Commit graph

24031 commits

Author SHA1 Message Date
Daniel J Walsh
aad97a1342
Merge pull request #24714 from openshift-cherrypick-robot/cherry-pick-24706-to-v5.3
[v5.3] Fixes missing binary in systemd.
2024-12-02 12:18:31 -05:00
SEIAROTg
cd1b2981b4 Fixes missing binary in systemd.
This is broken on e.g. NixOS as systemd only searches a small set of
directories for command binary, which does not include `/bin` [1].

[1]: https://www.freedesktop.org/software/systemd/man/latest/systemd.service.html#Command%20lines

Signed-off-by: SEIAROTg <seiarotg@gmail.com>
2024-11-29 14:28:26 +00:00
openshift-merge-bot[bot]
36ad25ad7c
Merge pull request #24710 from openshift-cherrypick-robot/cherry-pick-24682-to-v5.3
[v5.3] [skip-ci] Packit: remove epel and re-enable c9s
2024-11-29 11:56:32 +00:00
openshift-merge-bot[bot]
b0d967589d
Merge pull request #24709 from openshift-cherrypick-robot/cherry-pick-24700-to-v5.3
[v5.3] [skip-ci] Packit/copr: switch to fedora-all
2024-11-29 11:53:46 +00:00
Lokesh Mandvekar
d4976e0677 Packit: remove epel and re-enable c9s
We're moving away from proper rhel testing on upstream because of the
slower pace of RHEL. This has already been done on aardvark-dns and some
others.

CentOS 9 Stream does move fast enough that we can re-enable it here.

Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
2024-11-29 11:51:11 +00:00
Lokesh Mandvekar
fee50f0f31 Packit/copr: switch to fedora-all
Fedora 39 is now EOL.

Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
2024-11-29 11:48:50 +00:00
openshift-merge-bot[bot]
c2f09d78d5
Merge pull request #24668 from Luap99/v5.3
[v5.3] fix CI and backport quadlet build fix
2024-11-25 12:33:55 +00:00
Ygal Blum
0d22d7b74e
Quadlet - Use = sign when setting the pull arg for build
Signed-off-by: Ygal Blum <ygal.blum@gmail.com>
(cherry picked from commit 13affe96d6)
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2024-11-25 11:56:49 +01:00
Paul Holzinger
62c096bbce
win-installer test: revert to v5.3.0
Do not pull from a moving target, use a defined version so updates must
happen in a PR and do not break others.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
(cherry picked from commit 916b805f97)
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2024-11-25 11:56:19 +01:00
openshift-merge-bot[bot]
b8871c0a45
Merge pull request #24630 from mheon/bump_531
Bump to v5.3.1
2024-11-21 15:37:25 +00:00
Matt Heon
7bf22277ca Bump to v5.3.2-dev
Signed-off-by: Matt Heon <mheon@redhat.com>
2024-11-21 08:40:20 -05:00
Matt Heon
4cbdfde5d8 Bump to v5.3.1
Signed-off-by: Matt Heon <mheon@redhat.com>
2024-11-21 08:40:20 -05:00
Matt Heon
50960afe33 Update release notes for v5.3.1
Signed-off-by: Matt Heon <mheon@redhat.com>
2024-11-21 08:40:20 -05:00
openshift-merge-bot[bot]
f918c35a66
Merge pull request #24627 from openshift-cherrypick-robot/cherry-pick-24624-to-v5.3
[v5.3] On Windows avoid installing WSL during an update of Podman
2024-11-20 21:24:39 +00:00
Mario Loriedo
d26990702c Update windows installer tests
The windows installer tests are command line / non interactive. To test as much as
possible the GUI / interactive scenario (that is what user do), update tests
need to use the installer with the default options. That's because when using the GUI
for an update, changing options is not possible.

Signed-off-by: Mario Loriedo <mario.loriedo@gmail.com>
2024-11-20 20:27:36 +00:00
Mario Loriedo
2739822424 Windows: don't install WSL/HyperV on update
The condition `NOT Installed` had not effect and has been replaced with
`NOT WIX_UPGRADE_DETECTED` that is `true` during installation and
`false` during updates.

The `ExePackage` WSL Kernel Install is also not installed if Podman is
already present.

Signed-off-by: Mario Loriedo <mario.loriedo@gmail.com>
2024-11-20 20:27:36 +00:00
Mario Loriedo
a8d61c034b Switch to non-installing WSL by default
The Windows installer GUI has a checkbox to choose if WSL and HyperV
should be installed as part of the installation of Podman. Now, by
default, that checkbox is disabled for both WSL and HyperV.

Signed-off-by: Mario Loriedo <mario.loriedo@gmail.com>
2024-11-20 20:27:36 +00:00
openshift-merge-bot[bot]
efbe4e95e4
Merge pull request #24608 from Luap99/v5.3
[v5.3] v5.3 backports
2024-11-19 12:18:03 +00:00
Paul Holzinger
98353f27ed
docs: add 5.3 as Reference version
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
(cherry picked from commit e6e9d2c21c)
2024-11-19 11:35:30 +01:00
Paul Holzinger
4886a0ba64
only read ssh_config for non machine connections
For machine we know we have all the info we need so there is no reason
to read and parse another file.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
(cherry picked from commit 71f1f52894)
2024-11-19 11:28:30 +01:00
Paul Holzinger
93562b4955
ssh_config: allow IdentityFile file with tilde
The ssh_config can contain a path with ~/ to refer to the home dir like
done on shells. Handle that special case and resolve the path correctly
so it can be used.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
(cherry picked from commit cbb2820a7e)
2024-11-19 11:28:30 +01:00
Paul Holzinger
28e7b239ba
ssh_config: do not overwrite values from config file
When we alreadty get a full URL with user, port and identity then we
should not read the config file just to overwrite them with wrong
values. This is a bad regression for user using * wildcard in their
ssh_config as it makes podman machine unusable.

Fixes: #24567
Fixes: e523734ab6 ("Add support for ssh_config for connection")

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
(cherry picked from commit a7120b50b1)
2024-11-19 11:28:30 +01:00
Paul Holzinger
c49944ea02
connection: ignore errors when parsing ssh_config
The new ssh_Config feature doesn't work on my system because the lib
fails to parse configs using Match[1]. However Fedora and RHEL based
distros seem to ship /etc/ssh/ssh_config.d/50-redhat.conf which contains
a Match line thus it always fails to parse and never uses the proper
values from my home dir config.

[1] https://github.com/kevinburke/ssh_config/issues/6

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
(cherry picked from commit 8a5ec2c505)
2024-11-19 11:28:30 +01:00
Giuseppe Scrivano
f7877bf9db
spec: clamp rlimits in a userns
commit 5ebba75dbd implemented this
behaviour for rootless users, but the same limitation exists for any
user in a user namespace.  Change the check to use the clamp to the
current values anytime podman runs in a user namespace.

Closes: https://github.com/containers/podman/issues/24508

Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
(cherry picked from commit 0a69aefa41)
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2024-11-19 11:27:38 +01:00
Paul Holzinger
dcedf5f211
cirrus: set proper DEST_BRANCH for 5.3
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2024-11-19 11:25:30 +01:00
openshift-merge-bot[bot]
878f3ae687
Merge pull request #24594 from openshift-cherrypick-robot/cherry-pick-24578-to-v5.3
[v5.3] libpod: addHosts() prevent nil deref
2024-11-18 13:43:05 +00:00
Paul Holzinger
a39a749ce3 libpod: addHosts() prevent nil deref
In theory RootlessNetnsInfo() should never return nil here. However that
was actually only true when the rootless netns was set up before and
wrote the right cache file with the ip addresses.

Given this cache file is a new feature just added in 5.3 if you updated
from 5.2 or earlier the file will not exists thus cause failures for all
following started containers.
The fix for this is to stop all containers and make sure the
rootless-netns was removed so the next start creates it new with the
proper 5.3 cache file. However as there is no way to rely on users doing
that and it is also not requirement so simply handle the nil deref here.

The only way to test this would be to run the old version then the new
version which we cannot really do in CI. We do have upgrade test for
that but they are root only and likely need a lot more work to get them
going rootless but certainly worth to explore to prevent such problems
in the future.

Fixes: a1e6603133 ("libpod: make use of new pasta option from c/common")
Fixes: #24566

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2024-11-18 12:59:57 +00:00
openshift-merge-bot[bot]
d3e7d4e217
Merge pull request #24564 from openshift-cherrypick-robot/cherry-pick-24563-to-v5.3
[v5.3] Bump bundled krunkit to 0.1.4
2024-11-14 15:41:02 +00:00
Sergio Lopez
9a9f07aa4b Bump bundled krunkit to 0.1.4
Bump the bundled krunkit version from 0.1.3 to 0.1.4.

Fixes: #24559

Signed-off-by: Sergio Lopez <slp@redhat.com>
2024-11-14 15:05:16 +00:00
openshift-merge-bot[bot]
5a88fc45e3
Merge pull request #24560 from openshift-cherrypick-robot/cherry-pick-24321-to-v5.3
[v5.3] Fix for podman machine init not creating necessary JSON file when an ignition-path is passed
2024-11-14 13:07:02 +00:00
Graceson Aufderheide
5546dc6c20 fix podman machine init --ignition-path
Fix the issue where podman machine init does not create
all the necessary machine files when ignition-path is used. Fixes: #23544

Signed-off-by: Graceson Aufderheide <gracesonphoto@gmail.com>
2024-11-14 11:26:09 +00:00
openshift-merge-bot[bot]
2026506708
Merge pull request #24548 from mheon/bump_530
Bump to v5.3.0
2024-11-12 19:01:59 +00:00
Matt Heon
8efa1c1075 Bump to v5.3.1-dev
Signed-off-by: Matt Heon <mheon@redhat.com>
2024-11-12 11:10:36 -05:00
Matt Heon
874bf2c301 Bump to v5.3.0
Signed-off-by: Matt Heon <mheon@redhat.com>
2024-11-12 11:10:17 -05:00
Matt Heon
2e3836d226 Update release notes for v5.3.0
Signed-off-by: Matt Heon <mheon@redhat.com>
2024-11-12 10:58:28 -05:00
openshift-merge-bot[bot]
400240533d
Merge pull request #24528 from TomSweeneyRedHat/dev/tsweeney/buildahv1.38
[v5.3] Bump to Buildah v1.38.0
2024-11-11 21:43:40 +00:00
tomsweeneyredhat
31df1bb97c [v5.3] Bump to Buildah v1.38.0
Bump to Buildah v1.38.0 in preparation of Podman v5.3.

This will also ensure the following versions are in place:

c/storage: v1.56.0
c/image:   v5.33.0
c/common:  v0.61.0

Signed-off-by: tomsweeneyredhat <tsweeney@redhat.com>
2024-11-11 14:20:56 -05:00
tomsweeneyredhat
9556882bbf [v5.3] Skip FIPS mode secrets run test
The FIPS mode secrets test cannot run on this branch,
skip them for now.

Signed-off-by: tomsweeneyredhat <tsweeney@redhat.com>
2024-11-11 14:20:56 -05:00
Ed Santiago
c6dd2c77ab [v5.3] Buildah treadmill tweaks
* treadmill script: handle an obscure corner case
  wherein the script would bail because it thought
  there were no buildah-vendor changes.

* two new test skips

* update the diffs; line-number changes due to buildah
  PRs touching helpers.bash

Signed-off-by: Ed Santiago <santiago@redhat.com>
(cherry picked from commit 33398ebc1e)
Signed-off-by: tomsweeneyredhat <tsweeney@redhat.com>
2024-11-11 13:28:12 -05:00
openshift-merge-bot[bot]
d88d04e115
Merge pull request #24495 from Luap99/v5.3
[v5.3] Some backports for 5.3
2024-11-07 19:59:39 +00:00
Paul Holzinger
0710e83c41
test/buildah-bud: build new inet helper
Added in https://github.com/containers/buildah/pull/5783

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
(cherry picked from commit 22152a2f9c)
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2024-11-07 17:41:23 +01:00
Paul Holzinger
d852c58d6c
test/system: add regression test for TZDIR local issue
Regression test for #23550. Setting the TZDIR env should make no
difference for the local timezone as this is not a real timezone name
that is resolved from that directory.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
(cherry picked from commit fb3a0e93a8)
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2024-11-07 17:41:23 +01:00
Paul Holzinger
ac59fb9231
vendor latest c/{buildah,common,image,storage}
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
(cherry picked from commit f6af35c695)
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2024-11-07 17:41:23 +01:00
Ed Santiago
1f0e2db2a9
Reapply "CI: test nftables driver on fedora"
Temporary, until we get CI VMs with kernel 6.11.6.

I've lost track of where this is being discussed.

This reverts commit 7f836df303.

Signed-off-by: Ed Santiago <santiago@redhat.com>
(cherry picked from commit 0e66a793bc)
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2024-11-07 17:40:49 +01:00
Ed Santiago
16acfd7edb
Revert "cirrus: test only on f40/rawhide"
This reverts commit d03e8ffc56.

Signed-off-by: Ed Santiago <santiago@redhat.com>
(cherry picked from commit d770069062)
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2024-11-07 17:40:48 +01:00
Ed Santiago
dc97a7e0de
test f41 VMs
Signed-off-by: Ed Santiago <santiago@redhat.com>
(cherry picked from commit ba5ce49c10)
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2024-11-07 17:40:48 +01:00
Paul Holzinger
9e38b455e4
volume ls: fix race that caused it to fail
If volume ls was called while another volume was removed at the right
time it could have failed with "no such volume" as we did not ignore
such error during listing. As we list things and this no longer exists
the correct thing is to ignore the error and continue like we do with
containers, pods, etc...

This was pretty easy to reproduce with these two commands running in
different terminals:
while :; do bin/podman volume create test && bin/podman volume rm test || break; done
while :; do bin/podman volume ls || break ; done

I have a slight feeling that this might solve #23913 but I am not to
sure there so I am not adding a Fixes here.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
(cherry picked from commit 9a0c0b2eef)
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2024-11-07 17:39:55 +01:00
Daniel J Walsh
44df7344fe
AdditionalSupport for SubPath volume mounts
Add support for inspecting Mounts which include SubPaths.

Handle SubPaths for kubernetes image volumes.

Signed-off-by: Daniel J Walsh <dwalsh@redhat.com>
(cherry picked from commit 6346a11b09)
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2024-11-07 17:39:54 +01:00
openshift-merge-bot[bot]
5d60bd286f
Merge pull request #24483 from mheon/bump_530_rc3
[CI:ALL] Bump to v5.3.0-rc3
2024-11-06 19:09:00 +00:00
Matt Heon
17224fcb05 Bump to v5.3.0-dev
Signed-off-by: Matt Heon <mheon@redhat.com>
2024-11-06 10:43:38 -05:00