7f01d238e libnetwork: fix flaky Swarm service DNS
    062082ec9b daemon: containerStop: fix ordering of "stop" and "die" events
    bf002e51a0 Split [Program|Revoke]ExternalConnectivity out of libnet driverapi
    4ccbca1efe Add TestRoutedNonGateway
    d85513e1a3 daemon: LogContainerEventWithAttributes: minor optimisation
    ec185e57cf Test Nftabler params
    e43968d7ed vendor: github.com/moby/buildkit v0.23.0
    0c182d4d57 api/types/container: deprecate ExecOptions.Detach
    126f99d776 Add a way to undo nftables.Enable(), for unit tests
    1289519b03 vendor: update buildkit to v0.13.0-rc2
    c3ac979ecf vendor: github.com/moby/swarmkit/v2 v2.0.0
    4891396da6 docs(client/ContainerExecAttach): add a mention to stdcopy.StdCopy
    b7ef527bdc pkg/idtools: deprecate IdentityMapping, Identity.Chown
    66e9cd97f2 remove deprecated pkg/archive, pkg/chrootarchive
    d06c22f27d remove deprecated pkg/reexec
    98015c21ec remove deprecated pkg/atomicwriter
    cf91441a1b pkg/ioutils: remove deprecated atomicwriter functions
    1f0e9077e4 remove deprecated pkg/parsers
    c66abe486b nftabler: add mirrored WSL2 loopback0 workaround
    d31956b2f7 Add an outline nftabler
    04618dfc0b remove deprecated pkg/platform
    f1e93a1770 pkg/system: remove deprecated MkdirAll
    ce31bf3f0b gha: dco: bump alpine to 3.22
    1ad9599da7 Drop DOCKER-ISOLATION rules
    2d60b8eacd vendor: github.com/moby/swarmkit/v2 v2.0.0-20250613170222-a45be3cac15c
    6ec6e0991a libnetwork/networkdb: prioritize local broadcasts
    e9a7154909 libnetwork/networkdb: improve TestCRUDTableEntries
    dbb0d88109 libn/networkdb: use distinct type for own networks
    51f31826ee libnetwork/networkdb: don't clear queue on rejoin
    30b27ab6ea libnetwork/networkdb: drop id field from network
    9316396db0 gha: run windows 2025 on PRs, 2022 scheduled
    6f484d0d4c gha: update to windows 2022 / 2025
    0a30b98447 gha: lower timeouts on "build" and "merge" steps
    accbfde61e client: use go-winio.DialPipe directly
    df6b405796 libnetwork/d/overlay: drop initEncryption function
    713f887698 libnetwork/d/overlay: drop checkEncryption function
    cb4e7b2f03 libnetwork/d/overlay: make setupEncryption a method
    0d893252ac libnetwork/d/overlay: checkEncryption: drop isLocal param
    4b1c1236b9 libnetwork/d/overlay: peerdb: drop isLocal param
    48e0b24ff7 libnetwork/d/overlay: elide vtep for local peers
    a9e2d6d06e libnetwork/d/overlay: filter local peers explicitly

Signed-off-by: Bruce Ashfield &lt;bruce.ashfield@gmail.com&gt;
</content>
</entry>
<entry>
<title>docker: make ca-certificates a packageconfig</title>
<updated>2025-09-19T02:17:13+00:00</updated>
<author>
<name>Patrick Vogelaar</name>
<email>patrick.vogelaar@belden.com</email>
</author>
<published>2025-08-24T12:14:14+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-virtualization.git/commit/?id=39d095241e3a768c2d0f6292513597d5964d21d5'/>
<id>urn:sha1:39d095241e3a768c2d0f6292513597d5964d21d5</id>
<content type='text'>
Moving ca-certificates into a packageconfig allows using docker without
installing all the certificates.

Signed-off-by: Patrick Vogelaar &lt;patrick.vogelaar@belden.com&gt;
Signed-off-by: Bruce Ashfield &lt;bruce.ashfield@gmail.com&gt;
</content>
</entry>
<entry>
<title>docker: update to v28.3.3</title>
<updated>2025-08-21T15:40:45+00:00</updated>
<author>
<name>Bruce Ashfield</name>
<email>bruce.ashfield@gmail.com</email>
</author>
<published>2025-08-21T15:39:52+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-virtualization.git/commit/?id=1eb9f8ec48166a82e68d7c67fb1164afd4fdd16e'/>
<id>urn:sha1:1eb9f8ec48166a82e68d7c67fb1164afd4fdd16e</id>
<content type='text'>
Bumping moby to version v28.3.3-53-g80947b5724, which comprises the following commits:

    553c3b8c9f vendor: go.etcd.io/bbolt v1.4.2
    7d7edf46a6 go.mod: github.com/containerd/containerd/v2 v2.1.4
    993eae423e go.mod: dario.cat/mergo v1.0.2
    2c93d2f909 go.mod: github.com/docker/go-events v0.0.0-20250114142523-c867878c5e32
    6305a44e58 go.mod: github.com/fernet/fernet-go v0.0.0-20240119011108-303da6aec611
    03a4cd8d9a vendor: code.cloudfoundry.org/clock v1.37.0
    687cd8ebae integration/system: remove TestEventsBackwardsCompatible
    95c3340e75 integration/system: add TestEventsNonBlocking
    e364b6c466 ci: add golangci-lint configuration to ignore deprecated api type usage in daemon
    9396c31e13 api/types: deprecate disk usage types for build cache, container, images, and volumes
    bcbccc6eec pkg/jsonmessage: JSONMessage: deprecate From, Time, and TimeNano fields
    5a0d62cab0 Add multierror function to api network
    8a89fe5c19 daemon/router/image: initialize default authConfig
    e53cd07fcc client: remove getDockerOS utility in favor of "Ostype" header
    cf0958f89b docs: api: Tweak type of ForceUpdate to uin64
    fd89baef7e api: swagger: Tweak type of ForceUpdate to uint64
    3fc876cd7b update to go1.24.6
    85aaa37c08 Dockerfile: update containerd binary to v1.7.28
    16c7a35584 Dockerfile: update runc binary to v1.3.0
    61443a72c2 integration/container: XFAIL flaky TestExecResize on Windows
    492b3c94cb integration-cli: fix flaky TestRestartStoppedContainer
    d5b47b8fdf integration/container: fix flaky TestRemoveContainerWithVolume
    30663d3e86 Dockerfile: bump gotest.tools/gotestsum v1.12.3 (for go1.25)
    3a15e3ed23 download-frozen-image-v2: Use curl -L
    ad243becbe download-frozen-image-v2: handle 307 responses without decimal
    648c74d243 Add separate const for daemon httputils to avoid jsonmessage import
    eadee3e5b9 [28.x] api/types/filters: reimplement ToParamWithVersion
    60e84e7350 api/types/system: move DiskUsage, DiskUsageOptions to api/types/backend
    7d6a75b342 runconfig: update fixtures for TestDecodeContainerConfig
    596404f3aa integration-cli: remove tests for pre-docker 1.7 clients
    9fd8eaa95d Delete TestRunDNSOptionsBasedOnHostResolvConf
    b2f03f45ea profiles/apparmor, seccomp: migrate to separate module
    3e9ff78b94 bridge: Reapply endpoint iptables rules on firewalld reload
    29ed80aa86 bridge: Trigger firewalld reload during bridge integration tests
    e4b1f89996 daemon/server: remove compatibility with API v1.4 auth-config on push
    0c9e14dcce hack/buildkit-ref: temporarily bump BuildKit to head of v0.23 branch
    4205776b85 client: always send (empty) body on push
    38c0abffce update to go1.24.5
    bfade89ec2 integration/networking: increase context timeout for attach
    a818cfd87b gha: run windows 2025 on PRs, 2022 scheduled
    653777a522 gha: update to windows 2022 / 2025
    1ad3df4768 api: swagger: Tweak type of GwPriority to integer
    6323db8e78 docs: api: Tweak type of GwPriority to integer
    a3c8f7fa8c dockerfile: update govulncheck to v1.1.4
    dfbba63a34 gha: remove GO_VERSION build-arg from builds
    e17e96e3c5 vendor: update buildkit to v0.23.2
    a2af8bdebd gha/bin-image: add major and minor version image tags

docker/cli: update to v28.3.3

    873609d790 cli/command/*: remove deprecated cobra command constructors
    570a17b3bc internal/commands: RegisterLegacy: remove redundant copy
    4405c0bd50 internal/commands: remove mutexes / synchronisation
    56cab16779 Register CLI commands implicitly
    e650803f09 opts: deprecate ParseEnvFile
    bd8e3e4440 Unexport trust commands
    c6b7268932 Unexport plugin commands
    2ce94e4fff internal/registryclient: repositoryEndpoint: memoize repoName
    bf39340294 Unexport swarm commands
    d4588c711c Unexport registry commands
    630fe430ff Unexport stack commands
    3b0edc794c Unexport context command
    9961e39d40 Unexport volume commands
    88178eda32 Unexport service commands
    e00762ed7d Unexport secret commands
    02fda07211 Unexport manifest command
    ab3fcf9f9b Unexport node commands
    78a8856c14 Unexport network commands
    4286883b95 cli/command: inline resolveAuthConfigFromImage
    2d3b0b33b4 cli/command: fix godoc links
    9b9d103b29 cli/flags: remove special quote handling for `--tlsXXX` flags
    cfb8cb91f2 Unexport system commands
    1d571d178d docs: deprecated: fix formatting of deprecated/removed in
    13010ba673 cli/registry/client: deprecate and move internal
    5c76f7f2d8 docs/deprecated: legacy links env vars
    e66a1456d3 Unexport image commands
    ae1727c41e cli/command: TestRetrieveAuthTokenFromImage: don't decode authconfig
    38595fecb6 Unexport container commands
    cce29da061 Unexport config command
    3265cead1d Unexport checkpoint command
    1b9d0762a5 Unexport the builder command and bake stub command
    72f76f2720 cli-plugins/manager: deprecate annotation metadata aliases
    f9777d2517 cli: remove deprecated VisitAll, DisableFlagsInUseLine utilities
    5934553198 opts: remove deprecated NewNamedListOptsRef, NewNamedMapOpts
    a056cc6164 opts: remove deprecated ListOpts.GetAll
    15f3e910d1 opts: remove deprecated ValidateHost
    0c07d81a03 opts: remove deprecated QuotedString
    ee05a71513 Deprecate special handling for quoted values for TLS flags
    6f0c66c152 opts: deprecate NewNamedListOptsRef, NewNamedMapOpts
    4ead8784d0 Add command registration helpers
    69854c4e08 cli/command/container: TestRunPullTermination: rewrite with streamformatter
    f14eeeb361 cli/flags: add "hostVar" to handle --host / -H as a single string
    5ee2906e78 cli/flags: use a regular StringArray for the `--host` / `-H` flag
    d0ac0acff0 opts: deprecate ValidateHost utility
    187a942a88 opts: deprecate QuotedString
    5a38118956 cmd/docker: fix some minor linting issues
    6bd8a4b2b5 cli: deprecate VisitAll, DisableFlagsInUseLine utilities
    5a99022556 cli: remove HasCompletionArg utility
    bf13010df8 docs: fix output example for docker system prune
    4cd9833d7c gha/validate-pr: Replace `continue-on-error`
    1456b53e4e .github/workflows: Add kind label validation to PR workflow
    6d9b06d227 gha/validate-pr: Run on synchronize
    eb5b03a8a3 cli/command/container: copyToContainer: improve error-handling
    c5ea9079af cli/command/container: copyToContainer rename error-return
    f2af519f2e build(deps): bump actions/checkout from 4 to 5
    27a7947535 cli/command/image/build/internal/git: use stdlib errors
    53183396d7 internal/volumespec: use stdlib errors
    70f1147394 cli/command/trust: use stdlib errors
    a8f11a2fa2 cli/command/formatter: use stdlib errors
    c612e141b5 cli/command/registry: use stdlib errors
    9b7ee0e201 cli/config: use stdlib errors
    3b677449d8 cli/context: use stdlib errors
    d38317c781 cli/compose: use stdlib errors
    2dd462cc36 cli/command/idresolver: use stdlib errors
    4c89455378 cli/registry/client: use stdlib errors
    adbe04b5fc cli/manifest, cli/command/manifest: use stdlib errors
    097cc9ca64 cli/trust: use stdlib errors
    e069ded4c3 cli: reduce uses of pkg/errors for stdlib errors
    3529651fa7 vendor: github.com/docker/go-connections v0.6.0
    3035b6685b e2d skip flaky test: TestPromptExitCode/plugin_upgrade, plugin_install
    6769f62746 update to go1.24.6
    5052a39915 cli/command/completion: remove deprecated ValidArgsFn
    7026e68a71 cli/command: remove AddPlatformFlag utility
    c0fbbe05ca cli/command: remove AddTrustVerificationFlags
    8c22927978 cli/command: remove AddTrustSigningFlags
    3f5b1bdd32 cli/command/plugin: remove DCT
    d3c23a223c e2e/global: TestPromptExitCode: group plugin preparation steps
    081add2fc5 e2e/testutils: SetupPlugin: return path of directory
    8972e53ad0 cli/command: remove prompt utilities that were for internal use
    a93ed48d06 vendor: dario.cat/mergo v1.0.2
    abfe4d4629 remove deprecated `bind-nonrecursive` option for `--mount`
    f9431e3b35 vendor: moby/moby/api v1.52.0-alpha.1, moby/moby/client v0.1.0-alpha.0
    22cc0e90ae cli/command: remove deprecated ConfigureAuth utility
    de54347518 cli/command: remove deprecated CopyToFile utility
    2abcbf842f cli/connhelper: remove dependency on pkg/process
    513ceeec0a cli-plugins/manager: remove deprecated ResourceAttributesEnvvar
    5876b2941c cli-plugins/manager: deprecate metadata aliases
    50963accec cli-plugins/manager: wrapAsPluginError: don't special-case nil
    d789bac04a cli-plugins/manager: pluginError: remove Causer interface
    71460215d3 cli-plugins/manager: deprecate "IsNotFound"
    1cc698c68f cli-plugins/manager: un-export "NewPluginError"
    549d39a89f cli-plugins/manager: fix Plugin marshaling with regular errors
    54367b3283 cli-plugins/manager: un-export "Candidate" interface
    057f3128b6 cli-plugins/manager: reformat TestValidateCandidate table
    dfbac70efa remove some remnants from CLI "experimental" config option
    3b6a556533 cli/command: remove exported "RunPrune" functions
    bf8cb43025 system prune: delegate version check
    a888c4091c system prune: delegate confirmation message and validation
    02d578b637 system prune: use register function for prune functions
    21e8bbc8a2 internal/registry: remove RepositoryInfo, add NewIndexInfo
    066710ba7b opts/swarmopts: minor cleanup and refactor
    b8df4abeb5 bump version to v29.0.0-dev
    3f0ccd1b71 dockerd.md: Add --firewall-backend
    6176a7686e dockerd.md: add --bridge-accept-fwmark
    f937e62c89 replace direct uses of github.com/docker/go-connections/nat types
    bf16dd1251 vendor: docker/docker, moby/moby/api and moby/moby/client 4faedf2bec36
    149503a32c migrate e2e container rename test
    5c3577ff9f cli/command/service: credentialSpecOpt: use strings.Cut
    b6d7ac34be vendor: docker/docker, moby/moby/api and moby/moby/client 2574c2b2e917
    83e507377a vendor: docker/docker, moby/moby/api and moby/moby/client 25e2b4d48551
    86b5b528a6 internal/registry: ParseRepositoryInfo: remove unused error return
    89d8c8a2a7 remove aliases for containerd/errdefs, disallow docker/errdefs
    d63cae6f1c cli/command/formatter: use alias/wrapper for TruncateID
    4bd6b6897f vendor: update docker, api, client to master
    7ab3e7e774 templates: deprecate NewParse()
    c6f935eba5 cli/command/plugin: fix linting issues, and assorted cleanups
    ef7fd8bb67 refactor(cli/compose/loader): extract ParseVolume() to its own package
    9257cc7f68 image/tree: Unmark as experimental, warn when redirected
    f214f860b6 image/tree: Remove extra newline after legend
    f907c7a4b0 internal/registry: fix linting issues (revive)
    cd277a5815 cli/command/system: remove use of Mirrors field in test
    c297770d2d internal/registry: remove pkg/errors
    219cfc8b7d internal/registry: define local serviceConfig
    2607ba8062 internal/registry: remove ValidateIndexName
    5322affc9f internal/registry: remove duplicate endpoint methods
    dc41365b56 internal/registry: remove NewStaticCredentialStore
    dad2e67860 internal/registry: remove PingResponseError
    7cf245d2f7 internal/registry: Service.Auth remove unused statusmessage return
    e0b351b3d9 internal/registry: remove code related to mirrors
    7716219e17 internal/registry: remove dead code
    f6b90bc253 add internal fork of docker/docker/registry
    20181d4363 vendor: github.com/docker/docker master
    fa169b6933 vendor: docker/docker, moby/api, and moby/client master
    a87bde0068 cli/registry/client: remove deprecated RepoNameForReference
    323ef1997f vendor: docker/docker, moby/api, moby/client to latest
    e504faf6da cli/command/registry: remove uses of registry.ParseSearchIndexInfo
    644dc16b16 vendor: github.com/docker/docker master (v29.0-dev)
    7609dde8d0 build: remove DCT support for classic builder
    e2cab2c64c cli/command/image: remove use of api.NoBaseImageSpecifier
    64f33cd463 TestCloneArgsSmartHttp: fix unhandled error
    a3bea24086 Include FirewallBackend in docker info output
    b05aa464a6 Dockerfile: install git-daemon for use in tests
    e34616574f fix linting issues
    260f1dbebb cli/command/image: move build-context detection to build
    e95d133612 remove some redundant import aliases
    3dec3879c8 opts: minor cleanup in tests
    fdc90caeee cli/command/container: deprecate DiffFormatWrite
    0db7b9f774 cli/command/container: newDiffContext: use struct-literal
    239b727834 cli/command/container: DiffFormatWrite: remove intermediate var
    907507e22a cli/command/container: deprecate NewDiffFormat
    29263e865b cli/command: remove usages of RegistryAuthenticationPrivilegedFunc
    ea4c161067 Dockerfile: update to alpine 3.22
    3d985799d4 cli/command: remove some redundant import-aliases
    8b6436ecee Dockerfile: document ALPINE_VERSION build-arg
    2b56b66b10 cli/command: remove interactive login prompt from docker push/pull
    0f2b709c7c cli/command/container: diff: remove redundant validation and cleanup
    53d02ece89 remove use of github.com/docker/docker/pkg/longpath
    3600ebca76 remove uses of github.com/docker/docker/pkg/ioutils ReadCloserWrapper
    9b047a501f remove uses of pkg/stringid.GenerateRandomID()
    e0f4bc699c cli/command/formatter: add TrunateID utility
    1264a59779 Dockerfile: bump gotest.tools/gotestsum v1.12.3 (for go1.25)
    e6b8cc1c7d Dockerfile: update buildx to v0.25.0
    50fa436c21 Dockerfile: update compose to v2.38.2
    0be687acc0 cli/command/container: don't set CopyToContainerOptions.AllowOverwriteDirWithFile
    8eac03d5fa docs: fix CDI device configuration anchor
    0c5e258f8a e2e/global: TestPromptExitCode: check for trailing newline
    9bcc88611f update to go1.24.5
    ccd5bd8d57 registry: warn of DOCKER_AUTH_CONFIG usage in login and logout
    dec07e6fdf tui/note: add warning note type
    7e040d91ef docs: cdi is not experimental anymore
    76524e7d0e vendor: github.com/docker/docker v28.3.1
    3262107821 cli/config: export const dockerEnvConfig
    4ea6fbf538 cli/debug: fix OTELErrorHandler logging messages if there's no error
    94f097da28 rename codecov.yml to .codecov.yml
    e7e238eb4b cli/command/container: remove redundant uses of strslice.StrSlice
    2ba7cb8b44 mount /var/run/docker.sock for --use-api-socket
    52e1e4fb21 vendor: github.com/docker/docker v28.3.0
    88d1133224 cli/connhelper: quote ssh arguments to prevent shell injection
    82eda48066 cli/connhelper/internal/syntax: fix linting issues
    52d2a9b5ae cli/connhelper/internal/syntax: remove unused code from fork
    64a9a6d0c8 cli/connhelper: add fork of mvdan.cc/sh/v3/syntax v3.10.0
    0ba4362d69 Update markdown docs to indicate multi-platform support in image load/save.
    8993f54fc3 Add support for multiple platforms in docker image save
    38b99adc10 Add support for multiple platforms in docker image load.
    342f8bca25 builder: remove // import comments
    09a3c93f96 fix(QF1001): Apply De Morgan’s law
    a10a1e619b builder/remotecontext: remove unused named and "naked" returns
    75f791d904 builder: use lazyregexp to compile regexes on first use
    8d3c0fb6dc tests: migrate to assert.ErrorContains when possible
    45f09a1504 builder/remotecontext/git: remove redundant capturing of loop vars (copyloopvar)
    52c62bd13b Fix isGitURL regular expression
    8f865184a6 builder/remotecontext: format code with gofumpt
    6291744fa4 builder/remotecontext/git: use strings.Cut()
    60b326f814 builder/remotecontext/gitutils: switch back to os/exec
    66713384c3 builder/remotecontext/git: allow building on go1.18
    5c21ec520e builder: add missing doc comment
    212213e81e builder: fix running git commands on Windows
    bcd6c45731 builder: make git config isolation opt-in
    876fc1dac4 builder: isolate git from local system
    3bfb30acd7 builder: explicitly set CWD for all git commands
    3f4cc89f64 builder: modernize TestCheckoutGit
    a12090d787 gofmt GoDoc comments with go1.19
    26a11366a7 builder/remotecontext/urlutil: simplify and improve documentation
    9e39630a05 pkg/urlutil: deprecate, and move to builder/remotecontext/urlutil
    6d2a901118 refactor: move from io/ioutil to io and os package
    389ada7188 Use golang.org/x/sys/execabs
    a4c8c72411 replace pkg/symlink with github.com/moby/sys/symlink
    5896d383ca bump gotest.tools v3.0.1 for compatibility with Go 1.14
    ea850377cd builder/remotecontext: allow ssh:// urls for remote context
    2d0d4ce4af builder/remotecontext: use net/url instead of urlutil
    a0d9b0cf0d TestParseRemoteURL: use subtests
    70aef9f502 gosec: add ignore comments for reported issues that can be ignored
    04e2a24a9e gitutils: add validation for ref
    71672ece9c Update tests to use gotest.tools 👼
    db857b5d9c Post migration assertion fixes
    242f176825 Automated migration using
    6ea4877cff Add canonical import comment
    7bc503344a gitutils: remove checkout directory on error
    e2cc22d076 gitutils: fix checking out submodules
    e9831d75e2 Fix shallow git clone in docker-build
    9450481b7e Move IsGitTransport() to gitutils
    a6cc6cd878 Fix handling of remote "git@" notation
    e907d54fe6 Move pkg/gitutils to remotecontext/git

Signed-off-by: Bruce Ashfield &lt;bruce.ashfield@gmail.com&gt;
</content>
</entry>
<entry>
<title>Docker: add more required kernel modules as RRECOMMENDS:${PN}</title>
<updated>2025-07-31T17:44:59+00:00</updated>
<author>
<name>Koen Kooi</name>
<email>koen.kooi@oss.qualcomm.com</email>
</author>
<published>2025-07-02T07:03:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-virtualization.git/commit/?id=f707bbe323261f41f69267708d6751c1bb0edd0b'/>
<id>urn:sha1:f707bbe323261f41f69267708d6751c1bb0edd0b</id>
<content type='text'>
With a very minimal image recipe that just pulls in docker, the daemon
won't start due to missing modules, so add the missing ones.

The list of new modules was created by diffing the output of `lsmod`
before installing all kernel-modules and the output  after launching
docker with all modules installed.

Signed-off-by: Koen Kooi &lt;koen.kooi@oss.qualcomm.com&gt;
Signed-off-by: Bruce Ashfield &lt;bruce.ashfield@gmail.com&gt;
</content>
</entry>
<entry>
<title>docker: update to v28.3.0</title>
<updated>2025-07-07T15:42:27+00:00</updated>
<author>
<name>Bruce Ashfield</name>
<email>bruce.ashfield@gmail.com</email>
</author>
<published>2025-06-26T18:39:37+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-virtualization.git/commit/?id=e1fa9062b6dff772b2da3060c562434a543bfc52'/>
<id>urn:sha1:e1fa9062b6dff772b2da3060c562434a543bfc52</id>
<content type='text'>
Bumping moby to version v28.3.0-2-ge0183475e0, which comprises the following commits:

    a2af8bdebd gha/bin-image: add major and minor version image tags
    b2a9318a1e docs: cut api docs for v1.51
    8c713c1af4 gha: lower timeouts on "build" and "merge" steps
    8e7ea470cf vendor: update buildkit to v0.23.1
    222baf4ccb vendor: github.com/moby/buildkit v0.23.0
    0e0ca09ddc daemon: containerStop: fix ordering of "stop" and "die" events
    e62b0e2234 vendor: github.com/opencontainers/cgroups v0.0.3
    06ab9cd1ed daemon/config: Validate: add missing validation for registry mirrors
    97aa4e8550 registry: ValidateMirror: improve validation for missing schemes
    e18a9c95b8 Update containerd to v2.1.3
    09fef2b26e api/types/container: deprecate ExecOptions.Detach
    44c8cd2e8f vendor: update buildkit to v0.13.0-rc2
    78b6204f9e vendor: github.com/moby/swarmkit/v2 v2.0.0
    cf98237186 vendor: github.com/moby/swarmkit/v2 v2.0.0-20250613170222-a45be3cac15c
    fd96b01b0e pkg/idtools: deprecate IdentityMapping, Identity.Chown
    987b8a88a6 c8d/push: Extract shared push logic
    d9e7b86de4 c8d/push: Fix fallback single-manifest push not creating a tag
    53d12c96f8 vendor: github.com/containerd/containerd/v2 v2.1.2
    aac0260d21 Fix flaky test TestDaemonRestartRestoreBridgeNetwork
    cfcbfabb0f api/image/list: Return `Containers` count
    6d737371b8 fix comparison rule from errorlint
    941d09e265 Handle error message from token server with containerd backend
    e4e7fcf668 vendor: github.com/moby/buildkit v0.23.0-rc1
    d3d20b9195 integration-cli: TestCopyFromContainerPathIsNotDir: adjust for win 2025
    cf86f3a082 vendor: github.com/containerd/nydus-snapshotter v0.15.2
    9a85f50aaa vendor: github.com/pelletier/go-toml/v2 v2.2.4
    1764909076 vendor: github.com/fsnotify/fsnotify v1.9.0
    102adcab57 vendor: github.com/containerd/console v1.0.5
    5230692cad vendor: cloud.google.com/go/longrunning v0.5.5
    5fb6604642 vendor: google.golang.org/api v0.160.0
    d2954c4e05 vendor: otel v1.35.0, otel/contrib v0.60.0, grpc v1.72.2
    05f892190c vendor: github.com/prometheus/client_golang v1.22.0
    952cddd05b vendor: google.golang.org/protobuf v1.36.6
    ccf5f8036c vendor: golang.org/x/sys v0.33.0
    c81e03bc0b vendor: golang.org/x/sync v0.14.0
    05e8b1701c daemon/containerd remove leftover schema1 compatibility code
    2ff281e33a daemon/containerd: update link to containerd code
    d54f713d95 daemon/containerd: rename var that shadowed type
    8e6cd44ce4 daemon: ensuring state of stopped container is visible to other queries when container is stopped and before API response is sent (fix for https://github.com/moby/moby/issues/50133).
    7acb079403 Revert "libn/networkdb: don't exceed broadcast size limit"
    0df31cf585 Revert "libn/networkdb: fix data race in GetTableByNetwork"
    83b2fc245d Revert "Fix possible overlapping IPs when ingressNA == nil"
    e079583ab4 Revert "libnetwork/networkdb: use correct index in GetTableByNetwork"
    cfd5e5e4d4 Revert "libn/networkdb: b'cast watch events from local POV"
    576cf73add Revert "libn/networkdb: record tombstones for all deletes"
    2297ae3e64 Revert "libn/networkdb: Watch() without race conditions"
    cc60ec8d3c Revert "libn/networkdb: stop table events from racing network leaves"
    b5b349dbd6 Revert "libn/osl: drop unused AddNeighbor force parameter"
    35916f0869 Revert "libn/osl: refactor func (*Namespace) AddNeighbor"
    3eb59ba5a2 Revert "libnetwork/osl: remove superfluous locks in Namespace"
    5d6ae34753 Revert "libnetwork/osl: stop tracking neighbor entries"
    ea818a7f6f Revert "libnetwork/internal/setmatrix: make keys generic"
    78ccc20545 Revert "libn/d/overlay: use netip types more"
    23c56099ee daemon/logger/loggerutils: use defer to fix gocritic "badlock" linter
    0069360e3b volume/mounts: windowsDetectMountType: rewrite using switch
    027355d7b3 container/stream: TestRaceUnbuffered: put unused testing.T to use
    2bbf5f5a39 daemon/containerd: ImageService.resolveImage: cleanup resolve by name:tag
    2e25775c83 libnetwork: Replace deprecated usages
    3dd8f03f25 vendor: go.etcd.io/bbolt v1.4.0
    55f47f9e34 Windows: don't try to load "mirrored" network plugin
    20b6075380 fix badCall from go-critic
    10c4715a62 openrc: allow customizing containerd service name
    c466ae0f71 fix badLock from go-critic
    19f5ac3c81 fix initClause from go-critic
    aa632664b6 fix mapKey from go-critic
    5ad4e4edf7 fix deprecatedComment from go-critic
    b8a4f6534f fix stringsCompare and stringConcatSimplify from go-critic
    a62de57aa1 fix sprintfQuotedString from go-critic
    bc9ec5fc02 fix emptyStringTest from go-critic
    469afa5f8f fix httpNoBody from go-critic
    8f7faa01d1 fix boolExprSimplify from go-critic
    e5be7b54b1 fix yodaStyleExpr from go-critic
    64075850fc fix go-critic linter
    793dd8385a Only "prune" Windows networks created by Docker
    071d27cd3d Add contributor guidelines for where to put source code in packages
    1603ad636e update to go1.24.4
    9b5d8cd186 fix thelper linter
    ea581c96b9 Validate BIND_DIR variable in Makefile
    e32715ec03 Added support for AMD GPUs in "docker run --gpus".
    6bac5ca833 Set EnableIPv4=true in overlay network inspect response
    27f2e0ecc5 api: bump to 1.51
    bd20bfdc41 all: remove redundant import-aliases for "go-winio"
    f85394dd5d api: image inspect: add back fields that did not omitempty
    284904119a Dockerfile: update cli to v28.2.2
    8ba832cc8f docs/api: swagger: quote maxUint64 example value
    affe1d6335 api/swagger: quote maxUint64 example value
    b6fa565cba libnetwork/resolvconf: Build: decorate error for invalid nameservers
    35e062dde1 libnetwork/resolvconf: rewrite TestBuild tests to a table-test
    16ed51d864 libnetwork/networkdb: always shut down memberlist
    c1a27ea5af pkg/stack: remove // import comments
    dd382769bd pkg/rootless: remove // import comments
    ce191648c7 pkg/useragent: remove // import comments
    ad1a388895 pkg/tailfile: remove // import comments
    b6f99f6d7f pkg/stringid: remove // import comments
    ca2cca1286 pkg/stdcopy: remove // import comments
    225b7ca6b7 pkg/progress: remove // import comments
    0f9818ad03 pkg/pools: remove // import comments
    f0f4fa0038 pkg/plugingetter: remove // import comments
    5f4da92972 pkg/platform: remove // import comments
    7a703f3772 pkg/pidfile: remove // import comments
    511cf09e75 pkg/namesgenerator: remove // import comments
    864e3f9348 pkg/longpath: remove // import comments
    cc329af619 pkg/jsonmessage: remove // import comments
    0c70c762b2 pkg/streamformatter: remove // import comments
    fd8b6a24ab pkg/tarsum: remove // import comments
    17845556f2 pkg/system: remove // import comments
    18a1b61b49 pkg/sysinfo: remove // import comments
    126246ae39 pkg/plugins: remove // import comments
    0380c952a6 pkg/parsers: remove // import comments
    4800a9b50d pkg/ioutils: remove // import comments
    ca3982adea pkg/homedir: remove // import comments
    c93f18e0b8 pkg/fileutils: remove // import comments
    6a9f7c543c pkg/authorization: remove // import comments
    a4411f497f errdefs: remove // import comments
    0ea03c4add opts: remove // import comments
    7ce4e9685a oci: remove // import comments
    23009a700a testutil: remove // import comments
    fe1bc3e7fd runconfig: remove // import comments
    4656712b82 restartmanager: remove // import comments
    134f20c828 reference: remove // import comments
    97b20f6b79 registry: remove // import comments
    2548254317 quota: remove // import comments
    66055ea07c plugin: remove // import comments
    3bbb38f1d2 volume: remove // import comments
    021dd75bc4 libcontainerd: remove // import comments
    fe34e89992 layer: remove // import comments
    9abf9f2d0d internal: remove // import comments
    4970333621 integration: remove // import comments
    a4b0d32fa6 integration-cli: remove // import comments
    7eecd04c7b image: remove // import comments
    c1a3c51d9e dockerversion: remove // import comments
    c7cb2d9783 distribution: remove // import comments
    5318877858 daemon: remove // import comments
    076e98e8f3 daemon/links, daemon/network: remove // import comments
    2b42088bd5 daemon/listeners: remove // import comments
    241e0bca8b daemon/events: remove // import comments
    27956106d5 daemon/config: remove // import comments
    69c34390c0 daemon/logger: remove // import comments
    7d4caf4ba8 daemon/images: remove // import comments
    9876c9fbcf daemon/graphdriver: remove // import comments
    986ec3f877 daemon/cluster: remove // import comments
    89aa33001e container: remove // import comments
    d469079338 cmd: remove // import comments
    c6bbc3bb6e builder: remove // import comments
    4856e8ffad client: remove // import comments
    bf9d739561 api: remove // import comments
    fca97dae9d libnet/d/overlay/overlayutils: prevent uint32 overflow
    3d8195a20f daemon/logger/fluentd: cap max-retries to MaxInt32
    404f29c42d gha/bin-image: Don't push sha tags
    7994426e61 Revert "containerd: images overridden by a build are kept dangling"
    a2652d4b81 Don't set up iptables chain DOCKER-USER when using nftables
    d3289dda4b Add nftables NAT rules for internal DNS resolver
    c299ba3b38 Update worker.Platforms() in builder-next worker.
    6889039d76 Fix silent stop on error due to using output redirection together with `set -eu`.
    d6620915db portallocator: always check for ports allocated for 0.0.0.0/::
    027588eba0 builder: Pass cdi cache instead of CDISpecDirs
    bc6bc7aafa daemon/cdi: Log not found dirs as INFO
    9856bf52a2 daemon: Configure default CDI cache
    ae2fc2ddd1 PortAllocator: Use netip.Addr instead of string as map key
    19dc38f79b Listen on mapped host ports before mapping more ports
    dc519a0f18 iptables: Drop explicit RETURN rule from DOCKER-USER
    148a19b6d6 seccomp: Require CAP_SYS_ADMIN for lsm_* syscalls
    0ab8108b57 seccomp: Fix typo in lsm_set_self_attr
    21a165de23 Use env-var DOCKER_FIREWALL_BACKEND=nftables to enable nftables
    637e8142ce clean up golangci-lint config for deprectated errdefs.*
    37caf3881a volume: replace uses of errdefs package
    08768e4d9d testutil: replace uses of errdefs package
    416dc8c1bf runconfig: replace uses of errdefs package
    8803b58259 refernce: replace uses of errdefs package
    dcf253ffe2 plugin: replace uses of errdefs package
    8561016335 libnetwork: replace uses of errdefs package
    f06c450a8e libcontainerd: replace uses of errdefs package
    528f2284ee integration-cli: replace uses of errdefs package
    14852fcd82 integration: replace uses of errdefs package
    a1a789dbd0 image: replace uses of errdefs package
    6ee53a6831 errdefs: replace uses of errdefs package
    083ccfa486 distribution: replace uses of errdefs package
    55da8ea276 daemon: replace uses of errdefs package
    364d8d8b31 container: replace uses of errdefs package
    415fc7b41e builder: replace uses of errdefs package
    f0eaf228c1 api: replace uses of errdefs package
    f98b7005d2 remove fallback for non-OCI-compliant docker.pkg.github.com registry
    048199f191 Dockerfile: update cli to v28.2.0-rc.2
    d188df0039 libn/d/overlay: use netip types more
    0317f773a6 libnetwork/internal/setmatrix: make keys generic
    e48ea1c6e0 Make integration tests ready for nftables
    f9f0db0789 Add nftables support to testutil SetFilterForwardPolicies
    7ea0e60dde Skip test TestBridgeINCRouted in rootless mode
    0d6e7cd983 libnetwork/osl: stop tracking neighbor entries
    9866738736 libnetwork/osl: remove superfluous locks in Namespace
    b6d76eb572 libn/osl: refactor func (*Namespace) AddNeighbor
    3bdf99d127 libn/osl: drop unused AddNeighbor force parameter
    f834a0bd82 vendor: github.com/miekg/dns v1.1.66
    4da3b4bf2d run/pull: Warn/reject AI model images
    339be4e2ae Dockerfile: install nano as alternative to vim
    588a05a1ce docs/api: Cut docs for API v1.50
    94daa36f03 libnetwork: don't reinvent mutexes
    cd2702e04e Dockerfile: update compose to v2.36.2
    01fec904e4 Dockerfile: update buildx to v0.24.0
    072483f9d7 c8d/delete: Require --force when deleting platforms
    30da69d694 c8d/delete: Support deleting specific platforms
    acf6b6542e daemon/images: Make ImageDelete take opts struct
    871675be9b c8d/delete: Extract untagReferences
    153b16ad27 c8d: Extract memoryLabelStore
    d7cca3f997 docs/api: update deprecation version for erroneous fields
    4dc961d0e9 image-inspect: remove Config fields that are not part of the image
    0ec3278d48 profiles/seccomp: kernel v6.13
    6aa8288cfb profiles/seccomp: kernel v6.12
    e03ac1fad9 daemon: createCDICache: fix error-capitalization
    7263ae74cd contrib: systemd: update deprecated StartLimit options
    888cbfddf2 vendor: github.com/opencontainers/cgroups v0.0.2
    42970fc461 registry: replace uses of errdefs package
    979f18691a daemon: restore: fix fluentd-async-connect migration for downgrades
    c6b9bb00f9 api/server/router/build: BuilderVersion: allow buildkit on Windows
    560299a16f validation: re-enable check for changes in integration-cli"
    e354e42e14 vendor: update buildkit to v0.22.0
    a2ada6b258 daemon/create: Simplify GetImage args
    2c57455339 vendor: github.com/containerd/containerd/api v1.9.0
    a3ce441ae0 client: Use containerd errdefs to convert http errors
    86187b2606 vendor: github.com/vishvananda/netlink v1.3.1
    e8c269843c builder-next: remove support for deprecated schema1 images
    a9ec07a005 builder-next: add buildkit executor for wcow
    e655763837 client/volume: use containerd errdefs checks
    6bde39b729 client/utils: use containerd errdefs checks
    144363fea2 client/task_list_test: use containerd errdefs checks
    6cd9eaf5ab client/task_inspect_test: use containerd errdefs checks
    68a8a8f3c8 client/swarm: use containerd errdefs checks
    0b4495463f client/service: use containerd errdefs checks
    ad4a3d32c6 client/secret: use containerd errdefs checks
    df96159df0 client/request: use containerd errdefs checks
    7e8b26ecb9 client/plugin: use containerd errdefs checks
    2356f435a6 client/node: use containerd errdefs checks
    4a830df491 client/network: use containerd errdefs checks
    8f2bf4aef5 client/info_test: use containerd errdefs checks
    a1035ec59b client/image: use containerd errdefs checks
    370b7e65fc client/events_test: use containerd errdefs checks
    27e64d3bdb client/distribution_inspect_test: use containerd errdefs checks
    f030c7bf10 client/disk_usage_test: use containerd errdefs checks
    c75ca8ef10 client/container: use containerd errdefs checks
    eafa2266f6 client/config: use containerd errdefs checks
    685fa0bb91 client/checkpoint: use containerd errdefs checks
    bb41e5a32e Replace platforms.Format with platforms.FormatAll in functional code.
    9319fefe35 vendor: github.com/moby/buildkit v0.22.0-rc2
    cf11cd1aac Replace platforms.Format with platforms.FormatAll in user-visible messages and logs.
    0b1c7a8306 api/types: move ServiceUpdateOptions to api/types/swarm
    31d62930f7 api/types: move ServiceCreateOptions to api/types/swarm
    5ad0867236 api/types: move TaskListOptions to api/types/swarm
    7e8f630bec api/types: move SwarmUnlockKeyResponse to api/types/swarm
    f008d85edc api/types: move NodeListOptions, NodeRemoveOptions to types/swarm
    b13528522a api/types: move ServiceListOptions, ServiceInspectOptions to types/swarm
    5e8fd897e1 client/volume: use gotest.tools-style asserts
    9432eff6bc client/utils_test: use gotest.tools-style asserts
    adf7ecc366 client/task_list_test: use gotest.tools-style asserts
    b781699ee2 client/task_inspect_test: use gotest.tools-style asserts
    d8ee5caf9a client/swarm: use gotest.tools-style asserts
    a6cd40de6b client/service: use gotest.tools-style asserts
    3658dae265 client/secret: use gotest.tools-style asserts
    2e65796c86 client/request_test: use gotest.tools-style asserts
    44f30261da client/plugin: use gotest.tools-style asserts
    832efcd672 client/options_test: use gotest.tools-style asserts
    88453254af client/node: use gotest.tools-style asserts
    047343d070 client/network: use gotest.tools-style asserts
    6402a106e7 client/image: use gotest.tools-style asserts
    043c7fa539 client/hijack_test: use gotest.tools-style asserts
    a8ed3bd734 client/events_test: use gotest.tools-style asserts
    c88f921331 client/disk_usage_test: use gotest.tools-style asserts
    051dae4fdc client/container: use gotest.tools-style asserts
    cae3ccd34b client/config_create: use gotest.tools-style asserts
    bfc684d3f7 client/client_test: use gotest.tools-style asserts
    19f3259093 client/checkpoint: use gotest.tools-style asserts
    a411a39be0 api/types: move ConfigCreateResponse, ConfigListOptions to types/swarm
    23117afca8 api/types: move SecretCreateResponse, SecretListOptions to types/swarm
    3d1e4d9002 api/types: move build-related types to api/types/build
    bb7dbaafcd api/types: move BuildResult to api/types/build.Result
    6505d3877c API: /info: remove BridgeNfIptables, BridgeNfIp6tables fields
    114b8a4fa9 Remove unused image/v1 code
    7130cd4f16 Remove DockerSchema1RegistrySuite schema 2 version 1 tests
    7c09fa25fd distribution: remove v2 schema1 push
    a891e4e3e1 validation: temporarily allows changes in integration-cli
    2a96d2eb8d align //go:build versions
    c1b2be0399 client/info_test: Use gotest.tools asserts
    9095698a5c daemon: Discover devices and include in system info
    f95a7c47e8 api: bump API version to 1.50
    b70b496505 testutil/daemon: Don't use devcontainers daemon.json
    23bbfea718 daemon: Fix error log when CDI cache creation failed
    6d7a370fe5 Refactor CPU usage stats test to use go:embed
    eefe68a37c api/types: move build cache types to api/types/build
    7aa7369f1f client: deprecate IsErrNotFound
    a022e916c8 update authors and mailmap
    4cecce03f6 daemon: Enable CDI by default
    07466d2e9b daemon: Daemon.ContainerExecStart: rename err-return, and minor refactor
    d5c370dee6 libnetwork/networkdb: use correct index in GetTableByNetwork
    270a4d41dc libn/networkdb: stop table events from racing network leaves
    205ba05feb fix usestdlibvars
    23fa0ae74a Cleanup http status error checks
    fadb571106 Update api status checks to use containerd/errdefs
    5c16f2d091 Use standard library interface to unwrap errors
    a90a9d899b Ignore deprecations for internal errdefs package
    f1bb44aeee Use containerd errdefs for error checks
    ba2ddd75e4 Dockerfile: update crun to 1.21
    f07242f6d7 containerd: include present content size in disk usage calculations
    3ded7b97d0 vendor: github.com/containerd/accelerated-container-image v1.3.0
    68e025a11b daemon: startIngressWorker: fix S1000: should use for range (staticcheck)
    7bc6fd09da Dockerfile: update compose to v2.36.0
    76b24759f0 container: Snapshot.Health: change type to container.HealthStatus
    7a7d72e874 api/types/container: Summary.State change type to ContainerState
    8e57a019dc fix: load the CDI driver before the dockerd daemon starts
    b3ed54db81 integration/networking: mark TestPortMappedHairpinWindows as flaky
    7b5d2b4ec3 chore: bump golangci-lint to v2
    3d1cfb4de0 vendor: update buildkit to v0.22.0-rc1
    c9b01e0c4c libn/networkdb: SetPrimaryKey() under a write lock
    61646c8bfc containerd: remove unleaseSnapshotsFromDeletedConfigs
    350bb5197a nftables: attempt a table-reload after an Apply error
    06afbe9618 Check nftables is enabled before applying updates
    976f855f68 Add OTEL span for nftables updates
    eeba428939 Make WSL2Mirrored a Firewaller param
    1028b123e8 integration, libnetwork: fix some godoc comments (ST1020)
    a3aea15257 libn/networkdb: Watch() without race conditions
    ada8bc3695 libn/networkdb: record tombstones for all deletes
    c68671d908 libn/networkdb: b'cast watch events from local POV
    ba0ad9e80f Unit test the bridge driver in terms of its firewaller
    a7ef4a208d Fix multiarch image push tag for containerd snapshotter
    854f3f62db container: don't persist State.RemovalInProgress on disk
    44b653ef99 container: deprecate IsValidStateString
    e477df3b31 daemon/cluster/executor: use container.ContainerState consts
    3bbdda696d use container.ContainerState consts in tests
    b811829595 api/types/container: add ContainerState and const for container state
    8b6d6b9ad5 d/cluster/convert: expose Addr() on plugins
    37259540e9 Remove/replace integration-cli tests that use iptables directly
    daeb080ff1 Test Iptabler params
    ea2e147c4c TestPruneDontDeleteUsedDangling: rename var that shadowed import
    02e800dcbb plugin: use t.TempDir
    57b27f2e9e image: use t.TempDir and rename vars that shadowed
    08c5ebe040 layer: use t.TempDir and minor cleanups
    f84694ebdc container: use defer for locks
    24f305b666 Makefile: set BIND_DIR to "." by default
    4b6a9d23af cmd/dockerd/trap: use t.TempDir
    ea37a1f040 integration/build: use t.TempDir
    900bd88848 internal/directory: use t.TempDir
    46baf7deb0 distribution: use t.TempDir
    1b4ba20708 distribution/metadata: use t.TempDir, rename var that shadowed
    735ccfbc6f pkg/stack: use t.TempDir
    72a11b84d4 testutil/fakestorage: use t.TempDir
    b38f73afe3 daemon: cleanupContainer: leave decorating container-id/name to caller
    d44b2e4bd7 daemon: cleanupContainer: use state-fields instead of string form
    4a00ce10fa daemon: rmLink, cleanupContainer: rename args that shadowed import
    1cf7d7ea4b hack/make/.binary: update link to go source for "pie" support
    e991c7185d update to go1.24.3
    89ee292709 container: update GoDoc for State
    7dae7c54dd fluentd: add write timeout log option
    56ad941564 Fix possible overlapping IPs when ingressNA == nil
    dc1d23c646 Revert "rootless: skip tests that need br-netfilter loaded"
    4b9092aa27 Load br-netfilter for rootless test-integration
    7957a28859 container: remove GoDoc for deprecated aliases.
    fe403362b4 container: State.Wait(): don't use deprecated type
    0bd82bfac2 chore: add systemd-sysusers configuration
    df662ebc59 container: deprecate IsValidHealthString
    f9c4601760 volume/mounts: MountPoint.Setup: rename output-var, and simplify err-handling
    6ac3afe483 volume: remove/rename err-returns
    986988a394 testutil/daemon: Daemon.StopWithError: rename output-var to prevent shadowing
    3606712e2d testutil: remove named returns
    fe2d323c82 registry: remove/rename err-returns, and minor refactor
    79b1b561a3 registry/resumable: remove named err-return, fix minor linting issue
    e67b6bfc69 plugin: remove/rename err-returns
    943dfa985d oci: remove named err-return
    0b169d34e4 libnetwork: remove named (err)-returns
    154230cdd7 libnetwork/portallocator: getDynamicPortRange: fix err-handling on freeBSD
    962fd8bc41 libnetwork/ipams/remote: inline decodeToMap
    cfdfbfab9b libnetwork/drivers/remote: inline decodeToMap
    152db74d96 libcontainerd: remove/rename err-returns
    f87dcbe350 layer: remove/rename err-returns and remove naked returns
    6981aad790 internal/testutils: remove named returns
    d1c58bdbbe integration-cli: remove/rename err-returns and remove naked returns
    1b317b0323 distribution: remove named err-returns and minor refactor
    1244685329 Optimization methods in internal\metrics\metrics.go
    84ef7e4899 Allow TestIsolated/ipv6 to unexpectedly pass
    4c4810e5d2 rootless: skip tests that need br-netfilter loaded
    dacf445614 libn/networkdb: don't exceed broadcast size limit
    697c17ca95 libn/networkdb: take most tests off flaky list
    90ec2c209b libn/networkdb: listen only on loopback in tests
    e3f9edd348 libn/networkdb: advertise the configured bind port
    ec65f2d21b libn/networkdb: fix data race in GetTableByNetwork
    d0af7c3c08 Move Cory from Reviewers to Committers
    b0777be89e Use firewaller.IPVersion instead of iptables.IPVersion for gwmode
    3cbb1ae736 Move filter-FORWARD DROP setting to the firewaller
    44843d9917 Pass context to more places
    a9bf151260 Put Iptabler behind a Firewaller interface.
    92e497b9dc Create api interface to define build usage backend
    aef409dfb2 Remove unused reference store in image api
    9eec936eb0 project: update status of branches for Moby 28.x
    9315b15dc6 fix(ST1006): Poorly chosen receiver name
    70139978d3 fix(ST1016): Use consistent method receiver names
    9e9b6cc42e fix(ST1019): Importing the same package multiple times
    27bf320a72 fix(ST1017): Don’t use Yoda conditions
    98fa4bcfeb fix(exhaustive): missing cases in switch of type snapshots.Kind
    95af77d038 fix(ST1015): A switch’s default case should be the first or last case
    f770f6c5ec fix(QF1012): Use fmt.Fprintf(x, ...) instead of x.Write(fmt.Sprintf(...))
    a88c49f38e fix(QF1011): Omit redundant type from variable declaration
    4f9214c156 fix(QF1007): Merge conditional assignment into variable declaration
    be54c79d9c fix(QF1006): Lift if+break into loop condition
    2cce9a51ca fix(QF1004): Use strings.ReplaceAll instead of strings.Replace with n == -1
    e2e7f9964f fix(QF1003):  Convert if/else-if chain to tagged switch
    b0711d5fe9 fix(QF1001): Apply De Morgan’s law
    7d8df25d16 fix misused error
    fef139ccc1 fix import
    44a3453d73 Add daemon option --allow-direct-routing
    c16caabe36 Add TestNetworkConfigurationMarshalling
    a94643a1b3 bridge: add option com.docker.network.bridge.trusted_host_interfaces
    33f5b9e963 Don't add stub Endpoint/Network object to cache on Sandbox restore
    c129c0fa9f Improve logging and readability of Controller.sandboxRestore
    5d8192fcce Report endpoint id as well as name in ActiveEndpointsError
    9aa66be7ec vendor: github.com/moby/buildkit v0.21.1
    a79d081aa5 config: set buildkit gc enabled to default to true
    19ccb75c62 daemon: remove/rename err-returns and remove naked returns
    9ed975a247 daemon: NewDaemon: rename err-return
    3e586094fc daemon: parseXXVersion: rewrite to be slightly more iodiomatic
    2145cf6309 daemon: Daemon.ContainerStatPath, ContainerArchivePath: minor refactor
    6da1ff6bf9 builder/builder-next: fix vars that shadowed (govet)
    692610414a pkg/plugins: fix vars that shadowed (govet)
    0fcd23ec13 daemon/logger/loggertest: fix vars that shadowed (govet)
    4c57ffaca7 api/server/router/build: fix vars that shadowed (govet)
    eef5c75276 api/server/router/network: fix vars that shadowed (govet)
    7edd83a1b3 libnetwork: fix vars that shadowed, and slight refactor (govet)
    7dbe2f1fb6 libnetwork/portallocator: fix vars that shadowed (govet)
    357b136ee9 libnetwork/drivers: fix vars that shadowed (govet)
    f831618e5b libnetwork/networkdb: fix vars that shadowed (govet)
    f633e8f03f libnetwork/cmd/diagnostic: fix vars that shadowed (govet)
    190ad0610d daemon/logger: remove/rename err-returns and linting warnings
    ba15bbc422 daemon/images: rename err-returns to prevent shadowing
    48220008d8 daemon/graphdriver: remove/rename err-returns and remove naked returns
    088c180a9e daemon/containerd: remove named err-returns
    dc79403f7b daemon/cluster: remove/rename err-returns and remove naked returns
    9b62592bfe Dockerfile.windows: update github.com/tc-hib/go-winres to v0.3.3
    d6b2aec809 pkg/progress: remove named err-return
    029f267d9b pkg/pidfile: remove named err-returns
    fdbf246889 pkg/parsers: remove named err-returns
    b0f93d5283 pkg/fileutils: remove named err-returns
    ab8e3da82c pkg/stdcopy: remove/rename err-returns
    d17a62592f pkg/ioutils: remove named err-returns
    f193ff1317 pkg/broadcaster: remove named err-returns
    91f6e00ffa hack: Update broken links from README
    7868d3ee3e vendor: github.com/opencontainers/runtime-spec v1.2.1
    100102108b Use container status values from api
    878de14c8d man: vendor github.com/cpuguy83/go-md2man/v2 v2.0.7
    11f65b566d vendor: github.com/spf13/cobra v1.9.1
    ea7152e493 volume/local: use t.TempDir
    4b41198e3c volume/mounts: use t.TempDir
    2b869baea3 volume/service: use t.TempDir
    88f6dd72e5 volume/service: rename interface that collided with vars
    3b4e21081f container: remove unused named-returns
    35167dc616 client: Client: PluginInstall, PluginUpgrade: remove/rename err-returns
    bb57656932 builder/remotecontext: remove unused named and "naked" returns
    5416f2d57c builder/dockerfile: remove unused named and "naked" returns
    f38b1fa30d builder/builder-next: SanitizeRepoAndTags: remove named err return
    c025dd74f0 builder/builder-next: wrapRC.Read: remove intermediate err-var
    49d5b2cc8e builder/builder-next: puller.resolve: rename err-return
    3f2296cfc1 api/server/router: remove named (err) returns
    1e4bb14bcd api/types/container: define HealthStatus "pseudo" type
    c690e0076a use consts for health-status in tests
    91473ce253 api/server/backend/build: sanitizeRepoAndTags: remove named err return
    c5031c8632 api/types/time: remove named err return
    50a856157c containerd: images overridden by a build are kept dangling
    eee14cff72 builder/remotecontext: use t.TempDir
    5749bc242a builder/dockerfile: use t.TempDir, rename vars that shadowed
    b54a038bec docker exec: fail early on exec create if specified user doesn't exist
    37725b5eae Drop "-o com.docker.network.enable_ipv[46]" if overridden
    8d0c272e4a Add TestLegacyLink
    dfd59c0a95 Dockerfile: Fetch vpnkit from moby org
    af0232d52b integration/build: Unskip TestBuildEmitsImageCreateEvent for c8d
    a0ff0a361e iptables: Direct routing DROP rules per-container, not per-port
    dea236e0ce Split iptabler into multiple files
    282b3f7b97 Move bridge driver iptables code into its own package
    8c36a22e79 Rename function insertMirroredWSL2Rule
    aa4abaf820 Use firewaller (iptabler) structs in iptables unit tests
    75c60598b7 Move clearConntrackEntries to bridge_linux.go
    42d149e45d fix duplicate import, and force consistent alias for bolt
    eede75c9d4 testing: remove some defer cleanup in favor of test.Cleanup()
    e3a0f2e690 vendor: github.com/vbatts/tar-split v0.12.1
    bcc720abde builder/remotecontext: MakeGitContext: use "WithFields" for logs
    54a556a5ef builder/remotecontext: Deprecate Rel()
    2808e59f4c Dockerfile: update compose to v2.35.1
    a75be33ba0 Dockerfile: update buildx to v0.23.0
    dd36139b1a Dockerfile: update cli to v28.1.1
    f1e3ed0c48 Dockerfile: don't pin syntax to 1.7
    fc8361c078 vendor: github.com/containerd/containerd v2.0.5
    62f51e4367 vendor: golang.org/x/oauth2 v0.29.0
    bbbb0036df cleanup ignore files
    ead379a464 contrib/rootless-setuptool: Fix iptables detection
    7c52c4d92e update go:build tags to go1.23 to align with vendor.mod
    619f1ddd05 Warn when no external DNS nameservers are found
    6083fad7df Reset default bridge addresses after integration tests
    c2b7abacf8 Use setupTest instead of testutil.StartSpan in tests
    d4e0d6f2a1 Integration tests: use different docker0 addresses
    fd550344b1 vendor: github.com/moby/go-archive v0.1.0
    fd5e772aec CI: deduplicate execution of unit tests
    b8067d159f docs/api: update image tarball format
    a38ca9a548 daemon/initlayer: Setup: remove uses of idtools.Identity
    380ded6309 Store an endpoint count for networks, for downgrade
    ae0331d8f5 vendor: update buildkit to v0.21.0
    57bf7a8c70 bridge: Add a missing error check for firewaller setup
    c49ce64514 integration/TestStopContainerWithTimeout: Attempt to fix flakiness
    7eda35fd05 profiles/apparmor: IsLoaded: optimize
    0462b5e318 profiles/apparmor: add BenchmarkIsLoaded
    b23d267cb5 profiles/apparmor: add basic unit-test for IsLoaded
    0dd5959eeb profiles/apparmor: InstallDefault: slight cleanup and optimization
    0bb761698c profiles/apparmor: loadprofile: fix double command in error message
    8e1c366773 profiles/apparmor: remove "// import" comments
    1fa6a46c5d profiles/seccomp: remove "// import" comments
    89604f1df1 profiles/seccomp: use stdlib for asserting
    14623770e1 vendor: github.com/moby/buildkit v0.21.0-rc2
    eacbbdeec6 Revert "API: /info: remove BridgeNfIptables, BridgeNfIp6tables fields"
    ece7e02b86 Update AUTHORS
    adb9e9135a docs/api: add documentation for API v1.49
    099d3ee008 daemon: containerStart: add filtered labels to OTel span
    0c5e816638 daemon: trace containerCreate
    f96dc9d1a5 Dockerfile: update registry to v3.0.0
    4d35864c3d Fix removal of legacy links
    5d2006256f API: /info: remove BridgeNfIptables, BridgeNfIp6tables fields
    499e15d4ab api/server/middleware: fix debug-logs missing form-data
    97688e8d06 container: Container.SetupWorkingDirectory: remove use of pkg/idtools
    5f9d99b4cc integration-cli/swarm: Update to use gotest.tools
    ea6c76ee03 integration-cli/TestSwarmInit: Skip failing part on CLI after 18.06
    fab94808f5 integration-cli: Update default CLI version to v18.06.3-ce
    6c73266a71 Add registry error handling for push and pull
    ae3a1ac602 vendor: github.com/moby/buildkit v0.21.0-rc1
    cd89a35ea0 Run CLI tests with cgroups v2
    7435e4a1be registry: remove deprecated ServiceConfig.AllowNondistributableArtifacts
    ba03cd7a63 daemon/config: add test for deprecated daemon.json fields
    d72e434d30 vendor: golang.org/x/mod v0.24.0
    224b393eb3 vendor: golang.org/x/net v0.39.0
    b1ac2a53ed vendor: golang.org/x/crypto v0.37.0
    a8af27bbae vendor: golang.org/x/text v0.24.0
    7d49b014b6 vendor: golang.org/x/sync v0.13.0
    9d04c28def vendor: golang.org/x/time v0.11.0
    cdb3590e1a vendor: golang.org/x/sys v0.32.0
    970fc1b6f7 Basic compose file for testing OTEL bits
    d8a5e8928b replace uses of idtools.MkdirAllAndChown, MkdirAllAndChownNew
    d96d20d45f update golangci-lint exceptions
    29e0db25e7 Factor out top-level iptables setup into its own object
    241d685574 libnet: add ep name in 'has active endpoints' error
    489cd7edfc api, daemon, libnet: add a 'trigger' baggage member
    31ac5cb6d9 libnet: New: plumb context
    667c7d70b3 libnet/d/bridge: trace network setup steps
    eaae4b5fb6 libnet/d/bridge: put span prefix in var
    78be7ebad7 libnet/d/bridge: trace createNetwork
    f8806f2b80 libnet/osl: independent OTel trace for advertiseAddrs
    d0154d3e59 Update to use github.com/moby/go-archive
    45f9d679f8 Update remaining Ubuntu 20.04 uses to 22.04 and 24.04
    57a042b77c deprecate pkg/(chroot)archive for  github.com/moby/go-archive
    564abf9157 api: info: omit deprecated "Commit.Expected" fields on API &gt;= 1.49
    f410dbda88 dockerfile: dind target to build docker image for testing
    c3fa7c1779 Test that firewalld reload doesn't re-create deleted iptables rules
    dbea045e0d Report firewalld reload time in Info.FirewallBackend
    a527e5a546 Restore iptables for current networks on firewalld reload
    7d9c50db2b api: /info: omit non-distributable-artifacts fields for API &gt;= 1.49
    a0a86d0982 Add Info.FirewallBackend
    25a80bd48e vendor: github.com/moby/sys/atomicwriter v0.1.0
    4eebd2c920 libnet: TestNetworkStore: replace assert.Equal with Check
    e22d04e8a9 Improve CPU usage parsing and error reporting
    40650c6982 libnet: de-flake TestNetworkStore
    1c79c893b1 libnet: de-flake TestEndpointStore
    8a5f141b0e registry: Service.lookupV2Endpoints: wire-up context
    9d8c8382d3 registry: authorizeClient: wire-up context
    8b920b2812 registry: loginV2: wire-up context
    4642704ed7 registry: newTransport: remove intermediate var
    7acef8101e c8d/pull: Show progress for non-layer blobs
    b3791dea92 pkg/archive: fix linting issues
    a427477220 pkg/idtools: MkdirAllAndChownNew: improve deprecation message
    a91bcc677b vendor: github.com/klauspost/compress v1.18.0
    2c54f6f316 vendor: github.com/google/go-cmp v0.7.0
    6422ff2804 deprecate pkg/atomicwriter, migrate to github.com/moby/sys/atomicwriter
    f1ec5bf14f pkg/idtools: remove tests already covered in moby/sys/user
    3fc36bcac4 Update daemon to use moby sys/user identity mapping
    b5c99c0e95 Update moby/sys/user to version which includes mapping
    0a83a476d8 registry: v1Endpoint.ping: pass through context
    2a272a0c5d registry: newV1Endpoint: pass through context
    f158d2e809 registry: ReadCertsDirectory: internalize, and pass context
    51d7f95c4b libnet: remove struct endpointCnt
    d377cd3810 libnet: Controller: cache networks in-memory
    cc8bd2016e libnet: Controller: cache endpoints in-memory
    c6cdfbf495 pkg/atomicwriter: return early if parent directory is invalid
    00c988caa4 pkg/atomicwriter: add test for parent dir not being a directory
    ad386f64e5 pkg/atomicwriter: error on unknown file-modes
    ec82bc35c3 pkg/atomicwriter: disallow symlinked files for now
    f3aebbf9d8 pkg/atomicwriter: add basic godoc for package
    f80feba181 Rootlesskit: check for module nf_tables
    7d742ebf75 Add utils for manipulating nftables rules
    59169d0f97 image/inspect: Add platform selection
    d4e70f6325 vendor: tags.cncf.io/container-device-interface v1.0.1
    74b71c41ac update to go1.23.8 (fix CVE-2025-22871)
    fc58c829e8 registry: ParseRepositoryInfo: remove some intermediate vars
    44b7a42fc6 registry: ReadCertsDirectory: return early on error
    4f65e35f02 registry: NewService: return nil on error
    a7daab5df4 registry: authTransport: un-export AuthConfig, RoundTripper
    795461eceb docs: api v1.48: Move ImageGet api docs under Image tag
    e1e58409a1 docs: API v1.48 Add missing platform parameter to ImageGetAll api docs
    db275ddbc1 libnet: fix duplicated port mappings in overlay networks
    a9e22ee5e7 Don't run unit tests with mode rootless
    749e35cf5e Move ImageGet api docs under Image tag
    094df015b1 Add missing platform parameter to ImageGetAll api docs
    7243860557 Include per-port rules in iptablesNetwork
    4390ab275a api: bump API version to 1.49
    0b5e1f904a Use netip.Addr instead of net.IP for legacy links
    725e699741 Simplify iptables setup for legacy links
    31f9ae0d19 registry: TestValidateMirror: improve coverage
    cb0a9d713c registry: ValidateMirror: touch-up GoDoc
    6b258ce567 registry: session.searchRepositories: pass through context
    83aaa3428f distribution: pusher.push(): don't use APIEndpoint.Mirror field
    6439824449 distribution: pushDescriptor: remove unused endpoint field
    09ee47de39 distribution: cleanup some tests and add missing error-checks
    adfed82ab8 Install and run firewalld for CI's firewalld tests
    409707b633 bridge: factor out creation of network-level iptables rules
    ec7fe73690 distribution: pushDescriptor: rename repoInfo to repoName
    b1c526b4a9 daemon/containerd: remove registryResolver interface
    0d95e1680a registry: ResolveAuthConfig: inline newIndexInfo code
    6c643bc366 lookup auth-config without depending on RepositoryInfo
    a18dae049f daemon/containerd: registryResolver: remove IsInsecureRegistry
    abcc70b9ef distribution: GetRepositories skip using Service.ResolveRepository
    071d8b21e9 distribution: Push: skip using Service.ResolveRepository
    8b6a045aa4 distribution; newPusher: don't require RepositoryInfo
    8653af5854 distribution: pullEndpoints: skip using Service.ResolveRepository
    20a2807caa distribution: pullEndpoints: don't return RepositoryInfo
    f1ecce6877 distribution: pullEndpoints: don't require RepositoryInfo
    d6afe88b3c distribution: newPuller: don't require RepositoryInfo
    03918c5b07 distribution: layerDescriptor: don't require RepositoryInfo
    c91318e6c0 distribution: newRepository: don't require RepositoryInfo
    2e8bf8b0ab distribution: remove vars that shadowed imports or types
    d8fa2f8071 registry: deprecate APIEndpoint.Official field
    0ab6f07c31 Fix TestPassthrough
    2d643b6835 Firewalld: skip unit tests that run in their own netns
    4fbfb618c3 Skip flaky part of TestAccessPublishedPortFromHost
    b8323abe0a TestIsolated for IPv6 is broken under firewalld
    86eff82789 Firewalld: Skip tests that run dockerd in an L3Segment
    dc963a00c1 Firewalld should use its nftables backend
    b8cacdf324 Add test util "FirewalldRunning"
    8f506a51e5 containerd: ensure overwritten images from load are left dangling
    7b2e47846c Run systemd/rootless when systemd/rootless unit testing
    8d9e3502ab hack: Fix TestOverlay* test failure in pkg/archive
    f5d84a45cc Start containers, even when connected to a disabled bridge port
    072ea62fcc vendor: github.com/opencontainers/image-spec v1.1.1
    a60603bfa3 hack/validate: Add gocompat
    2be7f48561 implement module compatibility check
    cc90726fb8 Add missing go1.22 build constraints
    19a0f886da testutil: Update to `any` from `interface{}`
    f14c23a90f libnetwork: Update to `any` from `interface{}`
    82ec984d10 daemon: Update to `any` from `interface{}`
    003bf197d7 container: Update to `any` from `interface{}`
    444a1597ff c8d/builder: Fix missing `image tag` event with BuildKit
    2fce935df2 vendor: github.com/moby/buildkit v0.20.2
    7c09e4e607 TestBuildEmitsEvents: Skip Windows only for buildkit
    99356b6e17 integration-cli/TestBuildEmitsEvents: Verify event count
    3e957c6240 remove some redundant import-aliases
    4db84b197d switch to github.com/opencontainers/cgroups
    697956a8c7 vendor: github.com/opencontainers/selinux v1.12.0
    34bc972519 vendor: github.com/golang-jwt/jwt/v5 v5.2.2
    d01ee23c15 Dockerfile: update registry to v3.0.0-rc.4
    081987b647 Dockerfile: disable saving Golang telemetry in dev-container
    af14f3e7d3 Dockerfile: upgrade Delve to v1.24.1
    d0b4bdbd25 api/router: postContainersAttach, wsContainersAttach: minor cleanups
    73aa7e933c daemon: daemon.containerAttach: use structured logs
    d494520aa0 daemon: daemon.ContainerAttach: use Println instead of Printf
    183ca46099 daemon: daemon.ContainerLogs: move vars closer to where used
    c164eec7e9 daemon: daemon.ContainerAttach: move vars closer to where used
    f7853799fc daemon: daemon.containerAttach: remove redundant defers
    80bf93c9d7 daemon: daemon.containerAttach: rename vars for clarity and prevent shadow
    daeb6fb0b7 vendor: github.com/cilium/ebpf v0.17.3
    eeee17eaad Dockerfile: update runc binary to v1.2.6
    c1c5f16b8b vendor: github.com/opencontainers/runc v1.2.6
    be6e92a57b pkg/atomicwriter: use sequential file access on Windows
    452ff75159 Dockerfile.simple: avoid `Could not find installer for "proxy"`
    fa21996da5 containerd: prioritize non-dangling images with image list
    126d4cf672 client: remove version-gate for JSON response errors
    230f178f8b api: return plain-text errors for deprecated API versions
    c7fbe1c2ba integration-cli: fix duplicate close of body
    1c00755826 integration-cli: fix some unhandled errors
    8be5696c37 daemon/logger/journald: rename func that shadowed builtin
    f2a183a991 daemon: return port-mappings from all endpoints
    6b3b479192 daemon: getEndpointPortMapInfo: err is never used
    35766af7d2 Dockerfile: update containerd binary to v1.7.27
    c9a763ecc9 daemon: remove redundant call to getEndpointPortMapInfo
    fb3cce1988 vendor: github.com/containerd/containerd/v2 v2.0.4
    4276f330fc cmd/docker-proxy: do not eagerly GC one-sided UDP conns
    0356854327 cmd/docker-proxy: make the conntrack timeout a property of UDPProxy
    d70fd32a18 cmd/docker-proxy: UDP: thread-safe Write and Close
    485cb90b77 Remove duplicate iptables-enabled checks
    fce915897c Combine firewalld reload callbacks for IPv4/IPv6
    ac34bd9bda integration/container: Remove Parallel from TestWait*
    dd7f9f08d8 integration/container: Increase stop timeout for TestWaitRestartedContainer
    a8f14e06d6 Improve performance of daemon.Containers().
    c0ca783edb Allow macvlan endpoint to start with parent down
    26fea35942 daemon: Fix panic on Windows when restoring pre v28 container
    90a83063ee runconfig/errors: split `ErrConflictHostNetwork`
    a3fef5debc Mask Linux thermal interrupt info in /proc and /sys.
    cf3e42abaf Add an opt-out for iptables 'raw' rules
    0f11ee1ae2 registry: ReadCertsDirectory: don't process same file multiple times
    dd7ab0e82b registry: deprecate HostCertsDir
    3cc9881ab7 registry: always set a non-empty CertDir
    b633c4cc33 registry: deprecate SetCertsDir
    d0dd035278 builder-next: fix min-free-space prune with graphdriver backend
    1daeaec333 pkg/atomicwriter: validate destination path
    4d8cff7bd4 Don't skip DNAT for a routed network without userland-proxy
    084b7cec1a pkg/atomicwriter: add additional test-cases
    ff061e28c1 pkg/atomicwriter: don't overwrite destination on close without write
    88a5bca43c pkg/atomicwriter: add separate tests for New()
    09e804f570 pkg/atomicwriter: refactor tests
    2124706447 integration: Increase timeouts in TestStopContainerWithTimeout
    946bf70f89 integration: Deduplicate TestStopContainerWithTimeout
    fee063f01e daemon/c8d: Refactor singlePlatformSize into separate functions
    f7d7fd9c52 contrib/check-config: add IPv6 modules
    2a109e6c32 contrib/check-config: add ip_nf_raw
    0e54920e01 Dockerfile: update RootlessKit to v2.3.4
    7ae9e41ff6 vendor: github.com/rootless-containers/rootlesskit/v2 v2.3.4
    55ff0062ca vendor: github.com/containernetworking/plugins v1.6.2
    125aa3a682 vendor: golang.org/x/sys v0.31.0
    5d6b56699d client: add API-version dependent validation for mount options
    aa33bdaa71 registry: move emptyServiceConfig to test-file
    0823d76ec5 client: keep image refs in canonical format where possible
    907773160b registry: rewrite ParseSearchIndexInfo to not depend on IndexInfo
    b22431ee9c pkg/atomicwriter: New(): use absolute path for temp-file
    58bd93a625 pkg/atomicwriter: New(): prevent creating temp-file on errors
    49c89b0177 docs/api: improve doc for Secret and Config data fields (API v1.31-v1.48)
    df0cefcc95 api/swagger: improve doc for Secret and Config data fields
    f2d53142b0 api/types/swarm: document Secret and Config data fields
    c2c3d593cf registry: rewrite ParseRepositoryInfo to not depend on IndexInfo
    42f1e38e20 integration/image: TestRemoveImageGarbageCollector: don't set zero-values
    42ca9154e9 layer: remove StoreOptions.ExperimentalEnabled
    df519e9e1a daemon: Fix giving up too early while connecting to containerd socket
    ace8c9c94f vendor: golang.org/x/net v0.36.0
    bc0ca67b1c vendor: golang.org/x/net v0.35.0
    9278110260 Dockerfile: update containerd binary to v1.7.26
    0a58c73e0d integration/net: Retry TestAccessPublishedPortFromAnotherNetwork
    d34e1ff826 layer: remove StoreOptions.MetadataStorePathTemplate
    556633ca47 cmd/dockerd: daemonCLI.start: scope local errors
    8b59e1a398 cmd/dockerd: daemonCLI.start: return error instead of log.Fatal
    8a8cdaaa11 cmd/dockerd: daemonCLI.start: don't log warnings before failing
    6e30a4cc0c cmd/dockerd: explicitly access Config fields
    dfecaaf908 cmd/dockerd: rewrite getContainerdDaemonOpts to a func
    b95fdcd084 cmd/dockerd: createAndStartCluster: change to accept Config
    29aa7e15bd cmd/dockerd: rewrite getSwarmRunRoot to a regular func
    29c296e1dd cmd/dockerd: rename vars that shadowed imports
    f87ae7c914 gha: test-prepare: update to Ubuntu 24.04
    c41ed7c98c gha: build, cross: update to Ubuntu 24.04
    d29038d1cb gha: integration-cli-prepare: update to Ubuntu 24.04
    a23058e0d7 gha: integration-cli-report: update to Ubuntu 24.04
    de69b552ff gha: integration-report: update to Ubuntu 24.04
    b61f409972 gha: test: update Ubuntu 22.04 -&gt; 24.04
    60276fafca gha: integration-prepare: update to ubuntu 24.04
    651fb91c4d gha: arm64: update Ubuntu 22.04 -&gt; 24.04
    f6a9ed5f0a gha: arm64: test-integration-report: update to Ubuntu 24.04
    13e1ef6277 gha: arm64: test-unit-report: update to ubuntu 24.04
    27404044a6 gha: validate, build-dev: update to Ubuntu 24.04
    3571982458 gha: smoke: update to Ubuntu 24.04
    ee73f2e5da gha: docker-py: update to ubuntu 24.04
    b9ca3d198e gha: unit: update to ubuntu 24.04
    1a0afb0f9e gha: bin-image: update to ubuntu 24.04
    4919bf9f41 gha: buildkit: update to ubuntu 24.04
    7b1fd61864 gha: validate-pr: update to ubuntu 24.04
    eeffc099ef gha: dco: update to ubuntu 24.04
    06b87d80ee gha: docker-py: set TEST_SKIP_INTEGRATION_CLI=1
    c9f53d506a Merge ps_test.go into list_test.go.
    95bf53fb6c container/stream: Don't log error when streams are properly closed
    6e55f83747 Remove unused toml validation
    bf8a27a55a Remove inactive maintainers with no activity in last two years
    9e814fc0d7 Remove inactive former curators
    b868fad5e3 Update governance to replace TSC and add maintainer roles
    690f758505 vendor: golang.org/x/oauth2 v0.27.0
    55599fd9b3 vendor: golang.org/x/oauth2 v0.26.0
    a47d9c5f58 vendor: golang.org/x/crypto v0.35.0
    3a28163007 vendor: golang.org/x/crypto v0.34.0
    ffc91fd76a vendor: golang.org/x/crypto v0.33.0
    7cba8aef1c vendor: golang.org/x/text v0.22.0
    995d71a033 vendor: golang.org/x/sync v0.11.0
    e325564f38 vendor: golang.org/x/sys v0.30.0
    65b460b9ef vendor: update buildkit to v0.20.1
    6e8eb8a90f vendor.mod: update minimum go version to go1.23
    26edf2d0a7 Flush iptables chains DOCKER-CT, DOCKER-BRIDGE on startup
    5f912e4cf5 update to go1.23.7
    a8178613af golangci-lint: enable nakedret linter
    c359cc6829 api/types/registry: fix naked returns
    b1c008c007 api/server/router/build: fix naked returns
    4aecdd5744 image/tarexport: fix naked returns and slight refactor
    99b6012a02 daemon/logger/awslogs: remove unused named return
    4fa9ec3192 daemon/logger: fix naked returns and slight refactor
    eeb5651de5 daemon/graohdriver/fuse-overlayfs/: fix naked returns and slight refactor
    02b4610246 daemon/graohdriver: fix naked returns
    964413c3a1 daemon/cluster: fix naked returns
    387ec71630 daemon: fix naked returns
    85c8fb7fda daemon: getSystemCPUUsage(): fix naked returns, output vars
    5c85847a55 registry: fix naked returns, output vars
    17448ef1c8 plugin: fix naked returns, output vars
    faa9cb125b pkg/tarsum: fix naked returns
    b5b514ab04 pkg/stdcopy: fix naked returns
    d3d84bde4b pkg/pools: fix naked returns
    52b8298975 pkg/chrootarchive: remove unused named return
    b38f0dd804 pkg/archive: fix naked returns, output variables in tests
    d59a9d9b10 pkg/archive: fix naked returns, output variables
    c62f5aff42 libnetwork: fix naked returns
    8978b30b1a libnetwork/types: fix naked returns
    619e8f8148 libnetwork/osl: fix naked returns
    02b4c7cc52 libnetwork/drivers/overlay: fix naked returns, output variables
    94afddb18d libnetwork/cmd/networkdb-test: fix naked return
    379b82862f layer: fix naked returns
    b1c617681f internal/unix_noeintr: fix naked returns
    51f574ea0e internal/mod: fix naked returns
    e1538336c7 integration-cli: fix naked returns, output vars
    220b3c591f container/stream/bytespipe: fix naked returns, output vars
    0cd39d7b23 builder/remotecontext: fix naked returns
    0c1b37c50a builder/dockerfile: fix minor linting issues
    8302cd2d29 builder/dockerfile: downloadSource: fix naked returns, output vars
    00bd916203 libnetwork/resolvconf: Build: re-implement using new implementation
    2f19577877 libnetwork/resolvconf: Build: align order with new implementation
    03aeedcca9 libnetwork/resolvconf: update tests to use more correct values
    c34f8bbba3 integration/volume: setupTestVolume: minor cleanups and fixes
    28bf578a40 integration/volume: TestRunMountImage: use test-util for container cleanup
    e41eaf2c8d integration/volume: TestRunMountVolumeSubdir: remove some logs
    f1bec97dfe registry: use literal for empty slice
    7b4e21e5d0 registry: fix typo in godoc
    be9c4dd3c5 registry: TestNewIndexInfo: add more test-cases
    949afd933b registry: TestNewIndexInfo: assert all fields
    310d6d2fa5 registry: TestNewIndexInfo: use sub-tests
    50d17676e4 registry: TestParseRepositoryInfo: add test-cases for IPv6 refs
    328b808765 registry: TestParseRepositoryInfo: assert all index-info fields
    d9634c3b28 registry: TestParseRepositoryInfo: use sub-tests
    e2a5220ec3 registry: remove makeServiceConfig test-utility
    52419cf933 golangci-lint: enforce "is" alias for gotest.tools/v3/assert/cmp
    1c63f3983b volume/service: adjust "gotest.tools/v3/assert/cmp" import alias
    9766a446ae integration/network: adjust "gotest.tools/v3/assert/cmp" import alias
    c16fcdfc4b integration/image: adjust "gotest.tools/v3/assert/cmp" import alias
    6abe6a910a integration/container: adjust "gotest.tools/v3/assert/cmp" import alias
    22069f2431 integration-cli: adjust "gotest.tools/v3/assert/cmp" import alias
    605f02a59b distribution: adjust "gotest.tools/v3/assert/cmp" import alias
    75b86c47d9 daemon/logger/loggerutils: adjust "gotest.tools/v3/assert/cmp" import alias
    59e6d1d214 registry: TestLoadInsecureRegistries: don't mutate emptyServiceConfig
    849f344ecc registry: split normalizing index name from validating
    fee40a9333 registry: create emptyServiceConfig without parsing
    a3583b4b58 registry: newRepositoryInfo only check for official images for Docker Hub
    08654b0b30 registry: deprecate RepositoryInfo.Official field
    dbc9d56820 vendor: github.com/containerd/containerd v2.0.3
    15895d8ead daemon/graphdriver: rename vars that shadowed
    aa9817b0c5 testutil: remove isErrNotFoundSwarmClassic
    0ab7d41f9e testutil/environment: Execution.Clean: remove redundant condition
    b301c34b92 libcontainerd/local: remove arg-names for stubs
    12f89cc19b libcontainerd/local: NewClient: remove unused cli, stateDir, ns args
    620f26e1e3 libcontainerd/local: client.createWindows: remove unused runtimeOptions
    9c4e10126e libcontainerd/local: client.NewContainer: use early return
    7c1a2301f0 libcontainerd/local: client.extractResourcesFromSpec: use early return
    fc462d699a Dockerfile: update compose to v2.33.1
    855563fc43 Dockerfile: update docker CLI to v28.0.1
    ab7305c85a Check swarm's jump to DOCKER-INGRESS
    be14d9148c Make integration/service/network_test.go Linux-only
    cfc562c358 daemon/cluster: create "state" and "runtime-dir" closer to where used
    ef4f4d845d daemon/cluster: rename Cluster.root to Cluster.stateDir
    4d3d4bbeeb daemon/cluster: remove Config.WatchStream and move to constructor
    cdbb62394c builder/dockerfile: remove intermediate var that shadowed
    558da63444 Jump to DOCKER-INGRESS from DOCKER-FORWARD
    fdd534d2ca libcontainerd: windows: return errdefs type for pausing
    60782e6d39 container: fix some errors on Windows
    c37690b98e libnet/portallocator: un-export errors that were not used as sentinel errors
    cfc049c938 Use iptables-nft in the dev container / CI
    47ca352b0d vendor: github.com/opencontainers/runc v1.2.5, cyphar/filepath-securejoin v0.4.1

Signed-off-by: Bruce Ashfield &lt;bruce.ashfield@gmail.com&gt;
</content>
</entry>
<entry>
<title>containers: adapt to UNPACKDIR changes</title>
<updated>2025-06-26T02:40:08+00:00</updated>
<author>
<name>Bruce Ashfield</name>
<email>bruce.ashfield@gmail.com</email>
</author>
<published>2025-06-26T02:40:08+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-virtualization.git/commit/?id=bc2a750d5cd518706aff406da6e0719ce475e36b'/>
<id>urn:sha1:bc2a750d5cd518706aff406da6e0719ce475e36b</id>
<content type='text'>
This commit updates the container recipes to the OE core UNPACKDIR
changes.

  - We drop references to WORKDIR
  - We adjust destsuffix fetches to use BB_GIT_DEFAULT_DESTSUFFIX
    instead of 'git'
  - Update our GOPATH references to use UNPACKDIR
  - Drop S = assignemnts where possible

Signed-off-by: Bruce Ashfield &lt;bruce.ashfield@gmail.com&gt;
</content>
</entry>
<entry>
<title>metadata: add whitespace around assignments</title>
<updated>2025-04-03T17:56:53+00:00</updated>
<author>
<name>Martin Jansa</name>
<email>martin.jansa@gmail.com</email>
</author>
<published>2025-04-02T15:59:25+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-virtualization.git/commit/?id=c01273e001d033678bde91bc215cb05fd15e95cf'/>
<id>urn:sha1:c01273e001d033678bde91bc215cb05fd15e95cf</id>
<content type='text'>
With:
https://lists.openembedded.org/g/bitbake-devel/message/17508
there are many WARNINGs from this layer will cover src_uri.inc files
in next commit.

Signed-off-by: Martin Jansa &lt;martin.jansa@gmail.com&gt;
Signed-off-by: Bruce Ashfield &lt;bruce.ashfield@gmail.com&gt;
</content>
</entry>
<entry>
<title>docker: enable docker.service by default</title>
<updated>2025-03-13T18:38:18+00:00</updated>
<author>
<name>Bruce Ashfield</name>
<email>bruce.ashfield@gmail.com</email>
</author>
<published>2025-03-13T18:35:54+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-virtualization.git/commit/?id=2ea9f1593932b9ded5846e7ae1b0770b5cfdf8c7'/>
<id>urn:sha1:2ea9f1593932b9ded5846e7ae1b0770b5cfdf8c7</id>
<content type='text'>
Some platforms are seeing long (2+ minute) start times to
get the docker daemon initialized.

This doesn't happen when the daemon is started on boot.

To avoid this usability issue, we enable both the socket
and service automatically.

Signed-off-by: Bruce Ashfield &lt;bruce.ashfield@gmail.com&gt;
</content>
</entry>
<entry>
<title>moby: update to v28.0.1</title>
<updated>2025-03-06T17:17:59+00:00</updated>
<author>
<name>Bruce Ashfield</name>
<email>bruce.ashfield@gmail.com</email>
</author>
<published>2025-03-05T17:56:40+00:00</published>
<link rel='alternate' type='text/html' href='https://git.enea.com/cgit/linux/meta-virtualization.git/commit/?id=2762d232a544a5c3d3497c7933c99df5c3a6b804'/>
<id>urn:sha1:2762d232a544a5c3d3497c7933c99df5c3a6b804</id>
<content type='text'>
Bumping moby to version v28.0.1, which comprises the following commits:

    18143632f7 Revert "contrib/check-config: add ipset related flags"
    558da63444 Jump to DOCKER-INGRESS from DOCKER-FORWARD
    76417bf763 Don't use ipset
    c35159ed7d c8d/manifests: Fix Content size including missing content
    468c2c814d Fix swarm network creation from a config-only network
    8e6cc4ac48 Fix swarm net validation for config-from networks
    8cc4d1d4a2 Fix daemon startup on a no-IPv6 host
    341cafa611 Test with a drop rule appended to filter-FORWARD
    984a610a21 Add chain DOCKER-FORWARD
    21582b84fb c8d/list: Fix empty Manifests for some images
    6b1b170708 c8d/inspect: Fix image not found error for index-only image
    5ced8fd377 vendor: tags.cncf.io/container-device-interface v0.8.1
    a92d20bcc4 Better error message for missing ip_set kernel modules
    73f2a5336d libnet/d/bridge: fix compilation on i386
    013c43fb56 Mark default-bridge-only opts in --help and manpage
    3cf4ff971d Fix network inspect IPv6 gateway address format
    501ce33bab Fix v28 regression `protocol "tcp" is not supported by the RootlessKit port driver "slirp4netns"`
    ccdfac5328 contrib/check-config: add ipset related flags
    ac8b4e3e75 daemon: handleContainerExit: ignore networking errors
    d67f035d31 vendor: github.com/moby/buildkit v0.20.0
    1fde8c4615 builder-next: fix cdi manager
    cde9f0752e vendor: github.com/moby/buildkit v0.20.0-rc3
    b2b55903d0 Dockerfile: fix linting warnings
    a3628f3f8e docs/api: add documentation for API v1.48
    9eccc20a17 c8d/list: Fix panic when listing images
    4e97729f14 c8d/list: Test with SharedSize = true
    322eddfb41 api/swagger: remove custom example from /containers/{id}/json endpoint
    60539d0956 api/swagger: remove custom example from /containers/json endpoint
    119b52f302 golangci-lint: ignore "nested context" (fatcontext) in tests
    15fbd67407 Dockerfile: update golangci-lint to v1.64.5
    7b6c3ebe7b api/swagger: inline Exec example values
    2fc90096bf project: update status of branches
    bd92f2bb92 daemon/logger/splunk: New(): combine switches for format validation
    eac39ffdb8 daemon/logger/splunk: remove some intermediate variables
    9bb3900c30 daemon/logger: Info.ExtraAttributes: make env-var handling conditional
    cbbff10b01 daemon/logger: use consistent name for "extra attributes"
    ba559c4f12 daemon/logger/fluentd: fix minor (linting) issues
    b9e7e82b66 daemon/logger/splunk: plunkLogger.postMessages(): improve logs
    2f82cbb5f8 daemon/logger/splunk: suppress some unhandled errors
    f049d0c66b daemon/logger/splunk: don't defer in a loop
    0d938b6bb3 daemon/logger/splunk: rename var that shadowed import
    529a56d31a container: Container.StopSignal: fix handling of invalid signals
    ef0fe1ac00 container: define defaultStopSignal as a syscall.Signal
    0a4c4c9e82 container: some cleanups in view tests
    49f2320bc7 container: some cleanups in tests
    07aa4d96ea container: TestReplaceAndAppendEnvVars: assert with gotest.tools
    0914e97df2 container: rename test file
    9bcac6d573 c8d/progress: Fix panic when pulling some images
    acc4d45278 container: ensure image manifest is deep copied from the container into the snapshot
    903ba2f487 client: Move opts to separate files
    b9319f64ed client: Change ImageSave to use functional options
    ae4c688fd8 client: Change ImageLoad to use functional options
    85808a6abf client: Change ImageHistory to use functional options
    5719e8edf9 Don't create iptables rules when iptables is disabled
    068aa86c23 client: Group deprecated functions into ImageAPIClientDeprecated
    d1c6550f71 daemon: use structured logs for printing reloaded config, move to cli
    838ae09a23 Dockerfile: update runc binary to v1.2.5
    707d8d80b9 vendor: update buildkit to v0.20.0-rc2
    c9f8758570 golangci-lint: enable reassign linter
    04ae510a1e golangci-lint: enable gocheckcompilerdirectives linter
    179e621019 golangci-lint: enable exhaustive linter
    1f9ada6668 golangci-lint: enable errchkjson linter
    8b2439a383 golangci-lint: enable durationcheck linter
    d62e499bfe golangci-lint: enable dogsled linter
    75fc4de8c3 golangci-lint: enable asasalint linter
    7218a64e87 golangci-lint: enable wastedassign linter
    55b047e49c golangci-lint: enable fatcontext linter
    a97d6fe84f golangci-lint: enable nosprintfhostport linter (again)
    fc09a52d85 golangci-lint: enable spancheck linter
    a0ef452f0c golangci-lint: enable mirror linter
    0de3c1b7e3 golangci-lint: enable makezero linter
    e6e68278f6 golangci-lint: enable iface linter (with default settings)
    c8ee8c6302 golangci-lint: enable nilnesserr linter
    081fac187e golangci-lint: enable exptostd linter
    927e07e46e API: add Platform (OS and Architecture) to /containers/json
    e364e28ec8 vendor: update buildkit to v0.20.0-rc1
    d47eb241bf vendor: github.com/vishvananda/netlink 655392bc778a
    47ff7969b4 Add experimental feature warning for image mount
    3e51818c5c Add ability to return warnings from host config
    c5b226e377 vendor: github.com/miekg/dns v1.1.61
    56a6383883 api: deprecation of "error" and "progress" fields in streaming responses
    e36fb45eec vendor: github.com/spf13/pflag v1.0.6
    bd13fc37b0 pkg/jsonmessage: JSONMessage: fix deprecation of ProgressMessage, ErrorMessage
    66910da5a3 vendor: github.com/containerd/go-cni v1.1.12
    3d72df0e89 vendor: google.golang.org/grpc v1.69.4
    72c91e378d client: remove serverResponse and use http.Response directly
    b99b5422b0 api/types: deprecate IDResponse
    96dc9cb693 Don't log a warning when an IP address is already in an ipset
    b23b8f1567 Restore more iptables rules on firewalld reload
    9a20edf7b6 api/types/container: introduce ExecCreateResponse type
    0df3a0047a api/types/container: introduce CommitResponse type
    be1ac5d8e5 api/types/container: rename ContainerTopOKBody to TopResponse
    f4dc38cd36 api/types/container: rename ContainerUpdateOKBody to UpdateResponse
    85ff36de26 Dockerfile: update docker CLI to v28.0.0-rc.1
    cc6754f3fa Dockerfile: update buildx v0.20.1
    b90a2bac7d Dockerfile: bump gotest.tools/gotestsum v1.12.0
    c786cdf124 update authors and mailmap
    b4af9341af client: fix deprecation comment for ImageInspectWithRaw
    6ba4e78066 vendor: gotest.tools/v3 v3.5.2
    43532eb1e1 daemon: Daemon.Containers: make switches exhaustive (exhaustive)
    10ebdbbb92 daemon: Daemon.ProcessEvent: make switches exhaustive (exhaustive)
    f448d5ae3b daemon/events: make switches exhaustive (exhaustive)
    d9cf097402 daemon/cluster/executor/container: make switches exhaustive (exhaustive)
    bf3b4d4986 daemon/cluster/convert: make switches exhaustive (exhaustive)
    4d8dfc1409 daemon/cluster: make switches exhaustive (exhaustive)
    6929a3fd22 libnetwork/networkdb: make switches exhaustive (exhaustive)
    827f84d3ef volume/mounts: parseMountSpec: make switch exhaustive (exhaustive)
    0ee343222b daemon: eventTimestamp: make switch exhaustive (exhaustive)
    b343d235a0 container: State.conditionAlreadyMet: make switch exhaustive (exhaustive)
    8a35300b4a integration/internal/swarm: make switch excaustive (exhaustive)
    66ab2e9e77 plugin/executor/containerd: Executor.ProcessEvent: make switch excaustive (exhaustive)
    1a047bbe8b libnetwork: ignore unchecked json (Un)Marshal errors (errchkjson)
    63deb55263 libnetwork/drivers/bridge: bridgeEndpoint.UnmarshalJSON: fix unhandled errors (errchkjson)
    ccbcce2169 daemon/logger/templates: ignore unchecked error (errchkjson)
    32153dee9f daemon: Daemon.Reload: fix unhandled errors printing config (errchkjson)
    664558f916 daemon/cluster/convert: tmpfsOptionsToGRPC: ignore unchecked error (errchkjson)
    4a7f891fc3 integration/plugin: fix unhandled errors in tests (errchkjson)
    196a66a643 integration-cli: fix unhandled errors in tests (errchkjson)
    26d30159f7 libnetwork/driverapi: ignore unchecked error (for now) (errchkjson)
    b87c9fb3f4 libnetwork/diagnostic: ignore unchecked error (errchkjson)
    7dbceec8aa api/server/router/volume: fix unhandled errors in tests (errchkjson)
    07e2fc83ae pkg/plugins: fix "Multiplication of durations" (durationcheck)
    1ffbcb566b pkg/jsonmessage: fix "Multiplication of durations" (durationcheck)
    eac45daf06 runconfig: fix declaration has 3 blank identifiers (dogsled)
    09c5a01346 pks/plugins/pluginrpc-gen: fix unused value assign (wastedassign)
    a4dba91424 daemon/containerd: fix unused value assign (wastedassign)
    f1d7bd60ab integration/image: TestRemoveByDigest fixed unused values (wastedassign)
    9f8eafc101 plugin: withFetchProgress work around "nested context in loop (fatcontext)"
    e9c90834fa opts: host:port should be constructed with net.JoinHostPort (nosprintfhostport)
    0bf8c8b99e pkg/tailfile: avoid allocations with (*os.File).WriteString (mirror)
    4e6c91cc56 pkg/pools: avoid allocations with (*bufio.Writer).WriteString (mirror)
    f0a233bdc3 pkg/archive: avoid allocations with strings.Compare (mirror)
    17f32e8822 libnetwork/internal/resolvconf: avoid allocations with bytes.NewBufferString (mirror)
    0c8d086ed3 libnetwork: avoid allocations with regexp.Match (mirror)
    6ff3dfd88a integration-cli: avoid allocations with (*os.File).WriteString (mirror)
    405ce2ef15 distribution/xfer: avoid allocations with bytes.NewBufferString (mirror)
    d50492a70d container/stream: avoid allocations with (*bytes.Buffer).WriteString (mirror)
    dbf2cdd06c integration/networking: fix append to non-zero initialized length (makezero)
    dd8ee9eeb1 libnetwork/cnmallocator: fix append to non-zero initialized length (makezero)
    8e9fce7970 libnetwork/bitmap: fix append to non-zero initialized length (makezero)
    f9890d97d1 libnet: kvstore/boltdb: fix append to non-zero initialized length (makezero)
    1f7d497a99 errdefs: remove duplicate "causer" interface definition (iface)
    1784026740 client: custom trace options
    cab2157182 Dockerfile: update golangci-lint to v1.63.4
    f34a1aafe9 vendor: cloud.google.com/go/compute/metadata v0.5.2
    9c7112d118 daemon: configureMaxThreads: remove unused arg
    9e77d05967 add //go:build directives to prevent downgrading to go1.16 language
    192431cb35 pkg/idtools: un-deprecate Windows consts for now
    5a703c2eda libnet/osl: scan ns ifaces to generate ifname
    78b0475605 libnet/osl: AddInterface: un-alias props into local vars
    56a7817b2d libnet: add support for custom interface names
    6a8360012c libnet/osl: distinguish dstName &amp; dstPrefix
    2e9e7989f8 cmd/dockerd: initBuildkit: return close-func
    2dc03f934f cmd/dockerd: refactor buildkit init in daemon startup
    9509f27e28 rootless: use `getsubids` tool for validation if possible
    a096045678 all: Replace deprecated ImageInspectWithRaw usage
    3d37537f75 c8d/inspect: Add Manifests field
    639a1214fa client/image-inspect: Introduce client opts
    6664f1220a c8d/inspect: Avoid interim images.Image conversion
    bdb6a7abdc c8d/list: multiPlatformSummary
    d4fa252cd3 Wait for a route to ff02::1 before sending NAs
    1126d477fd Add live-restore tests for mount image
    90aea3b85f Add image subpath mounting functionality
    634951457d Implement GwAllocChecker for the remote network driver
    12756071f1 update to go1.23.6
    294df1c447 volumes/service: OpErr: implement go1.13 unwrapper
    db68c99d4b distribution: fallbackError, notFoundError implement go1.13 unwrapper
    b96b14d078 cluster/executor/container: exitError: implement go1.13 unwrapper
    2997c0ddc0 client: deprecate CommonAPIClient interface
    846b2272e6 client: deprecate ErrorConnectionFailed helper
    e93ff742e8 client: doRequest: use errors.As for error-detection
    3725998e7d client: define interface for all Swarm-specific methods
    a57d737a86 client: define separate interface for HijackDialer
    902c06fdf0 client: make setupHijackConn a regular function
    e6dabfa3b1 client: move resetting mediaType for hijack to where applicable
    b0e206b807 client: separate Dialer() implementation from public API
    fcb924712b integration/internal: JobComplete: require shallower interface
    0f04532956 errdefs: touch-up godoc for helpers
    329b2a26f3 client: normalize and validate empty ID / name arguments to fail early
    844797348e Implement image mount for the snapshotter
    8c58934106 Implement mount from image
    c935a4609d Fix typo in API docs
    30e75b8396 client: improve handling of JSON error-responses with incorrect schema
    9a6e96fd9c Before sending ARPs/NAs, check the bridge is ready
    8e529682af builder: wire up new gc types for buildkit prune functionality
    52ea449c55 daemon: Daemon.restore: make legacy-link code conditional
    9a69161992 daemon: remove Daemon.children(), Daemon.parents() wrappers
    513fd86710 daemon: Daemon.getNetworkedContainer: fix errors for invalid network container
    51cb066ec8 daemon: Daemon.rmLink: don't fuzzy-match container when using ID
    79b0e89628 github: Clarify release notes description
    c43aa0b6aa Fix concurrency issue in dind
    7ac0e34dba gha/validate-pr: Also run when PR has new commits
    9b5a51a881 api/types/container: remove use of errdefs package in test
    02eb72380f client: remove uses of pkg/errors in tests
    3f354e8c1b api/types/registry: use stdlib errors package
    0ca0ccd37a client: improve test-coverage for error-responses
    9fdcde7618 Add bridge gateway mode "isolated"
    97b50bca2c client: WithVersion: strip v-prefix when setting API version
    bbaa8af8f3 libnetwork/drivers/bridge: un-export errors
    3f9698e1f6 libnetwork/drivers/bridge: TestLinkDelete: use gotest.tools
    74fd2ec0cf libnetwork/drivers/bridge: TestLinkCreateNoEnableIPv6: use gotest.tools
    6e9ba725f8 libnetwork/drivers/bridge: TestLinkCreateTwo: use gotest.tools
    bf3323fd40 libnetwork/drivers/bridge: TestLinkCreate: use gotest.tools
    7012e3ce14 libnetwork/drivers/bridge: remove NonDefaultBridgeExistError
    47f6d4e1bc libnetwork/drivers/bridge: internalize ErrInvalidGateway
    3a9f4e0146 libnetwork/drivers/bridge: remove ErrInvalidMtu
    2f42aa0e26 libnetwork/drivers/bridge: remove IPv4AddrNoMatchError
    0c1b660048 libnetwork/drivers/bridge: remove IPv4AddrAddError
    dc52ecb1d0 libnetwork/drivers/bridge: remove ErrNoIPAddr
    77261b5e42 libnetwork/drivers/bridge: remove "InternalError()" method from errors
    2766298f49 libnetwork/drivers/bridge: remove unused errors
    59c2d2a4b3 libnetwork/drivers/bridge: remove ErrInvalidDriverConfig
    6bb9f581a5 libnetwork/drivers/windows: remove ErrUnsupportedAddressType
    54a969d1a4 Dockerfile: Use CLI generated completions in the dev shell
    510e6f4f8a libnetwork/options: rewrite tests with gotest.tools
    af9ffb64cd builder/dockerfile: more consistently put "expected" on the right
    86a8bfdce4 remove redundant uses of api/types/strslice.StrSlice
    d216084185 libnet/d/bridge: drop remote connections to port mapped on lo
    27adcd596b libnet/d/bridge: port mappings: drop direct-access when gw_mode=nat
    8474153e13 integration: accessing mappings from another docker network
    a7e6d0a8a3 libnet/d/bridge: releasePortBindings: append directly into 'errs'
    aa3a23d4f9 Temporary debug for unsolicited NA
    49b1ed6d27 libnetwork: remove ErrInvalidName
    a98ecc5f79 libnetwork: remove ErrInvalidID
    548b0b6290 libnetwork: remove ErrNoSuchEndpoint
    7cc81407aa Add trace/logging in waitForIfUpped
    30601d96b7 Dump daemon logs when TestAdvertiseAddrs fails
    8705018705 daemon/cluster/executor: containerConfig: store Network instead of envelope
    90323ae123 daemon/cluster/executor: networkCreateRequest: not a method
    f5f4a062a5 daemon/cluster/executor: networkCreateRequest: slight DRY cleanup
    16770340ea daemon/cluster/executor: networkCreateRequest don't shadow config
    cef6fd2fa2 libnetwork: remove Network.EndpointByID as it must not be used
    4e6535fd3e man: vendor github.com/cpuguy83/go-md2man/v2 v2.0.6
    5c1fe287fc libnetwork: remove UnknownNetworkError
    8f4c98e1eb libnetwork: TestControllerGetSandbox: use errdefs for error asserts
    d34ca256b8 libnetwork: TestNetworkConfig: use gotest.tools for errdefs assertions
    c6f0fe5fc0 libnetwork: parallelTester.Do: use errdefs for error assertions
    11a6cb5fac libnetwork: TestEndpointJoin: use gotest.tools for errdefs assertions
    ea7d17376e libnetwork: TestInvalidRemoteDriver: use gotest.tools for error assertions
    01c87cc809 libnetwork: TestContainerInvalidLeave: use gotest.tools for errdefs assertions
    9472c860de libnetwork: TestEndpointMultipleJoins: use gotest.tools for errdefs assertions
    ab9d250876 libnetwork: TestEndpointDeleteWithActiveContainer: use gotest.tools for errdefs assertions
    56debcfc1c libnetwork: TestNetworkQuery: use gotest.tools for errdefs assertions
    874fb4d2f4 libnetwork: TestControllerQuery: use gotest.tools for errdefs assertions
    53bf2e8960 libnetwork: TestUnknownEndpoint: use gotest.tools for errdefs assertions
    895ee1214a libnetwork: TestDuplicateEndpoint: use gotest.tools for errdefs assertions
    678a8a27f5 libnetwork: TestUnknownNetwork: use gotest.tools for errdefs assertions
    9304d98757 libnetwork: TestDeleteNetworkWithActiveEndpoints: use gotest.tools for errdefs assertions
    01b0fe1172 libnetwork: TestNetworkName: use gotest.tools for errdefs assertions
    24df497674 libnetwork: TestNilRemoteDriver: use gotest.tools for errdefs assertions
    532d36c251 libnetwork: TestUnknownDriver: use gotest.tools for errdefs assertions
    400ad04c74 libnetwork: TestNull: use gotest.tools for errdefs assertions
    3bb40af036 dockerd: enable shell-completion; add (hidden) completion subcommand
    816f3fa516 integration: remove assertAttachedStream, check both STDERR and STDOUT
    2197549e4f daemon: health: getShell: simplify logic (LCOW remnants)
    d3c0825439 daemon: make daemon.getEntrypointAndArgs a regular function
    65120d586b Create bridge veth in container netns
    b3b9e990ee Get netns before calling moveLink
    357fb9d58d Add trace/logging in waitForIfUpped
    203d6530d0 libnetwork: use gotest.tools assertions
    a39bee9b71 libnetwork: suppress some unhandled errors in tests
    376ff6add6 libnetwork: use assert.Check in defers
    71c9a45672 libnetwork: use assert.NilError (step 2)
    231012996f libnetwork: use assert.NilError (step 1)
    6bb69a21bf EnableIPv4:false is no longer --experimental
    9a37ae3657 Test unsolicited ARP/NA on interface creation
    bc130f367d bridge/macvlan endpoints always use a random MAC address
    a900e0b5bb libn/netutils: put more entropy into random MACs
    422e056b0f Treat failure to send an initial ARP/NA as an error
    522016a842 Configurable count and interval for gratuitous ARP/NA messages
    eaa84bc8f4 Send unsolicited ARP/NA requests when bringing up interfaces
    2f84e2b208 libnetwork/drivers/bridge: driver.configure: move vars close to where used
    3955c021ff libnetwork: remove redundant type conversion
    41d502892d libnetwork/drivers/bridge: remove redundant type conversion
    6e6cf999ed libnetwork: remove isNotfound test-utility
    c9c322785c libnetwork: Controller.defaultGwNetwork: use errdefs to check for not-found
    59722228d7 libnetwork/types: compareIPMask: make error more readable
    768b152494 libnetwork/types: TestUtilGetBroadcastIP: use gotest.tools, table-tests
    06ae35afb9 libnetwork/types: TestUtilGetHostPartIP: use gotest.tools, table-tests
    9e11ea9287 libnetwork/types: TestCompareIPMask: use gotest.tools, table-tests
    85cd2b7c94 libnetwork/types: TestErrorConstructors: use errdefs for asserting
    afcf1b92a5 libnetwork: TestErrorInterfaces: use errdefs helpers to check error-types
    2b4aa5eb52 gha: update DCO check to alpine 3.21
    9dab00554d libnetwork/driverapi: fix GoDoc for UpdateIpamConfig
    52d2d28148 libnetwork/types: align error-types with errdefs
    836a5fac10 Dockerfile: update compose to v2.32.4
    b75a75017d Dockerfile: update buildx to v0.20.0
    1e2a828ed5 Dockerfile: update docker CLI to v27.5.0
    c52c68a709 vendor: update buildkit to v0.19.0
    366f2b563d Clarify code/comments in defaultipam.newPoolData
    bc93bba099 Use addrset.AddrSet instead of bitmap.Bitmap in IPAM
    7e247e8b13 Add addrset.AddrSet to track a set of IP addresses
    46e290fec6 Don't increment "unselected" in Bitmap when clearing a 0
    5e9ee1a849 gha: Adjust release branches
    ae0fda655b update to go1.23.5 (fix CVE-2024-45341, CVE-2024-45336)
    fc7caf96d2 Revert "libnet/d/bridge: port mappings: filter by input iface"
    f658ea3152 Fix parsing of user/group during copy operation
    131441b37f daemon: NewDaemon: align max backoff delay with containerd 2.0
    76a496a482 daemon/links: fix duplicate env-vars and cleanup range-detection
    fcdd6f4ad2 daemon/links: fix port-ranges with mixed protocols
    251c68c647 daemon/links: fix port-sorting with mixed protocols
    3d37d54b8c daemon/links: Link.ToEnv: simplify adding default port env-var
    c508919b7c daemon/links: add BenchmarkLinkMultipleEnv
    3b27e36d67 daemon/links: add EnvVars function
    b54053d5da daemon/links: NewLink: simplify map to string conversion
    53fec9813f daemon: Daemon.setupLinkedContainers: don't fetch linked containers if not used
    6b14bdb7c7 daemon/config: validate network-diagnostic-port
    370c7a30e2 libnetwork/diagnostic: rename methods
    16cc0be0e1 libnetwork/diagnostic: move and improve logs for starting/stoping
    8f1a49fa8c libnetwork: Controller: remove redundant mutex for diagnosticServer
    e4abcad7ac libnetwork/diagnostic: make EnableDiagnostic, DisableDiagnostic idempotent
    e899092b25 libnetwork/diagnostic: make DisableDiagnostic idempotent
    1e6449dfc7 libnetwork/diagnostic: print newline after stackdump log path
    8cc0e11823 libnetwork: un-export Controller.DiagnosticServer
    bf7a87a15a docs: clarify fromImage vs tag behavior in ImageCreate
    aa565ec1ef Dockerfile: update RootlessKit to v2.3.2
    f3f9641f5d vendor.mod: github.com/rootless-containers/rootlesskit/v2 v2.3.2
    912a64e22a vendor.mod: golang.org/x/sys v0.29.0
    e8c6e7ceb0 build: don't print warning when connection was terminated
    52774154c9 distribution: continueOnError: handle context cancellation / timeout
    6b5f14a7bb distribution/utils: WriteDistributionProgress simplify check for broken pipe
    61aa1657f7 layerStore.registerWithDescriptor: improve logs for cleaning up cache
    e7bd60ee2d Allow users to ignore missing br_netfilter
    66e6a0b7a1 vendor: update buildkit to v0.19.0-rc3
    21870ad796 daemon: NewDaemon: update grpc options for containerd 2.0
    22c02219de Bridge: on network delete, make sure it's deleted from store
    feb2dabaa9 Ignore error when adding a bridge already in the ipset
    0fad8324a8 libcontainer/supervisor: monitorDaemon: move options inline again
    29ce3633e5 libcontainerd/supervisor: remove grpc options that are the default
    b750eb87cd daemon: NewDaemon: remove grpc options that are the default
    e94114305e daemon: NewDaemon: align grpc options with containerd's defaults
    80b0570445 spelling fix in comments
    8c236de735 ci: switch from jenkins to gha for arm64 build and tests
    c817ea2159 api/server/middleware: log before, not after the request
    d86920b9b3 ci(bin-image): fix bake build
    078c5edcd7 Adjust test to support cgroupv1
    c75e333b6f Satisfy linter
    ce3e34816a Add support for bare `writable-cgroups` security-opt
    f8187c0214 Error on invalid requests for writable-cgroups
    bc7d118fd7 Adjust TestCgroupRW to test output before exit code
    081b9d97db Update TestCgroupRW with subtests + nil case fix
    b5b5b7e983 integration/container: test the writable-cgroups security option
    e3cdd59a82 daemon/&amp;container/: enable `--security-opt writable-cgroups=true` as an option
    b1ea8032fa api: swagger: document StatsResponse
    9ed85f487d daemon: don't discard "invalid parameter" errors for archive endpoints
    c6d8a93d58 daemon: containerExtractToDir: remove handling for read-only paths on windows
    ca0158b235 daemon: containerExtractToDir: combine checks for read-only target
    0530750d7e daemon: containerExtractToDir: remove named error return
    9ed662e72e daemon: containerExtractToDir: remove handling for copyUIDGID on windows
    ca06b222e3 api/types/container: merge Stats and StatsResponse
    16cbb27e4e use StatsResponse instead of Stats in tests
    390cb4c2f1 Increase integration test timeout from 5m to 10m
    0aa8fe0bf9 Update to containerd v2.0.2, buildkit v0.19.0-rc2
    a63602472d Use local cleanup method rather than dependency
    3db60168e7 pkg/ioutils: remove crypto/sha256, crypto/sha512 imports
    f68eb9c3cb vendor: github.com/Microsoft/hcsshim v0.12.9
    488d6972b2 vendor: github.com/stretchr/testify v1.10.0
    2008799026 vendor: k8s.io/klog/v2 v2.130.1
    adec695d36 vendor: github.com/fsnotify/fsnotify v1.7.0
    1ef5957089 vendor: github.com/vbatts/tar-split v0.11.6
    de86c46158 vendor: github.com/containernetworking/cni v1.2.3
    6dd592bd49 vendor: github.com/containerd/go-cni  v1.1.11
    2ea97aec2d vendor: github.com/containerd/ttrpc v1.2.7
    cc120c4c05 testutil: update to semconv v1.26.0
    6439c46e06 vendor: github.com/containerd/errdefs v1.0.0
    f40b92272c vendor: github.com/AdamKorcz/go-118-fuzz-build v0.0.0-20231105174938-2b5cbb29f3e2
    eb592fecad vendor: github.com/AdaLogics/go-fuzz-headers v0.0.0-20240806141605-e8a1dd7889d6
    48e6b4e8f7 vendor: otel v0.56.0 / v1.31.0
    d60f164e21 vendor: github.com/creack/pty v1.1.24
    a78b84c212 vendor: github.com/aws/aws-sdk-go-v2 v1.30.3
    d5fe43335f vendor: google.golang.org/grpc v1.68.1, google.golang.org/genproto
    5066658f39 vendor: golang.org/x/oauth2 v0.23.0
    81d5487330 vendor: cloud.google.com/go/compute/metadata v0.5.0
    433b1f9b17 libnet/d/bridge: port mappings: filter by input iface
    49ec488036 logger/fluentd: remove deprecated fluentd-async-connect option
    d560704c91 libnet/d/bridge: init driver.nlh in newDriver
    5a6a980dad daemon/export: Stop when context is canceled
    15df1c9c40 imageService: Remove PerformWithBaseFS
    2f60d15ddf Internal macvlan networks don't need a gateway address.
    8b13cde274 L3 and internal ipvlans don't need a gateway address
    43f71fb582 Bridge - skip gateway allocation if no gateway is needed
    38e76ebea9 Only allocate a gateway if the n/w driver wants one
    64006f964a Simplify selection of gateway address
    24f09ef13c Update MAINTAINER file email for laurazard
    e26122c609 pkg/ioutils: remove unused NewReaderErrWrapper
    2b4db9383c pkg/archive: nosysFileInfo: implement tar.FileInfoNames to prevent lookups
    ce8d3d1c78 pkg/ioutils: remove deprecated NopWriteCloser
    39f1abb1fb pkg/ioutils: remove deprecated NopWriter
    3faa170371 pkg/ioutils: deprecate NopWriteCloser
    7fa3c553e7 pkg/ioutils: deprecate NopWriter
    ad860173a2 vendor: github.com/containerd/containerd v1.7.25
    c12bfda3cd Dockerfile: update containerd to v1.7.25
    d80e3410bc vendor: github.com/containerd/containerd/api v1.8.0
    d23871469b pkg/sysinfo: Remove deprecated `NumCPU`
    cdd4a7429f pkg/ioutils: remove errWriteFlusherClosed
    034cd27da0 pkg/ioutils: remove deprecated NopFlusher
    e183df63f9 pkg/ioutils: remove deprecated WriteCounter, NewWriteCounter
    15ce2914a5 pkg/ioutils: move BytesPipe to container/streams/bytespipe
    8f9c09edd4 Fix unit tests for an nftables host
    818a180fce pkg/ioutils: deprecate NopFlusher
    18f1ecafea c8d/snapshot: Rename variable that collided with import
    15d3c99ff6 daemon: Remove "Error: " error message prefix
    cd9c292de9 imageService: Unify `Mount` and `Unmount`
    0cbb604665 c8d: Implement `RWLayer` and remove `PrepareSnapshot`
    daed0bd4d6 container/rwLayer: Remove unused TarStreamer, ApplyDiff, Size and Name
    85de28901d container/rwLayer: Remove Changes
    bafebbbd8a container: Decouple RWLayer from graphdriver implementation
    383503d382 pkg/ioutils: deprecate WriteCounter, NewWriteCounter
    60971a66b4 pkg/ioutils: deprecate BytesPipe, NewBytesPipe, ErrClosed
    3db72b255d pkg/sysinfo: Deprecate NumCPU
    6d24a21643 improve validation of cpu-shares, and migrate TestRunInvalidCPUShares
    400f1ed95c runconfig: TestValidateResources: use subtests
    93907c904d runconfig: TestValidateResources: fix duplicate test-case
    5b18a7914c deprecate pkg/parsers.ParseKeyValueOpt and move internal
    aad7bcedd2 Dockerfile: update runc binary to v1.2.4
    35932cdeec pkg/ioutils: un-export readCloserWrapper
    392d33c98c image/save: set a stable timestamp for assets
    e324df3f1b image/tarexport: patch MkDirall to accept atime, mtime
    ca962cecfd image/tarexport: add fork of os.MkdirAll (non-buildable commit)
    ee1a15a970 daemon: ImageService.LogImageEvent: pass through context
    ea00e72c21 libnetwork/drivers/bridge: processIPAM: remove unused arg
    f8a973ba4e ci: update bake-action to v6
    586556eda7 runconfig: return correct error-types and touch-up error messages
    fbb421efaa runconfig: cleanup TestDecodeContainerConfig
    c76cab29df runconfig: cleanup TestValidatePrivileged
    ff64a348cc runconfig: fix and refactor TestDecodeContainerConfigIsolation
    7864454792 pkg/ioutils: move atomic file-writers to a separate (pkg/atomicwriter) package
    34ab9570ad daemon/links: TestLinkMultipleEnv: assert with gotest.tools, remove TestLinkPortRangeEnv
    97dc3056c6 Clear RWLayer reference under container lock
    080d8e7d63 daemon/links: TestLinkEnv: assert with gotest.tools
    702df89d9b daemon/links: TestLinkNaming: assert with gotest.tools
    51eb0c6a24 daemon/links: TestLinkNew: assert with gotest.tools
    382fb41563 daemon/links: remove newPortNoError utility
    3fa5e7e6a9 Update internal use of idtools to usergroup
    9c368a93b6 Split internal idtools functionality
    a4ae38b010 Use bridge consts for "DefaultGatewayIPv[46]" aux-addr keys
    0f7a43271c daemon/events: Move metrics to internal/metrics
    90e2afd0be daemon: Move direct usages of go-metrics to internal/metrics
    438f5801e1 daemon/images: Move ImageActions to metrics
    51c2689427 daemon/metrics: Move out to `internal/metrics`
    048fece105 Alias github.com/docker/go-metrics imports
    24ad9bef9d pkg/idtools: rewrite to use moby/sys/user
    f4e2cfa209 libnetwork/osl: Namespace.setSysctls: use stdlib errors
    064cdf475c pkg/parsers: deprecate ParseUintListMaximum, ParseUintList
    39c05177ef Check network connect/disconnect after live-restore
    c2fe1d31e9 Fix live-restore of the osSbox
    a77ee8b9c0 Mark endpoints as "populated" after live restore
    db1ed280f1 Live-restore gw-priority
    9138195cef Rename Controller.sandboxCleanup to sandboxRestore
    1359772433 pkg/sysinfo: parse cpuset.cpus/mems once and memoize
    35fcbc1d1a Test a container attached to l3-ipvlan and bridge networks
    81f6e087c1 Treat connected routes to unspecified addrs like default gws
    725defe1e9 Include iface routes to unspecified addrs when looking for default gws
    0416e31876 Add comments to selectGatewayEndpoint
    1b9c09e10a daemon/logger: un-export RingLogger
    263c46d755 integration/internal/container: IsInState: touch up error-logs
    2282279180 pkg/sysinfo: internalize parsing cpusets
    aa696ffbb1 pkg/sysinfo: touch-up docs for cgroupCpusetInfo.Cpus, Mems
    4597396cb5 pkg/sysinfo: define const for default Max CPUs
    799501d172 pkg/sysinfo: rename vars/arguments for clarity
    0d51680f91 pkg/sysinfo: stub out parsing cpusets on non-linux
    b7ed099727 daemon: isOnlineFSOperationPermitted: cleanup confusing syntax
    fb03a3c403 vendor: github.com/moby/term v0.5.2
    be39e4f732 man: remove --allow-nondistributable-artifacts
    4f9150cee5 Update swarm to latest for server alpn config
    a51baca00d pkg/fileutils: move GetTotalUsedFds internal in daemon
    ba8279bf1f golangci-lint: remove temporary exception for deprecated code
    e45f20352d pkg/fileutils: deprecate GetTotalUsedFds
    a079f62f47 Add testutil daemon.WithResolvConf
    d7f59cec05 daemon/config: add basic validation of exec-opt options
    a646467a66 integration-cli: migrate TestCreateByImageID to integration suite
    5b31a5b370 libnetwork/drivers/windows: fix error-matching for hcsshim "not found"
    1f4c9f23c3 libnetwork/drivers/bridge: format errors with '%v' for consistency
    3b8ba71fe3 libnetwork/drivers/windows: fix non-constant format string
    8c96e45375 distribution: fix non-constant format string
    e451b698d3 golangci-lint: add forbidigo rules to prevent regex.MustCompile
    86e470fe3a daemon/names: use lazyregexp
    b7c88502fb internal/testutils/networking: use lazyregexp
    ae13510577 daemon/logger/awslogs: use lazyregexp to compile regexes on first use
    690e00733e volume/mounts: use lazyregexp to compile regexes on first use
    72ebf2c309 testutil: use lazyregexp to compile regexes on first use
    b5d90d746b registry: use lazyregexp to compile regexes on first use
    b6b19059c5 plugin: use lazyregexp to compile regexes on first use
    0fe953dff0 pkg/idtools: use lazyregexp to compile regexes on first use
    48d63b99ef opts: use lazyregexp to compile regexes on first use
    06948b83f3 oci: use lazyregexp to compile regexes on first use
    98f7c45e7f integration-cli: use lazyregexp to compile regexes on first use
    bc1dbd9ea6 daemon: use lazyregexp to compile regexes on first use
    d61a6924d7 client: use lazyregexp to compile regexes on first use
    0672b3b7f7 builder: use lazyregexp to compile regexes on first use
    43b3aaa62d implement lazyregexp package
    ce37cb3ea0 Down with the sickness (AUTO_GOPATH)
    839b0afbc7 integration/container: use is.ErrorType for some tests
    4504ca6bf6 integration/container: rename vars that shadowed imports
    6b0085eebd integration/container: use consistent name for api-client
    fa0b9f9505 integration/container: use consistent alias for test-container pkg
    547151abd2 pkg/sysinfo: cleanup tests
    25009ed5c0 Restore labels when re-creating Windows networks
    7bd1b64058 daemon/logger/loggertest: remove workaround for OSC string terminator parsing
    5149401665 vendor: github.com/Azure/go-ansiterm faa5f7b0171c
    ddd885a961 daemon: don't repeatedly call NumCPU if not needed
    aa7493f953 daemon: minor cleanups for getting system info
    1c37a4454b daemon: adjust tests for changes in go1.24 JSON errors
    c5575b5119 daemon: add missing "//go:build" directive
    f8524ab041 daemon: remove workaround for  go1.21 compiler bug
    8e9213a6b6 daemon: remove kernel-version check for kernel &lt; 4.0.0
    86a2df8be6 pkg/parsers: rename var that collided with builtin
    cfc988e4da integration-cli: TestRunInvalidCpuset.. create instead of run
    8d5cf1db1e Use the roundtripper during build
    f321120767 daemon: parseSecurityOpt: rename var that shadowed function
    44db31b9cc remove pkg/broadcaster and make it internal to container/streams
    6ab9212168 pkg/ioutils: remove OnEOFReader and move it internal
    be4eac753f Remove use of bufio in cli import tests
    4c251b6b03 Add pool for archive decompress stream
    9189a6e0ab Fix chrootarchive test
    a93a079cb4 Remove use of pools in archive
    8d787e3461 builder/dockerfile: unconvert
    e19e4de775 daemon: ignore some errors when setting env-vars
    c759fb20d6 daemon: remove uses of deprecated system.MkdirAll
    1e060d3315 daemon/graphdriver/windows: remove uses of deprecated system.MkdirAll
    05ec732667 libcontainerd/supervisor: remove uses of deprecated system.MkdirAll
    84bb6e5afb container: remove uses of deprecated system.MkdirAll
    c02c2a3a79 cmd/dockerd: remove uses of deprecated system.MkdirAll
    e783bb5c69 builder/dockerfile: remove uses of deprecated system.MkdirAll
    bc61b31935 pkg/idtools: remove uses of deprecated system.MkdirAll
    4472e9b7f8 pkg/system: deprecate MkdirAll and remove custom volume GUID handling
    e5bf6d8ba0 libnet: pass store as an arg to netdrivers
    93e9f7f75f distribution: Pass Traceparent OTEL HTTP header
    524a63a958 pkg/chrootarchive: remove "// import" comments
    302ca6227f pkg/chrootarchive: use stdlib errors
    727ab584bb vendor: github.com/containerd/cgroups v3.0.5
    275bbcd300 builder: don't fall back to defaultKeepStorage when set to zero
    315891dd2e Remove import comments
    e4236c93d9 Remove unused pkg/system functions
    12b2b56fa6 Update archive to use fs.FileInfo over custom stat
    bb3e95dfdc Update archive to use unix.Mknod directly
    35b9525f9a Update archive to use its own xattr funcs
    1b4cbea3a8 Update archive to use time operations directly
    90fef061ec daemon/c8d: Force c8dimages alias for containerd/images
    8c30e11321 c8d/delete: Consistent method receiver
    1ad78f00b1 daemon/c8d: Fix duplicate containerd/images import
    6bd5840675 vendor: golang.org/x/net v0.33.0
    364e4790e1 docs/api: allow for an empty string for Isolation (api v1.25-v1.47)
    7e9a5064dc api: Remove unused imageStore and layerStore
    c452af6651 image: Remove unused `Details` fields
    d9795da33e image: Remove `GetImageManifest`
    4f5ec9994c pkg/reexec: deprecate and migrate to github.com/moby/sys/reexec
    7fbbd52b0e add Shaun Thompson as curator
    b0be1f3af8 Enable external DNS if a network has an IPv6 gateway
    ec8a5b0f4c libnet/d/bridge: move iptRule to iptables pkg
    1b823fb54e libnet: don't put external DNS answers in OTel spans
    1aecca8bbd docs: Update example section for SwarmJoinRequest
    b6594353f8 libnetwork/iptables: remove deprecated Passthrough()
    d34d092b42 libnetwork/iptables: remove deprecated IPV, Iptables, IP6Tables
    820dea0d2b libnet/d/bridge: hardcode chain names
    bd30a51ea7 libnet/iptables: split ProgramChain and move to bridge driver
    df3c78d061 Combine outgoing and ICC iptables rules
    0f259dd76d Rename setupIPTablesInternal -&gt; setupNonInternalNetworkRules
    556b8eed16 Tidy setupIPTablesInternal
    8fd177d79b pkg/reexec: Command: separate public API from implementation
    6568c06d12 pkg/reexec: make platform-agnostic (again)
    7672d60033 pkg/reexec: use const for name of test binary
    0ef2b24c80 Make libnetwork responsible for DOCKER-USER setup/reload
    9699284e8f Add iptablesdoc for a swarm network
    6473d37002 Run commands in an L3Segment netns without failing the test.
    3bf9a80818 Rename L3Segment Host.Run -&gt; Host.MustRun
    29e20fc904 Add static filter-FORWARD rules during bridge driver init
    5ccc699513 Use golden testdata in TestUserChain
    cd81985bfa vendor: update buildkit to v0.18.2
    d688389f4a libnetwork/iptables: deprecate Passthrough
    8991c4e382 Deprecate BridgeNfIptables and BridgeNfIp6tables fields
    30a365f543 docs/api: version-history.md: fix markdown
    01a55860c6 libnetwork/drivers/bridge: setupIPChains: fix defer checking wrong err
    31fc7dd750 libcontainer: ReplaceContainer: fix var shadowing import
    4e9df46a6e docs/api: document correct case for Api-Version header
    53a9127349 integration/build: make TestBuildEmitsImageCreateEvent less noisy
    504e1d4686 pkg/archive: replace uses of pkg/errors for stdlib errors
    f0ce367e1e pkg/system: deprecate types and functions that are only used internally
    f053beb34c libnet/osl: drop netns path GC
    27deff4da1 libnet/iptables: deprecate type IPV
    c8f19e5e4c libnet/iptables: remove mutex-based serialization
    537eea8744 vendor: golang.org/x/net v0.32.0
    678ef1a267 libnet/d/bridge: unconditionally error out if LinkSetMTU fails
    5c358743af daemon: info: remove bridge-nf-call-iptables / ip6tables warnings
    d8358ebc87 otel: Use non-noop tracer provider for grpc
    96ef85272f c8d/pull: Show `Extracting` layer status
    899360b649 integration/build_traces: Create own tracer provider
    4847557d1b otel: Avoid excessive memory allocations if not configured
    927ff16860 vendor: github.com/opencontainers/runc v1.2.3
    88a08a070e vendor: github.com/cyphar/filepath-securejoin v0.3.5
    ba90fd8da0 Decouple pkg/archive from pkg/ioutils
    ec5c9e06e3 Dockerfile: update runc binary to v1.2.3
    e6443e4af2 vendor: golang.org/x/crypto v0.31.0
    035eeee209 vendor: golang.org/x/text v0.21.0
    df8b3e787c vendor: golang.org/x/sync v0.10.0
    c4f80dd931 vendor: golang.org/x/sys v0.28.0
    8b243a1a82 docs/api: deprecate non-distributable artifacts
    1932091e21 remove support for non-distributable artifacts and deprecate API fields and config
    e394ff695c Dockerfile: remove libbtrfs-dev dependency
    7d79b301bc Dockerfile: remove libsecret-1-dev dependency
    3192b2aba7 Dockerfile: remove libudev-dev dependency
    7c4afb1e6b Dockerfile: remove dpkg-dev dependency
    7bba43a731 Dockerfile: remove libapparmor-dev dependency
    b08ff81204 builder: fall back to defaultKeepStorage if keepStorage is unset for GC policy
    1a453abfb1 integration-cli: don't skip AppArmor tests on SLES
    be9e39b48b registry: ConvertToHostname: use strings.Cut to reduce allocations
    a6f98dc60d registry: Service.lookupV2Endpoints: add arg to skip mirrors
    50215913db registry: loginV2: move variables closer to where they're used
    c1ef39e56e registry: loginV2: don't contact registry when failing to construct request
    a7da6fb2a7 man: vendor: github.com/cpuguy83/go-md2man v2.0.5
    89899b71a0 update xx to v1.6.1 for compatibility with alpine 3.21
    9da0e69608 api/server: Server.CreateMux: pass context and use structured logs
    9c1ff095e8 cmd/dockerd: pass debug-router instead of constructing in CreateMux
    27294df576 api/server: Server.CreateMux: also register API-version debug endpoints
    e2d2834be1 api/server: Server.CreateMux: register debug endpoints with correct methods
    2f5412de8d api/server: set /debug prefix as part of debug-router routes
    694c01620b chore: fix some function names in comment
    76a5ca1d4d Accurately reflect the canonical casing of `API-Version` and `OS-Type` headers
    5fc32c12c7 cmd/dockerd: ignore some unhandled errors
    b0ec823cc7 daemon: remove Daemon.NetworkControllerEnabled
    59bfc32a33 daemon/containerd: hostsWrapper: remove  unused regService argument
    3014d6d7a3 registry: deprecate APIEndpoint.TrimHostName
    fe2637a05b api/types/network: add godoc for EndpointSettings.GwPriority
    15ba03c8fc Jenkins: don't modprobe kernel module
    2af19b6b7c Don't try to modprobe ip6_tables in the moby dev container
    f2e1f52a04 Try to load kernel module ip6_tables, when necessary.
    4740820716 Use ioctl to try to trigger kernel module loads
    56eb47c622 Ignore kernel-assigned LL addrs when selecting "bip6"
    404118c22b vendor: google.golang.org/protobuf v1.35.2
    20ddbe2a0b vendor: golang.org/x/exp v0.0.0-20241108190413-2d47ceb2692f
    1e51b7a28c vendor: golang.org/x/tools v0.27.0
    750d6f4423 vendor: golang.org/x/mod v0.22.0
    99f593b762 vendor: golang.org/x/net v0.31.0
    e5895eacac vendor: golang.org/x/crypto v0.29.0
    fb9977e42e vendor: golang.org/x/text v0.20.0
    115acf7c15 vendor: golang.org/x/sync v0.9.0
    e542dee0a6 vendor: golang.org/x/sys v0.27.0
    8fee8a759f Remove test env var DOCKER_TEST_CREATE_DEFAULT_BRIDGE
    0eb3d431c0 Run tests that change docker0 in their own netns
    52d7e407b7 update to go1.23.4
    504ee465fc vendor: update buildkit to v0.18.1
    4e30acb63f Dockerd rootless: make {/etc,/var/run}/cdi available
    820520affd distribution: verifySchema1Manifest: pass through context
    9a0b61ab29 daemon/daemon_linux.go: Fix a minor typo
    d75394bf77 Wait longer for a stable goroutine count in tests
    dd7831187d Fix typo in waitForStableGourtineCount
    f91afea6ea c8d/commit,import,build: Preserve overriden image
    f0c8becffb c8d/tag: Extract createOrReplaceImage
    0194a18ca8 registry: remove assignment of default values in some tests
    a93f6c61db c8d/tag: Don't log a warning if the source image is not dangling
    28a700bf5b registry: override net.LookupIP per test, not globally
    d17cd847ea registry: isCIDRMatch: don't try to resolve host if not needed
    5f91c769f5 registry: deprecate RepositoryInfo.Class
    3903f71f9f registry: remove deprecated APIEndpoint.Version and APIVersion type
    0bd8738e33 registry: isCIDRMatch: return early if no CIDRs are set
    cce5dfe1e7 Jenkinsfile: modprobe br_netfilter
    59c5919b12 Put --help before --host in the dockerd manpage
    2fbb18ece2 Add --host-gateway to the dockerd manpage
    0aba67203a Implement gateway mode "nat-unprotected"
    07dff11a7e Wrap errors rather than using err.Error()
    d3c2376ff1 cmd/dockerd: change routerOptions.Build to a regular func
    5b752fab32 api: add Priority field to EndpointSettings
    229dc6676c daemon: early-return from buildJoinOptions
    c9f17bedc7 daemon/config: extract validation of userland-proxy config
    83f8f4efd7 daemon/config: deprecate Config.ValidatePlatformConfig
    74a00f183b daemon/config: move utility-functions separate from Config methods
    a4714fa04d daemon/config: verifyDefaultCgroupNsMode: update error message for consistency
    2c000b8ac4 daemon: Daemon.RegistryHosts: use internal method to get daemon config
    16be996b6b ci: use edge releases of buildx
    3e4f437697 cmd/dockerd: newRouterOptions: rename arg that shadowed import
    68a98a7263 daemon: getCD: remove use of parsers.ParseKeyValueOpt
    003e35fea5 libnetwork/ipams/null: gofumpt code
    a8e5a19706 libnetwork/drivers/bridge: gofumpt code
    da5e86a82b daemon: gofumpt code
    fb6e650ab9 integration: add wait
    e7d15d4d58 daemon/graphdriver/zfs: ignore non-existent dataset on removal
    264c15bfc4 Fix br_netfilter module loading logic
    b4769e86a4 vendor: update buildkit to v0.18.0
    b57aa7f3b7 integration: remove default poll delay and timeouts
    c9a1e4dc8c Test host-gateway addresses from docker0
    af0b973595 Allow IPv4 and IPv6 host-gateway-ip addresses
    01e2168c1e Move Linux-only integration/network tests into Linux-only file
    90250ce93a vendor: update buildkit to v0.18.0-rc2
    b7f43c3729 Remove buildkit init timeout
    0b5b1db1c1 Use default ULA prefix if fixed-cidr-v6 is not specified
    fdd2591cbe Separate IPv4 IPAM conf from the rest of default bridge conf
    cc538b2bf0 Drop fixed-cidr if not within user-managed bridge subnet
    311a8bc899 Allow increase of fixed-cidr subnet size
    85159ce09f Allow non-overlapping change of fixed-cidr
    237654a553 Refactor IPAM config for default bridge
    90baa2bc36 Fix selection of subnet from user-managed default bridge
    63b558af77 Don't clear top bits of IP then check if it's global unicast
    facb2323a0 Add tests for IPAM Config of default bridge
    4a2bd1085e Move default bridge test into linux-only file
    46a91a947e api/types/filters: reduce uses of non-exported fields in tests
    cffee85725 api/types/filters: also test generated JSON
    848f11aa7c api/types/filters: rewrite tests with gotest.tools
    4becdaca72 Add label on PrepareSnapshot to warn about non-expiring leases
    eef6b83e53 Update containerd image builder to use lease prune label
    e6170a5c4f Fix lease management during image operations
    1a26e627bc vendor: github.com/vishvananda/netns v0.0.5
    0666d4a585 vendor: github.com/moby/buildkit 94d0f6ed85e5 (master / v0.18.0-rc.2)
    557e4ed83b tests: migrate simple cases to assert.ErrorIs
    caae3c051d tests: migrate to assert.ErrorContains when possible
    1b470d15d8 tests: migrate away from assert.Assert(v == nil)
    0553d3d994 tests: migrate away from assert.Assert(err == nil)
    5e4e34a966 tests: migrate strings.Contains -&gt; is.Contains in assertions
    48b237f7af vendor: update buildkit to v0.18.0-rc1
    44f9eec1ae vendor: github.com/tonistiigi/go-actions-cache 394979b8119e
    1551d95727 vendor: resenje.org/singleflight v0.4.3
    b9a904c48a integration/container: TestCDISpecDirsAreInSystemInfo: use fixtures
    d23bc11b97 vendor: github.com/containerd/continuity v0.4.5
    8cecf3a71c Dockerfile: update containerd to v1.7.24
    a650dbd951 Update containerd to v1.7.24
    821d974789 volume/testutils: simplify fakePluginGetter
    b656cffe4c Disallow "network generic data" with type options.Generic
    223929a44d Test routed n/w inter-network communication
    0546d9084f Routed networks accept traffic from anywhere.
    10338053f0 Don't add default-RETURN rules to DOCKER-ISOLATION chains
    939bc14616 Tidy bridgeNetwork.isolateNetwork
    255fff4acd Propagate error from INC rule setup
    d3b7d84b23 Simplify setINC()
    1a607cf257 Rename gwMode.natDisabled() to gwMode.routed()
    9c9eccfb23 client: support multiple platforms on save and load
    e257856116 Dockerfile: update to runc v1.2.2
    44ed3067ca c8d/container/inspect: Return `ImageManifestDescriptor`
    0020c41e3a daemon: Best-effot container `OS` to `ImagePlatform` migration
    638172417c container: Add `ImagePlatform` field and deprecate `OS`
    60cd165012 Dockerfile/frozen-images: Add amd64 and arm64 hello world
    f303531757 client: ImageImport: omit empty query-parameters
    f96994ec17 Skip tests that are flaky for 4 already
    be36ac13e5 .golanci.yml: rm runc exception
    acf920823b update golangci-lint to v1.62.0
    329d35bcca vendor: github.com/opencontainers/runc v1.2.2
    4b26582bc6 vendor: google.golang.org/grpc v1.66.3
    1eccc326de vendor: github.com/golang-jwt/jwt/v4@v4.5.1
    a333c2990f client: TestImageImport: use table-test, asserts, add platform test-case
    2bab030d6c client: TestImageSave: use table-test, asserts, add platform test-case
    1ea24b7be3 client: TestImageLoad: add test-case for platform
    613538469b client: TestImageLoad: rewrite to use table-tests, use asserts
    b0b6357701 Makefile: don't automatically inherit graph-driver from host
    d88ab0f3a2 c8d/image/inspect: Return `Descriptor`
    c2c0046d11 remove logentries check and migration code
    5ef5ca3adc EnableIPv4 will be in API 1.48, not 1.47
    1a16f5099b daemon/logger: logDriverError: use WithFields for logs
    451fee91c5 libnetwork: add missing go:build tag
    0f0c5eeaca api/server/router/container: add missing go:build tag
    835b1f1063 daemon/containerd: add missing go:build tag
    354dfdb928 Delete /etc/hosts entries on network disconnect
    c1bf84fdbc Move Austin Vazquez (austinvazquez) to maintainers
    82fdae7730 daemon/images: fix godoc for ImageActions
    4a2c48e231 Dockerfile: update compose to v2.30.3
    ee95c7bd89 Dockerfile: update buildx to v0.18.0
    8a81a97af5 Only delete /etc/hosts entries for disconnected network
    b034dc41a2 deprecate pkg/platform and move internal
    b15cd283d8 c8d/list: Return `Descriptor`
    fc590032f3 hack: Add explicit containerd feature to `daemon.json`
    7d89d83485 golangci-lint: enable copyloopvar linter
    d67a21b6fc pkg/idtools: remove redundant capturing of loop vars (copyloopvar)
    3350920788 integration/service: remove redundant capturing of loop vars (copyloopvar)
    70b354713b runconfig: remove redundant capturing of loop vars (copyloopvar)
    1a89c1e4a6 pkg/archive: remove redundant capturing of loop vars (copyloopvar)
    517baee5f2 distribution: remove redundant capturing of loop vars (copyloopvar)
    04d8766d4e integration/network/bridge: remove redundant capturing of loop vars (copyloopvar)
    020b7102e3 daemon/logger/syslog: remove redundant capturing of loop vars (copyloopvar)
    59f68d3f99 api/server/middleware: remove redundant capturing of loop vars (copyloopvar)
    243442280e integration/system: remove redundant capturing of loop vars (copyloopvar)
    bb682f75f9 integration-cli: remove redundant capturing of loop vars (copyloopvar)
    a19b892c29 integration/volume: remove redundant capturing of loop vars (copyloopvar)
    cd5e043aff daemon/cluster/executor/container: remove redundant capturing of loop vars (copyloopvar)
    f797d70649 api/types/container: remove redundant capturing of loop vars (copyloopvar)
    08dbb7a593 integration/build: remove redundant capturing of loop vars (copyloopvar)
    ee54e43bf1 integration/daemon: remove redundant capturing of loop vars (copyloopvar)
    9a7278fbdc integration/capabilities: remove redundant capturing of loop vars (copyloopvar)
    ff97ff8320 daemon/logger/loggerutils: remove redundant capturing of loop vars (copyloopvar)
    67d91e7622 volume/local: remove redundant capturing of loop vars (copyloopvar)
    f7b547ba0d integration/network/ipvlan: remove redundant capturing of loop vars (copyloopvar)
    b5c0f6cd70 daemon: remove redundant capturing of loop vars (copyloopvar)
    d885d097ef libnetwork/ipams/defaultipam: remove redundant capturing of loop vars (copyloopvar)
    7db58fefdc internal/mod: remove redundant capturing of loop vars (copyloopvar)
    74e44345e7 distribution/xfer: remove redundant capturing of loop vars (copyloopvar)
    874ad2fcf0 api/types/filters: remove redundant capturing of loop vars (copyloopvar)
    3a34264129 volume/mounts: remove redundant capturing of loop vars (copyloopvar)
    a505b19170 integration/plugin/common: remove redundant capturing of loop vars (copyloopvar)
    742509150b libnetwork/bitmap: remove redundant capturing of loop vars (copyloopvar)
    082a52e8ac oci: remove redundant capturing of loop vars (copyloopvar)
    e9b009fef5 integration/networking: remove redundant capturing of loop vars (copyloopvar)
    53d78d73e6 integration/container: remove redundant capturing of loop vars (copyloopvar)
    0b2d687b06 daemon/containerd: remove redundant capturing of loop vars (copyloopvar)
    b5b077f2ea api/types/network: remove redundant capturing of loop vars (copyloopvar)
    0fc7b1c201 daemon/cluster/convert: remove redundant capturing of loop vars (copyloopvar)
    6a85a13c0a internal/testutils/specialimage: remove redundant capturing of loop vars (copyloopvar)
    1c6958bf13 integration/network/macvlan: remove redundant capturing of loop vars (copyloopvar)
    88e24ccda6 image/cache: remove redundant capturing of loop vars (copyloopvar)
    89add8c64f libnetwork/drivers/overlay: remove redundant capturing of loop vars (copyloopvar)
    ce1a39ab34 client: remove redundant capturing of loop vars (copyloopvar)
    ea10382ffa integration/image: remove redundant capturing of loop vars (copyloopvar)
    69d0c773ca daemon/logger/fluentd: remove redundant capturing of loop vars (copyloopvar)
    c2e22d85b3 api/server/httputils: remove redundant capturing of loop vars (copyloopvar)
    aea8a0724a integration/network: remove redundant capturing of loop vars (copyloopvar)
    f0b896c5f2 builder/remotecontext/git: remove redundant capturing of loop vars (copyloopvar)
    4768d680d1 libcontainerd/remote: remove redundant capturing of loop vars (copyloopvar)
    443a074fa4 profiles/seccomp: remove redundant capturing of loop vars (copyloopvar)
    93f98535c3 daemon/logger/loggertest: remove redundant capturing of loop vars (copyloopvar)
    35aa84fbc2 pkg/plugins: remove redundant capturing of loop vars (copyloopvar)
    63f0b9a1d5 opts: remove redundant capturing of loop vars (copyloopvar)
    c0de852afa integration/config: remove redundant capturing of loop vars (copyloopvar)
    41bf78226f daemon/config: remove redundant capturing of loop vars (copyloopvar)
    b01a37a6b7 libnetwork/drivers/bridge: remove redundant capturing of loop vars (copyloopvar)
    53e48e8623 libnetwork: remove redundant capturing of loop vars (copyloopvar)
    8b190b16df registry: remove redundant capturing of loop vars (copyloopvar)
    21e1038d12 golanci-lint: sync comments with docker/cli
    b453aa65fa update go:build tags to use go1.22
    bf251c33d0 Only masquerade access to own published ports for userland-proxy=false
    3dea9fd4e6 Add TestFilterForwardPolicy
    3cadadb4eb Add daemon option --ip-forward-no-drop
    5823b05c97 Modify IP forwarding and filter-FORWARD DROP setup.
    a4d74c6383 Move setupIPv6Forwarding() to setup_ip_forwarding.go
    24f53eba7f Move integration/network/bridge_test.go to bridge subdir
    ca273f465a Dockerfile: update registry to v3.0.0-rc.1
    c9570da15b chore(libnetwork): fix some comments
    756586e437 vendor: update buildkit to v0.17.1
    a6e5f7f86b Structured logs in sbJoin/sbLeave and funcs they call
    18327745c0 Allow separate IPv4/IPv6 gateway endpoints.
    869f7996fc Option to disable implicit mapping IPv6 host to IPv4.
    4ac7f14e99 Add EnableIPv4 to the bridge driver
    c0045476b8 all: Remove redundant `units` alias for `go-units`
    20818454c4 update to go1.23.3
    16f6fd1a95 Add a comment explaining host-networking hosts file generation
    7c1e41a06d libnetwork: Sandbox.buildHostsFile: remove intermediate var
    6a5ab42f28 libnetwork/etchosts: Delete: truncate file instead of close and write
    7d98e45a6e libnetwork/etchosts: Add: combine with "mergeRecords()"
    28d029cf9f libnetwork/etchosts: don't panic on invalid regex
    80e4631998 Use netip.Addr instead of string when building /etc/hosts
    c2a09d2721 Don't update /etc/hosts separately for each initial network
    0af6203b46 vendor: github.com/containerd/typeurl v2.2.3
    84965c0752 Windows: Run containerd as managed process
    5014c90516 api/swagger: Improve description for platform in images/push
    7766b35d74 golangci: govet: enable more rules
    24bd11ce22 pkg/plugins: TestLocalSocket ignore deepequalerrors (govet)
    626d9b421b distribution: TestLayerAlreadyExists: fix deepequalerrors (govet)
    06bf2a2699 distribution: manifestStore.Put: fix unusedwrite (govet)
    facdfc1751 daemon/images: onlyFallbackMatcher.Match: fix unusedwrite (govet)
    406e3a0ff7 daemon/containerd: storeJson: fix redundant err-check (govet)
    8e76998aee integration-cli: loadSpecialImage: fix shadowed variables (govet)
    a0b84a34c2 layer: verifiedReadCloser.Read: fix shadowed variables (govet)
    38db7265fc pkg/plugins: loadWithRetry: fix shadowed variables (govet)
    a28e6e2d21 daemon/graphdriver/btrfs: Driver.parseStorageOpt: fix shadowed variables (govet)
    b3705f12cd distribution: pushDescriptor.layerAlreadyExists: fix shadowed variables (govet)
    0c8c098719 libnetwork: Network.rmLBBackend: fix shadowed variables (govet)
    544b1574e2 builder/dockerfile: fix shadowed variables (govet)
    bb9251c46d daemon/containerd: fix shadowed variable in tests (govet)
    979227484f daemon/containerd: ImageService.imageDeleteHelper: fix shadowed variable (govet)
    6dc31171c5 builder/builder-next/exporter: patchImageConfig: fix shadowed variable (govet)
    b019372446 libnetwork/bitmap: fix shadowed variable in tests (govet)
    32aa56af00 pkg/idtools: fix shadowed variable (govet)
    6f3dd5f040 plugin: TestPluginAlreadyRunningOnStartup: fix shadowed variable (govet)
    e46e159001 plugin: Manager.getManifestDescriptor: fix shadowed variable (govet)
    d058e09200 daemon/graphdriver/overlay2: fix shadowed variable (govet)
    ee425a9773 builder/builder-next: fix "id" variable being shadowed (govet)
    79c5b938f4 daemon: Daemon.autoRemove: fix shadowing (govet)
    007daf5045 daemon: Daemon.handleContainerExit rename vars to prevent shadowing (govet)
    738fb74a1a libnetwork/datastore: MockStore.AtomicPut: remove redundant nil check (govet)
    473b1d419c golangci: run gosec on test files as well
    f6d86126c4 distribution/xfer: createChainIDFromParent: ignore G602 false positive (gosec)
    a309e88dff pkg/tarsum: renderSumForHeader: ignore G110 in tests (gosec)
    41b5645ba2 integration-cli: TestDaemonStartWithDefaultTLSHost: fix G402: TLS MinVersion too low
    4bb96a5a4a awslogs: TestNewAWSLogsClientCredentialEndpointDetect: ignore G101 (gosec)
    6f220c3340 daemon/logger/splunk: HTTPEventCollectorMock: fix G114 (gosec)
    79196deae9 pkg/authorization: fix G112 Potential Slowloris Attack (gosec)
    e6e6f0cdca client: TestTLSCloseWriter: fix G112 Potential Slowloris Attack (gosec)
    963a9d7504 integration-cli: ignore some file-permissions issues (gosec)
    7d7412af31 integration-cli: TestRunCreateVolumesInSymlinkDir: adjust file perms (gosec)
    0d1c645919 integration-cli: writeFile: fix file permissions (gosec)
    6ca0d3b1b1 integration-cli: inspectMountPoint: fix implicit memory aliasing (gosec)
    c8e085b56a volume/mounts: TestConvertTmpfsOptions: fix implicit memory aliasing (gosec)
    c3fa5b2e57 integration/plugin/logging: adjust file permissions in test (gosec)
    9fc2b45fa5 fix vendor of github.com/containerd/containerd
    73fae59cef golangci: remove invalid govet config
    1188e80cc5 golangci: move gosec exclusions to linters-settings section
    a0807e7cfe golangci: set go version to prevent fallback to go1.17 semantics
    29e5bfb0f0 golangci: fix deprecated run option
    7809dc08f1 golangci: remove global ignore for EXC0006 / G103 (gosec)
    79e9619412 pkg/archive: ignore G103 (gosec)
    88c178328f libnetwork/drivers/bridge: ignore G103 (gosec)
    62e137377b integration/image: ignore G103 (gosec)
    e567b816d2 golangci: sort linters-settings
    0940460c2f libnetwork: endpointJoinInfo.UnmarshalJSON: fix shadowed variable (govet)
    e601e71681 Remove function isLinkable
    083d595286 client: TestImageHistory: add minimal test for platform
    73fabd5a21 client: TestImageHistory: use fixture for JSON response
    5cfd326aa4 client: Client.ImageHistory: don't decorate error twice
    caf2d5dc7c Change meaning of return from DNSBackend.ResolveName
    ec3dde7001 Only allocate IPv6 addresses if IPv6 is enabled.
    fe856b94b5 Configure network endpoints after creating a container
    788db583b1 Make buildSandboxOption a function instead of a Daemon method
    4c553defce Separate Sandbox/Endpoint construction
    a715ccaaa3 Unconditionally update NetworkSettings
    933fcc9814 Re-remove the SetKey OCI prestart hook
    035b8afe04 chore: fix function name
    330e717403 fix(systemd): start Docker engine *after* DNS resolution is ready
    96039276b6 client: add utilities to encode platforms
    816dbbfddc ci: re-enable firewalld jobs
    8c3945c761 client: rename vars for consistency
    0e72863b9d vendor: update buildkit to v0.17.0
    17b76511d5 Fix: Duplicate event on network disconnect #48797
    fbb595cb66 Remove libnetwork_test.TestMain
    5f39567e56 vendor: github.com/containerd/containerd v1.7.23, hcsshim v0.12.8
    741cc494cd builder-next: exporter: emptyImageConfig: use platform directly
    9be6e902b5 Restore 27.x path for libnet's Bolt database
    2cc21208e6 vendor: update buildkit to v0.17.0-rc2
    cb966073ce container create: add warning for volumeDriver together with mounts
    93255bd748 vendor: github.com/Microsoft/hcsshim v0.12.7
    3dc042b1df vendor: sigs.k8s.io/yaml v1.4.0
    2807c0c2d2 Revert "ci: run integration tests with firewalld enabled"
    db68a019fd c8d/save: Add tests
    3cc736e95c chore: fix some function names
    ba454f573b c8d/inspect: Fix duplicate RepoDigests
    ae87c1d84c remove deprecated pkg/directory
    2054fd99b1 pkg/longpath: remove deprecated Prefix const
    c1652ab357 volume/service: use local driver as default for anonymous volumes
    31880791a4 volumes/mounts: test the actual MountConfig returned
    275609eb37 volumes/mounts: test the actual error returned
    6b0c4b5216 volumes/mounts: don't set "expected" values for fail cases
    e141be8752 volumes/mounts: remove backticks from test logs
    be7d57367b volumes/mounts: remove backticks from errors
    0b290094b5 volume/mounts: windowsParser.ConvertTmpfsOptions don't use runtime.GOOS
    75e8f57579 internal/safepath: Join(): remove workaround for ECI / Sysbox
    4b60c68803 internal/safepath: Join(): log some unhandled errors
    5fc5b0574b internal/safepath: kubernetesSafeOpen: explicitly suppress unhandled err
    4e5c7eeafc daemon: cdiHandler.getErrors: remove var that shadowed import
    0c43bc6891 demon: ImageService.Mount: use structured logs
    5c48736863 remove redundant alias for runtime-spec
    352b4ff2f1 volume: VolumesService.Create: fix log-level for debug logs
    2aaae08ade Cleanup legacy mirror string to registry host
    b3569ebd5a Add HTTP fallback to all insecure registries
    1c34581812 Use daemon config to check for legacy config
    8b4cb6f58c Update host resolver to use containerd host config
    8e0bf25bc3 container: update confusing GoDoc for Container and State
    f2a3acc104 vendor: go.opentelemetry.io/contrib/instrumentation/xxx v0.53.0
    d9a2ca7b49 vendor: go.opentelemetry.io/otel v1.28.0
    070d6c75a7 vendor: google.golang.org/genproto/googleapis/api f6361c86f094
    c2029cb257 Update tmLanguage file to cover first escape character
    95959f7000 vendor: github.com/prometheus/client_golang v1.20.5
    10d57fde44 volume/mounts: fix anonymous volume not being labeled
    7d7089247c api/types/filters: GetBoolOrDefault: remove unreachableCode
    f31188bc4c vendor: github.com/cenkalti/backoff/v4 v4.3.0
    c3cab4170b vendor: github.com/go-logr/logr v1.4.2
    d2557466c6 vendor: google.golang.org/protobuf v1.34.2
    c98c6d4f08 vendor: github.com/Azure/go-ansiterm v0.0.0-20230124172434-306776ec8161
    a6d5b48e67 vendor: github.com/opencontainers/runc v1.2.0
    bb364cc0f3 inte/t/networking: delete veth ifaces before netns
    4ab7644d8d c8d/load: Don't ignore missing platform when requested
    533e7d150a From 28.0.0, don't migrate per-endpoint sysctls.
    b79bba6b68 Remove feature flag "windows-dns-proxy"
    88b90ebbd2 vendor: github.com/opencontainers/selinux v1.11.1
    5c72a95a30 client: prevent idle connections leaking FDs
    0105091745 vendor: github.com/cilium/ebpf v0.16.0
    51dd387bc9 vendor: github.com/cyphar/filepath-securejoin v0.3.4
    6be2074aef daemon: use OwnCgroupPath in withCgroups
    d4159a7e73 ci/gha: enable go caching
    0acdc37a20 container: remove deprecated ErrNameReserved, ErrNameNotReserved
    1dcb7af2cb daemon: remove Daemon.containerRoot, Daemon.newBaseContainer
    7c087c3267 Fork buildkit resolver logic to daemon package
    aba8df74a1 Add TestDirectRoutingOpenPorts
    c9fdeaf70e Explicitly DROP packets for ports/protos that aren't mapped.
    6634fc5136 Allow ICMP in routed mode
    6131322c6f daemon: remove deprecated Daemon.IsPaused
    692024a18c daemon: remove deprecated Daemon.Exists
    3bbb9749f4 c8d/test: Add memoryLabelStore
    3f745f2b21 c8d/list: Extract fake service helpers
    1bb5f8bb67 update to go1.23.2
    a8cd0fc4d4 vendor: go.etcd.io/etcd/server/v3 v3.5.16
    5f994c49e8 vendor: go.etcd.io/etcd v3.5.16
    ac6e32cb5c daemon: deprecate Daemon.IsPaused
    d47c31ffdd daemon: deprecate Daemon.Exists
    d9ae34289a daemon: Daemon.newContainer: explicitly return nil-error
    303530c1f5 daemon: Daemon.newContainer: inline Daemon.generateHostname
    7faaa3afa8 client: explicitly return zero-type on failures in prune functions
    0539b7073e pkg/stringid: optimize GenerateRandomID
    7ebe625db7 pkg/archive: move deprecated NewTempArchive, TempArchive to test-utils
    b313fcb8ff pkg/archive: remove deprecated CanonicalTarNameForPath
    c837027a9c pkg/stringid: replace TestShortenIdXXX with TestTruncateID table test
    83f17b0cbb pkg/stringid: remove deprecated IsShortID, ValidateID
    77f97926ad daemon: remove secretsSupported utility
    c0b86dd068 daemon: remove configsSupported utility
    5208e2954c daemon: deprecate Daemon.Register and make it internal
    d122ea0aea api: GET /images/json: preserve original manifest order
    1aba291cd4 Releases container layer on export
    66f159dc24 build: log when build is cancelled
    cca7085464 cmd/dockerd: Add workaround for OTEL meter leak
    21b0d5f0c1 vendor: github.com/moby/swarmkit/v2 v2.0.0-20241017191044-e8ecf83ee08e
    fafdcd1194 dockerd-rootless-setuptool.sh: let --force ignore smoke test errors
    e7e555f573 distribution: remove formatPlatform utility
    abed0e1f97 client: ContainerResize, ContainerExecResize: don't overflow width/height
    ed44a05607 api: backend.ContainerExecResize: pass context and use uint32 for width, height
    2b2aa69100 api: exec resize: improve errors for invalid width/height
    8553d34593 api: backend.ContainerResize: pass context and use uint32 for width, height
    d19aa0c590 api: container resize: improve errors for invalid width/height
    1dd9d2c780 api/server/httputils: add Uint32Value utility
    0548fe251c Enable bridge netfiltering if userland-proxy=false
    039e164bf5 api/server/httputils: DecodePlatform: improve test-coverage
    a8bfa83667 Fix: setup user chains even if there are running containers
    1701bce9e0 api/server/middleware: use structured logs for debug-logs
    4e840b9e29 volume/service: change some logs to use structured logs
    bca54a6838 daemon: killWithSignal: use more structured logs
    44010e76c2 integration/container: add TestExecResize
    944dc4a559 integration/container: TestResize: add more test-cases
    3f2e9da010 api/server/router/container: move API adjustments to API
    0c595fe781 api/server/router/container: fix inconsistent receiver name
    59cf8e8565 Add iptables doc for a gateway-mode=routed network
    19328fdd4f Add iptables doc for a --internal network
    bc84b4b6d9 Add iptables doc for a network with icc=false
    a8eaeba3f9 Add iptables doc for a network with userland-proxy disabled
    ac4a95d1d0 Add iptables doc for a user-defined network
    20571e453b Generate iptables documentation
    a602054826 daemon: fix restoring containers with name matching an ID
    71977a841c daemon: Daemon.registerName: inline validateID utility
    4e567e1622 ci: run integration tests with firewalld enabled
    8883db20c5 hack: run firewalld when $DOCKER_FIREWALLD is set
    6c6174b371 cmd/docker-proxy: UDP: reply to clients with original daddr
    a0a0bbae6c Discard ErrDumpInterrupted and return data after maxRetries
    3cf90ca73f container: deprecate ErrNameReserved, ErrNameNotReserved
    0200c58c4a container: viewDB.ReserveName, view.GetID: return errdefs errors
    0603bd9577 container: viewDB.withTxn: don't wrap errors
    0d36ab1875 container: TestNames: don't string-match error assertions
    d9627b6159 docs: api: document w (width) and h (height) query params as required
    2a3a7e8ee8 api: document w (width) and h (height) query params as required
    a051aba82e gha: shorter time limits for smoke, validate
    91c448bfb5 gha: use "ubuntu-24.04" instead of "ubuntu-latest"
    9a14299540 gha: dco: small tweaks to running the container
    3cb98d759d gha: dco: update ALPINE_VERSION to 3.20
    7da4ab9a91 README: add some badges
    cfe0d2a131 gha: build (binary), build (dynbinary): limit to 20 minutes
    e75f7aca2f gha: dco: limit to 10 minutes
    4a2361ea09 pkg/authorization: update link to API documentation
    5b149d3faa client: update link to API documentation
    0f8f143a27 docs/api: version-history: update documentation links
    e06245a2a6 client: imageBuildOptionsToQuery: omit "default" networkmode
    b13cf4fc5f client: imageBuildOptionsToQuery: only send "rm" when disabling
    805e2c67e2 builder/builder-next: Builder.Build: use network-mode consts
    740798da34 client: imageBuildOptionsToQuery: omit empty values from query
    c68c9aed8c gha: restrict cross and bin-image to 20 minutes
    7fe04c142d vendor: github.com/moby/buildkit v0.17.0-rc1
    cd551b936b daemon/containerd: getPushDescriptor: fix formatting of platform in errors
    c16be54040 daemon/containerd: touch-up errPlatformNotFound error
    91f74c2fe0 Disable iptables/ip6tables in two tests to remove conflict
    8681b3c2ac images: GetImage: touch-up error message for missing platform
    d31c241ea5 PushImage: remove misleading error about --platform without containerd
    037bac89fc gha: remove stray double empty line
    26049febb2 api: Allow for an empty string for Isolation in Swagger specs This adds an empty string as a valid option for the Isolation field when inspecting a container. On non windows systems, this is always empty, so no error should be returned. Fixes #47452
    6b7e2783d1 gha: add guardrails timeouts on all jobs
    7fa6d3c230 integration/build: remove TestBuildWithSession, and fsutil direct dependency
    2e699872bc vendor: google.golang.org/grpc v1.66.2
    e007ef71c1 vendor: google.golang.org/protobuf v1.34.1
    30b6e58242 vendor: github.com/cespare/xxhash/v2 v2.3.0
    4592ce42b6 vendor: golang.org/x/tools v0.25.0
    36549fb56e vendor: golang.org/x/mod v0.21.0
    cc80652bcd vendor: golang.org/x/net v0.29.0
    9d6db83acc vendor: golang.org/x/crypto v0.27.0
    6e32888caa vendor: golang.org/x/text v0.18.0
    51cf0ed303 vendor: golang.org/x/sys v0.25.0
    6b7565ba40 vendor: go.etcd.io/bbolt v1.3.11
    02d4fc3234 gha: buildkit: make sure expected Go version is installed
    d7ff538467 Fix iptables rule descriptions
    77e51657fe cmd/docker-proxy: re-add SO_REUSEADDR
    38f0483ea7 Set NODAD on bridge IPv6 addresses
    58f4e916a3 build: create distinct history db for each store
    367125e0cc Use `pools.Copy` for archive file copy operations
    2f02f456f5 Fix comments
    fd0d008504 vendor: github.com/vishvananda/netlink v1.3.1-0.20240922070040-084abd93d350
    7ca9e9b496 libnet/d/bridge: port mapping: proxy LL connections
    49ab30ea2c Fix vendoring for moby/docker-image-spec
    7eb508e14c api: postImagesLoad: fix API version for platform
    5875b6e8cf inte/networking: test access to published ports from remote host
    2552782c1d inte/networking: test accessing a published port from the host
    98efe665a5 Log rather than error if port mapping is overspecified
    339592f59b Pass context to the port mapping code
    ca4c68ab95 update to go1.22.8
    c866a7e5f8 daemon/exec: don't overwrite exit code if set
    4babd72186 tests: skip docker-py exec exit code test
    e6488c9c0e runconfig: validateNetContainerMode: simplify validation
    5bdbc2f026 client: ContainerCreate: normalize CapAdd, CapDrop capabilities
    be248d18b5 client.ContainerCreate: use container.CreateRequest instead of local type
    98d74e3a3c Update download-frozen-image-v2.sh added OCI v1 support
    91df504bf1 inte/networking: move port mapping tests into a dedicated file
    6a1d8a9899 daemon: add IPv6 loopback as insecure registry
    7624a6bfa5 Dockerfile: update compose to v2.29.7
    233dce3dba Dockerfile: update docker CLI to v27.3.1
    edcefd4efb libnet/i/kv/boltdb: fail fast in case of contention
    ed08486ec7 libnet/ds: simplify datastore.New()
    3ca91a6a12 libnetwork: unit tests: drop OptionBoltdbWithRandomDBFile
    450200b4a6 gha: add CodeQL Analysis workflow
    32b9e7b8b9 libnet/i/kv/boltdb: remove unused field 'timeout'
    4f1d739de5 gha: govulncheck: make sure read permissions are set
    8c598b1005 cmd/dockerd: runDaemon: extract platform-agnostic code
    5228850225 cmd/dockerd: windows: don't use Fatal log to prevent early exit
    0aebbd0ba9 cmd/dockerd: use golang.org/x/sys/windows/service param-change consts
    b186261b84 cmd/dockerd: un-export DaemonCli, NewDaemonCli
    6f83fda310 cmd/dockerd: construct context in main
    52694ebe16 cmd/dockerd: windows: move setting PIDFile location to setPlatformOptions
    44a3bba2a2 cmd/dockerd: apply options when creating daemonCLI, not when starting
    5c1b037ff5 cmd/dockerd: rename loadCLIPlatformConfig to setPlatformOptions
    1388d959bc cmd/dockerd: set default configfile location as part of newDaemonOptions
    19a8e7ff7e cmd/dockerd: getDefaultDaemonConfigFile: add GoDoc for Windows implementation
    388c0a8cda cmd/dockerd: remove unused error-returns
    1624ae197e cmd/dockerd: move Windows code for data-root
    333cfa6402 Fix merge problem
    db25b0dcd0 Only enable bridge netfiltering when needed
    605f51172a Dockerfile: update compose to v2.29.4
    3d4831a23f Dockerfile: update buildx to v0.17.1
    45a9dde660 man: dockerd: add description for --log-format option
    c4aaa97f02 man: remove docs for deprecated --api-cors-header
    c2fc1f4a40 internal/opts: SetOpts: invalidate empty option-names
    908bb959e7 internal/opts: SetOpts.Set: remove redundant var assignment
    758cca6036 internal/opts: SetOpts,NamedSetOpts: test for optional value
    50e83a0713 man: dockerd: value is optional for --feature flag
    f9c0103413 Do not DNAT packets from WSL2's loopback0
    2b6550bb2e man: fix duplicate word in --feature flag description
    edaa0eb56d Add linting rules to spot use of un-wrapped netlink functions.
    00bf437d84 Add nlutil functions to retry on netlink EINTR
    8b0e94ffaf Update dlv in the dev-env
    3dd96ce3c4 Fix enableIPv4 for old networks
    fa06acc851 man: update dockerd man-page to include --feature flag
    ff191c58f7 api: info: deprecate "Commit.Expected" fields
    f13c08246d Add feature to daemon flags
    fefa98ae90 c8d/prune: Keep deletion order stable
    521fa833fe images: Support platform selection on graphdrivers
    f143f4ec51 image/save&amp;load: Support `Platform` parameter
    ab075ecd10 image/history: Support `Platform` parameter
    5128007116 Explicitly disable nvidia device injection for --gpus=0
    adb00d3d55 TestIPRangeAt64BitLimit: remove colon after XFAIL to help grepping
    23e79a261e c8d/prune: Add OTEL spans
    e4c2eb9d8a c8d/prune: Keep the last tagged image instead of creating dangling image
    962da27cdf Dockerfile: update compose to v2.29.2
    2b43979395 API: bump version to 1.48
    e5e8addeee Dockerfile: update buildx to 0.17.0
    d291722110 Dockerfile: update docker CLI to v27.2.1
    c095dbe512 project: update 23.0 EOL and add 25.0 LTM branch
    43036f350a Dockerfile: update RootlessKit to v2.3.1
    c98aad0518 vendor.mod: github.com/rootless-containers/rootlesskit/v2 v2.3.1
    829aa845bb integration/system: rename vars to prevent shadowing imports
    71e449de0a vendor: update buildkit to v0.16.0
    7263cd226f image/tarexport: saveSession.save: inline variables
    2e4079ff31 image/tarexport: saveSession.save: remove redundant Platform
    ab5c5df1d5 image/tarexport: rename variables that shadowed imports
    5fd3cd2d77 layer: layerStore.deleteLayer(): remove redundant error-check
    f5cc04284d remove deprecated image/spec package
    92195c1333 Dockerfile: update containerd binary to v1.7.22
    b4a3e8a307 vendor: github.com/containerd/containerd v1.7.22
    6f37e5a168 vendor: update buildkit to v0.16.0-rc2
    1161b790cf seccomp: add riscv64 mapping to seccomp_linux.go
    16d686c7bc internal/unix_noeintr: fix godoc for package
    47d5ce0ef8 gha/bin-image: Also run on branches like `27.x`
    09fc6ab2d9 docs/api: update deprecation version for erroneous fields (v1.46, v1.47)
    3df03d8e66 api/swagger: update deprecation version for erroneous fields
    aca38a4218 docs: api: fix documentation for image push endpoint (API v1.25-v1.47)
    07e31e393a api: swagger: fix documentation for image push endpoint
    fb6da4f4b7 daemon/logger/loggerutils: add //go:build directives to prevent downgrading to go1.16
    5403e3f4de libnetwork/networkdb: add //go:build directives to prevent downgrading to go1.16
    928e5aa524 container/stream: Config.CloseStreams(): use errors.Join
    59eba0ae13 Fix typos
    a2e14dd8bd update to go1.22.7
    5ebc179cb1 test: update since session signature has changed
    f4261dbb75 vendor: update buildkit to v0.16.0-rc1
    b5ec31f090 vendor: github.com/opencontainers/runc v1.1.14
    2189aa2426 update runc binary to 1.1.14
    4e0d1dfc17 docs/api: add documentation for API v1.47
    d000f12fcc hack/make/.binary: enable pie mode on windows/arm64
    28dc2f6fac Increase test handler sleep, replace deprecated assert
    c7f8557310 c8d/pull: Same error message for non-matching platform
    f5108e9c6b golangci-lint: temporarily disable G115: integer overflow conversion
    9b11bb507b update golangci-lint to v1.60.2
    3df59c9dcf update to go1.22.6
    4cd5c2b643 hack/make/.binary: set CGO_LDFLAGS=-latomic for arm/v5
    e853c093bf hack/make/.binary: set CCGO_CFLAGS=-Wno-atomic-alignment for arm/v5
    bb899c654a api/types: move RequestPrivilegeFunc to api/types/registry
    88b118688e man: create parent directories in install recipe
    9bbe5a50dd Dockerfile: update registry to v3.0.0-beta.1
    f4e82e2fb0 c8d/list: Don't exclude non-container images
    d6446d81d8 vendor.mod: golang.org/x/net v0.28.0, etc.
    65fdd363a0 vendor.mod: golang.org/x/time v0.6.0
    4bfdfd6f72 vendor.mod: golang.org/x/sys v0.24.0
    78d0ef5e87 vendor.mod: golang.org/x/sync v0.8.0
    492fe40052 vendor.mod: golang.org/x/mod v0.20.0
    d7ff6b5085 vendor.mod: drop direct dependency on golang.org/x/exp
    8e580efb73 portallocator: un-export PortAllocator.Begin, PortAllocator.End
    fb1ae4bdb7 portallocator: RequestPortsInRange: validate range once
    05d784d6da portallocator: make newPortMap a regular constructor
    c00f6281d9 portallocator: RequestPort: skip RequestPortInRange as intermediate
    78d88d06dc portallocator: use net.IPv4zero for defaultIP, and make it a property
    630a47177b portallocator: use new instance in tests
    1897a21d60 portallocator: ReleaseAll: remove unused error-return
    2a2176f317 portallocator: RequestPortInRange: fix doc-link in godoc
    a88efd7359 vendor: github.com/containerd/containerd v1.7.21
    de4fc1c927 Dockerfile: update containerd binary to v1.7.21 (static binaries and CI only)
    1ad5b5abb2 daemon: fix non-constant format string in call (govet)
    005b488506 api/types: fix non-constant format string in call (govet)
    0fd3a53c12 api/server/router: fix non-constant format string in call (govet)
    4a93233b88 container/stream: fix non-constant format string in call (govet)
    068c1bf3be libnetwork/drivers/bridge: fix non-constant format string in call (govet)
    f434cdd14a volume/testutils: fix non-constant format string in call (govet)
    81a1ca0217 builder/dockerfile: parseChownFlag: fix non-constant format string in call (govet)
    b56c58a860 layer: ignore G602: slice index out of range (gosec)
    c308bd3e0e internal/cleanups: fix non-constant format string in call (govet)
    7b60a7047d libnetwork/cnmallocator: fix non-constant format string in call (govet)
    06bfe8bab3 cmd/dockerd: fix non-constant format string in call (govet)
    6008c42ca2 libnetwork: fix non-constant format string in call (govet)
    b79a4696ee integration-cli: fix non-constant format string in call (govet)
    6bbacbec26 integration-cli: DockerSwarmSuite: rm redundant Fprintf, handle errors
    3ca38f0b5e integration-cli: DockerNetworkSuite: rm redundant Fprintf, handle errors
    2b7a687554 integration-cli: use erors.New() instead of fmt.Errorf
    c7b36f8953 libnetwork: TestDNSOptions: remove redundant skip check
    6bd7835cb6 integration-cli: remove redundant platform checks
    0afe684685 c8d/pull: Replace pointer to interface with interface
    db40a6132b c8d/pull: Keep the replaced image as dangling
    6ebe6a7353 c8d/load: Only unpack host platform images
    728894b7d0 c8d/load: Don't fail whole operation if unpack failed
    0db71bb629 vendor: dario.cat/mergo v1.0.1
    2c498c6a74 vendor: github.com/vishvananda/netlink v1.3.0
    6d0a5e31d7 vendor: github.com/vishvananda/netlink v1.2.1
    55f693e7b7 integration/TestAPIImagesListManifests: Check `Containers`
    29a2f6d339 c8d/list: Update benchmark to also have containers
    a5d75f6d27 c8d/list: Fix race condition when traversing containers
    2f0180934d vendor: tags.cncf.io/container-device-interface v0.8.0
    fe307b5dab libnetwork: resolvconf: remove dependency on errdefs
    afdfc04e10 libnetwork: resolvconf: remove var that shadowed import
    6d94122217 logger/journald: plumb contexts into reader
    9b6ba18fc9 logfile: Close reader when caller cancels
    c4ba1f4718 Dockerfile: update xx to v1.5.0
    abcb9e972b libcontainerd/supervisor: set log-level through the config-file
    edfde78355 man: support bringing your own go-md2man
    05d7008419 man: build dockerd man pages using make
    1804f0c911 integration/container: rename var that collided with import
    62bcc6ef50 libcontainerd/supervisor: consolidate platform-specific defaults
    f49fad75eb vendor.mod: github.com/microsoft/hcsshim v0.12.5
    b93cf37dcd c8d/list: Don't require `opts.ContainerCount` for manifest containers
    cd148d39d9 feat(stream): log the event when stream copy failed
    c459986399 vendor: update buildkit to v0.15.2
    6bb6befc37 c8d: Rename readConfig to readJSON
    495fab8e66 c8d/list: Add test for total and content size
    469c2ef3ec c8d/list: Fix `Total` size calculation
    e77e543b58 api/types/registry: fix godoc, and add some doc-links
    218c08b283 plugin: fix deprecation comments
    771377f9fa Test ipvlan IPv6-only
    390713607f Allow ipvlan containers with no address
    b95f8e7799 Fix some ipvlan error types for the API
    660e8118a4 Allow no-IPv4 on an ipvlan network
    8427de3bac Test macvlan IPv6-only
    d599cc5842 Allow macvlan containers with no address
    f57e0dc2ff Fix some macvlan error types for the API
    a7a5de676d Allow no-IPv4 on a macvlan network
    496b457ad8 Allow --ip-range ending on a 64-bit boundary
    9c6d30481d remove leftovers for building docker-proxy on Windows
    3cd28504de govulncheck to report known vulnerabilities
    a308f12ed8 add Austin Vazquez (austinvazquez) to curators
    7b0ef10a9a migrate to github.com/moby/sys/userns
    8411ecb5e3 Makefile: Add BIND_GIT variable
    050afe1e1a api/list: Expose manifests
    f8b638b98f c8d/list: Use ReadConfig helper
    85e9102dc9 api: Bump default version to 1.47
    efb3c50799 swagger: Disable ImageSummary model generation
    b24c2e95e5 update to go1.21.13
    925b484a40 No fallback nameservers for internal resolver
    d29767431c Use host netns for host's ext-dns servers
    344039b9ae Populate DNS records for IPv6-only endpoints
    b4cee5c3ee Removed all mentions of "please" from docs and messages
    f1ec84314d docs: add default-network-opt daemon option
    23812190c3 docs: remove devicemapper
    690d166632 man/dockerd.8: assorted formatting fixes
    374b779dd1 man/dockerd.8: escape asterisks and underscores
    386d0c0fbc docs: update dockerd usage output for new proxy-options
    54971ac807 Fix styling of arguments
    a8b8f9b288 Fix the max-concurrent-downloads and max-concurrent-uploads configs documentation
    68e9223289 docs: remove documentation about deprecated cluster-store
    6c702167bf Document `--validate` daemon option
    af45195a21 Update man-page source MarkDown to work with go-md2man v2
    562a6d2b13 docs: update for cgroup v2 and rootless
    7cf2132655 docker run: specify cgroup namespace mode with --cgroupns
    1cbcd5d47a daemon: document --max-download-attempts option
    3cfa74724c Update document links and title.
    462f38bd8b Allow user to specify default address pools for docker networks This is separate commit for CLI files to address PR 36054
    13ff896b38 Update docs and completion-scripts for deprecated features
    f3c3b05b50 Added docs for dockerd
    20f8455562 fix a number of minor typos
    c23d4b017a Introduce/document new IPC modes
    25baee8ab9 docs: add documentation for dm.libdm_log_level
    7d3f09a9c3 Restore dockerd man page
    ea914a66a2 Use retErr in Network.ipamAllocate
    cdea750966 Tell RootlessKit about port mappings when --userland-proxy=false
    b3fabedecc Create docker-proxy TCP/UDP listener sockets in the daemon
    dac7ffa340 Remove rootlesskit-docker-proxy
    f1e0746c08 Tell RootlessKit about docker-proxy port mappings
    384ca56d90 Fix error type used for ProgramExternalConnectivity
    7a8663c9ea cmd/docker-proxy: drop FrontendAddr() method
    88fb0c9fec cmd/docker-proxy: drop unused BackendAddr() method
    ba2f3c0a98 cmd/docker-proxy: pass open listener to proxy impl
    e0c7a839a8 Only build docker-proxy for Linux
    ee766ae7b1 c8d: Wrap matchRequestedOrDefault result with a platform
    842c5c584e c8d/image: Add `matchRequestedOrDefault`
    6617cdc66b daemon/c8d: Fill wanted platform in GetImageManifest
    427b111943 c8d/history: Unmarshal only a subset of ImageConfig
    b9d04c07c4 c8d: Simplify `presentImages` into `getBestPresentImageManifest`
    23d565cae3 c8d: Improve error message for platform not found
    e73c2a05b2 daemon/c8d: Simplify `presentImages` signature
    af84ddec13 vendor: github.com/containerd/nydus-snapshotter v0.14.0
    1e5c0c4d77 vendor: github.com/containerd/nydus-snapshotter v0.13.14
    dfe36fa226 touch-up security policy
    3b1341972b Only assign an IPv4 address if required
    15e5f6868a Don't auto-allocate IPv4 IPAM if !enableIPv4
    c0a6145f6d Enable IPv4 in the unit tests that will need it.
    b42f4b96aa Check for an IPv6 gateway before connecting to docker_gwbridge
    034a5a8986 Reject swarm n/w creation with IPv4 disabled.
    c91dc7e6dc Reject Windows network creation with IPv4 disabled.
    a86a9e3aa4 API 1.46: end per-interface sysctl migration in major release
    17adc1478b Migrate per-endpoint sysctls until 28.0.0
    d44f869a2d vendor: google.golang.org/grpc v1.62.0
    716ec490db vendor: golang.org/x/time v0.5.0
    ac145a82fd api/types: NewHijackedResponse: fix typo in GoDoc
    80822715cd plugin: fix typos in GoDoc
    1f542d5d6c Set EnableIPv4 for predefined networks
    903daa4dc4 Add flag 'enableIPv4' to libnetwork.Network
    d4d8611164 Added API create/inspect option EnableIPv4
    c7dec1c67a docs/api: swagger: fix x-nullable for SystemInfo.Containerd (api v1.46)
    66b5b8bfa8 api/swagger: fix x-nullable for SystemInfo.Containerd
    3279b4f8f4 hack/make: suppress "not mounted" message
    a23dcf4798 Bump API version to 1.47
    403f9dbc42 project: update supported release branches
    96762a28c7 libcontainerd/supervisor: remove remnants of adjusting oom-score
    2a71815b83 daemon: remove unused import
    2b5ffa0b63 gha: set permissions to read-only by default
    7a92f21445 daemon: isPermissibleC8dRuntimeName: use local utility to reduce c8d deps
    2847c4b7fe libnetwork/networkdb: switch to go-immutable-radix v2
    fca57ac32f Split Linux/bridge and Windows/nat integration tests
    ef8e2fe282 Use retErr in Endpoint.sbJoin
    58808e7748 Remove code to update Network.enableIPv6 if false
    8f1989556a Trivial tidy-up of Endpoint.assignAddress()
    6fe26e0629 Add IPv6 to the null IPAM driver
    dcf922e266 daemon: openContainerFS: log cleanup errors
    aa60f7891b daemon: openContainerFS: rename output var
    3539fef440 daemon: setupMounts: rename var that shadowed import
    a19c2ccc7b daemon: rename "mounts" type to reduce shadowing
    39c79e08e4 daemon: move sortMounts to a platform-agnostic file
    cdbfae1d3e api/server/router/grpc: NewRouter: set correct MaxRecvMsgSize, MaxSendMsgSize
    cd11843df8 images: Extract ImageInspect from GetImage
    1baf8f9e60 vendor: update buildkit to v0.15.1
    2ce811e632 migrate to github.com/moby/sys/user/userns
    91dfc326cf vendor: github.com/moby/sys/user v0.2.0
    1e2ccf8046 vendor: github.com/gofrs/flock v0.12.1
    077b32ac4e vendor: golang.org/x/sys v0.22.0
    4c97ff777d Clean up networks in 'integration/network' tests
    e2237240f5 dockerd-rootless-setuptool.sh: move RootlessKit smoke test
    a3efa3026b contrib/check-config.sh: remove special case for userns on CentOS/RHEL 7
    6d0b508699 daemon: remove setMayDetachMounts (set may_detach_mounts=1 on startup)
    ae96ce866f remove support for setting CORS headers (deprecated)
    dbf6873f45 Logfile: Add tracing spans
    1b46faf233 Logfile: skip files that are corrupted
    77f2d90e27 Refactor logfile reads
    b37c8a03c0 Fix time comparison in sharedtemp implementation
    21fd5a3f30 vendor: github.com/moby/sys/sequential v0.6.0
    e0b98a3222 gha: check-pr-branch: fix branch check regression
    fbbda057ac update containerd binary to v1.7.20
    f460110ef5 gha: check-pr-branch: verify major version only
    6a6b49f2de vendor: github.com/moby/sys/symlink v0.3.0
    68636d56fc vendor: github.com/moby/sys/signal v0.7.1
    44b266ab59 vendor: github.com/moby/sys/mount v0.3.4
    dc4a12874e vendor: github.com/moby/sys/mountinfo v0.7.2
    55a5f3fcaa vendor: github.com/containerd/containerd v1.7.20
    a42f7fd717 Dockerfile: update compose to v2.29.0
    97b51c6b72 Dockerfile: update buildx to v0.16.1
    b37c983d31 README: replace obsolete Docker EE mention
    508939821b daemon/containerd: rm use of regexp
    b66d4b567a image/v1: rm regexp use
    1c0dc8a94f layer: rm regexp use
    499c842c52 hack: explicitly control enabling the journald logging driver
    5282cb25d0 If url includes scheme, urlPath will drop hostname, which would not match the auth check
    2ac8a479c5 Authz plugin security fixes for 0-length content and path validation Signed-off-by: Jameson Hyde &lt;jameson.hyde@docker.com&gt;
    0fa71a4cfc vendor: cloud.google.com/go/logging v1.9.0
    eafad2cb86 vendor: golang.org/x/oauth2 v0.21.0
    9b782b8ff7 vendor: cloud.google.com/go/compute/metadata v0.3.0
    68bd630830 vendor: update buildkit to v0.15.0
    f649fd0c97 Fix API version in TestSetInterfaceSysctl
    7f04a603f6 docs/api: Add missing `
    89781912c1 vendor: update buildkit to v0.15.0-rc2
    8be292a7bb By-default, don't create an iptables rule to checksum SCTP
    1787c364e0 vendor: update buildkit to v0.15.0-rc1
    688301caf4 daemon/graphdriver: remove Capabilities, CapabilityDriver
    185b1e3d69 Add lint rule to forbid old-style atomic ops
    5e64a7a003 volume/service: switch to Go 1.19 atomics
    1c102140f8 libnetwork: switch to Go 1.19 atomics
    46133bdb8e libnetwork/diagnostic: drop unsound use of atomics
    5044778433 distribution: switch to Go 1.19 atomics
    2ab618696a daemon/images: switch to Go 1.19 atomics
    30d740ada0 daemon/logger/ring: switch to Go 1.19 atomics
    7ef0c7acbe d/logger/loggerutils: switch to Go 1.19 atomics
    e612990994 daemon/logger/journald: switch to Go 1.19 atomics
    78893cdc05 daemon/logger/gcplogs: switch to Go 1.19 atomics
    508f51044d daemon/containerd: switch to Go 1.19 atomics
    71a299ff6a daemon: switch to Go 1.19 atomics
    206445fa4f rootless: add `Requires=dbus.socket`
    4776e6dd60 Remove IPv6 bridge RouteAdd() that always fails
    066b7fa83c vendor: golang.org/x/net v0.25.0
    7721408db7 vendor: golang.org/x/crypto v0.23.0
    f43436e6b8 vendor: golang.org/x/text v0.15.0
    342ce515ab vendor: golang.org/x/sys v0.21.0
    2e58a29023 vendor: github.com/klauspost/compress v1.17.9
    fb18966aa5 api/types/container: InspectResponse: keep old name for embedded type
    837289ba62 update to go1.21.12 [part 2]
    4d1d7c3ebe update to go1.21.12
    398e15b7de update containerd binary to v1.7.19
    d0aa3eaccf Migrate to github.com/containerd/platforms module
    8983957ac5 vendor: github.com/containerd/containerd v1.7.19
    73979f3f04 daemon/logger/journald: add //nolint:unused for readSyncTimeout
    ef356c53ba api/types: remove deprecated ContainerNode, ContainerJSONBase.Node
    5b9ed8081b api/types: remove deprecated ImageLoadResponse
    d3defe9140 api/types: remove deprecated ImageImportSource
    6cdb123b6f api/types: remove deprecated ImageSearchOptions
    67b7b15674 api/types: remove deprecated EventsOptions
    3cbc166d2e api/types: remove deprecated container stats types
    ec5cede0a2 api/types: remove deprecated ContainerStats
    4ffe497ba4 api/types: remove deprecated CopyToContainerOptions
    345e31ab96 api/types: remove deprecated ContainerPathStat
    2bceb34717 api/types: remove deprecated ContainersPruneReport
    0e64c9e93b api/types: remove deprecated ContainerExecInspect
    6f0caec226 api/types: remove deprecated ExecStartCheck
    13fbd394ee api/types: remove deprecated ExecConfig
    665eef54db api/types: remove deprecated NetworksPruneReport
    d2256faa0e api/types: remove deprecated NetworkResource
    ffdd2de674 api/types: remove deprecated EndpointResource
    f0f2b8f7cb api/types: remove deprecated NetworkDisconnect
    cf9d9ff50d api/types: remove deprecated NetworkConnect
    39c7b5f3e3 api/types: remove deprecated NetworkInspectOptions
    64583771f0 api/types: remove deprecated NetworkCreateResponse
    c99e0bc8ae api/types: remove deprecated NetworkListOptions
    48f147e8d3 api/types: remove deprecated NetworkCreate
    ff1f1c58d5 api/types: remove deprecated NetworkCreateRequest
    4117a9308d api/types: remove deprecated VolumesPruneReport
    e0156f0f16 api/types: remove deprecated ImagesPruneReport
    1abc8f6158 api/types: move container-inspect types to api/types/container
    05b0e653dd api/types: move Container to api/types/container
    84ffc644ef api/types: move ContainerState to api/types/image
    7053007f71 api/types: move ImageInspect and RootFS to api/types/image
    da039ca918 api/types: move GraphDriverData to api/types/storage
    e12b7493b9 api/types: move Port to api/types/container
    5517322cf9 api/types: move MountPoint to api/types/container
    c130ce1f5d api/types: move container Health types to api/types/container
    df22a511cb api/types: move container-networksettings types to api/types/container
    53bc396ef4 c8d/build: Log `image tag` event when image was built with Buildkit
    1506bbcfe8 builder-next: Add ImageNamedByBuildkit callback
    bce76d486e builder-next: Don't return error from exported callback
    e4d792a06d api/types/system: remove Info.ExecutionDriver
    0f3273e71a daemon/graphdriver: move RefCounter to an internal package
    efdaca2792 pkg/rootless/specconv: move to internal
    b7d26f2f8f pkg/dmesg: remove deprecated package
    3a3bb1cb50 pkg/directory: deprecate, and move to internal
    80900bdbcd pkg/directory: fix comment, and remove import comments
    e55897977c daemon/graphdriver: simplify Checker, remove NewFsChecker, NewDefaultChecker
    554db8f113 daemon/internal/fstype: make FsMagic values not platform-dependent
    49f6e004f1 daemon/graphdriver: move FsMagic utilities to an internal package
    09f62a8a61 runconfig/opts: remove deprecated ConvertKVStringsToMap
    4a30231d05 runconfig: remove deprecated IsPreDefinedNetwork
    ed712ad0b9 runconfig: remove deprecated DefaultDaemonNetworkMode
    13984ef185 runconfig: remove deprecated SetDefaultNetModeIfBlank
    6e2b6399d7 runconfig: remove deprecated ContainerConfigWrapper
    d80a3f2e48 pkg/capabilities move to daemon/internal
    625c795785 errdefs: FromStatusCode(): use early returns
    81be279c6b daemon/logger, volume/drivers: remove redundant import-aliases
    f2970e5358 pkg/containerfs: move to internal
    a3e6ce95c4 pkg/containerfs: cleanup GoDoc, and make Windows a proper wrapper
    e2ae6907c6 pkg/containerfs: remove CleanScopedPath and make it internal
    fa150ca759 cleanup: Remove unnecessary return value
    a2fe103f0d vendor: github.com/microsoft/hcsshim v0.11.7
    dfbcddb9f5 Fix incorrect validation of port mapping
    4de54ee14c Fix duplicate subnet allocations
    6521057bb2 daemon/graphdriver/overlay2: set TarOptions.InUserNS for native differ
    969993a729 pkg/archive: createTarFile: consistently use the same value for userns
    379ce56cd8 pkg/archive: handleTarTypeBlockCharFifo: don't discard EPERM errors
    af85e47343 pkg/archive: getWhiteoutConverter: don't error with userns enabled
    080a8e1b6b libcontainerd: gofumpt
    56fa45773f pkg/plugins: gofumpt
    0e2d40c24a pkg/archive: gofumpt
    84e43da752 libnetwork: gofumpt
    bb1b766ddb layer: gofumpt
    07469b4509 internal: gofumpt
    8e50a96a78 integration: gofumpt
    c3ac7fee26 integration-cli: gofumpt
    e765dd90ee daemon: gofumpt
    181101c4a8 daemon/containerd: gofumpt
    46b0102da4 daemon/config: gofumpt
    4a89963f1e builder: gofumpt
    8768145519 api/types: gofumpt
    92346bcec6 api/server: gofumpt
    6ada1cff02 fix some gofmt issues reported by goreportcard
    84cabde357 daemon/graphdriver: deprecate GetDriver(), and remove its use
    b7896056c1 daemon/graphdriver: New(): update GoDoc
    25d12b54d3 daemon/graphdriver: combine GetDriver and getBuiltinDriver
    3928165cf7 Dockerfile: update docker CLI to v27.0.2
    555dac5e14 daemon/graphdriver: remove support for external graphdriver plugins
    bc4991e443 layer: rename vars that shadowed imports
    0ed172b700 daemon/graphdriver: rename vars that shadowed imports
    bbced07f96 builder/builder-next: applySourcePolicies: remove redundant check and vars
    790035f754 Dockerfile: update compose to v2.28.1
    95fae036ae update golangci-lint to v1.59.1
    d4160d5aa7 pkg/archive: reformat code to make #nosec comment work again
    04bf0e3d69 builder/remotecontext: reformat code to make #nosec comment work again
    1fc9236119 api/types: deprecate ContainerJSONBase.Node, ContainerNode
    ca396dfaaa awslogs: Prevent close from being blocked on log
    9893520c62 libnetwork: Mark flaky tests
    d0d8d5d97d hack/unit: Rerun failed flaky libnetwork tests
    a52aab8598 project,vendor.mod: document more clearly that we are not a Go module
    1e28299f77 project: document currently known packagers
    f502f49e49 project: document modern branch and tag practices

Bumping docker-cli to version v28.0.1, which comprises the following commits:

    d75f8d83d Add detailed descriptions for --ulimit options in docker run documentation
    75595836f vendor: github.com/go-jose/go-jose/v4 v4.0.5
    4e7497e9c Update dockerd command line ref, default bridge opts
    be669099c Update dockerd command line ref, changes in 28.0
    427c1361c gha: add docker 28 to test matrix
    aad2ae50e docs: network ls add heading and anchor for "--no-trunc"
    8a1b096e7 docs: fix missing anchors in swarm reference pages
    c99d3312e docs: fix broken anchor-link in "container restart" reference
    0cff34098 cmd/docker: do not print error status on exec/run
    8f5573857 completion: add completion for docker service flags
    768d10767 completion: add completion for docker node flags
    d5e6e2ec6 completion: add completion for node names
    7e71782ba cli/command/context: fix error-handling of skip-tls-verify
    762d59359 completion: use service names, and support DOCKER_COMPLETION_SHOW_SERVICE_IDS
    33f327a98 vendor: github.com/docker/docker v28.0.0-dev (af898abe4466)
    f977b923c Fix missing link from Configure node healthcheck heading
    f53cee5dd vendor: github.com/docker/docker v28.0.0-rc.3
    fe349e6a6 vendor: github.com/docker/docker 00ab386b5a2e (master, v28.0.0-rc.3)
    136901961 vendor: github.com/docker/docker v28.0.0-rc.2
    a8affefee golangci-lint: replace deprecated `tenv` linter in favor of `usetesting`
    1c8243cc9 golangci-lint: fix invalid nakedret config, disallow for any func length
    a5020ea16 cli/command/container: don't use naked returns (nakedret)
    e569b9f74 cli/internal/oauth: don't use naked returns (nakedret)
    3e9fa43ef cli/command/trust: fix "usetesting" linting errors
    aca0bd775 cli/command/trust: fix "usetesting" linting errors
    b2f3c1249 Dockerfile: update golangci-lint to v1.64.5
    2b169c1ab golangci-lint: enable revive "line-length-limit" linter
    a67c65657 golangci-lint: enable revive "unused-receiver" rule
    71c40dfa7 golangci-lint: sort revive rules
    a35b899df cmd/docker: fix "unused-receiver" linting
    1a4491f8c cli/command/stack: fix "unused-receiver" linting
    994e1b7ca cli/command/service: fix "unused-receiver" linting
    5ef673bb1 cli/command/system: fix "unused-receiver" linting
    e71380eb5 cli/command/container: fix "unused-receiver" linting
    4827fdef9 cli/command/trust: fix "unused-receiver" linting
    3e44cc4d0 cli/command/image: fix "unused-receiver", "line-length-limit" linting
    e2f28fac4 cli/command/registry: fix "unused-receiver" linting
    a54d356a7 cli/command/swarm: fix "unused-receiver" linting
    25e6b2da0 cli/command/formatter: fix "unused-receiver" linting
    450768c31 cli-plugins/manager: fix "unused-receiver" linting
    e5f3cc14c internal/test: fix "unused-receiver" linting
    1b3718f45 cli/command: fix "unused-receiver" linting
    d27f6a61a cli/registry: fix "unused-receiver" linting
    72b32c69c internal/test/notary: fix "unused-receiver" linting
    ba3f4fb41 cli/internal/oauth/manager: fix "unused-receiver" linting
    f0f19c6d4 cli/trust: fix "unused-receiver" linting
    c8bd0a7e5 cli/manifest: fix "unused-receiver" linting
    20b4ab366 cli/compose: fix "unused-receiver" linting
    1e7add9f4 cli/internal/oauth/api: fix "unused-receiver" linting
    9b62e5740 cli/config/configfile: fix "unused-receiver" linting
    f79193c22 opts: fix "unused-receiver", line-length-limit linting
    d0c3380ce cli/connhelper/commandconn: fix "unused-receiver" linting
    fdc665820 cli/config/credentials: fix "unused-receiver" linting
    88b2e78e0 internal/tui: fix "unused-receiver" linting
    20c15cee9 cli/compose/loader: shorten skip-comment to please the linters
    cac88ca34 cli/command: wrap some long lines (revive)
    eef4127de cli/internal/oauth/manager: ignore line-length-limit
    d8e76bc33 cli: define const for magic value
    9fda9134a cli/command/service/progress: define const for magic value
    3825d3792 cli/command: define some consts for repeated values
    2f65cf7d1 cli/command: fix some unused-receiver linting
    a368e3eb5 cmd/docker: fix unused-receiver (revive)
    add32e4b5 cli/compose: Handle Volume Subpath
    4cc2dce80 cli/compose: Fix Image Subpath
    e868f0f58 cli/command/container/opts_test: Fix entrypoint parsing logic
    c2ba77de4 vendor: github.com/docker/docker 57d4d23825f4 (master, v28.0.0-rc.2)
    1d3eb6f95 vendor: github.com/docker/docker 5cc3f1dab895 (master, v28.0.0-rc.2)
    591fcb273 vendor: golang.org/x/sys v0.29.0
    1edc4e07d gha: Mirror PR template and validate PR workflow from moby
    a656dfd40 Restrict completion for some commands with a limit paramter for ImageNames
    04b1b4e08 Add image mount options
    c6a7f9a64 vendor: github.com/docker/docker b570831cc3a3  (master, v28.0.0-rc.2)
    018bf1b23 vendor: google.golang.org/grpc v1.69.4
    558ebd592 vendor: github.com/spf13/pflag v1.0.6, remove local IPNetSliceVar fork
    2c17edf80 cli/connhelper/commandcon.New: pass context with WithoutCancel
    61a3b4bd5 Remove preceding white space from cobra help template
    1acf32cdc Dockerfile: dev-container: update buildx v0.20.1
    bb74513ef Dockerfile.dev: bump github.com/josephspurrier/goversioninfo to v1.4.1
    7b3f264a6 Dockerfile.dev: bump mvdan.cc/gofumpt to v0.7.0
    aecc31039 Dockerfile: bump gotest.tools/gotestsum v1.12.0
    e1a9d1cd3 Dockerfile: update golangci-lint to v1.63.4
    df8c19d8f vendor: gotest.tools/v3 v3.5.2
    3c0d703ac vendor: github.com/docker/docker/v28.0.0-rc.1
    2815d2337 add //go:build directives to prevent downgrading to go1.16 language
    01da8a582 vendor: github.com/docker/docker 6c3797923dcb (master, v28.0-dev)
    76e0088b5 minor cleanup
    85a77af59 Don't print "context canceled" if user terminated
    7e83ff773 bump version to v28.0.0-dev
    6d7afd48a login: improve text on already authenticated and on OAuth login
    1d9d349c1 update to go1.23.6
    81da375c4 cli/command/service: runScale: use errors.Join, and cleanup
    09b513ecf cli/command/service: runRollback: remove intermediate vars
    aa96cb7aa cli/command/volume: use errors.Join
    be985bd28 cli/command/stack/swarm: use errors.Join
    f1193effc cli/command/service: use errors.Join
    f9e433556 cli/command/secret: use errors.Join
    2a9fd4a93 cli/command/node: use errors.Join
    f8729c6da cli/command/manifest: use errors.Join
    1fd9d0dd3 cli/command/manifest: pass manifest-store and handle context
    f431f6156 cli/command/inspect: use errors.Join
    7147e85f6 cli/command/image: use errors.Join
    2b9a4d5f4 cli/command/context: use errors.Join
    150f27b68 cli/command/container: use errors.Join
    791e06b43 cli/command/config: RunConfigRemove: use errors.Join
    632f179e8 cli/command/image: minor cleanups
    e81d76ffe cli/command/container: minor cleanups
    deaa60118 cli/command/config: minor cleanups
    c950d48f7 image/tree: Chips to represent "in use"
    c51be7776 cmd/docker: add cause to user-terminated `context.Context`
    8169a5142 jsonstream: Display: rename var that shadowed type
    a4288003b service/progress: ServiceProgress: avoid fuzzy matching service ID in loop
    e88b1939f service/progress: newReplicatedJobProgressUpdater: slight cleanup
    dea59eabb cli/command/stack/swarm: waitOnServices remove redundant check for multi-error
    37b25f226 cli/command/plugins: runRemove: fix incorrect use of errors.Join
    007e88ec3 TestCheckpointCreateWithOptions check both "keep-running=true/false"
    31b819828 cli/command/volume: TestVolumeCreateClusterOpts: minor fixes and refactor
    5b8c08d19 cli/command/volume: TestVolumeCreateCluster: minor fixes and refactor
    a8265e72b cli/command/volume: TestVolumeCreateWithFlags: minor fixes
    8b5e5539e cli/command/volume: TestVolumeCreateWithName: minor fixes and improvements
    2e266001c cli/command/volume: TestVolumeCreateErrors: assert unhandled errors
    987da0957 cli/command/volume: remove example and var for long description
    13ef82974 cli/flags: suppress some errors
    dc5a4501a cli/command: minor cleanups: use Println, suppress errors
    cd6d902df cli/command/inspect: remove additional newline from log
    10f5b3f73 cli/command/volumes: minor cleanups: use Println, rename vars
    299aae041 cli/command/trust: minor cleanups: use Println, rename vars
    5cfc89c1c cli/command/system: minor cleanups: use Println, rename vars
    8c5e85d4c cli/command/swarm: minor cleanups: use Println, rename vars
    925b8fe34 cli/command/stack: minor cleanups: use Println, rename vars
    aa74f931d cli/command/service: minor cleanups: use Println, rename vars
    016dbef44 cli/command/registry: minor cleanups: use Println, rename vars
    53aed6119 cli/command/plugin: minor cleanups: use Println, rename vars
    35e74d58e cli/command/node: minor cleanups: use Println, rename vars
    886f2295c cli/command/network: minor cleanups: use Println, rename vars
    5d3bdf8ac cli/command/manifest: minor cleanups: use Println, rename vars
    c8f27b027 cli/command/image: minor cleanups: use Println, rename vars
    a0ca41e6f cli/command/formatter: suppress some errors
    82e2efbbf cli/command/context: minor cleanups
    c462eaee1 cli/command/container: minor cleanups: use Println
    8650ffef3 cli/command/checkpoint: minor cleanups: use Println, rename vars
    b10b79e6f cli-plugins: minor cleanups: use Println
    2e26ce145 e2e/testutils: remove uses of pkg/errors in tests
    4de5e9212 internal/test: remove uses of pkg/errors in tests
    c55b39a2e cli/config/credentials: remove uses of pkg/errors in tests
    832f5fa2c cli/compose/convert: remove uses of pkg/errors in tests
    45d81f849 cli/command: remove uses of pkg/errors in tests
    a85a94f46 cli/command/system: remove uses of pkg/errors in tests
    694d24800 cli/command/swarm: remove uses of pkg/errors in tests
    8b09ee1e1 cli/command/stack: remove uses of pkg/errors in tests
    ec5ae0c2d cli/command/secret: remove uses of pkg/errors in tests
    c50068f7e cli/command/plugin: remove uses of pkg/errors in tests
    2b02e05f9 cli/command/node: remove uses of pkg/errors in tests
    38f61539e cli/command/network: remove uses of pkg/errors in tests
    d6c26471d cli/command/manifest: remove uses of pkg/errors in tests
    f29fdd309 cli/command/image: remove uses of pkg/errors in tests
    d30c894af cli/command/idresolver: remove uses of pkg/errors in tests
    5a99ea9ad cli/command/container: remove uses of pkg/errors in tests
    0d913efe8 cli/command/config: remove uses of pkg/errors in tests
    957be84a3 cli/command/checkpoint: remove uses of pkg/errors in tests
    10aca7dd5 cli/command/volume: remove uses of pkg/errors in tests
    a87cb974f remove dockerd man-page (moved back to moby repository)
    6ab9b92aa Makefile: add "shell-completion" target
    0760e8513 Dockerfile: update to alpine 3.21
    2c35778a6 Allow '--link' with '--network bridge'
    1546f023f Dockerfile: update compose to v2.32.4
    7b0724270 Dockerfile: update buildx to v0.20.0
    91adb70d6 pkg/command: wrap `jsonmessage.DisplayJSONMessagesStream` with go context
    81b0bb58b gha: Adjust release branches
    3c0691146 update to go1.23.5 (fix CVE-2024-45341, CVE-2024-45336)
    26010e4c3 image/tree: Print longest names first and use full width
    f906139fc cli/tree: Use single character triple dot
    4c2fece0c cmd/docker: enable cobra completion descriptions
    48dbdc6f2 fix(dockerfiles): Update CMD instruction in 'Dockerfile.dev' to use exec form instead of shell form
    58bf0f184 switch to gopkg.in/yaml.v3
    9abd0ebdf cli/command: update semconv to 1.26.0
    2f42b3272 vendor: otel v0.56.0 / v1.31.0
    3d9b86116 vendor: github.com/mattn/go-runewidth v0.0.16
    aa540679e vendor: github.com/containerd/platforms v1.0.0-rc.1
    d3ca99585 vendor: github.com/creack/pty v1.1.24
    b412f7199 vendor: google.golang.org/grpc v1.68.1, google.golang.org/genproto 324edc3d5d38
    7244f7d42 update cli-docs-tool to v0.9.0
    6f3ba987b vendor: github.com/docker/cli-docs-tool v0.9.0
    97a14c456 update go-md2man to v2.0.5
    acbdad955 completion: replace fluentd-async-connect with fluentd-async
    3da5f5893 docs: mark logger opt 'fluentd-async-connect' as removed
    0df55307c vendor: github.com/docker/docker 69687190936d (master, v28.0-dev)
    cc571902b ci: update bake-action to v6
    987befaea gha/build: Publish bin image for release branches
    216674c3e vendor: github.com/docker/docker 50212d215ba7 (master, v28.0-dev)
    bf2dae22d cli/command/plugin: runCreate: minor cleanup
    a289f11ac vendor: github.com/moby/swarmkit/v2 v2.0.0-20250103191802-8c1959736554
    7e8f94903 docs, man: remove --allow-nondistributable-artifacts flag
    760326694 contrib/completion: remove --allow-nondistributable-artifacts flag
    2334df110 Deprecate configuration for pushing non-distributable artifacts
    2fc32c707 vendor: github.com/moby/term v0.5.2
    e1a0c377b vendor: github.com/Azure/go-ansiterm faa5f7b0171c
    f42c0ccd0 contrib/completion: remove deprecated --api-cors-header
    2db88599f contrib/completion: remove --oom-score-adj daemon flag
    eb5c507cd docs: dockerd: --oom-score-adj flag
    7b37f30da Use io.copy for build context compression
    7b7a4c020 docs, man: remove confusing example for "--isolation"
    25f02bc04 vendor: github.com/docker/docker 6f6c3b921180 (master, v28.0.0-dev)
    8c0cb3051 Fix cp test to separate source and destination
    c8c47b1dd golangci-lint: depguard: prevent uses of pkg/system
    76ec0ea2e vendor: github.com/docker/docker a72026acbbdf (master, v28.0.0-dev)
    a8f83d5d9 TestRunCopyFromContainerToFilesystem: use Tar without options
    0c04dc05b golangci-lint: sync some depguard settings with moby/moby
    cc65127cb vendor: github.com/docker/docker ad6929339acd (master, v28.0.0-dev)
    6f47bce41 vendor: golang.org/x/net v0.33.0
    83156e662 vendor: golang.org/x/net v0.32.0
    450f6b995 vendor: golang.org/x/crypto v0.31.0
    b74302eb5 vendor: golang.org/x/text v0.21.0
    cb2e35286 vendor: golang.org/x/sync v0.10.0
    e56b665d8 vendor: golang.org/x/sys v0.28.0
    1eda49878 cli/command/container: use local copy of pkg/system.IsAbs
    ffe0354c2 cli/command/system: remove BridgeNfIptables, BridgeNfIp6tables in tests
    73ff81b65 cli/command/system: TestEventsFormat: set cmd.Args to prevent test-failures
    55e404e7a cli/command/system: remove netfilter warnings from tests
    eaa8b5716 update go-md2man to v2.0.5
    b8fd20517 Makefile: use go1.22 semantics for gofumpt
    6a2cde6c7 Add option '--ipv4'
    5c896c95d Docs: emphasise that some options that are for docker0
    a5353e55d Docs: include --fixed-cidr-v6 and --bip6 docker0 options
    1e51ae7af update xx to v1.6.1 for compatibility with alpine 3.21
    b39f48287 update golangci-lint to v1.62.2
    2a5ac8f5a vendor: github.com/docker/docker b249c5ebd214 (master, v28.0.0-dev)
    afab76501 registry/client: remove uses of APIEndpoint.TrimHostName
    7dab597e6 tests: cleanup comment
    30c4637f0 run: don't hang if only attaching STDIN
    2eb77f4ed vendor: github.com/docker/docker 5d72419486fe (master, v28.0.0-dev)
    b51a71148 cli/command/system: don't use "non-distributable-artifacts" fields in tests
    f50dea6c4 vendor: google.golang.org/protobuf v1.35.2
    9399483f7 vendor: golang.org/x/net v0.31.0
    6751bcc97 vendor: golang.org/x/crypto v0.29.0
    d41ab7703 vendor: golang.org/x/term v0.26.0
    5972025fa vendor: golang.org/x/text v0.20.0
    feb1e2a34 vendor: golang.org/x/sync v0.9.0
    4c27c895f vendor: golang.org/x/sys v0.27.0
    a1e57ac72 update to go1.23.4
    e398d16c0 cli/command/registry: return status only instead of whole response
    297afb2a2 cli/command/registry: TestLoginWithCredStoreCreds slight refactor
    575e37366 cli/command/registry: rename some vars that collided with imports
    d4db289eb run, create, connect: add support for gw-priority
    cf89afb32 cli/command/registry: storeCredentials: accept configfile as arg
    b5a00d0b0 cli/command/registry: loginWithRegistry: use shallower interface
    13f0d4641 cli/command/registry: don't return creds on error
    a3d9fc494 run: cleanup – remove `errCh` nil check
    446f36ce5 run: cleanup – move "detached" early exit earlier
    843129882 run: cleanup – use `attached` where applicable
    aee9eebf3 run: return error code when only STDIN attached
    ed9fcf31e cli/trust: GetNotaryRepository: remove uses of RepositoryInfo.Class
    c629eca89 Put --help before --host in the dockerd manpage
    ea84e8f94 Add --host-gateway to the dockerd manpage
    cf88ab074 Docs: host-gateway-ip daemon option IPv4+IPv6
    ae54c9d97 Add --bip6 to the dockerd manpage
    1911dedcf Add --ip-filter-forward-drop
    0f058041c docs: fix janky rendering of toc on docs.docker.com
    fcd94feef cli-plugins: Simplify addPluginCandidatesFromDir
    6de3d71ab cli-plugins: Fix searching inaccessible directories
    30a73ff19 fix: ctx should cancel image pull on run
    1d4a7ae08 tests: cleanup table test names
    4a219b1a4 chore: update commit guidelines in CONTRIBUTING.md
    d41b80faf vendor: github.com/docker/docker e5c2b5e10d68 (master, v28.0.0-dev)
    11fbc9993 vendor: github.com/tonistiigi/go-rosetta v0.0.0-20220804170347-3f4430f2d346
    b0c0cd5e3 build(deps): bump codecov/codecov-action from 4 to 5
    f6599300f vendor: github.com/go-viper/mapstructure/v2 v2.2.1
    446d4138e vendor: github.com/moby/sys/capability v0.4.0
    07e5ddd05 update golangci-lint to v1.62.0
    93a931920 Dockerfile: bump github.com/josephspurrier/goversioninfo to v1.4.1
    cb2f95cee Optimise `docker stats` to not require clearing the whole screen
    d1d535326 cli/command/container: fix missing go:build tag
    3dd762124 Dockerfile: update compose to v2.30.3
    4242cda82 Dockerfile: update buildx to v0.18.0
    7c80e4f93 update go:build tags to use go1.22
    06260e68f Handle null completions with a default callback
    4525fe37b Add completion for `--volume-driver`
    db0ed1e21 Add completion for `--cgroupns`
    291574927 Add completion for `--uts`
    3a2503fa4 Add completion for --log-driver` and --log-opt`
    9a9ae231a Add completion for `--security-opt`
    5f7c43e5e Add completion for `--detach-keys`
    3292afe6e Add completion for `--userns`
    5d709a8d9 Add completion for `--ulimit`
    2d89339b3 Add completion for `--storage-opt`
    ac7bde6f6 Add completion for `--pid`
    e51345424 Add completion for `--link`
    c555327f0 Add completion for `--ipc`
    b598ec8cd Add completion for `--attach`
    761d76750 Share the container completions
    382d4c34a update to go1.23.3
    1440f9f8c docs: change link to desktop docs
    fafaac59f Add --bip6 to dockerd cmdline ref
    13754f677 deps: update `go-jose/go-jose` to `v4`
    172f34011 docs: update example redis tags from 3.0.x to 7.4.x
    4a7b04d41 golangci-lint: set go version to prevent fallback to go1.17
    d77760fe5 cli-plugins/manager: remove redundant capturing of loop vars (copyloopvar)
    32b40deb4 cli/command/service: remove redundant capturing of loop vars (copyloopvar)
    40833fd29 cli/compose/loader: remove redundant capturing of loop vars (copyloopvar)
    78a7e1503 cli/command/container: remove redundant capturing of loop vars (copyloopvar)
    4a71ce02e cli/command/image: remove redundant capturing of loop vars (copyloopvar)
    7d9ea2556 templates: remove redundant capturing of loop vars in tests (copyloopvar)
    046ac9714 service: remove redundant capturing of loop vars in tests (copyloopvar)
    762b5a8df opts: remove redundant capturing of loop vars in tests (copyloopvar)
    417974cdc cmd/docker: remove redundant capturing of loop vars in tests (copyloopvar)
    bf37e26b3 cli/manifest: remove redundant capturing of loop vars in tests (copyloopvar)
    6489a777e e2e: remove redundant capturing of loop vars in tests (copyloopvar)
    20de86113 cli/config: remove redundant capturing of loop vars in tests (copyloopvar)
    1448cecba cli/compose: remove redundant capturing of loop vars in tests (copyloopvar)
    67458f710 cli/command: remove redundant capturing of loop vars in tests (copyloopvar)
    0c999fe95 docs: Correct `run` exit code 126 description
    5f1311ae8 vendor: github.com/docker/docker 6ac445c42bad (master, v28.0-dev)
    10c5a5792 vendor: go.opentelemetry.io/contrib/instrumentation/xxx v0.53.0
    5e40d288c vendor: go.opentelemetry.io/otel v1.28.0
    9ba73a1a0 vendor: github.com/grpc-ecosystem/grpc-gateway/v2 v2.20.0
    f3cf1b421 vendor: go.etcd.io/etcd/raft/v3 v3.5.16
    cae19e392 vendor: github.com/AdaLogics/go-fuzz-headers v0.0.0-20240806141605-e8a1dd7889d6
    074d1028b vendor: update prometheus dependencies
    1dbcce205 vendor: google.golang.org/grpc v1.67.1
    1bba00994 vendor: google.golang.org/protobuf v1.35.1
    e3942d46a vendor: github.com/klauspost/compress v1.17.11
    97ff1b7c0 vendor: github.com/go-logr/logr v1.4.2
    4c85feb4d vendor: github.com/cenkalti/backoff/v4 v4.3.0
    3b48a57b0 vendor: github.com/Azure/go-ansiterm v0.0.0-20230124172434-306776ec8161
    36e6c4297 vendor: golang.org/x/net v0.30.0
    84bfa52a6 vendor: golang.org/x/crypto v0.28.0
    7a94f592e vendor: golang.org/x/text v0.19.0
    ef197f731 vendor: golang.org/x/term v0.25.0
    02b92c699 vendor: golang.org/x/sys v0.26.0
    42cda3884 update to go1.23.2
    0b16070ae Buffer 'docker stats' text to avoid terminal flickering
    9af049c61 bump golangci-lint to v1.61.0
    745629bd5 golangci-lint: update comment, and disable "exclude-dirs-use-default"
    7451339ab golangci-lint: move gosec excludes to linters-settings
    020f3a7ad golangci-lint: enable G204, add #nosec comments instead
    e1c5180db Add tests for completions that call the API
    d4f4cf141 Add completion for `events --filter`
    59b90305f cli/command/container: parse: remove client-side warning
    e9ae9f788 docker inspect: add support for swarm configs
    3c7806924 cli/config/credentials: add test for save being idempotent
    0dd6f7f1b cil/config/credentials: remove newStore() test-utility
    5f4b14950 cli: remove deprecated Errors type
    d96f8b7f9 cli/config: improve error when failing to parse config file
    d3f6867e4 cli/config/credentials: skip saving config-file if credentials didn't change
    6b9083776 cli/command: AddPlatformFlag: suppress unhandled error
    fb61156b0 cli/command/registry: fix minor linting issues
    3f7b156c8 Fix bash completion for `events --filter daemon=`
    4b7a1e461 cli/command: PromptUserForCredentials: suppress unhandled errors
    378a3d7d3 cli/command: PromptUserForCredentials: use consts for all hints
    54e3685bc cli/command: ConfigureAuth: fix deprecation comment
    3d8b49523 cli/command: PromptUserForCredentials: print error on terminal restore fail
    a21a5f424 cli/command: PromptUserForCredentials: always trim password
    eda78e9cd cli/command: PromptUserForCredentials: move trimming where it's used
    581cf36bd cli/command: PromptUserForCredentials: move "post" check for empty name
    a55cfe5f8 cli/command: PromptUserForCredentials: inline isDefaultRegistry
    3a8485085 cli/command: PromptUserForCredentials: remove named output variables
    d3bafa5f3 cli: deprecate Errors type
    71ebbb81a cli/command/plugins: use errors.Join instead of custom cli.Errors
    87acf77ae cli/hints: add tests
    9b525bc9d vendor: github.com/docker/docker 36a3bd090489 (master, v28.0-dev)
    670f81803 cmd/docker: add tests for flag-completions, and refactor
    12dcc6e25 templates: add test for HeaderFunctions
    cbbb91732 vendor: github.com/moby/swarmkit/v2 v2.0.0-20241017191044-e8ecf83ee08e
    2c6b80491 docs: update prose about image tag/name format
    50ef0c58c docs: corrected the max events returned
    35d7b1a7a cli/command/container: TestWaitExitOrRemoved use subtests
    3b38dc67b cli/command/container: set empty args in tests and discard output
    e1c472a43 completion: add test for VolumeNames
    302d73f99 completion: add test for NetworkNames
    ab418a38d completion: add test for ImageNames
    f3b4094eb completion: add test for ContainerNames
    be197da6b completion: add test for NoComplete
    51713196c completion: add test for FromList
    a5ca5b33f completion: add test for FileNames
    8f2e5662e completion: add test for EnvVarNames
    b8cddc63a completion: ContainerNames: don't panic on nil filter
    a58faf797 README: update pkg.go.dev badge, add OpenSSF scorecard
    b6d27ff60 vendor: google.golang.org/grpc v1.66.2
    200225f53 vendor: google.golang.org/protobuf v1.34.1
    9599251d0 vendor: github.com/cespare/xxhash/v2 v2.3.0
    ea8aa2a41 vendor: golang.org/x/net v0.29.0
    61867feec vendor: golang.org/x/crypto v0.27.0
    843ae6d7e vendor: golang.org/x/term v0.24.0
    bea4ee658 vendor: golang.org/x/text v0.18.0
    a88ee33f7 vendor: golang.org/x/sys v0.25.0
    147630a30 Only complete removable containers if --force is not given
    d085e2445 image/history: Add `--platform` flag
    b0bb4ba7f image/load: Add `--platform`
    a20eb45b2 image/save: Add `--platform`
    0319795d4 cli/compose: implement the ports validation method
    839dbbcf2 cli/command/images: set cmd.Args to prevent test-failures
    19eeb1015 cli/command/image: fix TestNewSaveCommandSuccess to actually test
    d42cf96e1 cli/command/image: add shell completion for --platform flags
    8c7f713db cli/command/container: add shell completion for --platform flags
    ce1aebcc3 cli/command/completion: add Platforms
    2f2b16a96 docs: fix inaccurate description of --restart=unless-stopped
    c70b2165a docs: Link supported Go duration strings
    442c38636 command: add tests for container kill, commit, and pause
    a6ab65948 ci: update to go1.22.8
    9ecfe4f5a move parsing key-value files to a separate package
    76196dbb0 opts: parseKeyValueFile: cleanup and remove redundant trimming
    95e221ef4 opts: remove ErrBadKey as it's not used as a sentinel error
    b129660dd opts: cleanup ParseEnvFile tests
    d49e72c0a cli/command/container: add unit tests for completion helpers
    462e08219 cli/container: use github.com/moby/sys/capability for completions
    bd96bdaf1 align "conflicting options" errors for consistency
    df8b34595 cli/command/container: stop, restart: rename "--time" to "--timeout"
    607530348 docs/reference: stop, restart: add flag descriptions
    8fca0a1f2 Check that --ip-range is a CIDR address
    ac502b590 cli/command/container: add unit tests for container stop
    16aa99425 cli/command/container: add unit tests for container restart
    54a20ce54 docs: fix a typo in run.md
    b12ac897f vendor: github.com/docker/docker 164cae56ed95 (master, v-next)
    df52ddcfc Images Tree: Change 'Used' to 'In Use'
    17040890e Do not underline image name
    46b360b05 command: add tests for container diff and rename
    465e87afc docs: fix anchor link to web-based login section
    8a3d838a1 docs: use important callout for buildkit vs legacy builder
    3e271461e cli/formatter: fix unbracketed IPv6 addrs
    91c90a979 Update `VERSION` file to `v27.3.1-dev`
    ce26ebc0e Dockerfile: update compose to v2.29.7
    1355d7e9f telemetry: fix early meterprovider shutdown
    f46860616 gha: codeql: minor touch-ups and fixes
    3472bbc28 command: change drive to lowercase for wsl path
    e1213edcc gha: update codeql workflow to go1.22.7
    b1956f507 telemetry: pass otel errors to the otel handler for shutdown and force flush
    f7a513cff Dockerfile: update compose to v2.29.4
    42ce06aa5 Dockerfile: update buildx to v0.17.1
    baceb4b15 docs: dockerd: add documentation for --log-format option
    a42ca1148 docs/reference: dockerd: add docs for --feature option
    9ae514fdc man: dockerd: add description for --log-format option
    1a0e32099 docs: dockerd: remove --api-cors-header (deprecated)
    9bfd0e1a4 man: remove docs for deprecated --api-cors-header
    a357db0ab man: dockerd: value is optional for --feature flag
    fb056d2ce man: fix duplicate word in --feature flag description
    610f9157f man: update dockerd man-page to include --feature flag
    605c9bf16 docs: Fix --rm=false flag in container_run.md
    dccb8bfa5 vendor: google.golang.org/grpc v1.62.0
    8cdf90cd9 vendor: tags.cncf.io/container-device-interface v0.8.0
    a5f15bee7 vendor: golang.org/x/net v0.28.0
    b93fc3963 vendor: golang.org/x/crypto v0.26.0
    3a63df265 vendor: golang.org/x/text v0.17.0
    c6e534193 vendor: golang.org/x/term v0.23.0
    5f9fe33b6 vendor: golang.org/x/time v0.6.0
    7074e5011 vendor: golang.org/x/sync v0.8.0
    958fff82f vendor: golang.org/x/sys v0.24.0
    fb264ffc0 vendor: dario.cat/mergo v1.0.1
    38c3fef1a command: check for wsl mount path on windows
    5b81f0dcb chore: remove duplicated `govet` linter config
    88ca4e958 info: stop printing "Expected" commits
    daea277ee volume/update: require 1 argument/fix panic
    0fcaffb7e chore: fix style/lint issues in deprecated.md
    45d55961d Fix broken links in CONTRIBUTING.md
    0b9d58245 cli/command: fix docstring for ContainerFormat.CreatedAt
    4a6ab2b37 fix: binary file line endings
    3bf39d25a update to go1.22.7
    1b8180a40 vendor.mod: put github.com/pkg/browser in the right group
    5ca40e0a3 docs: add front matter title to deprecated.md
    071f6f939 docs: rename plugins index file and add linkTitle
    bbb6e7643 login: handle non-tty scenario consistently
    60d045028 oauth/api: drain timer channel on each iteration
    d7d56599c update to go1.22.6
    9e2996796 scripts/build/plugins: don't override CGO_ENABLED set by .variables
    81744d7aa copynit: s/WEB BASED/WEB-BASED/
    2f206fff3 docs: update docker login reference
    1e6cbbc3f Dockerfile: update xx to v1.5.0
    e532eead9 login: use normalized hostname when storing
    dab9674db Revert "login: normalize `registry-1.docker.io`"
    c4a55df7c cli: rename args that collided with builtins (predeclard)
    9c8789127 e2e/global: fix n-constant format string in call (govet)
    f101f07a7 cli/command: fix n-constant format string in call (govet)
    cc1d7b7ac cli/command/system: remove redundant nil-check (gosimple)
    964155cd2 cli/formatter: bracket IPv6 addrs prepended to ports
    a327476f7 login: add e2e tests for oauth + escape hatch
    c974a8339 chore: update link to docker engine api reference
    846ecf59f login: add oauth escape hatch
    7b9164794 list/tree: No extra spacing for graphdriver
    351249dce list/tree: Print &lt;untagged&gt; as dangling image name
    6979ab073 list/tree: Fix some escape codes included in nonTTY
    a9b78da54 list/tree: Add spacing before the content and first image
    0242a1e3c list/tree: Capitalize column headers
    d417d0668 list/tree: Add an experimental warning
    b1a08f784 list/tree: Sort by created date
    18ab78882 list/tree: Align number right, text left
    ea8aafcd9 cli/tree: Add `Content size` column
    be11b74ee image/list: Add `--tree` flag
    f1befabe9 docs: use gh alert syntax for callouts
    c3fe7bc33 fallback to regular login if oauth login fails to start
    5eb3275c2 filestore: don't print warning multiple times
    e6624676e login: normalize `registry-1.docker.io`
    6e4818e7d Refactor `cli/command/registry`
    fcfdd7b91 auth: add support for oauth device-code login
    2dd4eb06a docs: update link to moved build context doc
    0fd3fb084 cli/connhelper: getConnectionHelper: move ssh-option funcs out of closure
    f3c2c26b1 disable pseudoterminal creation
    d4a362aa1 docs: update internal links after refactor
    78a8fba2c docs: fix link to http proxy document
    6440816c7 vendor: github.com/docker/docker 2269acc7a31d (master, v-next)
    b8a53ee34 vendor: github.com/docker/docker master  (f3cf9359bdf6)
    9c4480604 plugins: don't panic on Close if PluginServer nil
    434d8b75e update to go1.21.13
    73e78a582 run: fix GetList return empty issue for throttledevice
    e29292f92 add security policy
    40a5b297b vendor: go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.21.0
    e4d99b4b6 gha: set permissions to read-only by default
    eac83574c tests/run: fix flaky `RunAttachTermination` test
    7b46bfc5a attach: wait for exit code from `ContainerWait`
    f0a29af0f vendor: docker/docker 2b1097f08088 (removes containerd dependency)
    b34e8e4df vendor: github.com/moby/sys/sequential v0.6.0
    ea37ac9ba vendor: github.com/moby/sys/symlink v0.3.0
    435c65833 vendor: github.com/moby/sys/signal v0.7.1
    501904d48 vendor: golang.org/x/sys v0.22.0
    cc4163296 lint: replace deprecated linter names
    66aa0f672 attach: don't return context cancelled error
    4a7388f0d tests: fix other flaky `connhelper` tests
    cc68c66c9 tests: fix flaxy `TestCloseRunningCommand` test
    b36522b47 docs: refresh image versions in examples
    aa2c2cd90 Allow for OomScoreAdj
    401048b9c vendor: github.com/containerd/containerd v1.7.20
    6638deb9d add support for DOCKER_CUSTOM_HEADERS env-var (experimental)
    9617e8d0c gha: update to macOS 13, add macOS 14 arm64 (Apple Silicon M1)
    6d8fcbb23 gha: check-pr-branch: verify major version only
    77c0d8360 Dockerfile: update compose to v2.29.0
    d00e1abf5 Dockerfile: update buildx to v0.16.1
    ab80ea355 cli/config/credentials: move warning to fileStore
    fcefe44bd login: slightly cleanup warning about unencrypted store
    a78ab6380 login: don't print "unencrypted" warning when failing to save credentials
    90058df30 cli/command/container: remove reportError, and put StatusError to use
    64a3fb82d docs: fix typos and version for cli-docs-tool scripts
    e3e9b9901 vendor: github.com/docker/cli-docs-tool v0.8.0
    f28fc7f82 cli: FlagErrorFunc: don't print long usage output for invalid flags
    b1c0ddca0 cli/command/container: add completion for --stop-signal
    d6f78cdbb cli/command/container: add completion for --volumes-from
    7fe7223c2 cli/command/container: add completion for --restart
    f30158dbf cli/command/container: add completion for --cap-add, --cap-drop
    e4dd8b189 cli/context/store: Names(): fix panic when called with nil-interface
    42b68a3ed cmd/docker: fix completion for --context
    162d9748b cli/command/container: provide flag-completion for "docker create"
    5e7bcbeac cli/command/completion: add FromList utility
    e3427f341 cli/command/completion: add EnvVarNames utility
    9207ff104 cli/command/completion: add FileNames utility
    eed0e5b02 cli/command/container: NewRunCommand: slight cleanup of completion
    e8baee9c7 vendor: github.com/docker/docker aae044039ca4 (master, v-next)
    a77ba7eda vendor: google.golang.org/genproto/googleapis/api 49dd2c1f3d0b
    caa5d15e9 vendor: github.com/prometheus/procfs v0.15.1
    0f712827f vendor: github.com/containerd/containerd v1.7.19
    b28a1cd02 vendor: golang.org/x/sync v0.7.0
    991b1303d chore: restore ctx without cancel on container run
    6c04adc05 push: Improve note message and colors
    0579cd797 test: e2e SIGTERM attached container on `docker run`
    d40199440 c8d: Remove `docker convert` mention
    4ce6e50e2 push: Don't default to DOCKER_DEFAULT_PLATFORM
    3f3ecb94c Makefile: add completion target
    150fb55a8 fix: container stream should not be terminated by ctx
    3d80b7b0a Dockerfile.dev: install bash-completion in dev container
    eae75092a cmd/docker: split handling exit-code to a separate utility
    b7695d6c7 cli-plugins: RunPlugin(): rename error-variable that's possibly shadowed
    350a0b68a cli-plugins: Run(): don't discard cli.StatusError errors without message
    3dd6fc365 cmd/docker: don't discard cli.StatusError errors without custom message
    2f83064ec e2e/cli-plugins: check for exit-errors in tests
    baf35da40 e2e/cli-plugins: use cmd.CombinedOutput() instead of custom buffer
    c6b40640c e2e/cli-plugins: use identifiable output for test
    e9f32edac e2e/cli-plugins: explicitly ignore fmt.Printxx errors
    5e7948ec8 e2e/cli-plugins: rename var that shadowed import
    c60b360c3 cli: improve argument validation output
    a6e96c758 cli: improve output and consistency for unknown (sub)commands
    bca209006 cli: make cli.StatusError slightly prettier
    88896eeaa cli/command/container: TestSplitCpArg: cleaner skip
    b194274be replace uses of deprecated API types
    4cac8efb5 vendor: github.com/docker/docker 508cc7c61226 (master)
    dc22572e3 chore: regenerate docs
    8549d250f docs: update cli-docs-tool (v0.8.0)
    3d4c12af7 docs: update links to docker cli reference
    bf33c8f10 docs: regenerate base command
    b0650f281 docs: align heading structure for base command
    cfea2353b docs: remove frontmatter for base command
    03961449a docs: rename cli.md to docker.md (base command)
    a68382338 docs: remove empty docker base command reference
    a0c4e56de vendor: golang.org/x/net v0.25.0
    723130d7f vendor: golang.org/x/crypto v0.23.0
    d33ef57dc vendor: golang.org/x/text v0.15.0
    21dbedd41 vendor: golang.org/x/sys v0.21.0
    f8e7c0a0d vendor: github.com/klauspost/compress v1.17.9
    10a015f87 cli/command/network: NewPruneCommand: explicitly ignore error
    b3d8809f4 cli/command/network: rewrite consolidateIpam to take an option-struct
    ab230240a test spring-cleaning
    c7d46aa7a Enable completion for 'image' sub commands
    2eb61318b cli/command/network: some cleanup and pass smaller interfaces
    b711372ca cli/command/container: TestNewAttachCommandErrors: use struct-literals
    229616e17 cli/command/image: fakeClient.ImagesPrune: fix unhandled err-return
    42ba29395 rename vars to prevent colliding with imports
    3a77fdd91 cli/command/trust: unconvert
    26223f701 cli/command/formatter: don't use unkeyed structs
    c56f4a1ef workflow: remove git `autocrlf=false` setup on windows
    d73d7d4ed update to go1.21.12
    e91f0ded9 docs: make buildx build the canonical reference doc
    c15ade0c6 fix: ctx cancellation on login prompt
    2bd4e95bf feat: force lf line endings by default
    be14edca2 cli/command/stack: fix faulty sort for sorting stacks
    0f6370c94 vendor: github.com/fvbommel/sortorder v1.1.0
    2e6aaf05d vendor: github.com/docker/docker v27.0.3
    9455d6176 vendor: github.com/docker/docker v27.0.2
    1382fbe61 vendor: github.com/docker/docker v27.0.2-dev (e953d76450b6)
    ab0898ee3 vendor: github.com/docker/docker v27.0.2-dev (861fde8cc974)
    cfec21f28 vendor: github.com/docker/docker v27.0.1
    8b0a7b025 cli/config/credentials: ConvertToHostname: handle IP-addresses
    238048160 re-introduced support for port numbers in docker registry URL
    60775b615 gha/e2e: Update latest version to 27.0
    b5d1b4de1 update golangci-lint to v1.59.1

Signed-off-by: Bruce Ashfield &lt;bruce.ashfield@gmail.com&gt;
</content>
</entry>
</feed>
