Journald already records native timestamps for each entry, making the embedded timestamp in the Podman event string redundant and noisy.
Omit the timestamp prefix from the human-readable string dispatched to journald while preserving the timestamp for 'podman events' CLI output.
Fixes: #29835
Signed-off-by: Gabriel <g4briel.lima7@gmail.com>
Keep the selected subpath mounted while stat and copy use it so a shared volume cannot redirect the copy root with a symlink. Release the mount after each operation and cover source replacement in a regression test.
Signed-off-by: pooyanazad <pooyan.azadparvar@gmail.com>
When copying files from created or stopped containers, podman cp resolves
named volumes on the host instead of using the container mount namespace.
The host-side resolution currently starts at the volume root and ignores the
mount's configured subpath, so cp can read a different file than the one
visible inside the container.
Apply the configured volume subpath before resolving the remaining container
path. Keep the path within the volume using secure path resolution and add
coverage for created, running, and stopped containers.
Fixes: #29840
Signed-off-by: pooyanazad <pooyan.azadparvar@gmail.com>
Buildah added some variants of APIs that should improve support for
cancellation, so let's use them.
Remove the import alias for its copier package in
cmd/podman/containers/cp.go and libpod/container_copy_common.go to be
more friendly to grep.
Update the "prune leftover build containers" test to intentionally leave
some behind during its setup instead of SIGKILLing a build process.
Signed-off-by: Nalin Dahyabhai <nalin@redhat.com>
fix: return tty size in container_inspect_linux.go
This PR updates the console size field for containers with terminal enabled.
For cases where there is an issue with getting the size, suitable debug information is given, no update happens and default [0,0] is returned.
This implementation is only for Linux systems.
For FreeBSD, the console size is not implemented yet so, adds a todo for that.
Fixes: #28368
Signed-off-by: Priyansh Sao <saopriyansh06@gmail.com>
fix: add system test for podman inspect
Adds system test to verify console size is correctly updated, includes two cases:
When a tty is attached to the container - non-zero console size.
When a tty is not attached to the container - zero console size.
Fixes: #28368
Signed-off-by: Priyansh Sao <saopriyansh06@gmail.com>
podman events --filter network=<name> was unconditionally returning
'NETWORK is an invalid filter' because the NETWORK case was absent
from the generateEventFilter switch statement in filters.go.
All other first-class event types (container, image, pod, volume)
had corresponding filter cases, but the Network type - despite being
fully defined in config.go along with NetworkConnect/NetworkDisconnect
statuses and the Event.Network field - had no handler.
Add the NETWORK case to filter by network name (e.Network), consistent
with Docker's --filter network= behaviour. ID-prefix matching is
intentionally omitted: for network connect/disconnect events e.ID
holds the container ID, not the network ID, so prefix matching would
only work for create/remove events and silently miss join/leave events.
Also add unit tests (filters_test.go), integration tests
(test/e2e/events_test.go, test/system/090-events.bats), shell
completion support for --filter network= (completion.go), and
document the new filter key in the man page.
Fixes: https://github.com/podman-container-tools/podman/issues/29387
Signed-off-by: Aftab Ali <aftab123215@gmail.com>
These errors only happen on windows or freebsd. They happen when a
function always returns a hard error there so it assumes the condition
is always true which is not the case on another platform.
We then also need to use nolintlint so it does not trigger on linux
where the nolint is not needed otherwise.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
Looks like it picked up new deprecated matches so we need some more
nolint to silence them where we still need them for backwards compat in
the API.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
Existing KillContainer handling uses HTTP status code 409 when the request cannot be performed because of the current container state. HTTP status code 404 is also used when the target container does not exist.
In contrast, errors from the stats handler are not reflected in the HTTP status code. The HTTP status code is always 200, and the errors are recorded only as generic errors in the server log.
To maintain compatibility with both streaming enabled and disabled, this change treats obtaining at least one complete unit of response content as the response contract. It then keeps the response content consistent with the HTTP status code.
Signed-off-by: Hiroaki KAWAI <hiroaki.kawai@gmail.com>
Since I use go 1.26 the go fix does not have all the rules built in,
there are newer ones in modernize so run the explicitly to fix more code
for go 1.26.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
Docker API v1.44 now includes status properties
in Runtimes for the GET /info endpoint.
Read output of {oci_runtime_cmd} features command
lazily and expose the JSON
output as-is (with removed new lines and
whitespace) as the status field in GET
/info for v1.44+.
Add status to libpod GET /info in ociRuntime.features
and `podman info` (shared).
Add API tests for both endpoints.
Fixes: https://redhat.atlassian.net/browse/RUN-3319
Signed-off-by: Marek Simek <msimek@redhat.com>
Allow the `idmap` volume option to be combined with the overlay `O`
option, e.g. `-v /src:/mnt:O,idmap` or `-v myvol:/mnt:O,idmap`.
Previously any option other than `U`, `upperdir` and `workdir` combined
with `O` was rejected.
The parser in GenVolumeMounts now accepts `idmap` alongside `O` and
rejects the first disallowed option instead of counting flags. The
mappings from the container's user namespace are threaded onto the
generated overlay mount so the runtime idmaps it. This is done for both
the anonymous/host-path overlay volumes and the named-volume overlay
path, which are handled by separate code.
When a volume is idmapped the runtime shifts the mount so that on-disk
IDs map identically into the container, so the overlay backing dirs
(contentDir, upperdir, workdir) must be owned by real root (0) rather
than the host IDs the container root maps to; otherwise they surface as
the overflow ID inside the container and are inaccessible.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
When the user owning the storage is not mapped into the container user
namespace (e.g. root with --userns=auto), the runtime cannot mount an
overlay volume from inside the user namespace.
Mount the overlay in podman instead and pass the runtime a bind mount.
Closes: https://github.com/podman-container-tools/podman/issues/28758
Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
The subpath mount option is parsed with strings.Split(o, "=")[1], so it keeps only
the text between the first and second '='. A subpath that contains '=' gets cut
short and the container mounts a different directory than the one that was asked for.
--mount type=volume,src=v,dst=/mnt,subpath=/opt/a=b/c mounts /opt/a
Signed-off-by: Atishyy27 <sethatishayjain@gmail.com>
This commit modernizes the codebase by replacing older, reflection-based sort.Slice and sort.SliceIsSorted calls with the modern slices.Sort and slices.SortFunc introduced in Go 1.21.
This provides better performance and type safety by utilizing generics rather than runtime reflection.
Signed-off-by: Vishnu Kothakapu <vishnukothakapu27@gmail.com>
Imported volumes now get ownership and permissions matching the
container's mount tareget.
Previously, permission adjustment was skipped for imported volumes as
they were already non-empty when mounted.
Fixes: #25442
Signed-off-by: Jiwoo Ahn <ikwydls1314@gmail.com>
Replaces regexp.MustCompile with regexp.Delayed from go.podman.io/storage/pkg/regexp
for global regular expressions. This avoids compiling regular expressions
during the global init scope, improving startup performance for all commands.
Tests are kept using regexp.MustCompile where applicable.
Fixes: #29510
Signed-off-by: Vishnu Kothakapu <vishnukothakapu27@gmail.com>