Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
1664 commits
Select commit Hold shift + click to select a range
4887b7a
daemon/container: cleanup with maps, slices packages
thaJeztah Aug 31, 2026
2803839
api/swagger: Align Healthcheck name with Go struct
vvoland Sep 3, 2026
cc3463a
api/docs: Align Healthcheck name in older API versions
vvoland Sep 3, 2026
6996593
Merge pull request #53551 from vvoland/afvsock
thaJeztah Sep 3, 2026
d57fbc0
Merge pull request #53567 from vvoland/fix-healthcheck
thaJeztah Sep 3, 2026
092da14
Update module github.com/mdlayher/socket to v0.6.1
renovate-bot Sep 3, 2026
34ae0e1
Merge pull request #53564 from vvoland/fix-cri-disabled
vvoland Sep 3, 2026
021d7ff
integration/container: Detect LSM names in any option field
vvoland Sep 3, 2026
cd2afba
Merge pull request #53535 from thaJeztah/stdlib_assert
vvoland Sep 3, 2026
5ca194a
Merge pull request #53566 from thaJeztah/container_slices
vvoland Sep 3, 2026
b40d37e
Merge pull request #53359 from vvoland/ext-namegenerator
thaJeztah Sep 3, 2026
e1d06bd
Drop replace rules
vvoland Sep 3, 2026
9590d37
daemon/libnetwork: Skip flaky NetworkDB islands test
vvoland Sep 3, 2026
0df1a00
Dockerfile: update cli v29.7.2, compose v5.5.1, buildx v0.37.0
thaJeztah Sep 3, 2026
7d1ce6a
Merge pull request #53568 from renovate-bot/renovate/github.com-mdlay…
vvoland Sep 3, 2026
0af79c4
Merge pull request #53570 from vvoland/process-release
thaJeztah Sep 3, 2026
65be55a
Merge pull request #53513 from thaJeztah/daemon_fix_list
vvoland Sep 3, 2026
bb86302
Merge pull request #53569 from vvoland/afvsock-lsm
vvoland Sep 3, 2026
20beedb
api/docs: Cut v1.56
vvoland Sep 3, 2026
575cf82
Merge pull request #53571 from thaJeztah/bump_tools
thaJeztah Sep 3, 2026
9b2179d
Merge pull request #53572 from vvoland/api-docs-cut
thaJeztah Sep 3, 2026
e6fa167
vendor: github.com/moby/moby/api v1.56.0
vvoland Sep 3, 2026
ec7d485
Merge pull request #53574 from vvoland/vendor-api
vvoland Sep 3, 2026
25f4754
vendor: github.com/moby/moby/client v0.6.0
vvoland Sep 3, 2026
3b0f0ec
update milestones
thaJeztah Sep 3, 2026
3ce5872
Merge pull request #53575 from vvoland/vendor-client
vvoland Sep 3, 2026
26a92a0
Merge pull request #53578 from thaJeztah/bump_milestone
vvoland Sep 3, 2026
19ec953
Merge pull request #53579 from vvoland/flaky-islandsdb
thaJeztah Sep 3, 2026
7fa6346
vendor: tags.cncf.io/container-device-interface v1.1.1
thaJeztah Aug 11, 2026
90484e1
extpoints: Remove unused mobyextgen service directives
vvoland Sep 4, 2026
864598f
Merge pull request #53583 from vvoland/extensions-cleanup
thaJeztah Sep 4, 2026
65d3a5e
daemon/c8d-supervised: Disable CRI pod sandbox plugin
vvoland Sep 4, 2026
6cf7d6a
Merge pull request #53585 from vvoland/c8d-cri
vvoland Sep 4, 2026
906e69a
daemon: simplify healthcheck tests
thaJeztah Sep 4, 2026
b322544
Dockerfile: update CLI to v29.8.0
thaJeztah Sep 4, 2026
47a9562
daemon/internal/filters: cleanup with maps, slices packages
thaJeztah Aug 29, 2026
2280567
Merge pull request #53587 from thaJeztah/bump_cli
vvoland Sep 4, 2026
fdf0138
vendor: github.com/containerd/containerd/v2 v2.3.5
thaJeztah Sep 5, 2026
4724c82
Dockerfile: update to containerd v2.3.5
thaJeztah Sep 5, 2026
edcd284
Merge pull request #53589 from thaJeztah/bump_containerd_2.3_bin
vvoland Sep 7, 2026
e187c56
Merge pull request #53588 from thaJeztah/vendor_containerd_2.3
vvoland Sep 7, 2026
1019270
Merge pull request #53493 from thaJeztah/bump_cdi
vvoland Sep 7, 2026
275015b
Merge pull request #53586 from thaJeztah/health_table
vvoland Sep 7, 2026
9f94f66
daemon: check for error-type for "removal already in progress"
thaJeztah Sep 7, 2026
6144838
integration/networking: make TestNslookupWindows less flaky
thaJeztah Sep 8, 2026
5445d62
Merge pull request #53576 from thaJeztah/cleanup_filters
vvoland Sep 8, 2026
78eac31
integration: migrate TestImagesEnsureOnlyHeadsImagesShown
thaJeztah Sep 4, 2026
fa20051
integration: add TestAPIImagesListDanglingFilter
thaJeztah Sep 4, 2026
ec7f917
integration: migrate TestImagesFilterSinceAndBefore
thaJeztah Sep 4, 2026
432f75c
vendor: golang.org/x/sync v0.23.0
thaJeztah Sep 8, 2026
3a5a0d4
vendor: golang.org/x/sys v0.48.0
thaJeztah Sep 8, 2026
199fc35
vendor: golang.org/x/mod v0.41.0
thaJeztah Sep 8, 2026
55f8ee6
vendor: golang.org/x/time v0.16.0
thaJeztah Sep 8, 2026
c5c5390
vendor: golang.org/x/oauth2 v0.37.0
thaJeztah Sep 8, 2026
251d0ea
Merge pull request #53601 from thaJeztah/deflake_TestNslookupWindows
thaJeztah Sep 8, 2026
e0c1583
Merge pull request #53584 from thaJeztah/migrate_image_list_tests
thaJeztah Sep 8, 2026
c187397
Update module github.com/moby/sys/userns to v0.2.1
renovate-bot Sep 8, 2026
f1dfc4c
Merge pull request #53603 from thaJeztah/bump_x_deps
AkihiroSuda Sep 9, 2026
b21c422
Merge pull request #53605 from renovate-bot/renovate/github.com-moby-…
thaJeztah Sep 9, 2026
c475603
daemon/server/router/grpc: fix linting for deprecated http2 code
thaJeztah Sep 9, 2026
1214981
Dockerfile: update crun to v1.29.1
thaJeztah Sep 9, 2026
94b5ef1
Merge pull request #53609 from thaJeztah/fix_linting
thaJeztah Sep 9, 2026
d4b645a
vendor: golang.org/x/text v0.42.0
thaJeztah Sep 9, 2026
05f2d21
vendor: golang.org/x/term v0.46.0
thaJeztah Sep 9, 2026
8e44af4
vendor: golang.org/x/crypto v0.57.0
thaJeztah Sep 9, 2026
01c934b
vendor: golang.org/x/net v0.59.0
thaJeztah Sep 9, 2026
fce9664
Merge pull request #53598 from thaJeztah/rm_in_progress_errortype
vvoland Sep 9, 2026
c306521
Merge pull request #53608 from thaJeztah/bump_crun
AkihiroSuda Sep 10, 2026
dce3d05
nftablesdoc,nftabler: document dstnat priority normalization
thaJeztah Sep 10, 2026
f28c749
daemon/command: Replace deprecated tracing log hook
vvoland Sep 10, 2026
d0ecdbf
Merge pull request #53617 from vvoland/deprected-otel
thaJeztah Sep 10, 2026
2079abc
d/libnet: TestUserChain: simplify error matching for nonexistent chains
akerouanton Aug 25, 2025
f0816a8
Merge pull request #51642 from thaJeztah/trixie_test_changes
thaJeztah Sep 11, 2026
ad6f578
vendor: github.com/moby/extensions 86305e92aa39
glours Sep 11, 2026
073cfc5
vendor: github.com/containerd/log v0.2.0, with SetLevel
thaJeztah Aug 23, 2026
1cee3c3
windows: preserve hard links when committing a container
vagokuln-msft Sep 12, 2026
4e6e3f8
chore(deps): update github/codeql-action action to v4.38.0
renovate-bot Sep 12, 2026
5540cd0
Merge pull request #53628 from glours/update-moby-extension
vvoland Sep 12, 2026
bd6d437
fix(deps): update module github.com/containerd/nri to v0.12.3
renovate-bot Sep 13, 2026
d7ad478
Migrate user-defined network inspect integration test
efegokdemir Sep 14, 2026
c958419
windows: close tar writer on early returns in writeTarFromLayer
vagokuln-msft Sep 12, 2026
b789a5e
Migrate multiple bridge network IPAM test
efegokdemir Sep 13, 2026
90560e6
libn/osl: program FDB entries with NLM_F_REPLACE
macieklamberski Sep 14, 2026
0fd4683
CI: update Lima (2.2.0)
AkihiroSuda Sep 14, 2026
e5ce222
daemon/containerd: Avoid duplicate dangling images on load
vvoland Sep 4, 2026
8c8c1c3
Merge pull request #53444 from thaJeztah/update_log
vvoland Sep 14, 2026
52cd526
Merge pull request #53610 from thaJeztah/bump_x_deps
vvoland Sep 14, 2026
1bec1cd
Merge pull request #53665 from AkihiroSuda/lima
vvoland Sep 14, 2026
546da6c
Merge pull request #53613 from renovate-bot/renovate/github.com-conta…
vvoland Sep 14, 2026
088b7b4
Merge pull request #51970 from ricardobranco777/skiprootless
vvoland Sep 14, 2026
8210b0b
Merge pull request #53595 from vvoland/fix-53561
thaJeztah Sep 14, 2026
bed4f95
Merge pull request #53624 from vagokuln-msft/fix-windows-hardlinks-on…
thaJeztah Sep 14, 2026
3d458f1
iptables: handle missing rules on delete
thaJeztah Sep 10, 2026
eade131
Merge pull request #53644 from efegokdemir/50159-migrate-network-insp…
vvoland Sep 14, 2026
44c82fe
test/docker-py: Bump to master
vvoland Sep 14, 2026
f29c5d8
Merge pull request #53618 from thaJeztah/fix_iptables_rm
vvoland Sep 14, 2026
a648622
Dockerfile update to debian 13 "trixie"
thaJeztah Aug 13, 2025
893d1c6
iptables: inline Rule.ensure, and un-export Rule.exists
thaJeztah Sep 14, 2026
fe86271
Migrate bridge network inspect test
efegokdemir Sep 13, 2026
fc44b26
CI: extract VM provisioning into host scripts
AkihiroSuda Sep 15, 2026
9816469
build: export dependencies for native integration tests
AkihiroSuda Sep 15, 2026
4a233af
testutil: resolve rootless test binaries before invoking sudo
AkihiroSuda Sep 15, 2026
bc40bef
test: support older umount versions during daemon cleanup
AkihiroSuda Sep 15, 2026
abc2012
integration/container: use whole disks for blkio throttle tests
AkihiroSuda Sep 15, 2026
3c78817
integration/system: skip rootless cgroup v1 memory limits
AkihiroSuda Sep 15, 2026
724c8f0
integration/container: wait for the NAT server response
AkihiroSuda Sep 15, 2026
fcceff5
integration/container: stop the attach test daemon
AkihiroSuda Sep 15, 2026
7a85699
CI: run VM integration tests directly in the guest
AkihiroSuda Sep 15, 2026
e70117c
ci: validate-pr: revert "limit checks to relevant events"
thaJeztah Sep 15, 2026
483259d
Merge pull request #53675 from thaJeztah/validate_trigger_happier
thaJeztah Sep 15, 2026
e5a6e1a
daemon/network: fix filter-validation errors
thaJeztah Sep 15, 2026
1594430
Merge pull request #53674 from thaJeztah/iptables_clean
vvoland Sep 15, 2026
fb38fb5
Merge pull request #53673 from vvoland/update-dockerpy
vvoland Sep 15, 2026
ea507d1
Merge pull request #53638 from renovate-bot/renovate/github-codeql-ac…
vvoland Sep 15, 2026
b182eb6
Merge pull request #53678 from thaJeztah/filter_response_code
vvoland Sep 15, 2026
0e524eb
Merge pull request #53645 from efegokdemir/50159-migrate-network-ipam…
vvoland Sep 15, 2026
1358607
Merge pull request #53643 from efegokdemir/50159-migrate-network-insp…
vvoland Sep 15, 2026
7f348bb
Merge pull request #50726 from thaJeztah/trixie_me_trixie_you
thaJeztah Sep 15, 2026
e791312
integration-cli: fix unused import
thaJeztah Sep 15, 2026
eda8383
integration-cli: remove unused isNetworkAvailable utility
thaJeztah Sep 15, 2026
e4d2b20
integration-cli: inline connectNetwork, disconnectNetwork utils
thaJeztah Sep 15, 2026
79d7d1c
Merge pull request #53680 from thaJeztah/fix_import
thaJeztah Sep 15, 2026
714a316
vendor: github.com/klauspost/compress v1.20.0
thaJeztah Sep 15, 2026
464cd50
Merge pull request #53672 from AkihiroSuda/dedindify
vvoland Sep 15, 2026
8772d64
vendor: github.com/cyphar/filepath-securejoin v0.7.0
thaJeztah Sep 15, 2026
5e37bd9
CI: switch from oraclelinux-8 to almalinux-8
AkihiroSuda Sep 16, 2026
f4e43a1
releases: update to 29.8.2
thaJeztah Sep 16, 2026
9fa806a
releases: update to 29.9.0
thaJeztah Sep 16, 2026
16c83ba
go.mod: add back replace rules
thaJeztah Sep 16, 2026
1822bc4
Merge pull request #53690 from thaJeztah/bump_milestone
thaJeztah Sep 16, 2026
7cae8eb
Merge pull request #53691 from thaJeztah/add_replace
thaJeztah Sep 16, 2026
c5c10de
Merge pull request #53683 from thaJeztah/bump_compress
thaJeztah Sep 16, 2026
398ad31
client: deprecate WithResponseHook in favor of WithHTTPResponseHook
thaJeztah Sep 11, 2026
d2c7d13
integration-cli: remove redundant TestContainerAPIKill
ogulcanaydogan Sep 16, 2026
7073fb1
Merge pull request #53687 from AkihiroSuda/almalinux
vvoland Sep 16, 2026
e80eb37
Merge pull request #53684 from thaJeztah/bump_securejoin
vvoland Sep 16, 2026
1766f10
fix(deps): update aws-sdk-go-v2 monorepo
renovate-bot Sep 16, 2026
a31a432
fix(deps): update module github.com/mdlayher/socket to v0.7.0
renovate-bot Sep 16, 2026
05e5685
integration: skip TestStatsNetworkStats in rootless mode
AkihiroSuda Sep 16, 2026
d3b07d8
CI: run the VM integration tests on openSUSE Tumbleweed
AkihiroSuda Sep 16, 2026
6d68b44
daemon/container: include routed port bindings in container summaries
thaJeztah Sep 16, 2026
7f4424a
Merge pull request #53669 from ogulcanaydogan/fix/50159-remove-redund…
thaJeztah Sep 16, 2026
bb57a17
vendor: github.com/bits-and-blooms/bitset v1.25.0
thaJeztah Sep 16, 2026
cc50635
vendor: github.com/fxamacker/cbor/v2 v2.9.4
thaJeztah Sep 16, 2026
401ad75
renovate: Track the Windows Buildx version through an inline comment
vvoland Sep 16, 2026
20bbef7
renovate: Track the dev-container Docker CLI version
vvoland Sep 16, 2026
fd211c2
renovate: Remove the release-age delay for Buildx and Docker CLI
vvoland Sep 16, 2026
49dcc8e
Merge pull request #53693 from thaJeztah/ps_routed_binding
vvoland Sep 16, 2026
4f101e9
Merge pull request #53696 from thaJeztah/bump_bitset
vvoland Sep 16, 2026
f4fcf85
Merge pull request #53666 from thaJeztah/rename_withresponsehook
vvoland Sep 16, 2026
ad141db
client: postRaw: use consistent order or arguments
thaJeztah Sep 15, 2026
e20629c
Merge pull request #53697 from thaJeztah/bump_cbor
thaJeztah Sep 16, 2026
8e242c9
.github/workflows: Reject AI agent co-authors in PR commits
vvoland Sep 16, 2026
1b02d26
Merge pull request #53698 from vvoland/renovate-buildx
thaJeztah Sep 16, 2026
1b72393
chore(deps): update dependency docker/cli to v29.8.1
renovate-bot Sep 16, 2026
719d1ae
fix(deps): update module github.com/hashicorp/serf to v0.11.0
renovate-bot Sep 16, 2026
35ab918
Dockerfile: update to containerd v2.4.0
thaJeztah Aug 19, 2026
083b92f
Merge pull request #53612 from renovate-bot/renovate/github.com-mdlay…
thaJeztah Sep 17, 2026
1f1991c
Merge pull request #53663 from macieklamberski/osl-fdb-replace
thaJeztah Sep 17, 2026
3c84db9
Merge pull request #53702 from renovate-bot/renovate/docker-cli-29.x
thaJeztah Sep 17, 2026
141fb76
chore(deps): update docker/buildx-bin docker tag to v0.37.1
renovate-bot Sep 17, 2026
67f31d1
Merge pull request #53668 from renovate-bot/renovate/docker-buildx-bi…
thaJeztah Sep 17, 2026
b0a4687
Merge pull request #53704 from renovate-bot/renovate/github.com-hashi…
thaJeztah Sep 17, 2026
41a024b
Merge pull request #53504 from renovate-bot/renovate/aws-sdk-go-v2-mo…
thaJeztah Sep 17, 2026
4653231
chore(deps): update docker github actions
renovate-bot Sep 17, 2026
f304656
vendor: github.com/intel/goresctrl v0.13.0
thaJeztah Aug 11, 2026
e280245
vendor: github.com/containerd/go-cni v1.1.14
thaJeztah Sep 15, 2026
4c33c14
vendor: github.com/containernetworking/cni v1.3.1
thaJeztah Sep 15, 2026
e0cf8da
vendor: github.com/containerd/containerd/api v1.12.0
thaJeztah Aug 11, 2026
1dd648d
vendor: github.com/containerd/containerd/v2 v2.4.0
thaJeztah Aug 11, 2026
3231fdf
Merge pull request #53705 from renovate-bot/renovate/docker-actions
thaJeztah Sep 17, 2026
4bcb0c6
fix(deps): update github.com/moby/profiles/apparmor digest to 245180c
renovate-bot Sep 17, 2026
e39122e
client: rename client_responsehook.go -> client_hook.go
thaJeztah Sep 16, 2026
a324b83
client: rename responseHookTransport -> hookTransport
thaJeztah Sep 16, 2026
38e7314
client: prevent response hooks from consuming response body
thaJeztah Sep 14, 2026
badec8a
Merge pull request #53707 from renovate-bot/renovate/github.com-moby-…
thaJeztah Sep 17, 2026
b3dae76
Merge pull request #53667 from thaJeztah/improve_withresponsehook
thaJeztah Sep 17, 2026
b68bc6a
Merge pull request #53677 from thaJeztah/postraw_align
thaJeztah Sep 17, 2026
9e38a2d
Merge pull request #53664 from AkihiroSuda/ci-opensuse
vvoland Sep 17, 2026
43fc68c
Merge pull request #53695 from vvoland/assistedby
vvoland Sep 17, 2026
a24e541
gha: Remove broken sync-release-branch
vvoland Sep 17, 2026
34eea0a
Merge pull request #53712 from vvoland/gha-cleanup
thaJeztah Sep 17, 2026
0b6e0ca
Merge pull request #53361 from thaJeztah/vendor_containerd_2.4
thaJeztah Sep 17, 2026
41defc7
Merge pull request #53410 from thaJeztah/bump_containerd_bin_2.4
thaJeztah Sep 17, 2026
00b5d59
api/scripts: Allow isolated model generation with an API directory
vvoland Sep 11, 2026
70ee133
d/libn/networkdb: stop "purging" (no-op) left nodes
corhere Sep 15, 2026
cf89531
d/libn/networkdb: forget nodes which have left
corhere Sep 15, 2026
d6c7242
d/libn/networkdb: name the node state transitions
corhere Sep 16, 2026
73080e2
d/libn/networkdb: don't evict live peer on address collision
corhere Sep 14, 2026
a107266
Merge pull request #53688 from corhere/networkdb-reincarnation-fix
thaJeztah Sep 17, 2026
7420e62
daemon: fix docker cp with nested bind mounts
corhere Sep 17, 2026
9d3d6b4
fix(deps): update module google.golang.org/grpc to v1.84.0
renovate-bot Sep 18, 2026
ec16341
integration/image: Add regression test for pulls with retained snapshots
vvoland Sep 8, 2026
b829026
daemon/containerd: Always fetch missing layer content
vvoland Sep 10, 2026
f574f49
Merge pull request #53629 from vvoland/swaggergen-dir
thaJeztah Sep 18, 2026
053d561
Merge pull request #53719 from renovate-bot/renovate/google.golang.or…
thaJeztah Sep 18, 2026
67abf6e
Merge pull request #53716 from corhere/claude/nested-bind-mount-socke…
vvoland Sep 18, 2026
255cb3a
linting: ignore some dupwords false positives
thaJeztah Sep 15, 2026
669df54
daemon/libnetwork: resolver: ignore gosec G404
thaJeztah Sep 15, 2026
a30215c
daemon/libnetwork: fix G703, G705 (gosec)
thaJeztah Sep 15, 2026
cc63241
daemon/libnetwork: portConfigs: fix QF1012 (staticcheck)
thaJeztah Sep 15, 2026
eb6fdda
contrib/apparmor: fix gosec linting (G703)
thaJeztah Sep 15, 2026
dd00ec5
daemon: fix gosec linting (G703)
thaJeztah Sep 15, 2026
0a0a20a
daemon/graphdriver/overlay2, fuse-overlayfs: fix GoSec linting (G703)
thaJeztah Sep 15, 2026
917d5f5
daemon/graphdriver/overlay2: fix logging
thaJeztah Sep 15, 2026
01750a3
daemon/builder/remotecontext: use named error-return for defer
thaJeztah Sep 15, 2026
3959d80
integration/plugin/common: fix gosec G117 linting
thaJeztah Sep 15, 2026
3bc7ba2
builder-next: suppress SA1019 for deprecated Prestart hook
thaJeztah Sep 15, 2026
7c60545
builder-next: fix G118: Goroutine uses context.Background (gosec)
thaJeztah Sep 15, 2026
326dbc4
daemon/internal/distribution/metadata: fix G117 (gosec)
thaJeztah Sep 15, 2026
71be958
daemon/internal/rootless: fix G703 (gosec)
thaJeztah Sep 15, 2026
bf87aa3
internal/testutil: fix G703 (gosec)
thaJeztah Sep 15, 2026
6542cfe
daemon/internal: ignore G710 in test (gosec)
thaJeztah Sep 15, 2026
af03216
daemon/pkg/registry: fix G119 (gosec)
thaJeztah Sep 15, 2026
b5089cc
tarsum: migrate xattr tests to PAXRecords
thaJeztah Sep 15, 2026
c934be9
Merge pull request #53615 from vvoland/fix-missing-content
thaJeztah Sep 18, 2026
3ae1f88
integration; TestImagePullWithExistingSnapshot use resp.Wait
thaJeztah Sep 18, 2026
ebeca06
fix(deps): update github.com/azure/go-ansiterm digest to e937bb4
renovate-bot Sep 19, 2026
54c576a
fix(deps): update github.com/moby/extensions digest to e4c23d8
renovate-bot Sep 19, 2026
bfd255c
Merge pull request #53718 from renovate-bot/renovate/github.com-moby-…
thaJeztah Sep 19, 2026
430174a
Merge pull request #53728 from renovate-bot/renovate/github.com-azure…
thaJeztah Sep 19, 2026
91a74fa
fix(deps): update github.com/moby/swarmkit/v2 digest to 1fd637b
renovate-bot Sep 19, 2026
8acb5b5
Merge pull request #53729 from renovate-bot/renovate/github.com-moby-…
thaJeztah Sep 19, 2026
005aab0
fix(deps): update module cloud.google.com/go/compute/metadata to v0.9.1
renovate-bot Sep 19, 2026
5b1ad48
go.mod: github.com/gofrs/flock v0.13.1
AkihiroSuda Sep 19, 2026
9598f72
go.mod github.com/rootless-containers/rootlesskit/v3 v3.2.0
AkihiroSuda Sep 19, 2026
7d14f76
Update RootlessKit (3.2.0)
AkihiroSuda Sep 19, 2026
b7d48e3
Merge pull request #53607 from AkihiroSuda/rootlesskit
AkihiroSuda Sep 19, 2026
5c47efc
Merge pull request #53732 from renovate-bot/renovate/cloud.google.com…
thaJeztah Sep 19, 2026
69cab64
Update codecov/codecov-action action to v7.1.1
renovate-bot Sep 20, 2026
72752cf
Merge pull request #53717 from renovate-bot/renovate/codecov-codecov-…
thaJeztah Sep 20, 2026
2630d63
Merge pull request #53726 from thaJeztah/simplify_TestImagePullWithEx…
vvoland Sep 21, 2026
caf672f
Merge pull request #53681 from thaJeztah/fix_linting
vvoland Sep 21, 2026
ece3258
Add peer credential extraction middleware for Unix sockets
reboss May 6, 2026
2bd0948
Add unit tests for peer credential middleware
reboss May 6, 2026
b866c57
Add cgroup derivation utility for user cgroup adoption
reboss May 6, 2026
4731547
Add unit tests for cgroup derivation
reboss May 6, 2026
1cb013b
Add AdoptUserCgroups daemon config option
reboss May 6, 2026
3d7f797
Register --adopt-user-cgroups CLI flag
reboss May 6, 2026
0bce32f
Register peer credential middleware in daemon initialization
reboss May 6, 2026
b3a5fc0
Add test stubs for cgroup adoption enforcement
reboss May 6, 2026
ba3bec5
Implement cgroup adoption enforcement in daemon
reboss May 6, 2026
b0d6a1c
Add integration tests for cgroup adoption feature
reboss May 6, 2026
69222ef
Store connection in HTTP server context for peer credential extraction
reboss May 11, 2026
50b0c39
cgroups: adopt full cgroup path instead of just slice
reboss May 11, 2026
b95adc5
server: add peer credential extraction middleware
reboss May 11, 2026
09b741e
daemon: register peer credential middleware and ConnContext
reboss May 11, 2026
7714363
server: clean up whitespace
reboss May 11, 2026
32a2397
tests: update cgroup adoption and peer credential tests
reboss May 11, 2026
d4bbcc3
Trigger PR refresh
reboss Sep 21, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
4 changes: 2 additions & 2 deletions .devcontainer/devcontainer.json
Original file line number Diff line number Diff line change
Expand Up @@ -5,8 +5,8 @@
"dockerfile": "../Dockerfile",
"target": "devcontainer"
},
"workspaceFolder": "/go/src/github.com/docker/docker",
"workspaceMount": "source=${localWorkspaceFolder},target=/go/src/github.com/docker/docker,type=bind,consistency=cached",
"workspaceFolder": "/usr/src/moby",
"workspaceMount": "source=${localWorkspaceFolder},target=${containerWorkspaceFolder},type=bind,consistency=cached",

"remoteUser": "root",
"runArgs": ["--privileged"],
Expand Down
7 changes: 7 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -1 +1,8 @@
Dockerfile* linguist-language=Dockerfile

*.c diff=cpp
*.h diff=cpp
*.go diff=golang
*.md diff=markdown
*.py diff=python
*.sh diff=bash
13 changes: 0 additions & 13 deletions .github/CODEOWNERS

This file was deleted.

2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Bug report
description: Create a report to help us improve
type: "bug"
labels:
- kind/bug
- status/0-triage
body:
- type: markdown
attributes:
Expand Down
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/feature_request.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Feature request
description: Missing functionality? Come tell us about it!
type: "enhancement"
labels:
- kind/feature
- status/0-triage
body:
- type: textarea
id: description
Expand Down
22 changes: 22 additions & 0 deletions .github/ISSUE_TEMPLATE/flaky_test.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
name: Flaky test
description: Report a test that fails intermittently
title: "Flaky test: "
type: "bug"
labels:
- flaky
body:
- type: textarea
id: description
attributes:
label: Description
description: Add optional context, such as CI links, affected platforms or jobs, passing runs, frequency, suspected cause, or related issues
validations:
required: false
- type: textarea
id: failure_output
attributes:
label: Failure output
description: Paste the complete failure output, including the fully qualified test name
render: text
validations:
required: false
41 changes: 23 additions & 18 deletions .github/PULL_REQUEST_TEMPLATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,35 +2,40 @@
Please make sure you've read and understood our contributing guidelines;
https://github.com/moby/moby/blob/master/CONTRIBUTING.md

** Make sure all your commits include a signature generated with `git commit -s` **
Make sure commits are signed off (`git commit -s`) with your real name.

For additional information on our contributing process, read our contributing
guide https://github.com/moby/moby/blob/master/docs/contributing/
To explicitly stress-test specific integration tests for flakiness in CI,
add a /flaky-check directive anywhere in the PR body (outside of comments):
/flaky-check=TestFoo,TestBar

If this is a bug fix, make sure your description includes "fixes #xxxx", or
"closes #xxxx"
If the PR relates to an existing issue or PR, mention it at the top:

Please provide the following information:
- Fixes: https://github.com/moby/moby/issues/12345678
- Replaces: https://github.com/moby/moby/pull/12345678
- Follow up to: https://github.com/moby/moby/pull/12345678
- Related to: https://github.com/moby/moby/issues/12345678
-->

**- What I did**
## Summary

**- How I did it**
## Release notes (optional)

**- How to verify it**

**- Human readable description for the release notes**
<!--
Write a short (one line) summary that describes the changes in this
pull request for inclusion in the changelog.
It must be placed inside the below triple backticks section.
One-sentence user-facing release note.
Leave empty if the change is not changelog-worthy.
Use present tense and imperative tone.

Good:
- Fix a panic when running `docker top` on a non-running Windows container.
- Don't print warnings in `docker info` for broken symlinks in CLI plugin directories.

NOTE: Only fill this section if changes introduced in this PR are user-facing.
The PR must have a relevant impact/ label.
Bad:
- Refactor test TestFooWithBar
- Fixed a panic when running docker top
-->

```markdown changelog

```

**- A picture of a cute animal (not mandatory but encouraged)**

## A picture of a cute animal (not mandatory but encouraged)
31 changes: 31 additions & 0 deletions .github/actions/ensure-windows-docker/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
name: 'Ensure Windows Docker'
description: 'Ensure the Docker daemon is ready on Windows runners'

runs:
using: composite
steps:
- run: |
$tries = 30
Write-Host "Waiting for Docker daemon..."
while ($true) {
$ErrorActionPreference = "SilentlyContinue"
docker version 2>&1 | Out-Null
$ok = ($LastExitCode -eq 0)
$ErrorActionPreference = "Stop"
if ($ok) { break }
# Check if Docker service exists and try to start it if stopped
$svc = Get-Service docker -ErrorAction SilentlyContinue
if ($svc) {
if ($svc.Status -ne 'Running') {
Write-Host "Docker service status: $($svc.Status) - attempting to start..."
Start-Service docker -ErrorAction SilentlyContinue
}
} else {
Write-Host "Docker service not found!"
}
$tries--
if ($tries -le 0) { throw "Docker daemon did not become ready" }
Start-Sleep -Seconds 2
}
docker info
shell: pwsh
121 changes: 121 additions & 0 deletions .github/actions/setup-windows-test-daemon/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,121 @@
name: 'Setup Windows test daemon'
description: 'Set up the Windows test daemon as a service'

inputs:
bin_out:
description: 'Path containing the Docker binaries'
required: true
containerd:
description: 'Containerd mode (embedded or external)'
required: true
runtime:
description: 'Runtime mode (containerd or legacy)'
required: true
storage:
description: 'Storage mode (snapshotter or graphdriver)'
required: true

runs:
using: composite
steps:
-
# Docker is not installed as a PackageManagement package, so remove its
# service directly to let the test daemon register under the same name.
name: Removing current daemon
shell: pwsh
run: |
if (Get-Service docker -ErrorAction SilentlyContinue) {
$dockerVersion = (docker version -f "{{.Server.Version}}")
Write-Host "Current installed Docker version: $dockerVersion"
# remove service
Stop-Service -Force -Name docker
Remove-Service -Name docker
# removes event log entry. we could use "Remove-EventLog -LogName -Source docker"
# but this cmd is not available atm
$ErrorActionPreference = "SilentlyContinue"
& reg delete "HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\docker" /f 2>&1 | Out-Null
$ErrorActionPreference = "Stop"
Write-Host "Service removed"
}
-
name: Starting test daemon
shell: pwsh
env:
BIN_OUT: ${{ inputs.bin_out }}
INPUT_CONTAINERD: ${{ inputs.containerd }}
INPUT_RUNTIME: ${{ inputs.runtime }}
INPUT_STORAGE: ${{ inputs.storage }}
run: |
Write-Host "Creating service"
$args = @(
"--debug",
"--host=npipe:////./pipe/docker_engine", `
"--data-root=$env:TEMP\moby-root", `
"--exec-root=$env:TEMP\moby-exec", `
"--pidfile=$env:TEMP\docker.pid", `
"--register-service"
)
If ($env:INPUT_CONTAINERD -eq "embedded") {
$args += "--feature=embedded-containerd"
} ElseIf ($env:INPUT_RUNTIME -eq "containerd") {
$args += "--default-runtime=io.containerd.runhcs.v1"
echo "DOCKER_WINDOWS_CONTAINERD_RUNTIME=1" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf-8 -Append
}
if ($env:INPUT_STORAGE -eq "snapshotter") {
$args += "--feature=containerd-snapshotter"
}
New-Item -ItemType Directory "$env:TEMP\moby-root" -ErrorAction SilentlyContinue | Out-Null
New-Item -ItemType Directory "$env:TEMP\moby-exec" -ErrorAction SilentlyContinue | Out-Null
Start-Process -Wait -NoNewWindow "$env:BIN_OUT\dockerd" -ArgumentList $args
# Make the env-var visible to the service-managed dockerd, as there's no CLI flag for this option.
$dockerEnviron = @("DOCKER_MIN_API_VERSION=1.24")
$dockerEnviron += @(Get-Item Env:\OTEL_* -ErrorAction SilentlyContinue | ForEach-Object { "$($_.Name)=$($_.Value)" })
If ($env:INPUT_STORAGE -eq "graphdriver") {
$dockerEnviron += @("TEST_INTEGRATION_USE_GRAPHDRIVER=1")
echo "TEST_INTEGRATION_USE_GRAPHDRIVER=1" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf-8 -Append
}
If ($env:INPUT_CONTAINERD -eq "embedded") {
$dockerEnviron += @("TEST_INTEGRATION_CONTAINERD_EMBEDDED=1")
echo "TEST_INTEGRATION_CONTAINERD_EMBEDDED=1" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf-8 -Append
}
New-ItemProperty -Name "Environment" -Path "HKLM:\SYSTEM\CurrentControlSet\Services\docker" -PropertyType MultiString -Value $dockerEnviron
Write-Host "Starting service"
Start-Service -Name docker
Write-Host "Service started successfully!"
-
name: Waiting for test daemon to start
shell: pwsh
env:
BIN_OUT: ${{ inputs.bin_out }}
INPUT_CONTAINERD: ${{ inputs.containerd }}
INPUT_RUNTIME: ${{ inputs.runtime }}
DOCKER_HOST: npipe:////./pipe/docker_engine
run: |
$tries=20
Write-Host "Waiting for the test daemon to start..."
While ($true) {
$ErrorActionPreference = "SilentlyContinue"
& "$env:BIN_OUT\docker" version
$ErrorActionPreference = "Stop"
If ($LastExitCode -eq 0) {
break
}
$tries--
If ($tries -le 0) {
Throw "Failed to get a response from the daemon"
}
Write-Host -NoNewline "."
Start-Sleep -Seconds 1
}
Write-Host "Test daemon started and replied!"
If ($env:INPUT_CONTAINERD -eq "external" -and $env:INPUT_RUNTIME -eq "containerd") {
$containerdProcesses = Get-Process -Name containerd -ErrorAction:SilentlyContinue
If (-not $containerdProcesses) {
Throw "containerd process is not running"
} else {
foreach ($process in $containerdProcesses) {
$processPath = (Get-Process -Id $process.Id -FileVersionInfo).FileName
Write-Output "Running containerd instance binary Path: $($processPath)"
}
}
}
2 changes: 2 additions & 0 deletions .github/copilot-instructions.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
- When reviewing pull requests, do not rely only on the PR title, labels, or autogenerated dependency bump message. Inspect the actual diff and describe the likely behavioral, build, test, security, and compatibility impact.
- For changes that appear mechanical, check whether they affect daemon behavior, client behavior, API compatibility, packaging, CI reliability, supported platforms, or released artifacts.
15 changes: 15 additions & 0 deletions .github/instructions/review-ci-and-action-bumps.instructions.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# Review CI and action bumps carefully

For GitHub Actions, CI, toolchain, base image, or packaging bump PRs, review the effective change, not just the version or SHA update.

Check for impact on:

- workflow permissions and token usage
- defaults, inputs, deprecated behavior, and runner compatibility
- test reliability and coverage
- release, packaging, provenance, and published artifacts
- cache behavior, artifact handling, reproducibility, and multi-platform builds

Do not approve only because the change is in workflows, is SHA-pinned, or CI passes.

In the review summary, state what changed, what was inspected, and any remaining risk or recommended verification.
15 changes: 15 additions & 0 deletions .github/instructions/review-go-dependency-bumps.instructions.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
# Review Go dependency bumps carefully

For Go module, `go.sum`, and `vendor/` bump PRs, review the actual code changes, not just the version bump.

Check for impact on:

- daemon or API behavior
- container runtime, networking, storage, archive, registry, and BuildKit-related paths
- syscall, namespace, cgroup, mount, or rootless behavior
- transitive dependency changes
- major version jumps, default changes, error handling changes, or hidden logic changes in vendored churn

Do not approve only because the PR is autogenerated, the version bump is small, or CI passes.

In the review summary, state what changed, what relevant code paths were inspected, and any remaining risk or need for targeted testing.
1 change: 1 addition & 0 deletions .github/labeler.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,7 @@ area/networking:
- 'api/types/network/**'
- 'daemon/network*'
- 'daemon/network/**'
- 'daemon/libnetwork/**'
- 'integration/network/**'
- 'integration/networking/**'

Expand Down
29 changes: 29 additions & 0 deletions .github/renovate.json5
Original file line number Diff line number Diff line change
Expand Up @@ -9,13 +9,42 @@
":gitSignOff"
],
"postUpdateOptions": ["gomodTidy"],
"minimumReleaseAge": "3 days",
"internalChecksFilter": "strict",
"customManagers": [
{
"customType": "regex",
"managerFilePatterns": ["/^Dockerfile$/"],
"matchStrings": [
"# renovate: datasource=(?<datasource>\\S+) depName=(?<depName>\\S+) versioning=(?<versioning>\\S+)[ \\t]*\\r?\\n[ \\t]*ARG[ \\t]+\\w+=(?<currentValue>\\S+)"
]
},
{
"customType": "regex",
"managerFilePatterns": ["/^hack/make\\.ps1$/"],
"matchStrings": [
"# renovate: datasource=(?<datasource>\\S+) depName=(?<depName>\\S+) versioning=(?<versioning>\\S+)[ \\t]*\\r?\\n[ \\t]*\\$\\w+[ \\t]*=[ \\t]*\"(?<currentValue>[^\"]+)\""
]
}
],
"packageRules": [
{
"matchDatasources": ["docker", "github-tags"],
"matchDepNames": ["docker/buildx-bin", "docker/cli"],
"minimumReleaseAge": "0 days"
},
{
"matchManagers": ["gomod"],
"groupName": "golang.org/x packages",
"groupSlug": "golang-x",
"matchDepNames": ["/^golang\\.org\\/x\\//"]
},
{
"matchManagers": ["github-actions"],
"groupName": "docker GitHub Actions",
"groupSlug": "docker-actions",
"matchDepNames": ["/^docker\\//"]
},
{
// Keep all the google.golang.org/genproto modules at the same version.
"matchManagers": ["gomod"],
Expand Down
Loading
Loading