Release 1.5.2 - #5466
Merged
Merged
Release 1.5.2#5466
Conversation
kolyshkin
force-pushed
the
rel-1.5.2
branch
from
September 14, 2026 05:26
ebc08b2 to
26a9705
Compare
kolyshkin
force-pushed
the
rel-1.5.2
branch
2 times, most recently
from
September 21, 2026 20:43
3ef1088 to
c238145
Compare
cyphar
marked this pull request as ready for review
September 22, 2026 01:41
cyphar
marked this pull request as draft
September 22, 2026 01:42
This comment was marked as outdated.
This comment was marked as outdated.
This comment has been minimized.
This comment has been minimized.
kolyshkin
force-pushed
the
rel-1.5.2
branch
from
September 24, 2026 08:10
c238145 to
748efba
Compare
thaJeztah
reviewed
Sep 24, 2026
|
|
||
| ## [1.5.2] - 2026-09-25 | ||
|
|
||
| > Всё сбудется, стоит только расхотеть! |
Member
There was a problem hiding this comment.
For others, if they're interested 😅
Everything will come true, you just have to want it!
Contributor
Author
There was a problem hiding this comment.
Ah, that's wrong translation.
The correct one is "Everything will come true, you just have to stop wanting it".
Words of wisdom by Faina Ranevskaya.
Member
There was a problem hiding this comment.
Ah! Translate is always hit or miss; sometimes it does a good job though!
Signed-off-by: Kir Kolyshkin <kolyshkin@gmail.com>
Signed-off-by: Kir Kolyshkin <kolyshkin@gmail.com>
kolyshkin
force-pushed
the
rel-1.5.2
branch
from
September 24, 2026 21:16
748efba to
2d9e3b0
Compare
kolyshkin
marked this pull request as ready for review
September 24, 2026 21:17
Contributor
Author
|
@cyphar @thaJeztah @lifubang @AkihiroSuda PTAL (hope to release tomorrow) |
AkihiroSuda
approved these changes
Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release runc v1.5.2.
All the backport PRs this release depends on are now merged, so this PR is
rebased onto the current
release-1.5and consists of just two commits:"VERSION: release v1.5.2" and "VERSION: back to development".
The release commit also adds CHANGELOG entries for the already merged
PRs which were missing them (#5442 + #5449, #5381, #5465), and mentions #5451
and GO-2026-6238.
Copy-paste from the relevant CHANGELOG portion below:
[1.5.2] - 2026-09-25
Fixed
runc exec -pwith a process.json lackingenvnow setsHOMEagain(a regression in runc 1.3.0). (#5265, #5266, #5459)
which caused the kernel to write past the end of the structure
provided by userspace (runc). This resulted in memory corruption inside runc
(manifesting as random crashes) when configuring device rules on cgroup v2
systems. (#5403, #5428)
runc exec --cgroup(and the equivalent libcontainerProcess.SubCgroupPathsAPI) no longer accepts a sub-cgroup path that escapes the container's cgroup
into a sibling cgroup sharing the same name prefix. Note that using
--cgrouprequires the same privileges as runningrunc execitself, sothis is a correctness rather than a security fix. (#5403, #5457)
O_CLOEXECwhen opening the cgroup v2 directory to set updevice rules. (#5403, #5428)
fixed. (#5403, #5428)
rootfsPropagationis set torslave, the rootfs parent mount is nolonger made private before pivoting into the rootfs, so unmount/remount
events on host mountpoints under the rootfs are now propagated to the
running container. (#5192, #5200, #5458)
when that namespace has a full identity ID mapping (
0 0 4294967295), asused by systemd >= 260 units with
PrivateUsers=full. Previously this maderunc skip its user namespace code paths, so starting a container in such a
unit failed with
bpf_prog_query(BPF_CGROUP_DEVICE) failed: operation not permitted. (#5396, #5411, #5451, moby/sys#239)runc initpanic (SIGABRT) on the error path, caused by SELinuxlabels being reset after the cached libpathrs procfs handle was already
closed. This is fixed both by not resetting the labels on the init error
path, and by updating to libpathrs v0.2.6, which now handles a closed
procfs handle gracefully. (#5438, #5439, #5442, #5448, #5449, #5467,
#5469)
from the one it was compiled against (e.g. built with libseccomp >= 2.6.0 and
run with an older one), by updating to libseccomp-golang v0.12.0. This also
supersedes the
SECCOMP_FILTER_FLAG_WAIT_KILLABLE_RECVworkaround added inrunc 1.5.1. (#5436, #5461)
with optimizations enabled (the default
-g -O2CFLAGS); previously it wasbuilt unoptimized. (#5464, #5465)
Changed
high-level cilium/ebpf API to manage cgroup v2 device rules. As a result,
the runc binary shrunk by about 1 MiB (7.5%) on amd64. This also means runc
no longer calls the cilium/ebpf code affected by GO-2026-6238. (#5403, #5428)