summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAge
* Add Windows installer support for upgradesJason T. Greene2022-03-19
| | | | | | Fixes duplicate installer entries after multiple installs Signed-off-by: Jason T. Greene <jason.greene@redhat.com>
* Merge pull request #13560 from n1hility/backport-handle-incompatibleOpenShift Merge Robot2022-03-19
|\ | | | | [v4.0] Backport handling of incompatible machines
| * Handle incompatible machinesJason T. Greene2022-03-18
| | | | | | | | | | | | Start in a reduced mode for recovery, warn, and provide instructions to recreate them Signed-off-by: Jason T. Greene <jason.greene@redhat.com>
| * Fix type-o and cleanup doc punctuationJason T. Greene2022-03-18
| | | | | | | | Signed-off-by: Jason T. Greene <jason.greene@redhat.com>
| * machine rm -f stops and removes machineBrent Baude2022-03-18
| | | | | | | | | | | | | | | | | | | | | | | | If you want to remove a running machine, you can now pass the --force/-f to podman machine rm and the machine will be stopped and removed without confirmations. Fixes: #13448 [NO NEW TESTS NEEDED] Signed-off-by: Brent Baude <bbaude@redhat.com>
| * Improve agent install message to add restart instructionsJason T. Greene2022-03-18
| | | | | | | | Signed-off-by: Jason T. Greene <jason.greene@redhat.com>
| * MacOS improvementsBrent Baude2022-03-18
|/ | | | | | | | * Enable support of virtfs in Podman and darwin. At the time of this writing, it requires a special patch not yet included in upstream qemu. * Prefer to use a specially built qemu to support virtfs. The qemu is installed under libexec/podman. [NO NEW TESTS NEEDED] Signed-off-by: Brent Baude <bbaude@redhat.com>
* Merge pull request #13545 from cevich/backport_gvisor_url_fixOpenShift Merge Robot2022-03-18
|\ | | | | [v4.0] Backport: Fix windows win-sshproxy build
| * Fix windows win-sshproxy buildPaul Holzinger2022-03-17
|/ | | | | | | | | Github no longer supports the unauthenticated git protocol, so switch to using https instead. https://github.blog/2021-09-01-improving-git-protocol-security-github/ Signed-off-by: Paul Holzinger <pholzing@redhat.com>
* Merge pull request #13480 from TomSweeneyRedHat/dev/tsweeney/fujibackOpenShift Merge Robot2022-03-13
|\ | | | | [v4.0] Backport Set default rule at the head of dev config
| * [v4.0] Backport Set default rule at the head of dev configtomsweeneyredhat2022-03-10
|/ | | | | | | | | | | | | | | | | | | Backports: #13421 Set default rule at the head of device configuration by @hshiina The default rule should be set at the head of device configuration. Otherwise, rules for user devices are overridden by the default rule so that any access to the user devices are denied. This has been requested to backport and to include in RHEL 8.6 and 9.0. The exception process is underway. Addresses these BZs for the backport: https://bugzilla.redhat.com/show_bug.cgi?id=2059296 https://bugzilla.redhat.com/show_bug.cgi?id=2062835 Signed-off-by: tomsweeneyredhat <tsweeney@redhat.com>
* Merge pull request #13405 from lsm5/v402OpenShift Merge Robot2022-03-02
|\ | | | | Release v4.0.2
| * Bump to v4.0.3-devLokesh Mandvekar2022-03-02
| | | | | | | | | | | | [NO NEW TESTS NEEDED] Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
| * Bump to v4.0.2v4.0.2Lokesh Mandvekar2022-03-02
| | | | | | | | | | | | [NO NEW TESTS NEEDED] Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
| * Update release notes for v4.0.2Lokesh Mandvekar2022-03-02
|/ | | | | | [NO NEW TESTS NEEDED] Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
* Merge pull request #13392 from baude/v4revertsOpenShift Merge Robot2022-03-01
|\ | | | | V4reverts
| * Revert "use GetRuntimeDir() from c/common"Brent Baude2022-03-01
| | | | | | | | | | | | | | | | This reverts commit fc5cf812c81a10f8a021aae11df5f12ab2a6f6f6. [NO NEW TESTS NEEDED] Signed-off-by: Brent Baude <bbaude@redhat.com>
| * Revert "Option --url and --connection should imply --remote."Brent Baude2022-03-01
|/ | | | | | This reverts commit ca980c2e024bd33f4be3a33bb1dbb22c86bfe072. Signed-off-by: Brent Baude <bbaude@redhat.com>
* Merge pull request #13357 from ↵OpenShift Merge Robot2022-02-28
|\ | | | | | | | | Romain-Geissler-1A/backport-connection-implies-remote Option --url and --connection should imply --remote.
| * Option --url and --connection should imply --remote.Romain Geissler2022-02-26
|/ | | | | | Closes #13242 Signed-off-by: Romain Geissler <romain.geissler@amadeus.com>
* Merge pull request #13329 from mheon/bump_401OpenShift Merge Robot2022-02-23
|\ | | | | Bump to v4.0.1
| * Bump to v4.0.2-devMatthew Heon2022-02-23
| | | | | | | | Signed-off-by: Matthew Heon <mheon@redhat.com>
| * Bump to v4.0.1v4.0.1Matthew Heon2022-02-23
| | | | | | | | Signed-off-by: Matthew Heon <mheon@redhat.com>
| * Update release notes for v4.0.1Matthew Heon2022-02-23
| | | | | | | | Signed-off-by: Matthew Heon <mheon@redhat.com>
| * Fix a potential flake in volume plugins testsMatthew Heon2022-02-23
| | | | | | | | | | | | | | | | | | We could remove the container running the volume plugins, before the containers using the volume plugins; this could cause unmounting the volumes to fail because the plugin could not be contacted. Signed-off-by: Matthew Heon <mheon@redhat.com>
| * Propagate $CONTAINERS_CONF to conmonDavid Gibson2022-02-23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | The CONTAINERS_CONF environment variable can be used to override the configuration file, which is useful for testing. However, at the moment this variable is not propagated to conmon. That means in particular, that conmon can't propagate it back to podman when invoking its --exit-command. The mismatch in configuration between the starting and cleaning up podman instances can cause a variety of errors. This patch also adds two related test cases. One checks explicitly that the correct CONTAINERS_CONF value appears in conmon's environment. The other checks for a possible specific impact of this bug: if we use a nonstandard name for the runtime (even if its path is just a regular crun), then the podman container cleanup invoked at container exit will fail. That has the effect of meaning that a container started with -d --rm won't be correctly removed once complete. Fixes #12917 Signed-off-by: David Gibson <david@gibson.dropbear.id.au>
| * tests: Remove inaccurate commentDavid Gibson2022-02-23
| | | | | | | | | | | | | | | | This comment refers to overiding $PODMAN although the code below does nothing of the sort. Presumbly the comment has been outdated by altering the containers.conf / $CONTAINERS_CONF instead. Signed-off-by: David Gibson <david@gibson.dropbear.id.au>
| * System tests: show one-line config overviewEd Santiago2022-02-23
| | | | | | | | | | | | | | | | | | | | | | | | | | We're running into problems that are impossible to diagnose because we have no idea if the SUT is using netavark or CNI. We've previously run into similar problems with runc/crun, or cgroups 1/2. This adds a one-line 'echo' with important system info. Now, when viewing a full test log, it will be possible to view system settings in one glance. Signed-off-by: Ed Santiago <santiago@redhat.com>
| * provide better error on invalid flagPaul Holzinger2022-02-23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Add a extra `See 'podman command --help'` to the error output. With this patch you now get: ``` $ podman run -h Error: flag needs an argument: 'h' in -h See 'podman run --help' ``` Fixes #13082 Fixes #13002 Signed-off-by: Paul Holzinger <pholzing@redhat.com>
| * use GetRuntimeDir() from c/commonPaul Holzinger2022-02-23
| | | | | | | | | | | | | | | | | | To prevent duplication and potential bugs we should use the same GetRuntimeDir function that is used in c/common. [NO NEW TESTS NEEDED] Signed-off-by: Paul Holzinger <pholzing@redhat.com>
| * kube: honor --build=false and make --build=true by defaultAditya R2022-02-23
| | | | | | | | | | | | | | | | `podman play kube` tries to build images even if `--build` is set to false so lets honor that and make `--build` , `true` by default so it matches the original behviour. Signed-off-by: Aditya R <arajan@redhat.com>
| * system tests: cleanup networks on teardownPaul Holzinger2022-02-23
| | | | | | | | | | | | | | | | When a test which creates a network fail it will not remove the network. The teardown logic should remove the networks. Since there is no --all option for network rm we use network prune --force. Signed-off-by: Paul Holzinger <pholzing@redhat.com>
| * Remove the runtime lockMatthew Heon2022-02-23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This primarily served to protect us against shutting down the Libpod runtime while operations (like creating a container) were happening. However, it was very inconsistently implemented (a lot of our longer-lived functions, like pulling images, just didn't implement it at all...) and I'm not sure how much we really care about this very-specific error case? Removing it also removes a lot of potential deadlocks, which is nice. [NO NEW TESTS NEEDED] Signed-off-by: Matthew Heon <mheon@redhat.com>
| * Don't log errors on removing volumes inuse, if container --volumes-fromDaniel J Walsh2022-02-23
| | | | | | | | | | | | | | | | | | | | | | When removing a container created with a --volumes-from a container created with a built in volume, we complain if the original container still exists. Since this is an expected state, we should not complain about it. Fixes: https://github.com/containers/podman/issues/12808 Signed-off-by: Daniel J Walsh <dwalsh@redhat.com>
| * kube: honor mount propagation modeGiuseppe Scrivano2022-02-23
| | | | | | | | | | | | | | convert the propagation mode specified for the mount to the expected Linux mount option. Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
| * Load ip_tables modules at bootPaul Holzinger2022-02-23
|/ | | | | | | | | | | | | | | | | | Rootless users cannot load the ip_tables module, in fedora 36 this module is no longer loaded by default so we have to add it manually. This is needed because rootless network setup tries to use iptables and if iptables-legacy is used instead of iptables-nft it will fail. To provide a better user experience we will load the module at boot. Note that this is not needed for RHEL because iptables-legacy is not supported on RHEL 8 and newer. [NO NEW TESTS NEEDED] Fixes #12661 Signed-off-by: Paul Holzinger <pholzing@redhat.com>
* Merge pull request #13251 from cevich/new_4.0_vm_imagesOpenShift Merge Robot2022-02-19
|\ | | | | [v4.0] Cirrus: Update VM Images for 4.0 release
| * Cirrus: Disable F34 aka prior-fedora testingChris Evich2022-02-17
| | | | | | | | | | | | | | | | | | | | Podman 4.0 will never be supported in F34, and the use of F35 in CI is temporary until F36 is brought up to speed. Rather than fight with testing issues that will never be fixed/supported, simply disable it. This commit may be reverted at a future date when F36 VM support is added. Signed-off-by: Chris Evich <cevich@redhat.com>
| * Cirrus: Update VM Images for 4.0 releaseChris Evich2022-02-17
|/ | | | | | | | | | This is to ensure VM images for CI, which contain the intended dependency versions to support the podman 4.0 release. Ref: https://github.com/containers/automation_images/pull/114 Signed-off-by: Chris Evich <cevich@redhat.com>
* Merge pull request #13255 from mheon/bump_400_finalOpenShift Merge Robot2022-02-17
|\ | | | | Bump to v4.0.0 final
| * Bump to v4.0.1-devMatthew Heon2022-02-17
| | | | | | | | Signed-off-by: Matthew Heon <matthew.heon@pm.me>
| * Bump to v4.0.0Matthew Heon2022-02-17
| | | | | | | | Signed-off-by: Matthew Heon <matthew.heon@pm.me>
| * Release notes for v4.0.0 finalv4.0.0Matthew Heon2022-02-17
| | | | | | | | Signed-off-by: Matthew Heon <matthew.heon@pm.me>
| * Fix lintMatthew Heon2022-02-17
| | | | | | | | Signed-off-by: Matthew Heon <matthew.heon@pm.me>
| * Fix manifest 4.0 EndpointsJhon Honce2022-02-17
| | | | | | | | | | | | Branch forced 4.0 only endpoints Signed-off-by: Jhon Honce <jhonce@redhat.com>
| * Introduce podman machine init --root=t|f and podman machine set --root=t|fJason T. Greene2022-02-16
| | | | | | | | | | | | Switch default to rootless for mac and windows Signed-off-by: Jason T. Greene <jason.greene@redhat.com>
| * Initial implementation of mac forwarding using a privileged docker sock ↵Jason T. Greene2022-02-16
| | | | | | | | | | | | claim helper Signed-off-by: Jason T. Greene <jason.greene@redhat.com>
| * ignition: propagate proxy settings from a host into a vmesendjer2022-02-16
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Set proxy settings (such as `HTTP_PROXY`, and others) for the whole guest OS with setting up `DefaultEnvironment` with a `systemd` configuration file `default-env.conf`, a `profile.d` scenario file - `default-env.sh` and a `environment.d` configuration file `default-env.conf` The **actual** environment variables are read by podman at a start, then they are encrypted with base64 into a single string and after are provided into a VM through QEMU Firmware Configuration (fw_cfg) Device Inside a VM a systemd service `envset-fwcfg.service` reads the providead encrypted string from fw_cfg, decrypts and then adds to the files - `/etc/systemd/system.conf.d/default-env.conf` - `/etc/profile.d/default-env.sh` - `/etc/environment.d/default-env.conf` At the end this service execute `systemctl daemon-reload` to propagate new variables for systemd manager [NO NEW TESTS NEEDED] Closes #13168 Signed-off-by: esendjer <esendjer@gmail.com>
| * Update to podman4 copr streamJason T. Greene2022-02-16
| | | | | | | | Signed-off-by: Jason T. Greene <jason.greene@redhat.com>
| * Unify ls --filter docs for networks and podsPatrycja Guzik2022-02-16
| | | | | | | | | | | | Signed-off-by: Patrycja Guzik <patrycja.k.guzik@gmail.com> #13078 follow-up