Podman ships podman.socket units for systemd, in both system and per-user scope. With socket activation the service is not running until something connects, but the socket file exists, so reaching it starts the service and drives the engine. The user-scope socket lives under the user's runtime directory.
systemctl --user status podman.socket 2>/dev/null
systemctl status podman.socket 2>/dev/null # system scope (rootful)
ls -l /run/user/*/podman/podman.sock /run/podman/podman.sock 2>/dev/null
# Connecting activates the service
curl -s --unix-socket /run/user/1000/podman/podman.sock http://d/v1.40/libpod/info
Exploitation notes#
- System-scope
podman.socketis rootful and root-equivalent; user-scope is bounded by that user. - The socket path is the target: filesystem access to it (a shared runtime dir, a bind mount, a group membership) is engine access.
- Once connected, proceed as in API service socket.