diff --git a/libpod/define/container_inspect.go b/libpod/define/container_inspect.go index ba2df4fab9..51ad4a0da7 100644 --- a/libpod/define/container_inspect.go +++ b/libpod/define/container_inspect.go @@ -1,6 +1,7 @@ package define import ( + "bytes" "encoding/json" "fmt" "strings" @@ -153,11 +154,16 @@ func (insp *InspectContainerConfig) UnmarshalJSON(data []byte) error { } func (insp *InspectContainerConfig) MarshalJSON() ([]byte, error) { + buf := bytes.Buffer{} + enc := json.NewEncoder(&buf) + enc.SetEscapeHTML(false) + // the alias is needed otherwise MarshalJSON will type Alias InspectContainerConfig conf := (*Alias)(insp) if !insp.V4PodmanCompatMarshal { - return json.Marshal(conf) + err := enc.Encode(conf) + return buf.Bytes(), err } type v4InspectContainerConfig struct { @@ -171,7 +177,8 @@ func (insp *InspectContainerConfig) MarshalJSON() ([]byte, error) { StopSignal: uint(stopSignal), Alias: conf, } - return json.Marshal(newConf) + err := enc.Encode(newConf) + return buf.Bytes(), err } // InspectRestartPolicy holds information about the container's restart policy. diff --git a/test/e2e/inspect_test.go b/test/e2e/inspect_test.go index d1e0b776a4..d15c8d301e 100644 --- a/test/e2e/inspect_test.go +++ b/test/e2e/inspect_test.go @@ -263,6 +263,15 @@ var _ = Describe("Podman inspect", func() { Expect(baseJSON[0]).To(HaveField("Name", ctrName)) }) + It("podman inspect should not escape special chars", func() { + ctrName := "testlabel" + podmanTest.PodmanExitCleanly("create", "--name", ctrName, "--label", "abc=&&**<>123", ALPINE, "sh") + + // see https://github.com/containers/podman/issues/28560 + inspect := podmanTest.PodmanExitCleanly("inspect", ctrName) + Expect(inspect.OutputToString()).To(ContainSubstring(`"abc=&&**<>123"`)) + }) + It("podman inspect - HostConfig.SecurityOpt ", func() { if !selinux.GetEnabled() { Skip("SELinux not enabled")