Commit graph

4554 commits

Author SHA1 Message Date
Paul Holzinger
a91da8a402
Merge pull request #29789 from nalind/update-buildah
Some checks failed
ci / sys local root fedora-prior (push) Has been cancelled
ci / int local rootless fedora-prior (push) Has been cancelled
ci / sys local rootless fedora-prior (push) Has been cancelled
ci / int remote root fedora-prior (push) Has been cancelled
ci / sys remote root fedora-prior (push) Has been cancelled
ci / int local root fedora-rawhide (push) Has been cancelled
ci / sys local root fedora-rawhide (push) Has been cancelled
ci / int local rootless fedora-rawhide (push) Has been cancelled
ci / sys local rootless fedora-rawhide (push) Has been cancelled
ci / int remote root fedora-rawhide (push) Has been cancelled
ci / sys remote root fedora-rawhide (push) Has been cancelled
ci / apiv2 root fedora-current (push) Has been cancelled
ci / bindings root fedora-current (push) Has been cancelled
ci / compose_v2 root fedora-current (push) Has been cancelled
ci / docker_py root fedora-current (push) Has been cancelled
ci / unit root fedora-current (push) Has been cancelled
ci / apiv2 rootless fedora-current (push) Has been cancelled
ci / compose_v2 rootless fedora-current (push) Has been cancelled
ci / farm rootless fedora-current (push) Has been cancelled
ci / unit rootless fedora-current (push) Has been cancelled
ci / upgrade v5.3.1 root fedora-current (push) Has been cancelled
ci / upgrade v5.6.2 root fedora-current (push) Has been cancelled
ci / machine linux amd64 (push) Has been cancelled
ci / windows unit (push) Has been cancelled
ci / windows e2e (push) Has been cancelled
ci / windows machine hyperv (push) Has been cancelled
ci / windows machine wsl (push) Has been cancelled
ci / macos machine applehv (push) Has been cancelled
ci / macos machine libkrun (push) Has been cancelled
ci / Total Success (push) Has been cancelled
Bump buildah to main
2026-09-30 17:50:07 +02:00
Garv Changrani
d2b8502869 ps: fix label lookup in container and pod table headings
Table headings for `podman ps` and `podman pod ps` use a plain
`map[string]string`. A table template that calls `.Label` with an
argument fails while rendering the headings, before listing rows
are printed. For example: `podman ps --format 'table {{.Label "app"}}'`

Add a shared `PsHeader` type in `cmd/podman/common` with a `Label`
method that returns the requested label name as the column heading.
Use this type for both container and pod listings.

Add container unit tests and extend the existing container and pod
e2e tests to check label headings, label values, missing labels,
unlabeled objects, and `--noheading` output.

Fixes: #29831

Signed-off-by: Garv  Changrani <154041471+Garvity@users.noreply.github.com>
2026-09-29 11:29:57 +00:00
Nalin Dahyabhai
eda29a56bf image build contexts: pay attention to tlsVerify flags
When fetching build context tarballs for use in a build, pay attention
to the tlsVerify setting at the command line (in non-remote cases) or in
the build query (in remote cases), and whatever proxy settings are set
in the current environment for whichever process is connecting to a
server that may or may not be using TLS.

Signed-off-by: Nalin Dahyabhai <nalin@redhat.com>
2026-09-29 06:05:20 -04:00
Nalin Dahyabhai
61195895f3 Pass context.Context values down to newer buildah APIs
Buildah added some variants of APIs that should improve support for
cancellation, so let's use them.

Remove the import alias for its copier package in
cmd/podman/containers/cp.go and libpod/container_copy_common.go to be
more friendly to grep.

Update the "prune leftover build containers" test to intentionally leave
some behind during its setup instead of SIGKILLing a build process.

Signed-off-by: Nalin Dahyabhai <nalin@redhat.com>
2026-09-29 06:05:20 -04:00
Giuseppe Scrivano
a1ce95d761
Merge pull request #29825 from Maniii97/fix/rootless-quadlet
Some checks failed
ci / sys local root fedora-prior (push) Has been cancelled
ci / int local rootless fedora-prior (push) Has been cancelled
ci / sys local rootless fedora-prior (push) Has been cancelled
ci / int remote root fedora-prior (push) Has been cancelled
ci / sys remote root fedora-prior (push) Has been cancelled
ci / int local root fedora-rawhide (push) Has been cancelled
ci / sys local root fedora-rawhide (push) Has been cancelled
ci / int local rootless fedora-rawhide (push) Has been cancelled
ci / sys local rootless fedora-rawhide (push) Has been cancelled
ci / int remote root fedora-rawhide (push) Has been cancelled
ci / sys remote root fedora-rawhide (push) Has been cancelled
ci / apiv2 root fedora-current (push) Has been cancelled
ci / bindings root fedora-current (push) Has been cancelled
ci / compose_v2 root fedora-current (push) Has been cancelled
ci / docker_py root fedora-current (push) Has been cancelled
ci / unit root fedora-current (push) Has been cancelled
ci / apiv2 rootless fedora-current (push) Has been cancelled
ci / compose_v2 rootless fedora-current (push) Has been cancelled
ci / farm rootless fedora-current (push) Has been cancelled
ci / unit rootless fedora-current (push) Has been cancelled
ci / upgrade v5.3.1 root fedora-current (push) Has been cancelled
ci / upgrade v5.6.2 root fedora-current (push) Has been cancelled
ci / machine linux amd64 (push) Has been cancelled
ci / windows unit (push) Has been cancelled
ci / windows e2e (push) Has been cancelled
ci / windows machine hyperv (push) Has been cancelled
ci / windows machine wsl (push) Has been cancelled
ci / macos machine applehv (push) Has been cancelled
ci / macos machine libkrun (push) Has been cancelled
ci / Total Success (push) Has been cancelled
quadlet: resolve symlinks to find drop-ins in target unit directory
2026-09-25 16:59:59 +02:00
Marie Ramlow
7cef788844 Move cgroup check below help/completion/subcommands check
NixOS builds podman inside a sandbox and uses the `podman completion` subcommand.
While upgrading to Podman 6, we noticed that this command now started
failing in our build sandbox because of the cgroup check.
The cgroups are not relevant to completion generation.

Signed-off-by: Marie Ramlow <marie@marie.cologne>
2026-09-24 19:06:03 +02:00
Mani Shankar Jha
44e7c93c37 quadlet: search target directory of symlinked unit files for drop-ins
Fixes: #29821
Signed-off-by: Mani Shankar Jha <mani.jha@btr.group>
2026-09-24 19:17:48 +05:30
Matt Heon
109bd7acd2
Merge pull request #29791 from evanpurkhiser/codex/auto-update-filter
auto-update: Add container filters
2026-09-21 15:01:10 -04:00
Oleksandr Krutko
ff2eb1b0ca The feature which allows multiple Pods creation
Fixes: #26769

Signed-off-by: Oleksandr Krutko <alexander.krutko@gmail.com>
2026-09-20 15:41:06 +03:00
Evan Purkhiser
4458f041e1
use FilterArgumentsIntoFilters
Signed-off-by: Evan Purkhiser <git@evanpurkhiser.com>
2026-09-18 11:56:25 -04:00
Evan Purkhiser
9309b9183c
auto-update: Add container filters
Allow deployments and scheduled jobs to update a selected group of
containers without checking every auto-update-enabled application.
Reuse the existing container filters and expose them through the CLI,
remote bindings, and REST API.

Filter update candidates while preserving systemd unit and pod restart
behavior. Document the selection semantics and cover filtered updates,
invalid input, remote requests, and pod restarts in the existing tests.

Signed-off-by: Evan Purkhiser <git@evanpurkhiser.com>
2026-09-17 11:16:58 -04:00
Jan Rodák
fda861989d
Merge pull request #29395 from scallaway/image-scp-compression
image scp: add --compression-format and --compression-level
2026-09-17 17:09:06 +02:00
Paul Holzinger
91238111ba
Merge pull request #27857 from arsenalzp/podman60_27724
Fix startup health check command behavior
2026-09-17 16:32:42 +02:00
Jan Rodák
9de95641de
Merge pull request #27025 from StefanNienhuis/feat/api-autoupdate
feat: Implement autoupdate endpoint in libpod REST API
2026-09-17 14:32:57 +02:00
Stefan Nienhuis
9c923c019e
feat: Implement auto update support for podman-remote
Signed-off-by: Stefan Nienhuis <stefan@nienhuisdevelopment.com>
2026-09-17 11:08:24 +02:00
seonghun lee
655b8cee14 Hide --cpu-rt-period/--cpu-rt-runtime and mark them as NOP
Podman 6 dropped cgroups v1 support, and the kernel real-time
scheduler cgroup settings only exist on cgroups v1. That means the
--cpu-rt-period and --cpu-rt-runtime options can never take effect
anymore: on cgroups v2 the values only produce a warning and are
discarded.

As agreed in the linked issue, the full removal of the options is
deferred to the next major release (7.0) to avoid a breaking change
for anyone still setting them. For 6.x this commit implements the
agreed interim step:

- remove the option documentation (docs/source/markdown/options/
  cpu-rt-period.md and cpu-rt-runtime.md) and drop the @@option
  references from the podman-create, podman-run, podman-update and
  podman-container-clone man pages
- hide both flags from --help output
- change the existing warning to state that the option is a NOP,
  that the value is ignored, and that the option will be removed in
  the next major release

The e2e tests are updated to match the new warning text. Actual
removal of the flags and the spec fields is left for Podman 7.0.

Part of #29750

Signed-off-by: seonghun lee <harrisleesh@gmail.com>
2026-09-17 01:15:52 +09:00
Oleksandr Krutko
91c3d1d8ec Fix health-startup-cmd behaviour when the value is not set
Fixes: #27724

Signed-off-by: Oleksandr Krutko <alexander.krutko@gmail.com>
2026-09-15 22:09:57 +03:00
Danish Prakash
7417ed0613
Merge pull request #29388 from AftAb-25/fix/events-network-filter
events: add missing support for NETWORK filter
2026-09-11 16:39:41 +05:30
Aftab Ali
ff12dabebb events: add missing NETWORK filter to generateEventFilter
podman events --filter network=<name> was unconditionally returning
'NETWORK is an invalid filter' because the NETWORK case was absent
from the generateEventFilter switch statement in filters.go.

All other first-class event types (container, image, pod, volume)
had corresponding filter cases, but the Network type - despite being
fully defined in config.go along with NetworkConnect/NetworkDisconnect
statuses and the Event.Network field - had no handler.

Add the NETWORK case to filter by network name (e.Network), consistent
with Docker's --filter network= behaviour.  ID-prefix matching is
intentionally omitted: for network connect/disconnect events e.ID
holds the container ID, not the network ID, so prefix matching would
only work for create/remove events and silently miss join/leave events.

Also add unit tests (filters_test.go), integration tests
(test/e2e/events_test.go, test/system/090-events.bats), shell
completion support for --filter network= (completion.go), and
document the new filter key in the man page.

Fixes: https://github.com/podman-container-tools/podman/issues/29387
Signed-off-by: Aftab Ali <aftab123215@gmail.com>
2026-09-11 14:31:30 +05:30
Scott Callaway
79b35ad0d9
image scp: accept --compression-format=none
Until now the default could only be expressed by leaving the option off, which
reads as an omission rather than a choice and gives a script no way to say it
wants the archive transferred as podman save wrote it.

Accept none as a format meaning exactly that. It is taken on the API path too,
so both interfaces share one vocabulary, and it is treated as the absence of a
format throughout: nothing is compressed, a level attached to it is rejected the
same way a level with no format is, and the local user to user transfer has
nothing to warn about ignoring.

The remote client still leaves it off the request, so naming the default does
not make a transfer fail against a service that predates these options.

Signed-off-by: Scott Callaway <github@scottcallaway.co.uk>
2026-09-10 16:45:30 +01:00
Scott Callaway
8cec428401
image scp: add --compression-format and --compression-level
Expose the compression the transfer already knows how to do, and document what
each option means on each path.

--compression-format takes gzip or zstd, matching the vocabulary
--compression-format already uses on podman push, minus the algorithms this
cannot produce or detect. --compression-level takes the level, and is rejected
without a format to apply it to rather than being silently ignored.

The level needs one caveat spelling out in the man page. A remote source passes
it to the command line compressor, where every value is distinct. A local source
compresses through c/image, which groups zstd levels into four bands, so 10 and
above are the same there. The accepted zstd range also stops at 19 rather than
podman push's 20, because the command line compressor needs --ultra past that.

The flags are validated before the engine is reached, so podman --remote reports
a bad combination without a round trip; the transfer validates again for callers
arriving over the API.

Fixes: #23192
Signed-off-by: Scott Callaway <github@scottcallaway.co.uk>
2026-09-07 16:03:54 +01:00
Lokesh Mandvekar
10b487f229
Merge pull request #29722 from Luap99/lint
Update golangci/golangci-lint to v2.13.2
2026-09-07 09:33:26 -04:00
Danish Prakash
764021086d
Merge pull request #29606 from vishnukothakapu/perf-slices-sort
Performance: Upgrade sort.Slice to slices.SortFunc across codebase
2026-09-04 21:19:24 +05:30
Paul Holzinger
eea3fa25da
silence new platform specific staticcheck issues
These errors only happen on windows or freebsd. They happen when a
function always returns a hard error there so it assumes the condition
is always true which is not the case on another platform.

We then also need to use nolintlint so it does not trigger on linux
where the nolint is not needed otherwise.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-04 17:21:15 +02:00
Paul Holzinger
53a9bcbe13
run golangci-lint --fix
In order to fix the new formatting issues reported.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-04 16:30:10 +02:00
Paul Holzinger
6c6eac3a5c
run modernize -fix ./...
Since I use go 1.26 the go fix does not have all the rules built in,
there are newer ones in modernize so run the explicitly to fix more code
for go 1.26.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-04 11:53:04 +02:00
Paul Holzinger
eb96a9d5b8
run go fix ./...
Plus manually deleting the left over inline functions because go fix
doesn't do that even though they are private functions.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-04 11:53:04 +02:00
Ashley Cui
af579ec299 Add --platform to podman push
When pushing a manifest list, --platform=OS[/Arch[/Variant]] selects and pushes a single platform-specific manifest instead of the entire list.
Also, update compat POST /images/{name}/push to support the platform param (Compat v1.46)

Signed-off-by: Ashley Cui <acui@redhat.com>
2026-09-01 11:30:48 -04:00
Matt Heon
f542424eab
Merge pull request #29603 from gerryd/feature/create-passwd
Add support for --passwd to the create command
2026-08-27 22:03:01 -04:00
Gerry Demaret
bd8de9f7aa Add support for --passwd to the create command
Give create the same --passwd flag as run currently has.

Signed-off-by: Gerry Demaret <gerry@x-net.be>
2026-08-27 15:46:30 +02:00
Paul Holzinger
88023665ae
Merge pull request #29611 from vtushar06/fix-build-tmpdir-leak
build: do not leak context tmpdir
2026-08-25 12:44:52 +02:00
Vishnu Kothakapu
af9d0b995f Performance: Upgrade sort.Slice to slices.SortFunc across codebase
This commit modernizes the codebase by replacing older, reflection-based sort.Slice and sort.SliceIsSorted calls with the modern slices.Sort and slices.SortFunc introduced in Go 1.21.

This provides better performance and type safety by utilizing generics rather than runtime reflection.

Signed-off-by: Vishnu Kothakapu <vishnukothakapu27@gmail.com>
2026-08-24 14:45:40 +05:30
Danish Prakash
b297a50a05
Merge pull request #29601 from Lfan-ke/fix/exec-detach-keys-help
podman exec: align --detach-keys help text with run, start, and attach
2026-08-24 12:22:23 +05:30
Matt Heon
8efac905d6
Merge pull request #29530 from umar11b/artifact-ls-quiet
Some checks failed
ci / sys local root fedora-prior (push) Has been cancelled
ci / int local rootless fedora-prior (push) Has been cancelled
ci / sys local rootless fedora-prior (push) Has been cancelled
ci / int remote root fedora-prior (push) Has been cancelled
ci / sys remote root fedora-prior (push) Has been cancelled
ci / int local root fedora-rawhide (push) Has been cancelled
ci / sys local root fedora-rawhide (push) Has been cancelled
ci / int local rootless fedora-rawhide (push) Has been cancelled
ci / sys local rootless fedora-rawhide (push) Has been cancelled
ci / int remote root fedora-rawhide (push) Has been cancelled
ci / sys remote root fedora-rawhide (push) Has been cancelled
ci / apiv2 root fedora-current (push) Has been cancelled
ci / bindings root fedora-current (push) Has been cancelled
ci / compose_v2 root fedora-current (push) Has been cancelled
ci / docker_py root fedora-current (push) Has been cancelled
ci / unit root fedora-current (push) Has been cancelled
ci / apiv2 rootless fedora-current (push) Has been cancelled
ci / compose_v2 rootless fedora-current (push) Has been cancelled
ci / farm rootless fedora-current (push) Has been cancelled
ci / unit rootless fedora-current (push) Has been cancelled
ci / upgrade v5.3.1 root fedora-current (push) Has been cancelled
ci / upgrade v5.6.2 root fedora-current (push) Has been cancelled
ci / machine linux amd64 (push) Has been cancelled
ci / windows unit (push) Has been cancelled
ci / windows e2e (push) Has been cancelled
ci / windows machine hyperv (push) Has been cancelled
ci / windows machine wsl (push) Has been cancelled
ci / macos machine applehv (push) Has been cancelled
ci / macos machine libkrun (push) Has been cancelled
ci / Total Success (push) Has been cancelled
Add --quiet to podman artifact ls
2026-08-21 18:35:20 -04:00
Matt Heon
fbb90e15b0
Merge pull request #29541 from The-indigo/no-heading
Added implementation for --noheading option for podman farm list
2026-08-21 17:35:21 -04:00
Anisha Khairnar
0f9920fdb1 docs: fix the documented --detach-keys character list
Signed-off-by: Anisha Khairnar <anishakhairnar284@gmail.com>
2026-08-21 14:45:58 +05:30
Tushar Verma
fd3937cf62 build: do not leak context tmpdir
ParseBuildOpts downloads a URL or stdin context into a temp dir and
stores it in TmpDirToClose, but the caller only removes that when
ParseBuildOpts returns successfully. Every error return after the
download leaks it, including the authfile check reproduced in #22642
and a plain build of a git URL with no Containerfile, which leaves the
whole clone behind.

Use the same succeeded guard TempDirForURL itself uses, one level up so
it covers both tmpdir call sites and the logfile next to them.

Fixes: #22642
Signed-off-by: Tushar Verma <tusharmyself06@gmail.com>
2026-08-21 08:17:58 +05:30
umar11b
a46392e486 Add --quiet to podman artifact ls
Problem: podman artifact ls has no way to print just artifact
identifiers. Scripts that want to act on artifacts (e.g. remove them)
have to parse table output or use --format {{.Digest}}. Every other
listing command in podman (images, ps, artifact push/pull) already
supports -q/--quiet for this.

Impact: users can now run `podman artifact ls --quiet` to get one
digest per line, no header, suitable for piping into other podman
commands.

Change: adds a --quiet/-q bool flag to the list command. When set (and
--format is not also given), output.Digest is printed for each
artifact instead of the table.

Signed-off-by: umar11b <uzaman2018@gmail.com>
2026-08-20 16:31:13 -04:00
Adeyemi Adepoju
c7f04d0692 Added implementation for --noheading option for podman farm list
Signed-off-by: Adeyemi Adepoju <adepojuadeyemi11@gmail.com>
2026-08-20 13:02:58 -04:00
Paul Holzinger
eccf43cdbd
cmd/rootlessport: remove wsl workaround
Having a special wsl work around in the code always felt wrong to me.
This does nothing to fix the pasta or rootful port binding behavior.

To actually fix this for all we can set the new podman 6
default_host_ips containers.conf option in the WSL machine-os image by
default:

[network]
default_host_ips = ["0.0.0.0", "::"]

That should make all code paths bind two sockets which WSL needs as it
is unable to recognize a dual stack ipv6 socket for ipv4 as well.

ref https://github.com/podman-container-tools/podman/issues/29377

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-08-20 12:36:52 +02:00
Paul Holzinger
f6527ece2b
cmd/rootlessport: handle dual stack sockets right
With podman 6 we switch the main libpod port bind logic used as rootful
over to bind dual stack sockets correctly and no longer default the host
ip to 0.0.0.0.

So -p 8080:8080 should create one dual stack socket that binds all
addresses. While -p 0.0.0.0:8080:8080 -p [::]:8080:8080 should create
two sockets binding v4 and v6 respectively.

Because the go std lib always defaults to dual stack the second case
currently fails with EADDRINUSE which is wrong, so fix that to pass the
right protocol.

This is also how pasta works already so this makes everything consistent
now.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-08-20 12:36:51 +02:00
Jan Rodák
cd91b08c66
Merge pull request #29539 from ravencore06/refactor/remove-redundant-error-formatting
refactor: remove redundant err.Error() calls
2026-08-19 18:06:06 +02:00
Jan Rodák
4edc8d68e3
Merge pull request #29484 from ellieayla/artifact-list-json-output
feat: Add output format: podman artifact ls --format=json
2026-08-19 17:41:01 +02:00
Srinidhi
3bfcad5da2 refactor: remove redundant err.Error() calls
Signed-off-by: Srinidhi <srinidhisadhanala@gmail.com>
2026-08-19 20:38:00 +05:30
ellieayla
f596bb7a73 feat: Add output format: podman artifact ls --format=json
The 'podman artifact ls' command supports a --format flag accepting a go template string. Some commands (eg 'podman image ls') accept a --format=json parameter, and export pure json object to stdout.

This change adds a --format=json output mode to artifact lists too.

Includes simple documentation mention of --format=json option alongside go template description.

Signed-off-by: ellieayla <1447600+me@users.noreply.github.com>
2026-08-19 10:18:10 -04:00
Jan Rodák
dbd571e1ee
Merge pull request #29286 from GlediLami/fix-wslkerninst-filepath
podman-wslkerninst: remove unused binary
2026-08-18 11:17:14 +02:00
Matt Heon
db8802b1a3
Merge pull request #29536 from umar11b/farm-list-quiet
farm: add --quiet/-q flag to podman farm list
2026-08-17 16:23:19 -04:00
Jan Rodák
4b6873a5ef
Merge pull request #29527 from vishnukothakapu/perf-strings-equalfold
Performance: Replace strings.ToLower with strings.EqualFold
2026-08-17 21:59:25 +02:00
Paul Holzinger
5b366f4b34
Merge pull request #29511 from vishnukothakapu/perf-regexp-mustcompile
Performance: Hoist regexp.MustCompile out of functions
2026-08-17 12:53:04 +02:00
Gledis Lami
d35de2253c podman-wslkerninst: remove the unused binary
The Windows installer no longer references this binary: the WiX bundle
entry that launched it was removed in 91e4f69 ("Remove the option to
install WSL/HyperV") and the build step in df4aed7 ("Remove providers
checks from the Windows Installer"). Nothing else in the tree references
it, so the code is dead.

Removing it supersedes the earlier path.Base to filepath.Base fix: with
the binary gone there is no log prefix to repair.

Related to: #25165

Signed-off-by: Gledis Lami <lamigledi@gmail.com>
2026-08-16 11:58:31 +02:00