Skip to content

Tags: xigang/runc

Tags

v1.0.0-rc5

Toggle v1.0.0-rc5's commit message

Verified

This tag was signed with the committer’s verified signature.
cyphar Aleksa Sarai
v1.0.0~rc5

This is planned to be the final -rc release of runc. While we really
haven't followed the rules for release candidates (with huge features
introduced each release, and with massive gaps between releases) the
hope is that once we've release 1.0.0 we will be much more liberal with
releases in future. Let's see how that pans out. :P

Features:

+ Support cgroups in rootless containers. This is a continuation of the
  previous work done, and allows for users that have specialised setups
  (such as having the LXC pam_cg.so module set up) to use cgroups with
  rootless containers. opencontainers#1540
+ Add support for newuidmap and newgidmap with rootless containers.
  This is a continuation of some previous work, and allows users that
  have /etc/sub{uid,gid} configured to use the shadow-utils setuid
  helpers. Note that this support doesn't restrict users that don't want
  to use setuid binaries at all. opencontainers#1529
+ runc will now use a chroot when mount namespaces aren't provided in
  the config.json. While chroot does have its (many) downsides, this
  does allow for specialised configurations to work properly. opencontainers#1702
+ Expose annotations to hooks, so that the hook can have more direct
  information about the container it is being run against. opencontainers#1687
+ Add "runc exec --additional-gids" support. opencontainers#1608
+ Allow more signals to be sent with "runc kill" than are defined by
  Go's syscall package. opencontainers#1706
+ Emit an error if users try to use MS_PRIVATE with --no-pivot, as that
  is simply not safe. opencontainers#1606
+ Add support for "unbindable" and "runbindable" as rootfs propagation.
  opencontainers#1655
+ Implement intelrdt support in runc. opencontainers#1279 opencontainers#1590
+ Add support for lazy migration with CRIU. This includes the addition
  of "runc checkpoint httpd" which acts as a remote pagefault request
  server. opencontainers#1541
+ Add MIPS support. opencontainers#1475

Fixes:

* Delay seccomp application as late as possible, to reduce the syscall
  footprint of runc on profiles. opencontainers#1569
* Fix --read-only containers with user namespaces, which would
  previously fail under Docker because of privilege problems when trying
  to do the read-only remount. opencontainers#1572
* Switch away from stateDirFd entirely. This is an improvement over the
  protections we added for CVE-2016-9962, and protects against many
  other possible container escape bugs. opencontainers#1570
* Handle races between "runc start" and "runc delete" over the exec FIFO
  correctly, and avoid blocking "runc start" indefinitely. opencontainers#1698
* Correctly generate seccomp profiles that place requirements on syscall
  arguments, as well as multi-argument restrictions. opencontainers#1616 opencontainers#1424
* Prospective patch for remounting of old-root during pivot_root. This
  is intended to solve one of the many "mount leak" bugs that have been
  popping up recently -- caused by lots of container churn and host
  mounts being pinned during container setup. opencontainers#1500
* Fix "runc exec" on big-endian architectures. opencontainers#1727
* Correct systemd slice expansion to work with cAdvisor. opencontainers#1722
* Fix races against systemd cgroup scope creation. opencontainers#1683
* Do not wait for signalled processes if libcontainer is running in a
  process that is a subreaper. opencontainers#1678
* Remove dependency on libapparmor entirely, and just use
  /proc/$pid/attr directly. opencontainers#1675
* Improvements to our integration tests. opencontainers#1661 opencontainers#1629 opencontainers#1528
* Handle systemd's quirky CPUQuotaPerSecUSec handling in
  fractions-of-a-percent edge-cases. opencontainers#1651
* Remove docker/docker import in runc by moving the package to runc.
  opencontainers#1644
* Switch from docker's pkg/symlink to cyphar/filepath-securejoin. opencontainers#1622
* Enable integration and unit tests on arm64. opencontainers#1642 opencontainers#1640
* Add /proc/scsi to masked paths (mirror of Docker's CVE-2017-16539).
  opencontainers#1641
* Add several tests for specconv. opencontainers#1626 opencontainers#1619
* Add more extensive tests for terminal handling. opencontainers#1357
* Always write freezer state during retry-loop, to avoid an indefinite
  hang when new tasks are spawned in the container. opencontainers#1610
* Create cwd when it doesn't exist in the container. opencontainers#1604
* Set initial console size based on process spec, to avoid SIGWINCH
  races where initial console size is completely wrong. opencontainers#1275
* Small fixes for static builds. opencontainers#1579 opencontainers#1577
* Use epoll for PTY IO, to avoid issues with systemd's SAK protections.
  opencontainers#1455
* Update state.json after a "runc update". opencontainers#1558
* Switch to umoci's release scripts, to use a more "standardised" and
  distribution-friendly release scheme. Several makefile-fixes included
  as well. opencontainers#1554 opencontainers#1542 opencontainers#1555
* Reap "runc:[1:CHILD]" to avoid intermediate zombies building up. opencontainers#1506
* Use CRIU's RPC to check the version. opencontainers#1535
* Always save own namespace paths rather than the path given during
  start-up, to avoid issues where the path disappears afterwards. opencontainers#1477
* Fix that we incorrectly set the owners of devices. This is still (subtly)
  broken in user namespaces, but will be fixed in a future version. opencontainers#1743

* Lots of other miscellaneous fixes and cleanups, many of which were
  written by first-time contributors. Thanks for contributing, and
  welcome to the project! opencontainers#1729 opencontainers#1724 opencontainers#1695 opencontainers#1685 opencontainers#1703 opencontainers#1699 opencontainers#1682
  opencontainers#1665 opencontainers#1667 opencontainers#1669 opencontainers#1654 opencontainers#1664 opencontainers#1660 opencontainers#1645 opencontainers#1640 opencontainers#1621 opencontainers#1607 opencontainers#1206
  opencontainers#1615 opencontainers#1614 opencontainers#1453 opencontainers#1613 opencontainers#1600 opencontainers#1599 opencontainers#1598 opencontainers#1597 opencontainers#1593 opencontainers#1586 opencontainers#1588
  opencontainers#1587 opencontainers#1589 opencontainers#1575 opencontainers#1578 opencontainers#1573 opencontainers#1561 opencontainers#1560 opencontainers#1559 opencontainers#1556 opencontainers#1551 opencontainers#1553
  opencontainers#1548 opencontainers#1544 opencontainers#1545 opencontainers#1537

Removals:
- Andrej Vagin stepped down as a maintainer. Thanks for all of your hard
 work Andrej, and have fun working on your other projects! opencontainers#1543

Thanks to all of the contributors that made this release possible:

 * Adrian Reber <areber@redhat.com>
 * Akihiro Suda <suda.akihiro@lab.ntt.co.jp>
 * Aleksa Sarai <asarai@suse.de>
 * Alex Fang <littlelightlittlefire@gmail.com>
 * Allen Sun <allensun.shl@alibaba-inc.com>
 * Andrei Vagin <avagin@openvz.org>
 * Antonio Murdaca <runcom@redhat.com>
 * Bin Lu <bin.lu@arm.com>
 * Danail Branekov <danail.branekov@sap.com>
 * Daniel, Dao Quang Minh <dqminh89@gmail.com>
 * Ed King <eking@pivotal.io>
 * Euan Kemp <euan.kemp@coreos.com>
 * Giuseppe Scrivano <gscrivan@redhat.com>
 * Jianyong Wu <jianyong.wu@arm.com>
 * Kenfe-Mickael Laventure <mickael.laventure@gmail.com>
 * Konstantinos Karampogias <konstantinos.karampogias@swisscom.com>
 * leitwolf7 <leitwolf@wolke7.net>
 * Lorenzo Fontana <lo@linux.com>
 * Ma Shimiao <mashimiao.fnst@cn.fujitsu.com>
 * Matthew Heon <mheon@redhat.com>
 * Michael Crosby <crosbymichael@gmail.com>
 * Mrunal Patel <mrunal@me.com>
 * Nikolas Sepos <nikolas.sepos@gmail.com>
 * Peter Morjan <peter.morjan@de.ibm.com>
 * Petros Angelatos <petrosagg@gmail.com>
 * Qiang Huang <h.huangqiang@huawei.com>
 * ravisantoshgudimetla <ravisantoshgudimetla@gmail.com>
 * s7v7nislands <s7v7nislands@gmail.com>
 * Sebastien Boeuf <sebastien.boeuf@intel.com>
 * Seth Jennings <sjenning@redhat.com>
 * Steven Hartland <steven.hartland@multiplay.co.uk>
 * Sumit Sanghrajka <sumit.sanghrajka@gmail.com>
 * Taeung Song <treeze.taeung@gmail.com>
 * Thomas Hipp <thipp@suse.de>
 * Tobias Klauser <tklauser@distanz.ch>
 * Tom Godkin <tgodkin@pivotal.io>
 * Tycho Andersen <tycho@docker.com>
 * Valentin Kulesh <valentin.kulesh@virtuozzo.com>
 * vikaschoudhary16 <choudharyvikas16@gmail.com>
 * Vincent Demeester <vincent@sbr.pm>
 * Vladimir Stefanovic <vladimir.stefanovic@imgtec.com>
 * vsoch <vsochat@stanford.edu>
 * Will Martin <wmartin@pivotal.io>
 * W. Trevor King <wking@tremily.us>
 * Xiaochen Shen <xiaochen.shen@intel.com>
 * ynirk <julien.lavesque@gmail.com>
 * Yong Tang <yong.tang.github@outlook.com>
 * Yuanhong Peng <pengyuanhong@huawei.com>
 * yupeng <yu.peng36@zte.com.cn>

Signed-off-by: Aleksa Sarai <asarai@suse.de>

v1.0.0-rc4

Toggle v1.0.0-rc4's commit message

Verified

This tag was signed with the committer’s verified signature.
cyphar Aleksa Sarai
v1.0.0~rc4

Features:

+ runc now supports v1.0.0 of the OCI runtime specification. opencontainers#1527
+ Rootless containers support has been released. The current state of
  this feature is that it only supports single-{uid,gid} mappings as an
  unprivileged user, and cgroups are completely unsupported. Work is
  being done to improve this. opencontainers#774
+ Rather than relying on CRIU version nnumbers, actually check if the
  system supports pre-dumping. opencontainers#1371
+ Allow the PIDs cgroup limit to be updated. opencontainers#1423
+ Add support for checkpoint/restore of containers with orphaned PTYs
  (which is effectively all containers with terminal=true). opencontainers#1355
+ Permit prestart hooks to modify the cgroup configuration of a
  container. opencontainers#1239
+ Add support for a wide variety of mount options. opencontainers#1460
+ Expose memory.use_hierarchy in MemoryStats. opencontainers#1378

Fixes:

* Fix incorrect handling of systems without the freezer cgroup. opencontainers#1387
* Many, many changes to switch away from Go's "syscall" stdlib to
  "golang.org/x/sys/unix". opencontainers#1394 opencontainers#1398 opencontainers#1442 opencontainers#1464 opencontainers#1467 opencontainers#1470 opencontainers#1474
  opencontainers#1478 opencontainers#1491 opencontainers#1482 opencontainers#1504 opencontainers#1519 opencontainers#1530
* Set cgroup resources when restoring a container. opencontainers#1399
* Switch back to using /sbin as the installation directory. opencontainers#1406
* Remove the arbitrary container ID length restriction. opencontainers#1435
* Make container force deletion ignore non-existent containers. opencontainers#1451
* Improve handling of arbitrary cgroup mount locations when populating
  cpuset. opencontainers#1372
* Make the SaneTerminal interface public. opencontainers#1479
* Fix cases where runc would report a container to be in a "Running"
  state if the init was a zombie or dead. opencontainers#1489
* Do not set supplementary groups for numeric users. opencontainers#1450
* Fix various issues with the "owner" field in runc-list. opencontainers#1516
* Many other miscellaneous fixes, some of which were made by first-time
  contributors. Thanks, and welcome to the project! opencontainers#1406 opencontainers#1400 opencontainers#1365
  opencontainers#1396 opencontainers#1402 opencontainers#1414 opencontainers#1412 opencontainers#1408 opencontainers#1418 opencontainers#1425 opencontainers#1428 opencontainers#1436 opencontainers#1433 opencontainers#1438
  opencontainers#1410 opencontainers#1447 opencontainers#1388 opencontainers#1484 opencontainers#1481 opencontainers#1496 opencontainers#1245 opencontainers#1524 opencontainers#1534 opencontainers#1526 opencontainers#1533

Removals:

- Remove any semblance of non-Linux support. opencontainers#1502
- We no longer use shfmt for testing. opencontainers#1510

Thanks to all of the contributors that made this release possible:

* Adrian Reber <areber@redhat.com>
* Aleksa Sarai <asarai@suse.de>
* Andrei Vagin <avagin@virtuozzo.com>
* Antonio Murdaca <runcom@redhat.com>
* chchliang <chen.chuanliang@zte.com.cn>
* Christy Perez <christy@linux.vnet.ibm.com>
* Craig Furman <cfurman@pivotal.io>
* CuiHaozhi <cuihz@wise2c.com>
* Daniel, Dao Quang Minh <dqminh89@gmail.com>
* Derek Carr <decarr@redhat.com>
* Harshal Patil <harshal.patil@in.ibm.com>
* Jonh Wendell <jonh.wendell@redhat.com>
* Justin Cormack <justin.cormack@docker.com>
* Kang Liang <kangliang424@gmail.com>
* Kenfe-Mickael Laventure <mickael.laventure@gmail.com>
* Konstantinos Karampogias <konstantinos.karampogias@swisscom.com>
* Ma Shimiao <mashimiao.fnst@cn.fujitsu.com>
* Michael Crosby <crosbymichael@gmail.com>
* Mrunal Patel <mrunalp@gmail.com>
* Qiang Huang <h.huangqiang@huawei.com>
* Steven Hartland <steven.hartland@multiplay.co.uk>
* Tim Potter <tpot@hpe.com>
* Tobias Klauser <tklauser@distanz.ch>
* Valentin Rothberg <vrothberg@suse.com>
* Vincent Batts <vbatts@redhat.com>
* Wentao Zhang <zhangwentao234@huawei.com>
* Will Martin <wmartin@pivotal.io>
* W. Trevor King <wking@tremily.us>
* yangshukui <yangshukui@huawei.com>
* Zhang Wei <zhangwei555@huawei.com>

Vote-Closed: [Wed Aug 9 05:28:38 UTC 2017]
Vote-Results: [+5 -0 /2]

v1.0.0-rc3

Toggle v1.0.0-rc3's commit message

Verified

This tag was signed with the committer’s verified signature.
cyphar Aleksa Sarai
v1.0.0~rc3

Features:

+ Add slice management support to the systemd cgroup driver. Checks are
  done to make sure that systemd supports the feature. opencontainers#1084
+ Support for readonly mount labels. opencontainers#1112
+ Add a tmpcopyup mount extension for tmpfs mounts that are mounted over
  already existing directories, allowing for the contents of a volume to
  be copied up transparently. opencontainers#845
* Switch our pivot_root usage to no longer require temporary
  directories, improving the state of containters running in entirely
  readonly contexts. opencontainers#1125 opencontainers#1148
+ Allow updating of rt_period_us and rt_runtime_us in cpuacct cgroup.
+ Reimplement console handling to use AF_UNIX sockets such that the
  console is created inside the container's (namespaced) devpts
  instance, solving a wide variety of historical pty bugs with runC.
  opencontainers#1018 opencontainers#1356
* Support overlayfs in mounts. opencontainers#1314
+ Support creating devices with types 'p' and 'u'. opencontainers#1321
+ Add --preserve-fds=N to create and run commands. opencontainers#1320
+ Add pre-dump and parent-path to checkpoint. opencontainers#1001
+ Update to runtime-spec v1.0.0-rc5. opencontainers#1370

Fixes:

* Remove check for binding to /. opencontainers#1090
* Ensure we log to logrus on command errors. opencontainers#1089
* Don't enable kmem limits if they're not specified in the config. opencontainers#1095
* Handle cases where specs.Resources.* members would cause null
  dereferences. opencontainers#1111 opencontainers#1116
* Fix bugs in the GetProcessStartTime implementation. opencontainers#1136
* Make sysctl config validation checks handle network namespaces more
  gracefully. opencontainers#1138 opencontainers#1149
* Guarantee correct namespace creation ordering. This is part of the
  rootless container patchset, and is also required in certain SELinux
  setups. opencontainers#977
* Stop screwing around with '\n' in console output. opencontainers#1146
* Fix cpuset.cpu_exclusive handling. opencontainers#1194
* Sync HookState with the OCI specification. opencontainers#1201
* Split remounting mountpoints and bindmounts, resolving issues with
  mount options being dropped in certain cases. opencontainers#1222
* Fix leftover cgroup directory issue. opencontainers#1196
* Handle config.Devices and config.MaskPaths in checkpoint. opencontainers#1110.
* Don't create combined cgroup subsystem names. opencontainers#1268
* Ignore cgroupv2 mountpoints, fixing issues with systemd v232. opencontainers#1266
* Race condition when synchronising with children and grandchildren in
  nsexec.c. opencontainers#1237
* Fix state checks to no longer depend on _LIBCONTAINER being present in
  the environment, fixing both bugs as well as being part of the
  rootless container patchset. opencontainers#1317
* Fix systemd-notify when using different PID namespaces, and allow
  detach+notify socket. opencontainers#1308
* Don't fchown when inheriting stdio, which is necessary for rootless
  containers in certain scenarios. opencontainers#1354
* Fix cpu.cfs_quota_us being changed when systemd is reloaded. opencontainers#1344
* Add devices to whitelist for LXD, to make runC under LXC/LXD work
  better. opencontainers#1327
* Many improvements to testing. opencontainers#1121 opencontainers#1131 opencontainers#1132 opencontainers#1147

Security:

* Several fixes for CVE-2016-9962. 5d93fed opencontainers#1274

Thanks to all of the contributors that made this release possible:

* Qiang Huang <h.huangqiang@huawei.com>
* Aleksa Sarai <asarai@suse.de>
* Mrunal Patel <mrunalp@gmail.com>
* Michael Crosby <crosbymichael@gmail.com>
* Wang Long <long.wanglong@huawei.com>
* Daniel, Dao Quang Minh <dqminh89@gmail.com>
* rajasec <rajasec79@gmail.com>
* Zhang Wei <zhangwei555@huawei.com>
* Steven Hartland <steven.hartland@multiplay.co.uk>
* Giuseppe Scrivano <gscrivan@redhat.com>
* Shukui Yang <yangshukui@huawei.com>
* Ma Shimiao <mashimiao.fnst@cn.fujitsu.com>
* Daniel Dao <dqminh89@gmail.com>
* CuiHaozhi <cuihaozhi@chinacloud.com.cn>
* Antonio Murdaca <runcom@redhat.com>
* Xianglin Gao <xlgao@zju.edu.cn>
* Lei Jitang <leijitang@huawei.com>
* Justin Cormack <justin.cormack@docker.com>
* Dan Walsh <dwalsh@redhat.com>
* Daniel Martí <mvdan@mvdan.cc>
* Ce Gao <ce.gao@outlook.com>
* allencloud <allen.sun@daocloud.io>
* Alexander Morozov <lk4d4math@gmail.com>
* yupeng <yu.peng36@zte.com.cn>
* Yuanhong Peng <pengyuanhong@huawei.com>
* Yong Tang <yong.tang.github@outlook.com>
* xuxinkun <xuxinkun@gmail.com>
* Xianlu Bird <xianlubird@gmail.com>
* William Martin <wmartin@pivotal.io>
* Wentao Zhang <zhangwentao234@huawei.com>
* Vivek Goyal <vgoyal@redhat.com>
* Samuel Ortiz <sameo@linux.intel.com>
* rainrambler <wanganyu@outlook.com>
* Mohammad Arab <boynux@gmail.com>
* Michal Rostecki <michal@kinvolk.io>
* Máximo Cuadros <mcuadros@gmail.com>
* Kenfe-Mickael Laventure <mickael.laventure@gmail.com>
* Ian Campbell <ian.campbell@docker.com>
* Harry Zhang <harryz@hyper.sh>
* Fengtu Wang <wangfengtu@huawei.com>
* Eric Paris <eparis@redhat.com>
* Derek Carr <decarr@redhat.com>
* Deng Guangxing <dengguangxing@huawei.com>
* CuiHaozhi <61755280@qq.com>
* Crazykev <crazykev@zju.edu.cn>
* Chris Aniszczyk <caniszczyk@gmail.com>
* Casey Callendrello <c1@caseyc.net>
* Carlton-Semple <carlton.semple@ibm.com>
* Brian Goff <cpuguy83@gmail.com>
* Andrew Vagin <avagin@openvz.org>

v1.0.0-rc2

Toggle v1.0.0-rc2's commit message

Verified

This tag was signed with the committer’s verified signature.
cyphar Aleksa Sarai
runC 1.0.0-rc2

Features:
 + {create,run}: add --no-new-keyring flag so that a new session keyring
   is not created for the container and the calling process's keyring is
   inherited.
 + restore: add --empty-ns flag to tell CRIU to only create a network
   namespace for a container and not populate it (allowing higher levels
   to correctly handle re-creating the network namespace).
 + {create,start}: use a FIFO rather than signals to signal the starting
   of a container. This removes the Go version restriction, and also
   avoids potential issues with Go's signal handling.
 + exec: allow additional groups to be overridden.
 + delete: add --force flag.
 - exec: disable the subreaper option entirely, because the option
   causes many issues with reparenting in the context of containers.
   This is not a complete fix, which is intended to land for -rc3. Using
   the removed option will be silently ignored by runC.
 + {create,run}: add support for masking directories with MaskPaths.
 + delete: allow for the deletion of multiple containers in one cmdline.
 + build: add `make release` for distributions.

Fixes:
 * Major improvements and fixes to CLI handling. Now commands like
   `runc ps` and `runc exec` will act sanely when you're trying to use
   flags that are not meant to be parsed by runC.
 * Set the cp.rt_* cgroup options correctly so that runC running in
   SCHED_RR (realtime) mode can operate properly.
 * Massive improvements to kmem limit detection to ensure that we only
   attempt to change memory.kmem.* if it is safe to do so.
 * Part of a major cleanup of the nsenter code, with more intended to
   land before -rc3.
 * Restored containers now have a start time, which is the time that the
   new container was started (not when the original container was
   started).
 * Fix the default cgroupPath behaviour, so that we actually attach to
   subcgroups of all of the caller's current cgroups (rather than using
   the devices cgroup path for all other cgroups)
 + Support 32bit UIDs on i386 with the setuid32(2) syscall.
 + Add /proc/timer_list to the set of default masked paths.
 - Do not create /dev/fuse by default.
 * Parse cgroupPath correctly if it contains ':'.
 * Add some more debugging information for the test suite, along with
   fixes for race conditions and other issues. In addition, add more
   integration tests for edge conditions.
 * Improve check-config.sh script to handle more cases.
 * Fix incorrect type when setting of net_cls classid.
 * Lots of fixes to help pages and man pages.
 + *: append -dirty to the version if the git repo is unclean.
 * Fix the JSON tags for CpuRt* options.
 * Cleanups to the rootfs setup code.
 * Improve error messages related to SELinux.

Thanks to all of the contributors that made this release possible:

 * Akihiro Suda <suda.akihiro@lab.ntt.co.jp>
 * Aleksa Sarai <asarai@suse.de>
 * Alexander Morozov <lk4d4math@gmail.com>
 * Andrew Vagin <avagin@virtuozzo.com>
 * Ben <ben.gray@bskyb.com>
 * Buddha Prakash <buddhap@google.com>
 * Carl Henrik Lunde <chlunde@ifi.uio.no>
 * Christian Brauner <cbrauner@suse.de>
 * Dam Thomason <ad@mthomason.net>
 * Dan Walsh <dwalsh@redhat.com>
 * Daniel, Dao Quang Minh <dqminh89@gmail.com>
 * Davanum Srinivas <davanum@gmail.com>
 * Euan Kemp <euank@coreos.com>
 * Guilherme Rezende <guilhermebr@gmail.com>
 * Haiyan Meng <hmeng@redhat.com>
 * Hushan Jia <hushan.jia@gmail.com>
 * Jiuyue Ma <majiuyue@huawei.com>
 * Johnny Bieren <jbieren@redhat.com>
 * Jonathan Boulle <jonathanboulle@gmail.com>
 * Justin Cormack <justin.cormack@docker.com>
 * Kenfe-Mickael Laventure <mickael.laventure@gmail.com>
 * Michael Crosby <crosbymichael@gmail.com>
 * Mike Brown <brownwm@us.ibm.com>
 * Mrunal Patel <mrunalp@gmail.com>
 * Peng Gao <peng.gao.dut@gmail.com>
 * Petar Petrov <pppepito86@gmail.com>
 * Phil Estes <estesp@linux.vnet.ibm.com>
 * Qiang Huang <h.huangqiang@huawei.com>
 * Serge Hallyn <serge@hallyn.com>
 * Seth Jennings <sjenning@redhat.com>
 * Shukui Yang <yangshukui@huawei.com>
 * Tristan Cacqueray <tdecacqu@redhat.com>
 * Vishnu kannan <vishnuk@google.com>
 * Wang Long <long.wanglong@huawei.com>
 * Yang Hongyang <imhy.yang@gmail.com>
 * Yen-Lin Chen <hencrice+FOSS@gmail.com>
 * Yuanhong Peng <pengyuanhong@huawei.com>
 * Zhang Wei <zhangwei555@huawei.com>
 * Zhao Lei <zhaolei@cn.fujitsu.com>
 * rajasec <rajasec79@gmail.com>
 * xiekeyang <xiekeyang@huawei.com>

v1.0.0-rc1

Toggle v1.0.0-rc1's commit message
Update runc version to 1.0.0-rc1

Signed-off-by: Michael Crosby <crosbymichael@gmail.com>

v0.1.1

Toggle v0.1.1's commit message
Bump to 0.1.1

This includes a fix for selinux mount labels in the spec.

Signed-off-by: Michael Crosby <crosbymichael@gmail.com>

v0.1.0

Toggle v0.1.0's commit message
Update runc to 0.1.0

Signed-off-by: Michael Crosby <crosbymichael@gmail.com>

v0.0.9

Toggle v0.0.9's commit message
Bump runc to 0.0.9

Signed-off-by: Michael Crosby <crosbymichael@gmail.com>

v0.0.8

Toggle v0.0.8's commit message
Merge pull request opencontainers#549 from crosbymichael/tty-close

Close tty on error before handler

v0.0.7

Toggle v0.0.7's commit message
Merge pull request opencontainers#512 from LK4D4/bump_version

Bump runc version to 0.0.7