Commit graph

7699 commits

Author SHA1 Message Date
Matt Heon
029d759171
Merge pull request #29637 from ROKUMATE/remove-dead-ps-pod-sort
podman ps: allow sorting by pod (finishes #13033's --sort half)
2026-10-02 15:24:11 -04:00
Paul Holzinger
54afd0e512
Merge pull request #29853 from schmitt-christopher/fix/certificate-import-path-quoting
Fix: Quote paths on import of native CA Certificates to support special chars in hosts home path
2026-10-01 13:51:07 +02:00
Paul Holzinger
a91da8a402
Merge pull request #29789 from nalind/update-buildah
Some checks failed
ci / sys local root fedora-prior (push) Has been cancelled
ci / int local rootless fedora-prior (push) Has been cancelled
ci / sys local rootless fedora-prior (push) Has been cancelled
ci / int remote root fedora-prior (push) Has been cancelled
ci / sys remote root fedora-prior (push) Has been cancelled
ci / int local root fedora-rawhide (push) Has been cancelled
ci / sys local root fedora-rawhide (push) Has been cancelled
ci / int local rootless fedora-rawhide (push) Has been cancelled
ci / sys local rootless fedora-rawhide (push) Has been cancelled
ci / int remote root fedora-rawhide (push) Has been cancelled
ci / sys remote root fedora-rawhide (push) Has been cancelled
ci / apiv2 root fedora-current (push) Has been cancelled
ci / bindings root fedora-current (push) Has been cancelled
ci / compose_v2 root fedora-current (push) Has been cancelled
ci / docker_py root fedora-current (push) Has been cancelled
ci / unit root fedora-current (push) Has been cancelled
ci / apiv2 rootless fedora-current (push) Has been cancelled
ci / compose_v2 rootless fedora-current (push) Has been cancelled
ci / farm rootless fedora-current (push) Has been cancelled
ci / unit rootless fedora-current (push) Has been cancelled
ci / upgrade v5.3.1 root fedora-current (push) Has been cancelled
ci / upgrade v5.6.2 root fedora-current (push) Has been cancelled
ci / machine linux amd64 (push) Has been cancelled
ci / windows unit (push) Has been cancelled
ci / windows e2e (push) Has been cancelled
ci / windows machine hyperv (push) Has been cancelled
ci / windows machine wsl (push) Has been cancelled
ci / macos machine applehv (push) Has been cancelled
ci / macos machine libkrun (push) Has been cancelled
ci / Total Success (push) Has been cancelled
Bump buildah to main
2026-09-30 17:50:07 +02:00
Jan Rodák
7eaeecd7f8
Merge pull request #29851 from amccabe/fix-pidhandle-esrch
Handle ESRCH from openByHandleAt in addition to ESTALE in NewPIDHandleFromString
2026-09-30 17:35:17 +02:00
ROKUMATE
975833a33b podman ps: allow sorting by pod
Fixes: #13033
Signed-off-by: ROKUMATE <rohitkumawat0110@gmail.com>
2026-09-30 18:37:36 +05:30
Christopher Schmitt
55c233fc94 Quote the shell command arguments for copying certificate files into podman anchor path
Signed-off-by: Christopher Schmitt <schmitt.christopher1@web.de>
2026-09-30 14:54:13 +02:00
Andrew McCabe
a10ba5e474
pkg/pidhandle: handle ESRCH from openByHandleAt
The kernel can return ESRCH in addition to ESTALE from open_by_handle_at
when the process no longer exists.

Signed-off-by: Andrew McCabe <amccabe@users.noreply.github.com>
2026-09-29 13:21:09 -04:00
Paul Holzinger
30a0f83f39
Merge commit from fork
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
Revert "Enable 'podman run' for checkpoint images"
2026-09-29 14:49:04 +02:00
Nalin Dahyabhai
eda29a56bf image build contexts: pay attention to tlsVerify flags
When fetching build context tarballs for use in a build, pay attention
to the tlsVerify setting at the command line (in non-remote cases) or in
the build query (in remote cases), and whatever proxy settings are set
in the current environment for whichever process is connecting to a
server that may or may not be using TLS.

Signed-off-by: Nalin Dahyabhai <nalin@redhat.com>
2026-09-29 06:05:20 -04:00
Nalin Dahyabhai
61195895f3 Pass context.Context values down to newer buildah APIs
Buildah added some variants of APIs that should improve support for
cancellation, so let's use them.

Remove the import alias for its copier package in
cmd/podman/containers/cp.go and libpod/container_copy_common.go to be
more friendly to grep.

Update the "prune leftover build containers" test to intentionally leave
some behind during its setup instead of SIGKILLing a build process.

Signed-off-by: Nalin Dahyabhai <nalin@redhat.com>
2026-09-29 06:05:20 -04:00
Danish Prakash
602de6d1d0
Merge pull request #29366 from WasThatRudy/fix-compat-status-filter
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
compat: ignore dead and restarting status filters
2026-09-29 11:48:05 +05:30
Rudraksha Singh
2ac2529bf7
compat: ignore dead and restarting status filters
Docker documents `dead` and `restarting` as valid values for the
`status` filter on `/containers/json`. Podman returns HTTP 500 when
either of them is used even though no Podman container can ever be in
those states.

Ignore these values in the compat API. If they are the only status
filters, return an empty list like Docker does. Invalid status values
still return an error.

The libpod API still rejects these values since they are Docker
specific. Update the libpod API docs to list the states Podman
actually supports.

Reference:
https://docs.docker.com/reference/api/engine/version/v1.51/#tag/Container/operation/ContainerList

Fixes: #28904
Signed-off-by: Rudraksha Singh <rudraksharss@gmail.com>
2026-09-29 00:21:19 +05:30
renovate[bot]
8f78e9ab7f
Update dependency golangci/golangci-lint to v2.14.0
And tweak import formatting for one file which is now flagged.

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-28 15:36:29 +02:00
Matt Heon
c74b1d37b3 Error when a checkpoint image is run
Support for these was removed in 3721ff82ff as the feature is
inherently insecure. Checkpoints imply an extremely privileged
operation that is incompatible with the constraints of a
`podman run` command. However, we should still tell folks that
it no longer works with a clear error message. This is done
during Specgen processing, server side, which should be safer
than the previous client-side processing for these.

Signed-off-by: Matt Heon <matthew.heon@pm.me>
2026-09-28 09:26:35 -04:00
Matt Heon
3721ff82ff Revert "Enable 'podman run' for checkpoint images"
This reverts commit f4401567cd.

This commit has been identified as a serious security issue.
Running checkpoints via `podman run` introduces potentially
confusing behavior where all security for a container, even
options specified by the user at the command line, can be turned
off by the checkpoint. Checkpoints have special security
considerations and must be explicitly requested by the user to
ensure they are used safely. We recommend ensuring the lifecycle
of a checkpoint is fully monitored and integrity is ensured at
each stage to guarantee safety.

Signed-off-by: Matt Heon <matthew.heon@pm.me>
2026-09-28 07:48:00 -04:00
Paul Holzinger
95fc00bca3
Merge pull request #29657 from sundeep8967/fix/pause-process-environ
rootless: clear environment before spawning pause process
2026-09-28 12:54:47 +02:00
Matt Heon
5866b09c1f
Merge pull request #29726 from r-vdp/compat-inline-seccomp
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
compat API: accept inline seccomp profiles
2026-09-24 09:01:54 -04:00
r-vdp
4ce2583ad7
compat API: accept inline seccomp profiles
Docker clients send the seccomp profile JSON itself in
HostConfig.SecurityOpt (the docker CLI reads the profile file
client-side and inlines it). The compat API treated the value as a path
to a profile file, so container create failed with "file name too
long". This breaks docker-compat tooling that passes seccomp profiles
through the socket, like Nextcloud AIO and forgejo-runner.

Add a SeccompProfile field to specgen for inline profile content,
next to the existing SeccompProfilePath, as requested in review of the
earlier PR that tried to fix this (#28985). The compat create handler
extracts inline profiles (values starting with "{") from SecurityOpt
and sets the new field. Path-based values and "unconfined" keep their
current meaning, and duplicate seccomp options resolve last-one-wins,
like docker.

Fixes: #27710

Signed-off-by: r-vdp <ramses@well-founded.dev>
2026-09-24 10:31:00 +02:00
Matt Heon
0fff70d9a0
Merge pull request #29827 from Honny1/fix-pids-max
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
Map pids-limit 0 to unlimited for runc
2026-09-23 17:38:09 -04:00
Jan Rodák
5fa0cb1090
Map pids-limit 0 to unlimited for runc
Docker documents HostConfig.PidsLimit 0 as unlimited, but runc sets
pids.max=1 for OCI pids.limit 0. Normalize 0 to -1 when building the
OCI spec so native CLI, compat API, and kube play behave consistently.

Fixes: https://github.com/podman-container-tools/podman/issues/29826

Signed-off-by: Jan Rodák <hony.com@seznam.cz>
2026-09-23 20:45:45 +02:00
Jan Rodák
253e24f65e
Merge pull request #28358 from aaron-ang/issue-17726-distribution-api
api: implement compat distribution inspect endpoint
2026-09-23 10:49:31 +02:00
Aaron Ang
3611b67505 api: implement compat distribution inspect endpoint
Fixes: #17726
Signed-off-by: Aaron Ang <aaron.angyd@gmail.com>
2026-09-22 21:14:45 -04:00
Marek Simek
9a32b4a31c
compat: Omit empty Created field from GET /images/{id}/json
Docker API v1.44 omits the Created field (previously,
it was the zero value of 0001-01-01T00:00:00Z) if
the Created field is missing from the image config.

Omit it when zero from the compat API GET /images/{id}/json
(using `info.Created` instead of the previous `l.Created()`
that is set to `Now()` in storage/images.go when empty).

Add a test creating an image with the Created field missing.

Fixes: https://redhat.atlassian.net/browse/RUN-3317
Signed-off-by: Marek Simek <msimek@redhat.com>
2026-09-22 10:03:51 +02:00
Matt Heon
4c066a730a
Merge pull request #29343 from sudo-muneeb/fix-apple-leak-clean
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
prevent goroutine leak in StartGenericAppleVM
2026-09-21 15:32:04 -04:00
Matt Heon
155dab9f41
Merge pull request #29802 from Daksha1611/fix-bindings-unit-tests
Run the pkg/bindings unit tests in CI
2026-09-21 15:29:15 -04:00
Matt Heon
109bd7acd2
Merge pull request #29791 from evanpurkhiser/codex/auto-update-filter
auto-update: Add container filters
2026-09-21 15:01:10 -04:00
Danish Prakash
196e082727
Merge pull request #28686 from mheon/exec_no_streams_auto_detach
Allow running exec with no attach streams requested
2026-09-22 00:02:59 +05:30
Giuseppe Scrivano
871e58d8cb
Merge pull request #29798 from ijajmulani/sysctl-delegate-to-common-validation
pkg/util: delegate sysctl validation to c/common
2026-09-21 19:17:53 +02:00
Matthew Heon
7487854f10 Allow running exec with no attach streams requested
This is a small Docker compat fix with the API exec endpoints.
With Docker, sending a bare Exec Create (command only, nothing
else set) and then an Exec Start without Detach set performs
a detached exec. With Podman, we threw an error that at least one
stream must be attached to. Fix is trivial; look up the session
before start, check the config for attach streams, and force
detach on if none are set.

Signed-off-by: Matthew Heon <matthew.heon@pm.me>
2026-09-21 10:34:55 -04:00
Oleksandr Krutko
ff2eb1b0ca The feature which allows multiple Pods creation
Fixes: #26769

Signed-off-by: Oleksandr Krutko <alexander.krutko@gmail.com>
2026-09-20 15:41:06 +03:00
Sheikh Muneeb Ahmed
70b08badba prevent goroutine leak in StartGenericAppleVM
Added a done channel and select block to cleanly terminate the signal-forwarding goroutine when the VM starts or fails, preventing a goroutine leak on every 'podman machine start'.

Fixes: #29342
Signed-off-by: Sheikh Muneeb Ahmed <msheikh.bsai24seecs@seecs.edu.pk>
2026-09-20 15:15:25 +05:00
Matt Heon
0d12a23e7b
Merge pull request #29795 from arcusbuilds/compat-update-keep-restart-policy
Some checks failed
ci / sys local root fedora-prior (push) Has been cancelled
ci / int local rootless fedora-prior (push) Has been cancelled
ci / sys local rootless fedora-prior (push) Has been cancelled
ci / int remote root fedora-prior (push) Has been cancelled
ci / sys remote root fedora-prior (push) Has been cancelled
ci / int local root fedora-rawhide (push) Has been cancelled
ci / sys local root fedora-rawhide (push) Has been cancelled
ci / int local rootless fedora-rawhide (push) Has been cancelled
ci / sys local rootless fedora-rawhide (push) Has been cancelled
ci / int remote root fedora-rawhide (push) Has been cancelled
ci / sys remote root fedora-rawhide (push) Has been cancelled
ci / apiv2 root fedora-current (push) Has been cancelled
ci / bindings root fedora-current (push) Has been cancelled
ci / compose_v2 root fedora-current (push) Has been cancelled
ci / docker_py root fedora-current (push) Has been cancelled
ci / unit root fedora-current (push) Has been cancelled
ci / apiv2 rootless fedora-current (push) Has been cancelled
ci / compose_v2 rootless fedora-current (push) Has been cancelled
ci / farm rootless fedora-current (push) Has been cancelled
ci / unit rootless fedora-current (push) Has been cancelled
ci / upgrade v5.3.1 root fedora-current (push) Has been cancelled
ci / upgrade v5.6.2 root fedora-current (push) Has been cancelled
ci / machine linux amd64 (push) Has been cancelled
ci / windows unit (push) Has been cancelled
ci / windows e2e (push) Has been cancelled
ci / windows machine hyperv (push) Has been cancelled
ci / windows machine wsl (push) Has been cancelled
ci / macos machine applehv (push) Has been cancelled
ci / macos machine libkrun (push) Has been cancelled
ci / Total Success (push) Has been cancelled
compat: Restart policy no longer resets on compat update
2026-09-19 15:27:58 -04:00
Ashley Cui
dde83193d1
Merge pull request #28633 from aayushbaluni/fix/28378-iprange-compat-api
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
fix: include IPRange in Docker-compat network IPAM config
2026-09-18 16:36:36 -04:00
Daksha1611
20a077b16c pkg/bindings/images: fix TestConvertAdditionalBuildContexts on non-Windows hosts
TestConvertAdditionalBuildContexts asserted that the additional build
context "C:\test" is rewritten to "/mnt/c/test". That rewrite is done by
specgen.ConvertWinMountPath, which is a no-op unless shouldResolveWinPaths()
is true: always on Windows, but on Linux only when the client runs inside a
WSL or Hyper-V guest. On an ordinary Linux host the value is passed through
unchanged and the test fails.

Keep the platform independent expectations (URLs, images and unix paths are
never rewritten) in the shared test and move the drive letter case to a
Windows only file, following the existing split in pkg/specgen.

Signed-off-by: Daksha1611 <mehtadaksha1611@gmail.com>
2026-09-18 21:17:26 +05:30
Ijaj Mulani
66b7c34328 pkg/util: delegate sysctl validation to c/common
Remove duplicated ValidateSysctls logic and call
go.podman.io/common/pkg/sysctl.Validate instead. This change
picks up the latest validation from c/common.

Signed-off-by: Ijaj Mulani <ijajmulani786@gmail.com>
2026-09-18 07:31:07 -05:00
Jan Rodák
77d1fdf87a
Merge pull request #29303 from virzak/fix/compat-info-rootless-cgroup-driver
compat: report cgroup driver "none" when rootless with cgroupfs
2026-09-18 11:42:45 +02:00
Srijan Keshri
a50f49cab0 compat: Restart policy no longer resets on compat update
Fixed the compat container update path so it preserves the existing restart policy unless the request explicitly includes a new one, and added a regression test for it.

Fixes: #29790
Signed-off-by: Srijan Keshri <212402043+arcusbuilds@users.noreply.github.com>
2026-09-18 04:06:24 +00:00
Evan Purkhiser
9309b9183c
auto-update: Add container filters
Allow deployments and scheduled jobs to update a selected group of
containers without checking every auto-update-enabled application.
Reuse the existing container filters and expose them through the CLI,
remote bindings, and REST API.

Filter update candidates while preserving systemd unit and pod restart
behavior. Document the selection semantics and cover filtered updates,
invalid input, remote requests, and pod restarts in the existing tests.

Signed-off-by: Evan Purkhiser <git@evanpurkhiser.com>
2026-09-17 11:16:58 -04:00
Jan Rodák
6ba4ab29fc
Merge pull request #29587 from haneul-24/fix/kube-play-nested-image-path
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
Fix/kube play nested image path
2026-09-17 17:16:38 +02:00
Jan Rodák
fda861989d
Merge pull request #29395 from scallaway/image-scp-compression
image scp: add --compression-format and --compression-level
2026-09-17 17:09:06 +02:00
Paul Holzinger
91238111ba
Merge pull request #27857 from arsenalzp/podman60_27724
Fix startup health check command behavior
2026-09-17 16:32:42 +02:00
Jan Rodák
3568cf1c5b
Merge pull request #29765 from Xiaowen-Yang/fix-29474-orphan-proxy
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
machine: clean up orphaned gvproxy and win-sshproxy when starting Windows machines
2026-09-17 15:02:38 +02:00
Jan Rodák
9de95641de
Merge pull request #27025 from StefanNienhuis/feat/api-autoupdate
feat: Implement autoupdate endpoint in libpod REST API
2026-09-17 14:32:57 +02:00
Xiaowen-Yang
ce8df23914
machine: clean up orphaned gvproxy and win-sshproxy when starting Windows machines
Fixes: #29474
Signed-off-by: Xiaowen-Yang <xiaowenyang52@gmail.com>
2026-09-17 11:09:22 +02:00
Stefan Nienhuis
9c923c019e
feat: Implement auto update support for podman-remote
Signed-off-by: Stefan Nienhuis <stefan@nienhuisdevelopment.com>
2026-09-17 11:08:24 +02:00
seonghun lee
655b8cee14 Hide --cpu-rt-period/--cpu-rt-runtime and mark them as NOP
Podman 6 dropped cgroups v1 support, and the kernel real-time
scheduler cgroup settings only exist on cgroups v1. That means the
--cpu-rt-period and --cpu-rt-runtime options can never take effect
anymore: on cgroups v2 the values only produce a warning and are
discarded.

As agreed in the linked issue, the full removal of the options is
deferred to the next major release (7.0) to avoid a breaking change
for anyone still setting them. For 6.x this commit implements the
agreed interim step:

- remove the option documentation (docs/source/markdown/options/
  cpu-rt-period.md and cpu-rt-runtime.md) and drop the @@option
  references from the podman-create, podman-run, podman-update and
  podman-container-clone man pages
- hide both flags from --help output
- change the existing warning to state that the option is a NOP,
  that the value is ignored, and that the option will be removed in
  the next major release

The e2e tests are updated to match the new warning text. Actual
removal of the flags and the spec fields is left for Podman 7.0.

Part of #29750

Signed-off-by: seonghun lee <harrisleesh@gmail.com>
2026-09-17 01:15:52 +09:00
Matt Heon
c1922ea665
Merge pull request #29762 from madhoshyagnik/fix-quadlets-multipart
pkg/api/handlers/libpod: close quadlets multipart files per iteration and prevent duplicates
2026-09-16 10:05:15 -04:00
aayushbaluni
9f6b99950b fix: include IPRange in Docker-compat network IPAM config
The Docker-compatible network API omitted the IPRange field from the IPAM
config even though Libpod stores this data, so tools reading the Docker
API could not see the configured IP range.

Map Libpod's LeaseRange to Docker-compatible IPAMConfig.IPRange when it
aligns with a full CIDR span derived from FirstIPInSubnet/LastIPInSubnet,
and add an integration test that creates a network via the compat API with
an explicit IPRange and asserts it is returned on inspect.

The span is matched with bit arithmetic rather than by trying every prefix
length: the network address is start-1, and XORing that with end yields the
host mask, which identifies the prefix in a single pass. net/netip carries
the address handling throughout - Unmap collapses 4-in-6, Prev gives the
network address, and Masked confirms the network is aligned to the prefix.

Fixes: #28378

Signed-off-by: aayushbaluni <73417844+aayushbaluni@users.noreply.github.com>
2026-09-16 10:01:35 +05:30
Oleksandr Krutko
91c3d1d8ec Fix health-startup-cmd behaviour when the value is not set
Fixes: #27724

Signed-off-by: Oleksandr Krutko <alexander.krutko@gmail.com>
2026-09-15 22:09:57 +03:00
Jan Rodák
525dfd8700
Merge pull request #29758 from haneul-24/fix/api-endpoint-content-type
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
fix: set correct content-type for generate kube
2026-09-15 11:09:46 +02:00