This release adds 2 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
Summary
AI summaryExpose docker‑socket bridge via HTTP API and add --expose‑socket/--mount‑socket for arbitrary Unix socket forwarding.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Expose the docker-socket bridge in the machines HTTP API. Expose the docker-socket bridge in the machines HTTP API. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Low |
Add cuda to VmResources for CLI/SDK CUDA-over-vsock support. Add cuda to VmResources for CLI/SDK CUDA-over-vsock support. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Low |
Add --expose-socket and --mount-socket flags for arbitrary unix socket forwarding. Add --expose-socket and --mount-socket flags for arbitrary unix socket forwarding. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Feature | Low |
Implement CUDA fork independent serving with copy-on-fork isolation, graph mode, and network transport. Implement CUDA fork independent serving with copy-on-fork isolation, graph mode, and network transport. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Feature | Low |
Warn when CUDA remoting is requested on a host without usable GPU. Warn when CUDA remoting is requested on a host without usable GPU. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Feature | Low |
Implement address‑preserving per‑clone‑process fork isolation for CUDA Path 3. Implement address‑preserving per‑clone‑process fork isolation for CUDA Path 3. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Feature | Low |
Bundle CUDA shims and smolvm‑cuda‑run in agent‑rootfs for releases. Bundle CUDA shims and smolvm‑cuda‑run in agent‑rootfs for releases. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Feature | Low |
Export pack sidecar instead of executable stub when a machine is exported. Export pack sidecar instead of executable stub when a machine is exported. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Dependency | Low |
Bump the Nix flake to smolvm 1.6.0. Bump the Nix flake to smolvm 1.6.0. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Dependency | Low |
Bump the workspace to 1.6.1. Bump the workspace to 1.6.1. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Performance | Low |
Stream pack overlay export to disk. Stream pack overlay export to disk. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Performance | Low |
Never LRU‑evict the reference‑shared pack store. Never LRU‑evict the reference‑shared pack store. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Medium |
Fix pacman repo build to package both architectures. Fix pacman repo build to package both architectures. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Make VM boot failures diagnosable instead of opaque. Make VM boot failures diagnosable instead of opaque. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Resolve a named config.User to a numeric uid for crun exec. Resolve a named config.User to a numeric uid for crun exec. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Group container tasks under the sandbox shim for containerd 2.2+ compatibility. Group container tasks under the sandbox shim for containerd 2.2+ compatibility. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Detect stale CUDA guest shim at boot instead of opaque cuInit failure. Detect stale CUDA guest shim at boot instead of opaque cuInit failure. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Medium |
Fix fork crash issues, enable zero‑config forkable machines, and add remote (TCP) clone workers for CUDA Path 3 follow‑ups. Fix fork crash issues, enable zero‑config forkable machines, and add remote (TCP) clone workers for CUDA Path 3 follow‑ups. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Medium |
Release torn‑down golden's VRAM and close leaked export file descriptors in CUDA fork. Release torn‑down golden's VRAM and close leaked export file descriptors in CUDA fork. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Medium |
Fail fast when a clone's worker dies or its lineage is gone in CUDA fork. Fail fast when a clone's worker dies or its lineage is gone in CUDA fork. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Medium |
Fix silently dropped CUDA work after fork‑clone reconnect and rebuild captured graphs in clone workers. Fix silently dropped CUDA work after fork‑clone reconnect and rebuild captured graphs in clone workers. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Bugfix | Medium |
Fail image machine start when image pull fails. Fail image machine start when image pull fails. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Refactor | Low |
Rebuild linux libkrun.so with a glibc 2.35 floor and gate it in CI. Rebuild linux libkrun.so with a glibc 2.35 floor and gate it in CI. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Refactor | Low |
Rename CUDA fork environment variables to describe behavior. Rename CUDA fork environment variables to describe behavior. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Refactor | Low |
Gate engine PRs on compiling the smol CLI and script release cuts. Gate engine PRs on compiling the smol CLI and script release cuts. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
| Refactor | Low |
Flatten from‑vm packs to a single layer and share export, workload launch, and env handling in the library. Flatten from‑vm packs to a single layer and share export, workload launch, and env handling in the library. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
Full changelog
What's Changed
- Bump the Nix flake to smolvm 1.6.0 by @BinSquare in https://github.com/smol-machines/smolvm/pull/625
- Fix the pacman repo build so it packages both architectures by @BinSquare in https://github.com/smol-machines/smolvm/pull/626
- Make VM boot failures diagnosable instead of opaque by @BinSquare in https://github.com/smol-machines/smolvm/pull/627
- docs: recommend the unix-socket docker endpoint; document the TCP alternative and its caveats by @BinSquare in https://github.com/smol-machines/smolvm/pull/621
- Add cuda to VmResources for CLI/SDK CUDA-over-vsock by @BinSquare in https://github.com/smol-machines/smolvm/pull/628
- CUDA fork independent serving: copy-on-fork isolation, graph mode, network transport by @BinSquare in https://github.com/smol-machines/smolvm/pull/629
- Detect a stale CUDA guest shim at boot instead of an opaque cuInit failure by @BinSquare in https://github.com/smol-machines/smolvm/pull/630
- feat: expose the docker-socket bridge in the machines HTTP API by @BinSquare in https://github.com/smol-machines/smolvm/pull/631
- Resolve a named config.User to a numeric uid for crun exec (#632) by @BinSquare in https://github.com/smol-machines/smolvm/pull/634
- Warn at launch when CUDA remoting is requested on a host with no usable GPU by @BinSquare in https://github.com/smol-machines/smolvm/pull/635
- CUDA Path 3: address-preserving per-clone-process fork isolation by @BinSquare in https://github.com/smol-machines/smolvm/pull/633
- Bump the workspace to 1.6.1 by @BinSquare in https://github.com/smol-machines/smolvm/pull/641
- Group container tasks under the sandbox shim (fixes containers on containerd 2.2+) by @BinSquare in https://github.com/smol-machines/smolvm/pull/643
- Rebuild the linux libkrun.so with a glibc 2.35 floor and gate it in CI by @BinSquare in https://github.com/smol-machines/smolvm/pull/644
- CUDA Path 3 follow-ups: fork crash fixes, zero-config forkable machines, remote (TCP) clone workers by @BinSquare in https://github.com/smol-machines/smolvm/pull/648
- Route smolmachine pack references through the host-side pack flow instead of the in-guest OCI puller by @BinSquare in https://github.com/smol-machines/smolvm/pull/647
- Stamp pushed smolmachine manifests with the OCI 1.1 artifactType and standard annotations by @BinSquare in https://github.com/smol-machines/smolvm/pull/649
- CUDA fork: release a torn-down golden's VRAM (close leaked export fds) by @BinSquare in https://github.com/smol-machines/smolvm/pull/650
- CUDA fork: fail fast when a clone's worker dies or its lineage is gone by @BinSquare in https://github.com/smol-machines/smolvm/pull/652
- Rename the CUDA fork env vars to describe behavior by @BinSquare in https://github.com/smol-machines/smolvm/pull/653
- release: bundle CUDA shims + smolvm-cuda-run in agent-rootfs by @NickyHeC in https://github.com/smol-machines/smolvm/pull/601
- Stream the pack overlay export to disk by @BinSquare in https://github.com/smol-machines/smolvm/pull/654
- CUDA image machines: run the create workload, and fail fast when no GPU host answers by @BinSquare in https://github.com/smol-machines/smolvm/pull/655
- feat: add --expose-socket and --mount-socket for forwarding arbitrary unix sockets by @BinSquare in https://github.com/smol-machines/smolvm/pull/656
- Run the pack-from-vm helper as the source VM's isolated uid so it can read the source disks by @BinSquare in https://github.com/smol-machines/smolvm/pull/658
- Fix silently dropped CUDA work after a fork-clone reconnect, and rebuild captured graphs in clone workers by @BinSquare in https://github.com/smol-machines/smolvm/pull/659
- Gate engine PRs on compiling the smol CLI and script the release cut by @BinSquare in https://github.com/smol-machines/smolvm/pull/661
- Export the pack sidecar, not the executable stub, when a machine is exported by @BinSquare in https://github.com/smol-machines/smolvm/pull/662
- Route fork clones to workers by an explicit connection preamble so a golden's reconnect can never be misrouted by @BinSquare in https://github.com/smol-machines/smolvm/pull/663
- Never LRU-evict the reference-shared pack store by @BinSquare in https://github.com/smol-machines/smolvm/pull/666
- Fail an image machine's start when the image pull fails by @BinSquare in https://github.com/smol-machines/smolvm/pull/669
- Flatten from-vm packs to a single layer and share the pack export, workload launch, and machine-create env handling in the lib by @BinSquare in https://github.com/smol-machines/smolvm/pull/668
Full Changelog: https://github.com/smol-machines/smolvm/compare/v1.6.0...v1.6.11
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About smolvm
Tool to build & run portable, lightweight, self-contained virtual machines.
Related context
Related tools
Earlier breaking changes
- v1.0.0 Remove built‑in store; VM now relies on host environment/files only.
Beta — feedback welcome: [email protected]