SUSE 5183 Published by

A conmon, libcontainers-common, libseccomp, podman security update has been released for openSUSE Leap 15.3.



openSUSE-SU-2022:23018-1: moderate: Security update for conmon, libcontainers-common, libseccomp, podman


openSUSE Security Update: Security update for conmon, libcontainers-common, libseccomp, podman
______________________________________________________________________________

Announcement ID: openSUSE-SU-2022:23018-1
Rating: moderate
References: #1176804 #1177598 #1181640 #1182998 #1188520
#1188914 #1193166 #1193273 SLE-22714
Cross-References: CVE-2020-14370 CVE-2020-15157 CVE-2021-20199
CVE-2021-20291 CVE-2021-3602 CVE-2021-4024
CVE-2021-41190
CVSS scores:
CVE-2020-14370 (SUSE): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVE-2020-15157 (NVD) : 6.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
CVE-2020-15157 (SUSE): 6.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
CVE-2021-20199 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVE-2021-20199 (SUSE): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CVE-2021-20291 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2021-20291 (SUSE): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2021-3602 (SUSE): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CVE-2021-4024 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
CVE-2021-4024 (SUSE): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
CVE-2021-41190 (NVD) : 3 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N
CVE-2021-41190 (SUSE): 5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

Affected Products:
openSUSE Leap 15.3
______________________________________________________________________________

An update that solves 7 vulnerabilities, contains one
feature and has one errata is now available.

Description:

This update for conmon, libcontainers-common, libseccomp, podman fixes the
following issues:

podman was updated to 3.4.4.

Security issues fixed:

- fix CVE-2021-41190 [bsc#1193273], opencontainers: OCI manifest and index
parsing confusion
- fix CVE-2021-4024 [bsc#1193166], podman machine spawns gvproxy with
port binded to all IPs
- fix CVE-2021-20199 [bsc#1181640], Remote traffic to rootless containers
is seen as orginating from localhost

- Add: Provides: podman:/usr/bin/podman-remote subpackage for a clearer
upgrade path from podman < 3.1.2

Update to version 3.4.4:

* Bugfixes

- Fixed a bug where the podman exec command would, under some
circumstances, print a warning message about failing to move conmon
to the appropriate cgroup (#12535).
- Fixed a bug where named volumes created as part of container
creation (e.g. podman run --volume avolume:/a/mountpoint or similar)
would be mounted with incorrect permissions (#12523).
- Fixed a bug where the podman-remote create and podman-remote run
commands did not properly handle the --entrypoint="" option (to
clear the container's entrypoint) (#12521).

- Update to version 3.4.3:

* Security

- This release addresses CVE-2021-4024, where the podman machine
command opened the gvproxy API (used to forward ports to podman
machine VMs) to the public internet on port 7777.
- This release addresses CVE-2021-41190, where incomplete
specification of behavior regarding image manifests could lead to
inconsistent decoding on different clients.

* Features

- The --secret type=mount option to podman create and podman run
supports a new option, target=, which specifies where in the
container the secret will be mounted (#12287).

* Bugfixes

- Fixed a bug where rootless Podman would occasionally print warning
messages about failing to move the pause process to a new cgroup
(#12065).
- Fixed a bug where the podman run and podman create commands would,
when pulling images, still require TLS even with registries set to
Insecure via config file (#11933).
- Fixed a bug where the podman generate systemd command generated
units that depended on multi-user.target, which has been removed
from some distributions (#12438).
- Fixed a bug where Podman could not run containers with images that
had /etc/ as a symlink (#12189).
- Fixed a bug where the podman logs -f command would, when using the
journald logs backend, exit immediately if the container had
previously been restarted (#12263).
- Fixed a bug where, in containers on VMs created by podman machine,
the host.containers.internal name pointed to the VM, not the host
system (#11642).
- Fixed a bug where containers and pods created by the podman play
kube command in VMs managed by podman machine would not
automatically forward ports from the host machine (#12248).
- Fixed a bug where podman machine init would fail on OS X when GNU
Coreutils was installed (#12329).
- Fixed a bug where podman machine start would exit before SSH on the
started VM was accepting connections (#11532).
- Fixed a bug where the podman run command with signal proxying
(--sig-proxy) enabled could print an error if it attempted to send a
signal to a container that had just exited (#8086).
- Fixed a bug where the podman stats command would not return correct
information for containers running Systemd as PID1 (#12400).
- Fixed a bug where the podman image save command would fail on OS X
when writing the image to STDOUT (#12402).
- Fixed a bug where the podman ps command did not properly handle PS
arguments which contained whitespace (#12452).
- Fixed a bug where the podman-remote wait command could fail to
detect that the container exited and return an error under some
circumstances (#12457).
- Fixed a bug where the Windows MSI installer for podman-remote would
break the PATH environment variable by adding an extra " (#11416).

* API

- The Libpod Play Kube endpoint now also accepts ConfigMap YAML as
part of its payload, and will use provided any ConfigMap to
configure provided pods and services.
- Fixed a bug where the Compat Create endpoint for Containers would
not always create the container's working directory if it did not
exist (#11842).
- Fixed a bug where the Compat Create endpoint for Containers returned
an incorrect error message with 404 errors when the requested image
was not found (#12315).
- Fixed a bug where the Compat Create endpoint for Containers did not
properly handle the HostConfig.Mounts field (#12419).
- Fixed a bug where the Compat Archive endpoint for Containers did not
properly report errors when the operation failed (#12420).
- Fixed a bug where the Compat Build endpoint for Images ignored the
layers query parameter (for caching intermediate layers from the
build) (#12378).
- Fixed a bug where the Compat Build endpoint for Images did not
report errors in a manner compatible with Docker (#12392).
- Fixed a bug where the Compat Build endpoint for Images would fail to
build if the context directory was a symlink (#12409).
- Fixed a bug where the Compat List endpoint for Images included
manifest lists (and not just images) in returned results (#12453).

- Update to version 3.4.2:

* Fixed a bug where podman tag could not tag manifest lists (#12046).
* Fixed a bug where built-in volumes specified by images would not be
created correctly under some circumstances.
* Fixed a bug where, when using Podman Machine on OS X, containers in
pods did not have working port forwarding from the host (#12207).
* Fixed a bug where the podman network reload command command on
containers using the slirp4netns network mode and the rootlessport
port forwarding driver would make an unnecessary attempt to restart
rootlessport
on containers that did not forward ports.
* Fixed a bug where the podman generate kube command would generate YAML
including some unnecessary (set to default) fields (e.g. empty SELinux
and DNS configuration blocks, and the privileged flag when set to
false) (#11995).
* Fixed a bug where the podman pod rm command could, if interrupted at
the right moment, leave a reference to an already-removed infra
container behind (#12034).
* Fixed a bug where the podman pod rm command would not remove pods with
more than one container if all containers save for the infra container
were stopped unless --force was specified (#11713).
* Fixed a bug where the --memory flag to podman run and podman create
did not accept a limit of 0 (which should specify unlimited memory)
(#12002).
* Fixed a bug where the remote Podman client's podman build command
could attempt to build a Dockerfile in the working directory of the
podman system service instance instead of the Dockerfile specified by
the user (#12054).
* Fixed a bug where the podman logs --tail command could function
improperly (printing more output than requested) when the journald log
driver was used.
* Fixed a bug where containers run using the slirp4netns network mode
with IPv6 enabled would not have IPv6 connectivity until several
seconds after they started (#11062).
* Fixed a bug where some Podman commands could cause an extra
dbus-daemon process to be created (#9727).
* Fixed a bug where rootless Podman would sometimes print warnings about
a failure to move the pause process into a given CGroup (#12065).
* Fixed a bug where the checkpointed field in podman inspect on a
container was not set to false after a container was restored.
* Fixed a bug where the podman system service command would print
overly-verbose logs about request IDs (#12181).
* Fixed a bug where Podman could, when creating a new container without
a name explicitly specified by the user, sometimes use an
auto-generated name already in use by another container if multiple
containers were being created in parallel (#11735).

Update to version 3.4.1:

* Bugfixes

- Fixed a bug where podman machine init could, under some
circumstances, create invalid machine configurations which could not
be started (#11824).
- Fixed a bug where the podman machine list command would not properly
populate some output fields.
- Fixed a bug where podman machine rm could leave dangling sockets
from the removed machine (#11393).
- Fixed a bug where podman run --pids-limit=-1 was not supported (it
now sets the PID limit in the container to unlimited) (#11782).
- Fixed a bug where podman run and podman attach could throw errors
about a closed network connection when STDIN was closed by the
client (#11856).
- Fixed a bug where the podman stop command could fail when run on a
container that had another podman stop command run on it previously.
- Fixed a bug where the --sync flag to podman ps was nonfunctional.
- Fixed a bug where the Windows and OS X remote clients' podman stats
command would fail (#11909).
- Fixed a bug where the podman play kube command did not properly
handle environment variables whose values contained an = (#11891).
- Fixed a bug where the podman generate kube command could generate
invalid annotations when run on containers with volumes that use
SELinux relabelling (:z or :Z) (#11929).
- Fixed a bug where the podman generate kube command would generate
YAML including some unnecessary (set to default) fields (e.g. user
and group, entrypoint, default protocol for forwarded ports)
(#11914, #11915, and #11965).
- Fixed a bug where the podman generate kube command could, under some
circumstances, generate YAML including an invalid targetPort field
for forwarded ports (#11930).
- Fixed a bug where rootless Podman's podman info command could, under
some circumstances, not read available CGroup controllers (#11931).
- Fixed a bug where podman container checkpoint --export would fail to
checkpoint any container created with --log-driver=none (#11974).

* API

- Fixed a bug where the Compat Create endpoint for Containers could
panic when no options were passed to a bind mount of tmpfs (#11961).

Update to version 3.4.0:

* Features

- Pods now support init containers! Init containers are containers
which run before the rest of the pod starts. There are two types of
init containers: "always", which always run before the pod is
started, and "once", which only run the first time the pod starts
and are subsequently removed. They can be added using the podman
create command's --init-ctr option.
- Support for init containers has also been added to podman play kube
and podman generate kube - init containers contained in Kubernetes
YAML will be created as Podman init containers, and YAML generated
by Podman will include any init containers created.
- The podman play kube command now supports building images. If the
--build option is given and a directory with the name of the
specified image exists in the current working directory and contains
a valid Containerfile or Dockerfile, the image will be built and
used for the container.
- The podman play kube command now supports a new option, --teardown,
which removes any pods and containers created by the given
Kubernetes YAML.
- The podman generate kube command now generates annotations for
SELinux mount options on volume (:z and :Z) that are respected by
the podman play kube command.
- A new command has been added, podman pod logs, to return logs for
all containers in a pod at the same time.
- Two new commands have been added, podman volume export (to export a
volume to a tar file) and podman volume import) (to populate a
volume from a given tar file).
- The podman auto-update command now supports simple rollbacks. If a
container fails to start after an automatic update, it will be
rolled back to the previous image and restarted again.
- Pods now share their user namespace by default, and the podman pod
create command now supports the --userns option. This allows
rootless pods to be created with the --userns=keep-id option.
- The podman pod ps command now supports a new filter with its
--filter option, until, which returns pods created before a given
timestamp.
- The podman image scp command has been added. This command allows
images to be transferred between different hosts.
- The podman stats command supports a new option, --interval, to
specify the amount of time before the information is refreshed.
- The podman inspect command now includes ports exposed (but not
published) by containers (e.g. ports from --expose when
--publish-all is not specified).
- The podman inspect command now has a new boolean value,
Checkpointed, which indicates that a container was stopped as a
result of a podman container checkpoint operation.
- Volumes created by podman volume create now support setting quotas
when run atop XFS. The size and inode options allow the maximum size
and maximum number of inodes consumed by a volume to be limited.
- The podman info command now outputs information on what log drivers,
network drivers, and volume plugins are available for use (#11265).
- The podman info command now outputs the current log driver in use,
and the variant and codename of the distribution in use.
- The parameters of the VM created by podman machine init (amount of
disk space, memory, CPUs) can now be set in containers.conf.
- The podman machine ls command now shows additional information
(CPUs, memory, disk size) about VMs managed by podman machine.
- The podman ps command now includes healthcheck status in container
state for containers that have healthchecks (#11527).

* Changes

- The podman build command has a new alias, podman buildx, to improve
compatibility with Docker. We have already added support for many
docker buildx flags to podman build and aim to continue to do so.
- Cases where Podman is run without a user session or a writable
temporary files directory will now produce better error messages.
- The default log driver has been changed from file to journald. The
file driver did not properly support log rotation, so this should
lead to a better experience. If journald is not available on the
system, Podman will automatically revert to the file.
- Podman no longer depends on ip for removing networks (#11403).
- The deprecated --macvlan flag to podman network create now warns
when it is used. It will be removed entirely in the Podman 4.0
release.
- The podman machine start command now prints a message when the VM is
successfully started.
- The podman stats command can now be used on containers that are
paused.
- The podman unshare command will now return the exit code of the
command that was run in the user namespace (assuming the command was
successfully run).
- Successful healthchecks will no longer add a healthy line to the
system log to reduce log spam.
- As a temporary workaround for a lack of shortname prompts in the
Podman remote client, VMs created by podman machine now default to
only using the docker.io registry.

* Bugfixes

- Fixed a bug where whitespace in the definition of sysctls
(particularly default sysctls specified in containers.conf) would
cause them to be parsed incorrectly.
- Fixed a bug where the Windows remote client improperly validated
volume paths (#10900).
- Fixed a bug where the first line of logs from a container run with
the journald log driver could be skipped.
- Fixed a bug where images created by podman commit did not include
ports exposed by the container.
- Fixed a bug where the podman auto-update command would ignore the
io.containers.autoupdate.authfile label when pulling images (#11171).
- Fixed a bug where the --workdir option to podman create and podman
run could not be set to a directory where a volume was mounted
(#11352).
- Fixed a bug where systemd socket-activation did not properly work
with systemd-managed Podman containers (#10443).
- Fixed a bug where environment variable secrets added to a container
were not available to exec sessions launched in the container.
- Fixed a bug where rootless containers could fail to start the
rootlessport port-forwarding service when XDG_RUNTIME_DIR was set to
a long path.
- Fixed a bug where arguments to the --systemd option to podman create
and podman run were case-sensitive (#11387).
- Fixed a bug where the podman manifest rm command would also remove
images referenced by the manifest, not just the manifest itself
(#11344).
- Fixed a bug where the Podman remote client on OS X would not
function properly if the TMPDIR environment variable was not set
(#11418).
- Fixed a bug where the /etc/hosts file was not guaranteed to contain
an entry for localhost (this is still not guaranteed if --net=host
is used; such containers will exactly match the host's /etc/hosts)
(#11411).
- Fixed a bug where the podman machine start command could print
warnings about unsupported CPU features (#11421).
- Fixed a bug where the podman info command could segfault when
accessing cgroup information.
- Fixed a bug where the podman logs -f command could hang when a
container exited (#11461).
- Fixed a bug where the podman generate systemd command could not be
used on containers that specified a restart policy (#11438).
- Fixed a bug where the remote Podman client's podman build command
would fail to build containers if the UID and GID on the client were
higher than 65536 (#11474).
- Fixed a bug where the remote Podman client's podman build command
would fail to build containers if the context directory was a
symlink (#11732).
- Fixed a bug where the --network flag to podman play kube was not
properly parsed when a non-bridge network configuration was
specified.
- Fixed a bug where the podman inspect command could error when the
container being inspected was removed as it was being inspected
(#11392).
- Fixed a bug where the podman play kube command ignored the default
pod infra image specified in containers.conf.
- Fixed a bug where the --format option to podman inspect was
nonfunctional under some circumstances (#8785).
- Fixed a bug where the remote Podman client's podman run and podman
exec commands could skip a byte of output every 8192 bytes (#11496).
- Fixed a bug where the podman stats command would print nonsensical
results if the container restarted while it was running (#11469).
- Fixed a bug where the remote Podman client would error when STDOUT
was redirected on a Windows client (#11444).
- Fixed a bug where the podman run command could return 0 when the
application in the container exited with 125 (#11540).
- Fixed a bug where containers with --restart=always set using the
rootlessport port-forwarding service could not be restarted
automatically.
- Fixed a bug where the --cgroups=split option to podman create and
podman run was silently discarded if the container was part of a pod.
- Fixed a bug where the podman container runlabel command could fail
if the image name given included a tag.
- Fixed a bug where Podman could add an extra 127.0.0.1 entry to
/etc/hosts under some circumstances (#11596).
- Fixed a bug where the remote Podman client's podman untag command
did not properly handle tags including a digest (#11557).
- Fixed a bug where the --format option to podman ps did not properly
support the table argument for tabular output.
- Fixed a bug where the --filter option to podman ps did not properly
handle filtering by healthcheck status (#11687).
- Fixed a bug where the podman run and podman start --attach commands
could race when retrieving the exit code of a container that had
already been removed resulting in an error (e.g. by an external
podman rm -f) (#11633).
- Fixed a bug where the podman generate kube command would add default
environment variables to generated YAML.
- Fixed a bug where the podman generate kube command would add the
default CMD from the image to generated YAML (#11672).
- Fixed a bug where the podman rm --storage command could fail to
remove containers under some circumstances (#11207).
- Fixed a bug where the podman machine ssh command could fail when run
on Linux (#11731).
- Fixed a bug where the podman stop command would error when used on a
container that was already stopped (#11740).
- Fixed a bug where renaming a container in a pod using the podman
rename command, then removing the pod using podman pod rm, could
cause Podman to believe the new name of the container was
permanently in use, despite the container being removed (#11750).

* API

- The Libpod Pull endpoint for Images now has a new query parameter,
quiet, which (when set to true) suppresses image pull progress
reports (#10612).
- The Compat Events endpoint now includes several deprecated fields
from the Docker v1.21 API for improved compatibility with older
clients.
- The Compat List and Inspect endpoints for Images now prefix image
IDs with sha256: for improved Docker compatibility (#11623).
- The Compat Create endpoint for Containers now properly sets defaults
for healthcheck-related fields (#11225).
- The Compat Create endpoint for Containers now supports volume
options provided by the Mounts field (#10831).
- The Compat List endpoint for Secrets now supports a new query
parameter, filter, which allows returned results to be filtered.
- The Compat Auth endpoint now returns the correct response code (500
instead of 400) when logging into a registry fails.
- The Version endpoint now includes information about the OCI runtime
and Conmon in use (#11227).
- Fixed a bug where the X-Registry-Config header was not properly
handled, leading to errors when pulling images (#11235).
- Fixed a bug where invalid query parameters could cause a null
pointer dereference when creating error messages.
- Logging of API requests and responses at trace level has been
greatly improved, including the addition of an X-Reference-Id header
to correlate requests and responses (#10053).

Update to version 3.3.1:

* Bugfixes

- Fixed a bug where unit files created by podman generate systemd
could not cleanup shut down containers when stopped by systemctl
stop (#11304).
- Fixed a bug where podman machine commands would not properly locate
the gvproxy binary in some circumstances.
- Fixed a bug where containers created as part of a pod using the
--pod-id-file option would not join the pod's network namespace
(#11303).
- Fixed a bug where Podman, when using the systemd cgroups driver,
could sometimes leak dbus sessions.
- Fixed a bug where the until filter to podman logs and podman events
was improperly handled, requiring input to be negated (#11158).
- Fixed a bug where rootless containers using CNI networking run on
systems using systemd-resolved for DNS would fail to start if
resolved symlinked /etc/resolv.conf to an absolute path (#11358).

* API

- A large number of potential file descriptor leaks from improperly
closing client connections have been fixed.

Update to version 3.3.0:

* Fix network aliases with network id
* machine: compute sha256 as we read the image file
* machine: check for file exists instead of listing directory
* pkg/bindings/images.nTar(): slashify hdr.Name values
* Volumes: Only remove from DB if plugin removal succeeds
* For compatibility, ignore Content-Type
* [v3.3] Bump c/image 5.15.2, buildah v1.22.3
* Implement SD-NOTIFY proxy in conmon
* Fix rootless cni dns without systemd stub resolver
* fix rootlessport flake
* Skip stats test in CGv1 container environments
* Fix AVC denials in tests of volume mounts
* Restore buildah-bud test requiring new images
* Revert ".cirrus.yml: use fresh images for all VMs"
* Fix device tests using ls test files
* Enhance priv. dev. check
* Workaround host availability of /dev/kvm
* Skip cgroup-parent test due to frequent flakes
* Cirrus: Fix not uploading logformatter html

Switch to crun (bsc#1188914)

Update to version 3.2.3:

* Bump to v3.2.3
* Update release notes for v3.2.3
* vendor containers/common@v0.38.16
* vendor containers/buildah@v1.21.3
* Fix race conditions in rootless cni setup
* CNI-in-slirp4netns: fix bind-mount for
/run/systemd/resolve/stub-resolv.conf
* Make rootless-cni setup more robust
* Support uid,gid,mode options for secrets
* vendor containers/common@v0.38.15
* [CI:DOCS] podman search: clarify that results depend on implementation
* vendor containers/common@v0.38.14
* vendor containers/common@v0.38.13
* [3.2] vendor containers/common@v0.38.12
* Bump README to v3.2.2
* Bump to v3.2.3-dev

- Update to version 3.2.2:
* Bump to v3.2.2
* fix systemcontext to use correct TMPDIR
* Scrub podman commands to use report package
* Fix volumes with uid and gid options
* Vendor in c/common v0.38.11
* Initial release notes for v3.2.2
* Fix restoring of privileged containers
* Fix handling of podman-remote build --device
* Add support for podman remote build -f - .
* Fix panic condition in cgroups.getAvailableControllers
* Fix permissions on initially created named volumes
* Fix building static podman-remote
* add correct slirp ip to /etc/hosts
* disable tty-size exec checks in system tests
* Fix resize race with podman exec -it
* Fix documentation of the --format option of podman push
* Fix systemd-resolved detection.
* Health Check is not handled in the compat LibpodToContainerJSON
* Do not use inotify for OCICNI
* getContainerNetworkInfo: lock netNsCtr before sync
* [NO TESTS NEEDED] Create /etc/mtab with the correct ownership
* Create the /etc/mtab file if does not exists
* [v3.2] cp: do not allow dir->file copying
* create: support images with invalid platform
* vendor containers/common@v0.38.10
* logs: k8s-file: restore poll sleep
* logs: k8s-file: fix spurious error logs
* utils: move message from warning to debug
* Bump to v3.2.2-dev

- Update to version 3.2.1:
* Bump to v3.2.1
* Updated release notes for v3.2.1
* Fix network connect race with docker-compose
* Revert "Ensure minimum API version is set correctly in tests"
* Fall back to string for dockerfile parameter
* remote events: fix --stream=false
* [CI:DOCS] fix incorrect network remove api doc
* remote: always send resize before the container starts
* remote events: support labels
* remote pull: cancel pull when connection is closed
* Fix network prune api docs
* Improve systemd-resolved detection
* logs: k8s-file: fix race
* Fix image prune --filter cmd behavior
* Several shell completion fixes
* podman-remote build should handle -f option properly
* System tests: deal with crun 0.20.1
* Fix build tags for pkg/machine...
* Fix pre-checkpointing
* container: ignore named hierarchies
* [v3.2] vendor containers/common@v0.38.9
* rootless: fix fast join userns path
* [v3.2] vendor containers/common@v0.38.7
* [v3.2] vendor containers/common@v0.38.6
* Correct qemu options for Intel macs
* Ensure minimum API version is set correctly in tests
* Bump to v3.2.1-dev

- Update to version 3.2.0:
* Bump to v3.2.0
* Fix network create macvlan with subnet option
* Final release notes updates for v3.2.0
* add ipv6 nameservers only when the container has ipv6 enabled
* Use request context instead of background
* [v.3.2] events: support disjunctive filters
* System tests: add :Z to volume mounts
* generate systemd: make mounts portable
* vendor containers/storage@v1.31.3
* vendor containers/common@v0.38.5
* Bump to v3.2.0-dev
* Bump to v3.2.0-RC3
* Update release notes for v3.2.0-RC3
* Fix race on podman start --all
* Fix race condition in running ls container in a pod
* docs: --cert-dir: point to containers-certs.d(5)
* Handle hard links in different directories
* Improve OCI Runtime error
* Handle hard links in remote builds
* Podman info add support for status of cgroup controllers
* Drop container does not exist on removal to debugf
* Downgrade API service routing table logging
* add libimage events
* docs: generate systemd: XDG_RUNTIME_DIR
* Fix problem copying files when container is in host pid namespace
* Bump to v3.2.0-dev
* Bump to v3.2.0-RC2
* update c/common
* Update Cirrus DEST_BRANCH to v3.2
* Updated vendors of c/image, c/storage, Buildah
* Initial release notes for v3.2.0-RC2
* Add script for identifying commits in release branches
* Add host.containers.internal entry into container's etc/hosts
* image prune: remove unused images only with `--all`
* podman network reload add rootless support
* Use more recent `stale` release...
* network tutorial: update with rootless cni changes
* [CI:DOCS] Update first line in intro page
* Use updated VM images + updated automation tooling
* auto-update service: prune images
* make vendor
* fix system upgrade tests
* Print "extracting" only on compressed file
* podman image tree: restore previous behavior
* fix network restart always test
* fix incorrect log driver in podman container image
* Add support for cli network prune --filter flag
* Move filter parsing to common utils
* Bump github.com/containers/storage from 1.30.2 to 1.30.3
* Update nix pin with `make nixpkgs`
* [CI:DOCS] hack/bats - new helper for running system tests
* fix restart always with slirp4netns
* Bump github.com/opencontainers/runc from 1.0.0-rc93 to 1.0.0-rc94
* Bump github.com/coreos/go-systemd/v22 from 22.3.1 to 22.3.2
* Add host.serviceIsRemote to podman info results
* Add client disconnect to build handler loop
* Remove obsolete skips
* Fix podman-remote build --rm=false ...
* fix: improved "containers/{name}/wait" endpoint
* Bump github.com/containers/storage from 1.30.1 to 1.30.2
* Add envars to the generated systemd unit
* fix: use UTC Time Stamps in response JSON
* fix container startup for empty pidfile
* Kube like pods should share ipc,net,uts by default
* fix: compat API "images/get" for multiple images
* Revert escaped double dash man page flag syntax
* Report Download complete in Compatibility mode
* Add documentation on short-names
* Bump github.com/docker/docker
* Adds support to preserve auto update labels in generate and play kube
* [CI:DOCS] Stop conversion of `--` into en dash
* Revert Patch to relabel if selinux not enabled
* fix per review request
* Add support for environment variable secrets
* fix pre review request
* Fix infinite loop in isPathOnVolume
* Add containers.conf information for changing defaults
* CI: run rootless tests under ubuntu
* Fix wrong macvlan PNG in networking doc.
* Add restart-policy to container filters & --filter to podman start
* Fixes docker-compose cannot set static ip when use ipam
* channel: simplify implementation
* build: improve regex for iidfile
* Bump github.com/onsi/gomega from 1.11.0 to 1.12.0
* cgroup: fix rootless --cgroup-parent with pods
* fix: docker APIv2 `images/get`
* codespell cleanup
* Minor podmanimage docs updates.
* Fix handling of runlabel IMAGE and NAME
* Bump to v3.2.0-dev
* Bump to v3.2.0-rc1
* rootless: improve automatic range split
* podman: set volatile storage flag for --rm containers
* Bump github.com/onsi/ginkgo from 1.16.1 to 1.16.2
* Bump github.com/containers/image/v5 from 5.11.1 to 5.12.0
* migrate Podman to containers/common/libimage
* Add filepath glob support to --security-opt unmask
* Force log_driver to k8s-file for containers in containers
* add --mac-address to podman play kube
* compat api: Networks must be empty instead of null
* System tests: honor $OCI_RUNTIME (for CI)
* is this a bug?
* system test image: add arm64v8 image
* Fix troubleshooting documentation on handling sublemental groups.
* Add --all to podman start
* Fix variable reference typo. in multi-arch image action
* cgroup: always honor --cgroup-parent with cgroupfs
* Bump github.com/uber/jaeger-client-go
* Don't require tests for github-actions & metadata
* Detect if in podman machine virtual vm
* Fix multi-arch image workflow typo
* [CI:DOCS] Add titles to remote docs (windows)
* Remove unused VolumeList* structs
* Cirrus: Update F34beta -> F34
* Update container image docs + fix unstable execution
* Bump github.com/containers/storage from 1.30.0 to 1.30.1
* TODO complete
* Docker returns 'die' status rather then 'died' status
* Check if another VM is running on machine start
* [CI:DOCS] Improve titles of command HTML pages
* system tests: networking: fix another race condition
* Use seccomp_profile as default profile if defined in containers.conf
* Bump github.com/json-iterator/go from 1.1.10 to 1.1.11
* Vendored
* Autoupdate local label functional
* System tests: fix two race conditions
* Add more documentation on conmon
* Allow docker volume create API to pass without name
* Cirrus: Update Ubuntu images to 21.04
* Skip blkio-weight test when no kernel BFQ support
* rootless: Tell the user what was led to the error, not just what it is
* Add troubleshooting advice about the --userns option.
* Fix images prune filter until
* Fix logic for pushing stable multi-arch images
* Fixes generate kube incorrect when bind-mounting "/" and "/root"
* libpod/image: unit tests: don't use system's registries.conf.d
* runtime: create userns when CAP_SYS_ADMIN is not present
* rootless: attempt to copy current mappings first
* [CI:DOCS] Restore missing content to manpages
* [CI:DOCS] Fix Markdown layout bugs
* Fix podman ps --filter ancestor to match exact ImageName/ImageID
* Add machine-enabled to containers.conf for machine
* Several multi-arch image build/push fixes
* Add podman run --timeout option
* Parse slirp4netns net options with compat api
* Fix rootlesskit port forwarder with custom slirp cidr
* Fix removal race condition in ListContainers
* Add github-action workflow to build/push multi-arch
* rootless: if root is not sub?id raise a debug message
* Bump github.com/containers/common from 0.36.0 to 0.37.0
* Add go template shell completion for --format
* Add --group-add keep-groups: suplimentary groups into container
* Fixes from make codespell
* Typo fix to usage text of --compress option
* corrupt-image test: fix an oops
* Add --noheading flag to all list commands
* Bump github.com/containers/storage from 1.29.0 to 1.30.0
* Bump github.com/containers/image/v5 from 5.11.0 to 5.11.1
* [CI:DOCS] Fix Markdown table layout bugs
* podman-remote should show podman.sock info
* rmi: don't break when the image is missing a manifest
* [CI:DOCS] Rewrite --uidmap doc in podman-create.1.md and
podman-run.1.md
* Add support for CDI device configuration
* [CI:DOCS] Add missing dash to verbose option
* Bump github.com/uber/jaeger-client-go
* Remove an advanced layer diff function
* Ensure mount destination is clean, no trailing slash
* add it for inspect pidfile
* [CI:DOCS] Fix introduction page typo
* support pidfile on container restore
* fix start it
* skip pidfile test on remote
* improve document
* set pidfile default value int containerconfig
* add pidfile in inspection
* add pidfile it for container start
* skip pidfile it on remote
* Modify according to comments
* WIP: drop test requirement
* runtime: bump required conmon version
* runtime: return findConmon to libpod
* oci: drop ExecContainerCleanup
* oci: use `--full-path` option for conmon
* use AttachSocketPath when removing conmon files
* hide conmon-pidfile flag on remote mode
* Fix possible panic in libpod/image/prune.go
* add --ip to podman play kube
* add flag autocomplete
* add ut
* add flag "--pidfile" for podman create/run
* Add network bindings tests: remove and list
* Fix build with GO111MODULE=off
* system tests: build --pull-never: deal with flakes
* compose test: diagnose flakes v3
* podman play kube apply correct log driver
* Fixes podman-remote save to directories does not work
* Bump github.com/rootless-containers/rootlesskit from 0.14.1 to 0.14.2
* Update documentation of podman-run to reflect volume "U" option
* Fix flake on failed podman-remote build : try 2
* compose test: ongoing efforts to diagnose flakes
* Test that we don't error out on advertised --log-level values
* At trace log level, print error text using %+v instead of %v
* pkg/errorhandling.JoinErrors: don't throw away context for lone errors
* Recognize --log-level=trace
* Fix flake on failed podman-remote build
* System tests: fix racy podman-inspect
* Fixes invalid expression in save command
* Bump github.com/containers/common from 0.35.4 to 0.36.0
* Update nix pin with `make nixpkgs`
* compose test: try to get useful data from flakes
* Remove in-memory state implementation
* Fix message about runtime to show only the actual runtime
* System tests: setup: better cleanup of stray images
* Bump github.com/containers/ocicrypt from 1.1.0 to 1.1.1
* Reflect current state of prune implementation in docs
* Do not delete container twice
* [CI:DOCS] Correct status code for /pods/create
* vendor in containers/storage v1.29.0
* cgroup: do not set cgroup parent when rootless and cgroupfs
* Overhaul Makefile binary and release worflows
* Reorganize Makefile with sections and guide
* Simplify Makefile help target
* Don't shell to obtain current directory
* Remove unnecessary/not-needed release.txt target
* Fix incorrect version number output
* Exclude .gitignore from test req.
* Fix handling of $NAME and $IMAGE in runlabel
* Update podman image Dockerfile to support Podman in container
* Bump github.com/containers/image/v5 from 5.10.5 to 5.11.0
* Fix slashes in socket URLs
* Add network prune filters support to bindings
* Add support for play/generate kube volumes
* Update manifest API endpoints
* Fix panic when not giving a machine name for ssh
* cgroups: force 64 bits to ParseUint
* Bump k8s.io/api from 0.20.5 to 0.21.0
* [CI:DOCS] Fix formatting of podman-build man page
* buildah-bud tests: simplify
* Add missing return
* Bump github.com/onsi/ginkgo from 1.16.0 to 1.16.1
* speed up CI handling of images
* Volumes prune endpoint should use only prune filters
* Cirrus: Use Fedora 34beta images
* Bump go.sum + Makefile for golang 1.16
* Exempt Makefile changes from test requirements
* Adjust libpod API Container Wait documentation to the code
* [CI:DOCS] Update swagger definition of inspect manifest
* use updated ubuntu images
* podman unshare: add --rootless-cni to join the ns
* Update swagger-check
* swagger: remove name wildcards
* Update buildah-bud diffs
* Handle podman-remote --arch, --platform, --os
* buildah-bud tests: handle go pseudoversions, plus...
* Fix flaking rootless compose test
* rootless cni add /usr/sbin to PATH if not present
* System tests: special case for RHEL: require runc
* Add --requires flag to podman run/create
* [CI:DOCS] swagger-check: compare operations
* [CI:DOCS] Polish swagger OpertionIDs
* [NO TESTS NEEDED] Update nix pin with `make nixpkgs`
* Ensure that `--userns=keep-id` sets user in config
* [CI:DOCS] Set all operation id to be compatibile
* Move operationIds to swagger:operation line
* swagger: add operationIds that match with docker
* Cirrus: Make use of shared get_ci_vm container
* Don't relabel volumes if running in a privileged container
* Allow users to override default storage opts with --storage-opt
* Add support for podman --context default
* Verify existence of auth file if specified
* fix machine naming conventions
* Initial network bindings tests
* Update release notes to indicate CVE fix
* Move socket activation check into init() and set global condition.
* Bump github.com/onsi/ginkgo from 1.15.2 to 1.16.0
* Http api tests for network prune with until filter
* podman-run.1.md, podman-create.1.md : Adjust Markdown layout for
--userns
* Fix typos --uidmapping and --gidmapping
* Add transport and destination info to manifest doc
* Bump github.com/rootless-containers/rootlesskit from 0.14.0 to 0.14.1
* Add default template functions
* Fix missing podman-remote build options
* Bump github.com/coreos/go-systemd/v22 from 22.3.0 to 22.3.1
* Add ssh connection to root user
* Add rootless docker-compose test to the CI
* Use the slrip4netns dns in the rootless cni ns
* Cleanup the rootless cni namespace
* Add new docker-compose test for two networks
* Make the docker-compose test work rootless
* Remove unused rootless-cni-infra container files
* Only use rootless RLK when the container has ports
* Fix dnsname test
* Enable rootless network connect/disconnect
* Move slirp4netns functions into an extra file
* Fix pod infra container cni network setup
* Add rootless support for cni and --uidmap
* rootless cni without infra container
* Recreate until container prune tests for bindings
* Remove --execute from podman machine ssh
* Fixed podman-remote --network flag
* Makefile: introduce install.docker-full
* Makefile: ensure install.docker creates BINDIR
* Fix unmount doc reference in image.rst
* Should send the OCI runtime path not just the name to buildah
* podman machine shell completion
* Fix handling of remove --log-rusage param
* Fix bindings prune containers flaky test
* [CI:DOCS] Add local html build info to docs/README.md
* Add podman machine list
* Trim white space from /top endpoint results
* Remove semantic version suffices from API calls
* podman machine init --ignition-path
* Document --volume from podman-remote run/create client
* Update main branch to reflect the release of v3.1.0
* Silence podman network reload errors with iptables-nft
* Containers prune endpoint should use only prune filters
* resolve proper aarch64 image names
* APIv2 basic test: relax APIVersion check
* Add machine support for qemu-system-aarch64
* podman machine init user input
* manpage xref: helpful diagnostic for unescaped dash-dash
* Bump to v3.2.0-dev
* swagger: update system version response body
* buildah-bud tests: reenable pull-never test
* [NO TESTS NEEDED] Shrink the size of podman-remote
* Add powershell completions
* [NO TESTS NEEDED] Drop Warning to Info, if cgroups not mounted
* Fix long option format on docs.podman.io
* system tests: friendier messages for 2-arg is()
* service: use LISTEN_FDS
* man pages: correct seccomp-policy label
* rootless: use is_fd_inherited
* podman generate systemd --new do not duplicate params
* play kube: add support for env vars defined from secrets
* play kube: support optional/mandatory env var from config map
* play kube: prepare supporting other env source than config maps
* Add machine support for more Linux distros
* [NO TESTS NEEDED] Use same function podman-remote rmi as podman
* Podman machine enhancements
* Add problematic volume name to kube play error messages
* Fix podman build --pull-never
* [NO TESTS NEEDED] Fix for kernel without CONFIG_USER_NS
* [NO TESTS NEEDED] Turn on podman-remote build --isolation
* Fix list pods filter handling in libpod api
* Remove resize race condition
* [NO TESTS NEEDED] Vendor in containers/buildah v1.20.0
* Use TMPDIR when commiting images
* Add RequiresMountsFor= to systemd generate
* Bump github.com/vbauerster/mpb/v6 from 6.0.2 to 6.0.3
* Fix swapped dimensions from terminal.GetSize
* Rename podman machine create to init and clean up
* Correct json field name
* system tests: new interactive tests
* Improvements for machine
* libpod/image: unit tests: use a `registries.conf` for aliases
* libpod/image: unit tests: defer cleanup
* libpod/image: unit tests: use `require.NoError`
* Add --execute flag to podman machine ssh
* introduce podman machine
* Podman machine CLI and interface stub
* Support multi doc yaml for generate/play kube
* Fix filters in image http compat/libpod api endpoints
* Bump github.com/containers/common from 0.35.3 to 0.35.4
* Bump github.com/containers/storage from 1.28.0 to 1.28.1
* Check if stdin is a term in --interactive --tty mode
* [NO TESTS NEEDED] Remove /tmp/containers-users-* files on reboot
* [NO TESTS NEEDED] Fix rootless volume plugins
* Ensure manually-created volumes have correct ownership
* Bump github.com/rootless-containers/rootlesskit
* Unification of until filter across list/prune endpoints
* Unification of label filter across list/prune endpoints
* fixup
* fix: build endpoint for compat API
* [CI:DOCS] Add note to mappings for user/group userns in build
* Bump k8s.io/api from 0.20.1 to 0.20.5
* Validate passed in timezone from tz option
* WIP: run buildah bud tests using podman
* Fix containers list/prune http api filter behaviour
* Generate Kubernetes PersistentVolumeClaims from named volumes

- Update to version 3.1.2:
* Bump to v3.1.2
* Update release notes for v3.1.2
* Ensure mount destination is clean, no trailing slash
* Fixes podman-remote save to directories does not work
* [CI:DOCS] Add missing dash to verbose option
* [CI:DOCS] Fix Markdown table layout bugs
* [CI:DOCS] Rewrite --uidmap doc in podman-create.1.md and
podman-run.1.md
* rmi: don't break when the image is missing a manifest
* Bump containers/image to v5.11.1
* Bump github.com/coreos/go-systemd from 22.2.0 to 22.3.1
* Fix lint
* Bump to v3.1.2-dev
- Split podman-remote into a subpackage
- Add missing scriptlets for systemd units
- Escape macros in comments
- Drop some obsolete workarounds, including %{go_nostrip}

- Update to version 3.1.1:
* Bump to v3.1.1
* Update release notes for v3.1.1
* podman play kube apply correct log driver
* Fix build with GO111MODULE=off
* [CI:DOCS] Set all operation id to be compatibile
* Move operationIds to swagger:operation line
* swagger: add operationIds that match with docker
* Fix missing podman-remote build options
* [NO TESTS NEEDED] Shrink the size of podman-remote
* Move socket activation check into init() and set global condition.
* rootless: use is_fd_inherited
* Recreate until container prune tests for bindings
* System tests: special case for RHEL: require runc
* Document --volume from podman-remote run/create client
* Containers prune endpoint should use only prune filters
* Trim white space from /top endpoint results
* Fix unmount doc reference in image.rst
* Fix handling of remove --log-rusage param
* Makefile: introduce install.docker-full
* Makefile: ensure install.docker creates BINDIR
* Should send the OCI runtime path not just the name to buildah
* Fixed podman-remote --network flag
* podman-run.1.md, podman-create.1.md : Adjust Markdown layout for
--userns
* Fix typos --uidmapping and --gidmapping
* Add default template functions
* Don't relabel volumes if running in a privileged container
* Allow users to override default storage opts with --storage-opt
* Add transport and destination info to manifest doc
* Verify existence of auth file if specified
* Ensure that `--userns=keep-id` sets user in config
* [CI:DOCS] Update swagger definition of inspect manifest
* Volumes prune endpoint should use only prune filters
* Adjust libpod API Container Wait documentation to the code
* Add missing return
* [CI:DOCS] Fix formatting of podman-build man page
* cgroups: force 64 bits to ParseUint
* Fix slashes in socket URLs
* [CI:DOCS] Correct status code for /pods/create
* cgroup: do not set cgroup parent when rootless and cgroupfs
* Reflect current state of prune implementation in docs
* Do not delete container twice
* Test that we don't error out on advertised --log-level values
* At trace log level, print error text using %+v instead of %v
* pkg/errorhandling.JoinErrors: don't throw away context for lone errors
* Recognize --log-level=trace
* Fix message about runtime to show only the actual runtime
* Fix handling of $NAME and $IMAGE in runlabel
* Fix flake on failed podman-remote build : try 2
* Fix flake on failed podman-remote build
* Update documentation of podman-run to reflect volume "U" option
* Fixes invalid expression in save command
* Fix possible panic in libpod/image/prune.go
* Update all containers/ project vendors
* Fix tests
* Bump to v3.1.1-dev

- Update to version 3.1.0:
* Bump to v3.1.0
* Fix test failure
* Update release notes for v3.1.0 final release
* [NO TESTS NEEDED] Turn on podman-remote build --isolation
* Fix long option format on docs.podman.io
* Fix containers list/prune http api filter behaviour
* [CI:DOCS] Add note to mappings for user/group userns in build
* Validate passed in timezone from tz option
* Generate Kubernetes PersistentVolumeClaims from named volumes
* libpod/image: unit tests: use a `registries.conf` for aliases
- Require systemd 241 or newer due to podman dependency go-systemd v22,
otherwise build will fail with unknown C name errors

- Create docker subpackage to allow replacing docker with corresponding
aliases to podman.

- Update to v3.0.1
* Changes
- Several frequently-occurring WARN level log messages have been
downgraded to INFO or DEBUG to not clutter terminal output. Bugfixes
- Fixed a bug where the Created field of podman ps --format=json was
formatted as a string instead of an Unix timestamp (integer) (#9315).
- Fixed a bug where failing lookups of individual layers during the
podman images command would cause the whole command to fail without
printing output.
- Fixed a bug where --cgroups=split did not function properly on
cgroups v1 systems.
- Fixed a bug where mounting a volume over an directory in the
container that existed, but was empty, could fail (#9393).
- Fixed a bug where mounting a volume over a directory in the
container that existed could copy the entirety of the container's
rootfs, instead of just the directory mounted over, into the volume
(#9415).
- Fixed a bug where Podman would treat the --entrypoint=[""] option to
podman run and podman create as a literal empty string in the
entrypoint, when instead it should have been ignored (#9377).
- Fixed a bug where Podman would set the HOME environment variable to
"" when the container ran as a user without an assigned home
directory (#9378).
- Fixed a bug where specifying a pod infra image that had no tags (by
using its ID) would cause podman pod create to panic (#9374).
- Fixed a bug where the --runtime option was not properly handled by
the podman build command (#9365).
- Fixed a bug where Podman would incorrectly print an error message
related to the remote API when the remote API was not in use and
starting Podman failed.
- Fixed a bug where Podman would change ownership of a container's
working directory, even if it already existed (#9387).
- Fixed a bug where the podman generate systemd --new command would
incorrectly escape %t when generating the path for the PID file
(#9373).
- Fixed a bug where Podman could, when run inside a Podman container
with the host's containers/storage directory mounted into the
container, erroneously detect a reboot and reset container state if
the temporary directory was not also mounted in (#9191).
- Fixed a bug where some options of the podman build command
(including but not limited to --jobs) were nonfunctional (#9247).
* API
- Fixed a breaking change to the Libpod Wait API for Containers where
the Conditions parameter changed type in Podman v3.0 (#9351).
- Fixed a bug where the Compat Create endpoint for Containers did not
properly handle forwarded ports that did not specify a host port.
- Fixed a bug where the Libpod Wait endpoint for Containers could
write duplicate headers after an error occurred.
- Fixed a bug where the Compat Create endpoint for Images would not
pull images that already had a matching tag present locally, even if
a more recent version was available at the registry (#9232).
- The Compat Create endpoint for Images has had its compatibility with
Docker improved, allowing its use with the docker-java library.
* Misc
- Updated Buildah to v1.19.4
- Updated the containers/storage library to v1.24.6
- Changes from v3.0.0
* Features
- Podman now features initial support for Docker Compose.
- Added the podman rename command, which allows containers to be
renamed after they are created (#1925).
- The Podman remote client now supports the podman copy command.
- A new command, podman network reload, has been added. This command
will re-configure the network of all running containers, and can be
used to recreate firewall rules lost when the system firewall was
reloaded (e.g. via firewall-cmd --reload).
- Podman networks now have IDs. They can be seen in podman network ls
and can be used when removing and inspecting networks. Existing
networks receive IDs automatically.
- Podman networks now also support labels. They can be added via the
--label option to network create, and podman network ls can filter
labels based on them.
- The podman network create command now supports setting bridge MTU
and VLAN through the --opt option (#8454).
- The podman container checkpoint and podman container restore
commands can now checkpoint and restore containers that include
volumes.
- The podman container checkpoint command now supports the
--with-previous and --pre-checkpoint options, and the podman
container restore command now support the --import-previous option.
These add support for two-step checkpointing with lowered dump times.
- The podman push command can now push manifest lists. Podman will
first attempt to push as an image, then fall back to pushing as a
manifest list if that fails.
- The podman generate kube command can now be run on multiple
containers at once, and will generate a single pod containing all of
them.
- The podman generate kube and podman play kube commands now support
Kubernetes DNS configuration, and will preserve custom DNS
configuration when exporting or importing YAML (#9132).
- The podman generate kube command now properly supports generating
YAML for containers and pods creating using host networking
(--net=host) (#9077).
- The podman kill command now supports a --cidfile option to kill
containers given a file containing the container's ID (#8443).
- The podman pod create command now supports the --net=none option
(#9165).
- The podman volume create command can now specify volume UID and GID
as options with the UID and GID fields passed to the the --opt
option.
- Initial support has been added for Docker Volume Plugins. Podman can
now define available plugins in containers.conf and use them to
create volumes with podman volume create --driver.
- The podman run and podman create commands now support a new option,
--platform, to specify the platform of the image to be used when
creating the container.
- The --security-opt option to podman run and podman create now
supports the systempaths=unconfined option to unrestrict access to
all paths in the container, as well as mask and unmask options to
allow more granular restriction of container paths.
- The podman stats --format command now supports a new format
specified, MemUsageBytes, which prints the raw bytes of memory
consumed by a container without human-readable formatting #8945.
- The podman ps command can now filter containers based on what pod
they are joined to via the pod filter (#8512).
- The podman pod ps command can now filter pods based on what networks
they are joined to via the network filter. The podman pod ps command
can now print information on what networks a pod is joined to via
the .Networks specifier to the --format option.
- The podman system prune command now supports filtering what
containers, pods, images, and volumes will be pruned.
- The podman volume prune commands now supports filtering what volumes
will be pruned.
- The podman system prune command now includes information on space
reclaimed (#8658).
- The podman info command will now properly print information about
packages in use on Gentoo and Arch systems.
- The containers.conf file now contains an option for disabling
creation of a new kernel keyring on container creation (#8384).
- The podman image sign command can now sign multi-arch images by
producing a signature for each image in a given manifest list.
- The podman image sign command, when run as rootless, now supports
per-user registry configuration files in
$HOME/.config/containers/registries.d.
- Configuration options for slirp4netns can now be set system-wide via
the NetworkCmdOptions configuration option in containers.conf.
- The MTU of slirp4netns can now be configured via the mtu= network
command option (e.g. podman run --net slirp4netns:mtu=9000).
* Security
- A fix for CVE-2021-20199 is included. Podman between v1.8.0 and
v2.2.1 used 127.0.0.1 as the source address for all traffic
forwarded into rootless containers by a forwarded port; this has
been changed to address the issue.
* Changes
- Shortname aliasing support has now been turned on by default. All
Podman commands that must pull an image will, if a TTY is available,
prompt the user about what image to pull.
- The podman load command no longer accepts a NAME[:TAG] argument. The
presence of this argument broke CLI compatibility with Docker by
making docker load commands unusable with Podman (#7387).
- The Go bindings for the HTTP API have been rewritten with a focus on
limiting dependency footprint and improving extensibility. Read more
here.
- The legacy Varlink API has been completely removed from Podman.
- The default log level for Podman has been changed from Error to Warn.
- The podman network create command can now create macvlan networks
using the --driver macvlan option for Docker compatibility. The
existing --macvlan flag has been deprecated and will be removed in
Podman 4.0 some time next year.
- The podman inspect command has had the LogPath and LogTag fields
moved into the LogConfig structure (from the root of the Inspect
structure). The maximum size of the log file is also included.
- The podman generate systemd command no longer generates unit files
using the deprecated KillMode=none option (#8615).
- The podman stop command now releases the container lock while
waiting for it to stop - as such, commands like podman ps will no
longer block until podman stop completes (#8501).
- Networks created with podman network create --internal no longer use
the dnsname plugin. This configuration never functioned as expected.
- Error messages for the remote Podman client have been improved when
it cannot connect to a Podman service.
- Error messages for podman run when an invalid SELinux is specified
have been improved.
- Rootless Podman features improved support for containers with a
single user mapped into the rootless user namespace.
- Pod infra containers now respect default sysctls specified in
containers.conf allowing for advanced configuration of the
namespaces they will share.
- SSH public key handling for remote Podman has been improved.
* Bugfixes
- Fixed a bug where the podman history --no-trunc command would
truncate the Created By field (#9120).
- Fixed a bug where root containers that did not explicitly specify a
CNI network to join did not generate an entry for the network in use
in the Networks field of the output of podman inspect (#6618).
- Fixed a bug where, under some circumstances, container working
directories specified by the image (via the WORKDIR instruction) but
not present in the image, would not be created (#9040).
- Fixed a bug where the podman generate systemd command would generate
invalid unit files if the container was creating using a command
line that included doubled braces ({{ and }}), e.g.
--log-opt-tag={{.Name}} (#9034).
- Fixed a bug where the podman generate systemd --new command could
generate unit files including invalid Podman commands if the
container was created using merged short options (e.g. podman run
-dt) (#8847).
- Fixed a bug where the podman generate systemd --new command could
generate unit files that did not handle Podman commands including
some special characters (e.g. $) (#9176
- Fixed a bug where rootless containers joining CNI networks could not
set a static IP address (#7842).
- Fixed a bug where rootless containers joining CNI networks could not
set network aliases (#8567).
- Fixed a bug where the remote client could, under some circumstances,
not include the Containerfile when sending build context to the
server (#8374).
- Fixed a bug where rootless Podman did not mount /sys as a new sysfs
in some circumstances where it was acceptable.
- Fixed a bug where rootless containers that both joined a user
namespace and a CNI networks would cause a segfault. These options
are incompatible and now return an error.
- Fixed a bug where the podman play kube command did not properly
handle CMD and ARGS from images (#8803).
- Fixed a bug where the podman play kube command did not properly
handle environment variables from images (#8608).
- Fixed a bug where the podman play kube command did not properly
print errors that occurred when starting containers.
- Fixed a bug where the podman play kube command errored when
hostNetwork was used (#8790).
- Fixed a bug where the podman play kube command would always pull
images when the :latest tag was specified, even if the image was
available locally (#7838).
- Fixed a bug where the podman play kube command did not properly
handle SELinux configuration, rending YAML with custom SELinux
configuration unusable (#8710).
- Fixed a bug where the podman generate kube command incorrectly
populated the args and command fields of generated YAML (#9211).
- Fixed a bug where containers in a pod would create a duplicate entry
in the pod's shared /etc/hosts file every time the container
restarted (#8921).
- Fixed a bug where the podman search --list-tags command did not
support the --format option (#8740).
- Fixed a bug where the http_proxy option in containers.conf was not
being respected, and instead was set unconditionally to true (#8843).
- Fixed a bug where rootless Podman could, on systems with a recent
Conmon and users with a long username, fail to attach to containers
(#8798).
- Fixed a bug where the podman images command would break and fail to
display any images if an empty manifest list was present in storage
(#8931).
- Fixed a bug where locale environment variables were not properly
passed on to Conmon.
- Fixed a bug where Podman would not build on the MIPS architecture
(#8782).
- Fixed a bug where rootless Podman could fail to properly configure
user namespaces for rootless containers when the user specified a
--uidmap option that included a mapping beginning with UID 0.
- Fixed a bug where the podman logs command using the k8s-file backend
did not properly handle partial log lines with a length of 1 (#8879).
- Fixed a bug where the podman logs command with the --follow option
did not properly handle log rotation (#8733).
- Fixed a bug where user-specified HOSTNAME environment variables were
overwritten by Podman (#8886).
- Fixed a bug where Podman would applied default sysctls from
containers.conf in too many situations (e.g. applying network
sysctls when the container shared its network with a pod).
- Fixed a bug where Podman did not properly handle cases where a
secondary image store was in use and an image was present in both
the secondary and primary stores (#8176).
- Fixed a bug where systemd-managed rootless Podman containers where
the user in the container was not root could fail as the container's
PID file was not accessible to systemd on the host (#8506).
- Fixed a bug where the --privileged option to podman run and podman
create would, under some circumstances, not disable Seccomp (#8849).
- Fixed a bug where the podman exec command did not properly add
capabilities when the container or exec session were run with
--privileged.
- Fixed a bug where rootless Podman would use the --enable-sandbox
option to slirp4netns unconditionally, even when pivot_root was
disabled, rendering slirp4netns unusable when pivot_root was
disabled (#8846).
- Fixed a bug where podman build --logfile did not actually write the
build's log to the logfile.
- Fixed a bug where the podman system service command did not close
STDIN, and could display user-interactive prompts (#8700).
- Fixed a bug where the podman system reset command could, under some
circumstances, remove all the contents of the XDG_RUNTIME_DIR
directory (#8680).
- Fixed a bug where the podman network create command created CNI
configurations that did not include a default gateway (#8748).
- Fixed a bug where the podman.service systemd unit provided by
default used the wrong service type, and would cause systemd to not
correctly register the service as started (#8751).
- Fixed a bug where, if the TMPDIR environment variable was set for
the container engine in containers.conf, it was being ignored.
- Fixed a bug where the podman events command did not properly handle
future times given to the --until option (#8694).
- Fixed a bug where the podman logs command wrote container STDERR
logs to STDOUT instead of STDERR (#8683).
- Fixed a bug where containers created from an image with multiple
tags would report that they were created from the wrong tag (#8547).
- Fixed a bug where container capabilities were not set properly when
the --cap-add=all and --user options to podman create and podman run
were combined.
- Fixed a bug where the --layers option to podman build was
nonfunctional (#8643).
- Fixed a bug where the podman system prune command did not act
recursively, and thus would leave images, containers, pods, and
volumes present that would be removed by a subsequent call to podman
system prune (#7990).
- Fixed a bug where the --publish option to podman run and podman
create did not properly handle ports specified as a range of ports
with no host port specified (#8650).
- Fixed a bug where --format did not support JSON output for
individual fields (#8444).
- Fixed a bug where the podman stats command would fail when run on
root containers using the slirp4netns network mode (#7883).
- Fixed a bug where the Podman remote client would ask for a password
even if the server's SSH daemon did not support password
authentication (#8498).
- Fixed a bug where the podman stats command would fail if the system
did not support one or more of the cgroup controllers Podman
supports (#8588).
- Fixed a bug where the --mount option to podman create and podman run
did not ignore the consistency mount option.
- Fixed a bug where failures during the resizing of a container's TTY
would print the wrong error.
- Fixed a bug where the podman network disconnect command could cause
the podman inspect command to fail for a container until it was
restarted (#9234).
- Fixed a bug where containers created from a read-only rootfs (using
the --rootfs option to podman create and podman run) would fail
(#9230).
- Fixed a bug where specifying Go templates to the --format option to
multiple Podman commands did not support the join function (#8773).
- Fixed a bug where the podman rmi command could, when run in parallel
on multiple images, return layer not known errors (#6510).
- Fixed a bug where the podman inspect command on containers displayed
unlimited ulimits incorrectly (#9303).
- Fixed a bug where Podman would fail to start when a volume was
mounted over a directory in a container that contained symlinks that
terminated outside the directory and its subdirectories (#6003). API
- Libpod API version has been bumped to v3.0.0.
- All Libpod Pod APIs have been modified to properly report errors
with individual containers. Cases where the operation as a whole
succeeded but individual containers failed now report an HTTP 409
error (#8865).
- The Compat API for Containers now supports the Rename and Copy APIs.
- Fixed a bug where the Compat Prune APIs (for volumes, containers,
and images) did not return the amount of space reclaimed in their
responses.
- Fixed a bug where the Compat and Libpod Exec APIs for Containers
would drop errors that occurred prior to the exec session
successfully starting (e.g. a "no such file" error if an invalid
executable was passed) (#8281)
- Fixed a bug where the Volumes field in the Compat Create API for
Containers was being ignored (#8649).
- Fixed a bug where the NetworkMode field in the Compat Create API for
Containers was not handling some values, e.g. container:, correctly.
- Fixed a bug where the Compat Create API for Containers did not set
container name properly.
- Fixed a bug where containers created using the Compat Create API
unconditionally used Kubernetes file logging (the default specified
in containers.conf is now used).
- Fixed a bug where the Compat Inspect API for Containers could
include container states not recognized by Docker.
- Fixed a bug where Podman did not properly clean up after calls to
the Events API when the journald backend was in use, resulting in a
leak of file descriptors (#8864).
- Fixed a bug where the Libpod Pull endpoint for Images could fail
with an index out of range error under certain circumstances (#8870).
- Fixed a bug where the Libpod Exists endpoint for Images could panic.
- Fixed a bug where the Compat List API for Containers did not support
all filters (#8860).
- Fixed a bug where the Compat List API for Containers did not
properly populate the Status field.
- Fixed a bug where the Compat and Libpod Resize APIs for Containers
ignored the height and width parameters (#7102).
- Fixed a bug where the Compat Search API for Images returned an
incorrectly-formatted JSON response (#8758).
- Fixed a bug where the Compat Load API for Images did not properly
clean up temporary files.
- Fixed a bug where the Compat Create API for Networks could panic
when an empty IPAM configuration was specified.
- Fixed a bug where the Compat Inspect and List APIs for Networks did
not include Scope.
- Fixed a bug where the Compat Wait endpoint for Containers did not
support the same wait conditions that Docker did.
* Misc
- Updated Buildah to v1.19.2
- Updated the containers/storage library to v1.24.5
- Updated the containers/image library to v5.10.2
- Updated the containers/common library to v0.33.4

- Update to v2.2.1
* Changes
- Due to a conflict with a previously-removed field, we were forced to
modify the way image volumes (mounting images into containers using
--mount type=image) were handled in the database. As a result,
containers created in Podman 2.2.0 with image volume will not have them in
v2.2.1, and these containers will need to be re-created.
* Bugfixes
- Fixed a bug where rootless Podman would, on systems without the
XDG_RUNTIME_DIR environment variable defined, use an incorrect path
for the PID file of the Podman pause process, causing Podman to fail
to start (#8539).
- Fixed a bug where containers created using Podman v1.7 and earlier
were unusable in Podman due to JSON decode errors (#8613).
- Fixed a bug where Podman could retrieve invalid cgroup paths, instead
of erroring, for containers that were not running.
- Fixed a bug where the podman system reset command would print a
warning about a duplicate shutdown handler being registered.
- Fixed a bug where rootless Podman would attempt to mount sysfs in
circumstances where it was not allowed; some OCI runtimes (notably
crun) would fall back to alternatives and not fail, but others
(notably runc) would fail to run containers.
- Fixed a bug where the podman run and podman create commands would
fail to create containers from untagged images (#8558).
- Fixed a bug where remote Podman would prompt for a password even
when the server did not support password authentication (#8498).
- Fixed a bug where the podman exec command did not move the Conmon
process for the exec session into the correct cgroup.
- Fixed a bug where shell completion for the ancestor option to podman
ps --filter did not work correctly.
- Fixed a bug where detached containers would not properly clean
themselves up (or remove themselves if --rm was set) if the Podman
command that created them was invoked with --log-level=debug.
* API
- Fixed a bug where the Compat Create endpoint for Containers did not
properly handle the Binds and Mounts parameters in HostConfig.
- Fixed a bug where the Compat Create endpoint for Containers ignored
the Name query parameter.
- Fixed a bug where the Compat Create endpoint for Containers did not
properly handle the "default" value for NetworkMode (this value is
used extensively by docker-compose) (#8544).
- Fixed a bug where the Compat Build endpoint for Images would
sometimes incorrectly use the target query parameter as the image's
tag.
* Misc
- Podman v2.2.0 vendored a non-released, custom version of the
github.com/spf13/cobra package; this has been reverted to the latest
upstream release to aid in packaging.
- Updated the containers/image library to v5.9.0

- Update to v2.2.0
* Features
- Experimental support for shortname aliasing has been added. This is
not enabled by default, but can be turned on by setting the
environment variable CONTAINERS_SHORT_NAME_ALIASING to on.
Documentation is available here and here.
- Initial support has been added for the podman network connect and
podman network disconnect commands, which allow existing containers to
modify what networks they are connected to. At present, these commands
can only be used on running containers that did not specify
--network=none when they were created.
- The podman run command now supports the --network-alias option to set
network aliases (additional names the container can be accessed at
from other containers via DNS if the dnsname CNI plugin is in use).
Aliases can also be added and removed using the new podman network
connect and podman network disconnect commands. Please note that this
requires a new release (v1.1.0) of the dnsname plugin, and will only
work on newly-created CNI networks.
- The podman generate kube command now features support for exporting
container's memory and CPU limits (#7855).
- The podman play kube command now features support for setting CPU and
Memory limits for containers (#7742).
- The podman play kube command now supports persistent volumes claims
using Podman named volumes.
- The podman play kube command now supports Kubernetes configmaps via
the --configmap option (#7567).
- The podman play kube command now supports a --log-driver option to set
the log driver for created containers.
- The podman play kube command now supports a --start option, enabled by
default, to start the pod after creating it. This allows for podman
play kube to be more easily used in systemd unitfiles.
- The podman network create command now supports the --ipv6 option to
enable dual-stack IPv6 networking for created networks (#7302).
- The podman inspect command can now inspect pods, networks, and
volumes, in addition to containers and images (#6757).
- The --mount option for podman run and podman create now supports a new
type, image, to mount the contents of an image into the container at a
given location.
- The Bash and ZSH completions have been completely reworked and have
received significant enhancements! Additionally, support for Fish
completions and completions for the podman-remote executable have been
added.
- The --log-opt option for podman create and podman run now supports the
max-size option to set the maximum size for a container's logs (#7434).
- The --network option to the podman pod create command now allows pods
to be configured to use slirp4netns networking, even when run as root
(#6097).
- The podman pod stop, podman pod pause, podman pod unpause, and podman
pod kill commands now work on multiple containers in parallel and
should be significantly faster.
- The podman search command now supports a --list-tags option to list
all available tags for a single image in a single repository.
- The podman search command can now output JSON using the --format=json
option.
- The podman diff and podman mount commands now work with all containers
in the storage library, including those not created by Podman. This
allows them to be used with Buildah and CRI-O containers.
- The podman container exists command now features a --external option
to check if a container exists not just in Podman, but also in the
storage library. This will allow Podman to identify Buildah and CRI-O
containers.
- The --tls-verify and --authfile options have been enabled for use with
remote Podman.
- The /etc/hosts file now includes the container's name and hostname
(both pointing to localhost) when the container is run with --net=none
(#8095).
- The podman events command now supports filtering events based on the
labels of the container they occurred on using the --filter
label=key=value option.
- The podman volume ls command now supports filtering volumes based on
their labels using the --filter label=key=value option.
- The --volume and --mount options to podman run and podman create now
support two new mount propagation options, unbindable and runbindable.
- The name and id filters for podman pod ps now match based on a regular
expression, instead of requiring an exact match.
- The podman pod ps command now supports a new filter status, that
matches pods in a certain state.
* Changes
- The podman network rm --force command will now also remove pods that
are using the network (#7791).
- The podman volume rm, podman network rm, and podman pod rm commands
now return exit code 1 if the object specified for removal does not
exist, and exit code 2 if the object is in use and the --force option
was not given.
- If /dev/fuse is passed into Podman containers as a device, Podman will
open it before starting the container to ensure that the kernel module
is loaded on the host and the device is usable in the container.
- Global Podman options that were not supported with remote operation
have been removed from podman-remote (e.g. --cgroup-manager,
--storage-driver).
- Many errors have been changed to remove repetition and be more clear
as to what has gone wrong.
- The --storage option to podman rm is now enabled by default, with
slightly changed semantics. If the given container does not exist in
Podman but does exist in the storage library, it will be removed even
without the --storage option. If the container exists in Podman it
will be removed normally. The --storage option for podman rm is now
deprecated and will be removed in a future release.
- The --storage option to podman ps has been renamed to --external. An
alias has been added so the old form of the option will continue to
work.
- Podman now delays the SIGTERM and SIGINT signals during container
creation to ensure that Podman is not stopped midway through creating
a container resulting in potential resource leakage (#7941).
- The podman save command now strips signatures from images it is
exporting, as the formats we export to do not support signatures
(#7659).
- A new Degraded state has been added to pods. Pods that have some, but
not all, of their containers running are now considered to be Degraded
instead of Running.
- Podman will now print a warning when conflicting network options
related to port forwarding (e.g. --publish and --net=host) are
specified when creating a container.
- The --restart on-failure and --rm options for containers no longer
conflict. When both are specified, the container will be restarted if
it exits with a non-zero error code, and removed if it exits cleanly
(#7906).
- Remote Podman will no longer use settings from the client's
containers.conf; defaults will instead be provided by the server's
containers.conf (#7657).
- The podman network rm command now has a new alias, podman network
remove (#8402).
* Bugfixes
- Fixed a bug where podman load on the remote client did not error when
attempting to load a directory, which is not yet supported for remote
use.
- Fixed a bug where rootless Podman could hang when the newuidmap binary
was not installed (#7776).
- Fixed a bug where the --pull option to podman run, podman create, and
podman build did not match Docker's behavior.
- Fixed a bug where sysctl settings from the containers.conf
configuration file were applied, even if the container did not join
the namespace associated with a sysctl.
- Fixed a bug where Podman would not return the text of errors encounted
when trying to run a healthcheck for a container.
- Fixed a bug where Podman was accidentally setting the containers
environment variable in addition to the expected container environment
variable.
- Fixed a bug where rootless Podman using CNI networking did not
properly clean up DNS entries for removed containers (#7789).
- Fixed a bug where the podman untag --all command was not supported
with remote Podman.
- Fixed a bug where the podman system service command could time out
even if active attach connections were present (#7826).
- Fixed a bug where the podman system service command would sometimes
never time out despite no active connections being present.
- Fixed a bug where Podman's handling of capabilities, specifically
inheritable, did not match Docker's.
- Fixed a bug where podman run would fail if the image specified was a
manifest list and had already been pulled (#7798).
- Fixed a bug where Podman did not take search registries into account
when looking up images locally (#6381).
- Fixed a bug where the podman manifest inspect command would fail for
images that had already been pulled (#7726).
- Fixed a bug where rootless Podman would not add supplemental GIDs to
containers when when a user, but not a group, was set via the --user
option to podman create and podman run and sufficient GIDs were
available to add the groups (#7782).
- Fixed a bug where remote Podman commands did not properly handle cases
where the user gave a name that could also be a short ID for a pod or
container (#7837).
- Fixed a bug where podman image prune could leave images ready to be
pruned after podman image prune was run (#7872).
- Fixed a bug where the podman logs command with the journald log driver
would not read all available logs (#7476).
- Fixed a bug where the --rm and --restart options to podman create and
podman run did not conflict when a restart policy that is not
on-failure was chosen (#7878).
- Fixed a bug where the --format "table {{ .Field }}" option to numerous
Podman commands ceased to function on Podman v2.0 and up.
- Fixed a bug where pods did not properly share an SELinux label between
their containers, resulting in containers being unable to see the
processes of other containers when the pod shared a PID namespace
(#7886).
- Fixed a bug where the --namespace option to podman ps did not work
with the remote client (#7903).
- Fixed a bug where rootless Podman incorrectly calculated the number of
UIDs available in the container if multiple different ranges of UIDs
were specified.
- Fixed a bug where the /etc/hosts file would not be correctly populated
for containers in a user namespace (#7490).
- Fixed a bug where the podman network create and podman network remove
commands could race when run in parallel, with unpredictable results
(#7807).
- Fixed a bug where the -p option to podman run, podman create, and
podman pod create would, when given only a single number (e.g. -p 80),
assign the same port for both host and container, instead of
generating a random host port (#7947).
- Fixed a bug where Podman containers did not properly store the cgroup
manager they were created with, causing them to stop functioning after
the cgroup manager was changed in containers.conf or with the
--cgroup-manager option (#7830).
- Fixed a bug where the podman inspect command did not include
information on the CNI networks a container was connected to if it was
not running.
- Fixed a bug where the podman attach command would not print a newline
after detaching from the container (#7751).
- Fixed a bug where the HOME environment variable was not set properly
in containers when the --userns=keep-id option was set (#8004).
- Fixed a bug where the podman container restore command could panic
when the container in question was in a pod (#8026).
- Fixed a bug where the output of the podman image trust show --raw
command was not properly formatted.
- Fixed a bug where the podman runlabel command could panic if a label
to run was not given (#8038).
- Fixed a bug where the podman run and podman start --attach commands
would exit with an error when the user detached manually using the
detach keys on remote Podman (#7979).
- Fixed a bug where rootless CNI networking did not use the dnsname CNI
plugin if it was not available on the host, despite it always being
available in the container used for rootless networking (#8040).
- Fixed a bug where Podman did not properly handle cases where an OCI
runtime is specified by its full path, and could revert to using
another OCI runtime with the same binary path that existed in the
system $PATH on subsequent invocations.
- Fixed a bug where the --net=host option to podman create and podman
run would cause the /etc/hosts file to be incorrectly populated
(#8054).
- Fixed a bug where the podman inspect command did not include container
network information when the container shared its network namespace
(IE, joined a pod or another container's network namespace via
--net=container:...) (#8073).
- Fixed a bug where the podman ps command did not include information on
all ports a container was publishing.
- Fixed a bug where the podman build command incorrectly forwarded STDIN
into build containers from RUN instructions.
- Fixed a bug where the podman wait command's --interval option did not
work when units were not specified for the duration (#8088).
- Fixed a bug where the --detach-keys and --detach options could be
passed to podman create despite having no effect (and not making sense
in that context).
- Fixed a bug where Podman could not start containers if running on a
system without a /etc/resolv.conf file (which occurs on some WSL2
images) (#8089).
- Fixed a bug where the --extract option to podman cp was nonfunctional.
- Fixed a bug where the --cidfile option to podman run would, when the
container was not run with --detach, only create the file after the
container exited (#8091).
- Fixed a bug where the podman images and podman images -a commands
could panic and not list any images when certain improperly-formatted
images were present in storage (#8148).
- Fixed a bug where the podman events command could, when the journald
events backend was in use, become nonfunctional when a badly-formatted
event or a log message that container certain string was present in
the journal (#8125).
- Fixed a bug where remote Podman would, when using SSH transport, not
authenticate to the server using hostkeys when connecting on a port
other than 22 (#8139).
- Fixed a bug where the podman attach command would not exit when
containers stopped (#8154).
- Fixed a bug where Podman did not properly clean paths before verifying
them, resulting in Podman refusing to start if the root or temporary
directories were specified with extra trailing / characters (#8160).
- Fixed a bug where remote Podman did not support hashed hostnames in
the known_hosts file on the host for establishing connections (#8159).
- Fixed a bug where the podman image exists command would return
non-zero (false) when multiple potential matches for the given name
existed.
- Fixed a bug where the podman manifest inspect command on images that
are not manifest lists would error instead of inspecting the image
(#8023).
- Fixed a bug where the podman system service command would fail if the
directory the Unix socket was to be created inside did not exist
(#8184).
- Fixed a bug where pods that shared the IPC namespace (which is done by
default) did not share a /dev/shm filesystem between all containers in
the pod (#8181).
- Fixed a bug where filters passed to podman volume list were not
inclusive (#6765).
- Fixed a bug where the podman volume create command would fail when the
volume's data directory already existed (as might occur when a volume
was not completely removed) (#8253).
- Fixed a bug where the podman run and podman create commands would
deadlock when trying to create a container that mounted the same named
volume at multiple locations (e.g. podman run -v testvol:/test1 -v
testvol:/test2) (#8221).
- Fixed a bug where the parsing of the --net option to podman build was
incorrect (#8322).
- Fixed a bug where the podman build command would print the ID of the
built image twice when using remote Podman (#8332).
- Fixed a bug where the podman stats command did not show memory limits
for containers (#8265).
- Fixed a bug where the podman pod inspect command printed the static
MAC address of the pod in a non-human-readable format (#8386).
- Fixed a bug where the --tls-verify option of the podman play kube
command had its logic inverted (false would enforce the use of TLS,
true would disable it).
- Fixed a bug where the podman network rm command would error when
trying to remove macvlan networks and rootless CNI networks (#8491).
- Fixed a bug where Podman was not setting sane defaults for missing
XDG_ environment variables.
- Fixed a bug where remote Podman would check if volume paths to be
mounted in the container existed on the host, not the server (#8473).
- Fixed a bug where the podman manifest create and podman manifest add
commands on local images would drop any images in the manifest not
pulled by the host.
- Fixed a bug where networks made by podman network create did not
include the tuning plugin, and as such did not support setting custom
MAC addresses (#8385).
- Fixed a bug where container healthchecks did not use $PATH when
searching for the Podman executable to run the healthcheck.
- Fixed a bug where the --ip-range option to podman network create did
not properly handle non-classful subnets when calculating the last
usable IP for DHCP assignment (#8448).
- Fixed a bug where the podman container ps alias for podman ps was
missing (#8445).
* API
- The Compat Create endpoint for Container has received a major refactor
to share more code with the Libpod Create endpoint, and should be
significantly more stable.
- A Compat endpoint for exporting multiple images at once, GET
/images/get, has been added (#7950).
- The Compat Network Connect and Network Disconnect endpoints have been
added.
- Endpoints that deal with image registries now support a
X-Registry-Config header to specify registry authentication
configuration.
- The Compat Create endpoint for images now properly supports specifying
images by digest.
- The Libpod Build endpoint for images now supports an httpproxy query
parameter which, if set to true, will forward the server's HTTP proxy
settings into the build container for RUN instructions.
- The Libpod Untag endpoint for images will now remove all tags for the
given image if no repository and tag are specified for removal.
- Fixed a bug where the Ping endpoint misspelled a header name
(Libpod-Buildha-Version instead of Libpod-Buildah-Version).
- Fixed a bug where the Ping endpoint sent an extra newline at the end
of its response where Docker did not.
- Fixed a bug where the Compat Logs endpoint for containers did not send
a newline character after each log line.
- Fixed a bug where the Compat Logs endpoint for containers would mangle
line endings to change newline characters to add a preceding carriage
return (#7942).
- Fixed a bug where the Compat Inspect endpoint for Containers did not
properly list the container's stop signal (#7917).
- Fixed a bug where the Compat Inspect endpoint for Containers formatted
the container's create time incorrectly (#7860).
- Fixed a bug where the Compat Inspect endpoint for Containers did not
include the container's Path, Args, and Restart Count.
- Fixed a bug where the Compat Inspect endpoint for Containers prefixed
added and dropped capabilities with CAP_ (Docker does not do so).
- Fixed a bug where the Compat Info endpoint for the Engine did not
include configured registries.
- Fixed a bug where the server could panic if a client closed a
connection midway through an image pull (#7896).
- Fixed a bug where the Compat Create endpoint for volumes returned an
error when a volume with the same name already existed, instead of
succeeding with a 201 code (#7740).
- Fixed a bug where a client disconnecting from the Libpod or Compat
events endpoints could result in the server using 100% CPU (#7946).
- Fixed a bug where the "no such image" error message sent by the Compat
Inspect endpoint for Images returned a 404 status code with an error
that was improperly formatted for Docker compatibility.
- Fixed a bug where the Compat Create endpoint for networks did not
properly set a default for the driver parameter if it was not provided
by the client.
- Fixed a bug where the Compat Inspect endpoint for images did not
populate the RootFS field of the response.
- Fixed a bug where the Compat Inspect endpoint for images would omit
the ParentId field if the image had no parent, and the Created field
if the image did not have a creation time.
- Fixed a bug where the Compat Remove endpoint for Networks did not
support the Force query parameter.

- add dependency to timezone package or podman fails to build a
- Correct invalid use of %{_libexecdir} to ensure files should be in
/usr/lib SELinux support [jsc#SMO-15]

libseccomp was updated to release 2.5.3:

* Update the syscall table for Linux v5.15
* Fix issues with multiplexed syscalls on mipsel introduced in v2.5.2
* Document that seccomp_rule_add() may return -EACCES

Update to release 2.5.2

* Update the syscall table for Linux v5.14-rc7
* Add a function, get_notify_fd(), to the Python bindings to get the
nofication file descriptor.
* Consolidate multiplexed syscall handling for all architectures into one
location.
* Add multiplexed syscall support to PPC and MIPS
* The meaning of SECCOMP_IOCTL_NOTIF_ID_VALID changed within the kernel.
libseccomp's fd notification logic was modified to support the kernel's
previous and new usage of SECCOMP_IOCTL_NOTIF_ID_VALID.

update to 2.5.1:

* Fix a bug where seccomp_load() could only be called once
* Change the notification fd handling to only request a notification fd if
* the filter has a _NOTIFY action
* Add documentation about SCMP_ACT_NOTIFY to the seccomp_add_rule(3)
manpage
* Clarify the maintainers' GPG keys

Update to release 2.5.0

* Add support for the seccomp user notifications, see the
seccomp_notify_alloc(3), seccomp_notify_receive(3),
seccomp_notify_respond(3) manpages for more information
* Add support for new filter optimization approaches, including a balanced
tree optimization, see the SCMP_FLTATR_CTL_OPTIMIZE filter attribute for
more information
* Add support for the 64-bit RISC-V architecture
* Performance improvements when adding new rules to a filter thanks to the
use of internal shadow transactions and improved syscall lookup tables
* Properly document the libseccomp API return values and include them in
the stable API promise
* Improvements to the s390 and s390x multiplexed syscall handling
* Multiple fixes and improvements to the libseccomp manpages
* Moved from manually maintained syscall tables to an automatically
generated syscall table in CSV format
* Update the syscall tables to Linux v5.8.0-rc5
* Python bindings and build now default to Python 3.x
* Improvements to the tests have boosted code coverage to over 93%

Update to release 2.4.3

* Add list of authorized release signatures to README.md
* Fix multiplexing issue with s390/s390x shm* syscalls
* Remove the static flag from libseccomp tools compilation
* Add define for __SNR_ppoll
* Fix potential memory leak identified by clang in the scmp_bpf_sim tool

Update to release 2.4.2

* Add support for io-uring related system calls

conmon was updated to version 2.0.30:

* Remove unreachable code path
* exit: report if the exit command was killed
* exit: fix race zombie reaper
* conn_sock: allow watchdog messages through the notify socket proxy
* seccomp: add support for seccomp notify

Update to version 2.0.29:

* Reset OOM score back to 0 for container runtime
* call functions registered with atexit on SIGTERM
* conn_sock: fix potential segfault

Update to version 2.0.27:

* Add CRI-O integration test GitHub action
* exec: don't fail on EBADFD
* close_fds: fix close of external fds
* Add arm64 static build binary

Update to version 2.0.26:

* conn_sock: do not fail on EAGAIN
* fix segfault from a double freed pointer
* Fix a bug where conmon could never spawn a container, because a
disagreement between the caller and itself on where the attach socket
was.
* improve --full-attach to ignore the socket-dir directly. that means
callers don't need to specify a socket dir at all (and can remove it)
* add full-attach option to allow callers to not truncate a very long
path for the attach socket
* close only opened FDs
* set locale to inherit environment

Update to version 2.0.22:

* added man page
* attach: always chdir
* conn_sock: Explicitly free a heap-allocated string
* refactor I/O and add SD_NOTIFY proxy support

Update to version 2.0.21:

* protect against kill(-1)
* Makefile: enable debuginfo generation
* Remove go.sum file and add go.mod
* Fail if conmon config could not be written
* nix: remove double definition for e2fsprogs
* Speedup static build by utilizing CI cache on `/nix` folder
* Fix nix build for failing e2fsprogs tests
* test: fix CI
* Use Podman for building

libcontainers-common was updated to include:

- common 0.44.0
- image 5.16.0
- podman 3.3.1
- storage 1.36.0 (changes too long to list)

CVEs fixed:
CVE-2020-14370,CVE-2020-15157,CVE-2021-20199,CVE-2021-20291,CVE-2021-3602

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2022-23018=1


Package List:

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

conmon-2.0.30-150300.8.3.1
conmon-debuginfo-2.0.30-150300.8.3.1
libseccomp-debugsource-2.5.3-150300.10.5.1
libseccomp-devel-2.5.3-150300.10.5.1
libseccomp-tools-2.5.3-150300.10.5.1
libseccomp-tools-debuginfo-2.5.3-150300.10.5.1
libseccomp2-2.5.3-150300.10.5.1
libseccomp2-debuginfo-2.5.3-150300.10.5.1
podman-3.4.4-150300.9.3.2

- openSUSE Leap 15.3 (x86_64):

libseccomp2-32bit-2.5.3-150300.10.5.1
libseccomp2-32bit-debuginfo-2.5.3-150300.10.5.1

- openSUSE Leap 15.3 (noarch):

libcontainers-common-20210626-150300.8.3.1
podman-cni-config-3.4.4-150300.9.3.2

References:

  https://www.suse.com/security/cve/CVE-2020-14370.html
  https://www.suse.com/security/cve/CVE-2020-15157.html
  https://www.suse.com/security/cve/CVE-2021-20199.html
  https://www.suse.com/security/cve/CVE-2021-20291.html
  https://www.suse.com/security/cve/CVE-2021-3602.html
  https://www.suse.com/security/cve/CVE-2021-4024.html
  https://www.suse.com/security/cve/CVE-2021-41190.html
  https://bugzilla.suse.com/1176804
  https://bugzilla.suse.com/1177598
  https://bugzilla.suse.com/1181640
  https://bugzilla.suse.com/1182998
  https://bugzilla.suse.com/1188520
  https://bugzilla.suse.com/1188914
  https://bugzilla.suse.com/1193166
  https://bugzilla.suse.com/1193273