Commit graph

19320 commits

Author SHA1 Message Date
Valentin Rothberg
ff71df0e88 system service: unset listen fds on tcp
Disable leaking the LISTEN_* variables into containers which are
observed to be passed by systemd even without being socket activated as
described in https://access.redhat.com/solutions/6512011.

[NO NEW TESTS NEEDED] - Ultimately, the solution 6512011 should be updated.

Fixes: bugzilla.redhat.com/show_bug.cgi?id=2180483
Signed-off-by: Valentin Rothberg <vrothberg@redhat.com>
2023-07-12 09:17:49 +00:00
OpenShift Merge Robot
c27903d2e3
Merge pull request #19194 from Cydox/fix-notes
[CI:DOCS] [Release Notes]: add static routes
2023-07-11 12:19:00 -04:00
Jan Hendrik Farr
6960a81831
[CI:DOCS] [Release Notes]: add static routes
Signed-off-by: Jan Hendrik Farr <github@jfarr.cc>
2023-07-11 16:05:09 +02:00
OpenShift Merge Robot
93009a9005
Merge pull request #19151 from lsm5/v4.6-podmansh-tech-preview
[CI:DOCS] tag podmansh as tech preview in RELEASE_NOTES.md
2023-07-09 07:27:26 -04:00
Lokesh Mandvekar
e4cf2afbc0
[CI:DOCS] tag podmansh as tech preview in RELEASE_NOTES.md
Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
2023-07-07 10:31:30 -04:00
OpenShift Merge Robot
932b8a997e
Merge pull request #19149 from edsantiago/fix_corrupt_man_tables_46
[v4.6] fix corrupt man tables 46
2023-07-07 02:57:50 -04:00
Ed Santiago
c422072b65 [CI:DOCS] uidmap man pages: fix corrupt tables
[backport of #19088. No conflicts.]

The markdown-to-manpage sequence needs a long row of dashes,
not a single dash. A single dash, as used in this one option,
generates unreadable *roff.

Also, some tool somewhere doesn't like too-long columns. Shrtn thm.

Also, verify that there are no more three-or-fewer-dash columns:

    $ ack '\|\s+-{1,3}\s' docs/source/markdown

Reference: #19086

Signed-off-by: Ed Santiago <santiago@redhat.com>
2023-07-06 11:18:36 -06:00
OpenShift Merge Robot
be5e2dcfb8
Merge pull request #19111 from openshift-cherrypick-robot/cherry-pick-19101-to-v4.6
[v4.6] libpod: use new libcontainer BlockIO constructors
2023-07-04 08:08:53 -04:00
Peter Hunt
7680e5013a libpod: use new libcontainer BlockIO constructors
[NO NEW TESTS NEEDED]

Signed-off-by: Peter Hunt <pehunt@redhat.com>
2023-07-04 07:25:12 +00:00
OpenShift Merge Robot
8090f67b0a
Merge pull request #19091 from ashley-cui/rel460
Bump to v4.6.0-rc1
2023-07-03 08:55:02 -04:00
Ashley Cui
829b3e9b3d Bump to v4.6.0-dev
Signed-off-by: Ashley Cui <acui@redhat.com>
2023-07-03 02:13:57 -04:00
Ashley Cui
4d59a0f5c7
Bump to v4.6.0-rc1
Signed-off-by: Ashley Cui <acui@redhat.com>
2023-07-03 02:13:17 -04:00
OpenShift Merge Robot
3e45317660
Merge pull request #19077 from ashley-cui/rel460
Bump to v4.6.0
2023-07-02 07:10:49 -04:00
Ashley Cui
e4a7923ca4 Bump to v4.6.1-dev
Signed-off-by: Ashley Cui <acui@redhat.com>
2023-07-01 14:21:29 -04:00
Ashley Cui
c756b24f40
Bump to v4.6.0
Signed-off-by: Ashley Cui <acui@redhat.com>
2023-07-01 14:21:14 -04:00
Ashley Cui
2e53a5083f Release notes for v4.6.0
Signed-off-by: Ashley Cui <acui@redhat.com>
2023-07-01 14:21:04 -04:00
Ashley Cui
727362bdea Update Release Notes for v4.5.1
Signed-off-by: Ashley Cui <acui@redhat.com>
2023-07-01 14:20:23 -04:00
Paul Holzinger
8f2b73b036 rootless: use default_rootless_network_cmd config
Make sure we use the config field to know if we should use pasta or
slirp4netns as default.

While at it fix broken code which sets the default at two different
places, also do not set in Validate() as this should not modify the
specgen IMO, so set it directly before that.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2023-07-01 14:19:57 -04:00
Paul Holzinger
3bd4c6a107 tests: fix "Storing signatures" check
After[1] c/image no longer prints "Storing signatures" so we should
not check for it.

[1] https://github.com/containers/image/pull/2001

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2023-07-01 14:07:58 -04:00
Ed Santiago
d5e8cc1d17 Fixes for vendoring Buildah
This commit was automatically cherry-picked
by buildah-vendor-treadmill v0.3
from the buildah vendor treadmill PR, #13808

Changes since 2023-05-01:
  - skip a new test, it fails in remote
  - skip encrypted-FROM test, broken by buildah PR 4746

Signed-off-by: Ed Santiago <santiago@redhat.com>
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2023-07-01 14:07:58 -04:00
Daniel J Walsh
2203f2aa93 Make Podman/Buildah use same DecryptConfig/EncryptConfig funcs
Signed-off-by: Daniel J Walsh <dwalsh@redhat.com>
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2023-07-01 14:07:58 -04:00
Ashley Cui
a306eb5f6f Do not use deprecated hook functions from c/common
[NO NEW TESTS NEEDED]

Signed-off-by: Ashley Cui <acui@redhat.com>
2023-07-01 14:06:47 -04:00
Ashley Cui
bf36f1139c Bump c/storage to v1.48.0, c/image to v5.26.1, c/common to v0.55.1, buildah to v1.31.0
Signed-off-by: Ashley Cui <acui@redhat.com>
2023-07-01 14:06:32 -04:00
OpenShift Merge Robot
a1a73e30b6
Merge pull request #19072 from ashley-cui/backports
[v4.6] 4.6 Backports
2023-06-30 15:34:25 -04:00
David Gibson
a64016e174 pasta: Remove some leftover code from pasta bats tests
https://github.com/containers/podman/pull/19021 fixed bugs with the pasta
networking tests not working on hosts with multiple interfaces.  Alas, the
patch left in some stale code that generates spurious error messages for
the IPv6 case.  This is sort of harmless - later code overrides what's done
here and the tests can pass anyway.  However if a test fails for some other
reason it means we get a misleading irrelevant error message.

Signed-off-by: David Gibson <david@gibson.dropbear.id.au>
2023-06-30 13:37:52 -04:00
David Gibson
6feb179f40 pasta: Fix pasta tests to work on hosts with multiple interfaces
At various points the pasta bats tests need to know the name of the
interface that pasta will use by default, and the host addresses it will
use by default.  Currently we use the pre-existing helper functions
ether_get_name and ipv[46]_get_addr_global to retreive that.

However, those just pick the first non-loopback interface or address, which
may not be the one that pasta uses if there are multiple connected host
interfaces.

Replace those helpers with local ones which examine the routing table to
more closely match pasta's internal logic about which interface to select.
This allows the tests to run successfully on a host with multiple
interfaces.

Closes: https://github.com/containers/podman/issues/19007

Signed-off-by: David Gibson <david@gibson.dropbear.id.au>
2023-06-30 13:37:31 -04:00
Black-Hole1
9cc19b0550 fix(command): ignore --format in podman search --list-tags
Fix: https://github.com/containers/podman/issues/19033

Signed-off-by: Black-Hole1 <bh@bugs.cc>
2023-06-30 10:18:15 -04:00
Simon Brakhane
714c3fe72f Use /proc/self/gid_map as intended, not uid_map
GetKeepIDMapping never read the gid (as it intended) but reused the uid.
Most likely a typo that never bothered anybody as uid and gid usually
match.

Signed-off-by: Simon Brakhane <simon@brakhane.net>
2023-06-30 10:17:54 -04:00
Valentin Rothberg
d29e336504 podman machine start: fix ready service
When debugging #17403, the logs of sshd indicates that Podman tried to
ssh into the machine too soon as the `core` user has not yet been fully
set up:

 > error: kex_exchange_identification: Connection closed by remote host
 > fatal: Access denied for user core by PAM account configuration [preauth]

@dustymabe found that the we may have to wait for systemd-user sessions
to be up.  Doing that reduces the flake rate on my M2 machine but does
not entirely fix the issue.

Since I have seen multiple symptoms of flakiness, I think it does not
hurt to add the systemd-user sessions to the dependencies of the ready
service and continue investigating.

[NO NEW TESTS NEEDED] - once we have a fix out, I want to exercise
frequent stop/start in the machine tests but they won't pass now.

Signed-off-by: Valentin Rothberg <vrothberg@redhat.com>
2023-06-30 10:17:41 -04:00
Doug Rabson
1a1602b72b Makefile: don't rely on the non-standard -r flag for ln
This flag is not supported on BSD-derived systems including FreeBSD and
macos. We can get exactly the same symlink by passing the desired
relative path as source argument to 'ln -sf'.

Signed-off-by: Doug Rabson <dfr@rabson.org>
2023-06-30 10:17:27 -04:00
Doug Rabson
db91ce7886 cmd/podman, pkg/domain/infra: sockets should live in /var/run on FreeBSD
The /var/run directory is the preferred location for unix domain
sockets.

[NO NEW TESTS NEEDED]

Signed-off-by: Doug Rabson <dfr@rabson.org>
2023-06-30 10:17:04 -04:00
Doug Rabson
82a4b08169 cmd/podman/system: add API server support on FreeBSD
This adds the 'system service' command to the build on FreeBSD and
suppresses the call to servicereaper.Start which is only needed to
support slirp4netns on Linux. A stub for compat.StatsContainer is also
added - stats are still supported via the libpod.StatsContainer API
call.

[NO NEW TESTS NEEDED]

Signed-off-by: Doug Rabson <dfr@rabson.org>
2023-06-30 10:16:56 -04:00
David Gibson
2f25372de4 pasta: Create /etc/hosts entries for pods using pasta networking
For pods with bridged and slirp4netns networking we create /etc/hosts
entries to make it more convenient for the containers to address each
other.  We omitted to do this for pasta networking, however.  Add the
necessary code to do this.

Closes: https://github.com/containers/podman/issues/17922

Signed-off-by: David Gibson <david@gibson.dropbear.id.au>
2023-06-30 10:16:19 -04:00
OpenShift Merge Robot
39cdc99e2c
Merge pull request #19050 from openshift-cherrypick-robot/cherry-pick-19035-to-v4.6
[v4.6] [CI:BUILD] RPM: Fix koji and ELN issues
2023-06-29 20:14:49 +02:00
Lokesh Mandvekar
9555446d3e RPM: Fix koji and ELN issues
- build dnsname the old way otherwise it fails on koji
- use the binary path for go-md2man for successful ELN builds

[NO NEW TESTS NEEDED]

Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
2023-06-29 13:33:01 +00:00
Ashley Cui
0749d685ab Cirrus: Update operating branch
Signed-off-by: Ashley Cui <acui@redhat.com>
2023-06-26 13:29:33 -04:00
OpenShift Merge Robot
3a013b6256
Merge pull request #18998 from edsantiago/bats_prefetch
system tests: add and use _prefetch
2023-06-26 16:08:45 +02:00
Ed Santiago
dde6bcbca3 system tests: add and use _prefetch
Add new _prefetch helper for fetching and caching images.
Use it in a few places, most importantly 120-load.bats
where our teardown() now runs 'rmi -af'.

Reason: in #17911 we discovered that podman save + load do
not actually preserve the image: annotations and other metadata
are lost. This means that a test which runs after 120-load.bats
is operating on a different $IMAGE than a test which runs before.

This is not a problem except in very obscure corner cases, like
one fixed in #18542, but it seems irresponsible to just handwave
that issue away

The _prefetch function uses skopeo for fetching and saving
images, because skopeo preserves digests and metadata.

[Side note for posterity: I tried amending basic_setup() to
always rmi -a + prefetch, instead of the current images -a +
rmi unwanted ones. That slowed down system tests by 10 minutes,
presumably because loads are much slower than queries. I reverted
that change and am documenting it as a reminder of why we do things
the way we do.]

Signed-off-by: Ed Santiago <santiago@redhat.com>
2023-06-26 06:51:01 -06:00
OpenShift Merge Robot
1bca2d6a1e
Merge pull request #18983 from Luap99/api-top
pkg/api: top return error to client
2023-06-26 08:12:29 +02:00
OpenShift Merge Robot
384638861b
Merge pull request #18978 from rhatdan/man1
[CI:DOCS] Fix example on PublishPort
2023-06-23 20:57:22 +02:00
OpenShift Merge Robot
9f4ee47dc4
Merge pull request #18932 from lsm5/packit-cleanup
[CI:BUILD] Packit: cleanups
2023-06-23 17:49:31 +02:00
Paul Holzinger
0ee19f08cf
pkg/api: BufferedResponseWriter flush correctly
Somehow my error message in top was never printed for the compat API,
the libpod one using the same code worked fine. Turns out the compat one
is using this buffered writter instaed but never made sure to flush it
before closing the connection.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2023-06-23 16:51:22 +02:00
Paul Holzinger
d0505d6bac
pkg/api: top return error to client
Wait before sending status code 200 for the first top call and if that
fails return a proper error code.

This was leading to some confusion in [1] because podman just reported
200 but did not wirte anything back.

[1] https://bugzilla.redhat.com/show_bug.cgi?id=2215572

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2023-06-23 16:48:57 +02:00
OpenShift Merge Robot
84454987f5
Merge pull request #18974 from vrothberg/fix-13627
podman wait: support healthy/unhealthy
2023-06-23 16:03:50 +02:00
Valentin Rothberg
1398cbce8a container wait: support health states
Support two new wait conditions, "healthy" and "unhealthy".  This
further paves the way for integrating sdnotify with health checks which
is currently being tracked in #6160.

Fixes: #13627
Signed-off-by: Valentin Rothberg <vrothberg@redhat.com>
2023-06-23 14:16:32 +02:00
Daniel J Walsh
b680daa2de
[CI:DOCS] Fix example on PublishPort
Signed-off-by: Daniel J Walsh <dwalsh@redhat.com>
2023-06-23 06:47:05 -04:00
Valentin Rothberg
811867249b container wait API: use string slice instead of state slice
Massage the internal APIs to use a string slice instead of a state slice
for passing wait conditions.  This paves the way for waiting on
non-state conditions such as "healthy".

Signed-off-by: Valentin Rothberg <vrothberg@redhat.com>
2023-06-23 09:26:30 +02:00
Valentin Rothberg
64153ace05 podman wait: update man page
While reading the code I found the man page to be lacking some
information that I found worth mentioning and clarifying.
In particular, how the command behaves with respect to exit codes and
when more than one condition is specified.

Signed-off-by: Valentin Rothberg <vrothberg@redhat.com>
2023-06-23 09:26:30 +02:00
OpenShift Merge Robot
49e0bde2bf
Merge pull request #18946 from Luap99/slirp4netns
use slirp4netns code from c/common
2023-06-22 16:15:18 +02:00
OpenShift Merge Robot
436df1ba1f
Merge pull request #18971 from edsantiago/silence_esrch
StopContainer(): ignore one more conmon warning
2023-06-22 16:10:07 +02:00