What google/gvisor shipped
Written by FoxPlug from public releases; not affiliated with Gvisor. An automatic summary of the public release, pull request and commit data of github.com/google/gvisor. Gvisor did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Release 20260921.0 shipped with lint enforcement in the Buildkite pipeline. Release
- Added iptables comment match extension to netfilter for packet filtering. Pull request #14602
- Strace events now include thread ID to correctly pair syscall traces from multiple threads. Pull request #15015
- Signal masks now appear in /proc/[pid]/status showing which signals processes block, ignore or handle. Pull request #14499
- Implemented /proc/sys/user/max_user_namespaces with enforcement for user namespace limits. Pull request #13539
- Fixed file capabilities handling under
no_new_privsto match Linux behavior. Pull request #14912 - Made interrupt.Forwarder lock-free, reducing syscall latency by 2-4% on various platforms. Pull request #14952
- iptables now rejects REDIRECT, DNAT and SNAT targets on unsupported hooks and tables. Pull request #14509
- Implemented TCSETSF ioctl for master/replica tty devices. Pull request #14754
- Added bounds validation for checksum offset in nftables payload set operations. Pull request #13161
Why it matters
This week covers correctness fixes for system call tracing and capability enforcement, new netfilter and nftables features for packet processing, signal mask visibility in process status, and performance improvements on the syscall path. These changes improve container isolation semantics, debugging capabilities, and runtime performance.
Changelog entry
- DMI product data probes now treat missing host data as optional for hosts like Firecracker microVMs. Pull request #15049
- Checklocks inference now honors field-level ignore annotations when suggesting guard annotations. Pull request #15029
- Nogo reuses object-path encoders per package and updates x/tools to v0.45.0 for better performance. Pull request #14829
- Netfilter: added iptables comment match extension (revision 0) for packet filtering and iptables-save round-tripping. Pull request #14602
- Strace events now include thread ID field to prevent mis-pairing of concurrent syscalls. Pull request #15015
- Auth: fixed file capabilities to remain active under
no_new_privsas Linux does. Pull request #14912 - Plugin socket readiness caching now uses atomic compare-and-swap to prevent concurrent update race conditions. Pull request #14370
- Nftables: added bounds validation for checksum offset in payload set operations. Pull request #13161
- Checklocks fixtures now check all diagnostics instead of filtering suppressed text. Pull request #14827
- Checklocks: annotated synchronization in service state, logging, metrics and verification code. Pull request #14350
- Made interrupt.Forwarder lock-free, reducing kvm.getpid latency by 4.5% and systrap.getpidopt by 2.1%. Pull request #14952
- Cgroupfs now properly removes registry entries when filesystem is released. Pull request #13215
- /proc/[pid]/status now shows signal masks: SigPnd, ShdPnd, SigBlk, SigIgn and SigCgt. Pull request #14499
- Go package driver now targets Linux to fix file selection mismatches on non-Linux hosts. Pull request #14987
- Implemented TCSETSF ioctl for master/replica tty devices. Pull request #14754
- Checklocks now reads annotations from all declaration contexts including standalone docs and later names. Pull request #14881
- Auto-assign workflow now pins action commits for checkout v7.0.1 and github-script v9.0.0. Pull request #14740
- /proc/sys/user/max_user_namespaces now enforced to allow bubblewrap's --disable-userns to work. Pull request #13539
- TestSystemdDocker now verifies docker pause actually stops container execution. Pull request #14979
- //:release now ships race-instrumented runsc and Sentry when built with --config=race. Pull request #14962
gVisor 20260921.0 ships with strace thread tracking, iptables comment matches, /proc signal masks, user namespace limits, and 2-4% syscall speedup via lock-free forwarder.
gVisor 20260921.0 improves system call debugging with per-thread strace events, adds netfilter comment match extension and nftables checksum validation, exposes signal masks in /proc/[pid]/status, enforces /proc/sys/user/max_user_namespaces limits, fixes file capabilities under no_new_privs to match Linux, and makes the interrupt forwarder lock-free for 2-4% syscall latency reduction.
Week of September 14, 2026
What shipped
- gVisor 20260914.0 released with improvements to CPU reporting, seccomp performance, and systemd compatibility. Release
- Fixed FUSE file handling to properly support opening files larger than 2GiB by checking O_LARGEFILE flags before masking. Pull request #13957
- Added AT_PLATFORM to the initial auxiliary vector to match Linux behavior and improve application compatibility. Pull request #14816
- Added STATX_ATTR_MOUNT_ROOT reporting from statx to support systemd 60+ requirements. Pull request #14764
- Optimized seccomp initialization by lazily constructing precompiled programs instead of eagerly materializing all bytecode at startup. Pull request #14674
- Increased setsockopt maximum option length from 32KB to 1MB to support larger socket option payloads. Pull request #14600
- Fixed GPU device file restoration to create nvproxy device files on restore regardless of remap metadata availability. Pull request #14525
- Added writable net.ipv4.conf.all.route_localnet sysctl support for enabling martian loopback traffic routing. Pull request #14625
- Fixed tmpfs checkpoint handling to preserve binary and empty xattrs in filesystem checkpoints. Pull request #14793
- Added support for NVIDIA driver version 615.71.09 in nvproxy. Pull request #14751
Why it matters
Release 20260914.0 brings significant compatibility improvements, particularly for systemd integration and GPU support. Performance optimizations in seccomp and fixes to file handling make gVisor more practical for real-world workloads requiring large files and complex socket operations.
Changelog entry
- release: gVisor 20260914.0 Release
- fuse: check O_LARGEFILE before masking it out of the open flags Pull request #13957
- Add AT_PLATFORM to the initial auxv Pull request #14816
- Report STATX_ATTR_MOUNT_ROOT from statx Pull request #14764
- seccomp: Lazily construct precompiled seccomp programs Pull request #14674
- syscalls/linux: raise setsockopt maxOptLen to 1MB Pull request #14600
- Create nvproxy device files on restore regardless of remap metadata Pull request #14525
- proc, tcpip: add writable net.ipv4.conf.all.route_localnet Pull request #14625
- tmpfs: preserve binary and empty xattrs in filesystem checkpoints Pull request #14793
- nvproxy: Add support for NVIDIA driver version 615.71.09 Pull request #14751
- Fix clock overflow recovery and watchdog timing Pull request #14357
- Synchronize shared key permissions Pull request #14365
- runsc symbolize: Delegate symbolization to sentry binary Pull request #14718
- Cap host CPU deep idle states for GPU sandboxes on impacted CPUs Pull request #14526
- Reproduce host errno for unreadable RDMA netdev sysfs attributes Pull request #14567
- Fix races in shim version queries and RPC shutdown Pull request #14358
gVisor 20260914.0 is out. Better FUSE file support, systemd compatibility, GPU restoration, and seccomp performance improvements.
gVisor 20260914.0 released with major improvements: FUSE now handles files >2GB, seccomp initialization 8ms faster per sandbox, systemd 60+ compatibility via STATX_ATTR_MOUNT_ROOT, GPU device restoration fixes, and socket options up to 1MB. Check the changelog for full details.