This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
ReleasePort's take
Light signalThe release v1.6.5 adds the docker‑socket bridge to the machines HTTP API and renames CUDA fork environment variables.
Why it matters: Exposing the docker‑socket via HTTP enables container orchestration workflows; renaming CUDA variables clarifies configuration for GPU workloads in this version.
Summary
AI summaryExpose docker‑socket bridge via HTTP API and rename CUDA fork environment variables.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Expose the docker-socket bridge in the machines HTTP API. Expose the docker-socket bridge in the machines HTTP API. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Low |
Add cuda to VmResources for CLI/SDK CUDA-over-vsock support. Add cuda to VmResources for CLI/SDK CUDA-over-vsock support. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Low |
Add --expose-socket and --mount-socket flags for forwarding arbitrary Unix sockets. Add --expose-socket and --mount-socket flags for forwarding arbitrary Unix sockets. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Low |
Implement CUDA fork independent serving with copy-on-fork isolation, graph mode, and network transport. Implement CUDA fork independent serving with copy-on-fork isolation, graph mode, and network transport. Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Feature | Low |
Warn when CUDA remoting is requested on a host without usable GPU. Warn when CUDA remoting is requested on a host without usable GPU. Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Feature | Low |
Bundle CUDA shims and smolvm-cuda-run in agent-rootfs for releases. Bundle CUDA shims and smolvm-cuda-run in agent-rootfs for releases. Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Dependency | Low |
Bump the Nix flake to smolvm 1.6.0. Bump the Nix flake to smolvm 1.6.0. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Dependency | Low |
Rebuild linux libkrun.so with a glibc 2.35 floor and gate it in CI. Rebuild linux libkrun.so with a glibc 2.35 floor and gate it in CI. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Performance | Medium |
Implement address-preserving per-clone-process fork isolation for CUDA Path 3. Implement address-preserving per-clone-process fork isolation for CUDA Path 3. Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Performance | Medium |
Stream pack overlay export to disk instead of memory. Stream pack overlay export to disk instead of memory. Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Medium |
Fix pacman repo build to package both architectures. Fix pacman repo build to package both architectures. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Make VM boot failures diagnosable instead of opaque. Make VM boot failures diagnosable instead of opaque. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Group container tasks under the sandbox shim for containerd 2.2+ compatibility. Group container tasks under the sandbox shim for containerd 2.2+ compatibility. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Detect stale CUDA guest shim at boot instead of opaque cuInit failure. Detect stale CUDA guest shim at boot instead of opaque cuInit failure. Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Medium |
Fix fork crashes and enable zero-config forkable machines with remote (TCP) clone workers for CUDA Path 3 follow-ups. Fix fork crashes and enable zero-config forkable machines with remote (TCP) clone workers for CUDA Path 3 follow-ups. Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Bugfix | Medium |
Run create workload on CUDA image machines and fail fast when no GPU host answers. Run create workload on CUDA image machines and fail fast when no GPU host answers. Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
| Refactor | Low |
Rename CUDA fork environment variables to describe behavior. Rename CUDA fork environment variables to describe behavior. Source: granite4.1:30b@2026-07-17-audit Confidence: low |
— |
Full changelog
What's Changed
- Bump the Nix flake to smolvm 1.6.0 by @BinSquare in https://github.com/smol-machines/smolvm/pull/625
- Fix the pacman repo build so it packages both architectures by @BinSquare in https://github.com/smol-machines/smolvm/pull/626
- Make VM boot failures diagnosable instead of opaque by @BinSquare in https://github.com/smol-machines/smolvm/pull/627
- docs: recommend the unix-socket docker endpoint; document the TCP alternative and its caveats by @BinSquare in https://github.com/smol-machines/smolvm/pull/621
- Add cuda to VmResources for CLI/SDK CUDA-over-vsock by @BinSquare in https://github.com/smol-machines/smolvm/pull/628
- CUDA fork independent serving: copy-on-fork isolation, graph mode, network transport by @BinSquare in https://github.com/smol-machines/smolvm/pull/629
- Detect a stale CUDA guest shim at boot instead of an opaque cuInit failure by @BinSquare in https://github.com/smol-machines/smolvm/pull/630
- feat: expose the docker-socket bridge in the machines HTTP API by @BinSquare in https://github.com/smol-machines/smolvm/pull/631
- Resolve a named config.User to a numeric uid for crun exec (#632) by @BinSquare in https://github.com/smol-machines/smolvm/pull/634
- Warn at launch when CUDA remoting is requested on a host with no usable GPU by @BinSquare in https://github.com/smol-machines/smolvm/pull/635
- CUDA Path 3: address-preserving per-clone-process fork isolation by @BinSquare in https://github.com/smol-machines/smolvm/pull/633
- Bump the workspace to 1.6.1 by @BinSquare in https://github.com/smol-machines/smolvm/pull/641
- Group container tasks under the sandbox shim (fixes containers on containerd 2.2+) by @BinSquare in https://github.com/smol-machines/smolvm/pull/643
- Rebuild the linux libkrun.so with a glibc 2.35 floor and gate it in CI by @BinSquare in https://github.com/smol-machines/smolvm/pull/644
- CUDA Path 3 follow-ups: fork crash fixes, zero-config forkable machines, remote (TCP) clone workers by @BinSquare in https://github.com/smol-machines/smolvm/pull/648
- Route smolmachine pack references through the host-side pack flow instead of the in-guest OCI puller by @BinSquare in https://github.com/smol-machines/smolvm/pull/647
- Stamp pushed smolmachine manifests with the OCI 1.1 artifactType and standard annotations by @BinSquare in https://github.com/smol-machines/smolvm/pull/649
- CUDA fork: release a torn-down golden's VRAM (close leaked export fds) by @BinSquare in https://github.com/smol-machines/smolvm/pull/650
- CUDA fork: fail fast when a clone's worker dies or its lineage is gone by @BinSquare in https://github.com/smol-machines/smolvm/pull/652
- Rename the CUDA fork env vars to describe behavior by @BinSquare in https://github.com/smol-machines/smolvm/pull/653
- release: bundle CUDA shims + smolvm-cuda-run in agent-rootfs by @NickyHeC in https://github.com/smol-machines/smolvm/pull/601
- Stream the pack overlay export to disk by @BinSquare in https://github.com/smol-machines/smolvm/pull/654
- CUDA image machines: run the create workload, and fail fast when no GPU host answers by @BinSquare in https://github.com/smol-machines/smolvm/pull/655
- feat: add --expose-socket and --mount-socket for forwarding arbitrary unix sockets by @BinSquare in https://github.com/smol-machines/smolvm/pull/656
Full Changelog: https://github.com/smol-machines/smolvm/compare/v1.6.0...v1.6.5
Breaking Changes
- Rename the CUDA fork environment variables to describe behavior
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About smolvm
Tool to build & run portable, lightweight, self-contained virtual machines.
Related context
Related tools
Earlier breaking changes
- v1.0.0 Remove built‑in store; VM now relies on host environment/files only.
Beta — feedback welcome: [email protected]