Added PPP loadable modules back, which were removed in
Moved Docker's "registry-mirrors" configuration to the dockerd command
line to address Kubernetes cluster provisioning errors.
Date: Oct 08, 2020
Moved the configuration of Docker's "registry-mirrors" option from the
dockerd command line to /etc/docker/daemon.json. This should allow users
to configure a custom registry mirror, which can be useful when responding
to recent Docker Hub free tier changes.
Fixed CVE-2020-15157 in containerd.
Date: Sep 05, 2020
Fixed Linux kernel vulnerability CVE-2020-14386 by fixing an integer
overflow issue in tpacket_rcv.
Date: Aug 21, 2020
Enabled utmp in systemd to allow creation of utmp files.
Date: Aug 10, 2020
Disabled CONFIG_PPP to mitigate Linux Kernel CVE-2020-14416.
Fixed CVE-2020-15705 in grub.
Date: July 30, 2020
Removed the metrics daemon to address an issue where it would
periodically cause CPU usage spikes in some cases.
Date: July 13, 2020
Added rsync back into the image, which was removed in
Mount /var/lib/containerd with exec option.
Moved Kernel source to cos.googlesource.com.
Date: June 16, 2020
Updated toolbox base container image to include security patches.
Date: May 26, 2020
Fixed a few OS Login CVEs: CVE-2020-8903, CVE-2020-8907, CVE-2020-8933.
Date: May 21, 2020
Fixed a Stackdriver Monitoring agent bug where not all mounted disk partitions has their usage reported.
Date: Apr 29, 2020
Fixed a kernel bug where eBPF programs can cause softlockups.
Date: Apr 29, 2020
Disabled `accept_ra` on all interfaces by default.
Date: Apr 05, 2020
Upgraded the Linux kernel to v4.19.112.
Backported systemd patch ba0d56f55 to address an issue that resulted in
leaked mount units.
Date: Mar 17, 2020
Fixed a bug where DHCP is not started after link flaps.
Removed size limit on /etc/ to fix cluster creation failure because of large number of addons.
Upgraded the Linux kernel to v4.19.109.
Date: Feb 21, 2020
Upgraded the Linux kernel to v4.19.104.
Fixed TCP empty skb at the tail of the write queue bug in kernel.
Date: Feb 12, 2020
Enabled some QoS and Fair Queuing options in the Linux kernel.
Upgraded the Linux kernel to v4.19.102.
Upgraded runc to 1.0.0-rc10. This resolves CVE-2019-19921.
Date: Jan 07, 2020
Backported fix for Linux kernel CVE-2019-19072.
Fixed CFS quota throttling issue.
Upgraded the Linux kernel to v4.19.91.
Date: Oct 31, 2019
Increased sysctl net.ipv4.tcp_limit_output_bytes to 1048576.
Fixed the problem of spawning 8 runc state process for every exec on
containerd. This was leading to high cpu utilization.
Fixed the unnecessary creation of two separate test slices (resulting
in 4 systemd log messages total + runtime overhead) for every runc
Fixed an issue in runc that resulted in unnecessary CPU consumption.
Upgraded the Linux kernel to v4.19.80.
Fixed a performance regression in completely fair scheduler (CFS).
Date: Oct 9, 2019
Upgraded the Linux kernel to 4.19.76.
Backported a kernel patch to ensure the cfs cgroup quota/period ratio
always stays the same. This addresses a Kubernetes issue where the pod
cgroup could be changed into an inconsistent state.
Backported a kernel patch to fix performance regression in wbt
cos-77-12371-76-0 (vs Milestone 73)
Date: Sep 27, 2019
Enabled Shielded VM by default. Secure boot is not enabled by
Enabled cgroup v2 hybrid mode in systemd.
Added support for the virtio balloon driver.
Added the node-problem-detector package.
Added the conntrack-tools package.
Added the xfsprogs package.
Upgraded systemd to version 239.
Upgraded the Linux kernel to version 4.19.
Upgraded Docker to version 19.03.
Upgraded Kubelet to version 1.15.
Upgraded the compute-image-packages to version 20190304.