Skip to content

build(deps): Bump github.com/opencontainers/runc from 1.5.1 to 1.5.2 - #2120

Open
dependabot[bot] wants to merge 1 commit into
release-1.20from
dependabot/go_modules/release-1.20/github.com/opencontainers/runc-1.5.2
Open

dependabot[bot] wants to merge 1 commit into
release-1.20from
dependabot/go_modules/release-1.20/github.com/opencontainers/runc-1.5.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/opencontainers/runc from 1.5.1 to 1.5.2.

Release notes

Sourced from github.com/opencontainers/runc's releases.

runc v1.5.2 -- "Всё сбудется, стоит только расхотеть!"

This is the second patch release in the 1.5.z release series of runc, which primarily includes a workaround for a Linux kernel bug causing random runc crashes when using cgroup v2, and other fixes.

Fixed

  • runc exec -p with a process.json lacking env now sets HOME again (a regression in runc 1.3.0). (#5265, #5266, #5459)
  • Worked around a Linux kernel bug (present since kernel v6.17, fixed in v7.2) which caused the kernel to write past the end of the structure provided by userspace (runc). This resulted in memory corruption inside runc (manifesting as random crashes) when configuring device rules on cgroup v2 systems. (#5403, #5428)
  • runc exec --cgroup (and the equivalent libcontainer Process.SubCgroupPaths API) no longer accepts a sub-cgroup path that escapes the container's cgroup into a sibling cgroup sharing the same name prefix. Note that using --cgroup requires the same privileges as running runc exec itself, so this is a correctness rather than a security fix. (#5403, #5457)
  • Fixed a missing O_CLOEXEC when opening the cgroup v2 directory to set up device rules. (#5403, #5428)
  • Some long-standing file-descriptor leaks on the eBPF devices cgroups were fixed. (#5403, #5428)
  • When rootfsPropagation is set to rslave, the rootfs parent mount is no longer made private before pivoting into the rootfs, so unmount/remount events on host mountpoints under the rootfs are now propagated to the running container. (#5192, #5200, #5458)
  • runc no longer misdetects a non-initial user namespace as the initial one when that namespace has a full identity ID mapping (0 0 4294967295), as used by systemd >= 260 units with PrivateUsers=full. Previously this made runc skip its user namespace code paths, so starting a container in such a unit failed with bpf_prog_query(BPF_CGROUP_DEVICE) failed: operation not permitted. (#5396, #5411, #5451, moby/sys#239)
  • Fixed a runc init panic (SIGABRT) on the error path, caused by SELinux labels being reset after the cached libpathrs procfs handle was already closed. This is fixed both by not resetting the labels on the init error path, and by updating to libpathrs v0.2.6, which now handles a closed procfs handle gracefully. (#5438, #5439, #5442, #5448, #5449, #5467, #5469)
  • Fixed various issues when the libseccomp version runc is run with differs from the one it was compiled against (e.g. built with libseccomp >= 2.6.0 and run with an older one), by updating to libseccomp-golang v0.12.0. This also supersedes the SECCOMP_FILTER_FLAG_WAIT_KILLABLE_RECV workaround added in runc 1.5.1. (#5436, #5461)
  • The libseccomp library statically linked into release binaries is now built with optimizations enabled (the default -g -O2 CFLAGS); previously it was built unoptimized. (#5464, #5465)

... (truncated)

Changelog

Sourced from github.com/opencontainers/runc's changelog.

[1.5.2] - 2026-09-25

Всё сбудется, стоит только расхотеть!

Fixed

  • runc exec -p with a process.json lacking env now sets HOME again (a regression in runc 1.3.0). (#5265, #5266, #5459)
  • Worked around a Linux kernel bug (present since kernel v6.17, fixed in v7.2) which caused the kernel to write past the end of the structure provided by userspace (runc). This resulted in memory corruption inside runc (manifesting as random crashes) when configuring device rules on cgroup v2 systems. (#5403, #5428)
  • runc exec --cgroup (and the equivalent libcontainer Process.SubCgroupPaths API) no longer accepts a sub-cgroup path that escapes the container's cgroup into a sibling cgroup sharing the same name prefix. Note that using --cgroup requires the same privileges as running runc exec itself, so this is a correctness rather than a security fix. (#5403, #5457)
  • Fixed a missing O_CLOEXEC when opening the cgroup v2 directory to set up device rules. (#5403, #5428)
  • Some long-standing file-descriptor leaks on the eBPF devices cgroups were fixed. (#5403, #5428)
  • When rootfsPropagation is set to rslave, the rootfs parent mount is no longer made private before pivoting into the rootfs, so unmount/remount events on host mountpoints under the rootfs are now propagated to the running container. (#5192, #5200, #5458)
  • runc no longer misdetects a non-initial user namespace as the initial one when that namespace has a full identity ID mapping (0 0 4294967295), as used by systemd >= 260 units with PrivateUsers=full. Previously this made runc skip its user namespace code paths, so starting a container in such a unit failed with bpf_prog_query(BPF_CGROUP_DEVICE) failed: operation not permitted. (#5396, #5411, #5451, moby/sys#239)
  • Fixed a runc init panic (SIGABRT) on the error path, caused by SELinux labels being reset after the cached libpathrs procfs handle was already closed. This is fixed both by not resetting the labels on the init error path, and by updating to libpathrs v0.2.6, which now handles a closed procfs handle gracefully. (#5438, #5439, #5442, #5448, #5449, #5467, #5469)
  • Fixed various issues when the libseccomp version runc is run with differs from the one it was compiled against (e.g. built with libseccomp >= 2.6.0 and run with an older one), by updating to libseccomp-golang v0.12.0. This also supersedes the SECCOMP_FILTER_FLAG_WAIT_KILLABLE_RECV workaround added in runc 1.5.1. (#5436, #5461)
  • The libseccomp library statically linked into release binaries is now built with optimizations enabled (the default -g -O2 CFLAGS); previously it was built unoptimized. (#5464, #5465)

Changed

  • Switched to opencontainers/cgroups v0.1.0, which no longer uses the

... (truncated)

Commits
  • 29dd3dc VERSION: release v1.5.2
  • 59e1324 Merge pull request #5490 from kolyshkin/1.5-5487
  • 7bb23c5 CHANGELOG: Mention eBPF fd leaks are fixed now
  • d55c39d libct: Don't exclude BPF fds from leaks
  • f685154 Merge pull request #5465 from kolyshkin/1.5-5464
  • 80cc799 script: do not modify CFLAGS in set_cross_vars
  • 6dd4959 Merge pull request #5458 from kolyshkin/1.5-5200
  • ec3b692 fix(libcontainer): bats test for rootfs propagation
  • 2bf8dc5 fix(libcontainer): preserve rootfs slave propagation
  • a76b3b7 Merge pull request #5457 from kolyshkin/1.5-5403
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/opencontainers/runc](https://github.com/opencontainers/runc) from 1.5.1 to 1.5.2.
- [Release notes](https://github.com/opencontainers/runc/releases)
- [Changelog](https://github.com/opencontainers/runc/blob/v1.5.2/CHANGELOG.md)
- [Commits](opencontainers/runc@v1.5.1...v1.5.2)

---
updated-dependencies:
- dependency-name: github.com/opencontainers/runc
  dependency-version: 1.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Issue/PR Pull about a dependency file maintenance Issue/PR to create or address a team project management need labels Oct 4, 2026
@copy-pr-bot

copy-pr-bot Bot commented Oct 4, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Issue/PR Pull about a dependency file maintenance Issue/PR to create or address a team project management need

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants