From 3721ff82ffb44a4ceeaecc5abd3808e924a6b669 Mon Sep 17 00:00:00 2001 From: Matt Heon Date: Mon, 28 Sep 2026 07:48:00 -0400 Subject: [PATCH] Revert "Enable 'podman run' for checkpoint images" This reverts commit f4401567cdf6d7ccc1ef9f50345c865bc6262c22. This commit has been identified as a serious security issue. Running checkpoints via `podman run` introduces potentially confusing behavior where all security for a container, even options specified by the user at the command line, can be turned off by the checkpoint. Checkpoints have special security considerations and must be explicitly requested by the user to ensure they are used safely. We recommend ensuring the lifecycle of a checkpoint is fully monitored and integrity is ensured at each stage to guarantee safety. Signed-off-by: Matt Heon --- pkg/domain/infra/abi/containers.go | 39 --------------------------- pkg/domain/infra/tunnel/containers.go | 25 ----------------- 2 files changed, 64 deletions(-) diff --git a/pkg/domain/infra/abi/containers.go b/pkg/domain/infra/abi/containers.go index e1c511e435..62ce5fbdbe 100644 --- a/pkg/domain/infra/abi/containers.go +++ b/pkg/domain/infra/abi/containers.go @@ -9,7 +9,6 @@ import ( "fmt" "maps" "os" - "reflect" "strconv" "sync" "time" @@ -1197,44 +1196,6 @@ func (ic *ContainerEngine) ContainerRun(ctx context.Context, opts entities.Conta fmt.Fprintf(os.Stderr, "%s\n", w) } - if opts.Spec != nil && !reflect.ValueOf(opts.Spec).IsNil() { - // If this is a checkpoint image, restore it. - img, resolvedImageName := opts.Spec.GetImage() - if img != nil && resolvedImageName != "" { - imgData, err := img.Inspect(ctx, nil) - if err != nil { - return nil, err - } - if imgData != nil { - _, isCheckpointImage := imgData.Annotations[define.CheckpointAnnotationRuntimeName] - if isCheckpointImage { - var restoreOptions entities.RestoreOptions - restoreOptions.Name = opts.Spec.Name - restoreOptions.Pod = opts.Spec.Pod - responses, err := ic.ContainerRestore(ctx, []string{resolvedImageName}, restoreOptions) - if err != nil { - return nil, err - } - - report := entities.ContainerRunReport{} - for _, r := range responses { - report.Id = r.Id - report.ExitCode = 0 - if r.Err != nil { - logrus.Errorf("Failed to restore checkpoint image %s: %v", resolvedImageName, r.Err) - report.ExitCode = 126 - } - if r.RawInput != "" { - logrus.Errorf("Failed to restore checkpoint image %s: %v", resolvedImageName, r.RawInput) - report.ExitCode = 126 - } - } - return &report, nil - } - } - } - } - rtSpec, spec, optsN, err := generate.MakeContainer(ctx, ic.Libpod, opts.Spec, false, nil) if err != nil { return nil, err diff --git a/pkg/domain/infra/tunnel/containers.go b/pkg/domain/infra/tunnel/containers.go index 14d513d037..5dcff997fc 100644 --- a/pkg/domain/infra/tunnel/containers.go +++ b/pkg/domain/infra/tunnel/containers.go @@ -7,7 +7,6 @@ import ( "fmt" "io" "os" - "reflect" "strconv" "strings" "time" @@ -895,30 +894,6 @@ func (ic *ContainerEngine) ContainerListExternal(_ context.Context) ([]entities. } func (ic *ContainerEngine) ContainerRun(ctx context.Context, opts entities.ContainerRunOptions) (*entities.ContainerRunReport, error) { - if opts.Spec != nil && !reflect.ValueOf(opts.Spec).IsNil() && opts.Spec.RawImageName != "" { - // If this is a checkpoint image, restore it. - getImageOptions := new(images.GetOptions).WithSize(false) - inspectReport, err := images.GetImage(ic.ClientCtx, opts.Spec.RawImageName, getImageOptions) - if err != nil { - return nil, fmt.Errorf("no such container or image: %s", opts.Spec.RawImageName) - } - if inspectReport != nil { - _, isCheckpointImage := inspectReport.Annotations[define.CheckpointAnnotationRuntimeName] - if isCheckpointImage { - restoreOptions := new(containers.RestoreOptions) - restoreOptions.WithName(opts.Spec.Name) - restoreOptions.WithPod(opts.Spec.Pod) - - restoreReport, err := containers.Restore(ic.ClientCtx, inspectReport.ID, restoreOptions) - if err != nil { - return nil, err - } - runReport := entities.ContainerRunReport{Id: restoreReport.Id} - return &runReport, nil - } - } - } - con, err := containers.CreateWithSpec(ic.ClientCtx, opts.Spec, nil) if err != nil { return nil, err