The Docker validation provider (#1179) identifies a missing container by matching Docker's exact error text. That text changed in Docker 29 and differs on Podman, so cleanup can never be verified and the Docker suite fails although containers are removed correctly. Found while reviewing #1181.
Results (pinned lab, --require-complete)
| Engine |
main |
#1181 |
| Docker 29.7.2, linux/amd64 |
0/3 |
2/13 |
| Podman 5.8.4 via Docker CLI, macOS arm64 |
0/3 |
2/13 |
Causes
- Error-text matching (docker.py#L489-L509): the code checks for
"No such container" / "No such object" case-sensitively. Docker 29's inspect prints error: no such object: …, Podman prints … no such container, and Docker 29's rm --force on a missing container exits 0.
- Force-remove deadline (docker.py#L496): Podman's
rm --force waits the stop timeout before SIGKILL. That's 10.2 s measured, against a 10 s budget. Docker kills immediately.
- Test assumption (test_docker_lifecycle.py#L83): the test asserts
CapDrop == ["ALL"], but Podman lists each dropped capability individually.
Fix (branch ready, 13/13 on both engines)
- Verify ownership and removal by listing:
docker ps --all --filter name=… --format … returns an empty result for a missing container, whatever the wording, and a non-zero exit when the engine is unreachable.
- Launch with
--stop-timeout 0, so a forced removal kills immediately on Podman.
- Check that the capability bounding set is empty inside the subject (
CapBnd; CapEff is always 0 for a non-root user).
- Add unit tests covering each engine's output.
I'd like to work on this. The fix merges cleanly with the #1246–#1248 stack.
The Docker validation provider (#1179) identifies a missing container by matching Docker's exact error text. That text changed in Docker 29 and differs on Podman, so cleanup can never be verified and the Docker suite fails although containers are removed correctly. Found while reviewing #1181.
Results (pinned lab,
--require-complete)Causes
"No such container"/"No such object"case-sensitively. Docker 29'sinspectprintserror: no such object: …, Podman prints… no such container, and Docker 29'srm --forceon a missing container exits 0.rm --forcewaits the stop timeout before SIGKILL. That's 10.2 s measured, against a 10 s budget. Docker kills immediately.CapDrop == ["ALL"], but Podman lists each dropped capability individually.Fix (branch ready, 13/13 on both engines)
docker ps --all --filter name=… --format …returns an empty result for a missing container, whatever the wording, and a non-zero exit when the engine is unreachable.--stop-timeout 0, so a forced removal kills immediately on Podman.CapBnd;CapEffis always 0 for a non-root user).I'd like to work on this. The fix merges cleanly with the #1246–#1248 stack.