75 Commits
Author SHA1 Message Date
J Logan a5607a8cf6 Update to containerization 0.21.1. (#1064)
- Picks up apple/containerization#478
2026-01-20 14:25:07 -08:00
J Logan 744e7f7c7a Update for containerization 0.21.0. (#1056)
- Update image load and build to handle rejected paths during tar
extraction. For the image load command there is now a `--force` function
that fails extractions with rejected paths when false, and just warns
about the rejected paths when true.
- Update `container stats` for statistics API properties now all being
optional.

## Type of Change
- [x] Bug fix
- [ ] New feature  
- [ ] Breaking change
- [x] Documentation update

## Motivation and Context
See above

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [x] Added/updated docs
2026-01-16 16:26:13 -08:00
박성근 e465b109b2 Fix relative path resolution in entrypoint (#987)
- Fixes #962.
- Adds test to exercise apple/containerization#473.
- Updates containerization to 0.20.1.

Signed-off-by: ParkSeongGeun <phd0801@naver.com>
2026-01-12 10:30:51 -08:00
J Logan 98410fdb57 Adds IPv6 port forwarding. (#1029)
- Closes #1006.
2026-01-07 18:23:31 -08:00
J Logan db8932ab0f Resolve IPv6 address queries for container names. (#1016)
- Closes #1005.
- Adapt everything to use MACAddress type from containerization 0.20.0.
- Allocate MAC addresses for every container so that we have
deterministic IPv6 link local addresses.
- Add AAAA handling to ContainerDNSHandler.
- NOTE: Only works on Tahoe. On Sequoia, we don't have a good way to set
or determine the IPv6 network prefix when networks are created, so we
can't infer the IPv6 link local addresses for AAAA responses and we
instead return `NODATA`.
2026-01-07 15:35:35 -08:00
J Logan 9cd5397b8c Update to containerization 0.20.0. (#1027)
- Use MACAddress for Attachment and CZ interfaces.
- Move data validation closer to API surface.
2026-01-07 10:35:19 -08:00
J Logan 356c8d2f88 Reorganize client libraries. (#1020)
- Closes #461.
- Extract core types into ContainerResources target.
- Extract ContainerNetworkServiceClient from ContainerNetworkService.
- Relocate sandbox client from ContainerClient to
ContainerSandboxServiceClient.
- Relocate ContainerClient to ContainerAPIServiceClient.
- Common structure from services and clients under Source/Services.

Updated project hierarchy:

```
Sources/CAuditToken - audit token access wrapper
Sources/CLI - CLI executable
Sources/ContainerBuild - builder
Sources/ContainerCommands - CLI command implementations
Sources/ContainerLog - logging helpers
Sources/ContainerPersistence - persistent data and system property helpers
Sources/ContainerPlugin - plugin system
Sources/ContainerResource - resource (container, image, volume, network) types
Sources/ContainerVersion - version helpers
Sources/ContainerXPC - XPC helpers
Sources/CVersion - injected project version
Sources/DNSServer - container DNS resolver
Sources/Helpers - service executables
Sources/Services/*/Client - service clients
Sources/Services/*/Server - service implementations
Sources/SocketForwarder - port forwarding
Sources/TerminalProgress - progress bar
```

## Type of Change
- [ ] Bug fix
- [ ] New feature  
- [x] Breaking change
- [ ] Documentation update

## Motivation and Context
The ContainerClient library was a bit of a grab bag. This refactor
applies a more sensible project and library structure for resource data
types, services, and clients.

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [ ] Added/updated docs
2026-01-06 08:27:14 -08:00
Danny Canter 028e7e109f Deps: Bump Containerization to 0.19.0 (#1015)
Has read-only rootfs support.
2026-01-04 10:52:46 -08:00
J Logan cf64614173 Update OSS header in Package.swift. (#1010) 2026-01-02 14:10:48 -08:00
J Logan 5064b0ffd5 Adds network IPv6 configuration. (#975)
- Part of work for #460.
- Enable set/get of IPv6 network prefix in ReservedVmnetNetwork.
- Show IPv6 prefix in `network list` full output.
- Option for setting IPv6 prefix when creating a network.
- System property for default IPv6 prefix.

## Type of Change
- [ ] Bug fix
- [x] New feature  
- [ ] Breaking change
- [x] Documentation update

## Motivation and Context
See #460.

## Testing
- [x] Tested locally
- [ ] Added/updated tests
- [x] Added/updated docs
2025-12-22 10:16:14 -08:00
J Logan 4f88725158 Use new IP/CIDR types from Containerization. (#957)
- Part of work for #460.
- With CZ release 0.17.0, the IP and CIDR address
  types changed from String to IPv4Address and
  CIDRv4, respectively. This PR applies the corresponding
  adaptations to container.
2025-12-16 16:34:13 -08:00
Danny Canter 0cde1efe30 Deps: Bump Containerization to 0.16.2 (#947)
Closes https://github.com/apple/container/issues/928

Has a cgroup fix when stopping certain containers
2025-12-09 13:24:45 -08:00
J Logan 420be748f1 Data integrity: bump to cz 0.16.1, adjust sync mode. (#939)
- 0.16.1 changes an ext4 superblock setting that might have been causing
problems.
- #877 fixed an issue where the cache and sync settings for block
filesystems weren't being passed down to the VZ virtual machine
configuration. The default sync value getting passed down is `full`,
which reduces I/O performance. Relax this to use `fsync` for now.

## Type of Change
- [*] Bug fix
- [ ] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Motivation and Context
May address problems reported in #877.

## Testing
- [x] Tested locally
- [ ] Added/updated tests
- [ ] Added/updated docs
2025-12-07 22:00:02 -08:00
J Logan 1e19a4d6e3 Updates CZ to 0.16.0. (#927) 2025-12-02 20:48:37 -03:00
Raj 1c0e9888f3 Fix container image prune to actually remove images, add -a flag support, and bump cz to 0.15.0 (#909)
- Fixes #901.

## Type of Change
- [x] Bug fix
- [x] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Motivation and Context
Previously `container image prune` called `ImageStore.prune()` (renamed
to `cleanupOrphanedBlobs()` in cz 0.15.0) which only removed orphaned
content blobs and never actually removed images.

This PR fixes that behavior so `container image prune` removes dangling
images by default, and with `-a` removes all unused images, not just
dangling ones.

## Testing
- [x] Tested locally
- [ ] Added/updated tests
- [ ] Added/updated docs
2025-11-21 10:55:00 -08:00
Dmitry Kovba 7926c317f6 Build input file cannot be found: '.../CAuditToken.o' (#908)
Resolves a build error in Xcode:
> Build input file cannot be found: '.../CAuditToken.o'. Did you forget
to declare this file as an output of a script phase or custom build rule
which produces it?
2025-11-20 16:01:25 -08:00
J Logan 87862d1faa Updates to CZ 0.14.0. (#903) 2025-11-19 18:55:23 -03:00
J Logan b2f5f3ff2f Adds client uid validation to XPC server. (#896)
- When a user performs an `su` the effective UID changes but the bootstrap
  mach port does not, so that if container is running as `alice` from a
  GUI login session, it's possible to `su bob` and continue running
  container. While this doesn't pose a significant security risk as it's
  necessary for Alice to know Bob's password and manually enter it with
  `su`, this change closes the loophole by validating that client UID from
  the caller's audit token matches that of the API server.
2025-11-19 00:41:56 -03:00
J Logan 936c916916 Actually resolve symlink when loading bundle Info.plist. (#864)
- #859 added the traversal necessary to load the app bundle but forgot
to resolve symlinks. This fix adds the resolution, making it possible to
get default system properties from an app bundle Info.plist even if the
user invokes a command from, for example, `/usr/local/bin/container`
which is a symlink to the actual install path of the bundle.
- Also fixes bugs where an incorrect executable path was supplied in
some calls.
- Breaking change: `CommandLine.executablePathUrl` extension moved from
ContainerPlugin to ContainerVersion.
2025-11-10 17:00:18 -03:00
J Logan c88cd2ef4f Fix Info.plist system properties for symlinked container. (#859)
- Regular `Bundle.main.infoDictionary` doesn't work in this case.
- Load bundle using location presuming binary is under `Contents/MacOS`.
2025-11-07 09:38:53 -08:00
J Logan 384e3a12ff Use container-builder-shim 0.7.0, ensures use of Rosetta. (#858)
- Addresses slow cross-platform builds from #68.
- The shim wasn't doing everything needed to ensure the use of Rosetta for
  `container build`. The new shim adds an `--enable-qemu` option that
  controls whether `buildkit-qemu-emulator-x86_64 is available; when it is
  not available, buildkitd will attempt to build natively, meaning Rosetta
  will execute amd64 binaries.
2025-11-06 13:29:55 -08:00
Danny Canter a627c82a03 Deps: Bump Containerization to 0.13.0 (#848)
Speeds up unpacks.
2025-11-04 12:33:08 -08:00
Raj 13a2f1a9e3 Update builder-shim to 0.6.3 for metadata only Dockerfile support (#825)
- Fixes #736.
- BuildKit returns nil ref for Dockerfiles containing only metadata
  (`ENV/ARG/LABEL`) directives without filesystem operations
  (`RUN/COPY/ADD`). Previously, this caused builds to fail with "no build
  directives" error.
- Builder-shim 0.6.3 [fixes this](https://github.com/apple/container-builder-shim/pull/47) by
  creating a minimal marker layer when ref is nil but image config is
  valid, satisfying OCI manifest requirements.
- Also, added some tests for this behavior.
2025-10-30 16:27:38 -07:00
J Logan 8f2e20de5a CZ 0.12.1 - pick up relay fixes, other goodies. (#804) 2025-10-24 14:52:39 -07:00
J Logan 5de195f720 Bump Containerization to 0.12.0. (#802)
- Include change to bootlog API.
2025-10-23 14:26:45 -07:00
Danny Canter b4814f0c4a Deps: Bump Containerization to 0.11.0 (#796) 2025-10-21 14:28:52 -07:00
Kathryn Baldauf 6cb40b3687 Add image env variables to builder start command (#756)
## Type of Change
- [x] Bug fix

## Motivation and Context
Required for builder to run correctly with bug fix in containerization
here https://github.com/apple/containerization/pull/329. Builder was
previously not passing any environment variables when starting the
initial process.

## Testing
- [x] Tested locally

---------

Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
2025-10-14 11:13:18 -07:00
J Logan bc70b39182 Fix broken proxy configuration for default kernel fetch. (#747)
- Closes #466.

## Type of Change
- [x] Bug fix
- [ ] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Motivation and Context
Proxy logic worked well enough for CI but broken in general.

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [ ] Added/updated docs
2025-10-10 10:17:42 -07:00
J Logan bfc5ca9222 Removes "all rights reserved" from license header. (#711)
Closes #63.
2025-10-03 13:28:16 -07:00
J Logan d045e5b0f0 Updates containerization to 0.9.1. (#697)
- Converts client to work with ExitStatus instead of integer error
codes.

## Type of Change
- [ ] Bug fix
- [ ] New feature  
- [x] Breaking change (SandboxClient.wait() returns ExitStatus instead
of Int32, apple/containerization#300)
- [ ] Documentation update

## Motivation and Context
Pick up DNS bug fix, update for breaking API change.

## Testing
- [x] Tested locally
- [x] Added/updated tests (fixed DNS test, using correct `options` now,
apple/containerization#303).
- [ ] Added/updated docs
2025-10-01 10:04:39 -07:00
J Logan e448151f7e Bumps containerization to 0.8.1. (#674)
## Type of Change
- [ ] Bug fix
- [ ] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Motivation and Context
Avoid build errors due to NIOFilesystem import issues in
containerization.

## Testing
- [ ] Tested locally
- [ ] Added/updated tests
- [ ] Added/updated docs
2025-09-23 13:15:35 -07:00
Dmitry Kovba 6eaf51b8bc Remove Native Builder from the main branch (#634)
The work on the Native Builder has been moved to a separate branch
`dev/native-builder`. This PR removes it from the `main` branch.
2025-09-20 00:07:57 -07:00
Danny Canter 5ddb10f9af Bump CZ to 0.8.0 (#648)
Allows stop in LinuxContainer to be idempotent
2025-09-19 08:56:03 -07:00
Morris Richman 996a6819e3 Rename CLI and ExecutableCLI folders (#635)
## Motivation and Context
This is an extension of #603 to cleanup the folder structure and have it
match with the new library and target names.
2025-09-18 17:49:48 -07:00
Morris Richman dd6bdc20cf Expose Command Structs for Plugins (#603)
## Type of Change
- [ ] Bug fix
- [x] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Motivation and Context
Plugins technically exist, but to add shortcuts or to do existing things
with functions in `container` requires calling a compiled binary. This
pull request aims to remove that hurdle and instability by exposing
commands as a new `ContainerCommands ` target.

Simply import `ContainerCommands` and you can access almost
any command as if it were a native part of the binary. This makes
plugin development significantly easier.

Closes #609.
2025-09-17 15:24:26 -07:00
J Logan 79cc363e78 Relocates API server to Helpers, service to Services. (#616)
- Closes #615.

Improves project organization. Separates service so it can be tested and
used separately from the executable target. No functional changes.
2025-09-16 10:14:14 -07:00
J Logan a54be363f7 Add --labels for networks. (#600)
- Closes #557.
- Breaking change: removes `.upToNextOption` for labels on volumes as
this is not what is done for containers, and it forces the argument to
precede the options if a label is supplied, which is non-intuitive.

## Type of Change
- [ ] Bug fix
- [x] New feature  
- [x] Breaking change
- [x] Documentation update

## Motivation and Context
Consistent features and UX across managed resources.

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [x] Added/updated docs
2025-09-15 11:27:51 -07:00
J Logan 9692d79040 Bump containerization dependency to 0.7.2. (#610)
## Type of Change
- [ ] Bug fix
- [ ] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Motivation and Context
0.7.1 containerization contained a couple inadvertent commit reverts.

## Testing
- [ ] Tested locally
- [ ] Added/updated tests
- [ ] Added/updated docs
2025-09-15 09:07:42 -07:00
Kathryn Baldauf 1b68728629 Update builder shim version to 0.6.1 to support default global args (#605)
## Type of Change
- [x] Dependency update

## Motivation and Context
A change was made in container-builder-shim to support BuildKit's
default global args
https://github.com/apple/container-builder-shim/pull/44. A new tag of
container-builder-shim was made with this change and this PR updates to
that new tag for container-builder-shim.

Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
2025-09-12 15:11:49 -07:00
J Logan 243115504e Use containerization 0.7.1. (#606)
- Makes available the proxy utility from containerization#288.

## Type of Change
- [ ] Bug fix
- [x] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Motivation and Context
The proxy utility allows forward progress on #533.

## Testing
- [x] Tested locally
- [ ] Added/updated tests
- [ ] Added/updated docs
2025-09-12 12:49:57 -07:00
Dmitry Kovba 32e8c23265 Remove per-target concurrency checking (#601)
With `swift-tools-version: 6.2`, strict concurrency checking is enabled
by default - there is no need to enable it explicitly.
2025-09-11 11:42:02 -07:00
Danny Canter 8f6f39e89b Package.swift: Bump CZ to 0.7.0 (#584)
Closes #585

Has a fix for if a uid doesn't exist in /etc/passwd.
2025-09-08 11:35:30 -07:00
Danny Canter b50dc253e9 Bump CZ to 0.6.2 (#543)
Hopefully fixes CI..
2025-08-26 10:39:07 -07:00
Danny Canter 7f7090ff87 Bump CZ to 0.6.1 (#540)
This has one change since 0.6.0 that just adds a log in the guest to see
the spec for any execed processes.
2025-08-25 13:38:21 -07:00
J Logan 6767144d43 Bump containerization dependency to 0.6.0 (#526) 2025-08-19 18:58:09 -07:00
J Logan 07679d99c7 Extract version output logic so --version is consistent. (#517) 2025-08-18 10:27:27 -07:00
Sidhartha Mani 0885cdd6a9 Native Builder: DiffKey and Differ Procol (#482)
This PR introduces the `Differ` with methods:

```swift
// Differ protocol
func diff(base: Snapshot?, target: Snapshot) async throws -> Descriptor
func apply(descriptor: Descriptor, to base: Snapshot?) async throws -> Snapshot
```

It also introduces `DiffKey`, which is a MerkeTree based key for fast
diff computations between two dirs
2025-08-12 11:23:55 -07:00
J Logan 6242706c66 Fixes for install root and plugin detection. (#467)
- Sets up API server as source of truth for installation root, similarly
to what was done for the data root. `system start` establishes the
install root, setting the environment variable `CONTAINER_INSTALL_ROOT`
when launching the API server.
- The API server propagates the environment variable when launching
helpers, and returns the install root to the CLI via the health check
XPC.
- Includes several fixes for detecting plugins that use app bundle
layout.
2025-08-08 21:44:26 -07:00
J Logan d242864e9f Relocate and rename ClientDefaults. (#474)
- Part of #384.
- Rename to reflect that these are not just client defaults.
- Relocate so callers don't need the heavyweight coupling to
ContainerClient to access the type.
2025-08-08 16:04:32 -07:00
J Logan 88223d8add Select alternate data path with container system start --app-root path. (#419)
Closes #418.
2025-08-06 14:49:09 -07:00