Commit graph

7665 commits

Author SHA1 Message Date
Oleksandr Krutko
ff2eb1b0ca The feature which allows multiple Pods creation
Fixes: #26769

Signed-off-by: Oleksandr Krutko <alexander.krutko@gmail.com>
2026-09-20 15:41:06 +03:00
Matt Heon
0d12a23e7b
Merge pull request #29795 from arcusbuilds/compat-update-keep-restart-policy
Some checks failed
ci / sys local root fedora-prior (push) Has been cancelled
ci / int local rootless fedora-prior (push) Has been cancelled
ci / sys local rootless fedora-prior (push) Has been cancelled
ci / int remote root fedora-prior (push) Has been cancelled
ci / sys remote root fedora-prior (push) Has been cancelled
ci / int local root fedora-rawhide (push) Has been cancelled
ci / sys local root fedora-rawhide (push) Has been cancelled
ci / int local rootless fedora-rawhide (push) Has been cancelled
ci / sys local rootless fedora-rawhide (push) Has been cancelled
ci / int remote root fedora-rawhide (push) Has been cancelled
ci / sys remote root fedora-rawhide (push) Has been cancelled
ci / apiv2 root fedora-current (push) Has been cancelled
ci / bindings root fedora-current (push) Has been cancelled
ci / compose_v2 root fedora-current (push) Has been cancelled
ci / docker_py root fedora-current (push) Has been cancelled
ci / unit root fedora-current (push) Has been cancelled
ci / apiv2 rootless fedora-current (push) Has been cancelled
ci / compose_v2 rootless fedora-current (push) Has been cancelled
ci / farm rootless fedora-current (push) Has been cancelled
ci / unit rootless fedora-current (push) Has been cancelled
ci / upgrade v5.3.1 root fedora-current (push) Has been cancelled
ci / upgrade v5.6.2 root fedora-current (push) Has been cancelled
ci / machine linux amd64 (push) Has been cancelled
ci / windows unit (push) Has been cancelled
ci / windows e2e (push) Has been cancelled
ci / windows machine hyperv (push) Has been cancelled
ci / windows machine wsl (push) Has been cancelled
ci / macos machine applehv (push) Has been cancelled
ci / macos machine libkrun (push) Has been cancelled
ci / Total Success (push) Has been cancelled
compat: Restart policy no longer resets on compat update
2026-09-19 15:27:58 -04:00
Ashley Cui
dde83193d1
Merge pull request #28633 from aayushbaluni/fix/28378-iprange-compat-api
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
fix: include IPRange in Docker-compat network IPAM config
2026-09-18 16:36:36 -04:00
Jan Rodák
77d1fdf87a
Merge pull request #29303 from virzak/fix/compat-info-rootless-cgroup-driver
compat: report cgroup driver "none" when rootless with cgroupfs
2026-09-18 11:42:45 +02:00
Srijan Keshri
a50f49cab0 compat: Restart policy no longer resets on compat update
Fixed the compat container update path so it preserves the existing restart policy unless the request explicitly includes a new one, and added a regression test for it.

Fixes: #29790
Signed-off-by: Srijan Keshri <212402043+arcusbuilds@users.noreply.github.com>
2026-09-18 04:06:24 +00:00
Jan Rodák
6ba4ab29fc
Merge pull request #29587 from haneul-24/fix/kube-play-nested-image-path
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
Fix/kube play nested image path
2026-09-17 17:16:38 +02:00
Jan Rodák
fda861989d
Merge pull request #29395 from scallaway/image-scp-compression
image scp: add --compression-format and --compression-level
2026-09-17 17:09:06 +02:00
Paul Holzinger
91238111ba
Merge pull request #27857 from arsenalzp/podman60_27724
Fix startup health check command behavior
2026-09-17 16:32:42 +02:00
Jan Rodák
3568cf1c5b
Merge pull request #29765 from Xiaowen-Yang/fix-29474-orphan-proxy
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
machine: clean up orphaned gvproxy and win-sshproxy when starting Windows machines
2026-09-17 15:02:38 +02:00
Jan Rodák
9de95641de
Merge pull request #27025 from StefanNienhuis/feat/api-autoupdate
feat: Implement autoupdate endpoint in libpod REST API
2026-09-17 14:32:57 +02:00
Xiaowen-Yang
ce8df23914
machine: clean up orphaned gvproxy and win-sshproxy when starting Windows machines
Fixes: #29474
Signed-off-by: Xiaowen-Yang <xiaowenyang52@gmail.com>
2026-09-17 11:09:22 +02:00
Stefan Nienhuis
9c923c019e
feat: Implement auto update support for podman-remote
Signed-off-by: Stefan Nienhuis <stefan@nienhuisdevelopment.com>
2026-09-17 11:08:24 +02:00
seonghun lee
655b8cee14 Hide --cpu-rt-period/--cpu-rt-runtime and mark them as NOP
Podman 6 dropped cgroups v1 support, and the kernel real-time
scheduler cgroup settings only exist on cgroups v1. That means the
--cpu-rt-period and --cpu-rt-runtime options can never take effect
anymore: on cgroups v2 the values only produce a warning and are
discarded.

As agreed in the linked issue, the full removal of the options is
deferred to the next major release (7.0) to avoid a breaking change
for anyone still setting them. For 6.x this commit implements the
agreed interim step:

- remove the option documentation (docs/source/markdown/options/
  cpu-rt-period.md and cpu-rt-runtime.md) and drop the @@option
  references from the podman-create, podman-run, podman-update and
  podman-container-clone man pages
- hide both flags from --help output
- change the existing warning to state that the option is a NOP,
  that the value is ignored, and that the option will be removed in
  the next major release

The e2e tests are updated to match the new warning text. Actual
removal of the flags and the spec fields is left for Podman 7.0.

Part of #29750

Signed-off-by: seonghun lee <harrisleesh@gmail.com>
2026-09-17 01:15:52 +09:00
Matt Heon
c1922ea665
Merge pull request #29762 from madhoshyagnik/fix-quadlets-multipart
pkg/api/handlers/libpod: close quadlets multipart files per iteration and prevent duplicates
2026-09-16 10:05:15 -04:00
aayushbaluni
9f6b99950b fix: include IPRange in Docker-compat network IPAM config
The Docker-compatible network API omitted the IPRange field from the IPAM
config even though Libpod stores this data, so tools reading the Docker
API could not see the configured IP range.

Map Libpod's LeaseRange to Docker-compatible IPAMConfig.IPRange when it
aligns with a full CIDR span derived from FirstIPInSubnet/LastIPInSubnet,
and add an integration test that creates a network via the compat API with
an explicit IPRange and asserts it is returned on inspect.

The span is matched with bit arithmetic rather than by trying every prefix
length: the network address is start-1, and XORing that with end yields the
host mask, which identifies the prefix in a single pass. net/netip carries
the address handling throughout - Unmap collapses 4-in-6, Prev gives the
network address, and Masked confirms the network is aligned to the prefix.

Fixes: #28378

Signed-off-by: aayushbaluni <73417844+aayushbaluni@users.noreply.github.com>
2026-09-16 10:01:35 +05:30
Oleksandr Krutko
91c3d1d8ec Fix health-startup-cmd behaviour when the value is not set
Fixes: #27724

Signed-off-by: Oleksandr Krutko <alexander.krutko@gmail.com>
2026-09-15 22:09:57 +03:00
Jan Rodák
525dfd8700
Merge pull request #29758 from haneul-24/fix/api-endpoint-content-type
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
fix: set correct content-type for generate kube
2026-09-15 11:09:46 +02:00
Sejal
469bd43654 fix: support nested image paths in kube play build
Fixes: #28418

Signed-off-by: Sejal <sej1306kook@gmail.com>
2026-09-14 20:46:29 +00:00
Madhosh Yagnik
94b0c1df14 pkg/api/handlers/libpod: close quadlet files per iteration and prevent duplicates
processMultipartQuadlets previously deferred closing each multipart part
and file inside the loop, leaking descriptors until the handler returned.
It also opened files with os.Create, silently overwriting earlier files if
a request contained parts with duplicate names.

Align processMultipartQuadlets with the manifests multipart upload handler:
- Wrap each part processing in a closure so part and file descriptors close
  immediately on each loop iteration.
- Use os.OpenFile with os.O_CREATE|os.O_EXCL|os.O_WRONLY (0600) so duplicate
  filenames return an error instead of silently overwriting.
- Sanitize filenames using filepath.Base to prevent directory traversal.
- Add unit tests verifying multiple file extraction, duplicate name rejection,
  and path traversal sanitization.

Fixes: #29752
Signed-off-by: Madhosh Yagnik <madhosh1yagnik@gmail.com>
2026-09-14 23:55:57 +05:30
Matt Heon
6e10d5ac76
Merge pull request #29375 from Mahajan-Sachin/quadlet-volume-remainafterexit
quadlet: do not set RemainAfterExit=yes for volume units by default
2026-09-14 08:52:48 -04:00
Paul Holzinger
687c5e644a
Merge pull request #29525 from sahilnyk/exec-sigproxy-pgid
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
exec: forward signals to the exec session's process group
2026-09-14 13:32:46 +02:00
Sahil Nayak
903a1b6cb6 exec: forward signals to exec sessions over local and remote
Fixes: #19486
Signed-off-by: Sahil Nayak <contactsahilpnayak@gmail.com>
2026-09-11 21:32:26 +05:30
Matt Heon
b638cc9f48
Merge pull request #29295 from InvalidInterrupt/fix_api_restart_def_timeout
Respect container StopTimeout in container restart REST APIs
2026-09-11 06:40:44 -04:00
Paul Holzinger
0b62a84304
Merge pull request #29653 from Atishyy27/fix/remote-prune-filter-equals-v2
Some checks are pending
ci / int local rootless fedora-prior (push) Blocked by required conditions
ci / sys local rootless fedora-prior (push) Blocked by required conditions
ci / int remote root fedora-prior (push) Blocked by required conditions
ci / sys remote root fedora-prior (push) Blocked by required conditions
ci / int local root fedora-rawhide (push) Blocked by required conditions
ci / sys local root fedora-rawhide (push) Blocked by required conditions
ci / int local rootless fedora-rawhide (push) Blocked by required conditions
ci / sys local rootless fedora-rawhide (push) Blocked by required conditions
ci / int remote root fedora-rawhide (push) Blocked by required conditions
ci / sys remote root fedora-rawhide (push) Blocked by required conditions
ci / apiv2 root fedora-current (push) Blocked by required conditions
ci / bindings root fedora-current (push) Blocked by required conditions
ci / compose_v2 root fedora-current (push) Blocked by required conditions
ci / docker_py root fedora-current (push) Blocked by required conditions
ci / unit root fedora-current (push) Blocked by required conditions
ci / apiv2 rootless fedora-current (push) Blocked by required conditions
ci / compose_v2 rootless fedora-current (push) Blocked by required conditions
ci / farm rootless fedora-current (push) Blocked by required conditions
ci / unit rootless fedora-current (push) Blocked by required conditions
ci / upgrade v5.3.1 root fedora-current (push) Blocked by required conditions
ci / upgrade v5.6.2 root fedora-current (push) Blocked by required conditions
ci / machine linux amd64 (push) Blocked by required conditions
ci / windows unit (push) Blocked by required conditions
ci / windows e2e (push) Blocked by required conditions
ci / windows machine hyperv (push) Blocked by required conditions
ci / windows machine wsl (push) Blocked by required conditions
ci / macos machine applehv (push) Blocked by required conditions
ci / macos machine libkrun (push) Blocked by required conditions
ci / Total Success (push) Blocked by required conditions
zizmor: GitHub Actions Security Analysis / Zizmor (push) Waiting to run
fix(remote): keep '=' in a prune filter value
2026-09-10 18:20:31 +02:00
Scott Callaway
79b35ad0d9
image scp: accept --compression-format=none
Until now the default could only be expressed by leaving the option off, which
reads as an omission rather than a choice and gives a script no way to say it
wants the archive transferred as podman save wrote it.

Accept none as a format meaning exactly that. It is taken on the API path too,
so both interfaces share one vocabulary, and it is treated as the absence of a
format throughout: nothing is compressed, a level attached to it is rejected the
same way a level with no format is, and the local user to user transfer has
nothing to warn about ignoring.

The remote client still leaves it off the request, so naming the default does
not make a transfer fail against a service that predates these options.

Signed-off-by: Scott Callaway <github@scottcallaway.co.uk>
2026-09-10 16:45:30 +01:00
Paul Holzinger
5004e99e3b
pkg/machine/hyperv: fix incorrect timeout
The timeout is simply to low, I don't know the previous numbers were
collected because they are simply wrong. A machine init takes around 50s
total. And while the ready timeout itself could be shorter there is
really no good reason to set such a low limit as it will cause wrong
failures.

This is currently flaking a lot in CI, I see it in most hyperV logs I
looked at[1]. While there is likely another problem with the boot
failures I think this added a ton of false positives as it errors out
early.

[1] https://github.com/podman-container-tools/podman/actions/runs/34146238887/job/101820830173

Fixes: dd28c14f8c ("hyperv: add timeout to vsock ready wait")

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-08 12:42:15 +02:00
Paul Holzinger
2e589e7465
pkg/machine/e2e: lower command timeout
Even on the slowest of CI systems a normal VM start does not seem to
take more than 1 minute.

Instead we seem to have flakes which cause our command to hang on
startup. In that case we thought waiting longer might help but instead
it just wastes 10 minutes.

Se the default command timeout to 3 minutes which should be plenty even
on the slowest of CI systems. Anything above will likely never finish
and we can just abort the test as failed.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-08 12:31:04 +02:00
Paul Holzinger
d42ad4aae3
pkg/machine/e2e: combine one --import-native-ca test
Combine the no volume and --import-native-ca test into one.

This removes one full machine init/start/stop cycle.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-08 12:24:17 +02:00
Paul Holzinger
ee7d3c534c
pkg/machine/e2e: combine build context test
Instead of creating a fresh machine which is slow reuse an existing
test for this test.

Also fix the test to actually check the file content properly, it was
using the wrong build output. And then just use one cat for both files
to make it a tiny bit faster.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-08 12:24:17 +02:00
Paul Holzinger
66a1bee8d5
pkg/machine/e2e: inline one remove test
Avoid another init/start cycle by reusing an existing test which has a
VM running already.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-08 12:24:17 +02:00
Paul Holzinger
f1f52763cb
pkg/machine/e2e: combine api test cases
Only start a machine once, not three times to safe time.

Also include stdout/err as part of the curl command so errors are
visible. And lastly the latest moby client code should support unix
sockets on windows so we can test it there as well.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-08 12:16:45 +02:00
Paul Holzinger
49aec99596
pkg/machine/e2e: inline stop running machine
Instead of having to start a new machine again here just drop the test
and do the stop check as part of another test which already has a
machine running.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-08 12:16:45 +02:00
Paul Holzinger
9002dce687
pkg/machine/e2e: use withFakeImage for excessive cpus test
The test should fail before booting a real VM so we can use the fake
image which should make the test a few seconds faster.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-08 12:16:45 +02:00
Paul Holzinger
1b6d77299e
pkg/machine/e2e: remove simple init with start
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-08 12:16:44 +02:00
Paul Holzinger
ccd3778087
pkg/machine/e2e: remove start simple machine
The test starts a machine 3 times taking almost 180 seconds in linux CI.

We have a lot of machine starts elsewhere already so we really do not
need a basic start and for the quiet/noinfo checks we can just add them
to another existing start command.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-08 12:16:44 +02:00
Paul Holzinger
d99f1d5564
pkg/machine/e2e: rename toQemuInspectInfo to toInspectInfo
There is nothing qemu specifc about this for a long time. Just drop it
from the name.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-08 12:16:44 +02:00
Paul Holzinger
3ffe582563
pkg/machine/e2e: combine machine set rootful tests
Each machine start/stop adds up in CI, combine several related tests to
reduce the machine init/start/stops cycles.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-08 12:16:44 +02:00
Paul Holzinger
d3f30f698e
pkg/machine/e2e: correctly handle set --rootful=false
On podman machine set we have three modes, not set (keep user),
--rootful (set user to root), --rootful=false (set to rootless user).

The later could not be passed at all before this.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-08 12:16:44 +02:00
Paul Holzinger
f4df65a859
pkg/machine/e2e: combine two restart machine tests
The restart tests are rather slow. On the linux CI 60 seconds for the
stopped case and almost 120 seconds for the restart running case.

Combine both cases into one so we only have to start a machine twice,
not three times and only need to init it once.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-08 12:16:43 +02:00
Scott Callaway
8d5b091a45
image scp: pass the compression options over the remote API
The tunnel engine builds its own ScpOptions, so without this the flags parse
fine under podman --remote and are then dropped, transferring uncompressed with
no indication that anything was ignored.

Carry both options through the bindings to the libpod ImageScp handler, which
hands them to ExecuteTransfer the same way the local path does, and document
them on the endpoint.

This is also the point at which the transfer's own validation becomes reachable
over HTTP, so map it accordingly: a rejected format or level is the caller's
mistake and answers 400, not the 500 every error from the transfer used to
produce.

Signed-off-by: Scott Callaway <github@scottcallaway.co.uk>
2026-09-07 16:03:54 +01:00
Scott Callaway
c6029f9ab7
image scp: compress a remotely produced archive on the source host
When the source is a remote host the archive is produced there, so it has to be
compressed there too: compressing after copying it down would mean the
uncompressed archive had already crossed the network, which is the cost this is
meant to avoid.

The only thing we can do on that host is run a command, so the matching
compressor is invoked over ssh between the save and the copy. That is also why
the set of formats is limited to algorithms available as a command of the same
name.

Two details worth stating. A shell reports 127 when it cannot find the command,
which is worth reporting plainly as a host without the compressor installed;
anything else, a failure to connect included, must not be reported that way,
and a probe beforehand cannot make that distinction without also costing an
extra connection. And the compressor removes its input only once it succeeds
and may have written part of its output before giving up, so a failure cleans
up both paths.

Signed-off-by: Scott Callaway <github@scottcallaway.co.uk>
2026-09-07 16:03:54 +01:00
Scott Callaway
4c7a1a8408
image scp: compress a locally produced archive into the ssh stream
podman save writes docker-archive layers uncompressed, so podman image scp puts
the whole archive on the wire as is. Compressing it first takes a docker-archive
to around half its size or less, which is why people work around this today with
podman save | zstd, a manual copy and podman load on the far side. An
oci-archive keeps whatever compression its layers already have, so there is
little to gain there; the man page records the difference.

When the archive is produced locally it can be compressed on the way out: the
c/image compression package wraps the file as it is streamed into the ssh
connection feeding the remote podman image load. No second temporary file,
nothing buffered in full.

Nothing is needed on the destination. podman load detects the compression from
the stream and decompresses it itself, for docker-archive via c/image's
AutoDecompress and for oci-archive via c/storage's DecompressStream. Both are
covered, since which one runs depends on --format.

Signed-off-by: Scott Callaway <github@scottcallaway.co.uk>
2026-09-07 16:02:48 +01:00
Scott Callaway
69e300867e
image scp: describe and validate the compression options
Groundwork for compressing the transfer archive: the options themselves, the
set of algorithms that may be requested, and the check ExecuteTransfer runs
before it does anything else. Nothing acts on them yet.

The set of formats is deliberately narrower than what c/image knows. Every
entry has to satisfy three things: podman load has to detect and decompress it
from the stream alone, c/image has to be able to compress it (it only
decompresses bzip2 and xz), and a command line compressor of the same name has
to exist for the case where the archive is produced on a remote host. gzip and
zstd qualify, and they match the vocabulary --compression-format already uses
on podman push.

One table drives the accepted formats, their level ranges, and the list
offered on the command line, so there is nothing to keep in sync.

A transfer between two users on the same machine never crosses a network, so a
requested format is reported as ignored there rather than refused.

The validation is worded without flag names because it also runs on the API
path, where the caller never passed a flag.

Signed-off-by: Scott Callaway <github@scottcallaway.co.uk>
2026-09-07 15:59:33 +01:00
Scott Callaway
011b659569
pkg/domain/utils: tidy SaveToRemote's remote commands
Three small things in one place, all groundwork rather than behaviour:

The path SaveToRemote gets back from the remote mktemp still carries the
trailing newline ssh.Exec hands over with the rest of the raw output. That is
harmless while the path is only ever the last thing on a command line, but it
is a trap for anything that appends to it. Trim it.

The host, identity, port and user were restated in full for every command.
State them once and let each command copy the value and add its own argv.

Removing a file on the far end had one caller and was about to have more, so
give it a name. It also gains -f, since a caller cleaning up after a failure
cannot know which of the paths it is removing were created.

Lastly, the ssh operations a transfer performs are gathered into one value the
exported entry points pass in. Nothing about the options changes: SaveToRemote
and LoadToRemote keep taking their options struct, and the body moves to an
unexported function taking that same struct plus the operations to run it with.
That is what lets a test assert the sequence of remote commands, and what is
streamed to them, without a host to run against.

Signed-off-by: Scott Callaway <github@scottcallaway.co.uk>
2026-09-07 15:59:27 +01:00
Lokesh Mandvekar
10b487f229
Merge pull request #29722 from Luap99/lint
Update golangci/golangci-lint to v2.13.2
2026-09-07 09:33:26 -04:00
Sachin Mahajan
e822e89e5d quadlet: do not set RemainAfterExit=yes for volume units by default
Do not set RemainAfterExit=yes by default when converting Quadlet
.volume files to systemd oneshot services.

Setting RemainAfterExit=yes causes systemd to consider the volume
service active even after the volume is deleted manually, preventing
systemd from re-executing volume creation when dependent container
services restart.

Fixes #27862

Signed-off-by: Sachin Mahajan <sachinmahajan903@gmail.com>
2026-09-07 16:26:10 +05:30
Sejal
b5b558d671 fix: set correct content-type for generate kube
Fixes: #29674
Signed-off-by: Sejal <sej1306kook@gmail.com>
2026-09-05 23:21:50 +00:00
Danish Prakash
764021086d
Merge pull request #29606 from vishnukothakapu/perf-slices-sort
Performance: Upgrade sort.Slice to slices.SortFunc across codebase
2026-09-04 21:19:24 +05:30
Paul Holzinger
eea3fa25da
silence new platform specific staticcheck issues
These errors only happen on windows or freebsd. They happen when a
function always returns a hard error there so it assumes the condition
is always true which is not the case on another platform.

We then also need to use nolintlint so it does not trigger on linux
where the nolint is not needed otherwise.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-04 17:21:15 +02:00
Paul Holzinger
3222b4bc25
fix new golangci-lint staticcheck warnings
Looks like it picked up new deprecated matches so we need some more
nolint to silence them where we still need them for backwards compat in
the API.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2026-09-04 16:40:03 +02:00