Commit graph

26314 commits

Author SHA1 Message Date
Paul Holzinger
21071ebb13
Merge pull request #28254 from podmanbot/bump-5.8.2-dev
Bump Podman to v5.8.2-dev
2026-03-16 13:11:20 +01:00
mheon
6a9ea849a0 Bump Podman to v5.8.2-dev
Signed-off-by: mheon <7735048+mheon@users.noreply.github.com>
2026-03-11 19:53:44 +00:00
Paul Holzinger
9d66b48e1c
Merge pull request #28250 from mheon/bump_581
Bump to v5.8.1
2026-03-11 19:46:12 +01:00
Matt Heon
c6077f6457
Bump to v5.8.1
Signed-off-by: Matt Heon <mheon@redhat.com>
2026-03-11 09:31:04 -04:00
Matt Heon
dfe5dae2d6 Release notes for v5.8.1
Signed-off-by: Matt Heon <mheon@redhat.com>
2026-03-11 09:30:51 -04:00
Matt Heon
3bd2b272b2
Merge pull request #28237 from Luap99/5.8-migrate-docs
[v5.8] Updating migration doc and warning with more details
2026-03-10 15:49:13 -04:00
Paul Holzinger
cf0019e3ed
docs: make the --migrate-db more clear
Recommend the reboot option instead if users cannot shut down all podman
commands. Also update the wording that users MUST shut down commands for
correct migration.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-03-10 13:54:57 +01:00
Paul Holzinger
5dcc24d01d
update boltdb migrating warning
Mention the reboot which should be safer and that in order for the
command the user has to ensure they are no parallel commands.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-03-10 13:54:57 +01:00
Jan Rodák
241a5b9e66
Merge pull request #28227 from Luap99/5.8-migrate
[v5.8] fix automatic migration bug
2026-03-10 09:28:27 +01:00
Paul Holzinger
13deb46d81
libpod: prefer sqlite in getDBState()
If the sqlite file exists make sure we always use that db and no longer
botldb. There are known race conditions in the db migration logic that
might make it so that both database files exists at once.

In order to ensure we use the correctly migrated one we must prefer
sqlite here.

see https://github.com/containers/podman/issues/28216

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-03-09 20:55:53 +01:00
Paul Holzinger
0c473eb570
libpod: fix parallel migration issue
Once we have the alive lock and do not refresh check again if another
process migrated the state after we opened the db initially.

This is required to ensure parallel commands notice the migration and
correctly only use sqlite.

see https://github.com/containers/podman/issues/28219

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-03-09 20:55:53 +01:00
Paul Holzinger
9b810aed3a
libpod: return full path in sqliteStatePath()
It makes more sense for the callers.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-03-09 17:59:15 +01:00
Matt Heon
06ffb9b397
Merge pull request #28205 from timcoding1988/backport-aws-oidc-v5.8
BackPort for (aws migrate to oidc)
2026-03-05 13:17:01 -05:00
Tim Zhou
1e99e31575 migrate to oidc
Signed-off-by: Tim Zhou <tizhou@redhat.com>
2026-03-05 11:27:50 -05:00
Ashley Cui
3e6f49a0fd
Merge pull request #28082 from podmanbot/bump-5.8.1-dev
Bump Podman to v5.8.1-dev
2026-02-12 15:31:10 -05:00
mheon
935088fd14 Bump Podman to v5.8.1-dev
Signed-off-by: mheon <7735048+mheon@users.noreply.github.com>
2026-02-12 18:46:49 +00:00
Paul Holzinger
10a75bfa93
Merge pull request #28079 from mheon/bump_580
Bump to v5.8.0
2026-02-12 19:45:58 +01:00
Matt Heon
37bfeded1f Disable lint to fix CI
Signed-off-by: Matt Heon <mheon@redhat.com>
2026-02-12 11:06:35 -05:00
Matt Heon
07efc23e05
Bump to v5.8.0
Signed-off-by: Matt Heon <mheon@redhat.com>
2026-02-12 10:41:26 -05:00
Matt Heon
482462af7b Final release notes for v5.8.0
Signed-off-by: Matt Heon <mheon@redhat.com>
2026-02-12 10:41:04 -05:00
Matt Heon
cd885da4f0
Merge pull request #28071 from Luap99/v5.8
[v5.8] update github.com/containers/gvisor-tap-vsock to v0.8.8
2026-02-11 12:40:35 -05:00
Paul Holzinger
75a7259ea8
Merge pull request #28063 from podmanbot/bump-5.8.0-dev
Bump Podman to v5.8.0-dev
2026-02-11 16:45:51 +01:00
Paul Holzinger
dafa2e722c
update github.com/containers/gvisor-tap-vsock to v0.8.8
Fixes: #28003

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-02-11 16:06:19 +01:00
mheon
e3d9a7863f Bump Podman to v5.8.0-dev
Signed-off-by: mheon <7735048+mheon@users.noreply.github.com>
2026-02-10 20:23:52 +00:00
Matt Heon
7d598f7f90
Merge pull request #28058 from mheon/bump_580_rc1
Bump to v5.8.0-RC1
2026-02-10 15:00:10 -05:00
Matt Heon
cf2514451d
Bump to v5.8.0-RC1
Signed-off-by: Matt Heon <mheon@redhat.com>
2026-02-10 08:47:45 -05:00
Ashley Cui
649c074bf5
Merge pull request #28042 from mheon/backports_580_rc1
Backports and release notes for v5.8.0-RC1
2026-02-09 20:10:48 -05:00
Paul Holzinger
6bec23fd04
Merge pull request #27660 from mheon/58_migrate_db
[v5.8] Add migration code for BoltDB to SQLite
2026-02-09 16:06:57 +01:00
Matt Heon
b2325c1126 Extent timeout on Build Each Commit
Signed-off-by: Matt Heon <matthew.heon@pm.me>
2026-02-09 09:31:12 -05:00
Matt Heon
72838c8458 Update release notes for v5.8.0-RC1
Signed-off-by: Matt Heon <matthew.heon@pm.me>
2026-02-06 15:36:47 -05:00
MayorFaj
05135d35fe fix: remove unnecessary -t flag from podman run commands in documentation
Signed-off-by: MayorFaj <mayorfaj@gmail.com>
2026-02-06 15:36:47 -05:00
Jindrich Novy
e330a9fd83 Add /usr/libexec/podman/qemu-system-arch
Signed-off-by: Jindrich Novy <jnovy@redhat.com>
2026-02-06 15:36:47 -05:00
Paul Holzinger
949d406ed1 test/system: skip podman volumes with XFS quotas on fedora
It fails due selinux, it is unlcear why so I filled #27759 for now to
track that so we can get the image update merged.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-02-06 15:36:47 -05:00
Paul Holzinger
3235579b48 cirrus: ensure NOTIFY_SOCKET is properly unset for all tests
Podman uses this env toi do various things, we don't want the external
env to affect our tests here.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-02-06 15:36:47 -05:00
MayorFaj
faedb9c911 docs: Update filter options and add podman ps documentation
Signed-off-by: MayorFaj <mayorfaj@gmail.com>
2026-02-06 15:36:47 -05:00
MayorFaj
e70bfff716 docs: Deduplicate --filter descriptions
Signed-off-by: MayorFaj <mayorfaj@gmail.com>
2026-02-06 15:36:47 -05:00
Matt Heon
63ea75a599 Deterministically order pod inspect fields
There are two fields I'm worried about: shared namespaces and pod
containers. Both are generated via loops over maps and are thus
non-deterministic in ordering. Throw a sort on each to fix the
order so we can actually diff `podman pod inspect` output.

Signed-off-by: Matt Heon <mheon@redhat.com>
2026-02-06 15:36:47 -05:00
ZuhairM7
4e3dd47967 bindings: fix handling of env secrets in remote builds
Previously, using --secret=id=foo,env=BAR in remote mode would fail because the client sent the env var name to the server, which tried to resolve it locally. This patch modifies the client to resolve the environment variable locally, write it to a temp file, and send it as a file-based secret.

Fixes #27494

Signed-off-by: ZuhairM7 <ZuhairM7>
Signed-off-by: ZuhairM7 <zuhairmerali@gmail.com>
2026-02-06 15:36:47 -05:00
Brent Baude
b17e90703c Add perl to make validatepr
Users reported that our container image for make validatepr needs perl
base installed.

Signed-off-by: Brent Baude <bbaude@redhat.com>
2026-02-06 15:36:47 -05:00
Jan Rodák
86b6c75cef Fix unless-stopped restart policy to match Docker behavior
- Update documentation: Differentiate `unless-stopped` from `always` - containers stopped by the user before a reboot will not restart.
- Add `should-start-on-boot` filter: Identify containers that require a restart after a system reboot.
- Update command documentation: Add `restart-policy` and `label!` filters to the documentation for container commands (rm, ps, start, stop, pause, unpause, restart).
- Add `restart-policy` and `shoud-start-on-boot` to completions.
- Update service: Update `podman-restart.service` to use the `needs-restart=true` filter.
- Preserve state: Preserve the `StoppedByUser` state across reboots.
- Update API: Add a `ShouldStartOnBoot()` method to the Container API.
- Update documentation: Add descriptions for the `should-start-on-boot` filter.

Fixes: https://issues.redhat.com/browse/RHEL-129405
Fixes: https://github.com/containers/podman/issues/20418

Signed-off-by: Jan Rodák <hony.com@seznam.cz>

<MH: Fixed cherry-pick conflicts>

Signed-off-by: Matt Heon <matthew.heon@pm.me>
2026-02-06 15:36:47 -05:00
Timothée Ravier
8e93487dcc docs/podman.1: Fix leftover rootless mention
Fixes: 75f4215717

Signed-off-by: Timothée Ravier <tim@siosm.fr>
2026-02-06 15:36:47 -05:00
0xdvc
35c602bfbb fix: improve userns validation when joining pods
- remove old CLI validation that only checked --pod flag
- add validation in namespaces.go to catch all paths (cli, quadlet, api)
- block userns mixing for all pods with infra, not just ipc/net
- update error message to be clearer
- fix test cleanup to use PodmanExitCleanly()
- use dynamic pod names in system tests to avoid conflicts

fixes #26848

Signed-off-by: 0xdvc <neilohene@gmail.com>

<MH: Fixed cherry-pick conflicts>

Signed-off-by: Matt Heon <matthew.heon@pm.me>
2026-02-06 15:36:47 -05:00
Salim B
371b3ecdc1 docs: further tweaks
Signed-off-by: Salim B <git@salim.space>
2026-02-06 15:36:47 -05:00
Salim B
36b11b43fd docs: improve note about Quadlet TimeoutStartSec
Signed-off-by: Salim B <git@salim.space>
2026-02-06 15:36:47 -05:00
Vyacheslav Bespalov
d6c79580f8 [Fixes: #27571] Fix 'shouldResolveWinPaths' returning 'false' on Windows
Signed-off-by: Vyacheslav Bespalov <vbespalov@ptsecurity.com>
2026-02-06 15:36:47 -05:00
axel7083
243b623629 fix(api/compat): typo in the remove secret handle
Fixes https://github.com/containers/podman/issues/27548

Signed-off-by: axel7083 <42176370+axel7083@users.noreply.github.com>
2026-02-06 15:36:47 -05:00
Aaron Ang
8423b3bbd0 Clamp rootless rlimits to host on format
Signed-off-by: Aaron Ang <aaron.angyd@gmail.com>

<MH: Fixed cherry-pick conflicts>

Signed-off-by: Matt Heon <matthew.heon@pm.me>
2026-02-06 15:36:47 -05:00
Aaron Ang
58a15f1500 Add ulimits to podman update API
Signed-off-by: Aaron Ang <aaron.angyd@gmail.com>

<MH: Fixed cherry-pick conflicts>

Signed-off-by: Matt Heon <matthew.heon@pm.me>
2026-02-06 15:36:47 -05:00
Erik Sjölund
0f5b913a7c podman-systemd.unit.5: document /sbin/nologin accounts
Add command:
sudo systemctl --machine username@ --user list-unit-files

Fixes: https://github.com/containers/podman/issues/27544

Co-authored-by: Tom Sweeney <tsweeney@redhat.com>
Signed-off-by: Erik Sjölund <erik.sjolund@gmail.com>
2026-02-06 15:36:47 -05:00
ryanmccann1024
484858710c feat(exec): Add --no-session flag for improved performance
Fixes: #26588

For use cases like HPC, where `podman exec` is called in rapid succession, the standard exec process can become a bottleneck due to container locking and database I/O for session tracking.

This commit introduces a new `--no-session` flag to `podman exec`. When used, this flag invokes a new, lightweight backend implementation that:

- Skips container locking, reducing lock contention
- Bypasses the creation, tracking, and removal of exec sessions in the database
- Executes the command directly and retrieves the exit code without persisting session state
- Maintains consistency with regular exec for container lookup, TTY handling, and environment setup
- Shares implementation with health check execution to avoid code duplication

The implementation addresses all performance bottlenecks while preserving compatibility with existing exec functionality including --latest flag support and proper exit code handling.

Changes include:
- Add --no-session flag to cmd/podman/containers/exec.go
- Implement lightweight execution path in libpod/container_exec.go
- Ensure consistent container validation and environment setup
- Add comprehensive exit code testing including signal handling (exit 137)
- Optimize configuration to skip unnecessary exit command setup

Signed-off-by: Ryan McCann <ryan_mccann@student.uml.edu>
Signed-off-by: ryanmccann1024 <ryan_mccann@student.uml.edu>
2026-02-06 15:36:47 -05:00