spiegel_podman/pkg
Paul Holzinger 3280da0500
fix race conditions in start/attach logic
The current code did something like this:
lock()
getState()
unlock()

if state != running
  lock()
  getState() == running -> error
  unlock()

This of course is wrong because between the first unlock() and second
lock() call another process could have modified the state. This meant
that sometimes you would get a weird error on start because the internal
setup errored as the container was already running.

In general any state check without holding the lock is incorrect and
will result in race conditions. As such refactor the code to combine
both StartAndAttach and Attach() into one function that can handle both.
With that we can move the running check into the locked code.

Also use typed error for this specific error case then the callers can
check and ignore the specific error when needed. This also allows us to
fix races in the compat API that did a similar racy state check.

This commit changes slightly how we output the result, previously a
start on already running container would never print the id/name of the
container which is confusing and sort of breaks idempotence. Now it will
include the output except when --all is used. Then it only reports the
ids that were actually started.

Fixes #23246

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2024-07-12 15:11:34 +02:00
..
annotations Removing CRI-O related annotations 2024-03-12 14:56:06 +01:00
api fix race conditions in start/attach logic 2024-07-12 15:11:34 +02:00
auth Replace strings.SplitN with strings.Cut 2024-01-11 13:50:15 +00:00
autoupdate Bump Go module to v5 2024-02-08 09:35:39 -05:00
bindings CI: use local registry, part 2 of 3: fix tests 2024-07-11 04:39:45 -06:00
channel bump golangci-lint to v1.50.1 2022-12-15 13:39:56 +01:00
checkpoint restore: fix container restore into pod 2024-06-20 13:24:53 +01:00
copy Bump Go module to v5 2024-02-08 09:35:39 -05:00
criu chore: delete obsolete // +build lines 2024-01-04 11:53:38 +02:00
ctime chore: delete obsolete // +build lines 2024-01-04 11:53:38 +02:00
domain fix race conditions in start/attach logic 2024-07-12 15:11:34 +02:00
emulation chore: delete obsolete // +build lines 2024-01-04 11:53:38 +02:00
env pkg/env.Join(): don't modify passed-in maps 2024-02-29 11:47:44 -05:00
errorhandling Fix typos 2023-02-11 18:23:24 +01:00
farm chore: fix function names in comment 2024-04-24 12:07:38 +08:00
fileserver Bump Go module to v5 2024-02-08 09:35:39 -05:00
inspect Bump Go module to v5 2024-02-08 09:35:39 -05:00
k8s.io Bump Go module to v5 2024-02-08 09:35:39 -05:00
lookup Cease using deprecated runc userlookup 2024-02-02 11:02:43 -05:00
machine Merge pull request #23223 from baude/libkrundoc 2024-07-09 14:45:51 +00:00
namespaces Replace strings.SplitN with strings.Cut 2024-01-11 13:50:15 +00:00
parallel Bump Go module to v5 2024-02-08 09:35:39 -05:00
ps podman ps: show exposed ports under PORTS as well 2024-04-10 14:24:23 +02:00
rctl Replace strings.SplitN with strings.Cut 2024-01-11 13:50:15 +00:00
rootless pkg/rootless: simplify reexec for container code 2024-07-08 13:28:31 +02:00
seccomp pkg: switch to golang native error wrapping 2022-07-08 08:54:47 +02:00
selinux Fix SELinux functions names to not be repetitive 2020-04-23 15:57:34 -04:00
signal refacto: unknown signal return signal number without prefix 2024-02-28 19:45:03 +01:00
specgen specgen: parse devices even with privileged set 2024-07-01 11:46:34 +02:00
specgenutil podman run use pod userns even with --pod-id-file 2024-06-24 17:18:08 +02:00
specgenutilexternal Quadlet container mount - support non key=val options 2023-09-27 16:20:00 +03:00
systemd feat(quadlet): log option handling 2024-06-30 18:21:47 +10:00
terminal Fix Lint on Windows and enable the job 2024-02-20 08:06:18 -05:00
timetype Replace strings.SplitN with strings.Cut 2024-01-11 13:50:15 +00:00
trust pkg/trust: use fileutils.(Le|E)xists 2024-04-19 09:52:14 +02:00
util specgen: parse devices even with privileged set 2024-07-01 11:46:34 +02:00