Table headings for `podman ps` and `podman pod ps` use a plain
`map[string]string`. A table template that calls `.Label` with an
argument fails while rendering the headings, before listing rows
are printed. For example: `podman ps --format 'table {{.Label "app"}}'`
Add a shared `PsHeader` type in `cmd/podman/common` with a `Label`
method that returns the requested label name as the column heading.
Use this type for both container and pod listings.
Add container unit tests and extend the existing container and pod
e2e tests to check label headings, label values, missing labels,
unlabeled objects, and `--noheading` output.
Fixes: #29831
Signed-off-by: Garv Changrani <154041471+Garvity@users.noreply.github.com>
When fetching build context tarballs for use in a build, pay attention
to the tlsVerify setting at the command line (in non-remote cases) or in
the build query (in remote cases), and whatever proxy settings are set
in the current environment for whichever process is connecting to a
server that may or may not be using TLS.
Signed-off-by: Nalin Dahyabhai <nalin@redhat.com>
Buildah added some variants of APIs that should improve support for
cancellation, so let's use them.
Remove the import alias for its copier package in
cmd/podman/containers/cp.go and libpod/container_copy_common.go to be
more friendly to grep.
Update the "prune leftover build containers" test to intentionally leave
some behind during its setup instead of SIGKILLing a build process.
Signed-off-by: Nalin Dahyabhai <nalin@redhat.com>
NixOS builds podman inside a sandbox and uses the `podman completion` subcommand.
While upgrading to Podman 6, we noticed that this command now started
failing in our build sandbox because of the cgroup check.
The cgroups are not relevant to completion generation.
Signed-off-by: Marie Ramlow <marie@marie.cologne>
Allow deployments and scheduled jobs to update a selected group of
containers without checking every auto-update-enabled application.
Reuse the existing container filters and expose them through the CLI,
remote bindings, and REST API.
Filter update candidates while preserving systemd unit and pod restart
behavior. Document the selection semantics and cover filtered updates,
invalid input, remote requests, and pod restarts in the existing tests.
Signed-off-by: Evan Purkhiser <git@evanpurkhiser.com>
Podman 6 dropped cgroups v1 support, and the kernel real-time
scheduler cgroup settings only exist on cgroups v1. That means the
--cpu-rt-period and --cpu-rt-runtime options can never take effect
anymore: on cgroups v2 the values only produce a warning and are
discarded.
As agreed in the linked issue, the full removal of the options is
deferred to the next major release (7.0) to avoid a breaking change
for anyone still setting them. For 6.x this commit implements the
agreed interim step:
- remove the option documentation (docs/source/markdown/options/
cpu-rt-period.md and cpu-rt-runtime.md) and drop the @@option
references from the podman-create, podman-run, podman-update and
podman-container-clone man pages
- hide both flags from --help output
- change the existing warning to state that the option is a NOP,
that the value is ignored, and that the option will be removed in
the next major release
The e2e tests are updated to match the new warning text. Actual
removal of the flags and the spec fields is left for Podman 7.0.
Part of #29750
Signed-off-by: seonghun lee <harrisleesh@gmail.com>
podman events --filter network=<name> was unconditionally returning
'NETWORK is an invalid filter' because the NETWORK case was absent
from the generateEventFilter switch statement in filters.go.
All other first-class event types (container, image, pod, volume)
had corresponding filter cases, but the Network type - despite being
fully defined in config.go along with NetworkConnect/NetworkDisconnect
statuses and the Event.Network field - had no handler.
Add the NETWORK case to filter by network name (e.Network), consistent
with Docker's --filter network= behaviour. ID-prefix matching is
intentionally omitted: for network connect/disconnect events e.ID
holds the container ID, not the network ID, so prefix matching would
only work for create/remove events and silently miss join/leave events.
Also add unit tests (filters_test.go), integration tests
(test/e2e/events_test.go, test/system/090-events.bats), shell
completion support for --filter network= (completion.go), and
document the new filter key in the man page.
Fixes: https://github.com/podman-container-tools/podman/issues/29387
Signed-off-by: Aftab Ali <aftab123215@gmail.com>
Until now the default could only be expressed by leaving the option off, which
reads as an omission rather than a choice and gives a script no way to say it
wants the archive transferred as podman save wrote it.
Accept none as a format meaning exactly that. It is taken on the API path too,
so both interfaces share one vocabulary, and it is treated as the absence of a
format throughout: nothing is compressed, a level attached to it is rejected the
same way a level with no format is, and the local user to user transfer has
nothing to warn about ignoring.
The remote client still leaves it off the request, so naming the default does
not make a transfer fail against a service that predates these options.
Signed-off-by: Scott Callaway <github@scottcallaway.co.uk>
Expose the compression the transfer already knows how to do, and document what
each option means on each path.
--compression-format takes gzip or zstd, matching the vocabulary
--compression-format already uses on podman push, minus the algorithms this
cannot produce or detect. --compression-level takes the level, and is rejected
without a format to apply it to rather than being silently ignored.
The level needs one caveat spelling out in the man page. A remote source passes
it to the command line compressor, where every value is distinct. A local source
compresses through c/image, which groups zstd levels into four bands, so 10 and
above are the same there. The accepted zstd range also stops at 19 rather than
podman push's 20, because the command line compressor needs --ultra past that.
The flags are validated before the engine is reached, so podman --remote reports
a bad combination without a round trip; the transfer validates again for callers
arriving over the API.
Fixes: #23192
Signed-off-by: Scott Callaway <github@scottcallaway.co.uk>
These errors only happen on windows or freebsd. They happen when a
function always returns a hard error there so it assumes the condition
is always true which is not the case on another platform.
We then also need to use nolintlint so it does not trigger on linux
where the nolint is not needed otherwise.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
Since I use go 1.26 the go fix does not have all the rules built in,
there are newer ones in modernize so run the explicitly to fix more code
for go 1.26.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
Plus manually deleting the left over inline functions because go fix
doesn't do that even though they are private functions.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
When pushing a manifest list, --platform=OS[/Arch[/Variant]] selects and pushes a single platform-specific manifest instead of the entire list.
Also, update compat POST /images/{name}/push to support the platform param (Compat v1.46)
Signed-off-by: Ashley Cui <acui@redhat.com>
This commit modernizes the codebase by replacing older, reflection-based sort.Slice and sort.SliceIsSorted calls with the modern slices.Sort and slices.SortFunc introduced in Go 1.21.
This provides better performance and type safety by utilizing generics rather than runtime reflection.
Signed-off-by: Vishnu Kothakapu <vishnukothakapu27@gmail.com>
ParseBuildOpts downloads a URL or stdin context into a temp dir and
stores it in TmpDirToClose, but the caller only removes that when
ParseBuildOpts returns successfully. Every error return after the
download leaks it, including the authfile check reproduced in #22642
and a plain build of a git URL with no Containerfile, which leaves the
whole clone behind.
Use the same succeeded guard TempDirForURL itself uses, one level up so
it covers both tmpdir call sites and the logfile next to them.
Fixes: #22642
Signed-off-by: Tushar Verma <tusharmyself06@gmail.com>
Problem: podman artifact ls has no way to print just artifact
identifiers. Scripts that want to act on artifacts (e.g. remove them)
have to parse table output or use --format {{.Digest}}. Every other
listing command in podman (images, ps, artifact push/pull) already
supports -q/--quiet for this.
Impact: users can now run `podman artifact ls --quiet` to get one
digest per line, no header, suitable for piping into other podman
commands.
Change: adds a --quiet/-q bool flag to the list command. When set (and
--format is not also given), output.Digest is printed for each
artifact instead of the table.
Signed-off-by: umar11b <uzaman2018@gmail.com>
Having a special wsl work around in the code always felt wrong to me.
This does nothing to fix the pasta or rootful port binding behavior.
To actually fix this for all we can set the new podman 6
default_host_ips containers.conf option in the WSL machine-os image by
default:
[network]
default_host_ips = ["0.0.0.0", "::"]
That should make all code paths bind two sockets which WSL needs as it
is unable to recognize a dual stack ipv6 socket for ipv4 as well.
ref https://github.com/podman-container-tools/podman/issues/29377
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
With podman 6 we switch the main libpod port bind logic used as rootful
over to bind dual stack sockets correctly and no longer default the host
ip to 0.0.0.0.
So -p 8080:8080 should create one dual stack socket that binds all
addresses. While -p 0.0.0.0:8080:8080 -p [::]:8080:8080 should create
two sockets binding v4 and v6 respectively.
Because the go std lib always defaults to dual stack the second case
currently fails with EADDRINUSE which is wrong, so fix that to pass the
right protocol.
This is also how pasta works already so this makes everything consistent
now.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
The 'podman artifact ls' command supports a --format flag accepting a go template string. Some commands (eg 'podman image ls') accept a --format=json parameter, and export pure json object to stdout.
This change adds a --format=json output mode to artifact lists too.
Includes simple documentation mention of --format=json option alongside go template description.
Signed-off-by: ellieayla <1447600+me@users.noreply.github.com>