Commit graph

15830 commits

Author SHA1 Message Date
OpenShift Merge Robot
b53eccfc2a
Merge pull request #15234 from flouthoc/v4.2-buildah-1.27
[release-4.2] vendor: bump buildah to `v1.27.0`
2022-08-09 14:31:35 +00:00
OpenShift Merge Robot
9ee855a375
Merge pull request #15214 from ashley-cui/backport4.2
[4.2] Backport WSL Machine fixes
2022-08-09 12:14:34 +00:00
OpenShift Merge Robot
cd645e8ae9
Merge pull request #15240 from openshift-cherrypick-robot/cherry-pick-15235-to-v4.2
[CI:DOCS] [v4.2] pkginstaller: use correct GOARCH value in case of arm build
2022-08-09 07:43:58 +00:00
Aditya R
916d51bd0d
test: update apply-podman-deltas for new tests
Skip some newly added test for remote and modify error output of a test
case which is reporter early in case of podman.

[NO NEW TESTS NEEDED]
[NO TESTS NEEDED]

Signed-off-by: Aditya R <arajan@redhat.com>
2022-08-09 09:04:10 +05:30
Aditya R
3a239947af
build: implement --cache-to,--cache-from and --cache-ttl
[NO NEW TESTS NEEDED]
[NO TESTS NEEDED]

Signed-off-by: Aditya R <arajan@redhat.com>
2022-08-09 09:04:04 +05:30
Aditya R
6b2512f67f
vendor: bump buildah to v1.27.0
Bump buildah to v1.27.0

[NO NEW TESTS NEEDED]

Signed-off-by: Aditya R <arajan@redhat.com>
2022-08-09 09:03:58 +05:30
Gerard Braad
6beb3f208f Fixes #15154 Change order when config and connections are written
When the break out or the WSL environment fails to start, the config
and connections should not be written. Placing them at the end of the
provisioning step will mitigate the issue.

[NO NEW TESTS NEEDED]

Signed-off-by: Gerard Braad <me@gbraad.nl>
2022-08-08 16:15:28 -04:00
Jason T. Greene
eab03100f7 Add support, and default to rootless w/WSL prompt
Also force installation to use WSL2 to prevent accidental usage of WSL1

Signed-off-by: Jason T. Greene <jason.greene@redhat.com>
2022-08-08 16:15:28 -04:00
Jason T. Greene
f826ed5846 Disable F36 service that is incompat with WSL kern
(requires psi)

Signed-off-by: Jason T. Greene <jason.greene@redhat.com>
2022-08-08 16:15:28 -04:00
OpenShift Merge Robot
b3d5ba657b
Merge pull request #15216 from cevich/v4.2_image_search
[v4.2] Cirrus: Improve CI VM image updates for EC2
2022-08-08 15:20:10 +00:00
Anjan Nath
d16b42f265 pkginstaller: use correct GOARCH value in case of arm build
to compile arm bits the GOARCH should be set to amd64 script
was wrongly using aarch64 instead

[NO NEW TESTS NEEDED]

Signed-off-by: Anjan Nath <kaludios@gmail.com>
2022-08-08 13:37:28 +00:00
openshift-ci[bot]
518b7cdd39
Merge pull request #15202 from lsm5/v420RC3-release
Bump to v4.2.0-rc3
2022-08-05 17:26:14 +00:00
Chris Evich
0593ceb01f
Cirrus: Update DEST_BRANCH to v4.2
Signed-off-by: Chris Evich <cevich@redhat.com>
2022-08-05 11:53:38 -04:00
Chris Evich
fb85843324
Cirrus: Improve CI VM image updates for EC2
AWS EC2 keys VM images by an utterly unreadable, horrible to use,
generated "AMI ID" value.  This is very error prone for humans in
practice, since it's impossible to tell one image from the next by
eye.  Worse, EC2 permits duplicate name-tag values, complicating
image specification further.

However fortunately, Cirrus-CI recently implemented a feature by
which AMI's may be referenced by a name-tag search - choosing
the most recent AMI found.  Since the `containers/automation_images`
build workflow always assigns a unique name + `$IMAGE_SUFFIX` value,
we can simply re-use it for both AWS and GCP image specification.

In other words as of this commit, specifying new CI VM images can
be done by simply updating the `$IMAGE_SUFFIX` value as we've always
done.  No need to call out a specific AMI ID just for EC2 tasks.

Signed-off-by: Chris Evich <cevich@redhat.com>
2022-08-05 11:27:41 -04:00
Lokesh Mandvekar
d5793db280
Bump back to v4.2.0-dev
Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
2022-08-05 09:21:34 -04:00
Lokesh Mandvekar
7e1f3106ff Bump to v4.2.0-rc3
Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
2022-08-05 09:21:21 -04:00
openshift-ci[bot]
4b0343efeb
Merge pull request #15201 from lsm5/v420RC3
[CI:DOCS] v4.2.0-rc3 release notes
2022-08-05 13:21:00 +00:00
Lokesh Mandvekar
1b7e16654b
v4.2.0-rc3 release notes
Co-authored-by: Valentin Rothberg <vrothberg@redhat.com>
Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
2022-08-05 08:41:10 -04:00
openshift-ci[bot]
500a00c9ce
Merge pull request #15194 from ashley-cui/backports
[CI:DOCS] [4.2] Backport MacOS pkginstaller
2022-08-04 21:15:23 +00:00
Anjan Nath
bf2a53a2e0 pkginstaller: use correct GOARCH while building podman binaries
we were not using the correct GOARCH to build the podman remote
and podman-mac-helper binaries, this uses the ARCH value passed
to the make invocation to set the GORACH

[NO NEW TESTS NEEDED]

Signed-off-by: Anjan Nath <kaludios@gmail.com>
2022-08-04 09:46:35 -04:00
Anjan Nath
d4481a3170 pkginstaller: makefile improvements to avoid redownloading
this updates downloading of gvproxy and qemu using a standard
makefile rule which will avoid downloading them again if  its
already downloaded

[NO NEW TESTS NEEDED]

Signed-off-by: Anjan Nath <kaludios@gmail.com>
2022-08-04 09:46:09 -04:00
Anjan Nath
1b3844f655 pkginstaller: add makefile target to notarize the built pkg
[NO NEW TESTS NEEDED]

Signed-off-by: Anjan Nath <kaludios@gmail.com>
2022-08-04 09:46:03 -04:00
Anjan Nath
64db955e06 pkginstaller: sign qemu-system-* binary for the pkg
add file hvf.entitlements which has the com.apple.security.hypervisor
entitlement needed for qemu

[NO NEW TESTS NEEDED]

Signed-off-by: Anjan Nath <kaludios@gmail.com>
2022-08-04 09:45:57 -04:00
Anjan Nath
9a820b480a Add support for building macOS pkg installer
it installs podman and supporting binaries along with
qemu to have a functioning podman install using a pkg

podman and podman-mac-helper  is compiled from source

gvproxy binary is downloaded from its github releases
and qemu from github release of containers/podman-machine-qemu

[NO NEW TESTS NEEDED]

Signed-off-by: Anjan Nath <kaludios@gmail.com>
2022-08-04 09:44:36 -04:00
openshift-ci[bot]
49ae6cfed6
Merge pull request #15142 from mtrmac/sigstore-sign-4.2
[v4.2] Sigstore sign
2022-08-02 20:09:10 +00:00
Miloslav Trmač
5c95c0920f Add support for creating sigstore signatures, and providing passphrases
- Allow creating sigstore signatures via --sign-by-sigstore-private-key .
  Like existing --sign-by, it does not work remote (in this case
  because we would have to copy the private key to the server).
- Allow passing a passphrase (which is mandatory for sigstore private keys)
  via --sign-passphrase-file; if it is not provided, prompt interactively.
- Also, use that passphrase for --sign-by as well, allowing non-interactive
  GPG use. (But --sign-passphrase-file can only be used with _one of_
  --sign-by and --sign-by-sigstore-private-key.)

Note that unlike the existing code, (podman build) does not yet
implement sigstore (I'm not sure why it needs to, it seems not to
push images?) because Buildah does not expose the feature yet.

Also, (podman image sign) was not extended to support sigstore.

The test for this follows existing (podman image sign) tests
and doesn't work rootless; that could be improved by exposing
a registries.d override option.

The test for push is getting large; I didn't want to
start yet another registry container, but that would be an
alternative.  In the future, Ginkgo's Ordered/BeforeAll
would allow starting a registry once and using it for two
tests.

Signed-off-by: Miloslav Trmač <mitr@redhat.com>
2022-08-02 16:52:56 +02:00
Miloslav Trmač
0aebdb6875 Hide podman manifest push --sign-by on remote
... because it is documented to be ignored.

Signed-off-by: Miloslav Trmač <mitr@redhat.com>
2022-08-02 16:52:56 +02:00
Miloslav Trmač
b2b3edaca0 Use signByFlagName instead of copy&pasting the string
Signed-off-by: Miloslav Trmač <mitr@redhat.com>
2022-08-02 16:52:56 +02:00
Miloslav Trmač
49d40293b4 Remove libpod/common
AFAICS it is not used anywhere.

Signed-off-by: Miloslav Trmač <mitr@redhat.com>
2022-08-02 16:52:56 +02:00
Miloslav Trmač
eacee60c83 Update c/common to an unreleased version
... to get https://github.com/containers/common/pull/1106 .

Signed-off-by: Miloslav Trmač <mitr@redhat.com>
2022-08-02 16:52:56 +02:00
Miloslav Trmač
62cc871c66 Update the registry server we test against from 2.6 to 2.8
... primarily so that it can support OCI artifacts.

2.8 already seems to exist in the repo.

This requires changing WaitContainerReady to also check
stderr (ultimately because docker/distribution was
updated to a more recent sirupsen/logrus, which logs
by default to stderr instead of stdout).

Signed-off-by: Miloslav Trmač <mitr@redhat.com>
2022-08-02 16:52:56 +02:00
Miloslav Trmač
52db763737 Use existing REGISTRY_IMAGE variables in more places
... instead of hard-coding a copy of the value.

Notably this makes hack/podman_registry actually
support the documented -i option.

Signed-off-by: Miloslav Trmač <mitr@redhat.com>
2022-08-02 16:52:56 +02:00
Miloslav Trmač
2303632250 Use httpasswd from the surrouding OS instead of the registry image
htpasswd is no longer included in docker.io/library/distribution
after 2.7.0, per https://github.com/docker/distribution-library-image/issues/107 ,
and we want to upgrade to a recent version.

At least system tests currently execute htpasswd from the OS,
so it seems that it is likely to be available.

Signed-off-by: Miloslav Trmač <mitr@redhat.com>
2022-08-02 16:52:56 +02:00
Valentin Rothberg
74155705e4 fix e2e sign tests
The key used in the tests has expired.  Remove the expiration date to
turn CI happy and green.

Signed-off-by: Valentin Rothberg <vrothberg@redhat.com>
2022-08-02 16:52:56 +02:00
OpenShift Merge Robot
87f892e5b5
Merge pull request #15076 from mheon/bump_420_rc2
Bump to v4.2.0-RC2
2022-07-27 12:02:25 -04:00
Matthew Heon
983cfb90e6 Final v4.2.0-RC2 release notes
Signed-off-by: Matthew Heon <matthew.heon@pm.me>
2022-07-27 09:31:52 -04:00
Matthew Heon
bf6f796304 Skip one failing test on Ubuntu
Probably a result of the Ubuntu images being bumped on Main but
not in this branch. Not worth chasing down exactly what's going
wrong, so let's just disable it.

Signed-off-by: Matthew Heon <matthew.heon@pm.me>
2022-07-27 09:29:33 -04:00
Matthew Heon
25efc9b2e3 Fix incorrect release note about regexp
Label matching did not use regular expressions, it used glob
matching. Let's fix the release notes to prevent confusion.

Signed-off-by: Matthew Heon <matthew.heon@pm.me>
2022-07-26 14:55:19 -04:00
Matthew Heon
4acc14b4e3 Bump to v4.2.0-dev
Signed-off-by: Matthew Heon <matthew.heon@pm.me>
2022-07-26 14:52:14 -04:00
Matthew Heon
81005b8d80 Bump to v4.2.0-RC2
Signed-off-by: Matthew Heon <matthew.heon@pm.me>
2022-07-26 14:47:49 -04:00
Matthew Heon
6fafe120cb Final release notes for v4.2.0-RC2
Signed-off-by: Matthew Heon <matthew.heon@pm.me>
2022-07-26 14:47:26 -04:00
Erik Sjölund
990ef3cf6b [CI:DOCS] podman-generate-systemd.1.md: document --sdnotify
* Document why the default value for --sdnotify is overridden.
  Some was included text from
  https://github.com/containers/podman/issues/15029#issuecomment-1192244755

* Document that --sdnotify=ignore is overridden.

Fixes #15029

Co-authored-by: Valentin Rothberg <vrothberg@redhat.com>
Co-authored-by: Tom Sweeney <tsweeney@redhat.com>
Signed-off-by: Erik Sjölund <erik.sjolund@gmail.com>
2022-07-26 14:46:25 -04:00
Charlie Doern
c85722eb9f pod create --share none should not create infra
for podman pod create, when we are not sharing any namespaces there is no point for the infra container.
This is especially true since resources have also been decoupled from the container recently.

handle this on the cmd level so that we can still create infra if set explicitly

resolves #15048

Signed-off-by: Charlie Doern <cdoern@redhat.com>
2022-07-26 14:46:12 -04:00
Christophe Fergeau
c3e0f8ebef machine: Fix check which is always true
Before making / mutable/immutable, podman-machine checks if the mount is
being done in /home or /mnt. However the current check is always going
to be true:
```
!strings.HasPrefix(mount.Target, "/home") || !strings.HasPrefix(mount.Target, "/mnt")
```
is false when mount.Target starts with "/home" and mount.Target starts
with "/mnt", which cannot happen at the same time.

The correct check is:
```
!strings.HasPrefix(mount.Target, "/home") && !strings.HasPrefix(mount.Target, "/mnt")
```
which can also be written as:
```
!(strings.HasPrefix(mount.Target, "/home") || strings.HasPrefix(mount.Target, "/mnt"))
```

The impact is not too bad, it results in extra 'chattr -i' calls which
should be unneeded.

[NO NEW TESTS NEEDED]

Signed-off-by: Christophe Fergeau <cfergeau@redhat.com>
2022-07-26 14:45:12 -04:00
Vladimir Kochnev
e6ebfbd1e0 Set TLSVerify=true by default for API endpoints
Option defaults in API must be the same as in CLI.

```
% podman image push --help
% podman image pull --help
% podman manifest push --help
% podman image search --help
```

All of these CLI commands them have --tls-verify=true by default:
```
--tls-verify  require HTTPS and verify certificates when accessing the registry (default true)
```

As for `podman image build`, it doesn't have any means to control
`tlsVerify` parameter but it must be true by default.

Signed-off-by: Vladimir Kochnev <hashtable@yandex.ru>
2022-07-26 14:44:05 -04:00
Ed Santiago
64bc2ee97f Semiperiodoc cleanup of obsolete FIXMEs
Some refer to issues that are closed. Remove them.

Some are runc bugs that will never be fixed. Say so, and remove
the FIXME.

One (bps/iops) should probably be fixed. File an issue for it, and
update comment to include the issue# so my find-obsolete-skips script
can track it.

And one (rootless mount with a "kernel bug?" comment) is still
not fixed. Leave the skip, but add a comment documenting the symptom.

Signed-off-by: Ed Santiago <santiago@redhat.com>
2022-07-26 14:43:23 -04:00
Valentin Rothberg
b339045db5 benchmarks: fix create test
And a new one for `run --detach`.

Signed-off-by: Valentin Rothberg <vrothberg@redhat.com>
2022-07-26 14:43:08 -04:00
Paul Holzinger
fd1f5f55ab integration test: fix network backend option with remote
I honestly do not understand all this extra option parsing here but
there is really no reason to exclude  the option for remote, all the
other global options are also set there.

This fixes a problem with mixed cni/netavark use because the option was
unset.

Fixes #15017

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2022-07-26 14:42:48 -04:00
Paul Holzinger
c7fef73166 docs: remove CNI word where it is not applicable
Most network commands/features work with both netavark and CNI. When
we added added netavark most docs were not vetted and thus still use CNI
network, it should just say network.

Fixes #14990

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2022-07-26 14:42:32 -04:00
Giuseppe Scrivano
976f818f1e libpod: do not lock all containers on pod rm
do not attempt to lock all containers on pod rm since it can cause
deadlocks when other podman cleanup processes are attempting to lock
the same containers in a different order.

[NO NEW TESTS NEEDED]

Closes: https://github.com/containers/podman/issues/14929

Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
2022-07-26 14:42:19 -04:00