Fix podman tests - #1312
Merged
Abdurrahmaan Iqbal (abdurriq) merged 1 commit intoSep 29, 2026
Merged
Fix podman tests#1312Abdurrahmaan Iqbal (abdurriq) merged 1 commit into
Abdurrahmaan Iqbal (abdurriq) merged 1 commit into
Conversation
Kaniska (v-Kaniska244)
marked this pull request as ready for review
September 29, 2026 06:19
Abdurrahmaan Iqbal (abdurriq)
approved these changes
Sep 29, 2026
Abdurrahmaan Iqbal (abdurriq)
merged commit Sep 29, 2026
ee429fa
into
devcontainers:main
25 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Remove the manual installation of the Podman 5.5.2 static bundle from the Podman test job and use the Podman stack provided by the GitHub-hosted Ubuntu runner.
This resolves the
failed to reexec: Permission deniedfailure observed in the Podman test job for #1303.Background
The Podman test job manually installed a static Podman 5.5.2 bundle on
ubuntu-latest. Although this replaced the Podman executable and some related files, the tests continued to depend on other components and configuration supplied by the runner image.Podman is not an isolated executable. Rootless container builds depend on a compatible stack that includes:
crunorruncconmonaardvark-dnsInstalling only a static Podman bundle over the runner-provided environment resulted in a mixed runtime stack that was not guaranteed to be compatible.
Failure
The affected job failed while running the Podman integration tests with:
The tests invoke the Dev Containers CLI with:
The failure occurred in the Podman runtime environment rather than in the Dev Containers CLI logic.
Why It Started Failing
The workflow relied on implementation details of the moving
ubuntu-latestrunner image. A runner-image or host-policy update appears to have exposed an existing incompatibility between the downloaded static Podman bundle and the runtime components, paths, and confinement policy supplied by Ubuntu.The exact runner-image revision that triggered the regression was not isolated. However, the observed behavior is consistent with the following sequence:
Permission denied.This indicates an environment-integration problem rather than a regression in the Dev Containers CLI.
Investigation
Several approaches for retaining a manually pinned Podman version were evaluated:
crun.BUILDAH_ISOLATION=chroot.None produced a reliable configuration on the GitHub-hosted runner:
crunproduced runtime-version compatibility errors.crunled to rootless runtime-state permission errors under/run/user.These results demonstrate that replacing individual components is insufficient. A pinned Podman version requires a complete, internally compatible runtime environment.
Resolution
Remove the manual Podman 5.5.2 installation step and use the Podman installation supplied by the GitHub-hosted Ubuntu runner.
This keeps Podman aligned with the runner’s:
conmonThe existing Tools Info step remains in place and reports the actual Podman and Docker Buildx versions used by CI, preserving visibility into the test environment.
Test Coverage
The existing Podman integration tests remain unchanged and continue to exercise:
devcontainer up --docker-path podmanNo test assertions, behavior, or timeout values are changed by this PR.
Tradeoff
This change means CI no longer pins Podman to version 5.5.2. Instead, the Podman tests run against the distro-integrated version available on
ubuntu-latest.This trades exact version pinning for a runtime stack that is internally consistent and supported by the runner environment.
If coverage for an exact Podman version becomes mandatory, it should be implemented using a dedicated runner or VM image containing a complete and validated Podman stack. Replacing Podman binaries within a GitHub-hosted runner is not a reliable version-pinning mechanism because the runtime also depends on host configuration and multiple tightly coupled components.
The current
ubuntu-latestGH runner is ubuntu-24.04 which has the default podman engine version4.9.3which works for devcontainer build. In future if theubuntu-latestrunner is updated to ubuntu-26.04 and continues with similar AppArmor restriction as the current one, the podman test pipeline will get blocked with the issue fixed in #1280 because the in-built podman version is expected for that is > 5.5.2 and < 6.1.0 unless a fix received from upstream in GH runners.Test Plan
podman infocompletes successfully.Scope
This PR only removes the manual Podman installation from the test workflow. It does not change:
--docker-path podmanexecution path