惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
MyScale Blog
MyScale Blog
T
Tailwind CSS Blog
量子位
有赞技术团队
有赞技术团队
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
爱范儿
爱范儿
The Last Watchdog
The Last Watchdog
F
Fortinet All Blogs
博客园 - 叶小钗
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美
Recent Announcements
Recent Announcements
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Apple Machine Learning Research
Apple Machine Learning Research
云风的 BLOG
云风的 BLOG
Martin Fowler
Martin Fowler
美团技术团队
The GitHub Blog
The GitHub Blog
A
About on SuperTechFans
Stack Overflow Blog
Stack Overflow Blog
V
Visual Studio Blog
NISL@THU
NISL@THU
Last Week in AI
Last Week in AI
V
V2EX
S
Secure Thoughts
阮一峰的网络日志
阮一峰的网络日志
C
CXSECURITY Database RSS Feed - CXSecurity.com
U
Unit 42
T
The Blog of Author Tim Ferriss
雷峰网
雷峰网
宝玉的分享
宝玉的分享
P
Proofpoint News Feed
腾讯CDC
Attack and Defense Labs
Attack and Defense Labs
L
Lohrmann on Cybersecurity
J
Java Code Geeks
S
Securelist
P
Privacy International News Feed
Google Online Security Blog
Google Online Security Blog
M
MIT News - Artificial intelligence
N
News and Events Feed by Topic
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Forbes - Security
Forbes - Security
V
Vulnerabilities – Threatpost
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
博客园 - 三生石上(FineUI控件)
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
W
WeLiveSecurity
Webroot Blog
Webroot Blog

Open Container Initiative

OCI Runtime Spec v1.3 - Open Container Initiative OCI Image and Distribution Specs v1.1 Releases OCI Runtime Spec v1.2 - Open Container Initiative OCI in 2024 and TOB Election Results Summary of Upcoming Changes in OCI Image and Distribution Specs v1.1 OCI at The Container Plumbing Conference OCI in 2023 and TOB Election Results OCI in 2022 and TOB Election Results OCI Member Spotlight – Chainguard Calling All Registries to Submit OCI Conformance! OCI Summit 2021 - Open Container Initiative Introducing fuzzing for runC and Umoci OCI in 2021 and TOB Election Results Consuming Public Content - Open Container Initiative OCI accepts new project, umoci Introducing and open sourcing the OCI Icon Set Open Sourcing runc Security Audit Container Journal – “OCI Launches Artifacts Project to Reduce Registries Required” New OCI Artifacts Project - Open Container Initiative Open Container Initiative Explained…with Dolls! OCI 2019 Elections and New TOB Lineup 2018’s Biggest Moments + What’s Coming for OCI in 2019 Bringing OCI images to the desktop with Flatpak OCI Image Support Comes to Open Source Docker Registry Open Container Initiative Welcomes Alibaba Cloud as Newest Member PouchContainer – How OCI Specifications Power Alibaba CRI-O – How Standards Power a Container Runtime OCI Member Spotlight – OpenStack (Kata Containers) Teaming up with Docker to Support a Diverse Container Ecosystem The New Stack – “Open Container Initiative Creates a Distribution Specification for Registries” SDxCentral – “OCI Standardizes Container Image Distribution Based on Docker Registry” ZDNet – “​Open Container Initiative nails down container image distribution standard” Container Journal – “OCI Standardizes Container Registry Protocol” Distribution-Spec is Here! - Open Container Initiative OCI Announces 2018 TOB Election Results OCI Member Spotlight – Kontena Windows ITPro – Using Containers? Look for the OCI Seal of Approval SiliconAngle - Why the new Open Container Initiative standard is a milestone for software OCI Welcomes New Project Maintainers OCI Member Spotlight – EasyStack SDxCentral – Open Container Initiative Marks Success, Looks for What’s Next Fostering Diversity and Inclusivity at DockerCon Europe eWeek – Open Container Initiative Specifications Reach 1.0 Milestone GeekWire – Cloud computing’s Open Container Initiative hits the 1.0 release milestone InformationWeek – Unity Rules As OCI Launches 1.0 Container Spec OCI v1.0 – Bringing Containers Closer to Standardization TechCrunch – The Open Container Initiative launches version 1.0 of its container specs The New Stack – OCI’s Long-Awaited Container Runtime and Image Specifications Hit the Streets The Register – Contain(er) your enthusiasm, nerds – Docker-backed OCI runtime spec hits 1.0 ZDNet – Containers consolidation – Open Container Initiative 1.0 released Open Container Initiative (OCI) Releases v1.0 of Container Standards OCI Member Spotlight – CoreOS OCI Member Spotlight – Cycle.io Join OCI for OSCON’s Open Container Day Innovative Cloud Organizations Join the Open Container Initiative to Help Shape Industry Container Standards OCI Member Spotlight – Mesosphere OCI Member Spotlight – Univa OCI Member Spotlight – Wercker OCI Member Spotlight – IBM OCI Member Spotlight – Rancher Labs OCI Moves into 2017 - Open Container Initiative The OCI Applauds containerd and rkt to CNCF OCI Member Spotlight – ContainerShip OCI Member Spotlight – SUSE OCI Member Spotlight – Apcera OCI Member Spotlight – Portworx OCI Member Spotlight – Huawei OCI Member Spotlight – Pivotal OCI Member Spotlight – Fujitsu OCI Member Spotlight – Weaveworks OCI Member Spotlight – Red Hat OCI Member Spotlight – Google help-guide-the-future-of-container-technology-through-the-open-container-initiative - Open Container Initiative developerWorks Webcast Recap – Open Container Initiative at 12 months OCI Member Spotlight – Intel OCI Member Spotlight – Microsoft Docker 1.11 – The first runtime built on containerd and based on OCI technology Celebrating the Open Container Initiative Image Specification New Image Specification Project for Container Images Open Container Initiative Launches a Container Image Format Spec Open Container Format Progress Report Community Rallies Behind Open Container Initiative Industry Leaders Unite to Create Project for Open Container Standards About the Open Container Initiative Community Overview - Open Container Initiative Contact us - Open Container Initiative FAQ - Open Container Initiative Join - Open Container Initiative Leadership - Open Container Initiative OCI Certified - Open Container Initiative OCI distribution-spec v 1.0.0 release notice OCI distribution-spec v 1.0.1 release notice OCI distribution-spec v. 1.1.0 release notice OCI distribution-spec v. 1.1.1 release notice OCI image-spec v. 1.0.1 release notice OCI image-spec v. 1.0.2 release notice OCI image-spec v. 1.1.0 release notice OCI image-spec v. 1.1.1 release notice OCI runtime-spec v. 1.0.1 release notice OCI runtime-spec v. 1.0.2 release notice
OCI Runtime Spec v1.1 - Open Container Initiative
map[name:Open Container Initiative tag:oci] · 2026-05-31 · via Open Container Initiative

We are delighted to annouce the release of the OCI Runtime Spec v1.1.0 today. This release contains about 80 pull requests that were merged in the last three years. We appreciate everybody who contributed to this release.

What is the OCI Runtime Spec?

The OCI Runtime Spec defines the behavior and the configuration interface of low-level container runtimes such as runc. The spec is also implemented by crun, youki, gVisor, Kata Containers, and others. These low-level container runtimes are usually called from high-level container runtimes such as containerd and CRI-O.

“Breaking” Changes

config: change prestart hook spec to match reality (#1169)

In the OCI Runtime Spec v1.0, prestart hooks were required to be called during the start operation. This was contrary to the actual implementation of runc, which calls prestart hooks as a part of the create operation. The spec was partially revised to fix this several years ago with the addition of new lifecycle hooks and the deprecation of the prestart hook but the text was confusing and didn’t full explain the correct recommendations for implementations.

The spec has now been revised to completely resolve this issue and make the (deprecated) prestart hook have the same behaviour as the actual runc implementation. Technically, this is a “breaking” change of the spec, but given that existing runtimes have already implemented this behaviour (even before the runtime-spec 1.0.0 release), and the specification already included text dealing with this issue we do not feel this warrants a major version bump.

Deprecations

The memory.kernel and memory.kernelTCP resource configurations are now marked as deprecated, as the upstream Linux kernel has deprecated the support for setting kernel memory limits since 5.4.

Note that runc has ignored these configuration settings since runc v1.0.0-rc94.

Additions

cgroup: add cgroup v2 support (#1040)

The spec now has the native support for cgroup v2. Implementations no longer need to “emulate” v1 configuration on v2 hosts.

This has been already implemented in runc since runc v1.0.0-rc93.

seccomp: support RISC-V 64 (#1059)

The spec now supports the RISC-V (riscv64) architecture.

runc supports RISC-V since runc v1.1.8.

seccomp: add Seccomp Notify support (#1074)

The spec now supports seccomp_unotify (since Linux kernel v5.0) to allow hooking syscalls from user-space. For example, this is useful for accelerating networking of rootless containers by hooking syscalls and replacing file descriptors from the host.

The support for seccomp_unotify has been already implemented in runc since runc v1.1.0-rc.1.

config: add IDMapping field for mount point (#1143)

The spec now supports ID-mapped mounts using MOUNT_ATTR_IDMAP (since Linux kernel v5.12). This eliminates the overhead of chown that was an obstacle to adopt user namespaces, though it should be noted that the rootfs cannot have idmapped mounts configured so higher-level runtimes will need to implement rootfs idmapping (which is fairly trivial).

This was recently implemented in the main branch of runc. Will be included in runc v1.2.0.

features: add features.md to formalize the runc features JSON (#1130)

runc features (since runc v1.1-rc.1) is a command that prints the information about the compiled-in features such as the recognized mount options and the recognized seccomp architectures.

The information structure is now officially part of the spec.

config-linux: add support for time namespace (#1151)

Time namespaces (since Linux kernel v5.6) allows isolating the CLOCK_MONOTONIC and the CLOCK_BOOTTIME clocks from the host and from other containers. This is especially useful for checkpointing with CRIU.

Note that the CLOCK_REALTIME clock (the best known Linux clock) is not isolated with time namespaces.

runc doesn’t implement time namespaces yet, but there is a pull request to implement it.

Other changes

See here for the list of the full changes.

Coincidentally, OCI Image Spec v1.1 and OCI Distribution Spec v1.1 are planned to be released soon too.

However, it should be noted that the specs are usually not intended to be released in ensemble. The next releases of the specs will be probably made separately.

What’s next?

See the GitHub issues and the pull requests for the proposals toward the future releases. e.g.,

You are always welcome to submit your own proposals too.