Menambahkan kembali modul yang dapat dimuat PPP, yang dihapus di
cos-77-12371-1072-0.
Memindahkan konfigurasi "registry-mirrors" Docker ke command line dockerd untuk mengatasi error penyediaan cluster Kubernetes.
cos-77-12371-1086-0
Tanggal: 08 Okt 2020
Memindahkan konfigurasi opsi "registry-mirrors" Docker dari
command line dockerd ke /etc/docker/daemon.json. Hal ini akan memungkinkan pengguna
mengonfigurasi mirror registry kustom, yang dapat berguna saat merespons
perubahan paket gratis Docker Hub baru-baru ini.
Memperbaiki CVE-2020-15157 di containerd.
cos-77-12371-1079-0
Tanggal: 05 Sep 2020
Memperbaiki kerentanan kernel Linux CVE-2020-14386 dengan memperbaiki masalah integer overflow di tpacket_rcv.
cos-77-12371-1073-0
Tanggal: 21 Agustus 2020
Mengaktifkan utmp di systemd untuk mengizinkan pembuatan file utmp.
cos-77-12371-1072-0
Tanggal: 10 Agustus 2020
Menonaktifkan CONFIG_PPP untuk memitigasi CVE-2020-14416 Kernel Linux.
Memperbaiki CVE-2020-15705 di grub.
cos-77-12371-1064-0
Tanggal: 30 Juli 2020
Menghapus daemon metrik untuk mengatasi masalah yang terkadang menyebabkan lonjakan penggunaan CPU dalam beberapa kasus.
cos-77-12371-326-0
Tanggal: 13 Juli 2020
Menambahkan rsync kembali ke image, yang dihapus di
cos-dev-77-12293-0-0.
Pasang /var/lib/containerd dengan opsi exec.
Memindahkan sumber Kernel ke cos.googlesource.com.
Memperbaiki CVE-2019-9169.
cos-77-12371-296-0
Tanggal: 16 Juni 2020
Memperbarui image container dasar toolbox untuk menyertakan patch keamanan.
cos-77-12371-274-0
Tanggal: 26 Mei 2020
Memperbaiki beberapa CVE Login OS: CVE-2020-8903, CVE-2020-8907, CVE-2020-8933.
cos-77-12371-273-0
Tanggal: 21 Mei 2020
Memperbaiki bug agen Stackdriver Monitoring yang menyebabkan tidak semua partisi disk yang di-mount melaporkan penggunaannya.
cos-77-12371-251-0
Tanggal: 29 April 2020
Memperbaiki bug kernel yang menyebabkan program eBPF dapat menyebabkan softlockup.
cos-77-12371-233-0
Tanggal: 29 April 2020
Menonaktifkan `accept_ra` di semua antarmuka secara default.
cos-77-12371-227-0
Tanggal: 05 Apr 2020
Mengupgrade kernel Linux ke v4.19.112.
Patch systemd ba0d56f55 telah di-backport untuk mengatasi masalah yang menyebabkan unit pemasangan bocor.
cos-77-12371-208-0
Tanggal: 17 Maret 2020
Mengaktifkan NETFILTER_XT_MATCH_SOCKET.
Memperbaiki bug ketika DHCP tidak dimulai setelah link terputus.
Menghapus batas ukuran pada /etc/ untuk memperbaiki kegagalan pembuatan cluster karena banyaknya add-on.
Mengupgrade kernel Linux ke v4.19.109.
cos-77-12371-183-0
Tanggal: 21 Februari 2020
Mengupgrade kernel Linux ke v4.19.104.
Memperbaiki bug skb TCP kosong di akhir antrean tulis dalam kernel.
cos-77-12371-175-0
Tanggal: 12 Februari 2020
Mengaktifkan beberapa opsi QoS dan Fair Queuing di kernel Linux.
Mengupgrade kernel Linux ke v4.19.102.
Mengupgrade runc ke 1.0.0-rc10. Perubahan ini mengatasi CVE-2019-19921.
cos-77-12371-141-0
Tanggal: 07 Januari 2020
Perbaikan yang di-backport untuk CVE-2019-19072 kernel Linux.
Masalah pembatasan kuota CFS telah diperbaiki.
Mengupgrade kernel Linux ke v4.19.91.
cos-77-12371-114-0
Tanggal: 31 Oktober 2019
Meningkatkan sysctl net.ipv4.tcp_limit_output_bytes menjadi 1048576.
Memperbaiki masalah pembuatan 8 proses status runc untuk setiap exec di containerd. Hal ini menyebabkan pemakaian CPU yang tinggi.
Memperbaiki pembuatan dua slice pengujian terpisah yang tidak perlu (sehingga menghasilkan total 4 pesan log systemd + overhead runtime) untuk setiap eksekusi runc.
Memperbaiki masalah di runc yang menyebabkan konsumsi CPU yang tidak perlu.
Mengupgrade kernel Linux ke v4.19.80.
Memperbaiki regresi performa di scheduler yang sepenuhnya adil (CFS).
cos-77-12371-89-0
Tanggal: 9 Oktober 2019
Mengupgrade kernel Linux ke 4.19.76.
Melakukan backport patch kernel untuk memastikan rasio kuota/periode cgroup cfs
selalu sama. Hal ini mengatasi masalah Kubernetes saat cgroup pod dapat berubah menjadi status yang tidak konsisten.
Melakukan backport patch kernel untuk memperbaiki regresi performa dalam wbt
scale_up/scale_down.
cos-77-12371-76-0 (vs. Milestone 73)
Tanggal: 27 September 2019
Fitur baru
Mengaktifkan Shielded VM secara default. Booting aman tidak diaktifkan secara
default.
Mengaktifkan mode hybrid cgroup v2 di systemd.
Menambahkan dukungan untuk driver balon virtio.
Menambahkan paket node-problem-detector.
Menambahkan paket conntrack-tools.
Menambahkan paket xfsprogs.
Update paket
Mengupgrade systemd ke versi 239.
Kernel Linux telah diupgrade ke versi 4.19.
Docker telah diupgrade ke versi 19.03.
Mengupgrade Kubelet ke versi 1.15.
Mengupgrade compute-image-packages ke versi 20190304.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-09-04 UTC."],[[["\u003cp\u003eThis image family, cos-77-lts, was deprecated after January 11, 2021, and runs on Linux kernel 4.19.112, Kubernetes v1.15.3, and Docker v19.03.1.\u003c/p\u003e\n"],["\u003cp\u003eMultiple security vulnerabilities, identified as CVEs, have been addressed within the Linux kernel and containerd components over various updates.\u003c/p\u003e\n"],["\u003cp\u003eThere have been various fixes to address issues regarding Docker's "registry-mirrors" configuration, as well as performance and stability enhancements related to resource management and network.\u003c/p\u003e\n"],["\u003cp\u003eSeveral updates focused on upgrading the Linux kernel to address bugs, add features, and enhance performance in the areas of scheduling, quotas, and overall system stability.\u003c/p\u003e\n"],["\u003cp\u003eThe cos-77-lts image family has undergone significant package upgrades over time, including systemd, Docker, Kubelet, openssl, and openssh, with the kernel compiler also being switched from gcc to clang.\u003c/p\u003e\n"]]],[],null,["# Container-Optimized OS Release Notes: Milestone 77\n\nCurrent Status\n--------------\n\nChangelog\n---------\n\n### cos-77-12371-1109-0\n\n*Date: Jan 11, 2021*\n\n- Fixed CVE-2020-29660 in the Linux kernel.\n- Fixed CVE-2020-29661 in the Linux kernel.\n\n### cos-77-12371-1105-0\n\n*Date: Dec 02, 2020*\n\n- Fixed CVE-2020-15257 in containerd.\n\n### cos-77-12371-1096-0\n\n*Date: Oct 26, 2020*\n\n- Fixed CVE-2020-14356.\n\n### cos-77-12371-1088-0\n\n*Date: Oct 12, 2020*\n\n- Added PPP loadable modules back, which were removed in cos-77-12371-1072-0.\n- Moved Docker's \"registry-mirrors\" configuration to the dockerd command line to address Kubernetes cluster provisioning errors.\n\n### cos-77-12371-1086-0\n\n*Date: Oct 08, 2020*\n\n- Moved the configuration of Docker's \"registry-mirrors\" option from the dockerd command line to /etc/docker/daemon.json. This should allow users to configure a custom registry mirror, which can be useful when responding to recent Docker Hub free tier changes.\n- Fixed CVE-2020-15157 in containerd.\n\n### cos-77-12371-1079-0\n\n*Date: Sep 05, 2020*\n\n- Fixed Linux kernel vulnerability CVE-2020-14386 by fixing an integer overflow issue in tpacket_rcv.\n\n### cos-77-12371-1073-0\n\n*Date: Aug 21, 2020*\n\n- Enabled utmp in systemd to allow creation of utmp files.\n\n### cos-77-12371-1072-0\n\n*Date: Aug 10, 2020*\n\n- Disabled CONFIG_PPP to mitigate Linux Kernel CVE-2020-14416.\n- Fixed CVE-2020-15705 in grub.\n\n### cos-77-12371-1064-0\n\n*Date: July 30, 2020*\n\n- Removed the metrics daemon to address an issue where it would periodically cause CPU usage spikes in some cases.\n\n### cos-77-12371-326-0\n\n*Date: July 13, 2020*\n\n- Added rsync back into the image, which was removed in cos-dev-77-12293-0-0.\n- Mount /var/lib/containerd with exec option.\n- Moved Kernel source to cos.googlesource.com.\n- Fixed CVE-2019-9169.\n\n### cos-77-12371-296-0\n\n*Date: June 16, 2020*\n\n- Updated toolbox base container image to include security patches.\n\n### cos-77-12371-274-0\n\n*Date: May 26, 2020*\n\n- Fixed a few OS Login CVEs: CVE-2020-8903, CVE-2020-8907, CVE-2020-8933.\n\n### cos-77-12371-273-0\n\n*Date: May 21, 2020*\n\n- Fixed a Stackdriver Monitoring agent bug where not all mounted disk partitions has their usage reported.\n\n### cos-77-12371-251-0\n\n*Date: Apr 29, 2020*\n\n- Fixed a kernel bug where eBPF programs can cause softlockups.\n\n### cos-77-12371-233-0\n\n*Date: Apr 29, 2020*\n\n- Disabled \\`accept_ra\\` on all interfaces by default.\n\n### cos-77-12371-227-0\n\n*Date: Apr 05, 2020*\n\n- Upgraded the Linux kernel to v4.19.112.\n- Backported systemd patch ba0d56f55 to address an issue that resulted in leaked mount units.\n\n### cos-77-12371-208-0\n\n*Date: Mar 17, 2020*\n\n- Enabled NETFILTER_XT_MATCH_SOCKET.\n- Fixed a bug where DHCP is not started after link flaps.\n- Removed size limit on /etc/ to fix cluster creation failure because of large number of addons.\n- Upgraded the Linux kernel to v4.19.109.\n\n### cos-77-12371-183-0\n\n*Date: Feb 21, 2020*\n\n- Upgraded the Linux kernel to v4.19.104.\n- Fixed TCP empty skb at the tail of the write queue bug in kernel.\n\n### cos-77-12371-175-0\n\n*Date: Feb 12, 2020*\n\n- Enabled some QoS and Fair Queuing options in the Linux kernel.\n- Upgraded the Linux kernel to v4.19.102.\n- Upgraded runc to 1.0.0-rc10. This resolves CVE-2019-19921.\n\n### cos-77-12371-141-0\n\n*Date: Jan 07, 2020*\n\n- Backported fix for Linux kernel CVE-2019-19072.\n- Fixed CFS quota throttling issue.\n- Upgraded the Linux kernel to v4.19.91.\n\n### cos-77-12371-114-0\n\n*Date: Oct 31, 2019*\n\n- Increased sysctl net.ipv4.tcp_limit_output_bytes to 1048576.\n- Fixed the problem of spawning 8 runc state process for every exec on containerd. This was leading to high cpu utilization.\n- Fixed the unnecessary creation of two separate test slices (resulting in 4 systemd log messages total + runtime overhead) for every runc execution.\n- Fixed an issue in runc that resulted in unnecessary CPU consumption. Upgraded the Linux kernel to v4.19.80.\n- Fixed a performance regression in completely fair scheduler (CFS).\n\n### cos-77-12371-89-0\n\n*Date: Oct 9, 2019*\n\n- Upgraded the Linux kernel to 4.19.76.\n- Backported a kernel patch to ensure the cfs cgroup quota/period ratio always stays the same. This addresses a Kubernetes issue where the pod cgroup could be changed into an inconsistent state.\n- Backported a kernel patch to fix performance regression in wbt scale_up/scale_down.\n\n### cos-77-12371-76-0 (vs Milestone 73)\n\n*Date: Sep 27, 2019*\n\n#### New features\n\n- Enabled Shielded VM by default. Secure boot is not enabled by default.\n- Enabled cgroup v2 hybrid mode in systemd.\n- Added support for the virtio balloon driver.\n- Added the node-problem-detector package.\n- Added the conntrack-tools package.\n- Added the xfsprogs package.\n\n#### Package updates\n\n- Upgraded systemd to version 239.\n- Upgraded the Linux kernel to version 4.19.\n- Upgraded Docker to version 19.03.\n- Upgraded Kubelet to version 1.15.\n- Upgraded the compute-image-packages to version 20190304.\n- Upgraded openssl to version 1.0.2r.\n- Upgraded openssh to version 7.9p1.\n- Changed kernel compiler from gcc to clang."]]