This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
ReleasePort's take
Light signalRelease v1.6.10 renames CUDA fork environment variables and introduces `--expose-socket`/`--mount-socket` flags for arbitrary Unix socket forwarding.
Why it matters: If your workloads use CUDA‑over‑vsock or need generic Unix socket exposure, update to v1.6.10 before the next deployment cycle.
Summary
AI summaryRename CUDA fork environment variables and add socket‑expose flags for arbitrary Unix sockets.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Add `cuda` field to VmResources for CLI/SDK CUDA-over‑vsock support. Add `cuda` field to VmResources for CLI/SDK CUDA-over‑vsock support. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Medium |
Expose docker-socket bridge via machines HTTP API. Expose docker-socket bridge via machines HTTP API. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Medium |
Add `--expose-socket` and `--mount-socket` flags for arbitrary Unix socket forwarding. Add `--expose-socket` and `--mount-socket` flags for arbitrary Unix socket forwarding. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Dependency | Low |
Bump smolvm dependency to version 1.6.0. Bump smolvm dependency to version 1.6.0. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Dependency | Low |
Rebuild linux libkrun.so with glibc 2.35 minimum requirement and gate in CI. Rebuild linux libkrun.so with glibc 2.35 minimum requirement and gate in CI. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Dependency | Low |
Bump workspace to version 1.6.1. Bump workspace to version 1.6.1. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Medium |
Fix pacman repo build to package both architectures correctly. Fix pacman repo build to package both architectures correctly. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Resolve named `config.User` to numeric uid for crun exec calls. Resolve named `config.User` to numeric uid for crun exec calls. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Fail image machine start when the underlying image pull fails. Fail image machine start when the underlying image pull fails. Source: llm_adapter@2026-07-18 Confidence: low |
— |
| Bugfix | Medium |
Make VM boot failures diagnosable instead of opaque. Make VM boot failures diagnosable instead of opaque. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Medium |
Group container tasks under the sandbox shim to support containerd 2.2+ containers. Group container tasks under the sandbox shim to support containerd 2.2+ containers. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
Full changelog
What's Changed
- Bump the Nix flake to smolvm 1.6.0 by @BinSquare in https://github.com/smol-machines/smolvm/pull/625
- Fix the pacman repo build so it packages both architectures by @BinSquare in https://github.com/smol-machines/smolvm/pull/626
- Make VM boot failures diagnosable instead of opaque by @BinSquare in https://github.com/smol-machines/smolvm/pull/627
- docs: recommend the unix-socket docker endpoint; document the TCP alternative and its caveats by @BinSquare in https://github.com/smol-machines/smolvm/pull/621
- Add cuda to VmResources for CLI/SDK CUDA-over-vsock by @BinSquare in https://github.com/smol-machines/smolvm/pull/628
- CUDA fork independent serving: copy-on-fork isolation, graph mode, network transport by @BinSquare in https://github.com/smol-machines/smolvm/pull/629
- Detect a stale CUDA guest shim at boot instead of an opaque cuInit failure by @BinSquare in https://github.com/smol-machines/smolvm/pull/630
- feat: expose the docker-socket bridge in the machines HTTP API by @BinSquare in https://github.com/smol-machines/smolvm/pull/631
- Resolve a named config.User to a numeric uid for crun exec (#632) by @BinSquare in https://github.com/smol-machines/smolvm/pull/634
- Warn at launch when CUDA remoting is requested on a host with no usable GPU by @BinSquare in https://github.com/smol-machines/smolvm/pull/635
- CUDA Path 3: address-preserving per-clone-process fork isolation by @BinSquare in https://github.com/smol-machines/smolvm/pull/633
- Bump the workspace to 1.6.1 by @BinSquare in https://github.com/smol-machines/smolvm/pull/641
- Group container tasks under the sandbox shim (fixes containers on containerd 2.2+) by @BinSquare in https://github.com/smol-machines/smolvm/pull/643
- Rebuild the linux libkrun.so with a glibc 2.35 floor and gate it in CI by @BinSquare in https://github.com/smol-machines/smolvm/pull/644
- CUDA Path 3 follow-ups: fork crash fixes, zero-config forkable machines, remote (TCP) clone workers by @BinSquare in https://github.com/smol-machines/smolvm/pull/648
- Route smolmachine pack references through the host-side pack flow instead of the in-guest OCI puller by @BinSquare in https://github.com/smol-machines/smolvm/pull/647
- Stamp pushed smolmachine manifests with the OCI 1.1 artifactType and standard annotations by @BinSquare in https://github.com/smol-machines/smolvm/pull/649
- CUDA fork: release a torn-down golden's VRAM (close leaked export fds) by @BinSquare in https://github.com/smol-machines/smolvm/pull/650
- CUDA fork: fail fast when a clone's worker dies or its lineage is gone by @BinSquare in https://github.com/smol-machines/smolvm/pull/652
- Rename the CUDA fork env vars to describe behavior by @BinSquare in https://github.com/smol-machines/smolvm/pull/653
- release: bundle CUDA shims + smolvm-cuda-run in agent-rootfs by @NickyHeC in https://github.com/smol-machines/smolvm/pull/601
- Stream the pack overlay export to disk by @BinSquare in https://github.com/smol-machines/smolvm/pull/654
- CUDA image machines: run the create workload, and fail fast when no GPU host answers by @BinSquare in https://github.com/smol-machines/smolvm/pull/655
- feat: add --expose-socket and --mount-socket for forwarding arbitrary unix sockets by @BinSquare in https://github.com/smol-machines/smolvm/pull/656
- Run the pack-from-vm helper as the source VM's isolated uid so it can read the source disks by @BinSquare in https://github.com/smol-machines/smolvm/pull/658
- Fix silently dropped CUDA work after a fork-clone reconnect, and rebuild captured graphs in clone workers by @BinSquare in https://github.com/smol-machines/smolvm/pull/659
- Gate engine PRs on compiling the smol CLI and script the release cut by @BinSquare in https://github.com/smol-machines/smolvm/pull/661
- Export the pack sidecar, not the executable stub, when a machine is exported by @BinSquare in https://github.com/smol-machines/smolvm/pull/662
- Route fork clones to workers by an explicit connection preamble so a golden's reconnect can never be misrouted by @BinSquare in https://github.com/smol-machines/smolvm/pull/663
- Never LRU-evict the reference-shared pack store by @BinSquare in https://github.com/smol-machines/smolvm/pull/666
- Fail an image machine's start when the image pull fails by @BinSquare in https://github.com/smol-machines/smolvm/pull/669
Full Changelog: https://github.com/smol-machines/smolvm/compare/v1.6.0...v1.6.10
Breaking Changes
- Rename the CUDA fork env vars to describe behavior
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About smolvm
Tool to build & run portable, lightweight, self-contained virtual machines.
Related context
Related tools
Earlier breaking changes
- v1.0.0 Remove built‑in store; VM now relies on host environment/files only.
Beta — feedback welcome: [email protected]