mirror of
https://github.com/podman-container-tools/podman.git
synced 2026-10-06 14:07:50 +00:00
Revert "Enable 'podman run' for checkpoint images"
This reverts commit f4401567cd.
This commit has been identified as a serious security issue.
Running checkpoints via `podman run` introduces potentially
confusing behavior where all security for a container, even
options specified by the user at the command line, can be turned
off by the checkpoint. Checkpoints have special security
considerations and must be explicitly requested by the user to
ensure they are used safely. We recommend ensuring the lifecycle
of a checkpoint is fully monitored and integrity is ensured at
each stage to guarantee safety.
Signed-off-by: Matt Heon <matthew.heon@pm.me>
This commit is contained in:
parent
345b2c7fc2
commit
3721ff82ff
2 changed files with 0 additions and 64 deletions
|
|
@ -9,7 +9,6 @@ import (
|
|||
"fmt"
|
||||
"maps"
|
||||
"os"
|
||||
"reflect"
|
||||
"strconv"
|
||||
"sync"
|
||||
"time"
|
||||
|
|
@ -1197,44 +1196,6 @@ func (ic *ContainerEngine) ContainerRun(ctx context.Context, opts entities.Conta
|
|||
fmt.Fprintf(os.Stderr, "%s\n", w)
|
||||
}
|
||||
|
||||
if opts.Spec != nil && !reflect.ValueOf(opts.Spec).IsNil() {
|
||||
// If this is a checkpoint image, restore it.
|
||||
img, resolvedImageName := opts.Spec.GetImage()
|
||||
if img != nil && resolvedImageName != "" {
|
||||
imgData, err := img.Inspect(ctx, nil)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if imgData != nil {
|
||||
_, isCheckpointImage := imgData.Annotations[define.CheckpointAnnotationRuntimeName]
|
||||
if isCheckpointImage {
|
||||
var restoreOptions entities.RestoreOptions
|
||||
restoreOptions.Name = opts.Spec.Name
|
||||
restoreOptions.Pod = opts.Spec.Pod
|
||||
responses, err := ic.ContainerRestore(ctx, []string{resolvedImageName}, restoreOptions)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
report := entities.ContainerRunReport{}
|
||||
for _, r := range responses {
|
||||
report.Id = r.Id
|
||||
report.ExitCode = 0
|
||||
if r.Err != nil {
|
||||
logrus.Errorf("Failed to restore checkpoint image %s: %v", resolvedImageName, r.Err)
|
||||
report.ExitCode = 126
|
||||
}
|
||||
if r.RawInput != "" {
|
||||
logrus.Errorf("Failed to restore checkpoint image %s: %v", resolvedImageName, r.RawInput)
|
||||
report.ExitCode = 126
|
||||
}
|
||||
}
|
||||
return &report, nil
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
rtSpec, spec, optsN, err := generate.MakeContainer(ctx, ic.Libpod, opts.Spec, false, nil)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
|
|
|
|||
|
|
@ -7,7 +7,6 @@ import (
|
|||
"fmt"
|
||||
"io"
|
||||
"os"
|
||||
"reflect"
|
||||
"strconv"
|
||||
"strings"
|
||||
"time"
|
||||
|
|
@ -895,30 +894,6 @@ func (ic *ContainerEngine) ContainerListExternal(_ context.Context) ([]entities.
|
|||
}
|
||||
|
||||
func (ic *ContainerEngine) ContainerRun(ctx context.Context, opts entities.ContainerRunOptions) (*entities.ContainerRunReport, error) {
|
||||
if opts.Spec != nil && !reflect.ValueOf(opts.Spec).IsNil() && opts.Spec.RawImageName != "" {
|
||||
// If this is a checkpoint image, restore it.
|
||||
getImageOptions := new(images.GetOptions).WithSize(false)
|
||||
inspectReport, err := images.GetImage(ic.ClientCtx, opts.Spec.RawImageName, getImageOptions)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("no such container or image: %s", opts.Spec.RawImageName)
|
||||
}
|
||||
if inspectReport != nil {
|
||||
_, isCheckpointImage := inspectReport.Annotations[define.CheckpointAnnotationRuntimeName]
|
||||
if isCheckpointImage {
|
||||
restoreOptions := new(containers.RestoreOptions)
|
||||
restoreOptions.WithName(opts.Spec.Name)
|
||||
restoreOptions.WithPod(opts.Spec.Pod)
|
||||
|
||||
restoreReport, err := containers.Restore(ic.ClientCtx, inspectReport.ID, restoreOptions)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
runReport := entities.ContainerRunReport{Id: restoreReport.Id}
|
||||
return &runReport, nil
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
con, err := containers.CreateWithSpec(ic.ClientCtx, opts.Spec, nil)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue