Commit graph

8052 commits

Author SHA1 Message Date
Jan Rodák
8a7cbd9b15
Merge pull request #29842 from pooyanazad/fix-cp-volume-subpath-29840
libpod: honor volume subpath in cp
2026-10-02 12:46:09 +02:00
Kir Kolyshkin
9a2c84b130 test/e2e: fix podman run with noexec for ubuntu 26.04
Test case bind mounts host's /bin to /hostbin and tries to exec
/hostbin/ls, and expects a particular exit code.

It does not work on Ubuntu 26.04 because it ships with coreutils-rs
by default, in which:

	/bin/ls -> ../lib/cargo/bin/coreutils/ls

and so we get ENOENT instead of EPERM.

Fix by replacing ls with true. The funny thing is, it's also a symlink
on Ubuntu 26.04:

	/bin/true -> gnutrue

but it works since the destination is in the same directory.

(NOTE the whole test relies on the fact that the kernel checks
permissions first -- a dynamic binary from a different distro
won't be able to run anyway.)

Signed-off-by: Kir Kolyshkin <kolyshkin@gmail.com>
2026-10-01 11:29:30 -07:00
pooyanazad
bf3a78f22a libpod: honor volume subpath in cp
When copying files from created or stopped containers, podman cp resolves
named volumes on the host instead of using the container mount namespace.
The host-side resolution currently starts at the volume root and ignores the
mount's configured subpath, so cp can read a different file than the one
visible inside the container.

Apply the configured volume subpath before resolving the remaining container
path. Keep the path within the volume using secure path resolution and add
coverage for created, running, and stopped containers.

Fixes: #29840

Signed-off-by: pooyanazad <pooyan.azadparvar@gmail.com>
2026-09-30 18:19:10 +02:00
Paul Holzinger
a91da8a402
Merge pull request #29789 from nalind/update-buildah
Some checks failed
ci / sys local root fedora-prior (push) Has been cancelled
ci / int local rootless fedora-prior (push) Has been cancelled
ci / sys local rootless fedora-prior (push) Has been cancelled
ci / int remote root fedora-prior (push) Has been cancelled
ci / sys remote root fedora-prior (push) Has been cancelled
ci / int local root fedora-rawhide (push) Has been cancelled
ci / sys local root fedora-rawhide (push) Has been cancelled
ci / int local rootless fedora-rawhide (push) Has been cancelled
ci / sys local rootless fedora-rawhide (push) Has been cancelled
ci / int remote root fedora-rawhide (push) Has been cancelled
ci / sys remote root fedora-rawhide (push) Has been cancelled
ci / apiv2 root fedora-current (push) Has been cancelled
ci / bindings root fedora-current (push) Has been cancelled
ci / compose_v2 root fedora-current (push) Has been cancelled
ci / docker_py root fedora-current (push) Has been cancelled
ci / unit root fedora-current (push) Has been cancelled
ci / apiv2 rootless fedora-current (push) Has been cancelled
ci / compose_v2 rootless fedora-current (push) Has been cancelled
ci / farm rootless fedora-current (push) Has been cancelled
ci / unit rootless fedora-current (push) Has been cancelled
ci / upgrade v5.3.1 root fedora-current (push) Has been cancelled
ci / upgrade v5.6.2 root fedora-current (push) Has been cancelled
ci / machine linux amd64 (push) Has been cancelled
ci / windows unit (push) Has been cancelled
ci / windows e2e (push) Has been cancelled
ci / windows machine hyperv (push) Has been cancelled
ci / windows machine wsl (push) Has been cancelled
ci / macos machine applehv (push) Has been cancelled
ci / macos machine libkrun (push) Has been cancelled
ci / Total Success (push) Has been cancelled
Bump buildah to main
2026-09-30 17:50:07 +02:00
Jan Rodák
ac12be994e
Merge pull request #29844 from Garvity/fix/ps-label-table-headings
ps: fix label lookup in container and pod table headings
2026-09-30 09:18:32 +02:00
Matt Heon
c2f2b19ec8
Merge pull request #29852 from Luap99/multiple-pods-flake
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
test/e2e: fix flake in "multiple Pod replicas"
2026-09-29 18:01:02 -04:00
Paul Holzinger
30a0f83f39
Merge commit from fork
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
Revert "Enable 'podman run' for checkpoint images"
2026-09-29 14:49:04 +02:00
Garv Changrani
d2b8502869 ps: fix label lookup in container and pod table headings
Table headings for `podman ps` and `podman pod ps` use a plain
`map[string]string`. A table template that calls `.Label` with an
argument fails while rendering the headings, before listing rows
are printed. For example: `podman ps --format 'table {{.Label "app"}}'`

Add a shared `PsHeader` type in `cmd/podman/common` with a `Label`
method that returns the requested label name as the column heading.
Use this type for both container and pod listings.

Add container unit tests and extend the existing container and pod
e2e tests to check label headings, label values, missing labels,
unlabeled objects, and `--noheading` output.

Fixes: #29831

Signed-off-by: Garv  Changrani <154041471+Garvity@users.noreply.github.com>
2026-09-29 11:29:57 +00:00
Paul Holzinger
b2262db560
test/e2e: fix flake in "multiple Pod replicas"
GetPort() may return the same port twice, ensure we avoid the case to
not make the startup fail on a port conflict.

I saw this fail in CI once:
$ podman [options] kube play -q --multiple-pods --publish 5811:80,5811:80 /tmp/podman-e2e-759165132/subtest-4128675097/p/ptemp/kube.yaml
starting container b0aea9c7e396: rootlessport listen tcp :5811: bind: address already in use

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-29 13:12:32 +02:00
Paul Holzinger
b71273be85
test/e2e: remove duplicated test logic
The kube down test does the exact same thing already so there is really
no need to duplicate this in the interest of test runtime.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-29 13:03:28 +02:00
Nalin Dahyabhai
61195895f3 Pass context.Context values down to newer buildah APIs
Buildah added some variants of APIs that should improve support for
cancellation, so let's use them.

Remove the import alias for its copier package in
cmd/podman/containers/cp.go and libpod/container_copy_common.go to be
more friendly to grep.

Update the "prune leftover build containers" test to intentionally leave
some behind during its setup instead of SIGKILLing a build process.

Signed-off-by: Nalin Dahyabhai <nalin@redhat.com>
2026-09-29 06:05:20 -04:00
Rudraksha Singh
2ac2529bf7
compat: ignore dead and restarting status filters
Docker documents `dead` and `restarting` as valid values for the
`status` filter on `/containers/json`. Podman returns HTTP 500 when
either of them is used even though no Podman container can ever be in
those states.

Ignore these values in the compat API. If they are the only status
filters, return an empty list like Docker does. Invalid status values
still return an error.

The libpod API still rejects these values since they are Docker
specific. Update the libpod API docs to list the states Podman
actually supports.

Reference:
https://docs.docker.com/reference/api/engine/version/v1.51/#tag/Container/operation/ContainerList

Fixes: #28904
Signed-off-by: Rudraksha Singh <rudraksharss@gmail.com>
2026-09-29 00:21:19 +05:30
Matt Heon
fa6cef22c2 Rework podman run checkpoint test
Needs to properly handle the error now that we've removed the
functionality.

Signed-off-by: Matt Heon <matthew.heon@pm.me>
2026-09-28 10:28:29 -04:00
Giuseppe Scrivano
a1ce95d761
Merge pull request #29825 from Maniii97/fix/rootless-quadlet
Some checks failed
ci / sys local root fedora-prior (push) Has been cancelled
ci / int local rootless fedora-prior (push) Has been cancelled
ci / sys local rootless fedora-prior (push) Has been cancelled
ci / int remote root fedora-prior (push) Has been cancelled
ci / sys remote root fedora-prior (push) Has been cancelled
ci / int local root fedora-rawhide (push) Has been cancelled
ci / sys local root fedora-rawhide (push) Has been cancelled
ci / int local rootless fedora-rawhide (push) Has been cancelled
ci / sys local rootless fedora-rawhide (push) Has been cancelled
ci / int remote root fedora-rawhide (push) Has been cancelled
ci / sys remote root fedora-rawhide (push) Has been cancelled
ci / apiv2 root fedora-current (push) Has been cancelled
ci / bindings root fedora-current (push) Has been cancelled
ci / compose_v2 root fedora-current (push) Has been cancelled
ci / docker_py root fedora-current (push) Has been cancelled
ci / unit root fedora-current (push) Has been cancelled
ci / apiv2 rootless fedora-current (push) Has been cancelled
ci / compose_v2 rootless fedora-current (push) Has been cancelled
ci / farm rootless fedora-current (push) Has been cancelled
ci / unit rootless fedora-current (push) Has been cancelled
ci / upgrade v5.3.1 root fedora-current (push) Has been cancelled
ci / upgrade v5.6.2 root fedora-current (push) Has been cancelled
ci / machine linux amd64 (push) Has been cancelled
ci / windows unit (push) Has been cancelled
ci / windows e2e (push) Has been cancelled
ci / windows machine hyperv (push) Has been cancelled
ci / windows machine wsl (push) Has been cancelled
ci / macos machine applehv (push) Has been cancelled
ci / macos machine libkrun (push) Has been cancelled
ci / Total Success (push) Has been cancelled
quadlet: resolve symlinks to find drop-ins in target unit directory
2026-09-25 16:59:59 +02:00
Mani Shankar Jha
44e7c93c37 quadlet: search target directory of symlinked unit files for drop-ins
Fixes: #29821
Signed-off-by: Mani Shankar Jha <mani.jha@btr.group>
2026-09-24 19:17:48 +05:30
Matt Heon
5866b09c1f
Merge pull request #29726 from r-vdp/compat-inline-seccomp
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
compat API: accept inline seccomp profiles
2026-09-24 09:01:54 -04:00
r-vdp
4ce2583ad7
compat API: accept inline seccomp profiles
Docker clients send the seccomp profile JSON itself in
HostConfig.SecurityOpt (the docker CLI reads the profile file
client-side and inlines it). The compat API treated the value as a path
to a profile file, so container create failed with "file name too
long". This breaks docker-compat tooling that passes seccomp profiles
through the socket, like Nextcloud AIO and forgejo-runner.

Add a SeccompProfile field to specgen for inline profile content,
next to the existing SeccompProfilePath, as requested in review of the
earlier PR that tried to fix this (#28985). The compat create handler
extracts inline profiles (values starting with "{") from SecurityOpt
and sets the new field. Path-based values and "unconfined" keep their
current meaning, and duplicate seccomp options resolve last-one-wins,
like docker.

Fixes: #27710

Signed-off-by: r-vdp <ramses@well-founded.dev>
2026-09-24 10:31:00 +02:00
Matt Heon
0fff70d9a0
Merge pull request #29827 from Honny1/fix-pids-max
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
Map pids-limit 0 to unlimited for runc
2026-09-23 17:38:09 -04:00
Danish Prakash
7b76d74080
Merge pull request #29818 from BartSimpson001/feature/29811-init-container-inspect
inspect: expose init container information
2026-09-24 00:37:34 +05:30
Jan Rodák
5fa0cb1090
Map pids-limit 0 to unlimited for runc
Docker documents HostConfig.PidsLimit 0 as unlimited, but runc sets
pids.max=1 for OCI pids.limit 0. Normalize 0 to -1 when building the
OCI spec so native CLI, compat API, and kube play behave consistently.

Fixes: https://github.com/podman-container-tools/podman/issues/29826

Signed-off-by: Jan Rodák <hony.com@seznam.cz>
2026-09-23 20:45:45 +02:00
THARUN
14243b7675 inspect: add IsInitCtr and InitContainerType fields
Add IsInitCtr and InitContainerType fields to container inspect output to distinguish init containers from regular containers.

Fixes: #29811
Signed-off-by: THARUN <tharunpoongavanam@gmail.com>
2026-09-23 22:32:45 +05:30
Jan Rodák
253e24f65e
Merge pull request #28358 from aaron-ang/issue-17726-distribution-api
api: implement compat distribution inspect endpoint
2026-09-23 10:49:31 +02:00
Aaron Ang
3611b67505 api: implement compat distribution inspect endpoint
Fixes: #17726
Signed-off-by: Aaron Ang <aaron.angyd@gmail.com>
2026-09-22 21:14:45 -04:00
Matt Heon
8e3c572a85
Merge pull request #28579 from priyanshsao/inspect-tty-size
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
fix: return tty size in container_inspect.go
2026-09-22 11:30:58 -04:00
Matt Heon
41953b5742
Merge pull request #27631 from Mujib-Ahasan/extend-timeout-usec
fix: Container with Notify=healthy respect `HealthStartPeriod` larger than `TimeoutStartSec`.
2026-09-22 11:17:29 -04:00
Priyansh Sao
04250c6672 fix: implement console size for container inspect in linux
fix: return tty size in container_inspect_linux.go

This PR updates the console size field for containers with terminal enabled.

For cases where there is an issue with getting the size, suitable debug information is given, no update happens and default [0,0] is returned.

This implementation is only for Linux systems.

For FreeBSD, the console size is not implemented yet so, adds a todo for that.

Fixes: #28368

Signed-off-by: Priyansh Sao <saopriyansh06@gmail.com>

fix: add system test for podman inspect

Adds system test to verify console size is correctly updated, includes two cases:

When a tty is attached to the container - non-zero console size.

When a tty is not attached to the container - zero console size.

Fixes: #28368

Signed-off-by: Priyansh Sao <saopriyansh06@gmail.com>
2026-09-22 19:26:23 +05:30
Mujib Ahasan
92539ae033 fix: Container with Notify=healthy respect HealthStartPeriod larger than TimeoutStartSec
Fixes: #27290

Signed-off-by: Mujib Ahasan <ahasanmujib8@gmail.com>
2026-09-22 14:11:21 +05:30
Marek Simek
9a32b4a31c
compat: Omit empty Created field from GET /images/{id}/json
Docker API v1.44 omits the Created field (previously,
it was the zero value of 0001-01-01T00:00:00Z) if
the Created field is missing from the image config.

Omit it when zero from the compat API GET /images/{id}/json
(using `info.Created` instead of the previous `l.Created()`
that is set to `Now()` in storage/images.go when empty).

Add a test creating an image with the Created field missing.

Fixes: https://redhat.atlassian.net/browse/RUN-3317
Signed-off-by: Marek Simek <msimek@redhat.com>
2026-09-22 10:03:51 +02:00
Matt Heon
109bd7acd2
Merge pull request #29791 from evanpurkhiser/codex/auto-update-filter
auto-update: Add container filters
2026-09-21 15:01:10 -04:00
Danish Prakash
196e082727
Merge pull request #28686 from mheon/exec_no_streams_auto_detach
Allow running exec with no attach streams requested
2026-09-22 00:02:59 +05:30
Matthew Heon
7487854f10 Allow running exec with no attach streams requested
This is a small Docker compat fix with the API exec endpoints.
With Docker, sending a bare Exec Create (command only, nothing
else set) and then an Exec Start without Detach set performs
a detached exec. With Podman, we threw an error that at least one
stream must be attached to. Fix is trivial; look up the session
before start, check the config for attach streams, and force
detach on if none are set.

Signed-off-by: Matthew Heon <matthew.heon@pm.me>
2026-09-21 10:34:55 -04:00
Oleksandr Krutko
ff2eb1b0ca The feature which allows multiple Pods creation
Fixes: #26769

Signed-off-by: Oleksandr Krutko <alexander.krutko@gmail.com>
2026-09-20 15:41:06 +03:00
Matt Heon
0d12a23e7b
Merge pull request #29795 from arcusbuilds/compat-update-keep-restart-policy
Some checks failed
ci / sys local root fedora-prior (push) Has been cancelled
ci / int local rootless fedora-prior (push) Has been cancelled
ci / sys local rootless fedora-prior (push) Has been cancelled
ci / int remote root fedora-prior (push) Has been cancelled
ci / sys remote root fedora-prior (push) Has been cancelled
ci / int local root fedora-rawhide (push) Has been cancelled
ci / sys local root fedora-rawhide (push) Has been cancelled
ci / int local rootless fedora-rawhide (push) Has been cancelled
ci / sys local rootless fedora-rawhide (push) Has been cancelled
ci / int remote root fedora-rawhide (push) Has been cancelled
ci / sys remote root fedora-rawhide (push) Has been cancelled
ci / apiv2 root fedora-current (push) Has been cancelled
ci / bindings root fedora-current (push) Has been cancelled
ci / compose_v2 root fedora-current (push) Has been cancelled
ci / docker_py root fedora-current (push) Has been cancelled
ci / unit root fedora-current (push) Has been cancelled
ci / apiv2 rootless fedora-current (push) Has been cancelled
ci / compose_v2 rootless fedora-current (push) Has been cancelled
ci / farm rootless fedora-current (push) Has been cancelled
ci / unit rootless fedora-current (push) Has been cancelled
ci / upgrade v5.3.1 root fedora-current (push) Has been cancelled
ci / upgrade v5.6.2 root fedora-current (push) Has been cancelled
ci / machine linux amd64 (push) Has been cancelled
ci / windows unit (push) Has been cancelled
ci / windows e2e (push) Has been cancelled
ci / windows machine hyperv (push) Has been cancelled
ci / windows machine wsl (push) Has been cancelled
ci / macos machine applehv (push) Has been cancelled
ci / macos machine libkrun (push) Has been cancelled
ci / Total Success (push) Has been cancelled
compat: Restart policy no longer resets on compat update
2026-09-19 15:27:58 -04:00
Ashley Cui
dde83193d1
Merge pull request #28633 from aayushbaluni/fix/28378-iprange-compat-api
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
fix: include IPRange in Docker-compat network IPAM config
2026-09-18 16:36:36 -04:00
Evan Purkhiser
4458f041e1
use FilterArgumentsIntoFilters
Signed-off-by: Evan Purkhiser <git@evanpurkhiser.com>
2026-09-18 11:56:25 -04:00
Srijan Keshri
a50f49cab0 compat: Restart policy no longer resets on compat update
Fixed the compat container update path so it preserves the existing restart policy unless the request explicitly includes a new one, and added a regression test for it.

Fixes: #29790
Signed-off-by: Srijan Keshri <212402043+arcusbuilds@users.noreply.github.com>
2026-09-18 04:06:24 +00:00
Evan Purkhiser
9309b9183c
auto-update: Add container filters
Allow deployments and scheduled jobs to update a selected group of
containers without checking every auto-update-enabled application.
Reuse the existing container filters and expose them through the CLI,
remote bindings, and REST API.

Filter update candidates while preserving systemd unit and pod restart
behavior. Document the selection semantics and cover filtered updates,
invalid input, remote requests, and pod restarts in the existing tests.

Signed-off-by: Evan Purkhiser <git@evanpurkhiser.com>
2026-09-17 11:16:58 -04:00
Jan Rodák
6ba4ab29fc
Merge pull request #29587 from haneul-24/fix/kube-play-nested-image-path
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
Fix/kube play nested image path
2026-09-17 17:16:38 +02:00
Jan Rodák
fda861989d
Merge pull request #29395 from scallaway/image-scp-compression
image scp: add --compression-format and --compression-level
2026-09-17 17:09:06 +02:00
Paul Holzinger
91238111ba
Merge pull request #27857 from arsenalzp/podman60_27724
Fix startup health check command behavior
2026-09-17 16:32:42 +02:00
Jan Rodák
9de95641de
Merge pull request #27025 from StefanNienhuis/feat/api-autoupdate
feat: Implement autoupdate endpoint in libpod REST API
2026-09-17 14:32:57 +02:00
Jan Rodák
f60810039b
Merge pull request #29784 from harrisleesh/drop-cpu-rt-docs
Hide --cpu-rt-period/--cpu-rt-runtime and mark them as NOP
2026-09-17 13:40:40 +02:00
Stefan Nienhuis
9c923c019e
feat: Implement auto update support for podman-remote
Signed-off-by: Stefan Nienhuis <stefan@nienhuisdevelopment.com>
2026-09-17 11:08:24 +02:00
seonghun lee
655b8cee14 Hide --cpu-rt-period/--cpu-rt-runtime and mark them as NOP
Podman 6 dropped cgroups v1 support, and the kernel real-time
scheduler cgroup settings only exist on cgroups v1. That means the
--cpu-rt-period and --cpu-rt-runtime options can never take effect
anymore: on cgroups v2 the values only produce a warning and are
discarded.

As agreed in the linked issue, the full removal of the options is
deferred to the next major release (7.0) to avoid a breaking change
for anyone still setting them. For 6.x this commit implements the
agreed interim step:

- remove the option documentation (docs/source/markdown/options/
  cpu-rt-period.md and cpu-rt-runtime.md) and drop the @@option
  references from the podman-create, podman-run, podman-update and
  podman-container-clone man pages
- hide both flags from --help output
- change the existing warning to state that the option is a NOP,
  that the value is ignored, and that the option will be removed in
  the next major release

The e2e tests are updated to match the new warning text. Actual
removal of the flags and the spec fields is left for Podman 7.0.

Part of #29750

Signed-off-by: seonghun lee <harrisleesh@gmail.com>
2026-09-17 01:15:52 +09:00
aayushbaluni
9f6b99950b fix: include IPRange in Docker-compat network IPAM config
The Docker-compatible network API omitted the IPRange field from the IPAM
config even though Libpod stores this data, so tools reading the Docker
API could not see the configured IP range.

Map Libpod's LeaseRange to Docker-compatible IPAMConfig.IPRange when it
aligns with a full CIDR span derived from FirstIPInSubnet/LastIPInSubnet,
and add an integration test that creates a network via the compat API with
an explicit IPRange and asserts it is returned on inspect.

The span is matched with bit arithmetic rather than by trying every prefix
length: the network address is start-1, and XORing that with end yields the
host mask, which identifies the prefix in a single pass. net/netip carries
the address handling throughout - Unmap collapses 4-in-6, Prev gives the
network address, and Masked confirms the network is aligned to the prefix.

Fixes: #28378

Signed-off-by: aayushbaluni <73417844+aayushbaluni@users.noreply.github.com>
2026-09-16 10:01:35 +05:30
Oleksandr Krutko
91c3d1d8ec Fix health-startup-cmd behaviour when the value is not set
Fixes: #27724

Signed-off-by: Oleksandr Krutko <alexander.krutko@gmail.com>
2026-09-15 22:09:57 +03:00
Paul Holzinger
c1c5dc5aeb
test/system: correctly trim -remote from podman
$PODMAN in the bats tests is either podman or podman-remote for remote
tests. Because it is a absolute path the path itself can contain -remote
already. If we trim the path we should only do so on the last match.

Fixes: #26411

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-15 12:39:46 +02:00
Jan Rodák
525dfd8700
Merge pull request #29758 from haneul-24/fix/api-endpoint-content-type
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
fix: set correct content-type for generate kube
2026-09-15 11:09:46 +02:00
Sejal
469bd43654 fix: support nested image paths in kube play build
Fixes: #28418

Signed-off-by: Sejal <sej1306kook@gmail.com>
2026-09-14 20:46:29 +00:00
Matt Heon
6e10d5ac76
Merge pull request #29375 from Mahajan-Sachin/quadlet-volume-remainafterexit
quadlet: do not set RemainAfterExit=yes for volume units by default
2026-09-14 08:52:48 -04:00