Skip to content

Release 1.5.2 - #5466

Merged
kolyshkin merged 2 commits into
opencontainers:release-1.5from
kolyshkin:rel-1.5.2
Sep 25, 2026
Merged

kolyshkin merged 2 commits into
opencontainers:release-1.5from
kolyshkin:rel-1.5.2

Conversation

@kolyshkin

@kolyshkin kolyshkin commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Release runc v1.5.2.

All the backport PRs this release depends on are now merged, so this PR is
rebased onto the current release-1.5 and consists of just two commits:
"VERSION: release v1.5.2" and "VERSION: back to development".

The release commit also adds CHANGELOG entries for the already merged
PRs which were missing them (#5442 + #5449, #5381, #5465), and mentions #5451
and GO-2026-6238.

Copy-paste from the relevant CHANGELOG portion below:

[1.5.2] - 2026-09-25

Всё сбудется, стоит только расхотеть!

Fixed

  • runc exec -p with a process.json lacking env now sets HOME again
    (a regression in runc 1.3.0). (#5265, #5266, #5459)
  • Worked around a Linux kernel bug (present since kernel v6.17, fixed in v7.2)
    which caused the kernel to write past the end of the structure
    provided by userspace (runc). This resulted in memory corruption inside runc
    (manifesting as random crashes) when configuring device rules on cgroup v2
    systems. (#5403, #5428)
  • runc exec --cgroup (and the equivalent libcontainer Process.SubCgroupPaths
    API) no longer accepts a sub-cgroup path that escapes the container's cgroup
    into a sibling cgroup sharing the same name prefix. Note that using
    --cgroup requires the same privileges as running runc exec itself, so
    this is a correctness rather than a security fix. (#5403, #5457)
  • Fixed a missing O_CLOEXEC when opening the cgroup v2 directory to set up
    device rules. (#5403, #5428)
  • Some long-standing file-descriptor leaks on the eBPF devices cgroups were
    fixed. (#5403, #5428)
  • When rootfsPropagation is set to rslave, the rootfs parent mount is no
    longer made private before pivoting into the rootfs, so unmount/remount
    events on host mountpoints under the rootfs are now propagated to the
    running container. (#5192, #5200, #5458)
  • runc no longer misdetects a non-initial user namespace as the initial one
    when that namespace has a full identity ID mapping (0 0 4294967295), as
    used by systemd >= 260 units with PrivateUsers=full. Previously this made
    runc skip its user namespace code paths, so starting a container in such a
    unit failed with bpf_prog_query(BPF_CGROUP_DEVICE) failed: operation not permitted. (#5396, #5411, #5451, moby/sys#239)
  • Fixed a runc init panic (SIGABRT) on the error path, caused by SELinux
    labels being reset after the cached libpathrs procfs handle was already
    closed. This is fixed both by not resetting the labels on the init error
    path, and by updating to libpathrs v0.2.6, which now handles a closed
    procfs handle gracefully. (#5438, #5439, #5442, #5448, #5449, #5467,
    #5469)
  • Fixed various issues when the libseccomp version runc is run with differs
    from the one it was compiled against (e.g. built with libseccomp >= 2.6.0 and
    run with an older one), by updating to libseccomp-golang v0.12.0. This also
    supersedes the SECCOMP_FILTER_FLAG_WAIT_KILLABLE_RECV workaround added in
    runc 1.5.1. (#5436, #5461)
  • The libseccomp library statically linked into release binaries is now built
    with optimizations enabled (the default -g -O2 CFLAGS); previously it was
    built unoptimized. (#5464, #5465)

Changed

  • Switched to opencontainers/cgroups v0.1.0, which no longer uses the
    high-level cilium/ebpf API to manage cgroup v2 device rules. As a result,
    the runc binary shrunk by about 1 MiB (7.5%) on amd64. This also means runc
    no longer calls the cilium/ebpf code affected by GO-2026-6238. (#5403, #5428)
  • Updated golang.org/x/net to v0.55.0. (#5379, #5381)
  • Updated builds to libseccomp v2.6.1. (#5376, #5460)

@kolyshkin kolyshkin added this to the 1.5.2 milestone Sep 14, 2026
@kolyshkin
kolyshkin force-pushed the rel-1.5.2 branch 2 times, most recently from 3ef1088 to c238145 Compare September 21, 2026 20:43
@cyphar
cyphar marked this pull request as ready for review September 22, 2026 01:41
@cyphar
cyphar marked this pull request as draft September 22, 2026 01:42
@tdstein

This comment was marked as outdated.

@tdstein

This comment has been minimized.

Comment thread CHANGELOG.md

## [1.5.2] - 2026-09-25

> Всё сбудется, стоит только расхотеть!

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For others, if they're interested 😅

Everything will come true, you just have to want it!

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah, that's wrong translation.

The correct one is "Everything will come true, you just have to stop wanting it".

Words of wisdom by Faina Ranevskaya.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah! Translate is always hit or miss; sometimes it does a good job though!

Signed-off-by: Kir Kolyshkin <kolyshkin@gmail.com>
Signed-off-by: Kir Kolyshkin <kolyshkin@gmail.com>
@kolyshkin
kolyshkin marked this pull request as ready for review September 24, 2026 21:17
@kolyshkin

Copy link
Copy Markdown
Contributor Author

@cyphar @thaJeztah @lifubang @AkihiroSuda PTAL (hope to release tomorrow)

@thaJeztah thaJeztah left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@kolyshkin
kolyshkin merged commit 976e429 into opencontainers:release-1.5 Sep 25, 2026
58 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants