docker-v29.8.0-rc.1Pre-release
v29.8.0-rc.1
Added 2
- Remote network-driver plugins can now set the container-side interface name via the DstName field in their Join response
- Reserve network names "container" and "container:" to prevent creation of unusable networks
Changed 7
- dockerd now uses the embedded containerd if no system containerd service is configured and containerd is not installed
- Update BuildKit to v0.33.0-rc1
- Update containerd (static binaries) to v2.3.4
- Update Go runtime to 1.26.7
- Update runc (in static binaries) to v1.5.1
- Reduce gossip traffic generated by a node that repeatedly disconnects and rejoins the cluster
- Spread the daemon's periodic Swarm overlay network gossip and synchronization work over time, avoiding recurring bursts of CPU and network usage
Fixed 10
- Fix docker image inspect reporting a smaller image size than docker image ls for containerd image store
- Do not log expected image signature identity misses as errors for containerd image store images
- Fix GET /images/{name}/json not including unpacked snapshot usage in Size when using the containerd image store
- Fix NRI container metadata so Container.Args includes the resolved executable as argv[0], matching the process launched in the container
- Fix Swarm service creation failing when an automatically generated name is already in use
- Fix docker ps sorting published ports lexicographically instead of numerically
- Fix docker network inspect failing to find a healthy Swarm network when another Swarm network could not be allocated
- Fix a node gossiping a superseded value for a Swarm service discovery entry after concurrent updates to the same key
- Fix Swarm service names failing to resolve on a node indefinitely after it misses a network membership announcement
- Fix Swarm service names failing to resolve on healthy nodes after a transient node failure
Security 1
- Reject checkpoint IDs containing path separators to prevent access outside the container checkpoint directory
From Docker Engine
29.8.0-rc.1
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Bug fixes and enhancements
- containerd image store: Fix
docker image inspectreporting a smaller image size thandocker image ls. moby/moby#53426 - Do not log expected image signature identity misses as errors for containerd image store images. moby/moby#53495
- dockerd now uses the embedded containerd if no system containerd service is configured and containerd is not installed. moby/moby#53388
- Fix
GET /images/{name}/jsonnot including unpacked snapshot usage inSizewhen using the containerd image store. moby/moby#53426 - Fix NRI container metadata so
Container.Argsincludes the resolved executable asargv[0], matching the process launched in the container instead of only the DockerCmd. moby/moby#53423 - Fix Swarm service creation failing when an automatically generated name is already in use. moby/moby#53468
- Fixed
docker pssorting published ports lexicographically instead of numerically. docker/cli#7144 - Reject checkpoint IDs containing path separators to prevent access outside the container checkpoint directory. moby/moby#53377
Packaging updates
- Update BuildKit to v0.33.0-rc1. moby/moby#53476
- Update containerd (static binaries) to v2.3.4. moby/moby#53409
- Update Go runtime to 1.26.7. docker/cli#7224, moby/moby#53413
- Update runc (in static binaries) to v1.5.1. moby/moby#52306
Networking
- Fix
docker network inspectfailing to find a healthy Swarm network when another Swarm network could not be allocated. moby/moby#53325 - Fix a node gossiping a superseded value for a Swarm service discovery entry after concurrent updates to the same key. moby/moby#53479
- Fix Swarm service names failing to resolve on a node indefinitely after it misses a network membership announcement. moby/moby#53437
- Fix Swarm service names failing to resolve on healthy nodes after a transient node failure. moby/moby#53142
- Reduce gossip traffic generated by a node that repeatedly disconnects and rejoins the cluster. moby/moby#53479
- Remote network-driver plugins can now set the container-side interface name via the
DstNamefield in theirJoinresponse. moby/moby#52866 - Reserve network names "container" and "container:" to prevent creation of unusable networks. moby/moby#51973
- Spread the daemon's periodic Swarm overlay network gossip and synchronization work over time, avoiding recurring bursts of CPU and network usage. moby/moby#53475
Rootless
- Fix
--disable-host-loopbacknot being enforced for thepastanetwork driver in rootless mode. moby/moby#53358 - Update RootlessKit to v3.1.0, adding support for the
pestoport driver in rootless mode. SetDOCKERD_ROOTLESS_ROOTLESSKIT_PORT_DRIVER=pestoto use it; it requires thepastanetwork driver and supports IPv4 only. moby/moby#53358