Skip to content

Container runtime detection misses podman behind a docker binary (podman-docker shim) #2599

Description

@vieiralucas

Problem

fakecloud decides whether its container CLI is podman purely from the binary's file name: container_net::is_podman_binary checks whether the name contains podman. On distros that ship the podman-docker package (Fedora, RHEL, CentOS Stream, and others), docker is a shim that execs podman. When docker is found first (or FAKECLOUD_CONTAINER_CLI=docker is set), fakecloud treats podman as Docker and takes every Docker-only code path.

Places that branch on this today:

Expected

Detect the runtime by what it is, not by what it's called. docker --version behind the shim prints podman version X.Y.Z, and <cli> info exposes podman-specific fields. Probe once per CLI (bounded, like the existing cli_available probe), cache the result, and have every current is_podman_binary caller use it. Keep the name match as a fast path.

Repro

  1. On Fedora or RHEL, install podman-docker without Docker.
  2. Run fakecloud with the default CLI detection, which picks docker.
  3. Push an image to fakecloud ECR and run an ECS task that references <account>.dkr.ecr.<region>.amazonaws.com/<repo>:<tag>.
  4. The task stops with TaskFailedToStart, and the image pull fails with an HTTPS error.

Follow-up to #2585 / #2595.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions