- Switch the default guest kernel from vmlinux-6.18.15-186
(kata-static-3.28.0) to the newer version and variant
vmlinux-6.18.35-197-debug (kata-static-3.32.0).
- The debug variant enables eBPF, kprobes, uprobes, ftrace
and BTF (kata-containers/kata-containers#12567).
Signed-off-by: Agam Dua <agam_dua@apple.com>
This removes the AsyncParsableCommand protocol from ContainerCLI since
it does not leverage the features that the protocol provides and the
extension main can cause confusion.
Bump to latest containerization version.
- Closes#1713.
- Files under /etc/sudoers.d/ must not contain dots as these
will be ignored as "backup-files". When writing the sudoers
file, replace `.` with `_` in the username to form the filename.
- Closes#2078.
- Move all K8s sources from the container-k8s executable
into a new ContainerK8s library target. Sources/Plugins/K8s/
becomes a thin entry point (K8sMain.swift) that calls
K8sCommand.main().
- closes#2043
- introduces the k8s plugin, allowing users to make single
node clusters with the kind base image
- other functionality is included as well such as creation,
deletion, and loading custom images
- When pulling warmup images for concurrent tests, save
the images to a cache directory under the application root.
- Serial tests that aren't testing pull can save time by restoring
a cached warmup image.
Each container runs in its own guest VM sized to
`--memory` with no swap, so the guest kernel's
stock `vm` sysctl defaults are hit far too easily:
- `vm.overcommit_memory=0` (heuristic overcommit)
rejects an oversized `mmap()` upfront whenever the
reservation exceeds the small, swap-less VM's free
RAM — even if the memory is never touched —
returning `ENOMEM`.
- `vm.max_map_count=65530` caps per-process
mapping count, which mapping-heavy applications
(e.g. Elasticsearch, many JVMs) can exceed.
- When container is not running, the runtime helper
traverses the container's root fs and writes it to the
specified tar archive or stdout.
- When the container is running, the helper performs
the same operation but wraps it in freeze/thaw
to ensure data integrity for the resulting archive.
- Closes#2001.
- Handle "container exists" error gracefully instead
of failing, when trying to start the buildkit container.
- Move build tests to parallel suites, while the builder
lifecycle tests remain serial. Parallel builds don't
use the fixture lock that deletes and restarts the
builder and runs a build block in isolation.
Closes https://github.com/apple/container/issues/1687
The default kernel archive is downloaded from a remote release URL
during first-run setup and via `container system kernel set
--recommended`. Previously, the archive contents were not verified after
download, so integrity depended on HTTPS and the release artifact
remaining unchanged.
This change adds digest verification for kernel archives. The
recommended/default kernel now has pinned digest metadata using an
algorithm-prefixed value such as `sha256:<hex>`. `container system
kernel set --tar` accepts `--digest`; remote tar URLs require it, and
local tar archives can also be verified before unpacking and
installation.
The system config also supports `kernel.digest`, and a custom
`kernel.url` must provide a digest for that archive.
- Fixes#1789.
- Release 2.9.0 of `grpc-swift-nio-transport` fixes
an HTTP/2 initialization race where the server could
send SETTINGS before gRPC handlers are added to
the pipeline, causing the client to hang. The new
`WrappedChannel.wrapping(config:serviceConfig:makeChannel:)`
API calls `configure(channel)` inside the channel
initializer, ensuring the pipeline is set up before any inbound
bytes arrive. This eliminates the need for the custom
`HTTP2ConnectBufferingHandler` workaround.
- This fixes the LLVM coverage data not properly being emitted for XPC
services. It requires piping the `LLVM_PROFILE_FILE` environment
variable through to all the services and plugins. The variable itself
also required the "%c" formatter to ensure that it continuously emits
coverage data, otherwise when XPC services are killed via "bootout" they
do not emit coverage.
- Fixes#1801.
- When `container image save` runs without `--output`,
stdout carries the OCI tar archive. The command writes
the archive bytes to stdout and then `print(reference)`s
each saved image reference to stdout afterward,
appending non-archive text after the tar EOF marker,
which will cause strict tar/OCI consumers to fail.
- This routes the saved-reference list to stderr in the
no-`--output` branch, so stdout contains only archive
bytes. When saving to a file via `--output`, stdout is
free, so the references continue to print to stdout
exactly as before.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- `SystemStart` used `try!` when creating the apiserver
data directory. File system operations can fail for
legitimate reasons: insufficient permissions, disk full,
read-only volume. Crashing the process in these cases
gives the user no actionable error message.
- Replaced with `try` so the error propagates up and is
surfaced cleanly.
- Closes#1812.
- The network plugin is the source of truth for the variant, if any,
that applies to the network. Resolving a missing variant configuration
option in the API server can create a situation where the variant the
runtime uses for interface selection is incorrect.
- Adds serial suites trait to tests to see whether it helps current CI
issues.
## Type of Change
- [x] Bug fix
- [ ] New feature
- [ ] Breaking change
- [ ] Documentation update
## Motivation and Context
Fixes a flaw in our interface strategy logic.
## Testing
- [x] Tested locally
- [ ] Added/updated tests
- [ ] Added/updated docs
- `swift-argument-parser` enforces that `arguments` is
non-empty before `run()` is invoked, so the force-unwrap
of `arguments.first!` is not reachable in practice. However,
the guard makes the invariant explicit in the code itself,
removes reliance on ArgumentParser's implicit
enforcement, and would satisfy force-unwrap lint rules
if enabled in the future.
- Closes#1756.
- `RuntimeService.gracefulStopContainer(_:signal:timeout:)`
wraps the graceful-stop attempt in `do { … } catch {}`. The
empty catch silently discards any thrown error before falling
through to the unconditional `lc.stop()`. It is the only catch
in this file that does not log; every other one uses
`self.log.error(…, metadata: ["error": "\(error)"])`.
- This adds a single log line matching that convention, so
a failed graceful stop (and the resulting fall-through to a
forced VM shutdown) is more diagnosable. The intentional
fall-through to `lc.stop()` is unchanged.
- Instead of using force-unwrap to append to a list-valued
dictionary entry that should always exist, assign the value
with a default fallback and append to the (non-optional)
result.
- In `ProcessIO.swift`, the readability handlers for stdout and stderr
used `try!` when writing data to the output file handles. This would
cause crashes If the pipe is broken such that the force-try executes.
- Changed to handle a failed write similarly to an EOF.
Fixes#1738
`container cp` fails when the host source path is relative (e.g.
`container cp file foo:/root/`), because `NSString.standardizingPath`
only canonicalizes paths but does not make them absolute. The unchanged
relative path is then interpreted as `/file` (root-absolute) by
`URL(fileURLWithPath:)` on the runtime side.
Fixed by resolving relative paths against the current working directory
before use, matching the pattern already used by `container export`,
`container image save`, and `container image load`.
The same fix was also applied to the copy-out destination path (line
68), which had the same issue.
## Type of Change
- [x] Bug fix
- [ ] New feature
- [ ] Breaking change
- [ ] Documentation update
## Motivation and Context
`container cp file foo:/root/` fails with `"copyIn: source not found
'/file'"` because the relative path `file` is never expanded to an
absolute path. Using `$PWD/file` works, but relative paths should work
too — every other command in the codebase handles this correctly.
## Testing
- [x] Tested locally — builds and all existing tests pass
- [ ] Added/updated tests
- [ ] Added/updated docs
---------
Co-authored-by: jwhur <57657645+JaewonHur@users.noreply.github.com>
- Closes#1750.
- Applies permission code used for the `--ssh` mount to all
host-to-container socket mounts.
- Adds a user option to the `doExec` test support function.
- Updates the `testRunCommandUnixSocketMount` to install `nc` in the
test container, and check the socket permission, and check the mounted
socket using `nc` as the guest user.
This also includes custom kernels for container machine. Its required
with nested virt as CONFIG_KVM needs to be enabled.
---------
Signed-off-by: michael_crosby <michael_crosby@apple.com>
Remove manually specified default value from help string since
ArgumentParser already appends it automatically from the property's
default value.
Signed-off-by: Charlie Le <charlie_le@apple.com>