Fixed the compat container update path so it preserves the existing restart policy unless the request explicitly includes a new one, and added a regression test for it.
Fixes: #29790
Signed-off-by: Srijan Keshri <212402043+arcusbuilds@users.noreply.github.com>
Podman 6 dropped cgroups v1 support, and the kernel real-time
scheduler cgroup settings only exist on cgroups v1. That means the
--cpu-rt-period and --cpu-rt-runtime options can never take effect
anymore: on cgroups v2 the values only produce a warning and are
discarded.
As agreed in the linked issue, the full removal of the options is
deferred to the next major release (7.0) to avoid a breaking change
for anyone still setting them. For 6.x this commit implements the
agreed interim step:
- remove the option documentation (docs/source/markdown/options/
cpu-rt-period.md and cpu-rt-runtime.md) and drop the @@option
references from the podman-create, podman-run, podman-update and
podman-container-clone man pages
- hide both flags from --help output
- change the existing warning to state that the option is a NOP,
that the value is ignored, and that the option will be removed in
the next major release
The e2e tests are updated to match the new warning text. Actual
removal of the flags and the spec fields is left for Podman 7.0.
Part of #29750
Signed-off-by: seonghun lee <harrisleesh@gmail.com>
The Docker-compatible network API omitted the IPRange field from the IPAM
config even though Libpod stores this data, so tools reading the Docker
API could not see the configured IP range.
Map Libpod's LeaseRange to Docker-compatible IPAMConfig.IPRange when it
aligns with a full CIDR span derived from FirstIPInSubnet/LastIPInSubnet,
and add an integration test that creates a network via the compat API with
an explicit IPRange and asserts it is returned on inspect.
The span is matched with bit arithmetic rather than by trying every prefix
length: the network address is start-1, and XORing that with end yields the
host mask, which identifies the prefix in a single pass. net/netip carries
the address handling throughout - Unmap collapses 4-in-6, Prev gives the
network address, and Masked confirms the network is aligned to the prefix.
Fixes: #28378
Signed-off-by: aayushbaluni <73417844+aayushbaluni@users.noreply.github.com>
processMultipartQuadlets previously deferred closing each multipart part
and file inside the loop, leaking descriptors until the handler returned.
It also opened files with os.Create, silently overwriting earlier files if
a request contained parts with duplicate names.
Align processMultipartQuadlets with the manifests multipart upload handler:
- Wrap each part processing in a closure so part and file descriptors close
immediately on each loop iteration.
- Use os.OpenFile with os.O_CREATE|os.O_EXCL|os.O_WRONLY (0600) so duplicate
filenames return an error instead of silently overwriting.
- Sanitize filenames using filepath.Base to prevent directory traversal.
- Add unit tests verifying multiple file extraction, duplicate name rejection,
and path traversal sanitization.
Fixes: #29752
Signed-off-by: Madhosh Yagnik <madhosh1yagnik@gmail.com>
Until now the default could only be expressed by leaving the option off, which
reads as an omission rather than a choice and gives a script no way to say it
wants the archive transferred as podman save wrote it.
Accept none as a format meaning exactly that. It is taken on the API path too,
so both interfaces share one vocabulary, and it is treated as the absence of a
format throughout: nothing is compressed, a level attached to it is rejected the
same way a level with no format is, and the local user to user transfer has
nothing to warn about ignoring.
The remote client still leaves it off the request, so naming the default does
not make a transfer fail against a service that predates these options.
Signed-off-by: Scott Callaway <github@scottcallaway.co.uk>
The timeout is simply to low, I don't know the previous numbers were
collected because they are simply wrong. A machine init takes around 50s
total. And while the ready timeout itself could be shorter there is
really no good reason to set such a low limit as it will cause wrong
failures.
This is currently flaking a lot in CI, I see it in most hyperV logs I
looked at[1]. While there is likely another problem with the boot
failures I think this added a ton of false positives as it errors out
early.
[1] https://github.com/podman-container-tools/podman/actions/runs/34146238887/job/101820830173
Fixes: dd28c14f8c ("hyperv: add timeout to vsock ready wait")
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
Even on the slowest of CI systems a normal VM start does not seem to
take more than 1 minute.
Instead we seem to have flakes which cause our command to hang on
startup. In that case we thought waiting longer might help but instead
it just wastes 10 minutes.
Se the default command timeout to 3 minutes which should be plenty even
on the slowest of CI systems. Anything above will likely never finish
and we can just abort the test as failed.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
Combine the no volume and --import-native-ca test into one.
This removes one full machine init/start/stop cycle.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
Instead of creating a fresh machine which is slow reuse an existing
test for this test.
Also fix the test to actually check the file content properly, it was
using the wrong build output. And then just use one cat for both files
to make it a tiny bit faster.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
Only start a machine once, not three times to safe time.
Also include stdout/err as part of the curl command so errors are
visible. And lastly the latest moby client code should support unix
sockets on windows so we can test it there as well.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
Instead of having to start a new machine again here just drop the test
and do the stop check as part of another test which already has a
machine running.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
The test should fail before booting a real VM so we can use the fake
image which should make the test a few seconds faster.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
The test starts a machine 3 times taking almost 180 seconds in linux CI.
We have a lot of machine starts elsewhere already so we really do not
need a basic start and for the quiet/noinfo checks we can just add them
to another existing start command.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
Each machine start/stop adds up in CI, combine several related tests to
reduce the machine init/start/stops cycles.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
On podman machine set we have three modes, not set (keep user),
--rootful (set user to root), --rootful=false (set to rootless user).
The later could not be passed at all before this.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
The restart tests are rather slow. On the linux CI 60 seconds for the
stopped case and almost 120 seconds for the restart running case.
Combine both cases into one so we only have to start a machine twice,
not three times and only need to init it once.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
The tunnel engine builds its own ScpOptions, so without this the flags parse
fine under podman --remote and are then dropped, transferring uncompressed with
no indication that anything was ignored.
Carry both options through the bindings to the libpod ImageScp handler, which
hands them to ExecuteTransfer the same way the local path does, and document
them on the endpoint.
This is also the point at which the transfer's own validation becomes reachable
over HTTP, so map it accordingly: a rejected format or level is the caller's
mistake and answers 400, not the 500 every error from the transfer used to
produce.
Signed-off-by: Scott Callaway <github@scottcallaway.co.uk>
When the source is a remote host the archive is produced there, so it has to be
compressed there too: compressing after copying it down would mean the
uncompressed archive had already crossed the network, which is the cost this is
meant to avoid.
The only thing we can do on that host is run a command, so the matching
compressor is invoked over ssh between the save and the copy. That is also why
the set of formats is limited to algorithms available as a command of the same
name.
Two details worth stating. A shell reports 127 when it cannot find the command,
which is worth reporting plainly as a host without the compressor installed;
anything else, a failure to connect included, must not be reported that way,
and a probe beforehand cannot make that distinction without also costing an
extra connection. And the compressor removes its input only once it succeeds
and may have written part of its output before giving up, so a failure cleans
up both paths.
Signed-off-by: Scott Callaway <github@scottcallaway.co.uk>
podman save writes docker-archive layers uncompressed, so podman image scp puts
the whole archive on the wire as is. Compressing it first takes a docker-archive
to around half its size or less, which is why people work around this today with
podman save | zstd, a manual copy and podman load on the far side. An
oci-archive keeps whatever compression its layers already have, so there is
little to gain there; the man page records the difference.
When the archive is produced locally it can be compressed on the way out: the
c/image compression package wraps the file as it is streamed into the ssh
connection feeding the remote podman image load. No second temporary file,
nothing buffered in full.
Nothing is needed on the destination. podman load detects the compression from
the stream and decompresses it itself, for docker-archive via c/image's
AutoDecompress and for oci-archive via c/storage's DecompressStream. Both are
covered, since which one runs depends on --format.
Signed-off-by: Scott Callaway <github@scottcallaway.co.uk>
Groundwork for compressing the transfer archive: the options themselves, the
set of algorithms that may be requested, and the check ExecuteTransfer runs
before it does anything else. Nothing acts on them yet.
The set of formats is deliberately narrower than what c/image knows. Every
entry has to satisfy three things: podman load has to detect and decompress it
from the stream alone, c/image has to be able to compress it (it only
decompresses bzip2 and xz), and a command line compressor of the same name has
to exist for the case where the archive is produced on a remote host. gzip and
zstd qualify, and they match the vocabulary --compression-format already uses
on podman push.
One table drives the accepted formats, their level ranges, and the list
offered on the command line, so there is nothing to keep in sync.
A transfer between two users on the same machine never crosses a network, so a
requested format is reported as ignored there rather than refused.
The validation is worded without flag names because it also runs on the API
path, where the caller never passed a flag.
Signed-off-by: Scott Callaway <github@scottcallaway.co.uk>
Three small things in one place, all groundwork rather than behaviour:
The path SaveToRemote gets back from the remote mktemp still carries the
trailing newline ssh.Exec hands over with the rest of the raw output. That is
harmless while the path is only ever the last thing on a command line, but it
is a trap for anything that appends to it. Trim it.
The host, identity, port and user were restated in full for every command.
State them once and let each command copy the value and add its own argv.
Removing a file on the far end had one caller and was about to have more, so
give it a name. It also gains -f, since a caller cleaning up after a failure
cannot know which of the paths it is removing were created.
Lastly, the ssh operations a transfer performs are gathered into one value the
exported entry points pass in. Nothing about the options changes: SaveToRemote
and LoadToRemote keep taking their options struct, and the body moves to an
unexported function taking that same struct plus the operations to run it with.
That is what lets a test assert the sequence of remote commands, and what is
streamed to them, without a host to run against.
Signed-off-by: Scott Callaway <github@scottcallaway.co.uk>
Do not set RemainAfterExit=yes by default when converting Quadlet
.volume files to systemd oneshot services.
Setting RemainAfterExit=yes causes systemd to consider the volume
service active even after the volume is deleted manually, preventing
systemd from re-executing volume creation when dependent container
services restart.
Fixes#27862
Signed-off-by: Sachin Mahajan <sachinmahajan903@gmail.com>
These errors only happen on windows or freebsd. They happen when a
function always returns a hard error there so it assumes the condition
is always true which is not the case on another platform.
We then also need to use nolintlint so it does not trigger on linux
where the nolint is not needed otherwise.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
Looks like it picked up new deprecated matches so we need some more
nolint to silence them where we still need them for backwards compat in
the API.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>