summaryrefslogtreecommitdiffstats
path: root/recipes-containers
Commit message (Collapse)AuthorAgeFilesLines
* oci-runtime-tools: update to v0.9.0-tipBruce Ashfield2026-06-031-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping runtime-tools to version v0.9.0-147-g8a4db57, which comprises the following commits: 6372393 Add support for `riscv64` arch ce94ed3 ci: update golangci-lint for compatibility with go1.26 b58544f Makefile: add EXTRA_LDFLAGS 3c27840 cgroups: treat 'max' pids.max as -1 LinuxPids.Limit in GetPidsData(). 5f84332 cgroups,generate,validat{e,ion}: fix golangci-lint deprecation warnings. b521900 go.{mod,sum}: bump runtime-spec to v1.3.0. 79a3f0f ci: use "oldstable" and "stable" Go versions 4da4e5e ci: bump actions etc. to latest versions 1216466 golangci-lint: switch to v2 2734868 generate: fix a comment 80497fb validation: fix ST1017: don't use Yoda conditions 827638e validation/linux_cgroups_relative_cpus: fix staticcheck warning 9e87868 Add annotations to ignore some staticcheck warnings b00213a Fix staticcheck QF1003 warnings 5bae0b9 generate/seccomp: remove double package import 59d9b89 cmd/runtimetest: use strings.ReplaceAll bd70e01 Modernize the code b01335e Remove obsoleted +build tags 6072004 Add time namespace / TimeOffsets check and helper c2dadba Switch to github.com/moby/sys/capability 4c69808 ci: bump Go and github actions e1c9375 cmd/oci-runtime-tool: fix govet warning a3a57a9 cmd/runtimetest: use github.com/moby/sys/mountinfo 27bf223 go.mod: github.com/opencontainers/runtime-spec v1.1.0 28f43fa go.mod: golang.org/x/sys v0.1.0 c6b8fa3 gof(ump)t code b2e2dab Update GitHub actions base runner image b1f58fe Add Go 1.19 and Go 1.20 support cd79116 Update GitHub actions packages to resolve warnings 0f9ac2c Remove io/ioutil package references. 0524bb2 Revert "Change /dev to be mounted by default with /noexec" 2e043c6 validate/capabilities: fix incorrect package name. 4167830 Add CODEOWNERS, rm .pullapprove.yml 24aab90 generate, validate: isolate gojson* dependencies. e972318 generate: add support for domainname c3bea2c seccomp: Separate conditions for personality syscall into single rule 6666f24 Add devfs and fdescfs as default mounts for FreeBSD 91a7b1d Add generator support for FreeBSD 62ac333 Switch to `github.com/blang/semver/v4` 8d08049 generate/seccomp: Allow Landlock syscalls a65a3b6 Use new golangci-lint 932a8c1 generate: NewFromSpec() remove deprecated comment 7fdb100 seccomp: add CloneNewCgroup to check sysCloneFlagsIndex d58bc16 validate/CheckRoot: fix panic on empty spec 83399e7 validate/CheckRoot: fix error text 8927281 Add syscall "statx" in seccomp to fix Operation not permitted a202491 spec generator support setting unified 30cecc1 validation/linux_rootfs_propagation: fix 10d2584 runtimetest: validateRootfsPropagation: fixes 8b26e24 validate: rm Clean() arguments 3fb1264 validation: fix Cleanup 14cd51e Makefile: replace TAP with TAPTOOL adcb290 Fix hanging on runc create. 5ce2cac cmd/runtimetest: fix NewPid deprecation warning 8e1a3b5 deps: bump github.com/syndtr/gocapability to latest 543268b deps: github.com/hashicorp/go-multierror to v1.1.1 4b164a1 deps: bump github.com/opencontainers/selinux to v1.9.1 ee9c051 deps: bump github.com/mrunalp/fileutils to v0.5.0 01a6f47 deps: bump sirupsen/logrus to v1.8.1 abcb94d deps: switch to google/uuid 2253869 validation/.gitignore: fix 953e752 MAINTAINERS: add @kolyshkin 221e5ea deps: bump github.com/xeipuuv/gojsonschema to v1.2.0 67884fc validate: prepare for new xeipuuv/gojsonschema 09d837b Change /dev to be mounted by default with /noexec 10c865d ci: re-add commit subject length validation a22a894 ci: add golangci-lint run a7cecde Add*Hook: do not return errors c0037c9 runtimetest: silence errlint on unix.Unmount 9505f16 Explicitly ignore errors from YAML fec9c3c validation: fix Clean 0ab61ae validation: fix/rename ReadStandardStreams 6f4b5ba validate: fix staticcheck linter warning 6a9ad7c runtimtest: fix validatePosixMounts 44e9496 Fix "addr cannot be nil" staticcheck linter warnings d38bd63 Fix deprecation warnings from staticcheck linter 1826c32 Fix gosimple linter warnings e36f98f Fix deadcode linter warnings 112c88c Makefile: use fancy git commit ids 16dfbbd Makefile: add/use BUILD_FLAGS 5432bc4 ci: replace travis with gha ci fab664e Makefile: rm gofmt and golint, simplify gotest 98b2d35 Run make .gofmt 0e5956d Switch from Godeps to go modules 71a5e7c generate: add --linux-intelRdt-closid option 4f51ef9 validation: read pid in PostCreate 6502e57 Fix build of hugetlb tests on 32-bit platforms 10f8f55 generate: fix type for Umask 8f1e958 Remove spurious WARNING message 43243fe Add missing interface to set init processes Umask 120c67a AddDevice(): better diagnostic when creating dup 2affd45 Add missing clone rule for s390x. be9f6f1 Update hugetlb tests to be more portable 5a98426 Fix cgroup hugetlb size prefix for kB cd1349b Improve performance of AddProcessEnv 73e9a99 update Mashimiao email in MAINTAINERS Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* sloci-image: update to v0.1.2Bruce Ashfield2026-06-012-50/+4
| | | | | | | | | | | | | | | | Bumping sloci-image to version v0.1.2, which comprises the following commits: b45be2e Release version 0.1.2 ab128a4 License: Bump year f86399b Readme: Update preamble 056e127 Fix "--arch arm64" argument - don't rewrite it to "arm" 195b540 Replace Travis CI with GitHub Actions 6663693 Don't create top-level directory in tar archive fafbf1f Release version 0.1.1 f2ebd0a Fix escaping issues when generating the OCI image config files 4015e49 Makefile: Declare "install" as PHONY and sort targets Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* skopeo: update to v1.23.0-tipBruce Ashfield2026-06-012-9/+9
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping skopeo to version v1.23.0-2-g5e1d6f708, which comprises the following commits: 55a734787 Bump to the next dev, v1.24.0-dev 9645b282c Bump Skopeo to v1.23.0 09c22b5d2 Bump c/common 0.68.0, c/image 5.40.0, c/storage 1.63.0 e72b1c821 Update common, image, and storage deps to 4a820ae 7a6acb197 copy: add platform-based filtering via --multi-arch flag 1156ffcc4 Update module golang.org/x/term to v0.43.0 5856c947c Update common, image, and storage deps to abe824d c8831c8ba Update dependency golangci/golangci-lint to v2.12.2 4df9e1df7 Update dependency golangci/golangci-lint to v2.12.1 0157bbaed Update common, image, and storage deps to c03a490 bb107be5d Update module github.com/Masterminds/semver/v3 to v3.5.0 277f715d8 Packit: Only create dist-git PRs for rawhide f94b8a433 Cirrus: switch Sequoia matrix from Rawhide back to stable Fedora e6190508d Update common, image, and storage deps to b9d5b9a 95471ee7d Remove OWNERS file a1e4d9ecc Additional cleanup for go module changes 870378ba1 Move skopeo to go.podman.io ad331b3fa Update common, image, and storage deps to 618304d 0113070da Update module github.com/containers/ocicrypt to v1.3.0 aed4196f2 Update common, image, and storage deps to 129af75 3f4591c24 Update go.podman.io dependencies 100826b44 Update module golang.org/x/term to v0.42.0 783a44c9e Bump google.golang.org/grpc to v1.79.3 - CVE-2026-33186 583d584fb chore(deps): update module github.com/go-jose/go-jose/v4 to v4.1.4 [security] bfcd4c7a9 fix(deps): update go.podman.io/storage digest to f0ddf1a c341f6f78 fix(deps): update common, image, and storage deps to 8af7873 2b2257a19 integration: Force amd64 on TestProxyMetadata 1ae60936a fix(deps): update common, image, and storage deps to 94ad023 b376401a7 Try triggering an ostree image rebuild 16aceb436 chore(deps): update dependency golangci/golangci-lint to v2.11.4 13c63986a ci: add riscv64 to local-cross build target 2eb170a28 cmd, proxy: use logic from the container-libs/common package c1c2e83b6 vendor: update go.podman.io/common 993808b53 fix(deps): update common, image, and storage deps to ddaabae c468542c7 Use --retry-times 3 for (skopeo sync) tests 6be190479 Use t.Tempdir() instead of manual os.CreateTemp() in tests 9de2245b5 Fix references to a wrong err b94d15a21 fix(deps): update module golang.org/x/term to v0.41.0 33ea6c63a Use fmt.Appendf instead of Sprintf + conversion 8b9f757eb Use "any" instead of "interface{}" c49d55b2a Use WaitGroup.Go 3276580fb Update to Go 1.25 6a0b6b1c8 Update CI image and tests 726479d94 Replace the boolean for schema1 registry with an enum 7b622f0dd chore(deps): update dependency golangci/golangci-lint to v2.11.3 ff43ff736 fix(deps): update common, image, and storage deps to d48bc74 6da03342b Link to Podman's LLM policy ee83783bb fix(deps): update github.com/opencontainers/image-spec digest to a4c6ade 5e7720438 fix(deps): update common, image, and storage deps to 854aaaf 161072f6c Packit: Re-enable ELN tests af1b87a95 Add a --tls-details option and integration tests ade329895 Add an error return value to globalOptions.newSystemContext 4f6fffdd9 Pass a SystemContext to signature.DefaultPolicy 56bca05e9 Update container-libs after container-libs#623 1ea0fb4ba Packit: fix downstream post-modifications action 625e3631c chore(deps): update dependency golangci/golangci-lint to v2.10.1 4bf431704 chore(deps): update dependency golangci/golangci-lint to v2.9.0 cfc31fca1 fix(deps): update module golang.org/x/term to v0.40.0 800ea987b fix(deps): update common, image, and storage deps to 0e2aefd a64f780f8 Update tests for a changed error message 56c4a65ec fix(deps): update common, image, and storage deps to b5801a6 d395f3eb7 fix(deps): update common, image, and storage deps to b2572af c7e238a4f fix(deps): update module github.com/sirupsen/logrus to v1.9.4 669e21cd7 fix(deps): update common, image, and storage deps to e7626b7 b4516c6ee fix(deps): update module golang.org/x/term to v0.39.0 0c04335b2 chore(deps): update dependency golangci/golangci-lint to v2.8.0 ef323fcce Document the default of --retry-times f952b7fac chore: fix function name in comment 40f0e1677 skopeo: add `--require-signed` 767d9cb00 integration/signing_test: move findFingerprint to utils_test.go 01c33a7e4 fix(deps): update common, image, and storage deps to b0f86df 7c747f822 Update c/common to match #2765 9efaa1c01 fix(deps): update common, image, and storage deps to afd10d8 54b415918 chore(deps): update dependency golangci/golangci-lint to v2.7.2 ad431f6d1 fix(deps): update module golang.org/x/term to v0.38.0 e26a4237f Packit: use `post-modifications` hook to update downstream TMT plan 420cd29be docs: manpage update for `skopeo inspect --manifest-digest` f85b6db46 inspect: --manifest-digest flag a25bf9182 vendor: container-libs commit 01833ef7b7f1d306205be7fa6fb36d0d6a6e3a33 0291b1e00 chore(deps): update dependency golangci/golangci-lint to v2.7.1 f7d8ca987 fix(deps): update module github.com/spf13/cobra to v1.10.2 bad5bd046 chore(deps): update dependency golangci/golangci-lint to v2.7.0 31d50fd0f Bump version to 1.22.0-dev bd5ec4425 Update common, image, and storage deps to 63be353 287045706 Try triggering an image rebuild 3498d8fc7 Update common, image, and storage deps to 22d50c5 ae484462c Update dependency golangci/golangci-lint to v2.6.2 75bc19e33 vendor: Fetch the latest from container-libs main b62590531 golangci-lint: enable gofumpt formatter 7182fecc7 format the code with gofumpt 2a6fd7420 Packit: tmp disable ELN tests 4ac321f3b fix(deps): update module golang.org/x/term to v0.37.0 Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* runc: update to v1.5.0-rc.2-tipBruce Ashfield2026-05-311-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping runc to version v1.5.0-rc.2-37-gf8699560, which comprises the following commits: 524803cc [1.5] runc list: fix error reporting for non-existent root 3964cb7e Update `busybox:glibc` in integration tests to latest (1.38.0) builds d5dc5356 tests/int: relax testPids fork error match string 2b02fb63 tests/int: build TestPids pipelines programmatically 7522b506 tests/int: fix flake in "resources.unified override" 8cf2a2d6 libct: close rootFd ASAP in maskPaths e2eb5dd2 libct: optimize maskPaths for single-directory case d7791e5c integration: reuse tmpfs for directory masks 411b5f2f libct: reuse tmpfs for directory masks 24867ade libct: enforce strict tmpfs limits for masked paths 0fc29212 libct: skip mount for duplicate masked paths 86f61cc3 tests/rootless.sh: use command -v instead of which a03e109e CI: lima: add template name to cache key 27838f27 Complete migration from Cirrus CI to GHA (Lima) c2092624 libct/int: switch from bytes.Buffer to strings.Builder c63f7572 libct/int: remove buffers.Stdin 87edc296 libct/int: use readlink -v f3e4f8ec libct/int: show stderr if command failed c9fd1a38 libct/int: waitProcess: rm dead code 44838af3 tests/rootless.sh: fix skipping idmap tests for systemd 96ffda7b tests: rename AUX_{DIR,UID} to ROOTLESS_AUX_* 68388249 tests/int/checkpoint: drop unneeded tests d5cead38 libct: move cmsg helpers to new internal/cmsg package 83e60dda libcontainer/devices: add '//go:fix inline' directives 3bd7cbb5 VERSION: back to development Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* raft: update to v0.22.1-tipBruce Ashfield2026-05-311-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping raft to version v0.22.1-50-g148951f7, which comprises the following commits: f9e37bc3 v1: Memory ownership of RAFT_CONFIGURATION event fd02017e v1: Memory ownership of the RAFT_SNAPSHOT event 1706aa1d v1: Memory ownership of RAFT_PERSISTED_SNAPSHOT event 1ee30187 docs: Add memory ownership info for RAFT_START and RAFT_RECEIVE aee66da8 changed documentation for RECEIVE 2ee8f4d4 v1: Memory ownership of RAFT_INSTALL_SNAPSHOT messages bdb3167c v1: Cleanup RAFT_RECEIVE memory ownership d9ad91a9 recv: Don't destroy received entries in case of error 4d49611f updated documentation about RAFT_START and RAFT_RECEIVE 19dcaac9 recv: Assert that all entries are in the same batch dff384e9 changed memory ownership documentation for RAFT_START event 7377b759 step: Improve memory ownership of RAFT_START entries bc17d89c step: Improve memory ownership of RAFT_START configuration e5949e34 github: Add container, network and storage Incus test targets 613f2809 github: Update Incus downstream action to match upstream a3fe2df0 github: Bump to Ubuntu 24.04 for Incus downstream tests 6bb12a07 documented memory ownership of the raft_event structure passed to raft_step 0bd5a267 lint: Run clang against unformatted files 7d64f181 raft.h: Fix raft_step() docstring fd4dc36b recv: Add explicit comparison to 0 eff73f1e Update raft_voted_for doc 8d3c26a8 fix return type of raft_voted_for in raft.c 96cf6247 Update trail.h f42431bb Update log.h f96f0a5d fix doc typo 139759fa fix doc type 28eb3dba fix doc typo 7f155af3 fix typo 7121685d fix doc typo on messageEnsureQueueCapacity c66e700c test: Don't fail when kernel has tmpfs with direct I/O support 5e65164e github: Update incus downstream job 072ec04f github: Don't run dqlite downstream tests 3fe2dc99 github: Update downstream incus test by adding MinIO client 7aec814b C++ compiler reject sizeof of anonymous structs 09448e28 [atlesn] Don't default-initialize last_log_index, only set when it would otherwise not be set. 9d911c1d [atlesn] Fix use of uninitialized memory in outgoing message of type 'append entries result' c80dedfd [atlesn] Fix use of uninitialized memory in outgoing message of type 'append entries result' Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* podman-compose: update to v1.5.0-tipBruce Ashfield2026-05-311-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping podman-compose to version v1.5.0-178-g71e0fbd, which comprises the following commits: 899d7c3 Use new Podman flags for healthcheck fe77758 Add support for "start_interval" in healthcheck block 293b999 Use consistent Podman flags naming for healthcheck 9b1f00d tests/integration: Add tests 72e21e0 Only pull image before containers teardown if podman version >= 5.6.0 19eefc9 tests/unit: Add healthcheck test 7898c23 podman-compose: Format ValueError message to not include spaces 2b22922 tests/integration: Add healthcheck test 463a1a8 tests/integration: Pass -t 0 when tearing down containers af1dd2b tests: Move healthcheck helper class to test_utils 4c33aa1 Improve missing external network/volume error message 973d4a5 Honor `target` option for mount-type external secrets 3c6c86b build(deps): bump softprops/action-gh-release from 2 to 3 725642a Fix override tag to work with `depends_on` parameter 29a76d4 build(deps): bump cryptography from 46.0.6 to 46.0.7 1e2b223 build(deps): bump cryptography from 46.0.5 to 46.0.6 4aa5512 support nested variable interpolation d6a91cb Add integration test case for build phase env-sourced secrets 136b775 Add newsfragments/secrets-environment-source.feature 0d40feb Support secrets.*.environment f083a11 workaround for testing without systemd cfc2928 added an execution timeout for all --wait calls f7b6c30 added newsfragment a2ebd27 --wait is not supported for podman versions < 4.6 a6fb27d added integration tests for up/start wait 939a212 test/integration: Test top-level name interpolation cf4951a Fix top-level name attribute interpolation 52a0d9f --wait and --wait-timeout for up & start commands e999eae github: Setup tests for both rootful and rootless modes 114cc5d Simplify workflow for tests f7361bf fix: 'asyncio.iscoroutinefunction' is deprecated in python 3.15 6641f01 tests: Change github actions workflow to test with podman-5.7.1 9fde135 tests: Temporarily skip breaking tests after update to podman-5.7.1 8c35b51 added newsfragment 5326fd2 use nopush/podman-compose-test image for testing 7348cf5 added test case for using reset tag with extends 973baa6 better implementation of original_service method 9d60838 fixed yaml dumper class of override and reset tag 3787e75 Better error message when podman probe fails b85fa9e added support to parse extra hosts 2a3867b CONTRIBUTING: Add section about tests 6a4d975 CONTRIBUTING: Add `git rebase main --signoff` as useful command dc01295 .github: Refer to CONTRIBUTING.md in pull request template 3f76cd6 CONTRIBUTING: Clean up development environment setup 2e87ada CONTRIBUTING: Add development guidelines at the top 93e802f CONTRIBUTING: Remove "Who can contribute?" section b4c051c pre-commit-config: Run ruff check as well 5fc5a96 pre-commit-config: No longer run pylint - too slow 53696a1 pre-commit-config: Synchronize ruff version with tests 1436af5 tests/integration/build: Format files df7e12e gitignore: Ignore build/ at root only 7795c6d tests/unit: Cleanup assertions in get_net_args() tests 12e87d3 Include the service name in the error message when it's extends does not exist 1839720 Correctly modify volumes when normalizing services in a subdir 61b2b88 Don't double join path for dockerfile c99beff Remove unnecessary podman-compose down in tests fae5b09 tests: Change github actions workflow to test with podman-5.0.3 591753b Add test for incremental logger aba2344 Add timeout to util's run_subprocess in case of freezing 4b53ded Emit an error when bytes are incomplete at the end 797ec65 Use incremental decoder for log output 1c931fd Document Python 3.9 requirement ee52293 unittest: add volume mount_type test 35ab672 Add subpath support to volumes with type volume in `--mount` option 044f7f8 tests: Change github actions workflow to test with podman-4.9.5 574b91b tests: Temporarily skip breaking tests after update to podman-4.9.5 45acc63 Fix typos and other mistakes in podman-compose e69c09b tests: Change github actions workflow to test with podman-5.4.2 660fd0c tests: Temporarily skip breaking tests after update to podman-5.4.2 1e2dc24 Bump cryptography from 44.0.3 to 46.0.5 42ed080 tests/integration: Add tests for "logs" command 0e3ebe1 logs: Prefix log line with optional service name 9db8a66 logs: Make logs colored by default db07f5f Bump urllib3 from 2.6.0 to 2.6.3 586126d Add release note 09c0bb5 Add service reference support to the `additional_contexts` 319e30d Check if top-level object is parsed as None 0c83fc0 Exit gracefully if 'podman' not found 4922471 Fix merging of dicts into empty tags bf3f1e4 Move build and pull images into prepare_images() e70b929 Add newsfragment d36189c Image starts with "localhost/" should not pull 16fd556 Don't attach code to classes unnecessarily 856dc5e Pull images before teardown containers on up command c53e374 Fix "UP024 Replace aliased errors with `OSError`" warning 32ed357 Fix "UP009 [*] UTF-8 encoding declaration is unnecessary" warning 6f299c2 Fix "UP007 Use `X | Y` for type annotations" warning 55acc46 Fix "UP031 Use format specifiers instead of percent format" warning a930837 Fix "UP037 Remove quotes from type annotation" warning ea3e079 Fix "UP032 Use f-string instead of `format` call" warning 2ece5a8 Fix "UP015 Unnecessary mode argument" ruff warning 3db8b80 pyproject: Enable U ruff checks 3a3ee6d Upgrade ruff for tests 52c8d39 Fix Podman binary path f47a1e6 Support podman specific 'glob' mount type 5d4925d tests/integration: Add `compose.yml`,`__init__` files to run tests e674b9f tests/integration: Move `config`command test to a dedicated file 9000c37 Return error code from `pull` command properly 37ed118 Implement 'image' volume type for services d682071 Bump actions/checkout from 5 to 6 5a9e1d5 Add `--no-color` flag for `podman-compose logs` command 909355d fix: `--pull` option in `build` and `up` command can not set to pull policy. f66edc7 fix: Container may not have io.podman.compose.service label 13d2dc5 fix unittest failures after adding _config_hash 312d321 Adding integration tests for service level change detect c3d62c5 Add change log bfe5523 feat: Ensure running dependents are in running state after up command 640fdf7 feat: Process service level config changes on compose up bce5171 feat: set service level config hash to lebels ee32ffe Bump actions/checkout from 4 to 5 cd25efa Add integration test for compose down 967bced Fix dependency field selection in get_excluded() function 4aa11de fix: podman-compose down should not stop the upstream dependencies. c26387d tests: Add `workflow_dispatch` to allow manual execution of CI tests 4f9b419 tests: Add unit and integration tests for `create_host_path` 36fad25 Implement volumes `bind.create_host_path` option 28ec08c feat: Add support for COMPOSE_PROFILES environment variable 83c0d30 RELEASING: Add steps for uploading to Pypi Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* podman: update to v6.0.0-devBruce Ashfield2026-05-311-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping podman to version v5.4.0-rc1-3067-g62111c7e9d, which comprises the following commits: 33f0ed3fda Update module golang.org/x/net to v0.55.0 8d036cea7c Skip a number of failing tests e03516f6d4 Add compression-level/format and force-compression links in docs 8b1e46170b Adjust API calls for compression 6b02641f73 Bump Buildah to v1.44.0 40a9e21644 Update release ID in win-installer-main.ps1 7c7d56a0fb Use GH token to download Podman release in utils.ps1 4ec95b5de1 cmd/podman: don't warn on `podman run -ti -d` from not a tty 2e7178f428 hack/golangci-lint.sh: fix binary lookup order 13c6b5d786 pkg/bindings/generator: fall back to golangci-lint from $PATH c4c2778776 test/system: fix "podman kill - concurrent stop" ea51ae7305 test/system: use DISABLE_HC_SYSTEMD for 2 tests a2581cc82f test/e2e: deduplicate some network subnets d1d0c84a56 test/system: bump "unlock while waiting for timeout" timeout 1e0be4dec5 Improvements for newConmonOCIRuntime() in libpod/oci_conmon_common.go daaf8b62ba podman: Add support for blackhole routes 0ef5366c6d Update module golang.org/x/crypto to v0.52.0 e59b9dae8f api/libpod: fix r_limits cleared on update b498cefd5c test/system: do not run "podman pause/unpause" in parallel 90ba6562d5 test/system: fix "stop container when healthcheck runs" flake 34137c40f6 test/system: fix "podman stop - unlock while waiting for timeout" 472c53b122 test/e2e: fix static port assignment 0dbe00d272 test/system: skip one new pasta flake 97d0279e94 test/e2e: fix some duplciated network subnets 07e257e7f6 test/e2e: skip "podman run --shm-size-systemd" as root 1de60ebf7b test/e2e: skip "sshd and API services required" 39ee9baf66 test/system: fix "add username to /etc/passwd if --userns=keep-id" 9aca6010ee test/system: skip "IPv6 default address assignment" c22f67e729 .cirrus.yml: do not run golangci-lint for freebsd and mac 41a99a651f Bump c/common 0.68.0, c/image 5.40.0, c/storage 1.63.0 eede8790a0 Add Axoflow to ADOPTERS.md e9ec0ecef5 Makefile: run golangci-lint for all supported OSes cf021c4ba9 hack: reuse already installed golangci-lint ffb05a0921 Update krunkit.entitlements 3f427f4535 Skip pasta forwarder tests pending passt SELinux fix 2162404eaf Clarify inspect example in basic setup tutorial 6e98a49e03 inspect: use per-machine provider for GetMachineDirs f96cbda1b0 hyperv: propagate detailed error from Hyper-V permission checks d8fd8afad1 contrib/cirrus/prebuild.sh: drop unused get_env_key d4f60b5826 libpod: some modernize fixes for freebsd and darwin 329ce86835 test/e2e: modernize bf78f80b00 Replace strings.Split(..)[0] with strings.Cut 63166293c8 cmd/podman: replace strings.Split with strings.Cut b4d0747baa pkg/systemd/parser: use slices.Backward 7797dcb2ab pkg/domain/infra/abi: modernize 121948d69e pkg/rootless: modernize f45b4c506a ci: replace git-validation with a small shell script a4b755e1e6 Update module github.com/hugelgupf/p9 to v0.4.1 5c5389dddd .editorconfig: add indentation rule for shell files b2b552749d ci: rm contrib/cirrus/check_go_changes.sh 730934bd86 .golangci.yml: deny using obsoleted os.Is... checks 7f7b35356f Replace os.Is* error checks with errors.Is a7886d1fe8 Remove unused nolint annotations baf8fa6223 Document pasta forwarding mode for rootless bridge networks e598657244 Add pasta-based port forwarding for rootless bridge networks 0ff6ac85f0 Vendor storage@main, image/v5@main, common@main a53c10ced0 compat API: populate HostConfig in container list response 250e5f9914 use constant for timesync port and update mac_env.sh to print krunkit version f6d6365090 fix(deps): update module github.com/vbauerster/mpb/v8 to v8.12.1 cd78329c3f ci: pin all github actions aa2e532f64 tmt: archive audit and journal logs after test execution f2a51888f3 docs(api): drop trailing slash on podman.io/community contact URL e5bef8b124 machine: add vfkit timesync device for Apple VMs 6f048e6500 inspect: do not show <nil> as gateway 8842191d6e fix(deps): update module github.com/onsi/gomega to v1.41.0 e9df466ae3 fix(deps): update module github.com/onsi/ginkgo/v2 to v2.29.0 b50b9c0dbc events: support artifact events with refactored event forwarding 846d1a1b05 Close leaked file handles in container config, CRIU stats, and playbook read 39e5a0a0b9 Add unit tests for loadAndMergeConfig 72af655040 pkg/trust: fix directory handle leak in loadAndMergeConfig e36e2c97d2 bindings/artifacts: remove redundant nameOrID parameter from Remove for 6.0 e6c50d769f vendor: update container-libs to latest 3d899a8c25 volume prune: add dry-run support fb75774a43 Document tmpcopyup default behavior for tmpfs mounts 8ae6f02b3f docs: clarify podman pod ps default output 2f17614d0e fix: duplicated words in decompress.go log message and annotations.go comment 6ad87d00e0 Add nightly release pipeline validation 3ac6501fdd API Handlers should not error on empty request bodies f33ef6a77f test/system: log socat output in retry loop b571943fe4 api: emit aux trailer with manifest digest on image push 6e089b421b completion: add artifact support to podman inspect e131ee6274 Remove deprecated release actions 879594a2f9 chore(deps): update dependency requests to ~=2.34.0 40e572f2ed Update oc/selinux to v1.14.1 a6e58ea101 wsl: remove custom registries.conf 93b615c1f2 machine: move marker file to /etc/podman-machine e34f3bce0c machine: remove SSL_CERT_DIR/SSL_CERT_FILE copy b14e833ef6 machine: add test to check config mount 5e193ce96a wsl: mount config home dir like on other providers 41adad8ce9 machine test: combine three test cases 49ab599855 vendor: update container-libs to latest ec583fa17f filters: add annotation filter for containers Fixes: #28562 3f0cdca48a Update module github.com/containers/gvisor-tap-vsock to v0.8.9 1a20d82edc libpod: replace listen with socket+bind for dual-stack port reservation 33db50ab24 troubleshooting: document setgroups requirement 11399b7229 Update module golang.org/x/net to v0.54.0 06ce73de61 Update module github.com/openshift/imagebuilder to v1.2.21 d9836ac255 troubleshooting: add tip about is transient 6cc0439b8f troubleshooting: add tip about could not connect a3ea76b6a3 troubleshooting: add tip about bind permission denied ec6415f7c6 troubleshooting: add tip about Connection reset by peer 644104a8b5 troubleshooting: add tip about pod uid/gid map d420fbfde3 Add migration code for BoltDB to SQLite 462b24479b Use tmp context dir when building with process substitution 89efbf1dce pkg/api/grpcpb: auto-format generated protobuf files d54f1eb6fe machine/wsl: remove some dead code d9e7eaac87 Update dependency golangci/golangci-lint to v2.12.2 056ad339de vendor: update container-libs to latest 2ea149d850 Update module github.com/hugelgupf/p9 to v0.4.0 abf885dfcc Re-add a minimal version of BoltDB for migrations d8df5c37ef specgen: memoize isMqueueSupported with sync.OnceValue f4389592f9 test: ensure complex --output values have correct behaviour a267230118 docs: fix incorrect page name b74c4a3ec7 fix(markdown-preprocess): preserve unknown tokens in render() 1bda61b840 specgen: skip /dev/mqueue mount if not supported by the kernel e84d7fe691 Vendor container-libs and Buildah at main 821e4d263e Update dependency golangci/golangci-lint to v2.12.1 d5b4685cc8 Fix lint issue with replace reflect.Ptr with reflect.Pointer 7612af4c0e Rewrite the Quadlet documentation afd4d3d71f Update module google.golang.org/grpc to v1.81.0 e880d0550d AGENTS.md: address review feedback from PR #28593 27fde9c84a AGENTS.md: add structured Persona section for AI assistants ec4b72082a Update common, image, and storage deps to 3ceb1b2 74ea692e8b Update dependency golangci/golangci-lint to v2.12.0 8a064651e8 troubleshooting: document keep-id size option ddb3f8ec44 Update module github.com/shirou/gopsutil/v4 to v4.26.4 b197c3324f Core maintainer meeting minutes 3f883706ba Import local certificates to machines on macOS and Linux c7ed32c266 libpod: limit splitting of cgroup fields 4a3b214e3f Sort network ls labels dc4495ec64 volume ls: format labels as comma-separated key=value strings f460bc0ae5 ps: format labels as comma separated key=value for Docker compatibility 46b45de563 Packit: Only create dist-git PRs for rawhide 336601535a [skip-ci] Update r-lib/actions action to v2.12.0 456f75b975 vendor latest common, image, storage 15c9ca130f Add command `podman system hyperv-prep` 92d186f20d Hyperv machine init/rm: skip win registry operations when possible f6b6bce745 Minor hyperv stubber.go and vsock.go refactoring 86d0edfbc3 RUN-3620: Document dropped support 4e19b8e6a9 Update module github.com/mattn/go-sqlite3 to v1.14.44 fdd8cc17fa Fix filtering with negated labels efc6ddfcc4 cleanup: run go fix on pkg/machine for windows 91af36106c Update module github.com/onsi/ginkgo/v2 to v2.28.3 12d40777f0 test/system: fix quadlet - rootfs on kernel 7.1 bb02e49080 Adjust error messages for new netavark create 09103756cc Vendor container-libs main 50bf7db0d9 test/e2e: fix broken checkpoint tests c1d4e1491a test/e2e: port some checkpoint tests to PodmanExitCleanly 09b7f59f99 Improve docs on passing multiple --filter flags 7812e9d814 [skip-ci] Update dawidd6/action-send-mail action to v17 f68103d3ad Packit/TMT: Use podman-next for tmt-revdeps test 455367165c Update dependency openapi-schema-validator to ~=0.9.0 f275c72090 Packit: mention tmt_plan for cockpit revdep tests b0f1889de7 contrib/packit-tmt: Rename script for clarity of intent 61792bd9cd TMT: Remove test/tmt/tmt.fmf 9b253ab347 Update stale comments referencing slirp4netns f493ef0734 test/system: re-enable module command line completion test 6d2e083446 vendor: update latest common, image, storage 1b99ae56b0 New images 2026-04-24 94b56a82e3 Remove OWNERS file 2de618b13d Review MAINTAINERS.md 24130e2a0c keep pod hostname when a container is stopped d01cd46830 test/system: skip podman checkpoint --export, with volumes on aarch64 46aa8b83a4 test: remove outdated checkpoint skip 56a24d5183 fix container inspect output to not escape html chars e74582fcd5 remove CONTAINERS_REGISTRIES_CONF parsing code 5504338c36 vendor: update common, image, storage to latest bf76b9133f move old registries.conf v1 files to v2 f2994dc695 move the python API tests to the cache registry c4a4c7e117 API: Add Health field to compat ListContainers and restrict to v1.52+ d44655537e fix: ensure infra image is set from infra container spec in PodConfigToSpec 2cc3be7332 RUN-4539: Change podman module paths 6df67e0e19 Fix LegacyNetworks comments and add deprecation notice 9762b6b8dd Add lstocchi as Podman reviewer 103d059904 Reuse found network in NetworkDisconnect 2adfe1d4d9 Verify that a Volume config was actually deleted 57eeb47143 auto-add user to Hyper-V Administrators group a1734fb02b [skip-ci] Update dawidd6/action-send-mail action to v16 2e6f29a2df RUN-4538: Fix buildah vendoring d1ef890bd6 Update module github.com/moby/moby/api to v1.54.2 69ae4645c1 Add a process for adding and removing subprojects cae4c40323 compat: limit `err` scope in CommitContainer. 03afb7403d trust: fail on policy path resolution errors, remove fallback logic 54d61c2f02 trust: switch policy.json lookup to configfile ecf493dea0 Fix Docker compat /wait hanging on fast-exiting containers 64f9059d2e Fixes: #28531 Clean up temporary file for CreateImageFromSrc efba9996f6 Implement `--save-stages`/`--stage-labels` for build 5e94c95ad0 Move to deterministic network setup order d92cc360f1 Add Pod to quadlet list f15b8e1b2b Sort cliOpts fields alphabetically in Compat Create 41b785af5e remove isolate option from docker compat API d2d508bd89 Update module github.com/docker/go-connections to v0.7.0 f7dd6156d3 Import host certificates at machine startup on Windows 8e78ca8ee6 [skip-ci] Update actions/github-script action to v9 53fc1d902e Install WiX v5.0.2 to build the Windows installer 9598b30ac2 Fix healthcheck failing silently with --transient-store 111b4cf3f5 Fix docs --mount source not mandatory for type=volume 30cfafe39c Clarify specific pasta parameters passed by default 698c483b7c fix: Ensure OCIRuntime Field is not ignored with HTTP Rest Api (#28454) a73686120d Update module github.com/containers/libhvee to v0.11.0 3082e88d2e [skip-ci] Update zizmorcore/zizmor-action action to v0.5.3 8059539425 Quadlet - Support empty source for Mount key f374f2c95b Fix Docker API DeviceMapping for CDI devices b140b5d15d Update module github.com/mattn/go-shellwords to v1.0.13 571c842bd3 hyperV: fix powershell path escape a61147184d Remove misleading configurable reference in podman-network docs 3c79df31a4 Fix pasta_opts compose test to verify MTU option 9ff3f4cb1e Clean up outdated slirp4netns references in comments 3f85c7df43 FreeBSD: add lint exclusion for rootlessPortSync fields c23da53456 Remove unused slirp4netns imports and Slirp4NetNS field 8d6c23dad1 RPM/TMT: drop slirp4netns dependency 6859a9e512 Remove slirp4netns from documentation 42a98a5a82 Remove slirp4netns from CLI and completions cefb944647 Remove slirp4netns setup functions (preserve RLK) e81328e2a2 Remove Slirp network mode constant and error on usage 3317eb9abb Set pasta as default when default_rootless_network_cmd is unset a172d25f86 Add slirp4netns to pasta migration 22054b5180 test: Remove slirp4netns-specific test cases abd25c09e0 test/tools: update swagger to v0.33.2 eb9f39acff chore(deps): update module golang.org/x/crypto to v0.45.0 [security] b95a1b0af4 Update module golang.org/x/net to v0.53.0 3e9e9f3833 Update module golang.org/x/term to v0.42.0 12bec19426 bindings: artifact extract reject invalid names 25aee24cbd use chrootarchive over plain archive package abb5120624 fix symlink handling in checkpoint restore 92d0392ca2 Makefile: fail early with a clear message on darwin/amd64 8dd7ac5756 Fix: set Swappiness when no mem limits f0d1b54fad fix(deps): update module golang.org/x/sys to v0.43.0 4f252be4a0 Fix inconsistencies between --all and --filter=all in volume prune 5b60355fee docs: fix parameter name for podman-network-create 3ca47bf897 chore(deps): update dependency pytest to v9.0.3 23f0386587 Revert "fix(artifact): show :latest tag in ls output when no explicit tag given" af4f2be43b Revert "test(artifact): add e2e test for untagged artifact default tag" 98abcdcb19 Use AND to combine different volume filter keys 2d5f5395c2 test/system: Fix 260-sdnotify being silently skipped 85f300ef44 chore(deps): update module github.com/go-jose/go-jose/v4 to v4.1.4 [security] 5ff106da75 fix(deps): update module github.com/moby/moby/client to v0.4.0 a9a9eda883 rename ErrRelaunchAttempt to ErrRelaunchSucceeded and fix elevated error handling 8e5fde01c6 propose running init/rm command on hyperv machine in elevated mode 5b0ec91c54 move wsl' util_windows to windows package so it can be reused by hyperv d10a858cb6 fix(deps): update module github.com/mattn/go-sqlite3 to v1.14.39 2e66f1c38e Update quiet.md d20933df02 add missing O_CLOEXEC to open calls 1bf1c95f95 Docs: improve readability of quadlet documentation c57f9f49a3 Fix .containerignore patterns with leading/trailing slashes 24ee5aec48 Add new flag `--import-native-ca` for `machine init/set` 4bba8c267a Extract function LocalhostSSHCopy to make it visible from other packages too 8babd48d59 Fix IsPathAvailableOnMachine when Windows drive isn't C: e8ab721d59 fix(deps): update module google.golang.org/grpc to v1.80.0 ee83454a00 fix(deps): update module github.com/shirou/gopsutil/v4 to v4.26.3 e6b93ed936 fix(deps): update github.com/opencontainers/runtime-tools digest to 8a4db57 51175b7e17 fix(deps): update github.com/hugelgupf/p9 digest to ba5af0b cf6404f387 Fix Quadlet `Lookup()` stripping unmatched quotes 8b905613b5 Add e2e test for shell driver DriverOpts cross-contamination fix e76f70bb13 chore(deps): update module github.com/moby/moby/v2 to v2.0.0-beta.8 [security] 667f55c2ce Fix shell driver DriverOpts cross-contamination in secret creation 19e70b00fe fix(deps): update module github.com/mattn/go-sqlite3 to v1.14.38 1d4465abf7 test(artifact): add e2e test for untagged artifact default tag 3bd376401e fix(artifact): show :latest tag in ls output when no explicit tag given fdf663b079 compat: map internal states to Docker equivalents in LibpodToContainer 497185c14b libpod: fix data race on deferredErr in attachExecHTTP 04935fe867 Add a Status filter to podman quadlet list 6f286ef52f #28374 de-duplicated --quiet option from docs 0cb862ec35 feat: add list as ls alias for artifact command. Resolved ##28372 d2ff809c66 Fixes: #27620 replace dots by hyphens in kubectl volume names generation e58ec4dc07 Address seccomp profile todo: 047aae4116 feat: remove reference to `--help` from artifact man pages. Resolves: #28373 200cb42296 fix(deps): update module golang.org/x/net to v0.52.0 765ffb9a2e Consolidate build secret tests and assert no podman-build-secret leak e50974edc9 chore(deps): update dependency requests to ~=2.33.0 218f94785f Add Avassa Edge Platform to adopters list e18bb9ea8b Remote build: `nTar` secrets with relative paths and ignore bypass 1413923c13 Change `localapi.IsPathAvailableOnMachine` visibility 29d80a26af api: fix missing return after error in SystemCheck handler ef7d9aa672 fix(deps): update common, image, and storage deps to 7e1f14c c722f2f6e7 Validate memory on every init, not only with --memory bb4dda4855 Reject --cpus above host CPU count on podman machine init and set 48d36932e2 Error on WSL machine os apply|upgrade 427aded546 cirrus: do not remove /usr/share/containers/storage.conf 91bae6f6e4 test/system: drop outdated comment d6dd82bf24 winmake: fix typos in comments and warning messages 13022e739d chore(deps): update dependency golangci/golangci-lint to v2.11.4 b77531879b test: relax rootless runc pid namespace assertion f3f36d176d ci: add riscv64 cross-compilation to Cirrus CI alt-arch matrix acd5f94d84 specgenutil: remove special handling of `0.0.0.0` for netavark 9565002257 feat: add support for changing default host IPs via containers.conf a33114f248 test/upgrade: remove storage.conf mount ac49a4b416 cirrus: setup composefs in rootful storage.conf bb5f759ba8 test/e2e: fix podman pull and run on split imagestore test 6be50cbb38 test/system: fix empty default test c7e51fa1c1 cirrus: make sure we do not test the fedora storage.conf file 78c28fc254 vendor: update container-libs to pick up storage.conf rework f2bc5b86de New images 2026-03-19 da3c4aa21a Add --format to image scp 2eb20b3dd9 test: skip build-conflicting-isolation-chroot-and-network on remote 9837656d26 docs: remove rootless CNI troubleshooting section 040e6784d8 Makefile: remove FreeBSD CNI build tag 7d50844922 test: remove CNI_CONFIG_DIR env var handling 61cb417c26 Remove CNI references from comments 8d1f636e40 vendor update without CNI in buildah and container-libs a2db18f35c rootless: detect and remove stale pause.pid with recycled PIDs d887a8146a Fix creating unnamed volumes as anonymous a63910314f Refactor volume_prune tests to use PodmanExitCleanly 339acf880c volume prune: match Docker default and add --all 9a10cefd18 libpod: Don't dereference ctrSpec.Linux if it is nil 6f497d2437 Extend libpod pull API to show pull progress 0b3190b3b5 fix(deps): update module google.golang.org/grpc to v1.79.3 9dcc73079f Bump bundled krunkit from 1.1.1 to 1.2.1 b69c62be04 fix(deps): update module github.com/mattn/go-sqlite3 to v1.14.37 97691c8e1b chore(deps): update dependency containers/automation_images to v20260310 938d677ad9 cirrus: bump linux machine aarch64 test timeout 7326b862e3 Fix `unless-stopped` containers not restarting after `podman-restart.service` stop them acf6472f5b Ignore operational EndpointSettings.IPAddress for static IPs in compat API 68737b35cd Vendor: go.podman.io/storage@main, go.podman.io/image/v5@main, go.podman.io/common@main 1ccded76ce Use InspectNetwork helper in e2e tests 6acfd58026 Add multi-IP container support 71e0456b1b [skip-ci] Update actions/create-github-app-token action to v3 7ecac4a65e compat: return 409 Conflict when container name is already in use c7921b0049 feat: print client info from `podman version` when the server is unavailable 926f562bd5 quadlet: allow empty Entrypoint to clear image default 3edb22b509 [skip-ci] Update GitHub Artifact Actions 12d645ac20 fix(deps): update module google.golang.org/grpc to v1.79.2 67ccf4940c tests/e2e: Do not try to list /proc/acpi on non-amd64 07314bc606 fix(deps): update module golang.org/x/crypto to v0.49.0 1f3c344312 run modernize -fix ./... 9278b45424 bump go.mod to go 1.25 cd2f122fb4 test/e2e: Skip some tests on non-amd64 architectures a5dbe484d3 test/e2e: Introduce SkipIfNotAMD64 helper e5f61281ff test/e2e: skip LINUX32 personality check on non-amd64 architectures a4d0fd8853 test/e2e: Add linkat to seccomp profile 0904bab01e add trailing newline to subgid due to shadow-utils 4.19.0 regression e39781979e Improve mac_win_client tutorial structure and links 6637454464 Add tutorial for running podman machine on macOS startup a414460351 chore(api): add swagger docs for undocumented API parameters 791ade7c31 fix(deps): update module github.com/moby/moby/client to v0.3.0 1fe0238758 chore(deps): update dependency openapi-schema-validator to ~=0.8.1 ffeb0d103b Improve OOMKilled visibility in podman events and in podman inspect docs a57b1e72fd fix(deps): update module github.com/shirou/gopsutil/v4 to v4.26.2 89d4fcd791 [skip-ci] Update zizmorcore/zizmor-action action to v0.5.2 ed3d3688dc chore(deps): update dependency pytest to v9.0.2 1aadae04af Look for rootless quadlets in /usr/share/containers/systemd/users 4f1d4ae8a0 fix new lint issues from prealloc 1c21eed0fb update golangci-lint to v2.11.3 35f9d61fcb Improve relabel EPERM error for rootless 458fcaa1ba specgen: fix pod mount options leaking between mounts 8c4edb6121 libpod: include names-generator.go 76095dbadc Make libpod return error status code on failure to pull image 01688e7621 Deprecate Legacy structs and use port.String() c10f685b43 api/compat: Backport jsonmessage.JSONProgress.String() 65585e4338 compat/network: Remove temporary ipvAddress variables. 56e555bfc2 api/compat: switch to moby/moby c30fe73dfb Quadlet docs: clarify behaviour of `VolumeName` default 31b956e0f1 Fix CLI help example indentation for multi-line examples dd83595619 New images 2026-03-06 636eb1a401 libpod: Implement --log-opt label=LABEL=Value 047e178298 Quadlet docs: add section on referencing other template Quadlets 7fd3be8288 Add --tls-details support for (podman login) and (podman logout) 13e1d5af4b PARTIALLY TESTED: Add --tls-details, use it to affect libimage and the like 56ce3368be vendor: update container-libs to latest a2f0e0da47 artifact: do not set SystemContext in CopyOptions 9872cbd756 libpod: Validate that log tag requires journald driver b2d381c7a2 Inline createCommands into the caller a725f55ff1 Make CreateCommands and ScpCreateCommandsOptions private acdaa5372e Don't use strings.Split(fmt.Sprintf("--a b ...", ...), " ") b1837f8824 Rename the fedoraMinimal constant to FEDORA_MINIMAL cb9df63d63 Fix compilation of tests without CGo c42350a5a2 Fix compilation of tests on arm64 5c52f029f6 Add Danish Prakash as a reviewer 33a36bd56b fix(cmd/podman/quadlet): Behave like container ls a38a9b7d20 fix(quadlet): fix race condition, duplicates, and permissions 8b868f83af Governance: Make each role's GH permissions explicit 97a5e4ce01 Move Urvashi and Valentin to alumni a37bf83dfc Also set DestinationCtx in a copy e04b77e600 Consolidate the call to bindings.NewConnectionWithOptions fd86c3c25f Use pullOptions.systemContext in getDestArtifact 5946f7afcf Factor out pullOptions.systemContext from pull e807ae4350 Make ocipull.Pull and PullOptions private 2d4fb908a1 Pass all of Options to tcpClient d561f13d7c Simplify setting up Runtime.imageContext 2ac337dbd8 Behavior change: Don't change TMPDIR in WithRegistriesConf 2ab78a8d82 test/system: fix some teardown error logging 4bdc1d372a [Design Doc] New feature to import local CA certs f31ab04ec7 Update LLM_POLICY.md 6beca1cbeb Back New{Container,Image} engine with the remote implementation on macOS d06c4569f0 Make most of libpod, and everything that relies on it, non-darwin 4c3027c149 Make most of libpod, and everything that relies on it, non-darwin 30f067354f docs(podman-systemd.unit.5.md): document protocol support for PublishPort 84eff9ef3b Fix: Rootless Podman-in-Podman on WSL 6c41f55aa7 Quadlet Volume - allow setting mount option without a device f58c9dcbcb docs(podman-systemd.unit.5.md): add `ServiceName=` option to all Quadlet types 64ec31ac00 Add nocreate option for named volumes e914c30dd5 update swagger changes dc9adfeaff Add LLM (AI) Policy. 03d9de1528 Fix container clone with secret type=env 176bab3feb docs: update rootless default networking mode 9a1e5e8eeb cmd/podman-tetsing: fix incorrect error message 960165b8c5 test/system: fix pod inspect ordering test leak 35d088ff83 chore(deps): update dependency openapi-schema-validator to ~=0.7.1 02f0766a79 update golangci-lint to v2.10.1 8a0c777017 fix new staticcheck warnings 5e3719c81a fix two issues found by nilness 072018096d docs(podman-systemd.unit.5.md): Fix variable syntax fc089d7f1a docs: add examples for rm with --force and --time 476ca11994 test: Use yq for yaml2json when available 4fae160fcf Fix documentation inconsistency about labels 0d7f00b4c0 List all status values in status filter documentation 72a0a1179e test/buildah-bud: skip build-with-run-mount a3198235bf bindings: do not validate source policy on the client 474ff994b6 build: connect --source-policy-file, --mount for remote builds 8af2158a83 vendor: update go.podman.io/... and buildah to latest ed8eec6bbf using Debugf and removed wierd DEBUG logs 9b611b5380 docs(quadlet): Unify [Network] section on removal 64a3e31ab9 migrate to oidc 33e8abd637 Respect user-specified Restart= policy in pod units 1aefd06760 test: remove redundant test for restoring with --publish without --import 751d6f7953 updating pr review and approval process 901ac1b416 feat(cmd/podman/quadlet): Add 'ls' as 'list' alias b12c51e5a4 fix(cmd/podman/quadlet): Indent all examples 60cfb66d8f podman system reset: do not print storage.conf warning 0778bdaffe podman info: remove storage.conf path a1afa58e27 system service: remove config reload functionallity b45b826061 DESIGN DOC: update config-file-parsing 5a1a54424c fix: enforce --publish option usage with --import in podman restore de35ca847d fix(deps): update module github.com/kevinburke/ssh_config to v1.5.0 b584337bd6 compat/api: honor VolumeOptions.Subpath for HostConfig.Mounts e9ba515fcf Add debug logging for EnvSecrets to diagnose restart mapping issue ac7d6c3fc4 inspect: preserve secret target name in env masking 2369ed4b71 docs(podman-systemd.unit.5.md): remove false claim on Pods HostName key 24a04de921 libpod: fix build 243df78fb9 adding assign github action c69072edb1 update cherry pick with pr df0e3b6ec7 libpod: validate artifact volume on create 3d1dfe6540 fix(deps): update module google.golang.org/grpc to v1.79.0 d7a80dda1e Discover vendor from cdi spec before injecting CDI device for --gpu option 0ba42fe487 ci: bump golangci-lint to v2.9.0 94442ae44e pkg/machine/e2e: simplify runWslCommand f9002cfd31 Fix GOOS=windows prealloc linter warnings 3c3d32718f libpod: do not reuse names slice 2a99655120 machine: prepend LocalhostSSHArgs to args b046387979 Inline the initial slice into append 38f6bf07cc pkg/emulation: remove slice copying 030057aecd Preallocate a slice d316cbb362 Don't use append if not necessary 9727a43f5a Added setting UID and GID for volumes in quadlet d02c3d3b80 chore(deps): update docker.io/library/golang docker tag to v1.26 7713a75564 fix(deps): update module github.com/mattn/go-sqlite3 to v1.14.34 73cede901f fix(deps): update module github.com/containers/gvisor-tap-vsock to v0.8.8 1243b2baec Fix broken links in transfer.md cfc9510847 fix(deps): update module golang.org/x/net to v0.50.0 2828965a75 healthcheck_linux: avoid failing transient units 3856389fc9 podman-healthcheck-run: add --ignore-result flag 7cefd013ca chore(deps): update dependency setuptools to v82 460feba9c9 fix(deps): update module golang.org/x/sys to v0.41.0 e61ce8d6ea Added healthcheck documentation. Fixes: #27202 49cce3ec16 libpod: modernize state test a798f30849 fix(deps): update module github.com/shirou/gopsutil/v4 to v4.26.1 af7c36eae3 make curl error on non success status codes aec7f806b5 [skip-ci] Update zizmorcore/zizmor-action action to v0.5.0 2c4e9333ac fix(deps): update module github.com/openshift/imagebuilder to v1.2.20 246a4acde1 test/system: update module error messages bf7871fbcd vendor: update container-libs to main efdfece881 fix(deps): update module github.com/onsi/ginkgo/v2 to v2.28.1 90cf2ec34d Revert "cherry pick bot github action" fc18d3229d [DOCS] Update references common -> container-libs/common 22b10abbf3 [DOCS] Fix reference to containers.conf 36e7b9f1c0 fix(deps): update module github.com/onsi/gomega to v1.39.1 82e04e8d7f fix: prevent race condition during database initialization by using INSERT OR IGNORE. fae93fe483 fix: use localhost for host.containers.internal in host network mode e1dfd455e7 cherry pick bot github action 1bfd4cb95b Fix healthcheck argument with spaces split in Docker API (#27818) 827ba37b3e build: handle `--iidfile-raw` and `--metadata-file` flags 40b2a585f9 Autocomplete machine fixes 1a5822dc91 rootless_tutorial: mention LDAP support for subid ranges f4138d3599 add bootc transports to os-apply 644bf2e04a Fix interfering escaping of commas and spaces in no_proxy variable a6167bdecc Write DefaultEnvironment proxy values to /etc/systemd/user.conf.d/default-env.conf e545f9ca61 Fix test proxyenv/env_test.go for systems that use proxy variables 9e530ca938 Update Lewis' affiliation 3b3cb1f958 vendor: update buildah to latest main 19aba793c0 remove dep on github.com/containers/conmon 7778b427eb Do an update pass on rootless.md to bring it up to date 5f19b25aaf Add cache volumes for validatepr builds 07ab42eed5 [skip-ci] Update GitHub Artifact Actions 1bff1ad004 fix(deps): update module google.golang.org/grpc to v1.78.0 d9b42515da fix(deps): update module golang.org/x/net to v0.49.0 3be0eb8b40 fix(deps): update module github.com/coreos/go-systemd/v22 to v22.7.0 27d0f5fff6 typo: resouceNames to resourceNames 568f9645c5 chore(deps): update dependency setuptools to ~=80.10.2 0c04f53374 [skip-ci] Update zizmorcore/zizmor-action action to v0.4.1 ce568f75dc chore(machine): remove unused EvalSymlinksOrClean function and tests 36d4c7c696 fix(deps): update module github.com/rootless-containers/rootlesskit/v2 to v2.3.6 eb0c4716d3 Add GET /quadlets/{name}/exists 7331ccbc16 [skip-ci] Update actions/checkout action to v6.0.2 f71465a025 Fix PowerShell `Write-Error` multi-line argument 721e889476 Update tutorial documentation to remove CNI references 7ebb95a3bf Update man page documentation to remove CNI references 454167efa9 Remove CNI-specific code paths from libpod f6bddc8af2 Remove CNI backend configuration from runtime 73ef7cfcdc Remove CNI backend from CLI options and completions 83ffeb1b26 Remove test infrastructure for CNI/Netavark backend selection 858cb58c90 Remove CNI-specific test cases 2d67bf3b0a Vendor common test for artifact digest lookup d04c84e783 fix: generate correct error message if Wix is not installed d8f5368428 fix: correct env/envFrom precedence in kube play cfa1b51775 fix hyperv ignition cleanup and error handling f172ff789b rootless: use nsfs file handles to persist namespaces ea01acf325 Set architecture for validatepr builds f0dd315bdf systemd: update podman-restart.service description 6c1d8f5d76 libpod: fix Volume.Mount() returning empty path for plugin volumes 1ebdd09ab3 Don't assume v1.41 is the default docker c9e20280ed Bump Compat API version to supported v1.44 aba2df7517 Add podman machine os upgrade command 87df3e4749 Update the Podman on Windows tutorial for 6.0.x 0d3c438803 Quadlet - do not link pod service units to quadlet templates 2e23fcc5a5 Add DELETE /libpod/quadlets f96e0a3fb2 Fix podman run equivalent for HealthStartPeriod 86a3b681d2 secrets/create: remove pipe check and allow interactive stdin 8bd92f52ab Update the Podman on Windows tutorial for 5.7.x 231dbdf5b3 Fix container export emitting incorrect event type. f6e3200f40 libpod: simplify unnecessary loops 1abe1942f8 Update module github.com/crc-org/vfkit to v0.6.3 ca44e3a4d7 Fix race condition in CleanupGVProxy when reading gvproxy PID file d2ea5a3fd0 prevent starting/stopping legacy Hyper-v machines when not elevated 76e14f79f7 use bootc for os apply 6d28009edb test/e2e: Skip privileged container test if NoNewPrivs is set 86799cb2cb Fixes #27651 - Fix health inspect/ps for rootfs containers with empty healthcheck 174e02ae55 test: Fix --hostuser octal UID test flakiness 6fd970afe0 design doc: config file parsing changes 90f45bca77 extract shared TTY handling code into helper function 40587205cf Add Dave Darrah as community manager 356e6a3ecf Governance: Community Managers can assist in triage 73135ff6f0 test/system: fix log timestamp work around 7a87456fdd Fix docs for Volume User= and Group= options 8d3ac1a1f6 test: Fix PODMAN_BATS_LEAK_CHECK 74043cf726 Remove legacy win installer files d9975a5390 Stop copying gvproxy in legacy installation dir 7f16628a50 Stop releasing the legacy windows installer 7bcf5e1de4 docs: correct 'abbrieviated' to 'abbreviated' in RELEASE_PROCESS.md 05ddbbcd34 docs: fix typos and standardize timezone in ISSUE.md 02c2babe84 docs: correct 'where as' to 'whereas' in Downloads.md 309f8c0747 Use non-destructive 'set --rootful' command e4bd3e6f20 Update rootless_tutorial.md - minor text correction e6c3e4f411 docs: fix misleading TimeoutStartSec information for oneshot services 74c0795a7c [play_kube] Add validation to container image field aa1d7b189a Remove network-cmd-path d54a053d0a Remove extra spaces from secrets cmd example eaf4d4ebc9 fix: remove unnecessary -t flag from podman run commands in documentation 3e6781f05a Add POST /libpod/quadlets 9a2c8b615e Fix missing newlines in stderr error messages 890a3a1faf docs: Update LFX insights badges in README c186a337ca Add /usr/libexec/podman/qemu-system-arch 20e61ba88e [skip-ci] Update dessant/lock-threads action to v6 15ae942a48 test/system: remove apk from build 811c818fc9 test/system: skip podman volumes with XFS quotas on fedora 7e3caaed84 cirrus: ensure NOTIFY_SOCKET is properly unset for all tests e78fb1ed27 fix(deps): update module google.golang.org/protobuf to v1.36.11 3f49b284f7 Update podman-for-windows.md 0e45e7003c fix(deps): update module tags.cncf.io/container-device-interface to v1.1.0 5d79adbd6a update fedoral base image to 43 and related tests e49992fef6 fix(deps): update module golang.org/x/net to v0.48.0 0a1f564289 fix(deps): update module github.com/checkpoint-restore/checkpointctl to v1.4.1 88bacfc133 fix: skip execution of probes when initialDelaySeconds is not elapsed b53159d0f2 renovate: remove old c/{common, image, storage} config f348a0717d Vendor latest mono repo for libartifact changes 22b10fa153 Use explicit download-artifact name and path for win-installer release 9fe88a5539 Finish review comments 84a2902d32 kube play: Fix fd leak when handling symlinks f095336456 Update to resolve most review comments 8d7e200f88 Initial draft of AGENTS.md f87cefc262 Remove Intel MacOS support e28d1e57fa fix(logs): enhance timestamp format to include timezone in logs 2bbf26de0c fix(logs): add tests for nanosecond precision in log timestamps 4043a4bb0c docs: Update filter options and add podman ps documentation 60a5a476d5 fix(logs): improve timestamp precision in container logs 3b080ce918 docs: Deduplicate --filter descriptions a8ecb80ac0 Deterministically order pod inspect fields d18e44e9ab libpod: simplify resolveWorkDir() 7b1be7f177 libpod: fix workdir MkdirAll() all check 2461ccd621 Add Repository and Tag fields to image list --format JSON output 1dbb897733 ci: add Zizmor workflow fdbb696731 bindings: fix handling of env secrets in remote builds b78f1cf986 vendor: update container-libs to df55d6c661e8 for cgv1 removal 1bddd38e0a Add perl to make validatepr d150051d7a add windows platform tests 85fe4de1ee fix failing windows platform tests 1bd51314ff prevent non hyper-v admin users to execute machine commands 4d3c6311a5 Fix `unless-stopped` restart policy to match Docker behavior 67c050bb8e ci: use env vars to avoid template expansion in code contexts 3f4af378f4 ci: use --sandbox for dynamically generated sed scripts b9736e8d11 ci: pass secrets explicitly to reusable workflow 64ddbfea12 ci: disable caching for actions/setup-go 0752c5327e ci: specify persist-credentials for actions/checkout 30495081b7 ci: specify workflow permissions per job 248d8f64a6 ci: pin 3rd-party action dependencies by commit hashes 5fa0327246 Update module github.com/shirou/gopsutil/v4 to v4.25.11 b56ddd03a6 Update github.com/sirupsen/logrus digest to b61f268 89ddae8b12 Update common, image, and storage deps to 94e31d2 2e26deea33 Add test for exposing default network name in podman info 129f7ae152 docs/podman.1: Fix leftover rootless mention ed6f63af10 libpod: fix healthchecks not executing every interval on linux ee0efb9fc6 Add GET /quadlets/{name}/file f71b9335f1 Replace FindExecutablePeer with FindHelperBinary 2613d73ab6 Vendor container-libs to get Windows defaultHelperBinaries fix 786012a670 Remove deprecated --macvlan flag from network create b9a1f87b9e rootless_linux.c: use shortcut for system commands aaadb4726d SetupRootless handle case where conmon pid are not valid 4833357c72 preallocate paths in SetupRootless ed9d298fb4 fix noMoveProcess in SetupRootless c3f3dd36c4 use return error handling in SetupRootless 200030914f pkg/machine: make mount units hook into local-fs 417430c451 fix: improve userns validation when joining pods 99a7f9f38d fix(deps): update common, image, and storage deps to 22d50c5 7b30d9cd3f docs: further tweaks d1c2afc941 docs: improve note about Quadlet TimeoutStartSec d163c38a26 vendor: update common, image, storage to main a331c51c05 [Fixes: #27571] Fix 'shouldResolveWinPaths' returning 'false' on Windows d31f4e782d fix(api/compat): typo in the remove secret handle a9dd858c49 Clamp rootless rlimits to host on format e0fc51eb68 Add ulimits to `podman update` API 343a196448 Remove iptables references in docs aa5361ac53 Remove iptables references in upgrade tests bd02d6fd74 Remove iptables from Podman prerequisites db9e0b97f6 Remove iptables references in system tests 9c2a738963 Stop enforcing iptables on WSL 7741e047dd podman-systemd.unit.5: document /sbin/nologin accounts a23b90b119 [skip-ci] Update actions/checkout action to v6 901bd69e05 remove legacy registry entry 23a297198e add test to verify init reuse hvsock entries for hyperv machines ab89922f4b hyperv should reuse hvsock registry entries when possible e70076f809 New images 2025-11-20 8411881ab2 avoid potential nil ptr deref in image rm b62c82bff6 move HasAdminRights to windows pkg fdc738b0df fix: check err returned by newGenericDecompressor f8b968246d fix(deps): update module golang.org/x/crypto to v0.45.0 [security] 3d566d85cf Ignore prompt if stdin not a tty on machine start 61cbc0c3ee feat(exec): Add --no-session flag for improved performance 28b125837b Add --network=host to validatepr container for GitHub access d889aeb6af artifact: Skip AddLocal optimization on WSL 2f7094c0de Require absolute path for local API 91af437471 Add local artifact add API endpoint d22e50eac9 test/system: remove deprecated cgroupsv1 skip check 1e5a789bef fix(deps): update module google.golang.org/grpc to v1.77.0 c22c3271bb quadlet install: multiple quadlets from single file should share app 453a45142f machine: change default macOS provider to libkrun b8f24004d0 Packit: Disable testing-farm dnf repo 91183a40b4 pkg/specgen/generate: Fix adding host devices on FreeBSD bfd51c2715 fix(deps): update module github.com/opencontainers/selinux to v1.13.1 c9d99dc98a fix(deps): update module github.com/godbus/dbus/v5 to v5.2.0 65411d53c9 Revert "Fix copyUIDGID parameter inversion in Docker compat API" 6f9bf07a34 swagger: fix for new docker/moby module conflict df4905d68b Remove hardcoded refs from ociartifact code 613ac5bd73 chore(deps): update dependency pytest to v9.0.1 f47f74cad6 pkg/specgen/generate/kube: nolint and FIXMEs for seccomp deprecations 96aba07d95 libpod/container_internal.go: util.SizeOfPath -> directory.Size f11392c719 Remove deprecated fields ctrConfig.[StaticIP,StaticMAC] 3842f4d4e5 pkg/specgen: Remove deprecated CNINetworks 5d46171b7d bump golangcilint to 2.6.0 a3fcf52a1c Fix deprecation notice to make gocritic happy. 145540fed4 Remove ContainerStats.PerCPU: CGV1 only bb3c8b9ecd docs: Remove Cgroups v1 036bf7b44f test/system: delete CgV1 skips and skipped CgV2 tests 4970fd26e4 test/e2e: delete CgV1 skips, delete tests skipped on Cgv2 5e02967fd7 pkg/api/handlers/compat/containers_create.go: Remove Cgroups v1 6f43a66629 cmd/podman/system/service_abi_linux.go: Remove Cgroups v1 5d7358d2bf pkg/api/handlers/libpod/containers_stats.go: Remove Cgroups v1 30d07aa0c8 pkg/domain/infra/abi/containers.go: Remove Cgroups v1 a994aef330 pkg/domain/infra/abi/pods_stats.go: Remove Cgroups v1 850bae519e pkg/specgen/namespaces.go: Remove Cgroups v1 c98c50ec76 libpod/pod_api.go: Remove Cgroups v1 06bc277ad8 libpod/util_linux.go: Remove Cgroups v1 a12b3e97d2 libpod/runtime.go: Remove Cgroups v1 faa551a921 libpod/runtime_ctr.go: Remove Cgroups v1 72f8a01d9d pkg/specgen/generate/validate_linux.go: Remove Cgroups v1 2e6a923f1e pkg/domain/infra/runtime_libpod.go: Remove Cgroups v1 cb91d90835 libpod/runtime_pod_linux.go: Remove Cgroups v1 5499b79c8e libpod/runtime_linux.go: Remove Cgroups v1 7c45f43a46 libpod/info_linux.go: Remove Cgroups v1 4d404f1f1d libpod/container_internal*.go: Remove Cgroups v1 f2c9fcd68f cmd/podman/containers/unpause: Remove cgroupv1 check e860773c0d cmd/podman.persistentRunE(): Fatal linux check if no Cgroups v2 fffb1b3ba8 Packit: move scripts to contrib/packit-tmt 07e4b253c6 Packit: Bump podman-next repo priority for cockpit tests d58dddee66 fake images: windows hyperv 57052a8cc7 Fix regression in podman machine ssh c134825013 TMT: Exclude podman packages from podman-next repo for tests 675182c2e9 fix gofumpt issues on main 5beb7badbf fix(deps): update module golang.org/x/crypto to v0.44.0 dc6428cbbb docs: update version e93040e1e3 docs: fix redoc swagger URL cd0293a277 CONTRIBUTING: add gofumpt formatter note 5c1ed12d8d enable gofumpt formatter 37c3a75ce0 Update dependency pytest to v9 98c398b666 new image sfx for debian 14 9cbb64c525 Use fake images for machine tests e787b4f503 quadlet: add support for multiple quadlets in a single file d0d10c4ccd Update module google.golang.org/grpc to v1.76.0 a1725914ca Update module github.com/vbauerster/mpb/v8 to v8.11.2 4e169dac8f chore: fix the inconsistent method names in the comments 9246307408 Update module golang.org/x/sys to v0.38.0 02e5dfbdaf docs: Add references to quadlet b458ba0d49 Update module github.com/containers/psgo to v1.10.0 3f87f0765d hack/bats: port it to use the new remote support 950db09587 test/system: fix broken podman_runtime c31104f84e test/system: fix artifact test cleanup 09cf145f39 test/system: merge artifact tests into single file 348617fba6 test/system: rework artifact created test 9eba688ffa test/system: remove 701-artifact-created.bats ad34a695de test/system: do not run artifact test in parallel f89e2d3ac8 test/system: skip flaky restore test on debian b63a210dd9 test/e2e: try to fix clean up after terminated build flake e059055aa5 Fix WSL machine start with --update-connection 871b008ddd Bump to runc v1.3.3 - CVE-2025-52881 1c3daa7c81 CI: update VM images 06-11-2025 14cb9d2a6c test/system: Update test to handle new error message from runc 1.3.3 6493343ddc Update module github.com/vbauerster/mpb/v8 to v8.11.1 ac58beed26 Ignore auth header with empty JSON object a6f1c63c19 fix lint issues with github.com/cyphar/filepath-securejoin e0ef8362c0 update github.com/cyphar/filepath-securejoin to v0.5.1 47ab0f1e94 update github.com/opencontainers/cgroups to v0.0.6 469a8af9bb Fixes: #27444, Fix tiny typos in some artifact docs c581e0b392 Fixes #27421 aritfact push and pull with authfile e7b50c33df Add AppArmor key to quadlet .container files 424c19b897 Update module github.com/docker/docker to v28.5.2+incompatible f09508ffa5 Update github.com/containers/psgo digest to 533b50b 58c2fcd2d4 Fix incorrect function call 2e84246ad5 Update docs for most recent Windows version 623cb5f539 Bumping timeout for aarch64 machine b4ec460ed4 Add `update-connection` to machine start and init f06f77468d rotate aws meta_task keys 01f1d1ecec Add tmt integration plan 7c51ad0ef8 Fix cache misses when pulling WSL machine image f2aceb829f Bump bundled krunkit from 1.1.0 to 1.1.1 c0ae1a9bac Fix remote client rejecting empty --detach-keys string be82989be3 Add a no-op GRPC responder service to the podman system service e0800b5a24 Add GRPC dependencies ac888c73ef Makefile: Drop dead CONTAINER_RUNTIME df7f14afb1 fix(deps): update module github.com/onsi/ginkgo/v2 to v2.27.2 b309044006 fix(deps): update module github.com/shirou/gopsutil/v4 to v4.25.10 41ff61aba2 vendor neutral language, NIST database for known issues 46c428cd30 Update gh pull request template 553c4a16d5 Fix use of duplicate machine names ec5e40ae42 Allow RC Windows Installer to be built 57c7a026ea cncf: self-assessment doc eccffefe64 Allow failures on WSL machine tests 5e1c2f8d7d Machine init --provider 103788be2c Bump bundled krunkit from 0.2.2 to 1.1.0 f5bc2abe4c Remove BoltDB state support c872894615 Fixes #27378 Missing network type in events document a1ed779cd2 Update docs/source/markdown/podman-run.1.md.in 183ed100a6 Escape periods in path 601a072b51 Escape RequiresMountsFor value c8ba67f6b9 Introduce assert-has-key assertion 23057fd5ed Rename misleading assertion name 0f22c1c772 Provider obfuscation in command line dad3111a3d Fix Windows Installer GH release 2b848cca36 Fix copyUIDGID parameter inversion in Docker compat API 5551e90532 docs: expand --mount section with detailed type descriptions (#25888) f8ce377bb4 Fix tmpfs U/chown documentation 07a27f95d1 [skip-ci] Update GitHub Artifact Actions d71f383db1 add Honny1 as Maintainer af2d913f3d test: organize search tests with BeforeEach/AfterEach patterns 6b9310a0db test: refactor search_test.go to use helper functions and PodmanExitCleanly 91ff7801e6 test: Replace external registry deps with mock server in search tests 34166fc004 Bump Go version to v6 96ab027a3c Add CreatedAt format option to podman artifact ls 1cea51507b [CI:DOCS]Fix minor typo in buildah test ff6945a7dc fix(deps): update module github.com/onsi/ginkgo/v2 to v2.27.1 2cfd526ec8 rotate aws key 58e99d605c Add system test a19307f502 Fix podman build "newer" pull policy 18b5b2e2d6 test/e2e: fix 'block all syscalls' seccomp for runc b0bcb1269e Explain using `--subuidname` with `--uidmap` Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* podlet: update to v0.3.2Bruce Ashfield2026-05-312-160/+178
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping podlet to version v0.3.2, which comprises the following commits: fff343a release: Podlet v0.3.2 24dbc34 docs(readme): update demo, features, and usage 22c2060 ci(release): update dist 0692bc2 chore(deps): update dependencies 7d86818 docs(security): more explicit report directions 26bc213 docs(security): direct security reports to maintainers 12bce0a docs(maintainers): add maintainers list 33565d2 feat(readme): copy communication section to readme cab6278 docs(contributing): add Discord channels ac5b39c Add Podman v5.8.2 compatibility Fixes #209 c2b5e14 feat(container): add `AppArmor=` Quadlet option ed066c4 feat: add `podlet --quadlets-file` option 53d6194 feat: change stdout output to `.quadlets` file format e04a935 chore: add Podman v5.8 to Podman versions 046db49 fix: Escape quotes and backslashes when quoting whitespace 53eb9f5 feat(artifact): generate `.artifact` Quadlet file from command 48463f2 feat(kube): add `podman kube play --no-pod-prefix` flag fd3665a feat(kube): support setting `Yaml=` Quadlet option multiple times a6cf4b0 feat(build): add `IgnoreFile=` Quadlet option 52700d2 feat(build): add `BuildArg=` Quadlet option ee7607e feat(container): add `podman run --cert-dir` option 750c945 feat(container): add `podman run --creds` option 44b55eb feat(container): add `HttpProxy=` Quadlet option f369279 chore: add Podman v5.7 to Podman versions ee117fd feat(compose): support `stop_signal` when converting to k8s 6944438 feat(compose): support `cpuset` when converting to k8s 056cde8 feat(compose): support `pids_limit` when converting to k8s b4de490 feat(network): add `InterfaceName=` Quadlet option 6a23169 feat(image): add `Policy=` Quadlet option 7507685 feat(volume): add `podman volume create --gid` option 26579da feat(volume): add `podman volume create --uid` option 40283e3 feat(pod): add `ExitPolicy=` Quadlet option dbc3a2f feat(pod): add `Label=` Quadlet option c18bbaa feat(container): add `name` artifact mount option 8226845 feat(container): add `dest` as alias for `destination` mount option 553f30d chore: add Podman v5.6 to Podman versions 3f24112 feat: add `podman --cdi-spec-dir` global option dd8fec9 feat(unit): add `podlet --upholds` option ed74275 feat(install): add `podlet --upheld-by` option cab986d feat(build): add `podman build --inherit-labels` option cdc709b feat(build): add `RetryDelay=` Quadlet option ed48de0 feat(build): add `Retry=` Quadlet option 92b4cd2 feat(image): add `RetryDelay=` Quadlet option 68a20eb feat(image): add `Retry=` Quadlet option b1137ad refactor: unify `push_arg()` impls fc0b6e7 feat(pod): add `HostName=` Quadlet option f1f7ae7 feat(container): add `RetryDelay=` Quadlet option e1f4f2b feat(container): add `Retry=` Quadlet option 5722d59 feat(container): add `Memory=` Quadlet option b29bcac refactor: push downgrade errors into functions 5619e76 feat(container): add `artifact` mount type 326cb6a chore: add Podman v5.5 to Podman versions 99f06ea test: refactor tests to return `Result` 17d9f36 Fix: Problems with containers started with --detach=True ad595db Fixes #174 a520893 feat(pod): add `podman pod create --no-hostname` option 2319fc2 feat(pod): add `podman pod create --hosts-file` option 5d58cb0 feat(pod): add `ShmSize=` Quadlet option 2f7d6cd feat(container): add `podman run --no-hostname` option 1f227b8 feat(container): add `podman run --hosts-file` option 4c1a82b feat(container): add `subpath` volume mount option fce17b2 chore: add Podman v5.4 to Podman versions 7f94566 feat(container): add `--no-start-with-pod` flag 30d6147 feat: add `--disable-default-quadlet-dependencies` flag af66fa5 refactor: move `cli::{service, unit}` to `quadlet` b7eaad7 refactor: make `podlet::quadlet::File` fields non-optional 5240b6c feat: add `--service-name` option 067664f feat(pod): support setting `ImageTag=` Quadlet option multiple times 310ffb8 feat(pod): add `UserNS=` Quadlet option c1c386a feat(pod): add `UIDMap=` Quadlet option 4dea6c1 feat(pod): add `SubUIDMap=` Quadlet option 681aa14 feat(pod): add `SubGIDMap=` Quadlet option d7a9ba4 feat(pod): add `IP6=` Quadlet option d723602 feat(pod): add `IP=` Quadlet option 0aec632 feat(pod): add `GIDMap=` Quadlet option a5fe097 feat(pod): add `DNSSearch=` Quadlet option 516bd92 feat(pod): add `DNSOption=` Quadlet option ef9386d feat(pod): add `DNS=` Quadlet option 85a083e feat(pod): add `AddHost=` Quadlet option f3d1ef9 feat(compose): support `network_mode: "service:service_name"` 3c38d5d feat(container): add `HealthMaxLogSize=` Quadlet option 6acc7bd feat(container): add `HealthMaxLogCount=` Quadlet option 71abf83 feat(container): add `HealthLogDestination=` Quadlet option 400aca6 feat(container): add `CgroupsMode=` Quadlet option 896712a feat(container): add `AddHost=` Quadlet option edd4218 chore: add Podman v5.3 to Podman versions 2b93153 feat: add `--part-of` option (#192) 5a927ed release: Podlet v0.3.1 c2390d2 docs(changelog): update git-cliff configuration 930f58c docs(readme): update demo, features, and usage 843b968 chore: add Podman v5.2.5 to Podman versions a4baae9 chore(deps): update dependencies Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* oci-runtime-spec: update to v1.3.0-tipBruce Ashfield2026-05-311-2/+2
| | | | | | | | | | | | | | | Bumping runtime-spec to version v1.3.0-15-g6999a89, which comprises the following commits: 63c1dd6 Blank line before table Fixes #1134 53abf18 ci: bump golangci-lint to v2.10 90a6479 Fix an error in the docs 4361740 schema: fix definition for array type 04836b1 schema: fix path for uint32 type c668b01 config-linux: allow empty strings in memory policy nodes field 9d0d4bc version: v1.3.0+dev 0ef13af Add step to update website after a release Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* oci-image-spec: update to v1.1.1-tipBruce Ashfield2026-05-301-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | Bumping image-spec to version v1.1.1-32-g13cff54, which comprises the following commits: 751ed12 Fix one-sentence-per-line violations b9060a3 Clarify that whiteout filenames require a non-empty basename fccd049 Fix: Make the config field optional b71c0df Add missing backtick 431b3be Update OCI Image Implementations list 02ba6e2 Descriptor size cannot be negative cee899b Fix: Add entry to schema/go.sum 558802d Docs: Update pandoc for rendering documentation 693d8d7 Update to github.com/russross/blackfriday/v2 cbb69e2 Update to github.com/santhosh-tekuri/jsonschema/v6 d0e1005 Split github.com/opencontainers/image-spec/schema into a separate Go module 84ee56d Fix: correct a broken link to "applying changesets" 0bb67c2 Update GitHub Actions configuration ab50866 Chore: Remove GOPATH from GitHub Actions aca17c0 Clarify that canonical JSON is not a requirement 1809845 Bump back to +dev 4fecf47 Add blake3 as a registered/supported hash algorithm Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* alpine-oci-base: update to 3.23Bruce Ashfield2026-05-301-3/+3
| | | | | | | | | | | | | Alpine 3.19 reached end-of-life in November 2025; bump to 3.23, the newest released minor (supported through December 2027). The Docker Hub digest is taken from the 2026-04-15 rebuild. The recipe pins via CONTAINER_DIGESTS for reproducibility, so the filename's PV and both the CONTAINER_BUNDLES tag and the CONTAINER_DIGESTS[docker.io_library_alpine_<pv>] varflag key all move together. Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* nerdctl: update to v2.3.1-tipBruce Ashfield2026-05-307-303/+1517
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping nerdctl to version v2.3.1-37-g89ecd850, which comprises the following commits: 3a2bfc0c build(deps): bump github.com/containerd/typeurl/v2 from 2.2.3 to 2.3.0 819ba7a6 build(deps): bump github.com/rootless-containers/rootlesskit/v3 f5bf3cc2 build(deps): bump docker/setup-qemu-action from 4.0.0 to 4.1.0 12fd8ef3 Update RootlessKit (3.0.1) 2550e0ca fix: fix load image failed fad90465 fix: update status label should call after task is started 08b99f8c refactor(healthcheck): simplify ForceRemoveTransientHealthCheckFiles adfb7d4b fix(healthcheck): cleanup transient units on container exit and start da3187ef feat(ps): show container health status in STATUS column 67012003 build(deps): bump docker/setup-buildx-action from 4.0.0 to 4.1.0 e8f77912 build(deps): bump github.com/opencontainers/selinux 04e9823c fix: handle long fractional Unix timestamps 3c039f17 chore: remove go.uber.org/mock dependency 2dab3f71 build(deps): bump the golang-x group across 1 directory with 3 updates 0c21d50f build(deps): bump docker/metadata-action from 6.0.0 to 6.1.0 18728fe7 build(deps): bump docker/login-action from 4.1.0 to 4.2.0 c8766fe4 build(deps): bump docker/build-push-action from 7.1.0 to 7.2.0 8e4bee0e build(deps): bump zizmorcore/zizmor-action from 0.5.3 to 0.5.6 46b313e4 update gomod jail to v0.3.2 124dfc0c build(deps): bump the docker group across 1 directory with 2 updates 9e31c406 build(deps): bump github.com/containerd/containerd/v2 2203f242 Dockerfile: bump buildkit version to 0.30.0 a4ad4f42 Dockerfile: bump containerd to v2.3.1 228c5ff9 build(deps): bump github.com/compose-spec/compose-go/v2 fd235821 fix typo and missing import in tools.md 7168e713 build(deps): bump github.com/moby/moby/v2 cc52ce62 ci: add zizmor workflow linting 22ebf232 docs: remove stray quote from interactive flag e6655ce3 docs: fix sig-proxy flag spelling bd8704ed build(deps): bump the docker group with 2 updates fd113efa Compose Down to accept a list of Services de4166a5 build(deps): bump github.com/moby/moby/v2 8207c2e3 build(deps): bump github.com/opencontainers/selinux 0e3e7ae6 build(deps): bump the golang-x group with 5 updates e51bc852 test(compose): add test for healthcheck config 520a3df9 feat(compose): support healthcheck field in service config b5e6eff6 fix: handle CNI config stat errors without panic 3b331db0 build(deps): bump github.com/docker/cli 28985ae1 build(deps): bump github.com/klauspost/compress from 1.18.5 to 1.18.6 c55d91be test: refactor container_stop_linux.go to use Tigron ec02ca44 build(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 68982c9c build(deps): bump github.com/mattn/go-isatty from 0.0.21 to 0.0.22 bbb5c32f test: refactor container_run_security_linux_test.go to use Tigron Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* lxcfs: update to v7.0.0Bruce Ashfield2026-05-292-54/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping lxcfs to version v7.0.0, which comprises the following commits: 0995aec Release LXCFS 7.0.0 6389b7c chore: Remove manual cpu.max and TODO in test script 6de32d9 lxcfs: fix wrong cpu count when setting cfs in hierarchy 7241637 cpuset_parse: constify return value of cpuset_nexttok c8095bb tests: cover /proc/swaps in meminfo hierarchy test 30556e7 lxcfs: fix gettid on glibc < 2.30 0f7e541 github: drop cgroup1 related stuff f2229e2 github: add Codecov 13ac8db tests: use SIGTERM instead of SIGKILL 1aa236a tests: add cpu cfs hierarchy test 3d6d679 tests: add cpuset hierarchy test 172d6b6 tests: refactor meminfo_hierarchy test 4d69faa tests/meminfo_hierarchy: ensure that swap total size is correct 156c0f8 tests: cleanup using shellcheck d86b88b tests: extend meminfo hierarchy test a3ed02c tests: remove cgroup1 support 4e95204 cgroups: remove pure cgroup1 and hybrid support 14910a8 tests: remove test_readdir test 638d95a lxcfs: remove test_cgroup 417f19f Fix compiler warning. 7a90f31 lxcfs: make --enable-pidfd a default ab22161 lxcfs: nuke the cgroupfs code 8eb4043 lxcfs: remove --enable-cgroup option support 906161a lxcfs: remove cgroupfs support from hook c7d882f tests: remove cgroupfs-related tests d3fcf6a lxcfs: remove libfuse2-specific code ea2bcf0 lxcfs: drop libfuse2 support fab7ae2 github: switch to libfuse3 and drop libfuse2 dae1f7f CONTRIBUTING: add a note on AI generated code 849eec9 lxcfs: add .clang-format 9577b48 sysfs: fix duplicated /sys/devices/system/cpu/online 2e91ceb lxcfs: fix "Write to cache was truncated" on long-running / high-core-count systems ed65236 Fix issue where the pidfd_ functions are not detected during meson setup. 3aa1487 cgroups/cgfsng: check memory allocation in add_hierarchy 06db22c meson: don't forget to set PSI trigger mocks for liblxcfstest 726082c github: enable mocks for CI upgrade tests 6f27557 github: pass LIBFUSE env variable to upgrade tests b7efa05 cgroups/cgfsng: do not change host-wide cgroup2 superblock options 273a0b6 cgroups/cgfsng: fix whitespace errors in __cg_mount_direct 456047f lxcfs: add enable-psi-poll cmdline option 39e4724 tests: add /proc/pressure/* virtualization tests e422b64 github: enable mocks for CI builds e7f5d06 meson: add "mocks" option for CI/testing purposes f664a57 proc_fuse: add /proc/pressure/{cpu, io, memory} virtualization 34d5daf lxcfs: install noop signal handler for SIGRTMIN + 0 84ef19e proc_fuse: move release/releasedir at the end 8fae19b lxcfs: wire up ->poll callback for /proc 142b0cf lxcfs: wire up ->write callback for /proc d411fda bindings: add private_data field to struct file_info 282f237 proc_fuse: deduplicate read() handlers code for /proc/pressure files af454ab src/utils: fix in_same_namespace helper 82481b6 lxcfs: use macro to generate liblxcfs call helpers c503b12 cgroups: replace dup() call with openat_safe() 6bd2ebd proc_fuse: add zswap information to /proc/meminfo 0dc531d bindings: add zswap feature detection 7775056 lxcfs: add disable-zswap opt 21ce4aa cgroups: add zswap feature detection b54e16a cgroups: extract cgfsng_can_use_memory_feature() util function 255b7a7 proc_fuse: fix proc_stat_read reporting host cpu count under cgroup v2 8a281f9 github: Use Github Arm runners 3d81122 github: Bump actions/checkout to v5 2ea5561 proc_loadavg: Prevent integer overflow calculating the sleep interval 28be637 lxcfs: use strlcpy when handle runtime-dir parameter 0f253c7 utils: move strlcpy/strlcat helpers from cgroup_utils to utils 3aa1bb6 cpuset_parse: make a check for an empty string in cpu_in_cpuset() 531a988 utils: fix wait_for_sock to use time_t instead of int a43c87d tests/test-read: call close(2) only if there is an fd abdecf1 meminfo: Add slab_reclaimable to MemAvailable 31da3ae proc_fuse: add psi(pressure stall information) procfs 3a43ced github: Improve progress reporting f819442 github: Cleanup testsuite action a1f9602 github: Update checkout to v4 10c990f github: Simplify build action 370f6a4 github: Update coverity workflow 124ad8b github: Use shared logic ce45d17 tests: Make sure to enable cpuset controller 8c5f161 github: Add arm64 tests 39dc9b3 github: Simplify tests workflow c65ddc7 github: Bump Ubuntu version 49e862b cgroups/cgfsng: improve swap accounting support detection 2594ae8 tests: add proc readdir test 56fd97e lxcfs: fix readdir for procfs subtree bcb1b0a lxcfs_read: Added LXCFS_TYPE macro to all FUSE filesystem calls 1e4e184 Add missing linux/limits.h include 15f614c github: add live upgrade test between stable-{5,6} branches 8c88d4e github: add ISSUE_TEMPLATE.md bf571ae README.md: add info about how to collect a core dump fd35d40 github: update coverity test to use Ubuntu 22.04 e5a5c8c github: add lxcfs live upgrade compatibility test 5c42da9 lxcfs/bindings: add a flag for overriding the runtime dir 328a30b lxcfs/bindings: Refactor RUNTIME_PATH so that it can be overridden on startup 276cc1c proc: checks system security policy before trying to get personalities We also Drop 0001-bindings-fix-build-with-newer-linux-libc-headers.patch as v7.0.0 added its own conditional '#include <sys/pidfd.h>' inside '#if HAVE_PIDFD_OPEN', so the patch's unconditional include is now a duplicate. The system glibc sys/pidfd.h has a broken include guard (#ifndef _PIDFD_H without a matching #define), so two includes produce a 'struct pidfd_info' redefinition error. Also switch DEPENDS/RDEPENDS from fuse to fuse3, matching v7.0.0 which now requires libfuse3. Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* lxc: update to v7.0.0Bruce Ashfield2026-05-291-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping lxc to version v7.0.0, which comprises the following commits: e4415af07 Release LXC 7.0.0 14754e0b9 usernic: add a test for ovs port deletion permission 7c4348314 lxc-user-nic: clarify and fix aebd808da Don't leak an open fd 565540984 lvm.c: make sure tp gets freed cf5aa7ca5 tests/lxc-test-lxc-attach: Increase sleep time bae8a42f7 lsm/apparmor: allow binfmt_misc RW mounts c57010a38 apparmor: allow nosymfollow remounts b46f872d9 apparmor: allow nosymfollow remounts 9e541fa86 lxc: assume fsopen/open_tree/mount_setattr syscalls are supported 87ff1e31e lxc/start: assume CLONE_PIDFD and clone3 are supported eed40beb1 doc: mention that legacy/hybrid hierarchy support is dropped 27649a1f2 lxc/cgroups: warn if non-unified cgroup layout detected 105385172 config/templates: don't use cgroup1 settings 7d9be4a4b tests: use lxc.cgroup2 instead of lxc.cgroup f29c3a3a6 lxc/conf: drop cgroup1 config options (lxc.cgroup.*) db0d83e42 lxc/cgroups: drop cgroup1 mounting logic 936fa0629 lxc/cgroups: drop special handling logic for cgroup1 cpuset controller dfa8ea976 lxc/cgroup: drop cgroup1 device cgroup support 95ac49ec6 lxc/cgroups: drop cgroup1 freezer support 49bb4fad1 [nesting] Extend mount permissions in apparmor to allow systemd services' restrictions to work 88b44a5f9 cgroups: Skip systemd dbus logic when not using systemd cf5e950ee tests: mount_injection: ensure cleanup on test failure 110974e9c Fix issue where memfd functions were not being detected during meson setup. f5641d697 Fix issue where pidfd_ functions were not being detected during meson setup. 2bc6bac9c utils: Only single quote our own arguments 7174f2e2a utils: Update buffer size to account for quotes 589981f4f utils: Add quotes around exec arguments e4d847bd0 build(deps): bump actions/upload-artifact from 6 to 7 a01f7b4ac Add --rbuser to Japanese lxc-create(1) 29cd84d8e Add description for unprivileged containers to Japanese man page d8f2c55fa cmd/lxc-user-nic: prevent OOB read in name_is_in_groupnames aba5d1fbf lxc/network: define netlink uAPI constants for link properties 5e9b89c8f lxc/network: save/restore physical network interfaces altnames 3ba8131f0 lxc/network: optimize netdev_get_mtu 061acb0b3 meson.build: fix open_how include with glibc-2.43+ 511e4db8f meson.build: fix openat2 include typo, fix with glibc-2.43 +FORTIFY 5b64b5016 lxc: added support OpenRC init system c97f33e1f src/confile: fix values of lxc.cap.keep and lxc.cap.drop 97bd7699c tests/lxc-attach: ensure no data corruption happens during heavy IO on pts 4cb9884ed lxc/{terminal, file_utils}: ensure complete data writes in ptx/peer io handlers 4a30d82af github: test io_uring-based event loop 4a5aa19d7 build: update Makefile and meson.build 6a5550ec2 Improve the dbus scope creation error handling 0f5852edf cgfsng: fix reboots when using dbus 49c34b1bc copy_rdepends: Don't fail on missing source file 9e6caeabe start: Respect lxc.init.groups also in new user namespace e6ad17a79 start: Remove outdated comment about group dropping af691a1fa build(deps): bump actions/upload-artifact from 5 to 6 f085a8cbd Added documentation on unprivileged LXC containers 9799ebacc added doc for --rbduser 1090d85df added "--rbduser" option in "lxc-create -B rbd" fbeb7ce7e Fallback to XDG_RUNTIME_DIR when /run not found 969a3c599 checkonfig: Fixed compatible with toybox/gunzip fee221cae Initial changes without testing 9a1edb704 Enumerated all values in array 5d160e2a5 meson: add meson option for running doxygen in build 4d00d4f80 build: Check if P_PIDFD is defined 661780256 build(deps): bump actions/checkout from 5 to 6 1d1700a23 Ensure do_lxcapi_unfreeze returns false when getstate errors b89ed0a8e apparmor: skip /proc and /sys restrictions if nesting is enabled c81e03eb6 Update lxc.spec.in to use meson f3ff31e58 config/apparmor/abstractions: Drop manually generated container-base file 52929fc21 config/apparmor/abstractions: Fix meson build generation of container-base fc5a9422f build(deps): bump actions/upload-artifact from 4 to 5 4e48c0d09 builds workflow: make .orig.tar.gz unique per build 7f128c968 github: Drop focal source packages aa0fdd1a4 add MFD_EXEC and MFD_NOEXEC_SEAL flag to memfd_create 00f05b13d start: Only include linux/landlock.h when landlock is enabled 20aa142d5 Automatically detect compression format in the lxc-local template fba76ea65 lxccontainer: check if target exists before remove in create_mount_target() d269f0370 Standardize log file create mode to 0640 d79142d41 doc: add lxc.environment.{runtime,hooks} in Japanese man page c7bd5a357 Enable systemd to create /var/lib/lxc at runtime with StateDirectory e0290fa4a doc: add lxc.environment.{runtime, hooks} 9ebe1f11e api_extensions: add environment_runtime_hooks extension fbd37f04c conf: split `lxc.environment` into `runtime` and `hooks` 3f1658526 github: Enable landlock in tests 226bbf62f start: Add Landlock restrictions to monitor 8ef1ac504 start: Make lxc_handler mainloop to run in thread bfacedd4c meson: Add optional landlock protection for monitor 694944a7e commands: Fix indent 9b2422478 README: update links 95cad77e7 Rename CONTRIBUTING to CONTRIBUTING.md cc2a8494b README: Fix CI links e434816f2 build(deps): bump actions/checkout from 4 to 5 b3a5d2814 lxc/conf: do not leak opts.data memory in __lxc_idmapped_mounts_child() 5db329a4b lxc/network: null-terminate ifname string in lxc_network_recv_name_and_ifindex_from_child() 23633ab0f tests/lxc-test-snapdeps: try to load overlay kernel module 1d8d439af tests/lxc-test-rootfs: add idmapped rootfs testcase a53589e06 lxc/lxccontainer: stop printing misleading errors in enter_net_ns() a5189e3f5 lxc/process_utils.h: use strsignal() or sys_siglist[] for Non-GNU distros 39cb6d119 meson.build: use has_header_symbol() instead of get_define() to improve compatibility 0267998bc meson.build: fix checks for fsconfig and calls 6d6f0e1b0 meson.build: set `LXC_DISTRO_SYSCONF` when `-Dspecfile=true` ad0804e41 Add loong64 to list of recognized architectures d5beb15ae Revert "re-add onexec for apparmor, move label assumption until after container has been setup for attach" bba0a0d60 src/tests/oss-fuzz: pin meson to 1.7.2 to workaround build failures afb35f3de lxc/conf: support flag kind of mount options in lxc.mount.entry options 2e08794e0 lxc/conf: support nosymfollow mount flag 30b11e54a conf: Add support for "move" mount flag a9b343f48 src/tests/lxc-test-unpriv: prevent fail on cleanup path a13f86b07 src/tests/lxc-test-apparmor-mount: prevent fail on cleanup path 68e57809e src/tests/lxc-test-apparmor-generated: enable test ea92e49bd meson.build: remove quirk for Ubuntu 14.04 libcap-dev 7b9ee8967 apparmor test: add an overlay container start 50dee37cf re-add onexec for apparmor, move label assumption until after container has been setup for attach 0636ec66b lxc/conf,start: fix setting container_ttys environment variable c69830734 selinux: fix typo (AppArmor) 6cb00878e meson_options.txt: remove space before `:` for consistency 368ac7b80 meson_options.txt: don't use str when defining bool default values fc65c6a79 bionic: Remove custom getline, openpty and prlimit 4d52fe8e0 bionic: Remove bionic detection and support ee022cf05 README: Remove mention of old LXC version 0df81457d start: Re-introduce first SET_DUMPABLE call e5cc7a6be lxc/start: do prctl(PR_SET_DUMPABLE) after last uid/gid switch 3c6ea300b lxc/caps: fix open /proc/sys/kernel/cap_last_cap becd5538e lxc/conf: handle rootfs open_at error in lxc_mount_rootfs ff1ea5099 tools/lxc_attach: fix ENFORCE_MEMFD_REXEC checks c8cc47101 github: Add packaging workflow 7914afb0c global: Switch to new MAC prefix 7bd24f6cb global: Switch MAC generation to Zabbly prefix 31cd14682 sysconfig/lxc: remove false comment d047d81b7 Added LXC_IPV6_ENABLE option for lxc-net to enable or disable IPv6 9c9c27e8c github: Switch to native arm64 runners 59825e187 config-bcast: fix incorrect broadcast address calculation b4248f626 lxc/attach: Revert "- LXC attach should exit on SIGCHLD" 8d8fd27b5 conf: warn when capabilities are disabled or libcap is not found 844c49fcf dbus: replace hardcoded dbus address with environment variable 4c4636830 conf: log name of invalid capability in error 50be11e8d confile-vlanid: undefined is not a zero value f02158439 - LXC attach should exit on SIGCHLD 9589be83c github: Improve progress reporting 4fef63526 github: Cleanup OSS-fuzz 664344d9d github: Rework test workflow 6dd4c9bae github: Introduce shared testsuite logic 5b752b525 github: Introduce shared build logic e47b9ee65 github: Update coverity workflow 4527cec26 lxc.init: Allow SIGHUP from outside the container d25e7f306 lxc.init: Ignore user signals coming from inside the contianer c41c5ebfa lxc.init: Switch to sigaction 87dcdecf5 lxccontainer: fix enter_net_ns helper to work when netns is inherited 31012d49a lxc-net: Replace random IPv6 subnet d03cb0aca meson: fix minor typo f7c758537 fix return code of recursive all of cgroup_tree_prune d5c2d1eff Avoid null pointer dereference when using shared rootfs. rootfs->storage not set by lxc_storage_prepare when using a shared rootfs. d50ee6f7c create_run_template: don't use txtuid and txtguid out of scope 3764c1996 Add suppport for PuzzleFS images in the oci template a8ca9f5f3 meson.build: drop suggest-attribute=noreturn build option 36497cc90 meson.build: add -ffat-lto-objects 83bb86888 fix possible clang compile error in AARCH b79d2a525 README: Update security contact 7be043310 doc: Fix definitions of get_config_path and set_config_path b24d2d45b Exit 0 when there's no error 5db3d7299 idmap: Lower logging level of newXidmap tools to INFO 5603534a9 Remove unused function 01ae1fe55 meson: fix build with -Dtools-multicall=true on NixOS 4892749ef github: exclude clang & ubuntu-24.04 combination 20a14562d lxc/storage/zfs: ignore false-positive use-after-free warning 8a297c3ad github: properly check apparmor profile changes bdba5efee github: start using ubuntu-24.04 d29f72e37 apparmor: regenerate rules 32f88c8fe apparmor: use /{,**} instead of /** 083678be2 apparmor: regenerate rules 9c492b079 apparmor: fix rule path pattern specification syntax 63168bcf4 lxc-local: remove check for template existence before extraction d740a3423 lxc-local: fix incorrect path to `templates` file d7f2a52fd lxc-local: fix use of `LXC_PATH` before init 9a6448af4 Update lxc-execute.sgml.in 3bef71d7e Update lxc-{attach,execute}.sgml.in a7aa2974d Update lxc-execute.sgml.in 52bf34d8a Update lxc-attach.sgml.in ee8063bcf network: netdev_configure_server_veth: reduce scope of disable_ipv6_fd/path vars dd663dcb3 lxc/network: handle non-existing sysctl <ifname>/disable_ipv6 cca0f8767 github: test the lxc multicall binary builds too 4be1c12c1 meson: fix build on NixOS 054163193 meson: Set DEVEL flag post release Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* kubernetes: update to v1.36.1Bruce Ashfield2026-05-291-11/+14
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Cross-branch jump release-1.35 -> release-1.36 + kubernetes-release bump from v0.15.0-182 to v0.21.1-62 (~1200 commits of tooling churn). Recipe-side fixups beyond the SRCREV/PV/branch bumps: - kubepkg -> krel template path rename: kubernetes-release reorganized its templates tree, dropping 'kubepkg' in favor of 'krel' (the release tool), with a flatter layout that no longer wraps the unit files under deb/<pkg>/lib/systemd/system/. Updated do_install paths: cmd/kubepkg/templates/latest/deb/kubelet/lib/systemd/system/kubelet.service -> cmd/krel/templates/latest/kubelet/kubelet.service cmd/kubepkg/templates/latest/deb/kubeadm/10-kubeadm.conf -> cmd/krel/templates/latest/kubeadm/10-kubeadm.conf - Dual-class fixups: SRCREV_kubernetes:class-devupstream and SRCREV_kubernetes-release:class-devupstream synced to the same values as their non-class variants; PV:class-devupstream and CVE_VERSION bumped to 1.36.1. - SRC_URI branch=release-1.35 -> release-1.36 in both the regular and class-devupstream SRC_URI definitions. Bumping kubernetes to version v1.36.1-1-g102c4a4f87b, which comprises the following commits: 102c4a4f87b Update CHANGELOG/CHANGELOG-1.36.md for v1.36.1 756939600b9 Release commit for Kubernetes v1.36.1 b0b25e8ade2 kubeadm: use dedicated ClusterRole for apiserver kubelet client 2bd86062e71 KEP-5304: DecodeMetadataFromStream only skips metadata entries with unknown API versions b643483ccc4 DRA: merge same request metadata across drivers f0d0ff95d29 kubeadm: skip LocalAPIEndpoint defaulting on worker join 100bf5d4997 kubeadm: use the localAPIEndpoint for all API calls in 'init' 0008353cef2 kube-proxy: don't do full periodic syncs on large cluster mode a45cef81d62 Delete remote endpoint if it has same ip as local endpoint in the system. cbb38cd5ce6 Delete remote endpoint if it has same ip as local endpoint in the system. 28dd6f27570 hack/update-vendor.sh 529473cc4d8 register zfs cadvisor plugin 07144e39cd5 Add a (*Client) addEndpoint method 98ecfc63fe4 Evaluate etcd cluster health using quorum 891a905031b test/localupcluster: stop all components before starting replacements 1d850e84279 localupcluster: set readiness polling interval to 1 second 62d05adc8b7 localupcluster: properly query /readyz and /healthz 745e271a9cb Update CHANGELOG/CHANGELOG-1.36.md for v1.36.0 b2ba48e510e Escape path inside the container Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com> kubernetes-release: update to v0.21.1 Bumping release to version v0.21.1-62-g9e3980c6, which comprises the following commits: 8995cc83 schedule-builder: optionally extend upcoming patch window to 4 during maintenance overlap 8669ec6c Bump github/codeql-action from 4.35.5 to 4.36.0 in the actions group 339db283 Rebuild debian-base - bump to bookworm-v1.0.8 0765cb64 Bump the actions group with 2 updates 6122139a Bump goreleaser/goreleaser-action in the actions group 2179f52e Bump the all group with 2 updates 55ea775c Bump github/codeql-action from 4.35.4 to 4.35.5 in the actions group cf066d08 Bump step-security/harden-runner in the actions group 44d84ebf Bump step-security/harden-runner in the actions group 59d5e645 Bump k8s.io/apimachinery from 0.36.0 to 0.36.1 in the all group 3c81fd5a Bump distroless-iptables to use Go 1.26.3/1.25.10 0e27de90 Bump golang.org/x/text from 0.36.0 to 0.37.0 6e06dc1b Bump github/codeql-action from 4.35.3 to 4.35.4 in the actions group 25fa597b build kube-cross, go-runner, releng-ci with golang 1.26.3/1.25.10 5dd07a6d Bump sigstore/cosign-installer from 4.1.1 to 4.1.2 in the actions group 0faf54f5 Bump github.com/go-git/go-git/v5 from 5.18.0 to 5.19.0 02f113d3 Bump github.com/in-toto/in-toto-golang from 0.10.0 to 0.11.0 c484b887 Bump sigs.k8s.io/promo-tools/v4 from 4.4.1 to 4.5.0 c808377a Bump the actions group with 2 updates ae1d58f5 Bump github.com/mattn/go-isatty from 0.0.21 to 0.0.22 in the all group c271b925 Bump goreleaser/goreleaser-action in the actions group b0b65a11 krel: add validation for mutliple matching constraints 0ffd6e1f krel/templates: adjust kubeadm constraint for >= 1.30 73e308ec Bump k8s.io/apimachinery from 0.35.4 to 0.36.0 c3e4f32c Bump step-security/harden-runner in the actions group 011afb52 Bump goreleaser/goreleaser-action in the actions group fa5f1f21 Bump github.com/go-git/go-git/v5 from 5.17.2 to 5.18.0 6c97c5f3 Bump k8s.io/apimachinery from 0.35.3 to 0.35.4 in the all group cb1ab9d3 Bump the actions group with 2 updates 9d4d0461 Revert "Use blobless clone for fresh k/k checkouts during stage" 510d5c43 Bump softprops/action-gh-release from 2.6.1 to 3.0.0 d63d0e1c Bump github.com/sigstore/timestamp-authority/v2 from 2.0.3 to 2.0.6 aa1e2491 Bump the actions group across 1 directory with 2 updates e87cfe89 Bump github.com/google/go-containerregistry in the all group 2dbfe754 Bump golang.org/x/text from 0.35.0 to 0.36.0 c7525c60 Update the Go update issue template 5dd48ced Update k8s-cloud-builder and k8s-ci-builder to Go 1.26.2/1.25.9 caece2b1 Bump distroless-iptables to use Go 1.26.2/1.25.9 cfb2c5d3 build kube-cross, go-runner, releng-ci with golang 1.26.2/1.25.9 7c69784f Bump github.com/mattn/go-isatty from 0.0.20 to 0.0.21 in the all group a3330e4f Bump go.opentelemetry.io/otel/sdk from 1.42.0 to 1.43.0 eb1d1573 Bump kubernetes-sigs/release-actions in the actions group 6aab20a9 Bump github.com/google/go-containerregistry in the all group c470ce19 Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 743d177d Bump github.com/maxbrunsfeld/counterfeiter/v6 in the all group 9fc828ff Fix schedule-builder test data with stray tab character 2625de37 Bump the all group with 2 updates b36425fe Add go1.25 variants for release-1.33 and release-1.34 01cfe00a Bump the actions group across 1 directory with 3 updates ae079fd1 Switch cosign signing to new bundle format 58b1dc51 Bump sigs.k8s.io/promo-tools/v4 from 4.4.0 to 4.4.1 in the all group 38d62704 Fix release-notes -s crash on repos with parentless root commits 03674e04 Bump github/codeql-action from 4.34.1 to 4.35.1 in the actions group 360db206 Bump github.com/go-git/go-git/v5 from 5.17.0 to 5.17.1 in the all group f829acb4 Bump sigstore/cosign-installer from 4.1.0 to 4.1.1 in the actions group 44c0863d Add tests for obs/archive file c56c8d60 docs: clarify krel install locations + go install fe02c4c3 Wrap dependency subsection in dropdown Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* incus: regen go-mod-licenses.inc with module-path encoding fixBruce Ashfield2026-05-292-2/+4
| | | | | | | | | | | | | | | | | | | | | Picks up 2 entries that the previous writer silently dropped because their canonical module paths contained ASCII uppercase letters and the filter comparison was against the filesystem-encoded form: - github.com/LINBIT/golinstor (Apache-2.0) - github.com/Rican7/retry (MIT) Both are in incus's imported set per `go list -deps` and unpacked at build time, so they should always have been tracked. Also small benign churn in go-mod-cache.inc (vcs_ref hint shifts from non-deterministic nearest-tag resolution — bitbake fetcher uses the hash, not the ref). Root cause fix: 2f15273a "oe-go-mod-fetcher: encode Go module paths in LIC_FILES_CHKSUM URIs". Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* docker-compose: regen go-mod-licenses.incBruce Ashfield2026-05-291-280/+4
| | | | | | | | | | | | | | | | | | | | | | | | | | | Two corrections coming through in one regen: - Drop ~280 stale entries left over from the original commit, which was generated while GOMODCACHE was cold and the filter fell back to MVS-selected (`go list -m all`). MVS overshoots — it includes modules in the transitive go.sum graph that go build never actually compiles. The current run uses the GOMODCACHE-unpacked filter (tier 2) and matches the recipe's actual build pkg/mod (~143 modules). - Add 4 uppercase-bearing entries that the canonical-vs-encoded comparison previously dropped silently. Net: 428 lines -> 152 lines. Same recipe content, more accurate license tracking. Verify with `bitbake docker-compose` — do_populate_lic should pass cleanly (the previous larger file would have produced ~285 invalid-file QA errors on a fresh build but passed via sstate). Root cause fixes: - 07bfa04b "oe-go-mod-fetcher + go-mod-discovery: add --build-target license-scan filter" - 2f15273a "oe-go-mod-fetcher: encode Go module paths in LIC_FILES_CHKSUM URIs" Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* cosign: regen go-mod-licenses.inc with module-path encoding fixBruce Ashfield2026-05-292-1/+17
| | | | | | | | | | | | | | | | | | Picks up 16 entries that the previous writer silently dropped because their canonical module paths contained ASCII uppercase letters and the filter comparison was against the filesystem-encoded form. The added modules are Azure SDK-for-Go components, Aliyun container service, Azure-AD MSAL, and Azure/go-autorest — all present in cosign's imported set but missing from the committed licenses.inc. Also picks up a 1-line vcs_ref hint shift in go-mod-cache.inc for honnef.co/go/tools (v0.1.2 → v0.9.0). Metadata only — bitbake's fetcher uses the hash, not the ref hint, so the build is unchanged. Root cause fix: 2f15273a "oe-go-mod-fetcher: encode Go module paths in LIC_FILES_CHKSUM URIs". Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* k3s: update to v1.36.1+k3s1Bruce Ashfield2026-05-297-1006/+3650
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Aggressive jump release-1.35 -> release-1.36 (latest tagged minor), landing on v1.36.1+k3s1 exactly. Recipe changes beyond the SRCREV/PV/branch bump: - GO_MOD_DISCOVERY_LICENSE_TARGETS = "./cmd/server/main.go" — explicitly declares the recipe's build entry-point so the license-scan filter uses the new tier-1 mechanism (go list -deps) rather than the narrower GOMODCACHE walk. Critical for k3s given its ~2810-module discovery graph — only ~403 modules contribute code to the binary, and the precise filter avoids 2400+ stale LIC_FILES_CHKSUM entries. - include go-mod-licenses.inc (not require) so the recipe parses cleanly on first-time generation before the sidecar file exists. All 5 go-mod sidecars regenerated; new go-mod-licenses.inc (~416 lines, 407 license-bearing modules). do_populate_lic passes cleanly thanks to the companion script changes for module-path encoding. Bumping k3s to version v1.36.1+k3s1, which comprises the following commits: a9663261a7 Bump klipper-helm image tag 9da548c2bc Update to v1.36.1 (#14051) 76c84e57ac chore: Update rancher/local-path-provisioner image version 7bbbf7c9b2 Fix install-go cache key a4b0bc0b01 Bump kine to v0.15.0 bcc8df1ace add lost return e52c00c4a8 chore: Update rancher/klipper-lb image versions 5231ff7ef0 chore: Update CoreDNS image version in manifests/coredns.yaml 9f9f75591b chore: Update CoreDNS image version in scripts/airgap/image-list c96142270f Bump spegel to v0.7.0 32687ebb94 Move advertise-address setup before server prepare 73f157cfeb Replace PreparingExecutor with explicit executor init 7939da6c48 chore: Update rancher/klipper-lb image versions Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* incus: update to v7.0.0Bruce Ashfield2026-05-297-222/+649
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Major version cross: switches the recipe from stable-6.0 (LTS, frozen at v6.0.6 + maintenance) to main at the v7.0.0 release tag. v7.0.0 is the rebranding of incus to its v7 module path. Recipe changes: - GO_IMPORT: github.com/lxc/incus/v6 -> /v7 (Go major-version path rewrite landed upstream in commit 40dd4f151 "Rewrite Go import path to v7") - SRC_URI branch: stable-6.0 -> main - PV: 6.0.6+git -> 7.0.0+git - SRCREV bump to the v7.0.0 tag commit - Enable per-dep license tracking via 'require go-mod-licenses.inc' (parallel to cosign/docker-compose) - GO_MOD_DISCOVERY_LICENSE_TARGETS lists all 8 ./cmd/* targets the recipe's do_compile builds, so the license-scan filter uses the accurate `go list -deps` set rather than the narrower set derived from go build of the single GO_MOD_DISCOVERY_BUILD_TARGET (which only builds incus-migrate). See the companion oe-go-mod-fetcher commit for the tier-1 filter mechanism. All 5 go-mod sidecars and the new go-mod-licenses.inc regenerated. Bumping incus to version v7.0.0, which comprises the following commits: 6255b3956 Release Incus 7.0.0 50180d73e gomod: Update dependencies 40dd4f151 Rewrite Go import path to v7 d78350670 github/workflows/tests: Build cowsql and raft from source b56b7fc6b github/workflows/tests: Install mdl from rubygems instead of snap 676692e72 github/workflows/tests: Configure PPAs without apt-add-repository f55685170 Makefile: Switch to new golangci-lint install script 17502a12d gomod: Update dependencies 157465d65 incusd/instance/console: Emit a single instance-console event on SPICE c002012f1 incusd/instance/qemu: Don't restart the VM on shutdown 63c140a95 incusd/instance/qemu: Don't emit shutdown lifecycle event during restart d81c582dc tests: Extend sub-path tests to cover directory creation 7f5f2c9f3 doc: Update config d47b354cc doc/devices/disk: Update to cover sub-path creation 237e577da incusd/instance: Allow initial keys for sub-paths c8951dfc0 incusd/device/disk: Auto-create missing volume sub-directories 533fe9665 i18n: Update translation templates 08d9003a6 incus/storage: Add missing example description 24985d9ec incus/network_zone: Add missing example description d3ba5a8a4 incus/network_integration: Add missing example description 24ccbeab5 incus/network_address_set: Add missing example description f45f7e0f8 incus/network_acl: Add missing example description 9acd6ca19 incus/create: Add missing example description 962e9895c incus/config_template: Add missing example description 8844bd247 incus/launch: Add missing example description 137da4aa1 incus/storage_bucket/key: Fix incorrect list column description b5957ee10 incusd/instance/agent-loader: Remove some trailing whitespaces 59fc32002 tests: Adjust to work with next-hop 075b8ad8b incusd/device/nic: Set next-hop based on configured IP addresses 46dd21657 incusd/instance/qemu: Fix locking around VM reset a07727a76 doc/clustering: Add new scriptlet reason 78a5b3e4e incusd/cluster: Run placement scriptlet during re-balancing a18b30213 shared/api/scriptlet: Add InstancePlacementReasonRebalance bea1e3130 api: instances_placement_scriptlet_rebalance 5b8a1adea incus/cluster: Simplify logic ccfdb366e tests: Use a 5MiB test file for buckets e7223abd8 Makefile: Add help target and remove tags target 56a55c02e doc/rest-api: Refresh swagger YAML b69464a8e incusd: Add missing path parameters 3ad6ece9b doc/metrics: Mention Loki requirement 4add4e243 incus/server/network/ovn/driver: Fix duplicate external network ip check on network creation 0b1737305 i18n: Update translation templates 52f835d4d incus/image/copy: Add --reuse flag for --copy-aliases b4aab46e2 incus/cluster: Don't attempt to connect during join 67fe50f24 incusd: Implement core.shutdown_action 7d4b52778 incusd/evacuate: Extract evacuateStopInstance and evacuateMigrateInstance helpers 2b28bb462 doc: Update metadata b76536442 incusd/cluster/config: Add core.shutdown_action 4817f5ef6 api: Add server_shutdown_action extension 236711d0f incusd: Use QuotaWriter for backup and ISO uploads 5ceb17630 incusd: Fix nil pointer dereference in instance backup restore da44e2d05 incusd: Limit tarball YAML reads to 1MiB ec65c0015 incusd/storage/s3: Fix nil pointer dereference on truncated input afcf707e0 incusd/storage/instance: Fix bad snapshot index calculation 2b7d83a01 incusd/network/ovn: Fix TLS validation logic d768f81c0 incusd/storage/instance: Properly check dependent volumes on import 985a1dedf incusd/storage/volume: Validate snapshot entries on import 030ced1b5 incusd/storage/bucket: Validate expected metadata on import 09b6ce57f incusd/images: Add image server restriction check in image URL download path 4c480ba1d incus/server/network/ovn/driver: Validate that networks external ips are not used by another network, forward or loadbalancer 8c75386a7 incusd: Patch LINSTOR to set DrbdOptions/Disk/rs-discard-granularity 242436a30 gomod: Update dependencies 03da9f6b8 incusd/storage/s3: Derive AWS region from S3 endpoint URL 30969fc20 incusd: Switch minio S3 client for AWS SDK 1a947907f tests: Replace minio with simple built-in S3 endpoint 4226c0a58 incusd/storage/s3: Remove minio supervisor and ActivateBucket a49dcb509 incusd/storage: Remove remaining minio interactions be6107a27 incusd/storage/s3: Migrate data from minio to new format 5f7739d49 incusd/storage/s3: Switch to new listener 1cffadf40 incusd/storage/s3: Add in-process S3 handler package 9dbdeeaff incusd/instances: Fix gofump 1a8513c96 internal/server/cgroup: Fix gofumpt b3440a54e internal/rsync: Fix gofumpt 088bc766b i18n: Updatee translation templates 1c03717b7 incus/storage_bucket: Fix bad list column help message 1665ec10d i18n: Updatee translation templates ab9c4bffe incus/network_zone: Fix missing example description a4029535e i18n: Updatee translation templates fdb8f8754 incus/cluster: Fix spelling of YAML 260f5a750 i18n: Update translation templates e9cf5710b incus/storage: Fix typo 36611e884 incusd/storage/linstor: Tune DrbdOptions/Disk/rs-discard-granularity on pool creation 12257dd6d incusd: Fix cross-server migration being used instead of intra-cluster migration when storage and target are specified e96b5b7c4 incusd: Add support for overriding disk device pool during migration dd6e654cf incusd/instance: Add support for overriding disk device pool during migration 69b080dcf incusd/instance: Add UpdateDevices b8ba0244f incusd/storage: Add support for overriding disk device pool during migration 581475227 incusd/migration: Add support for overriding disk device pool during migration edc6875e9 client: Pass device override information during copy 872f3c203 incusd/migration: Add DeviceName field to DependentVolume 66f2ba05d incusd/storage: Allow overriding pool for dependent disk during migration 6da91897b github: Add disclaimer on bug reports 90f33b04c github: Automatically close untyped issues ec7ac5758 tests: Drop xtables firewall driver support ad217091e doc: Drop xtables/iptables/ebtables references f55dba32b incusd/firewall: Drop xtables/iptables/ebtables backend (nftables only) c76f48ba9 i18n: Update translation templates f57d9331a tests: Drop legacy [custom/] prefix a276dbb79 incus/storage_volume: Drop legacy [custom/] prefix a0e3a97b0 incus/usage: Add deprecation warning for the <key> <value> syntax 6ad50791e incus/color: Add warning prefix e1e02589e incus/remote_unix: Drop legacy <remote> syntax a14ec478b shared/cliconfig: Drop legacy <remote> syntax f416558d7 incus/config_trust: Drop legacy [<remote>:] ATOM syntax 1924513f3 incusd/storage/linstor: Update comment da54afdef Translated using Weblate (Portuguese) d5ccd2f26 incusd/network/bridge: Drop dnsmasq version checks below 2.90 a4246c546 incusd/rsync: Drop rsync version checks below 3.2.0 73d4ebc2f incusd/apparmor: Drop AppArmor version checks below 3.0.0 6d51ce3ac incusd/firewall/nftables: Drop nftables version checks below 1.0.0 0c8a5ba0e incusd/storage/truenas: Bump baseline to 0.7.7 a03b2c3f2 incusd/storage/lvm: Drop LVM version checks below 2.03.11 26d064e6a incusd/storage/btrfs: Drop btrfs version checks below 6.12.0 37525af0e incusd/storage/zfs: Drop ZFS version checks below 2.1.0 0aa222dd9 incusd/instance/qemu: Drop QEMU version checks below 8.2 0bedc0467 incusd: Drop kernel version checks (6.12 baseline) 57315170c doc/requirements: Expand on minimum versions e8b2db413 shared/idmap: Keep respecting INCUS_IDMAPPED_MOUNTS_DISABLE 2513e3430 incusd/instance/lxc: Drop pidfd fallback paths 87df02fad incusd/seccomp: Assume pidfd kernel support in MakePidFd 1d0a118f4 incusd/device/proxy: Drop pidfd fallback in setupProxyProcInfo e22258cc6 incusd/forknet: Remove unused info subcommand 11edb7ec1 incusd/instance/lxc: Drop forknet info fallback in networkState 21c4e5324 incusd/seccomp: Update LXC baseline b29832f79 incusd/seccomp: Update kernel baseline 328bde333 incusd/apparmor: Update kernel baseline 6e5459033 incusd/device: Update kernel baseline 3819225c0 incusd/instance/lxc: Update kernel baseline badeab48d incusd/sys: Update kernel baseline ab0375fba incusd: Remove kernel feature detection 3608a8226 client: Add bitmap manipulation functions 21fd4a1cf tests: Add more thorough tests for pull/push operations 198219b7e incus: Improve cp compatibility for pull operations 1cbe02367 incusd/seccomp: Update LXC baseline 2738dba58 incusd/instance/lxc: Update LXC baseline ddb9596c1 incusd/device: Update LXC baseline 96debc3fb incusd/cgroup: Update LXC baseline 63428c18e incusd: Reset LXC feature detection 6a0001aeb i18n: Update translation templates 5223b3afe incus: Generalize -a shorthand for --all 6fd85b2f3 incus: Generalize -t shorthand for --type 3013e8a32 incus: Generalize -f shorthand for --format 9af237518 incus: Generalize -f shorthand for --force 68db650ea incus: Wrap addition of native integer flags 1d26fd0ee incus: Wrap addition of boolean flags 17bdaeff5 incus: Wrap addition of integer flags 4bd27e795 incus: Wrap addition of string array flags 802bd453f incus: Wrap addition of string flags d7eaca04b i18n: Update translation templates 12e5b4dc4 incus/admin_sql: Clarify behavior on standalone systems 5e599d5cb incus/profile: Clarify example description a33515d91 incus: Add missing example descriptions 0de2b2036 incus; Fix copy/pasted list column description cc7daba8c incusd/storage/drivers: Fix migration import-shadowing 12f3fe8d5 incusd/instance/drivers: Check whether an instance snapshot can be safely restored 4da5b79c9 incusd/storage: Add CanRestoreInstanceSnapshot and qcow2CanRestoreSnapshot 4d217073f incusd/storage/drivers: Run Qcow2Info in read-only mode 9e3e53b7a incusd/storage/drivers: Add CanRestoreVolume 0710b22dd incus-agent: Work around issue when built with GO111MODULE=off 6daecfe4c Translated using Weblate (Russian) 501438798 doc: Remove cgroup1 mentions 5dd5ccbe3 incusd/sys: Remove cgroup1 support aec0b124d incusd/seccomp: Remove cgroup1 support 9d8d8358c incusd/device: Remove cgroup1 support 5ac30f130 incusd/apparmor: Remove cgroup1 support aa4e6470c incusd: Remove cgroup1 support 3d69764bc incusd/instance/lxc: Remove cgroup1 support 48ea96d4f incusd/cgroup: Require Cgroup V2 0a78b368b incus/instance/drivers/lxc: Early return state call in case instance is in error state Signed-off-by: Leon Schoch <git@darkress.xyz> f96d10c34 incus/instance/drivers/qemu: Early return state call in case instance is in error state Signed-off-by: Leon Schoch <git@darkress.xyz> f88c382cd incus/instance/drivers/common: Add isErrorStatusCode function Signed-off-by: Leon Schoch <git@darkress.xyz> 4eb479d18 doc/benchmark_performance: Mention GOPATH 7680c2699 i18n: Update translation templates 669564096 incus/network: Add --target to network list 2c92a0712 incusd/networks: Support targeting of network list 72b08d318 Translated using Weblate (Russian) c35a936f9 internal/linux: Add logging to ClearBlock a05cb3bd0 shared/validate: Fix name validation on single character 235b4dc89 incusd/storage: Prevent migration of dependent volumes for snapshot instances b54b7ca36 incusd/instances/qemu: Fix crash on nil qmp handler in RunJSON 2eb8f2cb2 incusd/instance/drivers: Add check to notify disk only during cluster move d19382c0a incusd/instance/drivers: Add support for live-migration of dependent volumes with a changed name a357bb02a incusd/storage: Add support for copying dependent volumes on the same target when the root volume storage changes 3dee40eab incusd/storage: Add support for migrating dependent volumes with a new name f6a612ac5 incusd/instance/drivers: Remove temporary snapshot block device after migration 685ef4c2c incusd/storage: Include dependent disks in copy requests 1e9450074 incusd: Allow copy only when all volumes are on remote storage 08fb9970f incusd: Add validation for dependent volumes during copy request a9df55ddf incusd/instance/qemu: Use timeouts for agent operations 995f4eb08 Translated using Weblate (Russian) 8d9c85c01 Translated using Weblate (Portuguese) b48d046bd incus-agent: Use psutil for process count 1de223c97 incusd/instance/qemu: Improve OS detection for FreeBSD 58c0823ca i18n: Update translation templates 2f516db4d tests: Test cp-like flags in incus storage volume file push e56a3a0fb incus: Add cp-like flags to incus storage volume file push be8630b9f incus: Defer dereferencing error handling 855ae0da5 tests: Test cp-like flags in incus file push e9b5ee4eb incus: Add cp-like flags to incus file push 6b508d741 incus: Widen stdout checks in pull commands 1b3db667c incusd/instance/edk2: Add support for seabios at bios-256k 4ac7b8ec3 Translated using Weblate (Portuguese) ecde36d9f incusd/storage: Add support for export/import qcow2 in raw format ff161e795 incusd/storage/drivers: Make createParentSnapshotDirIfMissing public 93a87a98b incusd/storage/drivers: Extract unpackVolume and backupVolume to util c45dfec15 incusd/images: Allow simpler HTTP headers 723a49347 Translated using Weblate (Tamil) 3cecb3b23 Translated using Weblate (French) e12d0b9fe Translated using Weblate (French) d9d4b9c21 Translated using Weblate (French) 18dc92a0b Translated using Weblate (French) f80c9cad5 Translated using Weblate (French) a261f9e4d Translated using Weblate (French) b59c809ec Translated using Weblate (French) 1fe001a03 Translated using Weblate (French) ac67a360c Translated using Weblate (French) b97d27483 Translated using Weblate (Japanese) ec6c78888 Translated using Weblate (Japanese) bb672a06b Translated using Weblate (Japanese) 185f11f79 Translated using Weblate (Georgian) cfef91def Translated using Weblate (Georgian) 32c8fce19 Translated using Weblate (German) add12c5b1 Translated using Weblate (German) ff2059c10 Translated using Weblate (German) aec7c7bb8 Translated using Weblate (German) 19e06dcca Translated using Weblate (German) 8b3b548d0 Translated using Weblate (Indonesian) d313395d9 Translated using Weblate (Indonesian) df09649b1 Translated using Weblate (Indonesian) 43aa2567b Translated using Weblate (Chinese (Simplified Han script)) 035ff34ef Translated using Weblate (Chinese (Simplified Han script)) 9c63faab4 Translated using Weblate (Chinese (Simplified Han script)) 791e595e1 Translated using Weblate (Chinese (Simplified Han script)) 646c7a710 Translated using Weblate (Chinese (Simplified Han script)) c59f0be76 Translated using Weblate (Chinese (Simplified Han script)) 8708d8b06 Translated using Weblate (Chinese (Simplified Han script)) 9a930e77c Translated using Weblate (Chinese (Simplified Han script)) e3e02890c Translated using Weblate (Chinese (Traditional Han script)) eb6c49cb1 Translated using Weblate (Chinese (Traditional Han script)) 5fc4f6a6e Translated using Weblate (Greek) 87e9699ef Translated using Weblate (Portuguese) d50a2b6e8 Translated using Weblate (Portuguese) f93b46581 Translated using Weblate (Swedish) fd8e5af34 Translated using Weblate (Swedish) f020810b3 Translated using Weblate (Portuguese (Brazil)) c8829442f Translated using Weblate (Portuguese (Brazil)) f9e0b711b Translated using Weblate (Portuguese (Brazil)) 5d999a9c7 Translated using Weblate (Norwegian Bokmål) 58ea9ea9f Translated using Weblate (Norwegian Bokmål) b478af42a Translated using Weblate (Spanish) 1d466f332 Translated using Weblate (Spanish) 99d041080 Translated using Weblate (Spanish) 27c4a7882 Translated using Weblate (Dutch) e25913a48 Translated using Weblate (Dutch) e806d2d7e Translated using Weblate (Russian) 088cd0149 Translated using Weblate (Russian) fbae00bb2 Translated using Weblate (Italian) b2ff3a455 Translated using Weblate (Italian) dc6833bbb shared/archive: Avoid concurrent calls to Wait c6b9378c1 incusd/migrate: Limit timeout to initial handshake c0ea1f952 incusd/instance/drivers: Add support for handling BLOCK_JOB_COMPLETED and BLOCK_JOB_ERROR events 31c5e214f incusd/instance/drivers/qmp: Wait for block job completion after issuing block-job-complete 8431a2829 i18n: Update translation templates 879a45185 tests: Add import from stdin and export to stdout 64bd8f9dc incus/storage_bucket: Improve import/export file handling e15aa2abc incus/storage_volume: Improve import/export file handling 9d332db99 incus/import: Improve stdin handling 3c262355d incus/export: Improve target file handling 47c8f826d i18n: Update translation templates 76ec6bcf2 incus/info: Tweak wording in resources output 115791cd4 i18n: Update translation templates b197dffe9 incus/cluster: Tweak error message 4777803e0 incusd/device/nic: Prevent USB NICs on migratable VMs 14e58f87b gomod: Update dependencies 18e9f0879 incusd: Increase devices tmpfs f1c264a79 incusd/devices/disk: Lock creation of ISO images 606647b88 incusd/instance/qemu: Fix boot state recording 7a7bb41ce Translated using Weblate (Russian) ec50d3b37 incusd/migration: Bump timeouts to 30s a474bf9cc Translated using Weblate (Russian) f05bd57bd incusd: Switch io.Copy to util.SafeCopy f932d77bb incus: Switch io.Copy to util.SafeCopy 27402978f incus-migrate: Switch io.Copy to util.SafeCopy 573ba5a66 incus-user: Switch io.Copy to util.SafeCopy c0079ad85 incus-agent: Switch io.Copy to util.SafeCopy 8b1aeac6e incus-simplestreams: Switch io.Copy to util.SafeCopy c37033dd5 lxc-to-incus: Switch io.Copy to util.SafeCopy e126d24f6 lxd-to-incus: Switch io.Copy to util.SafeCopy 3f98917f3 internal/rsync: Switch io.Copy to util.SafeCopy 262451981 internal/io: Switch io.Copy to util.SafeCopy 0e6b86c21 internal/util: Switch io.Copy to util.SafeCopy 309a2e60b shared/util: Switch io.Copy to util.SafeCopy efc0c11e1 shared/cliconfig: Switch io.Copy to util.SafeCopy a08d2db1b shared/ws: Switch io.Copy to util.SafeCopy 2614f7ff1 client: Switch io.Copy to util.SafeCopy 1396bcc73 incusd: Switch io.CopyN to util.SafeCopy 3a6f94d8c incus: Switch io.CopyN to util.SafeCopy 217433e53 incus-migrate: Switch io.CopyN to util.SafeCopy 9fb55bf99 shared/util: Introduce SafeCopy 85dc304ae incusd/migrate: Bump migration timeouts 4e8b67428 incusd/seccomp: Cleanup pointless check e57a32b76 shared/subprocess: Cleanup pointless check 42278bd2b shared/archive: Improve detection and error handling 865297b22 Translated using Weblate (Portuguese (Brazil)) eb4d8b09c Translated using Weblate (Portuguese (Brazil)) 70e773391 Translated using Weblate (German) 97791d99f Translated using Weblate (German) 78c85c4ba Translated using Weblate (German) 80f749062 Translated using Weblate (German) 6c02c0eff Translated using Weblate (German) a7db932b6 Translated using Weblate (Dutch) dfac19eb3 Translated using Weblate (Dutch) 0c719df86 Translated using Weblate (Portuguese) c84f10149 Translated using Weblate (Portuguese) 9d9c37d4f Translated using Weblate (Norwegian Bokmål) b0711d804 Translated using Weblate (Norwegian Bokmål) 8f0f166c8 Translated using Weblate (French) ca3e63832 Translated using Weblate (French) e9bfa975c Translated using Weblate (French) 75e97bf63 Translated using Weblate (French) d931dbd92 Translated using Weblate (French) e5f26b294 Translated using Weblate (French) 56c3fa313 Translated using Weblate (French) 26beb9fad Translated using Weblate (French) 705e3cfaf Translated using Weblate (Greek) 524ad4213 Translated using Weblate (Chinese (Traditional Han script)) 3ca794e5f Translated using Weblate (Chinese (Traditional Han script)) 271a432e3 Translated using Weblate (Italian) f6bc421d4 Translated using Weblate (Italian) 5b7b2c035 Translated using Weblate (Georgian) 7250a4391 Translated using Weblate (Georgian) 4d69a6b69 Translated using Weblate (Indonesian) 0954a6ea7 Translated using Weblate (Indonesian) 3d5e09e9a Translated using Weblate (Russian) fb0d8d848 Translated using Weblate (Russian) d70383bd3 Translated using Weblate (Swedish) 384920c8e Translated using Weblate (Swedish) 26e000eda Translated using Weblate (Chinese (Simplified Han script)) 7c5d0d882 Translated using Weblate (Chinese (Simplified Han script)) 891bc2e34 Translated using Weblate (Chinese (Simplified Han script)) d8aedb5ef Translated using Weblate (Chinese (Simplified Han script)) 51d70f9be Translated using Weblate (Chinese (Simplified Han script)) f7474f883 Translated using Weblate (Chinese (Simplified Han script)) 719942381 Translated using Weblate (Chinese (Simplified Han script)) e62d0af9d Translated using Weblate (Chinese (Simplified Han script)) 163a7b450 Translated using Weblate (Spanish) 7b011b8b0 Translated using Weblate (Spanish) d2af801a0 Translated using Weblate (Japanese) ab0015bb0 Translated using Weblate (Japanese) bf9a96602 Translated using Weblate (Japanese) 04a7a1358 Translated using Weblate (Tamil) 229da7b64 incusd/project: Make checkRestrictionsAndAggregateLimits validate pool access 677120895 doc: Update config d7cc9c59d incusd/project: Add support for restricted.storage-pools.access 003932c0f api: Add projects_restricted_storage_pool_access extension da618fb1d incusd/instances: Don't delete ephemeral instances on system shutdown d4c9dfcea incusd/storage/drivers: Use 'qemu-img info' in read-only mode 1de0a4652 incusd/storage/drivers: Add syncBtrfs 62cda5636 incusd/storage: Improve qcow2 volume handling 8f7b2a214 incus/server/network/ovn/driver: Only add discard route if it doesn't exist already 91868e436 incus/server/network/ovn/nb: Mark route as discord when nexthop is 'discard' 7f9535fa3 incusd/response/upgrade: Add small delay for NBD c9d51c466 client: Fix bad error handling bed4cd20f incusd/migrate: Set short timeouts on read/write of control data 69255206c incusd/instance/qemu: Handle stateful detection corner case 2826d1ae9 doc: Update config a59ad82eb incusd/instance/qemu: Don't export internal vcpus and numa nodes maps a4aed86f0 incusd/instance/qemu: Make use of new migration state logic 0c0a3ddfb incusd/instance/qemu: Move topology functions to new file 1f8037877 incusd/instance/qemu: Add new migration state volatile ee5cb850d incusd/instance/qemu: Rename internal structs 26227cae3 internal/instance: Introduce volatile.vm.boot_state f272bb356 incusd/storage: Improve snapshot creation rollback handling 99cc09c7b incusd/instance/drivers: Improve snapshot creation rollback handling 18d1e53dc incusd/storage/drivers: Fix ordering in Qcow2DeletionCleanup bf9506254 incusd/storage: Allow exposing dirty bitmaps through NBD export in offline mode 4bb79479d incusd/instance/drivers: Allow exposing dirty bitmaps through NBD export in online mode d5bc02c00 incusd/instance/qemu: Fix RTC handling on Windows b8ac4bde1 doc/rest-api: Refresh swagger YAML 5f26b611e incusd: Return bitmap endpoints by default, objects with recursion=1 38985cee8 i18n: Update translation templates aac4f8a20 tests: Add strict pull checks for directories f8ec5611a incus: Enforce stricter directory checks b67d5b8ab incus: Fix Windows absolute paths 629047c3f incusd/apparmor/qemuimg: Expand symlinks cb0dc427b incusd: Pass instanceStateful flag during instance snapshot 13f4389fa incusd/device: Pass instanceStateful flag during instance snapshot 17ce1b91c incusd/storage: Add instanceStateful flag to volume snapshot operations 89f548366 client: Forward skopeo errors a9e6edfc9 incusd/instance/lxc: Don't return nil when not implemented 5c0793cc2 doc/rest-api: Refresh swagger YAML a642e83ca incusd: Add API endpoints for managing dirty bitmaps 1de4ab1bc incusd/storage: Add InstanceByVolumeName b9d98fb6e incusd/instance: Add methods to manage dirty bitmaps f4ad06efb shared/api: Add structs for managing dirty bitmaps 46f96f983 incusd/instance/qmp: Add commands to manage dirty bitmaps b2d72df1b incusd/storage: Support NBD export in offline mode 437b102d2 incusd/storage/drivers: Implement ActivateTask 9833e0508 incusd/storage: Export snapshot when VM is running to ensure consistency 2db310feb incusd/instance: Export snapshot when VM is running to ensure consistency eaf588f07 incusd/instance/drivers: Improve error when NBD server is already running 020793d72 incusd/instance/qmp: Add QueryBlockExports and QueryNBDBlockExports d3f6f2ffe i18n: Update translation templates a9170d966 incus/storage/volume: Add NBD command fc7d19bb5 incusd/instance: Implement ConnectNBD ec3fde445 doc/rest-api: Refresh swagger YAML 926002c7f incusd/storage: Implement NBD functions 5f4869b5c incusd/storage_volumes: Add NBD API b2c209539 client: Add GetStoragePoolVolumeBlockNBDConn e133c59e9 incusd/auth: Add can_connect_nbd b5a81e51e api: storage_volume_nbd 8babda1d9 incus: Enable admin recover and admin sql on all platforms 9d4f3b770 incusd/instance/qemu: Scale SCSI queues with CPUs a001d5e8d incusd/instance/drivers: Fix live migration of instances with snapshots 7f4c58320 incusd/device/nic_bridged: Handle physical NICs 47512f962 doc/image_format: Update Pongo2 website ee5d142bf incusd/instances/qemu: Skip vmcoreinfo on ppc64le 974eb2b8a incusd/device/nic_physical: Fix inheritance from network 2259e714e incusd/device/nic_physical: Fix bridge handling eefd6f880 incusd: Don't expose the API extension list pre-authentication d71c37044 incusd/storage: Add support for stateful snapshots for qcow2 volumes b29ab524b incusd/instance: Add support for stateful snapshots for qcow2 volumes 034c4a1b2 gomod: Update dependencies 39eef9765 doc: Update config 880c84caa incusd/device/nic_physical: Fix device validation 3777a484e doc: Update metadata 644d69d7f incusd/cluster/config: Clarify description of oidc.claim option b84add734 tests: Add tests for exporting/importing dependent volumes 142e03b80 incusd/storage: Use device name when importing dependent volumes from backup 2889445b3 incusd/forksyscall: Handle mount arguments when using idmap 672189f10 incusd/storage: Improve comments on locks be1a60487 tests: Rewrite out-of-space test to use profiles 68d6be36e incusd/instance/drivers: Pass the cleanupDependencies flag to device Remove 58fd96a51 incusd/device: Add cleanupDependencies argument to Remove() method 1ea73e37b incusd/storage: Rename createDependentVolumes to createDependentVolumesFromBackup 068dce801 incusd/storage: Improve logging during dependent volume creation from backup 07faf5e0b incusd/storage: Support optimized storage for dependent volumes 65a56f4e3 incus/server/network/ovn/driver: Cleanup stale instance port uuids from acl port groups on instance stop 40a7bbae0 incus/server/network/ovn/nb: Add function to get PortGroups by Port UUID 617d88028 incusd/instance: Rename deleteDependentVolumes to cleanupDependencies 97825998c incusd: Configure exceptions to the 1MiB limit 6aa357331 incusd: Limit request body to 1MiB by default 9c4945c2b incusd: Clarify shutdown message ea8289d96 incusd/instances: Implement cancelation in exec logic d84ed053d incusd/migration: Implement cancelation in migration logic 913dd1482 incusd/storage: Fix potential deadlock 41589e836 incusd/storage: Fix race in caching logic a1d3f28c9 incusd/storage: Move dependent volume deletion from storage to instance delete() 95b761923 incusd/instance: Move dependent volume deletion from storage to instance delete() beed5b588 incusd/storage: Pass additional parameter to Delete method 6573e9bc7 incusd/instance: Pass additional parameter to Delete method 43d86bef5 incusd/storage: use ForEachDependentDiskType and HasDependentDisk from instance a223c01b8 incusd/instance: Add HasDependentDisk and ForEachDependentDiskType to instance interface c25590ea5 incusd/storage: Add support for cross-cluster dependent volumes migration 372818c85 incusd/instance/drivers: Add support for cross-cluster dependent volumes migration d2af510ec incusd/instance: Add support for disk name to ExportQcow2Block 8f8fc2835 incusd/storage: Add ShouldMigrateDependentVolume bca9d223d incusd/device: Ignore 'not found' errors when updating dependent config during device add/remove e69aba01f tests: Update for slight YAML differences 271cd4cf0 test: Fix ordering of godeps.list 81044dc52 incus: Update for new YAML empty reader behavior a996d03ae gomod: Update dependencies 853f96f9d test: Switch to go-yaml/v4 4b69bf2db incus: Switch to go-yaml/v4 0adef7322 incusd: Switch to go-yaml/v4 3d178e135 incusd/storage/drivers: Switch to go-yaml/v4 b73a1fe4c incusd/backup: Switch to go-yaml/v4 20a8c5e06 incus-simplestreams: Switch to go-yaml/v4 7a8c6aea4 incus-migrate: Switch to go-yaml/v4 39a18a73b incus-agent: Switch to go-yaml/v4 fa3a8d4dd incusd/storage: Switch to go-yaml/v4 de27e44be incusd/instance/drivers: Switch to go-yaml/v4 9f8574a71 shared/validate: Switch to go-yaml/v4 28e767d80 shared/subprocess: Switch to go-yaml/v4 cda3ac59b shared/cmd: Switch to go-yaml/v4 a74d566c0 shared/cliconfig: Switch to go-yaml/v4 0fae4ba67 shared/api: Switch to go-yaml/v4 ffeb2f1f1 Translated using Weblate (Chinese (Simplified Han script)) a328acf71 Translated using Weblate (Chinese (Simplified Han script)) 54c1875da Translated using Weblate (Chinese (Simplified Han script)) 2e2a90dbb Translated using Weblate (Chinese (Simplified Han script)) 5dbbf138b Translated using Weblate (Chinese (Simplified Han script)) a16f18074 Translated using Weblate (Chinese (Simplified Han script)) 8341cb20e Translated using Weblate (Chinese (Simplified Han script)) 1d2e9a8ce Translated using Weblate (Chinese (Simplified Han script)) 37bc93550 Translated using Weblate (Swedish) 5a741260a Translated using Weblate (Swedish) aca565572 Translated using Weblate (Indonesian) c096a39a9 Translated using Weblate (Indonesian) 2c81a01cf Translated using Weblate (Italian) 5ca094a56 Translated using Weblate (Italian) d70df485d Translated using Weblate (Norwegian Bokmål) a1a425222 Translated using Weblate (Norwegian Bokmål) 51f92c87e Translated using Weblate (Greek) 3cdda102e Translated using Weblate (German) a465af979 Translated using Weblate (German) 67184dafe Translated using Weblate (German) d6eda2813 Translated using Weblate (German) b91bc13bd Translated using Weblate (German) b6ecebee3 Translated using Weblate (Dutch) 8686539df Translated using Weblate (Dutch) 68d48808b Translated using Weblate (Russian) 6ec02bbc9 Translated using Weblate (Russian) dcc24fbd6 Translated using Weblate (Spanish) 683b1c720 Translated using Weblate (Spanish) 8e892cf41 Translated using Weblate (Chinese (Traditional Han script)) ee6091fae Translated using Weblate (Chinese (Traditional Han script)) e0e9e891a Translated using Weblate (French) 13c873017 Translated using Weblate (French) 9f403f270 Translated using Weblate (French) 8424417dc Translated using Weblate (French) 0232985c3 Translated using Weblate (French) 5e076e795 Translated using Weblate (French) a723c451d Translated using Weblate (French) 70d7b0f11 Translated using Weblate (French) 367262a09 Translated using Weblate (Georgian) 0b68e72f7 Translated using Weblate (Georgian) af5c0b7f2 Translated using Weblate (Tamil) 76f352459 Translated using Weblate (Portuguese) 141c33107 Translated using Weblate (Portuguese) e3b52179a Translated using Weblate (Japanese) 3a1a6a31b Translated using Weblate (Japanese) 1ab8747c8 Translated using Weblate (Japanese) 348b5b908 Translated using Weblate (Portuguese (Brazil)) d92cf3270 Translated using Weblate (Portuguese (Brazil)) ac893aecc incusd/storage/zfs: Use old-style ZFS types dfc98eeaf incusd/storage/truenas: Use old-style ZFS types 1b0c4d1d6 cmd/incus-simplestreams: Add flag for overriding product name 17e857533 incusd/network/state: Use canAccessNetwork c37b9bf7c shared/cliconfig: Avoid treating `=` as part of a remote name 8c8733af6 incusd/storage/truenas: Retry iSCSI map request 568bca413 incusd/instances: Allow more concurency ac805fc4a incusd/storage/truenas: Implement better caching 5d05e18a8 incusd/storage/zfs: Implement better caching 77d89e32e incusd: Remove explicit caching mechanism in favor of implicit 71b33fb57 incusd/instance/common: Don't perform costly storage actions when no snapshots f7f600b2d tests: Add additional tests for dependent volume handling ff71fe442 incusd/device: Update 'dependent' flag on device add and detach 2f3b0f04c incusd: Disallow setting the 'dependent' key on volume creation 33fa8fe83 incusd/response: Make pipeResponse flush headers ASAP 3d4a75f7c incusd: Trigger IncusOS update check on version mismatch 312ba9f57 internal/incusos: Implement TriggerSystemUpdateCheck 0c0fd0e32 internal/incusos: Allow non-GET requests 42653279a tests: Test dependent volume deletion on instance deletion e0ade0dfc incusd/storage: Delete dependent volumes on instance deletion 43b992af8 Translated using Weblate (Russian) db4deacff Translated using Weblate (Georgian) 204c0fa52 incusd/instance/qemu: Omit audio device on systems without virtio-sound 9d5c86f4f incusd/instance/qemu: Add virtio-sound detection logic f305f8fdd incusd/instance/qmp: Add QueryVirtioSoundDevice c95f5ba52 incusd: Fix bad type in format strings 5ee93ed5d incus-benchmark: Remove unused function 599396985 incusd: Un-export remaining exported functions da956b9f0 incus-benchmark: Un-export remaining exported functions 73a55dc5b incus-migrate: Un-export remaining exported functions d7696df14 incus: Un-export remaining exported functions cf7d05517 fuidshift: Un-export Command and Run functions 15e1c6011 lxc-to-incus: Un-export Command and Run functions 92d4bccb6 lxd-to-incus: Un-export Command and Run functions 3affc2304 incus-user: Un-export Command and Run functions 940eb2763 incus-agent: Un-export Command and Run functions 077443693 incus-simplestreams: Un-export Command and Run functions 2eda71422 incus-benchmark: Un-export Command and Run functions 511834c55 incus: Un-export Command and Run functions 60cc2aacb incusd/instance/qemu: enable SPICE audio via feature gate 1143820eb incusd/instance/qemu: Export plan9 drives only when supported 6b2bbb014 incusd/instance/qemu: Add plan9 detection logic 182a89bb2 incusd/instance/qmp: Add Query9pDevice 59bcf3c8b incusd/instances/qemu: Rework qemuArchConfig e87972362 incusd/instance/qemu: Disable SPICE on systems missing support 72d84b951 incusd/instance/qemu: Add SPICE detection logic 0ad430455 incusd/instance/qmp: Add QuerySpice ad80c0886 incusd/instance/agent-loader: Use Linux arch names 7144a9f7f incus/version: Gracefully fail when server unreachable c9c054f6d client: Optionally skip blocking for OIDC authentication b6f19e119 Added translation using Weblate (Georgian) 60ada6cbc github: format INCUS_VERSION from tag in release workflow 5068001c2 shared/cliconfig: Add support for encrypted TLS keys to keepalive proxy ff17bc7c7 shared/cliconfig: Implement TLS cert/key/ca caching 12dda5c91 shared/cliconfig: Shorten path to using keepalive proxy Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* docker-distribution: update to v3.1.1-tipBruce Ashfield2026-05-281-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping distribution to version v3.1.1-20-g22c97cc5, which comprises the following commits: 7c894b6e build(deps): bump docker/bake-action from 7.1.0 to 7.2.0 3578dde0 build(deps): bump codecov/codecov-action from 6.0.0 to 6.0.1 0d578958 chore: smol go fix changes 03e955e9 build(deps): bump github/codeql-action from 4.35.4 to 4.35.5 5c4717ce Fix blob type migration in the azure driver 1cf82e50 build(deps): bump github/codeql-action from 4.35.3 to 4.35.4 cc455206 build(deps): bump github/codeql-action from 4.35.2 to 4.35.3 d3c0df9f chore(release): prepare for v3.1.1 release 8baf3e08 fix: prevent tag deletion when storage.delete.enabled is false 194f5169 build(deps): bump github/codeql-action from 4.35.1 to 4.35.2 72c88bc9 fix(storage): bounds-check the file basename in PurgeUploads Walk callback 4a4b9586 build(deps): bump softprops/action-gh-release from 2.6.1 to 3.0.0 835c1c58 feat(s3): add express zone one support to S3 driver c6f552e5 fix(proxy): clamp oversized n query param instead of returning 400 3cf44639 Update docker-compose structure in deploying.md 4b5154db build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 203c505c build(deps): bump docker/bake-action from 7.0.0 to 7.1.0 fed26101 build(deps): bump actions/upload-pages-artifact from 4.0.0 to 5.0.0 0102b581 Bump Go 1.26 in CI 29eb2149 chore(build): Bump go version to latest 1.25 326a0d0b build(deps): bump go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp 0679fc13 refactor: use slices.Backward to simplify the code 445af38d build(deps): bump docker/login-action from 4.0.0 to 4.1.0 60de6e34 fix(proxy): fix tag list endpoint in proxy mode 567670f6 build(deps): bump go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp 5e721744 build(deps): bump github/codeql-action from 4.34.1 to 4.35.1 b1d5dbcf chore(ci): Prep for v3.1 release 49447e8e fix(vendor): fix broke vendpor validation 6a02a0e8 Opt: refactor tag list pagination support 7ed654e0 feat(registry): enhance authentication checks in htpasswd implementation 00056726 chore(app): warn when partial TLS config is used in Redis 2bf6ae00 build(deps): bump github.com/go-jose/go-jose/v4 f91da114 build(deps): bump codecov/codecov-action from 5.5.4 to 6.0.0 5cda7286 fix redis repo-scoped blob descriptor revocation bbc6f54c build(deps): bump actions/configure-pages from 5.0.0 to 6.0.0 0f4a2c5f build(deps): bump actions/setup-go from 6.3.0 to 6.4.0 f215e513 proxy: bind bearer realms to upstream trust boundary 3c670635 internal/client/auth/challenge: fix minor linting issues 055cc71b internal/client/auth/challenge: cleanup URL-normalization a35ff435 internal/client/auth/challenge: simpleManager: make zero value usable 069947f6 internal/client/auth/challenge: simpleManager: un-export fields 9304afc1 ci: update ${{ secrets.GITHUB_TOKEN }} -> ${{ github.token }} 187c1f9b ci: apply zizmor auto-fixes e9eb3c2f ci: pin all actions by sha b01c36a6 ci: labeler: fix indentation e0bac483 fix(registry/proxy): do not re-use http request context for background writes b6946f4c build(deps): bump actions/deploy-pages from 4 to 5 6d5a05cb build(deps): bump github/codeql-action from 4.32.5 to 4.34.1 fa05d6fa chore(deps): Bump Go to latest 1.25 in CI workflows and go.mod 0fb0a8d3 fix: report error in `DeleteManifest` when `Delete` returns `ErrDigestUnsupported` 830758b5 fix: correct Ed25519 JWK thumbprint `kty` from `"OTP"` to `"OKP"` b1ae1b21 Opt: refector tag list pagination support e7475483 Update Redis TLS configuration docs 6780dbbb Enable Redis TLS without client certificates 56ba10a6 Return error instead of panicking in parser 3b8ac2d2 Apply code review suggestions 714b78c4 Add test for inlined structs to configuration package 54b56cdb Inline env variables if the underlying struct is YAML inlined 8a5addfc Update the docs with correct information 10a83bad fix: removerepository skip pathNotfound error. 54c58910 Update vacuum.go f89be310 Update docs/content/storage-drivers/s3.md 075b5824 Update s3.md regionendpoint option Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* docker-compose: update to v5.1.4-tipBruce Ashfield2026-05-287-243/+944
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Enables per-dependency license tracking by requiring the new go-mod-licenses.inc sidecar (generated by oe-go-mod-fetcher --scan-licenses, parallel to cosign's setup). All five go-mod sidecars regenerated for the v5.1.4-tip SRCREV. Bumping compose to version v5.1.4-2-g7eeb7de7a, which comprises the following commits: 7eeb7de7a docs: compose logs: add links for since/until flag descriptions 40a2262a0 build(deps): bump github.com/docker/cli 4732a2ed2 build(deps): bump golang.org/x/sys from 0.42.0 to 0.44.0 5fb09a9b8 build(deps): bump github.com/docker/cli 32c78147b build(deps): bump github.com/compose-spec/compose-go/v2 eb4b1cc3f fix(publish): prompt on sensitive-looking env literals 0e25711ca build(deps): bump google.golang.org/grpc from 1.81.0 to 1.81.1 c59e13cde feat: pre-filter Desktop Logs view by Compose project 554a2ba3e refactor: drop Desktop beta-settings check; gate hint on LogsTab flag 71cd334db fix: restore stoppingEvent/stoppedEvent helpers for plugin stop hook 5b4586e3a fix: stop-only metadata no longer drops options for up/down 19fc292eb perf: avoid duplicate provider metadata fetch on stop 672dc14d2 feat: add stop lifecycle hook for external providers 8e0d5e17a fix: make e2e tests pass reliably locally with Docker Desktop - Fix stale image/container reuse across test runs - Add registry readiness check and async removal polling - Skip multi-arch test when docker driver supports it - Use t.Cleanup for reliable teardown, fix project name mismatches - Re-enable 4 previously skipped tests that now pass 66c21c3b6 fix: route OCI artifact pulls through Docker Desktop HTTP proxy 659b269e5 nit: use labelFilter consistently in filters.go 5c7071219 fix: restore deprecated Set.Clear/Union; use resource var in pull.go 07832c4df refactor: fix lint issues from cleanup changes 40d363baf refactor: miscellaneous small cleanups (forEach, filters, Set) 98163f561 refactor(compose): collapse resolveSharedNamespaces repeated blocks 96cb057d0 refactor(compose): extract forEachContainerConcurrent to deduplicate pause/kill logic c8325dd0d refactor(compose): extract removeResource helper in down.go 0eb2e4f4e refactor(compose): remove redundant wrapper funcs in dependencies.go da530c723 refactor(compose): collapse trivial event-helper wrappers in progress.go 616adea1b refactor(cmd): extract withBackend helper to remove CLI boilerplate 88545507e pkg/compose: go fix 2bbb88acf update to go1.26.3 4f69a8c99 build(deps): bump google.golang.org/grpc from 1.80.0 to 1.81.0 9581337d2 build(deps): bump github.com/docker/cli e1267ec10 build(deps): bump github.com/moby/moby/client from 0.4.0 to 0.4.1 0fcbaff45 build(deps): bump github.com/docker/cli b8effbacb Change verb tense in `compose` command documentation 60584e72b chore: update cagent-action to v1.4.4 baaaaa3ff build(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13 9fd9dc7ca ci: remove unused e2e job from merge workflow 977a4310f remove 'provenance' attribute' efb090183 feat: make hook hint deep links clickable using OSC 8 terminal hyperlinks 6ed7625d4 build(deps): bump github.com/containerd/containerd/v2 7a97400be Fix typo in SECURITY.md 9eb896670 fix: provider output handling and watch rebuild re-invocation d518da241 build and push Docker Desktop module image on release 182defa8a feat: add Docker Desktop Logs view hints and navigation shortcut ae92bef4e update to Go 1.25.9 ba417e439 use new moby/moby modules instead of docker/docker dependency 9085f7bda bump compose-go to version v2.10.2 89e3517f2 build(deps): bump github.com/docker/cli v29.4.0 d1296c346 build(deps): github.com/moby/moby/client v0.4.0, moby/api v1.54.1 63601ebbb test: migrate tar_test.go from testify to gotest.tools/v3 6ce3fb57a fix: return error on non-ErrNotExist stat failures in Tar.Sync() c1aefc74c build(deps): bump github.com/containerd/platforms 148ad64ee build(deps): bump google.golang.org/grpc from 1.79.3 to 1.80.0 3ecc08294 build(deps): bump github.com/docker/buildx v0.33.0, buildkit v0.29.0 1e3f4d0f4 fix: update e2e tests to expect exit code 130 on user decline 37cbf7a9c test: repurpose decline test to cover sensitive data detection path 9c5fd5098 publish: return ErrPublishAborted when user declines interactive prompts 73d8a6d57 test: use random host port for dind TLS build test 92a7ac1fa fix mixed assertion libraries in tests a97738de7 fix: add NetworkConnect fallback for API < 1.44 3b1004c4d fix: gate extra EndpointsConfig behind API >= 1.44 9cab43945 refactor: merge RuntimeVersion and CurrentAPIVersion into RuntimeAPIVersion ef836856f fix: don't cache transient errors in version negotiation c7d1a6030 fix: use pointer receivers for composeService methods with sync.Once fields 5f6f35ed2 pkg/compose: use negotiated API version for request shaping 3d2d03cd3 build(deps): bump github.com/hashicorp/go-version from 1.8.0 to 1.9.0 7aeb90c9a Skip PR review workflow for Dependabot PRs e5c6b9c3b fix: return error from ExecStart instead of nil in runWaitExec b529a3ca5 fix: add build tag to hook_test.go to fix Windows build failure (#13682) fa9762b15 build(deps): bump github.com/docker/cli 5bbdd239d pkg/compose: fix TestRunHook_ConsoleSize on macOS e742d0971 fix: initialize and pass envFiles map in processExtends 612b8c567 fix: preserve ssh:// URL scheme in dockerFilePath ef86a6ef0 build(deps): bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.42.0 0de456bc7 chore: bump GitHub Actions to latest versions 56e2dba36 chore: pin GitHub Actions to commit SHA, remove pr-review workflow 0c39d8a20 build(deps): bump github.com/moby/patternmatcher from 0.6.0 to 0.6.1 a57320fdf Fix up attach filtering 46d75d0be Update .github/workflows/pr-review.yml bd351d7f9 Update .github/workflows/pr-review.yml ece188682 update cagent-action to latest (with better permissions) 2b9f60ba5 Add AI-powered PR review workflow via docker/cagent-action b18354b9f refactor: thread context through publish sensitive data check 72bf113b0 build(deps): bump google.golang.org/grpc from 1.78.0 to 1.79.3 5de4353a6 bump golangci-lint to latest and configure CLAUDE to use it on change 27d9d5063 build(deps): bump github.com/containerd/platforms 0d8dc0904 cmd/display: left-pad timers for right-aligned column 02aaf253c Fix TTY timer alignment leaving stale suffix b04336802 Update docker/github-builder to v1.4.0 c7e889636 Fix forbidigo linting error e3fcdb823 Fix linting issues in tty_test.go b7d1c62ec exclude .idea from git commit 25b29d776 Fix deadlock in ttyWriter.Done() e8c214349 build(deps): bump github.com/moby/moby/client from 0.2.2 to 0.3.0 Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* moby: update to v29.5.2-tipBruce Ashfield2026-05-281-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping moby to version docker-v29.5.2-37-g19592a8ad2, which comprises the following commits: 96597f3098 daemon/libnetwork: Network.ResolveService: slight optimization 1574d48db0 daemon/libnetwork: inline some variables 059d3f36ee Update RootlessKit (3.0.1) 4c670ed4da github: Improve Pull Request template 88ff811d71 Minimal AGENTS instruction f82846d702 renovate: Add release-age cooldown db84483b7e chore(deps): update github/codeql-action action to v4.36.0 c208231f46 vendor: golang.org/x/net v0.55.0 ce6db0fd2c vendor: golang.org/x/crypto v0.52.0 76adc5038e vendor: golang.org/x/sys v0.45.0 09b0b8c3a0 c8d: tolerate NotFound when walking children for disk usage caba5b0e6a Dockerfile: update containerd binary to v2.2.4 2e61f4b067 fix(deps): update module github.com/opencontainers/selinux to v1.15.0 ec2abbc300 fix(deps): update module github.com/containerd/containerd/v2 to v2.2.4 [security] b7f738a9cb project: add issue types for bugs and features, remove status-triage auto-label 8c0420eac0 chore(deps): update docker/bake-action action to v7.2.0 3be04ad413 releases: Clarify last released Docker version fd39b7c206 chore(deps): update docker/github-builder action to v1.9.0 1b9dbf6d02 chore(deps): update docker/compose-bin docker tag to v5.1.4 79d50b27ee releases: Bump Docker version af35f3716e chore(deps): update docker/buildx-bin docker tag to v0.34.1 fb3702d033 daemon: resolve in-container symlinks before os.Root mount ops 8e35bde599 chore(deps): update codecov/codecov-action action to v6.0.1 dd24a3adc1 releases: Bump patch 2022313ffe daemon: Decompress archives before entering container filesystem ea952feee6 fix(deps): update module github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs to v1.74.0 43fa458a9c Fix bind mount target redirection via symlink swap during docker cp 64a22d80b9 daemon/copy: Fix symlink escape in mount destination creation df58acf56e libnet/iptables: don't filter on unspecified IP to delete conntrack 79e9b906b3 chore(deps): update github/codeql-action action to v4.35.5 1cd87fbcb2 gha/validate-check: Target the branch, not ref e922f63b0c gha/workflows: Validate milestone debug ee4b4f46e8 releases: Bump version 854307e013 dockerversion: touch-up escapeStr to mention RFC and add TODO 91ae7ea8c8 dockerversion: un-export UAStringKey, add WithUpstreamUserAgent 1dcbfd6181 dockerversion: DockerUserAgent: touch-up GoDoc bb71630486 chore(deps): update docker/buildx-bin docker tag to v0.34.0 b384e7b123 daemon: fix AppArmor support check for detached-netns 160a0112e1 integration-cli: Deflake TestBuildEmitsEvents 54af635140 daemon: isPermissibleC8dRuntimeName: fx link to c8d runtime conventions db8aba0b93 daemon: TestContainerWarningHostAndPublishPorts: use sub-tests 9418053039 The 28.x is unmaintained 71f6a9695b integration: Make some tests Parallel 60a04c7e9b vendor: update buildkit to v0.30.0 08eec0204c hack: authenticate BuildKit ref resolution 316c72d72b daemon/logger/jsonfilelog: cleanup tests 6d39b4ebed daemon/config: set userland-proxy default value in config.New c4122f3bc2 daemon/config: set default log-driver in config.New 1143f413f6 libnetwork: ref-count service aliases for VIP DNS records a222ebcfdb dockerversion: improve user-agent handling 323293bf44 dockerversion: rewrite TestDockerUserAgent as table-test 7f3b187795 fix(deps): update module github.com/opencontainers/selinux to v1.14.1 a97c3eb91d daemon: init container rootfs at end of create d1da585846 daemon: make getInspectData() reusable 5420d83a53 vendor: update buildkit to v0.30.0-rc2 2d9e93a38e Revert "builder-next: Stop using libnetwork-setkey reexec for BuildKit networking" c2075797fa c8d/resolver: Use per-host HTTP client for auth requests 00eb59541c vendor: update buildkit to 1da7e716224c 9160ad1dd7 integration/build: Add userns-remap test b9fe5eb4ab integration/build: Add error assertion in GetImageIDFromBody ee281d16a1 integration/internal/build: let Do accept ImageBuildOptions d3adafd853 volume: Fix file subpath mount over existing image file 57db5dedd0 hack: Fix test-integration-flaky 64872ca6e2 gha: Fix test-integration-flaky 40e9500da9 vendor: golang.org/x/tools v0.45.0 81bde7da97 vendor: golang.org/x/net v0.54.0 530b434cb7 vendor: golang.org/x/crypto v0.51.0 b1613d564e vendor: golang.org/x/text v0.37.0 87fc1c0454 vendor: golang.org/x/tools v0.44.0, golang.org/x/mod v0.36.0 62e124ee1e vendor: golang.org/x/term v0.43.0 41d5112707 vendor: golang.org/x/sys v0.44.0 982e463743 vendor: go.yaml.in/yaml/v2 v2.4.4 8bc239f340 hack: preserve pseudo-version hashes in buildkit-ref f186f6154e Update crazy-max/.github action to v1.8.0 cfb2ed2acd integration/d/nri: block until plugin is registered 9bf222b218 daemon: log event after reload is committed 704210f9e6 daemon: preserve CDI additional GIDs 14efa29c44 daemon: fix healthcheck empty-cmd panic 730c96a59d Minor cleanup 24872eb985 daemon: add "time-namespaces" feature-flag to disable time-namespaces daf25751d5 image list: match reference filter against canonical names 4d5cba3544 daemon: remove uses of deprecated selinux.ReserveLabel 05c1fd6373 Update module github.com/opencontainers/selinux to v1.14.0 09a42a319b Update module cloud.google.com/go/logging to v1.18.0 d92a8c97de container/logs: add support for JSON streams (experimental) 0cf2b69edc daemon/logger/local: optimize extraAttributes dbe72c6f8f add support for custom attributes with the "local" logger 0fdc152a31 update to go1.26.3 4cf35bf09d Update github/codeql-action action to v4.35.4 17a4b09bb9 Update github.com/moby/policy-helpers digest to a39d601 c2d6c1e4a7 libnet/iptables: DeleteConntrack: use structured logs 2ed9c69d99 libnet/drivers/bridge: clearConntrackEntries: move vars where used f26de9b9c4 libnet/iptables: DeleteConntrack: add early returns 79f5ddc271 gha/ci: Store slim test-results-* artifacts aea02086d9 gha/copilot: Add dependency bump review instructions 6ca030ca39 daemon: separate reserving SELinux label from loading f6319f0cc2 vendor: update buildkit to v0.30.0-rc1 c082826b4d Update module github.com/in-toto/in-toto-golang to v0.11.0 326dc53861 Update docker/github-builder action to v1.8.0 70ac493e97 server/router/build: replace output buffering workaround with EnableFullDuplex c40d3572c9 gha: set timeouts for buildkit tests e1ad921905 Update actions/labeler action to v6.1.0 3ffdbf6bce Update aws-sdk-go-v2 monorepo 4ee90199a4 Update github/codeql-action action to v4.35.3 35797366d7 vendor: github.com/moby/profiles/seccomp v0.2.3 (Drop socketcall block) 34e3b001b7 integration/container: Handle socketcall return EPERM e66731a919 vendor: github.com/moby/profiles/apparmor v0.2.1 (deny network alg) d4fc496755 integration/container: skip socketcall test without AppArmor or SELinux 9e6a3c6ea2 contrib/selinux: Add CIL policy to deny AF_ALG sockets in containers b9e11cf1a6 integration/container: Verify AF_INET socketcall still works dc163512bd daemon/containerd: ignore missing snapshots in shared size calculation 9f19521146 daemon/containerd: include shared content blobs in image SharedSize b9f5899fc1 Update module github.com/pelletier/go-toml/v2 to v2.3.1 c4df56a7aa daemon/libnetwork: waitForLocalDNSServer: rm error-type assert 528a806141 daemon: Always reload AppArmor profile at daemon startup 175eefc064 integration/container: Drop i386 cross-compile socketcall test 125decc558 gha/buildkit/windows: Fix flaky Docker info d5951a317d Dockerfile: update registry to v3.1.1 943f46c425 cmd/docker-proxy: remove redundant error-type asserts f52bb0e33c vendor: github.com/moby/profiles/seccomp v0.2.2 5a345809bc integration/container: Add socketcall AF_ALG denial tests 1cc7757e7e fix(deps): update module cloud.google.com/go/logging to v1.17.0 d8b0c6a0c0 vendor: github.com/moby/profiles/seccomp v0.2.1 ccabd78d73 integration/container: Add test for denied socket address families 4482047ac3 daemon/logger: refine the Logger contract bf486b74f6 gha/windows: Retry busybox image build on transient registry failures d9690cb8e2 fix(deps): update module pgregory.net/rapid to v1.3.0 744014b622 fix(deps): update module github.com/containerd/nri to v0.12.0 70050681f7 builder-next: Stop using libnetwork-setkey reexec for BuildKit networking 16c0107b42 gha/windows: Fix flaky Docker info 28810d88d1 docker-proxy: Retry UDP write on ECONNREFUSED from stale ICMP errors 69b8515bb5 daemon/cluster: Fix race in Stop() accessing fields after unlock 3b5ce461a7 daemon/cluster: Move context creation outside of critical section 748c5200cf daemon/cluster: Rename nodeRunner.stopping to stopped 0acd23fce0 daemon/cluster: Alway set stopping flag on Stop 93dce63433 layer: Close archive reader to prevent deadlock in ChecksumForGraphID 3da0279804 fix(deps): update module github.com/containerd/continuity to v0.5.0 92bb8ad731 layer: Migrate off deprecated NewInputTarStream 9fc0179fa5 vendor: github.com/vbatts/tar-split v0.12.3 217c9de0a0 integration: Try to fix flaky TestNslookupWindows 25e44d9eb0 fix(deps): update module github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs to v1.71.0 d5370d34d3 use private time-namespace for containers on supported kernels c735877246 pkg/sysinfo: add detection for time-namespaces support 25985f61ac fix(deps): update module github.com/aws/smithy-go to v1.25.1 368ab244b6 integration: reduce `skip.If(t, testEnv.IsRootless)` eeec56601b hack/dockerfile/install: fix RootlessKit version 038086f408 ci: validate: remove old "default-seccomp" validation e6b36ed6da ci: validate module-replace: ignore _test.go files 3feaea7d8b fix(deps): update module github.com/moby/profiles/apparmor to v0.2.0 4444bc40db fix(deps): update aws-sdk-go-v2 monorepo 5249b1d165 Update RootlessKit (3.0.0) 3bfa6901be go.mod: github.com/rootless-containers/rootlesskit/v3 v3.0.0 f2607daded fix(deps): update module github.com/moby/profiles/seccomp to v0.2.0 f3e4b626be libnetwork: expose proxy information in FirewallInfo 21eabccd8c fix(deps): update module github.com/moby/swarmkit/v2 to v2.1.2 08e7501fb4 gha/validate-milestone: Handle PR updating versions.yaml a818993815 releases/docker: Bump minor dbaa2f6f79 libnetwork/drivers/overlay: minor cleanups in peerdb a836506d19 Change Conntrack to delete by Both Port And IP 1ccbff10a5 integration/container: Fix flaky TestContainerRestartWithCancelledRequest on Windows 5d143db66b fix formatting strings for go1.26 785732e10e gha/validate-milestone: Read versions.yaml from base branch ed4700b1c6 daemon: explicitly mark some arguments as unused f3b931bfb2 pkg/sysinfo: TestNew: fix copy/paste mistake 2200a66cee chore(deps): update crazy-max/.github action to v1.7.1 a65bd0440b releases: Bump patch 34bd1ebdf4 vendor: github.com/moby/moby/client v0.4.1 b63208b64b vendor: github.com/moby/moby/api v1.54.2 5be108f817 vendor: github.com/sigstore/timestamp-authority/v2 v2.0.6 727b81991c vendor: github.com/sigstore/sigstore v1.10.5 bad8e1b799 vendor: github.com/go-openapi/* deps f3cadf69dc vendor: github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.0 5c6a343842 vendor: google.golang.org/api v0.272.0 463f4c0943 No longer a reviewer; update email address 98c7106fbe vendor: github.com/hashicorp/memberlist v0.5.4, hashicorp/serf v0.10.2 f69fed1350 fix(deps): update module github.com/aws/smithy-go to v1.25.0 eb2672a3b9 chore(deps): update actions/github-script action to v9 75c2f4fb37 fix(deps): update module go.opentelemetry.io/contrib/processors/baggagecopy to v0.16.0 6fa46cf8c7 fix(deps): update golang.org/x packages 0aaa2d3e3a README: Add Go modules section documenting the v29 module split 68d1d1a947 vendor: go.opentelemetry.io/contrib v0.68.0 8384598603 vendor: go.opentelemetry.io/otel v1.43.0 836b06d8da vendor: google.golang.org/genproto 9d38bb4040a9 0aa66fca01 fix(deps): update module google.golang.org/grpc to v1.80.0 7ab051cf89 daemon/logger/local: marshal: remove redundant resetProto 23020513e6 chore(deps): update docker/github-builder action to v1.6.0 6e22bc8095 chore(deps): update docker/bake-action action to v7.1.0 b1637ed54b vendor: github.com/hashicorp/golang-lru v1.0.2 d994daf576 daemon/containerd: fix label!= filter ignoring images without label c255b67c0f Update github/codeql-action action to v4.35.2 9136afe4fe Update actions/upload-artifact action to v7.0.1 dc48cea266 api/docs: cleanup changelog 9c084cad3e ci: skip using xargs c621624e2f libnetwork: Always clean up endpoint driver info in sbLeave 6e9f9bc0a5 ci: fix workflow permission errors 10b0401423 Update actions/cache action to v5.0.5 b7e7d3f065 libnetwork: Remove montanaflynn/stats dependency 70907e2988 libnetwork: Drop golang-set dependency 2437d5d646 ci: use bake matrix subaction 1743957d3f fix zizmor findings c8513239bf daemon/listeners: Support Unix socket on Windows 7136f5e946 Dockerfile: update delve to v1.26.1 0f5a7ae948 Dockerfile: update Docker CLI to v29.4.0 270b511972 Dockerfile: update docker compose to v5.1.3 cdb3fc279d Dockerfile: update buildx to v0.33.0 c6d4830c14 vendor: github.com/docker/go-connections v0.7.0 5c80a6e826 api: align Topology in versioned OpenAPI specs with Segments JSON shape 0c878186d3 ci: zizmor workflow 97cb71d7ed pkg/registry: use stdlib's x509.SystemCertPool on Windows ba1f3e8aa8 Dockerfile: update containerd binary to v2.2.3, runhcs v0.14.1 a2cdd57812 vendor: github.com/containerd/containerd/v2 v2.2.3 c4f4eb3f5f api: align Topology swagger with Segments JSON shape f8873b7796 daemon/logger: use consts for common log-options 30b7b3f919 daemon/logger: define consts for common log-options 9008249e8a daemon/logger/local: add a constructor for config 33261e9a45 daemon/logger/local: unify constructors 5d5797002d daemon/logger/local: test cleanups 69caf3d4c7 daemon/logger/local: improve TestDecode, rename to TestDecodeIncompleteRecord f3f3040713 daemon/logger/local: use struct-literal for pmetadata a331d4d7a3 gha: Add milestone validation workflow 10eb86543f Cleanup releases dir 3b22c500d5 daemon: retry secrets dir remount on transient EBUSY 0ea9255e50 daemon/logger/splunk: tryPostMessages use http.NewRequestWithContext 0677030570 daemon/logger: use uniform location for registering drivers 8e79aacee6 daemon/logger/journald: remove outdated comment e0b5ab2f98 daemon/logger/loggerutils: ParseLogTag: add fast path 3ba0b72b78 daemon/logger/loggerutils: ParseLogTag: fix panic and image ID 4f2553e81a daemon/logger/loggerutils: ParseLogTag: improve test-coverage 7bfa790f2b daemon/logger/jsonfilelog: be more explicit on handling optional "tag" ec909a2239 daemon/logger/jsonfilelog: JSONFileLogger: remove unused "tag" field 6a5e00fe5f daemon/logger: Info: touch-up godoc 1a45789c04 client: imageDiskUsageFromLegacyAPI: explicitly exclude "-1" for containers 25ffdb23d9 daemon: Daemon.imageDiskUsage: explicitly exclude "-1" for containers e0fc07b8cf gha/labeler: Only assign Windows to Windows-only changes b3bd13ad10 daemon/pkg/registry: minor cleanups 84aedb8055 rootless: support detach-netns mode 377e85700f vendor: github.com/Microsoft/hcsshim v0.14.1 e30a6fa93b libnetwork: respect gw priority per address family 3541b0d0fd update to Go 1.26.2 2601915b10 client/internal: touch-up godoc 689accfe29 client/internal: fix RSFilterReader returning (0, nil) after filtering 159b3317f0 client/internal: RSFilterReader: un-export, and remove unused buffer ba66582228 client/internal: Stream.JSONMessages: improve error handling 5f08008342 client/internal: Stream.JSONMessages: move reader inside the func d5d18015e1 client/internal: Stream.Wait: return errdefs errors 82ff7e9f76 client/internal: Stream.Wait: fix missing error-handling 4d1d9ee358 go.mod: add back replace rules 00840cd39c ci: buildkit: pin registry to v3.0.0 a2eaebb011 api/docs: lower deprecation heading to a h4 f44956451a CI: add back ubuntu-24.04 + rootless ca69153e28 api/docs: restore changelog for API v1.0 - v1.13 1055b7a1a6 api/docs: restore API versions v1.0 - v1.13 0d2d3f348d api/docs: restore API versions v1.14 - v1.17 dc824e3d8d api/docs: restore API versions v1.18 - v1.23 70043cd439 ci: fix bin-image workflow f42ff6a603 internal/testutil/daemon.New: cleanup test paths 7094e8c3ef integration/daemon: TestLiveRestore remove quote from test-name 3a7e8e285e vendor: github.com/moby/moby/client v0.4.0 f8946fc137 vendor: github.com/moby/moby/api v1.54.1 f1b420bf02 Drop replace rules c286d4ce13 Dockerfile: go install: use Git SourceOp d3a677d730 Dockerfile: use Git SourceOp 07a5e924ce Fix typos and misspellings in comments, tests, and docs 6604bd0ddc update AUTHORS and .mailmap 84743bdda3 client/internal/mod: swap order of "ok" bool 9dec3bf78f daemon: include moby module version in version response de68dce70d daemon/internal/mod: also check main module 1bed74db50 daemon/internal/mod: reimplement without golang.org/x/mod dependency 74e74ed5ee builder-next/worker: move mod package to daemon/internal 80c22f0982 daemon: respect explicit AppArmor profile on privileged containers b8057a3a58 api/types/network: fix handling of unmapped ports (ephemeral ports) 2d35a29f63 vendor: github.com/microsoft/hcsshim v0.14.0 4975231ecc daemon/volume/local: New: ignore non-volume directories 538f407103 daemon/volume/local: store path to opts.json 5eeb08ae1c fix: use t.Cleanup to prevent goroutine leak in TestCancelledUpload 735d17e1a5 fix: return 400 instead of 500 for invalid request parameters 9aa5ac3034 client/pkg/jsonmessage: use functional options for display funcs 06b31dcd12 daemon/pkg/opts: fix ValidateIPAddress docstring ad67096edf gha: validate-api-swagger: remove redundant 'make image' 8769bda667 gha: buildkit: fix go version e0999bd5ec update to go1.26.1 6ddd4ff73d integration/plugin: remove redundant assert 9295e2cd84 client: fix race in cancelReadCloser 6bfde409bd client: fix typo: TestWithHTTTPHeaders -> TestWithHTTPHeaders 72142ab278 daemon: buildSandboxOptions: warn, not panic on invalid extra host 98840db4d3 daemon: Daemon.restore: trim whitespace in extra-hosts dd11127524 daemon/pkg/opts: ValidateIPAddress: use netip.Parse 333f39ce02 remove uses of jsonmessage.DisplayJSONMessagesStream in tests 6aedc6ba32 client/pkg/jsonmessage: add DisplayStream and DisplayMessages utils 5672c51b00 vendor: update buildkit to v0.29.0 abb2a31c8a daemon: Daemon.SystemVersion: align fields with api type 65ce470c2a fix(deps): update module github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs to v1.66.0 281f4b6767 chore(deps): update actions/setup-go action to v6.4.0 38c77a9189 daemon/libnetwork/ns: make NetlinkSocketsTimeout a const 5378f5427f daemon/libnetwork/ns: remove ParseHandlerInt, add NsHandle af73684bc3 daemon/libnetwork/ns: use sync.OnceValues 635f4c3dc4 daemon/libnetwork/ns: remove windows stub 579280d444 daemon/libnetwork/ns: suppress some unhandled errors dee7411f05 fix(libnetwork): nil pointer will cause panic 434ec1655c daemon/volume/service: deprecate OpErr.Cause (Causer interface) 57d0f88684 golangci-lint: enable godoclint linter dee3c452d7 daemon/volume/local: remove duplicate package doc 28aeae20dc client: WithHTTPHeaders: produce error if duplicate headers are detected 1ec892c555 client: WithHTTPHeaders: improve doc and add test coverage d7d856927b daemon: fix typo in filedescriptors filenames d71f3ea5da ci: fix upload sarif action 1769b3eb5d chore(deps): update github/codeql-action action to v4.35.1 beba95c819 vendor: update buildkit to v0.29.0-rc1 5da773a71d chore(deps): update codecov/codecov-action action to v6 1293d50b38 fix(deps): update module github.com/pelletier/go-toml/v2 to v2.3.0 12ae6dd67e fix(deps): update module github.com/montanaflynn/stats to v0.9.0 3fa5ec578b chore(deps): update github/codeql-action action to v4.34.1 0c7f2b3d38 chore(deps): update codecov/codecov-action action to v5.5.4 c66815426c chore(deps): update docker/github-builder action to v1.4.0 615cf6345f chore(deps): update actions/setup-go action to v6.3.0 fb146a3806 fix(deps): update aws-sdk-go-v2 monorepo c36e70524b chore(deps): update actions/labeler action to v6.0.1 0d0751397d Dockerfile: update runc binary to v1.3.5 96343dd0b5 chore(deps): update actions/download-artifact action to v8.0.1 49a4a47df5 chore(deps): update actions/checkout action to v6.0.2 45ec277dd5 vendor: go.opentelemetry.io/otel/exporters v1.42.0 bb79587d84 fix(deps): update opentelemetry-go-contrib monorepo ce7b3aaa0e chore(deps): update actions/cache action to v5.0.4 f7e4fff10b docs: fix remaining broken links in contributing docs 9e26694618 vendor: github.com/moby/policy-helpers b7c0b994300b 044d59bbd1 Dockerfile: use set -x in here-docs for visibility in build-logs 695e8b3074 vendor: golang.org/x/tools v0.43.0 e18b58d6a4 vendor: golang.org/x/oauth2 v0.36.0 cb3065011c vendor: golang.org/x/mod v0.34.0 c02c294e81 vendor: golang.org/x/net v0.52.0 7b9fe27a4d vendor: golang.org/x/time v0.15.0 07304a4ffc vendor: golang.org/x/text v0.35.0 37ece0f46e vendor: golang.org/x/sync v0.20.0 c0e612d623 vendor: golang.org/x/sys v0.42.0 21d4e2525a fix(deps): update opentelemetry-go monorepo to v1.42.0 dcbc18d954 fix(deps): update module github.com/aws/smithy-go to v1.24.2 b24c8272e5 go fix "omitempty" f7aea04bb3 go fix (GOOS=linux and windows) 5cf47c0d15 pkg/plugins/pluginrpc-gen: go fix, and tidy up 91cd097119 docs: fix broken docker docs links in CONTRIBUTING.md 830ddb26a2 vendor: update buildkit to v0.28.1 b588d1a594 ci: pin all actions 99a095ecf0 plugin: Fix off-by-one in privilege validation 6f80a57b4f chore(deps): update docker/setup-qemu-action action to v4 849efd0d3e chore(deps): update docker/setup-buildx-action action to v4 ec76e94183 pkg/authz: Increase body limit to 4 MiB 7a767b27fd pkg/authz: Reject requests exceeding body size limit b66b2f77e0 ci: renovate: pin actions to digests 968fb5787c daemon: restore: register containers without rwlayer 1bd71d5d87 vendor: github.com/moby/patternmatcher v0.6.1 391789a6e1 vendor: github.com/klauspost/compress v1.18.5 435fd64319 client: fix TestNewClientWithOpsFromEnv 673e2e2467 client: WithTraceProvider don't wrap WithTraceOptions 760f375400 client: WithTLSClientConfig, WithTLSClientConfigFromEnv: touch-up docs d85e410aa6 daemon/containerd: register Sigstore media type prefixes to suppress unknown-type warnings 619ecc9b53 transport: enable HTTP keep-alive for registry connections 26d0774539 integration: ignore container Status field in DiskUsage test comparisons d74953b829 fix(deps): update module cloud.google.com/go/logging to v1.13.2 5220d603f9 chore(deps): update docker/compose-bin docker tag to v5.1.1 04c1d25809 daemon/internal/containerfs: Retry on ENOTEMPTY error during directory deletion 46dba49ec8 Fix reclaimable image disk usage calculation for in-use images a17a5647f8 fix(deps): update module google.golang.org/grpc to v1.79.3 [security] 3cb98cb1b3 ci: update docker/bake-action v7 7d06c6c502 add example for go fix 20f84d21ee client: add //go:fix inline directives to deprecated functions d0a29867e7 api/types/strslice: add //go:fix inline directives for deprecated type 8582136c90 golanci-lint: gocheckcompilerdirectives: ignore "//go:fix" 28b29bd8b0 builder-next: replace duplicated oneOffProgress with progress.OneOff da4a6385e6 client: New: ignore nil-Opt instead of panicking b5bc84bec3 Fix issue moby#48093: set SystemTemp environment variable On Windows also set the SystemTemp environment variable, because for system processes GetTempPath2() uses it rather than TEMP/TMP: https://learn.microsoft.com/en-us/windows/win32/api/fileapi/nf-fileapi-gettemppath2w f04f350568 dockerd-rootless.sh: check containerd-rootless.sh conflict 405a787917 daemon/server: don't log context cancelation as error f401a9678b daemon/server/backend: ContainerLogsOptions: use time.Time for since, until 210cdcbd46 daemon/server/router: fix "no stream selected" error and status 568312cb85 daemon/internal/timestamp: replace ParseTimestamps with ParseUnixTimestamp cfeceed9c0 daemon/internal/timestamp: improve unix timestamp parsing 553420b8f3 daemon/internal/timestamp: replace GetTimestamp for Parse fc3cb00398 daemon/internal/timestamp: don't return value on err f37fc9fb63 daemon/internal/timestamp: use table-tests 282297aa0c daemon/internal: GetTimestamp: don't discard nanosecs, and trim zero 8f8b23c729 daemon: fix some untyped "invalid parameter" errors 2d0676b8bb daemon: prevent invalid swarm events from unknown action kinds 3debf539c0 fix: typos in comments Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com> docker-moby/cli: update to v29.5.2-tip Bumping docker-cli to version v29.5.2-13-gd476e1d9bf, which comprises the following commits: 07bb5e458c build(deps): bump docker/bake-action from 7.1.0 to 7.2.0 45fc3b034a scripts/build: set grpcnotrace build-tag to reduce binary size 20f5e7c08c vendor: golang.org/x/net v0.55.0 20debc9c01 vendor: golang.org/x/sys v0.45.0 cf5f060b4d build(deps): bump github/codeql-action from 4.35.4 to 4.35.5 d6eded1632 bump VERSION to v29.5.3-dev 9177c7fc6b gha: Port validate milestones from Moby 382a92daa8 Dockerfile: update buildx to v0.34.1 a68dd7a4fb bump VERSION to v29.5.2-dev 066d508bd3 docs: further clarify authz plugins 9f18a0a70c docs: clarify authz content type ae9f429677 Update dockerd.md c41489ac39 bump VERSION to v29.5.1-dev 50712c9326 README: simplify instructions for using dev container f99747b9e0 docs: fix stale links in CONTRIBUTING.md ddac061db7 PR template: remove outdated contributing guide link 10b1e87d09 docs: remove outdated README e3802b8a0e experimental: sync with actual features gated by experimental 18bd1e7ce0 metrics-addr is not experimental since 20.10 8aa8342502 docs: remove stub for builder a6dc278db3 build(deps): bump github/codeql-action from 4.35.3 to 4.35.4 cc962d598a docs: Fix template error in cli example e4d651d792 docs: fix config, secret examples fb09d828e3 document `--rm` also removing anonymous volumes 88e93954a6 docs, completion: use symlinks instead of symbol(ic) links f550901e65 docs: minor grammar fixes a6d65ea31d Fix nits 80ad53b064 add commands of how to run the test fe78dc0be6 Reflect the new github URL for completion/zsh/_docker f12fc152a7 cli/config/configfile: use more idiomatic receiver name 8d8d405dc7 container/ps: add HealthStatus formatter field 517ca50506 docs: add more space in ps format table 7cbcd2f720 cli/command/image: rm redundant TestPrintImageTreeNoWarningWhenRedirected 970afd5cc4 vendor: golang.org/x/net v0.54.0 7e07bf127c vendor: golang.org/x/mod v0.36.0 5aeb52681b vendor: golang.org/x/text v0.37.0 644d046721 vendor: golang.org/x/term v0.43.0 a853f40a30 vendor: golang.org/x/sys v0.44.0 87f06ec70a refactor parsing restart-policies 033f8a1fd2 cli/compose/convert: use test-table for restart-policy tests 27bee792a0 decorate --env-file, --label-file errors 6d38b7a71a docs: clarify 64 KiB response-body buffer in authz plugin docs 1e1384fae2 vendor: github.com/docker/docker-credential-helpers v0.9.7 976d97dd23 build(deps): bump github/codeql-action from 4.35.2 to 4.35.3 77435c59ec update to go1.26.3 e93fe9083b cli/config/credentials: DetectDefaultStore: update GoDoc b7ab63387a cli-plugins/hooks: limit maximum number of lines / messages e03b8373c7 docs: clarify docker context use is sticky 6f144c6d70 cli/command/image/build: remove deprecated ResolveAndValidateContextPath util b124c707f0 cli/command/image/build: remove deprecated WriteTempDockerfile util 3dd0c846cd cli/command/image/build: remove deprecated DetectArchiveReader util 403bebeea2 cli/command/image/build: remove deprecated DefaultDockerfileName const 8e7ec44f9f cli/command/image/build: remove deprecated IsArchive utility 55fcffe743 cli/config/configfile: normalize hostname when resolving auth e8a0beb909 cli/compose/schema: TestValidatePorts: use subtests 9013c33372 bump VERSION to v29.5.0 7059ef4c9c formatter: Sort labels for stable output 9bbe02848d vendor: github.com/moby/swarmkit/v2 v2.1.2 b03176ddff build(deps): bump github/codeql-action from 4.35.1 to 4.35.2 9d8c1e4b70 bump VERSION to v29.4.2 d0f5b279e9 cmd/docker-trust: bump moby/client v0.4.1, moby/api v1.54.2 b7f37e86da vendor: github.com/moby/moby/client v0.4.1, moby/api v1.54.2 266f039bb5 Dockerfile: update compose to v5.1.3 d74d3c3b16 Dockerfile: update buildx to v0.33.0 58a7c3155b golangci-lint: fix lint failures from v2.10.1 upgrade f37a9e663f Dockerfile: update golangci-lint to v2.10.1 ee56098b07 cmd/docker-trust: bump dependencies efbbc0c68c gha: Add milestone validation workflow beac1144a6 vendor: github.com/containerd/platforms v1.0.0-rc.4 a75ab98e43 vendor: github.com/mattn/go-runewidth v0.0.23 b9549d3ab5 vendor: golang.org/x/net v0.53.0 2edf815a80 vendor: golang.org/x/term v0.42.0 258010c788 vendor: golang.org/x/text v0.36.0 cfa80d8644 vendor: golang.org/x/mod v0.35.0 c20b2479e0 vendor: golang.org/x/sys v0.43.0 573dd31bf7 vendor: github.com/docker/docker-credential-helpers v0.9.6 2988338b99 docs/reference: remove deprecated "--kernel-memory" flag 58c7328df6 man: remove deprecated "--kernel-memory" flag 5468871a02 contrib/completion: remove deprecated "--kernel-memory" flags acbbeb3c3a docs: refresh legacy plugin references 3362ae31d0 vendor: go.opentelemetry.io/contrib v0.68.0 a1edb22832 vendor: go.opentelemetry.io/otel v1.43.0 0a24da3382 vendor: google.golang.org/grpc v1.80.0 f24c779887 vendor: google.golang.org/genproto/* 9d38bb4040a9 99aaff1807 build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 f3c060c382 build(deps): bump docker/bake-action from 7.0.0 to 7.1.0 b9a052a987 vendor: github.com/docker/go-connections v0.7.0 0d32fde8e3 internal/registry: use stdlib's x509.SystemCertPool on Windows ad641e5d61 cmd/docker-trust: use stdlib's x509.SystemCertPool on Windows 14aa781767 build(deps): bump docker/login-action from 4.0.0 to 4.1.0 d1920f0b2c update to Go 1.26.2 b23c1a2d76 build(deps): bump github/codeql-action from 4.34.1 to 4.35.1 c88681f8d8 vendor: moby/api v1.54.1, moby/client v0.4.0 5ddc1553ae bump version to v29.4.0-dev a347d9e103 update AUTHORS and .mailmap 5fca671ef4 vendor: github.com/mattn/go-runewidth v0.0.22 42da40a605 vendor: moby/client and moby/api master 0029d5936a build(deps): bump codecov/codecov-action from 5.5.3 to 6.0.0 e7cbaafa9d cli/command/container: statsFormatWrite: inline render func c44a4d9758 cli/command/container: RunStats: avoid bytes to strings conversions d92d1187fc cli/command/container: RunStats: rename buffer var for brevity ee88c60a5e cli/command/container: stats: add snapshot method 4c5efd61ea cli/command/container: fix buffer reuse when printing stats b309524f60 cli/command/formatter: NewStats: update GoDoc and add TODO abd2e211b9 cli/command/formatter: add Format.templateString, remove Context.preFormat cb615a9772 cli/command/formatter: Context.postFormat: remove redundant buffer f7a909d56b cli/command/formatter: optimize ContainerContext.Names 94d4929a04 cli/streams: Out, In: preserve original os.File when available 526dfffc26 cli/streams: simplify CheckTty 48721c2340 cli/streams: don't depend on embedding 39e82e6524 cli/streams: move constructors to the start 34805dd013 cli/streams: (In|Out).SetRawTerminal: dry 6e1f03c2e0 cmd/docker-trust: bump dependencies 87a222158d Updated example tokens in swarm docs 98d978df6b vendor: go.opentelemetry.io/otel v1.42.0, otel/contrib v1.67.0 a48ff6b591 cli/command/completion: don't provide duplicate completions 091afa4957 vendor: github.com/go-jose/go-jose/v4 v4.1.4 968ad0ea6c vendor: golang.org/x/net v0.52.0 78fb018754 vendor: golang.org/x/time v0.15.0 18739a5ef6 vendor: golang.org/x/term v0.41.0 9b21846cde vendor: golang.org/x/text v0.35.0 c22bf3c77e vendor: golang.org/x/mod v0.34.0 d792fc53b7 vendor: golang.org/x/sync v0.20.0 e9664a72ea vendor: golang.org/x/sys v0.42.0 fb776458cb update to go1.26.1 62d80156e1 ci: pin remaining actions ea74248e8e cli/command/formatter: modernize 5efed5fa30 vendor: github.com/klauspost/compress v1.18.5 cd9e5ae84f vendor: github.com/moby/patternmatcher v0.6.1 bf6a1e1fcf cli-plugins/socket: modernize 8f7dc04070 update minimum go version to go1.25 a14db81c9c vendor: google.golang.org/grpc v1.79.3 e660030f3a docs: fix typo in run reference 58c1585b49 gha: validate gocompat ea42337d01 implement module compatibility check d573c171fe docs: clarify multiple --filter behavior in prune commands 07bb479a45 cli-plugins/hooks: add missing "go:build" comments 97b9e04a94 ci: pin actions to digests 2bc4307816 fix(cmd/docker): prevent race between force-exit goroutine and plugin wait 9c117d3c5d cli/command/container: add shell completion for docker rm --link df57ff7201 cli/command/completion: ContainerNames: skip legacy link names dfda342e51 cli/command/formatter: StripNamePrefix only strip "/" prefix b5efd66ba6 cli/command/container: stats: make stripping "/" prefix deterministic 64c8d68045 cli/command/image: getPossibleChips: simplify 4bf4d567bd cli-plugins/hooks: PrintNextSteps: slight cleanup dd1f7f5856 cli-plugins/hooks: simplify templating formats 9243240346 cli-plugins/hooks: add commandInfo type for templating 4a1b2ef2c5 cli-plugins/hooks: update godoc 4142d4026e cli-plugins/hooks: detect if templating is needed cd053606a6 cli-plugins/hooks: slight tweaks in templates aadfe6214f cli-plugins/hooks: update tests dce201d6ee cli-plugins/hooks: move template utils separate from render code e26f94d823 cli-plugins/hooks: add JSON labels, omitzero 0431e4d23c cli-plugins/hooks: rename HookType to ResponseType 607ebfca5d cli-plugins/hooks: rename HookMessage to Response 60180924e3 cli-plugins/manager: move HookPluginData to hooks.Request dd91ed3f2d cli-plugins/manager: refactor for easier debugging 0501cf8293 cli-plugins/manager: simplify ctx-cancel check 5343bdc792 cli-plugins/manager: Plugin.RunHook: improve error message 5fb5e0b0da docker stats --all: remove containers when removed 560db7d451 vendor: github.com/mattn/go-runewidth v0.0.21 dc4abf8b99 golangci-lint: gocheckcompilerdirectives: ignore "//go:fix" 7f781688ed golangci-lint: remove outdated exclusion 21293265b1 cli/command/image/build: use t.Chdir() in tests 3f51d0a9d2 cli/command/container: RunStats: refactor to DRY 9645db767a cli/command/container: RunStats: pass ctx to stats event handlers 2bc66ecbc7 docker cp: report both content size and transferred size 33790e88d0 docs: use generic myplugin example for plugin documentation 6b1ba1ad84 fix: restore os.Args after plugin completion and fix error return 300d8231da feat: add linux/riscv64 to bin-image-cross release target 9a471180cb cli/command: add missing "go:build" comments f7d83cbae8 update to go1.25.8 39d676c72d build(deps): bump docker/metadata-action from 5 to 6 6453c4c3a7 build(deps): bump docker/bake-action from 6 to 7 eef3c957be cli/config/credentials: ConvertToHostname: update godoc 71db1520de scripts/warn-outside-container: fix font representation 206fc8c165 vendor: github.com/moby/moby/client v0.3.0 874a8df0eb vendor: github.com/moby/moby/api v1.54.0 668b3671bd build(deps): bump docker/setup-buildx-action from 3 to 4 30a2ace7f2 build(deps): bump docker/login-action from 3 to 4 32aa575aff docs/service: Document bind-create-src c747cff9ab container/opts: Add bind-create-src mount option ba349f5afd build(deps): bump docker/setup-qemu-action from 3 to 4 e2cafd657e cli/command/registry: preserve all whitespace in secrets 10ebb3b204 build(deps): bump go.opentelemetry.io/otel/sdk 681f15674c Fix typos in code and documentation 0bf060f777 vendor: github.com/moby/moby/client v0.2.3-rc.1 139b58d7f4 vendor: github.com/moby/moby/api v1.54.0-rc.1 8eedbdc6a8 vendor: moby/api v1.54.0-dev, moby/client v0.2.3-dev cd070a5ed5 vendor: github.com/mattn/go-runewidth v0.0.20 8c3d05398e Dockerfile: update mvdan.cc/gofump to v0.9.2 b206927e0c Dockerfile: update buildx to v0.31.1 6b5acd3a6e Dockerfile: update compose to v5.1.0 caa8a50468 vendor: github.com/klauspost/compress v1.18.4 5c498778ec vendor: go.opentelemetry.io/contrib v0.65.0 fbd0e7f7c4 vendor: go.opentelemetry.io/otel v1.40.0 95a5a9e709 build(deps): bump actions/upload-artifact from 6 to 7 a7b95f228f chore: use canonical url for buildx build cli doc 13c993f101 cli/compose/loader: merge: use errors.Join 8b6f23d18b cli/compose/loader: remove some wrapper utilities b35a2d0837 cli/compose/loader: remove getLoggingDriver 42a211162c cli/compose/loader: mergeServices: inline mapByName 6e1393089b cli/compose/loader: mergeServices: remove intermediate map for overrides 78458e11e1 cli/compose/loader: mergeServices: tidy up and modernize 09cf89e82e cli/compose/convert: convertEndpointSpec: fix sorting of ports db28780976 cli/compose/convert: convertUlimits: modernize 830d05d16e error-hooks approach 9bc18993a4 Fix: run plugin hooks on command failure, not just success fdebf0afae cli/command/container: fix some unhandled errors in test e47a5c7734 remove redundant uses of streamformatter in tests 2fa6b736d0 scripts/build/.variables: don't use "netgo" when building Windows binaries 61f03db682 cli/command/registry: refactor reading from stdin 74d4554ccd github/issues: Add emojis 2ebd137abc github/issues: Add links for Docker Desktop and Sandboxes f5b6055bd1 cli/command/registry: add unit test for --password-stdin b82e30e58d cli/command/registry: remove uses of "gotest.tools/v3/fs" c4fd2406e0 e2e: use docker v29.x dind as default fddfe63ef9 modernize: fmtappendf 6d4b3b5f66 modernize: slicescontains 835d510b78 modernize: stringsseq dd73e2df77 modernize: reflecttypefor 7f5bb1e99c modernize: testingcontext 2875e48024 modernize: stringscut 4c7d40cf77 modernize: mapsloop 85ebca52fd modernize: minmax e8dc2fce32 modernize: rangeint e4f6019e62 vendor: golang.org/x/net v0.50.0 464e14c68e vendor: golang.org/x/term v0.40.0 1e31c2825e vendor: golang.org/x/text v0.34.0 355f7bb602 vendor: golang.org/x/sys v0.41.0 a934c75de7 Dockerfile: update golangci-lint to v2.9.0 ab06aebd4b internal/volumespec: fix prealloc linting 9a0c78fdc0 cli-plugins/manager: fix prealloc linting 2e544d6308 cli/command: fix prealloc linting 12a0b0b7b9 cli/compose: fix prealloc linting 99cef6f700 opts: fix prealloc linting 8a8a3e1309 opts/swarmopts: fix prealloc linting 9d2816c8a5 remove outdated "nolint" comments eaba9ecf18 cli/connhelper/ssh: remove outdated "nolint" comment 1f6b319d60 Dockerfile: update alpine to 3.23 b598f8f0b8 docs: fix docker volume prune example 5eb91665d1 docs: fix typos 02dee5c2d2 Fix: Remove inconsistent human readability warning from docker images Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* crun: update to 1.28-tipBruce Ashfield2026-05-281-6/+6
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Crosses both the 1.27 and 1.28 release tags. Adds json-c (>= 0.14) to DEPENDS — upstream crun's configure.ac now does an unconditional PKG_CHECK_MODULES([JSON_C], [json-c >= 0.14]) and won't configure without it. The dep is satisfied by oe-core's json-c_0.18.bb. Bumping crun to version 1.28-1-g7e45b26b, which comprises the following commits: 54f16ffb NEWS: tag 1.28 c6f338ac Do not follow rootfs /dev symlinks (CVE-2026-47766) 535e114b krun: request enabling DHCP client e521de6a krun: check krun_add_net_unixstream dlsym bd939e69 tests: add libzstd-devel to fuzzing Dockerfile 1edb6cc7 tests, system-blake3: drop libyajl-dev 21c96879 krun: document microVM configuration options in man page a6151b6a krun: add support for nested virtualization 9f67d80b Build: Use system libblake if available b62cfdda Replace YAJL with json-c for JSON parsing and generation b1cf0328 status: restrict valid container ID names 7771192e cgroup: reject ".." in delegate-cgroup annotation a773c6bb tests: set executable bit for python test files 5fc99f02 tests: drop centos8-build CI job a8deee3b chroot_realpath: fix potential buffer overflows in destination buffer db1be9b2 .clang-format: fixup for v22.1.4 d914b7d8 exec: use default env with --env d85bf0e8 crun exec: more verbose exec error message 8fab8854 build(deps): bump uraimo/run-on-arch-action from 3.0.1 to 3.1.0 ac46d9a0 krun: allow configuring the virtiofs device 3212b444 fix: correct UID/GID mapping buffer offset for multi-line mappings d328b172 krun: fix parsing optional fields from krun_vm.json 738f7ad7 krun: reopen config file d0277ef8 libcrun: use O_PATH where applicable 3ec076b3 NEWS: tag 1.27.1 60b2e8f8 tests, podman: pin to 5.8 3010d29d tests: fix failure in user namespace d6ffa244 krun: remove unused variable 1c5c2f7d linux: pass correct propagation to get_bind_mount d97461f0 tests: add regression test for idmapped mount leak 59cfa8b8 Revert "linux: skip redundant MS_PRIVATE propagation mounts" f1b70c0b tests: add subcgroup cleanup test 6177dd86 cgroup: fix recursive cgroup cleanup consuming caller's fd 6c58b0c6 fix -Wdiscarded-qualifiers warnings acb904c6 krun: Build passt argv based on nitro variant 8199cbb2 krun: implement support for passt networking 7c2500df krun: ignore RAM configurations below 128MB 23f7d9f0 krun: consolidate configuration in configure_vm 04c19ac6 krun: process the vm configuration earlier 81c21e0d handlers: add new hook to close fds d8813f3d .codespellrc: ignore passt 94d7f641 utils: fix apparmor profile not applied in user namespaces 805e6a44 libcrun: skip cgroup filesystem type check when cgroups are disabled 4c530d43 libcrun: fall back to bind mount for /dev/console on read-only file systems a718a92c NEWS: tag 1.27 6220914d nix: generate git-version.h in buildPhase 9553f8b8 exec: strengthen -u value validation 1bd7f424 exec: fix CVE-2026-30892 5699da29 nix: fix zlib cross-compilation for s390x 237f8100 nix: remove global overlay to eliminate rebuild cascade b37594dc release: use path: flake ref to avoid libgit2 safe.directory aaa6056c release: seed /nix from container image when empty c4e3fd22 linux: set MS_PRIVATE on detached mounts from get_bind_mount() 360621a3 Revert "container: skip sigaction reset in unblock_signals for the run path" 5d1b0284 nix: migrate to flakes 246a3367 nix: generate git-version.h in buildPhase 3e9986bc nix: bump nixos/nix image from 2.24.9 to 2.34.2 094c97f3 nix: update 195f664f seccomp_notify: tighten crun_make_error input 1d76be72 seccomp: tighten crun_make_error input 62d3e852 container: tighten crun_make_error input 254a8a75 linux: use open_tree+mount_setattr for device mounts 2d6f4c0e linux: use open_tree+move_mount for masked paths 45e62ce5 linux: use open_tree+mount_setattr for readonly paths f53aa376 linux: use mount_setattr for readonly remounts in finalize_mounts 2dae2238 linux: skip redundant MS_PRIVATE propagation mounts 38e17199 container: skip sigaction reset in unblock_signals for the run path 4b66d8f0 cgroup: skip enable_controllers when joined via CLONE_INTO_CGROUP a59b186b linux: validate run.oci.mount_context_type annotation value 16bd4e48 utils: do not use errno after success 63ce25da container: delete the container on poststart hooks failures crun/ocispec: update to latest fb6b69f src: replace YAJL with json-c for JSON parsing and generation eb7489b fuzzing: add multi-mode round-trip fuzzer and CI job e6cba25 tests: add test-15 for int64 and uint64 value parsing f6f93b0 validate: fix LibFuzzer build by removing HF_ITER and guarding main() f310714 tests: fix memory leak of error string in test-2 1315777 ci: update GitHub Actions to non-deprecated versions 7e13990 ci: pin to ubuntu 24.04 015bb87 sources: extract compound field generate pattern into emit_compound_gen() 37bba6c sources: extract pointer clone pattern into emit_pointer_clone() be6fbb4 sources: use free_and_null() in pointer type emit_free methods 92f2b1d sources: extract common array generate preamble into helper 790d3a6 sources: extract common array parse preamble into helper 689ac4b sources: centralize JSON library references into json_api.py 5a0e037 source: fix ByteArrayHandler nested array parsing 03bae1d source: add missing emit_clone() to BasicMapArrayHandler dbb5155 source: fix invalid else() syntax in byte array generation 692b0b6 source: fix typo in ByteArrayHandler nested array parsing 2acd6dc source: fix mapStringObject clone to copy len and keys crun/rspec: update to v1.3.0-tip 63c1dd6 Blank line before table Fixes #1134 c668b01 config-linux: allow empty strings in memory policy nodes field 0ef13af Add step to update website after a release crun/imagespec: update to v1.1.1-tip 751ed12 Fix one-sentence-per-line violations b9060a3 Clarify that whiteout filenames require a non-empty basename fccd049 Fix: Make the config field optional Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* criu: update to v4.2-tipBruce Ashfield2026-05-282-11/+12
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Switches the recipe from 'master' (frozen at v4.2 tag) to 'criu-dev' (active development), picking up 211 commits past v4.2 — including AMDGPU plugin work, kernel 7.0 rseq compat, protobuf 7.x compat, and a host of restore/zdtm fixes. Two recipe-side adjustments are needed for the new tree to build under OE: - Set HOSTCC=${BUILD_CC} so the compel host-tool build can find a host compiler. Upstream commit 36c63ecb5 ("make: default CC to cc instead of gcc") changed scripts/nmk/scripts/tools.mk to default HOSTCC to 'cc', which the native sysroot doesn't provide (only the prefixed x86_64-poky-linux-gcc). - Refresh 0001-plugins-cuda-pass-DEBUG_PREFIX_MAP.patch for new context: upstream added $(DEFINES) to the cuda_plugin.so build line, so the refreshed patch now inserts our $(DEBUG_PREFIX_MAP) before $(DEFINES) rather than at the (no-longer-present) original position. Bumping criu to version v4.2-211-g4d76d1acd, which comprises the following commits: 4d76d1acd ci: shard alpine-test into parallel jobs to reduce CI time da5b7bf82 zdtm: unregister rseq before zeroing the rseq area 3db4b0922 plugins/amdgpu: Fix unbalanced quotes in a warning message 3805d59cc plugins/amdgpu: Demote one more error to warning 71be2f42e plugins/amdgpu: Fix strtoul error handling eca973251 plugins/amdgpu: Fixup printf format in env handling f73bf1b05 plugins/amdgpu: Reduce scope of some globals 1961c5e0d plugins/amdgpu: Cleanup env variable handling e40e6f766 restore: add missing continue in restorer_get_vma_hint b0b89a94f zdtm: check reservation mmaps are restored correctly 7daaa11aa mem: don't PROT_WRITE on reservation mmaps 2c9ee0abd restore: update prev_vma_end after processing the last vma in a list 5039458f6 pie/restorer: normalize tv_nsec when re-anchoring absolute timerfd expiry 9a1453b38 compel: keep ELF metadata for ld.lld 36c63ecb5 make: default CC to cc instead of gcc 4bc9adf11 contrib: add tests for criu-service-client 57a92dbb3 contrib: add reference client for criu-service 14cb3c201 net: Route veth restore through usernsd for userns mode c1cea9004 pycriu: Fix FieldDescriptor.label removal in protobuf 7.x 5546c06a1 zdtm: Fix rseq01 test for kernel 7.0 rseq changes 9777d2cf0 zdtm: Skip socket_udplite test when kernel lacks UDPLITE 09d7f7a2e ci: Add vanilla next kernel test variant to Lima CI job 189ad2c6f sockets: Treat UDPLITE as optional in collect_err() f6b7fb610 plugins/amdgpu: Fix remaining wrong usages of pr_perror 543612ae4 plugins/amdgpu: amdgpu_plugin_drm_restore_file() does not need to use libdrm 4cf1e190e plugins/amdgpu: Use save_vma_updates for all call sites 93ee1c527 plugins/amdgpu: Do not try dmabuf fd restore if render restore failed 9a65f7ede plugins/amdgpu: Convert away from libc buffered file IO 909eb890f plugins/amdgpu: Use the load_img helper in drm file restore 65f7baaf0 plugins/amdgpu: Move drm file dump and restore into helpers 05961714e plugins/amdgpu: Add plugin to inventory even if process has no vmas 7041509a5 plugins/amdgpu: Check sdma operation type early and once 8315b1a7a plugins/amdgpu: Fix open_drm_render_device() a85c10c77 plugins/amdgpu: Do not eat the errno in kmtIoctl e656198ca plugins/amdgpu: Reduce amount of debug logging a little bit 59eac8cc6 plugins/amdgpu: Remove plugin_log_msg() ea080673b plugins/amdgpu: Consolidate vm_info collection 5659b3954 plugins/amdgpu: Correct offset type and add error handling for seek operations 830e6cd3b plugins/amdgpu: Flatten amdgpu_restore_init a bit b9b1600bf plugins/amdgpu: Close dma-buf image file if the read fails 19baa7c37 plugins/amdgpu: Close the directory when image probing fails 0bd0c14bd plugins/amdgpu: Propagate failure to save buffer object content e26ed5163 plugins/amdgpu: Fix logging of failures to open files during restore init b1281444a plugins/amdgpu: Fix drm pages size header c0002ed83 plugins/amdgpu: Remove unused new_minor from struct vma_metadata ae4ed06f5 plugins/amdgpu: Remove unused current_pid global variable 52faca651 plugins/amdgpu: Fix one error message 9293f14fd plugins/amdgpu: Check that image unpacking worked during plugin init 5b88d1690 plugins/amdgpu: Fix shared memory allocation and teardown 81df65929 plugins/amdgpu: Use correct sizes to unmap sdma copy objects 47ab00240 plugins/amdgpu: Fix error handling in plugin init d96a2eb29 plugins/amdgpu: Close file on failures in amdgpu_plugin_dmabuf_restore 79c347c1e plugins/amdgpu: Clarify open_img_file docstring 592f04507 files-reg: warn when external file has no inherit-fd mapping on restore 176f14019 zdtm/bpfmap: parse frozen field with SCNu32 1e200015a proc_parse: Preallocate extra space for possible option string growth 9afe2e92d zdtm/ipc: use snprintf and bounded writes for sysctl payloads 740d67749 zdtm/ipc: close sysctl fd on write error paths 712f68d49 zdtm/packet_sock_mmap: keep parser warning-free with unsigned maj/min d24bfbf7d test/bers: use size_t format specifiers for file counters 3d5eb1c14 proc_parse: use matching unsigned formats for uid/gid and tfd parsing f943d4f32 bfd: fix partial write handling in bwritev() 78a712021 bfd: Support dynamic buffer resizing 351a16cab plugin/amdgpu: validate dmabuf_fd before drmPrimeFDToHandle() call 315fbed8f plugin/amdgpu: fix resource leaks in drm dump error paths b518e768c plugin/amdgpu: fix use of uninitialized pointers on partial allocation failure c2fba65e5 plugin/amdgpu: fix device handle leak in handle_for_shared_bo_fd() 9965ede5c plugin/amdgpu: set errno in open_img_file() on read/write failure 3e8d166ab plugin/amdgpu: fix fd leak in open_img_file() on fdopen failure 8e36132ef plugin/amdgpu: fix resource leaks in drm restore error paths b8d118a75 plugin/amdgpu: fix memory leak in dmabuf restore error paths 16b252ee2 plugin/amdgpu: add missing xzalloc() NULL checks in drm af32d407a plugin/amdgpu: check posix_memalign() return value 611af0188 plugin/amdgpu: add open_img_file error handling 22c3ab6b8 proc: Fix potential buffer overflow in parse_threads e956db75f restore: Fix exit code truncation for zombies c11579493 criu: Fix garbage write to /proc files fbcc99480 restore: Fix incorrect mmap error check 2c20b0482 restore: Fix memory leak of siginfo_priv_nr b0ebc416a restore: Fix memory leaks in CoreEntry handling 128566551 ci: remove aarch64 Fedora Rawhide from Cirrus CI 81f26b6b1 ci: add aarch64 matrix build for Fedora Rawhide test 87951452f test/rpc: clean up stale pidfile and socket before starting service ab28d4466 test/rpc: add page server address test f513ac16a cr-service: fix address handling of requests b19f73467 zdtm: add pipe_owner test for pipe ownership preservation fa7918890 pipes: restore pipe ownership to fix /proc/self/fd access 711b4ebfb ci: port Vagrant Fedora Rawhide test to GitHub Actions 9d8b23d5d ci: fix podman pids limit for thread-bomb test 4bcf08ce7 compel: fix heap alignment for structs with xsave state e39ff5228 tests: it seems 30 seconds timeout is not always enough 31d941ba7 sk-queue: increase CMSG_MAX_SIZE to handle all SCM types 7539f399f coredump: enable coredump generation on riscv64 c70a4b384 zdtm: add timerslack_ns test b258d6454 criu: restore timer_slack_ns per thread dfed6f073 criu: collect and dump timer_slack_ns per thread 985e6c6dd images: add timerslack_ns field to thread_core_entry 21c14313d contributing: document AI-assisted contribution guidelines 33dca7905 zdtm: add file_lease05 test for broken read lease restore 64c8d4a11 file-lock: fix type confusion in broken lease restore 33e340bed zdtm: fix TOCTOU race creating criu.tree directory 010a346c6 feat: remove build-time patches from Nixpkgs bbcadd85f feat: specify ourselves as Nix flake source f81e46b73 ci: upgrade CodeQL actions from v3 to v4 bce0a3c75 plugin/amdgpu: Don't print error when restoring drm file bd4cd4e9e plugin/amdgpu: Check output of open_img_file af3f4be06 ci: remove mips64el-stable-cross and mips64el-unstable-cross 7582216e1 loongarch64: implement atomic_dec_and_test 65cb18af2 pycriu: Force python protobuf backend in 3.14+ c9a0190f0 ci: mark archlinux-test as continue-on-error a13ce915c zdtm: use private bind-mount as GCOV external mount target e6bea0372 ci: stabilize gcov-test coverage upload bcd66dc30 scripts: fully qualify base image references a72bf212e scripts: improve layer caching of container builds 941f9b108 readme: update reference to consolidated workflows 5e1531888 ci: use clean state before self-contained check 5add27e6c compel/infect: optimize compel_stop_tasks_on_syscall 4a67a9a46 restorer: use atomic to synchronize threads e718fac15 compel: simplify compel_stop_on_syscall 7daebbe46 compel: remove hardware breakpoint usage 869d481cf restore: parallelize task stopping in attach_to_tasks and catch_tasks 15f11e404 compel/infect: Use waitpid with specific PIDs in compel_stop_tasks_on_syscall 09134c8ca restore: read user ns from pstree ids image f5974cc32 pagemap-cache: stop filling cache on VMA_AREA_GUARD 1bcbc55eb criu: fix double-open of userns image in --stream mode 04f1b9fb6 test: libcriu: use installed headers and library 3f3acc320 scripts: rseq: fix detection of rseq_cpu_id_state 8c29a7ccd ci: Consolidate test workflows and gate them by Alpine Test 5468d4a53 plugin/amdgpu: fix pr_perror trailing newline 555b257c5 plugin/amdgpu: Catch error for failure to open drm device 50e22d80a sk-queue: Fix memory leaks in error paths 1524ffc99 sk-queue: Add missing MSG_CTRUNC check in dump_sk_queue c180188db zdtm: fix incorrect open() syscall use for file creation without mode f22c95d2d restore: move cgroup restore after creds are prepared 1a4b338ed unix: fix dangling pointers in icon hash on error path 813e1a525 sk-inet: remove trailing whitespace 39c66a704 pagemap: detect EOF on truncated pages in process_async_reads() cf2b8c4bc restorer: detect EOF on truncated pages file to prevent infinite loop 7c5b745c6 MAINTAINERS: Update maintainer roles c5b81c0d7 Add UPDATE_INETSK hook for inet address rewrite cff99dbcc fsnotify: Fix mnt_id type to avoid undefined behavior with -1 sentinel 859924c2f fsnotify: Check mntns_get_root_by_mnt_id() return value in get_mark_path() 82c09bb92 ci: Re-enable zdtm/static/binfmt_misc 5c994447a zdtm/static/binfmt_misc: make the random generation actually random 838a59087 zdtm/static/binfmt_misc: run cleanup hook before restore 577c9a0f2 zdtm.py: ignore utf-8 conversion errors in test logs e6510a338 criu: Support binfmt_misc sandboxing ecab9e357 criu: kerndat: add kerndat_has_binfmt_misc_sandboxing() 0ae3a9498 criu: Remove legacy binfmt_misc handling code 100b3087f compel/x86: probe kernel task_size at runtime c676864d4 test: Add ZDTM test for SIGEV_THREAD_ID timer on thread leader aef72658c dump: Initialize thread leader's vtid before dumping posix timers 4d293afbe page-xfer: Fix page_read resource leak in page_pipe_from_pagemap() b5d531eb4 sk-unix: fix mutex_ghost deadlock on connect failure in post_open_standalone fc2cddbdb plugin/amdgpu: Allow dump with victim unable to see all gpus cfccc8387 fsnotify: Fix memory leak in pre_dump_one_fanotify error path 90407c014 fsnotify: Fix memory leak in pre_dump_one_inotify error path 155514d34 fsnotify: Improve error messages with more context 9e2c0cc56 fsnotify: Fix file descriptor leak in restore_one_inotify() 15bd86094 github: add Copilot repository-specific instructions 9e5fbcd66 pycriu: Fix self-dump failure with explicit PID 21a675826 cr-restore/shstk: Make arch_shstk_unlock use correct pid 07af3304f restore/pie: check return value of sys_rseq on unregister fb59ae504 test: fix GCC 16 compile error b208bec12 crit: show dead task_state 9885fb3c7 crit: fix incorrect task state decoding 71fe85ec9 ci: add iproute2 to the list of packages in apt-packages.sh 36f1e9d38 amdgpu: use fseeko with large-file support instead of fseeko64 ddf7a170f infect-types: fix user_gcs redefine error 2dd66866e zdtm/cgroup_stray: fix uninitialized variable 974c1bc89 zdtm/tempfs_subns: fix uninitialized variable b1a51489d compel: fix sys_clock_gettime function signature fc1867c44 kerndat: Fix error handling for kerndat_has_timer_cr_ids() fail 2e5f9facf util: Make close_safe() reset fd to -1 even on close() failure d4e811413 readme: use a local copy of the CRIU logo 30acbabcd ci: also exclude docker version 29 f66e59ee5 cr-dump: fix error handling f78bea8d3 zdtm: gcs: add opt-in GCS test support for AArch64 d591e320e criu/restore: gcs: adds restore implementation for Guarded Control Stack 2429d49e6 criu/dump: gcs: save GCS state during dump 41ecb7ac7 images: aarch64: add user_aarch64_gcs_entry 92e6e523b compel: gcs: add opt-in GCS test support for AArch64 2f676d20e compel: gcs: set up GCS token/restorer for rt_sigreturn 6bb856b0a compel: gcs: initial GCS support for signal frames 73ca07148 gcs: add GCS constants and helper macros 501b714f7 compel/aarch64: refactor fpregs handling 90300748e tty: fix compiler error 09bb36266 restore: fix "Defect type: UNINIT" bf82389de dump: fix "Defect type: IDENTICAL_BRANCHES" 2cf8f13ca doc: update pipe/socket examples for --inherit-fd 62aadb22a amdgpu: use 64-bit offsets for parallel restore 1db7eed69 amdgpu: use local kernel headers instead of libdrm 29525f8cb codespell: skip amdgpu kernel headers e4a5e164b plugins/amdgpu: update kernel headers f56ccfd2d plugins/amdgpu: remove unused variable 6ed49894c plugins/amdgpu: add a comment for retry_needed 77e6558dd plugins/amdgpu: apply code-style fixes 690b61043 plugins/amdgpu: return 0 in post_dump_dmabuf_check ff35a9126 plugins/amdgpu: remove excessive debug messages 9e404e208 plugin/amdgpu: Support for checkpoint of dmabuf fds d43217dad plugin: Add DUMP_DEVICES_LATE callback db0ec806d plugin/amdgpu: Add handling for amdgpu drm buffer objects 5eb61e1b1 plugin/amdgpu: Add drm header 0b7ca29c1 plugin/amdgpu: Add amdgpu drm header fb02dbf68 files-ext: Allow plugin files to retry 7a4ee0ae8 restorer: Skip non-regular VMAs 920437205 plugins/amdgpu: Update `README.md` and `criu-amdgpu-plugin.txt` 4a3a695df plugins/amdgpu: Implement parallel restore 33ed774c8 plugins/amdgpu: Add parallel restore command 638614075 plugins/amdgpu: Add socket operations ddbb3dbd8 limit the field width of 'scanf' 3c7d4fa01 criu: Version 4.2 (CRIUTIBILITY) Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* cri-tools: update to v1.36.0-tipBruce Ashfield2026-05-282-7/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping cri-tools to version v1.36.0-90-g5b24423f, which comprises the following commits: 722f32d9 enable zizmor 44739caa build(deps): bump the gomod group with 4 updates 672af9eb align local containerized test with CI 4d8700e0 crictl: deduplicate pull-related CLI flags 327420d2 crictl: extract generic resourceStatus to deduplicate status functions feb33d5f Remove accidentally committed crictl binary 599eb98f crictl: extract shared helpers and fix ContainerStats context ca182722 build(deps): bump crate-ci/typos from 1.46.2 to 1.46.3 41d99943 RunPodSandbox state contract and blocking behavior 924b3f91 add a root span 27965b7a task: add prettier to dependencies 85613d53 build(deps): bump the gomod group with 2 updates cca05915 crictl: add unit tests for utility functions afc8031e crictl: replace sort.Sort types with slices.SortFunc 1132c1ec task: bump ubuntu to latest LTS baef25ec crictl: consolidate pull flag definitions 672f15df hack/tools: update cri-dockerd to v0.4.3 and go-md2man to v2.0.7 1cb460d4 crictl: use sentinel error for empty ID validation 2b23070f ci: cancel in-progress workflow runs on new push f8a06b7b crictl: encapsulate global config and add client injection for testability d4020096 smoke test for NRI integration tests fcce23a4 Bump crate-ci/typos from 1.46.1 to 1.46.2 64b7931f Bump the gomod group with 2 updates 09088498 bump k8s.io dependencies to v0.36.1 e283eb1f Bump google.golang.org/grpc from 1.81.0 to 1.81.1 in the gomod group 2936afd8 ci: declare contents: read across the 4 remaining workflows d1a6602a Bump Go version to 1.26.3 4fb994e1 Bump the gomod group across 1 directory with 3 updates 9670a1a9 Bump crate-ci/typos from 1.46.0 to 1.46.1 1cdbfd11 Bump the gomod group with 3 updates a48b368f fix: use full path for go-md2man in verify-docs.sh 3be057e2 bumped linter and made it run on all platforms 00547873 Bump github.com/opencontainers/selinux in the gomod group d4532c43 refactor: move linux-specific validation code to separate files 5d60ceed local dev docker-based containerd environment 37552aba improve agent docs and fix zeitgeist for macOS ebd7d9b8 Bump google.golang.org/grpc from 1.80.0 to 1.81.0 in the gomod group 9dcc45fc Bump crate-ci/typos from 1.45.2 to 1.46.0 40f63b5b remove year from boilerplate bb03b7a1 Bump the gomod group with 2 updates b2918849 Bump crate-ci/typos from 1.45.1 to 1.45.2 c7e207d7 Bump the gomod group across 1 directory with 9 updates ea9454e9 bump cri-tools version to v1.36.0 after release 82f28d67 bumpo to release version of 1.36 5988383a add copyright dfd5525f crictl: replace docker/docker timestamp dependency a846c714 fix typo: intead -> instead 3f28b1c4 Add SergeyKanzhelev and tallclair to sig-node-approvers 58a1a780 Bump crate-ci/typos from 1.45.0 to 1.45.1 31b19db9 Bump actions/cache from 5.0.4 to 5.0.5 a1fa6b1f Makefile: Don't explicitly pass GOFLAGS to go commands 507358f9 Bump actions/upload-artifact from 7.0.0 to 7.0.1 3f90c7cf Bump k8s.io dependencies to v0.36.0-rc.0 27c856e8 more gitignore 30434d06 bump go tp 1.26.2 7d5c1228 Bump crate-ci/typos from 1.44.0 to 1.45.0 aad688ce Bump google.golang.org/grpc from 1.79.3 to 1.80.0 in the gomod group af533d44 Bump actions/setup-go from 6.3.0 to 6.4.0 ffa8e166 validate: add KubernetesPodUIDLabel to container attributes test bdffd30d validate: use subset checks for labels and annotations 661c011e removed deprecated TODO 746da572 Use k8s v0.36.0-beta.0 c98d29d2 Remediate GHSA-6g7g-w4f8-9c9x (bummp jsonparser to 1.1.2) 58323188 Remediate CVE-2026-33186 (bump grpc to 1.79.3) d2f54006 validate: add conformance tests for attribute preservation a8b6fcf6 Revert "Disable runc integration tests due to AppArmor issue" c633d342 adopt the latest cri client 76ce604b Bump actions/cache from 5.0.3 to 5.0.4 5077d436 feat: add prettier validation to Makefile and AGENTS.md 43768b05 crictl: replace utilyaml with sigs.k8s.io/yaml 3866e388 Add verify rule to Makefile cdd3d738 created a local copy of AggregateGoroutines 14a98847 start using k8s.io/streaming 9ddc149f use latest cri client with the logger used from context Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* cri-o: update to v1.36.0-tipBruce Ashfield2026-05-281-3/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping cri-o to version v1.36.0-32-g869599c20b, which comprises the following commits: cdf4881647 Bump go 5b23b14018 Update nixpkgs 13d308b934 Bump version to v1.37.0 572a5a1530 test(server): add test case for empty env values 875a46be10 test: rewrite TestMergeEnvs to use table-driven tests with more edge cases a0d5a70e70 Remove incorrect deprecation notice from crio.conf 87e12006b4 Address PR feedback: simplify comment and remove benchmarks f22d2024a2 Fix markdown lint and typos errors 2d6fe8bf61 build(deps): bump the gomod group across 1 directory with 30 updates 727d18bfee pinns: terminate long_options array for getopt_long 698d2c477c build(deps): bump the actions group across 1 directory with 18 updates 7ffa9b6097 use compact logging only for List* RPCs 4a5b77d5cd netns file cleanup after CRI-O restart with invalid namespace 24f7b608b9 Improve release notes template 0305311d28 version: bump cri-o.spec in version bump and release scripts 92b75982c2 Update nixpkgs e5a6f664a3 Delete updateunified binary 698c222454 Bump k8s.io packages to v1.36 ff69f0eb7b oci: clone execPIDs map to avoid segfault 8ff525cf03 cnimgr: continuously poll CNI STATUS to detect runtime health changes 50bad6de7d metrics: add default_runtime 47cc14fe65 MAINTAINERS: move @kolyshkin to alumni d73341fb45 deps: bump go to 1.26.2 f50fd5bd2c vendor: update github.com/moby/spdystream to v0.5.1 1b111f660d Add inject_gomaxprocs via runtime handler precreate hook 88e8f422b5 oci: wait for exit file before defaulting to exit code 255 8b9a4a37e5 Add SLSA provenance attestation to release notes template ca4496cc7b Implement Stream* RPCs e70f41a322 Embed git commit in static binaries via ldflags 6c9718d73a Disable zlib s390x vectorized CRC32 for cross-compilation 498e33a723 Update nixpkgs ded8ab8c6b Modernize nix setup to use flakes 9c75852b3d Make artifact pinned status respect pinned_images configuration a21c685723 fix: address review comments for additional artifact stores c608ffc3a9 feat: add support for additional read-only artifact stores 5ca7b348ae Switch to go 1.26 456e2e70f9 Add integration test for updating cgroup v2 unified resources 5dd7bb4e3d Add libpathrs version to dependencies 2b23b4810d Add libpathrs-devel to github-actions 8d8d342a15 Add libpathrs-devel to Fedora packages for runc build cd2b28f0d4 Add unified cgroup resource update support for cgroup v2 a45b2e4977 version: sync cri-o.spec with development version 01ee67395e Update utils_bench_test.go 4201b78274 perf(server): optimize mergeEnvs to eliminate O(N*M) string splits Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* nerdctl: fix PV valueZhixiong Chi2026-05-281-1/+1
| | | | | | | | During the last upgradeing, the source has been upgraded to v2.2.1, but the PV is not. So make it be accurate. Signed-off-by: Zhixiong Chi <zhixiong.chi@windriver.com> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* cowsql: update to v1.15.9-tipBruce Ashfield2026-05-281-4/+1
| | | | | | | | | | | | | | | | | Drops the GCC 15 -Wno-error=discarded-qualifiers workaround — upstream fixed it (64982fb). Bumping cowsql to version v1.15.9-9-g7c4d731, which comprises the following commits: 64982fb Fix -Wdiscarded-qualifiers warnings when using C23 memchr 2fa8608 build(deps): bump actions/checkout from 5 to 6 a27e21b refactor: replace semaphores, mutexes, conditions and threads with uv equivalents 8e73441 refactor: remove unused semaphore 'stopped' from cowsql_node structure 5b67836 build(deps): bump actions/checkout from 4 to 5 83b1d3a Release v1.15.9 Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* cosign: update to v3.0.6-tipBruce Ashfield2026-05-287-1009/+884
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Bumping cosign to version v3.0.6-44-g55f4d9e2, which comprises the following commits: 55f4d9e2 Enable initialize command output in conformance (#4892) 9146e3fd Fix Ed25519ph check to respect custom signing configs in sign-blob (#4880) 0bfb59e0 chore(deps): bump github.com/jackc/pgx/v5 from 5.8.0 to 5.9.2 (#4833) 3384f6a2 chore(deps): bump the actions group with 4 updates (#4890) f3177523 chore(deps): bump actions/github-script from 8.0.0 to 9.0.0 (#4891) 074c598a chore(deps): bump k8s.io/apimachinery from 0.35.3 to 0.36.1 (#4859) ca9906d1 chore(deps): bump github.com/buildkite/agent/v3 from 3.118.0 to 3.127.0 (#4861) 5b603990 update go-github to v88 (#4887) 29dc88b8 bump static-debian to static-debian13 (#4888) 74650550 update builder to use go1.26.3 (#4885) cb68b297 bump golangci-lint (#4886) da174ac4 Fix unsafe type assertion in Rego policy evaluation (#4882) b4e1761f fix: check HTTP status code in LoadFileOrURL (#4877) a01e484b Use the configured Target Repository more consistently. (#4836) d3f481eb Deprecate Flags for v4: OCI Referrers (#4804) 6ea2f187 Fix crash verifying timestamps when no timestamp was verified (#4881) 7993b350 Undo skip setcap for HashiCorp Vault (#4879) cd402b41 Fix impossible status code checks in GitHub provider PutSecret (#4876) f02ee6f5 chore(deps): bump github.com/open-policy-agent/opa from 1.14.1 to 1.16.2 (#4862) cca05a3f chore(deps): bump github.com/go-piv/piv-go/v2 from 2.5.0 to 2.6.0 (#4863) 2d3bebf1 chore(deps): bump github.com/in-toto/attestation from 1.1.2 to 1.2.0 (#4798) 4df4c13c chore(deps): bump golang from 1.25.6 to 1.25.7 in the all group (#4690) b2cc7950 chore(deps): bump codecov/codecov-action from 5.5.2 to 6.0.0 (#4800) e5871155 chore(deps): bump github.com/in-toto/in-toto-golang (#4855) 4df629ef chore(deps): bump the actions group across 1 directory with 6 updates (#4864) bf57b898 feat(cli): add Rekor v2 flag to cosign signing-config create (#4868) 8a86a7cf fix: use Header.Set to prevent duplicate Authorization on retry (#4870) b33aaacb fix: close file descriptor leaked in WriteSignedImageIndexImages loop (#4869) d5891a86 deprecate private-infrastructure and record-creation-timestamp flags (#4854) a1ec0737 Add bundle upgrade command (#4820) 6a80f22c Fix typo in map of verify fields unsupported for new bundle format (#4853) f15ac759 Deprecate flags bundle (#4838) 08952e2c Deprecate flags signing config (#4844) f5373b06 Switch from cosign copy to oras copy (#4819) 5fff8869 Deprecate Flags for v4: Certificates (#4822) 39940de0 chore(deps): bump the gomod group across 1 directory with 10 updates (#4840) 394ab4da fix: honor --digestAlg when hashing a blob in verify-blob-attestation (#4813) f02250eb fix(load): pass NameOptions to name.ParseReference (#4786) 032c0ea4 Update conformance to latest (#4843) 13a3d79e Require bundle output or registry upload (#4785) 040443cf bundle create: Prevent IgnoreTlog when bundle contains SET (#4829) b7462fb6 ci: Skip setcap for HashiCorp Vault 1d5c7a6d Sign exclusively via sigstore-go (#4618) a6bd85fc fix(pkcs11-tool): GetKeysInfo not initializing YKCS11 correctly (#4803) f1ad3ee9 Fix DSSE predicate check (GHSA-w6c6-c85g-mmv6) (#4801) Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* containerd: update to v2.3.1Bruce Ashfield2026-05-272-8/+8
| | | | | | | | | | | | | | | | | | | | | | We refresh a patch for context, and also pickup the following changes: f588bc6fb contrib/checkpoint: increase timeouts to 30s 58af96519 Prepare release notes for v2.3.1 8f0b3ca83 Update api to v1.11.1 da7aef299 Prepare release notes for api/v1.11.1 5282d4e09 Wire task address and version fields e44f5f9ec protos: include task API address to CreateTaskRequest 4d80a31bf seccomp: Block AF_ALG in default socket policy 2ed0d97b6 seccomp: Document socket rule scope and socketcall limitation 2be0710b8 overlay: disable "rebase" capability when running in UserNS 3a88fdde0 server: tolerate failed gRPC plugins when starting listeners 1d601271a fix: close boltdb on metadata and mount plugin close 3b199c22b Update Go to 1.26.3 a05ae7885 oci: return explicit error for out-of-range USER values d666d2e42 Refactor transfer unpack configuration setup ccc3bd7b9 Fix optional transfer differ setup Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* conmon: update to v2.2.1-tipBruce Ashfield2026-05-271-1/+1
| | | | | | | | | | | | | Bumping conmon to version v2.2.1-33-g5352940, which comprises the following commits: 1b45f46 Update dependency opencontainers/runc to v1.4.2 8596fc6 Reset create_pid after waitpid to prevent signaling unrelated processes bafb655 signal: replace raise(SIGUSR1) with self-pipe to fix SIGABRT on glibc >= 2.42 e0c56ec ci: replace Cirrus CI with GitHub Actions 3bf4bd9 cgroup: skip legacy v1 controller lines when parsing cgroup v2 path 8bc1877 chore(deps): update dependency containernetworking/plugins to v1.9.1 Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* catatonit: update to v0.2.1-tipBruce Ashfield2026-05-271-1/+1
| | | | | | | | | | Bumping catatonit to version v0.2.1-7-g00f6c0f, which comprises the following commits: 40bf6d7 build: enable stricter format string warnings cfaa5d4 catatonit: fix format specifier for long long fd value 56579ad main: don't use secure_getenv Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* buildah: update to v1.43.1Bruce Ashfield2026-05-271-2/+2
| | | | | | | | | | | | | | | | | | | Bumping buildah to version v1.43.1-4-g1d61d5217, which comprises the following commits: 0203efa67 tests: remove dependencies on online apt repositories c2e1324b1 Cite go module change 310b1c8f5 [release-1.43] Bump Buildah to v1.43.1 fb349f2d6 [release-1.43] Bump c/common v0.67.1, c/image v5.39.2 ccba7c460 update module github.com/go-jose/go-jose/v4 to v4.1.4 [security] 0d8e18550 ignore ErrLayerUnknown in cache lookup 8499b1a41 fix setting of gid 3780f1490 fix call to chown 0158b5b31 [release-1.43] Bump Buildah to v1.43.0 f40d38a2f [release-1.43] fix source test 07b8495c8 [release-1.43] Bump common 0.67.0, image 5.39.1, storage 1.62.0 7178b10ac [release-1.43] Bump dest branch in cirrus to 1.43 Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* aardvark-dns: update to v1.17.1Bruce Ashfield2026-05-272-45/+47
| | | | | | | | | | | Bumping aardvark-dns to version v1.17.1-1-g880f690, which comprises the following commits: d9d17d4 release v1.17.1 b2cf5c7 release notes for v1.17.1 0bc10b3 migration to oidc connection b66c50e fix handling of incorrect tcp packets Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* docker-compose: fix PVBruce Ashfield2026-05-121-1/+1
| | | | | | | | When docker-compose was updated, the hash was set properly but the PV was not. We are actually building docker compose 5.1.x, so we adjust the PV to be accurate. Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* podlet: add podlet utilityPatrick Vogelaar2026-05-112-0/+378
| | | | | | | Podlet generates Podman Quadlet files from a Podman command, compose file, or existing object. Signed-off-by: Patrick Vogelaar <patrick.vogelaar@belden.com> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* container-registry: add multi-arch OCI push support and testsBruce Ashfield2026-05-101-0/+54
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The registry push script (container-registry-index.bb) treated all OCI directories as single-arch, calling 'skopeo copy oci:<dir>' which fails with "more than one image in oci, choose an image" when the directory contains a multi-arch image index. The original push implementation predated multi-arch OCI support and only handled the single-manifest case. Detect multi-arch OCI Image Index directories (both flat and nested layouts) in the direct-path push mode and use 'skopeo copy --all' to push the entire manifest list to the registry in one operation. This preserves the multi-platform structure so that clients pulling from the registry automatically get the correct architecture. Also strip the '-multiarch' suffix from directory names when deriving the registry image name, so container-base-multiarch-multiarch-oci pushes as 'container-base' rather than 'container-base-multiarch'. Add build-profiles.md documentation for the vcontainer distro, container multiconfigs, and multi-arch container build workflow. Add test_vcontainer_distro.py with 54 tests across three tiers: - Tier 1: Static file assertions (vruntime-base.inc, vcontainer.conf, multiconfigs, bbclass defaults, recipe structure) - Tier 2: Cross-file consistency (shared base, distro-MC alignment, bbclass-to-multiconfig file matching) - Tier 3: Build output verification (OCI index structure, platform entries, blob integrity, manifest validation) Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* vcontainer-common: support nested OCI layout and fix vimport shell errorsBruce Ashfield2026-05-101-31/+40
| | | | | | | | | | | | | | | | | | | | | | | | | | | The multi-arch OCI functions (is_oci_image_index, get_oci_platforms, select_platform_manifest) only checked index.json directly for platform information. With the skopeo-compatible nested OCI layout — where index.json references a single image index blob that in turn contains the per-platform manifests — the functions failed to detect multi-arch images because index.json no longer contains platform entries. Add _resolve_oci_platform_file() helper that handles both layouts: - Flat: platform info directly in index.json (legacy/simple case) - Nested: index.json → image index blob → platform manifests All three multi-arch functions now use this single helper, eliminating the layout resolution logic that would otherwise be duplicated in each. Also fixes two issues in the vimport case block: - 'local' keyword used outside a function (bash error on line 1879). The vimport handler is in a case statement in the main script body, not inside a function, so 'local' is invalid. The original multi-arch code was written assuming it would be inside a function. - OCI_SELECTED_PLATFORM was blank in output because select_platform_manifest sets it inside a $() subshell, where variable assignments are lost. Use normalize_arch_to_oci directly for the display message instead. Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* vcontainer: add --config / VDKR_CONFIG for docker/podman auth credentialsTim Orling2026-04-296-0/+392
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Add a VDKR_CONFIG / VPDMN_CONFIG env var and a matching --config <path> CLI flag that passes an existing docker config.json / podman auth.json into the QEMU-hosted container runtime so pulls from private registries work without having to retype --registry-user / --registry-pass on every command. Security posture (defence in depth): - Host-side pre-flight validation in vrunner.sh (validate_auth_config): reject symlinks, non-regular files, missing / unreadable files, files smaller than 2 bytes (minimum "{}") or larger than 1 MiB, and any permissions other than 0400 / 0600 / 0200. WARN if not owned by the invoking user. - Stage the file into a dedicated per-invocation directory under $TEMP_DIR at mode 0400 inside a 0700 parent; auto-cleanup rides the existing EXIT/INT/TERM trap. - Expose the staged file over a *separate* read-only virtio-9p tag ("${TOOL_NAME}_auth") so credentials cannot leak into the general /mnt/share input/output directory or into storage.tar outputs. - Only a boolean flag ("${CMDLINE_PREFIX}_auth=1") is appended to the kernel cmdline - never the path, the env var name, or the contents. - Guest mounts /mnt/auth ro,nosuid,nodev,noexec, copies to the runtime's canonical path, then unmounts immediately so neither the runtime nor user workloads keep a reference to the host staging directory. vrunner.sh: - Initialise AUTH_CONFIG from $VDKR_CONFIG / $VPDMN_CONFIG - Parse --config <path> (overrides the env vars) - Add validate_auth_config() and setup_auth_share() with the rules above - Call setup_auth_share in both the daemon start path and the non-daemon / batch-import path vcontainer-init-common.sh: - Default RUNTIME_AUTH="0" and parse ${VCONTAINER_RUNTIME_PREFIX}_auth=* from the kernel cmdline - Define mount_auth_share() / unmount_auth_share() using the per-runtime "${VCONTAINER_RUNTIME_NAME}_auth" 9p tag, mounted at /mnt/auth with ro,nosuid,nodev,noexec vdkr-init.sh: - install_auth_config() copies /mnt/auth/config.json to /root/.docker/config.json (mode 0600; parent dir 0700) - Called after install_registry_ca in main flow so --config takes precedence over --registry-user / --registry-pass; logs a NOTE when both mechanisms are supplied - Unmounts /mnt/auth after copy vpdmn-init.sh: - install_auth_config() copies to /run/containers/0/auth.json (the rootful podman canonical path) and exports REGISTRY_AUTH_FILE so the creds are picked up regardless of podman's search order - Mode 0600 on the file, 0700 on the containing directory - Unmounts /mnt/auth after copy vcontainer-common.sh: - Honour $VDKR_CONFIG / $VPDMN_CONFIG, parse --config, and forward AUTH_CONFIG to vrunner.sh via --config in build_runner_args - Document the flag and env vars in show_usage README.md: - New "Passing an existing docker/podman auth file (--config)" section with examples for both runtimes, a table of target paths, and the full security model AI-Generated: Claude Cowork Opus 4.7 Signed-off-by: Tim Orling <tim.orling@konsulko.com> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* vcontainer-common: fix vstorage commands with --state-dirBruce Ashfield2026-04-291-7/+15
| | | | | | | | | | | | | vstorage list/df/clean scanned DEFAULT_STATE_DIR (~/.vpdmn/) for arch subdirectories, ignoring --state-dir. On CI where tests use --state-dir ~/.vpdmn-test/x86_64, the default directory doesn't exist so vstorage list reports "(no storage directories found)" and test_vstorage_shows_memres_status fails. Derive VSTORAGE_ROOT from the parent of STATE_DIR when --state-dir is set, so all vstorage subcommands scan the correct storage root. Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* podman: fix CNI build tag for non-netavark networking configurationsBruce Ashfield2026-04-291-1/+7
| | | | | | | | | | | | | | | | BUILDTAGS_EXTRA was gated on VIRTUAL-RUNTIME_container_networking == "cni", which excluded the cni build tag in vruntime builds where that variable is intentionally blank (vpdmn-rootfs-image installs cni packages directly). This caused podman to be compiled with netavark-only support, failing at runtime with "cni support is not enabled in this build" when containers.conf sets network_backend = "cni". Include the cni build tag unless the distro explicitly selects netavark. This respects the podman profile's upstream preference for netavark-only while ensuring all other configurations (containerd, default, docker, k3s, vruntime) retain CNI support. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* vcontainer-tarball: add CI-safe environment script for autobuilderBruce Ashfield2026-04-281-2/+27
| | | | | | | | | | | | | The existing environment-setup-* script uses BASH_SOURCE to derive VCONTAINER_DIR, which is empty when parsed by yocto-autobuilder-helper's enable_tools_tarball() since it doesn't evaluate shell expressions. Generate a separate environment-setup-ci with flat export lines using baked-in absolute paths from ${SDKPATH}/${SDKPATHNATIVE}. The AB parser picks these up directly. SDK relocation rewrites the paths at install time. The interactive bash script is unchanged. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* cosign: switch to go-mod-vcs generated license scanningBruce Ashfield2026-04-283-276/+1047
| | | | | | | | | Replace the go-mod-update-modules generated cosign-licenses.inc with go-mod-licenses.inc produced by oe-go-mod-fetcher --scan-licenses. The new file is generated during discover_and_generate alongside the other .inc files. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* cosign: convert to go-mod-vcs hybrid fetchBruce Ashfield2026-04-287-268/+3081
| | | | | | | | | | | | | | | | Convert from go-mod + go-mod-update-modules to go-mod-vcs hybrid fetch mode, consistent with other Go recipes in the layer (k3s, nerdctl, docker-compose, etc.). - Replace cosign-go-mods.inc (gomod:// only) with generated go-mod-hybrid-{gomod,git,cache}.inc and go-mod-{git,cache}.inc - Keep cosign-licenses.inc for dependency license tracking (our go-mod-vcs tooling does not yet generate license metadata) - Add GO_MOD_VCS_EXCLUDE for buf.build (no git repo) and software.sslmate.com/src/go-pkcs12 (unreachable commit) - Set GO_MOD_DISCOVERY_SRCDIR to match go.bbclass source layout Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* cosign: add recipe for container signing tool v3.0.6Tim Orling2026-04-283-0/+554
| | | | | | | | | | | | | Add cosign [1] recipe for sigstore's [2] container signing, verification and storage tool [3]. Includes auto-generated Go module dependencies and license tracking via go-mod-update-modules. [1] https://github.com/sigstore/cosign/releases/tag/v3.0.6 [2] https://www.sigstore.dev/ [3] https://docs.sigstore.dev/cosign/signing/overview/ Signed-off-by: Tim Orling <tim.orling@konsulko.com> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* vcontainer-initramfs-create: fix kernel deploy dependency via do_buildBruce Ashfield2026-04-281-11/+10
| | | | | | | | | | | | | | | | | | | | | On sstate-accelerated builds, the kernel binary (bzImage/Image) was missing from MC_DEPLOY because do_compile depended on the image recipes' do_image_complete, which runs before do_build. The kernel deploy dependency (virtual/kernel:do_deploy) is attached to do_build in image.bbclass, so depending on do_image_complete cut the chain short and virtual/kernel:do_deploy was never guaranteed to have run. Fix by depending on do_build instead of do_image_complete. The image artifacts (cpio.gz, squashfs) are already in DEPLOY_DIR_IMAGE after do_image_complete, so they remain available. do_build additionally ensures virtual/kernel:do_deploy has completed, placing the kernel in MC_DEPLOY for our do_compile to copy. This avoids adding an explicit virtual/kernel:do_deploy dependency which would couple this recipe to the kernel and prevent use cases where the kernel is provided externally. Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* lxc: delete extraneous PACKAGECONFIG[systemd] lineGavvala, Kris2026-04-281-1/+0
| | | | | | | | | | | | | | | | | | The PACKAGECONFIG[systemd] variable is assigned twice, with the second assignment overriding the first. This patch removes the unused assignment to avoid confusion. The duplication was introduced in an August 25, 2022 patch: 05f316f7 lxc: update to 5.x and meson Verfied that the build did not change after this deletion by checking the log files before and after and finding the same message: export systemd_system_unitdir="/usr/lib/systemd/system" export systemd_unitdir="/usr/lib/systemd" export systemd_user_unitdir="/usr/lib/systemd/user" Signed-off-by: Kris Gavvala <kris.gavvala@windriver.com> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* podman: update version to match golangs version.goBruce Ashfield2026-04-281-1/+1
| | | | | | | | | | | | The update cycle used the git tags to update the PV version, but when you build podman, the version pulled into the executables is from: version/rawversion/version.go Which currently reports: 5.8.3-dev Bumping the PV to match. Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
* podman: update SRC_URIPatrick Vogelaar2026-04-241-2/+2
| | | | | | | | | | | | Podman is hosted under github as podman and not libpod. Accessing github.com/containers/libpod automatically forwards to github.com/containers/podman. This commit does not really fix a problem but reflects more the current repository name. Signed-off-by: Patrick Vogelaar <patrick.vogelaar@belden.com> Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>