SUSE-SU-2022:23018-1: moderate: Security update for conmon, libcontainers-common, libseccomp, podman

sle-security-updates at lists.suse.com sle-security-updates at lists.suse.com
Fri Mar 4 08:27:11 UTC 2022


   SUSE Security Update: Security update for conmon, libcontainers-common, libseccomp, podman
______________________________________________________________________________

Announcement ID:    SUSE-SU-2022:23018-1
Rating:             moderate
References:         #1176804 #1177598 #1181640 #1182998 #1188520 
                    #1188914 #1193166 #1193273 SLE-22714 
Cross-References:   CVE-2020-14370 CVE-2020-15157 CVE-2021-20199
                    CVE-2021-20291 CVE-2021-3602 CVE-2021-4024
                    CVE-2021-41190
CVSS scores:
                    CVE-2020-14370 (SUSE): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
                    CVE-2020-15157 (NVD) : 6.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
                    CVE-2020-15157 (SUSE): 6.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
                    CVE-2021-20199 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
                    CVE-2021-20199 (SUSE): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
                    CVE-2021-20291 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
                    CVE-2021-20291 (SUSE): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
                    CVE-2021-3602 (SUSE): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
                    CVE-2021-4024 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
                    CVE-2021-4024 (SUSE): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
                    CVE-2021-41190 (NVD) : 3 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N
                    CVE-2021-41190 (SUSE): 5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

Affected Products:
                    SUSE Linux Enterprise Desktop 15-SP3
                    SUSE Linux Enterprise High Performance Computing 15-SP3
                    SUSE Linux Enterprise Micro 5.1
                    SUSE Linux Enterprise Module for Basesystem 15-SP3
                    SUSE Linux Enterprise Module for Containers 15-SP3
                    SUSE Linux Enterprise Server 15-SP3
                    SUSE Linux Enterprise Server for SAP Applications 15-SP3
                    SUSE Manager Proxy 4.2
                    SUSE Manager Server 4.2
______________________________________________________________________________

   An update that solves 7 vulnerabilities, contains one
   feature and has one errata is now available.

Description:

   This update for conmon, libcontainers-common, libseccomp, podman fixes the
   following issues:

   podman was updated to 3.4.4.

   Security issues fixed:


   - fix CVE-2021-41190 [bsc#1193273], opencontainers: OCI manifest and index
     parsing confusion
   - fix CVE-2021-4024  [bsc#1193166], podman machine spawns gvproxy with
     port binded to all IPs
   - fix CVE-2021-20199 [bsc#1181640], Remote traffic to rootless containers
     is seen as orginating from localhost

   - Add: Provides: podman:/usr/bin/podman-remote subpackage for a clearer
     upgrade path from podman < 3.1.2

   Update to version 3.4.4:

     * Bugfixes

       - Fixed a bug where the podman exec command would, under some
         circumstances, print a warning message about failing to move conmon
         to the appropriate cgroup (#12535).
       - Fixed a bug where named volumes created as part of container
         creation (e.g. podman run --volume avolume:/a/mountpoint or similar)
         would be mounted with incorrect permissions (#12523).
       - Fixed a bug where the podman-remote create and podman-remote run
         commands did not properly handle the --entrypoint="" option (to
         clear the container's entrypoint) (#12521).

   - Update to version 3.4.3:

     * Security

       - This release addresses CVE-2021-4024, where the podman machine
         command opened the gvproxy API (used to forward ports to podman
         machine VMs) to the public internet on port 7777.
       - This release addresses CVE-2021-41190, where incomplete
         specification of behavior regarding image manifests could lead to
         inconsistent decoding on different clients.

     * Features

       - The --secret type=mount option to podman create and podman run
         supports a new option, target=, which specifies where in the
         container the secret will be mounted (#12287).

     * Bugfixes

       - Fixed a bug where rootless Podman would occasionally print warning
         messages about failing to move the pause process to a new cgroup
         (#12065).
       - Fixed a bug where the podman run and podman create commands would,
         when pulling images, still require TLS even with registries set to
         Insecure via config file (#11933).
       - Fixed a bug where the podman generate systemd command generated
         units that depended on multi-user.target, which has been removed
         from some distributions (#12438).
       - Fixed a bug where Podman could not run containers with images that
         had /etc/ as a symlink (#12189).
       - Fixed a bug where the podman logs -f command would, when using the
         journald logs backend, exit immediately if the container had
         previously been restarted (#12263).
       - Fixed a bug where, in containers on VMs created by podman machine,
         the host.containers.internal name pointed to the VM, not the host
         system (#11642).
       - Fixed a bug where containers and pods created by the podman play
         kube command in VMs managed by podman machine would not
         automatically forward ports from the host machine (#12248).
       - Fixed a bug where podman machine init would fail on OS X when GNU
         Coreutils was installed (#12329).
       - Fixed a bug where podman machine start would exit before SSH on the
         started VM was accepting connections (#11532).
       - Fixed a bug where the podman run command with signal proxying
         (--sig-proxy) enabled could print an error if it attempted to send a
         signal to a container that had just exited (#8086).
       - Fixed a bug where the podman stats command would not return correct
         information for containers running Systemd as PID1 (#12400).
       - Fixed a bug where the podman image save command would fail on OS X
         when writing the image to STDOUT (#12402).
       - Fixed a bug where the podman ps command did not properly handle PS
         arguments which contained whitespace (#12452).
       - Fixed a bug where the podman-remote wait command could fail to
         detect that the container exited and return an error under some
         circumstances (#12457).
       - Fixed a bug where the Windows MSI installer for podman-remote would
         break the PATH environment variable by adding an extra " (#11416).

     * API

       - The Libpod Play Kube endpoint now also accepts ConfigMap YAML as
         part of its payload, and will use provided any ConfigMap to
         configure provided pods and services.
       - Fixed a bug where the Compat Create endpoint for Containers would
         not always create the container's working directory if it did not
         exist (#11842).
       - Fixed a bug where the Compat Create endpoint for Containers returned
         an incorrect error message with 404 errors when the requested image
         was not found (#12315).
       - Fixed a bug where the Compat Create endpoint for Containers did not
         properly handle the HostConfig.Mounts field (#12419).
       - Fixed a bug where the Compat Archive endpoint for Containers did not
         properly report errors when the operation failed (#12420).
       - Fixed a bug where the Compat Build endpoint for Images ignored the
         layers query parameter (for caching intermediate layers from the
         build) (#12378).
       - Fixed a bug where the Compat Build endpoint for Images did not
         report errors in a manner compatible with Docker (#12392).
       - Fixed a bug where the Compat Build endpoint for Images would fail to
         build if the context directory was a symlink (#12409).
       - Fixed a bug where the Compat List endpoint for Images included
         manifest lists (and not just images) in returned results (#12453).

   - Update to version 3.4.2:

     * Fixed a bug where podman tag could not tag manifest lists (#12046).
     * Fixed a bug where built-in volumes specified by images would not be
       created correctly under some circumstances.
     * Fixed a bug where, when using Podman Machine on OS X, containers in
       pods did not have working port forwarding from the host (#12207).
     * Fixed a bug where the podman network reload command command on
       containers using the slirp4netns network mode and the rootlessport
       port forwarding driver would make an unnecessary attempt to restart
       rootlessport
       on containers that did not forward ports.
     * Fixed a bug where the podman generate kube command would generate YAML
       including some unnecessary (set to default) fields (e.g. empty SELinux
       and DNS configuration blocks, and the privileged flag when set to
       false) (#11995).
     * Fixed a bug where the podman pod rm command could, if interrupted at
       the right moment, leave a reference to an already-removed infra
       container behind (#12034).
     * Fixed a bug where the podman pod rm command would not remove pods with
       more than one container if all containers save for the infra container
       were stopped unless --force was specified (#11713).
     * Fixed a bug where the --memory flag to podman run and podman create
       did not accept a limit of 0 (which should specify unlimited memory)
       (#12002).
     * Fixed a bug where the remote Podman client's podman build command
       could attempt to build a Dockerfile in the working directory of the
       podman system service instance instead of the Dockerfile specified by
       the user (#12054).
     * Fixed a bug where the podman logs --tail command could function
       improperly (printing more output than requested) when the journald log
       driver was used.
     * Fixed a bug where containers run using the slirp4netns network mode
       with IPv6 enabled would not have IPv6 connectivity until several
       seconds after they started (#11062).
     * Fixed a bug where some Podman commands could cause an extra
       dbus-daemon process to be created (#9727).
     * Fixed a bug where rootless Podman would sometimes print warnings about
       a failure to move the pause process into a given CGroup (#12065).
     * Fixed a bug where the checkpointed field in podman inspect on a
       container was not set to false after a container was restored.
     * Fixed a bug where the podman system service command would print
       overly-verbose logs about request IDs (#12181).
     * Fixed a bug where Podman could, when creating a new container without
       a name explicitly specified by the user, sometimes use an
       auto-generated name already in use by another container if multiple
       containers were being created in parallel (#11735).

   Update to version 3.4.1:

     * Bugfixes

       - Fixed a bug where podman machine init could, under some
         circumstances, create invalid machine configurations which could not
         be started (#11824).
       - Fixed a bug where the podman machine list command would not properly
         populate some output fields.
       - Fixed a bug where podman machine rm could leave dangling sockets
         from the removed machine (#11393).
       - Fixed a bug where podman run --pids-limit=-1 was not supported (it
         now sets the PID limit in the container to unlimited) (#11782).
       - Fixed a bug where podman run and podman attach could throw errors
         about a closed network connection when STDIN was closed by the
         client (#11856).
       - Fixed a bug where the podman stop command could fail when run on a
         container that had another podman stop command run on it previously.
       - Fixed a bug where the --sync flag to podman ps was nonfunctional.
       - Fixed a bug where the Windows and OS X remote clients' podman stats
         command would fail (#11909).
       - Fixed a bug where the podman play kube command did not properly
         handle environment variables whose values contained an = (#11891).
       - Fixed a bug where the podman generate kube command could generate
         invalid annotations when run on containers with volumes that use
         SELinux relabelling (:z or :Z) (#11929).
       - Fixed a bug where the podman generate kube command would generate
         YAML including some unnecessary (set to default) fields (e.g. user
         and group, entrypoint, default protocol for forwarded ports)
         (#11914, #11915, and #11965).
       - Fixed a bug where the podman generate kube command could, under some
         circumstances, generate YAML including an invalid targetPort field
         for forwarded ports (#11930).
       - Fixed a bug where rootless Podman's podman info command could, under
         some circumstances, not read available CGroup controllers (#11931).
       - Fixed a bug where podman container checkpoint --export would fail to
         checkpoint any container created with --log-driver=none (#11974).

     * API

       - Fixed a bug where the Compat Create endpoint for Containers could
         panic when no options were passed to a bind mount of tmpfs (#11961).

   Update to version 3.4.0:

     * Features

       - Pods now support init containers! Init containers are containers
         which run before the rest of the pod starts. There are two types of
         init containers: "always", which always run before the pod is
         started, and "once", which only run the first time the pod starts
         and are subsequently removed. They can be added using the podman
         create command's --init-ctr option.
       - Support for init containers has also been added to podman play kube
         and podman generate kube - init containers contained in Kubernetes
         YAML will be created as Podman init containers, and YAML generated
         by Podman will include any init containers created.
       - The podman play kube command now supports building images. If the
         --build option is given and a directory with the name of the
         specified image exists in the current working directory and contains
         a valid Containerfile or Dockerfile, the image will be built and
         used for the container.
       - The podman play kube command now supports a new option, --teardown,
         which removes any pods and containers created by the given
         Kubernetes YAML.
       - The podman generate kube command now generates annotations for
         SELinux mount options on volume (:z and :Z) that are respected by
         the podman play kube command.
       - A new command has been added, podman pod logs, to return logs for
         all containers in a pod at the same time.
       - Two new commands have been added, podman volume export (to export a
         volume to a tar file) and podman volume import) (to populate a
         volume from a given tar file).
       - The podman auto-update command now supports simple rollbacks. If a
         container fails to start after an automatic update, it will be
         rolled back to the previous image and restarted again.
       - Pods now share their user namespace by default, and the podman pod
         create command now supports the --userns option. This allows
         rootless pods to be created with the --userns=keep-id option.
       - The podman pod ps command now supports a new filter with its
         --filter option, until, which returns pods created before a given
         timestamp.
       - The podman image scp command has been added. This command allows
         images to be transferred between different hosts.
       - The podman stats command supports a new option, --interval, to
         specify the amount of time before the information is refreshed.
       - The podman inspect command now includes ports exposed (but not
         published) by containers (e.g. ports from --expose when
         --publish-all is not specified).
       - The podman inspect command now has a new boolean value,
         Checkpointed, which indicates that a container was stopped as a
         result of a podman container checkpoint operation.
       - Volumes created by podman volume create now support setting quotas
         when run atop XFS. The size and inode options allow the maximum size
         and maximum number of inodes consumed by a volume to be limited.
       - The podman info command now outputs information on what log drivers,
         network drivers, and volume plugins are available for use (#11265).
       - The podman info command now outputs the current log driver in use,
         and the variant and codename of the distribution in use.
       - The parameters of the VM created by podman machine init (amount of
         disk space, memory, CPUs) can now be set in containers.conf.
       - The podman machine ls command now shows additional information
         (CPUs, memory, disk size) about VMs managed by podman machine.
       - The podman ps command now includes healthcheck status in container
         state for containers that have healthchecks (#11527).

     * Changes

       - The podman build command has a new alias, podman buildx, to improve
         compatibility with Docker. We have already added support for many
         docker buildx flags to podman build and aim to continue to do so.
       - Cases where Podman is run without a user session or a writable
         temporary files directory will now produce better error messages.
       - The default log driver has been changed from file to journald. The
         file driver did not properly support log rotation, so this should
         lead to a better experience. If journald is not available on the
         system, Podman will automatically revert to the file.
       - Podman no longer depends on ip for removing networks (#11403).
       - The deprecated --macvlan flag to podman network create now warns
         when it is used. It will be removed entirely in the Podman 4.0
         release.
       - The podman machine start command now prints a message when the VM is
         successfully started.
       - The podman stats command can now be used on containers that are
         paused.
       - The podman unshare command will now return the exit code of the
         command that was run in the user namespace (assuming the command was
         successfully run).
       - Successful healthchecks will no longer add a healthy line to the
         system log to reduce log spam.
       - As a temporary workaround for a lack of shortname prompts in the
         Podman remote client, VMs created by podman machine now default to
         only using the docker.io registry.

     * Bugfixes

       - Fixed a bug where whitespace in the definition of sysctls
         (particularly default sysctls specified in containers.conf) would
         cause them to be parsed incorrectly.
       - Fixed a bug where the Windows remote client improperly validated
         volume paths (#10900).
       - Fixed a bug where the first line of logs from a container run with
         the journald log driver could be skipped.
       - Fixed a bug where images created by podman commit did not include
         ports exposed by the container.
       - Fixed a bug where the podman auto-update command would ignore the
         io.containers.autoupdate.authfile label when pulling images (#11171).
       - Fixed a bug where the --workdir option to podman create and podman
         run could not be set to a directory where a volume was mounted
         (#11352).
       - Fixed a bug where systemd socket-activation did not properly work
         with systemd-managed Podman containers (#10443).
       - Fixed a bug where environment variable secrets added to a container
         were not available to exec sessions launched in the container.
       - Fixed a bug where rootless containers could fail to start the
         rootlessport port-forwarding service when XDG_RUNTIME_DIR was set to
         a long path.
       - Fixed a bug where arguments to the --systemd option to podman create
         and podman run were case-sensitive (#11387).
       - Fixed a bug where the podman manifest rm command would also remove
         images referenced by the manifest, not just the manifest itself
         (#11344).
       - Fixed a bug where the Podman remote client on OS X would not
         function properly if the TMPDIR environment variable was not set
         (#11418).
       - Fixed a bug where the /etc/hosts file was not guaranteed to contain
         an entry for localhost (this is still not guaranteed if --net=host
         is used; such containers will exactly match the host's /etc/hosts)
         (#11411).
       - Fixed a bug where the podman machine start command could print
         warnings about unsupported CPU features (#11421).
       - Fixed a bug where the podman info command could segfault when
         accessing cgroup information.
       - Fixed a bug where the podman logs -f command could hang when a
         container exited (#11461).
       - Fixed a bug where the podman generate systemd command could not be
         used on containers that specified a restart policy (#11438).
       - Fixed a bug where the remote Podman client's podman build command
         would fail to build containers if the UID and GID on the client were
         higher than 65536 (#11474).
       - Fixed a bug where the remote Podman client's podman build command
         would fail to build containers if the context directory was a
         symlink (#11732).
       - Fixed a bug where the --network flag to podman play kube was not
         properly parsed when a non-bridge network configuration was
         specified.
       - Fixed a bug where the podman inspect command could error when the
         container being inspected was removed as it was being inspected
         (#11392).
       - Fixed a bug where the podman play kube command ignored the default
         pod infra image specified in containers.conf.
       - Fixed a bug where the --format option to podman inspect was
         nonfunctional under some circumstances (#8785).
       - Fixed a bug where the remote Podman client's podman run and podman
         exec commands could skip a byte of output every 8192 bytes (#11496).
       - Fixed a bug where the podman stats command would print nonsensical
         results if the container restarted while it was running (#11469).
       - Fixed a bug where the remote Podman client would error when STDOUT
         was redirected on a Windows client (#11444).
       - Fixed a bug where the podman run command could return 0 when the
         application in the container exited with 125 (#11540).
       - Fixed a bug where containers with --restart=always set using the
         rootlessport port-forwarding service could not be restarted
         automatically.
       - Fixed a bug where the --cgroups=split option to podman create and
         podman run was silently discarded if the container was part of a pod.
       - Fixed a bug where the podman container runlabel command could fail
         if the image name given included a tag.
       - Fixed a bug where Podman could add an extra 127.0.0.1 entry to
         /etc/hosts under some circumstances (#11596).
       - Fixed a bug where the remote Podman client's podman untag command
         did not properly handle tags including a digest (#11557).
       - Fixed a bug where the --format option to podman ps did not properly
         support the table argument for tabular output.
       - Fixed a bug where the --filter option to podman ps did not properly
         handle filtering by healthcheck status (#11687).
       - Fixed a bug where the podman run and podman start --attach commands
         could race when retrieving the exit code of a container that had
         already been removed resulting in an error (e.g. by an external
         podman rm -f) (#11633).
       - Fixed a bug where the podman generate kube command would add default
         environment variables to generated YAML.
       - Fixed a bug where the podman generate kube command would add the
         default CMD from the image to generated YAML (#11672).
       - Fixed a bug where the podman rm --storage command could fail to
         remove containers under some circumstances (#11207).
       - Fixed a bug where the podman machine ssh command could fail when run
         on Linux (#11731).
       - Fixed a bug where the podman stop command would error when used on a
         container that was already stopped (#11740).
       - Fixed a bug where renaming a container in a pod using the podman
         rename command, then removing the pod using podman pod rm, could
         cause Podman to believe the new name of the container was
         permanently in use, despite the container being removed (#11750).

     * API

       - The Libpod Pull endpoint for Images now has a new query parameter,
         quiet, which (when set to true) suppresses image pull progress
         reports (#10612).
       - The Compat Events endpoint now includes several deprecated fields
         from the Docker v1.21 API for improved compatibility with older
         clients.
       - The Compat List and Inspect endpoints for Images now prefix image
         IDs with sha256: for improved Docker compatibility (#11623).
       - The Compat Create endpoint for Containers now properly sets defaults
         for healthcheck-related fields (#11225).
       - The Compat Create endpoint for Containers now supports volume
         options provided by the Mounts field (#10831).
       - The Compat List endpoint for Secrets now supports a new query
         parameter, filter, which allows returned results to be filtered.
       - The Compat Auth endpoint now returns the correct response code (500
         instead of 400) when logging into a registry fails.
       - The Version endpoint now includes information about the OCI runtime
         and Conmon in use (#11227).
       - Fixed a bug where the X-Registry-Config header was not properly
         handled, leading to errors when pulling images (#11235).
       - Fixed a bug where invalid query parameters could cause a null
         pointer dereference when creating error messages.
       - Logging of API requests and responses at trace level has been
         greatly improved, including the addition of an X-Reference-Id header
         to correlate requests and responses (#10053).

   Update to version 3.3.1:

     * Bugfixes

       - Fixed a bug where unit files created by podman generate systemd
         could not cleanup shut down containers when stopped by systemctl
         stop (#11304).
       - Fixed a bug where podman machine commands would not properly locate
         the gvproxy binary in some circumstances.
       - Fixed a bug where containers created as part of a pod using the
         --pod-id-file option would not join the pod's network namespace
   (#11303).
       - Fixed a bug where Podman, when using the systemd cgroups driver,
         could sometimes leak dbus sessions.
       - Fixed a bug where the until filter to podman logs and podman events
         was improperly handled, requiring input to be negated (#11158).
       - Fixed a bug where rootless containers using CNI networking run on
         systems using systemd-resolved for DNS would fail to start if
         resolved symlinked /etc/resolv.conf to an absolute path (#11358).

     * API

       - A large number of potential file descriptor leaks from improperly
         closing client connections have been fixed.

   Update to version 3.3.0:

     * Fix network aliases with network id
     * machine: compute sha256 as we read the image file
     * machine: check for file exists instead of listing directory
     * pkg/bindings/images.nTar(): slashify hdr.Name values
     * Volumes: Only remove from DB if plugin removal succeeds
     * For compatibility, ignore Content-Type
     * [v3.3] Bump c/image 5.15.2, buildah v1.22.3
     * Implement SD-NOTIFY proxy in conmon
     * Fix rootless cni dns without systemd stub resolver
     * fix rootlessport flake
     * Skip stats test in CGv1 container environments
     * Fix AVC denials in tests of volume mounts
     * Restore buildah-bud test requiring new images
     * Revert ".cirrus.yml: use fresh images for all VMs"
     * Fix device tests using ls test files
     * Enhance priv. dev. check
     * Workaround host availability of /dev/kvm
     * Skip cgroup-parent test due to frequent flakes
     * Cirrus: Fix not uploading logformatter html

   Switch to crun (bsc#1188914)

   Update to version 3.2.3:

     * Bump to v3.2.3
     * Update release notes for v3.2.3
     * vendor containers/common at v0.38.16
     * vendor containers/buildah at v1.21.3
     * Fix race conditions in rootless cni setup
     * CNI-in-slirp4netns: fix bind-mount for
       /run/systemd/resolve/stub-resolv.conf
     * Make rootless-cni setup more robust
     * Support uid,gid,mode options for secrets
     * vendor containers/common at v0.38.15
     * [CI:DOCS] podman search: clarify that results depend on implementation
     * vendor containers/common at v0.38.14
     * vendor containers/common at v0.38.13
     * [3.2] vendor containers/common at v0.38.12
     * Bump README to v3.2.2
     * Bump to v3.2.3-dev

   - Update to version 3.2.2:
     * Bump to v3.2.2
     * fix systemcontext to use correct TMPDIR
     * Scrub podman commands to use report package
     * Fix volumes with uid and gid options
     * Vendor in c/common v0.38.11
     * Initial release notes for v3.2.2
     * Fix restoring of privileged containers
     * Fix handling of podman-remote build --device
     * Add support for podman remote build -f - .
     * Fix panic condition in cgroups.getAvailableControllers
     * Fix permissions on initially created named volumes
     * Fix building static podman-remote
     * add correct slirp ip to /etc/hosts
     * disable tty-size exec checks in system tests
     * Fix resize race with podman exec -it
     * Fix documentation of the --format option of podman push
     * Fix systemd-resolved detection.
     * Health Check is not handled in the compat LibpodToContainerJSON
     * Do not use inotify for OCICNI
     * getContainerNetworkInfo: lock netNsCtr before sync
     * [NO TESTS NEEDED] Create /etc/mtab with the correct ownership
     * Create the /etc/mtab file if does not exists
     * [v3.2] cp: do not allow dir->file copying
     * create: support images with invalid platform
     * vendor containers/common at v0.38.10
     * logs: k8s-file: restore poll sleep
     * logs: k8s-file: fix spurious error logs
     * utils: move message from warning to debug
     * Bump to v3.2.2-dev

   - Update to version 3.2.1:
     * Bump to v3.2.1
     * Updated release notes for v3.2.1
     * Fix network connect race with docker-compose
     * Revert "Ensure minimum API version is set correctly in tests"
     * Fall back to string for dockerfile parameter
     * remote events: fix --stream=false
     * [CI:DOCS] fix incorrect network remove api doc
     * remote: always send resize before the container starts
     * remote events: support labels
     * remote pull: cancel pull when connection is closed
     * Fix network prune api docs
     * Improve systemd-resolved detection
     * logs: k8s-file: fix race
     * Fix image prune --filter cmd behavior
     * Several shell completion fixes
     * podman-remote build should handle -f option properly
     * System tests: deal with crun 0.20.1
     * Fix build tags for pkg/machine...
     * Fix pre-checkpointing
     * container: ignore named hierarchies
     * [v3.2] vendor containers/common at v0.38.9
     * rootless: fix fast join userns path
     * [v3.2] vendor containers/common at v0.38.7
     * [v3.2] vendor containers/common at v0.38.6
     * Correct qemu options for Intel macs
     * Ensure minimum API version is set correctly in tests
     * Bump to v3.2.1-dev

   - Update to version 3.2.0:
     * Bump to v3.2.0
     * Fix network create macvlan with subnet option
     * Final release notes updates for v3.2.0
     * add ipv6 nameservers only when the container has ipv6 enabled
     * Use request context instead of background
     * [v.3.2] events: support disjunctive filters
     * System tests: add :Z to volume mounts
     * generate systemd: make mounts portable
     * vendor containers/storage at v1.31.3
     * vendor containers/common at v0.38.5
     * Bump to v3.2.0-dev
     * Bump to v3.2.0-RC3
     * Update release notes for v3.2.0-RC3
     * Fix race on podman start --all
     * Fix race condition in running ls container in a pod
     * docs: --cert-dir: point to containers-certs.d(5)
     * Handle hard links in different directories
     * Improve OCI Runtime error
     * Handle hard links in remote builds
     * Podman info add support for status of cgroup controllers
     * Drop container does not exist on removal to debugf
     * Downgrade API service routing table logging
     * add libimage events
     * docs: generate systemd: XDG_RUNTIME_DIR
     * Fix problem copying files when container is in host pid namespace
     * Bump to v3.2.0-dev
     * Bump to v3.2.0-RC2
     * update c/common
     * Update Cirrus DEST_BRANCH to v3.2
     * Updated vendors of c/image, c/storage, Buildah
     * Initial release notes for v3.2.0-RC2
     * Add script for identifying commits in release branches
     * Add host.containers.internal entry into container's etc/hosts
     * image prune: remove unused images only with `--all`
     * podman network reload add rootless support
     * Use more recent `stale` release...
     * network tutorial: update with rootless cni changes
     * [CI:DOCS] Update first line in intro page
     * Use updated VM images + updated automation tooling
     * auto-update service: prune images
     * make vendor
     * fix system upgrade tests
     * Print "extracting" only on compressed file
     * podman image tree: restore previous behavior
     * fix network restart always test
     * fix incorrect log driver in podman container image
     * Add support for cli network prune --filter flag
     * Move filter parsing to common utils
     * Bump github.com/containers/storage from 1.30.2 to 1.30.3
     * Update nix pin with `make nixpkgs`
     * [CI:DOCS] hack/bats - new helper for running system tests
     * fix restart always with slirp4netns
     * Bump github.com/opencontainers/runc from 1.0.0-rc93 to 1.0.0-rc94
     * Bump github.com/coreos/go-systemd/v22 from 22.3.1 to 22.3.2
     * Add host.serviceIsRemote to podman info results
     * Add client disconnect to build handler loop
     * Remove obsolete skips
     * Fix podman-remote build --rm=false ...
     * fix: improved "containers/{name}/wait" endpoint
     * Bump github.com/containers/storage from 1.30.1 to 1.30.2
     * Add envars to the generated systemd unit
     * fix: use UTC Time Stamps in response JSON
     * fix container startup for empty pidfile
     * Kube like pods should share ipc,net,uts by default
     * fix: compat API "images/get" for multiple images
     * Revert escaped double dash man page flag syntax
     * Report Download complete in Compatibility mode
     * Add documentation on short-names
     * Bump github.com/docker/docker
     * Adds support to preserve auto update labels in generate and play kube
     * [CI:DOCS] Stop conversion of `--` into en dash
     * Revert Patch to relabel if selinux not enabled
     * fix per review request
     * Add support for environment variable secrets
     * fix pre review request
     * Fix infinite loop in isPathOnVolume
     * Add containers.conf information for changing defaults
     * CI: run rootless tests under ubuntu
     * Fix wrong macvlan PNG in networking doc.
     * Add restart-policy to container filters & --filter to podman start
     * Fixes docker-compose cannot set static ip when use ipam
     * channel: simplify implementation
     * build: improve regex for iidfile
     * Bump github.com/onsi/gomega from 1.11.0 to 1.12.0
     * cgroup: fix rootless --cgroup-parent with pods
     * fix: docker APIv2 `images/get`
     * codespell cleanup
     * Minor podmanimage docs updates.
     * Fix handling of runlabel IMAGE and NAME
     * Bump to v3.2.0-dev
     * Bump to v3.2.0-rc1
     * rootless: improve automatic range split
     * podman: set volatile storage flag for --rm containers
     * Bump github.com/onsi/ginkgo from 1.16.1 to 1.16.2
     * Bump github.com/containers/image/v5 from 5.11.1 to 5.12.0
     * migrate Podman to containers/common/libimage
     * Add filepath glob support to --security-opt unmask
     * Force log_driver to k8s-file for containers in containers
     * add --mac-address to podman play kube
     * compat api: Networks must be empty instead of null
     * System tests: honor $OCI_RUNTIME (for CI)
     * is this a bug?
     * system test image: add arm64v8 image
     * Fix troubleshooting documentation on handling sublemental groups.
     * Add --all to podman start
     * Fix variable reference typo. in multi-arch image action
     * cgroup: always honor --cgroup-parent with cgroupfs
     * Bump github.com/uber/jaeger-client-go
     * Don't require tests for github-actions & metadata
     * Detect if in podman machine virtual vm
     * Fix multi-arch image workflow typo
     * [CI:DOCS] Add titles to remote docs (windows)
     * Remove unused VolumeList* structs
     * Cirrus: Update F34beta -> F34
     * Update container image docs + fix unstable execution
     * Bump github.com/containers/storage from 1.30.0 to 1.30.1
     * TODO complete
     * Docker returns 'die' status rather then 'died' status
     * Check if another VM is running on machine start
     * [CI:DOCS] Improve titles of command HTML pages
     * system tests: networking: fix another race condition
     * Use seccomp_profile as default profile if defined in containers.conf
     * Bump github.com/json-iterator/go from 1.1.10 to 1.1.11
     * Vendored
     * Autoupdate local label functional
     * System tests: fix two race conditions
     * Add more documentation on conmon
     * Allow docker volume create API to pass without name
     * Cirrus: Update Ubuntu images to 21.04
     * Skip blkio-weight test when no kernel BFQ support
     * rootless: Tell the user what was led to the error, not just what it is
     * Add troubleshooting advice about the --userns option.
     * Fix images prune filter until
     * Fix logic for pushing stable multi-arch images
     * Fixes generate kube incorrect when bind-mounting "/" and "/root"
     * libpod/image: unit tests: don't use system's registries.conf.d
     * runtime: create userns when CAP_SYS_ADMIN is not present
     * rootless: attempt to copy current mappings first
     * [CI:DOCS] Restore missing content to manpages
     * [CI:DOCS] Fix Markdown layout bugs
     * Fix podman ps --filter ancestor to match exact ImageName/ImageID
     * Add machine-enabled to containers.conf for machine
     * Several multi-arch image build/push fixes
     * Add podman run --timeout option
     * Parse slirp4netns net options with compat api
     * Fix rootlesskit port forwarder with custom slirp cidr
     * Fix removal race condition in ListContainers
     * Add github-action workflow to build/push multi-arch
     * rootless: if root is not sub?id raise a debug message
     * Bump github.com/containers/common from 0.36.0 to 0.37.0
     * Add go template shell completion for --format
     * Add --group-add keep-groups: suplimentary groups into container
     * Fixes from make codespell
     * Typo fix to usage text of --compress option
     * corrupt-image test: fix an oops
     * Add --noheading flag to all list commands
     * Bump github.com/containers/storage from 1.29.0 to 1.30.0
     * Bump github.com/containers/image/v5 from 5.11.0 to 5.11.1
     * [CI:DOCS] Fix Markdown table layout bugs
     * podman-remote should show podman.sock info
     * rmi: don't break when the image is missing a manifest
     * [CI:DOCS] Rewrite --uidmap doc in podman-create.1.md and
       podman-run.1.md
     * Add support for CDI device configuration
     * [CI:DOCS] Add missing dash to verbose option
     * Bump github.com/uber/jaeger-client-go
     * Remove an advanced layer diff function
     * Ensure mount destination is clean, no trailing slash
     * add it for inspect pidfile
     * [CI:DOCS] Fix introduction page typo
     * support pidfile on container restore
     * fix start it
     * skip pidfile test on remote
     * improve document
     * set pidfile default value int containerconfig
     * add pidfile in inspection
     * add pidfile it for container start
     * skip pidfile it on remote
     * Modify according to comments
     * WIP: drop test requirement
     * runtime: bump required conmon version
     * runtime: return findConmon to libpod
     * oci: drop ExecContainerCleanup
     * oci: use `--full-path` option for conmon
     * use AttachSocketPath when removing conmon files
     * hide conmon-pidfile flag on remote mode
     * Fix possible panic in libpod/image/prune.go
     * add --ip to podman play kube
     * add flag autocomplete
     * add ut
     * add flag "--pidfile" for podman create/run
     * Add network bindings tests: remove and list
     * Fix build with GO111MODULE=off
     * system tests: build --pull-never: deal with flakes
     * compose test: diagnose flakes v3
     * podman play kube apply correct log driver
     * Fixes podman-remote save to directories does not work
     * Bump github.com/rootless-containers/rootlesskit from 0.14.1 to 0.14.2
     * Update documentation of podman-run to reflect volume "U" option
     * Fix flake on failed podman-remote build : try 2
     * compose test: ongoing efforts to diagnose flakes
     * Test that we don't error out on advertised --log-level values
     * At trace log level, print error text using %+v instead of %v
     * pkg/errorhandling.JoinErrors: don't throw away context for lone errors
     * Recognize --log-level=trace
     * Fix flake on failed podman-remote build
     * System tests: fix racy podman-inspect
     * Fixes invalid expression in save command
     * Bump github.com/containers/common from 0.35.4 to 0.36.0
     * Update nix pin with `make nixpkgs`
     * compose test: try to get useful data from flakes
     * Remove in-memory state implementation
     * Fix message about runtime to show only the actual runtime
     * System tests: setup: better cleanup of stray images
     * Bump github.com/containers/ocicrypt from 1.1.0 to 1.1.1
     * Reflect current state of prune implementation in docs
     * Do not delete container twice
     * [CI:DOCS] Correct status code for /pods/create
     * vendor in containers/storage v1.29.0
     * cgroup: do not set cgroup parent when rootless and cgroupfs
     * Overhaul Makefile binary and release worflows
     * Reorganize Makefile with sections and guide
     * Simplify Makefile help target
     * Don't shell to obtain current directory
     * Remove unnecessary/not-needed release.txt target
     * Fix incorrect version number output
     * Exclude .gitignore from test req.
     * Fix handling of $NAME and $IMAGE in runlabel
     * Update podman image Dockerfile to support Podman in container
     * Bump github.com/containers/image/v5 from 5.10.5 to 5.11.0
     * Fix slashes in socket URLs
     * Add network prune filters support to bindings
     * Add support for play/generate kube volumes
     * Update manifest API endpoints
     * Fix panic when not giving a machine name for ssh
     * cgroups: force 64 bits to ParseUint
     * Bump k8s.io/api from 0.20.5 to 0.21.0
     * [CI:DOCS] Fix formatting of podman-build man page
     * buildah-bud tests: simplify
     * Add missing return
     * Bump github.com/onsi/ginkgo from 1.16.0 to 1.16.1
     * speed up CI handling of images
     * Volumes prune endpoint should use only prune filters
     * Cirrus: Use Fedora 34beta images
     * Bump go.sum + Makefile for golang 1.16
     * Exempt Makefile changes from test requirements
     * Adjust libpod API Container Wait documentation to the code
     * [CI:DOCS] Update swagger definition of inspect manifest
     * use updated ubuntu images
     * podman unshare: add --rootless-cni to join the ns
     * Update swagger-check
     * swagger: remove name wildcards
     * Update buildah-bud diffs
     * Handle podman-remote --arch, --platform, --os
     * buildah-bud tests: handle go pseudoversions, plus...
     * Fix flaking rootless compose test
     * rootless cni add /usr/sbin to PATH if not present
     * System tests: special case for RHEL: require runc
     * Add --requires flag to podman run/create
     * [CI:DOCS] swagger-check: compare operations
     * [CI:DOCS] Polish swagger OpertionIDs
     * [NO TESTS NEEDED] Update nix pin with `make nixpkgs`
     * Ensure that `--userns=keep-id` sets user in config
     * [CI:DOCS] Set all operation id to be compatibile
     * Move operationIds to swagger:operation line
     * swagger: add operationIds that match with docker
     * Cirrus: Make use of shared get_ci_vm container
     * Don't relabel volumes if running in a privileged container
     * Allow users to override default storage opts with --storage-opt
     * Add support for podman --context default
     * Verify existence of auth file if specified
     * fix machine naming conventions
     * Initial network bindings tests
     * Update release notes to indicate CVE fix
     * Move socket activation check into init() and set global condition.
     * Bump github.com/onsi/ginkgo from 1.15.2 to 1.16.0
     * Http api tests for network prune with until filter
     * podman-run.1.md, podman-create.1.md : Adjust Markdown layout for
       --userns
     * Fix typos --uidmapping and --gidmapping
     * Add transport and destination info to manifest doc
     * Bump github.com/rootless-containers/rootlesskit from 0.14.0 to 0.14.1
     * Add default template functions
     * Fix missing podman-remote build options
     * Bump github.com/coreos/go-systemd/v22 from 22.3.0 to 22.3.1
     * Add ssh connection to root user
     * Add rootless docker-compose test to the CI
     * Use the slrip4netns dns in the rootless cni ns
     * Cleanup the rootless cni namespace
     * Add new docker-compose test for two networks
     * Make the docker-compose test work rootless
     * Remove unused rootless-cni-infra container files
     * Only use rootless RLK when the container has ports
     * Fix dnsname test
     * Enable rootless network connect/disconnect
     * Move slirp4netns functions into an extra file
     * Fix pod infra container cni network setup
     * Add rootless support for cni and --uidmap
     * rootless cni without infra container
     * Recreate until container prune tests for bindings
     * Remove --execute from podman machine ssh
     * Fixed podman-remote --network flag
     * Makefile: introduce install.docker-full
     * Makefile: ensure install.docker creates BINDIR
     * Fix unmount doc reference in image.rst
     * Should send the OCI runtime path not just the name to buildah
     * podman machine shell completion
     * Fix handling of remove --log-rusage param
     * Fix bindings prune containers flaky test
     * [CI:DOCS] Add local html build info to docs/README.md
     * Add podman machine list
     * Trim white space from /top endpoint results
     * Remove semantic version suffices from API calls
     * podman machine init --ignition-path
     * Document --volume from podman-remote run/create client
     * Update main branch to reflect the release of v3.1.0
     * Silence podman network reload errors with iptables-nft
     * Containers prune endpoint should use only prune filters
     * resolve proper aarch64 image names
     * APIv2 basic test: relax APIVersion check
     * Add machine support for qemu-system-aarch64
     * podman machine init user input
     * manpage xref: helpful diagnostic for unescaped dash-dash
     * Bump to v3.2.0-dev
     * swagger: update system version response body
     * buildah-bud tests: reenable pull-never test
     * [NO TESTS NEEDED] Shrink the size of podman-remote
     * Add powershell completions
     * [NO TESTS NEEDED] Drop Warning to Info, if cgroups not mounted
     * Fix long option format on docs.podman.io
     * system tests: friendier messages for 2-arg is()
     * service: use LISTEN_FDS
     * man pages: correct seccomp-policy label
     * rootless: use is_fd_inherited
     * podman generate systemd --new do not duplicate params
     * play kube: add support for env vars defined from secrets
     * play kube: support optional/mandatory env var from config map
     * play kube: prepare supporting other env source than config maps
     * Add machine support for more Linux distros
     * [NO TESTS NEEDED] Use same function podman-remote rmi as podman
     * Podman machine enhancements
     * Add problematic volume name to kube play error messages
     * Fix podman build --pull-never
     * [NO TESTS NEEDED] Fix for kernel without CONFIG_USER_NS
     * [NO TESTS NEEDED] Turn on podman-remote build --isolation
     * Fix list pods filter handling in libpod api
     * Remove resize race condition
     * [NO TESTS NEEDED] Vendor in containers/buildah v1.20.0
     * Use TMPDIR when commiting images
     * Add RequiresMountsFor= to systemd generate
     * Bump github.com/vbauerster/mpb/v6 from 6.0.2 to 6.0.3
     * Fix swapped dimensions from terminal.GetSize
     * Rename podman machine create to init and clean up
     * Correct json field name
     * system tests: new interactive tests
     * Improvements for machine
     * libpod/image: unit tests: use a `registries.conf` for aliases
     * libpod/image: unit tests: defer cleanup
     * libpod/image: unit tests: use `require.NoError`
     * Add --execute flag to podman machine ssh
     * introduce podman machine
     * Podman machine CLI and interface stub
     * Support multi doc yaml for generate/play kube
     * Fix filters in image http compat/libpod api endpoints
     * Bump github.com/containers/common from 0.35.3 to 0.35.4
     * Bump github.com/containers/storage from 1.28.0 to 1.28.1
     * Check if stdin is a term in --interactive --tty mode
     * [NO TESTS NEEDED] Remove /tmp/containers-users-* files on reboot
     * [NO TESTS NEEDED] Fix rootless volume plugins
     * Ensure manually-created volumes have correct ownership
     * Bump github.com/rootless-containers/rootlesskit
     * Unification of until filter across list/prune endpoints
     * Unification of label filter across list/prune endpoints
     * fixup
     * fix: build endpoint for compat API
     * [CI:DOCS] Add note to mappings for user/group userns in build
     * Bump k8s.io/api from 0.20.1 to 0.20.5
     * Validate passed in timezone from tz option
     * WIP: run buildah bud tests using podman
     * Fix containers list/prune http api filter behaviour
     * Generate Kubernetes PersistentVolumeClaims from named volumes

   - Update to version 3.1.2:
     * Bump to v3.1.2
     * Update release notes for v3.1.2
     * Ensure mount destination is clean, no trailing slash
     * Fixes podman-remote save to directories does not work
     * [CI:DOCS] Add missing dash to verbose option
     * [CI:DOCS] Fix Markdown table layout bugs
     * [CI:DOCS] Rewrite --uidmap doc in podman-create.1.md and
       podman-run.1.md
     * rmi: don't break when the image is missing a manifest
     * Bump containers/image to v5.11.1
     * Bump github.com/coreos/go-systemd from 22.2.0 to 22.3.1
     * Fix lint
     * Bump to v3.1.2-dev
   - Split podman-remote into a subpackage
   - Add missing scriptlets for systemd units
   - Escape macros in comments
   - Drop some obsolete workarounds, including %{go_nostrip}

   - Update to version 3.1.1:
     * Bump to v3.1.1
     * Update release notes for v3.1.1
     * podman play kube apply correct log driver
     * Fix build with GO111MODULE=off
     * [CI:DOCS] Set all operation id to be compatibile
     * Move operationIds to swagger:operation line
     * swagger: add operationIds that match with docker
     * Fix missing podman-remote build options
     * [NO TESTS NEEDED] Shrink the size of podman-remote
     * Move socket activation check into init() and set global condition.
     * rootless: use is_fd_inherited
     * Recreate until container prune tests for bindings
     * System tests: special case for RHEL: require runc
     * Document --volume from podman-remote run/create client
     * Containers prune endpoint should use only prune filters
     * Trim white space from /top endpoint results
     * Fix unmount doc reference in image.rst
     * Fix handling of remove --log-rusage param
     * Makefile: introduce install.docker-full
     * Makefile: ensure install.docker creates BINDIR
     * Should send the OCI runtime path not just the name to buildah
     * Fixed podman-remote --network flag
     * podman-run.1.md, podman-create.1.md : Adjust Markdown layout for
       --userns
     * Fix typos --uidmapping and --gidmapping
     * Add default template functions
     * Don't relabel volumes if running in a privileged container
     * Allow users to override default storage opts with --storage-opt
     * Add transport and destination info to manifest doc
     * Verify existence of auth file if specified
     * Ensure that `--userns=keep-id` sets user in config
     * [CI:DOCS] Update swagger definition of inspect manifest
     * Volumes prune endpoint should use only prune filters
     * Adjust libpod API Container Wait documentation to the code
     * Add missing return
     * [CI:DOCS] Fix formatting of podman-build man page
     * cgroups: force 64 bits to ParseUint
     * Fix slashes in socket URLs
     * [CI:DOCS] Correct status code for /pods/create
     * cgroup: do not set cgroup parent when rootless and cgroupfs
     * Reflect current state of prune implementation in docs
     * Do not delete container twice
     * Test that we don't error out on advertised --log-level values
     * At trace log level, print error text using %+v instead of %v
     * pkg/errorhandling.JoinErrors: don't throw away context for lone errors
     * Recognize --log-level=trace
     * Fix message about runtime to show only the actual runtime
     * Fix handling of $NAME and $IMAGE in runlabel
     * Fix flake on failed podman-remote build : try 2
     * Fix flake on failed podman-remote build
     * Update documentation of podman-run to reflect volume "U" option
     * Fixes invalid expression in save command
     * Fix possible panic in libpod/image/prune.go
     * Update all containers/ project vendors
     * Fix tests
     * Bump to v3.1.1-dev

   - Update to version 3.1.0:
     * Bump to v3.1.0
     * Fix test failure
     * Update release notes for v3.1.0 final release
     * [NO TESTS NEEDED] Turn on podman-remote build --isolation
     * Fix long option format on docs.podman.io
     * Fix containers list/prune http api filter behaviour
     * [CI:DOCS] Add note to mappings for user/group userns in build
     * Validate passed in timezone from tz option
     * Generate Kubernetes PersistentVolumeClaims from named volumes
     * libpod/image: unit tests: use a `registries.conf` for aliases
   - Require systemd 241 or newer due to podman dependency go-systemd v22,
     otherwise build will fail with unknown C name errors

   - Create docker subpackage to allow replacing docker with corresponding
     aliases to podman.

   - Update to v3.0.1
     * Changes
       - Several frequently-occurring WARN level log messages have been
         downgraded to INFO or DEBUG to not clutter terminal output. Bugfixes
       - Fixed a bug where the Created field of podman ps --format=json was
         formatted as a string instead of an Unix timestamp (integer) (#9315).
       - Fixed a bug where failing lookups of individual layers during the
         podman images command would cause the whole command to fail without
         printing output.
       - Fixed a bug where --cgroups=split did not function properly on
         cgroups v1 systems.
       - Fixed a bug where mounting a volume over an directory in the
         container that existed, but was empty, could fail (#9393).
       - Fixed a bug where mounting a volume over a directory in the
         container that existed could copy the entirety of the container's
         rootfs, instead of just the directory mounted over, into the volume
         (#9415).
       - Fixed a bug where Podman would treat the --entrypoint=[""] option to
         podman run and podman create as a literal empty string in the
         entrypoint, when instead it should have been ignored (#9377).
       - Fixed a bug where Podman would set the HOME environment variable to
         "" when the container ran as a user without an assigned home
         directory (#9378).
       - Fixed a bug where specifying a pod infra image that had no tags (by
         using its ID) would cause podman pod create to panic (#9374).
       - Fixed a bug where the --runtime option was not properly handled by
         the podman build command (#9365).
       - Fixed a bug where Podman would incorrectly print an error message
         related to the remote API when the remote API was not in use and
         starting Podman failed.
       - Fixed a bug where Podman would change ownership of a container's
         working directory, even if it already existed (#9387).
       - Fixed a bug where the podman generate systemd --new command would
         incorrectly escape %t when generating the path for the PID file
         (#9373).
       - Fixed a bug where Podman could, when run inside a Podman container
         with the host's containers/storage directory mounted into the
         container, erroneously detect a reboot and reset container state if
         the temporary directory was not also mounted in (#9191).
       - Fixed a bug where some options of the podman build command
         (including but not limited to --jobs) were nonfunctional (#9247).
     * API
       - Fixed a breaking change to the Libpod Wait API for Containers where
         the Conditions parameter changed type in Podman v3.0 (#9351).
       - Fixed a bug where the Compat Create endpoint for Containers did not
         properly handle forwarded ports that did not specify a host port.
       - Fixed a bug where the Libpod Wait endpoint for Containers could
         write duplicate headers after an error occurred.
       - Fixed a bug where the Compat Create endpoint for Images would not
         pull images that already had a matching tag present locally, even if
         a more recent version was available at the registry (#9232).
       - The Compat Create endpoint for Images has had its compatibility with
         Docker improved, allowing its use with the docker-java library.
     * Misc
       - Updated Buildah to v1.19.4
       - Updated the containers/storage library to v1.24.6
   - Changes from v3.0.0
     * Features
       - Podman now features initial support for Docker Compose.
       - Added the podman rename command, which allows containers to be
         renamed after they are created (#1925).
       - The Podman remote client now supports the podman copy command.
       - A new command, podman network reload, has been added. This command
         will re-configure the network of all running containers, and can be
         used to recreate firewall rules lost when the system firewall was
         reloaded (e.g. via firewall-cmd --reload).
       - Podman networks now have IDs. They can be seen in podman network ls
         and can be used when removing and inspecting networks. Existing
         networks receive IDs automatically.
       - Podman networks now also support labels. They can be added via the
         --label option to network create, and podman network ls can filter
         labels based on them.
       - The podman network create command now supports setting bridge MTU
         and VLAN through the --opt option (#8454).
       - The podman container checkpoint and podman container restore
         commands can now checkpoint and restore containers that include
         volumes.
       - The podman container checkpoint command now supports the
         --with-previous and --pre-checkpoint options, and the podman
         container restore command now support the --import-previous option.
         These add support for two-step checkpointing with lowered dump times.
       - The podman push command can now push manifest lists. Podman will
         first attempt to push as an image, then fall back to pushing as a
         manifest list if that fails.
       - The podman generate kube command can now be run on multiple
         containers at once, and will generate a single pod containing all of
         them.
       - The podman generate kube and podman play kube commands now support
         Kubernetes DNS configuration, and will preserve custom DNS
         configuration when exporting or importing YAML (#9132).
       - The podman generate kube command now properly supports generating
         YAML for containers and pods creating using host networking
         (--net=host) (#9077).
       - The podman kill command now supports a --cidfile option to kill
         containers given a file containing the container's ID (#8443).
       - The podman pod create command now supports the --net=none option
         (#9165).
       - The podman volume create command can now specify volume UID and GID
         as options with the UID and GID fields passed to the the --opt
         option.
       - Initial support has been added for Docker Volume Plugins. Podman can
         now define available plugins in containers.conf and use them to
         create volumes with podman volume create --driver.
       - The podman run and podman create commands now support a new option,
         --platform, to specify the platform of the image to be used when
         creating the container.
       - The --security-opt option to podman run and podman create now
         supports the systempaths=unconfined option to unrestrict access to
         all paths in the container, as well as mask and unmask options to
         allow more granular restriction of container paths.
       - The podman stats --format command now supports a new format
         specified, MemUsageBytes, which prints the raw bytes of memory
         consumed by a container without human-readable formatting #8945.
       - The podman ps command can now filter containers based on what pod
         they are joined to via the pod filter (#8512).
       - The podman pod ps command can now filter pods based on what networks
         they are joined to via the network filter. The podman pod ps command
         can now print information on what networks a pod is joined to via
         the .Networks specifier to the --format option.
       - The podman system prune command now supports filtering what
         containers, pods, images, and volumes will be pruned.
       - The podman volume prune commands now supports filtering what volumes
         will be pruned.
       - The podman system prune command now includes information on space
         reclaimed (#8658).
       - The podman info command will now properly print information about
         packages in use on Gentoo and Arch systems.
       - The containers.conf file now contains an option for disabling
         creation of a new kernel keyring on container creation (#8384).
       - The podman image sign command can now sign multi-arch images by
         producing a signature for each image in a given manifest list.
       - The podman image sign command, when run as rootless, now supports
         per-user registry configuration files in
         $HOME/.config/containers/registries.d.
       - Configuration options for slirp4netns can now be set system-wide via
         the NetworkCmdOptions configuration option in containers.conf.
       - The MTU of slirp4netns can now be configured via the mtu= network
         command option (e.g. podman run --net slirp4netns:mtu=9000).
     * Security
       - A fix for CVE-2021-20199 is included. Podman between v1.8.0 and
         v2.2.1 used 127.0.0.1 as the source address for all traffic
         forwarded into rootless containers by a forwarded port; this has
         been changed to address the issue.
     * Changes
       - Shortname aliasing support has now been turned on by default. All
         Podman commands that must pull an image will, if a TTY is available,
         prompt the user about what image to pull.
       - The podman load command no longer accepts a NAME[:TAG] argument. The
         presence of this argument broke CLI compatibility with Docker by
         making docker load commands unusable with Podman (#7387).
       - The Go bindings for the HTTP API have been rewritten with a focus on
         limiting dependency footprint and improving extensibility. Read more
         here.
       - The legacy Varlink API has been completely removed from Podman.
       - The default log level for Podman has been changed from Error to Warn.
       - The podman network create command can now create macvlan networks
         using the --driver macvlan option for Docker compatibility. The
         existing --macvlan flag has been deprecated and will be removed in
         Podman 4.0 some time next year.
       - The podman inspect command has had the LogPath and LogTag fields
         moved into the LogConfig structure (from the root of the Inspect
         structure). The maximum size of the log file is also included.
       - The podman generate systemd command no longer generates unit files
         using the deprecated KillMode=none option (#8615).
       - The podman stop command now releases the container lock while
         waiting for it to stop - as such, commands like podman ps will no
         longer block until podman stop completes (#8501).
       - Networks created with podman network create --internal no longer use
         the dnsname plugin. This configuration never functioned as expected.
       - Error messages for the remote Podman client have been improved when
         it cannot connect to a Podman service.
       - Error messages for podman run when an invalid SELinux is specified
         have been improved.
       - Rootless Podman features improved support for containers with a
         single user mapped into the rootless user namespace.
       - Pod infra containers now respect default sysctls specified in
         containers.conf allowing for advanced configuration of the
         namespaces they will share.
       - SSH public key handling for remote Podman has been improved.
     * Bugfixes
       - Fixed a bug where the podman history --no-trunc command would
         truncate the Created By field (#9120).
       - Fixed a bug where root containers that did not explicitly specify a
         CNI network to join did not generate an entry for the network in use
         in the Networks field of the output of podman inspect (#6618).
       - Fixed a bug where, under some circumstances, container working
         directories specified by the image (via the WORKDIR instruction) but
         not present in the image, would not be created (#9040).
       - Fixed a bug where the podman generate systemd command would generate
         invalid unit files if the container was creating using a command
         line that included doubled braces ({{ and }}), e.g.
         --log-opt-tag={{.Name}} (#9034).
       - Fixed a bug where the podman generate systemd --new command could
         generate unit files including invalid Podman commands if the
         container was created using merged short options (e.g. podman run
         -dt) (#8847).
       - Fixed a bug where the podman generate systemd --new command could
         generate unit files that did not handle Podman commands including
         some special characters (e.g. $) (#9176
       - Fixed a bug where rootless containers joining CNI networks could not
         set a static IP address (#7842).
       - Fixed a bug where rootless containers joining CNI networks could not
         set network aliases (#8567).
       - Fixed a bug where the remote client could, under some circumstances,
         not include the Containerfile when sending build context to the
         server (#8374).
       - Fixed a bug where rootless Podman did not mount /sys as a new sysfs
         in some circumstances where it was acceptable.
       - Fixed a bug where rootless containers that both joined a user
         namespace and a CNI networks would cause a segfault. These options
         are incompatible and now return an error.
       - Fixed a bug where the podman play kube command did not properly
         handle CMD and ARGS from images (#8803).
       - Fixed a bug where the podman play kube command did not properly
         handle environment variables from images (#8608).
       - Fixed a bug where the podman play kube command did not properly
         print errors that occurred when starting containers.
       - Fixed a bug where the podman play kube command errored when
         hostNetwork was used (#8790).
       - Fixed a bug where the podman play kube command would always pull
         images when the :latest tag was specified, even if the image was
         available locally (#7838).
       - Fixed a bug where the podman play kube command did not properly
         handle SELinux configuration, rending YAML with custom SELinux
         configuration unusable (#8710).
       - Fixed a bug where the podman generate kube command incorrectly
         populated the args and command fields of generated YAML (#9211).
       - Fixed a bug where containers in a pod would create a duplicate entry
         in the pod's shared /etc/hosts file every time the container
         restarted (#8921).
       - Fixed a bug where the podman search --list-tags command did not
         support the --format option (#8740).
       - Fixed a bug where the http_proxy option in containers.conf was not
         being respected, and instead was set unconditionally to true (#8843).
       - Fixed a bug where rootless Podman could, on systems with a recent
         Conmon and users with a long username, fail to attach to containers
         (#8798).
       - Fixed a bug where the podman images command would break and fail to
         display any images if an empty manifest list was present in storage
         (#8931).
       - Fixed a bug where locale environment variables were not properly
         passed on to Conmon.
       - Fixed a bug where Podman would not build on the MIPS architecture
         (#8782).
       - Fixed a bug where rootless Podman could fail to properly configure
         user namespaces for rootless containers when the user specified a
         --uidmap option that included a mapping beginning with UID 0.
       - Fixed a bug where the podman logs command using the k8s-file backend
         did not properly handle partial log lines with a length of 1 (#8879).
       - Fixed a bug where the podman logs command with the --follow option
         did not properly handle log rotation (#8733).
       - Fixed a bug where user-specified HOSTNAME environment variables were
         overwritten by Podman (#8886).
       - Fixed a bug where Podman would applied default sysctls from
         containers.conf in too many situations (e.g. applying network
         sysctls when the container shared its network with a pod).
       - Fixed a bug where Podman did not properly handle cases where a
         secondary image store was in use and an image was present in both
         the secondary and primary stores (#8176).
       - Fixed a bug where systemd-managed rootless Podman containers where
         the user in the container was not root could fail as the container's
         PID file was not accessible to systemd on the host (#8506).
       - Fixed a bug where the --privileged option to podman run and podman
         create would, under some circumstances, not disable Seccomp (#8849).
       - Fixed a bug where the podman exec command did not properly add
         capabilities when the container or exec session were run with
         --privileged.
       - Fixed a bug where rootless Podman would use the --enable-sandbox
         option to slirp4netns unconditionally, even when pivot_root was
         disabled, rendering slirp4netns unusable when pivot_root was
         disabled (#8846).
       - Fixed a bug where podman build --logfile did not actually write the
         build's log to the logfile.
       - Fixed a bug where the podman system service command did not close
         STDIN, and could display user-interactive prompts (#8700).
       - Fixed a bug where the podman system reset command could, under some
         circumstances, remove all the contents of the XDG_RUNTIME_DIR
         directory (#8680).
       - Fixed a bug where the podman network create command created CNI
         configurations that did not include a default gateway (#8748).
       - Fixed a bug where the podman.service systemd unit provided by
         default used the wrong service type, and would cause systemd to not
         correctly register the service as started (#8751).
       - Fixed a bug where, if the TMPDIR environment variable was set for
         the container engine in containers.conf, it was being ignored.
       - Fixed a bug where the podman events command did not properly handle
         future times given to the --until option (#8694).
       - Fixed a bug where the podman logs command wrote container STDERR
         logs to STDOUT instead of STDERR (#8683).
       - Fixed a bug where containers created from an image with multiple
         tags would report that they were created from the wrong tag (#8547).
       - Fixed a bug where container capabilities were not set properly when
         the --cap-add=all and --user options to podman create and podman run
         were combined.
       - Fixed a bug where the --layers option to podman build was
         nonfunctional (#8643).
       - Fixed a bug where the podman system prune command did not act
         recursively, and thus would leave images, containers, pods, and
         volumes present that would be removed by a subsequent call to podman
         system prune (#7990).
       - Fixed a bug where the --publish option to podman run and podman
         create did not properly handle ports specified as a range of ports
         with no host port specified (#8650).
       - Fixed a bug where --format did not support JSON output for
         individual fields (#8444).
       - Fixed a bug where the podman stats command would fail when run on
         root containers using the slirp4netns network mode (#7883).
       - Fixed a bug where the Podman remote client would ask for a password
         even if the server's SSH daemon did not support password
         authentication (#8498).
       - Fixed a bug where the podman stats command would fail if the system
         did not support one or more of the cgroup controllers Podman
         supports (#8588).
       - Fixed a bug where the --mount option to podman create and podman run
         did not ignore the consistency mount option.
       - Fixed a bug where failures during the resizing of a container's TTY
         would print the wrong error.
       - Fixed a bug where the podman network disconnect command could cause
         the podman inspect command to fail for a container until it was
         restarted (#9234).
       - Fixed a bug where containers created from a read-only rootfs (using
         the --rootfs option to podman create and podman run) would fail
         (#9230).
       - Fixed a bug where specifying Go templates to the --format option to
         multiple Podman commands did not support the join function (#8773).
       - Fixed a bug where the podman rmi command could, when run in parallel
         on multiple images, return layer not known errors (#6510).
       - Fixed a bug where the podman inspect command on containers displayed
         unlimited ulimits incorrectly (#9303).
       - Fixed a bug where Podman would fail to start when a volume was
         mounted over a directory in a container that contained symlinks that
         terminated outside the directory and its subdirectories (#6003). API
       - Libpod API version has been bumped to v3.0.0.
       - All Libpod Pod APIs have been modified to properly report errors
         with individual containers. Cases where the operation as a whole
         succeeded but individual containers failed now report an HTTP 409
         error (#8865).
       - The Compat API for Containers now supports the Rename and Copy APIs.
       - Fixed a bug where the Compat Prune APIs (for volumes, containers,
         and images) did not return the amount of space reclaimed in their
         responses.
       - Fixed a bug where the Compat and Libpod Exec APIs for Containers
         would drop errors that occurred prior to the exec session
         successfully starting (e.g. a "no such file" error if an invalid
         executable was passed) (#8281)
       - Fixed a bug where the Volumes field in the Compat Create API for
         Containers was being ignored (#8649).
       - Fixed a bug where the NetworkMode field in the Compat Create API for
         Containers was not handling some values, e.g. container:, correctly.
       - Fixed a bug where the Compat Create API for Containers did not set
         container name properly.
       - Fixed a bug where containers created using the Compat Create API
         unconditionally used Kubernetes file logging (the default specified
         in containers.conf is now used).
       - Fixed a bug where the Compat Inspect API for Containers could
         include container states not recognized by Docker.
       - Fixed a bug where Podman did not properly clean up after calls to
         the Events API when the journald backend was in use, resulting in a
         leak of file descriptors (#8864).
       - Fixed a bug where the Libpod Pull endpoint for Images could fail
         with an index out of range error under certain circumstances (#8870).
       - Fixed a bug where the Libpod Exists endpoint for Images could panic.
       - Fixed a bug where the Compat List API for Containers did not support
         all filters (#8860).
       - Fixed a bug where the Compat List API for Containers did not
         properly populate the Status field.
       - Fixed a bug where the Compat and Libpod Resize APIs for Containers
         ignored the height and width parameters (#7102).
       - Fixed a bug where the Compat Search API for Images returned an
         incorrectly-formatted JSON response (#8758).
       - Fixed a bug where the Compat Load API for Images did not properly
         clean up temporary files.
       - Fixed a bug where the Compat Create API for Networks could panic
         when an empty IPAM configuration was specified.
       - Fixed a bug where the Compat Inspect and List APIs for Networks did
         not include Scope.
       - Fixed a bug where the Compat Wait endpoint for Containers did not
         support the same wait conditions that Docker did.
     * Misc
       - Updated Buildah to v1.19.2
       - Updated the containers/storage library to v1.24.5
       - Updated the containers/image library to v5.10.2
       - Updated the containers/common library to v0.33.4

   - Update to v2.2.1
     * Changes
       - Due to a conflict with a previously-removed field, we were forced to
         modify the way image volumes (mounting images into containers using
         --mount type=image) were handled in the database. As a result,
   containers created in Podman 2.2.0 with image volume will not have them in
   v2.2.1, and these containers will need to be re-created.
     * Bugfixes
       - Fixed a bug where rootless Podman would, on systems without the
         XDG_RUNTIME_DIR environment variable defined, use an incorrect path
         for the PID file of the Podman pause process, causing Podman to fail
         to start (#8539).
       - Fixed a bug where containers created using Podman v1.7 and earlier
         were unusable in Podman due to JSON decode errors (#8613).
       - Fixed a bug where Podman could retrieve invalid cgroup paths, instead
         of erroring, for containers that were not running.
       - Fixed a bug where the podman system reset command would print a
         warning about a duplicate shutdown handler being registered.
       - Fixed a bug where rootless Podman would attempt to mount sysfs in
         circumstances where it was not allowed; some OCI runtimes (notably
         crun) would fall back to alternatives and not fail, but others
         (notably runc) would fail to run containers.
       - Fixed a bug where the podman run and podman create commands would
         fail to create containers from untagged images (#8558).
       - Fixed a bug where remote Podman would prompt for a password even
         when the server did not support password authentication (#8498).
       - Fixed a bug where the podman exec command did not move the Conmon
         process for the exec session into the correct cgroup.
       - Fixed a bug where shell completion for the ancestor option to podman
         ps --filter did not work correctly.
       - Fixed a bug where detached containers would not properly clean
         themselves up (or remove themselves if --rm was set) if the Podman
         command that created them was invoked with --log-level=debug.
     * API
       - Fixed a bug where the Compat Create endpoint for Containers did not
         properly handle the Binds and Mounts parameters in HostConfig.
       - Fixed a bug where the Compat Create endpoint for Containers ignored
         the Name query parameter.
       - Fixed a bug where the Compat Create endpoint for Containers did not
         properly handle the "default" value for NetworkMode (this value is
         used extensively by docker-compose) (#8544).
       - Fixed a bug where the Compat Build endpoint for Images would
         sometimes incorrectly use the target query parameter as the image's
         tag.
     * Misc
       - Podman v2.2.0 vendored a non-released, custom version of the
         github.com/spf13/cobra package; this has been reverted to the latest
         upstream release to aid in packaging.
       - Updated the containers/image library to v5.9.0

   - Update to v2.2.0
    * Features
     - Experimental support for shortname aliasing has been added. This is
       not enabled by default, but can be turned on by setting the
       environment variable CONTAINERS_SHORT_NAME_ALIASING to on.
       Documentation is available here and here.
     - Initial support has been added for the podman network connect and
       podman network disconnect commands, which allow existing containers to
       modify what networks they are connected to. At present, these commands
       can only be used on running containers that did not specify
       --network=none when they were created.
     - The podman run command now supports the --network-alias option to set
       network aliases (additional names the container can be accessed at
       from other containers via DNS if the dnsname CNI plugin is in use).
       Aliases can also be added and removed using the new podman network
       connect and podman network disconnect commands. Please note that this
       requires a new release (v1.1.0) of the dnsname plugin, and will only
       work on newly-created CNI networks.
     - The podman generate kube command now features support for exporting
       container's memory and CPU limits (#7855).
     - The podman play kube command now features support for setting CPU and
       Memory limits for containers (#7742).
     - The podman play kube command now supports persistent volumes claims
       using Podman named volumes.
     - The podman play kube command now supports Kubernetes configmaps via
       the --configmap option (#7567).
     - The podman play kube command now supports a --log-driver option to set
       the log driver for created containers.
     - The podman play kube command now supports a --start option, enabled by
       default, to start the pod after creating it. This allows for podman
       play kube to be more easily used in systemd unitfiles.
     - The podman network create command now supports the --ipv6 option to
       enable dual-stack IPv6 networking for created networks (#7302).
     - The podman inspect command can now inspect pods, networks, and
       volumes, in addition to containers and images (#6757).
     - The --mount option for podman run and podman create now supports a new
       type, image, to mount the contents of an image into the container at a
       given location.
     - The Bash and ZSH completions have been completely reworked and have
       received significant enhancements! Additionally, support for Fish
       completions and completions for the podman-remote executable have been
       added.
     - The --log-opt option for podman create and podman run now supports the
       max-size option to set the maximum size for a container's logs (#7434).
     - The --network option to the podman pod create command now allows pods
       to be configured to use slirp4netns networking, even when run as root
       (#6097).
     - The podman pod stop, podman pod pause, podman pod unpause, and podman
       pod kill commands now work on multiple containers in parallel and
       should be significantly faster.
     - The podman search command now supports a --list-tags option to list
       all available tags for a single image in a single repository.
     - The podman search command can now output JSON using the --format=json
       option.
     - The podman diff and podman mount commands now work with all containers
       in the storage library, including those not created by Podman. This
       allows them to be used with Buildah and CRI-O containers.
     - The podman container exists command now features a --external option
       to check if a container exists not just in Podman, but also in the
       storage library. This will allow Podman to identify Buildah and CRI-O
       containers.
     - The --tls-verify and --authfile options have been enabled for use with
       remote Podman.
     - The /etc/hosts file now includes the container's name and hostname
       (both pointing to localhost) when the container is run with --net=none
       (#8095).
     - The podman events command now supports filtering events based on the
       labels of the container they occurred on using the --filter
       label=key=value option.
     - The podman volume ls command now supports filtering volumes based on
       their labels using the --filter label=key=value option.
     - The --volume and --mount options to podman run and podman create now
       support two new mount propagation options, unbindable and runbindable.
     - The name and id filters for podman pod ps now match based on a regular
       expression, instead of requiring an exact match.
     - The podman pod ps command now supports a new filter status, that
       matches pods in a certain state.
    * Changes
     - The podman network rm --force command will now also remove pods that
       are using the network (#7791).
     - The podman volume rm, podman network rm, and podman pod rm commands
       now return exit code 1 if the object specified for removal does not
       exist, and exit code 2 if the object is in use and the --force option
       was not given.
     - If /dev/fuse is passed into Podman containers as a device, Podman will
       open it before starting the container to ensure that the kernel module
       is loaded on the host and the device is usable in the container.
     - Global Podman options that were not supported with remote operation
       have been removed from podman-remote (e.g. --cgroup-manager,
       --storage-driver).
     - Many errors have been changed to remove repetition and be more clear
       as to what has gone wrong.
     - The --storage option to podman rm is now enabled by default, with
       slightly changed semantics. If the given container does not exist in
       Podman but does exist in the storage library, it will be removed even
       without the --storage option. If the container exists in Podman it
       will be removed normally. The --storage option for podman rm is now
       deprecated and will be removed in a future release.
     - The --storage option to podman ps has been renamed to --external. An
       alias has been added so the old form of the option will continue to
       work.
     - Podman now delays the SIGTERM and SIGINT signals during container
       creation to ensure that Podman is not stopped midway through creating
       a container resulting in potential resource leakage (#7941).
     - The podman save command now strips signatures from images it is
       exporting, as the formats we export to do not support signatures
       (#7659).
     - A new Degraded state has been added to pods. Pods that have some, but
       not all, of their containers running are now considered to be Degraded
       instead of Running.
     - Podman will now print a warning when conflicting network options
       related to port forwarding (e.g. --publish and --net=host) are
       specified when creating a container.
     - The --restart on-failure and --rm options for containers no longer
       conflict. When both are specified, the container will be restarted if
       it exits with a non-zero error code, and removed if it exits cleanly
       (#7906).
     - Remote Podman will no longer use settings from the client's
       containers.conf; defaults will instead be provided by the server's
       containers.conf (#7657).
     - The podman network rm command now has a new alias, podman network
       remove (#8402).
    * Bugfixes
     - Fixed a bug where podman load on the remote client did not error when
       attempting to load a directory, which is not yet supported for remote
       use.
     - Fixed a bug where rootless Podman could hang when the newuidmap binary
       was not installed (#7776).
     - Fixed a bug where the --pull option to podman run, podman create, and
       podman build did not match Docker's behavior.
     - Fixed a bug where sysctl settings from the containers.conf
       configuration file were applied, even if the container did not join
       the namespace associated with a sysctl.
     - Fixed a bug where Podman would not return the text of errors encounted
       when trying to run a healthcheck for a container.
     - Fixed a bug where Podman was accidentally setting the containers
       environment variable in addition to the expected container environment
       variable.
     - Fixed a bug where rootless Podman using CNI networking did not
       properly clean up DNS entries for removed containers (#7789).
     - Fixed a bug where the podman untag --all command was not supported
       with remote Podman.
     - Fixed a bug where the podman system service command could time out
       even if active attach connections were present (#7826).
     - Fixed a bug where the podman system service command would sometimes
       never time out despite no active connections being present.
     - Fixed a bug where Podman's handling of capabilities, specifically
       inheritable, did not match Docker's.
     - Fixed a bug where podman run would fail if the image specified was a
       manifest list and had already been pulled (#7798).
     - Fixed a bug where Podman did not take search registries into account
       when looking up images locally (#6381).
     - Fixed a bug where the podman manifest inspect command would fail for
       images that had already been pulled (#7726).
     - Fixed a bug where rootless Podman would not add supplemental GIDs to
       containers when when a user, but not a group, was set via the --user
       option to podman create and podman run and sufficient GIDs were
       available to add the groups (#7782).
     - Fixed a bug where remote Podman commands did not properly handle cases
       where the user gave a name that could also be a short ID for a pod or
       container (#7837).
     - Fixed a bug where podman image prune could leave images ready to be
       pruned after podman image prune was run (#7872).
     - Fixed a bug where the podman logs command with the journald log driver
       would not read all available logs (#7476).
     - Fixed a bug where the --rm and --restart options to podman create and
       podman run did not conflict when a restart policy that is not
       on-failure was chosen (#7878).
     - Fixed a bug where the --format "table {{ .Field }}" option to numerous
       Podman commands ceased to function on Podman v2.0 and up.
     - Fixed a bug where pods did not properly share an SELinux label between
       their containers, resulting in containers being unable to see the
       processes of other containers when the pod shared a PID namespace
       (#7886).
     - Fixed a bug where the --namespace option to podman ps did not work
       with the remote client (#7903).
     - Fixed a bug where rootless Podman incorrectly calculated the number of
       UIDs available in the container if multiple different ranges of UIDs
       were specified.
     - Fixed a bug where the /etc/hosts file would not be correctly populated
       for containers in a user namespace (#7490).
     - Fixed a bug where the podman network create and podman network remove
       commands could race when run in parallel, with unpredictable results
       (#7807).
     - Fixed a bug where the -p option to podman run, podman create, and
       podman pod create would, when given only a single number (e.g. -p 80),
       assign the same port for both host and container, instead of
       generating a random host port (#7947).
     - Fixed a bug where Podman containers did not properly store the cgroup
       manager they were created with, causing them to stop functioning after
       the cgroup manager was changed in containers.conf or with the
       --cgroup-manager option (#7830).
     - Fixed a bug where the podman inspect command did not include
       information on the CNI networks a container was connected to if it was
       not running.
     - Fixed a bug where the podman attach command would not print a newline
       after detaching from the container (#7751).
     - Fixed a bug where the HOME environment variable was not set properly
       in containers when the --userns=keep-id option was set (#8004).
     - Fixed a bug where the podman container restore command could panic
       when the container in question was in a pod (#8026).
     - Fixed a bug where the output of the podman image trust show --raw
       command was not properly formatted.
     - Fixed a bug where the podman runlabel command could panic if a label
       to run was not given (#8038).
     - Fixed a bug where the podman run and podman start --attach commands
       would exit with an error when the user detached manually using the
       detach keys on remote Podman (#7979).
     - Fixed a bug where rootless CNI networking did not use the dnsname CNI
       plugin if it was not available on the host, despite it always being
       available in the container used for rootless networking (#8040).
     - Fixed a bug where Podman did not properly handle cases where an OCI
       runtime is specified by its full path, and could revert to using
       another OCI runtime with the same binary path that existed in the
       system $PATH on subsequent invocations.
     - Fixed a bug where the --net=host option to podman create and podman
       run would cause the /etc/hosts file to be incorrectly populated
       (#8054).
     - Fixed a bug where the podman inspect command did not include container
       network information when the container shared its network namespace
       (IE, joined a pod or another container's network namespace via
       --net=container:...) (#8073).
     - Fixed a bug where the podman ps command did not include information on
       all ports a container was publishing.
     - Fixed a bug where the podman build command incorrectly forwarded STDIN
       into build containers from RUN instructions.
     - Fixed a bug where the podman wait command's --interval option did not
       work when units were not specified for the duration (#8088).
     - Fixed a bug where the --detach-keys and --detach options could be
       passed to podman create despite having no effect (and not making sense
       in that context).
     - Fixed a bug where Podman could not start containers if running on a
       system without a /etc/resolv.conf file (which occurs on some WSL2
       images) (#8089).
     - Fixed a bug where the --extract option to podman cp was nonfunctional.
     - Fixed a bug where the --cidfile option to podman run would, when the
       container was not run with --detach, only create the file after the
       container exited (#8091).
     - Fixed a bug where the podman images and podman images -a commands
       could panic and not list any images when certain improperly-formatted
       images were present in storage (#8148).
     - Fixed a bug where the podman events command could, when the journald
       events backend was in use, become nonfunctional when a badly-formatted
       event or a log message that container certain string was present in
       the journal (#8125).
     - Fixed a bug where remote Podman would, when using SSH transport, not
       authenticate to the server using hostkeys when connecting on a port
       other than 22 (#8139).
     - Fixed a bug where the podman attach command would not exit when
       containers stopped (#8154).
     - Fixed a bug where Podman did not properly clean paths before verifying
       them, resulting in Podman refusing to start if the root or temporary
       directories were specified with extra trailing / characters (#8160).
     - Fixed a bug where remote Podman did not support hashed hostnames in
       the known_hosts file on the host for establishing connections (#8159).
     - Fixed a bug where the podman image exists command would return
       non-zero (false) when multiple potential matches for the given name
       existed.
     - Fixed a bug where the podman manifest inspect command on images that
       are not manifest lists would error instead of inspecting the image
       (#8023).
     - Fixed a bug where the podman system service command would fail if the
       directory the Unix socket was to be created inside did not exist
       (#8184).
     - Fixed a bug where pods that shared the IPC namespace (which is done by
       default) did not share a /dev/shm filesystem between all containers in
       the pod (#8181).
     - Fixed a bug where filters passed to podman volume list were not
       inclusive (#6765).
     - Fixed a bug where the podman volume create command would fail when the
       volume's data directory already existed (as might occur when a volume
       was not completely removed) (#8253).
     - Fixed a bug where the podman run and podman create commands would
       deadlock when trying to create a container that mounted the same named
       volume at multiple locations (e.g. podman run -v testvol:/test1 -v
       testvol:/test2) (#8221).
     - Fixed a bug where the parsing of the --net option to podman build was
       incorrect (#8322).
     - Fixed a bug where the podman build command would print the ID of the
       built image twice when using remote Podman (#8332).
     - Fixed a bug where the podman stats command did not show memory limits
       for containers (#8265).
     - Fixed a bug where the podman pod inspect command printed the static
       MAC address of the pod in a non-human-readable format (#8386).
     - Fixed a bug where the --tls-verify option of the podman play kube
       command had its logic inverted (false would enforce the use of TLS,
       true would disable it).
     - Fixed a bug where the podman network rm command would error when
       trying to remove macvlan networks and rootless CNI networks (#8491).
     - Fixed a bug where Podman was not setting sane defaults for missing
       XDG_ environment variables.
     - Fixed a bug where remote Podman would check if volume paths to be
       mounted in the container existed on the host, not the server (#8473).
     - Fixed a bug where the podman manifest create and podman manifest add
       commands on local images would drop any images in the manifest not
       pulled by the host.
     - Fixed a bug where networks made by podman network create did not
       include the tuning plugin, and as such did not support setting custom
       MAC addresses (#8385).
     - Fixed a bug where container healthchecks did not use $PATH when
       searching for the Podman executable to run the healthcheck.
     - Fixed a bug where the --ip-range option to podman network create did
       not properly handle non-classful subnets when calculating the last
       usable IP for DHCP assignment (#8448).
     - Fixed a bug where the podman container ps alias for podman ps was
       missing (#8445).
    * API
     - The Compat Create endpoint for Container has received a major refactor
       to share more code with the Libpod Create endpoint, and should be
       significantly more stable.
     - A Compat endpoint for exporting multiple images at once, GET
       /images/get, has been added (#7950).
     - The Compat Network Connect and Network Disconnect endpoints have been
       added.
     - Endpoints that deal with image registries now support a
       X-Registry-Config header to specify registry authentication
       configuration.
     - The Compat Create endpoint for images now properly supports specifying
       images by digest.
     - The Libpod Build endpoint for images now supports an httpproxy query
       parameter which, if set to true, will forward the server's HTTP proxy
       settings into the build container for RUN instructions.
     - The Libpod Untag endpoint for images will now remove all tags for the
       given image if no repository and tag are specified for removal.
     - Fixed a bug where the Ping endpoint misspelled a header name
       (Libpod-Buildha-Version instead of Libpod-Buildah-Version).
     - Fixed a bug where the Ping endpoint sent an extra newline at the end
       of its response where Docker did not.
     - Fixed a bug where the Compat Logs endpoint for containers did not send
       a newline character after each log line.
     - Fixed a bug where the Compat Logs endpoint for containers would mangle
       line endings to change newline characters to add a preceding carriage
       return (#7942).
     - Fixed a bug where the Compat Inspect endpoint for Containers did not
       properly list the container's stop signal (#7917).
     - Fixed a bug where the Compat Inspect endpoint for Containers formatted
       the container's create time incorrectly (#7860).
     - Fixed a bug where the Compat Inspect endpoint for Containers did not
       include the container's Path, Args, and Restart Count.
     - Fixed a bug where the Compat Inspect endpoint for Containers prefixed
       added and dropped capabilities with CAP_ (Docker does not do so).
     - Fixed a bug where the Compat Info endpoint for the Engine did not
       include configured registries.
     - Fixed a bug where the server could panic if a client closed a
       connection midway through an image pull (#7896).
     - Fixed a bug where the Compat Create endpoint for volumes returned an
       error when a volume with the same name already existed, instead of
       succeeding with a 201 code (#7740).
     - Fixed a bug where a client disconnecting from the Libpod or Compat
       events endpoints could result in the server using 100% CPU (#7946).
     - Fixed a bug where the "no such image" error message sent by the Compat
       Inspect endpoint for Images returned a 404 status code with an error
       that was improperly formatted for Docker compatibility.
     - Fixed a bug where the Compat Create endpoint for networks did not
       properly set a default for the driver parameter if it was not provided
       by the client.
     - Fixed a bug where the Compat Inspect endpoint for images did not
       populate the RootFS field of the response.
     - Fixed a bug where the Compat Inspect endpoint for images would omit
       the ParentId field if the image had no parent, and the Created field
       if the image did not have a creation time.
     - Fixed a bug where the Compat Remove endpoint for Networks did not
       support the Force query parameter.

   - add dependency to timezone package or podman fails to build a
   - Correct invalid use of %{_libexecdir} to ensure files should be in
     /usr/lib SELinux support [jsc#SMO-15]


   libseccomp was updated to release 2.5.3:

   * Update the syscall table for Linux v5.15
   * Fix issues with multiplexed syscalls on mipsel introduced in v2.5.2
   * Document that seccomp_rule_add() may return -EACCES

   Update to release 2.5.2

   * Update the syscall table for Linux v5.14-rc7
   * Add a function, get_notify_fd(), to the Python bindings to get the
     nofication file descriptor.
   * Consolidate multiplexed syscall handling for all architectures into one
     location.
   * Add multiplexed syscall support to PPC and MIPS
   * The meaning of SECCOMP_IOCTL_NOTIF_ID_VALID changed within the kernel.
     libseccomp's fd notification logic was modified to support the kernel's
     previous and new usage of SECCOMP_IOCTL_NOTIF_ID_VALID.

   update to 2.5.1:

   * Fix a bug where seccomp_load() could only be called once
   * Change the notification fd handling to only request a notification fd if
   * the filter has a _NOTIFY action
   * Add documentation about SCMP_ACT_NOTIFY to the seccomp_add_rule(3)
     manpage
   * Clarify the maintainers' GPG keys

   Update to release 2.5.0

   * Add support for the seccomp user notifications, see the
     seccomp_notify_alloc(3), seccomp_notify_receive(3),
     seccomp_notify_respond(3) manpages for more information
   * Add support for new filter optimization approaches, including a balanced
     tree optimization, see the SCMP_FLTATR_CTL_OPTIMIZE filter attribute for
     more information
   * Add support for the 64-bit RISC-V architecture
   * Performance improvements when adding new rules to a filter thanks to the
     use of internal shadow transactions and improved syscall lookup tables
   * Properly document the libseccomp API return values and include them in
     the stable API promise
   * Improvements to the s390 and s390x multiplexed syscall handling
   * Multiple fixes and improvements to the libseccomp manpages
   * Moved from manually maintained syscall tables to an automatically
     generated syscall table in CSV format
   * Update the syscall tables to Linux v5.8.0-rc5
   * Python bindings and build now default to Python 3.x
   * Improvements to the tests have boosted code coverage to over 93%

   Update to release 2.4.3

   * Add list of authorized release signatures to README.md
   * Fix multiplexing issue with s390/s390x shm* syscalls
   * Remove the static flag from libseccomp tools compilation
   * Add define for __SNR_ppoll
   * Fix potential memory leak identified by clang in the scmp_bpf_sim tool

   Update to release 2.4.2

   * Add support for io-uring related system calls


   conmon was updated to version 2.0.30:

     * Remove unreachable code path
     * exit: report if the exit command was killed
     * exit: fix race zombie reaper
     * conn_sock: allow watchdog messages through the notify socket proxy
     * seccomp: add support for seccomp notify

   Update to version 2.0.29:

     * Reset OOM score back to 0 for container runtime
     * call functions registered with atexit on SIGTERM
     * conn_sock: fix potential segfault

   Update to version 2.0.27:

     * Add CRI-O integration test GitHub action
     * exec: don't fail on EBADFD
     * close_fds: fix close of external fds
     * Add arm64 static build binary

   Update to version 2.0.26:

     * conn_sock: do not fail on EAGAIN
     * fix segfault from a double freed pointer
     * Fix a bug where conmon could never spawn a container, because a
       disagreement between the caller and itself on where the attach socket
       was.
     * improve --full-attach to ignore the socket-dir directly. that means
       callers don't need to specify a socket dir at all (and can remove it)
     * add full-attach option to allow callers to not truncate a very long
       path for the attach socket
     * close only opened FDs
     * set locale to inherit environment

   Update to version 2.0.22:

     * added man page
     * attach: always chdir
     * conn_sock: Explicitly free a heap-allocated string
     * refactor I/O and add SD_NOTIFY proxy support

   Update to version 2.0.21:

     * protect against kill(-1)
     * Makefile: enable debuginfo generation
     * Remove go.sum file and add go.mod
     * Fail if conmon config could not be written
     * nix: remove double definition for e2fsprogs
     * Speedup static build by utilizing CI cache on `/nix` folder
     * Fix nix build for failing e2fsprogs tests
     * test: fix CI
     * Use Podman for building

   libcontainers-common was updated to include:

   - common 0.44.0
   - image 5.16.0
   - podman 3.3.1
   - storage 1.36.0 (changes too long to list)

   CVEs fixed:
   CVE-2020-14370,CVE-2020-15157,CVE-2021-20199,CVE-2021-20291,CVE-2021-3602


Patch Instructions:

   To install this SUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Module for Containers 15-SP3:

      zypper in -t patch SUSE-SLE-Module-Containers-15-SP3-2022-23018=1

   - SUSE Linux Enterprise Module for Basesystem 15-SP3:

      zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2022-23018=1

   - SUSE Linux Enterprise Micro 5.1:

      zypper in -t patch SUSE-SUSE-MicroOS-5.1-2022-23018=1



Package List:

   - SUSE Linux Enterprise Module for Containers 15-SP3 (aarch64 ppc64le s390x x86_64):

      conmon-2.0.30-150300.8.3.1
      conmon-debuginfo-2.0.30-150300.8.3.1
      podman-3.4.4-150300.9.3.2

   - SUSE Linux Enterprise Module for Containers 15-SP3 (noarch):

      podman-cni-config-3.4.4-150300.9.3.2

   - SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64):

      libseccomp-debugsource-2.5.3-150300.10.5.1
      libseccomp-devel-2.5.3-150300.10.5.1
      libseccomp2-2.5.3-150300.10.5.1
      libseccomp2-debuginfo-2.5.3-150300.10.5.1

   - SUSE Linux Enterprise Module for Basesystem 15-SP3 (noarch):

      libcontainers-common-20210626-150300.8.3.1

   - SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64):

      conmon-2.0.30-150300.8.3.1
      conmon-debuginfo-2.0.30-150300.8.3.1
      libseccomp-debugsource-2.5.3-150300.10.5.1
      libseccomp2-2.5.3-150300.10.5.1
      libseccomp2-debuginfo-2.5.3-150300.10.5.1
      podman-3.4.4-150300.9.3.2

   - SUSE Linux Enterprise Micro 5.1 (noarch):

      libcontainers-common-20210626-150300.8.3.1
      podman-cni-config-3.4.4-150300.9.3.2


References:

   https://www.suse.com/security/cve/CVE-2020-14370.html
   https://www.suse.com/security/cve/CVE-2020-15157.html
   https://www.suse.com/security/cve/CVE-2021-20199.html
   https://www.suse.com/security/cve/CVE-2021-20291.html
   https://www.suse.com/security/cve/CVE-2021-3602.html
   https://www.suse.com/security/cve/CVE-2021-4024.html
   https://www.suse.com/security/cve/CVE-2021-41190.html
   https://bugzilla.suse.com/1176804
   https://bugzilla.suse.com/1177598
   https://bugzilla.suse.com/1181640
   https://bugzilla.suse.com/1182998
   https://bugzilla.suse.com/1188520
   https://bugzilla.suse.com/1188914
   https://bugzilla.suse.com/1193166
   https://bugzilla.suse.com/1193273



More information about the sle-security-updates mailing list