containerd 1.2.11
Welcome to the v1.2.11 release of containerd!
The eleventh patch release for containerd 1.2 includes an updated runc with
an additional fix for CVE-2019-16884 and a Golang update.
Notable Updates
-
Update the runc vendor to v1.0.0-rc9 which includes an additional mitigation for CVE-2019-16884.
- More details on the runc CVE in opencontainers/runc#2128, and the additional mitigations in opencontainers/runc#2130.
-
Add local-fs.target to service file to fix corrupt image after unexpected host reboot. Reported in containerd/containerd#3671, and fixed by containerd/containerd#3746.
-
Update Golang runtime to 1.12.13, which includes security fixes to the
crypto/dsapackage made in Go 1.12.11 (CVE-2019-17596), and fixes to the go command,runtime,syscallandnetpackages (Go 1.12.12). -
CRI fixes:
- Fix shim delete error code to avoid unnecessary retries in the CRI plugin. Discovered in containerd/cri#1309, and fixed by containerd/containerd#3732 and containerd/containerd#3739.
Please try out the release binaries and report any issues at
https://github.com/containerd/containerd/issues.
Contributors
- Sebastiaan van Stijn
- Michael Crosby
- Derek McGowan
- Lantao Liu
- Wei Fu
- Maksym Pavlenko
- Mike Brown
- Phil Estes
Changes
f772c10a58Merge pull request #3811 from thaJeztah/release_1.2.111b4aebd681Prepare v1.2.11 releasedb4537e43dMerge pull request #3821 from fuweid/cherry-pick-3819-1.2128664b677snapshots: return error if readSnapshot failsa287c087b6Merge pull request #3809 from thaJeztah/1.2_backport_bump_golang_1.12.13342c953a53Update to Golang 1.12.136b94990c11Revert "[release/1.2] pin travis to go 1.12.12"c2383a5f2cMerge pull request #3768 from thaJeztah/1.2_backport_bump_golang_1.12.xd1960b4129Merge pull request #3771 from estesp/update-vndr0b9135f1dcCatch up vndr with state of vendor/ dir435e05fd0d[release/1.2] pin travis to go 1.12.12e319caedc4Update Golang 1.12.12 (CVE-2019-17596)b0d7ef6110Merge pull request #3746 from crosbymichael/localfs2c471c95bc5Add local-fs.target to service filec3532a35ccMerge pull request #3739 from estesp/cp-1.2-3736847f74c284Fix delete error code on the containerd daemon side.445638104eMerge pull request #3732 from Random-Liu/cherrypick-#3730-release-1.2611766aff3Fix shim delete error code.816dfe3960Merge pull request #3723 from thaJeztah/1.2_backport_bump_runc_1.0.0-rc9639be35858bump runc v1.0.0-rc9b30190905fBump runc to 1b8a1eeec3f337ab5d94f289808fb208fb14Revert "Revert "bump libseccomp-golang v0.9.1""deca8e0e31Merge pull request #3700 from Random-Liu/automate-cri-tarball-release889f5f8036Automate CRI tarball release.
Changes from containerd/cri
bab7348fMerge pull request #1304 from Random-Liu/cherrypick-#1266-release-1.2ec7287acSupport local containerd release.
Dependency Changes
Previous release can be found at v1.2.10
- github.com/containerd/cri 40affe7c7402d41618b9791a8cf105ac74ce56d0 -> bab7348fcfcc795e0dda2cc02e8cac6316c85edc
- github.com/opencontainers/runc 3e425f80a8c931f88e6d94a8c831b9d5aa481657 -> d736ef14f0288d6993a1845745d6756cfc9ddd5a
- github.com/seccomp/libseccomp-golang 32f571b70023028bd57d9288c20efbcb237f3ce0 -> v0.9.1