Skip to content

[pull] main from containerd:main - #307

Open
pull[bot] wants to merge 1553 commits into
fahedouch:mainfrom
containerd:main
Open

pull[bot] wants to merge 1553 commits into
fahedouch:mainfrom
containerd:main

Conversation

@pull

@pull pull Bot commented May 10, 2025 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.1)

Can you help keep this open source service alive? 💖 Please sponsor : )

@pull pull Bot added the ⤵️ pull label May 10, 2025
AkihiroSuda and others added 29 commits August 2, 2026 03:52
…cker/login-action-4.6.0

build(deps): bump docker/login-action from 4.5.1 to 4.6.0
fix: suppress spurious hostsstore NotFound warning on container removal
….com/docker/go-connections-0.8.1

build(deps): bump github.com/docker/go-connections from 0.8.0 to 0.8.1
feat(network): support --aux-address on network create
…-matches-all-tags

fix: image ls with a bare repository name should match all tags
pkg/identifiers had no test coverage, though ValidateDockerCompat gates
container, volume, and network names across the codebase. Add table-driven
tests for the accepted charset, the Docker-compatible two-character minimum,
leading-separator and invalid-character rejection, and the empty case,
asserting both the message and the wrapped errdefs.ErrInvalidArgument.

Signed-off-by: Nikolaus Schuetz <nikolauspschuetz@gmail.com>
…atedockercompat

pkg/identifiers: add tests for ValidateDockerCompat
events: rename Status field to Action to match Docker v29
Signed-off-by: ningmingxiao <ning.mingxiao@zte.com.cn>
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
Signed-off-by: ningmingxiao <ning.mingxiao@zte.com.cn>
Make the default `nerdctl images` output match Docker v29: a collapsed
view with IMAGE, ID, DISK USAGE, CONTENT SIZE and EXTRA columns, an
"In Use" (U) indicator, and <untagged> for dangling images.
Multi-platform images are collapsed into a single row with aggregated
disk and content size. Like Docker, the "In Use" legend is only printed
when the output is a terminal, so piped and redirected output stays
clean, and rows are ordered by image reference with untagged images
last rather than by creation time.

In-use is resolved by image target digest, the way Docker matches
containers to images, so every reference to a used target is flagged,
not only the one the container was created from.

The new view is used only for the bare command. Passing --format,
--quiet, --no-trunc, --digests or --names falls back to the legacy table
(REPOSITORY, TAG, IMAGE ID, CREATED, PLATFORM, SIZE, BLOB SIZE), so
existing scripts and templates keep working, including their
creation-time ordering. This mirrors Docker's own shouldUseTree
fallback.

Since the default output now matches Docker, the images tests also run
against the Docker target; only the nerdctl-specific --names subtest
stays gated. Tests that assert on the default `images` output for
untagged images (image prune/remove and build-without-tag) are updated
to expect <untagged>.

The expanded per-platform `--tree` view is left for a follow-up.

Closes #5027

Signed-off-by: Eugene Kalinin <e.v.kalinin@gmail.com>
Bumps the docker group with 2 updates: [github.com/docker/cli](https://github.com/docker/cli) and [github.com/moby/moby/v2](https://github.com/moby/moby).


Updates `github.com/docker/cli` from 29.6.2+incompatible to 29.7.1+incompatible
- [Commits](docker/cli@v29.6.2...v29.7.1)

Updates `github.com/moby/moby/v2` from 2.0.0-beta.19 to 2.0.0-beta.21
- [Release notes](https://github.com/moby/moby/releases)
- [Commits](moby/moby@v2.0.0-beta.19...v2.0.0-beta.21)

---
updated-dependencies:
- dependency-name: github.com/docker/cli
  dependency-version: 29.7.1+incompatible
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: docker
- dependency-name: github.com/moby/moby/v2
  dependency-version: 2.0.0-beta.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: docker
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/compose-spec/compose-go/v2](https://github.com/compose-spec/compose-go) from 2.13.0 to 2.14.0.
- [Release notes](https://github.com/compose-spec/compose-go/releases)
- [Commits](compose-spec/compose-go@v2.13.0...v2.14.0)

---
updated-dependencies:
- dependency-name: github.com/compose-spec/compose-go/v2
  dependency-version: 2.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
….com/compose-spec/compose-go/v2-2.14.0

build(deps): bump github.com/compose-spec/compose-go/v2 from 2.13.0 to 2.14.0
…-195c575c6f

build(deps): bump the docker group with 2 updates
feature: support to print snapshot info for container
feat(image): adopt Docker v29 output for images list
Signed-off-by: Subota Ivan <73706465+subotac@users.noreply.github.com>
host-local's IPAM range has no ipRange field, so `network create --ip-range`
was writing a property the plugin ignores into the on-disk conflist. Drop it
and instead recompute the range CIDR from rangeStart/rangeEnd when reporting
IPRange in `network inspect`, which is the only place the value was read back.

Fixes #5068

Signed-off-by: Mayur Das <mayur.das@neevcloud.com>
feature: support to print snapshot info for image
Bumps [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) from 0.6.1 to 0.6.2.
- [Release notes](https://github.com/zizmorcore/zizmor-action/releases)
- [Commits](zizmorcore/zizmor-action@6fc4b00...3dc1ecc)

---
updated-dependencies:
- dependency-name: zizmorcore/zizmor-action
  dependency-version: 0.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Migrate TestComposePushAndPullWithCosignVerify from testutil.NewBase to
nerdtest.Setup, the last remaining file in the nerdtest migration (#4613).
Uses nerdtest.RegistryWithNoAuth and nerdtest.GenerateCosignKeyPair, and
WithPseudoTTY in place of the unbuffer helper for the tty runs.

Signed-off-by: Ogulcan Aydogan <ogulcanaydogan@gmail.com>
Signed-off-by: ningmingxiao <ning.mingxiao@zte.com.cn>
Parse() appends the standard HTTPS port to the registry address, but the
containerd authorizer calls the credentials callback with the request URL
host, which omits the default port (or uses the registry-1.docker.io alias
for Docker Hub). The strict equality check then fails and login aborts.

Replace the strict equality check with an equivalence check that accepts
the same hostname with the default port omitted, and the Docker Hub
index.docker.io/registry-1.docker.io alias pair. Callback hosts with an
explicit non-standard port must still match exactly.

Fixes #3992
Refs #3245

Signed-off-by: rainwu <xianyuwu@foxmail.com>
Bumps [github.com/rootless-containers/rootlesskit/v3](https://github.com/rootless-containers/rootlesskit) from 3.0.2 to 3.1.0.
- [Release notes](https://github.com/rootless-containers/rootlesskit/releases)
- [Commits](rootless-containers/rootlesskit@v3.0.2...v3.1.0)

---
updated-dependencies:
- dependency-name: github.com/rootless-containers/rootlesskit/v3
  dependency-version: 3.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/klauspost/compress](https://github.com/klauspost/compress) from 1.19.1 to 1.19.2.
- [Release notes](https://github.com/klauspost/compress/releases)
- [Commits](klauspost/compress@v1.19.1...v1.19.2)

---
updated-dependencies:
- dependency-name: github.com/klauspost/compress
  dependency-version: 1.19.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
dependabot Bot and others added 30 commits September 28, 2026 22:32
Bumps [github.com/containerd/nydus-snapshotter](https://github.com/containerd/nydus-snapshotter) from 0.15.16 to 0.16.0.
- [Release notes](https://github.com/containerd/nydus-snapshotter/releases)
- [Commits](containerd/nydus-snapshotter@v0.15.16...v0.16.0)

---
updated-dependencies:
- dependency-name: github.com/containerd/nydus-snapshotter
  dependency-version: 0.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Compose expanded every devices entry to source:target:permissions, so a CDI qualified name reached nerdctl run as a malformed host path and the container failed to create.

Signed-off-by: Adam Clettborn <a.clettborn@gmail.com>
Signed-off-by: Immanuel Tikhonov <pchpr.00@list.ru>
….com/containerd/containerd/v2-2.4.1

build(deps): bump github.com/containerd/containerd/v2 from 2.4.0 to 2.4.1
GNU tar 1.30-13.el8_10 (AlmaLinux 8, released 2026-09-18) aborts with
"Cannot getcwd: No such file or directory" when its working directory
is under /proc/<pid>/root of a container, as the path is unreachable
from the host mount namespace (the kernel returns "(unreachable)/...",
and glibc turns it into ENOENT).

The regression comes from the combination of two upstream tar commits
as backported to RHEL/AlmaLinux 8's tar 1.30:

- 56fb4a96 ("chdir_id refactoring"), backported in 1.30-12 as part of
  the CVE-2025-45582 fix, introduced grow_wd(). Upstream initializes
  wd[0].abspath lazily (NULL), but the 1.30 backport keeps calling
  xgetcwd() eagerly and fails fatally on error.

- 1b91f5f6 ("Draft patch for openat2 changes vs --one-top-level"),
  backported in 1.30-13, adds an unconditional
  `chdir_do (chdir_arg (".", ...), false)` to name_init(), so
  grow_wd() (and thus getcwd) is now reached on every invocation,
  not only when -C is specified.

AlmaLinux 8 went from 1.30-11 directly to 1.30-13.
Upstream tar is not affected (getcwd is lazy there), and neither commit
is in an upstream release as of v1.35.

Using `-C <dir>` keeps the tar process's working directory on the host
while tar opens the directory by itself.

As the tar process no longer chdirs into the extraction directory, an
inaccessible destination is now checked with access(2) beforehand, so
that it is still reported as ErrTargetIsReadOnly.

Fixes #5237 (the `nerdctl cp` part)

Assisted-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
….com/containerd/accelerated-container-image-1.4.5

build(deps): bump github.com/containerd/accelerated-container-image from 1.4.4 to 1.4.5
Pass cgroup_parent and cgroup through to nerdctl run as --cgroup-parent and --cgroupns, which compose previously ignored.

Signed-off-by: Adam Clettborn <a.clettborn@gmail.com>
….com/containerd/nydus-snapshotter-0.16.0

build(deps): bump github.com/containerd/nydus-snapshotter from 0.15.16 to 0.16.0
cp: pass the directory to tar via -C instead of the working directory
Bumps the docker group with 1 update in the / directory: [github.com/docker/cli](https://github.com/docker/cli).


Updates `github.com/docker/cli` from 29.8.1+incompatible to 29.8.2+incompatible
- [Commits](docker/cli@v29.8.1...v29.8.2)

---
updated-dependencies:
- dependency-name: github.com/docker/cli
  dependency-version: 29.8.2+incompatible
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: docker
...

Signed-off-by: dependabot[bot] <support@github.com>
…-9474f3c817

build(deps): bump github.com/docker/cli from 29.8.1+incompatible to 29.8.2+incompatible in the docker group across 1 directory
….com/klauspost/compress-1.20.1

build(deps): bump github.com/klauspost/compress from 1.20.0 to 1.20.1
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
Disable the new revive rule `multiline-if-init` (revive v1.17), which has 34
occurrences in the tree.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
fix(compose): pass CDI device names through unchanged
fix(compose): support cgroup_parent and cgroup service fields
…appings

fix(netutil): enable portMappings and dns capabilities in default nat CNI plugin (#5157)
update containerd (2.4.1), runc (1.5.2), BuildKit (0.33.1), and CI deps
Bumps [containerd/project-checks](https://github.com/containerd/project-checks) from 1.2.2 to 1.2.3.
- [Release notes](https://github.com/containerd/project-checks/releases)
- [Commits](containerd/project-checks@d7751f3...9d887fa)

---
updated-dependencies:
- dependency-name: containerd/project-checks
  dependency-version: 1.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
…ntainerd/project-checks-1.2.3

build(deps): bump containerd/project-checks from 1.2.2 to 1.2.3
… images

nerdctl rmi -f on an image still used by a running container renames
it before deleting the original, so containerd keeps the layers alive
instead of garbage-collecting them. That dangling ref was always
renamed to the literal string ":". Since containerd's image store
requires unique names, force-removing a second running image's image
in a separate invocation made its own rename fail with
"image \":\": already exists", aborting the command.

Name the dangling ref after its content digest (":<digest>") instead,
so each kept-alive ref gets a distinct name. Tolerate AlreadyExists on
the create call: if two different tags share the same digest and are
both force-removed as running images, the second create legitimately
no-ops (the digest is already pinned). The one other consumer that
special-cased the exact ":" name (pkg/imgutil filtering, used by
--filter reference=... to skip unparsable dangling names without
erroring) is updated to match on the ":" prefix instead.

Fixes #4109

Signed-off-by: Ogulcan Aydogan <ogulcanaydogan@gmail.com>
…lision

fix(image): avoid dangling-ref name collision on rmi -f for running images
Bumps the docker group with 2 updates in the / directory: [github.com/moby/moby/client](https://github.com/moby/moby) and [github.com/moby/moby/v2](https://github.com/moby/moby).


Updates `github.com/moby/moby/client` from 0.6.0 to 0.6.1
- [Release notes](https://github.com/moby/moby/releases)
- [Changelog](https://github.com/moby/moby/blob/v0.6.1/CHANGELOG.md)
- [Commits](moby/moby@v0.6.0...v0.6.1)

Updates `github.com/moby/moby/v2` from 2.0.0-beta.24 to 2.0.0-beta.25
- [Release notes](https://github.com/moby/moby/releases)
- [Commits](moby/moby@v2.0.0-beta.24...v2.0.0-beta.25)

---
updated-dependencies:
- dependency-name: github.com/moby/moby/client
  dependency-version: 0.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: docker
- dependency-name: github.com/moby/moby/v2
  dependency-version: 2.0.0-beta.25
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: docker
...

Signed-off-by: dependabot[bot] <support@github.com>
…-eb72446c24

build(deps): bump the docker group across 1 directory with 2 updates
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.