Linux 容器工具,LXC 1.1.4 發布

jopen 9年前發布 | 7K 次閱讀 LXC

LXC 項目由一個 Linux 內核補丁和一些 userspace 工具組成。這些 userspace 工具使用由補丁增加的內核新特性,提供一套簡化的工具來維護容器。

Linux 容器工具,LXC 1.1.4 發布

LXC 1.1.4 發布,此版本更新內容如下:

重要改進

  • Security fix for CVE-2015-1335

    </li> </ul>

    核心改進

    • Check for NULL pointers before calling setenv()

      </li>

    • Factorize handle of create=dir and create=file

      </li>

    • Refactor and factorize mount entries

      </li>

    • Split handle of lxc.mount* with 3 functions

      </li>

    • init: Support older apparmor

      </li>

    • Make LXC_CLONE_KEEPNAME work

      </li>

    • Fix automatic mounts without a rootfs

      </li>

    • Fix container creation without a rootfs

      </li>

    • Fix /dev symlinks without a rootfs

      </li>

    • Allow autodev without a rootfs

      </li>

    • Only mount /proc if needed, even without a rootfs

      </li>

    • When creating container, save configuration if rootfs already exists

      </li>

    • Fix verification of start hook without a rootfs

      </li>

    • Tear down network devices during container halt

      </li>

    • coverity: fix mount_entry_create_dir_file

      </li>

    • Add a nesting.conf which can be included to support nesting containers

      </li>

    • Fix reallocation calculation

      </li>

    • Add bdev_destroy() and bdev_destroy_wrapper()

      </li>

    • overlayfs_clone: rsync the mounted rootfs

      </li>

    • lxc_rmdir_onedev: don't fail if path doesn't exist

      </li>

    • overlayfs_mount: create delta dir if it doesn't exist

      </li>

    • ovl_rsync: make sure to umount

      </li>

    • Destroy bdevs using bdev_destroy() from bdev.h

      </li>

    • Fix indentation

      </li>

    • cmds: fix abstract socket length problem

      </li>

    • coverity: drop second (redundant) block

      </li>

    • Check return value of snprintf in mount_proc_if_needed()

      </li>

    • Add CAP_AUDIT_READ

      </li>

    • Add CAP_BLOCK_SUSPEND

      </li>

    • Free allocated memory on failure (v2)

      </li>

    • Define O_PATH and O_NOFOLLOW for Android

      </li>

    • seccomp: add aarch64 support

      </li>

    • lxc-test-symlink: add a test using absolute symlink

      </li>

    • lxc_mount_auto_mounts: fix weirdness

      </li>

    • Fix the type of i in lxc_mount_auto_mounts

      </li> </ul>

      工具:

      • Fix grammar in some of the executables "NAME for name of the container" becomes "NAME of the container"

        </li>

      • lxc-checkconfig: add some more config options

        </li>

      • lxc-start-ephemeral: Parse passwd directly

        </li> </ul>

        文檔:

        • Add long option for -P in documentation

          </li>

        • Add doc for optional, create=dir and create=file in lxc.container.conf man

          </li>

        • Update lxc.cgroup.use in lxc.system.conf(5)

          </li>

        • Add the description of common options in lxc-destroy(1)

          </li>

        • Add LXC-specific mount option in Japanese lxc.container.conf(5)

          </li> </ul>

          模板:

          • lxc-debian: support stretch (Debian 9) images

            </li>

          • lxc-debian: allow not including contrib/non-free

            </li>

          • lxc-debian: Test dpkg for multiarch support

            </li>

          • lxc-debian: Alternative test for dpkg multiarch support in lxc-debian template

            </li>

          • lxc-ubuntu: ubuntu.common.conf: mount /dev/mqueue

            </li>

          • lxc-debian: We should only check the kernel architecture.

            </li>

          • lxc-alpine: avoid GNU BRE extensions for better portability

            </li>

          • lxc-alpine: use getopt to parse options

            </li> </ul>

            這些穩定修復是 14 為個人貢獻者完成的。

            下載:https://linuxcontainers.org/lxc/downloads  


             本文由用戶 jopen 自行上傳分享,僅供網友學習交流。所有權歸原作者,若您的權利被侵害,請聯系管理員。
             轉載本站原創文章,請注明出處,并保留原始鏈接、圖片水印。
             本站是一個以用戶分享為主的開源技術平臺,歡迎各類分享!