Cesar Talledo
0ba4362d69
Update markdown docs to indicate multi-platform support in image load/save.
...
Signed-off-by: Cesar Talledo <cesar.talledo@docker.com >
2025-06-10 16:42:39 -07:00
Cesar Talledo
8993f54fc3
Add support for multiple platforms in docker image save
...
Signed-off-by: Cesar Talledo <cesar.talledo@docker.com >
2025-06-10 16:34:07 -07:00
Cesar Talledo
38b99adc10
Add support for multiple platforms in docker image load.
...
Signed-off-by: Cesar Talledo <cesar.talledo@docker.com >
2025-06-10 16:34:02 -07:00
Sebastiaan van Stijn
8b8f558b83
Merge pull request #6124 from vvoland/update-go
...
update to go1.24.4
2025-06-10 15:12:26 +02:00
Sebastiaan van Stijn
5487986681
Merge pull request #6123 from ndeloof/pluginserver
...
only close plugin server if actually created
2025-06-10 15:12:06 +02:00
Nicolas De Loof
b9c563a581
only close plugin server if actually created
...
Signed-off-by: Nicolas De Loof <nicolas.deloof@gmail.com >
2025-06-10 14:57:19 +02:00
Paweł Gronowski
fe7fc2ff7f
update to go1.24.4
...
- https://github.com/golang/go/issues?q=milestone%3AGo1.24.4+label%3ACherryPickApproved
- full diff: https://github.com/golang/go/compare/go1.24.3...go1.24.4
This release includes 3 security fixes following the security policy:
- net/http: sensitive headers not cleared on cross-origin redirect
Proxy-Authorization and Proxy-Authenticate headers persisted on cross-origin redirects potentially leaking sensitive information.
Thanks to Takeshi Kaneko (GMO Cybersecurity by Ierae, Inc.) for reporting this issue.
This is CVE-2025-4673 and Go issue https://go.dev/issue/73816 .
- os: inconsistent handling of O_CREATE|O_EXCL on Unix and Windows
os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent location, OpenFile would create a file in that location.
OpenFile now always returns an error when the O_CREATE and O_EXCL flags are both set and the target path is a symlink.
Thanks to Junyoung Park and Dong-uk Kim of KAIST Hacking Lab for discovering this issue.
This is CVE-2025-0913 and Go issue https://go.dev/issue/73702 .
- crypto/x509: usage of ExtKeyUsageAny disables policy validation
Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.
Thanks to Krzysztof Skrzętnicki (@Tener) of Teleport for reporting this issue.
This is CVE-2025-22874 and Go issue https://go.dev/issue/73612 .
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com >
2025-06-09 16:25:41 +02:00
Sebastiaan van Stijn
9e506545fd
Merge pull request #6120 from thaJeztah/fix_url
...
docs: fix link to live-restore
2025-06-02 13:02:40 +02:00
Sebastiaan van Stijn
3c1bbfd82f
docs: fix link to live-restore
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-06-02 12:56:04 +02:00
Sebastiaan van Stijn
0bfd4c9f29
Merge pull request #6119 from thaJeztah/bump_engine
...
vendor: github.com/docker/docker v28.2.2
2025-06-02 10:15:52 +02:00
Sebastiaan van Stijn
3b25977f82
Merge pull request #50110 from thaJeztah/remove_import_comments
...
all: remove // import comments
2025-05-30 20:35:54 +02:00
Sebastiaan van Stijn
d8f09a1b75
Merge pull request #6117 from vvoland/binimage-nosha
...
gha/bin-image: Don't push sha tags
2025-05-30 17:42:22 +02:00
Sebastiaan van Stijn
473b248260
vendor: github.com/docker/docker v28.2.2
...
no diff; same commit, but tagged:
https://github.com/docker/docker/compare/45873be4ae3f...v28.2.2
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-05-30 17:37:57 +02:00
Sebastiaan van Stijn
342f8bca25
builder: remove // import comments
...
These comments were added to enforce using the correct import path for
our packages ("github.com/docker/docker", not "github.com/moby/moby").
However, when working in go module mode (not GOPATH / vendor), they have
no effect, so their impact is limited.
Remove these imports in preparation of migrating our code to become an
actual go module.
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-05-30 15:59:11 +02:00
Paweł Gronowski
b2d63d17af
gha/bin-image: Don't push sha tags
...
This change eliminates the automatic creation of image tags in the
format `dockereng/cli-bin:sha-ad132f5` for every push.
They're not too useful, produce noise and use a lot of space.
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com >
2025-05-30 12:00:29 +02:00
Paweł Gronowski
e6534b4eb7
Merge pull request #6116 from vvoland/vendor-docker
...
build / prepare (push) Has been cancelled
build / build (push) Has been cancelled
build / bin-image (push) Has been cancelled
build / prepare-plugins (push) Has been cancelled
build / plugins (push) Has been cancelled
codeql / codeql (push) Has been cancelled
e2e / tests (alpine, 23, connhelper-ssh) (push) Has been cancelled
e2e / tests (alpine, 23, local) (push) Has been cancelled
e2e / tests (alpine, 26, connhelper-ssh) (push) Has been cancelled
e2e / tests (alpine, 26, local) (push) Has been cancelled
e2e / tests (alpine, 27, connhelper-ssh) (push) Has been cancelled
e2e / tests (alpine, 27, local) (push) Has been cancelled
e2e / tests (alpine, 28, connhelper-ssh) (push) Has been cancelled
e2e / tests (alpine, 28, local) (push) Has been cancelled
e2e / tests (debian, 23, connhelper-ssh) (push) Has been cancelled
e2e / tests (debian, 23, local) (push) Has been cancelled
e2e / tests (debian, 26, connhelper-ssh) (push) Has been cancelled
e2e / tests (debian, 26, local) (push) Has been cancelled
e2e / tests (debian, 27, connhelper-ssh) (push) Has been cancelled
e2e / tests (debian, 27, local) (push) Has been cancelled
e2e / tests (debian, 28, connhelper-ssh) (push) Has been cancelled
e2e / tests (debian, 28, local) (push) Has been cancelled
test / ctn (push) Has been cancelled
test / host (macos-13) (push) Has been cancelled
test / host (macos-14) (push) Has been cancelled
validate / validate (lint) (push) Has been cancelled
validate / validate (shellcheck) (push) Has been cancelled
validate / validate (update-authors) (push) Has been cancelled
validate / validate (validate-vendor) (push) Has been cancelled
validate / validate-md (push) Has been cancelled
validate / validate-make (manpages) (push) Has been cancelled
validate / validate-make (yamldocs) (push) Has been cancelled
vendor: github.com/docker/docker v28.2.2-dev (45873be4ae3f)
v28.2.2
2025-05-30 09:39:08 +00:00
Paweł Gronowski
5c3128e95e
vendor: github.com/docker/docker v28.2.2-dev (45873be4ae3f)
...
full diff: https://github.com/docker/docker/compare/0e2cc22d36ae...45873be4ae3f
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com >
2025-05-30 11:15:35 +02:00
Paweł Gronowski
879ac3f88f
Merge pull request #6110 from thaJeztah/bump_engine
...
build / prepare (push) Has been cancelled
build / build (push) Has been cancelled
build / bin-image (push) Has been cancelled
build / prepare-plugins (push) Has been cancelled
build / plugins (push) Has been cancelled
codeql / codeql (push) Has been cancelled
e2e / tests (alpine, 23, connhelper-ssh) (push) Has been cancelled
e2e / tests (alpine, 23, local) (push) Has been cancelled
e2e / tests (alpine, 26, connhelper-ssh) (push) Has been cancelled
e2e / tests (alpine, 26, local) (push) Has been cancelled
e2e / tests (alpine, 27, connhelper-ssh) (push) Has been cancelled
e2e / tests (alpine, 27, local) (push) Has been cancelled
e2e / tests (alpine, 28, connhelper-ssh) (push) Has been cancelled
e2e / tests (alpine, 28, local) (push) Has been cancelled
e2e / tests (debian, 23, connhelper-ssh) (push) Has been cancelled
e2e / tests (debian, 23, local) (push) Has been cancelled
e2e / tests (debian, 26, connhelper-ssh) (push) Has been cancelled
e2e / tests (debian, 26, local) (push) Has been cancelled
e2e / tests (debian, 27, connhelper-ssh) (push) Has been cancelled
e2e / tests (debian, 27, local) (push) Has been cancelled
e2e / tests (debian, 28, connhelper-ssh) (push) Has been cancelled
e2e / tests (debian, 28, local) (push) Has been cancelled
test / ctn (push) Has been cancelled
test / host (macos-13) (push) Has been cancelled
test / host (macos-14) (push) Has been cancelled
validate / validate (lint) (push) Has been cancelled
validate / validate (shellcheck) (push) Has been cancelled
validate / validate (update-authors) (push) Has been cancelled
validate / validate (validate-vendor) (push) Has been cancelled
validate / validate-md (push) Has been cancelled
validate / validate-make (manpages) (push) Has been cancelled
validate / validate-make (yamldocs) (push) Has been cancelled
vendor: github.com/docker/docker 0e2cc22d36ae (v28.2-dev)
v28.2.0
v28.2.1
2025-05-28 13:17:56 +00:00
Sebastiaan van Stijn
92fa1e1fc9
vendor: github.com/docker/docker 0e2cc22d36ae (v28.2-dev)
...
no changes in vendored code
full diff: https://github.com/docker/docker/compare/26db31fdab628a2345ed8f179e575099384166a9...0e2cc22d36ae3013f83863c8da2e1b808f25e78e
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-05-28 15:05:58 +02:00
Sebastiaan van Stijn
4bec3a6795
Merge pull request #6114 from thaJeztah/deprecate_non_compliant_registries
...
docs: deprecated: fallback for non-OCI-compliant registries is removed
2025-05-28 14:28:52 +02:00
Paweł Gronowski
a007d1ae24
Merge pull request #6113 from thaJeztah/config_suppress_err
...
cli/config/configfile: explicitly ignore error
2025-05-28 12:08:37 +00:00
Sebastiaan van Stijn
bbfbd54f4d
docs: deprecated: fallback for non-OCI-compliant registries is removed
...
GitHub deprecated the legacy registry, and it was [sunset on Feb 24th, 2025][1]
in favor of GitHub Container Registry (GHCR) (ghcr.io), so the fallback
was removed.
[1]: https://github.blog/changelog/2025-01-23-legacy-docker-registry-closing-down/
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-05-28 10:05:40 +02:00
Sebastiaan van Stijn
2d21e1f7a5
cli/config/configfile: explicitly ignore error
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-05-28 09:55:33 +02:00
Sebastiaan van Stijn
bc9be0bdea
Merge pull request #6112 from thaJeztah/bump_tools
...
Dockerfile: bump buildx v0.24.0, compose v2.36.2
2025-05-28 09:09:24 +02:00
Sebastiaan van Stijn
3fe7dc5cb4
Dockerfile: update compose to v2.36.2
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-05-27 22:50:20 +02:00
Sebastiaan van Stijn
9eae2a8976
Dockerfile: update buildx to v0.24.0
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-05-27 22:49:34 +02:00
Sebastiaan van Stijn
a29e53dab7
Merge pull request #6111 from thaJeztah/update_deprecations
...
docs: deprecated: update status for non-standard fields in image inspect
2025-05-27 16:57:52 +02:00
Sebastiaan van Stijn
da0c976fb0
docs: deprecated: update status for non-standard fields in image inspect
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-05-27 16:14:00 +02:00
Sebastiaan van Stijn
17dc2880fa
Merge pull request #6109 from thaJeztah/image_rm_platform
...
image rm: add --platform option
2025-05-27 12:11:26 +02:00
Sebastiaan van Stijn
bb0ca9f9ef
image rm: add --platform option
...
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-05-27 10:58:11 +02:00
Sebastiaan van Stijn
f567263802
Merge pull request #6099 from thaJeztah/bump_engine
...
vendor: github.com/docker/docker 26db31fdab62 (v28.2-dev)
2025-05-27 10:49:43 +02:00
Sebastiaan van Stijn
7775f01caa
vendor: github.com/docker/docker 26db31fdab62 (v28.2-dev)
...
full diff: https://github.com/docker/docker/compare/v28.2.0-rc.2...26db31fdab628a2345ed8f179e575099384166a9
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-05-27 09:20:06 +02:00
Paweł Gronowski
908ff04d6e
Merge pull request #6108 from thaJeztah/bump_engine_28.2
...
vendor: github.com/docker/docker v28.2.0-rc.2
2025-05-26 13:17:15 +00:00
Sebastiaan van Stijn
519bc2daa1
vendor: github.com/docker/docker v28.2.0-rc.2
...
no changes in vendored code
full diff: https://github.com/docker/docker/compare/f4ffeb8c38b3...v28.2.0-rc.2
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-05-26 14:06:52 +02:00
Paweł Gronowski
b2c4452acb
Merge pull request #6101 from thaJeztah/deprecated_api_versions_removed
...
build / prepare (push) Has been cancelled
build / build (push) Has been cancelled
build / bin-image (push) Has been cancelled
build / prepare-plugins (push) Has been cancelled
build / plugins (push) Has been cancelled
codeql / codeql (push) Has been cancelled
e2e / tests (alpine, 23, connhelper-ssh) (push) Has been cancelled
e2e / tests (alpine, 23, local) (push) Has been cancelled
e2e / tests (alpine, 26, connhelper-ssh) (push) Has been cancelled
e2e / tests (alpine, 26, local) (push) Has been cancelled
e2e / tests (alpine, 27, connhelper-ssh) (push) Has been cancelled
e2e / tests (alpine, 27, local) (push) Has been cancelled
e2e / tests (alpine, 28, connhelper-ssh) (push) Has been cancelled
e2e / tests (alpine, 28, local) (push) Has been cancelled
e2e / tests (debian, 23, connhelper-ssh) (push) Has been cancelled
e2e / tests (debian, 23, local) (push) Has been cancelled
e2e / tests (debian, 26, connhelper-ssh) (push) Has been cancelled
e2e / tests (debian, 26, local) (push) Has been cancelled
e2e / tests (debian, 27, connhelper-ssh) (push) Has been cancelled
e2e / tests (debian, 27, local) (push) Has been cancelled
e2e / tests (debian, 28, connhelper-ssh) (push) Has been cancelled
e2e / tests (debian, 28, local) (push) Has been cancelled
test / ctn (push) Has been cancelled
test / host (macos-13) (push) Has been cancelled
test / host (macos-14) (push) Has been cancelled
validate / validate (lint) (push) Has been cancelled
validate / validate (shellcheck) (push) Has been cancelled
validate / validate (update-authors) (push) Has been cancelled
validate / validate (validate-vendor) (push) Has been cancelled
validate / validate-md (push) Has been cancelled
validate / validate-make (manpages) (push) Has been cancelled
validate / validate-make (yamldocs) (push) Has been cancelled
docs: deprecated: mark API < v1.24 as "removed"
v28.2.0-rc.2
2025-05-22 12:09:34 +00:00
Sebastiaan van Stijn
3e287df661
Merge pull request #6100 from thaJeztah/fluentd_async_connect_removed
...
docs: deprecated: mark `fluentd-async-connect` as "removed"
2025-05-22 14:09:24 +02:00
Paweł Gronowski
f1fb3e3011
Merge pull request #5282 from willww64/fix-configfile-relative-symlink
...
correctly handle configuration file saving when it is a relative symlink
2025-05-22 12:08:40 +00:00
Sebastiaan van Stijn
9c8666c106
docs: deprecated: mark API < v1.24 as "removed"
...
Support for API versions lower than v1.24 was removed in v26.0.
The DOCKER_MIN_API_VERSION environment-variable is still present
in the docker daemon, but can currently only be used to raise the
minimum version.
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-05-22 13:37:44 +02:00
Sebastiaan van Stijn
21d0466ff1
docs: deprecated: mark fluentd-async-connect as "removed"
...
The daemon still has migration code in place, but no longer accepts
the option for new containers, so marking it as "removed";
https://github.com/moby/moby//commit/49ec488036d9702df8432ec0e6f33c170a4a2bbe
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-05-22 13:28:18 +02:00
Sebastiaan van Stijn
1d3b933ac3
Merge pull request #6098 from thaJeztah/deprecated_inspect_fields
...
docs: deprecated: set Container and ContainerConfig fields to "removed"
2025-05-22 11:54:10 +02:00
Sebastiaan van Stijn
649d088ddf
Merge pull request #6096 from thaJeztah/graphdriver_plugin_deprecation
...
docs: update deprecation status of graphdriver-plugins to "removed"
2025-05-22 11:49:53 +02:00
Paweł Gronowski
e135563c1f
Merge pull request #6097 from vvoland/28.x
...
vendor: github.com/docker/docker v28.2.0-dev (f4ffeb8c38b3)
2025-05-22 09:48:20 +00:00
Sebastiaan van Stijn
026ae7a11f
docs: deprecated: set Container and ContainerConfig fields to "removed"
...
These fields have been removed in v26.0 (API v1.45 and up), and are always
omitted when using the containerd image store;
https://github.com/moby/moby/commit/03cddc62f4bcd48fbc3a31dd94f2bf84e44840dd
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-05-22 11:45:57 +02:00
Paweł Gronowski
681c705be6
vendor: github.com/docker/docker v28.2.0-dev (f4ffeb8c38b3)
...
full diff: https://github.com/docker/docker/compare/b590eff717b3...f4ffeb8c38b3
Signed-off-by: Paweł Gronowski <pawel.gronowski@docker.com >
2025-05-22 11:38:51 +02:00
Sebastiaan van Stijn
bdd994b79a
docs: update deprecation status of graphdriver-plugins to "removed"
...
This functionality, was removed and the DOCKERD_DEPRECATED_GRAPHDRIVER_PLUGINS
no longer can be used in v28.0;
https://github.com/moby/moby/commit/42ca9154e9b8f8120011add4c09c6edcecd1e6f5
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-05-22 11:29:37 +02:00
Will Wang
1015d15621
fix bug with config file being a relative symlink
...
- use filepath.EvalSymlink instead of check with filepath.IsAbs
- allow for dangling symlinks
- extract path from error when NotExist error occurs
Co-authored-by: Paweł Gronowski <me@woland.xyz >
Co-authored-by: Sebastiaan van Stijn <github@gone.nl >
Signed-off-by: Will Wang <willww64@gmail.com >
Signed-off-by: Sebastiaan van Stijn <github@gone.nl >
2025-05-22 11:11:07 +02:00
Sebastiaan van Stijn
ae922ec177
Merge pull request #6092 from thaJeztah/hijack_oncefunc
...
cli/command/container: hijackedIOStreamer.setupInput: use sync.OnceFunc
2025-05-22 10:02:11 +02:00
Sebastiaan van Stijn
881c68f690
Merge pull request #4966 from Benehiko/relative-mount-path
...
feat: relative parent paths on bind mount src
2025-05-22 08:38:06 +02:00
Alano Terblanche
761285bfee
feat: relative parent paths on bind mount src
...
Signed-off-by: Alano Terblanche <18033717+Benehiko@users.noreply.github.com >
2025-05-22 08:15:32 +02:00
Sebastiaan van Stijn
f23ec25a12
Merge pull request #6095 from thaJeztah/update_schema1_deprecation
...
docs: move deprecation status of legacy schema1 images to "removed"
2025-05-22 08:06:45 +02:00