@@ -6,12 +6,31 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
66
77## [ Unreleased 1.1.z]
88
9+ ## [ 1.1.15] - 2024-10-07
10+
11+ > How, dear sir, did you cross the flood? By not stopping, friend, and by not
12+ > straining I crossed the flood.
13+
914### Fixed
1015
16+ * The ` -ENOSYS ` seccomp stub is now always generated for the native
17+ architecture that ` runc ` is running on. This is needed to work around some
18+ arguably specification-incompliant behaviour from Docker on architectures
19+ such as ppc64le, where the allowed architecture list is set to ` null ` . This
20+ ensures that we always generate at least one ` -ENOSYS ` stub for the native
21+ architecture even with these weird configs. (#4391 )
1122 * On a system with older kernel, reading ` /proc/self/mountinfo ` may skip some
1223 entries, as a consequence runc may not properly set mount propagation,
1324 causing container mounts leak onto the host mount namespace. (#2404 , #4425 )
1425
26+ ### Removed
27+
28+ * In order to fix performance issues in the "lightweight" bindfd protection
29+ against [ CVE-2019 -5736] , the temporary ` ro ` bind-mount of ` /proc/self/exe `
30+ has been removed. runc now creates a binary copy in all cases. (#4392 , #2532 )
31+
32+ [ CVE-2019-5736 ] : https://www.openwall.com/lists/oss-security/2019/02/11/2
33+
1534## [ 1.1.14] - 2024-09-03
1635
1736> 年を取っていいことは、驚かなくなることね。
@@ -34,8 +53,6 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
3453 (#4370 , #4382 )
3554 * rootfs: consolidate mountpoint creation logic. (#4359 )
3655
37- ### Changed
38-
3956## [ 1.1.13] - 2024-06-13
4057
4158> There is no certainty in the world. This is the only certainty I have.
@@ -568,7 +585,8 @@ implementation (libcontainer) is *not* covered by this policy.
568585[ 1.0.1 ] : https://github.com/opencontainers/runc/compare/v1.0.0...v1.0.1
569586
570587<!-- 1.1.z patch releases -->
571- [ Unreleased 1.1.z ] : https://github.com/opencontainers/runc/compare/v1.1.14...release-1.1
588+ [ Unreleased 1.1.z ] : https://github.com/opencontainers/runc/compare/v1.1.15...release-1.1
589+ [ 1.1.15 ] : https://github.com/opencontainers/runc/compare/v1.1.14...v1.1.15
572590[ 1.1.14 ] : https://github.com/opencontainers/runc/compare/v1.1.13...v1.1.14
573591[ 1.1.13 ] : https://github.com/opencontainers/runc/compare/v1.1.12...v1.1.13
574592[ 1.1.12 ] : https://github.com/opencontainers/runc/compare/v1.1.11...v1.1.12
0 commit comments