commit 3407cc3f16a75c587a6d9d68285c7a31c9965acf Author: Kathryn Baldauf Date: Thu May 29 11:07:37 2025 -0700 initial commit Co-authored-by: Aditya Ramani Co-authored-by: Agam Dua Co-authored-by: Danny Canter Co-authored-by: Dmitry Kovba Co-authored-by: Eric Ernst Co-authored-by: Evan Hazlett Co-authored-by: Gilbert Song Co-authored-by: Hugh Bussell Co-authored-by: John Logan Co-authored-by: Kathryn Baldauf Co-authored-by: Madhu Venugopal Co-authored-by: Michael Crosby Co-authored-by: Sidhartha Mani Co-authored-by: Tanweer Noor Co-authored-by: Ximena Perez Diaz Co-authored-by: Yibo Zhuang diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 00000000..1cecd154 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,47 @@ +# 🌈 📦️ Welcome to the Containerization community! 📦️ 🌈 + +Contributions to Containerization are welcomed and encouraged. + +## How you can help + +We would love your contributions in the form of: + +* 🐛 Bug fixes +* ⚡️ Performance improvements +* ✨ API additions or enhancements +* 📝 Documentation +* 🧑‍💻 Project advocacy: blogs, conference talks, and more +* Anything else that could enhance the project! + +## Submitting Issues and Pull Requests + +### Issues + +To file a bug or feature request, use [GitHub](https://github.com/apple/containerization/issues/new) + +🚧 For unexpected behavior or usability limitations, detailed instructions on how to reproduce the issue are appreciated. This will greatly help the priority setting and speed of which maintainers can get to your issue. + +### Pull Requests + +To make a pull request, use [GitHub](https://github.com/apple/containerization/compare). Please give the team a few days to review but it's ok to check in on occassion. We appreciate your contribution! + +> [!IMPORTANT] +> If you plan to make substantial changes or add new features, we encourage you to first discuss them with the wider containerization developer community. +> You can do this by filing a [GitHub issue](https://github.com/apple/containerization/issues/new) +> This will save time and increases the chance of your pull request being accepted. + +#### Fomatting Contributions + +Make sure your contributions are consistent with the rest of the project's formatting. You can do this using our Makefile: + +```bash +$ make fmt +``` + +#### Applying License Header to New Files + +If you submit a contribution that adds a new file, please add the license header. You can do this using our Makefile: + +```bash +$ make update-licenses +``` diff --git a/CONTRIBUTORS.txt b/CONTRIBUTORS.txt new file mode 100644 index 00000000..6f4e0619 --- /dev/null +++ b/CONTRIBUTORS.txt @@ -0,0 +1,22 @@ +This file contains a list of contributors who have made meaningful changes to this repository. +Please add your name to this file as an optional step in the contribution process for attribution. +Email is not required. + +### Contributors + +Aditya Ramani +Agam Dua +Danny Canter +Dmitry Kovba +Eric (ASE) Ernst +Evan Hazlett +Gilbert Song +Hugh Bussell +John (ASE) Logan +Kathryn Baldauf +Madhu Venugopal +Michael Crosby +Sidhartha Mani +Tanweer Noor +Ximena Perez Diaz +Yibo Zhuang diff --git a/LICENSE.txt b/LICENSE.txt new file mode 100644 index 00000000..7a4a3ea2 --- /dev/null +++ b/LICENSE.txt @@ -0,0 +1,202 @@ + + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + + Copyright [yyyy] [name of copyright owner] + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. \ No newline at end of file diff --git a/Makefile b/Makefile new file mode 100644 index 00000000..ba8b7a0b --- /dev/null +++ b/Makefile @@ -0,0 +1,133 @@ +# Copyright © 2024-2025 Apple Inc. and the containerization project authors. All rights reserved. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# https://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +# Version and build configuration variables +# The default version ID 0.0.0 indicates a local development build or PRB +BUILD_CONFIGURATION ?= debug + +# Commonly used locations +SWIFT := "/usr/bin/swift" +ROOT_DIR := $(shell git rev-parse --show-toplevel) +BUILD_BIN_DIR := $(shell $(SWIFT) build -c $(BUILD_CONFIGURATION) --show-bin-path) + +# Variables for libarchive integration +LIBARCHIVE_UPSTREAM_REPO := https://github.com/libarchive/libarchive +LIBARCHIVE_UPSTREAM_VERSION := v3.7.7 +LIBARCHIVE_LOCAL_DIR := workdir/libarchive + +include Protobuf.Makefile +.DEFAULT_GOAL := all + +.PHONY: all +all: containerization +all: init + +.PHONY: release +release: BUILD_CONFIGURATION = release +release: all + +.PHONY: containerization +containerization: + @echo Building containerization binaries... + @mkdir -p bin + @$(SWIFT) build -c $(BUILD_CONFIGURATION) + + @echo Copying containerization binaries... + @install $(BUILD_BIN_DIR)/cctl ./bin/ + @install $(BUILD_BIN_DIR)/containerization-integration ./bin/ + + @echo Signing containerization binaries... + @codesign --force --sign - --timestamp=none --entitlements=signing/vz.entitlements bin/cctl + @codesign --force --sign - --timestamp=none --entitlements=signing/vz.entitlements bin/containerization-integration + +.PHONY: init +init: vminitd + @echo Creating init.ext4... + @rm -f bin/init.rootfs.tar.gz bin/init.block + @./bin/cctl rootfs create --vminitd vminitd/bin/vminitd --labels org.opencontainers.image.source=https://github.com/apple-uat/containerization --vmexec vminitd/bin/vmexec bin/init.rootfs.tar.gz vminit:latest + +.PHONY: cross-prep +cross-prep: + @"$(MAKE)" -C vminitd cross-prep + +.PHONY: vminitd +vminitd: + @mkdir -p ./bin + @"$(MAKE)" -C vminitd BUILD_CONFIGURATION=$(BUILD_CONFIGURATION) + +.PHONY: update-libarchive-source +update-libarchive-source: + @echo Updating the libarchive source files... + @git clone $(LIBARCHIVE_UPSTREAM_REPO) --depth 1 --branch $(LIBARCHIVE_UPSTREAM_VERSION) $(LIBARCHIVE_LOCAL_DIR) + @cp $(LIBARCHIVE_LOCAL_DIR)/libarchive/archive_entry.h Sources/ContainerizationArchive/CArchive/include + @cp $(LIBARCHIVE_LOCAL_DIR)/libarchive/archive.h Sources/ContainerizationArchive/CArchive/include + @cp $(LIBARCHIVE_LOCAL_DIR)/COPYING Sources/ContainerizationArchive/CArchive/COPYING + @rm -rf $(LIBARCHIVE_LOCAL_DIR) + +.PHONY: test +test: + @echo Testing all test targets... + @$(SWIFT) test --enable-code-coverage + +.PHONY: integration +integration: + @echo Running the integration tests... + @./bin/containerization-integration --bootlog ./bin/boot.log + +.PHONY: fmt +fmt: swift-fmt update-licenses + +.PHONY: swift-fmt +SWIFT_SRC = $(shell find . -type f -name '*.swift' -not -path "*/.*" -not -path "*.pb.swift" -not -path "*.grpc.swift" -not -path "*/checkouts/*") +swift-fmt: + @echo Applying the standard code formatting... + @$(SWIFT) format --recursive --configuration .swift-format -i $(SWIFT_SRC) + +.PHONY: update-licenses +update-licenses: + @echo Updating license headers... + @./scripts/ensure-hawkeye-exists.sh + @.local/bin/hawkeye format --fail-if-unknown --fail-if-updated false + +.PHONY: check-licenses +check-licenses: + @echo Checking license headers existence in source files... + @./scripts/ensure-hawkeye-exists.sh + @.local/bin/hawkeye check --fail-if-unknown + +.PHONY: serve-docs +serve-docs: site + @echo 'to browse: open http://127.0.0.1:8000/documentation/' + @python3 -m http.server --bind 127.0.0.1 --directory ./_site + +.PHONY: docs +docs: _site + +_site: + @echo Updating API documentation... + rm -rf $@ + @scripts/make-docs.sh $@ + +.PHONY: cleancontent +cleancontent: + @echo Cleaning the content... + @rm -rf ~/Library/Application\ Support/com.apple.containerization + +.PHONY: clean +clean: + @echo Cleaning the build files... + @rm -rf bin/ + @rm -rf _site/ + @$(SWIFT) package clean + @"$(MAKE)" -C vminitd clean diff --git a/Package.resolved b/Package.resolved new file mode 100644 index 00000000..8a0c5fc0 --- /dev/null +++ b/Package.resolved @@ -0,0 +1,204 @@ +{ + "originHash" : "944785f35daba39211e1c0033414cff9c136956de50baf611c6220a3ae0fa5bd", + "pins" : [ + { + "identity" : "async-http-client", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swift-server/async-http-client", + "state" : { + "revision" : "333f51104b75d1a5b94cb3b99e4c58a3b442c9f7", + "version" : "1.25.2" + } + }, + { + "identity" : "grpc-swift", + "kind" : "remoteSourceControl", + "location" : "https://github.com/grpc/grpc-swift", + "state" : { + "revision" : "67ae0617e1be215ca8cb4a8df5b4af940095c818", + "version" : "1.26.0" + } + }, + { + "identity" : "swift-algorithms", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-algorithms.git", + "state" : { + "revision" : "87e50f483c54e6efd60e885f7f5aa946cee68023", + "version" : "1.2.1" + } + }, + { + "identity" : "swift-argument-parser", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-argument-parser", + "state" : { + "revision" : "41982a3656a71c768319979febd796c6fd111d5c", + "version" : "1.5.0" + } + }, + { + "identity" : "swift-asn1", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-asn1.git", + "state" : { + "revision" : "a54383ada6cecde007d374f58f864e29370ba5c3", + "version" : "1.3.2" + } + }, + { + "identity" : "swift-atomics", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-atomics.git", + "state" : { + "revision" : "cd142fd2f64be2100422d658e7411e39489da985", + "version" : "1.2.0" + } + }, + { + "identity" : "swift-collections", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-collections.git", + "state" : { + "revision" : "671108c96644956dddcd89dd59c203dcdb36cec7", + "version" : "1.1.4" + } + }, + { + "identity" : "swift-crypto", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-crypto.git", + "state" : { + "revision" : "e8d6eba1fef23ae5b359c46b03f7d94be2f41fed", + "version" : "3.12.3" + } + }, + { + "identity" : "swift-docc-plugin", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-docc-plugin", + "state" : { + "revision" : "85e4bb4e1cd62cec64a4b8e769dcefdf0c5b9d64", + "version" : "1.4.3" + } + }, + { + "identity" : "swift-docc-symbolkit", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-docc-symbolkit", + "state" : { + "revision" : "b45d1f2ed151d057b54504d653e0da5552844e34", + "version" : "1.0.0" + } + }, + { + "identity" : "swift-http-structured-headers", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-http-structured-headers.git", + "state" : { + "revision" : "f280fc7676b9940ff2c6598642751ea333c6544f", + "version" : "1.2.2" + } + }, + { + "identity" : "swift-http-types", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-http-types.git", + "state" : { + "revision" : "a0a57e949a8903563aba4615869310c0ebf14c03", + "version" : "1.4.0" + } + }, + { + "identity" : "swift-log", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-log.git", + "state" : { + "revision" : "3d8596ed08bd13520157f0355e35caed215ffbfa", + "version" : "1.6.3" + } + }, + { + "identity" : "swift-nio", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-nio", + "state" : { + "revision" : "0f54d58bb5db9e064f332e8524150de379d1e51c", + "version" : "2.82.1" + } + }, + { + "identity" : "swift-nio-extras", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-nio-extras.git", + "state" : { + "revision" : "f1f6f772198bee35d99dd145f1513d8581a54f2c", + "version" : "1.26.0" + } + }, + { + "identity" : "swift-nio-http2", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-nio-http2.git", + "state" : { + "revision" : "4281466512f63d1bd530e33f4aa6993ee7864be0", + "version" : "1.36.0" + } + }, + { + "identity" : "swift-nio-ssl", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-nio-ssl.git", + "state" : { + "revision" : "6df102a39c8da5fdc2eae29a0f63546d660866fc", + "version" : "2.30.0" + } + }, + { + "identity" : "swift-nio-transport-services", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-nio-transport-services.git", + "state" : { + "revision" : "cd1e89816d345d2523b11c55654570acd5cd4c56", + "version" : "1.24.0" + } + }, + { + "identity" : "swift-numerics", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-numerics.git", + "state" : { + "revision" : "e0ec0f5f3af6f3e4d5e7a19d2af26b481acb6ba8", + "version" : "1.0.3" + } + }, + { + "identity" : "swift-protobuf", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-protobuf.git", + "state" : { + "revision" : "d72aed98f8253ec1aa9ea1141e28150f408cf17f", + "version" : "1.29.0" + } + }, + { + "identity" : "swift-syntax", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-syntax.git", + "state" : { + "revision" : "0687f71944021d616d34d922343dcef086855920", + "version" : "600.0.1" + } + }, + { + "identity" : "swift-system", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-system", + "state" : { + "revision" : "a34201439c74b53f0fd71ef11741af7e7caf01e1", + "version" : "1.4.2" + } + } + ], + "version" : 3 +} diff --git a/Package.swift b/Package.swift new file mode 100644 index 00000000..0350ae71 --- /dev/null +++ b/Package.swift @@ -0,0 +1,266 @@ +// swift-tools-version: 6.0 +//===----------------------------------------------------------------------===// +// Copyright © 2024-2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// The swift-tools-version declares the minimum version of Swift required to build this package. + +import CompilerPluginSupport +import Foundation +import PackageDescription + +let settings: [SwiftSetting] +if ProcessInfo.processInfo.environment["CURRENT_SDK"] != nil { + // TODO: Remove this compile condition when the updated macOS SDK is available publicly + settings = [.define("CURRENT_SDK")] +} else { + settings = [] +} + +let package = Package( + name: "containerization", + platforms: [.macOS("15")], + products: [ + .library(name: "Containerization", targets: ["Containerization", "ContainerizationError"]), + .library(name: "ContainerizationEXT4", targets: ["ContainerizationEXT4"]), + .library(name: "ContainerizationOCI", targets: ["ContainerizationOCI"]), + .library(name: "ContainerizationNetlink", targets: ["ContainerizationNetlink"]), + .library(name: "ContainerizationIO", targets: ["ContainerizationIO"]), + .library(name: "ContainerizationOS", targets: ["ContainerizationOS"]), + .library(name: "ContainerizationExtras", targets: ["ContainerizationExtras"]), + .library(name: "ContainerizationArchive", targets: ["ContainerizationArchive"]), + .library(name: "SendableProperty", targets: ["SendableProperty"]), + .executable(name: "cctl", targets: ["cctl"]), + ], + dependencies: [ + .package(url: "https://github.com/apple/swift-log.git", from: "1.0.0"), + .package(url: "https://github.com/apple/swift-argument-parser.git", from: "1.3.0"), + .package(url: "https://github.com/apple/swift-collections.git", from: "1.1.4"), + .package(url: "https://github.com/apple/swift-crypto.git", from: "3.0.0"), + .package(url: "https://github.com/grpc/grpc-swift.git", from: "1.26.0"), + .package(url: "https://github.com/apple/swift-protobuf.git", from: "1.29.0"), + .package(url: "https://github.com/apple/swift-nio.git", from: "2.80.0"), + .package(url: "https://github.com/swift-server/async-http-client.git", from: "1.20.1"), + .package(url: "https://github.com/apple/swift-system.git", from: "1.4.0"), + .package(url: "https://github.com/swiftlang/swift-syntax.git", from: "600.0.0-latest"), + .package(url: "https://github.com/swiftlang/swift-docc-plugin", from: "1.1.0"), + ], + targets: [ + .target( + name: "ContainerizationError" + ), + .target( + name: "Containerization", + dependencies: [ + .product(name: "Logging", package: "swift-log"), + .product(name: "GRPC", package: "grpc-swift"), + .product(name: "SystemPackage", package: "swift-system"), + .product(name: "_NIOFileSystem", package: "swift-nio"), + "ContainerizationOCI", + "ContainerizationOS", + "ContainerizationIO", + "ContainerizationExtras", + "SendableProperty", + .target(name: "ContainerizationEXT4", condition: .when(platforms: [.macOS])), + ], + exclude: [ + "../Containerization/SandboxContext/SandboxContext.proto" + ], + swiftSettings: settings + ), + .executableTarget( + name: "cctl", + dependencies: [ + .product(name: "Logging", package: "swift-log"), + .product(name: "ArgumentParser", package: "swift-argument-parser"), + "Containerization", + "ContainerizationOS", + ] + ), + .executableTarget( + name: "containerization-integration", + dependencies: [ + .product(name: "Logging", package: "swift-log"), + .product(name: "ArgumentParser", package: "swift-argument-parser"), + "Containerization", + ], + path: "Sources/Integration" + ), + .testTarget( + name: "ContainerizationUnitTests", + dependencies: ["Containerization"], + path: "Tests/ContainerizationTests", + resources: [.copy("ImageTests/Resources/scratch.tar")] + ), + .target( + name: "ContainerizationEXT4", + dependencies: [ + .target(name: "ContainerizationArchive", condition: .when(platforms: [.macOS])), + .product(name: "SystemPackage", package: "swift-system"), + "ContainerizationOS", + ] + ), + .testTarget( + name: "ContainerizationEXT4Tests", + dependencies: [ + "ContainerizationEXT4", + "ContainerizationArchive", + ], + resources: [ + .copy( + "Resources/content/blobs/sha256/ad59e9f71edceca7b1ac7c642410858489b743c97233b0a26a5e2098b1443762"), // index + .copy( + "Resources/content/blobs/sha256/48a06049d3738991b011ca8b12473d712b7c40666a1462118dae3c403676afc2"), // manifest + .copy( + "Resources/content/blobs/sha256/8e2eb240a6cd7be1a0d308125afe0060b020e89275ced2e729eda7d4eeff62a2"), // config + .copy( + "Resources/content/blobs/sha256/c6b39de5b33961661dc939b997cc1d30cda01e38005a6c6625fd9c7e748bab44"), // layer 1 + .copy( + "Resources/content/blobs/sha256/4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1"), // layer 2 + ] + ), + .target( + name: "ContainerizationArchive", + dependencies: [ + "CArchive", + .product(name: "SystemPackage", package: "swift-system"), + "ContainerizationExtras", + ], + exclude: [ + "CArchive" + ] + ), + .testTarget( + name: "ContainerizationArchiveTests", + dependencies: [ + "ContainerizationArchive" + ] + ), + .target( + name: "CArchive", + dependencies: [], + path: "Sources/ContainerizationArchive/CArchive", + cSettings: [ + .define( + "PLATFORM_CONFIG_H", to: "\"config_darwin.h\"", + .when(platforms: [.iOS, .macOS, .macCatalyst, .watchOS, .driverKit, .tvOS])), + .define("PLATFORM_CONFIG_H", to: "\"config_linux.h\"", .when(platforms: [.linux])), + ], + linkerSettings: [ + .linkedLibrary("z"), + .linkedLibrary("bz2"), + .linkedLibrary("lzma"), + .linkedLibrary("archive"), + .linkedLibrary("iconv", .when(platforms: [.macOS])), + .linkedLibrary("crypto", .when(platforms: [.linux])), + ] + ), + .target( + name: "ContainerizationOCI", + dependencies: [ + .product(name: "AsyncHTTPClient", package: "async-http-client"), + .product(name: "Crypto", package: "swift-crypto"), + .product(name: "Logging", package: "swift-log"), + .product(name: "_NIOFileSystem", package: "swift-nio"), + "ContainerizationError", + "ContainerizationOS", + "ContainerizationExtras", + ] + ), + .testTarget( + name: "ContainerizationOCITests", + dependencies: [ + "ContainerizationOCI", + "Containerization", + "ContainerizationIO", + .product(name: "NIO", package: "swift-nio"), + .product(name: "Crypto", package: "swift-crypto"), + ] + ), + .target( + name: "ContainerizationNetlink", + dependencies: [ + .product(name: "Logging", package: "swift-log"), + "ContainerizationOS", + "ContainerizationExtras", + ] + ), + .testTarget( + name: "ContainerizationNetlinkTests", + dependencies: [ + "ContainerizationNetlink" + ] + ), + .target( + name: "ContainerizationOS", + dependencies: [ + .product(name: "Logging", package: "swift-log"), + "CShim", + "ContainerizationError", + "SendableProperty", + ], + exclude: [ + "../ContainerizationOS/README.md" + ] + ), + .testTarget( + name: "ContainerizationOSTests", + dependencies: [ + "ContainerizationOS", + "ContainerizationExtras", + ] + ), + .target( + name: "ContainerizationIO", + dependencies: [ + "ContainerizationOS", + .product(name: "NIO", package: "swift-nio"), + .product(name: "NIOCore", package: "swift-nio"), + .product(name: "NIOFoundationCompat", package: "swift-nio"), + ] + ), + .target( + name: "ContainerizationExtras", + dependencies: [ + "ContainerizationError", + .product(name: "Collections", package: "swift-collections"), + .product(name: "Logging", package: "swift-log"), + ] + ), + .target( + name: "CShim" + ), + // Library that exposes a macro as part of its API, which is used in client programs. + .target(name: "SendableProperty", dependencies: ["SendablePropertyMacros"]), + // Macro implementation that performs the source transformation of a macro. + .macro( + name: "SendablePropertyMacros", + dependencies: [ + .product(name: "SwiftSyntaxMacros", package: "swift-syntax"), + .product(name: "SwiftCompilerPlugin", package: "swift-syntax"), + ] + ), + // A test target used to develop the macro implementation. + .testTarget( + name: "SendablePropertyMacrosTests", + dependencies: [ + "SendablePropertyMacros", + .product(name: "SwiftSyntaxMacrosTestSupport", package: "swift-syntax"), + ] + ), + // A test target for the macro implementation. + .testTarget(name: "SendablePropertyTests", dependencies: ["SendableProperty"]), + ] +) diff --git a/Protobuf.Makefile b/Protobuf.Makefile new file mode 100644 index 00000000..cfc6f9fb --- /dev/null +++ b/Protobuf.Makefile @@ -0,0 +1,37 @@ +LOCAL_DIR := $(ROOT_DIR)/.local +LOCALBIN := $(LOCAL_DIR)/bin + +## Versions +PROTOC_VERSION=26.1 + +# protoc binary installation +PROTOC_ZIP = protoc-$(PROTOC_VERSION)-osx-universal_binary.zip +PROTOC = $(LOCALBIN)/protoc@$(PROTOC_VERSION)/protoc +$(PROTOC): + @echo Downloading protocol buffers... + @mkdir -p $(LOCAL_DIR) + @curl -OL https://github.com/protocolbuffers/protobuf/releases/download/v$(PROTOC_VERSION)/$(PROTOC_ZIP) + @mkdir -p $(dir $@) + @unzip -jo $(PROTOC_ZIP) bin/protoc -d $(dir $@) + @unzip -o $(PROTOC_ZIP) 'include/*' -d $(dir $@) + @rm -f $(PROTOC_ZIP) + +protoc_gen_grpc_swift: + swift build --product protoc-gen-grpc-swift + +protoc-gen-swift: + swift build --product protoc-gen-swift + +.PHONY: protos +protos: $(PROTOC) protoc_gen_grpc_swift protoc-gen-swift + @echo Generating protocol buffers source code... + @$(PROTOC) Sources/Containerization/SandboxContext/SandboxContext.proto \ + --plugin=protoc-gen-grpc-swift=$(BUILD_BIN_DIR)/protoc-gen-grpc-swift \ + --plugin=protoc-gen-swift=$(BUILD_BIN_DIR)/protoc-gen-swift \ + --proto_path=Sources/Containerization/SandboxContext \ + --grpc-swift_out="Sources/Containerization/SandboxContext" \ + --grpc-swift_opt=Visibility=Public \ + --swift_out="Sources/Containerization/SandboxContext" \ + --swift_opt=Visibility=Public \ + -I. + @"$(MAKE)" update-licenses diff --git a/README.md b/README.md new file mode 100644 index 00000000..8af42748 --- /dev/null +++ b/README.md @@ -0,0 +1,109 @@ +# Containerization + +The Containerization package allows applications to use Linux containers. +Containerization is written in [Swift](https://www.swift.org) and uses [Virtualization.framework](https://developer.apple.com/documentation/virtualization) on Apple Silicon. + +Containerization provides APIs to: +- Manage OCI images. +- Interact with remote registries. +- Create and populate ext4 file systems. +- Interact with the Netlink socket family. +- Create an optimized Linux kernel for fast boot times. +- Spawn lightweight virtual machines. +- Manage the runtime environment of virtual machines. +- Spawn and interact with containerized processes. +- Use Rosetta 2 for executing x86_64 processes on Apple Silicon. + +Please view the [API documentation]() for information on the Swift packages that Containerization provides. + +## Design + +Containerization executes each Linux container inside of its own lightweight virtual machine. +Provide a dedicated IP address to the container to remove the need for individual port forwarding. + +Containers achieve sub-second start times using an optimized [Linux kernel configuration](/kernel) and a small init system. + +[vminitd](/vminitd) is a small init system, which is a subproject within Containerization. +`vminitd` is spawned as the initial process inside of the virtual machine and provides a GRPC API over vsock. +The API allows the runtime environment to be configured and containerized processes to be launched. +`vminitd` provides I/O, signals, and events to the calling process when a process is ran. + +## Requirements + +You need an Apple silicon Mac to build and run Containerization. + +To build the Containerization package, your system needs either: + +- macOS 15 or newer and Xcode 17 beta +- macOS 16 Developer Preview. + +Applications built using the package will run on macOS Sequoia or later, but the following features are not available on macOS Sequoia: + +- Non-isolated container networking - with macOS Sequoia, containers on the same vmnet network cannot communicate with each other +- Paravirtualized GPU support + +## Build the package + +Install Swiftly, [Swift](https://www.swift.org), and [Static Linux SDK](https://www.swift.org/documentation/articles/static-linux-getting-started.html): + +```bash +make cross-prep +``` + +If you use a custom terminal application, you may need to move this command from `.zprofile` to `.zshrc` (replace ``): +```bash +# Added by swiftly +. "/Users//.swiftly/env.sh" +``` + +Restart the terminal application. Ensure this command returns `/Users//.swiftly/bin/swift` (replace ``): +```bash +which swift +``` + +If you've installed or used a Static Linux SDK previously, you may need to remove older SDK versions from the system (replace ``): +``` +swift sdk list +swift sdk remove +``` + +Build Containerization from sources and run basic and integration tests: + +```bash +make all test integration +``` + +## Visual Studio Code + +To make changes to [vminitd](/vminitd), we recommend installing the [Swift](https://marketplace.visualstudio.com/items?itemName=swiftlang.swift-vscode) extension for Visual Studio Code. + +Set "Swift: Path" in the Settings to `/Users//.swiftly/bin` (replace ``) and "Swift: Swift SDK" to `x86_64-swift-linux-musl`. Restart Visual Studio Code to apply the settings. + +Open the folder [vminitd](/vminitd). Use "Run Task" - "Show All Tasks..." - "Build All" to build the package. + +## Protobufs + +Containerization depends on specific versions of `grpc-swift` and `swift-protobuf`. You can install them and re-generate RPC interfaces with: + +```bash +make protos +``` + +## Documentation + +Generate the API documentation for local viewing with: + +```bash +make docs +make serve-docs +``` + +Preview the documentation by running in another terminal: + +```bash +open http://localhost:8000/documentation/ +``` + +## Contributing + +Contributions to Containerization are welcomed and encouraged. Please see [CONTRIBUTING.md](/CONTRIBUTING.md) for more information. diff --git a/Sources/CShim/exec_command.c b/Sources/CShim/exec_command.c new file mode 100644 index 00000000..2fabfa7b --- /dev/null +++ b/Sources/CShim/exec_command.c @@ -0,0 +1,314 @@ +/* + * Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * https://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include + +#include "exec_command.h" + +void exec_command_attrs_init(struct exec_command_attrs *attrs) { + attrs->setpgid = 0; + attrs->pgid = 0; + attrs->setsid = 0; + attrs->setctty = 0; + attrs->ctty = 0; + attrs->mask = 0; + attrs->uid = -1; + attrs->gid = -1; +} + +static void child_handler(const int sync_pipes[2], const char *executable, + char *const args[], char *const environment[], + const int file_handles[], const int file_handle_count, + const char *cwd, const sigset_t old_mask, + const struct exec_command_attrs attrs) { + int i = 0; + int err = 0; + int fd_index = 0; + int fd_table[file_handle_count]; + struct rlimit limits = {0}; + int syncfd = sync_pipes[1]; + struct sigaction action = {0}; + + // closing our parent's side of the pipe + if (close(sync_pipes[0]) < 0) { + goto fail; + } + + // clear sighandlers + action.sa_flags = 0; + action.sa_handler = SIG_DFL; + sigemptyset(&action.sa_mask); + for (i = 0; i < NSIG; i++) { + sigaction(i, &action, 0); + } + + sigset_t local_mask; + sigemptyset(&local_mask); + if (pthread_sigmask(SIG_SETMASK, &local_mask, NULL) < 0) { + goto fail; + } + + // start shuffeling fds. + // look at all the filehandles and find the highest one, + // use that for our pipe, + // + // Then, we need to start dup2 the fds starting for the final process + // at 0-n. + // as an example we have this list of FDs that should be passed to the + // process: + // + /* + The index of this list is the final result that the new process expects. + The values are open fds provided from the parent process. + [0] == 12 + [1] == 7 + [2] == 9 + [3] == 0 + + We also have a pipe to sync the child and parent so that adds an additional + parameter to consider. + + So we start by finding the highest open fd in the list, then move our pipe to + the next. + + i.e. fd12 is highest so move our pipe to fd13 + + Now start moving all the fds above our pipe as we will need to start placing + the fds in the child process into the right order. Make sure they are all + marked cloexec. + + pipe == 13 + [0] == 12 dup2 14 + [1] == 7 dup2 15 + [2] == 9 dup2 16 + [3] == 0 dup2 17 + + Now overwrite the fd table for the child with the current index. + + Make index == fd. + + pipe == 13 + [0] == 14 dup2 0 + [1] == 15 dup2 1 + [2] == 16 dup2 2 + [3] == 17 dup2 3 + + Clear cloexec on this new fds. + */ + + // find the highest fd value in our list. + for (i = 0; i < file_handle_count; i++) { + if (file_handles[i] > fd_index) { + fd_index = file_handles[i]; + } + fd_table[i] = file_handles[i]; + } + // now fd_index is == to the highest fd in our list of handles. + // Increment it and set our pipe to it. + fd_index++; + + if (syncfd != fd_index) { + if (dup2(syncfd, fd_index) < 0) { + goto fail; + } + if (close(syncfd) < 0) { + goto fail; + } + syncfd = fd_index; + } + fd_index++; + + // make sure our syncfd retains its cloexec + if (fcntl(syncfd, F_SETFD, FD_CLOEXEC) == -1) { + goto fail; + } + + // move the rest of the fds up above our index if they don't match the index. + for (i = 0; i < file_handle_count; i++) { + if (fd_table[i] == i) { + continue; + } + if (dup2(fd_table[i], fd_index) < 0) { + goto fail; + } + if (fcntl(fd_index, F_SETFD, FD_CLOEXEC) == -1) { + goto fail; + } + fd_table[i] = fd_index; + fd_index++; + } + + // now create the child process's final fd table. where i == i + for (i = 0; i < file_handle_count; i++) { + if (fd_table[i] != i) { + if (dup2(fd_table[i], i) < 0) { + goto fail; + } + } + // now fd[i] should == i + // clear cloexec as this fd is where we want it. + if (fcntl(i, F_SETFD, 0) == -1) { + goto fail; + } + } + + if (attrs.setsid) { + if (setsid() == -1) { + goto fail; + } + } + if (attrs.setpgid) { + if (setpgid(0, attrs.pgid) < 0) { + goto fail; + } + } + + if (attrs.setctty) { + if (ioctl(attrs.ctty, TIOCSCTTY, 0)) { + goto fail; + } + } + + // Get our current open fd limit and close exec everything outside of our + // child's fd_table. + if (getrlimit(RLIMIT_NOFILE, &limits) < 0) { + goto fail; + } + for (i = file_handle_count; i <= limits.rlim_cur; i++) { + if (fcntl(i, F_SETFD, FD_CLOEXEC) == -1 && errno != EBADF) { + goto fail; + } + } + + // set gid + if (attrs.gid != -1) { + if (setgid(attrs.gid) != 0) { + goto fail; + } + } + + // set uid + if (attrs.uid != -1) { + if (setreuid(attrs.uid, attrs.uid) != 0) { + goto fail; + } + } + + if (cwd != NULL) { + if (chdir(cwd)) { + goto fail; + } + } + + execve(executable, args, environment); +fail: + err = errno; + if (err) { + // send our error to the parent + while (write(syncfd, &err, sizeof(err)) < 0) + ; + } + exit(127); +} + +int exec_command(pid_t *result, const char *executable, char *const args[], + char *const envp[], const int file_handles[], + const int file_handle_count, const char *working_directory, + struct exec_command_attrs *attrs) { + pid_t pid = 0; + int err = 0; + int sync_pipe[2]; + sigset_t old_mask; + + sigset_t all; + sigfillset(&all); + + if (pipe(sync_pipe)) { + goto fail; + } + + if (pthread_sigmask(SIG_SETMASK, &all, &old_mask) < 0) { + goto fail; + } + + pid = fork(); + if (pid == -1) { + close(sync_pipe[0]); + close(sync_pipe[1]); + goto fail; + } + + if (pid == 0) { + // hand off to child + child_handler(sync_pipe, executable, args, envp, file_handles, + file_handle_count, working_directory, old_mask, *attrs); + exit(EXIT_FAILURE); + } + + // handle parent operations + if (close(sync_pipe[1]) < 0) { + goto fail; + } + + // sync with our child process + err = 0; + ssize_t size = read(sync_pipe[0], &err, sizeof(err)); + // -- we didn't get an errno back + if (size != sizeof(err)) { + // will be used as return result + err = 0; + } else { + // we did get an errno back from the child process and our + // err var is set to that errno + // lets set our errno and then reap the process + errno = err; + int status = 0; + waitpid(pid, &status, 0); + // lets continue our journey below + } + + if (close(sync_pipe[0]) < 0) { + goto fail; + } + if (err) { + goto fail; + } + + (*result) = pid; + err = 0; +fail: + if (pthread_sigmask(SIG_SETMASK, &old_mask, 0) < 0) { + printf("restoring signal mask: %s\n", strerror(errno)); + } + if (err) { + printf("exec_command execve: %s\n", strerror(err)); + return -1; + } + return 0; +} diff --git a/Sources/CShim/include/exec_command.h b/Sources/CShim/include/exec_command.h new file mode 100644 index 00000000..a503ae2f --- /dev/null +++ b/Sources/CShim/include/exec_command.h @@ -0,0 +1,49 @@ +/* + * Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * https://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +#ifndef exec_command_h +#define exec_command_h + +#include +#include + +struct exec_command_attrs { + int setpgid; + /// parent group id + pid_t pgid; + /// set the controlling terminal + int setctty; + /// controlling terminal fd + int ctty; + /// set the process as session leader + int setsid; + /// set the process user id + uid_t uid; + /// set the process group id + gid_t gid; + /// signal mask for the child process + int mask; +}; + +void exec_command_attrs_init(struct exec_command_attrs *attrs); + +/// spawn a new child process with the provided attrs +int exec_command(pid_t *result, const char *executable, char *const argv[], + char *const envp[], const int file_handles[], + const int file_handle_count, const char *working_directory, + struct exec_command_attrs *attrs); + +#endif /* exec_command_h */ diff --git a/Sources/CShim/include/vsock.h b/Sources/CShim/include/vsock.h new file mode 100644 index 00000000..6d03c519 --- /dev/null +++ b/Sources/CShim/include/vsock.h @@ -0,0 +1,33 @@ +/* + * Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * https://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +// + +#ifndef vsock_h +#define vsock_h + +#include + +#ifdef __APPLE__ + #include +#else + #include + #include +#endif /* __APPLE__ */ + +extern const unsigned long VsockLocalCIDIoctl; + +#endif /* vsock_h */ diff --git a/Sources/CShim/vsock.c b/Sources/CShim/vsock.c new file mode 100644 index 00000000..76e4c1cd --- /dev/null +++ b/Sources/CShim/vsock.c @@ -0,0 +1,19 @@ +/* + * Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * https://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +#include "vsock.h" + +const unsigned long VsockLocalCIDIoctl = IOCTL_VM_SOCKETS_GET_LOCAL_CID; diff --git a/Sources/Containerization/Agent/Vminitd+Rosetta.swift b/Sources/Containerization/Agent/Vminitd+Rosetta.swift new file mode 100644 index 00000000..21eb8c66 --- /dev/null +++ b/Sources/Containerization/Agent/Vminitd+Rosetta.swift @@ -0,0 +1,36 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationOS +import Foundation + +extension Vminitd { + /// Enable Rosetta's x86_64 emulation. + public func enableRosetta() async throws { + let path = "/run/rosetta" + try await self.mount( + .init( + type: "virtiofs", + source: "rosetta", + destination: path + ) + ) + try await self.setupEmulator( + binaryPath: "\(path)/rosetta", + configuration: Binfmt.Entry.amd64() + ) + } +} diff --git a/Sources/Containerization/Agent/Vminitd+SocketRelay.swift b/Sources/Containerization/Agent/Vminitd+SocketRelay.swift new file mode 100644 index 00000000..f0e14b6e --- /dev/null +++ b/Sources/Containerization/Agent/Vminitd+SocketRelay.swift @@ -0,0 +1,47 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +extension Vminitd: SocketRelayAgent { + /// Sets up a relay between a host socket to a newly created guest socket, or vice versa. + public func relaySocket(port: UInt32, configuration: UnixSocketConfiguration) async throws { + let request = Com_Apple_Containerization_Sandbox_V3_ProxyVsockRequest.with { + $0.id = configuration.id + $0.vsockPort = port + + if let perms = configuration.permissions { + $0.guestSocketPermissions = UInt32(perms.rawValue) + } + + switch configuration.direction { + case .into: + $0.guestPath = configuration.to.path + $0.action = .into + case .outOf: + $0.guestPath = configuration.from.path + $0.action = .outOf + } + } + _ = try await client.proxyVsock(request) + } + + /// Stops the specified socket relay. + public func stopSocketRelay(configuration: UnixSocketConfiguration) async throws { + let request = Com_Apple_Containerization_Sandbox_V3_StopVsockProxyRequest.with { + $0.id = configuration.id + } + _ = try await client.stopVsockProxy(request) + } +} diff --git a/Sources/Containerization/Agent/Vminitd.swift b/Sources/Containerization/Agent/Vminitd.swift new file mode 100644 index 00000000..16714702 --- /dev/null +++ b/Sources/Containerization/Agent/Vminitd.swift @@ -0,0 +1,352 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationError +import ContainerizationOCI +import ContainerizationOS +import Foundation +import GRPC +import NIOPosix + +/// A remote connection into the vminitd Linux guest agent via a port (vsock). +/// Used to modify the runtime environment of the Linux sandbox. +public struct Vminitd: Sendable { + public typealias Client = Com_Apple_Containerization_Sandbox_V3_SandboxContextAsyncClient + + // Default vsock port that the agent and client use. + public static let port: UInt32 = 1024 + + private static let defaultPath = "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin" + + let client: Client + + public init(client: Client) { + self.client = client + } + + public init(connection: FileHandle, group: MultiThreadedEventLoopGroup) { + self.client = .init(connection: connection, group: group) + } + + public func close() async throws { + try await client.close() + } +} + +extension Vminitd: VirtualMachineAgent { + public func standardSetup() async throws { + try await up(name: "lo") + + try await setenv(key: "PATH", value: Self.defaultPath) + + let mounts: [ContainerizationOCI.Mount] = [ + .init(type: "sysfs", source: "sysfs", destination: "/sys"), + .init(type: "tmpfs", source: "tmpfs", destination: "/tmp"), + .init(type: "devpts", source: "devpts", destination: "/dev/pts", options: ["gid=5", "mode=620", "ptmxmode=666"]), + .init(type: "cgroup2", source: "none", destination: "/sys/fs/cgroup"), + ] + for mount in mounts { + try await self.mount(mount) + } + } + + /// Mount a filesystem in the sandbox's environment. + public func mount(_ mount: ContainerizationOCI.Mount) async throws { + _ = try await client.mount( + .with { + $0.type = mount.type + $0.source = mount.source + $0.destination = mount.destination + $0.options = mount.options + }) + } + + /// Unmount a filesystem in the sandbox's environment. + public func umount(path: String, flags: Int32) async throws { + _ = try await client.umount( + .with { + $0.path = path + $0.flags = flags + }) + } + + /// Create a directory inside the sandbox's environment. + public func mkdir(path: String, all: Bool, perms: UInt32) async throws { + _ = try await client.mkdir( + .with { + $0.path = path + $0.all = all + $0.perms = perms + }) + } + + public func createProcess( + id: String, + containerID: String?, + stdinPort: UInt32?, + stdoutPort: UInt32?, + stderrPort: UInt32?, + configuration: ContainerizationOCI.Spec, + options: Data? + ) async throws { + let enc = JSONEncoder() + _ = try await client.createProcess( + .with { + $0.id = id + if let stdinPort { + $0.stdin = stdinPort + } + if let stdoutPort { + $0.stdout = stdoutPort + } + if let stderrPort { + $0.stderr = stderrPort + } + if let containerID { + $0.containerID = containerID + } + $0.configuration = try enc.encode(configuration) + }) + } + + @discardableResult + public func startProcess(id: String, containerID: String?) async throws -> Int32 { + let request = Com_Apple_Containerization_Sandbox_V3_StartProcessRequest.with { + $0.id = id + if let containerID { + $0.containerID = containerID + } + } + let resp = try await client.startProcess(request) + return resp.pid + } + + public func signalProcess(id: String, containerID: String?, signal: Int32) async throws { + let request = Com_Apple_Containerization_Sandbox_V3_KillProcessRequest.with { + $0.id = id + $0.signal = signal + if let containerID { + $0.containerID = containerID + } + } + _ = try await client.killProcess(request) + } + + public func resizeProcess(id: String, containerID: String?, columns: UInt32, rows: UInt32) async throws { + let request = Com_Apple_Containerization_Sandbox_V3_ResizeProcessRequest.with { + if let containerID { + $0.containerID = containerID + } + $0.id = id + $0.columns = columns + $0.rows = rows + } + _ = try await client.resizeProcess(request) + } + + public func waitProcess(id: String, containerID: String?, timeoutInSeconds: Int64? = nil) async throws -> Int32 { + let request = Com_Apple_Containerization_Sandbox_V3_WaitProcessRequest.with { + $0.id = id + if let containerID { + $0.containerID = containerID + } + } + var callOpts: CallOptions? + if let timeoutInSeconds { + var copts = CallOptions() + copts.timeLimit = .timeout(.seconds(timeoutInSeconds)) + callOpts = copts + } + do { + let resp = try await client.waitProcess(request, callOptions: callOpts) + return resp.exitCode + } catch { + if let err = error as? GRPCError.RPCTimedOut { + throw ContainerizationError( + .timeout, + message: "failed to wait for process exit within timeout of \(timeoutInSeconds!) seconds", + cause: err + ) + } + throw error + } + } + + public func deleteProcess(id: String, containerID: String?) async throws { + let request = Com_Apple_Containerization_Sandbox_V3_DeleteProcessRequest.with { + $0.id = id + if let containerID { + $0.containerID = containerID + } + } + _ = try await client.deleteProcess(request) + } + + public func up(name: String) async throws { + let request = Com_Apple_Containerization_Sandbox_V3_IpLinkSetRequest.with { + $0.interface = name + $0.up = true + } + _ = try await client.ipLinkSet(request) + } + + public func down(name: String) async throws { + let request = Com_Apple_Containerization_Sandbox_V3_IpLinkSetRequest.with { + $0.interface = name + $0.up = false + } + _ = try await client.ipLinkSet(request) + } + + /// Get an environment variable from the sandbox's environment. + public func getenv(key: String) async throws -> String { + let response = try await client.getenv( + .with { + $0.key = key + }) + return response.value + } + + /// Set an environment variable in the sandbox's environment. + public func setenv(key: String, value: String) async throws { + _ = try await client.setenv( + .with { + $0.key = key + $0.value = value + }) + } +} + +/// Vminitd specific rpcs. +extension Vminitd { + /// Sets up an emulator in the guest. + public func setupEmulator(binaryPath: String, configuration: Binfmt.Entry) async throws { + let request = Com_Apple_Containerization_Sandbox_V3_SetupEmulatorRequest.with { + $0.binaryPath = binaryPath + $0.name = configuration.name + $0.type = configuration.type + $0.offset = configuration.offset + $0.magic = configuration.magic + $0.mask = configuration.mask + $0.flags = configuration.flags + } + _ = try await client.setupEmulator(request) + } + + /// Sets the guest time. + public func setTime(sec: Int64, usec: Int32) async throws { + let request = Com_Apple_Containerization_Sandbox_V3_SetTimeRequest.with { + $0.sec = sec + $0.usec = usec + } + _ = try await client.setTime(request) + } + + /// Set the provided sysctls inside the Sandbox's environment. + public func sysctl(settings: [String: String]) async throws { + let request = Com_Apple_Containerization_Sandbox_V3_SysctlRequest.with { + $0.settings = settings + } + _ = try await client.sysctl(request) + } + + /// Add an IP address to the sandbox's network interfaces. + public func addressAdd(name: String, address: String) async throws { + _ = try await client.ipAddrAdd( + .with { + $0.interface = name + $0.address = address + }) + } + + /// Set the default route in the sandbox's environment. + public func routeAddDefault(name: String, gateway: String) async throws { + _ = try await client.ipRouteAddDefault( + .with { + $0.interface = name + $0.gateway = gateway + }) + } + + /// Configure DNS within the sandbox's environment. + public func configureDNS(config: DNS, location: String) async throws { + _ = try await client.configureDns( + .with { + $0.location = location + $0.nameservers = config.nameservers + if let domain = config.domain { + $0.domain = domain + } + $0.searchDomains = config.searchDomains + $0.options = config.options + }) + } + + /// Perform a sync call. + public func sync() async throws { + _ = try await client.sync(.init()) + } + + public func kill(pid: Int32, signal: Int32) async throws -> Int32 { + let response = try await client.kill( + .with { + $0.pid = pid + $0.signal = signal + }) + return response.result + } + + /// Syncing shutdown will send a SIGTERM to all processes + /// and wait, perform a sync operation, then issue a SIGKILL + /// to the remaining processes before syncing again. + public func syncingShutdown() async throws { + _ = try await self.kill(pid: -1, signal: SIGTERM) + try await Task.sleep(for: .milliseconds(10)) + try await self.sync() + + _ = try await self.kill(pid: -1, signal: SIGKILL) + try await Task.sleep(for: .milliseconds(10)) + try await self.sync() + } +} + +extension Vminitd.Client { + public init(socket: String, group: MultiThreadedEventLoopGroup) { + var config = ClientConnection.Configuration.default( + target: .unixDomainSocket(socket), + eventLoopGroup: group + ) + config.maximumReceiveMessageLength = Int(64.mib()) + config.connectionBackoff = ConnectionBackoff(retries: .upTo(5)) + + self = .init(channel: ClientConnection(configuration: config)) + } + + public init(connection: FileHandle, group: MultiThreadedEventLoopGroup) { + var config = ClientConnection.Configuration.default( + target: .connectedSocket(connection.fileDescriptor), + eventLoopGroup: group + ) + config.maximumReceiveMessageLength = Int(64.mib()) + config.connectionBackoff = ConnectionBackoff(retries: .upTo(5)) + + self = .init(channel: ClientConnection(configuration: config)) + } + + public func close() async throws { + try await self.channel.close().get() + } +} diff --git a/Sources/Containerization/AttachedFilesystem.swift b/Sources/Containerization/AttachedFilesystem.swift new file mode 100644 index 00000000..c9e1cd37 --- /dev/null +++ b/Sources/Containerization/AttachedFilesystem.swift @@ -0,0 +1,50 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationExtras +import ContainerizationOCI + +/// A filesystem that was attached and able to be mounted inside the runtime environment. +public struct AttachedFilesystem: Sendable { + /// The type of the filesystem. + public var type: String + /// The path to the filesystem within a sandbox. + public var source: String + /// Destination when mounting the filesystem inside a sandbox. + public var destination: String + /// The options to use when mounting the filesystem. + public var options: [String] + + #if os(macOS) + public init(mount: Mount, allocator: any AddressAllocator) throws { + switch mount.type { + case "virtiofs": + let name = try hashMountSource(source: mount.source) + self.type = mount.type + self.source = name + case "ext4": + let char = try allocator.allocate() + self.type = mount.type + self.source = "/dev/vd\(char)" + default: + self.type = mount.type + self.source = mount.source + } + self.options = mount.options + self.destination = mount.destination + } + #endif +} diff --git a/Sources/Containerization/ConnectionStream.swift b/Sources/Containerization/ConnectionStream.swift new file mode 100644 index 00000000..b896b5b8 --- /dev/null +++ b/Sources/Containerization/ConnectionStream.swift @@ -0,0 +1,57 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +#if os(macOS) +import Virtualization +#endif + +public final class ConnectionStream: NSObject, Sendable { + /// A stream of connections dialed from the remote. + public let connections: AsyncStream + + private let cont: AsyncStream.Continuation + private let port: UInt32 + + public init(port: UInt32) { + self.port = port + let (stream, continuation) = AsyncStream.makeStream(of: FileHandle.self) + self.connections = stream + self.cont = continuation + } + + public func finish() { + self.cont.finish() + } +} + +#if os(macOS) + +extension ConnectionStream: VZVirtioSocketListenerDelegate { + public func listener( + _: VZVirtioSocketListener, shouldAcceptNewConnection conn: VZVirtioSocketConnection, + from _: VZVirtioSocketDevice + ) -> Bool { + let fd = dup(conn.fileDescriptor) + conn.close() + + cont.yield(FileHandle(fileDescriptor: fd, closeOnDealloc: false)) + return true + } +} + +#endif diff --git a/Sources/Containerization/Container.swift b/Sources/Containerization/Container.swift new file mode 100644 index 00000000..252d4c57 --- /dev/null +++ b/Sources/Containerization/Container.swift @@ -0,0 +1,25 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +/// The core protocol container implementations must implement. +public protocol Container { + var id: String { get } + + var cpus: Int { get } + var memoryInBytes: UInt64 { get } + + var interfaces: [any Interface] { get } +} diff --git a/Sources/Containerization/DNSConfiguration.swift b/Sources/Containerization/DNSConfiguration.swift new file mode 100644 index 00000000..84e4fc43 --- /dev/null +++ b/Sources/Containerization/DNSConfiguration.swift @@ -0,0 +1,60 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +public struct DNS: Sendable { + public static let defaultNameservers = ["1.1.1.1"] + + public var nameservers: [String] + public var domain: String? + public var searchDomains: [String] + public var options: [String] + + public init( + nameservers: [String] = defaultNameservers, + domain: String? = nil, + searchDomains: [String] = [], + options: [String] = [] + ) { + self.nameservers = nameservers + self.domain = domain + self.searchDomains = searchDomains + self.options = options + } +} + +extension DNS { + public var resolvConf: String { + var text = "" + + if !nameservers.isEmpty { + text += nameservers.map { "nameserver \($0)" }.joined(separator: "\n") + "\n" + } + + if let domain { + text += "domain \(domain)\n" + } + + if !searchDomains.isEmpty { + text += "search \(searchDomains.joined(separator: " "))\n" + } + + if !options.isEmpty { + text += "opts \(options.joined(separator: " "))\n" + } + + return text + } +} diff --git a/Sources/Containerization/Hash.swift b/Sources/Containerization/Hash.swift new file mode 100644 index 00000000..a266ff2e --- /dev/null +++ b/Sources/Containerization/Hash.swift @@ -0,0 +1,29 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +#if os(macOS) + +import Crypto +import ContainerizationError + +func hashMountSource(source: String) throws -> String { + guard let data = source.data(using: .utf8) else { + throw ContainerizationError(.invalidArgument, message: "\(source) could not be converted to Data") + } + return String(SHA256.hash(data: data).encoded.prefix(36)) +} + +#endif diff --git a/Sources/Containerization/IO/ReaderStream.swift b/Sources/Containerization/IO/ReaderStream.swift new file mode 100644 index 00000000..a35ea479 --- /dev/null +++ b/Sources/Containerization/IO/ReaderStream.swift @@ -0,0 +1,22 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +/// A type that returns a stream of Data. +public protocol ReaderStream: Sendable { + func stream() -> AsyncStream +} diff --git a/Sources/Containerization/IO/Terminal+ReaderStream.swift b/Sources/Containerization/IO/Terminal+ReaderStream.swift new file mode 100644 index 00000000..602f2551 --- /dev/null +++ b/Sources/Containerization/IO/Terminal+ReaderStream.swift @@ -0,0 +1,36 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationOS +import Foundation + +extension Terminal: ReaderStream { + public func stream() -> AsyncStream { + .init { cont in + self.handle.readabilityHandler = { handle in + let data = handle.availableData + if data.isEmpty { + self.handle.readabilityHandler = nil + cont.finish() + return + } + cont.yield(data) + } + } + } +} + +extension Terminal: Writer {} diff --git a/Sources/Containerization/IO/Writer.swift b/Sources/Containerization/IO/Writer.swift new file mode 100644 index 00000000..5d23a168 --- /dev/null +++ b/Sources/Containerization/IO/Writer.swift @@ -0,0 +1,22 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +/// A type that writes the provided Data. +public protocol Writer: Sendable { + func write(_ data: Data) throws +} diff --git a/Sources/Containerization/Image/Image.swift b/Sources/Containerization/Image/Image.swift new file mode 100644 index 00000000..1a396fa1 --- /dev/null +++ b/Sources/Containerization/Image/Image.swift @@ -0,0 +1,206 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationError +import ContainerizationOCI +import ContainerizationOS +import Foundation + +#if os(macOS) +import ContainerizationArchive +import ContainerizationEXT4 +import SystemPackage +import ContainerizationExtras +#endif + +public struct Image: Sendable { + + private let contentStore: ContentStore + /// The description for the image that comprises of its name and a reference to its root descriptor. + public let description: Description + + public struct Description: Sendable { + public let reference: String + public let descriptor: Descriptor + public var digest: String { descriptor.digest } + public var mediaType: String { descriptor.mediaType } + + public init(reference: String, descriptor: Descriptor) { + self.reference = reference + self.descriptor = descriptor + } + } + + public var descriptor: Descriptor { description.descriptor } + public var digest: String { description.digest } + public var mediaType: String { description.mediaType } + public var reference: String { description.reference } + + public init(description: Description, contentStore: ContentStore) { + self.description = description + self.contentStore = contentStore + } + + /// Returns the underlying OCI index for the image. + public func index() async throws -> Index { + guard let content: Content = try await contentStore.get(digest: digest) else { + throw ContainerizationError(.notFound, message: "Content with digest \(digest)") + } + return try content.decode() + } + + /// Returns the manifest for the specified platform. + public func manifest(for platform: Platform) async throws -> Manifest { + let index = try await self.index() + let desc = index.manifests.first { desc in + desc.platform == platform + } + guard let desc else { + throw ContainerizationError(.unsupported, message: "Platform \(platform.description)") + } + guard let content: Content = try await contentStore.get(digest: desc.digest) else { + throw ContainerizationError(.notFound, message: "Content with digest \(digest)") + } + return try content.decode() + } + + public func descriptor(for platform: Platform) async throws -> Descriptor { + let index = try await self.index() + let desc = index.manifests.first { $0.platform == platform } + guard let desc else { + throw ContainerizationError(.invalidArgument, message: "unsupported platform \(platform)") + } + return desc + } + + /// Returns the OCI config for the specified platform. + public func config(for platform: Platform) async throws -> ContainerizationOCI.Image { + let manifest = try await self.manifest(for: platform) + let desc = manifest.config + guard let content: Content = try await contentStore.get(digest: desc.digest) else { + throw ContainerizationError(.notFound, message: "Content with digest \(digest)") + } + return try content.decode() + } + + /// Returns a list of digests to all the referenced OCI objects. + public func referencedDigests() async throws -> [String] { + var referenced: [String] = [self.digest.trimmingDigestPrefix] + let index = try await self.index() + for manifest in index.manifests { + referenced.append(manifest.digest.trimmingDigestPrefix) + guard let m: Manifest = try? await contentStore.get(digest: manifest.digest) else { + // If the requested digest does not exist or is not a manifest. Skip. + // Its safe to skip processing this digest as it wont have any child layers. + continue + } + let descs = m.layers + [m.config] + referenced.append(contentsOf: descs.map { $0.digest.trimmingDigestPrefix }) + } + return referenced + } + + /// Returns a reference to the content blob for the image. The specified digest must be referenced by the image in one of its layers. + public func getContent(digest: String) async throws -> Content { + guard try await self.referencedDigests().contains(digest.trimmingDigestPrefix) else { + throw ContainerizationError(.internalError, message: "Image \(self.reference) does not reference digest \(digest)") + } + guard let content: Content = try await contentStore.get(digest: digest) else { + throw ContainerizationError(.notFound, message: "Content with digest \(digest)") + } + return content + } +} + +#if os(macOS) + +extension Image { + /// Unpack the image into a filesystem. + public func unpack(for platform: Platform, at path: URL, blockSizeInBytes: UInt64 = 512.gib(), progress: ProgressHandler? = nil) async throws -> Mount { + let blockPath = try prepareUnpackPath(path: path) + let manifest = try await loadManifest(platform: platform) + return try await unpackContents( + path: blockPath, + manifest: manifest, + blockSizeInBytes: blockSizeInBytes, + progress: progress + ) + } + + private func loadManifest(platform: Platform) async throws -> Manifest { + let manifest = try await descriptor(for: platform) + guard let m: Manifest = try await self.contentStore.get(digest: manifest.digest) else { + throw ContainerizationError(.notFound, message: "content not found \(manifest.digest)") + } + return m + } + + private func prepareUnpackPath(path: URL) throws -> String { + let blockPath = path.absolutePath() + guard !FileManager.default.fileExists(atPath: blockPath) else { + throw ContainerizationError(.exists, message: "block device already exists at \(blockPath)") + } + return blockPath + } + + private func unpackContents(path: String, manifest: Manifest, blockSizeInBytes: UInt64, progress: ProgressHandler?) async throws -> Mount { + let filesystem = try EXT4.Formatter(FilePath(path), minDiskSize: blockSizeInBytes) + defer { try? filesystem.close() } + + for layer in manifest.layers { + try Task.checkCancellation() + guard let content = try await self.contentStore.get(digest: layer.digest) else { + throw ContainerizationError(.notFound, message: "Content with digest \(layer.digest)") + } + + switch layer.mediaType { + case MediaTypes.imageLayer, MediaTypes.dockerImageLayer: + try filesystem.unpack( + source: content.path, + format: .paxRestricted, + compression: .none, + progress: progress + ) + case MediaTypes.imageLayerGzip, MediaTypes.dockerImageLayerGzip: + try filesystem.unpack( + source: content.path, + format: .paxRestricted, + compression: .gzip, + progress: progress + ) + default: + throw ContainerizationError(.unsupported, message: "Media type \(layer.mediaType) not supported.") + } + } + + return .block( + format: "ext4", + source: path, + destination: "/", + options: [] + ) + } +} + +#else + +extension Image { + public func unpack(for platform: Platform, at path: URL, blockSizeInBytes: UInt64 = 512.gib()) async throws -> Mount { + throw ContainerizationError(.unsupported, message: "Image unpack unsupported on current platform") + } +} + +#endif diff --git a/Sources/Containerization/Image/ImageStore/ImageStore+Export.swift b/Sources/Containerization/Image/ImageStore/ImageStore+Export.swift new file mode 100644 index 00000000..2bb79537 --- /dev/null +++ b/Sources/Containerization/Image/ImageStore/ImageStore+Export.swift @@ -0,0 +1,176 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// + +import ContainerizationError +import ContainerizationExtras +import ContainerizationIO +import ContainerizationOCI +import Crypto +import Foundation + +extension ImageStore { + internal struct ExportOperation { + let name: String + let tag: String + let contentStore: ContentStore + let client: ContentClient + let progress: ProgressHandler? + + init(name: String, tag: String, contentStore: ContentStore, client: ContentClient, progress: ProgressHandler? = nil) { + self.contentStore = contentStore + self.client = client + self.progress = progress + self.name = name + self.tag = tag + } + + @discardableResult + internal func export(index: Descriptor, platforms: (Platform) -> Bool) async throws -> Descriptor { + var pushQueue: [[Descriptor]] = [] + var current: [Descriptor] = [index] + while !current.isEmpty { + let children = try await self.getChildren(descs: current) + let matches = try filterPlatforms(matcher: platforms, children).uniqued { $0.digest } + pushQueue.append(matches) + current = matches + } + let localIndexData = try await self.createIndex(from: index, matching: platforms) + + await updatePushProgress(pushQueue: pushQueue, localIndexData: localIndexData) + + // We need to work bottom up when pushing an image. + // First, the tar blobs / config layers, then, the manifests and so on... + // When processing a given "level", the requests maybe made in parallel. + // We need to ensure that the child level has been uploaded fully + // before uploading the parent level. + try await withThrowingTaskGroup(of: Void.self) { group in + for layerGroup in pushQueue.reversed() { + for chunk in layerGroup.chunks(ofCount: 8) { + for desc in chunk { + guard let content = try await self.contentStore.get(digest: desc.digest) else { + throw ContainerizationError(.notFound, message: "Content with digest \(desc.digest)") + } + group.addTask { + let readStream = try ReadStream(url: content.path) + try await self.pushContent(descriptor: desc, stream: readStream) + } + } + try await group.waitForAll() + } + } + } + + // Lastly, we need to construct and push a new index, since we may + // have pushed content only for specific platforms. + let digest = SHA256.hash(data: localIndexData) + let descriptor = Descriptor( + mediaType: MediaTypes.index, + digest: digest.digestString, + size: Int64(localIndexData.count)) + let stream = ReadStream(data: localIndexData) + try await self.pushContent(descriptor: descriptor, stream: stream) + return descriptor + } + + private func updatePushProgress(pushQueue: [[Descriptor]], localIndexData: Data) async { + for layerGroup in pushQueue { + for desc in layerGroup { + await progress?([ + ProgressEvent(event: "add-total-size", value: desc.size), + ProgressEvent(event: "add-total-items", value: 1), + ]) + } + } + await progress?([ + ProgressEvent(event: "add-total-size", value: localIndexData.count), + ProgressEvent(event: "add-total-items", value: 1), + ]) + } + + private func createIndex(from index: Descriptor, matching: (Platform) -> Bool) async throws -> Data { + guard let content = try await self.contentStore.get(digest: index.digest) else { + throw ContainerizationError(.notFound, message: "Content with digest \(index.digest)") + } + var idx: Index = try content.decode() + let manifests = idx.manifests + var matchedManifests: [Descriptor] = [] + var skippedPlatforms = false + for manifest in manifests { + guard let p = manifest.platform else { + continue + } + if matching(p) { + matchedManifests.append(manifest) + } else { + skippedPlatforms = true + } + } + if !skippedPlatforms { + return try content.data() + } + idx.manifests = matchedManifests + return try JSONEncoder().encode(idx) + } + + private func pushContent(descriptor: Descriptor, stream: ReadStream) async throws { + do { + let generator = { + try stream.reset() + return stream.stream + } + try await client.push(name: name, ref: tag, descriptor: descriptor, streamGenerator: generator, progress: progress) + await progress?([ + ProgressEvent(event: "add-size", value: descriptor.size), + ProgressEvent(event: "add-items", value: 1), + ]) + } catch let err as ContainerizationError { + guard err.code != .exists else { + // We reported the total items and size and have to account for them in existing content. + await progress?([ + ProgressEvent(event: "add-size", value: descriptor.size), + ProgressEvent(event: "add-items", value: 1), + ]) + return + } + throw err + } + } + + private func getChildren(descs: [Descriptor]) async throws -> [Descriptor] { + var out: [Descriptor] = [] + for desc in descs { + let mediaType = desc.mediaType + guard let content = try await self.contentStore.get(digest: desc.digest) else { + throw ContainerizationError(.notFound, message: "Content with digest \(desc.digest)") + } + switch mediaType { + case MediaTypes.index, MediaTypes.dockerManifestList: + let index: Index = try content.decode() + out.append(contentsOf: index.manifests) + case MediaTypes.imageManifest, MediaTypes.dockerManifest: + let manifest: Manifest = try content.decode() + out.append(manifest.config) + out.append(contentsOf: manifest.layers) + default: + continue + } + } + return out + } + } +} diff --git a/Sources/Containerization/Image/ImageStore/ImageStore+Import.swift b/Sources/Containerization/Image/ImageStore/ImageStore+Import.swift new file mode 100644 index 00000000..36f2e461 --- /dev/null +++ b/Sources/Containerization/Image/ImageStore/ImageStore+Import.swift @@ -0,0 +1,236 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// + +import ContainerizationError +import ContainerizationExtras +import ContainerizationOCI +import Foundation + +extension ImageStore { + internal struct ImportOperation { + static let decoder = JSONDecoder() + + let client: ContentClient + let ingestDir: URL + let contentStore: ContentStore + let progress: ProgressHandler? + let name: String + + init(name: String, contentStore: ContentStore, client: ContentClient, ingestDir: URL, progress: ProgressHandler? = nil) { + self.client = client + self.ingestDir = ingestDir + self.contentStore = contentStore + self.progress = progress + self.name = name + } + + /// Pull the required image layers for the provided descriptor and platform(s) into the given directory using the provided client. Returns a descriptor to the Index manifest. + internal func `import`(root: Descriptor, matcher: (ContainerizationOCI.Platform) -> Bool) async throws -> Descriptor { + var toProcess = [root] + while !toProcess.isEmpty { + // Count the total number of blobs and their size + if let progress { + var size: Int64 = 0 + for desc in toProcess { + size += desc.size + } + await progress([ + ProgressEvent(event: "add-total-size", value: size), + ProgressEvent(event: "add-total-items", value: toProcess.count), + ]) + } + + try await self.fetch(toProcess) + let children = try await self.walk(toProcess) + let filtered = try filterPlatforms(matcher: matcher, children) + toProcess = filtered.uniqued { $0.digest } + } + + guard root.mediaType != MediaTypes.dockerManifestList && root.mediaType != MediaTypes.index else { + return root + } + + // Create an index for the root descriptor and write it to the content store + let index = try await self.createIndex(for: root) + // In cases where the root descriptor pointed to `MediaTypes.imageManifest` + // Or `MediaTypes.dockerManifest`, it is required that we check the supported platform + // matches the platforms we were asked to pull. This can be done only after we created + // the Index. + let supportedPlatforms = index.manifests.compactMap { $0.platform } + guard supportedPlatforms.allSatisfy(matcher) else { + throw ContainerizationError(.unsupported, message: "Image \(root.digest) does not support required platforms") + } + let writer = try ContentWriter(for: self.ingestDir) + let result = try writer.create(from: index) + return Descriptor( + mediaType: MediaTypes.index, + digest: result.digest.digestString, + size: Int64(result.size)) + } + + private func getManifestContent(descriptor: Descriptor) async throws -> T { + do { + if let content = try await self.contentStore.get(digest: descriptor.digest.trimmingDigestPrefix) { + return try content.decode() + } + if let content = try? LocalContent(path: ingestDir.appending(path: descriptor.digest.trimmingDigestPrefix)) { + return try content.decode() + } + return try await self.client.fetch(name: name, descriptor: descriptor) + } catch { + throw ContainerizationError(.internalError, message: "Cannot fetch content with digest \(descriptor.digest)") + } + } + + private func walk(_ descriptors: [Descriptor]) async throws -> [Descriptor] { + var out: [Descriptor] = [] + for desc in descriptors { + let mediaType = desc.mediaType + switch mediaType { + case MediaTypes.index, MediaTypes.dockerManifestList: + let index: Index = try await self.getManifestContent(descriptor: desc) + out.append(contentsOf: index.manifests) + case MediaTypes.imageManifest, MediaTypes.dockerManifest: + let manifest: Manifest = try await self.getManifestContent(descriptor: desc) + out.append(manifest.config) + out.append(contentsOf: manifest.layers) + default: + // TODO: Explicitly handle other content types + continue + } + } + return out + } + + private func fetch(_ inDesc: [Descriptor]) async throws { + try await withThrowingTaskGroup(of: Void.self) { group in + for chunk in inDesc.chunks(ofCount: 8) { + for desc in chunk { + if let found = try await self.contentStore.get(digest: desc.digest) { + try FileManager.default.copyItem(at: found.path, to: ingestDir.appendingPathComponent(desc.digest.trimmingDigestPrefix)) + await progress?([ + // Count the size of the blob + ProgressEvent(event: "add-size", value: desc.size), + // Count the number of blobs + ProgressEvent(event: "add-items", value: 1), + ]) + continue + } + group.addTask { + if desc.size > 1.mib() { + try await self.fetchBlob(desc) + } else { + try await self.fetchData(desc) + } + // Count the number of blobs + await progress?([ + ProgressEvent(event: "add-items", value: 1) + ]) + } + } + try await group.waitForAll() + } + } + } + + private func fetchBlob(_ descriptor: Descriptor) async throws { + let id = UUID().uuidString + let fm = FileManager.default + let tempFile = ingestDir.appendingPathComponent(id) + let (_, digest) = try await client.fetchBlob(name: name, descriptor: descriptor, into: tempFile, progress: progress) + guard digest.digestString == descriptor.digest else { + throw ContainerizationError(.internalError, message: "Digest mismatch expected \(descriptor.digest), got \(digest.digestString)") + } + do { + try fm.moveItem(at: tempFile, to: ingestDir.appendingPathComponent(digest.encoded)) + } catch let err as NSError { + guard err.code == NSFileWriteFileExistsError else { + throw err + } + try fm.removeItem(at: tempFile) + } + } + + @discardableResult + private func fetchData(_ descriptor: Descriptor) async throws -> Data { + let data = try await client.fetchData(name: name, descriptor: descriptor) + let writer = try ContentWriter(for: ingestDir) + let result = try writer.write(data) + if let progress { + let size = Int64(result.size) + await progress([ + ProgressEvent(event: "add-size", value: size) + ]) + } + guard result.digest.digestString == descriptor.digest else { + throw ContainerizationError(.internalError, message: "Digest mismatch expected \(descriptor.digest), got \(result.digest.digestString)") + } + return data + } + + private func createIndex(for root: Descriptor) async throws -> Index { + switch root.mediaType { + case MediaTypes.index, MediaTypes.dockerManifestList: + return try await self.getManifestContent(descriptor: root) + case MediaTypes.imageManifest, MediaTypes.dockerManifest: + let supportedPlatforms = try await getSupportedPlatforms(for: root) + guard supportedPlatforms.count == 1 else { + throw ContainerizationError( + .internalError, + message: + "Descriptor \(root.mediaType) with digest \(root.digest) does not list any supported platform or supports more than one platform. Supported platforms = \(supportedPlatforms)" + ) + } + let platform = supportedPlatforms.first! + var root = root + root.platform = platform + let index = ContainerizationOCI.Index(schemaVersion: 2, manifests: [root]) + return index + default: + throw ContainerizationError(.internalError, message: "Failed to create index for descriptor \(root.digest), media type \(root.mediaType)") + } + } + + private func getSupportedPlatforms(for root: Descriptor) async throws -> [ContainerizationOCI.Platform] { + var supportedPlatforms: [ContainerizationOCI.Platform] = [] + var toProcess = [root] + while !toProcess.isEmpty { + let children = try await self.walk(toProcess) + for child in children { + if let p = child.platform { + supportedPlatforms.append(p) + continue + } + switch child.mediaType { + case MediaTypes.imageConfig, MediaTypes.dockerImageConfig: + let config: ContainerizationOCI.Image = try await self.getManifestContent(descriptor: child) + let p = ContainerizationOCI.Platform( + arch: config.architecture, os: config.os, osFeatures: config.osFeatures, variant: config.variant + ) + supportedPlatforms.append(p) + default: + continue + } + } + toProcess = children + } + return supportedPlatforms + } + + } +} diff --git a/Sources/Containerization/Image/ImageStore/ImageStore+OCILayout.swift b/Sources/Containerization/Image/ImageStore/ImageStore+OCILayout.swift new file mode 100644 index 00000000..9e9583aa --- /dev/null +++ b/Sources/Containerization/Image/ImageStore/ImageStore+OCILayout.swift @@ -0,0 +1,112 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationError +import ContainerizationExtras +import ContainerizationOCI +import Foundation + +extension ImageStore { + /// Exports the specified images and their associated layers to an OCI Image Layout directory. + /// This function saves the images identified by the `references` array, including their + /// manifests and layer blobs, into a directory structure compliant with the OCI Image Layout specification at the given `out` URL. + /// + /// - Parameters: + /// - references : A list image references that exists in the `ImageStore` that are to be saved in the OCI Image Layout format. + /// - out: A URL to a directory on disk at which the OCI Image Layout structure will be created. + /// - platform: An optional parameter to indicate the platform to be saved for the images. + /// Defaults to `nil` signifying that layers for all supported platforms by the images will be saved. + /// + public func save(references: [String], out: URL, platform: Platform? = nil) async throws { + let matcher = createPlatformMatcher(for: platform) + let fileManager = FileManager.default + let tempDir = fileManager.uniqueTemporaryDirectory() + defer { + try? fileManager.removeItem(at: tempDir) + } + + var toSave: [Image] = [] + for reference in references { + let image = try await self.get(reference: reference) + let allowedMediaTypes = [MediaTypes.dockerManifestList, MediaTypes.index] + guard allowedMediaTypes.contains(image.mediaType) else { + throw ContainerizationError(.internalError, message: "Cannot save image \(image.reference) with Index media type \(image.mediaType)") + } + toSave.append(image) + } + let client = try LocalOCILayoutClient(root: out) + var saved: [Descriptor] = [] + + for image in toSave { + let ref = try Reference.parse(image.reference) + let name = ref.path + guard let tag = ref.tag ?? ref.digest else { + throw ContainerizationError(.invalidArgument, message: "Invalid tag/digest for image reference \(image.reference)") + } + let operation = ExportOperation(name: name, tag: tag, contentStore: self.contentStore, client: client, progress: nil) + var descriptor = try await operation.export(index: image.descriptor, platforms: matcher) + client.setImageReferenceAnnotation(descriptor: &descriptor, reference: image.reference) + saved.append(descriptor) + } + try client.createOCILayoutStructre(directory: out, manifests: saved) + } + + /// Imports one or more images and their associated layers from an OCI Image Layout directory. + /// + /// - Parameters: + /// - from : A URL to a directory on disk at that follows the OCI Image Layout structure. + /// - progress: An optional handler over which progress update events about the load operation can be received. + /// - Returns: The list of images that were loaded into the `ImageStore`. + /// + public func load(from directory: URL, progress: ProgressHandler? = nil) async throws -> [Image] { + let client = try LocalOCILayoutClient(root: directory) + let index = try client.loadIndexFromOCILayout(directory: directory) + let matcher = createPlatformMatcher(for: nil) + + var loaded: [Image.Description] = [] + let (id, tempDir) = try await self.contentStore.newIngestSession() + do { + for descriptor in index.manifests { + guard let reference = client.getImageReferencefromDescriptor(descriptor: descriptor) else { + continue + } + let ref = try Reference.parse(reference) + let name = ref.path + let operation = ImportOperation(name: name, contentStore: self.contentStore, client: client, ingestDir: tempDir, progress: progress) + let indexDesc = try await operation.import(root: descriptor, matcher: matcher) + loaded.append(Image.Description(reference: reference, descriptor: indexDesc)) + } + + let loadedImages = loaded + let importedImages = try await self.lock.withLock { lock in + var images: [Image] = [] + try await self.contentStore.completeIngestSession(id) + for description in loadedImages { + let img = try await self._create(description: description, lock: lock) + images.append(img) + } + return images + } + guard importedImages.count > 0 else { + throw ContainerizationError(.internalError, message: "Failed to import image") + } + return importedImages + } catch { + try? await self.contentStore.cancelIngestSession(id) + throw error + } + } +} diff --git a/Sources/Containerization/Image/ImageStore/ImageStore+ReferenceManager.swift b/Sources/Containerization/Image/ImageStore/ImageStore+ReferenceManager.swift new file mode 100644 index 00000000..0f188063 --- /dev/null +++ b/Sources/Containerization/Image/ImageStore/ImageStore+ReferenceManager.swift @@ -0,0 +1,90 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationError +import ContainerizationOCI +import Foundation + +extension ImageStore { + /// A ReferenceManager handles the mappings between an image's + /// reference and the underlying descriptor inside of a content store. + internal actor ReferenceManager: Sendable { + private let path: URL + + private typealias State = [String: Descriptor] + private var images: State + + public init(path: URL) throws { + try FileManager.default.createDirectory(at: path, withIntermediateDirectories: true) + + self.path = path + self.images = [:] + } + + private func load() throws -> State { + let statePath = self.path.appendingPathComponent("state.json") + guard FileManager.default.fileExists(atPath: statePath.absolutePath()) else { + return [:] + } + do { + let data = try Data(contentsOf: statePath) + return try JSONDecoder().decode(State.self, from: data) + } catch { + throw ContainerizationError(.internalError, message: "Failed to load image state \(error.localizedDescription)") + } + } + + private func save(_ state: State) throws { + let statePath = self.path.appendingPathComponent("state.json") + try JSONEncoder().encode(state).write(to: statePath) + } + + public func delete(reference: String) throws { + var state = try self.load() + state.removeValue(forKey: reference) + try self.save(state) + } + + public func delete(image: Image.Description) throws { + try self.delete(reference: image.reference) + } + + public func create(description: Image.Description) throws { + var state = try self.load() + state[description.reference] = description.descriptor + try self.save(state) + } + + public func list() throws -> [Image.Description] { + let state = try self.load() + return state.map { key, val in + let description = Image.Description(reference: key, descriptor: val) + return description + } + } + + public func get(reference: String) throws -> Image.Description { + let images = try self.list() + let hit = images.first(where: { image in + image.reference == reference + }) + guard let hit else { + throw ContainerizationError(.notFound, message: "image \(reference) not found") + } + return hit + } + } +} diff --git a/Sources/Containerization/Image/ImageStore/ImageStore.swift b/Sources/Containerization/Image/ImageStore/ImageStore.swift new file mode 100644 index 00000000..8ecfb0cd --- /dev/null +++ b/Sources/Containerization/Image/ImageStore/ImageStore.swift @@ -0,0 +1,247 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationError +import ContainerizationExtras +import ContainerizationOCI +import Foundation + +/// An ImageStore handles the mappings between an image's +/// reference and the underlying descriptor inside of a content store. +public actor ImageStore: Sendable { + private let referenceManager: ReferenceManager + internal let contentStore: ContentStore + internal let lock: AsyncLock = AsyncLock() + + public init(path: URL, contentStore: ContentStore) throws { + try FileManager.default.createDirectory(at: path, withIntermediateDirectories: true) + + self.contentStore = contentStore + self.referenceManager = try ReferenceManager(path: path) + } +} + +extension ImageStore { + /// Get an image from the `ImageStore`. + /// + /// - Parameters: + /// - reference: Name of the image. + /// + /// - Returns: A `Containerization.Image` object whose `reference` matches the given string. + /// This method throws a `ContainerizationError(code: .notFound)` if the provided reference does not exist in the `ImageStore`. + public func get(reference: String) async throws -> Image { + let desc = try await self.referenceManager.get(reference: reference) + return Image(description: desc, contentStore: self.contentStore) + } + + /// Get a list of all images in the `ImageStore`. + /// + /// - Returns: A `[Containerization.Image]` for all the images in the `ImageStore`. + public func list() async throws -> [Image] { + try await self.referenceManager.list().map { desc in + Image(description: desc, contentStore: self.contentStore) + } + } + + /// Create a new image in the `ImageStore`. + /// + /// - Parameters: + /// - description: The underlying `Image.Description` that contains information about the reference and index descriptor for the image to be created. + /// + /// - Note: It is assumed that the underlying manifests and blob layers for the image already exists in the `ContentStore` that the `ImageStore` was initialized with. This method is invoked when the `pull(...)` , `load(...)` and `tag(...)` methods are used. + /// - Returns: A `Containerization.Image` + @discardableResult + internal func create(description: Image.Description) async throws -> Image { + try await self.lock.withLock { ctx in + try await self._create(description: description, lock: ctx) + } + } + + @discardableResult + internal func _create(description: Image.Description, lock: AsyncLock.Context) async throws -> Image { + try await self.referenceManager.create(description: description) + return Image(description: description, contentStore: self.contentStore) + } + + /// Delete an image from the `ImageStore`. + /// + /// - Parameters: + /// - reference: Name of the image that is to be deleted. + /// - performCleanup: Perform a garbage collection on the `ContentStore`, removing all unreferenced image layers and manifests, + public func delete(reference: String, performCleanup: Bool = false) async throws { + try await self.lock.withLock { lockCtx in + try await self.referenceManager.delete(reference: reference) + if performCleanup { + try await self._prune(lockCtx) + } + } + } + + /// Perform a garbage collection in the underlying `ContentStore` that is managed by the `ImageStore`. + /// + /// - Returns: Returns a tuple of `(deleted, freed)`. + /// `deleted` : A list of the names of the content items that were deleted from the `ContentStore`, + /// `freed` : The total size of the items that were deleted. + @discardableResult + public func prune() async throws -> (deleted: [String], freed: UInt64) { + try await self.lock.withLock { lockCtx in + try await self._prune(lockCtx) + } + } + + @discardableResult + private func _prune(_ lock: AsyncLock.Context) async throws -> ([String], UInt64) { + let images = try await self.list() + var referenced: [String] = [] + for image in images { + try await referenced.append(contentsOf: image.referencedDigests().uniqued()) + } + let (deleted, size) = try await self.contentStore.delete(keeping: referenced) + return (deleted, size) + + } + + /// Tag an existing image such that it can be referenced by another name. + /// + /// - Parameters: + /// - existing: The reference to an image that already exists in the `ImageStore`. + /// - new: The new reference by which the image should also be referenced as. + /// - Note: The new image created in the `ImageStore` will have the same `Image.Description` + /// as that of the image with reference `existing.` + /// - Returns: A `Containerization.Image` object to the newly created image. + public func tag(existing: String, new: String) async throws -> Image { + let old = try await self.get(reference: existing) + let descriptor = old.descriptor + do { + _ = try Reference.parse(new) + } catch { + throw ContainerizationError(.invalidArgument, message: "Invalid reference \(new). Error: \(error)") + } + let newDescription = Image.Description(reference: new, descriptor: descriptor) + return try await self.create(description: newDescription) + } +} + +extension ImageStore { + /// Pull an image and its associated manifest and blob layers from a remote registry. + /// + /// - Parameters: + /// - reference: A string that references an image in a remote registry of the form `[:]/repository:` + /// For example: "docker.io/library/alpine:latest". + /// - platform: An optional parameter to indicate the platform to be pulled for the image. + /// Defaults to `nil` signifying that layers for all supported platforms by the image will be pulled. + /// - insecure: A boolean indicating if the connection to the remote registry should be made via plain-text http or not. + /// Defaults to false, meaning the connection to the registry will be over https. + /// - auth: An object that implements the `Authentication` protocol, + /// used to add any credentials to the HTTP requests that are made to the registry. + /// Defaults to `nil` meaning no additional credentials are added to any HTTP requests made to the registry. + /// - progress: An optional handler over which progress update events about the pull operation can be received. + /// + /// - Returns: A `Containerization.Image` object to the newly pulled image. + public func pull( + reference: String, platform: Platform? = nil, insecure: Bool = false, + auth: Authentication? = nil, progress: ProgressHandler? = nil + ) async throws -> Image { + + let matcher = createPlatformMatcher(for: platform) + let client = try RegistryClient(reference: reference, insecure: insecure, auth: auth) + + let ref = try Reference.parse(reference) + let name = ref.path + guard let tag = ref.tag ?? ref.digest else { + throw ContainerizationError(.invalidArgument, message: "Invalid tag/digest for image reference \(reference)") + } + + let rootDescriptor = try await client.resolve(name: name, tag: tag) + let (id, tempDir) = try await self.contentStore.newIngestSession() + let operation = ImportOperation(name: name, contentStore: self.contentStore, client: client, ingestDir: tempDir, progress: progress) + do { + let index = try await operation.import(root: rootDescriptor, matcher: matcher) + return try await self.lock.withLock { lock in + try await self.contentStore.completeIngestSession(id) + let description = Image.Description(reference: reference, descriptor: index) + let image = try await self._create(description: description, lock: lock) + return image + } + } catch { + try? await self.contentStore.cancelIngestSession(id) + throw error + } + } + + /// Push an image and its associated manifest and blob layers to a remote registry. + /// + /// - Parameters: + /// - reference: A string that references an image in the `ImageStore`. It must be of the form `[:]/repository:` + /// For example: "ghcr.io/foo-bar-baz/image:v1". + /// - platform: An optional parameter to indicate the platform to be pushed for the image. + /// Defaults to `nil` signifying that layers for all supported platforms by the image will be pushed to the remote registry. + /// - insecure: A boolean indicating if the connection to the remote registry should be made via plain-text http or not. + /// Defaults to false, meaning the connection to the registry will be over https. + /// - auth: An object that implements the `Authentication` protocol, + /// used to add any credentials to the HTTP requests that are made to the registry. + /// Defaults to `nil` meaning no additional credentials are added to any HTTP requests made to the registry. + /// - progress: An optional handler over which progress update events about the push operation can be received. + /// + public func push(reference: String, platform: Platform? = nil, insecure: Bool = false, auth: Authentication? = nil, progress: ProgressHandler? = nil) async throws { + let matcher = createPlatformMatcher(for: platform) + let img = try await self.get(reference: reference) + let allowedMediaTypes = [MediaTypes.dockerManifestList, MediaTypes.index] + guard allowedMediaTypes.contains(img.mediaType) else { + throw ContainerizationError(.internalError, message: "Cannot push image \(reference) with Index media type \(img.mediaType)") + } + let ref = try Reference.parse(reference) + let name = ref.path + guard let tag = ref.tag ?? ref.digest else { + throw ContainerizationError(.invalidArgument, message: "Invalid tag/digest for image reference \(reference)") + } + let client = try RegistryClient(reference: reference, insecure: insecure, auth: auth) + let operation = ExportOperation(name: name, tag: tag, contentStore: self.contentStore, client: client, progress: progress) + try await operation.export(index: img.descriptor, platforms: matcher) + } +} + +extension ImageStore { + /// Get the kernel image from the image store. + /// If the kernel image does not exist locally, pull the image. + public func getKernel(reference: String, auth: Authentication? = nil, progress: ProgressHandler? = nil) async throws -> KernelImage { + do { + let image = try await self.get(reference: reference) + return KernelImage(image: image) + } catch let error as ContainerizationError { + if error.code == .notFound { + let image = try await self.pull(reference: reference, auth: auth, progress: progress) + return KernelImage(image: image) + } + throw error + } + } + + /// Get the image for the init block from the image store. + /// If the image does not exist locally, pull the image. + public func getInitImage(reference: String, auth: Authentication? = nil, progress: ProgressHandler? = nil) async throws -> InitImage { + do { + let image = try await self.get(reference: reference) + return InitImage(image: image) + } catch let error as ContainerizationError { + if error.code == .notFound { + let image = try await self.pull(reference: reference, auth: auth, progress: progress) + return InitImage(image: image) + } + throw error + } + } +} diff --git a/Sources/Containerization/Image/InitImage.swift b/Sources/Containerization/Image/InitImage.swift new file mode 100644 index 00000000..98671d75 --- /dev/null +++ b/Sources/Containerization/Image/InitImage.swift @@ -0,0 +1,81 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationError +import ContainerizationOCI +import Foundation + +public struct InitImage: Sendable { + public var name: String { image.reference } + + let image: Image + + public init(image: Image) { + self.image = image + } +} + +extension InitImage { + /// Unpack the initial filesystem for the desired platform at a given path. + public func initBlock(at: URL, for platform: SystemPlatform) async throws -> Mount { + var fs = try await image.unpack(for: platform.ociPlatform(), at: at, blockSizeInBytes: 512.mib()) + fs.options = ["ro"] + return fs + } + + /// Create a new InitImage with the reference as the name. + /// The `rootfs` parameter must be a tar.gz file whose contents make up the filesystem for the image. + public static func create( + reference: String, rootfs: URL, platform: Platform, + labels: [String: String] = [:], imageStore: ImageStore, contentStore: ContentStore + ) async throws -> InitImage { + + let indexDescriptorStore = AsyncStore() + try await contentStore.ingest { dir in + let writer = try ContentWriter(for: dir) + var result = try writer.create(from: rootfs) + let layerDescriptor = Descriptor(mediaType: ContainerizationOCI.MediaTypes.imageLayerGzip, digest: result.digest.digestString, size: result.size) + + // TODO: compute and fill in the correct diffID for the above layer + // We currently put in the sha of the fully compressed layer, this needs to be replaced with + // the sha of the uncompressed layer. + let rootfsConfig = ContainerizationOCI.Rootfs(type: "layers", diffIDs: [result.digest.digestString]) + let runtimeConfig = ContainerizationOCI.ImageConfig(labels: labels) + let imageConfig = ContainerizationOCI.Image(architecture: platform.architecture, os: platform.os, config: runtimeConfig, rootfs: rootfsConfig) + result = try writer.create(from: imageConfig) + let configDescriptor = Descriptor(mediaType: ContainerizationOCI.MediaTypes.imageConfig, digest: result.digest.digestString, size: result.size) + + let manifest = Manifest(config: configDescriptor, layers: [layerDescriptor]) + result = try writer.create(from: manifest) + let manifestDescriptor = Descriptor(mediaType: ContainerizationOCI.MediaTypes.imageManifest, digest: result.digest.digestString, size: result.size, platform: platform) + + let index = ContainerizationOCI.Index(manifests: [manifestDescriptor]) + result = try writer.create(from: index) + + let indexDescriptor = Descriptor(mediaType: ContainerizationOCI.MediaTypes.index, digest: result.digest.digestString, size: result.size) + await indexDescriptorStore.set(indexDescriptor) + + } + + guard let indexDescriptor = await indexDescriptorStore.get() else { + throw ContainerizationError(.notFound, message: "image for \(reference) not found") + } + + let description = Image.Description(reference: reference, descriptor: indexDescriptor) + let image = try await imageStore.create(description: description) + return InitImage(image: image) + } +} diff --git a/Sources/Containerization/Image/KernelImage.swift b/Sources/Containerization/Image/KernelImage.swift new file mode 100644 index 00000000..cdbe896b --- /dev/null +++ b/Sources/Containerization/Image/KernelImage.swift @@ -0,0 +1,94 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationError +import ContainerizationOCI +import Foundation + +/// A multi-arch kernel image represented by an OCI image. +public struct KernelImage: Sendable { + /// The media type for a kernel image. + public static let mediaType = "application/vnd.apple.containerization.kernel" + + /// The name or reference of the image. + public var name: String { image.reference } + + let image: Image + + public init(image: Image) { + self.image = image + } +} + +extension KernelImage { + /// Return the kernel from a multi arch image for a specific system platform. + public func kernel(for platform: SystemPlatform) async throws -> Kernel { + let manifest = try await image.manifest(for: platform.ociPlatform()) + guard let descriptor = manifest.layers.first, descriptor.mediaType == Self.mediaType else { + throw ContainerizationError(.notFound, message: "kernel descriptor for \(platform) not found") + } + let content = try await image.getContent(digest: descriptor.digest) + return Kernel( + path: content.path, + platform: platform + ) + } + + /// Create a new kernel image with the reference as the name. + /// This will create a multi arch image containing kernel's for each provided architecture. + public static func create(reference: String, binaries: [Kernel], labels: [String: String] = [:], imageStore: ImageStore, contentStore: ContentStore) async throws -> KernelImage + { + let indexDescriptorStore = AsyncStore() + try await contentStore.ingest { ingestPath in + var descriptors = [Descriptor]() + let writer = try ContentWriter(for: ingestPath) + + for kernel in binaries { + var result = try writer.create(from: kernel.path) + let platform = kernel.platform.ociPlatform() + let layerDescriptor = Descriptor( + mediaType: mediaType, + digest: result.digest.digestString, + size: result.size, + platform: platform) + let rootfsConfig = ContainerizationOCI.Rootfs(type: "layers", diffIDs: [result.digest.digestString]) + let runtimeConfig = ContainerizationOCI.ImageConfig(labels: labels) + let imageConfig = ContainerizationOCI.Image(architecture: platform.architecture, os: platform.os, config: runtimeConfig, rootfs: rootfsConfig) + + result = try writer.create(from: imageConfig) + let configDescriptor = Descriptor(mediaType: ContainerizationOCI.MediaTypes.imageConfig, digest: result.digest.digestString, size: result.size) + + let manifest = Manifest(config: configDescriptor, layers: [layerDescriptor]) + result = try writer.create(from: manifest) + let manifestDescriptor = Descriptor( + mediaType: ContainerizationOCI.MediaTypes.imageManifest, digest: result.digest.digestString, size: result.size, platform: platform) + descriptors.append(manifestDescriptor) + } + let index = ContainerizationOCI.Index(manifests: descriptors) + let result = try writer.create(from: index) + let indexDescriptor = Descriptor(mediaType: ContainerizationOCI.MediaTypes.index, digest: result.digest.digestString, size: result.size) + await indexDescriptorStore.set(indexDescriptor) + } + + guard let indexDescriptor = await indexDescriptorStore.get() else { + throw ContainerizationError(.notFound, message: "image for \(reference) not found") + } + + let description = Image.Description(reference: reference, descriptor: indexDescriptor) + let image = try await imageStore.create(description: description) + return KernelImage(image: image) + } +} diff --git a/Sources/Containerization/Interface.swift b/Sources/Containerization/Interface.swift new file mode 100644 index 00000000..b8e10c1b --- /dev/null +++ b/Sources/Containerization/Interface.swift @@ -0,0 +1,22 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +/// A network interface. +public protocol Interface: Sendable { + var address: String { get } + var gateway: String { get } + var macAddress: String? { get } +} diff --git a/Sources/Containerization/Kernel.swift b/Sources/Containerization/Kernel.swift new file mode 100644 index 00000000..183e7eb4 --- /dev/null +++ b/Sources/Containerization/Kernel.swift @@ -0,0 +1,93 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +/// A kernel used to boot a sandbox. +public struct Kernel: Sendable, Codable { + /// The command line arguments passed to the kernel on boot. + public struct CommandLine: Sendable, Codable { + public static let kernelDefaults = [ + "console=hvc0", + "tsc=reliable", + ] + + /// Adds the debug argument to the kernel commandline. + mutating public func addDebug() { + self.kernelArgs.append("debug") + } + + /// Adds a panic level to the kernel commandline. + mutating public func addPanic(level: Int) { + self.kernelArgs.append("panic=\(level)") + } + + /// Additional kernel arguments. + public var kernelArgs: [String] + /// Additional arguments passsed to the Initial Process / Agent. + public var initArgs: [String] + + /// Initializes the kernel commandline using the mix of kernel arguments + /// and init arguments. + public init( + kernelArgs: [String] = kernelDefaults, + initArgs: [String] = [] + ) { + self.kernelArgs = kernelArgs + self.initArgs = initArgs + } + + /// Initializes the kernel commandline to the defaults of Self.kernelDefaults, + /// adds a debug and panic flag as instructed, and optionally a set of init + /// process flags to supply to vminitd. + public init(debug: Bool, panic: Int, initArgs: [String] = []) { + var args = Self.kernelDefaults + if debug { + args.append("debug") + } + args.append("panic=\(panic)") + self.kernelArgs = args + self.initArgs = initArgs + } + } + + /// Path on disk to the kernel binary. + public var path: URL + /// Platform for the kernel. + public var platform: SystemPlatform + /// Kernel and init process command line. + public var commandLine: Self.CommandLine + + /// Kernel command line arguments. + public var kernelArgs: [String] { + self.commandLine.kernelArgs + } + + /// Init process arguments. + public var initArgs: [String] { + self.commandLine.initArgs + } + + public init( + path: URL, + platform: SystemPlatform, + commandline: Self.CommandLine = CommandLine(debug: false, panic: 0) + ) { + self.path = path + self.platform = platform + self.commandLine = commandline + } +} diff --git a/Sources/Containerization/LinuxContainer.swift b/Sources/Containerization/LinuxContainer.swift new file mode 100644 index 00000000..1ab0b92f --- /dev/null +++ b/Sources/Containerization/LinuxContainer.swift @@ -0,0 +1,786 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +#if os(macOS) +import ContainerizationError +import ContainerizationExtras +import ContainerizationOCI +import Foundation +import Logging +import SendableProperty + +import struct ContainerizationOS.Terminal + +/// `LinuxContainer` is an easy to use type for launching and managing the +/// full lifecycle of a Linux container ran inside of a virtual machine. +/// +/// NOTE: Editing the properties of `LinuxContainer` after calling `start()` +/// have no effect. +public final class LinuxContainer: Container, Sendable { + /// The default PATH value for a process. + public static let defaultPath = "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin" + + /// The identifier of the container. + public let id: String + + /// Rootfs for the container. + public let rootfs: Mount + + private struct Configuration { + var spec: Spec + var cpus: Int = 4 + var memoryInBytes: UInt64 = 1024.mib() + var interfaces: [any Interface] = [] + var sockets: [UnixSocketConfiguration] = [] + var gpu: Bool = false + var rosetta: Bool = false + var virtualization: Bool = false + var terminal: Terminal? = nil + var ioHandlers: LinuxProcess.IOHandler = .nullIO() + var mounts: [Mount] + var dns: DNS? = nil + } + + @SendableProperty + private var state: State + + @SendableProperty + private var config: Configuration + // Ports to be allocated from for stdio and for + // unix socket relays that are sharing a guest + // uds to the host. + private let hostVsockPorts: Atomic + // Ports we request the guest to allocate for unix socket relays from + // the host. + private let guestVsockPorts: Atomic + + private enum State: Sendable { + /// The container class has been created but no live resources are running. + case initialized + /// The container is creating and booting the underlying virtual resources. + case creating(CreatingState) + /// The container's virtual machine has been setup and the runtime environment has been configured. + case created(CreatedState) + /// The initial process of the container is preparing to start. + case starting(StartingState) + /// The initial process of the container has started and is running. + case started(StartedState) + /// The container is preparing to stop. + case stopping(StoppingState) + /// The container has ran and fully stopped. + case stopped + /// An error occured during the lifetime of this class. + case errored(Swift.Error) + + struct CreatingState: Sendable {} + + struct CreatedState: Sendable { + let vm: any VirtualMachineInstance + let relayManager: UnixSocketRelayManager + } + + struct StartingState: Sendable { + let vm: any VirtualMachineInstance + let relayManager: UnixSocketRelayManager + + init(_ state: CreatedState) { + self.vm = state.vm + self.relayManager = state.relayManager + } + } + + struct StartedState: Sendable { + let vm: any VirtualMachineInstance + let process: LinuxProcess + let relayManager: UnixSocketRelayManager + + init(_ state: StartingState, process: LinuxProcess) { + self.vm = state.vm + self.relayManager = state.relayManager + self.process = process + } + } + + struct StoppingState: Sendable { + let vm: any VirtualMachineInstance + + init(_ state: StartedState) { + self.vm = state.vm + } + } + + mutating func setCreating() throws { + switch self { + case .initialized: + self = .creating(.init()) + default: + throw ContainerizationError( + .invalidState, + message: "container must be in initialized state to start" + ) + } + } + + mutating func setCreated( + vm: any VirtualMachineInstance, + relayManager: UnixSocketRelayManager + ) throws { + switch self { + case .creating: + self = .created(.init(vm: vm, relayManager: relayManager)) + default: + throw ContainerizationError( + .invalidState, + message: "container must be in creating state before created" + ) + + } + } + + mutating func setStarting() throws -> any VirtualMachineInstance { + switch self { + case .created(let state): + self = .starting(.init(state)) + return state.vm + default: + throw ContainerizationError( + .invalidState, + message: "container must be in created state before starting" + ) + } + } + + mutating func setStarted(process: LinuxProcess) throws { + switch self { + case .starting(let state): + self = .started(.init(state, process: process)) + default: + throw ContainerizationError( + .invalidState, + message: "container must be in starting state before started" + ) + } + } + + mutating func stopping() throws -> StartedState { + switch self { + case .started(let state): + self = .stopping(.init(state)) + return state + default: + throw ContainerizationError( + .invalidState, + message: "container must be in a started state before stopping" + ) + } + } + + func startedState(_ operation: String) throws -> StartedState { + switch self { + case .started(let state): + return state + default: + throw ContainerizationError( + .invalidState, + message: "failed to \(operation): container must be running" + ) + } + } + + mutating func stopped() throws { + switch self { + case .stopping(_): + self = .stopped + default: + throw ContainerizationError( + .invalidState, + message: "container must be in a stopping state before setting to stopped" + ) + } + } + + mutating func errored(error: Swift.Error) { + self = .errored(error) + } + } + + private let vmm: VirtualMachineManager + private let logger: Logger? + + /// Create a new `LinuxContainer`. A `Mount` that contains the contents + /// of the container image must be provided, as well as a `VirtualMachineManager` + /// instance that will handle launching the virtual machine the container will + /// execute inside of. + public init( + _ id: String, + rootfs: Mount, + vmm: VirtualMachineManager, + logger: Logger? = nil + ) { + self.id = id + self.vmm = vmm + self.hostVsockPorts = Atomic(0x1000_0000) + self.guestVsockPorts = Atomic(0x1000_0000) + self.rootfs = rootfs + self.logger = logger + self.config = Configuration( + spec: Self.createDefaultRuntimeSpec(id), + mounts: Self.createDefaultMounts() + ) + self.state = .initialized + } + + private static func createDefaultRuntimeSpec(_ id: String) -> Spec { + .init( + process: .init( + cwd: "/", + env: ["PATH=\(Self.defaultPath)"] + ), + hostname: id, + root: .init( + path: Self.guestRootfsPath(id), + readonly: false + ), + linux: .init( + resources: .init() + ) + ) + } + + private static func guestRootfsPath(_ id: String) -> String { + "/run/container/\(id)/rootfs" + } + + private static func createDefaultMounts() -> [Mount] { + let defaultOptions = ["nosuid", "noexec", "nodev"] + return [ + .any(type: "proc", source: "proc", destination: "/proc", options: defaultOptions), + .any(type: "sysfs", source: "sysfs", destination: "/sys", options: defaultOptions), + .any(type: "devtmpfs", source: "none", destination: "/dev", options: ["nosuid", "mode=755"]), + .any(type: "mqueue", source: "mqueue", destination: "/dev/mqueue", options: defaultOptions), + .any(type: "tmpfs", source: "tmpfs", destination: "/dev/shm", options: defaultOptions + ["mode=1777", "size=65536k"]), + .any(type: "cgroup2", source: "none", destination: "/sys/fs/cgroup", options: defaultOptions), + .any(type: "devpts", source: "devpts", destination: "/dev/pts", options: ["nosuid", "noexec", "gid=5", "mode=620", "ptmxmode=666"]), + ] + } +} + +extension LinuxContainer { + package var root: String { + self.config.spec.root!.path + } + + /// Number of CPU cores allocated. + public var cpus: Int { + get { + config.cpus + } + set { + config.cpus = newValue + } + } + + /// Amount of memory in bytes allocated for the container. + /// This will be aligned to a 1MB boundary if it isn't already. + public var memoryInBytes: UInt64 { + get { + config.memoryInBytes + } + set { + config.memoryInBytes = newValue + } + } + + /// Network interfaces of the container. + public var interfaces: [any Interface] { + get { + config.interfaces + } + set { + config.interfaces = newValue + } + } + + /// DNS configuration for the container. + public var dns: DNS? { + get { config.dns } + set { config.dns = newValue } + } + + /// Unix sockets to share into or out of the container. + /// + /// The VirtualMachineAgent used to launch the container + /// MUST conform to `SocketRelayAgent` to support this, otherwise + /// a ContainerizationError will be returned on start with the code + /// set to `.unsupported`. + public var sockets: [UnixSocketConfiguration] { + get { + config.sockets + } + set { + config.sockets = newValue + } + } + + /// Enable/disable gpu accelaration in the container. + public var gpu: Bool { + get { + config.gpu + } + set { + config.gpu = newValue + } + } + + /// Enable/disable x86-64 emulation in the container. + public var rosetta: Bool { + get { + config.rosetta + } + set { + config.rosetta = newValue + } + } + + /// Enable/disable virtualization capabilities in the container. + public var virtualization: Bool { + get { + config.virtualization + } + set { + config.virtualization = newValue + } + } + + /// Filesystem mounts for the container. + public var mounts: [Mount] { + get { + config.mounts + } + set { + config.mounts = newValue + } + } + + /// Arguments passed to the container. + public var arguments: [String] { + get { + config.spec.process!.args + } + set { + config.spec.process!.args = newValue + } + } + + /// Environment variables for the container. + public var environment: [String] { + get { config.spec.process!.env } + set { config.spec.process!.env = newValue } + } + + /// The current working directory (cwd) for the container. + public var workingDirectory: String { + get { config.spec.process!.cwd } + set { config.spec.process!.cwd = newValue } + } + + /// The User the container should execute under. + public var user: ContainerizationOCI.User { + get { config.spec.process!.user } + set { config.spec.process!.user = newValue } + } + + /// Set the hostname for the container. + public var hostname: String { + get { config.spec.hostname } + set { config.spec.hostname = newValue } + } + + /// Set any sysctls for the container's environment. + public var sysctl: [String: String]? { + get { config.spec.linux!.sysctl } + set { config.spec.linux!.sysctl = newValue } + } + + /// Rlimits for the container. + public var rlimits: [POSIXRlimit] { + get { config.spec.process!.rlimits } + set { config.spec.process!.rlimits = newValue } + } +} + +extension LinuxContainer { + /// Set a pty device as the container's stdio. + public var terminalDevice: Terminal? { + get { config.terminal } + set { + config.spec.process!.terminal = newValue != nil ? true : false + config.terminal = newValue + config.ioHandlers.stdin = newValue + config.ioHandlers.stdout = newValue + config.ioHandlers.stderr = nil + } + } + + /// If the container has a pty allocated. + public var terminal: Bool { + get { config.spec.process!.terminal } + set { config.spec.process!.terminal = newValue } + } + + /// Set the stdin stream for the initial process of the container. + public var stdin: ReaderStream? { + get { + config.ioHandlers.stdin + } + set { + config.ioHandlers.stdin = newValue + } + } + + /// Set the stdout handler for the initial process of the container. + public var stdout: Writer? { + get { + config.ioHandlers.stdout + } + set { + config.ioHandlers.stdout = newValue + } + } + + /// Set the stderr handler for the initial process of the container. + public var stderr: Writer? { + get { + config.ioHandlers.stderr + } + set { + config.ioHandlers.stderr = newValue + } + } + + public func setProcessConfig(from imageConfig: ImageConfig) { + let process = ContainerizationOCI.Process(from: imageConfig) + self.config.spec.process = process + } +} + +extension LinuxContainer { + /// Create the underlying container's virtual machine + /// and setup the runtime environment. + public func create() async throws { + try state.setCreating() + + let vm = try vmm.create(container: self) + try await vm.start() + + let agent = try await vm.dialAgent() + do { + let relayManager = UnixSocketRelayManager(vm: vm) + + try await agent.standardSetup() + + // Mount the rootfs. + var rootfs = vm.mounts[0].to + rootfs.destination = Self.guestRootfsPath(self.id) + try await agent.mount(rootfs) + + // Start up our friendly unix socket relays. + for socket in self.sockets { + try await self.relayUnixSocket( + socket: socket, + relayManager: relayManager, + agent: agent + ) + } + + for (index, i) in self.interfaces.enumerated() { + let name = "eth\(index)" + try await agent.addressAdd(name: name, address: i.address) + try await agent.up(name: name) + try await agent.routeAddDefault(name: name, gateway: i.gateway) + } + if let dns = self.dns { + try await agent.configureDNS(config: dns, location: rootfs.destination) + } + + try state.setCreated(vm: vm, relayManager: relayManager) + } catch { + try? await agent.close() + try? await vm.stop() + + state.errored(error: error) + throw error + } + } + + /// Start the container container's initial process. + public func start() async throws { + let vm = try state.setStarting() + + let agent = try await vm.dialAgent() + do { + var specCopy = config.spec + // We don't need the rootfs, nor do OCI runtimes want it included. + specCopy.mounts = vm.mounts.dropFirst().map { $0.to } + + let stdio = Self.setupIO( + portAllocator: self.hostVsockPorts, + stdin: self.stdin, + stdout: self.stdout, + stderr: self.stderr + ) + + let process = LinuxProcess( + self.id, + containerID: self.id, + spec: specCopy, + io: stdio, + agent: agent, + vm: vm, + logger: self.logger + ) + try await process.start() + + try state.setStarted(process: process) + } catch { + try? await agent.close() + + state.errored(error: error) + throw error + } + } + + private static func setupIO( + portAllocator: borrowing Atomic, + stdin: ReaderStream?, + stdout: Writer?, + stderr: Writer? + ) -> LinuxProcess.Stdio { + var stdinSetup: LinuxProcess.StdioReaderSetup? = nil + if let reader = stdin { + let ret = portAllocator.wrappingAdd(1, ordering: .relaxed) + stdinSetup = .init( + port: ret.oldValue, + reader: reader + ) + } + + var stdoutSetup: LinuxProcess.StdioSetup? = nil + if let writer = stdout { + let ret = portAllocator.wrappingAdd(1, ordering: .relaxed) + stdoutSetup = LinuxProcess.StdioSetup( + port: ret.oldValue, + writer: writer + ) + } + + var stderrSetup: LinuxProcess.StdioSetup? = nil + if let writer = stderr { + let ret = portAllocator.wrappingAdd(1, ordering: .relaxed) + stderrSetup = LinuxProcess.StdioSetup( + port: ret.oldValue, + writer: writer + ) + } + + return LinuxProcess.Stdio( + stdin: stdinSetup, + stdout: stdoutSetup, + stderr: stderrSetup + ) + } +} + +extension LinuxContainer { + /// Stop the container from executing. + public func stop() async throws { + let startedState = try state.stopping() + + try await startedState.relayManager.stopAll() + + // It's possible the state of the vm is not in a great spot + // if the guest panicked or had any sort of bug/fault. + // First check if the vm is even still running, as trying to + // use a vsock handle like below here will cause NIO to + // fatalError because we'll get an EBADF. + if startedState.vm.state == .stopped { + try state.stopped() + return + } + + try await startedState.vm.withAgent { agent in + // First, we need to stop any unix socket relays as this will + // keep the rootfs from being able to umount (EBUSY). + let sockets = self.config.sockets + if !sockets.isEmpty { + guard let relayAgent = agent as? SocketRelayAgent else { + throw ContainerizationError( + .unsupported, + message: "VirtualMachineAgent does not support relaySocket surface" + ) + } + for socket in sockets { + try await relayAgent.stopSocketRelay(configuration: socket) + } + } + + // Now lets ensure every process is donezo. + try await agent.kill(pid: -1, signal: SIGKILL) + + // Wait on init proc exit. Give it 5 seconds of leeway. + _ = try await agent.waitProcess( + id: self.id, + containerID: self.id, + timeoutInSeconds: 5 + ) + + // Today, we leave EBUSY looping and other fun logic up to the + // guest agent. + try await agent.umount( + path: Self.guestRootfsPath(self.id), + flags: 0 + ) + } + + try await startedState.vm.stop() + try state.stopped() + } + + /// Send a signal to the container. + public func kill(_ signal: Int32) async throws { + let state = try self.state.startedState("kill") + try await state.process.kill(signal) + } + + /// Wait for the container to exit. Returns the exit code. + @discardableResult + public func wait(timeoutInSeconds: Int64? = nil) async throws -> Int32 { + let state = try self.state.startedState("wait") + return try await state.process.wait(timeoutInSeconds: timeoutInSeconds) + } + + /// Resize the container's terminal (if one was requested). This + /// will error if terminal was set to false before creating the container. + public func resize(to: Terminal.Size) async throws { + let state = try self.state.startedState("resize") + try await state.process.resize(to: to) + } +} + +extension LinuxContainer { + /// Execute a new process in the container. + public func exec( + _ id: String, + configuration: ContainerizationOCI.Process, + stdin: ReaderStream? = nil, + stdout: Writer? = nil, + stderr: Writer? = nil + ) async throws -> LinuxProcess { + let state = try self.state.startedState("exec") + + var specCopy = config.spec + specCopy.process = configuration + + let stdio = Self.setupIO( + portAllocator: self.hostVsockPorts, + stdin: stdin, + stdout: stdout, + stderr: stderr + ) + let agent = try await state.vm.dialAgent() + let process = LinuxProcess( + id, + containerID: self.id, + spec: specCopy, + io: stdio, + agent: agent, + vm: state.vm, + logger: self.logger + ) + return process + } + + /// Dial a vsock port in the container. + public func dialVsock(port: UInt32) async throws -> FileHandle { + let state = try self.state.startedState("dialVsock") + return try await state.vm.dial(port) + } + + /// Relay a unix socket from in the container to the host, or from the host + /// to inside the container. + public func relayUnixSocket(socket: UnixSocketConfiguration) async throws { + let state = try self.state.startedState("relayUnixSocket") + + let agent = try await state.vm.dialAgent() + try await self.relayUnixSocket( + socket: socket, + relayManager: state.relayManager, + agent: agent + ) + } + + private func relayUnixSocket( + socket: UnixSocketConfiguration, + relayManager: UnixSocketRelayManager, + agent: any VirtualMachineAgent + ) async throws { + guard let relayAgent = agent as? SocketRelayAgent else { + throw ContainerizationError( + .unsupported, + message: "VirtualMachineAgent does not support relaySocket surface" + ) + } + + var socket = socket + let rootInGuest = URL(filePath: self.root) + + if socket.direction == .into { + socket.to = rootInGuest.appending(path: socket.to.path) + } else { + socket.from = rootInGuest.appending(path: socket.from.path) + } + + let port = self.hostVsockPorts.wrappingAdd(1, ordering: .relaxed).oldValue + try await relayManager.start(port: port, socket: socket) + try await relayAgent.relaySocket(port: port, configuration: socket) + } +} + +extension VirtualMachineInstance { + fileprivate func withAgent(fn: @Sendable (VirtualMachineAgent) async throws -> Void) async throws { + let agent = try await self.dialAgent() + do { + try await fn(agent) + try await agent.close() + } catch { + try await agent.close() + throw error + } + } +} + +extension AttachedFilesystem { + fileprivate var to: ContainerizationOCI.Mount { + .init( + type: self.type, + source: self.source, + destination: self.destination, + options: self.options + ) + } +} + +#endif diff --git a/Sources/Containerization/LinuxProcess.swift b/Sources/Containerization/LinuxProcess.swift new file mode 100644 index 00000000..3ea40ee9 --- /dev/null +++ b/Sources/Containerization/LinuxProcess.swift @@ -0,0 +1,337 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationError +import ContainerizationExtras +import ContainerizationOCI +import ContainerizationOS +import Foundation +import Logging +import Synchronization + +/// `LinuxProcess` represents a Linux process and is used to +/// setup and control the full lifecycle for the process. +public final class LinuxProcess: Sendable { + /// `IOHandler` informs the process about what should be done + /// for the stdio streams. + public struct IOHandler: Sendable { + public var stdin: ReaderStream? + public var stdout: Writer? + public var stderr: Writer? + + public init(stdin: ReaderStream? = nil, stdout: Writer? = nil, stderr: Writer? = nil) { + self.stdin = stdin + self.stdout = stdout + self.stderr = stderr + } + + public static func nullIO() -> IOHandler { + .init() + } + } + + /// The ID of the process. This is purely metadata for the caller. + public let id: String + + /// What container owns this process (if any). + public let owningContainer: String? + + package struct StdioSetup: Sendable { + let port: UInt32 + let writer: Writer + } + + package struct StdioReaderSetup { + let port: UInt32 + let reader: ReaderStream + } + + package struct Stdio: Sendable { + let stdin: StdioReaderSetup? + let stdout: StdioSetup? + let stderr: StdioSetup? + } + + private struct StdioHandles: Sendable { + var stdin: FileHandle? + var stdout: FileHandle? + var stderr: FileHandle? + + func close() throws { + if let stdin { + try stdin.close() + } + if let stdout { + try stdout.close() + } + if let stderr { + try stderr.close() + } + } + } + + private struct State { + var spec: ContainerizationOCI.Spec + var pid: Int32 + var stdio: StdioHandles + var stdinRelay: Task<(), Never>? + } + + /// The process ID for the container process. This will be -1 + /// if the process has not been started. + public var pid: Int32 { + state.withLock { $0.pid } + } + + /// Arguments passed to the Process. + public var arguments: [String] { + get { + state.withLock { $0.spec.process!.args } + } + set { + state.withLock { $0.spec.process!.args = newValue } + } + } + + /// Environment variables for the Process. + public var environment: [String] { + get { state.withLock { $0.spec.process!.env } } + set { state.withLock { $0.spec.process!.env = newValue } } + } + + /// The current working directory (cwd) for the Process. + public var workingDirectory: String { + get { state.withLock { $0.spec.process!.cwd } } + set { state.withLock { $0.spec.process!.cwd = newValue } } + } + + /// A boolean value indicating if a Terminal or PTY device should + /// be attached to the Process's Standard I/O. + public var terminal: Bool { + get { state.withLock { $0.spec.process!.terminal } } + set { state.withLock { $0.spec.process!.terminal = newValue } } + } + + /// The User a Process should execute under. + public var user: ContainerizationOCI.User { + get { state.withLock { $0.spec.process!.user } } + set { state.withLock { $0.spec.process!.user = newValue } } + } + + /// Rlimits for the Process. + public var rlimits: [POSIXRlimit] { + get { state.withLock { $0.spec.process!.rlimits } } + set { state.withLock { $0.spec.process!.rlimits = newValue } } + } + + private let state: Mutex + private let ioSetup: Stdio + private let agent: any VirtualMachineAgent + private let vm: any VirtualMachineInstance + private let logger: Logger? + + init( + _ id: String, + containerID: String? = nil, + spec: Spec, + io: Stdio, + agent: any VirtualMachineAgent, + vm: any VirtualMachineInstance, + logger: Logger? + ) { + self.id = id + self.owningContainer = containerID + self.state = Mutex(.init(spec: spec, pid: -1, stdio: StdioHandles())) + self.ioSetup = io + self.agent = agent + self.vm = vm + self.logger = logger + } +} + +extension LinuxProcess { + func setupIO(streams: [ConnectionStream?]) async throws -> [FileHandle?] { + let handles = try await Timeout.run(seconds: 3) { + await withTaskGroup(of: (Int, FileHandle?).self) { group in + var results = [FileHandle?](repeating: nil, count: 3) + + for (index, stream) in streams.enumerated() { + guard let stream = stream else { continue } + + group.addTask { + let first = await stream.connections.first(where: { _ in true }) + return (index, first) + } + } + + for await (index, fileHandle) in group { + results[index] = fileHandle + } + return results + } + } + + if let stdin = self.ioSetup.stdin { + if let handle = handles[0] { + self.state.withLock { + $0.stdinRelay = Task { + for await data in stdin.reader.stream() { + do { + try handle.write(contentsOf: data) + } catch { + self.logger?.error("failed to write to stdin: \(error)") + } + } + } + } + } + } + + if let stdout = self.ioSetup.stdout { + handles[1]?.readabilityHandler = { handle in + // NOTE: We need some way to know when this data is done being piped, + // so DispatchGroup or similar. `availableData` is also pretty poor, + // as it always allocates. We can likely do the read loop ourselves + // with a buffer we allocate once on creation of the process. + do { + try stdout.writer.write(handle.availableData) + } catch { + self.logger?.error("failed to write to stdout: \(error)") + } + } + } + + if let stderr = self.ioSetup.stderr { + handles[2]?.readabilityHandler = { handle in + do { + try stderr.writer.write(handle.availableData) + } catch { + self.logger?.error("failed to write to stderr: \(error)") + } + } + } + + return handles + } + + /// Start the process. + public func start() async throws { + let spec = self.state.withLock { $0.spec } + + var streams = [ConnectionStream?](repeating: nil, count: 3) + if let stdin = self.ioSetup.stdin { + streams[0] = try self.vm.listen(stdin.port) + } + if let stdout = self.ioSetup.stdout { + streams[1] = try self.vm.listen(stdout.port) + } + if let stderr = self.ioSetup.stderr { + if spec.process!.terminal { + throw ContainerizationError( + .invalidArgument, + message: "stderr should not be configured with terminal=true" + ) + } + streams[2] = try self.vm.listen(stderr.port) + } + + let t = Task { + try await self.setupIO(streams: streams) + } + + try await agent.createProcess( + id: self.id, + containerID: self.owningContainer, + stdinPort: self.ioSetup.stdin?.port, + stdoutPort: self.ioSetup.stdout?.port, + stderrPort: self.ioSetup.stderr?.port, + configuration: spec, + options: nil + ) + + let result = try await t.value + let pid = try await self.agent.startProcess( + id: self.id, + containerID: self.owningContainer + ) + + self.state.withLock { + $0.stdio = StdioHandles( + stdin: result[0], + stdout: result[1], + stderr: result[2] + ) + $0.pid = pid + } + } + + /// Kill the process with the specified signal. + public func kill(_ signal: Int32) async throws { + try await agent.signalProcess( + id: self.id, + containerID: self.owningContainer, + signal: signal + ) + } + + /// Resize the processes pty (if requested). + public func resize(to: Terminal.Size) async throws { + try await agent.resizeProcess( + id: self.id, + containerID: self.owningContainer, + columns: UInt32(to.width), + rows: UInt32(to.height) + ) + } + + /// Wait on the process to exit with an optional timeout. Returns the exit code of the process. + @discardableResult + public func wait(timeoutInSeconds: Int64? = nil) async throws -> Int32 { + do { + return try await self.agent.waitProcess( + id: self.id, + containerID: self.owningContainer, + timeoutInSeconds: timeoutInSeconds + ) + } catch { + if error is ContainerizationError { + throw error + } + throw ContainerizationError( + .internalError, + message: "failed to wait on process", + cause: error + ) + } + } + + /// Cleans up guest state and waits on and closes any host resources (stdio handles). + public func delete() async throws { + try await self.agent.deleteProcess( + id: self.id, + containerID: self.owningContainer + ) + + // FIXME: Add in IO drain waiting here. We can wait for 2-3 seconds or + // so and then just continue on. + + // Now free up stdio handles. + try self.state.withLock { + $0.stdinRelay?.cancel() + try $0.stdio.close() + } + } +} diff --git a/Sources/Containerization/Mount.swift b/Sources/Containerization/Mount.swift new file mode 100644 index 00000000..5b628a4d --- /dev/null +++ b/Sources/Containerization/Mount.swift @@ -0,0 +1,228 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +#if os(macOS) +import Foundation +import Virtualization +import ContainerizationError +#endif + +/// A filesystem mount exposed to a container. +public struct Mount: Sendable { + /// The filesystem or mount type. This is the string + /// that will be used for the mount syscall itself. + public var type: String + /// The source path of the mount. + public var source: String + /// The destination path of the mount. + public var destination: String + /// Filesystem or mount specific options. + public var options: [String] + /// Runtime specific options. This can be used + /// as a way to discern what kind of device a vmm + /// should create for this specific mount (virtioblock + /// virtiofs etc.). + public let runtimeOptions: RuntimeOptions + + /// A type representing a "hint" of what type + /// of mount this really is (block, directory, purely + /// guest mount) and a set of type specific options, if any. + public enum RuntimeOptions: Sendable { + case virtioblk([String]) + case virtiofs([String]) + case any + } + + init( + type: String, + source: String, + destination: String, + options: [String], + runtimeOptions: RuntimeOptions + ) { + self.type = type + self.source = source + self.destination = destination + self.options = options + self.runtimeOptions = runtimeOptions + } + + /// Mount representing a virtio block device. + public static func block( + format: String, + source: String, + destination: String, + options: [String] = [], + runtimeOptions: [String] = [] + ) -> Self { + .init( + type: format, + source: source, + destination: destination, + options: options, + runtimeOptions: .virtioblk(runtimeOptions) + ) + } + + /// Mount representing a virtiofs share. + public static func share( + source: String, + destination: String, + options: [String] = [], + runtimeOptions: [String] = [] + ) -> Self { + .init( + type: "virtiofs", + source: source, + destination: destination, + options: options, + runtimeOptions: .virtiofs(runtimeOptions) + ) + } + + /// A generic mount. + public static func any( + type: String, + source: String, + destination: String, + options: [String] = [] + ) -> Self { + .init( + type: type, + source: source, + destination: destination, + options: options, + runtimeOptions: .any + ) + } + + #if os(macOS) + /// Clone the Mount to the provided path. + /// + /// This uses `clonefile` to provide a copy-on-write copy of the Mount. + public func clone(to: String) throws -> Self { + let fm = FileManager.default + let src = self.source + try fm.copyItem(atPath: src, toPath: to) + + return .init( + type: self.type, + source: to, + destination: self.destination, + options: self.options, + runtimeOptions: self.runtimeOptions + ) + } + #endif +} + +#if os(macOS) + +extension Mount { + func configure(config: inout VZVirtualMachineConfiguration) throws { + switch self.runtimeOptions { + case .virtioblk(let options): + let device = try VZDiskImageStorageDeviceAttachment.mountToVZAttachment(mount: self, options: options) + let attachment = VZVirtioBlockDeviceConfiguration(attachment: device) + config.storageDevices.append(attachment) + case .virtiofs(_): + guard FileManager.default.fileExists(atPath: self.source) else { + throw ContainerizationError(.notFound, message: "directory \(source) does not exist") + } + + let name = try hashMountSource(source: self.source) + let urlSource = URL(fileURLWithPath: source) + + let device = VZVirtioFileSystemDeviceConfiguration(tag: name) + device.share = VZSingleDirectoryShare( + directory: VZSharedDirectory( + url: urlSource, + readOnly: readonly + ) + ) + config.directorySharingDevices.append(device) + case .any: + break + } + } +} + +extension VZDiskImageStorageDeviceAttachment { + static func mountToVZAttachment(mount: Mount, options: [String]) throws -> VZDiskImageStorageDeviceAttachment { + var cachingMode: VZDiskImageCachingMode = .automatic + var synchronizationMode: VZDiskImageSynchronizationMode = .none + + for option in options { + let split = option.split(separator: "=") + if split.count != 2 { + continue + } + + let key = String(split[0]) + let value = String(split[1]) + + switch key { + case "vzDiskImageCachingMode": + switch value { + case "automatic": + cachingMode = .automatic + case "cached": + cachingMode = .cached + case "uncached": + cachingMode = .uncached + default: + throw ContainerizationError( + .invalidArgument, + message: "unknown vzDiskImageCachingMode value for virtio block device: \(value)" + ) + } + case "vzDiskImageSynchronizationMode": + switch value { + case "full": + synchronizationMode = .full + case "fsync": + synchronizationMode = .fsync + case "none": + synchronizationMode = .none + default: + throw ContainerizationError( + .invalidArgument, + message: "unknown vzDiskImageSynchronizationMode value for virtio block device: \(value)" + ) + } + default: + throw ContainerizationError( + .invalidArgument, + message: "unknown vmm option encountered: \(key)" + ) + } + } + return try VZDiskImageStorageDeviceAttachment( + url: URL(filePath: mount.source), + readOnly: mount.readonly, + cachingMode: cachingMode, + synchronizationMode: synchronizationMode + ) + } +} + +#endif + +extension Mount { + fileprivate var readonly: Bool { + self.options.contains("ro") + } +} diff --git a/Sources/Containerization/NATInterface.swift b/Sources/Containerization/NATInterface.swift new file mode 100644 index 00000000..fccddbf0 --- /dev/null +++ b/Sources/Containerization/NATInterface.swift @@ -0,0 +1,27 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +public struct NATInterface: Interface { + public var address: String + public var gateway: String + public var macAddress: String? + + public init(address: String, gateway: String, macAddress: String? = nil) { + self.address = address + self.gateway = gateway + self.macAddress = macAddress + } +} diff --git a/Sources/Containerization/NATNetworkInterface.swift b/Sources/Containerization/NATNetworkInterface.swift new file mode 100644 index 00000000..e07d6236 --- /dev/null +++ b/Sources/Containerization/NATNetworkInterface.swift @@ -0,0 +1,112 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +#if os(macOS) + +import vmnet +import Virtualization +import ContainerizationError +import Foundation +import Synchronization + +@available(macOS 16, *) +public final class NATNetworkInterface: Interface, Sendable { + public var address: String { + get { state.withLock { $0.address } } + set { state.withLock { $0.address = newValue } } + + } + + public var gateway: String { + get { state.withLock { $0.gateway } } + set { state.withLock { $0.gateway = newValue } } + } + + public var macAddress: String? { + get { state.withLock { $0.macAddress } } + set { state.withLock { $0.macAddress = newValue } } + } + + struct State { + var address: String + var gateway: String + var macAddress: String? + #if !CURRENT_SDK + var reference: vmnet_network_ref + #endif + } + + #if !CURRENT_SDK + public var reference: vmnet_network_ref { + state.withLock { $0.reference } + } + #endif + + private let state: Mutex + #if !CURRENT_SDK + public init( + address: String, + gateway: String, + reference: sending vmnet_network_ref, + macAddress: String? = nil + ) { + self.state = .init( + .init( + address: address, + gateway: gateway, + macAddress: macAddress, + reference: reference + ) + ) + } + #else + public init( + address: String, + gateway: String, + macAddress: String? = nil + ) { + self.state = .init( + .init( + address: address, + gateway: gateway, + macAddress: macAddress + ) + ) + } + #endif +} + +@available(macOS 16, *) +extension NATNetworkInterface: VZInterface { + public func device() throws -> VZVirtioNetworkDeviceConfiguration { + let config = VZVirtioNetworkDeviceConfiguration() + if let macAddress = self.macAddress { + guard let mac = VZMACAddress(string: macAddress) else { + throw ContainerizationError(.invalidArgument, message: "invalid mac address \(macAddress)") + } + config.macAddress = mac + } + + #if !CURRENT_SDK + config.attachment = VZVmnetNetworkDeviceAttachment(network: self.reference) + #else + config.attachment = VZNATNetworkDeviceAttachment() + #endif + return config + } +} + +#endif diff --git a/Sources/Containerization/SandboxContext/SandboxContext.grpc.swift b/Sources/Containerization/SandboxContext/SandboxContext.grpc.swift new file mode 100644 index 00000000..2693b25a --- /dev/null +++ b/Sources/Containerization/SandboxContext/SandboxContext.grpc.swift @@ -0,0 +1,2527 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// +// DO NOT EDIT. +// swift-format-ignore-file +// +// Generated by the protocol buffer compiler. +// Source: SandboxContext.proto +// +import GRPC +import NIO +import NIOConcurrencyHelpers +import SwiftProtobuf + + +/// Context for interacting with a container's runtime environment. +/// +/// Usage: instantiate `Com_Apple_Containerization_Sandbox_V3_SandboxContextClient`, then call methods of this protocol to make API calls. +public protocol Com_Apple_Containerization_Sandbox_V3_SandboxContextClientProtocol: GRPCClient { + var serviceName: String { get } + var interceptors: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientInterceptorFactoryProtocol? { get } + + func mount( + _ request: Com_Apple_Containerization_Sandbox_V3_MountRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func umount( + _ request: Com_Apple_Containerization_Sandbox_V3_UmountRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func setenv( + _ request: Com_Apple_Containerization_Sandbox_V3_SetenvRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func getenv( + _ request: Com_Apple_Containerization_Sandbox_V3_GetenvRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func mkdir( + _ request: Com_Apple_Containerization_Sandbox_V3_MkdirRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func sysctl( + _ request: Com_Apple_Containerization_Sandbox_V3_SysctlRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func setTime( + _ request: Com_Apple_Containerization_Sandbox_V3_SetTimeRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func setupEmulator( + _ request: Com_Apple_Containerization_Sandbox_V3_SetupEmulatorRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func createProcess( + _ request: Com_Apple_Containerization_Sandbox_V3_CreateProcessRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func deleteProcess( + _ request: Com_Apple_Containerization_Sandbox_V3_DeleteProcessRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func startProcess( + _ request: Com_Apple_Containerization_Sandbox_V3_StartProcessRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func killProcess( + _ request: Com_Apple_Containerization_Sandbox_V3_KillProcessRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func waitProcess( + _ request: Com_Apple_Containerization_Sandbox_V3_WaitProcessRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func resizeProcess( + _ request: Com_Apple_Containerization_Sandbox_V3_ResizeProcessRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func proxyVsock( + _ request: Com_Apple_Containerization_Sandbox_V3_ProxyVsockRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func stopVsockProxy( + _ request: Com_Apple_Containerization_Sandbox_V3_StopVsockProxyRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func ipLinkSet( + _ request: Com_Apple_Containerization_Sandbox_V3_IpLinkSetRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func ipAddrAdd( + _ request: Com_Apple_Containerization_Sandbox_V3_IpAddrAddRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func ipRouteAddLink( + _ request: Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func ipRouteAddDefault( + _ request: Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func configureDns( + _ request: Com_Apple_Containerization_Sandbox_V3_ConfigureDnsRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func sync( + _ request: Com_Apple_Containerization_Sandbox_V3_SyncRequest, + callOptions: CallOptions? + ) -> UnaryCall + + func kill( + _ request: Com_Apple_Containerization_Sandbox_V3_KillRequest, + callOptions: CallOptions? + ) -> UnaryCall +} + +extension Com_Apple_Containerization_Sandbox_V3_SandboxContextClientProtocol { + public var serviceName: String { + return "com.apple.containerization.sandbox.v3.SandboxContext" + } + + /// Mount a filesystem. + /// + /// - Parameters: + /// - request: Request to send to Mount. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func mount( + _ request: Com_Apple_Containerization_Sandbox_V3_MountRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.mount.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeMountInterceptors() ?? [] + ) + } + + /// Unmount a filesystem. + /// + /// - Parameters: + /// - request: Request to send to Umount. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func umount( + _ request: Com_Apple_Containerization_Sandbox_V3_UmountRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.umount.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeUmountInterceptors() ?? [] + ) + } + + /// Set an environment variable on the init process. + /// + /// - Parameters: + /// - request: Request to send to Setenv. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func setenv( + _ request: Com_Apple_Containerization_Sandbox_V3_SetenvRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.setenv.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeSetenvInterceptors() ?? [] + ) + } + + /// Get an environment variable from the init process. + /// + /// - Parameters: + /// - request: Request to send to Getenv. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func getenv( + _ request: Com_Apple_Containerization_Sandbox_V3_GetenvRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.getenv.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeGetenvInterceptors() ?? [] + ) + } + + /// Create a new directory inside the sandbox. + /// + /// - Parameters: + /// - request: Request to send to Mkdir. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func mkdir( + _ request: Com_Apple_Containerization_Sandbox_V3_MkdirRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.mkdir.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeMkdirInterceptors() ?? [] + ) + } + + /// Set sysctls in the context of the sandbox. + /// + /// - Parameters: + /// - request: Request to send to Sysctl. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func sysctl( + _ request: Com_Apple_Containerization_Sandbox_V3_SysctlRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.sysctl.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeSysctlInterceptors() ?? [] + ) + } + + /// Set time in the guest. + /// + /// - Parameters: + /// - request: Request to send to SetTime. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func setTime( + _ request: Com_Apple_Containerization_Sandbox_V3_SetTimeRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.setTime.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeSetTimeInterceptors() ?? [] + ) + } + + /// Set up an emulator in the guest for a specific binary format. + /// + /// - Parameters: + /// - request: Request to send to SetupEmulator. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func setupEmulator( + _ request: Com_Apple_Containerization_Sandbox_V3_SetupEmulatorRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.setupEmulator.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeSetupEmulatorInterceptors() ?? [] + ) + } + + /// Create a new process inside the container. + /// + /// - Parameters: + /// - request: Request to send to CreateProcess. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func createProcess( + _ request: Com_Apple_Containerization_Sandbox_V3_CreateProcessRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.createProcess.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeCreateProcessInterceptors() ?? [] + ) + } + + /// Delete an existing process inside the container. + /// + /// - Parameters: + /// - request: Request to send to DeleteProcess. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func deleteProcess( + _ request: Com_Apple_Containerization_Sandbox_V3_DeleteProcessRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.deleteProcess.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeDeleteProcessInterceptors() ?? [] + ) + } + + /// Start the provided process. + /// + /// - Parameters: + /// - request: Request to send to StartProcess. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func startProcess( + _ request: Com_Apple_Containerization_Sandbox_V3_StartProcessRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.startProcess.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeStartProcessInterceptors() ?? [] + ) + } + + /// Send a signal to the provided process. + /// + /// - Parameters: + /// - request: Request to send to KillProcess. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func killProcess( + _ request: Com_Apple_Containerization_Sandbox_V3_KillProcessRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.killProcess.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeKillProcessInterceptors() ?? [] + ) + } + + /// Wait for a process to exit and return the exit code. + /// + /// - Parameters: + /// - request: Request to send to WaitProcess. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func waitProcess( + _ request: Com_Apple_Containerization_Sandbox_V3_WaitProcessRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.waitProcess.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeWaitProcessInterceptors() ?? [] + ) + } + + /// Resize the tty of a given process. This will error if the process does + /// not have a pty allocated. + /// + /// - Parameters: + /// - request: Request to send to ResizeProcess. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func resizeProcess( + _ request: Com_Apple_Containerization_Sandbox_V3_ResizeProcessRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.resizeProcess.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeResizeProcessInterceptors() ?? [] + ) + } + + /// Proxy a vsock port to a unix domain socket in the guest, or vice versa. + /// + /// - Parameters: + /// - request: Request to send to ProxyVsock. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func proxyVsock( + _ request: Com_Apple_Containerization_Sandbox_V3_ProxyVsockRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.proxyVsock.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeProxyVsockInterceptors() ?? [] + ) + } + + /// Stop a vsock proxy to a unix domain socket. + /// + /// - Parameters: + /// - request: Request to send to StopVsockProxy. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func stopVsockProxy( + _ request: Com_Apple_Containerization_Sandbox_V3_StopVsockProxyRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.stopVsockProxy.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeStopVsockProxyInterceptors() ?? [] + ) + } + + /// Set the link state of a network interface. + /// + /// - Parameters: + /// - request: Request to send to IpLinkSet. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func ipLinkSet( + _ request: Com_Apple_Containerization_Sandbox_V3_IpLinkSetRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.ipLinkSet.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeIpLinkSetInterceptors() ?? [] + ) + } + + /// Add an IPv4 address to a network interface. + /// + /// - Parameters: + /// - request: Request to send to IpAddrAdd. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func ipAddrAdd( + _ request: Com_Apple_Containerization_Sandbox_V3_IpAddrAddRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.ipAddrAdd.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeIpAddrAddInterceptors() ?? [] + ) + } + + /// Add an IP route for a network interface. + /// + /// - Parameters: + /// - request: Request to send to IpRouteAddLink. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func ipRouteAddLink( + _ request: Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.ipRouteAddLink.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeIpRouteAddLinkInterceptors() ?? [] + ) + } + + /// Add an IP route for a network interface. + /// + /// - Parameters: + /// - request: Request to send to IpRouteAddDefault. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func ipRouteAddDefault( + _ request: Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.ipRouteAddDefault.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeIpRouteAddDefaultInterceptors() ?? [] + ) + } + + /// Configure DNS resolver. + /// + /// - Parameters: + /// - request: Request to send to ConfigureDns. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func configureDns( + _ request: Com_Apple_Containerization_Sandbox_V3_ConfigureDnsRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.configureDns.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeConfigureDnsInterceptors() ?? [] + ) + } + + /// Perform the sync syscall. + /// + /// - Parameters: + /// - request: Request to send to Sync. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func sync( + _ request: Com_Apple_Containerization_Sandbox_V3_SyncRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.sync.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeSyncInterceptors() ?? [] + ) + } + + /// Send a signal to a process via the PID. + /// + /// - Parameters: + /// - request: Request to send to Kill. + /// - callOptions: Call options. + /// - Returns: A `UnaryCall` with futures for the metadata, status and response. + public func kill( + _ request: Com_Apple_Containerization_Sandbox_V3_KillRequest, + callOptions: CallOptions? = nil + ) -> UnaryCall { + return self.makeUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.kill.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeKillInterceptors() ?? [] + ) + } +} + +@available(*, deprecated) +extension Com_Apple_Containerization_Sandbox_V3_SandboxContextClient: @unchecked Sendable {} + +@available(*, deprecated, renamed: "Com_Apple_Containerization_Sandbox_V3_SandboxContextNIOClient") +public final class Com_Apple_Containerization_Sandbox_V3_SandboxContextClient: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientProtocol { + private let lock = Lock() + private var _defaultCallOptions: CallOptions + private var _interceptors: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientInterceptorFactoryProtocol? + public let channel: GRPCChannel + public var defaultCallOptions: CallOptions { + get { self.lock.withLock { return self._defaultCallOptions } } + set { self.lock.withLockVoid { self._defaultCallOptions = newValue } } + } + public var interceptors: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientInterceptorFactoryProtocol? { + get { self.lock.withLock { return self._interceptors } } + set { self.lock.withLockVoid { self._interceptors = newValue } } + } + + /// Creates a client for the com.apple.containerization.sandbox.v3.SandboxContext service. + /// + /// - Parameters: + /// - channel: `GRPCChannel` to the service host. + /// - defaultCallOptions: Options to use for each service call if the user doesn't provide them. + /// - interceptors: A factory providing interceptors for each RPC. + public init( + channel: GRPCChannel, + defaultCallOptions: CallOptions = CallOptions(), + interceptors: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientInterceptorFactoryProtocol? = nil + ) { + self.channel = channel + self._defaultCallOptions = defaultCallOptions + self._interceptors = interceptors + } +} + +public struct Com_Apple_Containerization_Sandbox_V3_SandboxContextNIOClient: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientProtocol { + public var channel: GRPCChannel + public var defaultCallOptions: CallOptions + public var interceptors: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientInterceptorFactoryProtocol? + + /// Creates a client for the com.apple.containerization.sandbox.v3.SandboxContext service. + /// + /// - Parameters: + /// - channel: `GRPCChannel` to the service host. + /// - defaultCallOptions: Options to use for each service call if the user doesn't provide them. + /// - interceptors: A factory providing interceptors for each RPC. + public init( + channel: GRPCChannel, + defaultCallOptions: CallOptions = CallOptions(), + interceptors: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientInterceptorFactoryProtocol? = nil + ) { + self.channel = channel + self.defaultCallOptions = defaultCallOptions + self.interceptors = interceptors + } +} + +/// Context for interacting with a container's runtime environment. +@available(macOS 10.15, iOS 13, tvOS 13, watchOS 6, *) +public protocol Com_Apple_Containerization_Sandbox_V3_SandboxContextAsyncClientProtocol: GRPCClient { + static var serviceDescriptor: GRPCServiceDescriptor { get } + var interceptors: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientInterceptorFactoryProtocol? { get } + + func makeMountCall( + _ request: Com_Apple_Containerization_Sandbox_V3_MountRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeUmountCall( + _ request: Com_Apple_Containerization_Sandbox_V3_UmountRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeSetenvCall( + _ request: Com_Apple_Containerization_Sandbox_V3_SetenvRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeGetenvCall( + _ request: Com_Apple_Containerization_Sandbox_V3_GetenvRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeMkdirCall( + _ request: Com_Apple_Containerization_Sandbox_V3_MkdirRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeSysctlCall( + _ request: Com_Apple_Containerization_Sandbox_V3_SysctlRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeSetTimeCall( + _ request: Com_Apple_Containerization_Sandbox_V3_SetTimeRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeSetupEmulatorCall( + _ request: Com_Apple_Containerization_Sandbox_V3_SetupEmulatorRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeCreateProcessCall( + _ request: Com_Apple_Containerization_Sandbox_V3_CreateProcessRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeDeleteProcessCall( + _ request: Com_Apple_Containerization_Sandbox_V3_DeleteProcessRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeStartProcessCall( + _ request: Com_Apple_Containerization_Sandbox_V3_StartProcessRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeKillProcessCall( + _ request: Com_Apple_Containerization_Sandbox_V3_KillProcessRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeWaitProcessCall( + _ request: Com_Apple_Containerization_Sandbox_V3_WaitProcessRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeResizeProcessCall( + _ request: Com_Apple_Containerization_Sandbox_V3_ResizeProcessRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeProxyVsockCall( + _ request: Com_Apple_Containerization_Sandbox_V3_ProxyVsockRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeStopVsockProxyCall( + _ request: Com_Apple_Containerization_Sandbox_V3_StopVsockProxyRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeIpLinkSetCall( + _ request: Com_Apple_Containerization_Sandbox_V3_IpLinkSetRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeIpAddrAddCall( + _ request: Com_Apple_Containerization_Sandbox_V3_IpAddrAddRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeIpRouteAddLinkCall( + _ request: Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeIpRouteAddDefaultCall( + _ request: Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeConfigureDnsCall( + _ request: Com_Apple_Containerization_Sandbox_V3_ConfigureDnsRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeSyncCall( + _ request: Com_Apple_Containerization_Sandbox_V3_SyncRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall + + func makeKillCall( + _ request: Com_Apple_Containerization_Sandbox_V3_KillRequest, + callOptions: CallOptions? + ) -> GRPCAsyncUnaryCall +} + +@available(macOS 10.15, iOS 13, tvOS 13, watchOS 6, *) +extension Com_Apple_Containerization_Sandbox_V3_SandboxContextAsyncClientProtocol { + public static var serviceDescriptor: GRPCServiceDescriptor { + return Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.serviceDescriptor + } + + public var interceptors: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientInterceptorFactoryProtocol? { + return nil + } + + public func makeMountCall( + _ request: Com_Apple_Containerization_Sandbox_V3_MountRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.mount.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeMountInterceptors() ?? [] + ) + } + + public func makeUmountCall( + _ request: Com_Apple_Containerization_Sandbox_V3_UmountRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.umount.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeUmountInterceptors() ?? [] + ) + } + + public func makeSetenvCall( + _ request: Com_Apple_Containerization_Sandbox_V3_SetenvRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.setenv.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeSetenvInterceptors() ?? [] + ) + } + + public func makeGetenvCall( + _ request: Com_Apple_Containerization_Sandbox_V3_GetenvRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.getenv.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeGetenvInterceptors() ?? [] + ) + } + + public func makeMkdirCall( + _ request: Com_Apple_Containerization_Sandbox_V3_MkdirRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.mkdir.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeMkdirInterceptors() ?? [] + ) + } + + public func makeSysctlCall( + _ request: Com_Apple_Containerization_Sandbox_V3_SysctlRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.sysctl.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeSysctlInterceptors() ?? [] + ) + } + + public func makeSetTimeCall( + _ request: Com_Apple_Containerization_Sandbox_V3_SetTimeRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.setTime.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeSetTimeInterceptors() ?? [] + ) + } + + public func makeSetupEmulatorCall( + _ request: Com_Apple_Containerization_Sandbox_V3_SetupEmulatorRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.setupEmulator.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeSetupEmulatorInterceptors() ?? [] + ) + } + + public func makeCreateProcessCall( + _ request: Com_Apple_Containerization_Sandbox_V3_CreateProcessRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.createProcess.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeCreateProcessInterceptors() ?? [] + ) + } + + public func makeDeleteProcessCall( + _ request: Com_Apple_Containerization_Sandbox_V3_DeleteProcessRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.deleteProcess.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeDeleteProcessInterceptors() ?? [] + ) + } + + public func makeStartProcessCall( + _ request: Com_Apple_Containerization_Sandbox_V3_StartProcessRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.startProcess.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeStartProcessInterceptors() ?? [] + ) + } + + public func makeKillProcessCall( + _ request: Com_Apple_Containerization_Sandbox_V3_KillProcessRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.killProcess.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeKillProcessInterceptors() ?? [] + ) + } + + public func makeWaitProcessCall( + _ request: Com_Apple_Containerization_Sandbox_V3_WaitProcessRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.waitProcess.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeWaitProcessInterceptors() ?? [] + ) + } + + public func makeResizeProcessCall( + _ request: Com_Apple_Containerization_Sandbox_V3_ResizeProcessRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.resizeProcess.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeResizeProcessInterceptors() ?? [] + ) + } + + public func makeProxyVsockCall( + _ request: Com_Apple_Containerization_Sandbox_V3_ProxyVsockRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.proxyVsock.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeProxyVsockInterceptors() ?? [] + ) + } + + public func makeStopVsockProxyCall( + _ request: Com_Apple_Containerization_Sandbox_V3_StopVsockProxyRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.stopVsockProxy.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeStopVsockProxyInterceptors() ?? [] + ) + } + + public func makeIpLinkSetCall( + _ request: Com_Apple_Containerization_Sandbox_V3_IpLinkSetRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.ipLinkSet.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeIpLinkSetInterceptors() ?? [] + ) + } + + public func makeIpAddrAddCall( + _ request: Com_Apple_Containerization_Sandbox_V3_IpAddrAddRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.ipAddrAdd.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeIpAddrAddInterceptors() ?? [] + ) + } + + public func makeIpRouteAddLinkCall( + _ request: Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.ipRouteAddLink.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeIpRouteAddLinkInterceptors() ?? [] + ) + } + + public func makeIpRouteAddDefaultCall( + _ request: Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.ipRouteAddDefault.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeIpRouteAddDefaultInterceptors() ?? [] + ) + } + + public func makeConfigureDnsCall( + _ request: Com_Apple_Containerization_Sandbox_V3_ConfigureDnsRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.configureDns.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeConfigureDnsInterceptors() ?? [] + ) + } + + public func makeSyncCall( + _ request: Com_Apple_Containerization_Sandbox_V3_SyncRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.sync.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeSyncInterceptors() ?? [] + ) + } + + public func makeKillCall( + _ request: Com_Apple_Containerization_Sandbox_V3_KillRequest, + callOptions: CallOptions? = nil + ) -> GRPCAsyncUnaryCall { + return self.makeAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.kill.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeKillInterceptors() ?? [] + ) + } +} + +@available(macOS 10.15, iOS 13, tvOS 13, watchOS 6, *) +extension Com_Apple_Containerization_Sandbox_V3_SandboxContextAsyncClientProtocol { + public func mount( + _ request: Com_Apple_Containerization_Sandbox_V3_MountRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_MountResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.mount.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeMountInterceptors() ?? [] + ) + } + + public func umount( + _ request: Com_Apple_Containerization_Sandbox_V3_UmountRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_UmountResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.umount.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeUmountInterceptors() ?? [] + ) + } + + public func setenv( + _ request: Com_Apple_Containerization_Sandbox_V3_SetenvRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_SetenvResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.setenv.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeSetenvInterceptors() ?? [] + ) + } + + public func getenv( + _ request: Com_Apple_Containerization_Sandbox_V3_GetenvRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_GetenvResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.getenv.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeGetenvInterceptors() ?? [] + ) + } + + public func mkdir( + _ request: Com_Apple_Containerization_Sandbox_V3_MkdirRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_MkdirResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.mkdir.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeMkdirInterceptors() ?? [] + ) + } + + public func sysctl( + _ request: Com_Apple_Containerization_Sandbox_V3_SysctlRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_SysctlResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.sysctl.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeSysctlInterceptors() ?? [] + ) + } + + public func setTime( + _ request: Com_Apple_Containerization_Sandbox_V3_SetTimeRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_SetTimeResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.setTime.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeSetTimeInterceptors() ?? [] + ) + } + + public func setupEmulator( + _ request: Com_Apple_Containerization_Sandbox_V3_SetupEmulatorRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_SetupEmulatorResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.setupEmulator.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeSetupEmulatorInterceptors() ?? [] + ) + } + + public func createProcess( + _ request: Com_Apple_Containerization_Sandbox_V3_CreateProcessRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_CreateProcessResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.createProcess.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeCreateProcessInterceptors() ?? [] + ) + } + + public func deleteProcess( + _ request: Com_Apple_Containerization_Sandbox_V3_DeleteProcessRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_DeleteProcessResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.deleteProcess.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeDeleteProcessInterceptors() ?? [] + ) + } + + public func startProcess( + _ request: Com_Apple_Containerization_Sandbox_V3_StartProcessRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_StartProcessResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.startProcess.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeStartProcessInterceptors() ?? [] + ) + } + + public func killProcess( + _ request: Com_Apple_Containerization_Sandbox_V3_KillProcessRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_KillProcessResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.killProcess.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeKillProcessInterceptors() ?? [] + ) + } + + public func waitProcess( + _ request: Com_Apple_Containerization_Sandbox_V3_WaitProcessRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_WaitProcessResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.waitProcess.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeWaitProcessInterceptors() ?? [] + ) + } + + public func resizeProcess( + _ request: Com_Apple_Containerization_Sandbox_V3_ResizeProcessRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_ResizeProcessResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.resizeProcess.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeResizeProcessInterceptors() ?? [] + ) + } + + public func proxyVsock( + _ request: Com_Apple_Containerization_Sandbox_V3_ProxyVsockRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_ProxyVsockResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.proxyVsock.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeProxyVsockInterceptors() ?? [] + ) + } + + public func stopVsockProxy( + _ request: Com_Apple_Containerization_Sandbox_V3_StopVsockProxyRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_StopVsockProxyResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.stopVsockProxy.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeStopVsockProxyInterceptors() ?? [] + ) + } + + public func ipLinkSet( + _ request: Com_Apple_Containerization_Sandbox_V3_IpLinkSetRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_IpLinkSetResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.ipLinkSet.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeIpLinkSetInterceptors() ?? [] + ) + } + + public func ipAddrAdd( + _ request: Com_Apple_Containerization_Sandbox_V3_IpAddrAddRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_IpAddrAddResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.ipAddrAdd.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeIpAddrAddInterceptors() ?? [] + ) + } + + public func ipRouteAddLink( + _ request: Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.ipRouteAddLink.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeIpRouteAddLinkInterceptors() ?? [] + ) + } + + public func ipRouteAddDefault( + _ request: Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.ipRouteAddDefault.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeIpRouteAddDefaultInterceptors() ?? [] + ) + } + + public func configureDns( + _ request: Com_Apple_Containerization_Sandbox_V3_ConfigureDnsRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_ConfigureDnsResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.configureDns.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeConfigureDnsInterceptors() ?? [] + ) + } + + public func sync( + _ request: Com_Apple_Containerization_Sandbox_V3_SyncRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_SyncResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.sync.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeSyncInterceptors() ?? [] + ) + } + + public func kill( + _ request: Com_Apple_Containerization_Sandbox_V3_KillRequest, + callOptions: CallOptions? = nil + ) async throws -> Com_Apple_Containerization_Sandbox_V3_KillResponse { + return try await self.performAsyncUnaryCall( + path: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.kill.path, + request: request, + callOptions: callOptions ?? self.defaultCallOptions, + interceptors: self.interceptors?.makeKillInterceptors() ?? [] + ) + } +} + +@available(macOS 10.15, iOS 13, tvOS 13, watchOS 6, *) +public struct Com_Apple_Containerization_Sandbox_V3_SandboxContextAsyncClient: Com_Apple_Containerization_Sandbox_V3_SandboxContextAsyncClientProtocol { + public var channel: GRPCChannel + public var defaultCallOptions: CallOptions + public var interceptors: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientInterceptorFactoryProtocol? + + public init( + channel: GRPCChannel, + defaultCallOptions: CallOptions = CallOptions(), + interceptors: Com_Apple_Containerization_Sandbox_V3_SandboxContextClientInterceptorFactoryProtocol? = nil + ) { + self.channel = channel + self.defaultCallOptions = defaultCallOptions + self.interceptors = interceptors + } +} + +public protocol Com_Apple_Containerization_Sandbox_V3_SandboxContextClientInterceptorFactoryProtocol: Sendable { + + /// - Returns: Interceptors to use when invoking 'mount'. + func makeMountInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'umount'. + func makeUmountInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'setenv'. + func makeSetenvInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'getenv'. + func makeGetenvInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'mkdir'. + func makeMkdirInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'sysctl'. + func makeSysctlInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'setTime'. + func makeSetTimeInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'setupEmulator'. + func makeSetupEmulatorInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'createProcess'. + func makeCreateProcessInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'deleteProcess'. + func makeDeleteProcessInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'startProcess'. + func makeStartProcessInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'killProcess'. + func makeKillProcessInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'waitProcess'. + func makeWaitProcessInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'resizeProcess'. + func makeResizeProcessInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'proxyVsock'. + func makeProxyVsockInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'stopVsockProxy'. + func makeStopVsockProxyInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'ipLinkSet'. + func makeIpLinkSetInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'ipAddrAdd'. + func makeIpAddrAddInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'ipRouteAddLink'. + func makeIpRouteAddLinkInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'ipRouteAddDefault'. + func makeIpRouteAddDefaultInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'configureDns'. + func makeConfigureDnsInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'sync'. + func makeSyncInterceptors() -> [ClientInterceptor] + + /// - Returns: Interceptors to use when invoking 'kill'. + func makeKillInterceptors() -> [ClientInterceptor] +} + +public enum Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata { + public static let serviceDescriptor = GRPCServiceDescriptor( + name: "SandboxContext", + fullName: "com.apple.containerization.sandbox.v3.SandboxContext", + methods: [ + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.mount, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.umount, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.setenv, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.getenv, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.mkdir, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.sysctl, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.setTime, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.setupEmulator, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.createProcess, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.deleteProcess, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.startProcess, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.killProcess, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.waitProcess, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.resizeProcess, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.proxyVsock, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.stopVsockProxy, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.ipLinkSet, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.ipAddrAdd, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.ipRouteAddLink, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.ipRouteAddDefault, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.configureDns, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.sync, + Com_Apple_Containerization_Sandbox_V3_SandboxContextClientMetadata.Methods.kill, + ] + ) + + public enum Methods { + public static let mount = GRPCMethodDescriptor( + name: "Mount", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/Mount", + type: GRPCCallType.unary + ) + + public static let umount = GRPCMethodDescriptor( + name: "Umount", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/Umount", + type: GRPCCallType.unary + ) + + public static let setenv = GRPCMethodDescriptor( + name: "Setenv", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/Setenv", + type: GRPCCallType.unary + ) + + public static let getenv = GRPCMethodDescriptor( + name: "Getenv", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/Getenv", + type: GRPCCallType.unary + ) + + public static let mkdir = GRPCMethodDescriptor( + name: "Mkdir", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/Mkdir", + type: GRPCCallType.unary + ) + + public static let sysctl = GRPCMethodDescriptor( + name: "Sysctl", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/Sysctl", + type: GRPCCallType.unary + ) + + public static let setTime = GRPCMethodDescriptor( + name: "SetTime", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/SetTime", + type: GRPCCallType.unary + ) + + public static let setupEmulator = GRPCMethodDescriptor( + name: "SetupEmulator", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/SetupEmulator", + type: GRPCCallType.unary + ) + + public static let createProcess = GRPCMethodDescriptor( + name: "CreateProcess", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/CreateProcess", + type: GRPCCallType.unary + ) + + public static let deleteProcess = GRPCMethodDescriptor( + name: "DeleteProcess", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/DeleteProcess", + type: GRPCCallType.unary + ) + + public static let startProcess = GRPCMethodDescriptor( + name: "StartProcess", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/StartProcess", + type: GRPCCallType.unary + ) + + public static let killProcess = GRPCMethodDescriptor( + name: "KillProcess", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/KillProcess", + type: GRPCCallType.unary + ) + + public static let waitProcess = GRPCMethodDescriptor( + name: "WaitProcess", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/WaitProcess", + type: GRPCCallType.unary + ) + + public static let resizeProcess = GRPCMethodDescriptor( + name: "ResizeProcess", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/ResizeProcess", + type: GRPCCallType.unary + ) + + public static let proxyVsock = GRPCMethodDescriptor( + name: "ProxyVsock", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/ProxyVsock", + type: GRPCCallType.unary + ) + + public static let stopVsockProxy = GRPCMethodDescriptor( + name: "StopVsockProxy", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/StopVsockProxy", + type: GRPCCallType.unary + ) + + public static let ipLinkSet = GRPCMethodDescriptor( + name: "IpLinkSet", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/IpLinkSet", + type: GRPCCallType.unary + ) + + public static let ipAddrAdd = GRPCMethodDescriptor( + name: "IpAddrAdd", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/IpAddrAdd", + type: GRPCCallType.unary + ) + + public static let ipRouteAddLink = GRPCMethodDescriptor( + name: "IpRouteAddLink", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/IpRouteAddLink", + type: GRPCCallType.unary + ) + + public static let ipRouteAddDefault = GRPCMethodDescriptor( + name: "IpRouteAddDefault", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/IpRouteAddDefault", + type: GRPCCallType.unary + ) + + public static let configureDns = GRPCMethodDescriptor( + name: "ConfigureDns", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/ConfigureDns", + type: GRPCCallType.unary + ) + + public static let sync = GRPCMethodDescriptor( + name: "Sync", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/Sync", + type: GRPCCallType.unary + ) + + public static let kill = GRPCMethodDescriptor( + name: "Kill", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/Kill", + type: GRPCCallType.unary + ) + } +} + +/// Context for interacting with a container's runtime environment. +/// +/// To build a server, implement a class that conforms to this protocol. +public protocol Com_Apple_Containerization_Sandbox_V3_SandboxContextProvider: CallHandlerProvider { + var interceptors: Com_Apple_Containerization_Sandbox_V3_SandboxContextServerInterceptorFactoryProtocol? { get } + + /// Mount a filesystem. + func mount(request: Com_Apple_Containerization_Sandbox_V3_MountRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Unmount a filesystem. + func umount(request: Com_Apple_Containerization_Sandbox_V3_UmountRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Set an environment variable on the init process. + func setenv(request: Com_Apple_Containerization_Sandbox_V3_SetenvRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Get an environment variable from the init process. + func getenv(request: Com_Apple_Containerization_Sandbox_V3_GetenvRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Create a new directory inside the sandbox. + func mkdir(request: Com_Apple_Containerization_Sandbox_V3_MkdirRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Set sysctls in the context of the sandbox. + func sysctl(request: Com_Apple_Containerization_Sandbox_V3_SysctlRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Set time in the guest. + func setTime(request: Com_Apple_Containerization_Sandbox_V3_SetTimeRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Set up an emulator in the guest for a specific binary format. + func setupEmulator(request: Com_Apple_Containerization_Sandbox_V3_SetupEmulatorRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Create a new process inside the container. + func createProcess(request: Com_Apple_Containerization_Sandbox_V3_CreateProcessRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Delete an existing process inside the container. + func deleteProcess(request: Com_Apple_Containerization_Sandbox_V3_DeleteProcessRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Start the provided process. + func startProcess(request: Com_Apple_Containerization_Sandbox_V3_StartProcessRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Send a signal to the provided process. + func killProcess(request: Com_Apple_Containerization_Sandbox_V3_KillProcessRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Wait for a process to exit and return the exit code. + func waitProcess(request: Com_Apple_Containerization_Sandbox_V3_WaitProcessRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Resize the tty of a given process. This will error if the process does + /// not have a pty allocated. + func resizeProcess(request: Com_Apple_Containerization_Sandbox_V3_ResizeProcessRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Proxy a vsock port to a unix domain socket in the guest, or vice versa. + func proxyVsock(request: Com_Apple_Containerization_Sandbox_V3_ProxyVsockRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Stop a vsock proxy to a unix domain socket. + func stopVsockProxy(request: Com_Apple_Containerization_Sandbox_V3_StopVsockProxyRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Set the link state of a network interface. + func ipLinkSet(request: Com_Apple_Containerization_Sandbox_V3_IpLinkSetRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Add an IPv4 address to a network interface. + func ipAddrAdd(request: Com_Apple_Containerization_Sandbox_V3_IpAddrAddRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Add an IP route for a network interface. + func ipRouteAddLink(request: Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Add an IP route for a network interface. + func ipRouteAddDefault(request: Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Configure DNS resolver. + func configureDns(request: Com_Apple_Containerization_Sandbox_V3_ConfigureDnsRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Perform the sync syscall. + func sync(request: Com_Apple_Containerization_Sandbox_V3_SyncRequest, context: StatusOnlyCallContext) -> EventLoopFuture + + /// Send a signal to a process via the PID. + func kill(request: Com_Apple_Containerization_Sandbox_V3_KillRequest, context: StatusOnlyCallContext) -> EventLoopFuture +} + +extension Com_Apple_Containerization_Sandbox_V3_SandboxContextProvider { + public var serviceName: Substring { + return Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.serviceDescriptor.fullName[...] + } + + /// Determines, calls and returns the appropriate request handler, depending on the request's method. + /// Returns nil for methods not handled by this service. + public func handle( + method name: Substring, + context: CallHandlerContext + ) -> GRPCServerHandlerProtocol? { + switch name { + case "Mount": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeMountInterceptors() ?? [], + userFunction: self.mount(request:context:) + ) + + case "Umount": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeUmountInterceptors() ?? [], + userFunction: self.umount(request:context:) + ) + + case "Setenv": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeSetenvInterceptors() ?? [], + userFunction: self.setenv(request:context:) + ) + + case "Getenv": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeGetenvInterceptors() ?? [], + userFunction: self.getenv(request:context:) + ) + + case "Mkdir": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeMkdirInterceptors() ?? [], + userFunction: self.mkdir(request:context:) + ) + + case "Sysctl": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeSysctlInterceptors() ?? [], + userFunction: self.sysctl(request:context:) + ) + + case "SetTime": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeSetTimeInterceptors() ?? [], + userFunction: self.setTime(request:context:) + ) + + case "SetupEmulator": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeSetupEmulatorInterceptors() ?? [], + userFunction: self.setupEmulator(request:context:) + ) + + case "CreateProcess": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeCreateProcessInterceptors() ?? [], + userFunction: self.createProcess(request:context:) + ) + + case "DeleteProcess": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeDeleteProcessInterceptors() ?? [], + userFunction: self.deleteProcess(request:context:) + ) + + case "StartProcess": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeStartProcessInterceptors() ?? [], + userFunction: self.startProcess(request:context:) + ) + + case "KillProcess": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeKillProcessInterceptors() ?? [], + userFunction: self.killProcess(request:context:) + ) + + case "WaitProcess": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeWaitProcessInterceptors() ?? [], + userFunction: self.waitProcess(request:context:) + ) + + case "ResizeProcess": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeResizeProcessInterceptors() ?? [], + userFunction: self.resizeProcess(request:context:) + ) + + case "ProxyVsock": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeProxyVsockInterceptors() ?? [], + userFunction: self.proxyVsock(request:context:) + ) + + case "StopVsockProxy": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeStopVsockProxyInterceptors() ?? [], + userFunction: self.stopVsockProxy(request:context:) + ) + + case "IpLinkSet": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeIpLinkSetInterceptors() ?? [], + userFunction: self.ipLinkSet(request:context:) + ) + + case "IpAddrAdd": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeIpAddrAddInterceptors() ?? [], + userFunction: self.ipAddrAdd(request:context:) + ) + + case "IpRouteAddLink": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeIpRouteAddLinkInterceptors() ?? [], + userFunction: self.ipRouteAddLink(request:context:) + ) + + case "IpRouteAddDefault": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeIpRouteAddDefaultInterceptors() ?? [], + userFunction: self.ipRouteAddDefault(request:context:) + ) + + case "ConfigureDns": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeConfigureDnsInterceptors() ?? [], + userFunction: self.configureDns(request:context:) + ) + + case "Sync": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeSyncInterceptors() ?? [], + userFunction: self.sync(request:context:) + ) + + case "Kill": + return UnaryServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeKillInterceptors() ?? [], + userFunction: self.kill(request:context:) + ) + + default: + return nil + } + } +} + +/// Context for interacting with a container's runtime environment. +/// +/// To implement a server, implement an object which conforms to this protocol. +@available(macOS 10.15, iOS 13, tvOS 13, watchOS 6, *) +public protocol Com_Apple_Containerization_Sandbox_V3_SandboxContextAsyncProvider: CallHandlerProvider, Sendable { + static var serviceDescriptor: GRPCServiceDescriptor { get } + var interceptors: Com_Apple_Containerization_Sandbox_V3_SandboxContextServerInterceptorFactoryProtocol? { get } + + /// Mount a filesystem. + func mount( + request: Com_Apple_Containerization_Sandbox_V3_MountRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_MountResponse + + /// Unmount a filesystem. + func umount( + request: Com_Apple_Containerization_Sandbox_V3_UmountRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_UmountResponse + + /// Set an environment variable on the init process. + func setenv( + request: Com_Apple_Containerization_Sandbox_V3_SetenvRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_SetenvResponse + + /// Get an environment variable from the init process. + func getenv( + request: Com_Apple_Containerization_Sandbox_V3_GetenvRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_GetenvResponse + + /// Create a new directory inside the sandbox. + func mkdir( + request: Com_Apple_Containerization_Sandbox_V3_MkdirRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_MkdirResponse + + /// Set sysctls in the context of the sandbox. + func sysctl( + request: Com_Apple_Containerization_Sandbox_V3_SysctlRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_SysctlResponse + + /// Set time in the guest. + func setTime( + request: Com_Apple_Containerization_Sandbox_V3_SetTimeRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_SetTimeResponse + + /// Set up an emulator in the guest for a specific binary format. + func setupEmulator( + request: Com_Apple_Containerization_Sandbox_V3_SetupEmulatorRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_SetupEmulatorResponse + + /// Create a new process inside the container. + func createProcess( + request: Com_Apple_Containerization_Sandbox_V3_CreateProcessRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_CreateProcessResponse + + /// Delete an existing process inside the container. + func deleteProcess( + request: Com_Apple_Containerization_Sandbox_V3_DeleteProcessRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_DeleteProcessResponse + + /// Start the provided process. + func startProcess( + request: Com_Apple_Containerization_Sandbox_V3_StartProcessRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_StartProcessResponse + + /// Send a signal to the provided process. + func killProcess( + request: Com_Apple_Containerization_Sandbox_V3_KillProcessRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_KillProcessResponse + + /// Wait for a process to exit and return the exit code. + func waitProcess( + request: Com_Apple_Containerization_Sandbox_V3_WaitProcessRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_WaitProcessResponse + + /// Resize the tty of a given process. This will error if the process does + /// not have a pty allocated. + func resizeProcess( + request: Com_Apple_Containerization_Sandbox_V3_ResizeProcessRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_ResizeProcessResponse + + /// Proxy a vsock port to a unix domain socket in the guest, or vice versa. + func proxyVsock( + request: Com_Apple_Containerization_Sandbox_V3_ProxyVsockRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_ProxyVsockResponse + + /// Stop a vsock proxy to a unix domain socket. + func stopVsockProxy( + request: Com_Apple_Containerization_Sandbox_V3_StopVsockProxyRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_StopVsockProxyResponse + + /// Set the link state of a network interface. + func ipLinkSet( + request: Com_Apple_Containerization_Sandbox_V3_IpLinkSetRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_IpLinkSetResponse + + /// Add an IPv4 address to a network interface. + func ipAddrAdd( + request: Com_Apple_Containerization_Sandbox_V3_IpAddrAddRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_IpAddrAddResponse + + /// Add an IP route for a network interface. + func ipRouteAddLink( + request: Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkResponse + + /// Add an IP route for a network interface. + func ipRouteAddDefault( + request: Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultResponse + + /// Configure DNS resolver. + func configureDns( + request: Com_Apple_Containerization_Sandbox_V3_ConfigureDnsRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_ConfigureDnsResponse + + /// Perform the sync syscall. + func sync( + request: Com_Apple_Containerization_Sandbox_V3_SyncRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_SyncResponse + + /// Send a signal to a process via the PID. + func kill( + request: Com_Apple_Containerization_Sandbox_V3_KillRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_KillResponse +} + +@available(macOS 10.15, iOS 13, tvOS 13, watchOS 6, *) +extension Com_Apple_Containerization_Sandbox_V3_SandboxContextAsyncProvider { + public static var serviceDescriptor: GRPCServiceDescriptor { + return Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.serviceDescriptor + } + + public var serviceName: Substring { + return Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.serviceDescriptor.fullName[...] + } + + public var interceptors: Com_Apple_Containerization_Sandbox_V3_SandboxContextServerInterceptorFactoryProtocol? { + return nil + } + + public func handle( + method name: Substring, + context: CallHandlerContext + ) -> GRPCServerHandlerProtocol? { + switch name { + case "Mount": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeMountInterceptors() ?? [], + wrapping: { try await self.mount(request: $0, context: $1) } + ) + + case "Umount": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeUmountInterceptors() ?? [], + wrapping: { try await self.umount(request: $0, context: $1) } + ) + + case "Setenv": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeSetenvInterceptors() ?? [], + wrapping: { try await self.setenv(request: $0, context: $1) } + ) + + case "Getenv": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeGetenvInterceptors() ?? [], + wrapping: { try await self.getenv(request: $0, context: $1) } + ) + + case "Mkdir": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeMkdirInterceptors() ?? [], + wrapping: { try await self.mkdir(request: $0, context: $1) } + ) + + case "Sysctl": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeSysctlInterceptors() ?? [], + wrapping: { try await self.sysctl(request: $0, context: $1) } + ) + + case "SetTime": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeSetTimeInterceptors() ?? [], + wrapping: { try await self.setTime(request: $0, context: $1) } + ) + + case "SetupEmulator": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeSetupEmulatorInterceptors() ?? [], + wrapping: { try await self.setupEmulator(request: $0, context: $1) } + ) + + case "CreateProcess": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeCreateProcessInterceptors() ?? [], + wrapping: { try await self.createProcess(request: $0, context: $1) } + ) + + case "DeleteProcess": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeDeleteProcessInterceptors() ?? [], + wrapping: { try await self.deleteProcess(request: $0, context: $1) } + ) + + case "StartProcess": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeStartProcessInterceptors() ?? [], + wrapping: { try await self.startProcess(request: $0, context: $1) } + ) + + case "KillProcess": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeKillProcessInterceptors() ?? [], + wrapping: { try await self.killProcess(request: $0, context: $1) } + ) + + case "WaitProcess": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeWaitProcessInterceptors() ?? [], + wrapping: { try await self.waitProcess(request: $0, context: $1) } + ) + + case "ResizeProcess": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeResizeProcessInterceptors() ?? [], + wrapping: { try await self.resizeProcess(request: $0, context: $1) } + ) + + case "ProxyVsock": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeProxyVsockInterceptors() ?? [], + wrapping: { try await self.proxyVsock(request: $0, context: $1) } + ) + + case "StopVsockProxy": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeStopVsockProxyInterceptors() ?? [], + wrapping: { try await self.stopVsockProxy(request: $0, context: $1) } + ) + + case "IpLinkSet": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeIpLinkSetInterceptors() ?? [], + wrapping: { try await self.ipLinkSet(request: $0, context: $1) } + ) + + case "IpAddrAdd": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeIpAddrAddInterceptors() ?? [], + wrapping: { try await self.ipAddrAdd(request: $0, context: $1) } + ) + + case "IpRouteAddLink": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeIpRouteAddLinkInterceptors() ?? [], + wrapping: { try await self.ipRouteAddLink(request: $0, context: $1) } + ) + + case "IpRouteAddDefault": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeIpRouteAddDefaultInterceptors() ?? [], + wrapping: { try await self.ipRouteAddDefault(request: $0, context: $1) } + ) + + case "ConfigureDns": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeConfigureDnsInterceptors() ?? [], + wrapping: { try await self.configureDns(request: $0, context: $1) } + ) + + case "Sync": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeSyncInterceptors() ?? [], + wrapping: { try await self.sync(request: $0, context: $1) } + ) + + case "Kill": + return GRPCAsyncServerHandler( + context: context, + requestDeserializer: ProtobufDeserializer(), + responseSerializer: ProtobufSerializer(), + interceptors: self.interceptors?.makeKillInterceptors() ?? [], + wrapping: { try await self.kill(request: $0, context: $1) } + ) + + default: + return nil + } + } +} + +public protocol Com_Apple_Containerization_Sandbox_V3_SandboxContextServerInterceptorFactoryProtocol: Sendable { + + /// - Returns: Interceptors to use when handling 'mount'. + /// Defaults to calling `self.makeInterceptors()`. + func makeMountInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'umount'. + /// Defaults to calling `self.makeInterceptors()`. + func makeUmountInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'setenv'. + /// Defaults to calling `self.makeInterceptors()`. + func makeSetenvInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'getenv'. + /// Defaults to calling `self.makeInterceptors()`. + func makeGetenvInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'mkdir'. + /// Defaults to calling `self.makeInterceptors()`. + func makeMkdirInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'sysctl'. + /// Defaults to calling `self.makeInterceptors()`. + func makeSysctlInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'setTime'. + /// Defaults to calling `self.makeInterceptors()`. + func makeSetTimeInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'setupEmulator'. + /// Defaults to calling `self.makeInterceptors()`. + func makeSetupEmulatorInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'createProcess'. + /// Defaults to calling `self.makeInterceptors()`. + func makeCreateProcessInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'deleteProcess'. + /// Defaults to calling `self.makeInterceptors()`. + func makeDeleteProcessInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'startProcess'. + /// Defaults to calling `self.makeInterceptors()`. + func makeStartProcessInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'killProcess'. + /// Defaults to calling `self.makeInterceptors()`. + func makeKillProcessInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'waitProcess'. + /// Defaults to calling `self.makeInterceptors()`. + func makeWaitProcessInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'resizeProcess'. + /// Defaults to calling `self.makeInterceptors()`. + func makeResizeProcessInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'proxyVsock'. + /// Defaults to calling `self.makeInterceptors()`. + func makeProxyVsockInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'stopVsockProxy'. + /// Defaults to calling `self.makeInterceptors()`. + func makeStopVsockProxyInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'ipLinkSet'. + /// Defaults to calling `self.makeInterceptors()`. + func makeIpLinkSetInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'ipAddrAdd'. + /// Defaults to calling `self.makeInterceptors()`. + func makeIpAddrAddInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'ipRouteAddLink'. + /// Defaults to calling `self.makeInterceptors()`. + func makeIpRouteAddLinkInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'ipRouteAddDefault'. + /// Defaults to calling `self.makeInterceptors()`. + func makeIpRouteAddDefaultInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'configureDns'. + /// Defaults to calling `self.makeInterceptors()`. + func makeConfigureDnsInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'sync'. + /// Defaults to calling `self.makeInterceptors()`. + func makeSyncInterceptors() -> [ServerInterceptor] + + /// - Returns: Interceptors to use when handling 'kill'. + /// Defaults to calling `self.makeInterceptors()`. + func makeKillInterceptors() -> [ServerInterceptor] +} + +public enum Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata { + public static let serviceDescriptor = GRPCServiceDescriptor( + name: "SandboxContext", + fullName: "com.apple.containerization.sandbox.v3.SandboxContext", + methods: [ + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.mount, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.umount, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.setenv, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.getenv, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.mkdir, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.sysctl, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.setTime, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.setupEmulator, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.createProcess, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.deleteProcess, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.startProcess, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.killProcess, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.waitProcess, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.resizeProcess, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.proxyVsock, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.stopVsockProxy, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.ipLinkSet, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.ipAddrAdd, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.ipRouteAddLink, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.ipRouteAddDefault, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.configureDns, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.sync, + Com_Apple_Containerization_Sandbox_V3_SandboxContextServerMetadata.Methods.kill, + ] + ) + + public enum Methods { + public static let mount = GRPCMethodDescriptor( + name: "Mount", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/Mount", + type: GRPCCallType.unary + ) + + public static let umount = GRPCMethodDescriptor( + name: "Umount", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/Umount", + type: GRPCCallType.unary + ) + + public static let setenv = GRPCMethodDescriptor( + name: "Setenv", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/Setenv", + type: GRPCCallType.unary + ) + + public static let getenv = GRPCMethodDescriptor( + name: "Getenv", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/Getenv", + type: GRPCCallType.unary + ) + + public static let mkdir = GRPCMethodDescriptor( + name: "Mkdir", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/Mkdir", + type: GRPCCallType.unary + ) + + public static let sysctl = GRPCMethodDescriptor( + name: "Sysctl", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/Sysctl", + type: GRPCCallType.unary + ) + + public static let setTime = GRPCMethodDescriptor( + name: "SetTime", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/SetTime", + type: GRPCCallType.unary + ) + + public static let setupEmulator = GRPCMethodDescriptor( + name: "SetupEmulator", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/SetupEmulator", + type: GRPCCallType.unary + ) + + public static let createProcess = GRPCMethodDescriptor( + name: "CreateProcess", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/CreateProcess", + type: GRPCCallType.unary + ) + + public static let deleteProcess = GRPCMethodDescriptor( + name: "DeleteProcess", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/DeleteProcess", + type: GRPCCallType.unary + ) + + public static let startProcess = GRPCMethodDescriptor( + name: "StartProcess", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/StartProcess", + type: GRPCCallType.unary + ) + + public static let killProcess = GRPCMethodDescriptor( + name: "KillProcess", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/KillProcess", + type: GRPCCallType.unary + ) + + public static let waitProcess = GRPCMethodDescriptor( + name: "WaitProcess", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/WaitProcess", + type: GRPCCallType.unary + ) + + public static let resizeProcess = GRPCMethodDescriptor( + name: "ResizeProcess", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/ResizeProcess", + type: GRPCCallType.unary + ) + + public static let proxyVsock = GRPCMethodDescriptor( + name: "ProxyVsock", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/ProxyVsock", + type: GRPCCallType.unary + ) + + public static let stopVsockProxy = GRPCMethodDescriptor( + name: "StopVsockProxy", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/StopVsockProxy", + type: GRPCCallType.unary + ) + + public static let ipLinkSet = GRPCMethodDescriptor( + name: "IpLinkSet", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/IpLinkSet", + type: GRPCCallType.unary + ) + + public static let ipAddrAdd = GRPCMethodDescriptor( + name: "IpAddrAdd", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/IpAddrAdd", + type: GRPCCallType.unary + ) + + public static let ipRouteAddLink = GRPCMethodDescriptor( + name: "IpRouteAddLink", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/IpRouteAddLink", + type: GRPCCallType.unary + ) + + public static let ipRouteAddDefault = GRPCMethodDescriptor( + name: "IpRouteAddDefault", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/IpRouteAddDefault", + type: GRPCCallType.unary + ) + + public static let configureDns = GRPCMethodDescriptor( + name: "ConfigureDns", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/ConfigureDns", + type: GRPCCallType.unary + ) + + public static let sync = GRPCMethodDescriptor( + name: "Sync", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/Sync", + type: GRPCCallType.unary + ) + + public static let kill = GRPCMethodDescriptor( + name: "Kill", + path: "/com.apple.containerization.sandbox.v3.SandboxContext/Kill", + type: GRPCCallType.unary + ) + } +} diff --git a/Sources/Containerization/SandboxContext/SandboxContext.pb.swift b/Sources/Containerization/SandboxContext/SandboxContext.pb.swift new file mode 100644 index 00000000..4f11e9ee --- /dev/null +++ b/Sources/Containerization/SandboxContext/SandboxContext.pb.swift @@ -0,0 +1,2531 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// DO NOT EDIT. +// swift-format-ignore-file +// swiftlint:disable all +// +// Generated by the Swift generator plugin for the protocol buffer compiler. +// Source: SandboxContext.proto +// +// For information on using the generated types, please see the documentation: +// https://github.com/apple/swift-protobuf/ + +import Foundation +import SwiftProtobuf + +// If the compiler emits an error on this type, it is because this file +// was generated by a version of the `protoc` Swift plug-in that is +// incompatible with the version of SwiftProtobuf to which you are linking. +// Please ensure that you are building against the same version of the API +// that was used to generate this file. +fileprivate struct _GeneratedWithProtocGenSwiftVersion: SwiftProtobuf.ProtobufAPIVersionCheck { + struct _2: SwiftProtobuf.ProtobufAPIVersion_2 {} + typealias Version = _2 +} + +public struct Com_Apple_Containerization_Sandbox_V3_Stdio: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var stdinPort: Int32 { + get {return _stdinPort ?? 0} + set {_stdinPort = newValue} + } + /// Returns true if `stdinPort` has been explicitly set. + public var hasStdinPort: Bool {return self._stdinPort != nil} + /// Clears the value of `stdinPort`. Subsequent reads from it will return its default value. + public mutating func clearStdinPort() {self._stdinPort = nil} + + public var stdoutPort: Int32 { + get {return _stdoutPort ?? 0} + set {_stdoutPort = newValue} + } + /// Returns true if `stdoutPort` has been explicitly set. + public var hasStdoutPort: Bool {return self._stdoutPort != nil} + /// Clears the value of `stdoutPort`. Subsequent reads from it will return its default value. + public mutating func clearStdoutPort() {self._stdoutPort = nil} + + public var stderrPort: Int32 { + get {return _stderrPort ?? 0} + set {_stderrPort = newValue} + } + /// Returns true if `stderrPort` has been explicitly set. + public var hasStderrPort: Bool {return self._stderrPort != nil} + /// Clears the value of `stderrPort`. Subsequent reads from it will return its default value. + public mutating func clearStderrPort() {self._stderrPort = nil} + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} + + fileprivate var _stdinPort: Int32? = nil + fileprivate var _stdoutPort: Int32? = nil + fileprivate var _stderrPort: Int32? = nil +} + +public struct Com_Apple_Containerization_Sandbox_V3_SetupEmulatorRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var binaryPath: String = String() + + public var name: String = String() + + public var type: String = String() + + public var offset: String = String() + + public var magic: String = String() + + public var mask: String = String() + + public var flags: String = String() + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_SetupEmulatorResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_SetTimeRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var sec: Int64 = 0 + + public var usec: Int32 = 0 + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_SetTimeResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_SysctlRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var settings: Dictionary = [:] + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_SysctlResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_ProxyVsockRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var id: String = String() + + public var vsockPort: UInt32 = 0 + + public var guestPath: String = String() + + public var guestSocketPermissions: UInt32 { + get {return _guestSocketPermissions ?? 0} + set {_guestSocketPermissions = newValue} + } + /// Returns true if `guestSocketPermissions` has been explicitly set. + public var hasGuestSocketPermissions: Bool {return self._guestSocketPermissions != nil} + /// Clears the value of `guestSocketPermissions`. Subsequent reads from it will return its default value. + public mutating func clearGuestSocketPermissions() {self._guestSocketPermissions = nil} + + public var action: Com_Apple_Containerization_Sandbox_V3_ProxyVsockRequest.Action = .into + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public enum Action: SwiftProtobuf.Enum, Swift.CaseIterable { + public typealias RawValue = Int + case into // = 0 + case outOf // = 1 + case UNRECOGNIZED(Int) + + public init() { + self = .into + } + + public init?(rawValue: Int) { + switch rawValue { + case 0: self = .into + case 1: self = .outOf + default: self = .UNRECOGNIZED(rawValue) + } + } + + public var rawValue: Int { + switch self { + case .into: return 0 + case .outOf: return 1 + case .UNRECOGNIZED(let i): return i + } + } + + // The compiler won't synthesize support with the UNRECOGNIZED case. + public static let allCases: [Com_Apple_Containerization_Sandbox_V3_ProxyVsockRequest.Action] = [ + .into, + .outOf, + ] + + } + + public init() {} + + fileprivate var _guestSocketPermissions: UInt32? = nil +} + +public struct Com_Apple_Containerization_Sandbox_V3_ProxyVsockResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_StopVsockProxyRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var id: String = String() + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_StopVsockProxyResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_MountRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var type: String = String() + + public var source: String = String() + + public var destination: String = String() + + public var options: [String] = [] + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_MountResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_UmountRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var path: String = String() + + public var flags: Int32 = 0 + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_UmountResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_SetenvRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var key: String = String() + + public var value: String { + get {return _value ?? String()} + set {_value = newValue} + } + /// Returns true if `value` has been explicitly set. + public var hasValue: Bool {return self._value != nil} + /// Clears the value of `value`. Subsequent reads from it will return its default value. + public mutating func clearValue() {self._value = nil} + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} + + fileprivate var _value: String? = nil +} + +public struct Com_Apple_Containerization_Sandbox_V3_SetenvResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_GetenvRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var key: String = String() + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_GetenvResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var value: String { + get {return _value ?? String()} + set {_value = newValue} + } + /// Returns true if `value` has been explicitly set. + public var hasValue: Bool {return self._value != nil} + /// Clears the value of `value`. Subsequent reads from it will return its default value. + public mutating func clearValue() {self._value = nil} + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} + + fileprivate var _value: String? = nil +} + +public struct Com_Apple_Containerization_Sandbox_V3_CreateProcessRequest: @unchecked Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var id: String = String() + + public var containerID: String { + get {return _containerID ?? String()} + set {_containerID = newValue} + } + /// Returns true if `containerID` has been explicitly set. + public var hasContainerID: Bool {return self._containerID != nil} + /// Clears the value of `containerID`. Subsequent reads from it will return its default value. + public mutating func clearContainerID() {self._containerID = nil} + + public var stdin: UInt32 { + get {return _stdin ?? 0} + set {_stdin = newValue} + } + /// Returns true if `stdin` has been explicitly set. + public var hasStdin: Bool {return self._stdin != nil} + /// Clears the value of `stdin`. Subsequent reads from it will return its default value. + public mutating func clearStdin() {self._stdin = nil} + + public var stdout: UInt32 { + get {return _stdout ?? 0} + set {_stdout = newValue} + } + /// Returns true if `stdout` has been explicitly set. + public var hasStdout: Bool {return self._stdout != nil} + /// Clears the value of `stdout`. Subsequent reads from it will return its default value. + public mutating func clearStdout() {self._stdout = nil} + + public var stderr: UInt32 { + get {return _stderr ?? 0} + set {_stderr = newValue} + } + /// Returns true if `stderr` has been explicitly set. + public var hasStderr: Bool {return self._stderr != nil} + /// Clears the value of `stderr`. Subsequent reads from it will return its default value. + public mutating func clearStderr() {self._stderr = nil} + + public var configuration: Data = Data() + + public var options: Data { + get {return _options ?? Data()} + set {_options = newValue} + } + /// Returns true if `options` has been explicitly set. + public var hasOptions: Bool {return self._options != nil} + /// Clears the value of `options`. Subsequent reads from it will return its default value. + public mutating func clearOptions() {self._options = nil} + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} + + fileprivate var _containerID: String? = nil + fileprivate var _stdin: UInt32? = nil + fileprivate var _stdout: UInt32? = nil + fileprivate var _stderr: UInt32? = nil + fileprivate var _options: Data? = nil +} + +public struct Com_Apple_Containerization_Sandbox_V3_CreateProcessResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_AttachProcessRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var id: String = String() + + public var containerID: String { + get {return _containerID ?? String()} + set {_containerID = newValue} + } + /// Returns true if `containerID` has been explicitly set. + public var hasContainerID: Bool {return self._containerID != nil} + /// Clears the value of `containerID`. Subsequent reads from it will return its default value. + public mutating func clearContainerID() {self._containerID = nil} + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} + + fileprivate var _containerID: String? = nil +} + +public struct Com_Apple_Containerization_Sandbox_V3_AttachProcessResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var ports: Com_Apple_Containerization_Sandbox_V3_Stdio { + get {return _ports ?? Com_Apple_Containerization_Sandbox_V3_Stdio()} + set {_ports = newValue} + } + /// Returns true if `ports` has been explicitly set. + public var hasPorts: Bool {return self._ports != nil} + /// Clears the value of `ports`. Subsequent reads from it will return its default value. + public mutating func clearPorts() {self._ports = nil} + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} + + fileprivate var _ports: Com_Apple_Containerization_Sandbox_V3_Stdio? = nil +} + +public struct Com_Apple_Containerization_Sandbox_V3_WaitProcessRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var id: String = String() + + public var containerID: String { + get {return _containerID ?? String()} + set {_containerID = newValue} + } + /// Returns true if `containerID` has been explicitly set. + public var hasContainerID: Bool {return self._containerID != nil} + /// Clears the value of `containerID`. Subsequent reads from it will return its default value. + public mutating func clearContainerID() {self._containerID = nil} + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} + + fileprivate var _containerID: String? = nil +} + +public struct Com_Apple_Containerization_Sandbox_V3_WaitProcessResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var exitCode: Int32 = 0 + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_ResizeProcessRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var id: String = String() + + public var containerID: String { + get {return _containerID ?? String()} + set {_containerID = newValue} + } + /// Returns true if `containerID` has been explicitly set. + public var hasContainerID: Bool {return self._containerID != nil} + /// Clears the value of `containerID`. Subsequent reads from it will return its default value. + public mutating func clearContainerID() {self._containerID = nil} + + public var rows: UInt32 = 0 + + public var columns: UInt32 = 0 + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} + + fileprivate var _containerID: String? = nil +} + +public struct Com_Apple_Containerization_Sandbox_V3_ResizeProcessResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_DeleteProcessRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var id: String = String() + + public var containerID: String { + get {return _containerID ?? String()} + set {_containerID = newValue} + } + /// Returns true if `containerID` has been explicitly set. + public var hasContainerID: Bool {return self._containerID != nil} + /// Clears the value of `containerID`. Subsequent reads from it will return its default value. + public mutating func clearContainerID() {self._containerID = nil} + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} + + fileprivate var _containerID: String? = nil +} + +public struct Com_Apple_Containerization_Sandbox_V3_DeleteProcessResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_StartProcessRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var id: String = String() + + public var containerID: String { + get {return _containerID ?? String()} + set {_containerID = newValue} + } + /// Returns true if `containerID` has been explicitly set. + public var hasContainerID: Bool {return self._containerID != nil} + /// Clears the value of `containerID`. Subsequent reads from it will return its default value. + public mutating func clearContainerID() {self._containerID = nil} + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} + + fileprivate var _containerID: String? = nil +} + +public struct Com_Apple_Containerization_Sandbox_V3_StartProcessResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var pid: Int32 = 0 + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_KillProcessRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var id: String = String() + + public var containerID: String { + get {return _containerID ?? String()} + set {_containerID = newValue} + } + /// Returns true if `containerID` has been explicitly set. + public var hasContainerID: Bool {return self._containerID != nil} + /// Clears the value of `containerID`. Subsequent reads from it will return its default value. + public mutating func clearContainerID() {self._containerID = nil} + + public var signal: Int32 = 0 + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} + + fileprivate var _containerID: String? = nil +} + +public struct Com_Apple_Containerization_Sandbox_V3_KillProcessResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var result: Int32 = 0 + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_MkdirRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var path: String = String() + + public var all: Bool = false + + public var perms: UInt32 = 0 + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_MkdirResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_IpLinkSetRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var interface: String = String() + + public var up: Bool = false + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_IpLinkSetResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_IpAddrAddRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var interface: String = String() + + public var address: String = String() + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_IpAddrAddResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var interface: String = String() + + public var address: String = String() + + public var srcAddr: String = String() + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var interface: String = String() + + public var gateway: String = String() + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_ConfigureDnsRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var location: String = String() + + public var nameservers: [String] = [] + + public var domain: String { + get {return _domain ?? String()} + set {_domain = newValue} + } + /// Returns true if `domain` has been explicitly set. + public var hasDomain: Bool {return self._domain != nil} + /// Clears the value of `domain`. Subsequent reads from it will return its default value. + public mutating func clearDomain() {self._domain = nil} + + public var searchDomains: [String] = [] + + public var options: [String] = [] + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} + + fileprivate var _domain: String? = nil +} + +public struct Com_Apple_Containerization_Sandbox_V3_ConfigureDnsResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_SyncRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_SyncResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_KillRequest: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var pid: Int32 = 0 + + public var signal: Int32 = 0 + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +public struct Com_Apple_Containerization_Sandbox_V3_KillResponse: Sendable { + // SwiftProtobuf.Message conformance is added in an extension below. See the + // `Message` and `Message+*Additions` files in the SwiftProtobuf library for + // methods supported on all messages. + + public var result: Int32 = 0 + + public var unknownFields = SwiftProtobuf.UnknownStorage() + + public init() {} +} + +// MARK: - Code below here is support for the SwiftProtobuf runtime. + +fileprivate let _protobuf_package = "com.apple.containerization.sandbox.v3" + +extension Com_Apple_Containerization_Sandbox_V3_Stdio: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".Stdio" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "stdinPort"), + 2: .same(proto: "stdoutPort"), + 3: .same(proto: "stderrPort"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularInt32Field(value: &self._stdinPort) }() + case 2: try { try decoder.decodeSingularInt32Field(value: &self._stdoutPort) }() + case 3: try { try decoder.decodeSingularInt32Field(value: &self._stderrPort) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every if/case branch local when no optimizations + // are enabled. https://github.com/apple/swift-protobuf/issues/1034 and + // https://github.com/apple/swift-protobuf/issues/1182 + try { if let v = self._stdinPort { + try visitor.visitSingularInt32Field(value: v, fieldNumber: 1) + } }() + try { if let v = self._stdoutPort { + try visitor.visitSingularInt32Field(value: v, fieldNumber: 2) + } }() + try { if let v = self._stderrPort { + try visitor.visitSingularInt32Field(value: v, fieldNumber: 3) + } }() + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_Stdio, rhs: Com_Apple_Containerization_Sandbox_V3_Stdio) -> Bool { + if lhs._stdinPort != rhs._stdinPort {return false} + if lhs._stdoutPort != rhs._stdoutPort {return false} + if lhs._stderrPort != rhs._stderrPort {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_SetupEmulatorRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".SetupEmulatorRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .standard(proto: "binary_path"), + 2: .same(proto: "name"), + 3: .same(proto: "type"), + 4: .same(proto: "offset"), + 5: .same(proto: "magic"), + 6: .same(proto: "mask"), + 7: .same(proto: "flags"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.binaryPath) }() + case 2: try { try decoder.decodeSingularStringField(value: &self.name) }() + case 3: try { try decoder.decodeSingularStringField(value: &self.type) }() + case 4: try { try decoder.decodeSingularStringField(value: &self.offset) }() + case 5: try { try decoder.decodeSingularStringField(value: &self.magic) }() + case 6: try { try decoder.decodeSingularStringField(value: &self.mask) }() + case 7: try { try decoder.decodeSingularStringField(value: &self.flags) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + if !self.binaryPath.isEmpty { + try visitor.visitSingularStringField(value: self.binaryPath, fieldNumber: 1) + } + if !self.name.isEmpty { + try visitor.visitSingularStringField(value: self.name, fieldNumber: 2) + } + if !self.type.isEmpty { + try visitor.visitSingularStringField(value: self.type, fieldNumber: 3) + } + if !self.offset.isEmpty { + try visitor.visitSingularStringField(value: self.offset, fieldNumber: 4) + } + if !self.magic.isEmpty { + try visitor.visitSingularStringField(value: self.magic, fieldNumber: 5) + } + if !self.mask.isEmpty { + try visitor.visitSingularStringField(value: self.mask, fieldNumber: 6) + } + if !self.flags.isEmpty { + try visitor.visitSingularStringField(value: self.flags, fieldNumber: 7) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_SetupEmulatorRequest, rhs: Com_Apple_Containerization_Sandbox_V3_SetupEmulatorRequest) -> Bool { + if lhs.binaryPath != rhs.binaryPath {return false} + if lhs.name != rhs.name {return false} + if lhs.type != rhs.type {return false} + if lhs.offset != rhs.offset {return false} + if lhs.magic != rhs.magic {return false} + if lhs.mask != rhs.mask {return false} + if lhs.flags != rhs.flags {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_SetupEmulatorResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".SetupEmulatorResponse" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_SetupEmulatorResponse, rhs: Com_Apple_Containerization_Sandbox_V3_SetupEmulatorResponse) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_SetTimeRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".SetTimeRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "sec"), + 2: .same(proto: "usec"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularInt64Field(value: &self.sec) }() + case 2: try { try decoder.decodeSingularInt32Field(value: &self.usec) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + if self.sec != 0 { + try visitor.visitSingularInt64Field(value: self.sec, fieldNumber: 1) + } + if self.usec != 0 { + try visitor.visitSingularInt32Field(value: self.usec, fieldNumber: 2) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_SetTimeRequest, rhs: Com_Apple_Containerization_Sandbox_V3_SetTimeRequest) -> Bool { + if lhs.sec != rhs.sec {return false} + if lhs.usec != rhs.usec {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_SetTimeResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".SetTimeResponse" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_SetTimeResponse, rhs: Com_Apple_Containerization_Sandbox_V3_SetTimeResponse) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_SysctlRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".SysctlRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "settings"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeMapField(fieldType: SwiftProtobuf._ProtobufMap.self, value: &self.settings) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + if !self.settings.isEmpty { + try visitor.visitMapField(fieldType: SwiftProtobuf._ProtobufMap.self, value: self.settings, fieldNumber: 1) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_SysctlRequest, rhs: Com_Apple_Containerization_Sandbox_V3_SysctlRequest) -> Bool { + if lhs.settings != rhs.settings {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_SysctlResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".SysctlResponse" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_SysctlResponse, rhs: Com_Apple_Containerization_Sandbox_V3_SysctlResponse) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_ProxyVsockRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".ProxyVsockRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "id"), + 2: .standard(proto: "vsock_port"), + 3: .same(proto: "guestPath"), + 4: .same(proto: "guestSocketPermissions"), + 5: .same(proto: "action"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.id) }() + case 2: try { try decoder.decodeSingularUInt32Field(value: &self.vsockPort) }() + case 3: try { try decoder.decodeSingularStringField(value: &self.guestPath) }() + case 4: try { try decoder.decodeSingularUInt32Field(value: &self._guestSocketPermissions) }() + case 5: try { try decoder.decodeSingularEnumField(value: &self.action) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every if/case branch local when no optimizations + // are enabled. https://github.com/apple/swift-protobuf/issues/1034 and + // https://github.com/apple/swift-protobuf/issues/1182 + if !self.id.isEmpty { + try visitor.visitSingularStringField(value: self.id, fieldNumber: 1) + } + if self.vsockPort != 0 { + try visitor.visitSingularUInt32Field(value: self.vsockPort, fieldNumber: 2) + } + if !self.guestPath.isEmpty { + try visitor.visitSingularStringField(value: self.guestPath, fieldNumber: 3) + } + try { if let v = self._guestSocketPermissions { + try visitor.visitSingularUInt32Field(value: v, fieldNumber: 4) + } }() + if self.action != .into { + try visitor.visitSingularEnumField(value: self.action, fieldNumber: 5) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_ProxyVsockRequest, rhs: Com_Apple_Containerization_Sandbox_V3_ProxyVsockRequest) -> Bool { + if lhs.id != rhs.id {return false} + if lhs.vsockPort != rhs.vsockPort {return false} + if lhs.guestPath != rhs.guestPath {return false} + if lhs._guestSocketPermissions != rhs._guestSocketPermissions {return false} + if lhs.action != rhs.action {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_ProxyVsockRequest.Action: SwiftProtobuf._ProtoNameProviding { + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 0: .same(proto: "INTO"), + 1: .same(proto: "OUT_OF"), + ] +} + +extension Com_Apple_Containerization_Sandbox_V3_ProxyVsockResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".ProxyVsockResponse" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_ProxyVsockResponse, rhs: Com_Apple_Containerization_Sandbox_V3_ProxyVsockResponse) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_StopVsockProxyRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".StopVsockProxyRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "id"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.id) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + if !self.id.isEmpty { + try visitor.visitSingularStringField(value: self.id, fieldNumber: 1) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_StopVsockProxyRequest, rhs: Com_Apple_Containerization_Sandbox_V3_StopVsockProxyRequest) -> Bool { + if lhs.id != rhs.id {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_StopVsockProxyResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".StopVsockProxyResponse" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_StopVsockProxyResponse, rhs: Com_Apple_Containerization_Sandbox_V3_StopVsockProxyResponse) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_MountRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".MountRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "type"), + 2: .same(proto: "source"), + 3: .same(proto: "destination"), + 4: .same(proto: "options"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.type) }() + case 2: try { try decoder.decodeSingularStringField(value: &self.source) }() + case 3: try { try decoder.decodeSingularStringField(value: &self.destination) }() + case 4: try { try decoder.decodeRepeatedStringField(value: &self.options) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + if !self.type.isEmpty { + try visitor.visitSingularStringField(value: self.type, fieldNumber: 1) + } + if !self.source.isEmpty { + try visitor.visitSingularStringField(value: self.source, fieldNumber: 2) + } + if !self.destination.isEmpty { + try visitor.visitSingularStringField(value: self.destination, fieldNumber: 3) + } + if !self.options.isEmpty { + try visitor.visitRepeatedStringField(value: self.options, fieldNumber: 4) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_MountRequest, rhs: Com_Apple_Containerization_Sandbox_V3_MountRequest) -> Bool { + if lhs.type != rhs.type {return false} + if lhs.source != rhs.source {return false} + if lhs.destination != rhs.destination {return false} + if lhs.options != rhs.options {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_MountResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".MountResponse" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_MountResponse, rhs: Com_Apple_Containerization_Sandbox_V3_MountResponse) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_UmountRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".UmountRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "path"), + 2: .same(proto: "flags"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.path) }() + case 2: try { try decoder.decodeSingularInt32Field(value: &self.flags) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + if !self.path.isEmpty { + try visitor.visitSingularStringField(value: self.path, fieldNumber: 1) + } + if self.flags != 0 { + try visitor.visitSingularInt32Field(value: self.flags, fieldNumber: 2) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_UmountRequest, rhs: Com_Apple_Containerization_Sandbox_V3_UmountRequest) -> Bool { + if lhs.path != rhs.path {return false} + if lhs.flags != rhs.flags {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_UmountResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".UmountResponse" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_UmountResponse, rhs: Com_Apple_Containerization_Sandbox_V3_UmountResponse) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_SetenvRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".SetenvRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "key"), + 2: .same(proto: "value"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.key) }() + case 2: try { try decoder.decodeSingularStringField(value: &self._value) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every if/case branch local when no optimizations + // are enabled. https://github.com/apple/swift-protobuf/issues/1034 and + // https://github.com/apple/swift-protobuf/issues/1182 + if !self.key.isEmpty { + try visitor.visitSingularStringField(value: self.key, fieldNumber: 1) + } + try { if let v = self._value { + try visitor.visitSingularStringField(value: v, fieldNumber: 2) + } }() + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_SetenvRequest, rhs: Com_Apple_Containerization_Sandbox_V3_SetenvRequest) -> Bool { + if lhs.key != rhs.key {return false} + if lhs._value != rhs._value {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_SetenvResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".SetenvResponse" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_SetenvResponse, rhs: Com_Apple_Containerization_Sandbox_V3_SetenvResponse) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_GetenvRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".GetenvRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "key"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.key) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + if !self.key.isEmpty { + try visitor.visitSingularStringField(value: self.key, fieldNumber: 1) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_GetenvRequest, rhs: Com_Apple_Containerization_Sandbox_V3_GetenvRequest) -> Bool { + if lhs.key != rhs.key {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_GetenvResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".GetenvResponse" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "value"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self._value) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every if/case branch local when no optimizations + // are enabled. https://github.com/apple/swift-protobuf/issues/1034 and + // https://github.com/apple/swift-protobuf/issues/1182 + try { if let v = self._value { + try visitor.visitSingularStringField(value: v, fieldNumber: 1) + } }() + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_GetenvResponse, rhs: Com_Apple_Containerization_Sandbox_V3_GetenvResponse) -> Bool { + if lhs._value != rhs._value {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_CreateProcessRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".CreateProcessRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "id"), + 2: .same(proto: "containerID"), + 3: .same(proto: "stdin"), + 4: .same(proto: "stdout"), + 5: .same(proto: "stderr"), + 6: .same(proto: "configuration"), + 7: .same(proto: "options"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.id) }() + case 2: try { try decoder.decodeSingularStringField(value: &self._containerID) }() + case 3: try { try decoder.decodeSingularUInt32Field(value: &self._stdin) }() + case 4: try { try decoder.decodeSingularUInt32Field(value: &self._stdout) }() + case 5: try { try decoder.decodeSingularUInt32Field(value: &self._stderr) }() + case 6: try { try decoder.decodeSingularBytesField(value: &self.configuration) }() + case 7: try { try decoder.decodeSingularBytesField(value: &self._options) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every if/case branch local when no optimizations + // are enabled. https://github.com/apple/swift-protobuf/issues/1034 and + // https://github.com/apple/swift-protobuf/issues/1182 + if !self.id.isEmpty { + try visitor.visitSingularStringField(value: self.id, fieldNumber: 1) + } + try { if let v = self._containerID { + try visitor.visitSingularStringField(value: v, fieldNumber: 2) + } }() + try { if let v = self._stdin { + try visitor.visitSingularUInt32Field(value: v, fieldNumber: 3) + } }() + try { if let v = self._stdout { + try visitor.visitSingularUInt32Field(value: v, fieldNumber: 4) + } }() + try { if let v = self._stderr { + try visitor.visitSingularUInt32Field(value: v, fieldNumber: 5) + } }() + if !self.configuration.isEmpty { + try visitor.visitSingularBytesField(value: self.configuration, fieldNumber: 6) + } + try { if let v = self._options { + try visitor.visitSingularBytesField(value: v, fieldNumber: 7) + } }() + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_CreateProcessRequest, rhs: Com_Apple_Containerization_Sandbox_V3_CreateProcessRequest) -> Bool { + if lhs.id != rhs.id {return false} + if lhs._containerID != rhs._containerID {return false} + if lhs._stdin != rhs._stdin {return false} + if lhs._stdout != rhs._stdout {return false} + if lhs._stderr != rhs._stderr {return false} + if lhs.configuration != rhs.configuration {return false} + if lhs._options != rhs._options {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_CreateProcessResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".CreateProcessResponse" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_CreateProcessResponse, rhs: Com_Apple_Containerization_Sandbox_V3_CreateProcessResponse) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_AttachProcessRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".AttachProcessRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "id"), + 2: .same(proto: "containerID"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.id) }() + case 2: try { try decoder.decodeSingularStringField(value: &self._containerID) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every if/case branch local when no optimizations + // are enabled. https://github.com/apple/swift-protobuf/issues/1034 and + // https://github.com/apple/swift-protobuf/issues/1182 + if !self.id.isEmpty { + try visitor.visitSingularStringField(value: self.id, fieldNumber: 1) + } + try { if let v = self._containerID { + try visitor.visitSingularStringField(value: v, fieldNumber: 2) + } }() + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_AttachProcessRequest, rhs: Com_Apple_Containerization_Sandbox_V3_AttachProcessRequest) -> Bool { + if lhs.id != rhs.id {return false} + if lhs._containerID != rhs._containerID {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_AttachProcessResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".AttachProcessResponse" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "ports"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularMessageField(value: &self._ports) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every if/case branch local when no optimizations + // are enabled. https://github.com/apple/swift-protobuf/issues/1034 and + // https://github.com/apple/swift-protobuf/issues/1182 + try { if let v = self._ports { + try visitor.visitSingularMessageField(value: v, fieldNumber: 1) + } }() + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_AttachProcessResponse, rhs: Com_Apple_Containerization_Sandbox_V3_AttachProcessResponse) -> Bool { + if lhs._ports != rhs._ports {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_WaitProcessRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".WaitProcessRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "id"), + 2: .same(proto: "containerID"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.id) }() + case 2: try { try decoder.decodeSingularStringField(value: &self._containerID) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every if/case branch local when no optimizations + // are enabled. https://github.com/apple/swift-protobuf/issues/1034 and + // https://github.com/apple/swift-protobuf/issues/1182 + if !self.id.isEmpty { + try visitor.visitSingularStringField(value: self.id, fieldNumber: 1) + } + try { if let v = self._containerID { + try visitor.visitSingularStringField(value: v, fieldNumber: 2) + } }() + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_WaitProcessRequest, rhs: Com_Apple_Containerization_Sandbox_V3_WaitProcessRequest) -> Bool { + if lhs.id != rhs.id {return false} + if lhs._containerID != rhs._containerID {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_WaitProcessResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".WaitProcessResponse" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "exitCode"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularInt32Field(value: &self.exitCode) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + if self.exitCode != 0 { + try visitor.visitSingularInt32Field(value: self.exitCode, fieldNumber: 1) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_WaitProcessResponse, rhs: Com_Apple_Containerization_Sandbox_V3_WaitProcessResponse) -> Bool { + if lhs.exitCode != rhs.exitCode {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_ResizeProcessRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".ResizeProcessRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "id"), + 2: .same(proto: "containerID"), + 3: .same(proto: "rows"), + 4: .same(proto: "columns"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.id) }() + case 2: try { try decoder.decodeSingularStringField(value: &self._containerID) }() + case 3: try { try decoder.decodeSingularUInt32Field(value: &self.rows) }() + case 4: try { try decoder.decodeSingularUInt32Field(value: &self.columns) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every if/case branch local when no optimizations + // are enabled. https://github.com/apple/swift-protobuf/issues/1034 and + // https://github.com/apple/swift-protobuf/issues/1182 + if !self.id.isEmpty { + try visitor.visitSingularStringField(value: self.id, fieldNumber: 1) + } + try { if let v = self._containerID { + try visitor.visitSingularStringField(value: v, fieldNumber: 2) + } }() + if self.rows != 0 { + try visitor.visitSingularUInt32Field(value: self.rows, fieldNumber: 3) + } + if self.columns != 0 { + try visitor.visitSingularUInt32Field(value: self.columns, fieldNumber: 4) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_ResizeProcessRequest, rhs: Com_Apple_Containerization_Sandbox_V3_ResizeProcessRequest) -> Bool { + if lhs.id != rhs.id {return false} + if lhs._containerID != rhs._containerID {return false} + if lhs.rows != rhs.rows {return false} + if lhs.columns != rhs.columns {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_ResizeProcessResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".ResizeProcessResponse" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_ResizeProcessResponse, rhs: Com_Apple_Containerization_Sandbox_V3_ResizeProcessResponse) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_DeleteProcessRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".DeleteProcessRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "id"), + 2: .same(proto: "containerID"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.id) }() + case 2: try { try decoder.decodeSingularStringField(value: &self._containerID) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every if/case branch local when no optimizations + // are enabled. https://github.com/apple/swift-protobuf/issues/1034 and + // https://github.com/apple/swift-protobuf/issues/1182 + if !self.id.isEmpty { + try visitor.visitSingularStringField(value: self.id, fieldNumber: 1) + } + try { if let v = self._containerID { + try visitor.visitSingularStringField(value: v, fieldNumber: 2) + } }() + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_DeleteProcessRequest, rhs: Com_Apple_Containerization_Sandbox_V3_DeleteProcessRequest) -> Bool { + if lhs.id != rhs.id {return false} + if lhs._containerID != rhs._containerID {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_DeleteProcessResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".DeleteProcessResponse" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_DeleteProcessResponse, rhs: Com_Apple_Containerization_Sandbox_V3_DeleteProcessResponse) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_StartProcessRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".StartProcessRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "id"), + 2: .same(proto: "containerID"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.id) }() + case 2: try { try decoder.decodeSingularStringField(value: &self._containerID) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every if/case branch local when no optimizations + // are enabled. https://github.com/apple/swift-protobuf/issues/1034 and + // https://github.com/apple/swift-protobuf/issues/1182 + if !self.id.isEmpty { + try visitor.visitSingularStringField(value: self.id, fieldNumber: 1) + } + try { if let v = self._containerID { + try visitor.visitSingularStringField(value: v, fieldNumber: 2) + } }() + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_StartProcessRequest, rhs: Com_Apple_Containerization_Sandbox_V3_StartProcessRequest) -> Bool { + if lhs.id != rhs.id {return false} + if lhs._containerID != rhs._containerID {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_StartProcessResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".StartProcessResponse" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "pid"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularInt32Field(value: &self.pid) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + if self.pid != 0 { + try visitor.visitSingularInt32Field(value: self.pid, fieldNumber: 1) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_StartProcessResponse, rhs: Com_Apple_Containerization_Sandbox_V3_StartProcessResponse) -> Bool { + if lhs.pid != rhs.pid {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_KillProcessRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".KillProcessRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "id"), + 2: .same(proto: "containerID"), + 3: .same(proto: "signal"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.id) }() + case 2: try { try decoder.decodeSingularStringField(value: &self._containerID) }() + case 3: try { try decoder.decodeSingularInt32Field(value: &self.signal) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every if/case branch local when no optimizations + // are enabled. https://github.com/apple/swift-protobuf/issues/1034 and + // https://github.com/apple/swift-protobuf/issues/1182 + if !self.id.isEmpty { + try visitor.visitSingularStringField(value: self.id, fieldNumber: 1) + } + try { if let v = self._containerID { + try visitor.visitSingularStringField(value: v, fieldNumber: 2) + } }() + if self.signal != 0 { + try visitor.visitSingularInt32Field(value: self.signal, fieldNumber: 3) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_KillProcessRequest, rhs: Com_Apple_Containerization_Sandbox_V3_KillProcessRequest) -> Bool { + if lhs.id != rhs.id {return false} + if lhs._containerID != rhs._containerID {return false} + if lhs.signal != rhs.signal {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_KillProcessResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".KillProcessResponse" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "result"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularInt32Field(value: &self.result) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + if self.result != 0 { + try visitor.visitSingularInt32Field(value: self.result, fieldNumber: 1) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_KillProcessResponse, rhs: Com_Apple_Containerization_Sandbox_V3_KillProcessResponse) -> Bool { + if lhs.result != rhs.result {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_MkdirRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".MkdirRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "path"), + 2: .same(proto: "all"), + 3: .same(proto: "perms"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.path) }() + case 2: try { try decoder.decodeSingularBoolField(value: &self.all) }() + case 3: try { try decoder.decodeSingularUInt32Field(value: &self.perms) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + if !self.path.isEmpty { + try visitor.visitSingularStringField(value: self.path, fieldNumber: 1) + } + if self.all != false { + try visitor.visitSingularBoolField(value: self.all, fieldNumber: 2) + } + if self.perms != 0 { + try visitor.visitSingularUInt32Field(value: self.perms, fieldNumber: 3) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_MkdirRequest, rhs: Com_Apple_Containerization_Sandbox_V3_MkdirRequest) -> Bool { + if lhs.path != rhs.path {return false} + if lhs.all != rhs.all {return false} + if lhs.perms != rhs.perms {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_MkdirResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".MkdirResponse" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_MkdirResponse, rhs: Com_Apple_Containerization_Sandbox_V3_MkdirResponse) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_IpLinkSetRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".IpLinkSetRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "interface"), + 2: .same(proto: "up"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.interface) }() + case 2: try { try decoder.decodeSingularBoolField(value: &self.up) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + if !self.interface.isEmpty { + try visitor.visitSingularStringField(value: self.interface, fieldNumber: 1) + } + if self.up != false { + try visitor.visitSingularBoolField(value: self.up, fieldNumber: 2) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_IpLinkSetRequest, rhs: Com_Apple_Containerization_Sandbox_V3_IpLinkSetRequest) -> Bool { + if lhs.interface != rhs.interface {return false} + if lhs.up != rhs.up {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_IpLinkSetResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".IpLinkSetResponse" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_IpLinkSetResponse, rhs: Com_Apple_Containerization_Sandbox_V3_IpLinkSetResponse) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_IpAddrAddRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".IpAddrAddRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "interface"), + 2: .same(proto: "address"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.interface) }() + case 2: try { try decoder.decodeSingularStringField(value: &self.address) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + if !self.interface.isEmpty { + try visitor.visitSingularStringField(value: self.interface, fieldNumber: 1) + } + if !self.address.isEmpty { + try visitor.visitSingularStringField(value: self.address, fieldNumber: 2) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_IpAddrAddRequest, rhs: Com_Apple_Containerization_Sandbox_V3_IpAddrAddRequest) -> Bool { + if lhs.interface != rhs.interface {return false} + if lhs.address != rhs.address {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_IpAddrAddResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".IpAddrAddResponse" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_IpAddrAddResponse, rhs: Com_Apple_Containerization_Sandbox_V3_IpAddrAddResponse) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".IpRouteAddLinkRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "interface"), + 2: .same(proto: "address"), + 3: .same(proto: "srcAddr"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.interface) }() + case 2: try { try decoder.decodeSingularStringField(value: &self.address) }() + case 3: try { try decoder.decodeSingularStringField(value: &self.srcAddr) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + if !self.interface.isEmpty { + try visitor.visitSingularStringField(value: self.interface, fieldNumber: 1) + } + if !self.address.isEmpty { + try visitor.visitSingularStringField(value: self.address, fieldNumber: 2) + } + if !self.srcAddr.isEmpty { + try visitor.visitSingularStringField(value: self.srcAddr, fieldNumber: 3) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkRequest, rhs: Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkRequest) -> Bool { + if lhs.interface != rhs.interface {return false} + if lhs.address != rhs.address {return false} + if lhs.srcAddr != rhs.srcAddr {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".IpRouteAddLinkResponse" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkResponse, rhs: Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkResponse) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".IpRouteAddDefaultRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "interface"), + 2: .same(proto: "gateway"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.interface) }() + case 2: try { try decoder.decodeSingularStringField(value: &self.gateway) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + if !self.interface.isEmpty { + try visitor.visitSingularStringField(value: self.interface, fieldNumber: 1) + } + if !self.gateway.isEmpty { + try visitor.visitSingularStringField(value: self.gateway, fieldNumber: 2) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultRequest, rhs: Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultRequest) -> Bool { + if lhs.interface != rhs.interface {return false} + if lhs.gateway != rhs.gateway {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".IpRouteAddDefaultResponse" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultResponse, rhs: Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultResponse) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_ConfigureDnsRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".ConfigureDnsRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "location"), + 2: .same(proto: "nameservers"), + 3: .same(proto: "domain"), + 4: .same(proto: "searchDomains"), + 5: .same(proto: "options"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularStringField(value: &self.location) }() + case 2: try { try decoder.decodeRepeatedStringField(value: &self.nameservers) }() + case 3: try { try decoder.decodeSingularStringField(value: &self._domain) }() + case 4: try { try decoder.decodeRepeatedStringField(value: &self.searchDomains) }() + case 5: try { try decoder.decodeRepeatedStringField(value: &self.options) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every if/case branch local when no optimizations + // are enabled. https://github.com/apple/swift-protobuf/issues/1034 and + // https://github.com/apple/swift-protobuf/issues/1182 + if !self.location.isEmpty { + try visitor.visitSingularStringField(value: self.location, fieldNumber: 1) + } + if !self.nameservers.isEmpty { + try visitor.visitRepeatedStringField(value: self.nameservers, fieldNumber: 2) + } + try { if let v = self._domain { + try visitor.visitSingularStringField(value: v, fieldNumber: 3) + } }() + if !self.searchDomains.isEmpty { + try visitor.visitRepeatedStringField(value: self.searchDomains, fieldNumber: 4) + } + if !self.options.isEmpty { + try visitor.visitRepeatedStringField(value: self.options, fieldNumber: 5) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_ConfigureDnsRequest, rhs: Com_Apple_Containerization_Sandbox_V3_ConfigureDnsRequest) -> Bool { + if lhs.location != rhs.location {return false} + if lhs.nameservers != rhs.nameservers {return false} + if lhs._domain != rhs._domain {return false} + if lhs.searchDomains != rhs.searchDomains {return false} + if lhs.options != rhs.options {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_ConfigureDnsResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".ConfigureDnsResponse" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_ConfigureDnsResponse, rhs: Com_Apple_Containerization_Sandbox_V3_ConfigureDnsResponse) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_SyncRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".SyncRequest" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_SyncRequest, rhs: Com_Apple_Containerization_Sandbox_V3_SyncRequest) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_SyncResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".SyncResponse" + public static let _protobuf_nameMap = SwiftProtobuf._NameMap() + + public mutating func decodeMessage(decoder: inout D) throws { + // Load everything into unknown fields + while try decoder.nextFieldNumber() != nil {} + } + + public func traverse(visitor: inout V) throws { + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_SyncResponse, rhs: Com_Apple_Containerization_Sandbox_V3_SyncResponse) -> Bool { + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_KillRequest: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".KillRequest" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "pid"), + 3: .same(proto: "signal"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularInt32Field(value: &self.pid) }() + case 3: try { try decoder.decodeSingularInt32Field(value: &self.signal) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + if self.pid != 0 { + try visitor.visitSingularInt32Field(value: self.pid, fieldNumber: 1) + } + if self.signal != 0 { + try visitor.visitSingularInt32Field(value: self.signal, fieldNumber: 3) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_KillRequest, rhs: Com_Apple_Containerization_Sandbox_V3_KillRequest) -> Bool { + if lhs.pid != rhs.pid {return false} + if lhs.signal != rhs.signal {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} + +extension Com_Apple_Containerization_Sandbox_V3_KillResponse: SwiftProtobuf.Message, SwiftProtobuf._MessageImplementationBase, SwiftProtobuf._ProtoNameProviding { + public static let protoMessageName: String = _protobuf_package + ".KillResponse" + public static let _protobuf_nameMap: SwiftProtobuf._NameMap = [ + 1: .same(proto: "result"), + ] + + public mutating func decodeMessage(decoder: inout D) throws { + while let fieldNumber = try decoder.nextFieldNumber() { + // The use of inline closures is to circumvent an issue where the compiler + // allocates stack space for every case branch when no optimizations are + // enabled. https://github.com/apple/swift-protobuf/issues/1034 + switch fieldNumber { + case 1: try { try decoder.decodeSingularInt32Field(value: &self.result) }() + default: break + } + } + } + + public func traverse(visitor: inout V) throws { + if self.result != 0 { + try visitor.visitSingularInt32Field(value: self.result, fieldNumber: 1) + } + try unknownFields.traverse(visitor: &visitor) + } + + public static func ==(lhs: Com_Apple_Containerization_Sandbox_V3_KillResponse, rhs: Com_Apple_Containerization_Sandbox_V3_KillResponse) -> Bool { + if lhs.result != rhs.result {return false} + if lhs.unknownFields != rhs.unknownFields {return false} + return true + } +} diff --git a/Sources/Containerization/SandboxContext/SandboxContext.proto b/Sources/Containerization/SandboxContext/SandboxContext.proto new file mode 100644 index 00000000..f2948e19 --- /dev/null +++ b/Sources/Containerization/SandboxContext/SandboxContext.proto @@ -0,0 +1,249 @@ +syntax = "proto3"; + +package com.apple.containerization.sandbox.v3; + +// Context for interacting with a container's runtime environment. +service SandboxContext { + // Mount a filesystem. + rpc Mount(MountRequest) returns (MountResponse); + // Unmount a filesystem. + rpc Umount(UmountRequest) returns (UmountResponse); + // Set an environment variable on the init process. + rpc Setenv(SetenvRequest) returns (SetenvResponse); + // Get an environment variable from the init process. + rpc Getenv(GetenvRequest) returns (GetenvResponse); + // Create a new directory inside the sandbox. + rpc Mkdir(MkdirRequest) returns (MkdirResponse); + // Set sysctls in the context of the sandbox. + rpc Sysctl(SysctlRequest) returns (SysctlResponse); + // Set time in the guest. + rpc SetTime(SetTimeRequest) returns (SetTimeResponse); + // Set up an emulator in the guest for a specific binary format. + rpc SetupEmulator(SetupEmulatorRequest) returns (SetupEmulatorResponse); + + // Create a new process inside the container. + rpc CreateProcess(CreateProcessRequest) returns (CreateProcessResponse); + // Delete an existing process inside the container. + rpc DeleteProcess(DeleteProcessRequest) returns (DeleteProcessResponse); + // Start the provided process. + rpc StartProcess(StartProcessRequest) returns (StartProcessResponse); + // Send a signal to the provided process. + rpc KillProcess(KillProcessRequest) returns (KillProcessResponse); + // Wait for a process to exit and return the exit code. + rpc WaitProcess(WaitProcessRequest) returns (WaitProcessResponse); + // Resize the tty of a given process. This will error if the process does + // not have a pty allocated. + rpc ResizeProcess(ResizeProcessRequest) returns (ResizeProcessResponse); + + // Proxy a vsock port to a unix domain socket in the guest, or vice versa. + rpc ProxyVsock(ProxyVsockRequest) returns (ProxyVsockResponse); + // Stop a vsock proxy to a unix domain socket. + rpc StopVsockProxy(StopVsockProxyRequest) returns (StopVsockProxyResponse); + + // Set the link state of a network interface. + rpc IpLinkSet(IpLinkSetRequest) returns (IpLinkSetResponse); + // Add an IPv4 address to a network interface. + rpc IpAddrAdd(IpAddrAddRequest) returns (IpAddrAddResponse); + // Add an IP route for a network interface. + rpc IpRouteAddLink(IpRouteAddLinkRequest) returns (IpRouteAddLinkResponse); + // Add an IP route for a network interface. + rpc IpRouteAddDefault(IpRouteAddDefaultRequest) returns (IpRouteAddDefaultResponse); + // Configure DNS resolver. + rpc ConfigureDns(ConfigureDnsRequest) returns (ConfigureDnsResponse); + // Perform the sync syscall. + rpc Sync(SyncRequest) returns (SyncResponse); + // Send a signal to a process via the PID. + rpc Kill(KillRequest) returns (KillResponse); +} + +message Stdio { + optional int32 stdinPort = 1; + optional int32 stdoutPort = 2; + optional int32 stderrPort = 3; +} + +message SetupEmulatorRequest { + string binary_path = 1; + string name = 2; + string type = 3; + string offset = 4; + string magic = 5; + string mask = 6; + string flags = 7; +} + +message SetupEmulatorResponse {} + +message SetTimeRequest { + int64 sec = 1; + int32 usec = 2; +} + +message SetTimeResponse {} + +message SysctlRequest { map settings = 1; } + +message SysctlResponse {} + +message ProxyVsockRequest { + enum Action { + INTO = 0; + OUT_OF = 1; + } + string id = 1; + uint32 vsock_port = 2; + string guestPath = 3; + optional uint32 guestSocketPermissions = 4; + Action action = 5; +} + +message ProxyVsockResponse {} + +message StopVsockProxyRequest { string id = 1; } + +message StopVsockProxyResponse {} + +message MountRequest { + string type = 1; + string source = 2; + string destination = 3; + repeated string options = 4; +} + +message MountResponse {} + +message UmountRequest { + string path = 1; + int32 flags = 2; +} + +message UmountResponse {} + +message SetenvRequest { + string key = 1; + optional string value = 2; +} + +message SetenvResponse {} + +message GetenvRequest { string key = 1; } + +message GetenvResponse { optional string value = 1; } + +message CreateProcessRequest { + string id = 1; + optional string containerID = 2; + optional uint32 stdin = 3; + optional uint32 stdout = 4; + optional uint32 stderr = 5; + bytes configuration = 6; + optional bytes options = 7; +} + +message CreateProcessResponse {} + +message AttachProcessRequest { + string id = 1; + optional string containerID = 2; +} + +message AttachProcessResponse { + Stdio ports = 1; +} + +message WaitProcessRequest { + string id = 1; + optional string containerID = 2; +} + +message WaitProcessResponse { + int32 exitCode = 1; +} + +message ResizeProcessRequest { + string id = 1; + optional string containerID = 2; + uint32 rows = 3; + uint32 columns = 4; +} + +message ResizeProcessResponse {} + +message DeleteProcessRequest { + string id = 1; + optional string containerID = 2; +} + +message DeleteProcessResponse {} + +message StartProcessRequest { + string id = 1; + optional string containerID = 2; +} + +message StartProcessResponse { int32 pid = 1; } + +message KillProcessRequest { + string id = 1; + optional string containerID = 2; + int32 signal = 3; +} + +message KillProcessResponse { int32 result = 1; } + +message MkdirRequest { + string path = 1; + bool all = 2; + uint32 perms = 3; +} + +message MkdirResponse {} + +message IpLinkSetRequest { + string interface = 1; + bool up = 2; +} + +message IpLinkSetResponse {} + +message IpAddrAddRequest { + string interface = 1; + string address = 2; +} + +message IpAddrAddResponse {} + +message IpRouteAddLinkRequest { + string interface = 1; + string address = 2; + string srcAddr = 3; +} + +message IpRouteAddLinkResponse {} + +message IpRouteAddDefaultRequest { + string interface = 1; + string gateway = 2; +} + +message IpRouteAddDefaultResponse {} + +message ConfigureDnsRequest { + string location = 1; + repeated string nameservers = 2; + optional string domain = 3; + repeated string searchDomains = 4; + repeated string options = 5; +} + +message ConfigureDnsResponse {} + +message SyncRequest {} +message SyncResponse {} + +message KillRequest { + int32 pid = 1; + int32 signal = 3; +} + +message KillResponse { int32 result = 1; } diff --git a/Sources/Containerization/SystemPlatform.swift b/Sources/Containerization/SystemPlatform.swift new file mode 100644 index 00000000..b597837e --- /dev/null +++ b/Sources/Containerization/SystemPlatform.swift @@ -0,0 +1,38 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationOCI + +public struct SystemPlatform: Sendable, Codable { + public enum OS: String, CaseIterable, Sendable, Codable { + case linux + case darwin + } + public let os: OS + + public enum Architecture: String, CaseIterable, Sendable, Codable { + case arm64 + case amd64 + } + public let architecture: Architecture + + public func ociPlatform() -> ContainerizationOCI.Platform { + ContainerizationOCI.Platform(arch: architecture.rawValue, os: os.rawValue) + } + + public static var linuxArm: SystemPlatform { .init(os: .linux, architecture: .arm64) } + public static var linuxAmd: SystemPlatform { .init(os: .linux, architecture: .amd64) } +} diff --git a/Sources/Containerization/TimeSyncer.swift b/Sources/Containerization/TimeSyncer.swift new file mode 100644 index 00000000..f1e6fb22 --- /dev/null +++ b/Sources/Containerization/TimeSyncer.swift @@ -0,0 +1,67 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation +import Logging + +actor TimeSyncer: Sendable { + private var task: Task? + private var context: Vminitd? + private let logger: Logger? + + init(logger: Logger?) { + self.logger = logger + } + + func start(context: Vminitd, interval: Duration = .seconds(30)) { + precondition(task == nil, "time syncer is already running") + self.context = context + self.task = Task { + while true { + do { + do { + try await Task.sleep(for: interval) + } catch { + return + } + + var timeval = timeval() + guard gettimeofday(&timeval, nil) == 0 else { + throw POSIXError.fromErrno() + } + + try await context.setTime( + sec: Int64(timeval.tv_sec), + usec: Int32(timeval.tv_usec) + ) + } catch { + self.logger?.error("failed to sync time with guest agent: \(error)") + } + } + } + } + + func close() async throws { + guard let task else { + preconditionFailure("time syncer was already closed") + } + + task.cancel() + try await self.context?.close() + self.task = nil + self.context = nil + } +} diff --git a/Sources/Containerization/UnixSocketConfiguration.swift b/Sources/Containerization/UnixSocketConfiguration.swift new file mode 100644 index 00000000..0de3cbf7 --- /dev/null +++ b/Sources/Containerization/UnixSocketConfiguration.swift @@ -0,0 +1,69 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation +import SystemPackage + +/// Represents a UnixSocket that can be shared into or out of a container/guest. +public struct UnixSocketConfiguration: Sendable { + // TODO: Realistically, we can just hash this struct and use it as the "id". + package var id: String { + _id + } + + private let _id = UUID().uuidString + + /// The path to the socket you'd like relayed. For .into + /// direction this should be the path on the host to a unix socket. + /// For direction .outOf this should be the path in the container/guest + /// to a unix socket. + public var from: URL + + /// The path you'd like the socket to be relayed to. For .into + /// direction this should be ther path in the container/guest. For + /// direction .outOf this should be the path on your host. + public var to: URL + + /// What to set the file permissions of the unix socket being created + /// to. For .into direction this will be the socket in the guest. For + /// .outOf direction this will be the socket on the host. + public var permissions: FilePermissions? + + /// The direction of the relay. `.into` for sharing a unix socket on your + /// host into the container/guest. `outOf` shares a socket in the container/guest + /// onto your host. + public var direction: Direction + + /// Type that denotes the direction of the unix socket relay. + public enum Direction: Sendable { + /// Share the socket into the container/guest. + case into + /// Share a socket in the container/guest onto the host. + case outOf + } + + public init( + host: URL, + destination: URL, + permissions: FilePermissions? = nil, + direction: Direction = .into + ) { + self.from = host + self.to = destination + self.permissions = permissions + self.direction = direction + } +} diff --git a/Sources/Containerization/UnixSocketRelay.swift b/Sources/Containerization/UnixSocketRelay.swift new file mode 100644 index 00000000..60a3ea0d --- /dev/null +++ b/Sources/Containerization/UnixSocketRelay.swift @@ -0,0 +1,382 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationError +import ContainerizationIO +import ContainerizationOS +import Foundation +import Logging +import Synchronization + +package actor UnixSocketRelayManager { + private let vm: any VirtualMachineInstance + private var relays: [String: SocketRelay] + private let q: DispatchQueue + private let log: Logger? + + init(vm: any VirtualMachineInstance, log: Logger? = nil) { + self.vm = vm + self.relays = [:] + self.q = DispatchQueue(label: "com.apple.containerization.socket-relay") + self.log = log + } +} + +extension UnixSocketRelayManager { + func start(port: UInt32, socket: UnixSocketConfiguration) async throws { + guard self.relays[socket.id] == nil else { + throw ContainerizationError( + .invalidState, + message: "socket relay \(socket.id) already started" + ) + } + + let socketRelay = try SocketRelay( + port: port, + socket: socket, + vm: self.vm, + queue: self.q, + log: self.log + ) + + do { + self.relays[socket.id] = socketRelay + try await socketRelay.start() + } catch { + self.relays.removeValue(forKey: socket.id) + } + } + + func stop(socket: UnixSocketConfiguration) async throws { + guard let storedRelay = self.relays.removeValue(forKey: socket.id) else { + throw ContainerizationError( + .notFound, + message: "failed to stop socket relay" + ) + } + try storedRelay.stop() + } + + func stopAll() async throws { + for (_, relay) in self.relays { + try relay.stop() + } + } +} + +package final class SocketRelay: Sendable { + private let port: UInt32 + private let configuration: UnixSocketConfiguration + private let log: Logger? + private let vm: any VirtualMachineInstance + private let q: DispatchQueue + private let state: Mutex + + private struct State { + var relaySources: [String: ConnectionSources] = [:] + var t: Task<(), Never>? = nil + } + + // `DispatchSourceRead` is thread-safe. + private struct ConnectionSources: @unchecked Sendable { + let hostSource: DispatchSourceRead + let guestSource: DispatchSourceRead + } + + init( + port: UInt32, + socket: UnixSocketConfiguration, + vm: any VirtualMachineInstance, + queue: DispatchQueue, + log: Logger? = nil + ) throws { + self.port = port + self.configuration = socket + self.state = Mutex(.init()) + self.vm = vm + self.log = log + self.q = queue + } + + deinit { + self.state.withLock { $0.t?.cancel() } + } +} + +extension SocketRelay { + func start() async throws { + switch configuration.direction { + case .outOf: + try await setupHostVsockDial() + case .into: + try setupHostVsockListener() + } + } + + func stop() throws { + try self.state.withLock { + guard let t = $0.t else { + throw ContainerizationError( + .invalidState, + message: "failed to stop socket relay: relay has not been started" + ) + } + t.cancel() + $0.t = nil + $0.relaySources.removeAll() + } + + switch configuration.direction { + case .outOf: + // If we created the host conn, lets unlink it also. It's possible it was + // already unlinked if the relay failed earlier. + try? FileManager.default.removeItem(at: self.configuration.to) + case .into: + try self.vm.stopListen(self.port) + } + } + + private func setupHostVsockDial() async throws { + let hostConn = self.configuration.to + + let socketType = try UnixType( + path: hostConn.path, + unlinkExisting: true + ) + let hostSocket = try Socket(type: socketType) + try hostSocket.listen() + + let connectionStream = try hostSocket.acceptStream(closeOnDeinit: false) + self.state.withLock { + $0.t = Task { + do { + for try await connection in connectionStream { + try await self.handleHostUnixConn( + hostConn: connection, + port: self.port, + vm: self.vm, + log: self.log + ) + } + } catch { + log?.error("failed in unix socket relay loop: \(error)") + } + try? FileManager.default.removeItem(at: hostConn) + } + } + } + + private func setupHostVsockListener() throws { + let hostPath = self.configuration.from + let port = self.port + let log = self.log + + let connectionStream = try self.vm.listen(self.port) + self.state.withLock { + $0.t = Task { + do { + defer { connectionStream.finish() } + for await connection in connectionStream.connections { + try await self.handleGuestVsockConn( + vsockConn: connection, + hostConnectionPath: hostPath, + port: port, + log: log + ) + } + } catch { + log?.error("failed to setup relay between vsock \(port) and \(hostPath.path): \(error)") + } + } + } + } + + private func handleHostUnixConn( + hostConn: ContainerizationOS.Socket, + port: UInt32, + vm: any VirtualMachineInstance, + log: Logger? + ) async throws { + do { + let guestConn = try await vm.dial(port) + try await self.relay( + hostConn: hostConn, + guestFd: guestConn.fileDescriptor + ) + } catch { + log?.error("failed to relay between vsock \(port) and \(hostConn)") + throw error + } + } + + private func handleGuestVsockConn( + vsockConn: FileHandle, + hostConnectionPath: URL, + port: UInt32, + log: Logger? + ) async throws { + let hostPath = hostConnectionPath.path + let socketType = try UnixType(path: hostPath) + let hostSocket = try Socket( + type: socketType, + closeOnDeinit: false + ) + try hostSocket.connect() + + do { + try await self.relay( + hostConn: hostSocket, + guestFd: vsockConn.fileDescriptor + ) + } catch { + log?.error("failed to relay between vsock \(port) and \(hostPath)") + } + } + + private func relay( + hostConn: Socket, + guestFd: Int32 + ) async throws { + let connSource = DispatchSource.makeReadSource( + fileDescriptor: hostConn.fileDescriptor, + queue: self.q + ) + let vsockConnectionSource = DispatchSource.makeReadSource( + fileDescriptor: guestFd, + queue: self.q + ) + + let pairID = UUID().uuidString + self.state.withLock { + $0.relaySources[pairID] = ConnectionSources( + hostSource: connSource, + guestSource: vsockConnectionSource + ) + } + + nonisolated(unsafe) let buf1 = UnsafeMutableBufferPointer.allocate(capacity: Int(getpagesize())) + connSource.setEventHandler { + Self.fdCopyHandler( + buffer: buf1, + source: connSource, + from: hostConn.fileDescriptor, + to: guestFd + ) + } + + nonisolated(unsafe) let buf2 = UnsafeMutableBufferPointer.allocate(capacity: Int(getpagesize())) + vsockConnectionSource.setEventHandler { + Self.fdCopyHandler( + buffer: buf2, + source: vsockConnectionSource, + from: guestFd, + to: hostConn.fileDescriptor + ) + } + + connSource.setCancelHandler { + if !connSource.isCancelled { + connSource.cancel() + } + if !vsockConnectionSource.isCancelled { + vsockConnectionSource.cancel() + } + try? hostConn.close() + } + + vsockConnectionSource.setCancelHandler { + if !vsockConnectionSource.isCancelled { + vsockConnectionSource.cancel() + } + if !connSource.isCancelled { + connSource.cancel() + } + close(guestFd) + } + + connSource.activate() + vsockConnectionSource.activate() + } + + private static func fdCopyHandler( + buffer: UnsafeMutableBufferPointer, + source: DispatchSourceRead, + from sourceFd: Int32, + to destinationFd: Int32, + log: Logger? = nil + ) { + if source.data == 0 { + if !source.isCancelled { + source.cancel() + } + return + } + + do { + try self.fileDescriptorCopy( + buffer: buffer, + size: source.data, + from: sourceFd, + to: destinationFd + ) + } catch { + log?.error("file descriptor copy failed \(error)") + if !source.isCancelled { + source.cancel() + } + } + } + + private static func fileDescriptorCopy( + buffer: UnsafeMutableBufferPointer, + size: UInt, + from sourceFd: Int32, + to destinationFd: Int32 + ) throws { + let bufferSize = buffer.count + var readBytesRemaining = min(Int(size), bufferSize) + + guard let baseAddr = buffer.baseAddress else { + throw ContainerizationError( + .invalidState, + message: "buffer has no base address" + ) + } + + while readBytesRemaining > 0 { + let readResult = read(sourceFd, baseAddr, min(bufferSize, readBytesRemaining)) + if readResult <= 0 { + throw ContainerizationError( + .internalError, + message: "missing pointer base address" + ) + } + readBytesRemaining -= readResult + + var writeBytesRemaining = readResult + while writeBytesRemaining > 0 { + let writeResult = write(destinationFd, baseAddr, writeBytesRemaining) + if writeResult <= 0 { + throw ContainerizationError( + .internalError, + message: "zero byte write or error in socket relay" + ) + } + writeBytesRemaining -= writeResult + } + } + } +} diff --git a/Sources/Containerization/VZVirtualMachine+Helpers.swift b/Sources/Containerization/VZVirtualMachine+Helpers.swift new file mode 100644 index 00000000..41c72b80 --- /dev/null +++ b/Sources/Containerization/VZVirtualMachine+Helpers.swift @@ -0,0 +1,121 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +#if os(macOS) +import Foundation +import Logging +import Virtualization +import ContainerizationError + +extension VZVirtualMachine { + nonisolated func connect(queue: DispatchQueue, port: UInt32) async throws -> VZVirtioSocketConnection { + try await withCheckedThrowingContinuation { cont in + queue.sync { + guard let vsock = self.socketDevices[0] as? VZVirtioSocketDevice else { + let error = ContainerizationError(.invalidArgument, message: "no vsock device") + cont.resume(throwing: error) + return + } + vsock.connect(toPort: port) { result in + switch result { + case .success(let conn): + // `conn` isn't used concurrently. + nonisolated(unsafe) let conn = conn + cont.resume(returning: conn) + case .failure(let error): + cont.resume(throwing: error) + } + } + } + } + } + + func listen(queue: DispatchQueue, port: UInt32, listener: VZVirtioSocketListener) throws { + try queue.sync { + guard let vsock = self.socketDevices[0] as? VZVirtioSocketDevice else { + throw ContainerizationError(.invalidArgument, message: "no vsock device") + } + vsock.setSocketListener(listener, forPort: port) + } + } + + func removeListener(queue: DispatchQueue, port: UInt32) throws { + try queue.sync { + guard let vsock = self.socketDevices[0] as? VZVirtioSocketDevice else { + throw ContainerizationError( + .invalidArgument, + message: "no vsock device to remove" + ) + } + vsock.removeSocketListener(forPort: port) + } + } + + func start(queue: DispatchQueue) async throws { + try await withCheckedThrowingContinuation { (cont: CheckedContinuation) in + queue.sync { + self.start { result in + if case .failure(let error) = result { + cont.resume(throwing: error) + return + } + cont.resume() + } + } + } + } + + func stop(queue: DispatchQueue) async throws { + try await withCheckedThrowingContinuation { (cont: CheckedContinuation) in + queue.sync { + self.stop { error in + if let error { + cont.resume(throwing: error) + return + } + cont.resume() + } + } + } + } +} + +extension VZVirtualMachine { + func waitForAgent(queue: DispatchQueue) async throws -> FileHandle { + let agentConnectionRetryCount: Int = 150 + let agentConnectionSleepDuration: Duration = .milliseconds(20) + + for _ in 0...agentConnectionRetryCount { + do { + return try await self.connect(queue: queue, port: Vminitd.port).dupHandle() + } catch { + try await Task.sleep(for: agentConnectionSleepDuration) + continue + } + } + throw ContainerizationError(.invalidArgument, message: "no connection to agent socket") + } +} + +extension VZVirtioSocketConnection { + func dupHandle() -> FileHandle { + let fd = dup(self.fileDescriptor) + self.close() + return FileHandle(fileDescriptor: fd, closeOnDealloc: false) + } +} + +#endif diff --git a/Sources/Containerization/VZVirtualMachineInstance.swift b/Sources/Containerization/VZVirtualMachineInstance.swift new file mode 100644 index 00000000..39311532 --- /dev/null +++ b/Sources/Containerization/VZVirtualMachineInstance.swift @@ -0,0 +1,397 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +#if os(macOS) +import Foundation +import ContainerizationError +import ContainerizationExtras +import ContainerizationOCI +import Logging +import NIOCore +import NIOPosix +import Synchronization + +@preconcurrency import Virtualization + +struct VZVirtualMachineInstance: VirtualMachineInstance, Sendable { + typealias Agent = Vminitd + + /// Attached mounts on the sandbox. + public let mounts: [AttachedFilesystem] + + /// Returns the runtime state of the vm. + public var state: VirtualMachineInstanceState { + vzStateToInstanceState() + } + + /// The sandbox configuration. + private let config: Configuration + public struct Configuration: Sendable { + /// Amount of cpus to allocated. + public var cpus: Int + /// Amount of memory in bytes allocated. + public var memoryInBytes: UInt64 + /// Toggle rosetta's x86_64 emulation support. + public var rosetta: Bool + /// Toggle nested virtualization support. + public var nestedVirtualization: Bool + /// Mount attachments. + public var mounts: [Mount] + /// Network interface attachments. + public var interfaces: [any Interface] + /// Kernel image. + public var kernel: Kernel? + /// The root Filesystem. + public var initialFilesystem: Mount? + /// File path to store the sandbox boot logs. + public var bootlog: URL? + /// Enable GPU support. + public var gpu: Bool + + init() { + self.cpus = 4 + self.memoryInBytes = 1024.mib() + self.rosetta = false + self.nestedVirtualization = false + self.mounts = [] + self.interfaces = [] + self.gpu = false + } + } + + private nonisolated(unsafe) let vm: VZVirtualMachine + private let queue: DispatchQueue + private let group: MultiThreadedEventLoopGroup + private let lock: AsyncLock + private let timeSyncer: TimeSyncer + private let logger: Logger? + + public init( + group: MultiThreadedEventLoopGroup = MultiThreadedEventLoopGroup(numberOfThreads: System.coreCount), + logger: Logger? = nil, + with: (inout Configuration) throws -> Void + ) throws { + var config = Configuration() + try with(&config) + try self.init(group: group, config: config, logger: logger) + } + + init(group: MultiThreadedEventLoopGroup, config: Configuration, logger: Logger?) throws { + self.config = config + self.group = group + self.lock = .init() + self.queue = DispatchQueue(label: "com.apple.containerization.sandbox.\(UUID().uuidString)") + self.mounts = try config.mountAttachments() + self.logger = logger + self.timeSyncer = .init(logger: logger) + + self.vm = VZVirtualMachine( + configuration: try config.toVZ(), + queue: self.queue + ) + } +} + +extension VZVirtualMachineInstance { + func vzStateToInstanceState() -> VirtualMachineInstanceState { + self.queue.sync { + let state: VirtualMachineInstanceState + switch self.vm.state { + case .starting: + state = .starting + case .running: + state = .running + case .stopping: + state = .stopping + case .stopped: + state = .stopped + default: + state = .unknown + } + return state + } + } + + func start() async throws { + try await lock.withLock { _ in + guard self.state == .stopped else { + throw ContainerizationError( + .invalidState, + message: "sandbox is not stopped \(self.state)" + ) + } + + try await self.vm.start(queue: self.queue) + + let agent = Vminitd( + connection: try await self.vm.waitForAgent(queue: self.queue), + group: self.group + ) + + do { + if self.config.rosetta { + try await agent.enableRosetta() + } + } catch { + try await agent.close() + throw error + } + + // Don't close our remote context as we are providing + // it to our time sync routine. + await self.timeSyncer.start(context: agent) + } + } + + func stop() async throws { + try await lock.withLock { _ in + // NOTE: We should record HOW the vm stopped eventually. If the vm exited + // unexpectedly virtualization framework offers you a way to store + // an error on how it exited. We should report that here instead of the + // generic vm is not running. + guard self.state == .running else { + throw ContainerizationError(.invalidState, message: "vm is not running") + } + + try await self.timeSyncer.close() + + try await self.vm.stop(queue: self.queue) + try await self.group.shutdownGracefully() + } + } + + public func dialAgent() async throws -> Vminitd { + let conn = try await dial(Vminitd.port) + return Vminitd(connection: conn, group: self.group) + } +} + +extension VZVirtualMachineInstance { + func dial(_ port: UInt32) async throws -> FileHandle { + try await vm.connect( + queue: queue, + port: port + ).dupHandle() + } + + func listen(_ port: UInt32) throws -> ConnectionStream { + let stream = ConnectionStream(port: port) + let listener = VZVirtioSocketListener() + listener.delegate = stream + + try self.vm.listen( + queue: queue, + port: port, + listener: listener + ) + return stream + } + + func stopListen(_ port: UInt32) throws { + try self.vm.removeListener( + queue: queue, + port: port + ) + } +} + +extension VZVirtualMachineInstance.Configuration { + public static func installRosetta() throws { + #if arch(arm64) + do { + let _err: Mutex = .init(nil) + VZLinuxRosettaDirectoryShare.installRosetta(completionHandler: { error in + _err.withLock { + $0 = error + } + }) + let err = _err.withLock { $0 } + guard let err else { + return + } + throw err + } catch { + throw ContainerizationError( + .internalError, + message: "failed to install rosetta", + cause: error + ) + } + #endif + } + private func serialPort(path: URL) throws -> [VZVirtioConsoleDeviceSerialPortConfiguration] { + let c = VZVirtioConsoleDeviceSerialPortConfiguration() + c.attachment = try VZFileSerialPortAttachment(url: path, append: true) + return [c] + } + + func toVZ() throws -> VZVirtualMachineConfiguration { + var config = VZVirtualMachineConfiguration() + + config.cpuCount = self.cpus + config.memorySize = self.memoryInBytes + config.entropyDevices = [VZVirtioEntropyDeviceConfiguration()] + config.socketDevices = [VZVirtioSocketDeviceConfiguration()] + if let bootlog = self.bootlog { + config.serialPorts = try serialPort(path: bootlog) + } + + config.networkDevices = try self.interfaces.map { + guard let vzi = $0 as? VZInterface else { + throw ContainerizationError(.invalidArgument, message: "interface type not supported by VZ") + } + return try vzi.device() + } + + if self.rosetta { + switch VZLinuxRosettaDirectoryShare.availability { + case .notSupported: + throw ContainerizationError( + .invalidArgument, + message: "rosetta was requested but is not supported on this machine" + ) + case .notInstalled: + try Self.installRosetta() + fallthrough + case .installed: + let share = try VZLinuxRosettaDirectoryShare() + let device = VZVirtioFileSystemDeviceConfiguration(tag: "rosetta") + device.share = share + config.directorySharingDevices.append(device) + @unknown default: + throw ContainerizationError( + .invalidArgument, + message: "unknown rosetta availability encountered: \(VZLinuxRosettaDirectoryShare.availability)" + ) + } + } + + guard let kernel = self.kernel else { + throw ContainerizationError(.invalidArgument, message: "kernel cannot be nil") + } + + guard let initialFilesystem = self.initialFilesystem else { + throw ContainerizationError(.invalidArgument, message: "rootfs cannot be nil") + } + + let loader = VZLinuxBootLoader(kernelURL: kernel.path) + loader.commandLine = kernel.linuxCommandline(initialFilesystem: initialFilesystem) + config.bootLoader = loader + + try initialFilesystem.configure(config: &config) + for mount in self.mounts { + try mount.configure(config: &config) + } + + #if !CURRENT_SDK + if #available(macOS 16.0, *), self.gpu { + let graphicsConfig = VZVirtioGraphicsDeviceConfiguration() + let scanOut = VZVirtioGraphicsScanoutConfiguration(widthInPixels: 1024, heightInPixels: 768) + graphicsConfig.scanouts = [scanOut] + graphicsConfig.isAccelerationEnabled = true + config.graphicsDevices = [graphicsConfig] + } + #endif + + #if arch(arm64) + + let platform = VZGenericPlatformConfiguration() + if VZGenericPlatformConfiguration.isNestedVirtualizationSupported { + platform.isNestedVirtualizationEnabled = self.nestedVirtualization + } + config.platform = platform + + #endif + + try config.validate() + return config + } + + func mountAttachments() throws -> [AttachedFilesystem] { + let allocator = Character.blockDeviceTagAllocator() + if let initialFilesystem { + // When the initial filesystem is a blk, allocate the first letter "vd(a)" + // as that is what this blk will be attached under. + if initialFilesystem.isBlock { + _ = try allocator.allocate() + } + } + + var attachments: [AttachedFilesystem] = [] + for mount in self.mounts { + attachments.append(try .init(mount: mount, allocator: allocator)) + } + return attachments + } +} + +extension Mount { + var isBlock: Bool { + type == "ext4" + } +} + +extension Kernel { + func linuxCommandline(initialFilesystem: Mount) -> String { + var args = self.commandLine.kernelArgs + + args.append("init=/sbin/vminitd") + // rootfs is always set as ro. + args.append("ro") + + switch initialFilesystem.type { + case "virtiofs": + args.append(contentsOf: [ + "rootfstype=virtiofs", + "root=rootfs", + ]) + case "ext4": + args.append(contentsOf: [ + "rootfstype=ext4", + "root=/dev/vda", + ]) + default: + fatalError("unsupported initfs filesystem \(initialFilesystem.type)") + } + + if self.commandLine.initArgs.count > 0 { + args.append("--") + args.append(contentsOf: self.commandLine.initArgs) + } + + return args.joined(separator: " ") + } +} + +public protocol VZInterface { + func device() throws -> VZVirtioNetworkDeviceConfiguration +} + +extension NATInterface: VZInterface { + public func device() throws -> VZVirtioNetworkDeviceConfiguration { + let config = VZVirtioNetworkDeviceConfiguration() + if let macAddress = self.macAddress { + guard let mac = VZMACAddress(string: macAddress) else { + throw ContainerizationError(.invalidArgument, message: "invalid mac address \(macAddress)") + } + config.macAddress = mac + } + config.attachment = VZNATNetworkDeviceAttachment() + return config + } +} + +#endif diff --git a/Sources/Containerization/VZVirtualMachineManager.swift b/Sources/Containerization/VZVirtualMachineManager.swift new file mode 100644 index 00000000..6f6c8497 --- /dev/null +++ b/Sources/Containerization/VZVirtualMachineManager.swift @@ -0,0 +1,71 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +#if os(macOS) +import ContainerizationError +import ContainerizationOCI +import Foundation +import Logging + +/// A virtualization.framework backed `VirtualMachineManager` implementation. +public struct VZVirtualMachineManager: VirtualMachineManager { + private let kernel: Kernel + private let bootlog: String? + private let initialFilesystem: Mount + private let logger: Logger? + + public init( + kernel: Kernel, + initialFilesystem: Mount, + bootlog: String?, + logger: Logger? = nil + ) { + self.kernel = kernel + self.bootlog = bootlog + self.initialFilesystem = initialFilesystem + self.logger = logger + } + + public func create(container: Container) throws -> any VirtualMachineInstance { + guard let c = container as? LinuxContainer else { + throw ContainerizationError( + .invalidArgument, + message: "provided container is not a LinuxContainer" + ) + } + + return try VZVirtualMachineInstance( + logger: self.logger, + with: { config in + config.cpus = container.cpus + config.memoryInBytes = container.memoryInBytes + + config.kernel = self.kernel + config.initialFilesystem = self.initialFilesystem + + config.interfaces = container.interfaces + if let bootlog { + config.bootlog = URL(filePath: bootlog) + } + config.gpu = c.gpu + config.rosetta = c.rosetta + config.nestedVirtualization = c.virtualization + + config.mounts = [c.rootfs] + c.mounts + }) + } +} +#endif diff --git a/Sources/Containerization/VirtualMachineAgent+Additions.swift b/Sources/Containerization/VirtualMachineAgent+Additions.swift new file mode 100644 index 00000000..2f566c38 --- /dev/null +++ b/Sources/Containerization/VirtualMachineAgent+Additions.swift @@ -0,0 +1,22 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +/// Protocol to conform to if your agent is capable of relaying unix domain socket +/// connections. +public protocol SocketRelayAgent { + func relaySocket(port: UInt32, configuration: UnixSocketConfiguration) async throws + func stopSocketRelay(configuration: UnixSocketConfiguration) async throws +} diff --git a/Sources/Containerization/VirtualMachineAgent.swift b/Sources/Containerization/VirtualMachineAgent.swift new file mode 100644 index 00000000..10ded654 --- /dev/null +++ b/Sources/Containerization/VirtualMachineAgent.swift @@ -0,0 +1,61 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationOCI +import Foundation + +/// A protocol for the agent running inside a virtual machine. If an operation isn't +/// supported the implementation MUST return a ContainerizationError with a code of +/// `.unsupported`. +public protocol VirtualMachineAgent: Sendable { + /// Perform a platform specific standard setup + /// of the runtime environment. + func standardSetup() async throws + /// Close any resources held by the agent. + func close() async throws + + // POSIX + func getenv(key: String) async throws -> String + func setenv(key: String, value: String) async throws + func mount(_ mount: ContainerizationOCI.Mount) async throws + func umount(path: String, flags: Int32) async throws + func mkdir(path: String, all: Bool, perms: UInt32) async throws + @discardableResult + func kill(pid: Int32, signal: Int32) async throws -> Int32 + + // Process lifecycle + func createProcess( + id: String, + containerID: String?, + stdinPort: UInt32?, + stdoutPort: UInt32?, + stderrPort: UInt32?, + configuration: ContainerizationOCI.Spec, + options: Data? + ) async throws + func startProcess(id: String, containerID: String?) async throws -> Int32 + func signalProcess(id: String, containerID: String?, signal: Int32) async throws + func resizeProcess(id: String, containerID: String?, columns: UInt32, rows: UInt32) async throws + func waitProcess(id: String, containerID: String?, timeoutInSeconds: Int64?) async throws -> Int32 + func deleteProcess(id: String, containerID: String?) async throws + + // Networking + func up(name: String) async throws + func down(name: String) async throws + func addressAdd(name: String, address: String) async throws + func routeAddDefault(name: String, gateway: String) async throws + func configureDNS(config: DNS, location: String) async throws +} diff --git a/Sources/Containerization/VirtualMachineInstance.swift b/Sources/Containerization/VirtualMachineInstance.swift new file mode 100644 index 00000000..4c9be15c --- /dev/null +++ b/Sources/Containerization/VirtualMachineInstance.swift @@ -0,0 +1,49 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +/// The runtime state of the virtual machine instance. +public enum VirtualMachineInstanceState: Sendable { + case starting + case running + case stopped + case stopping + case unknown +} + +/// A manager that can spawn and manage a virtual machine. +public protocol VirtualMachineInstance: Sendable { + associatedtype Agent: VirtualMachineAgent + + // The state of the virtual machine. + var state: VirtualMachineInstanceState { get } + + var mounts: [AttachedFilesystem] { get } + /// Dial the Agent. It's up the VirtualMachineInstance to determine + /// what port the agent is listening on. + func dialAgent() async throws -> Agent + /// Dial a vsock port in the guest. + func dial(_ port: UInt32) async throws -> FileHandle + /// Listen on a host vsock port. + func listen(_ port: UInt32) throws -> ConnectionStream + /// Stop listening on a vsock port. + func stopListen(_ port: UInt32) throws + /// Start the virtual machine. + func start() async throws + /// Stop the virtual machine. + func stop() async throws +} diff --git a/Sources/Containerization/VirtualMachineManager.swift b/Sources/Containerization/VirtualMachineManager.swift new file mode 100644 index 00000000..79f8ef94 --- /dev/null +++ b/Sources/Containerization/VirtualMachineManager.swift @@ -0,0 +1,20 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +/// A protocol to implement for virtual machine isolated containers. +public protocol VirtualMachineManager: Sendable { + func create(container: Container) throws -> any VirtualMachineInstance +} diff --git a/Sources/ContainerizationArchive/ArchiveError.swift b/Sources/ContainerizationArchive/ArchiveError.swift new file mode 100644 index 00000000..fdca7fac --- /dev/null +++ b/Sources/ContainerizationArchive/ArchiveError.swift @@ -0,0 +1,95 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import CArchive +import Foundation + +public enum ArchiveError: Error, CustomStringConvertible { + case unableToCreateArchive + case noUnderlyingArchive + case noArchiveInCallback + case noDelegateConfigured + case delegateFreedBeforeCallback + case unableToSetFormat(CInt, Format) + case unableToAddFilter(CInt, Filter) + case unableToWriteEntryHeader(CInt) + case unableToWriteData(CLong) + case unableToCloseArchive(CInt) + case unableToOpenArchive(CInt) + case unableToSetOption(CInt) + case failedToSetLocale(locales: [String]) + case failedToGetProperty(String, URLResourceKey) + case failedToDetectFilter + case failedToDetectFormat + case failedToExtractArchive(String) + + public var description: String { + switch self { + case .unableToCreateArchive: + return "Unable to create an archive." + case .noUnderlyingArchive: + return "No underlying archive was provided." + case .noArchiveInCallback: + return "No archive was provided in the callback." + case .noDelegateConfigured: + return "No delegate was configured." + case .delegateFreedBeforeCallback: + return "The delegate was freed before the callback was invoked." + case .unableToSetFormat(let code, let name): + return "Unable to set the archive format \(name), code \(code)" + case .unableToAddFilter(let code, let name): + return "Unable to set the archive filter \(name), code \(code)" + case .unableToWriteEntryHeader(let code): + return "Unable to write the entry header to the archive. Error code \(code)" + case .unableToWriteData(let code): + return "Unable to write data to the archive. Error code \(code)" + case .unableToCloseArchive(let code): + return "Unable to close the archive. Error code \(code)" + case .unableToOpenArchive(let code): + return "Unable to open the archive. Error code \(code)" + case .unableToSetOption(_): + return "Unable to set an option on the archive." + case .failedToSetLocale(let locales): + return "Failed to set locale to \(locales)" + case .failedToGetProperty(let path, let propertyName): + return "Failed to read property \(propertyName) from file at path \(path)" + case .failedToDetectFilter: + return "Failed to detect filter from archive." + case .failedToDetectFormat: + return "Failed to detect format from archive." + case .failedToExtractArchive(let reason): + return "Failed to extract archive: \(reason)" + } + } +} + +public struct LibArchiveError: Error { + public let source: ArchiveError + public let description: String +} + +func wrap(_ f: @autoclosure () -> CInt, _ e: (CInt) -> ArchiveError, underlying: OpaquePointer? = nil) throws { + let result = f() + guard result == ARCHIVE_OK else { + let error = e(result) + guard let underlying = underlying, + let description = archive_error_string(underlying).map(String.init(cString:)) + else { + throw error + } + throw LibArchiveError(source: error, description: description) + } +} diff --git a/Sources/ContainerizationArchive/ArchiveWriter.swift b/Sources/ContainerizationArchive/ArchiveWriter.swift new file mode 100644 index 00000000..8511f6ca --- /dev/null +++ b/Sources/ContainerizationArchive/ArchiveWriter.swift @@ -0,0 +1,309 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import CArchive +import Foundation + +public final class ArchiveWriter { + var underlying: OpaquePointer! + var delegate: ArchiveWriterDelegate? + + public init(configuration: ArchiveWriterConfiguration) throws { + // because for some bizarre reason, UTF8 paths won't work unless this process explicitly sets a locale like en_US.UTF-8 + try Self.attemptSetLocales(locales: configuration.locales) + + guard let underlying = archive_write_new() else { throw ArchiveError.unableToCreateArchive } + self.underlying = underlying + + try setFormat(configuration.format) + try addFilter(configuration.filter) + try setOptions(configuration.options) + } + + public convenience init(configuration: ArchiveWriterConfiguration, delegate: ArchiveWriterDelegate) throws { + try self.init(configuration: configuration) + self.delegate = delegate + try self.open() + } + + public func open(file: URL) throws { + guard let underlying = underlying else { throw ArchiveError.noUnderlyingArchive } + let res = archive_write_open_filename(underlying, file.path) + try wrap(res, ArchiveError.unableToOpenArchive, underlying: underlying) + } + + public func open(fileDescriptor: Int32) throws { + guard let underlying = underlying else { throw ArchiveError.noUnderlyingArchive } + let res = archive_write_open_fd(underlying, fileDescriptor) + try wrap(res, ArchiveError.unableToOpenArchive, underlying: underlying) + } + + public func finishEncoding() throws { + if let u = underlying { + let r = archive_free(u) + do { + try wrap(r, ArchiveError.unableToCloseArchive, underlying: underlying) + underlying = nil + } catch { + underlying = nil + throw error + } + } + } + + deinit { + if let u = underlying { + archive_free(u) + underlying = nil + } + } + + public static func attemptSetLocales(locales: [String]) throws { + for locale in locales { + if setlocale(LC_ALL, locale) != nil { + return + } + } + throw ArchiveError.failedToSetLocale(locales: locales) + } +} + +extension ArchiveWriter { + fileprivate func open() throws { + guard let underlying = underlying else { throw ArchiveError.noUnderlyingArchive } + // TODO: to be or not to be retained, that is the question + let pointerToSelf = Unmanaged.passUnretained(self).toOpaque() + + let res = archive_write_open2( + underlying, + pointerToSelf, + /// The open callback is invoked by archive_write_open(). It should return ARCHIVE_OK if the underlying file or data source is successfully opened. If the open fails, it should call archive_set_error() to register an error code and message and return ARCHIVE_FATAL. Please note that + /// if open fails, close is not called and resources must be freed inside the open callback or with the free callback. + { underlying, pointerToSelf in + do { + guard let pointerToSelf = pointerToSelf else { + throw ArchiveError.noArchiveInCallback + } + let archive: ArchiveWriter = Unmanaged.fromOpaque(pointerToSelf).takeUnretainedValue() + guard let delegate = archive.delegate else { + throw ArchiveError.noDelegateConfigured + } + try delegate.open(archive: archive) + return ARCHIVE_OK + } catch { + archive_set_error_wrapper(underlying, ARCHIVE_FATAL, "\(error)") + return ARCHIVE_FATAL + } + }, + /// The write callback is invoked whenever the library needs to write raw bytes to the archive. For correct blocking, each call to the write callback function should translate into a single write(2) system call. This is especially critical when writing archives to tape drives. On + /// success, the write callback should return the number of bytes actually written. On error, the callback should invoke archive_set_error() to register an error code and message and return -1. + { underlying, pointerToSelf, dataPointer, count in + do { + guard let pointerToSelf = pointerToSelf else { + throw ArchiveError.noArchiveInCallback + } + let archive: ArchiveWriter = Unmanaged.fromOpaque(pointerToSelf).takeUnretainedValue() + guard let delegate = archive.delegate else { + throw ArchiveError.noDelegateConfigured + } + return try delegate.write( + archive: archive, buffer: UnsafeRawBufferPointer(start: dataPointer, count: count)) + } catch { + archive_set_error_wrapper(underlying, ARCHIVE_FATAL, "\(error)") + return -1 + } + }, + /// The close callback is invoked by archive_close when the archive processing is complete. If the open callback fails, the close callback is not invoked. The callback should return ARCHIVE_OK on success. On failure, the callback should invoke archive_set_error() to register an + /// error code and message and return + { underlying, pointerToSelf in + do { + guard let pointerToSelf = pointerToSelf else { + throw ArchiveError.noArchiveInCallback + } + let archive: ArchiveWriter = Unmanaged.fromOpaque(pointerToSelf).takeUnretainedValue() + guard let delegate = archive.delegate else { + throw ArchiveError.noDelegateConfigured + } + try delegate.close(archive: archive) + return ARCHIVE_OK + } catch { + archive_set_error_wrapper(underlying, ARCHIVE_FATAL, "\(error)") + return ARCHIVE_FATAL + } + }, + /// The free callback is always invoked on archive_free. The return code of this callback is not processed. + { underlying, pointerToSelf in + do { + guard let pointerToSelf = pointerToSelf else { + throw ArchiveError.noArchiveInCallback + } + let archive: ArchiveWriter = Unmanaged.fromOpaque(pointerToSelf).takeUnretainedValue() + guard let delegate = archive.delegate else { + throw ArchiveError.noDelegateConfigured + } + delegate.free(archive: archive) + + // TODO: should we balance the Unmanaged refcount here? Need to test for leaks. + return ARCHIVE_OK + } catch { + archive_set_error_wrapper(underlying, ARCHIVE_FATAL, "\(error)") + return ARCHIVE_FATAL + } + } + ) + + try wrap(res, ArchiveError.unableToOpenArchive, underlying: underlying) + } +} + +public class ArchiveWriterTransaction { + private let writer: ArchiveWriter + + fileprivate init(writer: ArchiveWriter) { + self.writer = writer + } + + public func writeHeader(entry: WriteEntry) throws { + try writer.writeHeader(entry: entry) + } + + public func writeChunk(data: UnsafeRawBufferPointer) throws { + try writer.writeData(data: data) + } + + public func finish() throws { + try writer.finishEntry() + } +} + +extension ArchiveWriter { + public func makeTransactionWriter() -> ArchiveWriterTransaction { + ArchiveWriterTransaction(writer: self) + } + + public func writeEntry(entry: WriteEntry, data: Data) throws { + try data.withUnsafeBytes { bytes in + try writeEntry(entry: entry, data: bytes) + } + } + + public func writeEntry(entry: WriteEntry, data: UnsafeRawBufferPointer?) throws { + try writeHeader(entry: entry) + if let data = data { + try writeData(data: data) + } + try finishEntry() + } + + fileprivate func writeHeader(entry: WriteEntry) throws { + guard let underlying = self.underlying else { throw ArchiveError.noUnderlyingArchive } + + try wrap( + archive_write_header(underlying, entry.underlying), ArchiveError.unableToWriteEntryHeader, + underlying: underlying) + } + + fileprivate func finishEntry() throws { + guard let underlying = self.underlying else { throw ArchiveError.noUnderlyingArchive } + + archive_write_finish_entry(underlying) + } + + fileprivate func writeData(data: UnsafeRawBufferPointer) throws { + guard let underlying = self.underlying else { throw ArchiveError.noUnderlyingArchive } + + let result = archive_write_data(underlying, data.baseAddress, data.count) + guard result >= 0 else { + throw ArchiveError.unableToWriteData(result) + } + } +} + +extension ArchiveWriter { + /// Recursively archives the content of a directory. Regular files, symlinks and directories are added to the archive. + /// Note: Symlinks are added to the archive if both the source and target for the symlink are both contained in the top level directory. + public func archiveDirectory(_ dir: URL) throws { + let fm = FileManager.default + let resourceKeys = Set([ + .fileSizeKey, .fileResourceTypeKey, + .creationDateKey, .contentAccessDateKey, .contentModificationDateKey, .fileSecurityKey, + ]) + guard let directoryEnumerator = fm.enumerator(at: dir, includingPropertiesForKeys: Array(resourceKeys), options: .producesRelativePathURLs) else { + throw POSIXError(.ENOTDIR) + } + for case let fileURL as URL in directoryEnumerator { + var mode = mode_t() + var uid = uid_t() + var gid = gid_t() + let resourceValues = try fileURL.resourceValues(forKeys: resourceKeys) + guard let type = resourceValues.fileResourceType else { + throw ArchiveError.failedToGetProperty(fileURL.path(), .fileResourceTypeKey) + } + let allowedTypes: [URLFileResourceType] = [.directory, .regular, .symbolicLink] + guard allowedTypes.contains(type) else { + continue + } + var size: Int64 = 0 + let entry = WriteEntry() + if type == .regular { + guard let _size = resourceValues.fileSize else { + throw ArchiveError.failedToGetProperty(fileURL.path(), .fileSizeKey) + } + size = Int64(_size) + } else if type == .symbolicLink { + let target = fileURL.resolvingSymlinksInPath().absoluteString + let root = dir.absoluteString + guard target.hasPrefix(root) else { + continue + } + let linkTarget = target.dropFirst(root.count + 1) + entry.symlinkTarget = String(linkTarget) + } + + guard let created = resourceValues.creationDate else { + throw ArchiveError.failedToGetProperty(fileURL.path(), .creationDateKey) + } + guard let access = resourceValues.contentAccessDate else { + throw ArchiveError.failedToGetProperty(fileURL.path(), .contentAccessDateKey) + } + guard let modified = resourceValues.contentModificationDate else { + throw ArchiveError.failedToGetProperty(fileURL.path(), .contentModificationDateKey) + } + guard let perms = resourceValues.fileSecurity else { + throw ArchiveError.failedToGetProperty(fileURL.path(), .fileSecurityKey) + } + CFFileSecurityGetMode(perms, &mode) + CFFileSecurityGetOwner(perms, &uid) + CFFileSecurityGetGroup(perms, &gid) + entry.path = fileURL.relativePath + entry.size = size + entry.creationDate = created + entry.modificationDate = modified + entry.contentAccessDate = access + entry.fileType = type + entry.group = gid + entry.owner = uid + entry.permissions = mode + if type == .regular { + let p = dir.appending(path: fileURL.relativePath) + let data = try Data(contentsOf: p, options: .uncached) + try self.writeEntry(entry: entry, data: data) + } else { + try self.writeHeader(entry: entry) + } + } + } +} diff --git a/Sources/ContainerizationArchive/ArchiveWriterConfiguration.swift b/Sources/ContainerizationArchive/ArchiveWriterConfiguration.swift new file mode 100644 index 00000000..f730f1c8 --- /dev/null +++ b/Sources/ContainerizationArchive/ArchiveWriterConfiguration.swift @@ -0,0 +1,182 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import CArchive + +public struct ArchiveWriterConfiguration { + public var format: Format + public var filter: Filter + public var options: [Options] + public var locales: [String] + + public init( + format: Format, filter: Filter, options: [Options] = [], locales: [String] = ["en_US.UTF-8", "C.UTF-8"] + ) { + self.format = format + self.filter = filter + self.options = options + self.locales = locales + } +} + +extension ArchiveWriter { + func setFormat(_ format: Format) throws { + guard let underlying = self.underlying else { throw ArchiveError.noUnderlyingArchive } + let r = archive_write_set_format(underlying, format.code) + guard r == ARCHIVE_OK else { throw ArchiveError.unableToSetFormat(r, format) } + } + + func addFilter(_ filter: Filter) throws { + guard let underlying = self.underlying else { throw ArchiveError.noUnderlyingArchive } + let r = archive_write_add_filter(underlying, filter.code) + guard r == ARCHIVE_OK else { throw ArchiveError.unableToAddFilter(r, filter) } + } + + func setOptions(_ options: [Options]) throws { + try options.forEach { + switch $0 { + case .compressionLevel(let level): + try wrap( + archive_write_set_option(underlying, nil, "compression-level", "\(level)"), + ArchiveError.unableToSetOption, underlying: self.underlying) + case .compression(.store): + try wrap( + archive_write_set_option(underlying, nil, "compression", "store"), ArchiveError.unableToSetOption, + underlying: self.underlying) + case .compression(.deflate): + try wrap( + archive_write_set_option(underlying, nil, "compression", "deflate"), ArchiveError.unableToSetOption, + underlying: self.underlying) + case .xattrformat(let value): + let v = value.description + try wrap( + archive_write_set_option(underlying, nil, "xattrheader", v), ArchiveError.unableToSetOption, + underlying: self.underlying) + } + } + } +} + +public enum Options { + case compressionLevel(UInt32) + case compression(Compression) + case xattrformat(XattrFormat) + + public enum Compression { + case store + case deflate + } + + public enum XattrFormat: String, CustomStringConvertible { + case schily + case libarchive + case all + + public var description: String { + switch self { + case .libarchive: + return "LIBARCHIVE" + case .schily: + return "SCHILY" + case .all: + return "ALL" + } + } + } +} + +public enum Format: String, Sendable { + /// POSIX-standard `ustar` archives + case ustar + case gnutar + /// POSIX `pax interchange format` archives + case pax + case paxRestricted + /// POSIX octet-oriented cpio archives + case cpio + case cpioNewc + /// Zip archive + case zip + /// two different variants of shar archives + case shar + case sharDump + /// ISO9660 CD images + case iso9660 + /// 7-Zip archives + case sevenZip + /// ar archives + case arBSD + case arGNU + /// mtree file tree descriptions + case mtree + /// XAR archives + case xar + + var code: CInt { + switch self { + case .ustar: return ARCHIVE_FORMAT_TAR_USTAR + case .pax: return ARCHIVE_FORMAT_TAR_PAX_INTERCHANGE + case .paxRestricted: return ARCHIVE_FORMAT_TAR_PAX_RESTRICTED + case .gnutar: return ARCHIVE_FORMAT_TAR_GNUTAR + case .cpio: return ARCHIVE_FORMAT_CPIO_POSIX + case .cpioNewc: return ARCHIVE_FORMAT_CPIO_AFIO_LARGE + case .zip: return ARCHIVE_FORMAT_ZIP + case .shar: return ARCHIVE_FORMAT_SHAR_BASE + case .sharDump: return ARCHIVE_FORMAT_SHAR_DUMP + case .iso9660: return ARCHIVE_FORMAT_ISO9660 + case .sevenZip: return ARCHIVE_FORMAT_7ZIP + case .arBSD: return ARCHIVE_FORMAT_AR_BSD + case .arGNU: return ARCHIVE_FORMAT_AR_GNU + case .mtree: return ARCHIVE_FORMAT_MTREE + case .xar: return ARCHIVE_FORMAT_XAR + } + } +} + +/// A filter (compression / encoding) to use when writing. +public enum Filter: String, Sendable { + case none + case gzip + case bzip2 + case compress + case lzma + case xz + case uu + case rpm + case lzip + case lrzip + case lzop + case grzip + case lz4 + + var code: CInt { + switch self { + case .none: return ARCHIVE_FILTER_NONE + case .gzip: return ARCHIVE_FILTER_GZIP + case .bzip2: return ARCHIVE_FILTER_BZIP2 + case .compress: return ARCHIVE_FILTER_COMPRESS + case .lzma: return ARCHIVE_FILTER_LZMA + case .xz: return ARCHIVE_FILTER_XZ + case .uu: return ARCHIVE_FILTER_UU + case .rpm: return ARCHIVE_FILTER_RPM + case .lzip: return ARCHIVE_FILTER_LZIP + case .lrzip: return ARCHIVE_FILTER_LRZIP + case .lzop: return ARCHIVE_FILTER_LZOP + case .grzip: return ARCHIVE_FILTER_GRZIP + case .lz4: return ARCHIVE_FILTER_LZ4 + } + } +} diff --git a/Sources/ContainerizationArchive/ArchiveWriterDelegate.swift b/Sources/ContainerizationArchive/ArchiveWriterDelegate.swift new file mode 100644 index 00000000..d4d782c7 --- /dev/null +++ b/Sources/ContainerizationArchive/ArchiveWriterDelegate.swift @@ -0,0 +1,30 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import CArchive + +public protocol ArchiveWriterDelegate: AnyObject { + /// The open callback is invoked by archive_write_open(). It should return ARCHIVE_OK if the underlying file or data source is successfully opened. If the open fails, it should call archive_set_error() to register an error code and message and return ARCHIVE_FATAL. Please note that + /// if open fails, close is not called and resources must be freed inside the open callback or with the free callback. + func open(archive: ArchiveWriter) throws + /// returns number of bytes written + func write(archive: ArchiveWriter, buffer: UnsafeRawBufferPointer) throws -> Int + /// The close callback is invoked by archive_close when the archive processing is complete. If the open callback fails, the close callback is not invoked. The callback should return ARCHIVE_OK on success. On failure, the callback should invoke archive_set_error() to register an + /// error code and message and return + func close(archive: ArchiveWriter) throws + /// The free callback is always invoked on archive_free. The return code of this callback is not processed. + func free(archive: ArchiveWriter) +} diff --git a/Sources/ContainerizationArchive/CArchive/COPYING b/Sources/ContainerizationArchive/CArchive/COPYING new file mode 100644 index 00000000..1b972357 --- /dev/null +++ b/Sources/ContainerizationArchive/CArchive/COPYING @@ -0,0 +1,65 @@ +The libarchive distribution as a whole is Copyright by Tim Kientzle +and is subject to the copyright notice reproduced at the bottom of +this file. + +Each individual file in this distribution should have a clear +copyright/licensing statement at the beginning of the file. If any do +not, please let me know and I will rectify it. The following is +intended to summarize the copyright status of the individual files; +the actual statements in the files are controlling. + +* Except as listed below, all C sources (including .c and .h files) + and documentation files are subject to the copyright notice reproduced + at the bottom of this file. + +* The following source files are also subject in whole or in part to + a 3-clause UC Regents copyright; please read the individual source + files for details: + libarchive/archive_read_support_filter_compress.c + libarchive/archive_write_add_filter_compress.c + libarchive/mtree.5 + +* The following source files are in the public domain: + libarchive/archive_getdate.c + +* The following source files are triple-licensed with the ability to choose + from CC0 1.0 Universal, OpenSSL or Apache 2.0 licenses: + libarchive/archive_blake2.h + libarchive/archive_blake2_impl.h + libarchive/archive_blake2s_ref.c + libarchive/archive_blake2sp_ref.c + +* The build files---including Makefiles, configure scripts, + and auxiliary scripts used as part of the compile process---have + widely varying licensing terms. Please check individual files before + distributing them to see if those restrictions apply to you. + +I intend for all new source code to use the license below and hope over +time to replace code with other licenses with new implementations that +do use the license below. The varying licensing of the build scripts +seems to be an unavoidable mess. + + +Copyright (c) 2003-2018 +All rights reserved. + +Redistribution and use in source and binary forms, with or without +modification, are permitted provided that the following conditions +are met: +1. Redistributions of source code must retain the above copyright + notice, this list of conditions and the following disclaimer + in this position and unchanged. +2. Redistributions in binary form must reproduce the above copyright + notice, this list of conditions and the following disclaimer in the + documentation and/or other materials provided with the distribution. + +THIS SOFTWARE IS PROVIDED BY THE AUTHOR(S) ``AS IS'' AND ANY EXPRESS OR +IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES +OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. +IN NO EVENT SHALL THE AUTHOR(S) BE LIABLE FOR ANY DIRECT, INDIRECT, +INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT +NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, +DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY +THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT +(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF +THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. diff --git a/Sources/ContainerizationArchive/CArchive/archive_swift_bridge.c b/Sources/ContainerizationArchive/CArchive/archive_swift_bridge.c new file mode 100644 index 00000000..33568692 --- /dev/null +++ b/Sources/ContainerizationArchive/CArchive/archive_swift_bridge.c @@ -0,0 +1,21 @@ +/* + * Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * https://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +#include "archive_bridge.h" + +void archive_set_error_wrapper(struct archive *a, int error_number, const char *error_string) { + archive_set_error(a, error_number, "%s", error_string); +} diff --git a/Sources/ContainerizationArchive/CArchive/include/archive.h b/Sources/ContainerizationArchive/CArchive/include/archive.h new file mode 100644 index 00000000..5b65475f --- /dev/null +++ b/Sources/ContainerizationArchive/CArchive/include/archive.h @@ -0,0 +1,1214 @@ +/*- + * Copyright (c) 2003-2010 Tim Kientzle + * All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR(S) ``AS IS'' AND ANY EXPRESS OR + * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES + * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. + * IN NO EVENT SHALL THE AUTHOR(S) BE LIABLE FOR ANY DIRECT, INDIRECT, + * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT + * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, + * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY + * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT + * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF + * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + */ + +#ifndef ARCHIVE_H_INCLUDED +#define ARCHIVE_H_INCLUDED + +/* + * The version number is expressed as a single integer that makes it + * easy to compare versions at build time: for version a.b.c, the + * version number is printf("%d%03d%03d",a,b,c). For example, if you + * know your application requires version 2.12.108 or later, you can + * assert that ARCHIVE_VERSION_NUMBER >= 2012108. + */ +/* Note: Compiler will complain if this does not match archive_entry.h! */ +#define ARCHIVE_VERSION_NUMBER 3007007 + +#include +#include /* for wchar_t */ +#include /* For FILE * */ +#include /* For time_t */ + +/* + * Note: archive.h is for use outside of libarchive; the configuration + * headers (config.h, archive_platform.h, etc.) are purely internal. + * Do NOT use HAVE_XXX configuration macros to control the behavior of + * this header! If you must conditionalize, use predefined compiler and/or + * platform macros. + */ +#if defined(__BORLANDC__) && __BORLANDC__ >= 0x560 +# include +#elif !defined(__WATCOMC__) && !defined(_MSC_VER) && !defined(__INTERIX) && !defined(__BORLANDC__) && !defined(_SCO_DS) && !defined(__osf__) && !defined(__CLANG_INTTYPES_H) +# include +#endif + +/* Get appropriate definitions of 64-bit integer */ +#if !defined(__LA_INT64_T_DEFINED) +/* Older code relied on the __LA_INT64_T macro; after 4.0 we'll switch to the typedef exclusively. */ +# if ARCHIVE_VERSION_NUMBER < 4000000 +#define __LA_INT64_T la_int64_t +# endif +#define __LA_INT64_T_DEFINED +# if defined(_WIN32) && !defined(__CYGWIN__) && !defined(__WATCOMC__) +typedef __int64 la_int64_t; +# else +# include /* ssize_t */ +# if defined(_SCO_DS) || defined(__osf__) +typedef long long la_int64_t; +# else +typedef int64_t la_int64_t; +# endif +# endif +#endif + +/* The la_ssize_t should match the type used in 'struct stat' */ +#if !defined(__LA_SSIZE_T_DEFINED) +/* Older code relied on the __LA_SSIZE_T macro; after 4.0 we'll switch to the typedef exclusively. */ +# if ARCHIVE_VERSION_NUMBER < 4000000 +#define __LA_SSIZE_T la_ssize_t +# endif +#define __LA_SSIZE_T_DEFINED +# if defined(_WIN32) && !defined(__CYGWIN__) && !defined(__WATCOMC__) +# if defined(_SSIZE_T_DEFINED) || defined(_SSIZE_T_) +typedef ssize_t la_ssize_t; +# elif defined(_WIN64) +typedef __int64 la_ssize_t; +# else +typedef long la_ssize_t; +# endif +# else +# include /* ssize_t */ +typedef ssize_t la_ssize_t; +# endif +#endif + +/* Large file support for Android */ +#if defined(__LIBARCHIVE_BUILD) && defined(__ANDROID__) +#include "android_lf.h" +#endif + +/* + * On Windows, define LIBARCHIVE_STATIC if you're building or using a + * .lib. The default here assumes you're building a DLL. Only + * libarchive source should ever define __LIBARCHIVE_BUILD. + */ +#if ((defined __WIN32__) || (defined _WIN32) || defined(__CYGWIN__)) && (!defined LIBARCHIVE_STATIC) +# ifdef __LIBARCHIVE_BUILD +# ifdef __GNUC__ +# define __LA_DECL __attribute__((dllexport)) extern +# else +# define __LA_DECL __declspec(dllexport) +# endif +# else +# ifdef __GNUC__ +# define __LA_DECL +# else +# define __LA_DECL __declspec(dllimport) +# endif +# endif +#elif defined __LIBARCHIVE_ENABLE_VISIBILITY +# define __LA_DECL __attribute__((visibility("default"))) +#else +/* Static libraries or non-Windows needs no special declaration. */ +# define __LA_DECL +#endif + +#if defined(__GNUC__) && __GNUC__ >= 3 && !defined(__MINGW32__) +#define __LA_PRINTF(fmtarg, firstvararg) \ + __attribute__((__format__ (__printf__, fmtarg, firstvararg))) +#else +#define __LA_PRINTF(fmtarg, firstvararg) /* nothing */ +#endif + +#if defined(__GNUC__) && __GNUC__ >= 3 && __GNUC_MINOR__ >= 1 +# define __LA_DEPRECATED __attribute__((deprecated)) +#else +# define __LA_DEPRECATED +#endif + +#ifdef __cplusplus +extern "C" { +#endif + +/* + * The version number is provided as both a macro and a function. + * The macro identifies the installed header; the function identifies + * the library version (which may not be the same if you're using a + * dynamically-linked version of the library). Of course, if the + * header and library are very different, you should expect some + * strangeness. Don't do that. + */ +__LA_DECL int archive_version_number(void); + +/* + * Textual name/version of the library, useful for version displays. + */ +#define ARCHIVE_VERSION_ONLY_STRING "3.7.7" +#define ARCHIVE_VERSION_STRING "libarchive " ARCHIVE_VERSION_ONLY_STRING +__LA_DECL const char * archive_version_string(void); + +/* + * Detailed textual name/version of the library and its dependencies. + * This has the form: + * "libarchive x.y.z zlib/a.b.c liblzma/d.e.f ... etc ..." + * the list of libraries described here will vary depending on how + * libarchive was compiled. + */ +__LA_DECL const char * archive_version_details(void); + +/* + * Returns NULL if libarchive was compiled without the associated library. + * Otherwise, returns the version number that libarchive was compiled + * against. + */ +__LA_DECL const char * archive_zlib_version(void); +__LA_DECL const char * archive_liblzma_version(void); +__LA_DECL const char * archive_bzlib_version(void); +__LA_DECL const char * archive_liblz4_version(void); +__LA_DECL const char * archive_libzstd_version(void); + +/* Declare our basic types. */ +struct archive; +struct archive_entry; + +/* + * Error codes: Use archive_errno() and archive_error_string() + * to retrieve details. Unless specified otherwise, all functions + * that return 'int' use these codes. + */ +#define ARCHIVE_EOF 1 /* Found end of archive. */ +#define ARCHIVE_OK 0 /* Operation was successful. */ +#define ARCHIVE_RETRY (-10) /* Retry might succeed. */ +#define ARCHIVE_WARN (-20) /* Partial success. */ +/* For example, if write_header "fails", then you can't push data. */ +#define ARCHIVE_FAILED (-25) /* Current operation cannot complete. */ +/* But if write_header is "fatal," then this archive is dead and useless. */ +#define ARCHIVE_FATAL (-30) /* No more operations are possible. */ + +/* + * As far as possible, archive_errno returns standard platform errno codes. + * Of course, the details vary by platform, so the actual definitions + * here are stored in "archive_platform.h". The symbols are listed here + * for reference; as a rule, clients should not need to know the exact + * platform-dependent error code. + */ +/* Unrecognized or invalid file format. */ +/* #define ARCHIVE_ERRNO_FILE_FORMAT */ +/* Illegal usage of the library. */ +/* #define ARCHIVE_ERRNO_PROGRAMMER_ERROR */ +/* Unknown or unclassified error. */ +/* #define ARCHIVE_ERRNO_MISC */ + +/* + * Callbacks are invoked to automatically read/skip/write/open/close the + * archive. You can provide your own for complex tasks (like breaking + * archives across multiple tapes) or use standard ones built into the + * library. + */ + +/* Returns pointer and size of next block of data from archive. */ +typedef la_ssize_t archive_read_callback(struct archive *, + void *_client_data, const void **_buffer); + +/* Skips at most request bytes from archive and returns the skipped amount. + * This may skip fewer bytes than requested; it may even skip zero bytes. + * If you do skip fewer bytes than requested, libarchive will invoke your + * read callback and discard data as necessary to make up the full skip. + */ +typedef la_int64_t archive_skip_callback(struct archive *, + void *_client_data, la_int64_t request); + +/* Seeks to specified location in the file and returns the position. + * Whence values are SEEK_SET, SEEK_CUR, SEEK_END from stdio.h. + * Return ARCHIVE_FATAL if the seek fails for any reason. + */ +typedef la_int64_t archive_seek_callback(struct archive *, + void *_client_data, la_int64_t offset, int whence); + +/* Returns size actually written, zero on EOF, -1 on error. */ +typedef la_ssize_t archive_write_callback(struct archive *, + void *_client_data, + const void *_buffer, size_t _length); + +typedef int archive_open_callback(struct archive *, void *_client_data); + +typedef int archive_close_callback(struct archive *, void *_client_data); + +typedef int archive_free_callback(struct archive *, void *_client_data); + +/* Switches from one client data object to the next/prev client data object. + * This is useful for reading from different data blocks such as a set of files + * that make up one large file. + */ +typedef int archive_switch_callback(struct archive *, void *_client_data1, + void *_client_data2); + +/* + * Returns a passphrase used for encryption or decryption, NULL on nothing + * to do and give it up. + */ +typedef const char *archive_passphrase_callback(struct archive *, + void *_client_data); + +/* + * Codes to identify various stream filters. + */ +#define ARCHIVE_FILTER_NONE 0 +#define ARCHIVE_FILTER_GZIP 1 +#define ARCHIVE_FILTER_BZIP2 2 +#define ARCHIVE_FILTER_COMPRESS 3 +#define ARCHIVE_FILTER_PROGRAM 4 +#define ARCHIVE_FILTER_LZMA 5 +#define ARCHIVE_FILTER_XZ 6 +#define ARCHIVE_FILTER_UU 7 +#define ARCHIVE_FILTER_RPM 8 +#define ARCHIVE_FILTER_LZIP 9 +#define ARCHIVE_FILTER_LRZIP 10 +#define ARCHIVE_FILTER_LZOP 11 +#define ARCHIVE_FILTER_GRZIP 12 +#define ARCHIVE_FILTER_LZ4 13 +#define ARCHIVE_FILTER_ZSTD 14 + +#if ARCHIVE_VERSION_NUMBER < 4000000 +#define ARCHIVE_COMPRESSION_NONE ARCHIVE_FILTER_NONE +#define ARCHIVE_COMPRESSION_GZIP ARCHIVE_FILTER_GZIP +#define ARCHIVE_COMPRESSION_BZIP2 ARCHIVE_FILTER_BZIP2 +#define ARCHIVE_COMPRESSION_COMPRESS ARCHIVE_FILTER_COMPRESS +#define ARCHIVE_COMPRESSION_PROGRAM ARCHIVE_FILTER_PROGRAM +#define ARCHIVE_COMPRESSION_LZMA ARCHIVE_FILTER_LZMA +#define ARCHIVE_COMPRESSION_XZ ARCHIVE_FILTER_XZ +#define ARCHIVE_COMPRESSION_UU ARCHIVE_FILTER_UU +#define ARCHIVE_COMPRESSION_RPM ARCHIVE_FILTER_RPM +#define ARCHIVE_COMPRESSION_LZIP ARCHIVE_FILTER_LZIP +#define ARCHIVE_COMPRESSION_LRZIP ARCHIVE_FILTER_LRZIP +#endif + +/* + * Codes returned by archive_format. + * + * Top 16 bits identifies the format family (e.g., "tar"); lower + * 16 bits indicate the variant. This is updated by read_next_header. + * Note that the lower 16 bits will often vary from entry to entry. + * In some cases, this variation occurs as libarchive learns more about + * the archive (for example, later entries might utilize extensions that + * weren't necessary earlier in the archive; in this case, libarchive + * will change the format code to indicate the extended format that + * was used). In other cases, it's because different tools have + * modified the archive and so different parts of the archive + * actually have slightly different formats. (Both tar and cpio store + * format codes in each entry, so it is quite possible for each + * entry to be in a different format.) + */ +#define ARCHIVE_FORMAT_BASE_MASK 0xff0000 +#define ARCHIVE_FORMAT_CPIO 0x10000 +#define ARCHIVE_FORMAT_CPIO_POSIX (ARCHIVE_FORMAT_CPIO | 1) +#define ARCHIVE_FORMAT_CPIO_BIN_LE (ARCHIVE_FORMAT_CPIO | 2) +#define ARCHIVE_FORMAT_CPIO_BIN_BE (ARCHIVE_FORMAT_CPIO | 3) +#define ARCHIVE_FORMAT_CPIO_SVR4_NOCRC (ARCHIVE_FORMAT_CPIO | 4) +#define ARCHIVE_FORMAT_CPIO_SVR4_CRC (ARCHIVE_FORMAT_CPIO | 5) +#define ARCHIVE_FORMAT_CPIO_AFIO_LARGE (ARCHIVE_FORMAT_CPIO | 6) +#define ARCHIVE_FORMAT_CPIO_PWB (ARCHIVE_FORMAT_CPIO | 7) +#define ARCHIVE_FORMAT_SHAR 0x20000 +#define ARCHIVE_FORMAT_SHAR_BASE (ARCHIVE_FORMAT_SHAR | 1) +#define ARCHIVE_FORMAT_SHAR_DUMP (ARCHIVE_FORMAT_SHAR | 2) +#define ARCHIVE_FORMAT_TAR 0x30000 +#define ARCHIVE_FORMAT_TAR_USTAR (ARCHIVE_FORMAT_TAR | 1) +#define ARCHIVE_FORMAT_TAR_PAX_INTERCHANGE (ARCHIVE_FORMAT_TAR | 2) +#define ARCHIVE_FORMAT_TAR_PAX_RESTRICTED (ARCHIVE_FORMAT_TAR | 3) +#define ARCHIVE_FORMAT_TAR_GNUTAR (ARCHIVE_FORMAT_TAR | 4) +#define ARCHIVE_FORMAT_ISO9660 0x40000 +#define ARCHIVE_FORMAT_ISO9660_ROCKRIDGE (ARCHIVE_FORMAT_ISO9660 | 1) +#define ARCHIVE_FORMAT_ZIP 0x50000 +#define ARCHIVE_FORMAT_EMPTY 0x60000 +#define ARCHIVE_FORMAT_AR 0x70000 +#define ARCHIVE_FORMAT_AR_GNU (ARCHIVE_FORMAT_AR | 1) +#define ARCHIVE_FORMAT_AR_BSD (ARCHIVE_FORMAT_AR | 2) +#define ARCHIVE_FORMAT_MTREE 0x80000 +#define ARCHIVE_FORMAT_RAW 0x90000 +#define ARCHIVE_FORMAT_XAR 0xA0000 +#define ARCHIVE_FORMAT_LHA 0xB0000 +#define ARCHIVE_FORMAT_CAB 0xC0000 +#define ARCHIVE_FORMAT_RAR 0xD0000 +#define ARCHIVE_FORMAT_7ZIP 0xE0000 +#define ARCHIVE_FORMAT_WARC 0xF0000 +#define ARCHIVE_FORMAT_RAR_V5 0x100000 + +/* + * Codes returned by archive_read_format_capabilities(). + * + * This list can be extended with values between 0 and 0xffff. + * The original purpose of this list was to let different archive + * format readers expose their general capabilities in terms of + * encryption. + */ +#define ARCHIVE_READ_FORMAT_CAPS_NONE (0) /* no special capabilities */ +#define ARCHIVE_READ_FORMAT_CAPS_ENCRYPT_DATA (1<<0) /* reader can detect encrypted data */ +#define ARCHIVE_READ_FORMAT_CAPS_ENCRYPT_METADATA (1<<1) /* reader can detect encryptable metadata (pathname, mtime, etc.) */ + +/* + * Codes returned by archive_read_has_encrypted_entries(). + * + * In case the archive does not support encryption detection at all + * ARCHIVE_READ_FORMAT_ENCRYPTION_UNSUPPORTED is returned. If the reader + * for some other reason (e.g. not enough bytes read) cannot say if + * there are encrypted entries, ARCHIVE_READ_FORMAT_ENCRYPTION_DONT_KNOW + * is returned. + */ +#define ARCHIVE_READ_FORMAT_ENCRYPTION_UNSUPPORTED -2 +#define ARCHIVE_READ_FORMAT_ENCRYPTION_DONT_KNOW -1 + +/*- + * Basic outline for reading an archive: + * 1) Ask archive_read_new for an archive reader object. + * 2) Update any global properties as appropriate. + * In particular, you'll certainly want to call appropriate + * archive_read_support_XXX functions. + * 3) Call archive_read_open_XXX to open the archive + * 4) Repeatedly call archive_read_next_header to get information about + * successive archive entries. Call archive_read_data to extract + * data for entries of interest. + * 5) Call archive_read_free to end processing. + */ +__LA_DECL struct archive *archive_read_new(void); + +/* + * The archive_read_support_XXX calls enable auto-detect for this + * archive handle. They also link in the necessary support code. + * For example, if you don't want bzlib linked in, don't invoke + * support_compression_bzip2(). The "all" functions provide the + * obvious shorthand. + */ + +#if ARCHIVE_VERSION_NUMBER < 4000000 +__LA_DECL int archive_read_support_compression_all(struct archive *) + __LA_DEPRECATED; +__LA_DECL int archive_read_support_compression_bzip2(struct archive *) + __LA_DEPRECATED; +__LA_DECL int archive_read_support_compression_compress(struct archive *) + __LA_DEPRECATED; +__LA_DECL int archive_read_support_compression_gzip(struct archive *) + __LA_DEPRECATED; +__LA_DECL int archive_read_support_compression_lzip(struct archive *) + __LA_DEPRECATED; +__LA_DECL int archive_read_support_compression_lzma(struct archive *) + __LA_DEPRECATED; +__LA_DECL int archive_read_support_compression_none(struct archive *) + __LA_DEPRECATED; +__LA_DECL int archive_read_support_compression_program(struct archive *, + const char *command) __LA_DEPRECATED; +__LA_DECL int archive_read_support_compression_program_signature + (struct archive *, const char *, + const void * /* match */, size_t) __LA_DEPRECATED; + +__LA_DECL int archive_read_support_compression_rpm(struct archive *) + __LA_DEPRECATED; +__LA_DECL int archive_read_support_compression_uu(struct archive *) + __LA_DEPRECATED; +__LA_DECL int archive_read_support_compression_xz(struct archive *) + __LA_DEPRECATED; +#endif + +__LA_DECL int archive_read_support_filter_all(struct archive *); +__LA_DECL int archive_read_support_filter_by_code(struct archive *, int); +__LA_DECL int archive_read_support_filter_bzip2(struct archive *); +__LA_DECL int archive_read_support_filter_compress(struct archive *); +__LA_DECL int archive_read_support_filter_gzip(struct archive *); +__LA_DECL int archive_read_support_filter_grzip(struct archive *); +__LA_DECL int archive_read_support_filter_lrzip(struct archive *); +__LA_DECL int archive_read_support_filter_lz4(struct archive *); +__LA_DECL int archive_read_support_filter_lzip(struct archive *); +__LA_DECL int archive_read_support_filter_lzma(struct archive *); +__LA_DECL int archive_read_support_filter_lzop(struct archive *); +__LA_DECL int archive_read_support_filter_none(struct archive *); +__LA_DECL int archive_read_support_filter_program(struct archive *, + const char *command); +__LA_DECL int archive_read_support_filter_program_signature + (struct archive *, const char * /* cmd */, + const void * /* match */, size_t); +__LA_DECL int archive_read_support_filter_rpm(struct archive *); +__LA_DECL int archive_read_support_filter_uu(struct archive *); +__LA_DECL int archive_read_support_filter_xz(struct archive *); +__LA_DECL int archive_read_support_filter_zstd(struct archive *); + +__LA_DECL int archive_read_support_format_7zip(struct archive *); +__LA_DECL int archive_read_support_format_all(struct archive *); +__LA_DECL int archive_read_support_format_ar(struct archive *); +__LA_DECL int archive_read_support_format_by_code(struct archive *, int); +__LA_DECL int archive_read_support_format_cab(struct archive *); +__LA_DECL int archive_read_support_format_cpio(struct archive *); +__LA_DECL int archive_read_support_format_empty(struct archive *); +__LA_DECL int archive_read_support_format_gnutar(struct archive *); +__LA_DECL int archive_read_support_format_iso9660(struct archive *); +__LA_DECL int archive_read_support_format_lha(struct archive *); +__LA_DECL int archive_read_support_format_mtree(struct archive *); +__LA_DECL int archive_read_support_format_rar(struct archive *); +__LA_DECL int archive_read_support_format_rar5(struct archive *); +__LA_DECL int archive_read_support_format_raw(struct archive *); +__LA_DECL int archive_read_support_format_tar(struct archive *); +__LA_DECL int archive_read_support_format_warc(struct archive *); +__LA_DECL int archive_read_support_format_xar(struct archive *); +/* archive_read_support_format_zip() enables both streamable and seekable + * zip readers. */ +__LA_DECL int archive_read_support_format_zip(struct archive *); +/* Reads Zip archives as stream from beginning to end. Doesn't + * correctly handle SFX ZIP files or ZIP archives that have been modified + * in-place. */ +__LA_DECL int archive_read_support_format_zip_streamable(struct archive *); +/* Reads starting from central directory; requires seekable input. */ +__LA_DECL int archive_read_support_format_zip_seekable(struct archive *); + +/* Functions to manually set the format and filters to be used. This is + * useful to bypass the bidding process when the format and filters to use + * is known in advance. + */ +__LA_DECL int archive_read_set_format(struct archive *, int); +__LA_DECL int archive_read_append_filter(struct archive *, int); +__LA_DECL int archive_read_append_filter_program(struct archive *, + const char *); +__LA_DECL int archive_read_append_filter_program_signature + (struct archive *, const char *, const void * /* match */, size_t); + +/* Set various callbacks. */ +__LA_DECL int archive_read_set_open_callback(struct archive *, + archive_open_callback *); +__LA_DECL int archive_read_set_read_callback(struct archive *, + archive_read_callback *); +__LA_DECL int archive_read_set_seek_callback(struct archive *, + archive_seek_callback *); +__LA_DECL int archive_read_set_skip_callback(struct archive *, + archive_skip_callback *); +__LA_DECL int archive_read_set_close_callback(struct archive *, + archive_close_callback *); +/* Callback used to switch between one data object to the next */ +__LA_DECL int archive_read_set_switch_callback(struct archive *, + archive_switch_callback *); + +/* This sets the first data object. */ +__LA_DECL int archive_read_set_callback_data(struct archive *, void *); +/* This sets data object at specified index */ +__LA_DECL int archive_read_set_callback_data2(struct archive *, void *, + unsigned int); +/* This adds a data object at the specified index. */ +__LA_DECL int archive_read_add_callback_data(struct archive *, void *, + unsigned int); +/* This appends a data object to the end of list */ +__LA_DECL int archive_read_append_callback_data(struct archive *, void *); +/* This prepends a data object to the beginning of list */ +__LA_DECL int archive_read_prepend_callback_data(struct archive *, void *); + +/* Opening freezes the callbacks. */ +__LA_DECL int archive_read_open1(struct archive *); + +/* Convenience wrappers around the above. */ +__LA_DECL int archive_read_open(struct archive *, void *_client_data, + archive_open_callback *, archive_read_callback *, + archive_close_callback *); +__LA_DECL int archive_read_open2(struct archive *, void *_client_data, + archive_open_callback *, archive_read_callback *, + archive_skip_callback *, archive_close_callback *); + +/* + * A variety of shortcuts that invoke archive_read_open() with + * canned callbacks suitable for common situations. The ones that + * accept a block size handle tape blocking correctly. + */ +/* Use this if you know the filename. Note: NULL indicates stdin. */ +__LA_DECL int archive_read_open_filename(struct archive *, + const char *_filename, size_t _block_size); +/* Use this for reading multivolume files by filenames. + * NOTE: Must be NULL terminated. Sorting is NOT done. */ +__LA_DECL int archive_read_open_filenames(struct archive *, + const char **_filenames, size_t _block_size); +__LA_DECL int archive_read_open_filename_w(struct archive *, + const wchar_t *_filename, size_t _block_size); +#if defined(_WIN32) && !defined(__CYGWIN__) +__LA_DECL int archive_read_open_filenames_w(struct archive *, + const wchar_t **_filenames, size_t _block_size); +#endif +/* archive_read_open_file() is a deprecated synonym for ..._open_filename(). */ +__LA_DECL int archive_read_open_file(struct archive *, + const char *_filename, size_t _block_size) __LA_DEPRECATED; +/* Read an archive that's stored in memory. */ +__LA_DECL int archive_read_open_memory(struct archive *, + const void * buff, size_t size); +/* A more involved version that is only used for internal testing. */ +__LA_DECL int archive_read_open_memory2(struct archive *a, const void *buff, + size_t size, size_t read_size); +/* Read an archive that's already open, using the file descriptor. */ +__LA_DECL int archive_read_open_fd(struct archive *, int _fd, + size_t _block_size); +/* Read an archive that's already open, using a FILE *. */ +/* Note: DO NOT use this with tape drives. */ +__LA_DECL int archive_read_open_FILE(struct archive *, FILE *_file); + +/* Parses and returns next entry header. */ +__LA_DECL int archive_read_next_header(struct archive *, + struct archive_entry **); + +/* Parses and returns next entry header using the archive_entry passed in */ +__LA_DECL int archive_read_next_header2(struct archive *, + struct archive_entry *); + +/* + * Retrieve the byte offset in UNCOMPRESSED data where last-read + * header started. + */ +__LA_DECL la_int64_t archive_read_header_position(struct archive *); + +/* + * Returns 1 if the archive contains at least one encrypted entry. + * If the archive format not support encryption at all + * ARCHIVE_READ_FORMAT_ENCRYPTION_UNSUPPORTED is returned. + * If for any other reason (e.g. not enough data read so far) + * we cannot say whether there are encrypted entries, then + * ARCHIVE_READ_FORMAT_ENCRYPTION_DONT_KNOW is returned. + * In general, this function will return values below zero when the + * reader is uncertain or totally incapable of encryption support. + * When this function returns 0 you can be sure that the reader + * supports encryption detection but no encrypted entries have + * been found yet. + * + * NOTE: If the metadata/header of an archive is also encrypted, you + * cannot rely on the number of encrypted entries. That is why this + * function does not return the number of encrypted entries but# + * just shows that there are some. + */ +__LA_DECL int archive_read_has_encrypted_entries(struct archive *); + +/* + * Returns a bitmask of capabilities that are supported by the archive format reader. + * If the reader has no special capabilities, ARCHIVE_READ_FORMAT_CAPS_NONE is returned. + */ +__LA_DECL int archive_read_format_capabilities(struct archive *); + +/* Read data from the body of an entry. Similar to read(2). */ +__LA_DECL la_ssize_t archive_read_data(struct archive *, + void *, size_t); + +/* Seek within the body of an entry. Similar to lseek(2). */ +__LA_DECL la_int64_t archive_seek_data(struct archive *, la_int64_t, int); + +/* + * A zero-copy version of archive_read_data that also exposes the file offset + * of each returned block. Note that the client has no way to specify + * the desired size of the block. The API does guarantee that offsets will + * be strictly increasing and that returned blocks will not overlap. + */ +__LA_DECL int archive_read_data_block(struct archive *a, + const void **buff, size_t *size, la_int64_t *offset); + +/*- + * Some convenience functions that are built on archive_read_data: + * 'skip': skips entire entry + * 'into_buffer': writes data into memory buffer that you provide + * 'into_fd': writes data to specified filedes + */ +__LA_DECL int archive_read_data_skip(struct archive *); +__LA_DECL int archive_read_data_into_fd(struct archive *, int fd); + +/* + * Set read options. + */ +/* Apply option to the format only. */ +__LA_DECL int archive_read_set_format_option(struct archive *_a, + const char *m, const char *o, + const char *v); +/* Apply option to the filter only. */ +__LA_DECL int archive_read_set_filter_option(struct archive *_a, + const char *m, const char *o, + const char *v); +/* Apply option to both the format and the filter. */ +__LA_DECL int archive_read_set_option(struct archive *_a, + const char *m, const char *o, + const char *v); +/* Apply option string to both the format and the filter. */ +__LA_DECL int archive_read_set_options(struct archive *_a, + const char *opts); + +/* + * Add a decryption passphrase. + */ +__LA_DECL int archive_read_add_passphrase(struct archive *, const char *); +__LA_DECL int archive_read_set_passphrase_callback(struct archive *, + void *client_data, archive_passphrase_callback *); + + +/*- + * Convenience function to recreate the current entry (whose header + * has just been read) on disk. + * + * This does quite a bit more than just copy data to disk. It also: + * - Creates intermediate directories as required. + * - Manages directory permissions: non-writable directories will + * be initially created with write permission enabled; when the + * archive is closed, dir permissions are edited to the values specified + * in the archive. + * - Checks hardlinks: hardlinks will not be extracted unless the + * linked-to file was also extracted within the same session. (TODO) + */ + +/* The "flags" argument selects optional behavior, 'OR' the flags you want. */ + +/* Default: Do not try to set owner/group. */ +#define ARCHIVE_EXTRACT_OWNER (0x0001) +/* Default: Do obey umask, do not restore SUID/SGID/SVTX bits. */ +#define ARCHIVE_EXTRACT_PERM (0x0002) +/* Default: Do not restore mtime/atime. */ +#define ARCHIVE_EXTRACT_TIME (0x0004) +/* Default: Replace existing files. */ +#define ARCHIVE_EXTRACT_NO_OVERWRITE (0x0008) +/* Default: Try create first, unlink only if create fails with EEXIST. */ +#define ARCHIVE_EXTRACT_UNLINK (0x0010) +/* Default: Do not restore ACLs. */ +#define ARCHIVE_EXTRACT_ACL (0x0020) +/* Default: Do not restore fflags. */ +#define ARCHIVE_EXTRACT_FFLAGS (0x0040) +/* Default: Do not restore xattrs. */ +#define ARCHIVE_EXTRACT_XATTR (0x0080) +/* Default: Do not try to guard against extracts redirected by symlinks. */ +/* Note: With ARCHIVE_EXTRACT_UNLINK, will remove any intermediate symlink. */ +#define ARCHIVE_EXTRACT_SECURE_SYMLINKS (0x0100) +/* Default: Do not reject entries with '..' as path elements. */ +#define ARCHIVE_EXTRACT_SECURE_NODOTDOT (0x0200) +/* Default: Create parent directories as needed. */ +#define ARCHIVE_EXTRACT_NO_AUTODIR (0x0400) +/* Default: Overwrite files, even if one on disk is newer. */ +#define ARCHIVE_EXTRACT_NO_OVERWRITE_NEWER (0x0800) +/* Detect blocks of 0 and write holes instead. */ +#define ARCHIVE_EXTRACT_SPARSE (0x1000) +/* Default: Do not restore Mac extended metadata. */ +/* This has no effect except on Mac OS. */ +#define ARCHIVE_EXTRACT_MAC_METADATA (0x2000) +/* Default: Use HFS+ compression if it was compressed. */ +/* This has no effect except on Mac OS v10.6 or later. */ +#define ARCHIVE_EXTRACT_NO_HFS_COMPRESSION (0x4000) +/* Default: Do not use HFS+ compression if it was not compressed. */ +/* This has no effect except on Mac OS v10.6 or later. */ +#define ARCHIVE_EXTRACT_HFS_COMPRESSION_FORCED (0x8000) +/* Default: Do not reject entries with absolute paths */ +#define ARCHIVE_EXTRACT_SECURE_NOABSOLUTEPATHS (0x10000) +/* Default: Do not clear no-change flags when unlinking object */ +#define ARCHIVE_EXTRACT_CLEAR_NOCHANGE_FFLAGS (0x20000) +/* Default: Do not extract atomically (using rename) */ +#define ARCHIVE_EXTRACT_SAFE_WRITES (0x40000) + +__LA_DECL int archive_read_extract(struct archive *, struct archive_entry *, + int flags); +__LA_DECL int archive_read_extract2(struct archive *, struct archive_entry *, + struct archive * /* dest */); +__LA_DECL void archive_read_extract_set_progress_callback(struct archive *, + void (*_progress_func)(void *), void *_user_data); + +/* Record the dev/ino of a file that will not be written. This is + * generally set to the dev/ino of the archive being read. */ +__LA_DECL void archive_read_extract_set_skip_file(struct archive *, + la_int64_t, la_int64_t); + +/* Close the file and release most resources. */ +__LA_DECL int archive_read_close(struct archive *); +/* Release all resources and destroy the object. */ +/* Note that archive_read_free will call archive_read_close for you. */ +__LA_DECL int archive_read_free(struct archive *); +#if ARCHIVE_VERSION_NUMBER < 4000000 +/* Synonym for archive_read_free() for backwards compatibility. */ +__LA_DECL int archive_read_finish(struct archive *) __LA_DEPRECATED; +#endif + +/*- + * To create an archive: + * 1) Ask archive_write_new for an archive writer object. + * 2) Set any global properties. In particular, you should set + * the compression and format to use. + * 3) Call archive_write_open to open the file (most people + * will use archive_write_open_file or archive_write_open_fd, + * which provide convenient canned I/O callbacks for you). + * 4) For each entry: + * - construct an appropriate struct archive_entry structure + * - archive_write_header to write the header + * - archive_write_data to write the entry data + * 5) archive_write_close to close the output + * 6) archive_write_free to cleanup the writer and release resources + */ +__LA_DECL struct archive *archive_write_new(void); +__LA_DECL int archive_write_set_bytes_per_block(struct archive *, + int bytes_per_block); +__LA_DECL int archive_write_get_bytes_per_block(struct archive *); +/* XXX This is badly misnamed; suggestions appreciated. XXX */ +__LA_DECL int archive_write_set_bytes_in_last_block(struct archive *, + int bytes_in_last_block); +__LA_DECL int archive_write_get_bytes_in_last_block(struct archive *); + +/* The dev/ino of a file that won't be archived. This is used + * to avoid recursively adding an archive to itself. */ +__LA_DECL int archive_write_set_skip_file(struct archive *, + la_int64_t, la_int64_t); + +#if ARCHIVE_VERSION_NUMBER < 4000000 +__LA_DECL int archive_write_set_compression_bzip2(struct archive *) + __LA_DEPRECATED; +__LA_DECL int archive_write_set_compression_compress(struct archive *) + __LA_DEPRECATED; +__LA_DECL int archive_write_set_compression_gzip(struct archive *) + __LA_DEPRECATED; +__LA_DECL int archive_write_set_compression_lzip(struct archive *) + __LA_DEPRECATED; +__LA_DECL int archive_write_set_compression_lzma(struct archive *) + __LA_DEPRECATED; +__LA_DECL int archive_write_set_compression_none(struct archive *) + __LA_DEPRECATED; +__LA_DECL int archive_write_set_compression_program(struct archive *, + const char *cmd) __LA_DEPRECATED; +__LA_DECL int archive_write_set_compression_xz(struct archive *) + __LA_DEPRECATED; +#endif + +/* A convenience function to set the filter based on the code. */ +__LA_DECL int archive_write_add_filter(struct archive *, int filter_code); +__LA_DECL int archive_write_add_filter_by_name(struct archive *, + const char *name); +__LA_DECL int archive_write_add_filter_b64encode(struct archive *); +__LA_DECL int archive_write_add_filter_bzip2(struct archive *); +__LA_DECL int archive_write_add_filter_compress(struct archive *); +__LA_DECL int archive_write_add_filter_grzip(struct archive *); +__LA_DECL int archive_write_add_filter_gzip(struct archive *); +__LA_DECL int archive_write_add_filter_lrzip(struct archive *); +__LA_DECL int archive_write_add_filter_lz4(struct archive *); +__LA_DECL int archive_write_add_filter_lzip(struct archive *); +__LA_DECL int archive_write_add_filter_lzma(struct archive *); +__LA_DECL int archive_write_add_filter_lzop(struct archive *); +__LA_DECL int archive_write_add_filter_none(struct archive *); +__LA_DECL int archive_write_add_filter_program(struct archive *, + const char *cmd); +__LA_DECL int archive_write_add_filter_uuencode(struct archive *); +__LA_DECL int archive_write_add_filter_xz(struct archive *); +__LA_DECL int archive_write_add_filter_zstd(struct archive *); + + +/* A convenience function to set the format based on the code or name. */ +__LA_DECL int archive_write_set_format(struct archive *, int format_code); +__LA_DECL int archive_write_set_format_by_name(struct archive *, + const char *name); +/* To minimize link pollution, use one or more of the following. */ +__LA_DECL int archive_write_set_format_7zip(struct archive *); +__LA_DECL int archive_write_set_format_ar_bsd(struct archive *); +__LA_DECL int archive_write_set_format_ar_svr4(struct archive *); +__LA_DECL int archive_write_set_format_cpio(struct archive *); +__LA_DECL int archive_write_set_format_cpio_bin(struct archive *); +__LA_DECL int archive_write_set_format_cpio_newc(struct archive *); +__LA_DECL int archive_write_set_format_cpio_odc(struct archive *); +__LA_DECL int archive_write_set_format_cpio_pwb(struct archive *); +__LA_DECL int archive_write_set_format_gnutar(struct archive *); +__LA_DECL int archive_write_set_format_iso9660(struct archive *); +__LA_DECL int archive_write_set_format_mtree(struct archive *); +__LA_DECL int archive_write_set_format_mtree_classic(struct archive *); +/* TODO: int archive_write_set_format_old_tar(struct archive *); */ +__LA_DECL int archive_write_set_format_pax(struct archive *); +__LA_DECL int archive_write_set_format_pax_restricted(struct archive *); +__LA_DECL int archive_write_set_format_raw(struct archive *); +__LA_DECL int archive_write_set_format_shar(struct archive *); +__LA_DECL int archive_write_set_format_shar_dump(struct archive *); +__LA_DECL int archive_write_set_format_ustar(struct archive *); +__LA_DECL int archive_write_set_format_v7tar(struct archive *); +__LA_DECL int archive_write_set_format_warc(struct archive *); +__LA_DECL int archive_write_set_format_xar(struct archive *); +__LA_DECL int archive_write_set_format_zip(struct archive *); +__LA_DECL int archive_write_set_format_filter_by_ext(struct archive *a, const char *filename); +__LA_DECL int archive_write_set_format_filter_by_ext_def(struct archive *a, const char *filename, const char * def_ext); +__LA_DECL int archive_write_zip_set_compression_deflate(struct archive *); +__LA_DECL int archive_write_zip_set_compression_store(struct archive *); +/* Deprecated; use archive_write_open2 instead */ +__LA_DECL int archive_write_open(struct archive *, void *, + archive_open_callback *, archive_write_callback *, + archive_close_callback *); +__LA_DECL int archive_write_open2(struct archive *, void *, + archive_open_callback *, archive_write_callback *, + archive_close_callback *, archive_free_callback *); +__LA_DECL int archive_write_open_fd(struct archive *, int _fd); +__LA_DECL int archive_write_open_filename(struct archive *, const char *_file); +__LA_DECL int archive_write_open_filename_w(struct archive *, + const wchar_t *_file); +/* A deprecated synonym for archive_write_open_filename() */ +__LA_DECL int archive_write_open_file(struct archive *, const char *_file) + __LA_DEPRECATED; +__LA_DECL int archive_write_open_FILE(struct archive *, FILE *); +/* _buffSize is the size of the buffer, _used refers to a variable that + * will be updated after each write into the buffer. */ +__LA_DECL int archive_write_open_memory(struct archive *, + void *_buffer, size_t _buffSize, size_t *_used); + +/* + * Note that the library will truncate writes beyond the size provided + * to archive_write_header or pad if the provided data is short. + */ +__LA_DECL int archive_write_header(struct archive *, + struct archive_entry *); +__LA_DECL la_ssize_t archive_write_data(struct archive *, + const void *, size_t); + +/* This interface is currently only available for archive_write_disk handles. */ +__LA_DECL la_ssize_t archive_write_data_block(struct archive *, + const void *, size_t, la_int64_t); + +__LA_DECL int archive_write_finish_entry(struct archive *); +__LA_DECL int archive_write_close(struct archive *); +/* Marks the archive as FATAL so that a subsequent free() operation + * won't try to close() cleanly. Provides a fast abort capability + * when the client discovers that things have gone wrong. */ +__LA_DECL int archive_write_fail(struct archive *); +/* This can fail if the archive wasn't already closed, in which case + * archive_write_free() will implicitly call archive_write_close(). */ +__LA_DECL int archive_write_free(struct archive *); +#if ARCHIVE_VERSION_NUMBER < 4000000 +/* Synonym for archive_write_free() for backwards compatibility. */ +__LA_DECL int archive_write_finish(struct archive *) __LA_DEPRECATED; +#endif + +/* + * Set write options. + */ +/* Apply option to the format only. */ +__LA_DECL int archive_write_set_format_option(struct archive *_a, + const char *m, const char *o, + const char *v); +/* Apply option to the filter only. */ +__LA_DECL int archive_write_set_filter_option(struct archive *_a, + const char *m, const char *o, + const char *v); +/* Apply option to both the format and the filter. */ +__LA_DECL int archive_write_set_option(struct archive *_a, + const char *m, const char *o, + const char *v); +/* Apply option string to both the format and the filter. */ +__LA_DECL int archive_write_set_options(struct archive *_a, + const char *opts); + +/* + * Set an encryption passphrase. + */ +__LA_DECL int archive_write_set_passphrase(struct archive *_a, const char *p); +__LA_DECL int archive_write_set_passphrase_callback(struct archive *, + void *client_data, archive_passphrase_callback *); + +/*- + * ARCHIVE_WRITE_DISK API + * + * To create objects on disk: + * 1) Ask archive_write_disk_new for a new archive_write_disk object. + * 2) Set any global properties. In particular, you probably + * want to set the options. + * 3) For each entry: + * - construct an appropriate struct archive_entry structure + * - archive_write_header to create the file/dir/etc on disk + * - archive_write_data to write the entry data + * 4) archive_write_free to cleanup the writer and release resources + * + * In particular, you can use this in conjunction with archive_read() + * to pull entries out of an archive and create them on disk. + */ +__LA_DECL struct archive *archive_write_disk_new(void); +/* This file will not be overwritten. */ +__LA_DECL int archive_write_disk_set_skip_file(struct archive *, + la_int64_t, la_int64_t); +/* Set flags to control how the next item gets created. + * This accepts a bitmask of ARCHIVE_EXTRACT_XXX flags defined above. */ +__LA_DECL int archive_write_disk_set_options(struct archive *, + int flags); +/* + * The lookup functions are given uname/uid (or gname/gid) pairs and + * return a uid (gid) suitable for this system. These are used for + * restoring ownership and for setting ACLs. The default functions + * are naive, they just return the uid/gid. These are small, so reasonable + * for applications that don't need to preserve ownership; they + * are probably also appropriate for applications that are doing + * same-system backup and restore. + */ +/* + * The "standard" lookup functions use common system calls to lookup + * the uname/gname, falling back to the uid/gid if the names can't be + * found. They cache lookups and are reasonably fast, but can be very + * large, so they are not used unless you ask for them. In + * particular, these match the specifications of POSIX "pax" and old + * POSIX "tar". + */ +__LA_DECL int archive_write_disk_set_standard_lookup(struct archive *); +/* + * If neither the default (naive) nor the standard (big) functions suit + * your needs, you can write your own and register them. Be sure to + * include a cleanup function if you have allocated private data. + */ +__LA_DECL int archive_write_disk_set_group_lookup(struct archive *, + void * /* private_data */, + la_int64_t (*)(void *, const char *, la_int64_t), + void (* /* cleanup */)(void *)); +__LA_DECL int archive_write_disk_set_user_lookup(struct archive *, + void * /* private_data */, + la_int64_t (*)(void *, const char *, la_int64_t), + void (* /* cleanup */)(void *)); +__LA_DECL la_int64_t archive_write_disk_gid(struct archive *, const char *, la_int64_t); +__LA_DECL la_int64_t archive_write_disk_uid(struct archive *, const char *, la_int64_t); + +/* + * ARCHIVE_READ_DISK API + * + * This is still evolving and somewhat experimental. + */ +__LA_DECL struct archive *archive_read_disk_new(void); +/* The names for symlink modes here correspond to an old BSD + * command-line argument convention: -L, -P, -H */ +/* Follow all symlinks. */ +__LA_DECL int archive_read_disk_set_symlink_logical(struct archive *); +/* Follow no symlinks. */ +__LA_DECL int archive_read_disk_set_symlink_physical(struct archive *); +/* Follow symlink initially, then not. */ +__LA_DECL int archive_read_disk_set_symlink_hybrid(struct archive *); +/* TODO: Handle Linux stat32/stat64 ugliness. */ +__LA_DECL int archive_read_disk_entry_from_file(struct archive *, + struct archive_entry *, int /* fd */, const struct stat *); +/* Look up gname for gid or uname for uid. */ +/* Default implementations are very, very stupid. */ +__LA_DECL const char *archive_read_disk_gname(struct archive *, la_int64_t); +__LA_DECL const char *archive_read_disk_uname(struct archive *, la_int64_t); +/* "Standard" implementation uses getpwuid_r, getgrgid_r and caches the + * results for performance. */ +__LA_DECL int archive_read_disk_set_standard_lookup(struct archive *); +/* You can install your own lookups if you like. */ +__LA_DECL int archive_read_disk_set_gname_lookup(struct archive *, + void * /* private_data */, + const char *(* /* lookup_fn */)(void *, la_int64_t), + void (* /* cleanup_fn */)(void *)); +__LA_DECL int archive_read_disk_set_uname_lookup(struct archive *, + void * /* private_data */, + const char *(* /* lookup_fn */)(void *, la_int64_t), + void (* /* cleanup_fn */)(void *)); +/* Start traversal. */ +__LA_DECL int archive_read_disk_open(struct archive *, const char *); +__LA_DECL int archive_read_disk_open_w(struct archive *, const wchar_t *); +/* + * Request that current entry be visited. If you invoke it on every + * directory, you'll get a physical traversal. This is ignored if the + * current entry isn't a directory or a link to a directory. So, if + * you invoke this on every returned path, you'll get a full logical + * traversal. + */ +__LA_DECL int archive_read_disk_descend(struct archive *); +__LA_DECL int archive_read_disk_can_descend(struct archive *); +__LA_DECL int archive_read_disk_current_filesystem(struct archive *); +__LA_DECL int archive_read_disk_current_filesystem_is_synthetic(struct archive *); +__LA_DECL int archive_read_disk_current_filesystem_is_remote(struct archive *); +/* Request that the access time of the entry visited by traversal be restored. */ +__LA_DECL int archive_read_disk_set_atime_restored(struct archive *); +/* + * Set behavior. The "flags" argument selects optional behavior. + */ +/* Request that the access time of the entry visited by traversal be restored. + * This is the same as archive_read_disk_set_atime_restored. */ +#define ARCHIVE_READDISK_RESTORE_ATIME (0x0001) +/* Default: Do not skip an entry which has nodump flags. */ +#define ARCHIVE_READDISK_HONOR_NODUMP (0x0002) +/* Default: Skip a mac resource fork file whose prefix is "._" because of + * using copyfile. */ +#define ARCHIVE_READDISK_MAC_COPYFILE (0x0004) +/* Default: Traverse mount points. */ +#define ARCHIVE_READDISK_NO_TRAVERSE_MOUNTS (0x0008) +/* Default: Xattrs are read from disk. */ +#define ARCHIVE_READDISK_NO_XATTR (0x0010) +/* Default: ACLs are read from disk. */ +#define ARCHIVE_READDISK_NO_ACL (0x0020) +/* Default: File flags are read from disk. */ +#define ARCHIVE_READDISK_NO_FFLAGS (0x0040) +/* Default: Sparse file information is read from disk. */ +#define ARCHIVE_READDISK_NO_SPARSE (0x0080) + +__LA_DECL int archive_read_disk_set_behavior(struct archive *, + int flags); + +/* + * Set archive_match object that will be used in archive_read_disk to + * know whether an entry should be skipped. The callback function + * _excluded_func will be invoked when an entry is skipped by the result + * of archive_match. + */ +__LA_DECL int archive_read_disk_set_matching(struct archive *, + struct archive *_matching, void (*_excluded_func) + (struct archive *, void *, struct archive_entry *), + void *_client_data); +__LA_DECL int archive_read_disk_set_metadata_filter_callback(struct archive *, + int (*_metadata_filter_func)(struct archive *, void *, + struct archive_entry *), void *_client_data); + +/* Simplified cleanup interface; + * This calls archive_read_free() or archive_write_free() as needed. */ +__LA_DECL int archive_free(struct archive *); + +/* + * Accessor functions to read/set various information in + * the struct archive object: + */ + +/* Number of filters in the current filter pipeline. */ +/* Filter #0 is the one closest to the format, -1 is a synonym for the + * last filter, which is always the pseudo-filter that wraps the + * client callbacks. */ +__LA_DECL int archive_filter_count(struct archive *); +__LA_DECL la_int64_t archive_filter_bytes(struct archive *, int); +__LA_DECL int archive_filter_code(struct archive *, int); +__LA_DECL const char * archive_filter_name(struct archive *, int); + +#if ARCHIVE_VERSION_NUMBER < 4000000 +/* These don't properly handle multiple filters, so are deprecated and + * will eventually be removed. */ +/* As of libarchive 3.0, this is an alias for archive_filter_bytes(a, -1); */ +__LA_DECL la_int64_t archive_position_compressed(struct archive *) + __LA_DEPRECATED; +/* As of libarchive 3.0, this is an alias for archive_filter_bytes(a, 0); */ +__LA_DECL la_int64_t archive_position_uncompressed(struct archive *) + __LA_DEPRECATED; +/* As of libarchive 3.0, this is an alias for archive_filter_name(a, 0); */ +__LA_DECL const char *archive_compression_name(struct archive *) + __LA_DEPRECATED; +/* As of libarchive 3.0, this is an alias for archive_filter_code(a, 0); */ +__LA_DECL int archive_compression(struct archive *) + __LA_DEPRECATED; +#endif + +__LA_DECL int archive_errno(struct archive *); +__LA_DECL const char *archive_error_string(struct archive *); +__LA_DECL const char *archive_format_name(struct archive *); +__LA_DECL int archive_format(struct archive *); +__LA_DECL void archive_clear_error(struct archive *); +__LA_DECL void archive_set_error(struct archive *, int _err, + const char *fmt, ...) __LA_PRINTF(3, 4); +__LA_DECL void archive_copy_error(struct archive *dest, + struct archive *src); +__LA_DECL int archive_file_count(struct archive *); + +/* + * ARCHIVE_MATCH API + */ +__LA_DECL struct archive *archive_match_new(void); +__LA_DECL int archive_match_free(struct archive *); + +/* + * Test if archive_entry is excluded. + * This is a convenience function. This is the same as calling all + * archive_match_path_excluded, archive_match_time_excluded + * and archive_match_owner_excluded. + */ +__LA_DECL int archive_match_excluded(struct archive *, + struct archive_entry *); + +/* + * Test if pathname is excluded. The conditions are set by following functions. + */ +__LA_DECL int archive_match_path_excluded(struct archive *, + struct archive_entry *); +/* Control recursive inclusion of directory content when directory is included. Default on. */ +__LA_DECL int archive_match_set_inclusion_recursion(struct archive *, int); +/* Add exclusion pathname pattern. */ +__LA_DECL int archive_match_exclude_pattern(struct archive *, const char *); +__LA_DECL int archive_match_exclude_pattern_w(struct archive *, + const wchar_t *); +/* Add exclusion pathname pattern from file. */ +__LA_DECL int archive_match_exclude_pattern_from_file(struct archive *, + const char *, int _nullSeparator); +__LA_DECL int archive_match_exclude_pattern_from_file_w(struct archive *, + const wchar_t *, int _nullSeparator); +/* Add inclusion pathname pattern. */ +__LA_DECL int archive_match_include_pattern(struct archive *, const char *); +__LA_DECL int archive_match_include_pattern_w(struct archive *, + const wchar_t *); +/* Add inclusion pathname pattern from file. */ +__LA_DECL int archive_match_include_pattern_from_file(struct archive *, + const char *, int _nullSeparator); +__LA_DECL int archive_match_include_pattern_from_file_w(struct archive *, + const wchar_t *, int _nullSeparator); +/* + * How to get statistic information for inclusion patterns. + */ +/* Return the amount number of unmatched inclusion patterns. */ +__LA_DECL int archive_match_path_unmatched_inclusions(struct archive *); +/* Return the pattern of unmatched inclusion with ARCHIVE_OK. + * Return ARCHIVE_EOF if there is no inclusion pattern. */ +__LA_DECL int archive_match_path_unmatched_inclusions_next( + struct archive *, const char **); +__LA_DECL int archive_match_path_unmatched_inclusions_next_w( + struct archive *, const wchar_t **); + +/* + * Test if a file is excluded by its time stamp. + * The conditions are set by following functions. + */ +__LA_DECL int archive_match_time_excluded(struct archive *, + struct archive_entry *); + +/* + * Flags to tell a matching type of time stamps. These are used for + * following functions. + */ +/* Time flag: mtime to be tested. */ +#define ARCHIVE_MATCH_MTIME (0x0100) +/* Time flag: ctime to be tested. */ +#define ARCHIVE_MATCH_CTIME (0x0200) +/* Comparison flag: Match the time if it is newer than. */ +#define ARCHIVE_MATCH_NEWER (0x0001) +/* Comparison flag: Match the time if it is older than. */ +#define ARCHIVE_MATCH_OLDER (0x0002) +/* Comparison flag: Match the time if it is equal to. */ +#define ARCHIVE_MATCH_EQUAL (0x0010) +/* Set inclusion time. */ +__LA_DECL int archive_match_include_time(struct archive *, int _flag, + time_t _sec, long _nsec); +/* Set inclusion time by a date string. */ +__LA_DECL int archive_match_include_date(struct archive *, int _flag, + const char *_datestr); +__LA_DECL int archive_match_include_date_w(struct archive *, int _flag, + const wchar_t *_datestr); +/* Set inclusion time by a particular file. */ +__LA_DECL int archive_match_include_file_time(struct archive *, + int _flag, const char *_pathname); +__LA_DECL int archive_match_include_file_time_w(struct archive *, + int _flag, const wchar_t *_pathname); +/* Add exclusion entry. */ +__LA_DECL int archive_match_exclude_entry(struct archive *, + int _flag, struct archive_entry *); + +/* + * Test if a file is excluded by its uid ,gid, uname or gname. + * The conditions are set by following functions. + */ +__LA_DECL int archive_match_owner_excluded(struct archive *, + struct archive_entry *); +/* Add inclusion uid, gid, uname and gname. */ +__LA_DECL int archive_match_include_uid(struct archive *, la_int64_t); +__LA_DECL int archive_match_include_gid(struct archive *, la_int64_t); +__LA_DECL int archive_match_include_uname(struct archive *, const char *); +__LA_DECL int archive_match_include_uname_w(struct archive *, + const wchar_t *); +__LA_DECL int archive_match_include_gname(struct archive *, const char *); +__LA_DECL int archive_match_include_gname_w(struct archive *, + const wchar_t *); + +/* Utility functions */ +/* Convenience function to sort a NULL terminated list of strings */ +__LA_DECL int archive_utility_string_sort(char **); + +#ifdef __cplusplus +} +#endif + +/* These are meaningless outside of this header. */ +#undef __LA_DECL + +#endif /* !ARCHIVE_H_INCLUDED */ diff --git a/Sources/ContainerizationArchive/CArchive/include/archive_bridge.h b/Sources/ContainerizationArchive/CArchive/include/archive_bridge.h new file mode 100644 index 00000000..6b30015f --- /dev/null +++ b/Sources/ContainerizationArchive/CArchive/include/archive_bridge.h @@ -0,0 +1,7 @@ +// + +#pragma once + +#include "archive.h" + +void archive_set_error_wrapper(struct archive *a, int error_number, const char *error_string); diff --git a/Sources/ContainerizationArchive/CArchive/include/archive_entry.h b/Sources/ContainerizationArchive/CArchive/include/archive_entry.h new file mode 100644 index 00000000..97f5cdaf --- /dev/null +++ b/Sources/ContainerizationArchive/CArchive/include/archive_entry.h @@ -0,0 +1,731 @@ +/*- + * Copyright (c) 2003-2008 Tim Kientzle + * Copyright (c) 2016 Martin Matuska + * All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY THE AUTHOR(S) ``AS IS'' AND ANY EXPRESS OR + * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES + * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. + * IN NO EVENT SHALL THE AUTHOR(S) BE LIABLE FOR ANY DIRECT, INDIRECT, + * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT + * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, + * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY + * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT + * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF + * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. + */ + +#ifndef ARCHIVE_ENTRY_H_INCLUDED +#define ARCHIVE_ENTRY_H_INCLUDED + +/* Note: Compiler will complain if this does not match archive.h! */ +#define ARCHIVE_VERSION_NUMBER 3007007 + +/* + * Note: archive_entry.h is for use outside of libarchive; the + * configuration headers (config.h, archive_platform.h, etc.) are + * purely internal. Do NOT use HAVE_XXX configuration macros to + * control the behavior of this header! If you must conditionalize, + * use predefined compiler and/or platform macros. + */ + +#include +#include /* for wchar_t */ +#include +#include + +#if defined(_WIN32) && !defined(__CYGWIN__) +#include +#endif + +/* Get a suitable 64-bit integer type. */ +#if !defined(__LA_INT64_T_DEFINED) +# if ARCHIVE_VERSION_NUMBER < 4000000 +#define __LA_INT64_T la_int64_t +# endif +#define __LA_INT64_T_DEFINED +# if defined(_WIN32) && !defined(__CYGWIN__) && !defined(__WATCOMC__) +typedef __int64 la_int64_t; +# else +#include +# if defined(_SCO_DS) || defined(__osf__) +typedef long long la_int64_t; +# else +typedef int64_t la_int64_t; +# endif +# endif +#endif + +/* The la_ssize_t should match the type used in 'struct stat' */ +#if !defined(__LA_SSIZE_T_DEFINED) +/* Older code relied on the __LA_SSIZE_T macro; after 4.0 we'll switch to the typedef exclusively. */ +# if ARCHIVE_VERSION_NUMBER < 4000000 +#define __LA_SSIZE_T la_ssize_t +# endif +#define __LA_SSIZE_T_DEFINED +# if defined(_WIN32) && !defined(__CYGWIN__) && !defined(__WATCOMC__) +# if defined(_SSIZE_T_DEFINED) || defined(_SSIZE_T_) +typedef ssize_t la_ssize_t; +# elif defined(_WIN64) +typedef __int64 la_ssize_t; +# else +typedef long la_ssize_t; +# endif +# else +# include /* ssize_t */ +typedef ssize_t la_ssize_t; +# endif +#endif + +/* Get a suitable definition for mode_t */ +#if ARCHIVE_VERSION_NUMBER >= 3999000 +/* Switch to plain 'int' for libarchive 4.0. It's less broken than 'mode_t' */ +# define __LA_MODE_T int +#elif defined(_WIN32) && !defined(__CYGWIN__) && !defined(__BORLANDC__) && !defined(__WATCOMC__) +# define __LA_MODE_T unsigned short +#else +# define __LA_MODE_T mode_t +#endif + +/* Large file support for Android */ +#if defined(__LIBARCHIVE_BUILD) && defined(__ANDROID__) +#include "android_lf.h" +#endif + +/* + * On Windows, define LIBARCHIVE_STATIC if you're building or using a + * .lib. The default here assumes you're building a DLL. Only + * libarchive source should ever define __LIBARCHIVE_BUILD. + */ +#if ((defined __WIN32__) || (defined _WIN32) || defined(__CYGWIN__)) && (!defined LIBARCHIVE_STATIC) +# ifdef __LIBARCHIVE_BUILD +# ifdef __GNUC__ +# define __LA_DECL __attribute__((dllexport)) extern +# else +# define __LA_DECL __declspec(dllexport) +# endif +# else +# ifdef __GNUC__ +# define __LA_DECL +# else +# define __LA_DECL __declspec(dllimport) +# endif +# endif +#elif defined __LIBARCHIVE_ENABLE_VISIBILITY +# define __LA_DECL __attribute__((visibility("default"))) +#else +/* Static libraries on all platforms and shared libraries on non-Windows. */ +# define __LA_DECL +#endif + +#if defined(__GNUC__) && __GNUC__ >= 3 && __GNUC_MINOR__ >= 1 +# define __LA_DEPRECATED __attribute__((deprecated)) +#else +# define __LA_DEPRECATED +#endif + +#ifdef __cplusplus +extern "C" { +#endif + +/* + * Description of an archive entry. + * + * You can think of this as "struct stat" with some text fields added in. + * + * TODO: Add "comment", "charset", and possibly other entries that are + * supported by "pax interchange" format. However, GNU, ustar, cpio, + * and other variants don't support these features, so they're not an + * excruciatingly high priority right now. + * + * TODO: "pax interchange" format allows essentially arbitrary + * key/value attributes to be attached to any entry. Supporting + * such extensions may make this library useful for special + * applications (e.g., a package manager could attach special + * package-management attributes to each entry). + */ +struct archive; +struct archive_entry; + +/* + * File-type constants. These are returned from archive_entry_filetype() + * and passed to archive_entry_set_filetype(). + * + * These values match S_XXX defines on every platform I've checked, + * including Windows, AIX, Linux, Solaris, and BSD. They're + * (re)defined here because platforms generally don't define the ones + * they don't support. For example, Windows doesn't define S_IFLNK or + * S_IFBLK. Instead of having a mass of conditional logic and system + * checks to define any S_XXX values that aren't supported locally, + * I've just defined a new set of such constants so that + * libarchive-based applications can manipulate and identify archive + * entries properly even if the hosting platform can't store them on + * disk. + * + * These values are also used directly within some portable formats, + * such as cpio. If you find a platform that varies from these, the + * correct solution is to leave these alone and translate from these + * portable values to platform-native values when entries are read from + * or written to disk. + */ +/* + * In libarchive 4.0, we can drop the casts here. + * They're needed to work around Borland C's broken mode_t. + */ +#define AE_IFMT ((__LA_MODE_T)0170000) +#define AE_IFREG ((__LA_MODE_T)0100000) +#define AE_IFLNK ((__LA_MODE_T)0120000) +#define AE_IFSOCK ((__LA_MODE_T)0140000) +#define AE_IFCHR ((__LA_MODE_T)0020000) +#define AE_IFBLK ((__LA_MODE_T)0060000) +#define AE_IFDIR ((__LA_MODE_T)0040000) +#define AE_IFIFO ((__LA_MODE_T)0010000) + +/* + * Symlink types + */ +#define AE_SYMLINK_TYPE_UNDEFINED 0 +#define AE_SYMLINK_TYPE_FILE 1 +#define AE_SYMLINK_TYPE_DIRECTORY 2 + +/* + * Basic object manipulation + */ + +__LA_DECL struct archive_entry *archive_entry_clear(struct archive_entry *); +/* The 'clone' function does a deep copy; all of the strings are copied too. */ +__LA_DECL struct archive_entry *archive_entry_clone(struct archive_entry *); +__LA_DECL void archive_entry_free(struct archive_entry *); +__LA_DECL struct archive_entry *archive_entry_new(void); + +/* + * This form of archive_entry_new2() will pull character-set + * conversion information from the specified archive handle. The + * older archive_entry_new(void) form is equivalent to calling + * archive_entry_new2(NULL) and will result in the use of an internal + * default character-set conversion. + */ +__LA_DECL struct archive_entry *archive_entry_new2(struct archive *); + +/* + * Retrieve fields from an archive_entry. + * + * There are a number of implicit conversions among these fields. For + * example, if a regular string field is set and you read the _w wide + * character field, the entry will implicitly convert narrow-to-wide + * using the current locale. Similarly, dev values are automatically + * updated when you write devmajor or devminor and vice versa. + * + * In addition, fields can be "set" or "unset." Unset string fields + * return NULL, non-string fields have _is_set() functions to test + * whether they've been set. You can "unset" a string field by + * assigning NULL; non-string fields have _unset() functions to + * unset them. + * + * Note: There is one ambiguity in the above; string fields will + * also return NULL when implicit character set conversions fail. + * This is usually what you want. + */ +__LA_DECL time_t archive_entry_atime(struct archive_entry *); +__LA_DECL long archive_entry_atime_nsec(struct archive_entry *); +__LA_DECL int archive_entry_atime_is_set(struct archive_entry *); +__LA_DECL time_t archive_entry_birthtime(struct archive_entry *); +__LA_DECL long archive_entry_birthtime_nsec(struct archive_entry *); +__LA_DECL int archive_entry_birthtime_is_set(struct archive_entry *); +__LA_DECL time_t archive_entry_ctime(struct archive_entry *); +__LA_DECL long archive_entry_ctime_nsec(struct archive_entry *); +__LA_DECL int archive_entry_ctime_is_set(struct archive_entry *); +__LA_DECL dev_t archive_entry_dev(struct archive_entry *); +__LA_DECL int archive_entry_dev_is_set(struct archive_entry *); +__LA_DECL dev_t archive_entry_devmajor(struct archive_entry *); +__LA_DECL dev_t archive_entry_devminor(struct archive_entry *); +__LA_DECL __LA_MODE_T archive_entry_filetype(struct archive_entry *); +__LA_DECL int archive_entry_filetype_is_set(struct archive_entry *); +__LA_DECL void archive_entry_fflags(struct archive_entry *, + unsigned long * /* set */, + unsigned long * /* clear */); +__LA_DECL const char *archive_entry_fflags_text(struct archive_entry *); +__LA_DECL la_int64_t archive_entry_gid(struct archive_entry *); +__LA_DECL int archive_entry_gid_is_set(struct archive_entry *); +__LA_DECL const char *archive_entry_gname(struct archive_entry *); +__LA_DECL const char *archive_entry_gname_utf8(struct archive_entry *); +__LA_DECL const wchar_t *archive_entry_gname_w(struct archive_entry *); +__LA_DECL void archive_entry_set_link_to_hardlink(struct archive_entry *); +__LA_DECL const char *archive_entry_hardlink(struct archive_entry *); +__LA_DECL const char *archive_entry_hardlink_utf8(struct archive_entry *); +__LA_DECL const wchar_t *archive_entry_hardlink_w(struct archive_entry *); +__LA_DECL int archive_entry_hardlink_is_set(struct archive_entry *); +__LA_DECL la_int64_t archive_entry_ino(struct archive_entry *); +__LA_DECL la_int64_t archive_entry_ino64(struct archive_entry *); +__LA_DECL int archive_entry_ino_is_set(struct archive_entry *); +__LA_DECL __LA_MODE_T archive_entry_mode(struct archive_entry *); +__LA_DECL time_t archive_entry_mtime(struct archive_entry *); +__LA_DECL long archive_entry_mtime_nsec(struct archive_entry *); +__LA_DECL int archive_entry_mtime_is_set(struct archive_entry *); +__LA_DECL unsigned int archive_entry_nlink(struct archive_entry *); +__LA_DECL const char *archive_entry_pathname(struct archive_entry *); +__LA_DECL const char *archive_entry_pathname_utf8(struct archive_entry *); +__LA_DECL const wchar_t *archive_entry_pathname_w(struct archive_entry *); +__LA_DECL __LA_MODE_T archive_entry_perm(struct archive_entry *); +__LA_DECL int archive_entry_perm_is_set(struct archive_entry *); +__LA_DECL int archive_entry_rdev_is_set(struct archive_entry *); +__LA_DECL dev_t archive_entry_rdev(struct archive_entry *); +__LA_DECL dev_t archive_entry_rdevmajor(struct archive_entry *); +__LA_DECL dev_t archive_entry_rdevminor(struct archive_entry *); +__LA_DECL const char *archive_entry_sourcepath(struct archive_entry *); +__LA_DECL const wchar_t *archive_entry_sourcepath_w(struct archive_entry *); +__LA_DECL la_int64_t archive_entry_size(struct archive_entry *); +__LA_DECL int archive_entry_size_is_set(struct archive_entry *); +__LA_DECL const char *archive_entry_strmode(struct archive_entry *); +__LA_DECL void archive_entry_set_link_to_symlink(struct archive_entry *); +__LA_DECL const char *archive_entry_symlink(struct archive_entry *); +__LA_DECL const char *archive_entry_symlink_utf8(struct archive_entry *); +__LA_DECL int archive_entry_symlink_type(struct archive_entry *); +__LA_DECL const wchar_t *archive_entry_symlink_w(struct archive_entry *); +__LA_DECL la_int64_t archive_entry_uid(struct archive_entry *); +__LA_DECL int archive_entry_uid_is_set(struct archive_entry *); +__LA_DECL const char *archive_entry_uname(struct archive_entry *); +__LA_DECL const char *archive_entry_uname_utf8(struct archive_entry *); +__LA_DECL const wchar_t *archive_entry_uname_w(struct archive_entry *); +__LA_DECL int archive_entry_is_data_encrypted(struct archive_entry *); +__LA_DECL int archive_entry_is_metadata_encrypted(struct archive_entry *); +__LA_DECL int archive_entry_is_encrypted(struct archive_entry *); + +/* + * Set fields in an archive_entry. + * + * Note: Before libarchive 2.4, there were 'set' and 'copy' versions + * of the string setters. 'copy' copied the actual string, 'set' just + * stored the pointer. In libarchive 2.4 and later, strings are + * always copied. + */ + +__LA_DECL void archive_entry_set_atime(struct archive_entry *, time_t, long); +__LA_DECL void archive_entry_unset_atime(struct archive_entry *); +#if defined(_WIN32) && !defined(__CYGWIN__) +__LA_DECL void archive_entry_copy_bhfi(struct archive_entry *, BY_HANDLE_FILE_INFORMATION *); +#endif +__LA_DECL void archive_entry_set_birthtime(struct archive_entry *, time_t, long); +__LA_DECL void archive_entry_unset_birthtime(struct archive_entry *); +__LA_DECL void archive_entry_set_ctime(struct archive_entry *, time_t, long); +__LA_DECL void archive_entry_unset_ctime(struct archive_entry *); +__LA_DECL void archive_entry_set_dev(struct archive_entry *, dev_t); +__LA_DECL void archive_entry_set_devmajor(struct archive_entry *, dev_t); +__LA_DECL void archive_entry_set_devminor(struct archive_entry *, dev_t); +__LA_DECL void archive_entry_set_filetype(struct archive_entry *, unsigned int); +__LA_DECL void archive_entry_set_fflags(struct archive_entry *, + unsigned long /* set */, unsigned long /* clear */); +/* Returns pointer to start of first invalid token, or NULL if none. */ +/* Note that all recognized tokens are processed, regardless. */ +__LA_DECL const char *archive_entry_copy_fflags_text(struct archive_entry *, + const char *); +__LA_DECL const char *archive_entry_copy_fflags_text_len(struct archive_entry *, + const char *, size_t); +__LA_DECL const wchar_t *archive_entry_copy_fflags_text_w(struct archive_entry *, + const wchar_t *); +__LA_DECL void archive_entry_set_gid(struct archive_entry *, la_int64_t); +__LA_DECL void archive_entry_set_gname(struct archive_entry *, const char *); +__LA_DECL void archive_entry_set_gname_utf8(struct archive_entry *, const char *); +__LA_DECL void archive_entry_copy_gname(struct archive_entry *, const char *); +__LA_DECL void archive_entry_copy_gname_w(struct archive_entry *, const wchar_t *); +__LA_DECL int archive_entry_update_gname_utf8(struct archive_entry *, const char *); +__LA_DECL void archive_entry_set_hardlink(struct archive_entry *, const char *); +__LA_DECL void archive_entry_set_hardlink_utf8(struct archive_entry *, const char *); +__LA_DECL void archive_entry_copy_hardlink(struct archive_entry *, const char *); +__LA_DECL void archive_entry_copy_hardlink_w(struct archive_entry *, const wchar_t *); +__LA_DECL int archive_entry_update_hardlink_utf8(struct archive_entry *, const char *); +__LA_DECL void archive_entry_set_ino(struct archive_entry *, la_int64_t); +__LA_DECL void archive_entry_set_ino64(struct archive_entry *, la_int64_t); +__LA_DECL void archive_entry_set_link(struct archive_entry *, const char *); +__LA_DECL void archive_entry_set_link_utf8(struct archive_entry *, const char *); +__LA_DECL void archive_entry_copy_link(struct archive_entry *, const char *); +__LA_DECL void archive_entry_copy_link_w(struct archive_entry *, const wchar_t *); +__LA_DECL int archive_entry_update_link_utf8(struct archive_entry *, const char *); +__LA_DECL void archive_entry_set_mode(struct archive_entry *, __LA_MODE_T); +__LA_DECL void archive_entry_set_mtime(struct archive_entry *, time_t, long); +__LA_DECL void archive_entry_unset_mtime(struct archive_entry *); +__LA_DECL void archive_entry_set_nlink(struct archive_entry *, unsigned int); +__LA_DECL void archive_entry_set_pathname(struct archive_entry *, const char *); +__LA_DECL void archive_entry_set_pathname_utf8(struct archive_entry *, const char *); +__LA_DECL void archive_entry_copy_pathname(struct archive_entry *, const char *); +__LA_DECL void archive_entry_copy_pathname_w(struct archive_entry *, const wchar_t *); +__LA_DECL int archive_entry_update_pathname_utf8(struct archive_entry *, const char *); +__LA_DECL void archive_entry_set_perm(struct archive_entry *, __LA_MODE_T); +__LA_DECL void archive_entry_set_rdev(struct archive_entry *, dev_t); +__LA_DECL void archive_entry_set_rdevmajor(struct archive_entry *, dev_t); +__LA_DECL void archive_entry_set_rdevminor(struct archive_entry *, dev_t); +__LA_DECL void archive_entry_set_size(struct archive_entry *, la_int64_t); +__LA_DECL void archive_entry_unset_size(struct archive_entry *); +__LA_DECL void archive_entry_copy_sourcepath(struct archive_entry *, const char *); +__LA_DECL void archive_entry_copy_sourcepath_w(struct archive_entry *, const wchar_t *); +__LA_DECL void archive_entry_set_symlink(struct archive_entry *, const char *); +__LA_DECL void archive_entry_set_symlink_type(struct archive_entry *, int); +__LA_DECL void archive_entry_set_symlink_utf8(struct archive_entry *, const char *); +__LA_DECL void archive_entry_copy_symlink(struct archive_entry *, const char *); +__LA_DECL void archive_entry_copy_symlink_w(struct archive_entry *, const wchar_t *); +__LA_DECL int archive_entry_update_symlink_utf8(struct archive_entry *, const char *); +__LA_DECL void archive_entry_set_uid(struct archive_entry *, la_int64_t); +__LA_DECL void archive_entry_set_uname(struct archive_entry *, const char *); +__LA_DECL void archive_entry_set_uname_utf8(struct archive_entry *, const char *); +__LA_DECL void archive_entry_copy_uname(struct archive_entry *, const char *); +__LA_DECL void archive_entry_copy_uname_w(struct archive_entry *, const wchar_t *); +__LA_DECL int archive_entry_update_uname_utf8(struct archive_entry *, const char *); +__LA_DECL void archive_entry_set_is_data_encrypted(struct archive_entry *, char is_encrypted); +__LA_DECL void archive_entry_set_is_metadata_encrypted(struct archive_entry *, char is_encrypted); +/* + * Routines to bulk copy fields to/from a platform-native "struct + * stat." Libarchive used to just store a struct stat inside of each + * archive_entry object, but this created issues when trying to + * manipulate archives on systems different than the ones they were + * created on. + * + * TODO: On Linux and other LFS systems, provide both stat32 and + * stat64 versions of these functions and all of the macro glue so + * that archive_entry_stat is magically defined to + * archive_entry_stat32 or archive_entry_stat64 as appropriate. + */ +__LA_DECL const struct stat *archive_entry_stat(struct archive_entry *); +__LA_DECL void archive_entry_copy_stat(struct archive_entry *, const struct stat *); + +/* + * Storage for Mac OS-specific AppleDouble metadata information. + * Apple-format tar files store a separate binary blob containing + * encoded metadata with ACL, extended attributes, etc. + * This provides a place to store that blob. + */ + +__LA_DECL const void * archive_entry_mac_metadata(struct archive_entry *, size_t *); +__LA_DECL void archive_entry_copy_mac_metadata(struct archive_entry *, const void *, size_t); + +/* + * Digest routine. This is used to query the raw hex digest for the + * given entry. The type of digest is provided as an argument. + */ +#define ARCHIVE_ENTRY_DIGEST_MD5 0x00000001 +#define ARCHIVE_ENTRY_DIGEST_RMD160 0x00000002 +#define ARCHIVE_ENTRY_DIGEST_SHA1 0x00000003 +#define ARCHIVE_ENTRY_DIGEST_SHA256 0x00000004 +#define ARCHIVE_ENTRY_DIGEST_SHA384 0x00000005 +#define ARCHIVE_ENTRY_DIGEST_SHA512 0x00000006 + +__LA_DECL const unsigned char * archive_entry_digest(struct archive_entry *, int /* type */); + +/* + * ACL routines. This used to simply store and return text-format ACL + * strings, but that proved insufficient for a number of reasons: + * = clients need control over uname/uid and gname/gid mappings + * = there are many different ACL text formats + * = would like to be able to read/convert archives containing ACLs + * on platforms that lack ACL libraries + * + * This last point, in particular, forces me to implement a reasonably + * complete set of ACL support routines. + */ + +/* + * Permission bits. + */ +#define ARCHIVE_ENTRY_ACL_EXECUTE 0x00000001 +#define ARCHIVE_ENTRY_ACL_WRITE 0x00000002 +#define ARCHIVE_ENTRY_ACL_READ 0x00000004 +#define ARCHIVE_ENTRY_ACL_READ_DATA 0x00000008 +#define ARCHIVE_ENTRY_ACL_LIST_DIRECTORY 0x00000008 +#define ARCHIVE_ENTRY_ACL_WRITE_DATA 0x00000010 +#define ARCHIVE_ENTRY_ACL_ADD_FILE 0x00000010 +#define ARCHIVE_ENTRY_ACL_APPEND_DATA 0x00000020 +#define ARCHIVE_ENTRY_ACL_ADD_SUBDIRECTORY 0x00000020 +#define ARCHIVE_ENTRY_ACL_READ_NAMED_ATTRS 0x00000040 +#define ARCHIVE_ENTRY_ACL_WRITE_NAMED_ATTRS 0x00000080 +#define ARCHIVE_ENTRY_ACL_DELETE_CHILD 0x00000100 +#define ARCHIVE_ENTRY_ACL_READ_ATTRIBUTES 0x00000200 +#define ARCHIVE_ENTRY_ACL_WRITE_ATTRIBUTES 0x00000400 +#define ARCHIVE_ENTRY_ACL_DELETE 0x00000800 +#define ARCHIVE_ENTRY_ACL_READ_ACL 0x00001000 +#define ARCHIVE_ENTRY_ACL_WRITE_ACL 0x00002000 +#define ARCHIVE_ENTRY_ACL_WRITE_OWNER 0x00004000 +#define ARCHIVE_ENTRY_ACL_SYNCHRONIZE 0x00008000 + +#define ARCHIVE_ENTRY_ACL_PERMS_POSIX1E \ + (ARCHIVE_ENTRY_ACL_EXECUTE \ + | ARCHIVE_ENTRY_ACL_WRITE \ + | ARCHIVE_ENTRY_ACL_READ) + +#define ARCHIVE_ENTRY_ACL_PERMS_NFS4 \ + (ARCHIVE_ENTRY_ACL_EXECUTE \ + | ARCHIVE_ENTRY_ACL_READ_DATA \ + | ARCHIVE_ENTRY_ACL_LIST_DIRECTORY \ + | ARCHIVE_ENTRY_ACL_WRITE_DATA \ + | ARCHIVE_ENTRY_ACL_ADD_FILE \ + | ARCHIVE_ENTRY_ACL_APPEND_DATA \ + | ARCHIVE_ENTRY_ACL_ADD_SUBDIRECTORY \ + | ARCHIVE_ENTRY_ACL_READ_NAMED_ATTRS \ + | ARCHIVE_ENTRY_ACL_WRITE_NAMED_ATTRS \ + | ARCHIVE_ENTRY_ACL_DELETE_CHILD \ + | ARCHIVE_ENTRY_ACL_READ_ATTRIBUTES \ + | ARCHIVE_ENTRY_ACL_WRITE_ATTRIBUTES \ + | ARCHIVE_ENTRY_ACL_DELETE \ + | ARCHIVE_ENTRY_ACL_READ_ACL \ + | ARCHIVE_ENTRY_ACL_WRITE_ACL \ + | ARCHIVE_ENTRY_ACL_WRITE_OWNER \ + | ARCHIVE_ENTRY_ACL_SYNCHRONIZE) + +/* + * Inheritance values (NFS4 ACLs only); included in permset. + */ +#define ARCHIVE_ENTRY_ACL_ENTRY_INHERITED 0x01000000 +#define ARCHIVE_ENTRY_ACL_ENTRY_FILE_INHERIT 0x02000000 +#define ARCHIVE_ENTRY_ACL_ENTRY_DIRECTORY_INHERIT 0x04000000 +#define ARCHIVE_ENTRY_ACL_ENTRY_NO_PROPAGATE_INHERIT 0x08000000 +#define ARCHIVE_ENTRY_ACL_ENTRY_INHERIT_ONLY 0x10000000 +#define ARCHIVE_ENTRY_ACL_ENTRY_SUCCESSFUL_ACCESS 0x20000000 +#define ARCHIVE_ENTRY_ACL_ENTRY_FAILED_ACCESS 0x40000000 + +#define ARCHIVE_ENTRY_ACL_INHERITANCE_NFS4 \ + (ARCHIVE_ENTRY_ACL_ENTRY_FILE_INHERIT \ + | ARCHIVE_ENTRY_ACL_ENTRY_DIRECTORY_INHERIT \ + | ARCHIVE_ENTRY_ACL_ENTRY_NO_PROPAGATE_INHERIT \ + | ARCHIVE_ENTRY_ACL_ENTRY_INHERIT_ONLY \ + | ARCHIVE_ENTRY_ACL_ENTRY_SUCCESSFUL_ACCESS \ + | ARCHIVE_ENTRY_ACL_ENTRY_FAILED_ACCESS \ + | ARCHIVE_ENTRY_ACL_ENTRY_INHERITED) + +/* We need to be able to specify combinations of these. */ +#define ARCHIVE_ENTRY_ACL_TYPE_ACCESS 0x00000100 /* POSIX.1e only */ +#define ARCHIVE_ENTRY_ACL_TYPE_DEFAULT 0x00000200 /* POSIX.1e only */ +#define ARCHIVE_ENTRY_ACL_TYPE_ALLOW 0x00000400 /* NFS4 only */ +#define ARCHIVE_ENTRY_ACL_TYPE_DENY 0x00000800 /* NFS4 only */ +#define ARCHIVE_ENTRY_ACL_TYPE_AUDIT 0x00001000 /* NFS4 only */ +#define ARCHIVE_ENTRY_ACL_TYPE_ALARM 0x00002000 /* NFS4 only */ +#define ARCHIVE_ENTRY_ACL_TYPE_POSIX1E (ARCHIVE_ENTRY_ACL_TYPE_ACCESS \ + | ARCHIVE_ENTRY_ACL_TYPE_DEFAULT) +#define ARCHIVE_ENTRY_ACL_TYPE_NFS4 (ARCHIVE_ENTRY_ACL_TYPE_ALLOW \ + | ARCHIVE_ENTRY_ACL_TYPE_DENY \ + | ARCHIVE_ENTRY_ACL_TYPE_AUDIT \ + | ARCHIVE_ENTRY_ACL_TYPE_ALARM) + +/* Tag values mimic POSIX.1e */ +#define ARCHIVE_ENTRY_ACL_USER 10001 /* Specified user. */ +#define ARCHIVE_ENTRY_ACL_USER_OBJ 10002 /* User who owns the file. */ +#define ARCHIVE_ENTRY_ACL_GROUP 10003 /* Specified group. */ +#define ARCHIVE_ENTRY_ACL_GROUP_OBJ 10004 /* Group who owns the file. */ +#define ARCHIVE_ENTRY_ACL_MASK 10005 /* Modify group access (POSIX.1e only) */ +#define ARCHIVE_ENTRY_ACL_OTHER 10006 /* Public (POSIX.1e only) */ +#define ARCHIVE_ENTRY_ACL_EVERYONE 10107 /* Everyone (NFS4 only) */ + +/* + * Set the ACL by clearing it and adding entries one at a time. + * Unlike the POSIX.1e ACL routines, you must specify the type + * (access/default) for each entry. Internally, the ACL data is just + * a soup of entries. API calls here allow you to retrieve just the + * entries of interest. This design (which goes against the spirit of + * POSIX.1e) is useful for handling archive formats that combine + * default and access information in a single ACL list. + */ +__LA_DECL void archive_entry_acl_clear(struct archive_entry *); +__LA_DECL int archive_entry_acl_add_entry(struct archive_entry *, + int /* type */, int /* permset */, int /* tag */, + int /* qual */, const char * /* name */); +__LA_DECL int archive_entry_acl_add_entry_w(struct archive_entry *, + int /* type */, int /* permset */, int /* tag */, + int /* qual */, const wchar_t * /* name */); + +/* + * To retrieve the ACL, first "reset", then repeatedly ask for the + * "next" entry. The want_type parameter allows you to request only + * certain types of entries. + */ +__LA_DECL int archive_entry_acl_reset(struct archive_entry *, int /* want_type */); +__LA_DECL int archive_entry_acl_next(struct archive_entry *, int /* want_type */, + int * /* type */, int * /* permset */, int * /* tag */, + int * /* qual */, const char ** /* name */); + +/* + * Construct a text-format ACL. The flags argument is a bitmask that + * can include any of the following: + * + * Flags only for archive entries with POSIX.1e ACL: + * ARCHIVE_ENTRY_ACL_TYPE_ACCESS - Include POSIX.1e "access" entries. + * ARCHIVE_ENTRY_ACL_TYPE_DEFAULT - Include POSIX.1e "default" entries. + * ARCHIVE_ENTRY_ACL_STYLE_MARK_DEFAULT - Include "default:" before each + * default ACL entry. + * ARCHIVE_ENTRY_ACL_STYLE_SOLARIS - Output only one colon after "other" and + * "mask" entries. + * + * Flags only for archive entries with NFSv4 ACL: + * ARCHIVE_ENTRY_ACL_STYLE_COMPACT - Do not output the minus character for + * unset permissions and flags in NFSv4 ACL permission and flag fields + * + * Flags for for archive entries with POSIX.1e ACL or NFSv4 ACL: + * ARCHIVE_ENTRY_ACL_STYLE_EXTRA_ID - Include extra numeric ID field in + * each ACL entry. + * ARCHIVE_ENTRY_ACL_STYLE_SEPARATOR_COMMA - Separate entries with comma + * instead of newline. + */ +#define ARCHIVE_ENTRY_ACL_STYLE_EXTRA_ID 0x00000001 +#define ARCHIVE_ENTRY_ACL_STYLE_MARK_DEFAULT 0x00000002 +#define ARCHIVE_ENTRY_ACL_STYLE_SOLARIS 0x00000004 +#define ARCHIVE_ENTRY_ACL_STYLE_SEPARATOR_COMMA 0x00000008 +#define ARCHIVE_ENTRY_ACL_STYLE_COMPACT 0x00000010 + +__LA_DECL wchar_t *archive_entry_acl_to_text_w(struct archive_entry *, + la_ssize_t * /* len */, int /* flags */); +__LA_DECL char *archive_entry_acl_to_text(struct archive_entry *, + la_ssize_t * /* len */, int /* flags */); +__LA_DECL int archive_entry_acl_from_text_w(struct archive_entry *, + const wchar_t * /* wtext */, int /* type */); +__LA_DECL int archive_entry_acl_from_text(struct archive_entry *, + const char * /* text */, int /* type */); + +/* Deprecated constants */ +#define OLD_ARCHIVE_ENTRY_ACL_STYLE_EXTRA_ID 1024 +#define OLD_ARCHIVE_ENTRY_ACL_STYLE_MARK_DEFAULT 2048 + +/* Deprecated functions */ +__LA_DECL const wchar_t *archive_entry_acl_text_w(struct archive_entry *, + int /* flags */) __LA_DEPRECATED; +__LA_DECL const char *archive_entry_acl_text(struct archive_entry *, + int /* flags */) __LA_DEPRECATED; + +/* Return bitmask of ACL types in an archive entry */ +__LA_DECL int archive_entry_acl_types(struct archive_entry *); + +/* Return a count of entries matching 'want_type' */ +__LA_DECL int archive_entry_acl_count(struct archive_entry *, int /* want_type */); + +/* Return an opaque ACL object. */ +/* There's not yet anything clients can actually do with this... */ +struct archive_acl; +__LA_DECL struct archive_acl *archive_entry_acl(struct archive_entry *); + +/* + * extended attributes + */ + +__LA_DECL void archive_entry_xattr_clear(struct archive_entry *); +__LA_DECL void archive_entry_xattr_add_entry(struct archive_entry *, + const char * /* name */, const void * /* value */, + size_t /* size */); + +/* + * To retrieve the xattr list, first "reset", then repeatedly ask for the + * "next" entry. + */ + +__LA_DECL int archive_entry_xattr_count(struct archive_entry *); +__LA_DECL int archive_entry_xattr_reset(struct archive_entry *); +__LA_DECL int archive_entry_xattr_next(struct archive_entry *, + const char ** /* name */, const void ** /* value */, size_t *); + +/* + * sparse + */ + +__LA_DECL void archive_entry_sparse_clear(struct archive_entry *); +__LA_DECL void archive_entry_sparse_add_entry(struct archive_entry *, + la_int64_t /* offset */, la_int64_t /* length */); + +/* + * To retrieve the xattr list, first "reset", then repeatedly ask for the + * "next" entry. + */ + +__LA_DECL int archive_entry_sparse_count(struct archive_entry *); +__LA_DECL int archive_entry_sparse_reset(struct archive_entry *); +__LA_DECL int archive_entry_sparse_next(struct archive_entry *, + la_int64_t * /* offset */, la_int64_t * /* length */); + +/* + * Utility to match up hardlinks. + * + * The 'struct archive_entry_linkresolver' is a cache of archive entries + * for files with multiple links. Here's how to use it: + * 1. Create a lookup object with archive_entry_linkresolver_new() + * 2. Tell it the archive format you're using. + * 3. Hand each archive_entry to archive_entry_linkify(). + * That function will return 0, 1, or 2 entries that should + * be written. + * 4. Call archive_entry_linkify(resolver, NULL) until + * no more entries are returned. + * 5. Call archive_entry_linkresolver_free(resolver) to free resources. + * + * The entries returned have their hardlink and size fields updated + * appropriately. If an entry is passed in that does not refer to + * a file with multiple links, it is returned unchanged. The intention + * is that you should be able to simply filter all entries through + * this machine. + * + * To make things more efficient, be sure that each entry has a valid + * nlinks value. The hardlink cache uses this to track when all links + * have been found. If the nlinks value is zero, it will keep every + * name in the cache indefinitely, which can use a lot of memory. + * + * Note that archive_entry_size() is reset to zero if the file + * body should not be written to the archive. Pay attention! + */ +struct archive_entry_linkresolver; + +/* + * There are three different strategies for marking hardlinks. + * The descriptions below name them after the best-known + * formats that rely on each strategy: + * + * "Old cpio" is the simplest, it always returns any entry unmodified. + * As far as I know, only cpio formats use this. Old cpio archives + * store every link with the full body; the onus is on the dearchiver + * to detect and properly link the files as they are restored. + * "tar" is also pretty simple; it caches a copy the first time it sees + * any link. Subsequent appearances are modified to be hardlink + * references to the first one without any body. Used by all tar + * formats, although the newest tar formats permit the "old cpio" strategy + * as well. This strategy is very simple for the dearchiver, + * and reasonably straightforward for the archiver. + * "new cpio" is trickier. It stores the body only with the last + * occurrence. The complication is that we might not + * see every link to a particular file in a single session, so + * there's no easy way to know when we've seen the last occurrence. + * The solution here is to queue one link until we see the next. + * At the end of the session, you can enumerate any remaining + * entries by calling archive_entry_linkify(NULL) and store those + * bodies. If you have a file with three links l1, l2, and l3, + * you'll get the following behavior if you see all three links: + * linkify(l1) => NULL (the resolver stores l1 internally) + * linkify(l2) => l1 (resolver stores l2, you write l1) + * linkify(l3) => l2, l3 (all links seen, you can write both). + * If you only see l1 and l2, you'll get this behavior: + * linkify(l1) => NULL + * linkify(l2) => l1 + * linkify(NULL) => l2 (at end, you retrieve remaining links) + * As the name suggests, this strategy is used by newer cpio variants. + * It's noticeably more complex for the archiver, slightly more complex + * for the dearchiver than the tar strategy, but makes it straightforward + * to restore a file using any link by simply continuing to scan until + * you see a link that is stored with a body. In contrast, the tar + * strategy requires you to rescan the archive from the beginning to + * correctly extract an arbitrary link. + */ + +__LA_DECL struct archive_entry_linkresolver *archive_entry_linkresolver_new(void); +__LA_DECL void archive_entry_linkresolver_set_strategy( + struct archive_entry_linkresolver *, int /* format_code */); +__LA_DECL void archive_entry_linkresolver_free(struct archive_entry_linkresolver *); +__LA_DECL void archive_entry_linkify(struct archive_entry_linkresolver *, + struct archive_entry **, struct archive_entry **); +__LA_DECL struct archive_entry *archive_entry_partial_links( + struct archive_entry_linkresolver *res, unsigned int *links); +#ifdef __cplusplus +} +#endif + +/* This is meaningless outside of this header. */ +#undef __LA_DECL + +#endif /* !ARCHIVE_ENTRY_H_INCLUDED */ diff --git a/Sources/ContainerizationArchive/FileArchiveWriterDelegate.swift b/Sources/ContainerizationArchive/FileArchiveWriterDelegate.swift new file mode 100644 index 00000000..b9510aaf --- /dev/null +++ b/Sources/ContainerizationArchive/FileArchiveWriterDelegate.swift @@ -0,0 +1,65 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation +import SystemPackage + +public final class FileArchiveWriterDelegate: ArchiveWriterDelegate { + + public let path: FilePath + private var fd: FileDescriptor! + + public init(path: FilePath) { + self.path = path + } + + public convenience init(url: URL) { + self.init(path: FilePath(url.path)) + } + + public func open(archive: ArchiveWriter) throws { + self.fd = try FileDescriptor.open( + self.path, .writeOnly, options: [.create, .append], permissions: [.groupRead, .otherRead, .ownerReadWrite]) + } + + public func write(archive: ArchiveWriter, buffer: UnsafeRawBufferPointer) throws -> Int { + try fd.write(buffer) + } + + public func close(archive: ArchiveWriter) throws { + try self.fd.close() + } + + public func free(archive: ArchiveWriter) { + self.fd = nil + } + + deinit { + if let fd = self.fd { + try? fd.close() + } + } +} + +extension ArchiveWriter { + public convenience init(configuration: ArchiveWriterConfiguration, file: URL) throws { + try self.init(configuration: configuration, delegate: FileArchiveWriterDelegate(url: file)) + } + public convenience init(format: Format, filter: Filter, options: [Options] = [], file: URL) throws { + try self.init( + configuration: .init(format: format, filter: filter), delegate: FileArchiveWriterDelegate(url: file)) + } +} diff --git a/Sources/ContainerizationArchive/Reader.swift b/Sources/ContainerizationArchive/Reader.swift new file mode 100644 index 00000000..84d5055e --- /dev/null +++ b/Sources/ContainerizationArchive/Reader.swift @@ -0,0 +1,142 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import CArchive +import Foundation + +public final class ArchiveReader { + var underlying: OpaquePointer? + let fileHandle: FileHandle? + + public convenience init(format: Format, filter: Filter, file: URL) throws { + let fileHandle = try FileHandle(forReadingFrom: file) + try self.init(format: format, filter: filter, fileHandle: fileHandle) + } + + public init(format: Format, filter: Filter, fileHandle: FileHandle) throws { + self.underlying = archive_read_new() + self.fileHandle = fileHandle + + try archive_read_set_format(underlying, format.code) + .checkOk(elseThrow: .unableToSetFormat(format.code, format)) + try archive_read_append_filter(underlying, filter.code) + .checkOk(elseThrow: .unableToAddFilter(filter.code, filter)) + + let fd = fileHandle.fileDescriptor + try archive_read_open_fd(underlying, fd, 4096) + .checkOk(elseThrow: { .unableToOpenArchive($0) }) + } + + // Initialize the archive reader by trying to auto detect the archive and compression format + public init(file: URL) throws { + self.underlying = archive_read_new() + let fileHandle = try FileHandle(forReadingFrom: file) + self.fileHandle = fileHandle + try archive_read_support_filter_all(underlying) + .checkOk(elseThrow: .failedToDetectFilter) + try archive_read_support_format_all(underlying) + .checkOk(elseThrow: .failedToDetectFormat) + let fd = fileHandle.fileDescriptor + try archive_read_open_fd(underlying, fd, 4096) + .checkOk(elseThrow: { .unableToOpenArchive($0) }) + } + + deinit { + archive_read_free(underlying) + try? fileHandle?.close() + } +} + +extension CInt { + fileprivate func checkOk(elseThrow error: @autoclosure () -> ArchiveError) throws { + guard self == ARCHIVE_OK else { throw error() } + } + fileprivate func checkOk(elseThrow error: (CInt) -> ArchiveError) throws { + guard self == ARCHIVE_OK else { throw error(self) } + } + +} + +extension ArchiveReader: Sequence { + public func makeIterator() -> Iterator { + Iterator(reader: self) + } + + public struct Iterator: IteratorProtocol { + var reader: ArchiveReader + + public mutating func next() -> (WriteEntry, Data)? { + let entry = WriteEntry() + let result = archive_read_next_header2(reader.underlying, entry.underlying) + if result == ARCHIVE_EOF { + return nil + } + + var data = Data() + while true { + let capacity = Int(data.isEmpty ? (entry.size ?? 4096) : 4096) + + var part = Data(count: capacity) + let c = part.withUnsafeMutableBytes { (buffer: UnsafeMutableRawBufferPointer) in + archive_read_data(reader.underlying, buffer.baseAddress!, buffer.count) + } + guard c > 0 else { break } + part.count = c + data.append(part) + } + return (entry, data) + } + } +} + +extension ArchiveReader { + public convenience init(name: String, bundle: Data, tempDirectoryBaseName: String? = nil) throws { + let baseName = tempDirectoryBaseName ?? "Unarchiver" + let url = createTemporaryDirectory(baseName: baseName)!.appendingPathComponent(name) + + try bundle.write(to: url, options: .atomic) + + try self.init(format: .zip, filter: .none, file: url) + } + + /// Extracts the contents of an archive to the provided directory. + /// Currently only handles regular files and directories present in the archive. + public func extractContents(to directory: URL) throws { + let fm = FileManager.default + var foundEntry = false + for (entry, data) in self { + guard let p = entry.path else { continue } + foundEntry = true + let type = entry.fileType + let target = directory.appending(path: p) + switch type { + case .regular: + try data.write(to: target, options: .atomic) + case .directory: + try fm.createDirectory(at: target, withIntermediateDirectories: true) + default: + continue + } + chmod(target.path(), entry.permissions) + if let owner = entry.owner, let group = entry.group { + chown(target.path(), owner, group) + } + } + guard foundEntry else { + throw ArchiveError.failedToExtractArchive("No entries found in archive") + } + } +} diff --git a/Sources/ContainerizationArchive/TempDir.swift b/Sources/ContainerizationArchive/TempDir.swift new file mode 100644 index 00000000..f8d432a7 --- /dev/null +++ b/Sources/ContainerizationArchive/TempDir.swift @@ -0,0 +1,31 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationExtras +import Foundation + +func createTemporaryDirectory(baseName: String) -> URL? { + let url = FileManager.default.uniqueTemporaryDirectory().appendingPathComponent( + "\(baseName).XXXXXX") + guard let templatePathData = (url.absoluteURL.path as NSString).utf8String else { + return nil + } + + let pathData = UnsafeMutablePointer(mutating: templatePathData) + mkdtemp(pathData) + + return URL(fileURLWithPath: String(cString: pathData), isDirectory: true) +} diff --git a/Sources/ContainerizationArchive/WriteEntry.swift b/Sources/ContainerizationArchive/WriteEntry.swift new file mode 100644 index 00000000..54bc535e --- /dev/null +++ b/Sources/ContainerizationArchive/WriteEntry.swift @@ -0,0 +1,301 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import CArchive +import Foundation + +public final class WriteEntry { + let underlying: OpaquePointer + + public init(_ archive: ArchiveWriter) { + underlying = archive_entry_new2(archive.underlying) + } + + public init() { + underlying = archive_entry_new() + } + + deinit { + archive_entry_free(underlying) + } +} + +extension WriteEntry { + public var size: Int64? { + get { + guard archive_entry_size_is_set(underlying) != 0 else { return nil } + return archive_entry_size(underlying) + } + set { + if let s = newValue { + archive_entry_set_size(underlying, s) + } else { + archive_entry_unset_size(underlying) + } + } + } + + public var permissions: mode_t { + get { + archive_entry_perm(underlying) + } + set { + archive_entry_set_perm(underlying, newValue) + } + } + + public var owner: uid_t? { + get { + uid_t(exactly: archive_entry_uid(underlying)) + } + set { + archive_entry_set_uid(underlying, Int64(newValue ?? 0)) + } + } + + public var group: gid_t? { + get { + gid_t(exactly: archive_entry_gid(underlying)) + } + set { + archive_entry_set_gid(underlying, Int64(newValue ?? 0)) + } + } + + public var hardlink: String? { + get { + guard let cstr = archive_entry_hardlink(underlying) else { + return nil + } + return String(cString: cstr) + } + set { + guard let newValue else { + archive_entry_set_hardlink(underlying, nil) + return + } + newValue.withCString { + archive_entry_set_hardlink(underlying, $0) + } + } + } + + public var hardlinkUtf8: String? { + get { + guard let cstr = archive_entry_hardlink_utf8(underlying) else { + return nil + } + return String(cString: cstr, encoding: .utf8) + } + set { + guard let newValue else { + archive_entry_set_hardlink_utf8(underlying, nil) + return + } + newValue.withCString { + archive_entry_set_hardlink_utf8(underlying, $0) + } + } + } + + public var strmode: String? { + if let cstr = archive_entry_strmode(underlying) { + return String(cString: cstr) + } + return nil + } + + public var fileType: URLFileResourceType { + get { + switch archive_entry_filetype(underlying) { + case S_IFIFO: return .namedPipe + case S_IFCHR: return .characterSpecial + case S_IFDIR: return .directory + case S_IFBLK: return .blockSpecial + case S_IFREG: return .regular + case S_IFLNK: return .symbolicLink + case S_IFSOCK: return .socket + default: return .unknown + } + } + set { + switch newValue { + case .namedPipe: archive_entry_set_filetype(underlying, UInt32(S_IFIFO as mode_t)) + case .characterSpecial: archive_entry_set_filetype(underlying, UInt32(S_IFCHR as mode_t)) + case .directory: archive_entry_set_filetype(underlying, UInt32(S_IFDIR as mode_t)) + case .blockSpecial: archive_entry_set_filetype(underlying, UInt32(S_IFBLK as mode_t)) + case .regular: archive_entry_set_filetype(underlying, UInt32(S_IFREG as mode_t)) + case .symbolicLink: archive_entry_set_filetype(underlying, UInt32(S_IFLNK as mode_t)) + case .socket: archive_entry_set_filetype(underlying, UInt32(S_IFSOCK as mode_t)) + default: archive_entry_set_filetype(underlying, 0) + } + } + } + + public var contentAccessDate: Date? { + get { + Date( + underlying, + archive_entry_atime_is_set, + archive_entry_atime, + archive_entry_atime_nsec) + } + set { + setDate( + newValue, + underlying, archive_entry_set_atime, + archive_entry_unset_atime) + } + } + + public var creationDate: Date? { + get { + Date( + underlying, + archive_entry_ctime_is_set, + archive_entry_ctime, + archive_entry_ctime_nsec) + } + set { + setDate( + newValue, + underlying, archive_entry_set_ctime, + archive_entry_unset_ctime) + } + } + + public var modificationDate: Date? { + get { + Date( + underlying, + archive_entry_mtime_is_set, + archive_entry_mtime, + archive_entry_mtime_nsec) + } + set { + setDate( + newValue, + underlying, archive_entry_set_mtime, + archive_entry_unset_mtime) + } + } + + public var path: String? { + get { + guard let pathname = archive_entry_pathname(underlying) else { + return nil + } + return String(cString: pathname) + } + set { + guard let newValue else { + archive_entry_set_pathname(underlying, nil) + return + } + newValue.withCString { + archive_entry_set_pathname(underlying, $0) + } + } + } + + public var pathUtf8: String? { + get { + guard let pathname = archive_entry_pathname_utf8(underlying) else { + return nil + } + return String(cString: pathname) + } + set { + guard let newValue else { + archive_entry_set_pathname_utf8(underlying, nil) + return + } + newValue.withCString { + archive_entry_set_pathname_utf8(underlying, $0) + } + } + } + + public var symlinkTarget: String? { + get { + guard let target = archive_entry_symlink(underlying) else { + return nil + } + return String(cString: target) + } + set { + guard let newValue else { + archive_entry_set_symlink(underlying, nil) + return + } + newValue.withCString { + archive_entry_set_symlink(underlying, $0) + } + } + } + + public var xattrs: [String: Data] { + get { + archive_entry_xattr_reset(self.underlying) + var attrs: [String: Data] = [:] + var namePtr: UnsafePointer? + var valuePtr: UnsafeRawPointer? + var size: Int = 0 + while archive_entry_xattr_next(self.underlying, &namePtr, &valuePtr, &size) == 0 { + let _name = namePtr.map { String(cString: $0) } + let _value = valuePtr.map { Data(bytes: $0, count: size) } + guard let name = _name, let value = _value else { + continue + } + attrs[name] = value + } + return attrs + } + set { + archive_entry_xattr_clear(self.underlying) + for (key, value) in newValue { + value.withUnsafeBytes { ptr in + archive_entry_xattr_add_entry(self.underlying, key, ptr.baseAddress, [UInt8](value).count) + } + } + } + } + + fileprivate func setDate( + _ date: Date?, _ underlying: OpaquePointer, _ setter: (OpaquePointer, time_t, CLong) -> Void, + _ unset: (OpaquePointer) -> Void + ) { + if let d = date { + let ti = d.timeIntervalSince1970 + let seconds = floor(ti) + let nsec = max(0, min(1_000_000_000, ti - seconds * 1_000_000_000)) + setter(underlying, time_t(seconds), CLong(nsec)) + } else { + unset(underlying) + } + } +} + +extension Date { + init?( + _ underlying: OpaquePointer, _ isSet: (OpaquePointer) -> CInt, _ seconds: (OpaquePointer) -> time_t, + _ nsec: (OpaquePointer) -> CLong + ) { + guard isSet(underlying) != 0 else { return nil } + let ti = TimeInterval(seconds(underlying)) + TimeInterval(nsec(underlying)) * 0.000_000_001 + self.init(timeIntervalSince1970: ti) + } +} diff --git a/Sources/ContainerizationEXT4/EXT4+Export.swift b/Sources/ContainerizationEXT4/EXT4+Export.swift new file mode 100644 index 00000000..559088dd --- /dev/null +++ b/Sources/ContainerizationEXT4/EXT4+Export.swift @@ -0,0 +1,202 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +#if os(macOS) +import ContainerizationArchive +import Foundation +import SystemPackage + +extension EXT4.EXT4Reader { + public func export(archive: FilePath) throws { + let config = ArchiveWriterConfiguration( + format: .paxRestricted, filter: .none, options: [Options.xattrformat(.schily)]) + let writer = try ArchiveWriter(configuration: config) + try writer.open(file: archive.url) + var items = self.tree.root.pointee.children + let hardlinkedInodes = Set(self.hardlinks.values) + var hardlinkTargets: [EXT4.InodeNumber: FilePath] = [:] + + while items.count > 0 { + let itemPtr = items.removeFirst() + let item = itemPtr.pointee + let inode = try self.getInode(number: item.inode) + let entry = WriteEntry() + let mode = inode.mode + let size: UInt64 = (UInt64(inode.sizeHigh) << 32) | UInt64(inode.sizeLow) + entry.permissions = mode + guard let path = item.path else { + continue + } + if hardlinkedInodes.contains(item.inode) { + hardlinkTargets[item.inode] = path + } + guard self.hardlinks[path] == nil else { + continue + } + var attributes: [EXT4.ExtendedAttribute] = [] + let buffer: [UInt8] = EXT4.tupleToArray(inode.inlineXattrs) + if !buffer.allZeros { + try attributes.append(contentsOf: Self.readInlineExtenedAttributes(from: buffer)) + } + if inode.xattrBlockLow != 0 { + let block = inode.xattrBlockLow + try self.seek(block: block) + guard let buffer = try self.handle.read(upToCount: Int(self.blockSize)) else { + throw EXT4.Error.couldNotReadBlock(block) + } + try attributes.append(contentsOf: Self.readBlockExtenedAttributes(from: [UInt8](buffer))) + } + + var xattrs: [String: Data] = [:] + for attribute in attributes { + guard attribute.fullName != "system.data" else { + continue + } + xattrs[attribute.fullName] = Data(attribute.value) + } + + let pathStr = path.description + entry.path = pathStr + entry.size = Int64(size) + entry.group = gid_t(inode.gid) + entry.owner = uid_t(inode.uid) + entry.creationDate = Date(fsTimestamp: UInt64((inode.ctimeExtra << 32) | inode.ctime)) + entry.modificationDate = Date(fsTimestamp: UInt64((inode.mtimeExtra << 32) | inode.mtime)) + entry.contentAccessDate = Date(fsTimestamp: UInt64((inode.atimeExtra << 32) | inode.atime)) + entry.xattrs = xattrs + + if mode.isDir() { + entry.fileType = .directory + for child in item.children { + items.append(child) + } + if pathStr == "" { + continue + } + try writer.writeEntry(entry: entry, data: nil) + } else if mode.isReg() { + entry.fileType = .regular + var data = Data() + var remaining: UInt64 = size + if let block = item.blocks { + for dataBlock in block.start.. self.blockSize { + count = self.blockSize + } else { + count = remaining + } + guard let dataBytes = try self.handle.read(upToCount: Int(count)) else { + throw EXT4.Error.couldNotReadBlock(dataBlock) + } + data.append(dataBytes) + remaining -= UInt64(dataBytes.count) + } + } + if let additionalBlocks = item.additionalBlocks { + for block in additionalBlocks { + for dataBlock in block.start.. self.blockSize { + count = self.blockSize + } else { + count = remaining + } + guard let dataBytes = try self.handle.read(upToCount: Int(count)) else { + throw EXT4.Error.couldNotReadBlock(dataBlock) + } + data.append(dataBytes) + remaining -= UInt64(dataBytes.count) + } + } + } + try writer.writeEntry(entry: entry, data: data) + } else if mode.isLink() { + entry.fileType = .symbolicLink + if size < 60 { + let linkBytes = EXT4.tupleToArray(inode.block) + entry.symlinkTarget = String(data: Data(linkBytes), encoding: .utf8) ?? "" + } else { + if let block = item.blocks { + try self.seek(block: block.start) + guard let linkBytes = try self.handle.read(upToCount: Int(size)) else { + throw EXT4.Error.couldNotReadBlock(block.start) + } + entry.symlinkTarget = String(data: Data(linkBytes), encoding: .utf8) ?? "" + } + } + try writer.writeEntry(entry: entry, data: nil) + } else { // do not process sockets, fifo, character and block devices + continue + } + } + for (path, number) in self.hardlinks { + guard let targetPath = hardlinkTargets[number] else { + continue + } + let inode = try self.getInode(number: number) + let entry = WriteEntry() + entry.path = path.description + entry.hardlink = targetPath.description + entry.permissions = inode.mode + entry.group = gid_t(inode.gid) + entry.owner = uid_t(inode.uid) + entry.creationDate = Date(fsTimestamp: UInt64((inode.ctimeExtra << 32) | inode.ctime)) + entry.modificationDate = Date(fsTimestamp: UInt64((inode.mtimeExtra << 32) | inode.mtime)) + entry.contentAccessDate = Date(fsTimestamp: UInt64((inode.atimeExtra << 32) | inode.atime)) + try writer.writeEntry(entry: entry, data: nil) + } + try writer.finishEncoding() + } + + public static func readInlineExtenedAttributes(from buffer: [UInt8]) throws -> [EXT4.ExtendedAttribute] { + let header = UInt32(littleEndian: buffer[0...4].withUnsafeBytes { $0.load(as: UInt32.self) }) + if header != EXT4.XAttrHeaderMagic { + throw EXT4.FileXattrsState.Error.missingXAttrHeader + } + return try EXT4.FileXattrsState.read(buffer: buffer, start: 4, offset: 4) + } + + public static func readBlockExtenedAttributes(from buffer: [UInt8]) throws -> [EXT4.ExtendedAttribute] { + let header = UInt32(littleEndian: buffer[0...4].withUnsafeBytes { $0.load(as: UInt32.self) }) + if header != EXT4.XAttrHeaderMagic { + throw EXT4.FileXattrsState.Error.missingXAttrHeader + } + + return try EXT4.FileXattrsState.read(buffer: [UInt8](buffer), start: 32, offset: 0) + } + + func seek(block: UInt32) throws { + try self.handle.seek(toOffset: UInt64(block) * blockSize) + } +} + +extension Date { + init(fsTimestamp: UInt64) { + if fsTimestamp == 0 { + self = Date.distantPast + return + } + + let seconds = Int64(fsTimestamp & 0x3_ffff_ffff) + let nanoseconds = Double(fsTimestamp >> 34) / 1_000_000_000 + + self = Date(timeIntervalSince1970: Double(seconds) + nanoseconds) + } +} +#endif diff --git a/Sources/ContainerizationEXT4/EXT4+Extensions.swift b/Sources/ContainerizationEXT4/EXT4+Extensions.swift new file mode 100644 index 00000000..d811af84 --- /dev/null +++ b/Sources/ContainerizationEXT4/EXT4+Extensions.swift @@ -0,0 +1,99 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +extension EXT4.InodeFlag { + public static func | (lhs: Self, rhs: Self) -> Self { + Self(rawValue: lhs.rawValue | rhs.rawValue) + } + + public static func | (lhs: Self, rhs: Self) -> UInt32 { + lhs.rawValue | rhs.rawValue + } + + public static func | (lhs: Self, rhs: UInt32) -> UInt32 { + lhs.rawValue | rhs + } +} + +extension EXT4.CompatFeature { + public static func | (lhs: Self, rhs: Self) -> Self { + EXT4.CompatFeature(rawValue: lhs.rawValue | rhs.rawValue) + } + + public static func | (lhs: Self, rhs: Self) -> UInt32 { + lhs.rawValue | rhs.rawValue + } +} + +extension EXT4.IncompatFeature { + public static func | (lhs: Self, rhs: Self) -> Self { + EXT4.IncompatFeature(rawValue: lhs.rawValue | rhs.rawValue) + } + + public static func | (lhs: Self, rhs: Self) -> UInt32 { + lhs.rawValue | rhs.rawValue + } +} + +extension EXT4.RoCompatFeature { + public static func | (lhs: Self, rhs: Self) -> Self { + EXT4.RoCompatFeature(rawValue: lhs.rawValue | rhs.rawValue) + } + + public static func | (lhs: Self, rhs: Self) -> UInt32 { + lhs.rawValue | rhs.rawValue + } +} + +extension EXT4.FileModeFlag { + public static func | (lhs: Self, rhs: Self) -> Self { + Self(rawValue: lhs.rawValue | rhs.rawValue) + } + + public static func | (lhs: Self, rhs: Self) -> UInt16 { + lhs.rawValue | rhs.rawValue + } +} + +extension EXT4.XAttrEntry { + init(using bytes: [UInt8]) throws { + guard bytes.count == 16 else { + throw EXT4.Error.invalidXattrEntry + } + nameLength = bytes[0] + nameIndex = bytes[1] + let rawValue = Array(bytes[2...3]) + valueOffset = UInt16(littleEndian: rawValue.withUnsafeBytes { $0.load(as: UInt16.self) }) + + let rawValueInum = Array(bytes[4...7]) + valueInum = UInt32(littleEndian: rawValueInum.withUnsafeBytes { $0.load(as: UInt32.self) }) + + let rawSize = Array(bytes[8...11]) + valueSize = UInt32(littleEndian: rawSize.withUnsafeBytes { $0.load(as: UInt32.self) }) + + let rawHash = Array(bytes[12...]) + hash = UInt32(littleEndian: rawHash.withUnsafeBytes { $0.load(as: UInt32.self) }) + } +} + +extension EXT4 { + static func tupleToArray(_ tuple: T) -> [UInt8] { + let reflection = Mirror(reflecting: tuple) + return reflection.children.compactMap { $0.value as? UInt8 } + } +} diff --git a/Sources/ContainerizationEXT4/EXT4+FileTree.swift b/Sources/ContainerizationEXT4/EXT4+FileTree.swift new file mode 100644 index 00000000..5b2d4111 --- /dev/null +++ b/Sources/ContainerizationEXT4/EXT4+FileTree.swift @@ -0,0 +1,115 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation +import SystemPackage + +extension EXT4 { + class FileTree { + class FileTreeNode { + let inode: InodeNumber + let name: String + var children: [Ptr] = [] + var blocks: (start: UInt32, end: UInt32)? + var additionalBlocks: [(start: UInt32, end: UInt32)]? + var link: InodeNumber? + private var parent: Ptr? + + init( + inode: InodeNumber, + name: String, + parent: Ptr?, + children: [Ptr] = [], + blocks: (start: UInt32, end: UInt32)? = nil, + additionalBlocks: [(start: UInt32, end: UInt32)]? = nil, + link: InodeNumber? = nil + ) { + self.inode = inode + self.name = name + self.children = children + self.blocks = blocks + self.additionalBlocks = additionalBlocks + self.link = link + self.parent = parent + } + + deinit { + self.children.removeAll() + self.children = [] + self.blocks = nil + self.additionalBlocks = nil + self.link = nil + } + + var path: FilePath? { + var components: [String] = [self.name] + var _ptr = self.parent + while let ptr = _ptr { + components.append(ptr.pointee.name) + _ptr = ptr.pointee.parent + } + guard let last = components.last else { + return nil + } + guard components.count > 1 else { + return FilePath(last) + } + components = components.dropLast() + let path = components.reversed().joined(separator: "/") + guard let data = path.data(using: .utf8) else { + return nil + } + guard let dataPath = String(data: data, encoding: .utf8) else { + return nil + } + return FilePath(dataPath).pushing(FilePath(last)).lexicallyNormalized() + } + } + + var root: Ptr + + init(_ root: InodeNumber, _ name: String) { + self.root = Ptr.allocate(capacity: 1) + self.root.initialize(to: FileTreeNode(inode: root, name: name, parent: nil)) + } + + func lookup(path: FilePath) -> Ptr? { + var components: [String] = path.items + var node = self.root + if components.first == "/" { + components = Array(components.dropFirst()) + } + if components.count == 0 { + return node + } + for component in components { + var found = false + for childPtr in node.pointee.children { + let child = childPtr.pointee + if child.name == component { + node = childPtr + found = true + break + } + } + guard found else { + return nil + } + } + return node + } + } +} diff --git a/Sources/ContainerizationEXT4/EXT4+Format.swift b/Sources/ContainerizationEXT4/EXT4+Format.swift new file mode 100644 index 00000000..748b5d2d --- /dev/null +++ b/Sources/ContainerizationEXT4/EXT4+Format.swift @@ -0,0 +1,1340 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// swiftlint: disable discouraged_direct_init shorthand_operator syntactic_sugar + +import ContainerizationOS +import Foundation +import SystemPackage + +extension EXT4 { + /// The `EXT4.Formatter` class provides methods to format a block device with the ext4 filesystem. + /// It allows customization of block size and maximum disk size + public class Formatter { + private let blockSize: UInt32 + private var size: UInt64 + private let groupDescriptorSize: UInt32 = 32 + + private var blocksPerGroup: UInt32 { + blockSize * 8 + } + + private var maxInodesPerGroup: UInt32 { + blockSize * 8 // limited by inode bitmap + } + + private var groupsPerDescriptorBlock: UInt32 { + blockSize / groupDescriptorSize + } + + private var blockCount: UInt32 { + ((size - 1) / blockSize) + 1 + } + + private var groupCount: UInt32 { + (blockCount - 1) / blocksPerGroup + 1 + } + + private var groupDescriptorBlocks: UInt32 { + ((groupCount - 1) / groupsPerDescriptorBlock + 1) * 32 + } + + /// Initializes an ext4 filesystem formatter. + /// + /// This constructor creates an instance of the ext4 formatter designed to format a block device + /// with the ext4 filesystem. The formatter takes the path to the destination block device and + /// the desired block size of the filesystem as parameters. + /// + /// - Parameters: + /// - devicePath: The path to the block device where the ext4 filesystem will be created. + /// - blockSize: The block size of the ext4 filesystem, specified in bytes. Common values are + /// 4096 (4KB) or 1024 (1KB). Default is 4096 (4KB) + /// + /// - Note: This ext4 formatter is designed for creating block devices out of container images and does not support all the + /// features and options available in the full ext4 filesystem implementation. It focuses + /// on the core functionality required for formatting a block device with ext4. + /// + /// - Important: Ensure that the destination block device is accessible and has sufficient permissions + /// for formatting. The formatting process will erase all existing data on the device. + public init(_ devicePath: FilePath, blockSize: UInt32 = 4096, minDiskSize: UInt64 = 256.kib()) throws { + /// The constructor performs the following steps: + /// + /// 1. Creates the first 10 inodes: + /// - Inode 2 is reserved for the root directory ('/'). + /// - Inodes 1 and 3-10 are reserved for other special purposes. + /// + /// 2. Marks inode 11 as the first inode available for consumption by files, directories, sockets, + /// FIFOs, etc. + /// + /// 3. Initializes a directory tree with the root directory pointing to inode 2. + /// + /// 4. Moves the file descriptor to the start of the block where file metadata and data can be + /// written, which is located past the filesystem superblocks and group descriptor blocks. + /// + /// 5. Creates a "/lost+found" directory to satisfy the requirements of e2fsck (ext2/3/4 filesystem + /// checker). + + if !FileManager.default.fileExists(atPath: devicePath.description) { + FileManager.default.createFile(atPath: devicePath.description, contents: nil) + } + guard let fileHandle = FileHandle(forWritingTo: devicePath) else { + throw Error.notFound(devicePath) + } + self.handle = fileHandle + self.blockSize = blockSize + self.size = minDiskSize + // make this a 0 byte file + guard ftruncate(self.handle.fileDescriptor, 0) == 0 else { + throw Error.cannotTruncateFile(devicePath) + } + // make it a sparse file + guard lseek(self.handle.fileDescriptor, off_t(self.size - 1), 0) == self.size - 1 else { + throw Error.cannotCreateSparseFile(devicePath) + } + let zero: [UInt8] = [0] + try self.handle.write(contentsOf: zero) + // step #1 + self.inodes = [ + Ptr.allocate(capacity: 1), // defective block inode + { + let root = Inode.Root() + let rootPtr = Ptr.allocate(capacity: 1) + rootPtr.initialize(to: root) + return rootPtr + }(), + ] + // reserved inodes + for _ in 2...allocate(capacity: 1)) + } + // step #2 + self.tree = FileTree(EXT4.RootInode, "/") + // skip past the superblock and block descriptor table + try self.seek(block: self.groupDescriptorBlocks + 1) + // lost+found directory is required for e2fsck to pass + try self.create(path: FilePath("/lost+found"), mode: Inode.Mode(.S_IFDIR, 0o700)) + } + + // Creates a hard link at the path specified by `link` that points to the same file or directory as the path specified by `target`. + // + // A hard link is a directory entry that points to the same inode as another directory entry. It allows multiple paths to refer to the same file on the file system. + // + // - `link`: The path at which to create the new hard link. + // - `target`: The path of the existing file or directory to which the hard link should point. + // + // Throws an error if `target` path does not exist, or `target` is a directory. + public func link( + link: FilePath, + target: FilePath + ) throws { + // ensure that target exists + guard let targetPtr = self.tree.lookup(path: target) else { + throw Error.notFound(target) + } + let targetNode = targetPtr.pointee + let targetInodePtr = self.inodes[Int(targetNode.inode) - 1] + var targetInode = targetInodePtr.pointee + // ensure that target is not a directory since hardlinks cannot be + // created to directories + if targetInode.mode.isDir() { + throw Error.cannotCreateHardlinkstoDirTarget(link) + } + targetInode.linksCount += 1 + targetInodePtr.initialize(to: targetInode) + let parentPath: FilePath = link.dir + if self.tree.lookup(path: link) != nil { + try self.unlink(path: link) + } + guard let parentTreeNodePtr = self.tree.lookup(path: parentPath) else { + throw Error.notFound(parentPath) + } + let parentTreeNode = parentTreeNodePtr.pointee + let parentInodePtr = self.inodes[Int(parentTreeNode.inode) - 1] + let parentInode = parentInodePtr.pointee + guard parentInode.linksCount < EXT4.MaxLinks else { + throw Error.maximumLinksExceeded(parentPath) + } + let linkTreeNodePtr = Ptr.allocate(capacity: 1) + let linkTreeNode = FileTree.FileTreeNode( + inode: InodeNumber(2), // this field is ignored, using 2 so array operations dont panic + name: link.base, + parent: parentTreeNodePtr, + children: [], + blocks: nil, + link: targetNode.inode + ) + linkTreeNodePtr.initialize(to: linkTreeNode) + parentTreeNode.children.append(linkTreeNodePtr) + parentTreeNodePtr.initialize(to: parentTreeNode) + } + + // Deletes the file or directory at the specified path from the filesystem. + // + // It performs the following actions + // - set link count of the file's inode to 0 + // - recursively set link count to 0 for its children + // - free the inode + // - free data blocks + // - remove directory entry + // + // - `path`: The `FilePath` specifying the path of the file or directory to delete. + public func unlink(path: FilePath, directoryWhiteout: Bool = false) throws { + guard let pathPtr = self.tree.lookup(path: path) else { + // We are being asked to unlink something that does not exist. Ignore + return + } + let pathNode = pathPtr.pointee + let inodeNumber = Int(pathNode.inode) - 1 + let pathInodePtr = self.inodes[inodeNumber] + var pathInode = pathInodePtr.pointee + + if directoryWhiteout && !pathInode.mode.isDir() { + throw Error.notDirectory(path) + } + + for childPtr in pathNode.children { + try self.unlink(path: path.join(childPtr.pointee.name)) + } + + guard !directoryWhiteout else { + return + } + + if let parentNodePtr = self.tree.lookup(path: path.dir) { + let parentNode = parentNodePtr.pointee + let parentInodePtr = self.inodes[Int(parentNode.inode) - 1] + var parentInode = parentInodePtr.pointee + if pathInode.mode.isDir() { + if parentInode.linksCount > 2 { + parentInode.linksCount -= 1 + } + } + parentInodePtr.initialize(to: parentInode) + parentNode.children.removeAll { childPtr in + childPtr.pointee.name == path.base + } + parentNodePtr.initialize(to: parentNode) + } + + if let hardlink = pathNode.link { + // the file we are deleting is a hardlink, decrement the link count + let linkedInodePtr = self.inodes[Int(hardlink - 1)] + var linkedInode = linkedInodePtr.pointee + if linkedInode.linksCount > 2 { + linkedInode.linksCount -= 1 + linkedInodePtr.initialize(to: linkedInode) + } + } + + guard inodeNumber > FirstInode else { + // Free the inodes and the blocks related to the inode only if its valid + return + } + if let blocks = pathNode.blocks { + if !(blocks.start == blocks.end) { + self.deletedBlocks.append((start: blocks.start, end: blocks.end)) + } + } + for block in pathNode.additionalBlocks ?? [] { + self.deletedBlocks.append((start: block.start, end: block.end)) + } + let now = Date().fs() + pathInode = Inode() + pathInode.dtime = now.lo + pathInodePtr.initialize(to: pathInode) + } + + // Creates a file, directory, or symlink at the specified path, recursively creating parent directories if they don't already exist. + // + // - Parameters: + // - path: The FilePath representing the path where the file, directory, or symlink should be created. + // - link: An optional FilePath representing the target path for a symlink. If `nil`, a regular file or directory will be created. Preceeding '/' should be ommitted + // - mode: The permissions to set for the created file, directory, or symlink. + // - buf: An `InputStream` object providing the contents for the created file. Ignored when creating directories or symlinks. + // + // - Note: + // - This function recursively creates parent directories if they don't already exist. The `uid` and `gid` of the created parent directories are set to the values of their parent's `uid` and `gid`. + // - It is expected that the user sets the permissions explicity later + // - This function only supports creating files, directories, and symlinks. Attempting to create other types of file system objects will result in an error. + // - In case of symlinks, the preceeding '/' should be omitted + // + // - Example usage: + // ```swift + // let formatter = EXT4.Formatter(devicePath: "ext4.img") + // // create a directory + // try formatter.create(path: FilePath("/dir"), + // mode: EXT4.Inode.Mode(.S_IFDIR, 0o700)) + // + // // create a file + // let inputStream = InputStream(data: "data".data(using: .utf8)!) + // inputStream.open() + // try formatter.create(path: FilePath("/dir/file"), + // mode: EXT4.Inode.Mode(.S_IFREG, 0o755), buf: inputStream) + // inputStream.close() + // + // // create a symlink + // try formatter.create(path: FilePath("/symlink"), link: "/dir/file", + // mode: EXT4.Inode.Mode(.S_IFLNK, 0o700)) + // ``` + public func create( + path: FilePath, + link: FilePath? = nil, // to create symbolic links + mode: UInt16, + ts: FileTimestamps = FileTimestamps(), + buf: InputStream? = nil, + uid: UInt32? = nil, + gid: UInt32? = nil, + xattrs: [String: Data]? = nil, + recursion: Bool = false + ) throws { + if let nodePtr = self.tree.lookup(path: path) { + let node = nodePtr.pointee + let inodePtr = self.inodes[Int(node.inode) - 1] + let inode = inodePtr.pointee + // Allowed replace + // ----------------------------- + // + // Original Type File Directory Symlink + // ---------------------------------------------- + // File | ✔ | ✘ | ✔ + // Directory | ✘ | ✔ | ✔ + // Symlink | ✔ | ✘ | ✔ + if mode.isDir() { + if !inode.mode.isDir() { + guard inode.mode.isLink() else { + throw Error.notDirectory(path) + } + } + // mkdir -p + if path.base == node.name { + guard !recursion else { + return + } + // create a new tree node to replace this one + var inode = inode + inode.mode = mode + if let uid { + inode.uid = uid.lo + inode.uidHigh = uid.hi + } + if let gid { + inode.gid = gid.lo + inode.gidHigh = gid.hi + } + inodePtr.initialize(to: inode) + return + } + } else if let _ = node.link { // ok to overwrite links + try self.unlink(path: path) + } else { // file can only be overwritten by another file + if inode.mode.isDir() { + guard mode.isLink() else { // unless it is a link, then it can be replaced by a dir + throw Error.notFile(path) + } + } + try self.unlink(path: path) + } + } + // create all predecessors recursively + let parentPath: FilePath = path.dir + try self.create(path: parentPath, mode: Inode.Mode(.S_IFDIR, 0o755), recursion: true) + guard let parentTreeNodePtr = self.tree.lookup(path: parentPath) else { + throw Error.notFound(parentPath) + } + let parentTreeNode = parentTreeNodePtr.pointee + let parentInodePtr = self.inodes[Int(parentTreeNode.inode) - 1] + var parentInode = parentInodePtr.pointee + guard parentInode.linksCount < EXT4.MaxLinks else { + throw Error.maximumLinksExceeded(parentPath) + } + + let childInodePtr = Ptr.allocate(capacity: 1) + var childInode = Inode() + var startBlock: UInt32 = 0 + var endBlock: UInt32 = 0 + defer { // update metadata + childInodePtr.initialize(to: childInode) + parentInodePtr.initialize(to: parentInode) + self.inodes.append(childInodePtr) + let childTreeNodePtr = Ptr.allocate(capacity: 1) + let childTreeNode = FileTree.FileTreeNode( + inode: InodeNumber(self.inodes.count), + name: path.base, + parent: parentTreeNodePtr, + children: [], + blocks: (startBlock, endBlock) + ) + childTreeNodePtr.initialize(to: childTreeNode) + parentTreeNode.children.append(childTreeNodePtr) + parentTreeNodePtr.initialize(to: parentTreeNode) + } + childInode.mode = mode + // uid,gid + if let uid { + childInode.uid = UInt16(uid & 0xffff) + childInode.uidHigh = UInt16((uid >> 16) & 0xffff) + } else { + childInode.uid = parentInode.uid + childInode.uidHigh = parentInode.uidHigh + } + if let gid { + childInode.gid = UInt16(gid & 0xffff) + childInode.gidHigh = UInt16((gid >> 16) & 0xffff) + } else { + childInode.gid = parentInode.gid + childInode.gidHigh = parentInode.gidHigh + } + if let xattrs, !xattrs.isEmpty { + var state = FileXattrsState( + inode: UInt32(self.inodes.count), inodeXattrCapacity: EXT4.InodeExtraSize, blockCapacity: blockSize) + try state.add(ExtendedAttribute(name: "system.data", value: [])) + for (s, d) in xattrs { + let attribute = ExtendedAttribute(name: s, value: [UInt8](d)) + try state.add(attribute) + } + if !state.inlineAttributes.isEmpty { + var buffer: [UInt8] = .init(repeating: 0, count: Int(EXT4.InodeExtraSize)) + try state.writeInlineAttributes(buffer: &buffer) + childInode.inlineXattrs = ( + buffer[0], buffer[1], buffer[2], buffer[3], buffer[4], buffer[5], buffer[6], buffer[7], + buffer[8], + buffer[9], + buffer[10], buffer[11], buffer[12], buffer[13], buffer[14], buffer[15], buffer[16], buffer[17], + buffer[18], + buffer[19], + buffer[20], buffer[21], buffer[22], buffer[23], buffer[24], buffer[25], buffer[26], buffer[27], + buffer[28], + buffer[29], + buffer[30], buffer[31], buffer[32], buffer[33], buffer[34], buffer[35], buffer[36], buffer[37], + buffer[38], + buffer[39], + buffer[40], buffer[41], buffer[42], buffer[43], buffer[44], buffer[45], buffer[46], buffer[47], + buffer[48], + buffer[49], + buffer[50], buffer[51], buffer[52], buffer[53], buffer[54], buffer[55], buffer[56], buffer[57], + buffer[58], + buffer[59], + buffer[60], buffer[61], buffer[62], buffer[63], buffer[64], buffer[65], buffer[66], buffer[67], + buffer[68], + buffer[69], + buffer[70], buffer[71], buffer[72], buffer[73], buffer[74], buffer[75], buffer[76], buffer[77], + buffer[78], + buffer[79], + buffer[80], buffer[81], buffer[82], buffer[83], buffer[84], buffer[85], buffer[86], buffer[87], + buffer[88], + buffer[89], + buffer[90], buffer[91], buffer[92], buffer[93], buffer[94], buffer[95] + ) + childInode.flags |= InodeFlag.inlineData.rawValue + } + if !state.blockAttributes.isEmpty { + var buffer: [UInt8] = .init(repeating: 0, count: Int(blockSize)) + try state.writeBlockAttributes(buffer: &buffer) + if self.pos % self.blockSize != 0 { + try self.seek(block: self.currentBlock + 1) + } + childInode.xattrBlockLow = self.currentBlock + try self.handle.write(contentsOf: buffer) + childInode.blocksLow += 1 + } + } + + childInode.atime = ts.accessLo + childInode.atimeExtra = ts.accessHi + // ctime is the last time the inode was changed which is now + childInode.ctime = ts.nowLo + childInode.ctimeExtra = ts.nowHi + childInode.mtime = ts.modificationLo + childInode.mtimeExtra = ts.modificationHi + childInode.crtime = ts.creationLo + childInode.crtimeExtra = ts.creationHi + childInode.linksCount = 1 + childInode.extraIsize = UInt16(EXT4.ExtraIsize) + // flags + childInode.flags = InodeFlag.hugeFile.rawValue + // size check + var size: UInt64 = 0 + // align with block boundary + if self.pos % self.blockSize != 0 { + try self.seek(block: self.currentBlock + 1) + } + // dir + if childInode.mode.isDir() { + childInode.linksCount += 1 + parentInode.linksCount += 1 + // to pass e2fsck, the convention is to sort children + // before committing to disk. Therefore, we are deferring + // writing dentries until commit() is called + return + } + // symbolic link + if let link { + startBlock = self.currentBlock + let linkPath = link.bytes + if linkPath.count < 60 { + size += UInt64(linkPath.count) + var blockData: [UInt8] = .init(repeating: 0, count: 60) + for i in 0...allocate(capacity: Int(self.blockSize)) + defer { tempBuf.deallocate() } + while case let block = buf.read(tempBuf.underlying, maxLength: Int(self.blockSize)), block > 0 { + size += UInt64(block) + if size > EXT4.MaxFileSize { + throw Error.fileTooBig(size) + } + let data = UnsafeRawBufferPointer(start: tempBuf.underlying, count: block) + try withUnsafeLittleEndianBuffer(of: data) { b in + try self.handle.write(contentsOf: b) + } + } + } + if self.pos % self.blockSize != 0 { + try self.seek(block: self.currentBlock + 1) + } + endBlock = self.currentBlock + childInode.sizeLow = size.lo + childInode.sizeHigh = size.hi + childInode = try self.writeExtents(childInode, (startBlock, endBlock)) + return + } + // FIFO, Socket and other types are not handled + throw Error.unsupportedFiletype + } + + public func setOwner(path: FilePath, uid: UInt16? = nil, gid: UInt16? = nil, recursive: Bool = false) throws { + // ensure that target exists + guard let pathPtr = self.tree.lookup(path: path) else { + throw Error.notFound(path) + } + let pathNode = pathPtr.pointee + let pathInodePtr = self.inodes[Int(pathNode.inode) - 1] + var pathInode = pathInodePtr.pointee + if let uid { + pathInode.uid = uid + } + if let gid { + pathInode.gid = gid + } + pathInodePtr.initialize(to: pathInode) + if recursive { + for childPtr in pathNode.children { + let child = childPtr.pointee + try self.setOwner(path: path.join(child.name), uid: uid, gid: gid, recursive: recursive) + } + } + } + + // Completes the formatting of an ext4 filesystem after writing the necessary structures. + // + // This function is responsible for finalizing the formatting process of an ext4 filesystem + // after the following structures have been written: + // - Inode table: Contains information about each file and directory in the filesystem. + // - Block bitmap: Tracks the allocation status of each block in the filesystem. + // - Inode bitmap: Tracks the allocation status of each inode in the filesystem. + // - Directory tree: Represents the hierarchical structure of directories and files. + // - Group descriptors: Stores metadata about each block group in the filesystem. + // - Superblock: Contains essential information about the filesystem's configuration. + // + // The function performs any necessary final steps to ensure the integrity and consistency + // of the ext4 filesystem before it can be mounted and used. + public func close() throws { + var breathWiseChildTree: [(parent: Ptr?, child: Ptr)] = [ + (nil, self.tree.root) + ] + while !breathWiseChildTree.isEmpty { + let (parent, child) = breathWiseChildTree.removeFirst() + try self.commit(parent, child) // commit directories iteratively + if child.pointee.link != nil { + continue + } + breathWiseChildTree.append(contentsOf: child.pointee.children.map { (child, $0) }) + } + let blockGroupSize = optimizeBlockGroupLayout(blocks: self.currentBlock, inodes: UInt32(self.inodes.count)) + let inodeTableOffset = try self.commitInodeTable( + blockGroups: blockGroupSize.blockGroups, + inodesPerGroup: blockGroupSize.inodesPerGroup + ) + if self.pos % self.blockSize != 0 { + try self.seek(block: self.currentBlock + 1) + } + // write bitmaps and group descriptors + + let bitmapOffset = self.currentBlock + let bitmapSize: UInt32 = blockGroupSize.blockGroups * 2 // each group has two bitmaps - for inodes, and for blocks + let dataSize: UInt32 = bitmapOffset + bitmapSize // last data block + var diskSize = dataSize + var minimumDiskSize = (blockGroupSize.blockGroups - 1) * self.blocksPerGroup + 1 + if blockGroupSize.blockGroups == 1 { + minimumDiskSize = self.blocksPerGroup // atleast 1 block group + } + if diskSize < minimumDiskSize { // for data + metadata + diskSize = minimumDiskSize + } + if self.size < minimumDiskSize { + self.size = UInt64(minimumDiskSize) * self.blockSize + } + // number of blocks needed for group descriptors + let groupDescriptorBlockCount: UInt32 = (blockGroupSize.blockGroups - 1) / self.groupsPerDescriptorBlock + 1 + guard groupDescriptorBlockCount <= self.groupDescriptorBlocks else { + throw Error.insufficientSpaceForGroupDescriptorBlocks + } + + var totalBlocks: UInt32 = 0 + var totalInodes: UInt32 = 0 + let inodeTableSizePerGroup: UInt32 = blockGroupSize.inodesPerGroup * EXT4.InodeSize / self.blockSize + var groupDescriptors: [GroupDescriptor] = [] + + let minGroups = (((self.pos / UInt64(self.blockSize)) - 1) / UInt64(self.blocksPerGroup)) + 1 + if self.size < minGroups * blocksPerGroup * blockSize { + self.size = UInt64(minGroups * blocksPerGroup * blockSize) + let pos = self.pos + guard lseek(self.handle.fileDescriptor, off_t(self.size - 1), 0) == self.size - 1 else { + throw Error.cannotResizeFS(self.size) + } + let zero: [UInt8] = [0] + try self.handle.write(contentsOf: zero) + try self.handle.seek(toOffset: pos) + } + let totalGroups = (((self.size / UInt64(self.blockSize)) - 1) / UInt64(self.blocksPerGroup)) + 1 + + // If the provided disk size is not aligned to a blockgroup boundary, it needs to + // be expanded to the next blockgroup boundary. + // Example: + // Provided disk size: 2 GB + 100MB: 2148 MB + // BlockSize: 4096 + // Blockgroup size: 32768 blocks: 128MB + // Number of blocks: 549888 + // Number of blockgroups = 549888 / 32768 = 16.78125 + // Aligned disk size = 557056 blocks = 17 blockgroups: 2176 MB + if self.size < totalGroups * blocksPerGroup * blockSize { + self.size = UInt64(totalGroups * blocksPerGroup * blockSize) + let pos = self.pos + guard lseek(self.handle.fileDescriptor, off_t(self.size - 1), 0) == self.size - 1 else { + throw Error.cannotResizeFS(self.size) + } + let zero: [UInt8] = [0] + try self.handle.write(contentsOf: zero) + try self.handle.seek(toOffset: pos) + } + for group in 0..> (j % 8)) & 1) + bitmap[Int(j / 8)] &= ~(1 << (j % 8)) + } + } + + // inodes bitmap goes into second bitmap block + for i in 0.. self.inodes.count { + continue + } + let inode = self.inodes[Int(ino) - 1] + if ino > 10 && inode.pointee.linksCount == 0 { // deleted files + continue + } + bitmap[Int(self.blockSize) + Int(i / 8)] |= 1 << (i % 8) + inodes += 1 + if inode.pointee.mode.isDir() { + dirs += 1 + } + } + + for i in (blockGroupSize.inodesPerGroup / 8)...init(repeating: 0, count: 1024)) + + let computedInodes = totalGroups * blockGroupSize.inodesPerGroup + var blocksCount = totalGroups * self.blocksPerGroup + while blocksCount < totalBlocks { + blocksCount = UInt64(totalBlocks) + } + let totalFreeBlocks: UInt64 + if totalBlocks > blocksCount { + totalFreeBlocks = 0 + } else { + totalFreeBlocks = blocksCount - totalBlocks + } + var superblock = SuperBlock() + superblock.inodesCount = computedInodes.lo + superblock.blocksCountLow = blocksCount.lo + superblock.blocksCountHigh = blocksCount.hi + superblock.freeBlocksCountLow = totalFreeBlocks.lo + superblock.freeBlocksCountHigh = totalFreeBlocks.hi + let freeInodesCount = computedInodes.lo - totalInodes + superblock.freeInodesCount = freeInodesCount + superblock.firstDataBlock = 0 + superblock.logBlockSize = 2 + superblock.logClusterSize = 2 + superblock.blocksPerGroup = self.blocksPerGroup + superblock.clustersPerGroup = self.blocksPerGroup + superblock.inodesPerGroup = blockGroupSize.inodesPerGroup + superblock.magic = EXT4.SuperBlockMagic + superblock.state = 1 // cleanly unmounted + superblock.errors = 1 // continue on error + superblock.creatorOS = 3 // freeBSD + superblock.revisionLevel = 1 // dynamic inode sizes + superblock.firstInode = EXT4.FirstInode + superblock.lpfInode = EXT4.LostAndFoundInode + superblock.inodeSize = UInt16(EXT4.InodeSize) + superblock.featureCompat = CompatFeature.sparseSuper2 | CompatFeature.extAttr + superblock.featureIncompat = + IncompatFeature.filetype | IncompatFeature.extents | IncompatFeature.flexBg | IncompatFeature.inlineData + superblock.featureRoCompat = + RoCompatFeature.largeFile | RoCompatFeature.hugeFile | RoCompatFeature.extraIsize + superblock.minExtraIsize = EXT4.ExtraIsize + superblock.wantExtraIsize = EXT4.ExtraIsize + superblock.logGroupsPerFlex = 31 + superblock.uuid = UUID().uuid + try withUnsafeLittleEndianBytes(of: superblock) { bytes in + try self.handle.write(contentsOf: bytes) + } + try self.handle.write(contentsOf: Array.init(repeating: 0, count: 2048)) + } + + // MARK: Private Methods and Properties + private var handle: FileHandle + private var inodes: [Ptr] + private var tree: FileTree + private var deletedBlocks: [(start: UInt32, end: UInt32)] = [] + + private var pos: UInt64 { + guard let offset = try? self.handle.offset() else { + return 0 + } + return offset + } + + private var currentBlock: UInt32 { + self.pos / self.blockSize + } + + private func seek(block: UInt32) throws { + try self.handle.seek(toOffset: UInt64(block) * blockSize) + } + + private func commitInodeTable(blockGroups: UInt32, inodesPerGroup: UInt32) throws -> UInt64 { + // inodeTable must go into a new block + if self.pos % blockSize != 0 { + try seek(block: currentBlock + 1) + } + let inodeTableOffset = UInt64(currentBlock) + + let inodeSize = MemoryLayout.size + // Write InodeTable + for inode in self.inodes { + try withUnsafeLittleEndianBytes(of: inode.pointee) { bytes in + try handle.write(contentsOf: bytes) + } + try self.handle.write( + contentsOf: Array.init(repeating: 0, count: Int(EXT4.InodeSize) - inodeSize)) + } + let tableSize: UInt64 = UInt64(EXT4.InodeSize) * blockGroups * inodesPerGroup + let rest = tableSize - uint32(self.inodes.count) * EXT4.InodeSize + let zeroBlock = Array.init(repeating: 0, count: Int(self.blockSize)) + for _ in 0..<(rest / self.blockSize) { + try self.handle.write(contentsOf: zeroBlock) + } + try self.handle.write(contentsOf: Array.init(repeating: 0, count: Int(rest % self.blockSize))) + return inodeTableOffset + } + + // optimizes the distribution of blockGroups to obtain the lowest number of blockGroups needed to + // represent all the inodes and all the blocks in the FS + private func optimizeBlockGroupLayout(blocks: UInt32, inodes: UInt32) -> ( + blockGroups: UInt32, inodesPerGroup: UInt32 + ) { + // counts the number of blockGroups given a particular inodesPerGroup size + let groupCount: (_ blocks: UInt32, _ inodes: UInt32, _ inodesPerGroup: UInt32) -> UInt32 = { + blocks, inodes, inodesPerGroup in + let inodeBlocksPerGroup: UInt32 = inodesPerGroup * EXT4.InodeSize / self.blockSize + let dataBlocksPerGroup: UInt32 = self.blocksPerGroup - inodeBlocksPerGroup - 2 // save room for the bitmaps + // Increase the block count to ensure there are enough groups for all the inodes. + let minBlocks: UInt32 = (inodes - 1) / inodesPerGroup * dataBlocksPerGroup + 1 + var updatedBlocks = blocks + if blocks < minBlocks { + updatedBlocks = minBlocks + } + return (updatedBlocks + dataBlocksPerGroup - 1) / dataBlocksPerGroup + } + + var groups: UInt32 = UInt32.max + var inodesPerGroup: UInt32 = 0 + let inc = Int(self.blockSize * 512) / Int(EXT4.InodeSize) // inodesPerGroup + // minimizes the number of blockGroups needed to its lowest value + for ipg in stride(from: inc, through: Int(self.maxInodesPerGroup), by: inc) { + let g = groupCount(blocks, inodes, UInt32(ipg)) + if g < groups { + groups = g + inodesPerGroup = UInt32(ipg) + } + } + return (groups, inodesPerGroup) + } + + private func commit(_ parentPtr: Ptr?, _ nodePtr: Ptr) throws { + let node = nodePtr.pointee + let inodePtr = self.inodes[Int(node.inode) - 1] + var inode = inodePtr.pointee + guard inode.linksCount > 0 else { + return + } + if node.link != nil { + return + } + if self.pos % self.blockSize != 0 { + try self.seek(block: self.currentBlock + 1) + } + if inode.mode.isDir() { + let startBlock = self.currentBlock + var left: Int = Int(self.blockSize) + try writeDirEntry(name: ".", inode: node.inode, left: &left) + if let parent = parentPtr { + try writeDirEntry(name: "..", inode: parent.pointee.inode, left: &left) + } else { + try writeDirEntry(name: "..", inode: node.inode, left: &left) + } + var sortedChildren = Array(node.children) + sortedChildren.sort { left, right in + left.pointee.inode < right.pointee.inode + } + for childPtr in sortedChildren { + let child = childPtr.pointee + try writeDirEntry(name: child.name, inode: child.inode, left: &left, link: child.link) + } + try finishDirEntryBlock(&left) + let endBlock = self.currentBlock + let size: UInt64 = UInt64(endBlock - startBlock) * self.blockSize + inode.sizeLow = size.lo + inode.sizeHigh = size.hi + inodePtr.initialize(to: inode) + node.blocks = (startBlock, endBlock) + nodePtr.initialize(to: node) + if self.pos % self.blockSize != 0 { + try self.seek(block: self.currentBlock + 1) + } + inode = try self.writeExtents(inode, (startBlock, endBlock)) + inodePtr.initialize(to: inode) + } + } + + private func fillExtents( + node: inout ExtentLeafNode, numExtents: UInt32, numBlocks: UInt32, start: UInt32, offset: UInt32 + ) { + for i in 0.. EXT4.MaxBlocksPerExtent { + length = EXT4.MaxBlocksPerExtent + } + let extentStart: UInt32 = start + extentBlock + let extent = ExtentLeaf( + block: extentBlock, + length: UInt16(length), + startHigh: 0, + startLow: extentStart + ) + node.leaves.append(extent) + } + } + + private func writeExtents(_ inode: Inode, _ blocks: (start: UInt32, end: UInt32)) throws -> Inode { + var inode = inode + // rest of code assumes that extents MUST go into a new block + if self.pos % self.blockSize != 0 { + try self.seek(block: self.currentBlock + 1) + } + let dataBlocks = blocks.end - blocks.start + let numExtents = (dataBlocks + EXT4.MaxBlocksPerExtent - 1) / EXT4.MaxBlocksPerExtent + var usedBlocks = dataBlocks + let extentNodeSize = 12 + let extentsPerBlock = self.blockSize / extentNodeSize - 1 + var blockData: [UInt8] = .init(repeating: 0, count: 60) + var blockIndex: Int = 0 + switch numExtents { + case 0: + return inode // noop + case 1..<5: + let extentHeader = ExtentHeader( + magic: EXT4.ExtentHeaderMagic, + entries: UInt16(numExtents), + max: 4, + depth: 0, + generation: 0) + + var node = ExtentLeafNode(header: extentHeader, leaves: []) + fillExtents(node: &node, numExtents: numExtents, numBlocks: dataBlocks, start: blocks.start, offset: 0) + withUnsafeLittleEndianBytes(of: node.header) { bytes in + for b in bytes { + blockData[blockIndex] = b + blockIndex = blockIndex + 1 + } + } + for leaf in node.leaves { + withUnsafeLittleEndianBytes(of: leaf) { bytes in + for b in bytes { + blockData[blockIndex] = b + blockIndex = blockIndex + 1 + } + } + } + case 5..<4 * UInt32(extentsPerBlock) + 1: + let extentBlocks = numExtents / extentsPerBlock + 1 + usedBlocks += extentBlocks + let extentHeader = ExtentHeader( + magic: EXT4.ExtentHeaderMagic, + entries: UInt16(extentBlocks), + max: 4, + depth: 1, + generation: 0 + ) + var root = ExtentIndexNode(header: extentHeader, indices: []) + for i in 0.. extentsPerBlock { + extentsInBlock = extentsPerBlock + } + let leafHeader = ExtentHeader( + magic: EXT4.ExtentHeaderMagic, + entries: UInt16(extentsInBlock), + max: UInt16(extentsPerBlock), + depth: 0, + generation: 0 + ) + var leafNode = ExtentLeafNode(header: leafHeader, leaves: []) + let offset = i * extentsPerBlock * EXT4.MaxBlocksPerExtent + fillExtents( + node: &leafNode, numExtents: extentsInBlock, numBlocks: dataBlocks, + start: blocks.start + offset, + offset: offset) + try withUnsafeLittleEndianBytes(of: leafNode.header) { bytes in + try self.handle.write(contentsOf: bytes) + } + for leaf in leafNode.leaves { + try withUnsafeLittleEndianBytes(of: leaf) { bytes in + try self.handle.write(contentsOf: bytes) + } + } + let extentTail = ExtentTail(checksum: leafNode.leaves.last!.block) + try withUnsafeLittleEndianBytes(of: extentTail) { bytes in + try self.handle.write(contentsOf: bytes) + } + root.indices.append(extentIdx) + } + withUnsafeLittleEndianBytes(of: root.header) { bytes in + for b in bytes { + blockData[blockIndex] = b + blockIndex = blockIndex + 1 + } + } + for leaf in root.indices { + withUnsafeLittleEndianBytes(of: leaf) { bytes in + for b in bytes { + blockData[blockIndex] = b + blockIndex = blockIndex + 1 + } + } + } + default: + throw Error.fileTooBig(UInt64(dataBlocks) * self.blockSize) + } + inode.block = ( + blockData[0], blockData[1], blockData[2], blockData[3], blockData[4], blockData[5], blockData[6], + blockData[7], + blockData[8], blockData[9], + blockData[10], blockData[11], blockData[12], blockData[13], blockData[14], blockData[15], blockData[16], + blockData[17], blockData[18], blockData[19], + blockData[20], blockData[21], blockData[22], blockData[23], blockData[24], blockData[25], blockData[26], + blockData[27], blockData[28], blockData[29], + blockData[30], blockData[31], blockData[32], blockData[33], blockData[34], blockData[35], blockData[36], + blockData[37], blockData[38], blockData[39], + blockData[40], blockData[41], blockData[42], blockData[43], blockData[44], blockData[45], blockData[46], + blockData[47], blockData[48], blockData[49], + blockData[50], blockData[51], blockData[52], blockData[53], blockData[54], blockData[55], blockData[56], + blockData[57], blockData[58], blockData[59] + ) + // ensure that inode's block count includes extent blocks + inode.blocksLow += usedBlocks + inode.flags = InodeFlag.extents | inode.flags + return inode + } + // writes a single directory entry + private func writeDirEntry(name: String, inode: InodeNumber, left: inout Int, link: InodeNumber? = nil) throws { + guard self.inodes[Int(inode) - 1].pointee.linksCount > 0 else { + return + } + guard let nameData = name.data(using: .utf8) else { + throw Error.invalidName(name) + } + let directoryEntrySize = MemoryLayout.size + let rlb = directoryEntrySize + nameData.count + let rl = (rlb + 3) & ~3 + if left < rl + 12 { + try self.finishDirEntryBlock(&left) + } + var mode = self.inodes[Int(inode) - 1].pointee.mode + var inodeNum = inode + if let link { + mode = self.inodes[Int(link) - 1].pointee.mode | 0o777 + inodeNum = link + } + let entry = DirectoryEntry( + inode: inodeNum, + recordLength: UInt16(rl), + nameLength: UInt8(nameData.count), + fileType: mode.fileType() + ) + try withUnsafeLittleEndianBytes(of: entry) { bytes in + try self.handle.write(contentsOf: bytes) + } + + try nameData.withUnsafeBytes { buffer in + try withUnsafeLittleEndianBuffer(of: buffer) { b in + try self.handle.write(contentsOf: b) + } + } + try self.handle.write(contentsOf: [UInt8](repeating: 0, count: rl - rlb)) + left = left - rl + } + + private func finishDirEntryBlock(_ left: inout Int) throws { + defer { left = Int(self.blockSize) } + if left <= 0 { + return + } + let entry = DirectoryEntry( + inode: InodeNumber(0), + recordLength: UInt16(left), + nameLength: 0, + fileType: 0 + ) + try withUnsafeLittleEndianBytes(of: entry) { bytes in + try self.handle.write(contentsOf: bytes) + } + left = left - MemoryLayout.size + if left < 4 { + throw Error.noSpaceForTrailingDEntry + } + try self.handle.write(contentsOf: [UInt8](repeating: 0, count: Int(left))) + } + + public enum Error: Swift.Error, CustomStringConvertible, Sendable, Equatable { + case notDirectory(_ path: FilePath) + case notFile(_ path: FilePath) + case notFound(_ path: FilePath) + case alreadyExists(_ path: FilePath) + case unsupportedFiletype + case maximumLinksExceeded(_ path: FilePath) + case fileTooBig(_ size: UInt64) + case invalidLink(_ path: FilePath) + case invalidName(_ name: String) + case noSpaceForTrailingDEntry + case insufficientSpaceForGroupDescriptorBlocks + case cannotCreateHardlinkstoDirTarget(_ path: FilePath) + case cannotTruncateFile(_ path: FilePath) + case cannotCreateSparseFile(_ path: FilePath) + case cannotResizeFS(_ size: UInt64) + public var description: String { + switch self { + case .notDirectory(let path): + return "\(path) is not a directory" + case .notFile(let path): + return "\(path) is not a file" + case .notFound(let path): + return "\(path) not found" + case .alreadyExists(let path): + return "\(path) already exists" + case .unsupportedFiletype: + return "file type not supported" + case .maximumLinksExceeded(let path): + return "maximum links exceeded for path: \(path)" + case .fileTooBig(let size): + return "\(size) exceeds max file size (128 GiB)" + case .invalidLink(let path): + return "'\(path)' is an invalid link" + case .invalidName(let name): + return "'\(name)' is an invalid name" + case .noSpaceForTrailingDEntry: + return "not enough space for trailing dentry" + case .insufficientSpaceForGroupDescriptorBlocks: + return "not enough space for group descriptor blocks" + case .cannotCreateHardlinkstoDirTarget(let path): + return "cannot create hard links to directory target: \(path)" + case .cannotTruncateFile(let path): + return "cannot truncate file: \(path)" + case .cannotCreateSparseFile(let path): + return "cannot create sparse file at \(path)" + case .cannotResizeFS(let size): + return "cannot resize fs to \(size) bytes" + } + } + } + + deinit { + for inode in inodes { + inode.deinitialize(count: 1) + inode.deallocate() + } + self.inodes.removeAll() + } + } +} + +extension Date { + func fs() -> UInt64 { + if self == Date.distantPast { + return 0 + } + + let s = self.timeIntervalSince1970 + + if s < -0x8000_0000 { + return 0x8000_0000 + } + + if s > 0x3_7fff_ffff { + return 0x3_7fff_ffff + } + + let seconds = UInt64(s) + let nanoseconds = UInt64(self.timeIntervalSince1970.truncatingRemainder(dividingBy: 1) * 1_000_000_000) + + return seconds | (nanoseconds << 34) + } +} diff --git a/Sources/ContainerizationEXT4/EXT4+Ptr.swift b/Sources/ContainerizationEXT4/EXT4+Ptr.swift new file mode 100644 index 00000000..f2603994 --- /dev/null +++ b/Sources/ContainerizationEXT4/EXT4+Ptr.swift @@ -0,0 +1,85 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +extension EXT4 { + class Ptr { + let underlying: UnsafeMutablePointer + private var capacity: Int + private var initialized: Bool + private var allocated: Bool + + var pointee: T { + underlying.pointee + } + + init(capacity: Int) { + self.underlying = UnsafeMutablePointer.allocate(capacity: capacity) + self.capacity = capacity + self.allocated = true + self.initialized = false + } + + static func allocate(capacity: Int) -> Ptr { + Ptr(capacity: capacity) + } + + func initialize(to value: T) { + guard self.allocated else { + return + } + if self.initialized { + self.underlying.deinitialize(count: self.capacity) + } + self.underlying.initialize(to: value) + self.allocated = true + self.initialized = true + } + + func deallocate() { + guard self.allocated else { + return + } + self.underlying.deallocate() + self.allocated = false + self.initialized = false + } + + func deinitialize(count: Int) { + guard self.allocated else { + return + } + guard self.initialized else { + return + } + self.underlying.deinitialize(count: count) + self.initialized = false + self.allocated = true + } + + func move() -> T { + self.initialized = false + self.allocated = true + return self.underlying.move() + } + + deinit { + self.deinitialize(count: self.capacity) + self.deallocate() + } + } +} diff --git a/Sources/ContainerizationEXT4/EXT4+Reader.swift b/Sources/ContainerizationEXT4/EXT4+Reader.swift new file mode 100644 index 00000000..6f76ee8e --- /dev/null +++ b/Sources/ContainerizationEXT4/EXT4+Reader.swift @@ -0,0 +1,271 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation +import SystemPackage + +extension EXT4 { + public class EXT4Reader { + let handle: FileHandle + let superBlock: EXT4.SuperBlock + + private var groupDescriptors: [UInt32: EXT4.GroupDescriptor] = [:] + private var inodes: [InodeNumber: EXT4.Inode] = [:] + + var hardlinks: [FilePath: InodeNumber] = [:] + var tree: EXT4.FileTree = EXT4.FileTree(EXT4.RootInode, ".") + var blockSize: UInt64 { + UInt64(1024 * (1 << superBlock.logBlockSize)) + } + + private var groupDescriptorSize: UInt16 { + if superBlock.featureIncompat & EXT4.IncompatFeature.bit64.rawValue != 0 { + return superBlock.descSize + } + return UInt16(MemoryLayout.size) + } + + public init(blockDevice: FilePath) throws { + guard FileManager.default.fileExists(atPath: blockDevice.description) else { + throw EXT4.Error.notFound(blockDevice.description) + } + + guard let fileHandle = FileHandle(forReadingAtPath: blockDevice) else { + throw Error.notFound(blockDevice.description) + } + self.handle = fileHandle + try handle.seek(toOffset: EXT4.SuperBlockOffset) + + let superBlockSize = MemoryLayout.size + guard let data = try? self.handle.read(upToCount: superBlockSize) else { + throw EXT4.Error.couldNotReadSuperBlock(blockDevice.description, EXT4.SuperBlockOffset, superBlockSize) + } + let sb = data.withUnsafeBytes { ptr in + ptr.loadLittleEndian(as: EXT4.SuperBlock.self) + } + guard sb.magic == EXT4.SuperBlockMagic else { + throw EXT4.Error.invalidSuperBlock + } + self.superBlock = sb + var items: [(item: Ptr, inode: InodeNumber)] = [ + (self.tree.root, EXT4.RootInode) + ] + while items.count > 0 { + guard let item = items.popLast() else { + break + } + let (itemPtr, inodeNum) = item + let childItems = try self.children(of: inodeNum) + let root = itemPtr.pointee + for (itemName, itemInodeNum) in childItems { + if itemName == "." || itemName == ".." { + continue + } + + if self.inodes[itemInodeNum] != nil { + // we have seen this inode before, we will hard link this file to it + guard let parentPath = itemPtr.pointee.path else { + continue + } + let path = parentPath.join(itemName) + self.hardlinks[path] = itemInodeNum + continue + } + + let blocks = try self.getExtents(inode: itemInodeNum) + let itemTreeNodePtr = Ptr.allocate(capacity: 1) + let itemTreeNode = FileTree.FileTreeNode( + inode: itemInodeNum, + name: itemName, + parent: itemPtr, + children: [] + ) + if let blocks { + if blocks.count > 1 { + itemTreeNode.additionalBlocks = Array(blocks.dropFirst()) + } + itemTreeNode.blocks = blocks.first + } + itemTreeNodePtr.initialize(to: itemTreeNode) + root.children.append(itemTreeNodePtr) + itemPtr.initialize(to: root) + let itemInode = try self.getInode(number: itemInodeNum) + if itemInode.mode.isDir() { + items.append((itemTreeNodePtr, itemInodeNum)) + } + } + } + } + + deinit { + try? self.handle.close() + } + + private func readGroupDescriptor(_ number: UInt32) throws -> GroupDescriptor { + let bs = UInt64(1024 * (1 << superBlock.logBlockSize)) + let offset = bs + UInt64(number) * UInt64(self.groupDescriptorSize) + try self.handle.seek(toOffset: offset) + guard let data = try? self.handle.read(upToCount: MemoryLayout.size) else { + throw EXT4.Error.couldNotReadGroup(number) + } + let gd = data.withUnsafeBytes { ptr in + ptr.loadLittleEndian(as: EXT4.GroupDescriptor.self) + } + return gd + } + + private func readInode(_ number: UInt32) throws -> Inode { + let inodeGroupNumber = ((number - 1) / self.superBlock.inodesPerGroup) + let numberInGroup = UInt64((number - 1) % self.superBlock.inodesPerGroup) + + let gd = try getGroupDescriptor(inodeGroupNumber) + let inodeTableStart = UInt64(gd.inodeTableLow) * self.blockSize + + let inodeOffset: UInt64 = inodeTableStart + numberInGroup * UInt64(superBlock.inodeSize) + try self.handle.seek(toOffset: inodeOffset) + guard let inodeData = try self.handle.read(upToCount: MemoryLayout.size) else { + throw EXT4.Error.couldNotReadInode(number) + } + let inode = inodeData.withUnsafeBytes { ptr in + ptr.loadLittleEndian(as: EXT4.Inode.self) + } + return inode + } + + private func getDirTree(_ number: InodeNumber) throws -> [(String, InodeNumber)] { + var children: [(String, InodeNumber)] = [] + let extents = try getExtents(inode: number) ?? [] + for (start, end) in extents { + try self.seek(block: start) + for i in 0..<(end - start) { + guard let dirEntryBlock = try self.handle.read(upToCount: Int(self.blockSize)) else { + throw EXT4.Error.couldNotReadBlock(start + i) + } + let childEntries = try getDirEntries(dirTree: dirEntryBlock) + children.append(contentsOf: childEntries) + } + } + return children.sorted { a, b in + a.0 < b.0 + } + } + + private func getDirEntries(dirTree: Data) throws -> [(String, InodeNumber)] { + var children: [(String, InodeNumber)] = [] + var offset = 0 + while offset < dirTree.count { + let length = MemoryLayout.size + let dirEntry = dirTree.subdata(in: offset.. [(start: UInt32, end: UInt32)]? { + let inode = try self.getInode(number: inode) + let inodeBlock = Data(tupleToArray(inode.block)) + var offset = 0 + var extents: [(start: UInt32, end: UInt32)] = [] + + let extentHeaderSize = MemoryLayout.size + let extentIndexSize = MemoryLayout.size + let extentLeafSize = MemoryLayout.size + // read extent header + let header = inodeBlock.subdata(in: offset.. Inode { + if let inode = self.inodes[number] { + return inode + } + + let inode = try readInode(number) + self.inodes[number] = inode + return inode + } + + func getGroupDescriptor(_ number: UInt32) throws -> GroupDescriptor { + if let gd = self.groupDescriptors[number] { + return gd + } + let gd = try readGroupDescriptor(number) + self.groupDescriptors[number] = gd + return gd + } + + func children(of number: EXT4.InodeNumber) throws -> [(String, InodeNumber)] { + try getDirTree(number) + } + } +} diff --git a/Sources/ContainerizationEXT4/EXT4+Types.swift b/Sources/ContainerizationEXT4/EXT4+Types.swift new file mode 100644 index 00000000..eb81546d --- /dev/null +++ b/Sources/ContainerizationEXT4/EXT4+Types.swift @@ -0,0 +1,620 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// swiftlint:disable large_tuple + +import Foundation + +extension EXT4 { + struct SuperBlock { + var inodesCount: UInt32 = 0 + var blocksCountLow: UInt32 = 0 + var rootBlocksCountLow: UInt32 = 0 + var freeBlocksCountLow: UInt32 = 0 + var freeInodesCount: UInt32 = 0 + var firstDataBlock: UInt32 = 0 + var logBlockSize: UInt32 = 0 + var logClusterSize: UInt32 = 0 + var blocksPerGroup: UInt32 = 0 + var clustersPerGroup: UInt32 = 0 + var inodesPerGroup: UInt32 = 0 + var mtime: UInt32 = 0 + var wtime: UInt32 = 0 + var mountCount: UInt16 = 0 + var maxMountCount: UInt16 = 0 + var magic: UInt16 = 0 + var state: UInt16 = 0 + var errors: UInt16 = 0 + var minorRevisionLevel: UInt16 = 0 + var lastCheck: UInt32 = 0 + var checkInterval: UInt32 = 0 + var creatorOS: UInt32 = 0 + var revisionLevel: UInt32 = 0 + var defaultReservedUid: UInt16 = 0 + var defaultReservedGid: UInt16 = 0 + var firstInode: UInt32 = 0 + var inodeSize: UInt16 = 0 + var blockGroupNr: UInt16 = 0 + var featureCompat: UInt32 = 0 + var featureIncompat: UInt32 = 0 + var featureRoCompat: UInt32 = 0 + var uuid: + ( + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8 + ) = ( + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0 + ) + var volumeName: + ( + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8 + ) = ( + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0 + ) + var lastMounted: + ( + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8 + ) = ( + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0 + ) + var algorithmUsageBitmap: UInt32 = 0 + var preallocBlocks: UInt8 = 0 + var preallocDirBlocks: UInt8 = 0 + var reservedGdtBlocks: UInt16 = 0 + var journalUUID: + ( + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8 + ) = ( + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0 + ) + var journalInum: UInt32 = 0 + var journalDev: UInt32 = 0 + var lastOrphan: UInt32 = 0 + var hashSeed: (UInt32, UInt32, UInt32, UInt32) = (0, 0, 0, 0) + var defHashVersion: UInt8 = 0 + var journalBackupType: UInt8 = 0 + var descSize: UInt16 = UInt16(MemoryLayout.size) + var defaultMountOpts: UInt32 = 0 + var firstMetaBg: UInt32 = 0 + var mkfsTime: UInt32 = 0 + var journalBlocks: + ( + UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, + UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, + UInt32 + ) = ( + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0 + ) + var blocksCountHigh: UInt32 = 0 + var rBlocksCountHigh: UInt32 = 0 + var freeBlocksCountHigh: UInt32 = 0 + var minExtraIsize: UInt16 = 0 + var wantExtraIsize: UInt16 = 0 + var flags: UInt32 = 0 + var raidStride: UInt16 = 0 + var mmpInterval: UInt16 = 0 + var mmpBlock: UInt64 = 0 + var raidStripeWidth: UInt32 = 0 + var logGroupsPerFlex: UInt8 = 0 + var checksumType: UInt8 = 0 + var reservedPad: UInt16 = 0 + var kbytesWritten: UInt64 = 0 + var snapshotInum: UInt32 = 0 + var snapshotID: UInt32 = 0 + var snapshotRBlocksCount: UInt64 = 0 + var snapshotList: UInt32 = 0 + var errorCount: UInt32 = 0 + var firstErrorTime: UInt32 = 0 + var firstErrorInode: UInt32 = 0 + var firstErrorBlock: UInt64 = 0 + var firstErrorFunc: + ( + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8 + ) = ( + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0 + ) + var firstErrorLine: UInt32 = 0 + var lastErrorTime: UInt32 = 0 + var lastErrorInode: UInt32 = 0 + var lastErrorLine: UInt32 = 0 + var lastErrorBlock: UInt64 = 0 + var lastErrorFunc: + ( + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8 + ) = ( + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0 + ) + var mountOpts: + ( + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8 + ) = ( + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0 + ) + var userQuotaInum: UInt32 = 0 + var groupQuotaInum: UInt32 = 0 + var overheadBlocks: UInt32 = 0 + var backupBgs: (UInt32, UInt32) = (0, 0) + var encryptAlgos: (UInt8, UInt8, UInt8, UInt8) = (0, 0, 0, 0) + var encryptPwSalt: + ( + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8 + ) = ( + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0 + ) + var lpfInode: UInt32 = 0 + var projectQuotaInum: UInt32 = 0 + var checksumSeed: UInt32 = 0 + var wtimeHigh: UInt8 = 0 + var mtimeHigh: UInt8 = 0 + var mkfsTimeHigh: UInt8 = 0 + var lastcheckHigh: UInt8 = 0 + var firstErrorTimeHigh: UInt8 = 0 + var lastErrorTimeHigh: UInt8 = 0 + var pad: (UInt8, UInt8) = (0, 0) + var reserved: + ( + UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, + UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, + UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, + UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, + UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, + UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, + UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, + UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, + UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, + UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, + UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, + UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32, UInt32 + ) = ( + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0 + ) + var checksum: UInt32 = 0 + } + + struct CompatFeature { + let rawValue: UInt32 + + static let dirPrealloc = CompatFeature(rawValue: 0x1) + static let imagicInodes = CompatFeature(rawValue: 0x2) + static let hasJournal = CompatFeature(rawValue: 0x4) + static let extAttr = CompatFeature(rawValue: 0x8) + static let resizeInode = CompatFeature(rawValue: 0x10) + static let dirIndex = CompatFeature(rawValue: 0x20) + static let lazyBg = CompatFeature(rawValue: 0x40) + static let excludeInode = CompatFeature(rawValue: 0x80) + static let excludeBitmap = CompatFeature(rawValue: 0x100) + static let sparseSuper2 = CompatFeature(rawValue: 0x200) + } + + struct IncompatFeature { + let rawValue: UInt32 + + static let compression = IncompatFeature(rawValue: 0x1) + static let filetype = IncompatFeature(rawValue: 0x2) + static let recover = IncompatFeature(rawValue: 0x4) + static let journalDev = IncompatFeature(rawValue: 0x8) + static let metaBg = IncompatFeature(rawValue: 0x10) + static let extents = IncompatFeature(rawValue: 0x40) + static let bit64 = IncompatFeature(rawValue: 0x80) + static let mmp = IncompatFeature(rawValue: 0x100) + static let flexBg = IncompatFeature(rawValue: 0x200) + static let eaInode = IncompatFeature(rawValue: 0x400) + static let dirdata = IncompatFeature(rawValue: 0x1000) + static let csumSeed = IncompatFeature(rawValue: 0x2000) + static let largedir = IncompatFeature(rawValue: 0x4000) + static let inlineData = IncompatFeature(rawValue: 0x8000) + static let encrypt = IncompatFeature(rawValue: 0x10000) + } + + struct RoCompatFeature { + let rawValue: UInt32 + + static let sparseSuper = RoCompatFeature(rawValue: 0x1) + static let largeFile = RoCompatFeature(rawValue: 0x2) + static let btreeDir = RoCompatFeature(rawValue: 0x4) + static let hugeFile = RoCompatFeature(rawValue: 0x8) + static let gdtCsum = RoCompatFeature(rawValue: 0x10) + static let dirNlink = RoCompatFeature(rawValue: 0x20) + static let extraIsize = RoCompatFeature(rawValue: 0x40) + static let hasSnapshot = RoCompatFeature(rawValue: 0x80) + static let quota = RoCompatFeature(rawValue: 0x100) + static let bigalloc = RoCompatFeature(rawValue: 0x200) + static let metadataCsum = RoCompatFeature(rawValue: 0x400) + static let replica = RoCompatFeature(rawValue: 0x800) + static let readonly = RoCompatFeature(rawValue: 0x1000) + static let project = RoCompatFeature(rawValue: 0x2000) + } + + struct BlockGroupFlag { + let rawValue: UInt16 + + static let inodeUninit = BlockGroupFlag(rawValue: 0x1) + static let blockUninit = BlockGroupFlag(rawValue: 0x2) + static let inodeZeroed = BlockGroupFlag(rawValue: 0x4) + } + + struct GroupDescriptor { + let blockBitmapLow: UInt32 + let inodeBitmapLow: UInt32 + let inodeTableLow: UInt32 + let freeBlocksCountLow: UInt16 + let freeInodesCountLow: UInt16 + let usedDirsCountLow: UInt16 + let flags: UInt16 + let excludeBitmapLow: UInt32 + let blockBitmapCsumLow: UInt16 + let inodeBitmapCsumLow: UInt16 + let itableUnusedLow: UInt16 + let checksum: UInt16 + } + + struct GroupDescriptor64 { + let groupDescriptor: GroupDescriptor + let blockBitmapHigh: UInt32 + let inodeBitmapHigh: UInt32 + let inodeTableHigh: UInt32 + let freeBlocksCountHigh: UInt16 + let freeInodesCountHigh: UInt16 + let usedDirsCountHigh: UInt16 + let itableUnusedHigh: UInt16 + let excludeBitmapHigh: UInt32 + let blockBitmapCsumHigh: UInt16 + let inodeBitmapCsumHigh: UInt16 + let reserved: UInt32 + } + + public struct FileModeFlag: Sendable { + let rawValue: UInt16 + + public static let S_IXOTH = FileModeFlag(rawValue: 0x1) + public static let S_IWOTH = FileModeFlag(rawValue: 0x2) + public static let S_IROTH = FileModeFlag(rawValue: 0x4) + public static let S_IXGRP = FileModeFlag(rawValue: 0x8) + public static let S_IWGRP = FileModeFlag(rawValue: 0x10) + public static let S_IRGRP = FileModeFlag(rawValue: 0x20) + public static let S_IXUSR = FileModeFlag(rawValue: 0x40) + public static let S_IWUSR = FileModeFlag(rawValue: 0x80) + public static let S_IRUSR = FileModeFlag(rawValue: 0x100) + public static let S_ISVTX = FileModeFlag(rawValue: 0x200) + public static let S_ISGID = FileModeFlag(rawValue: 0x400) + public static let S_ISUID = FileModeFlag(rawValue: 0x800) + public static let S_IFIFO = FileModeFlag(rawValue: 0x1000) + public static let S_IFCHR = FileModeFlag(rawValue: 0x2000) + public static let S_IFDIR = FileModeFlag(rawValue: 0x4000) + public static let S_IFBLK = FileModeFlag(rawValue: 0x6000) + public static let S_IFREG = FileModeFlag(rawValue: 0x8000) + public static let S_IFLNK = FileModeFlag(rawValue: 0xA000) + public static let S_IFSOCK = FileModeFlag(rawValue: 0xC000) + + public static let TypeMask = FileModeFlag(rawValue: 0xF000) + } + + typealias InodeNumber = UInt32 + + public struct Inode { + var mode: UInt16 = 0 + var uid: UInt16 = 0 + var sizeLow: UInt32 = 0 + var atime: UInt32 = 0 + var ctime: UInt32 = 0 + var mtime: UInt32 = 0 + var dtime: UInt32 = 0 + var gid: UInt16 = 0 + var linksCount: UInt16 = 0 + var blocksLow: UInt32 = 0 + var flags: UInt32 = 0 + var version: UInt32 = 0 + var block: + ( + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8 + ) = ( + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0 + ) + var generation: UInt32 = 0 + var xattrBlockLow: UInt32 = 0 + var sizeHigh: UInt32 = 0 + var obsoleteFragmentAddr: UInt32 = 0 + var blocksHigh: UInt16 = 0 + var xattrBlockHigh: UInt16 = 0 + var uidHigh: UInt16 = 0 + var gidHigh: UInt16 = 0 + var checksumLow: UInt16 = 0 + var reserved: UInt16 = 0 + var extraIsize: UInt16 = 0 + var checksumHigh: UInt16 = 0 + var ctimeExtra: UInt32 = 0 + var mtimeExtra: UInt32 = 0 + var atimeExtra: UInt32 = 0 + var crtime: UInt32 = 0 + var crtimeExtra: UInt32 = 0 + var versionHigh: UInt32 = 0 + var projid: UInt32 = 0 // Size until this point is 160 bytes + var inlineXattrs: + ( // 96 bytes for extended attributes + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, UInt8, + UInt8, UInt8, UInt8, UInt8, UInt8, UInt8 + ) = ( + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0 + ) + public static func Mode(_ mode: FileModeFlag, _ perm: UInt16) -> UInt16 { + mode.rawValue | perm + } + } + + struct InodeFlag { + let rawValue: UInt32 + + static let secRm = InodeFlag(rawValue: 0x1) + static let unRm = InodeFlag(rawValue: 0x2) + static let compressed = InodeFlag(rawValue: 0x4) + static let sync = InodeFlag(rawValue: 0x8) + static let immutable = InodeFlag(rawValue: 0x10) + static let append = InodeFlag(rawValue: 0x20) + static let noDump = InodeFlag(rawValue: 0x40) + static let noAtime = InodeFlag(rawValue: 0x80) + static let dirtyCompressed = InodeFlag(rawValue: 0x100) + static let compressedClusters = InodeFlag(rawValue: 0x200) + static let noCompress = InodeFlag(rawValue: 0x400) + static let encrypted = InodeFlag(rawValue: 0x800) + static let hashedIndex = InodeFlag(rawValue: 0x1000) + static let magic = InodeFlag(rawValue: 0x2000) + static let journalData = InodeFlag(rawValue: 0x4000) + static let noTail = InodeFlag(rawValue: 0x8000) + static let dirSync = InodeFlag(rawValue: 0x10000) + static let topDir = InodeFlag(rawValue: 0x20000) + static let hugeFile = InodeFlag(rawValue: 0x40000) + static let extents = InodeFlag(rawValue: 0x80000) + static let eaInode = InodeFlag(rawValue: 0x200000) + static let eofBlocks = InodeFlag(rawValue: 0x400000) + static let snapfile = InodeFlag(rawValue: 0x0100_0000) + static let snapfileDeleted = InodeFlag(rawValue: 0x0400_0000) + static let snapfileShrunk = InodeFlag(rawValue: 0x0800_0000) + static let inlineData = InodeFlag(rawValue: 0x1000_0000) + static let projectIDInherit = InodeFlag(rawValue: 0x2000_0000) + static let reserved = InodeFlag(rawValue: 0x8000_0000) + } + + struct ExtentHeader { + let magic: UInt16 + let entries: UInt16 + let max: UInt16 + let depth: UInt16 + let generation: UInt32 + } + + struct ExtentIndex { + let block: UInt32 + let leafLow: UInt32 + let leafHigh: UInt16 + let unused: UInt16 + } + + struct ExtentLeaf { + let block: UInt32 + let length: UInt16 + let startHigh: UInt16 + let startLow: UInt32 + } + + struct ExtentTail { + let checksum: UInt32 + } + + struct ExtentIndexNode { + var header: ExtentHeader + var indices: [ExtentIndex] + } + + struct ExtentLeafNode { + var header: ExtentHeader + var leaves: [ExtentLeaf] + } + + struct DirectoryEntry { + let inode: InodeNumber + let recordLength: UInt16 + let nameLength: UInt8 + let fileType: UInt8 + // let name: [UInt8] + } + + enum FileType: UInt8 { + case unknown = 0x0 + case regular = 0x1 + case directory = 0x2 + case character = 0x3 + case block = 0x4 + case fifo = 0x5 + case socket = 0x6 + case symbolicLink = 0x7 + } + + struct DirectoryEntryTail { + let reservedZero1: UInt32 + let recordLength: UInt16 + let reservedZero2: UInt8 + let fileType: UInt8 + let checksum: UInt32 + } + + struct DirectoryTreeRoot { + let dot: DirectoryEntry + let dotName: [UInt8] + let dotDot: DirectoryEntry + let dotDotName: [UInt8] + let reservedZero: UInt32 + let hashVersion: UInt8 + let infoLength: UInt8 + let indirectLevels: UInt8 + let unusedFlags: UInt8 + let limit: UInt16 + let count: UInt16 + let block: UInt32 + // let entries: [DirectoryTreeEntry] + } + + struct DirectoryTreeNode { + let fakeInode: UInt32 + let fakeRecordLength: UInt16 + let nameLength: UInt8 + let fileType: UInt8 + let limit: UInt16 + let count: UInt16 + let block: UInt32 + // let entries: [DirectoryTreeEntry] + } + + struct DirectoryTreeEntry { + let hash: UInt32 + let block: UInt32 + } + + struct DirectoryTreeTail { + let reserved: UInt32 + let checksum: UInt32 + } + + struct XAttrEntry { + let nameLength: UInt8 + let nameIndex: UInt8 + let valueOffset: UInt16 + let valueInum: UInt32 + let valueSize: UInt32 + let hash: UInt32 + } + + struct XAttrHeader { + let magic: UInt32 + let referenceCount: UInt32 + let blocks: UInt32 + let hash: UInt32 + let checksum: UInt32 + let reserved: [UInt32] + } + +} + +extension EXT4.Inode { + public static func Root() -> EXT4.Inode { + var inode = Self() // inode + inode.mode = Self.Mode(.S_IFDIR, 0o755) + inode.linksCount = 2 + inode.uid = 0 + inode.gid = 0 + // time + let now = Date().fs() + let now_lo: UInt32 = now.lo + let now_hi: UInt32 = now.hi + inode.atime = now_lo + inode.atimeExtra = now_hi + inode.ctime = now_lo + inode.ctimeExtra = now_hi + inode.mtime = now_lo + inode.mtimeExtra = now_hi + inode.crtime = now_lo + inode.crtimeExtra = now_hi + inode.flags = EXT4.InodeFlag.hugeFile.rawValue + inode.extraIsize = UInt16(EXT4.ExtraIsize) + return inode + } +} diff --git a/Sources/ContainerizationEXT4/EXT4+Xattrs.swift b/Sources/ContainerizationEXT4/EXT4+Xattrs.swift new file mode 100644 index 00000000..eeca1771 --- /dev/null +++ b/Sources/ContainerizationEXT4/EXT4+Xattrs.swift @@ -0,0 +1,306 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +/* + * Note: Both the entries and values for the attributes need to occupy a size that is a multiple of 4, + * meaning, in cases where the attribute name or value is less than not a multiple of 4, it is padded with 0 + * until it reaches that size. + */ + +extension EXT4 { + public struct ExtendedAttribute { + public static let prefixMap: [Int: String] = [ + 1: "user.", + 2: "system.posix_acl_access", + 3: "system.posix_acl_default", + 4: "trusted.", + 6: "security.", + 7: "system.", + 8: "system.richacl", + ] + + let name: String + let index: UInt8 + let value: [UInt8] + + var sizeValue: UInt32 { + UInt32((value.count + 3) & ~3) + } + + var sizeEntry: UInt32 { + UInt32((name.count + 3) & ~3 + 16) // 16 bytes are needed to store other metadata for the xattr entry + } + + var size: UInt32 { + sizeEntry + sizeValue + } + + var fullName: String { + Self.decompressName(id: Int(index), suffix: name) + } + + var hash: UInt32 { + var hash: UInt32 = 0 + for char in name { + hash = (hash << 5) ^ (hash >> 27) ^ UInt32(char.asciiValue!) + } + var i = 0 + while i + 3 < value.count { + let s = value[i..> 16) ^ v + i += 4 + } + if value.count % 4 != 0 { + let last = value.count & ~3 + var buff: [UInt8] = [0, 0, 0, 0] + for (i, byte) in value[last...].enumerated() { + buff[i] = byte + } + let v = UInt32(littleEndian: buff.withUnsafeBytes { $0.load(as: UInt32.self) }) + hash = (hash << 16) ^ (hash >> 16) ^ v + } + return hash + } + + init(name: String, value: [UInt8]) { + let compressed = Self.compressName(name) + self.name = compressed.str + self.index = compressed.id + self.value = value + } + + init(idx: UInt8, compressedName name: String, value: [UInt8]) { + self.name = name + self.index = idx + self.value = value + } + + // MARK: Class methods + public static func compressName(_ name: String) -> (id: UInt8, str: String) { + for (id, prefix) in prefixMap.sorted(by: { $1.1.count < $0.1.count }) where name.hasPrefix(prefix) { + return (UInt8(id), String(name.dropFirst(prefix.count))) + } + return (0, name) + } + + public static func decompressName(id: Int, suffix: String) -> String { + guard let prefix = prefixMap[id] else { + return suffix + } + return "\(prefix)\(suffix)" + } + } + + public struct FileXattrsState { + private let inodeCapacity: UInt32 + private let blockCapacity: UInt32 + private let inode: UInt32 // the inode number for which we are tracking these xattrs + + var inlineAttributes: [ExtendedAttribute] = [] + var blockAttributes: [ExtendedAttribute] = [] + private var usedSizeInline: UInt32 = 0 + private var usedSizeBlock: UInt32 = 0 + + private var inodeFreeBytes: UInt32 { + self.inodeCapacity - EXT4.XattrInodeHeaderSize - usedSizeInline - 4 // need to have 4 null bytes b/w xattr entries and values + } + + private var blockFreeBytes: UInt32 { + self.blockCapacity - EXT4.XattrBlockHeaderSize - usedSizeBlock - 4 + } + + init(inode: UInt32, inodeXattrCapacity: UInt32, blockCapacity: UInt32) { + self.inode = inode + self.inodeCapacity = inodeXattrCapacity + self.blockCapacity = blockCapacity + } + + public mutating func add(_ attribute: ExtendedAttribute) throws { + let size = attribute.size + if size <= inodeFreeBytes { + usedSizeInline += size + inlineAttributes.append(attribute) + return + } + if size <= blockFreeBytes { + usedSizeBlock += size + blockAttributes.append(attribute) + return + } + throw Error.insufficientSpace(Int(self.inode)) + } + + public func writeInlineAttributes(buffer: inout [UInt8]) throws { + var idx = 0 + withUnsafeLittleEndianBytes( + of: EXT4.XAttrHeaderMagic, + body: { bytes in + for byte in bytes { + buffer[idx] = byte + idx += 1 + } + }) + try Self.write(buffer: &buffer, attrs: self.inlineAttributes, start: UInt16(idx), delta: 0, inline: true) + } + + public func writeBlockAttributes(buffer: inout [UInt8]) throws { + var idx = 0 + for val in [EXT4.XAttrHeaderMagic, 1, 1] { + withUnsafeLittleEndianBytes( + of: UInt32(val), + body: { bytes in + for byte in bytes { + buffer[idx] = byte + idx += 1 + } + }) + } + while idx != 32 { + buffer[idx] = 0 + idx += 1 + } + var attributes = self.blockAttributes + attributes.sort(by: { + if ($0.index < $1.index) || ($0.name.count < $1.name.count) || ($0.name < $1.name) { + return true + } + return false + }) + try Self.write(buffer: &buffer, attrs: attributes, start: UInt16(idx), delta: UInt16(idx), inline: false) + } + + /// Writes the specified list of extended atrribute entries and their values to the provided + /// This method does not fill in any headers (Inode inline / block level) that may be requried to parse these attributes + /// + /// - Parameters: + /// - buffer: An array of [UInt8] where the data will be written into + /// - attrs: The list of ExtendedAttributes to write + /// - start: the index from where data should be put into the buffer - useful when if you dont want this method to be overwriting existing data + /// - delta: index from where the begin the offset calculations + /// - inline: if the byte buffer being written into is an inline data block for an inode: Determines the hash calculation + private static func write( + buffer: inout [UInt8], attrs: [ExtendedAttribute], start: UInt16, delta: UInt16, inline: Bool + ) throws { + var offset: UInt16 = UInt16(buffer.count) + delta - start + var front = Int(start) + var end = buffer.count + + for attribute in attrs { + guard end - front >= 4 else { + throw Error.malformedXattrBuffer + } + + var out: [UInt8] = [] + let v = attribute.sizeValue + offset -= UInt16(v) + out.append(UInt8(attribute.name.count)) + out.append(attribute.index) + withUnsafeLittleEndianBytes( + of: UInt16(offset), + body: { bytes in + out.append(contentsOf: bytes) + }) + out.append(contentsOf: [0, 0, 0, 0]) // these next four bytes indicate that the attr values are in the same block + withUnsafeLittleEndianBytes( + of: UInt32(attribute.value.count), + body: { bytes in + out.append(contentsOf: bytes) + }) + if !inline { + withUnsafeLittleEndianBytes( + of: UInt32(attribute.hash), + body: { bytes in + out.append(contentsOf: bytes) + }) + } else { + out.append(contentsOf: [0, 0, 0, 0]) + } + guard let name = attribute.name.data(using: .ascii) else { + throw Error.convertAsciiString(attribute.name) + } + out.append(contentsOf: [UInt8](name)) + while out.count < Int(attribute.sizeEntry) { // ensure that xattr entry size is a multiple of 4 + out.append(0) + } + for (i, byte) in out.enumerated() { + buffer[front + i] = byte + } + front += out.count + + end -= Int(attribute.sizeValue) + for (i, byte) in attribute.value.enumerated() { + buffer[end + i] = byte + } + } + } + + public static func read(buffer: [UInt8], start: Int, offset: Int) throws -> [ExtendedAttribute] { + var i = start + var attribs: [ExtendedAttribute] = [] + // 16 is the size of 1 XAttrEntry + while i + 16 < buffer.count { + let attributeStart = i + let rawXattrEntry = Array(buffer[i.. Data blocks. In this implementation, inode size is set to 256 bytes. + Inode table uses extents to efficiently describe the mapping. + + +-----------------------+ + | Inode Table | + +-----------------------+ + | Inode | Metadata | + +-------+---------------+ + | 1 | permissions | + | | size | + | | user ID | + | | group ID | + | | timestamps | + | | block | + | | blocks count | + +-------+---------------+ + | 2 | ... | + +-------+---------------+ + | ... | ... | + +-------+---------------+ + + The length of `block` field in the inode table is 60 bytes. This field contains an extent tree + that holds information about ranges of blocks used by the file. For smaller files, the entire extent + tree can be stored within this field. + + +-----------------------+ + | Inode | + +-----------------------+ + | Metadata | + +-----------------------+ + | Extent Tree | + | +-------------------+ | + | | Extent Leaf Node | | + | +-------------------+ | + | | - Start Block | | + | | - Block Count | | + | | - ... | | + | +-------------------+ | + +-----------------------+ + + For larger files which span across multiple non-contiguous blocks, extent tree's root points to extent + blocks, which in-turn point to the blocks used by the file + + +-----------------------+ + | Extent Tree | + | +-------------------+ | + | | Extent Root | | + | +-------------------+ | + | | - Pointers to | | + | | Extent Blocks | | + | +-------------------+ | + +-----------------------+ + | + v + +-----------------------+ + | Extent Block | + +-----------------------+ + | +-------------------+ | + | | Extent Leaf Node | | + | +-------------------+ | + | | - Start Block | | + | | - Block Count | | + | | - ... | | + | +-------------------+ | + | +-------------------+ | + | | Extent Leaf Node | | + | +-------------------+ | + | | - Start Block | | + | | - Block Count | | + | | - ... | | + | +-------------------+ | + +-----------------------+ + + ## Directory entries + + The data blocks for directory inodes point to a list of directory entrees. Each entry + consists of only a name and inode number. The name and inode number correspond to the + name and inode number of the children of the directory + + +-------------------------+ + | Directory Entry | + +-------------------------+ + | inode | rec_len | name | + +-------------------------+ + | 2 | 1 | "." | + +-------------------------+ + | Directory Entry | + +-------------------------+ + | inode | rec_len | name | + +-------------------------+ + | 1 | 2 | ".." | + +-------------------------+ + | Directory Entry | + +-------------------------+ + | inode | rec_len | name | + +-------------------------+ + | 11 | 10 | lost& | + | | | found | + +-------------------------+ + +More details can be found here https://ext4.wiki.kernel.org/index.php/Ext4_Disk_Layout + +``` +*/ + +/// A class for interacting with ext4 file systems. +/// +/// The `Ext4` class provides functionality to read the superblock of an existing ext4 block device +/// and format a new block device with the ext4 file system. +/// +/// Usage: +/// - To read the superblock of an existing ext4 block device, create an instance of `Ext4` with the +/// path to the block device +/// - To format a new block device with ext4, create an instance of `Ext4.Formatter` with the path to the block +/// device and call the `close()` method. +/// +/// Example 1: Read an existing block device +/// ```swift +/// let blockDevice = URL(filePath: "/dev/sdb") +/// // succeeds if a valid ext4 fs is found at path +/// let ext4 = try Ext4(blockDevice: blockDevice) +/// print("Block size: \(ext4.blockSize)") +/// print("Total size: \(ext4.size)") +/// +/// // Reading the superblock +/// let superblock = ext4.superblock +/// print("Superblock information:") +/// print("Total blocks: \(superblock.blocksCountLow)") +/// ``` +/// +/// Example 2: Format a new block device (Refer [`EXT4.Formatter`](x-source-tag://EXT4.Formatter) for more info) +/// ```swift +/// let devicePath = URL(filePath: "/dev/sdc") +/// let formatter = try EXT4.Formatter(devicePath, blockSize: 4096) +/// try formatter.close() +/// ``` +public enum EXT4 { + public static let SuperBlockMagic: UInt16 = 0xef53 + + static let ExtentHeaderMagic: UInt16 = 0xf30a + static let XAttrHeaderMagic: UInt32 = 0xea02_0000 + + static let DefectiveBlockInode: InodeNumber = 1 + static let RootInode: InodeNumber = 2 + static let FirstInode: InodeNumber = 11 + static let LostAndFoundInode: InodeNumber = 11 + + static let InodeActualSize: UInt32 = 160 // 160 bytes used by metadata + static let InodeExtraSize: UInt32 = 96 // 96 bytes for inline xattrs + static let InodeSize: UInt32 = UInt32(MemoryLayout.size) // 256 bytes. This is the max size of an inode + static let XattrInodeHeaderSize: UInt32 = 4 + static let XattrBlockHeaderSize: UInt32 = 32 + static let ExtraIsize: UInt16 = UInt16(InodeActualSize) - 128 + + static let MaxLinks: UInt32 = 65000 + static let MaxBlocksPerExtent: UInt32 = 0x8000 + static let MaxFileSize: UInt64 = 128.gib() + static let SuperBlockOffset: UInt64 = 1024 +} + +extension EXT4 { + public enum Error: Swift.Error, CustomStringConvertible, Sendable, Equatable { + case notFound(_ path: String) + case couldNotReadSuperBlock(_ path: String, _ offset: UInt64, _ size: Int) + case invalidSuperBlock + case deepExtentsUnimplemented + case invalidExtents + case invalidXattrEntry + case couldNotReadBlock(_ block: UInt32) + case invalidPathEncoding(_ path: String) + case couldNotReadInode(_ inode: UInt32) + case couldNotReadGroup(_ group: UInt32) + public var description: String { + switch self { + case .notFound(let path): + return "file at path \(path) not found" + case .couldNotReadSuperBlock(let path, let offset, let size): + return "could not read \(size) bytes of superblock from \(path) at offset \(offset)" + case .invalidSuperBlock: + return "not a valid EXT4 superblock" + case .deepExtentsUnimplemented: + return "deep extents are not supported" + case .invalidExtents: + return "extents invalid or corrupted" + case .invalidXattrEntry: + return "invalid extended attribute entry" + case .couldNotReadBlock(let block): + return "could not read block \(block)" + case .invalidPathEncoding(let path): + return "path encoding for '\(path)' is invalid, must be ascii or utf8" + case .couldNotReadInode(let inode): + return "could not read inode \(inode)" + case .couldNotReadGroup(let group): + return "could not read group descriptor \(group)" + } + } + } +} diff --git a/Sources/ContainerizationEXT4/FilePath+Extensions.swift b/Sources/ContainerizationEXT4/FilePath+Extensions.swift new file mode 100644 index 00000000..bbe73e87 --- /dev/null +++ b/Sources/ContainerizationEXT4/FilePath+Extensions.swift @@ -0,0 +1,125 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation +import SystemPackage + +extension FilePath { + public static let Separator: String = "/" + + public var bytes: [UInt8] { + self.withCString { cstr in + var ptr = cstr + var rawBytes: [UInt8] = [] + while UInt(bitPattern: ptr) != 0 { + if ptr.pointee == 0x00 { break } + rawBytes.append(UInt8(bitPattern: ptr.pointee)) + ptr = ptr.successor() + } + return rawBytes + } + } + + public var base: String { + self.lastComponent?.string ?? "/" + } + + public var dir: FilePath { + self.removingLastComponent() + } + + public var url: URL { + URL(fileURLWithPath: self.string) + } + + public var items: [String] { + self.components.map { $0.string } + } + + public init(_ url: URL) { + self.init(url.path(percentEncoded: false)) + } + + public init?(_ data: Data) { + let cstr: String? = data.withUnsafeBytes { (rbp: UnsafeRawBufferPointer) in + guard let baseAddress = rbp.baseAddress else { + return nil + } + + let cString = baseAddress.bindMemory(to: CChar.self, capacity: data.count) + return String(cString: cString) + } + + guard let cstr else { + return nil + } + self.init(cstr) + } + + public func join(_ path: FilePath) -> FilePath { + self.pushing(path) + } + + public func join(_ path: String) -> FilePath { + self.join(FilePath(path)) + } + + public func split() -> (dir: FilePath, base: String) { + (self.dir, self.base) + } + + public func clean() -> FilePath { + self.lexicallyNormalized() + } + + public static func rel(_ basepath: String, _ targpath: String) -> FilePath { + let base = FilePath(basepath) + let targ = FilePath(targpath) + + if base == targ { + return "." + } + + let baseComponents = base.items + let targComponents = targ.items + + var commonPrefix = 0 + while commonPrefix < min(baseComponents.count, targComponents.count) + && baseComponents[commonPrefix] == targComponents[commonPrefix] + { + commonPrefix += 1 + } + + let upCount = baseComponents.count - commonPrefix + let relComponents = Array(repeating: "..", count: upCount) + targComponents[commonPrefix...] + + return FilePath(relComponents.joined(separator: Self.Separator)) + } +} + +extension FileHandle { + public convenience init?(forWritingTo path: FilePath) { + self.init(forWritingAtPath: path.description) + } + + public convenience init?(forReadingAtPath path: FilePath) { + self.init(forReadingAtPath: path.description) + } + + public convenience init?(forReadingFrom path: FilePath) { + self.init(forReadingAtPath: path.description) + } +} diff --git a/Sources/ContainerizationEXT4/FileTimestamps.swift b/Sources/ContainerizationEXT4/FileTimestamps.swift new file mode 100644 index 00000000..9cb7d0c1 --- /dev/null +++ b/Sources/ContainerizationEXT4/FileTimestamps.swift @@ -0,0 +1,67 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +public struct FileTimestamps { + private let access: Date + private let modification: Date + private let creation: Date + private let now: Date + + var accessLo: UInt32 { + access.fs().lo + } + + var accessHi: UInt32 { + access.fs().hi + } + + var modificationLo: UInt32 { + modification.fs().lo + } + + var modificationHi: UInt32 { + modification.fs().hi + } + + var creationLo: UInt32 { + creation.fs().lo + } + + var creationHi: UInt32 { + creation.fs().hi + } + + var nowLo: UInt32 { + now.fs().lo + } + + var nowHi: UInt32 { + now.fs().hi + } + + init(access: Date?, modification: Date?, creation: Date?) { + now = Date() + self.access = access ?? now + self.modification = modification ?? now + self.creation = creation ?? now + } + + public init() { + self.init(access: nil, modification: nil, creation: nil) + } +} diff --git a/Sources/ContainerizationEXT4/Formatter+Unpack.swift b/Sources/ContainerizationEXT4/Formatter+Unpack.swift new file mode 100644 index 00000000..fc85aad7 --- /dev/null +++ b/Sources/ContainerizationEXT4/Formatter+Unpack.swift @@ -0,0 +1,193 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +#if os(macOS) +import ContainerizationArchive +import Foundation +import ContainerizationOS +import SystemPackage +import ContainerizationExtras + +private typealias Hardlinks = [FilePath: FilePath] + +extension EXT4.Formatter { + /// Unpack the provided archive on to the ext4 filesystem. + public func unpack(reader: ArchiveReader, progress: ProgressHandler? = nil) throws { + var hardlinks: Hardlinks = [:] + for (entry, data) in reader { + try Task.checkCancellation() + guard var pathEntry = entry.path else { + continue + } + + defer { + // Count the number of entries + if let progress { + Task { + await progress([ + ProgressEvent(event: "add-items", value: 1) + ]) + } + } + } + + pathEntry = preProcessPath(s: pathEntry) + let path = FilePath(pathEntry) + + if path.base.hasPrefix(".wh.") { + if path.base == ".wh..wh..opq" { // whiteout directory + try self.unlink(path: path.dir, directoryWhiteout: true) + continue + } + let startIndex = path.base.index(path.base.startIndex, offsetBy: ".wh.".count) + let filePath = String(path.base[startIndex...]) + let dir: FilePath = path.dir + try self.unlink(path: dir.join(filePath)) + continue + } + + if let hardlink = entry.hardlink { + let hl = preProcessPath(s: hardlink) + hardlinks[path] = FilePath(hl) + continue + } + let ts = FileTimestamps( + access: entry.contentAccessDate, modification: entry.modificationDate, creation: entry.creationDate) + switch entry.fileType { + case .directory: + try self.create( + path: path, mode: EXT4.Inode.Mode(.S_IFDIR, entry.permissions), ts: ts, uid: entry.owner, + gid: entry.group, + xattrs: entry.xattrs) + case .regular: + let inputStream = InputStream(data: data) + inputStream.open() + try self.create( + path: path, mode: EXT4.Inode.Mode(.S_IFREG, entry.permissions), ts: ts, buf: inputStream, + uid: entry.owner, + gid: entry.group, xattrs: entry.xattrs) + inputStream.close() + + // Count the size of files + if let progress { + Task { + let size = Int64(data.count) + await progress([ + ProgressEvent(event: "add-size", value: size) + ]) + } + } + case .symbolicLink: + var symlinkTarget: FilePath? + if let target = entry.symlinkTarget { + symlinkTarget = FilePath(target) + } + try self.create( + path: path, link: symlinkTarget, mode: EXT4.Inode.Mode(.S_IFLNK, entry.permissions), ts: ts, + uid: entry.owner, + gid: entry.group, xattrs: entry.xattrs) + default: + continue + } + } + guard hardlinks.acyclic else { + throw UnpackError.circularLinks + } + for (path, _) in hardlinks { + if let resolvedTarget = try hardlinks.resolve(path) { + try self.link(link: path, target: resolvedTarget) + } + } + } + + /// Unpack an archive at the source URL on to the ext4 filesystem. + public func unpack( + source: URL, + format: ContainerizationArchive.Format = .paxRestricted, + compression: ContainerizationArchive.Filter = .gzip, + progress: ProgressHandler? = nil + ) throws { + let reader = try ArchiveReader( + format: format, + filter: compression, + file: source + ) + try self.unpack(reader: reader, progress: progress) + } + + private func preProcessPath(s: String) -> String { + var p = s + if p.hasPrefix("./") { + p = String(p.dropFirst()) + } + if !p.hasPrefix("/") { + p = "/" + p + } + return p + } +} + +/// Common errors for unpacking an archive onto an ext4 filesystem. +public enum UnpackError: Swift.Error, CustomStringConvertible, Sendable, Equatable { + /// The name is invalid. + case invalidName(_ name: String) + /// A circular link is found. + case circularLinks + + /// The description of the error. + public var description: String { + switch self { + case .invalidName(let name): + return "'\(name)' is an invalid name" + case .circularLinks: + return "circular links found" + } + } +} + +extension Hardlinks { + fileprivate var acyclic: Bool { + for (_, target) in self { + var visited: Set = [target] + var next = target + while let item = self[next] { + if visited.contains(item) { + return false + } + next = item + visited.insert(next) + } + } + return true + } + + fileprivate func resolve(_ key: FilePath) throws -> FilePath? { + let target = self[key] + guard let target else { + return nil + } + var next = target + let visited: Set = [next] + while let item = self[next] { + if visited.contains(item) { + throw UnpackError.circularLinks + } + next = item + } + return next + } +} +#endif diff --git a/Sources/ContainerizationEXT4/Integer+Extensions.swift b/Sources/ContainerizationEXT4/Integer+Extensions.swift new file mode 100644 index 00000000..43760046 --- /dev/null +++ b/Sources/ContainerizationEXT4/Integer+Extensions.swift @@ -0,0 +1,133 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +extension UInt64 { + public var lo: UInt32 { + UInt32(self & 0xffff_ffff) + } + + public var hi: UInt32 { + UInt32(self >> 32) + } + + public static func - (lhs: Self, rhs: UInt32) -> UInt64 { + lhs - UInt64(rhs) + } + + public static func % (lhs: Self, rhs: UInt32) -> UInt64 { + lhs % UInt64(rhs) + } + + public static func / (lhs: Self, rhs: UInt32) -> UInt32 { + (lhs / UInt64(rhs)).lo + } + + public static func * (lhs: Self, rhs: UInt32) -> UInt64 { + lhs * UInt64(rhs) + } + + public static func * (lhs: Self, rhs: Int) -> UInt64 { + lhs * UInt64(rhs) + } +} + +extension UInt32 { + public var lo: UInt16 { + UInt16(self & 0xffff) + } + + public var hi: UInt16 { + UInt16(self >> 16) + } + + public static func + (lhs: Self, rhs: Int.IntegerLiteralType) -> UInt32 { + lhs + UInt32(rhs) + } + + public static func - (lhs: Self, rhs: Int.IntegerLiteralType) -> UInt32 { + lhs - UInt32(rhs) + } + + public static func / (lhs: Self, rhs: Int.IntegerLiteralType) -> UInt32 { + lhs / UInt32(rhs) + } + + public static func - (lhs: Self, rhs: UInt16) -> UInt32 { + lhs - UInt32(rhs) + } + + public static func * (lhs: Self, rhs: Int.IntegerLiteralType) -> Int { + Int(lhs) * rhs + } +} + +extension Int { + public static func + (lhs: Self, rhs: UInt32) -> Int { + lhs + Int(rhs) + } + + public static func + (lhs: Self, rhs: UInt32) -> UInt32 { + UInt32(lhs) + rhs + } +} + +extension UInt16 { + func isDir() -> Bool { + self & EXT4.FileModeFlag.TypeMask.rawValue == EXT4.FileModeFlag.S_IFDIR.rawValue + } + + func isLink() -> Bool { + self & EXT4.FileModeFlag.TypeMask.rawValue == EXT4.FileModeFlag.S_IFLNK.rawValue + } + + func isReg() -> Bool { + self & EXT4.FileModeFlag.TypeMask.rawValue == EXT4.FileModeFlag.S_IFREG.rawValue + } + + func fileType() -> UInt8 { + typealias FMode = EXT4.FileModeFlag + typealias FileType = EXT4.FileType + switch self & FMode.TypeMask.rawValue { + case FMode.S_IFREG.rawValue: + return FileType.regular.rawValue + case FMode.S_IFDIR.rawValue: + return FileType.directory.rawValue + case FMode.S_IFCHR.rawValue: + return FileType.character.rawValue + case FMode.S_IFBLK.rawValue: + return FileType.block.rawValue + case FMode.S_IFIFO.rawValue: + return FileType.fifo.rawValue + case FMode.S_IFSOCK.rawValue: + return FileType.socket.rawValue + case FMode.S_IFLNK.rawValue: + return FileType.symbolicLink.rawValue + default: + return FileType.unknown.rawValue + } + } +} + +extension [UInt8] { + var allZeros: Bool { + for num in self where num != 0 { + return false + } + return true + } +} diff --git a/Sources/ContainerizationEXT4/UnsafeLittleEndianBytes.swift b/Sources/ContainerizationEXT4/UnsafeLittleEndianBytes.swift new file mode 100644 index 00000000..c041a887 --- /dev/null +++ b/Sources/ContainerizationEXT4/UnsafeLittleEndianBytes.swift @@ -0,0 +1,82 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +// takes a pointer and converts its contents to native endian bytes +public func withUnsafeLittleEndianBytes(of value: T, body: (UnsafeRawBufferPointer) throws -> Result) + rethrows -> Result +{ + switch Endian { + case .little: + return try withUnsafeBytes(of: value) { bytes in + try body(bytes) + } + case .big: + return try withUnsafeBytes(of: value) { buffer in + let reversedBuffer = Array(buffer.reversed()) + return try reversedBuffer.withUnsafeBytes { buf in + try body(buf) + } + } + } +} + +public func withUnsafeLittleEndianBuffer( + of value: UnsafeRawBufferPointer, body: (UnsafeRawBufferPointer) throws -> T +) rethrows -> T { + switch Endian { + case .little: + return try body(value) + case .big: + let reversed = Array(value.reversed()) + return try reversed.withUnsafeBytes { buf in + try body(buf) + } + } +} + +extension UnsafeRawBufferPointer { + // loads littleEndian raw data, converts it native endian format and calls UnsafeRawBufferPointer.load + public func loadLittleEndian(as type: T.Type) -> T { + switch Endian { + case .little: + return self.load(as: T.self) + case .big: + let buffer = Array(self.reversed()) + return buffer.withUnsafeBytes { ptr in + ptr.load(as: T.self) + } + } + } +} + +public enum Endianness { + case little + case big +} + +// returns current endianness +public var Endian: Endianness { + switch CFByteOrderGetCurrent() { + case CFByteOrder(CFByteOrderLittleEndian.rawValue): + return .little + case CFByteOrder(CFByteOrderBigEndian.rawValue): + return .big + default: + fatalError("impossible") + } +} diff --git a/Sources/ContainerizationError/ContainerizationError.swift b/Sources/ContainerizationError/ContainerizationError.swift new file mode 100644 index 00000000..4f06ccae --- /dev/null +++ b/Sources/ContainerizationError/ContainerizationError.swift @@ -0,0 +1,156 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +/// The core error type for Containerization. +/// +/// Most API surfaces for the core container/process/agent types will +/// return a ContainerizationError. +public struct ContainerizationError: Swift.Error, Sendable { + public var code: Code + public var message: String + public var cause: (any Error)? + + /// Creates a new error. + /// + /// - Parameters: + /// - code: The error code. + /// - message: A description of the error. + /// - cause: The original error which led to this error being thrown. + public init(_ code: Code, message: String, cause: (any Error)? = nil) { + self.code = code + self.message = message + self.cause = cause + } + + /// Creates a new error. + /// + /// - Parameters: + /// - rawCode: The error code value as a String. + /// - message: A description of the error. + /// - cause: The original error which led to this error being thrown. + public init(_ rawCode: String, message: String, cause: (any Error)? = nil) { + self.code = Code(rawValue: rawCode) + self.message = message + self.cause = cause + } + + public func hash(into hasher: inout Hasher) { + hasher.combine(self.code) + hasher.combine(self.message) + } + + public static func == (lhs: Self, rhs: Self) -> Bool { + lhs.code == rhs.code && lhs.message == rhs.message + } + + public func isCode(_ code: Code) -> Bool { + self.code == code + } +} + +extension ContainerizationError: CustomStringConvertible { + public var description: String { + guard let cause = self.cause else { + return "\(self.code): \"\(self.message)\"" + } + return "\(self.code): \"\(self.message)\" (cause: \"\(cause)\")" + } +} + +extension ContainerizationError { + public struct Code: Sendable, Hashable { + private enum Value: Hashable, Sendable, CaseIterable { + case unknown + case invalidArgument + case internalError + case exists + case notFound + case cancelled + case invalidState + case empty + case timeout + case unsupported + case interrupted + } + + private var value: Value + private init(_ value: Value) { + self.value = value + } + + init(rawValue: String) { + let values = Value.allCases.reduce(into: [String: Value]()) { + $0[String(describing: $1)] = $1 + } + + let match = values[rawValue] + guard let match else { + fatalError("invalid Code Value \(rawValue)") + } + self.value = match + } + + public static var unknown: Self { + Self(.unknown) + } + + public static var invalidArgument: Self { + Self(.invalidArgument) + } + + public static var internalError: Self { + Self(.internalError) + } + + public static var exists: Self { + Self(.exists) + } + + public static var notFound: Self { + Self(.notFound) + } + + public static var cancelled: Self { + Self(.cancelled) + } + + public static var invalidState: Self { + Self(.invalidState) + } + + public static var empty: Self { + Self(.empty) + } + + public static var timeout: Self { + Self(.timeout) + } + + public static var unsupported: Self { + Self(.unsupported) + } + + public static var interrupted: Self { + Self(.interrupted) + } + } +} + +extension ContainerizationError.Code: CustomStringConvertible { + public var description: String { + String(describing: self.value) + } +} diff --git a/Sources/ContainerizationExtras/AddressAllocator.swift b/Sources/ContainerizationExtras/AddressAllocator.swift new file mode 100644 index 00000000..bee05594 --- /dev/null +++ b/Sources/ContainerizationExtras/AddressAllocator.swift @@ -0,0 +1,64 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +/// Conforming objects can allocate and free various address types. +public protocol AddressAllocator: Sendable { + associatedtype AddressType: Sendable + + /// Allocate a new address. + func allocate() throws -> AddressType + + /// Attempt to reserve a specific address. + func reserve(_ address: AddressType) throws + + /// Free an allocated address. + func release(_ address: AddressType) throws + + /// If no addresses are allocated, prevent future allocations and return true. + func disableAllocator() -> Bool +} + +public enum AllocatorError: Swift.Error, CustomStringConvertible, Equatable { + case allocatorDisabled + case allocatorFull + case alreadyAllocated(_ address: String) + case invalidAddress(_ index: String) + case invalidArgument(_ msg: String) + case invalidIndex(_ index: Int) + case notAllocated(_ address: String) + case rangeExceeded + + public var description: String { + switch self { + case .allocatorDisabled: + return "the allocator is shutting down" + case .allocatorFull: + return "no free indices are available for allocation" + case .alreadyAllocated(let address): + return "cannot choose already-allocated address \(address)" + case .invalidAddress(let address): + return "cannot create index using address \(address)" + case .invalidArgument(let msg): + return "invalid argument: \(msg)" + case .invalidIndex(let index): + return "cannot create address using index \(index)" + case .notAllocated(let address): + return "cannot free unallocated address \(address)" + case .rangeExceeded: + return "cannot create allocator that overflows maximum address value" + } + } +} diff --git a/Sources/ContainerizationExtras/AsyncLock.swift b/Sources/ContainerizationExtras/AsyncLock.swift new file mode 100644 index 00000000..22fe7ed4 --- /dev/null +++ b/Sources/ContainerizationExtras/AsyncLock.swift @@ -0,0 +1,50 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +public actor AsyncLock { + private var busy = false + private var queue: ArraySlice> = [] + + public struct Context: Sendable { + fileprivate init() {} + } + + public init() {} + + public func withLock(_ body: @Sendable @escaping (Context) async throws -> T) async rethrows -> T { + while self.busy { + await withCheckedContinuation { cc in + self.queue.append(cc) + } + } + + self.busy = true + + defer { + self.busy = false + if let next = self.queue.popFirst() { + next.resume(returning: ()) + } else { + self.queue = [] + } + } + + let context = Context() + return try await body(context) + } +} diff --git a/Sources/ContainerizationExtras/CIDRAddress.swift b/Sources/ContainerizationExtras/CIDRAddress.swift new file mode 100644 index 00000000..89bd26f3 --- /dev/null +++ b/Sources/ContainerizationExtras/CIDRAddress.swift @@ -0,0 +1,132 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +/// Describes an IPv4 CIDR address block. +public struct CIDRAddress: CustomStringConvertible, Equatable, Sendable { + + /// The base IPv4 address of the CIDR block. + public let lower: IPv4Address + + /// The last IPv4 address of the CIDR block + public let upper: IPv4Address + + /// The IPv4 address component of the CIDR block. + public let address: IPv4Address + + /// The address prefix length for the CIDR block, which determines its size. + public let prefixLength: PrefixLength + + /// Create an CIDR address block from its text representation. + public init(_ cidr: String) throws { + let split = cidr.components(separatedBy: "/") + guard split.count == 2 else { + throw NetworkAddressError.invalidCIDR(cidr: cidr) + } + address = try IPv4Address(split[0]) + guard let prefixLength = PrefixLength(split[1]) else { + throw NetworkAddressError.invalidCIDR(cidr: cidr) + } + guard prefixLength >= 0 && prefixLength <= 32 else { + throw NetworkAddressError.invalidCIDR(cidr: cidr) + } + + self.prefixLength = prefixLength + lower = address.prefix(prefixLength: prefixLength) + upper = IPv4Address(fromValue: lower.value + prefixLength.suffixMask32) + } + + /// Create a CIDR address from a member IP and a prefix length. + public init(_ address: IPv4Address, prefixLength: PrefixLength) throws { + guard prefixLength >= 0 && prefixLength <= 32 else { + throw NetworkAddressError.invalidCIDR(cidr: "\(address)/\(prefixLength)") + } + + self.prefixLength = prefixLength + self.address = address + lower = address.prefix(prefixLength: prefixLength) + upper = IPv4Address(fromValue: lower.value + prefixLength.suffixMask32) + } + + /// Create the smallest CIDR block that includes the lower and upper bounds. + public init(lower: IPv4Address, upper: IPv4Address) throws { + guard lower.value <= upper.value else { + throw NetworkAddressError.invalidAddressRange(lower: lower.description, upper: upper.description) + } + + address = lower + for prefixLength: PrefixLength in 1...32 { + // find the first case where a subnet mask would put lower and upper in different CIDR block + let mask = prefixLength.prefixMask32 + + if (lower.value & mask) != (upper.value & mask) { + self.prefixLength = prefixLength - 1 + self.lower = address.prefix(prefixLength: self.prefixLength) + self.upper = IPv4Address(fromValue: self.lower.value + self.prefixLength.suffixMask32) + return + } + } + + // if lower and upper are same, create a /32 block + self.prefixLength = 32 + self.lower = lower + self.upper = upper + } + + /// Get the offset of the specified address, relative to the + /// base address for the CIDR block, returning nil if the block + /// does not contain the address. + public func getIndex(_ address: IPv4Address) -> UInt32? { + guard address.value >= lower.value && address.value <= upper.value else { + return nil + } + + return address.value - lower.value + } + + /// Return true if the CIDR block contains the specified address. + public func contains(ipv4: IPv4Address) -> Bool { + lower.value <= ipv4.value && ipv4.value <= upper.value + } + + /// Return true if the CIDR block contains all addresses of another CIDR block. + public func contains(cidr: CIDRAddress) -> Bool { + lower.value <= cidr.lower.value && cidr.upper.value <= upper.value + } + + /// Return true if the CIDR block shares any addresses with another CIDR block. + public func overlaps(cidr: CIDRAddress) -> Bool { + (lower.value <= cidr.lower.value && upper.value >= cidr.lower.value) + || (upper.value >= cidr.upper.value && lower.value <= cidr.upper.value) + } + + /// Retrieve the text representation of the CIDR block. + public var description: String { + "\(address)/\(prefixLength)" + } +} + +extension CIDRAddress: Codable { + public init(from decoder: Decoder) throws { + let container = try decoder.singleValueContainer() + let text = try container.decode(String.self) + try self.init(text) + } + + public func encode(to encoder: Encoder) throws { + var container = encoder.singleValueContainer() + try container.encode(self.description) + } +} diff --git a/Sources/ContainerizationExtras/FileManager+Temporary.swift b/Sources/ContainerizationExtras/FileManager+Temporary.swift new file mode 100644 index 00000000..e982b57a --- /dev/null +++ b/Sources/ContainerizationExtras/FileManager+Temporary.swift @@ -0,0 +1,28 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +extension FileManager { + public func uniqueTemporaryDirectory(create: Bool = true) -> URL { + let tempDirectoryURL = temporaryDirectory + let uniqueDirectoryURL = tempDirectoryURL.appendingPathComponent(UUID().uuidString) + if create { + try? createDirectory(at: uniqueDirectoryURL, withIntermediateDirectories: true, attributes: nil) + } + return uniqueDirectoryURL + } +} diff --git a/Sources/ContainerizationExtras/IPAddress.swift b/Sources/ContainerizationExtras/IPAddress.swift new file mode 100644 index 00000000..6db48498 --- /dev/null +++ b/Sources/ContainerizationExtras/IPAddress.swift @@ -0,0 +1,92 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +/// Facilitates conversion between IPv4 address representations. +public struct IPv4Address: Codable, CustomStringConvertible, Equatable, Sendable { + /// The address as a 32-bit integer. + public let value: UInt32 + + /// Create an address from a dotted-decimal string, such as "192.168.64.10". + public init(_ fromString: String) throws { + let split = fromString.components(separatedBy: ".") + if split.count != 4 { + throw NetworkAddressError.invalidStringAddress(address: fromString) + } + + var parsedValue: UInt32 = 0 + for index in 0..<4 { + guard let octet = UInt8(split[index]) else { + throw NetworkAddressError.invalidStringAddress(address: fromString) + } + parsedValue |= UInt32(octet) << ((3 - index) * 8) + } + + value = parsedValue + } + + /// Create an address from an array of four bytes in network order (big-endian), + /// such as [192, 168, 64, 10]. + public init(fromNetworkBytes: [UInt8]) throws { + guard fromNetworkBytes.count == 4 else { + throw NetworkAddressError.invalidNetworkByteAddress(address: fromNetworkBytes) + } + + value = + (UInt32(fromNetworkBytes[0]) << 24) + | (UInt32(fromNetworkBytes[1]) << 16) + | (UInt32(fromNetworkBytes[2]) << 8) + | UInt32(fromNetworkBytes[3]) + } + + /// Create an address from a 32-bit integer, such as 0xc0a8_400a. + public init(fromValue: UInt32) { + value = fromValue + } + + /// Retrieve the address as an array of bytes in network byte order. + public var networkBytes: [UInt8] { + [ + UInt8((value >> 24) & 0xff), + UInt8((value >> 16) & 0xff), + UInt8((value >> 8) & 0xff), + UInt8(value & 0xff), + ] + } + + /// Retrieve the address as a dotted decimal string. + public var description: String { + networkBytes.map(String.init).joined(separator: ".") + } + + /// Create the base IPv4 address for a network that contains this + /// address and uses the specified subnet mask length. + public func prefix(prefixLength: PrefixLength) -> IPv4Address { + IPv4Address(fromValue: value & prefixLength.prefixMask32) + } +} + +extension IPv4Address { + public init(from decoder: Decoder) throws { + let container = try decoder.singleValueContainer() + let text = try container.decode(String.self) + try self.init(text) + } + + public func encode(to encoder: Encoder) throws { + var container = encoder.singleValueContainer() + try container.encode(self.description) + } +} diff --git a/Sources/ContainerizationExtras/IndexedAddressAllocator.swift b/Sources/ContainerizationExtras/IndexedAddressAllocator.swift new file mode 100644 index 00000000..6409bc82 --- /dev/null +++ b/Sources/ContainerizationExtras/IndexedAddressAllocator.swift @@ -0,0 +1,127 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Collections +import Synchronization + +/// Maps a network address to an array index value, or nil in the case of a domain error. +package typealias AddressToIndexTransform = @Sendable (AddressType) -> Int? + +/// Maps an array index value to a network address, or nil in the case of a domain error. +package typealias IndexToAddressTransform = @Sendable (Int) -> AddressType? + +package final class IndexedAddressAllocator: AddressAllocator { + private class State { + var allocations: BitArray + var enabled: Bool + var allocationCount: Int + let addressToIndex: AddressToIndexTransform + let indexToAddress: IndexToAddressTransform + + init( + size: Int, + addressToIndex: @escaping AddressToIndexTransform, + indexToAddress: @escaping IndexToAddressTransform + ) { + self.allocations = BitArray.init(repeating: false, count: size) + self.enabled = true + self.allocationCount = 0 + self.addressToIndex = addressToIndex + self.indexToAddress = indexToAddress + } + } + + private let stateGuard: Mutex + + /// Create an allocator with specified size and index mappings. + package init( + size: Int, + addressToIndex: @escaping AddressToIndexTransform, + indexToAddress: @escaping IndexToAddressTransform + ) { + let state = State( + size: size, + addressToIndex: addressToIndex, + indexToAddress: indexToAddress + ) + self.stateGuard = Mutex(state) + } + + public func allocate() throws -> AddressType { + try self.stateGuard.withLock { state in + guard state.enabled else { + throw AllocatorError.allocatorDisabled + } + + guard let index = state.allocations.firstIndex(of: false) else { + throw AllocatorError.allocatorFull + } + + guard let address = state.indexToAddress(index) else { + throw AllocatorError.invalidIndex(index) + } + + state.allocations[index] = true + state.allocationCount += 1 + return address + } + } + + package func reserve(_ address: AddressType) throws { + try self.stateGuard.withLock { state in + guard state.enabled else { + throw AllocatorError.allocatorDisabled + } + + guard let index = state.addressToIndex(address) else { + throw AllocatorError.invalidAddress(address.description) + } + + guard !state.allocations[index] else { + throw AllocatorError.alreadyAllocated("\(address.description)") + } + + state.allocations[index] = true + state.allocationCount += 1 + } + + } + + package func release(_ address: AddressType) throws { + try self.stateGuard.withLock { state in + guard let index = state.addressToIndex(address) else { + throw AllocatorError.invalidAddress(address.description) + } + + guard state.allocations[index] else { + throw AllocatorError.notAllocated("\(address.description)") + } + + state.allocations[index] = false + state.allocationCount -= 1 + } + } + + package func disableAllocator() -> Bool { + self.stateGuard.withLock { state in + guard state.allocationCount == 0 else { + return false + } + state.enabled = false + return true + } + } +} diff --git a/Sources/ContainerizationExtras/NetworkAddress+Allocator.swift b/Sources/ContainerizationExtras/NetworkAddress+Allocator.swift new file mode 100644 index 00000000..68b503c6 --- /dev/null +++ b/Sources/ContainerizationExtras/NetworkAddress+Allocator.swift @@ -0,0 +1,89 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +extension IPv4Address { + /// Creates an allocator for IPv4 addresses. + public static func allocator(lower: UInt32, size: Int) throws -> any AddressAllocator { + // NOTE: 2^31 - 1 size limit in the very improbable case that we run on 32-bit. + guard size > 0 && size < Int.max && 0xffff_ffff - lower >= size - 1 else { + throw AllocatorError.rangeExceeded + } + return IndexedAddressAllocator( + size: size, + addressToIndex: { address in + guard address.value >= lower && address.value - lower <= UInt32(size) else { + return nil + } + return Int(address.value - lower) + }, + indexToAddress: { IPv4Address(fromValue: lower + UInt32($0)) } + ) + } +} + +extension UInt16 { + /// Creates an allocator for TCP/UDP ports and other UInt16 values. + public static func allocator(lower: UInt16, size: Int) throws -> any AddressAllocator { + guard 0xffff - lower + 1 >= size else { + throw AllocatorError.rangeExceeded + } + + return IndexedAddressAllocator( + size: size, + addressToIndex: { address in + guard address >= lower && address <= lower + UInt16(size) else { + return nil + } + return Int(address - lower) + }, + indexToAddress: { lower + UInt16($0) } + ) + } +} + +extension UInt32 { + /// Creates an allocator for vsock ports, or any UInt32 values. + public static func allocator(lower: UInt32, size: Int) throws -> any AddressAllocator { + guard 0xffff_ffff - lower + 1 >= size else { + throw AllocatorError.rangeExceeded + } + + return IndexedAddressAllocator( + size: size, + addressToIndex: { address in + guard address >= lower && address <= lower + UInt32(size) else { + return nil + } + return Int(address - lower) + }, + indexToAddress: { lower + UInt32($0) } + ) + } +} + +extension Character { + private static let deviceLetters = Array("abcdefghijklmnopqrstuvwxyz") + + public static func blockDeviceTagAllocator() -> any AddressAllocator { + IndexedAddressAllocator( + size: Self.deviceLetters.count, + addressToIndex: { address in + Self.deviceLetters.firstIndex(of: address) + }, + indexToAddress: { Self.deviceLetters[$0] } + ) + } +} diff --git a/Sources/ContainerizationExtras/NetworkAddress.swift b/Sources/ContainerizationExtras/NetworkAddress.swift new file mode 100644 index 00000000..79a96916 --- /dev/null +++ b/Sources/ContainerizationExtras/NetworkAddress.swift @@ -0,0 +1,69 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +/// Errors related to IP and CIDR addresses. +public enum NetworkAddressError: Swift.Error, Equatable, CustomStringConvertible { + case invalidStringAddress(address: String) + case invalidNetworkByteAddress(address: [UInt8]) + case invalidCIDR(cidr: String) + case invalidAddressForSubnet(address: String, cidr: String) + case invalidAddressRange(lower: String, upper: String) + + public var description: String { + switch self { + case .invalidStringAddress(let address): + return "invalid IP address string \(address)" + case .invalidNetworkByteAddress(let address): + return "invalid IP address bytes \(address)" + case .invalidCIDR(let cidr): + return "invalid CIDR block: \(cidr)" + case .invalidAddressForSubnet(let address, let cidr): + return "invalid address \(address) for subnet \(cidr)" + case .invalidAddressRange(let lower, let upper): + return "invalid range for addresses \(lower) and \(upper)" + } + } +} + +public typealias PrefixLength = UInt8 + +extension PrefixLength { + /// Compute a bit mask that passes the suffix bits, given the network prefix mask length. + public var suffixMask32: UInt32 { + if self <= 0 { + return 0xffff_ffff + } + return self >= 32 ? 0x0000_0000 : (1 << (32 - self)) - 1 + } + + /// Compute a bit mask that passes the prefix bits, given the network prefix mask length. + public var prefixMask32: UInt32 { + ~self.suffixMask32 + } + + /// Compute a bit mask that passes the suffix bits, given the network prefix mask length. + public var suffixMask48: UInt64 { + if self <= 0 { + return 0x0000_ffff_ffff_ffff + } + return self >= 48 ? 0x0000_0000_0000_0000 : (1 << (48 - self)) - 1 + } + + /// Compute a bit mask that passes the prefix bits, given the network prefix mask length. + public var prefixMask48: UInt64 { + ~self.suffixMask48 & 0x0000_ffff_ffff_ffff + } +} diff --git a/Sources/ContainerizationExtras/ProgressEvent.swift b/Sources/ContainerizationExtras/ProgressEvent.swift new file mode 100644 index 00000000..5e484c17 --- /dev/null +++ b/Sources/ContainerizationExtras/ProgressEvent.swift @@ -0,0 +1,39 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +/// A progress update event. +public struct ProgressEvent: Sendable { + /// The event name. The possible values: + /// - `add-items`: Increment the number of processed items by `value`. + /// - `add-total-items`: Increment the total number of items to process by `value`. + /// - `add-size`: Increment the size of processed items by `value`. + /// - `add-total-size`: Increment the total size of items to process by `value`. + public let event: String + /// The event value. + public let value: any Sendable + + /// Creates an instance. + /// - Parameters: + /// - event: The event name. + /// - value: The event value. + public init(event: String, value: any Sendable) { + self.event = event + self.value = value + } +} + +/// The progress update handler. +public typealias ProgressHandler = @Sendable (_ events: [ProgressEvent]) async -> Void diff --git a/Sources/ContainerizationExtras/Timeout.swift b/Sources/ContainerizationExtras/Timeout.swift new file mode 100644 index 00000000..9049ff29 --- /dev/null +++ b/Sources/ContainerizationExtras/Timeout.swift @@ -0,0 +1,42 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +public struct Timeout { + public static func run( + seconds: UInt32, + operation: @escaping @Sendable () async -> T + ) async throws -> T { + try await withThrowingTaskGroup(of: T.self) { group in + group.addTask { + await operation() + } + + group.addTask { + try await Task.sleep(for: .seconds(seconds)) + throw CancellationError() + } + + guard let result = try await group.next() else { + fatalError() + } + + group.cancelAll() + return result + } + } +} diff --git a/Sources/ContainerizationExtras/UInt8+DataBinding.swift b/Sources/ContainerizationExtras/UInt8+DataBinding.swift new file mode 100644 index 00000000..f39f60b6 --- /dev/null +++ b/Sources/ContainerizationExtras/UInt8+DataBinding.swift @@ -0,0 +1,78 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +extension ArraySlice { + package func hexEncodedString() -> String { + self.map { String(format: "%02hhx", $0) }.joined() + } +} + +extension [UInt8] { + package func hexEncodedString() -> String { + self.map { String(format: "%02hhx", $0) }.joined() + } + + package mutating func bind(as type: T.Type, offset: Int = 0, size: Int? = nil) -> UnsafeMutablePointer? { + guard self.count >= (size ?? MemoryLayout.size) + offset else { + return nil + } + + return self.withUnsafeMutableBytes { $0.baseAddress?.advanced(by: offset).assumingMemoryBound(to: T.self) } + } + + package mutating func copyIn(as type: T.Type, value: T, offset: Int = 0, size: Int? = nil) -> Int? { + let size = size ?? MemoryLayout.size + guard self.count >= size - offset else { + return nil + } + + return self.withUnsafeMutableBytes { + $0.baseAddress?.advanced(by: offset).assumingMemoryBound(to: T.self).pointee = value + return offset + MemoryLayout.size + } + } + + package mutating func copyOut(as type: T.Type, offset: Int = 0, size: Int? = nil) -> (Int, T)? { + guard self.count >= (size ?? MemoryLayout.size) - offset else { + return nil + } + + return self.withUnsafeMutableBytes { + guard let value = $0.baseAddress?.advanced(by: offset).assumingMemoryBound(to: T.self).pointee else { + return nil + } + return (offset + MemoryLayout.size, value) + } + } + + package mutating func copyIn(buffer: [UInt8], offset: Int = 0) -> Int? { + guard offset + buffer.count <= self.count else { + return nil + } + + self[offset.. Int? { + guard offset + buffer.count <= self.count else { + return nil + } + + buffer[0.. { + AsyncStream { cont in + self._stream.open() + defer { self._stream.close() } + + let readBuffer = UnsafeMutablePointer.allocate(capacity: _buffSize) + + while true { + let byteRead = self._stream.read(readBuffer, maxLength: _buffSize) + if byteRead <= 0 { + readBuffer.deallocate() + cont.finish() + break + } else { + let data = Data(bytes: readBuffer, count: byteRead) + let buffer = ByteBuffer(bytes: data) + cont.yield(buffer) + } + } + } + } + + public var dataStream: AsyncStream { + AsyncStream { cont in + self._stream.open() + defer { self._stream.close() } + + let readBuffer = UnsafeMutablePointer.allocate(capacity: self._buffSize) + while true { + let byteRead = self._stream.read(readBuffer, maxLength: self._buffSize) + if byteRead <= 0 { + readBuffer.deallocate() + cont.finish() + break + } else { + let data = Data(bytes: readBuffer, count: byteRead) + cont.yield(data) + } + } + } + } +} + +extension ReadStream { + enum Error: Swift.Error, CustomStringConvertible { + case failedToCreateStream + case noSuchFileOrDirectory(_ p: URL) + + var description: String { + switch self { + case .failedToCreateStream: + return "failed to create stream" + case .noSuchFileOrDirectory(let p): + return "no such file or directory: \(p.path)" + } + } + } +} diff --git a/Sources/ContainerizationNetlink/NetlinkSession.swift b/Sources/ContainerizationNetlink/NetlinkSession.swift new file mode 100644 index 00000000..c51a14be --- /dev/null +++ b/Sources/ContainerizationNetlink/NetlinkSession.swift @@ -0,0 +1,526 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationExtras +import ContainerizationOS +import Logging + +public struct NetlinkSession { + private static let receiveDataLength = 65536 + + private let socket: any NetlinkSocket + + private let log: Logger + public init(socket: any NetlinkSocket, log: Logger? = nil) { + self.socket = socket + self.log = log ?? Logger(label: "com.apple.containerization.netlink") + } + + public enum Error: Swift.Error, CustomStringConvertible, Equatable { + case invalidIpAddress + case invalidPrefixLength + case unexpectedInfo(type: UInt16) + case unexpectedOffset(offset: Int, size: Int) + case unexpectedResidualPackets + case unexpectedResultSet(count: Int, expected: Int) + + public var description: String { + switch self { + case .invalidIpAddress: + return "invalid IP address" + case .invalidPrefixLength: + return "invalid prefix length" + case .unexpectedInfo(let type): + return "unexpected response information, type = \(type)" + case .unexpectedOffset(let offset, let size): + return "unexpected buffer state, offset = \(offset), size = \(size)" + case .unexpectedResidualPackets: + return "unexpected residual response packets" + case .unexpectedResultSet(let count, let expected): + return "unexpected result set size, count = \(count), expected = \(expected)" + } + } + } + + /// ip link set dev [interface] [up|down] + public func linkSet(interface: String, up: Bool) throws { + let interfaceIndex = try getInterfaceIndex(interface) + let requestSize = NetlinkMessageHeader.size + InterfaceInfo.size + var requestBuffer = [UInt8](repeating: 0, count: requestSize) + var requestOffset = 0 + + let requestHeader = NetlinkMessageHeader( + len: UInt32(requestBuffer.count), + type: NetlinkType.RTM_NEWLINK, + flags: NetlinkFlags.NLM_F_REQUEST | NetlinkFlags.NLM_F_ACK, + pid: socket.pid) + requestOffset = try requestHeader.appendBuffer(&requestBuffer, offset: requestOffset) + + let flags = up ? InterfaceFlags.IFF_UP : 0 + let requestInfo = InterfaceInfo( + family: UInt8(AddressFamily.AF_PACKET), + index: interfaceIndex, + flags: flags, + change: InterfaceFlags.DEFAULT_CHANGE) + requestOffset = try requestInfo.appendBuffer(&requestBuffer, offset: requestOffset) + + guard requestOffset == requestSize else { + throw Error.unexpectedOffset(offset: requestOffset, size: requestSize) + } + + try sendRequest(buffer: &requestBuffer) + let (infos, _) = try parseResponse(infoType: NetlinkType.RTM_NEWLINK) { InterfaceInfo() } + guard infos.count == 0 else { + throw Error.unexpectedResultSet(count: infos.count, expected: 0) + } + } + + /// ip link ip show + public func linkGet(interface: String? = nil) throws -> [LinkResponse] { + let maskAttr = RTAttribute( + len: UInt16(RTAttribute.size + MemoryLayout.size), type: LinkAttributeType.IFLA_EXT_MASK) + let interfaceName = try interface.map { try getInterfaceName($0) } + let interfaceNameAttr = interfaceName.map { + RTAttribute(len: UInt16(RTAttribute.size + $0.count), type: LinkAttributeType.IFLA_EXT_IFNAME) + } + let requestSize = + NetlinkMessageHeader.size + InterfaceInfo.size + maskAttr.paddedLen + (interfaceNameAttr?.paddedLen ?? 0) + var requestBuffer = [UInt8](repeating: 0, count: requestSize) + var requestOffset = 0 + + let flags = + interface != nil ? NetlinkFlags.NLM_F_REQUEST : (NetlinkFlags.NLM_F_REQUEST | NetlinkFlags.NLM_F_DUMP) + let requestHeader = NetlinkMessageHeader( + len: UInt32(requestBuffer.count), + type: NetlinkType.RTM_GETLINK, + flags: flags, + pid: socket.pid) + requestOffset = try requestHeader.appendBuffer(&requestBuffer, offset: requestOffset) + + let requestInfo = InterfaceInfo( + family: UInt8(AddressFamily.AF_PACKET), + index: 0, + flags: InterfaceFlags.IFF_UP, + change: InterfaceFlags.DEFAULT_CHANGE) + requestOffset = try requestInfo.appendBuffer(&requestBuffer, offset: requestOffset) + + requestOffset = try maskAttr.appendBuffer(&requestBuffer, offset: requestOffset) + guard + var requestOffset = requestBuffer.copyIn( + as: UInt32.self, + value: LinkAttributeMaskFilter.RTEXT_FILTER_VF | LinkAttributeMaskFilter.RTEXT_FILTER_SKIP_STATS, + offset: requestOffset) + else { + throw NetlinkDataError.sendMarshalFailure + } + + if let interfaceNameAttr { + if let interfaceName { + requestOffset = try interfaceNameAttr.appendBuffer(&requestBuffer, offset: requestOffset) + guard let updatedRequestOffset = requestBuffer.copyIn(buffer: interfaceName, offset: requestOffset) + else { + throw NetlinkDataError.sendMarshalFailure + } + + requestOffset = updatedRequestOffset + } + } + + guard requestOffset == requestSize else { + throw Error.unexpectedOffset(offset: requestOffset, size: requestSize) + } + + try sendRequest(buffer: &requestBuffer) + let (infos, attrDataLists) = try parseResponse(infoType: NetlinkType.RTM_NEWLINK) { InterfaceInfo() } + var linkResponses: [LinkResponse] = [] + for i in 0...size * ipAddressBytes.count + let requestSize = NetlinkMessageHeader.size + AddressInfo.size + 2 * addressAttrSize + var requestBuffer = [UInt8](repeating: 0, count: requestSize) + var requestOffset = 0 + + let header = NetlinkMessageHeader( + len: UInt32(requestBuffer.count), + type: NetlinkType.RTM_NEWADDR, + flags: NetlinkFlags.NLM_F_REQUEST | NetlinkFlags.NLM_F_ACK | NetlinkFlags.NLM_F_EXCL + | NetlinkFlags.NLM_F_CREATE, + seq: 0, + pid: socket.pid) + requestOffset = try header.appendBuffer(&requestBuffer, offset: requestOffset) + + let requestInfo = AddressInfo( + family: UInt8(AddressFamily.AF_INET), + prefixLength: parsed.prefix, + flags: 0, + scope: NetlinkScope.RT_SCOPE_UNIVERSE, + index: UInt32(interfaceIndex)) + requestOffset = try requestInfo.appendBuffer(&requestBuffer, offset: requestOffset) + + let ipLocalAttr = RTAttribute(len: UInt16(addressAttrSize), type: AddressAttributeType.IFA_LOCAL) + requestOffset = try ipLocalAttr.appendBuffer(&requestBuffer, offset: requestOffset) + guard var requestOffset = requestBuffer.copyIn(buffer: ipAddressBytes, offset: requestOffset) else { + throw NetlinkDataError.sendMarshalFailure + } + + let ipAddressAttr = RTAttribute(len: UInt16(addressAttrSize), type: AddressAttributeType.IFA_ADDRESS) + requestOffset = try ipAddressAttr.appendBuffer(&requestBuffer, offset: requestOffset) + guard let requestOffset = requestBuffer.copyIn(buffer: ipAddressBytes, offset: requestOffset) else { + throw NetlinkDataError.sendMarshalFailure + } + + guard requestOffset == requestSize else { + throw Error.unexpectedOffset(offset: requestOffset, size: requestSize) + } + + try sendRequest(buffer: &requestBuffer) + let (infos, _) = try parseResponse(infoType: NetlinkType.RTM_NEWLINK) { AddressInfo() } + guard infos.count == 0 else { + throw Error.unexpectedResultSet(count: infos.count, expected: 0) + } + } + + private func parseCIDR(cidr: String) throws -> (address: String, prefix: UInt8) { + let split = cidr.components(separatedBy: "/") + guard split.count == 2 else { + throw NetworkAddressError.invalidCIDR(cidr: cidr) + } + let address = split[0] + guard let prefixLength = PrefixLength(split[1]) else { + throw NetworkAddressError.invalidCIDR(cidr: cidr) + } + guard prefixLength >= 0 && prefixLength <= 32 else { + throw NetworkAddressError.invalidCIDR(cidr: cidr) + } + return (address, prefixLength) + } + + /// ip route add [dest-cidr] dev [interface] src [src-addr] proto kernel + public func routeAdd( + interface: String, + destinationAddress: String, + srcAddr: String + ) throws { + let parsed = try parseCIDR(cidr: destinationAddress) + let interfaceIndex = try getInterfaceIndex(interface) + let dstAddrBytes = try IPv4Address(parsed.address).networkBytes + let dstAddrAttrSize = RTAttribute.size + dstAddrBytes.count + let srcAddrBytes = try IPv4Address(srcAddr).networkBytes + let srcAddrAttrSize = RTAttribute.size + srcAddrBytes.count + let interfaceAttrSize = RTAttribute.size + MemoryLayout.size + let requestSize = + NetlinkMessageHeader.size + RouteInfo.size + dstAddrAttrSize + srcAddrAttrSize + interfaceAttrSize + var requestBuffer = [UInt8](repeating: 0, count: requestSize) + var requestOffset = 0 + + let header = NetlinkMessageHeader( + len: UInt32(requestBuffer.count), + type: NetlinkType.RTM_NEWROUTE, + flags: NetlinkFlags.NLM_F_REQUEST | NetlinkFlags.NLM_F_ACK | NetlinkFlags.NLM_F_EXCL + | NetlinkFlags.NLM_F_CREATE, + pid: socket.pid) + requestOffset = try header.appendBuffer(&requestBuffer, offset: requestOffset) + + let requestInfo = RouteInfo( + family: UInt8(AddressFamily.AF_INET), + dstLen: parsed.prefix, + srcLen: 0, + tos: 0, + table: RouteTable.MAIN, + proto: RouteProtocol.KERNEL, + scope: RouteScope.LINK, + type: RouteType.UNICAST, + flags: 0) + requestOffset = try requestInfo.appendBuffer(&requestBuffer, offset: requestOffset) + + let dstAddrAttr = RTAttribute(len: UInt16(dstAddrAttrSize), type: RouteAttributeType.DST) + requestOffset = try dstAddrAttr.appendBuffer(&requestBuffer, offset: requestOffset) + guard var requestOffset = requestBuffer.copyIn(buffer: dstAddrBytes, offset: requestOffset) else { + throw NetlinkDataError.sendMarshalFailure + } + + let srcAddrAttr = RTAttribute(len: UInt16(dstAddrAttrSize), type: RouteAttributeType.PREFSRC) + requestOffset = try srcAddrAttr.appendBuffer(&requestBuffer, offset: requestOffset) + guard var requestOffset = requestBuffer.copyIn(buffer: srcAddrBytes, offset: requestOffset) else { + throw NetlinkDataError.sendMarshalFailure + } + + let interfaceAttr = RTAttribute(len: UInt16(interfaceAttrSize), type: RouteAttributeType.OIF) + requestOffset = try interfaceAttr.appendBuffer(&requestBuffer, offset: requestOffset) + guard + let requestOffset = requestBuffer.copyIn( + as: UInt32.self, + value: UInt32(interfaceIndex), + offset: requestOffset) + else { + throw NetlinkDataError.sendMarshalFailure + } + + guard requestOffset == requestSize else { + throw Error.unexpectedOffset(offset: requestOffset, size: requestSize) + } + + try sendRequest(buffer: &requestBuffer) + let (infos, _) = try parseResponse(infoType: NetlinkType.RTM_NEWLINK) { AddressInfo() } + guard infos.count == 0 else { + throw Error.unexpectedResultSet(count: infos.count, expected: 0) + } + } + + /// ip route add default via [dst-address] src [src-address] + public func routeAddDefault( + interface: String, + gateway: String + ) throws { + let dstAddrBytes = try IPv4Address(gateway).networkBytes + let dstAddrAttrSize = RTAttribute.size + dstAddrBytes.count + + let interfaceAttrSize = RTAttribute.size + MemoryLayout.size + let interfaceIndex = try getInterfaceIndex(interface) + let requestSize = NetlinkMessageHeader.size + RouteInfo.size + dstAddrAttrSize + interfaceAttrSize + + var requestBuffer = [UInt8](repeating: 0, count: requestSize) + var requestOffset = 0 + + let header = NetlinkMessageHeader( + len: UInt32(requestBuffer.count), + type: NetlinkType.RTM_NEWROUTE, + flags: NetlinkFlags.NLM_F_REQUEST | NetlinkFlags.NLM_F_ACK | NetlinkFlags.NLM_F_EXCL + | NetlinkFlags.NLM_F_CREATE, + pid: socket.pid) + requestOffset = try header.appendBuffer(&requestBuffer, offset: requestOffset) + + let requestInfo = RouteInfo( + family: UInt8(AddressFamily.AF_INET), + dstLen: 0, + srcLen: 0, + tos: 0, + table: RouteTable.MAIN, + proto: RouteProtocol.BOOT, + scope: RouteScope.UNIVERSE, + type: RouteType.UNICAST, + flags: 0) + requestOffset = try requestInfo.appendBuffer(&requestBuffer, offset: requestOffset) + + let dstAddrAttr = RTAttribute(len: UInt16(dstAddrAttrSize), type: RouteAttributeType.GATEWAY) + requestOffset = try dstAddrAttr.appendBuffer(&requestBuffer, offset: requestOffset) + guard var requestOffset = requestBuffer.copyIn(buffer: dstAddrBytes, offset: requestOffset) else { + throw NetlinkDataError.sendMarshalFailure + } + let interfaceAttr = RTAttribute(len: UInt16(interfaceAttrSize), type: RouteAttributeType.OIF) + requestOffset = try interfaceAttr.appendBuffer(&requestBuffer, offset: requestOffset) + guard + let requestOffset = requestBuffer.copyIn( + as: UInt32.self, + value: UInt32(interfaceIndex), + offset: requestOffset) + else { + throw NetlinkDataError.sendMarshalFailure + } + + guard requestOffset == requestSize else { + throw Error.unexpectedOffset(offset: requestOffset, size: requestSize) + } + + try sendRequest(buffer: &requestBuffer) + let (infos, _) = try parseResponse(infoType: NetlinkType.RTM_NEWLINK) { AddressInfo() } + guard infos.count == 0 else { + throw Error.unexpectedResultSet(count: infos.count, expected: 0) + } + } + + private func getInterfaceName(_ interface: String) throws -> [UInt8] { + guard let interfaceNameData = interface.data(using: .utf8) else { + throw NetlinkDataError.sendMarshalFailure + } + + var interfaceName = [UInt8](interfaceNameData) + interfaceName.append(0) + + while interfaceName.count % MemoryLayout.size != 0 { + interfaceName.append(0) + } + + return interfaceName + } + + private func getInterfaceIndex(_ interface: String) throws -> Int32 { + let linkResponses = try linkGet(interface: interface) + guard linkResponses.count == 1 else { + throw Error.unexpectedResultSet(count: linkResponses.count, expected: 1) + } + + return linkResponses[0].interfaceIndex + } + + private func sendRequest(buffer: inout [UInt8]) throws { + log.debug("SEND-LENGTH: \(buffer.count)") + log.debug("SEND-DUMP: \(buffer[0.. ([UInt8], Int) { + var buffer = [UInt8](repeating: 0, count: Self.receiveDataLength) + let size = try socket.recv(buf: &buffer, len: Self.receiveDataLength, flags: 0) + log.debug("RECV-LENGTH: \(size)") + log.debug("RECV-DUMP: \(buffer[0..(infoType: UInt16? = nil, _ infoProvider: () -> T) throws -> ( + [T], [[RTAttributeData]] + ) { + var infos: [T] = [] + var attrDataLists: [[RTAttributeData]] = [] + + var moreResponses = false + repeat { + var (buffer, size) = try receiveResponse() + let header: NetlinkMessageHeader + var offset = 0 + + (header, offset) = try parseHeader(buffer: &buffer, offset: offset) + if let infoType { + if header.type == infoType { + log.debug( + "RECV-INFO-DUMP: dump = \(buffer[offset.. (Int32, Int) { + guard let errorPtr = buffer.bind(as: Int32.self, offset: offset) else { + throw NetlinkDataError.recvUnmarshalFailure + } + + let rc = errorPtr.pointee + log.debug("RECV-ERR-CODE: \(rc)") + + return (rc, offset + MemoryLayout.size) + } + + private func parseErrorResponse(buffer: inout [UInt8], offset: Int) throws -> Int { + var (rc, offset) = try parseErrorCode(buffer: &buffer, offset: offset) + log.debug( + "RECV-ERR-HEADER-DUMP: dump = \(buffer[offset.. (NetlinkMessageHeader, Int) { + log.debug("RECV-HEADER-DUMP: dump = \(buffer[offset.. ( + [RTAttributeData], Int + ) { + var attrDatas: [RTAttributeData] = [] + var offset = offset + var residualCount = residualCount + log.debug("RECV-RESIDUAL: \(residualCount)") + + while residualCount > 0 { + var attr = RTAttribute() + log.debug(" RECV-ATTR-DUMP: dump = \(buffer[offset..= 0 { + log.debug(" RECV-ATTR-DATA-DUMP: dump = \(buffer[offset.. Int + func recv(buf: UnsafeMutableRawPointer!, len: Int, flags: Int32) throws -> Int +} + +public typealias NetlinkSocketProvider = () throws -> any NetlinkSocket + +public enum NetlinkSocketError: Swift.Error, CustomStringConvertible, Equatable { + case socketFailure(rc: Int32) + case bindFailure(rc: Int32) + case sendFailure(rc: Int32) + case recvFailure(rc: Int32) + case notImplemented + + public var description: String { + switch self { + case .socketFailure(let rc): + return "could not create netlink socket, rc = \(rc)" + case .bindFailure(let rc): + return "could not bind netlink socket, rc = \(rc)" + case .sendFailure(let rc): + return "could not send netlink packet, rc = \(rc)" + case .recvFailure(let rc): + return "could not receive netlink packet, rc = \(rc)" + case .notImplemented: + return "socket function not implemented for platform" + } + } +} + +#if canImport(Musl) +import Musl +let osSocket = Musl.socket +let osBind = Musl.bind +let osSend = Musl.send +let osRecv = Musl.recv + +public class DefaultNetlinkSocket: NetlinkSocket { + private let sockfd: Int32 + + public let pid: UInt32 + + public init() throws { + pid = UInt32(getpid()) + sockfd = osSocket(Int32(AddressFamily.AF_NETLINK), SocketType.SOCK_RAW, NetlinkProtocol.NETLINK_ROUTE) + guard sockfd >= 0 else { + throw NetlinkSocketError.socketFailure(rc: errno) + } + + let addr = SockaddrNetlink(family: AddressFamily.AF_NETLINK, pid: pid) + var buffer = [UInt8](repeating: 0, count: SockaddrNetlink.size) + _ = try addr.appendBuffer(&buffer, offset: 0) + guard let ptr = buffer.bind(as: sockaddr.self, size: buffer.count) else { + throw NetlinkSocketError.bindFailure(rc: 0) + } + guard osBind(sockfd, ptr, UInt32(buffer.count)) >= 0 else { + throw NetlinkSocketError.bindFailure(rc: errno) + } + } + + deinit { + close(sockfd) + } + + public func send(buf: UnsafeRawPointer!, len: Int, flags: Int32) throws -> Int { + let count = osSend(sockfd, buf, len, flags) + guard count >= 0 else { + throw NetlinkSocketError.sendFailure(rc: errno) + } + + return count + } + + public func recv(buf: UnsafeMutableRawPointer!, len: Int, flags: Int32) throws -> Int { + let count = osRecv(sockfd, buf, len, flags) + guard count >= 0 else { + throw NetlinkSocketError.recvFailure(rc: errno) + } + + return count + } +} +#else +public class DefaultNetlinkSocket: NetlinkSocket { + public var pid: UInt32 { 0 } + + public init() throws {} + + public func send(buf: UnsafeRawPointer!, len: Int, flags: Int32) throws -> Int { + throw NetlinkSocketError.notImplemented + } + + public func recv(buf: UnsafeMutableRawPointer!, len: Int, flags: Int32) throws -> Int { + throw NetlinkSocketError.notImplemented + } +} +#endif diff --git a/Sources/ContainerizationNetlink/Types.swift b/Sources/ContainerizationNetlink/Types.swift new file mode 100644 index 00000000..a7cbbbd4 --- /dev/null +++ b/Sources/ContainerizationNetlink/Types.swift @@ -0,0 +1,587 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationExtras +import Foundation + +struct SocketType { + static let SOCK_RAW: Int32 = 3 +} + +struct AddressFamily { + static let AF_UNSPEC: UInt16 = 0 + static let AF_INET: UInt16 = 2 + static let AF_INET6: UInt16 = 10 + static let AF_NETLINK: UInt16 = 16 + static let AF_PACKET: UInt16 = 17 +} + +struct NetlinkProtocol { + static let NETLINK_ROUTE: Int32 = 0 +} + +struct NetlinkType { + static let NLMSG_NOOP: UInt16 = 1 + static let NLMSG_ERROR: UInt16 = 2 + static let NLMSG_DONE: UInt16 = 3 + static let NLMSG_OVERRUN: UInt16 = 4 + static let RTM_NEWLINK: UInt16 = 16 + static let RTM_DELLINK: UInt16 = 17 + static let RTM_GETLINK: UInt16 = 18 + static let RTM_NEWADDR: UInt16 = 20 + static let RTM_NEWROUTE: UInt16 = 24 +} + +struct NetlinkFlags { + static let NLM_F_REQUEST: UInt16 = 0x01 + static let NLM_F_MULTI: UInt16 = 0x02 + static let NLM_F_ACK: UInt16 = 0x04 + static let NLM_F_ECHO: UInt16 = 0x08 + static let NLM_F_DUMP_INTR: UInt16 = 0x10 + static let NLM_F_DUMP_FILTERED: UInt16 = 0x20 + + // GET request + static let NLM_F_ROOT: UInt16 = 0x100 + static let NLM_F_MATCH: UInt16 = 0x200 + static let NLM_F_ATOMIC: UInt16 = 0x400 + static let NLM_F_DUMP: UInt16 = NetlinkFlags.NLM_F_ROOT | NetlinkFlags.NLM_F_MATCH + + // NEW request flags + static let NLM_F_REPLACE: UInt16 = 0x100 + static let NLM_F_EXCL: UInt16 = 0x200 + static let NLM_F_CREATE: UInt16 = 0x400 + static let NLM_F_APPEND: UInt16 = 0x800 +} + +struct NetlinkScope { + static let RT_SCOPE_UNIVERSE: UInt8 = 0 +} + +struct InterfaceFlags { + static let IFF_UP: UInt32 = 1 << 0 + static let DEFAULT_CHANGE: UInt32 = 0xffff_ffff +} + +struct LinkAttributeType { + static let IFLA_EXT_IFNAME: UInt16 = 3 + static let IFLA_EXT_MASK: UInt16 = 29 +} + +struct LinkAttributeMaskFilter { + static let RTEXT_FILTER_VF: UInt32 = 1 << 0 + static let RTEXT_FILTER_SKIP_STATS: UInt32 = 1 << 3 +} + +struct AddressAttributeType { + // subnet mask + static let IFA_ADDRESS: UInt16 = 1 + // IPv4 address + static let IFA_LOCAL: UInt16 = 2 +} + +struct RouteTable { + static let MAIN: UInt8 = 254 +} + +struct RouteProtocol { + static let UNSPEC: UInt8 = 0 + static let REDIRECT: UInt8 = 1 + static let KERNEL: UInt8 = 2 + static let BOOT: UInt8 = 3 + static let STATIC: UInt8 = 4 +} + +struct RouteScope { + static let UNIVERSE: UInt8 = 0 + static let LINK: UInt8 = 253 +} + +struct RouteType { + static let UNSPEC: UInt8 = 0 + static let UNICAST: UInt8 = 1 +} + +struct RouteAttributeType { + static let UNSPEC: UInt16 = 0 + static let DST: UInt16 = 1 + static let SRC: UInt16 = 2 + static let IIF: UInt16 = 3 + static let OIF: UInt16 = 4 + static let GATEWAY: UInt16 = 5 + static let PRIORITY: UInt16 = 6 + static let PREFSRC: UInt16 = 7 +} + +protocol Bindable: Equatable { + static var size: Int { get } + func appendBuffer(_ buffer: inout [UInt8], offset: Int) throws -> Int + mutating func bindBuffer(_ buffer: inout [UInt8], offset: Int) throws -> Int +} + +struct SockaddrNetlink: Bindable { + static let size = 12 + + var family: UInt16 + var pad: UInt16 = 0 + var pid: UInt32 + var groups: UInt32 + + init(family: UInt16 = 0, pid: UInt32 = 0, groups: UInt32 = 0) { + self.family = family + self.pid = pid + self.groups = groups + } + + func appendBuffer(_ buffer: inout [UInt8], offset: Int) throws -> Int { + guard let offset = buffer.copyIn(as: UInt16.self, value: family, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt32.self, value: pid, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt32.self, value: groups, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + + return offset + } + + mutating func bindBuffer(_ buffer: inout [UInt8], offset: Int) throws -> Int { + guard let (offset, value) = buffer.copyOut(as: UInt16.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + family = value + + guard let (offset, value) = buffer.copyOut(as: UInt32.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + pid = value + + guard let (offset, value) = buffer.copyOut(as: UInt32.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + groups = value + + return offset + Self.size + } +} + +struct NetlinkMessageHeader: Bindable { + static let size = 16 + + var len: UInt32 + var type: UInt16 + var flags: UInt16 + var seq: UInt32 + var pid: UInt32 + + init(len: UInt32 = 0, type: UInt16 = 0, flags: UInt16 = 0, seq: UInt32? = nil, pid: UInt32 = 0) { + self.len = len + self.type = type + self.flags = flags + self.seq = seq ?? UInt32.random(in: 0.. Int { + guard let offset = buffer.copyIn(as: UInt32.self, value: len, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt16.self, value: type, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt16.self, value: flags, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt32.self, value: seq, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt32.self, value: pid, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + + return offset + } + + mutating func bindBuffer(_ buffer: inout [UInt8], offset: Int) throws -> Int { + guard let (offset, value) = buffer.copyOut(as: UInt32.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + len = value + + guard let (offset, value) = buffer.copyOut(as: UInt16.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + type = value + + guard let (offset, value) = buffer.copyOut(as: UInt16.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + flags = value + + guard let (offset, value) = buffer.copyOut(as: UInt32.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + seq = value + + guard let (offset, value) = buffer.copyOut(as: UInt32.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + pid = value + + return offset + } + + var moreResponses: Bool { + (self.flags & NetlinkFlags.NLM_F_MULTI) != 0 + && (self.type != NetlinkType.NLMSG_DONE && self.type != NetlinkType.NLMSG_ERROR + && self.type != NetlinkType.NLMSG_OVERRUN) + } +} + +struct InterfaceInfo: Bindable { + static let size = 16 + + var family: UInt8 + var _pad: UInt8 = 0 + var type: UInt16 + var index: Int32 + var flags: UInt32 + var change: UInt32 + + init( + family: UInt8 = UInt8(AddressFamily.AF_UNSPEC), type: UInt16 = 0, index: Int32 = 0, flags: UInt32 = 0, + change: UInt32 = 0 + ) { + self.family = family + self.type = type + self.index = index + self.flags = flags + self.change = change + } + + func appendBuffer(_ buffer: inout [UInt8], offset: Int) throws -> Int { + guard let offset = buffer.copyIn(as: UInt8.self, value: family, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt8.self, value: _pad, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt16.self, value: type, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: Int32.self, value: index, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt32.self, value: flags, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt32.self, value: change, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + + return offset + } + + mutating func bindBuffer(_ buffer: inout [UInt8], offset: Int) throws -> Int { + guard let (offset, value) = buffer.copyOut(as: UInt8.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + family = value + + guard let (offset, value) = buffer.copyOut(as: UInt8.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + _pad = value + + guard let (offset, value) = buffer.copyOut(as: UInt16.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + type = value + + guard let (offset, value) = buffer.copyOut(as: Int32.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + index = value + + guard let (offset, value) = buffer.copyOut(as: UInt32.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + flags = value + + guard let (offset, value) = buffer.copyOut(as: UInt32.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + change = value + + return offset + } +} + +struct AddressInfo: Bindable { + static let size = 8 + + var family: UInt8 + var prefixLength: UInt8 + var flags: UInt8 + var scope: UInt8 + var index: UInt32 + + init( + family: UInt8 = UInt8(AddressFamily.AF_UNSPEC), prefixLength: UInt8 = 32, flags: UInt8 = 0, scope: UInt8 = 0, + index: UInt32 = 0 + ) { + self.family = family + self.prefixLength = prefixLength + self.flags = flags + self.scope = scope + self.index = index + } + + func appendBuffer(_ buffer: inout [UInt8], offset: Int) throws -> Int { + guard let offset = buffer.copyIn(as: UInt8.self, value: family, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt8.self, value: prefixLength, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt8.self, value: flags, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt8.self, value: scope, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt32.self, value: index, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + + return offset + } + + mutating func bindBuffer(_ buffer: inout [UInt8], offset: Int) throws -> Int { + guard let (offset, value) = buffer.copyOut(as: UInt8.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + family = value + + guard let (offset, value) = buffer.copyOut(as: UInt8.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + prefixLength = value + + guard let (offset, value) = buffer.copyOut(as: UInt8.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + flags = value + + guard let (offset, value) = buffer.copyOut(as: UInt8.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + scope = value + + guard let (offset, value) = buffer.copyOut(as: UInt32.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + index = value + + return offset + } +} + +struct RouteInfo: Bindable { + static let size = 12 + + var family: UInt8 + var dstLen: UInt8 + var srcLen: UInt8 + var tos: UInt8 + var table: UInt8 + var proto: UInt8 + var scope: UInt8 + var type: UInt8 + var flags: UInt32 + + init( + family: UInt8 = UInt8(AddressFamily.AF_INET), + dstLen: UInt8, + srcLen: UInt8, + tos: UInt8, + table: UInt8, + proto: UInt8, + scope: UInt8, + type: UInt8, + flags: UInt32 + ) { + self.family = family + self.dstLen = dstLen + self.srcLen = srcLen + self.tos = tos + self.table = table + self.proto = proto + self.scope = scope + self.type = type + self.flags = flags + } + + func appendBuffer(_ buffer: inout [UInt8], offset: Int) throws -> Int { + guard let offset = buffer.copyIn(as: UInt8.self, value: family, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt8.self, value: dstLen, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt8.self, value: srcLen, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt8.self, value: tos, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt8.self, value: table, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt8.self, value: proto, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt8.self, value: scope, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt8.self, value: type, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt32.self, value: flags, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + + return offset + } + + mutating func bindBuffer(_ buffer: inout [UInt8], offset: Int) throws -> Int { + guard let (offset, value) = buffer.copyOut(as: UInt8.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + family = value + + guard let (offset, value) = buffer.copyOut(as: UInt8.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + dstLen = value + + guard let (offset, value) = buffer.copyOut(as: UInt8.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + srcLen = value + + guard let (offset, value) = buffer.copyOut(as: UInt8.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + tos = value + + guard let (offset, value) = buffer.copyOut(as: UInt8.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + table = value + + guard let (offset, value) = buffer.copyOut(as: UInt8.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + proto = value + + guard let (offset, value) = buffer.copyOut(as: UInt8.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + scope = value + + guard let (offset, value) = buffer.copyOut(as: UInt8.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + type = value + + guard let (offset, value) = buffer.copyOut(as: UInt32.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + flags = value + + return offset + } +} + +public struct RTAttribute: Bindable { + static let size = 4 + + public var len: UInt16 + public var type: UInt16 + public var paddedLen: Int { Int(((len + 3) >> 2) << 2) } + + init(len: UInt16 = 0, type: UInt16 = 0) { + self.len = len + self.type = type + } + + func appendBuffer(_ buffer: inout [UInt8], offset: Int) throws -> Int { + guard let offset = buffer.copyIn(as: UInt16.self, value: len, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + guard let offset = buffer.copyIn(as: UInt16.self, value: type, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + + return offset + } + + mutating func bindBuffer(_ buffer: inout [UInt8], offset: Int) throws -> Int { + guard let (offset, value) = buffer.copyOut(as: UInt16.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + len = value + + guard let (offset, value) = buffer.copyOut(as: UInt16.self, offset: offset) else { + throw NetlinkDataError.sendMarshalFailure + } + type = value + + return offset + } +} + +public struct RTAttributeData { + public let attribute: RTAttribute + public let data: [UInt8] +} + +public struct LinkResponse { + public let interfaceIndex: Int32 + public let attrDatas: [RTAttributeData] +} + +public enum NetlinkDataError: Swift.Error, CustomStringConvertible, Equatable { + case sendMarshalFailure + case recvUnmarshalFailure + case responseError(rc: Int32) + case unsupportedPlatform + + public var description: String { + switch self { + case .sendMarshalFailure: + return "could not marshal netlink packet" + case .recvUnmarshalFailure: + return "could not unmarshal netlink packet" + case .responseError(let rc): + return "netlink response indicates error, rc = \(rc)" + case .unsupportedPlatform: + return "unsupported platform" + } + } +} diff --git a/Sources/ContainerizationOCI/AnnotationKeys.swift b/Sources/ContainerizationOCI/AnnotationKeys.swift new file mode 100644 index 00000000..5c6aac6f --- /dev/null +++ b/Sources/ContainerizationOCI/AnnotationKeys.swift @@ -0,0 +1,23 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +/// AnnotationKeys contains a subset of "dictionary keys" for commonly used annotaions in a OCI Image Descriptor +/// https://github.com/opencontainers/image-spec/blob/main/annotations.md +public struct AnnotationKeys: Codable, Sendable { + public static let containerizationImageName = "com.apple.containerization.image.name" + public static let containerdImageName = "io.containerd.image.name" + public static let openContainersImageName = "org.opencontainers.image.ref.name" +} diff --git a/Sources/ContainerizationOCI/Bundle.swift b/Sources/ContainerizationOCI/Bundle.swift new file mode 100644 index 00000000..3fa20ac5 --- /dev/null +++ b/Sources/ContainerizationOCI/Bundle.swift @@ -0,0 +1,105 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationError +import Foundation + +#if canImport(Musl) +import Musl +private let _mount = Musl.mount +private let _umount = Musl.umount2 +#elseif canImport(Glibc) +import Glibc +private let _mount = Glibc.mount +private let _umount = Glibc.umount2 +#endif + +public struct Bundle: Sendable { + public let path: URL + + public var configPath: URL { + self.path.appending(path: "config.json") + } + + public var rootfsPath: URL { + self.path.appending(path: "rootfs") + } + + public static func create(path: URL, spec: Data) throws -> Bundle { + try self.init(path: path, spec: spec) + } + + public static func create(path: URL, spec: ContainerizationOCI.Spec) throws -> Bundle { + try self.init(path: path, spec: spec) + } + + public static func load(path: URL) throws -> Bundle { + try self.init(path: path) + } + + private init(path: URL) throws { + let fm = FileManager.default + if !fm.fileExists(atPath: path.path) { + throw ContainerizationError(.invalidArgument, message: "no bundle at \(path.path)") + } + self.path = path + } + + // This constructor does not do any validation that data is actually a + // valid OCI spec. + private init(path: URL, spec: Data) throws { + self.path = path + + let fm = FileManager.default + try fm.createDirectory( + atPath: self.path.appending(component: "rootfs").path, + withIntermediateDirectories: true + ) + + try spec.write(to: self.configPath) + } + + private init(path: URL, spec: ContainerizationOCI.Spec) throws { + self.path = path + + let fm = FileManager.default + try fm.createDirectory( + atPath: self.path.appending(component: "rootfs").path, + withIntermediateDirectories: true + ) + + let specData = try JSONEncoder().encode(spec) + try specData.write(to: self.configPath) + } + + public func delete() throws { + // Unmount, and then blow away the dir. + #if os(Linux) + let rootfs = self.rootfsPath.path + guard _umount(rootfs, 0) == 0 else { + throw POSIXError.fromErrno() + } + #endif + // removeItem is recursive so should blow away the rootfs dir inside as well. + let fm = FileManager.default + try fm.removeItem(at: self.path) + } + + public func loadConfig() throws -> ContainerizationOCI.Spec { + let data = try Data(contentsOf: self.configPath) + return try JSONDecoder().decode(ContainerizationOCI.Spec.self, from: data) + } +} diff --git a/Sources/ContainerizationOCI/Client/Authentication.swift b/Sources/ContainerizationOCI/Client/Authentication.swift new file mode 100644 index 00000000..04ef9535 --- /dev/null +++ b/Sources/ContainerizationOCI/Client/Authentication.swift @@ -0,0 +1,46 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +public protocol Authentication: Sendable { + func token() async throws -> String +} + +/// Type representing authentication information for client to access the registry. +public struct BasicAuthentication: Authentication { + /// The username for the authentication. + let username: String + /// The password or identity token for the user. + let password: String + + public init(username: String, password: String) { + self.username = username + self.password = password + } + + public func token() async throws -> String { + let credentials = "\(username):\(password)" + if let authenticationData = credentials.data(using: .utf8)?.base64EncodedString() { + return "Basic \(authenticationData)" + } + throw Error.invalidCredentials + } + + public enum Error: Swift.Error { + case invalidCredentials + } +} diff --git a/Sources/ContainerizationOCI/Client/KeychainWrapper.swift b/Sources/ContainerizationOCI/Client/KeychainWrapper.swift new file mode 100644 index 00000000..096a8957 --- /dev/null +++ b/Sources/ContainerizationOCI/Client/KeychainWrapper.swift @@ -0,0 +1,86 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +#if os(macOS) +import Foundation +import ContainerizationOS + +public struct KeychainHelper: Sendable { + private let id: String + public init(id: String) { + self.id = id + } + + public func lookup(domain: String) throws -> Authentication { + let kq = KeychainQuery() + + guard try kq.exists(id: self.id, host: domain) else { + throw Self.Error.keyNotFound + } + guard let fetched = try kq.get(id: self.id, host: domain) else { + throw Self.Error.keyNotFound + } + + return BasicAuthentication( + username: fetched.account, + password: fetched.data + ) + } + + public func delete(domain: String) throws { + let kq = KeychainQuery() + try kq.delete(id: self.id, host: domain) + } + + public func save(domain: String, username: String, password: String) throws { + let kq = KeychainQuery() + try kq.save(id: self.id, host: domain, user: username, token: password) + } + + public func credentialPrompt(domain: String) throws -> Authentication { + let username = try userPrompt(domain: domain) + let password = try passwordPrompt() + return BasicAuthentication(username: username, password: password) + } + + public func userPrompt(domain: String) throws -> String { + print("Provide registry username \(domain): ", terminator: "") + guard let username = readLine() else { + throw Self.Error.invalidInput + } + return username + } + + public func passwordPrompt() throws -> String { + print("Provide registry password: ", terminator: "") + let console = try Terminal.current + defer { console.tryReset() } + try console.disableEcho() + + guard let password = readLine() else { + throw Self.Error.invalidInput + } + return password + } +} + +extension KeychainHelper { + public enum Error: Swift.Error { + case keyNotFound + case invalidInput + } +} +#endif diff --git a/Sources/ContainerizationOCI/Client/LocalOCILayoutClient.swift b/Sources/ContainerizationOCI/Client/LocalOCILayoutClient.swift new file mode 100644 index 00000000..6548e841 --- /dev/null +++ b/Sources/ContainerizationOCI/Client/LocalOCILayoutClient.swift @@ -0,0 +1,194 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationError +import ContainerizationExtras +import Crypto +import Foundation +import NIOCore + +package final class LocalOCILayoutClient: ContentClient { + let cs: LocalContentStore + + package init(root: URL) throws { + self.cs = try LocalContentStore(path: root) + } + + private func _fetch(digest: String) async throws -> Content { + guard let c: Content = try await self.cs.get(digest: digest) else { + throw Error.missingContent(digest) + } + return c + } + + package func fetch(name: String, descriptor: Descriptor) async throws -> T { + let c = try await self._fetch(digest: descriptor.digest) + return try c.decode() + } + + package func fetchBlob(name: String, descriptor: Descriptor, into file: URL, progress: ProgressHandler?) async throws -> (Int64, SHA256Digest) { + let c = try await self._fetch(digest: descriptor.digest) + let fileManager = FileManager.default + let filePath = file.absolutePath() + if !fileManager.fileExists(atPath: filePath) { + let src = c.path + try fileManager.copyItem(at: src, to: file) + + if let progress, let fileSize = fileManager.fileSize(atPath: filePath) { + await progress([ + ProgressEvent(event: "add-size", value: fileSize) + ]) + } + } + let size = try Int64(c.size()) + let digest = try c.digest() + return (size, digest) + } + + package func fetchData(name: String, descriptor: Descriptor) async throws -> Data { + let c = try await self._fetch(digest: descriptor.digest) + return try c.data() + } + + package func push( + name: String, + ref: String, + descriptor: Descriptor, + streamGenerator: () throws -> T, + progress: ProgressHandler? + ) async throws where T.Element == ByteBuffer { + let input = try streamGenerator() + + try await self.cs.ingest { dir in + let into = dir.appendingPathComponent(descriptor.digest.trimmingDigestPrefix) + guard FileManager.default.createFile(atPath: into.path, contents: nil) else { + throw Error.cannotCreateFile + } + let fd = try FileHandle(forWritingTo: into) + defer { + try? fd.close() + } + var wrote = 0 + var hasher = SHA256() + + for try await buffer in input { + wrote += buffer.readableBytes + try buffer.withUnsafeReadableBytes { pointer in + let unsafeBufferPointer = pointer.bindMemory(to: [UInt8].self) + if let addr = unsafeBufferPointer.baseAddress { + let d = Data(bytes: addr, count: buffer.readableBytes) + try fd.write(contentsOf: d) + hasher.update(data: d) + } + } + } + } + } +} + +extension LocalOCILayoutClient { + private static let ociLayoutFileName = "oci-layout" + private static let ociLayoutVersionString = "imageLayoutVersion" + private static let ociLayoutIndexFileName = "index.json" + + package func loadIndexFromOCILayout(directory: URL) throws -> ContainerizationOCI.Index { + let fm = FileManager.default + let decoder = JSONDecoder() + + let ociLayoutFile = directory.appendingPathComponent(Self.ociLayoutFileName) + guard fm.fileExists(atPath: ociLayoutFile.absolutePath()) else { + throw ContainerizationError(.notFound, message: ociLayoutFile.absolutePath()) + } + var data = try Data(contentsOf: ociLayoutFile) + let ociLayout = try decoder.decode([String: String].self, from: data) + guard ociLayout[Self.ociLayoutVersionString] != nil else { + throw ContainerizationError(.empty, message: "missing key \(Self.ociLayoutVersionString) in \(ociLayoutFile.absolutePath())") + } + + let indexFile = directory.appendingPathComponent(Self.ociLayoutIndexFileName) + guard fm.fileExists(atPath: indexFile.absolutePath()) else { + throw ContainerizationError(.notFound, message: indexFile.absolutePath()) + } + data = try Data(contentsOf: indexFile) + let index = try decoder.decode(ContainerizationOCI.Index.self, from: data) + return index + } + + package func createOCILayoutStructre(directory: URL, manifests: [Descriptor]) throws { + let fm = FileManager.default + let encoder = JSONEncoder() + encoder.outputFormatting = [.withoutEscapingSlashes] + + let ingestDir = directory.appendingPathComponent("ingest") + try? fm.removeItem(at: ingestDir) + let ociLayoutContent: [String: String] = [ + Self.ociLayoutVersionString: "1.0.0" + ] + + var data = try encoder.encode(ociLayoutContent) + var p = directory.appendingPathComponent(Self.ociLayoutFileName).absolutePath() + guard fm.createFile(atPath: p, contents: data) else { + throw ContainerizationError(.internalError, message: "failed to create file \(p)") + } + let idx = ContainerizationOCI.Index(schemaVersion: 2, manifests: manifests) + data = try encoder.encode(idx) + p = directory.appendingPathComponent(Self.ociLayoutIndexFileName).absolutePath() + guard fm.createFile(atPath: p, contents: data) else { + throw ContainerizationError(.internalError, message: "failed to create file \(p)") + } + } + + package func setImageReferenceAnnotation(descriptor: inout Descriptor, reference: String) { + var annotations = descriptor.annotations ?? [:] + annotations[AnnotationKeys.containerizationImageName] = reference + annotations[AnnotationKeys.containerdImageName] = reference + annotations[AnnotationKeys.openContainersImageName] = reference + descriptor.annotations = annotations + } + + package func getImageReferencefromDescriptor(descriptor: Descriptor) -> String? { + let annotations = descriptor.annotations + guard let annotations else { + return nil + } + + // Annotations here do not conform to the OCI image specification. + // The interpretation of the annotations "org.opencontainers.image.ref.name" and + // "io.containerd.image.name" is under debate: + // - OCI spec examples suggest it should be the image tag: + // https://github.com/opencontainers/image-spec/blob/fbb4662eb53b80bd38f7597406cf1211317768f0/image-layout.md?plain=1#L175 + // - Buildkitd maintainers argue it should represent the full image name: + // https://github.com/moby/buildkit/issues/4615#issuecomment-2521810830 + // Until a consensus is reached, the preference is given to "com.apple.containerization.image.name" and then to + // using "io.containerd.image.name" as it is the next safest choice + if let name = annotations[AnnotationKeys.containerizationImageName] { + return name + } + if let name = annotations[AnnotationKeys.containerdImageName] { + return name + } + if let name = annotations[AnnotationKeys.openContainersImageName] { + return name + } + return nil + } + + package enum Error: Swift.Error { + case missingContent(_ digest: String) + case unsupportedInput + case cannotCreateFile + } +} diff --git a/Sources/ContainerizationOCI/Client/RegistryClient+Error.swift b/Sources/ContainerizationOCI/Client/RegistryClient+Error.swift new file mode 100644 index 00000000..c57818c3 --- /dev/null +++ b/Sources/ContainerizationOCI/Client/RegistryClient+Error.swift @@ -0,0 +1,30 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import NIOHTTP1 + +extension RegistryClient { + public enum Error: Swift.Error, CustomStringConvertible { + case invalidStatus(url: String, HTTPResponseStatus) + + public var description: String { + switch self { + case .invalidStatus(let u, let response): + return "HTTP request to \(u) failed with response: \(response.description)" + } + } + } +} diff --git a/Sources/ContainerizationOCI/Client/RegistryClient+Fetch.swift b/Sources/ContainerizationOCI/Client/RegistryClient+Fetch.swift new file mode 100644 index 00000000..8515adaa --- /dev/null +++ b/Sources/ContainerizationOCI/Client/RegistryClient+Fetch.swift @@ -0,0 +1,235 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import AsyncHTTPClient +import ContainerizationError +import ContainerizationExtras +import Crypto +import Foundation + +#if os(macOS) +import NIOFileSystem +#endif + +extension RegistryClient { + /// Resolve sends a HEAD request to the registry to find root manifest descriptor. + /// This descriptor serves as an entry point to retrieve resources from the registry. + public func resolve(name: String, tag: String) async throws -> Descriptor { + var components = base + + // Make HEAD request to retrieve the digest header + components.path = "/v2/\(name)/manifests/\(tag)" + + // The client should include an Accept header indicating which manifest content types it supports. + let mediaTypes = [ + MediaTypes.dockerManifest, + MediaTypes.dockerManifestList, + MediaTypes.imageManifest, + MediaTypes.index, + "*/*", + ] + + let headers = [ + ("Accept", mediaTypes.joined(separator: ", ")) + ] + + return try await request(components: components, method: .HEAD, headers: headers) { response in + guard response.status == .ok else { + let url = components.url?.absoluteString ?? "unknown" + throw Error.invalidStatus(url: url, response.status) + } + + guard let digest = response.headers.first(name: "Docker-Content-Digest") else { + throw ContainerizationError(.invalidArgument, message: "Missing required header Docker-Content-Digest") + } + + guard let type = response.headers.first(name: "Content-Type") else { + throw ContainerizationError(.invalidArgument, message: "Missing required header Content-Type") + } + + guard let sizeStr = response.headers.first(name: "Content-Length") else { + throw ContainerizationError(.invalidArgument, message: "Missing required header Content-Length") + } + + guard let size = Int64(sizeStr) else { + throw ContainerizationError(.invalidArgument, message: "Cannot convert \(sizeStr) to Int64") + } + + return Descriptor(mediaType: type, digest: digest, size: size) + } + } + + /// Fetch resource (either manifest or blob) to memory with JSON decoding. + public func fetch(name: String, descriptor: Descriptor) async throws -> T { + var components = base + + let manifestTypes = [ + MediaTypes.dockerManifest, + MediaTypes.dockerManifestList, + MediaTypes.imageManifest, + MediaTypes.index, + ] + + let isManifest = manifestTypes.contains(where: { $0 == descriptor.mediaType }) + let resource = isManifest ? "manifests" : "blobs" + + components.path = "/v2/\(name)/\(resource)/\(descriptor.digest)" + + let mediaType = descriptor.mediaType + if mediaType.isEmpty { + throw ContainerizationError(.invalidArgument, message: "Missing media type for descriptor \(descriptor.digest)") + } + + let headers = [ + ("Accept", mediaType) + ] + + return try await requestJSON(components: components, headers: headers) + } + + /// Fetch resource (either manifest or blob) to memory as raw `Data`. + public func fetchData(name: String, descriptor: Descriptor) async throws -> Data { + var components = base + + let manifestTypes = [ + MediaTypes.dockerManifest, + MediaTypes.dockerManifestList, + MediaTypes.imageManifest, + MediaTypes.index, + ] + + let isManifest = manifestTypes.contains(where: { $0 == descriptor.mediaType }) + let resource = isManifest ? "manifests" : "blobs" + + components.path = "/v2/\(name)/\(resource)/\(descriptor.digest)" + + let mediaType = descriptor.mediaType + if mediaType.isEmpty { + throw ContainerizationError(.invalidArgument, message: "Missing media type for descriptor \(descriptor.digest)") + } + + let headers = [ + ("Accept", mediaType) + ] + + return try await requestData(components: components, headers: headers) + } + + /// Fetch a blob from remote registry. + /// This method is suitable for streaming data. + public func fetchBlob( + name: String, + descriptor: Descriptor, + closure: (Int64, HTTPClientResponse.Body) async throws -> Void + ) async throws { + var components = base + components.path = "/v2/\(name)/blobs/\(descriptor.digest)" + + let mediaType = descriptor.mediaType + if mediaType.isEmpty { + throw ContainerizationError(.invalidArgument, message: "Missing media type for descriptor \(descriptor.digest)") + } + + let headers = [ + ("Accept", mediaType) + ] + + try await request(components: components, headers: headers) { response in + guard response.status == .ok else { + let url = components.url?.absoluteString ?? "unknown" + throw Error.invalidStatus(url: url, response.status) + } + + // How many bytes to expect + guard let expectedBytes = response.headers.first(name: "Content-Length").flatMap(Int64.init) else { + throw ContainerizationError(.invalidArgument, message: "Missing required header Content-Length") + } + + try await closure(expectedBytes, response.body) + } + } + + #if os(macOS) + /// Fetch a blob from remote registry and write the contents into a file in the provided directory. + public func fetchBlob(name: String, descriptor: Descriptor, into file: URL, progress: ProgressHandler?) async throws -> (Int64, SHA256Digest) { + var hasher = SHA256() + var received: Int64 = 0 + let fs = NIOFileSystem.FileSystem.shared + let handle = try await fs.openFile(forWritingAt: FilePath(file.absolutePath()), options: .newFile(replaceExisting: true)) + var writer = handle.bufferedWriter() + do { + try await self.fetchBlob(name: name, descriptor: descriptor) { (size, body) in + var itr = body.makeAsyncIterator() + while var buf = try await itr.next() { + let readBytes = Int64(buf.readableBytes) + received += readBytes + await progress?([ + ProgressEvent(event: "add-size", value: readBytes) + ]) + let written = try await writer.write(contentsOf: buf) + guard written == readBytes else { + throw ContainerizationError(.internalError, message: "Could not write \(readBytes) bytes to file \(file)") + } + guard let d = buf.readData(length: buf.readableBytes) else { + throw ContainerizationError(.internalError, message: "Failed to convert byte buffer to data to compute checksum") + } + hasher.update(data: d) + } + } + try await writer.flush() + try await handle.close() + } catch { + try? await handle.close() + throw error + } + let computedDigest = hasher.finalize() + return (received, computedDigest) + } + #else + /// Fetch a blob from remote registry and write the contents into a file in the provided directory. + public func fetchBlob(name: String, descriptor: Descriptor, into file: URL, progress: ProgressHandler?) async throws -> (Int64, SHA256Digest) { + var hasher = SHA256() + var received: Int64 = 0 + guard FileManager.default.createFile(atPath: file.path, contents: nil) else { + throw ContainerizationError(.internalError, message: "Cannot create file at path \(file.path)") + } + try await self.fetchBlob(name: name, descriptor: descriptor) { (size, body) in + let fd = try FileHandle(forWritingTo: file) + defer { + try? fd.close() + } + var itr = body.makeAsyncIterator() + while let buf = try await itr.next() { + let readBytes = Int64(buf.readableBytes) + received += readBytes + await progress?([ + ProgressEvent(event: "add-size", value: readBytes) + ]) + try buf.withUnsafeReadableBytes { pointer in + let unsafeBufferPointer = pointer.bindMemory(to: [UInt8].self) + if let addr = unsafeBufferPointer.baseAddress { + let d = Data(bytes: addr, count: buf.readableBytes) + try fd.write(contentsOf: d) + hasher.update(data: d) + } + } + } + } + let computedDigest = hasher.finalize() + return (received, computedDigest) + } + #endif +} diff --git a/Sources/ContainerizationOCI/Client/RegistryClient+Push.swift b/Sources/ContainerizationOCI/Client/RegistryClient+Push.swift new file mode 100644 index 00000000..4dc72bec --- /dev/null +++ b/Sources/ContainerizationOCI/Client/RegistryClient+Push.swift @@ -0,0 +1,179 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import AsyncHTTPClient +import ContainerizationError +import ContainerizationExtras +import Foundation +import NIO + +extension RegistryClient { + /// Pushes the content specified by a descriptor to a remote registry. + /// + /// - Parameters: + /// - name: The namespace which the descriptor should belong under. + /// - ref: The tag or digest for uniquely identifying the manifest. + /// By convention, any portion that may be a partial or whole digest + /// will be proceeded by an `@`. Anything preceding the `@` will be referred + /// to as "tag". + /// This is usually broken down into the following possibilities: + /// 1. + /// 2. @ + /// 3. @ + /// The tag is anything except `@` and `:`, and digest is anything after the `@` + /// - descriptor: The OCI descriptor of the content to be pushed. + /// - streamGenerator: A closure that produces an`AsyncStream` of `ByteBuffer` + /// for streaming data to the `HTTPClientRequest.Body`. + /// The caller is responsible for providing the `AsyncStream` where the data may come from + /// a file on disk, data in memory, etc. + /// - progress: The progress handler to invoke as data is sent. + public func push( + name: String, + ref tag: String, + descriptor: Descriptor, + streamGenerator: () throws -> T, + progress: ProgressHandler? + ) async throws where T.Element == ByteBuffer { + var components = base + + let mediaType = descriptor.mediaType + if mediaType.isEmpty { + throw ContainerizationError(.invalidArgument, message: "Missing media type for descriptor \(descriptor.digest)") + } + + var isManifest = false + var existCheck: [String] = [] + + switch mediaType { + case MediaTypes.dockerManifest, MediaTypes.dockerManifestList, MediaTypes.imageManifest, MediaTypes.index: + isManifest = true + existCheck = self.getManifestPath(tag: tag, digest: descriptor.digest) + default: + existCheck = ["blobs", descriptor.digest] + } + + // Check if the content already exists. + components.path = "/v2/\(name)/\(existCheck.joined(separator: "/"))" + + let mediaTypes = [ + mediaType, + "*/*", + ] + + var headers = [ + ("Accept", mediaTypes.joined(separator: ", ")) + ] + + try await request(components: components, method: .HEAD, headers: headers) { response in + if response.status == .ok { + var exists = false + if isManifest && existCheck[1] != descriptor.digest { + if descriptor.digest == response.headers.first(name: "Docker-Content-Digest") { + exists = true + } + } else { + exists = true + } + + if exists { + throw ContainerizationError(.exists, message: "Content already exists \(descriptor.digest)") + } + } else if response.status != .notFound { + let url = components.url?.absoluteString ?? "unknown" + throw Error.invalidStatus(url: url, response.status) + } + } + + if isManifest { + let path = self.getManifestPath(tag: tag, digest: descriptor.digest) + components.path = "/v2/\(name)/\(path.joined(separator: "/"))" + headers = [ + ("Content-Type", mediaType) + ] + } else { + // Start upload request for blobs. + components.path = "/v2/\(name)/blobs/uploads/" + try await request(components: components, method: .POST) { response in + switch response.status { + case .ok, .accepted, .noContent: + break + case .created: + throw ContainerizationError(.exists, message: "Content already exists \(descriptor.digest)") + default: + let url = components.url?.absoluteString ?? "unknown" + throw Error.invalidStatus(url: url, response.status) + } + + // Get the location to upload the blob. + guard let location = response.headers.first(name: "Location") else { + throw ContainerizationError(.invalidArgument, message: "Missing required header Location") + } + + guard let urlComponents = URLComponents(string: location) else { + throw ContainerizationError(.invalidArgument, message: "Invalid url \(location)") + } + var queryItems = urlComponents.queryItems ?? [] + queryItems.append(URLQueryItem(name: "digest", value: descriptor.digest)) + components.path = urlComponents.path + components.queryItems = queryItems + headers = [ + ("Content-Type", "application/octet-stream"), + ("Content-Length", String(descriptor.size)), + ] + } + } + + // We have to pass a body closure rather than a body to reset the stream when retrying. + let bodyClosure = { + let stream = try streamGenerator() + let body = HTTPClientRequest.Body.stream(stream, length: .known(descriptor.size)) + return body + } + + return try await request(components: components, method: .PUT, bodyClosure: bodyClosure, headers: headers) { response in + switch response.status { + case .ok, .created, .noContent: + break + default: + let url = components.url?.absoluteString ?? "unknown" + throw Error.invalidStatus(url: url, response.status) + } + + guard descriptor.digest == response.headers.first(name: "Docker-Content-Digest") else { + let required = response.headers.first(name: "Docker-Content-Digest") ?? "" + throw ContainerizationError(.internalError, message: "Digest mismatch \(descriptor.digest) != \(required)") + } + } + } + + private func getManifestPath(tag: String, digest: String) -> [String] { + var object = tag + if let i = tag.firstIndex(of: "@") { + let index = tag.index(after: i) + if String(tag[index...]) != digest { + object = "" + } else { + object = String(tag[...i]) + } + } + + if object == "" { + return ["manifests", digest] + } + + return ["manifests", object] + } +} diff --git a/Sources/ContainerizationOCI/Client/RegistryClient+Token.swift b/Sources/ContainerizationOCI/Client/RegistryClient+Token.swift new file mode 100644 index 00000000..36f0448e --- /dev/null +++ b/Sources/ContainerizationOCI/Client/RegistryClient+Token.swift @@ -0,0 +1,210 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import AsyncHTTPClient +import ContainerizationError +import Foundation + +struct TokenRequest { + public static let authenticateHeaderName = "WWW-Authenticate" + + /// The credentials that will be used in the authentication header when fetching the token. + let authentication: Authentication? + /// The realm against which the token should be requested. + let realm: String + /// The name of the service which hosts the resource. + let service: String + /// Whether to return a refresh token along with the bearer token. + let offlineToken: Bool + /// String identifying the client. + let clientId: String + /// The resource in question, formatted as one of the space-delimited entries from the scope parameters from the WWW-Authenticate header shown above. + let scope: String? + + init( + realm: String, + service: String, + clientId: String, + scope: String?, + offlineToken: Bool = false, + authentication: Authentication? = nil + ) { + self.realm = realm + self.service = service + self.offlineToken = offlineToken + self.clientId = clientId + self.scope = scope + self.authentication = authentication + } +} + +struct TokenResponse: Codable, Hashable { + /// An opaque Bearer token that clients should supply to subsequent requests in the Authorization header. + let token: String? + /// For compatibility with OAuth 2.0, we will also accept token under the name access_token. + /// At least one of these fields must be specified, but both may also appear (for compatibility with older clients). + /// When both are specified, they should be equivalent; if they differ the client's choice is undefined. + let accessToken: String? + /// The duration in seconds since the token was issued that it will remain valid. + /// When omitted, this defaults to 60 seconds. + let expiresIn: UInt? + /// The RFC3339-serialized UTC standard time at which a given token was issued. + /// If issued_at is omitted, the expiration is from when the token exchange completed. + let issuedAt: String? + /// Token which can be used to get additional access tokens for the same subject with different scopes. + /// This token should be kept secure by the client and only sent to the authorization server which issues bearer tokens. + /// This field will only be set when `offline_token=true` is provided in the request. + let refreshToken: String? + + var scope: String? + + private enum CodingKeys: String, CodingKey { + case token = "token" + case accessToken = "access_token" + case expiresIn = "expires_in" + case issuedAt = "issued_at" + case refreshToken = "refresh_token" + } + + func getToken() -> String? { + if let t = token ?? accessToken { + return "Bearer \(t)" + } + return nil + } + + func isValid(scope: String?) -> Bool { + guard let issuedAt else { + return false + } + let isoFormatter = ISO8601DateFormatter() + isoFormatter.formatOptions = [.withInternetDateTime, .withFractionalSeconds] + guard let issued = isoFormatter.date(from: issuedAt) else { + return false + } + let expiresIn = expiresIn ?? 0 + let now = Date() + let elapsed = now.timeIntervalSince(issued) + guard elapsed < Double(expiresIn) else { + return false + } + if let requiredScope = scope { + return requiredScope == self.scope + } + return false + } +} + +struct AuthenticateChallenge { + let type: String + let realm: String? + let service: String? + let scope: String? + let error: String? + + init(type: String, realm: String?, service: String?, scope: String?, error: String?) { + self.type = type + self.realm = realm + self.service = service + self.scope = scope + self.error = error + } + + init(type: String, values: [String: String]) { + self.type = type + self.realm = values["realm"] + self.service = values["service"] + self.scope = values["scope"] + self.error = values["error"] + } +} + +extension RegistryClient { + /// Fetch an auto token for all subsequent HTTP requests + /// See https://docs.docker.com/registry/spec/auth/token/ + internal func fetchToken(request: TokenRequest) async throws -> TokenResponse { + guard var components = URLComponents(string: request.realm) else { + throw ContainerizationError(.invalidArgument, message: "Cannot create URL from \(request.realm)") + } + components.queryItems = [ + URLQueryItem(name: "client_id", value: request.clientId), + URLQueryItem(name: "service", value: request.service), + ] + var scope = "" + if let reqScope = request.scope { + scope = reqScope + components.queryItems?.append(URLQueryItem(name: "scope", value: reqScope)) + } + + if request.offlineToken { + components.queryItems?.append(URLQueryItem(name: "offline_token", value: "true")) + } + var response: TokenResponse = try await requestJSON(components: components, headers: []) + response.scope = scope + return response + } + + internal func createTokenRequest(parsing authenticateHeaders: [String]) throws -> TokenRequest { + let parsedHeaders = parseWWWAuthenticateHeaders(headers: authenticateHeaders) + let bearerChallenge = parsedHeaders.first { $0.type == "Bearer" } + guard let bearerChallenge else { + throw ContainerizationError(.invalidArgument, message: "Missing Bearer challenge in \(TokenRequest.authenticateHeaderName) header") + } + guard let realm = bearerChallenge.realm else { + throw ContainerizationError(.invalidArgument, message: "Cannot parse realm from \(TokenRequest.authenticateHeaderName) header") + } + guard let service = bearerChallenge.service else { + throw ContainerizationError(.invalidArgument, message: "Cannot parse service from \(TokenRequest.authenticateHeaderName) header") + } + let scope = bearerChallenge.scope + let tokenRequest = TokenRequest(realm: realm, service: service, clientId: self.clientID, scope: scope, authentication: self.authentication) + return tokenRequest + } + + internal func parseWWWAuthenticateHeaders(headers: [String]) -> [AuthenticateChallenge] { + var parsed: [String: [String: String]] = [:] + for challenge in headers { + let trimmedChallenge = challenge.trimmingCharacters(in: .whitespacesAndNewlines) + let parts = trimmedChallenge.split(separator: " ", maxSplits: 2) + guard parts.count == 2 else { + continue + } + guard let scheme = parts.first else { + continue + } + var params: [String: String] = [:] + let header = String(parts[1]) + let pattern = #"(\w+)="([^"]+)"# + let regex = try! NSRegularExpression(pattern: pattern, options: []) + let matches = regex.matches(in: header, options: [], range: NSRange(header.startIndex..., in: header)) + for match in matches { + if let keyRange = Range(match.range(at: 1), in: header), + let valueRange = Range(match.range(at: 2), in: header) + { + let key = String(header[keyRange]) + let value = String(header[valueRange]) + params[key] = value + } + } + parsed[String(scheme)] = params + } + var parsedChallenges: [AuthenticateChallenge] = [] + for (type, values) in parsed { + parsedChallenges.append(.init(type: type, values: values)) + } + return parsedChallenges + } +} diff --git a/Sources/ContainerizationOCI/Client/RegistryClient.swift b/Sources/ContainerizationOCI/Client/RegistryClient.swift new file mode 100644 index 00000000..e460a12c --- /dev/null +++ b/Sources/ContainerizationOCI/Client/RegistryClient.swift @@ -0,0 +1,264 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import AsyncHTTPClient +import ContainerizationError +import ContainerizationOS +import Foundation +import Logging +import NIO +import NIOHTTP1 + +#if os(macOS) +import Network +#endif + +public struct RetryOptions: Sendable { + let maxRetries: Int + let retryInterval: UInt64 + let shouldRetry: (@Sendable (HTTPClientResponse) -> Bool)? + + public init(maxRetries: Int, retryInterval: UInt64, shouldRetry: (@Sendable (HTTPClientResponse) -> Bool)? = nil) { + self.maxRetries = maxRetries + self.retryInterval = retryInterval + self.shouldRetry = shouldRetry + } +} + +public final class RegistryClient: ContentClient { + private static let defaultRetryOptions = RetryOptions( + maxRetries: 3, + retryInterval: 1_000_000_000, + shouldRetry: ({ response in + response.status.code >= 500 + }) + ) + + let client: HTTPClient + let base: URLComponents + let clientID: String + let authentication: Authentication? + let retryOptions: RetryOptions? + let bufferSize: Int + + public convenience init( + reference: String, + insecure: Bool = false, + auth: Authentication? = nil, + logger: Logger? = nil + ) throws { + let ref = try Reference.parse(reference) + guard let domain = ref.resolvedDomain else { + throw ContainerizationError(.invalidArgument, message: "Invalid domain for image reference \(reference)") + } + let scheme = insecure ? "http" : "https" + let _url = "\(scheme)://\(domain)" + guard let url = URL(string: _url) else { + throw ContainerizationError(.invalidArgument, message: "Cannot convert \(_url) to URL") + } + guard let host = url.host else { + throw ContainerizationError(.invalidArgument, message: "Invalid host \(domain)") + } + let port = url.port + self.init( + host: host, + scheme: scheme, + port: port, + authentication: auth, + retryOptions: Self.defaultRetryOptions + ) + } + + public init( + host: String, + scheme: String? = "https", + port: Int? = nil, + authentication: Authentication? = nil, + clientID: String? = nil, + retryOptions: RetryOptions? = nil, + bufferSize: Int = Int(4.mib()), + logger: Logger? = nil + ) { + var components = URLComponents() + components.scheme = scheme + components.host = host + components.port = port + + self.base = components + self.clientID = clientID ?? "containerization-registry-client" + self.authentication = authentication + self.retryOptions = retryOptions + self.bufferSize = bufferSize + var httpConfiguration = HTTPClient.Configuration() + let proxyConfig: HTTPClient.Configuration.Proxy? = { + let proxyEnv = ProcessInfo.processInfo.environment["HTTP_PROXY"] + guard let proxyEnv else { + return nil + } + guard let url = URL(string: proxyEnv), let host = url.host(), let port = url.port else { + return nil + } + return .server(host: host, port: port) + }() + httpConfiguration.proxy = proxyConfig + if let logger { + self.client = HTTPClient(eventLoopGroupProvider: .singleton, configuration: httpConfiguration, backgroundActivityLogger: logger) + } else { + self.client = HTTPClient(eventLoopGroupProvider: .singleton, configuration: httpConfiguration) + } + } + + deinit { + _ = client.shutdown() + } + + func host() -> String { + base.host ?? "" + } + + internal func request( + components: URLComponents, + method: HTTPMethod = .GET, + bodyClosure: () throws -> HTTPClientRequest.Body? = { nil }, + headers: [(String, String)]? = nil, + closure: (HTTPClientResponse) async throws -> T + ) async throws -> T { + guard let path = components.url?.absoluteString else { + throw ContainerizationError(.invalidArgument, message: "Invalid url \(components.path)") + } + + var request = HTTPClientRequest(url: path) + request.method = method + + var currentToken: TokenResponse? + let token: String? = try await { + if let basicAuth = authentication { + return try await basicAuth.token() + } + return nil + }() + + if let token { + request.headers.add(name: "Authorization", value: "\(token)") + } + + // Add any arbitrary headers + headers?.forEach { (k, v) in request.headers.add(name: k, value: v) } + var retryCount = 0 + var response: HTTPClientResponse? + while true { + request.body = try bodyClosure() + do { + let _response = try await client.execute(request, deadline: .distantFuture) + response = _response + if _response.status == .unauthorized || _response.status == .forbidden { + let authHeader = _response.headers[TokenRequest.authenticateHeaderName] + let tokenRequest: TokenRequest + do { + tokenRequest = try self.createTokenRequest(parsing: authHeader) + } catch { + // The server did not tell us how to authenticate our requests, + // Or we do not support scheme the server is requesting for. + // Throw the 401/403 to the caller, and let them decide how to proceed. + throw RegistryClient.Error.invalidStatus(url: path, _response.status) + } + if let ct = currentToken, ct.isValid(scope: tokenRequest.scope) { + break + } + let _currentToken = try await fetchToken(request: tokenRequest) + guard let token = _currentToken.getToken() else { + throw ContainerizationError(.internalError, message: "Failed to fetch Bearer token") + } + currentToken = _currentToken + request.headers.replaceOrAdd(name: "Authorization", value: token) + retryCount += 1 + continue + } + guard let retryOptions = self.retryOptions else { + break + } + guard retryCount < retryOptions.maxRetries else { + break + } + guard let shouldRetry = retryOptions.shouldRetry, shouldRetry(_response) else { + break + } + retryCount += 1 + try await Task.sleep(nanoseconds: retryOptions.retryInterval) + continue + } catch let err as RegistryClient.Error { + throw err + } catch { + #if os(macOS) + if let err = error as? NWError { + if err.errorCode == kDNSServiceErr_NoSuchRecord { + throw ContainerizationError(.internalError, message: "No Such DNS Record \(host())") + } + } + #endif + guard let retryOptions = self.retryOptions, retryCount < retryOptions.maxRetries else { + throw error + } + retryCount += 1 + try await Task.sleep(nanoseconds: retryOptions.retryInterval) + } + } + guard let response else { + throw ContainerizationError(.internalError, message: "Invalid response") + } + return try await closure(response) + } + + internal func requestData( + components: URLComponents, + headers: [(String, String)]? = nil + ) async throws -> Data { + try await request(components: components, method: .GET, headers: headers) { response in + guard response.status == .ok else { + let url = components.url?.absoluteString ?? "unknown" + throw Error.invalidStatus(url: url, response.status) + } + + var body = try await response.body.collect(upTo: self.bufferSize) + guard let bytes = body.readBytes(length: body.readableBytes) else { + throw ContainerizationError(.internalError, message: "Cannot read bytes from HTTP response") + } + return Data(bytes) + } + } + + internal func requestJSON( + components: URLComponents, + headers: [(String, String)]? = nil + ) async throws -> T { + let data = try await self.requestData(components: components, headers: headers) + return try JSONDecoder().decode(T.self, from: data) + } + + /// A minimal endpoint, mounted at /v2/ will provide version support information based on its response statuses. + /// See https://distribution.github.io/distribution/spec/api/#api-version-check + public func ping() async throws { + var components = base + components.path = "/v2/" + + try await request(components: components) { response in + guard response.status == .ok else { + let url = components.url?.absoluteString ?? "unknown" + throw Error.invalidStatus(url: url, response.status) + } + } + } +} diff --git a/Sources/ContainerizationOCI/Config.swift b/Sources/ContainerizationOCI/Config.swift new file mode 100644 index 00000000..baef58f8 --- /dev/null +++ b/Sources/ContainerizationOCI/Config.swift @@ -0,0 +1,173 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// Source: https://github.com/opencontainers/image-spec/blob/main/specs-go/v1/config.go + +import Foundation + +/// ImageConfig defines the execution parameters which should be used as a base when running a container using an image. +public struct ImageConfig: Codable, Sendable { + enum CodingKeys: String, CodingKey { + case user = "User" + case env = "Env" + case entrypoint = "Entrypoint" + case cmd = "Cmd" + case workingDir = "WorkingDir" + case labels = "Labels" + case stopSignal = "StopSignal" + } + + /// user defines the username or UID which the process in the container should run as. + public let user: String? + + /// env is a list of environment variables to be used in a container. + public let env: [String]? + + /// entrypoint defines a list of arguments to use as the command to execute when the container starts. + public let entrypoint: [String]? + + /// cmd defines the default arguments to the entrypoint of the container. + public let cmd: [String]? + + /// workingDir sets the current working directory of the entrypoint process in the container. + public let workingDir: String? + + /// labels contains arbitrary metadata for the container. + public let labels: [String: String]? + + /// stopSignal contains the system call signal that will be sent to the container to exit. + public let stopSignal: String? + + public init( + user: String? = nil, env: [String]? = nil, entrypoint: [String]? = nil, cmd: [String]? = nil, + workingDir: String? = nil, labels: [String: String]? = nil, stopSignal: String? = nil + ) { + self.user = user + self.env = env + self.entrypoint = entrypoint + self.cmd = cmd + self.workingDir = workingDir + self.labels = labels + self.stopSignal = stopSignal + } +} + +/// RootFS describes a layer content addresses +public struct Rootfs: Codable, Sendable { + enum CodingKeys: String, CodingKey { + case type + case diffIDs = "diff_ids" + } + + /// type is the type of the rootfs. + public let type: String + + /// diffIDs is an array of layer content hashes (DiffIDs), in order from bottom-most to top-most. + public let diffIDs: [String] + + public init(type: String, diffIDs: [String]) { + self.type = type + self.diffIDs = diffIDs + } +} + +/// History describes the history of a layer. +public struct History: Codable, Sendable { + enum CodingKeys: String, CodingKey { + case created + case createdBy = "created_by" + case author + case comment + case emptyLayer = "empty_layer" + } + + /// created is the combined date and time at which the layer was created, formatted as defined by RFC 3339, section 5.6. + public let created: String? + + /// createdBy is the command which created the layer. + public let createdBy: String? + + /// author is the author of the build point. + public let author: String? + + /// comment is a custom message set when creating the layer. + public let comment: String? + + /// emptyLayer is used to mark if the history item created a filesystem diff. + public let emptyLayer: Bool? + + public init( + created: String? = nil, createdBy: String? = nil, author: String? = nil, comment: String? = nil, + emptyLayer: Bool? = nil + ) { + self.created = created + self.createdBy = createdBy + self.author = author + self.comment = comment + self.emptyLayer = emptyLayer + } +} + +/// Image is the JSON structure which describes some basic information about the image. +/// This provides the `application/vnd.oci.image.config.v1+json` mediatype when marshalled to JSON. +public struct Image: Codable, Sendable { + /// created is the combined date and time at which the image was created, formatted as defined by RFC 3339, section 5.6. + public let created: String? + + /// author defines the name and/or email address of the person or entity which created and is responsible for maintaining the image. + public let author: String? + + /// architecture field specifies the CPU architecture, for example `amd64` or `ppc64`. + public let architecture: String + + /// os specifies the operating system, for example `linux` or `windows`. + public let os: String + + /// osVersion is an optional field specifying the operating system version, for example on Windows `10.0.14393.1066`. + public let osVersion: String? + + /// osFeatures is an optional field specifying an array of strings, each listing a required OS feature (for example on Windows `win32k`). + public let osFeatures: [String]? + + /// variant is an optional field specifying a variant of the CPU, for example `v7` to specify ARMv7 when architecture is `arm`. + public let variant: String? + + /// config defines the execution parameters which should be used as a base when running a container using the image. + public let config: ImageConfig? + + /// rootfs references the layer content addresses used by the image. + public let rootfs: Rootfs + + /// history describes the history of each layer. + public let history: [History]? + + public init( + created: String? = nil, author: String? = nil, architecture: String, os: String, osVersion: String? = nil, + osFeatures: [String]? = nil, variant: String? = nil, config: ImageConfig? = nil, rootfs: Rootfs, + history: [History]? = nil + ) { + self.created = created + self.author = author + self.architecture = architecture + self.os = os + self.osVersion = osVersion + self.osFeatures = osFeatures + self.variant = variant + self.config = config + self.rootfs = rootfs + self.history = history + } +} diff --git a/Sources/ContainerizationOCI/Content/AsyncTypes.swift b/Sources/ContainerizationOCI/Content/AsyncTypes.swift new file mode 100644 index 00000000..2da9ae14 --- /dev/null +++ b/Sources/ContainerizationOCI/Content/AsyncTypes.swift @@ -0,0 +1,56 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +public actor AsyncStore { + private var _value: T? + + public init(_ value: T? = nil) { + self._value = value + } + + public func get() -> T? { + self._value + } + + public func set(_ value: T) { + self._value = value + } +} + +public actor AsyncSet { + private var buffer: Set + + public init(_ elements: S) where S.Element == T { + buffer = Set(elements) + } + + public var count: Int { + buffer.count + } + + public func insert(_ element: T) { + buffer.insert(element) + } + + @discardableResult + public func remove(_ element: T) -> T? { + buffer.remove(element) + } + + public func contains(_ element: T) -> Bool { + buffer.contains(element) + } +} diff --git a/Sources/ContainerizationOCI/Content/Content.swift b/Sources/ContainerizationOCI/Content/Content.swift new file mode 100644 index 00000000..4614322f --- /dev/null +++ b/Sources/ContainerizationOCI/Content/Content.swift @@ -0,0 +1,59 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationExtras +import Crypto +import Foundation +import NIOCore + +/// Protocol for defining a single OCI content +public protocol Content: Sendable { + /// URL to the content + var path: URL { get } + + /// sha256 of content + func digest() throws -> SHA256.Digest + + /// size of content + func size() throws -> UInt64 + + /// Data represenatation of entire content + func data() throws -> Data + + /// Data representation partial content + func data(offset: UInt64, length: Int) throws -> Data? + + /// Decode the content into an object + func decode() throws -> T where T: Decodable +} + +/// Protocol defining methods to fetch and push OCI content +public protocol ContentClient: Sendable { + func fetch(name: String, descriptor: Descriptor) async throws -> T + + func fetchBlob(name: String, descriptor: Descriptor, into file: URL, progress: ProgressHandler?) async throws -> (Int64, SHA256Digest) + + func fetchData(name: String, descriptor: Descriptor) async throws -> Data + + func push( + name: String, + ref: String, + descriptor: Descriptor, + streamGenerator: () throws -> T, + progress: ProgressHandler? + ) async throws where T.Element == ByteBuffer + +} diff --git a/Sources/ContainerizationOCI/Content/ContentStoreProtocol.swift b/Sources/ContainerizationOCI/Content/ContentStoreProtocol.swift new file mode 100644 index 00000000..8f7ed8c1 --- /dev/null +++ b/Sources/ContainerizationOCI/Content/ContentStoreProtocol.swift @@ -0,0 +1,63 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Crypto +import Foundation + +/// Protocol for defining a content store where OCI image metadata and layers will be managed +/// and manipulated. +public protocol ContentStore: Sendable { + /// Retrieves a piece of Content based on the digest string. + /// Returns `nil` if the requested digest is not found. + func get(digest: String) async throws -> Content? + + /// Retrieves a specific content metadata type based on the digest string. + /// Returns `nil` if the requested digest is not found. + func get(digest: String) async throws -> T? + + /// Remove a list of digests in the content store. + @discardableResult + func delete(digests: [String]) async throws -> ([String], UInt64) + + /// Removes all content from the store except for the digests in the provided list. + @discardableResult + func delete(keeping: [String]) async throws -> ([String], UInt64) + + /// Creates a transactional write to the content store. + /// The function takes a closure given a temporary `URL` of the base directory which all contents should be written to. + /// This is transaction write where any failed operation in the closure (caught exception) will result in all contents written + /// in the closure to be deleted. + /// + /// If the closure succeeds, then all the content that have been written to the temporary `URL` will be moved into the actual + /// blobs path of the content store. + @discardableResult + func ingest(_ body: @Sendable @escaping (URL) async throws -> Void) async throws -> [String] + + /// Creates a new ingest session and returns the session ID and temporary ingest directory corresponding to the session. + /// The contents from the ingest directory are processed and moved into the content store once the session is marked complete. + /// This can be done by invoking the `completeIngestSession` method with the returned session ID. + func newIngestSession() async throws -> (id: String, ingestDir: URL) + + /// Completes a previously started ingest session corresponding to `id`. + /// The contents from the ingest directory from the session are moved into the content store atomically. + /// Any failure encountered will result in a transaction failure causing none of the contents to be ingested into the store. + @discardableResult + func completeIngestSession(_ id: String) async throws -> [String] + + /// Cancels a previously started ingest session corresponding to `id`. + /// The contents from the ingest directory corresponding to the session are removed. + func cancelIngestSession(_ id: String) async throws +} diff --git a/Sources/ContainerizationOCI/Content/ContentWriter.swift b/Sources/ContainerizationOCI/Content/ContentWriter.swift new file mode 100644 index 00000000..4d20378b --- /dev/null +++ b/Sources/ContainerizationOCI/Content/ContentWriter.swift @@ -0,0 +1,58 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationError +import Crypto +import Foundation +import NIOCore + +/// Provides a context to write data into a directory. +public class ContentWriter { + private let base: URL + private let encoder = JSONEncoder() + + private var done: Bool = false + + public init(for base: URL) throws { + self.base = base + var isDirectory = ObjCBool(true) + let exists = FileManager.default.fileExists(atPath: base.path, isDirectory: &isDirectory) + + guard exists && isDirectory.boolValue else { + throw ContainerizationError(.internalError, message: "Cannot create ContentWriter for path \(base.absolutePath()). Not a directory") + } + } + + @discardableResult + public func write(_ data: Data) throws -> (size: Int64, digest: SHA256.Digest) { + let digest = SHA256.hash(data: data) + let destination = base.appendingPathComponent(digest.encoded) + try data.write(to: destination) + return (Int64(data.count), digest) + } + + @discardableResult + public func create(from u: URL) throws -> (size: Int64, digest: SHA256.Digest) { + let data = try Data(contentsOf: u) + return try self.write(data) + } + + @discardableResult + public func create(from content: T) throws -> (size: Int64, digest: SHA256.Digest) { + let data = try self.encoder.encode(content) + return try self.write(data) + } +} diff --git a/Sources/ContainerizationOCI/Content/LocalContent.swift b/Sources/ContainerizationOCI/Content/LocalContent.swift new file mode 100644 index 00000000..830a264c --- /dev/null +++ b/Sources/ContainerizationOCI/Content/LocalContent.swift @@ -0,0 +1,78 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationError +import Crypto +import Foundation + +public final class LocalContent: Content { + public let path: URL + private let file: FileHandle + + public init(path: URL) throws { + guard FileManager.default.fileExists(atPath: path.path) else { + throw ContainerizationError(.notFound, message: "Content at path \(path.absolutePath())") + } + + self.file = try FileHandle(forReadingFrom: path) + self.path = path + } + + public func digest() throws -> SHA256.Digest { + let bufferSize = 64 * 1024 // 64 KB + var hasher = SHA256() + + try self.file.seek(toOffset: 0) + while case let data = file.readData(ofLength: bufferSize), !data.isEmpty { + hasher.update(data: data) + } + + let digest = hasher.finalize() + + try self.file.seek(toOffset: 0) + return digest + } + + public func data(offset: UInt64 = 0, length size: Int = 0) throws -> Data? { + try file.seek(toOffset: offset) + if size == 0 { + return try file.readToEnd() + } + return try file.read(upToCount: size) + } + + public func data() throws -> Data { + try Data(contentsOf: self.path) + } + + public func size() throws -> UInt64 { + let fileAttrs = try FileManager.default.attributesOfItem(atPath: self.path.absolutePath()) + if let size = fileAttrs[FileAttributeKey.size] as? UInt64 { + return size + } + throw ContainerizationError(.internalError, message: "Could not determine file size for \(path.absolutePath())") + } + + public func decode() throws -> T where T: Decodable { + let json = JSONDecoder() + let data = try Data(contentsOf: self.path) + return try json.decode(T.self, from: data) + } + + deinit { + try? self.file.close() + } +} diff --git a/Sources/ContainerizationOCI/Content/LocalContentStore.swift b/Sources/ContainerizationOCI/Content/LocalContentStore.swift new file mode 100644 index 00000000..59e172b8 --- /dev/null +++ b/Sources/ContainerizationOCI/Content/LocalContentStore.swift @@ -0,0 +1,159 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// swiftlint:disable unused_optional_binding + +import ContainerizationError +import ContainerizationExtras +import Crypto +import Foundation + +public actor LocalContentStore: ContentStore { + private static let encoder = JSONEncoder() + + private let _basePath: URL + private let _ingestPath: URL + private let _blobPath: URL + private let _lock: AsyncLock + + private var activeIngestSessions: AsyncSet = AsyncSet([]) + + public init(path: URL) throws { + let ingestPath = path.appendingPathComponent("ingest") + let blobPath = path.appendingPathComponent("blobs/sha256") + + let fileManager = FileManager.default + try fileManager.createDirectory(at: ingestPath, withIntermediateDirectories: true) + try fileManager.createDirectory(at: blobPath, withIntermediateDirectories: true) + + self._basePath = path + self._ingestPath = ingestPath + self._blobPath = blobPath + self._lock = AsyncLock() + Self.encoder.outputFormatting = .sortedKeys + } + + public func get(digest: String) throws -> Content? { + let d = digest.trimmingDigestPrefix + let path = self._blobPath.appendingPathComponent(d) + do { + return try LocalContent(path: path) + } catch let err as ContainerizationError { + switch err.code { + case .notFound: + return nil + default: + throw err + } + } + } + + public func get(digest: String) throws -> T? { + guard let content: Content = try self.get(digest: digest) else { + return nil + } + return try content.decode() + } + + public func delete(keeping: [String]) async throws -> ([String], UInt64) { + let fileManager = FileManager.default + let all = try fileManager.contentsOfDirectory(at: self._blobPath, includingPropertiesForKeys: nil) + let allDigests = Set(all.map { $0.lastPathComponent }) + let toDelete = allDigests.subtracting(keeping) + return try await self.delete(digests: Array(toDelete)) + } + + @discardableResult + public func delete(digests: [String]) async throws -> ([String], UInt64) { + let store = AsyncStore<([String], UInt64)>() + try await self._lock.withLock { context in + let fileManager = FileManager.default + var deleted: [String] = [] + var deletedBytes: UInt64 = 0 + for toDelete in digests { + let p = self._blobPath.appendingPathComponent(toDelete) + guard let content = try? LocalContent(path: p) else { + continue + } + deletedBytes += try content.size() + try fileManager.removeItem(at: p) + deleted.append(toDelete) + } + await store.set((deleted, deletedBytes)) + } + return await store.get() ?? ([], 0) + } + + @discardableResult + public func ingest(_ body: @Sendable @escaping (URL) async throws -> Void) async throws -> [String] { + let (id, tempPath) = try await self.newIngestSession() + try await body(tempPath) + return try await self.completeIngestSession(id) + } + + public func newIngestSession() async throws -> (id: String, ingestDir: URL) { + let id = UUID().uuidString + let temporaryPath = self._ingestPath.appendingPathComponent(id) + let fileManager = FileManager.default + try fileManager.createDirectory(atPath: temporaryPath.path, withIntermediateDirectories: true) + await self.activeIngestSessions.insert(id) + return (id, temporaryPath) + } + + @discardableResult + public func completeIngestSession(_ id: String) async throws -> [String] { + guard await activeIngestSessions.contains(id) else { + throw ContainerizationError(.internalError, message: "Invalid session id \(id)") + } + await activeIngestSessions.remove(id) + let temporaryPath = self._ingestPath.appendingPathComponent(id) + let fileManager = FileManager.default + defer { + try? fileManager.removeItem(at: temporaryPath) + } + let tempDigests: [URL] = try fileManager.contentsOfDirectory(at: temporaryPath, includingPropertiesForKeys: nil) + return try await self._lock.withLock { context in + var moved: [String] = [] + let fileManager = FileManager.default + do { + try tempDigests.forEach { + let digest = $0.lastPathComponent + let target = self._blobPath.appendingPathComponent(digest) + // only ingest if not exists + if !fileManager.fileExists(atPath: target.path) { + try fileManager.moveItem(at: $0, to: target) + moved.append(digest) + } + } + } catch { + moved.forEach { + try? fileManager.removeItem(at: self._blobPath.appendingPathComponent($0)) + } + throw error + } + return tempDigests.map { $0.lastPathComponent } + } + } + + public func cancelIngestSession(_ id: String) async throws { + guard let _ = await self.activeIngestSessions.remove(id) else { + return + } + let temporaryPath = self._ingestPath.appendingPathComponent(id) + let fileManager = FileManager.default + try? fileManager.removeItem(at: temporaryPath) + } +} diff --git a/Sources/ContainerizationOCI/Content/SHA256+Extensions.swift b/Sources/ContainerizationOCI/Content/SHA256+Extensions.swift new file mode 100644 index 00000000..62db6cd3 --- /dev/null +++ b/Sources/ContainerizationOCI/Content/SHA256+Extensions.swift @@ -0,0 +1,30 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Crypto +import Foundation + +extension SHA256.Digest { + public var digestString: String { + let parts = self.description.split(separator: ": ") + return "sha256:\(parts[1])" + } + + public var encoded: String { + let parts = self.description.split(separator: ": ") + return String(parts[1]) + } +} diff --git a/Sources/ContainerizationOCI/Content/String+Extension.swift b/Sources/ContainerizationOCI/Content/String+Extension.swift new file mode 100644 index 00000000..bf9b1ed3 --- /dev/null +++ b/Sources/ContainerizationOCI/Content/String+Extension.swift @@ -0,0 +1,25 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +extension String { + public var trimmingDigestPrefix: String { + let split = self.split(separator: ":") + if split.count == 2 { + return String(split[1]) + } + return self + } +} diff --git a/Sources/ContainerizationOCI/Content/URL+Extensions.swift b/Sources/ContainerizationOCI/Content/URL+Extensions.swift new file mode 100644 index 00000000..02a905af --- /dev/null +++ b/Sources/ContainerizationOCI/Content/URL+Extensions.swift @@ -0,0 +1,35 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +extension URL { + /// returns the unescaped absolutePath of a URL joined by separator + public func absolutePath() -> String { + #if os(macOS) + return self.path(percentEncoded: false) + #else + return self.path + #endif + } + + public var domain: String? { + guard let host = self.absoluteString.split(separator: ":").first else { + return nil + } + return String(host) + } +} diff --git a/Sources/ContainerizationOCI/Descriptor.swift b/Sources/ContainerizationOCI/Descriptor.swift new file mode 100644 index 00000000..b6c473a5 --- /dev/null +++ b/Sources/ContainerizationOCI/Descriptor.swift @@ -0,0 +1,56 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// Source: https://github.com/opencontainers/image-spec/blob/main/specs-go/v1/descriptor.go + +import Foundation + +/// Descriptor describes the disposition of targeted content. +/// This structure provides `application/vnd.oci.descriptor.v1+json` mediatype +/// when marshalled to JSON. +public struct Descriptor: Codable, Sendable, Equatable { + /// mediaType is the media type of the object this schema refers to. + public let mediaType: String + + /// digest is the digest of the targeted content. + public let digest: String + + /// size specifies the size in bytes of the blob. + public let size: Int64 + + /// urls specifies a list of URLs from which this object MAY be downloaded. + public let urls: [String]? + + /// annotations contains arbitrary metadata relating to the targeted content. + public var annotations: [String: String]? + + /// platform describes the platform which the image in the manifest runs on. + /// + /// This should only be used when referring to a manifest. + public var platform: Platform? + + public init( + mediaType: String, digest: String, size: Int64, urls: [String]? = nil, annotations: [String: String]? = nil, + platform: Platform? = nil + ) { + self.mediaType = mediaType + self.digest = digest + self.size = size + self.urls = urls + self.annotations = annotations + self.platform = platform + } +} diff --git a/Sources/ContainerizationOCI/FileManager+Size.swift b/Sources/ContainerizationOCI/FileManager+Size.swift new file mode 100644 index 00000000..5a1fa5bb --- /dev/null +++ b/Sources/ContainerizationOCI/FileManager+Size.swift @@ -0,0 +1,31 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +extension FileManager { + func fileSize(atPath path: String) -> Int64? { + do { + let attributes = try attributesOfItem(atPath: path) + guard let fileSize = attributes[.size] as? NSNumber else { + return nil + } + return fileSize.int64Value + } catch { + return nil + } + } +} diff --git a/Sources/ContainerizationOCI/Index.swift b/Sources/ContainerizationOCI/Index.swift new file mode 100644 index 00000000..bdcfbb3a --- /dev/null +++ b/Sources/ContainerizationOCI/Index.swift @@ -0,0 +1,45 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// Source: https://github.com/opencontainers/image-spec/blob/main/specs-go/v1/index.go + +import Foundation + +/// Index references manifests for various platforms. +/// This structure provides `application/vnd.oci.image.index.v1+json` mediatype when marshalled to JSON. +public struct Index: Codable, Sendable { + /// schemaVersion is the image manifest schema that this image follows + public let schemaVersion: Int + + /// mediaType specifies the type of this document data structure e.g. `application/vnd.oci.image.index.v1+json` + public let mediaType: String + + /// manifests references platform specific manifests. + public var manifests: [Descriptor] + + /// annotations contains arbitrary metadata for the image index. + public var annotations: [String: String]? + + public init( + schemaVersion: Int = 2, mediaType: String = MediaTypes.index, manifests: [Descriptor], + annotations: [String: String]? = nil + ) { + self.schemaVersion = schemaVersion + self.mediaType = mediaType + self.manifests = manifests + self.annotations = annotations + } +} diff --git a/Sources/ContainerizationOCI/Manifest.swift b/Sources/ContainerizationOCI/Manifest.swift new file mode 100644 index 00000000..3c34ad76 --- /dev/null +++ b/Sources/ContainerizationOCI/Manifest.swift @@ -0,0 +1,49 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// Source: https://github.com/opencontainers/image-spec/blob/main/specs-go/v1/manifest.go + +import Foundation + +/// Manifest provides `application/vnd.oci.image.manifest.v1+json` mediatype structure when marshalled to JSON. +public struct Manifest: Codable, Sendable { + /// `schemaVersion` is the image manifest schema that this image follows. + public let schemaVersion: Int + + /// `mediaType` specifies the type of this document data structure, e.g. `application/vnd.oci.image.manifest.v1+json`. + public let mediaType: String? + + /// `config` references a configuration object for a container, by digest. + /// The referenced configuration object is a JSON blob that the runtime uses to set up the container. + public let config: Descriptor + + /// `layers` is an indexed list of layers referenced by the manifest. + public let layers: [Descriptor] + + /// `annotations` contains arbitrary metadata for the image manifest. + public let annotations: [String: String]? + + public init( + schemaVersion: Int = 2, mediaType: String = MediaTypes.imageManifest, config: Descriptor, layers: [Descriptor], + annotations: [String: String]? = nil + ) { + self.schemaVersion = schemaVersion + self.mediaType = mediaType + self.config = config + self.layers = layers + self.annotations = annotations + } +} diff --git a/Sources/ContainerizationOCI/MediaType.swift b/Sources/ContainerizationOCI/MediaType.swift new file mode 100644 index 00000000..364faf4d --- /dev/null +++ b/Sources/ContainerizationOCI/MediaType.swift @@ -0,0 +1,69 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +/// MediaTypes represent all supported OCI image content types for both metadata and layer formats. +/// Follows all distributable media types in: https://github.com/opencontainers/image-spec/blob/main/specs-go/v1/mediatype.go +public struct MediaTypes: Codable, Sendable { + /// Specifies the media type for a content descriptor. + public static let descriptor = "application/vnd.oci.descriptor.v1+json" + + /// Specifies the media type for the oci-layout. + public static let layoutHeader = "application/vnd.oci.layout.header.v1+json" + + /// Specifies the media type for an image index. + public static let index = "application/vnd.oci.image.index.v1+json" + + /// Specifies the media type for an image manifest. + public static let imageManifest = "application/vnd.oci.image.manifest.v1+json" + + /// Specifies the media type for the image configuration. + public static let imageConfig = "application/vnd.oci.image.config.v1+json" + + /// Specifies the media type for an unused blob containing the value "{}". + public static let emptyJSON = "application/vnd.oci.empty.v1+json" + + /// Specifies the media type for a Docker image manifest. + public static let dockerManifest = "application/vnd.docker.distribution.manifest.v2+json" + + /// Specifies the media type for a Docker image manifest list. + public static let dockerManifestList = "application/vnd.docker.distribution.manifest.list.v2+json" + + /// The Docker media type used for image configurations. + public static let dockerImageConfig = "application/vnd.docker.container.image.v1+json" + + /// The media type used for layers referenced by the manifest. + public static let imageLayer = "application/vnd.oci.image.layer.v1.tar" + + /// The media type used for gzipped layers referenced by the manifest. + public static let imageLayerGzip = "application/vnd.oci.image.layer.v1.tar+gzip" + + /// The media type used for zstd compressed layers referenced by the manifest. + public static let imageLayerZstd = "application/vnd.oci.image.layer.v1.tar+zstd" + + /// The Docker media type used for uncompressed layers referenced by an image manifest. + public static let dockerImageLayer = "application/vnd.docker.image.rootfs.diff.tar" + + /// The Docker media type used for gzipped layers referenced by an image manifest. + public static let dockerImageLayerGzip = "application/vnd.docker.image.rootfs.diff.tar.gzip" + + /// The Docker media type used for zstd compressed layers referenced by an image manifest. + public static let dockerImageLayerZstd = "application/vnd.docker.image.rootfs.diff.tar.zstd" + + /// The media type used for in-toto attestations blobs. + public static let intototAttestationBlob = "application/vnd.in-toto+json" +} diff --git a/Sources/ContainerizationOCI/Platform.swift b/Sources/ContainerizationOCI/Platform.swift new file mode 100644 index 00000000..80f0794a --- /dev/null +++ b/Sources/ContainerizationOCI/Platform.swift @@ -0,0 +1,340 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// Source: https://github.com/opencontainers/image-spec/blob/main/specs-go/v1/config.go + +import ContainerizationError +import Foundation + +/// Platform describes the platform which the image in the manifest runs on. +public struct Platform: Sendable, Equatable { + public static var current: Self { + var systemInfo = utsname() + uname(&systemInfo) + let arch = withUnsafePointer(to: &systemInfo.machine) { + $0.withMemoryRebound(to: CChar.self, capacity: 1) { + String(cString: $0) + } + } + switch arch { + case "arm64": + return .init(arch: "arm64", os: "linux", variant: "v8") + case "x86_64": + return .init(arch: "amd64", os: "linux") + default: + fatalError("unsupported arch \(arch)") + } + } + + /// description is the processed value (eg. `linux/arm64/v8`) + public var description: String { + let architecture = architecture + if let variant = variant { + return "\(os)/\(architecture)/\(variant)" + } + return "\(os)/\(architecture)" + } + + /// architecture field specifies the CPU architecture, for example `amd64` or `ppc64`. + public var architecture: String { + switch _rawArch { + case "arm64", "arm", "aarch64", "armhf", "armel": + return "arm64" + case "x86_64", "x86-64", "amd64": + return "amd64" + case "386", "ppc64le", "i386", "s390x", "riscv64": + return _rawArch + default: + return _rawArch + } + } + + /// os specifies the operating system, for example `linux` or `windows`. + public var os: String { + _rawOS + } + + /// osVersion is an optional field specifying the operating system version, for example on Windows `10.0.14393.1066`. + public var osVersion: String? + + /// osFeatures is an optional field specifying an array of strings, each listing a required OS feature (for example on Windows `win32k`). + public var osFeatures: [String]? + + /// variant is an optional field specifying a variant of the CPU, for example `v7` to specify ARMv7 when architecture is `arm`. + public var variant: String? + + /// rawOS is the operation system of the image (eg. `linux`) + private let _rawOS: String + /// rawArch is the CPU architecture (eg. `arm64`) + private let _rawArch: String + + public init(arch: String, os: String, osVersion: String? = nil, osFeatures: [String]? = nil, variant: String? = nil) { + self._rawArch = arch + self._rawOS = os + self.osVersion = osVersion + self.osFeatures = osFeatures + self.variant = variant + } + + /// Initializes new platform from string + /// - Parameters: + /// - from: `string` value representing the platform + /// ```swift + /// // create a new ImagePlatform from string + /// let platform = try Platform(from: "linux/amd64") + /// ``` + /// ## Throws ## + /// - Throws: `Error.missingOS` if input is empty + /// - Throws: `Error.invalidOS` if os is not `linux` + /// - Throws: `Error.missingArch` if only one `/` is present + /// - Throws: `Error.invalidArch` if an unrecognized architecture is provided + /// - Throws: `Error.invalidVariant` if a variant is provided, and it does not apply to the specified architecture + public init(from platform: String) throws { + let items = platform.split(separator: "/", maxSplits: 1) + guard let osValue = items.first else { + throw ContainerizationError(.invalidArgument, message: "Missing OS in \(platform)") + } + switch osValue { + case "linux": + _rawOS = osValue.description + case "darwin": + _rawOS = osValue.description + case "windows": + _rawOS = osValue.description + default: + throw ContainerizationError(.invalidArgument, message: "Unknown OS in \(osValue)") + } + guard items.count > 1 else { + throw ContainerizationError(.invalidArgument, message: "Missing architecture in \(platform)") + } + + guard let archItems = items.last?.split(separator: "/", maxSplits: 1, omittingEmptySubsequences: false) else { + throw ContainerizationError(.invalidArgument, message: "Missing architecture in \(platform)") + } + + guard let archName = archItems.first else { + throw ContainerizationError(.invalidArgument, message: "Missing architecture in \(platform)") + } + + switch archName { + case "arm", "armhf", "armel": + _rawArch = "arm" + variant = "v7" + case "aarch64", "arm64": + variant = "v8" + _rawArch = "arm64" + case "x86_64", "x86-64", "amd64": + _rawArch = "amd64" + default: + _rawArch = archName.description + } + + if archItems.count == 2 { + guard let archVariant = archItems.last else { + throw ContainerizationError(.invalidArgument, message: "Missing variant in \(platform)") + } + + switch archName { + case "arm": + switch archVariant { + case "v5", "v6", "v7", "v8": + variant = archVariant.description + default: + throw ContainerizationError(.invalidArgument, message: "Invalid variant \(archVariant)") + } + case "armhf": + switch archVariant { + case "v7": + variant = "v7" + default: + throw ContainerizationError(.invalidArgument, message: "Invalid variant \(archVariant)") + } + case "armel": + switch archVariant { + case "v6": + variant = "v6" + default: + throw ContainerizationError(.invalidArgument, message: "Invalid variant \(archVariant)") + } + case "aarch64", "arm64": + switch archVariant { + case "v8", "8": + variant = "v8" + default: + throw ContainerizationError(.invalidArgument, message: "Invalid variant \(archVariant)") + } + case "x86_64", "x86-64", "amd64": + switch archVariant { + case "v1": + variant = nil + default: + throw ContainerizationError(.invalidArgument, message: "Invalid variant \(archVariant)") + } + case "i386", "386", "ppc64le", "riscv64": + throw ContainerizationError(.invalidArgument, message: "Invalid variant \(archVariant)") + default: + throw ContainerizationError(.invalidArgument, message: "Invalid variant \(archVariant)") + } + } + } + +} + +extension Platform: Hashable { + /** + `~=` compares two platforms to check if **lhs** platform images are compatible with **rhs** platform + This operator can be used to check if an image of **lhs** platform can run on **rhs**: + - `true`: when **rhs**=`arm/v8`, **lhs** is any of `arm/v8`, `arm/v7`, `arm/v6` and `arm/v5` + - `true`: when **rhs**=`arm/v7`, **lhs** is any of `arm/v7`, `arm/v6` and `arm/v5` + - `true`: when **rhs**=`arm/v6`, **lhs** is any of `arm/v6` and `arm/v5` + - `true`: when **rhs**=`amd64`, **lhs** is any of `amd64` and `386` + - `true`: when **rhs**=**lhs** + - `false`: otherwise + - Parameters: + - lhs: platform whose compatibility is being checked + - rhs: platform against which compatibility is being checked + - Returns: `true | false` + */ + public static func ~= (lhs: Platform, rhs: Platform) -> Bool { + if lhs.os == rhs.os { + if lhs._rawArch == rhs._rawArch { + switch rhs._rawArch { + case "arm": + guard let lVariant = lhs.variant else { + return lhs == rhs + } + guard let rVariant = rhs.variant else { + return lhs == rhs + } + switch rVariant { + case "v8": + switch lVariant { + case "v5", "v6", "v7", "v8": + return true + default: + return false + } + case "v7": + switch lVariant { + case "v5", "v6", "v7": + return true + default: + return false + } + case "v6": + switch lVariant { + case "v5", "v6": + return true + default: + return false + } + default: + return lhs == rhs + } + default: + return lhs == rhs + } + } + if lhs._rawArch == "386" && rhs._rawArch == "amd64" { + return true + } + } + return false + } + + /// `==` compares if **lhs** and **rhs** are the exact same platforms + public static func == (lhs: Platform, rhs: Platform) -> Bool { + // NOTE: + // If the platform struct was created by setting the fields directly and not using (from: String) + // then, there is a possibility that for arm64 architecture, the variant may be set to nil + // In that case, the variant should be assumed to v8 + if lhs.architecture == "arm64" && rhs.architecture == "arm64" { + // The following checks effictively verify + // that one operand has nil value and other has "v8" + if lhs.variant == nil || rhs.variant == nil { + if lhs.variant == "v8" || rhs.variant == "v8" { + return true + } + } + } + + let osEqual = lhs.os == rhs.os + let archEqual = lhs.architecture == rhs.architecture + let variantEqual = lhs.variant == rhs.variant + + return osEqual && archEqual && variantEqual + } + + public func hash(into hasher: inout Swift.Hasher) { + hasher.combine(description) + } +} + +extension Platform: Codable { + + enum CodingKeys: String, CodingKey { + case os = "os" + case architecture = "architecture" + case variant = "variant" + } + + public func encode(to encoder: Encoder) throws { + var container = encoder.container(keyedBy: CodingKeys.self) + try container.encode(os, forKey: .os) + try container.encode(architecture, forKey: .architecture) + try container.encodeIfPresent(variant, forKey: .variant) + } + + public init(from decoder: Decoder) throws { + let container = try decoder.container(keyedBy: CodingKeys.self) + let architecture = try container.decodeIfPresent(String.self, forKey: .architecture) + guard let architecture else { + throw ContainerizationError(.invalidArgument, message: "Missing architecture") + } + let os = try container.decodeIfPresent(String.self, forKey: .os) + guard let os else { + throw ContainerizationError(.invalidArgument, message: "Missing OS") + } + let variant = try container.decodeIfPresent(String.self, forKey: .variant) + self.init(arch: architecture, os: os, variant: variant) + } +} + +public func createPlatformMatcher(for platform: Platform?) -> @Sendable (Platform) -> Bool { + if let platform { + return { other in + platform == other + } + } + return { _ in + true + } +} + +public func filterPlatforms(matcher: (Platform) -> Bool, _ descriptors: [Descriptor]) throws -> [Descriptor] { + var outDescriptors: [Descriptor] = [] + for desc in descriptors { + guard let p = desc.platform else { + // pass along descriptor if the platform is not defined + outDescriptors.append(desc) + continue + } + if matcher(p) { + outDescriptors.append(desc) + } + } + return outDescriptors +} diff --git a/Sources/ContainerizationOCI/Reference.swift b/Sources/ContainerizationOCI/Reference.swift new file mode 100644 index 00000000..c4c694f0 --- /dev/null +++ b/Sources/ContainerizationOCI/Reference.swift @@ -0,0 +1,280 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationError +import Foundation + +private let referenceTotalLengthMax = 255 +private let nameTotalLengthMax = 127 +private let legacyDockerRegistryHost = "docker.io" +private let dockerRegistryHost = "registry-1.docker.io" +private let defaultDockerRegistryRepo = "library" +private let defaultTag = "latest" + +/// A Reference is composed of the various parts of an OCI image reference. +/// For example: +/// let imageReference = "my-registry.com/repository/image:tag2" +/// let reference = Reference.parse(imageReference) +/// print(reference.domain!) // gives us "my-registry.com" +/// print(reference.name) // gives us "my-registry.com/repository/image" +/// print(reference.path) // gives us "repository/image" +/// print(reference.tag!) // gives us "tag2" +/// print(reference.digest) // gives us "nil" +public class Reference: CustomStringConvertible { + private var _domain: String? + public var domain: String? { + _domain + } + public var resolvedDomain: String? { + if let d = _domain { + return Self.resolveDomain(domain: d) + } + return nil + } + + private var _path: String + public var path: String { + _path + } + + private var _tag: String? + public var tag: String? { + _tag + } + + private var _digest: String? + public var digest: String? { + _digest + } + + public var name: String { + if let domain, !domain.isEmpty { + return "\(domain)/\(path)" + } + return path + } + + public var description: String { + if let tag { + return "\(name):\(tag)" + } + if let digest { + return "\(name)@\(digest)" + } + return name + } + + static let identifierPattern = "([a-f0-9]{64})" + + static let domainPattern = { + let domainNameComponent = "(?:[a-zA-Z0-9]|[a-zA-Z0-9][a-zA-Z0-9-]*[a-zA-Z0-9])" + let optionalPort = "(?::[0-9]+)?" + let ipv6address = "\\[(?:[a-fA-F0-9:]+)\\]" + let domainName = "\(domainNameComponent)(?:\\.\(domainNameComponent))*" + let host = "(?:\(domainName)|\(ipv6address))" + let domainAndPort = "\(host)\(optionalPort)" + return domainAndPort + }() + + static let pathPattern = "(?(?:[a-z0-9]+(?:[._]|__|-|/)?)*[a-z0-9]+)" + static let tagPattern = "(?::(?[\\w][\\w.-]{0,127}))?(?:@(?sha256:[0-9a-fA-F]{64}))?" + static let pathTagPattern = "\(pathPattern)\(tagPattern)" + + public init(path: String, domain: String? = nil, tag: String? = nil, digest: String? = nil) throws { + if let domain, !domain.isEmpty { + self._domain = domain + } + + self._path = path + self._tag = tag + self._digest = digest + } + + public static func parse(_ s: String) throws -> Reference { + if s.count > referenceTotalLengthMax { + throw ContainerizationError(.invalidArgument, message: "Reference length \(s.count) greater than \(referenceTotalLengthMax)") + } + + let identifierRegex = try Regex(Self.identifierPattern) + guard try identifierRegex.wholeMatch(in: s) == nil else { + throw ContainerizationError(.invalidArgument, message: "Cannot specify 64 byte hex string as reference") + } + + let (domain, remainder) = try Self.parseDomain(from: s) + let constructedRawReference: String = remainder + if let domain { + let domainRegex = try Regex(domainPattern) + guard try domainRegex.wholeMatch(in: domain) != nil else { + throw ContainerizationError(.invalidArgument, message: "Invalid domain \(domain) for reference \(s)") + } + } + let fields = try constructedRawReference.matches(regex: pathTagPattern) + guard let path = fields["path"] else { + throw ContainerizationError(.invalidArgument, message: "Cannot parse path for reference \(s)") + } + + let ref = try Reference(path: path, domain: domain) + if ref.name.count > nameTotalLengthMax { + throw ContainerizationError(.invalidArgument, message: "Repo length \(ref.name.count) greater than \(nameTotalLengthMax)") + } + + // Extract tag and digest + let tag = fields["tag"] ?? "" + let digest = fields["digest"] ?? "" + + if !digest.isEmpty { + return try ref.withDigest(digest) + } else if !tag.isEmpty { + return try ref.withTag(tag) + } + return ref + } + + private static func parseDomain(from s: String) throws -> (domain: String?, remainder: String) { + var domain: String? = nil + var path: String = s + let charset = CharacterSet(charactersIn: ".:") + let splits = s.split(separator: "/", maxSplits: 1) + guard splits.count == 2 else { + if s.starts(with: "localhost") { + return (s, "") + } + return (nil, s) + } + let _domain = String(splits[0]) + let _path = String(splits[1]) + if _domain.starts(with: "localhost") || _domain.rangeOfCharacter(from: charset) != nil { + domain = _domain + path = _path + } + return (domain, path) + } + + public static func withName(_ name: String) throws -> Reference { + if name.count > nameTotalLengthMax { + throw ContainerizationError(.invalidArgument, message: "Name length \(name.count) greater than \(nameTotalLengthMax)") + } + let fields = try name.matches(regex: Self.domainPattern) + // Extract domain and path + let domain = fields["domain"] ?? "" + let path = fields["path"] ?? "" + + if domain.isEmpty || path.isEmpty { + throw ContainerizationError(.invalidArgument, message: "Image reference domain or path is empty") + } + + return try Reference(path: path, domain: domain) + } + + public func withTag(_ tag: String) throws -> Reference { + var tag = tag + if !tag.starts(with: ":") { + tag = ":" + tag + } + let fields = try tag.matches(regex: Self.tagPattern) + tag = fields["tag"] ?? "" + + if tag.isEmpty { + throw ContainerizationError(.invalidArgument, message: "Invalid format for image reference. Missing tag") + } + return try Reference(path: self.path, domain: self.domain, tag: tag) + } + + public func withDigest(_ digest: String) throws -> Reference { + var digest = digest + if !digest.starts(with: "@") { + digest = "@" + digest + } + let fields = try digest.matches(regex: Self.tagPattern) + digest = fields["digest"] ?? "" + + if digest.isEmpty { + throw ContainerizationError(.invalidArgument, message: "Invalid format for image reference. Missing digest") + } + return try Reference(path: self.path, domain: self.domain, digest: digest) + } + + private static func splitDomain(_ name: String) -> (domain: String, path: String) { + let parts = name.split(separator: "/") + guard parts.count == 2 else { + return ("", name) + } + return (String(parts[0]), String(parts[1])) + } + + /// Normalize the reference object. + /// Normalization is useful in cases where the reference object is to be used to + /// fetch/push an image from/to a remote registry. + /// It does the following: + /// - Adds a default tag of "latest" if the reference had no tag/digest set. + /// - If the domain is "registry-1.docker.io" or "docker.io" and the path has no repository set, + /// it adds a default "library/" repository name. + public func normalize() { + if let domain = self.domain, domain == dockerRegistryHost || domain == legacyDockerRegistryHost { + // Check if the image is being referenced by a named tag. + // If it is, and a repository is not specified, prefix it with "library/". + // This needs to be done only if we are using the Docker registry. + if !self.path.contains("/") { + self._path = "\(defaultDockerRegistryRepo)/\(self._path)" + } + } + let identifier = self._tag ?? self._digest + if identifier == nil { + // If the user did not specify a tag or a digest for the reference, set the tag to "latest". + self._tag = defaultTag + } + } + + public static func resolveDomain(domain: String) -> String { + if domain == legacyDockerRegistryHost { + return dockerRegistryHost + } + return domain + } +} + +extension String { + func matches(regex: String) throws -> [String: String] { + do { + let regex = try NSRegularExpression(pattern: regex, options: []) + let nsRange = NSRange(self.startIndex.. [String] { + let pattern = self.pattern + let regex = try NSRegularExpression(pattern: "\\(\\?<(\\w+)>", options: []) + let nsRange = NSRange(pattern.startIndex.. { + let (stream, cont) = AsyncStream.makeStream(of: Int32.self) + self.state.withLock { + $0.conts.append(cont) + } + cont.onTermination = { @Sendable _ in + self.cancel() + } + return stream + } + + /// Cancel every AsyncStream of signals, as well as the underlying + /// DispatchSignalSource's for each registered signal. + public func cancel() { + self.state.withLock { + if $0.conts.isEmpty { + return + } + + for cont in $0.conts { + cont.finish() + } + for source in $0.sources { + source.cancel() + } + $0.conts.removeAll() + $0.sources.removeAll() + } + } + + struct State: Sendable { + var conts: [AsyncStream.Continuation] = [] + nonisolated(unsafe) var sources: [any DispatchSourceSignal] = [] + } + + // We keep a reference to the continuation object that is created for + // our AsyncStream and tell our singal handler to yield a value to it + // returing a value to the consumer + private func handler(_ sig: Int32) { + self.state.withLock { + for cont in $0.conts { + cont.yield(sig) + } + } + } + + private let state: Mutex = .init(State()) + + /// Create a new `AsyncSignalHandler` for the list of given signals `notify`. + /// The default signal handlers for these signals are removed and async handlers + /// added in their place. The async signal handlers that are installed simply + /// yield to a stream if and when a signal is caught. + public static func create(notify on: [Int32]) -> AsyncSignalHandler { + let out = AsyncSignalHandler() + var sources = [any DispatchSourceSignal]() + for sig in on { + signal(sig, SIG_IGN) + let source = DispatchSource.makeSignalSource(signal: sig) + source.setEventHandler { + out.handler(sig) + } + source.resume() + // Retain a reference to our signal sources so that they + // do not go out of scope. + sources.append(source) + } + out.state.withLock { $0.sources = sources } + return out + } +} diff --git a/Sources/ContainerizationOS/BinaryInteger+Extensions.swift b/Sources/ContainerizationOS/BinaryInteger+Extensions.swift new file mode 100644 index 00000000..e123c0e3 --- /dev/null +++ b/Sources/ContainerizationOS/BinaryInteger+Extensions.swift @@ -0,0 +1,49 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +extension BinaryInteger { + private func toUnsignedMemoryAmount(_ amount: UInt64) -> UInt64 { + guard self > 0 else { + fatalError("encountered negative number during conversion to memory amount") + } + let val = UInt64(self) + let (newVal, overflow) = val.multipliedReportingOverflow(by: amount) + guard !overflow else { + fatalError("UInt64 overflow when converting to memory amount") + } + return newVal + } + + public func kib() -> UInt64 { + self.toUnsignedMemoryAmount(1 << 10) + } + + public func mib() -> UInt64 { + self.toUnsignedMemoryAmount(1 << 20) + } + + public func gib() -> UInt64 { + self.toUnsignedMemoryAmount(1 << 30) + } + + public func tib() -> UInt64 { + self.toUnsignedMemoryAmount(1 << 40) + } + + public func pib() -> UInt64 { + self.toUnsignedMemoryAmount(1 << 50) + } +} diff --git a/Sources/ContainerizationOS/Command.swift b/Sources/ContainerizationOS/Command.swift new file mode 100644 index 00000000..a79c80e9 --- /dev/null +++ b/Sources/ContainerizationOS/Command.swift @@ -0,0 +1,322 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import CShim +import Foundation +import Synchronization + +#if canImport(Darwin) +import Darwin +private let _kill = Darwin.kill +#elseif canImport(Musl) +import Musl +private let _kill = Musl.kill +#elseif canImport(Glibc) +import Glibc +private let _kill = Glibc.kill +#endif + +/// Use a command to run an executable. +public struct Command: Sendable { + /// Path to the executable binary. + public var executable: String + /// Arguments provided to the binary. + public var arguments: [String] + /// Environment variables for the process. + public var environment: [String] + /// The directory where the process should execute. + public var directory: String? + /// Additional files to pass to the process. + public var extraFiles: [FileHandle] + /// The standard input. + public var stdin: FileHandle? + /// The standard output. + public var stdout: FileHandle? + /// The standard error. + public var stderr: FileHandle? + + private let state: State + + /// System level attributes to set on the process. + public struct Attrs: Sendable { + /// Set pgroup for the new process. + public var setPGroup: Bool + /// Inherit the real uid/gid of the parent. + public var resetIDs: Bool + /// Reset the child's signal handlers to the default. + public var setSignalDefault: Bool + /// The initial signal mask for the process. + public var signalMask: UInt32 + /// Create a new session for the process. + public var setsid: Bool + /// Set the controlling terminal for the process to fd 0. + public var setctty: Bool + /// Set the process user ID. + public var uid: UInt32? + /// Set the process group ID. + public var gid: UInt32? + + public init( + setPGroup: Bool = false, + resetIDs: Bool = false, + setSignalDefault: Bool = true, + signalMask: UInt32 = 0, + setsid: Bool = false, + setctty: Bool = false, + uid: UInt32? = nil, + gid: UInt32? = nil + ) { + self.setPGroup = setPGroup + self.resetIDs = resetIDs + self.setSignalDefault = setSignalDefault + self.signalMask = signalMask + self.setsid = setsid + self.setctty = setctty + self.uid = uid + self.gid = gid + } + } + + private final class State: Sendable { + let pid: Atomic = Atomic(-1) + } + + /// Attributes to set on the process. + public var attrs = Attrs() + + /// System level process identifier. + public var pid: Int32 { self.state.pid.load(ordering: .acquiring) } + + public init( + _ executable: String, + arguments: [String] = [], + environment: [String] = environment(), + directory: String? = nil, + extraFiles: [FileHandle] = [] + ) { + self.executable = executable + self.arguments = arguments + self.environment = environment + self.extraFiles = extraFiles + self.directory = directory + self.state = State() + } + + public static func environment() -> [String] { + ProcessInfo.processInfo.environment + .map { "\($0)=\($1)" } + } +} + +extension Command { + public enum Error: Swift.Error, CustomStringConvertible { + case processRunning + + public var description: String { + switch self { + case .processRunning: + return "the process is already running" + } + } + } +} + +extension Command { + @discardableResult + public func kill(_ signal: Int32) -> Int32? { + let pid = self.pid + guard pid > 0 else { + return nil + } + return _kill(pid, signal) + } +} + +extension Command { + /// Start the process. + public func start() throws { + guard self.pid == -1 else { + throw Error.processRunning + } + let child = try execute() + self.state.pid.store(child, ordering: .releasing) + } + + /// Wait for the process to exit and return the exit status. + @discardableResult + public func wait() throws -> Int32 { + var rus = rusage() + var ws = Int32() + + let pid = self.pid + guard pid > 0 else { + return -1 + } + + let result = wait4(pid, &ws, 0, &rus) + guard result == pid else { + throw POSIXError(.init(rawValue: errno)!) + } + return Self.toExitStatus(ws) + } + + private func execute() throws -> pid_t { + var attrs = exec_command_attrs() + exec_command_attrs_init(&attrs) + + let set = try createFileset() + defer { + try? set.null.close() + } + var fds = [Int32](repeating: 0, count: set.handles.count) + for (i, handle) in set.handles.enumerated() { + fds[i] = handle.fileDescriptor + } + + attrs.setsid = self.attrs.setsid ? 1 : 0 + attrs.setctty = self.attrs.setctty ? 1 : 0 + attrs.setpgid = self.attrs.setPGroup ? 1 : 0 + + var cwdPath: UnsafeMutablePointer? + if let chdir = self.directory { + cwdPath = strdup(chdir) + } + defer { + if let cwdPath { + free(cwdPath) + } + } + + if let uid = self.attrs.uid { + attrs.uid = uid + } + if let gid = self.attrs.gid { + attrs.gid = gid + } + + var pid: pid_t = 0 + var argv = ([executable] + arguments).map { strdup($0) } + [nil] + defer { + for arg in argv where arg != nil { + free(arg) + } + } + + let env = environment.map { strdup($0) } + [nil] + defer { + for e in env where e != nil { + free(e) + } + } + + let result = fds.withUnsafeBufferPointer { file_handles in + exec_command( + &pid, + argv[0], + &argv, + env, + file_handles.baseAddress!, Int32(file_handles.count), + cwdPath ?? nil, + &attrs) + } + guard result == 0 else { + throw POSIXError(.init(rawValue: errno)!) + } + + return pid + } + + /// Create a posix_spawn file actions set of fds to pass to the new process + private func createFileset() throws -> (null: FileHandle, handles: [FileHandle]) { + // grab dev null incase a handle passed by the user is nil + let null = try openDevNull() + var files = [FileHandle]() + files.append(stdin ?? null) + files.append(stdout ?? null) + files.append(stderr ?? null) + files.append(contentsOf: extraFiles) + return (null: null, handles: files) + } + + /// Returns a file handle to /dev/null. + private func openDevNull() throws -> FileHandle { + let fd = open("/dev/null", O_WRONLY, 0) + guard fd > 0 else { + throw POSIXError(.init(rawValue: errno)!) + } + return FileHandle(fileDescriptor: fd, closeOnDealloc: false) + } +} + +extension Command { + private static let signalOffset: Int32 = 128 + + private static let shift: Int32 = 8 + private static let mask: Int32 = 0x7F + private static let stopped: Int32 = 0x7F + private static let exited: Int32 = 0x00 + + static func signaled(_ ws: Int32) -> Bool { + ws & mask != stopped && ws & mask != exited + } + + static func exited(_ ws: Int32) -> Bool { + ws & mask == exited + } + + static func exitStatus(_ ws: Int32) -> Int32 { + let r: Int32 + #if os(Linux) + r = ws >> shift & 0xFF + #else + r = ws >> shift + #endif + return r + } + + public static func toExitStatus(_ ws: Int32) -> Int32 { + if signaled(ws) { + // We use the offset as that is how existing container + // runtimes minic bash for the status when signaled. + return Int32(Self.signalOffset + ws & mask) + } + if exited(ws) { + return exitStatus(ws) + } + return ws + } + +} + +private func WIFEXITED(_ status: Int32) -> Bool { + _WSTATUS(status) == 0 +} + +private func _WSTATUS(_ status: Int32) -> Int32 { + status & 0x7f +} + +private func WIFSIGNALED(_ status: Int32) -> Bool { + (_WSTATUS(status) != 0) && (_WSTATUS(status) != 0x7f) +} + +private func WEXITSTATUS(_ status: Int32) -> Int32 { + (status >> 8) & 0xff +} + +private func WTERMSIG(_ status: Int32) -> Int32 { + status & 0x7f +} diff --git a/Sources/ContainerizationOS/File.swift b/Sources/ContainerizationOS/File.swift new file mode 100644 index 00000000..bf03e831 --- /dev/null +++ b/Sources/ContainerizationOS/File.swift @@ -0,0 +1,107 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +public struct File: Sendable { + public enum Error: Swift.Error, CustomStringConvertible { + case errno(_ e: Int32) + + public var description: String { + switch self { + case .errno(let code): + return "errno \(code)" + } + } + } + public static func info(_ url: URL) throws -> FileInfo { + try info(url.path) + } + + public static func info(_ path: String) throws -> FileInfo { + var st = stat() + guard stat(path, &st) == 0 else { + throw Error.errno(errno) + } + return FileInfo(path, stat: st) + } +} + +public struct FileInfo: Sendable { + private let _stat_t: Foundation.stat + private let _path: String + + init(_ path: String, stat: stat) { + self._path = path + self._stat_t = stat + } + + public var mode: mode_t { + self._stat_t.st_mode + } + + public var uid: Int { + Int(self._stat_t.st_uid) + } + + public var gid: Int { + Int(self._stat_t.st_gid) + } + + public var dev: Int { + Int(self._stat_t.st_dev) + } + + public var ino: Int { + Int(self._stat_t.st_ino) + } + + public var size: Int { + Int(self._stat_t.st_size) + } + + public var path: String { + self._path + } + + public var isDirectory: Bool { + mode & S_IFMT == S_IFDIR + } + + public var isPipe: Bool { + mode & S_IFMT == S_IFIFO + } + + public var isSocket: Bool { + mode & S_IFMT == S_IFSOCK + } + + public var isLink: Bool { + mode & S_IFMT == S_IFLNK + } + + public var isRegularFile: Bool { + mode & S_IFMT == S_IFREG + } + + public var isBlock: Bool { + mode & S_IFMT == S_IFBLK + } + + public var isChar: Bool { + mode & S_IFMT == S_IFCHR + } +} diff --git a/Sources/ContainerizationOS/Keychain/KeychainQuery.swift b/Sources/ContainerizationOS/Keychain/KeychainQuery.swift new file mode 100644 index 00000000..bb5b0fe5 --- /dev/null +++ b/Sources/ContainerizationOS/Keychain/KeychainQuery.swift @@ -0,0 +1,139 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +#if os(macOS) +import Foundation + +public struct KeychainQueryResult { + public var account: String + public var data: String + public var modifiedDate: Date + public var createdDate: Date +} + +public struct KeychainQuery { + public init() {} + + public func save(id: String, host: String, user: String, token: String) throws { + if try exists(id: id, host: host) { + try delete(id: id, host: host) + } + + guard let tokenEncoded = token.data(using: String.Encoding.utf8) else { + throw Self.Error.invalidTokenConversion + } + let query: [String: Any] = [ + kSecClass as String: kSecClassInternetPassword, + kSecAttrSecurityDomain as String: id, + kSecAttrServer as String: host, + kSecAttrAccount as String: user, + kSecValueData as String: tokenEncoded, + kSecAttrAccessible as String: kSecAttrAccessibleAfterFirstUnlock, + kSecAttrSynchronizable as String: false, + ] + let status = SecItemAdd(query as CFDictionary, nil) + guard status == errSecSuccess else { throw Self.Error.unhandledError(status: status) } + } + + public func delete(id: String, host: String) throws { + let query: [String: Any] = [ + kSecClass as String: kSecClassInternetPassword, + kSecAttrSecurityDomain as String: id, + kSecAttrServer as String: host, + kSecMatchLimit as String: kSecMatchLimitOne, + ] + let status = SecItemDelete(query as CFDictionary) + guard status == errSecSuccess || status == errSecItemNotFound else { + throw Self.Error.unhandledError(status: status) + } + } + + public func get(id: String, host: String) throws -> KeychainQueryResult? { + let query: [String: Any] = [ + kSecClass as String: kSecClassInternetPassword, + kSecAttrSecurityDomain as String: id, + kSecAttrServer as String: host, + kSecReturnAttributes as String: true, + kSecMatchLimit as String: kSecMatchLimitOne, + kSecReturnData as String: true, + ] + var item: CFTypeRef? + let status = SecItemCopyMatching(query as CFDictionary, &item) + let exists = try isQuerySuccessful(status) + if !exists { + return nil + } + + guard let fetched = item as? [String: Any] else { + throw Self.Error.unexpectedDataFetched + } + guard let data = fetched[kSecValueData as String] as? Data else { + throw Self.Error.keyNotPresent(key: kSecValueData as String) + } + guard let decodedData = String(data: data, encoding: String.Encoding.utf8) else { + throw Self.Error.unexpectedDataFetched + } + guard let account = fetched[kSecAttrAccount as String] as? String else { + throw Self.Error.keyNotPresent(key: kSecAttrAccount as String) + } + guard let modifiedDate = fetched[kSecAttrModificationDate as String] as? Date else { + throw Self.Error.keyNotPresent(key: kSecAttrModificationDate as String) + } + guard let createdDate = fetched[kSecAttrCreationDate as String] as? Date else { + throw Self.Error.keyNotPresent(key: kSecAttrCreationDate as String) + } + return KeychainQueryResult( + account: account, + data: decodedData, + modifiedDate: modifiedDate, + createdDate: createdDate + ) + } + + private func isQuerySuccessful(_ status: Int32) throws -> Bool { + guard status != errSecItemNotFound else { + return false + } + guard status == errSecSuccess else { + throw Self.Error.unhandledError(status: status) + } + return true + } + + public func exists(id: String, host: String) throws -> Bool { + let query: [String: Any] = [ + kSecClass as String: kSecClassInternetPassword, + kSecAttrSecurityDomain as String: id, + kSecAttrServer as String: host, + kSecReturnAttributes as String: true, + kSecMatchLimit as String: kSecMatchLimitOne, + kSecReturnData as String: false, + ] + + let status = SecItemCopyMatching(query as CFDictionary, nil) + return try isQuerySuccessful(status) + } +} + +extension KeychainQuery { + enum Error: Swift.Error { + case unhandledError(status: Int32) + case unexpectedDataFetched + case keyNotPresent(key: String) + case invalidTokenConversion + } +} +#endif diff --git a/Sources/ContainerizationOS/Linux/Binfmt.swift b/Sources/ContainerizationOS/Linux/Binfmt.swift new file mode 100644 index 00000000..5309c5a5 --- /dev/null +++ b/Sources/ContainerizationOS/Linux/Binfmt.swift @@ -0,0 +1,97 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +#if canImport(Musl) +import Musl +private let _mount = Musl.mount +#elseif canImport(Glibc) +import Glibc +private let _mount = Glibc.mount +#endif + +/// Small utility to mount or create new binfmt_misc entries. +public struct Binfmt: Sendable { + public static let path = "/proc/sys/fs/binfmt_misc" + + public struct Entry { + public var name: String + public var type: String + public var offset: String + public var magic: String + public var mask: String + public var flags: String + + public init( + name: String, + type: String = "M", + offset: String = "", + magic: String, + mask: String, + flags: String = "CF" + ) { + self.name = name + self.type = type + self.offset = offset + self.magic = magic + self.mask = mask + self.flags = flags + } + + public static func amd64() -> Self { + Binfmt.Entry( + name: "x86_64", + magic: #"\x7fELF\x02\x01\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x02\x00\x3e\x00"#, + mask: #"\xff\xff\xff\xff\xff\xfe\xfe\x00\xff\xff\xff\xff\xff\xff\xff\xff\xfe\xff\xff\xff"# + ) + } + + #if os(Linux) + public func register(binaryPath: String) throws { + let registration = ":\(self.name):\(self.type):\(self.offset):\(self.magic):\(self.mask):\(binaryPath):\(self.flags)" + + try registration.write( + to: URL(fileURLWithPath: Binfmt.path).appendingPathComponent("register"), + atomically: false, + encoding: .ascii + ) + } + + public func unregister() throws { + let data = "-1" + try data.write( + to: URL(fileURLWithPath: Binfmt.path).appendingPathComponent(self.name), + atomically: false, + encoding: .ascii + ) + } + #endif // os(Linux) + } + + #if os(Linux) + /// Crude check to see if /proc/sys/fs/binfmt_misc/register exists. + public static func mounted() -> Bool { + FileManager.default.fileExists(atPath: "\(Self.path)/register") + } + + public static func mount() throws { + guard _mount("binfmt_misc", Self.path, "binfmt_misc", 0, "") == 0 else { + throw POSIXError.fromErrno() + } + } + #endif // os(Linux) +} diff --git a/Sources/ContainerizationOS/Linux/Epoll.swift b/Sources/ContainerizationOS/Linux/Epoll.swift new file mode 100644 index 00000000..3588b3cc --- /dev/null +++ b/Sources/ContainerizationOS/Linux/Epoll.swift @@ -0,0 +1,183 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +#if os(Linux) + +#if canImport(Musl) +import Musl +#elseif canImport(Glibc) +import Glibc +#else +#error("Epoll not supported on this platform") +#endif + +import Foundation +import Synchronization + +/// Register file descriptors to receive events. +public final class Epoll: Sendable { + public typealias Mask = Int32 + public typealias Handler = (@Sendable (Mask) -> Void) + + private let epollFD: Int32 + private let handlers = SafeMap() + private let pipe = Pipe() // to wake up a waiting epoll_wait + + public init() throws { + let efd = epoll_create1(EPOLL_CLOEXEC) + guard efd > 0 else { + throw POSIXError.fromErrno() + } + self.epollFD = efd + try self.add(pipe.fileHandleForReading.fileDescriptor) { _ in } + } + + public func add( + _ fd: Int32, + mask: Int32 = EPOLLIN | EPOLLOUT, // HUP is always added + handler: @escaping Handler + ) throws { + guard fcntl(fd, F_SETFL, O_NONBLOCK) == 0 else { + throw POSIXError.fromErrno() + } + + let events = EPOLLET | UInt32(bitPattern: mask) + + var event = epoll_event() + event.events = events + event.data.fd = fd + + try withUnsafeMutablePointer(to: &event) { ptr in + while true { + if epoll_ctl(self.epollFD, EPOLL_CTL_ADD, fd, ptr) == -1 { + if errno == EAGAIN || errno == EINTR { + continue + } + throw POSIXError.fromErrno() + } + break + } + } + + self.handlers.set(fd, handler) + } + + /// Run the main epoll loop. + /// + /// max events to return in a single wait + /// timeout in ms. + /// -1 means block forever. + /// 0 means return immediately if no events. + public func run(maxEvents: Int = 128, timeout: Int32 = -1) throws { + var events: [epoll_event] = .init( + repeating: epoll_event(), + count: maxEvents + ) + + while true { + let n = epoll_wait(self.epollFD, &events, Int32(events.count), timeout) + guard n >= 0 else { + if errno == EINTR || errno == EAGAIN { + continue // go back to epoll_wait + } + throw POSIXError.fromErrno() + } + + if n == 0 { + return // if epoll wait times out, then n will be 0 + } + + for i in 0.. Bool { + errno == ENOENT || errno == EBADF || errno == EPERM + } + + /// Shutdown the epoll handler. + public func shutdown() throws { + // wakes up epoll_wait and triggers a shutdown + try self.pipe.fileHandleForWriting.close() + } + + private final class SafeMap: Sendable { + let dict = Mutex<[Key: Value]>([:]) + + func set(_ key: Key, _ value: Value) { + dict.withLock { @Sendable in + $0[key] = value + } + } + + func get(_ key: Key) -> Value? { + dict.withLock { @Sendable in + $0[key] + } + } + + func del(_ key: Key) { + dict.withLock { @Sendable in + _ = $0.removeValue(forKey: key) + } + } + } +} + +extension Epoll.Mask { + public var isHangup: Bool { + (self & (EPOLLHUP | EPOLLERR | EPOLLRDHUP)) != 0 + } + + public var readyToRead: Bool { + (self & EPOLLIN) != 0 + } + + public var readyToWrite: Bool { + (self & EPOLLOUT) != 0 + } +} + +#endif // os(Linux) diff --git a/Sources/ContainerizationOS/Mount/Mount.swift b/Sources/ContainerizationOS/Mount/Mount.swift new file mode 100644 index 00000000..5eac6964 --- /dev/null +++ b/Sources/ContainerizationOS/Mount/Mount.swift @@ -0,0 +1,206 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +#if canImport(Musl) +import Musl +private let _mount = Musl.mount +private let _umount = Musl.umount2 +#elseif canImport(Glibc) +import Glibc +private let _mount = Glibc.mount +private let _umount = Glibc.umount2 +#endif + +/// Mount package modeled closely from containerd's: https://github.com/containerd/containerd/tree/main/core/mount +/// Technically, this would be fine in the Linux subdirectory as it's Linux specific for now, but that +/// might not always be the case. + +public struct Mount: Sendable { + // Type specifies the host-specific of the mount. + public var type: String + // Source specifies where to mount from. Depending on the host system, this + // can be a source path or device. + public var source: String + // Target specifies an optional subdirectory as a mountpoint. + public var target: String + // Options contains zero or more fstab-style mount options. + public var options: [String] + + public init(type: String, source: String, target: String, options: [String]) { + self.type = type + self.source = source + self.target = target + self.options = options + } +} + +extension Mount { + internal struct FlagBehavior { + let clear: Bool + let flag: Int32 + + public init(_ clear: Bool, _ flag: Int32) { + self.clear = clear + self.flag = flag + } + } + + #if os(Linux) + internal static let flagsDictionary: [String: FlagBehavior] = [ + "async": .init(true, MS_SYNCHRONOUS), + "atime": .init(true, MS_NOATIME), + "bind": .init(false, MS_BIND), + "defaults": .init(false, 0), + "dev": .init(true, MS_NODEV), + "diratime": .init(true, MS_NODIRATIME), + "dirsync": .init(false, MS_DIRSYNC), + "exec": .init(true, MS_NOEXEC), + "mand": .init(false, MS_MANDLOCK), + "noatime": .init(false, MS_NOATIME), + "nodev": .init(false, MS_NODEV), + "nodiratime": .init(false, MS_NODIRATIME), + "noexec": .init(false, MS_NOEXEC), + "nomand": .init(true, MS_MANDLOCK), + "norelatime": .init(true, MS_RELATIME), + "nostrictatime": .init(true, MS_STRICTATIME), + "nosuid": .init(false, MS_NOSUID), + "rbind": .init(false, MS_BIND | MS_REC), + "relatime": .init(false, MS_RELATIME), + "remount": .init(false, MS_REMOUNT), + "ro": .init(false, MS_RDONLY), + "rw": .init(true, MS_RDONLY), + "strictatime": .init(false, MS_STRICTATIME), + "suid": .init(true, MS_NOSUID), + "sync": .init(false, MS_SYNCHRONOUS), + ] + + internal struct MountOptions { + var flags: Int32 + var data: [String] + + public init(_ flags: Int32 = 0, data: [String] = []) { + self.flags = flags + self.data = data + } + } + + public var readOnly: Bool { + for option in self.options { + if option == "ro" { + return true + } + } + return false + } + + private func mountToTarget(target: String, createWithPerms: Int16?) throws { + let pageSize = sysconf(_SC_PAGESIZE) + + let opts = parseMountOptions() + let dataString = opts.data.joined(separator: ",") + if dataString.count > pageSize { + throw Error.validation("data string exceeds page size (\(dataString.count) > \(pageSize))") + } + + let propagationTypes: Int32 = MS_SHARED | MS_PRIVATE | MS_SLAVE | MS_UNBINDABLE + + // Ensure propagation type change flags aren't included in other calls. + let originalFlags = opts.flags & ~(propagationTypes) + + let targetURL = URL(fileURLWithPath: self.target) + let targetParent = targetURL.deletingLastPathComponent().path + if let perms = createWithPerms { + try mkdirAll(targetParent, perms) + } + try mkdirAll(target, 0o755) + + if opts.flags & MS_REMOUNT == 0 || !dataString.isEmpty { + guard _mount(self.source, target, self.type, UInt(originalFlags), dataString) == 0 else { + throw Error.errno( + errno, + "failed initial mount source=\(self.source) target=\(target) type=\(self.type) data=\(dataString)" + ) + } + } + + if opts.flags & propagationTypes != 0 { + // Change the propagation type. + let pflags = propagationTypes | MS_REC | MS_SILENT + guard _mount("", target, "", UInt(opts.flags & pflags), "") == 0 else { + throw Error.errno(errno, "failed propagation change mount") + } + } + + let bindReadOnlyFlags = MS_BIND | MS_RDONLY + if originalFlags & bindReadOnlyFlags == bindReadOnlyFlags { + guard _mount("", target, "", UInt(originalFlags | MS_REMOUNT), "") == 0 else { + throw Error.errno(errno, "failed bind mount") + } + } + } + + public func mount(root: String, createWithPerms: Int16? = nil) throws { + var rootURL = URL(fileURLWithPath: root) + rootURL = rootURL.resolvingSymlinksInPath() + rootURL = rootURL.appendingPathComponent(self.target) + try self.mountToTarget(target: rootURL.path, createWithPerms: createWithPerms) + } + + public func mount(createWithPerms: Int16? = nil) throws { + try self.mountToTarget(target: self.target, createWithPerms: createWithPerms) + } + + private func mkdirAll(_ name: String, _ perm: Int16) throws { + try FileManager.default.createDirectory( + atPath: name, + withIntermediateDirectories: true, + attributes: [.posixPermissions: perm] + ) + } + + private func parseMountOptions() -> MountOptions { + var mountOpts = MountOptions() + for option in self.options { + if let entry = Self.flagsDictionary[option], entry.flag != 0 { + if entry.clear { + mountOpts.flags &= ~entry.flag + } else { + mountOpts.flags |= entry.flag + } + } else { + mountOpts.data.append(option) + } + } + return mountOpts + } + + public enum Error: Swift.Error, CustomStringConvertible { + case errno(Int32, String) + case validation(String) + + public var description: String { + switch self { + case .errno(let errno, let message): + return "mount failed with errno \(errno): \(message)" + case .validation(let message): + return "failed during validation: \(message)" + } + } + } + #endif +} diff --git a/Sources/ContainerizationOS/NSLock+Closure.swift b/Sources/ContainerizationOS/NSLock+Closure.swift new file mode 100644 index 00000000..defa5eeb --- /dev/null +++ b/Sources/ContainerizationOS/NSLock+Closure.swift @@ -0,0 +1,27 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +extension NSLock { + /// lock during the execution of the provided function + public func lock(_ fn: () throws -> T) rethrows -> T { + self.lock() + defer { self.unlock() } + + return try fn() + } +} diff --git a/Sources/ContainerizationOS/POSIXError+Helpers.swift b/Sources/ContainerizationOS/POSIXError+Helpers.swift new file mode 100644 index 00000000..c4127d97 --- /dev/null +++ b/Sources/ContainerizationOS/POSIXError+Helpers.swift @@ -0,0 +1,26 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +extension POSIXError { + public static func fromErrno() -> POSIXError { + guard let errCode = POSIXErrorCode(rawValue: errno) else { + fatalError("failed to convert errno to POSIXErrorCode") + } + return POSIXError(errCode) + } +} diff --git a/Sources/ContainerizationOS/Path.swift b/Sources/ContainerizationOS/Path.swift new file mode 100644 index 00000000..9ef0fa82 --- /dev/null +++ b/Sources/ContainerizationOS/Path.swift @@ -0,0 +1,72 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +public struct Path { + /// lookPath looks up an executable's path from $PATH + public static func lookPath(_ name: String) -> URL? { + lookup(name, path: getPath()) + } + + // getEnv returns the default environment of the process + // with the default $PATH added for the context of a macOS application bundle + public static func getEnv() -> [String: String] { + var env = ProcessInfo.processInfo.environment + env["PATH"] = getPath() + return env + } + + private static func lookup(_ name: String, path: String) -> URL? { + if name.contains("/") { + if findExec(name) { + return URL(fileURLWithPath: name) + } + return nil + } + + for var lookdir in path.split(separator: ":") { + if lookdir.isEmpty { + lookdir = "." + } + let file = URL(fileURLWithPath: String(lookdir)).appendingPathComponent(name) + if findExec(file.path) { + return file + } + } + return nil + } + + /// getPath returns $PATH for the current process + private static func getPath() -> String { + let env = ProcessInfo.processInfo.environment + return env["PATH"] ?? "/usr/local/bin:/usr/bin:/bin:/usr/sbin:/sbin" + } + + // findPath returns a string containing the 'PATH' environment variable + private static func findPath(_ env: [String]) -> String? { + env.first(where: { path in + let split = path.split(separator: "=") + return split.count == 2 && split[0] == "PATH" + }) + } + + // findExec returns true if the provided path is an executable + private static func findExec(_ path: String) -> Bool { + let fm = FileManager.default + return fm.isExecutableFile(atPath: path) + } +} diff --git a/Sources/ContainerizationOS/Pipe+Close.swift b/Sources/ContainerizationOS/Pipe+Close.swift new file mode 100644 index 00000000..9b2101dd --- /dev/null +++ b/Sources/ContainerizationOS/Pipe+Close.swift @@ -0,0 +1,43 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +extension Pipe { + /// Close both sides of the pipe. + public func close() throws { + var err: Swift.Error? + do { + try self.fileHandleForReading.close() + } catch { + err = error + } + try self.fileHandleForWriting.close() + if let err { + throw err + } + } + + /// Ensure that both sides of the pipe are set with O_CLOEXEC. + public func setCloexec() throws { + if fcntl(self.fileHandleForWriting.fileDescriptor, F_SETFD, FD_CLOEXEC) == -1 { + throw POSIXError(.init(rawValue: errno)!) + } + if fcntl(self.fileHandleForReading.fileDescriptor, F_SETFD, FD_CLOEXEC) == -1 { + throw POSIXError(.init(rawValue: errno)!) + } + } +} diff --git a/Sources/ContainerizationOS/README.md b/Sources/ContainerizationOS/README.md new file mode 100644 index 00000000..70277970 --- /dev/null +++ b/Sources/ContainerizationOS/README.md @@ -0,0 +1,3 @@ +## OS + +This target contains general useful OS related definitions or wrappers. \ No newline at end of file diff --git a/Sources/ContainerizationOS/RWLock.swift b/Sources/ContainerizationOS/RWLock.swift new file mode 100644 index 00000000..5c4d7cb3 --- /dev/null +++ b/Sources/ContainerizationOS/RWLock.swift @@ -0,0 +1,83 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +#if canImport(Musl) +import Musl +#elseif canImport(Glibc) +import Glibc +#elseif canImport(Darwin) +import Darwin +#else +#error("RWLock unsupported on this platform.") +#endif + +public final class RWLock: @unchecked Sendable { + private var rwlock = pthread_rwlock_t() + + public init() { + withUnsafeMutablePointer(to: &self.rwlock) { ptr in + guard pthread_rwlock_init(ptr, nil) == 0 else { + preconditionFailure("pthread rwlock failed to initialize") + } + } + } + + deinit { + withUnsafeMutablePointer(to: &self.rwlock) { ptr in + guard pthread_rwlock_destroy(ptr) == 0 else { + preconditionFailure("pthread rwlock failed to destroy") + } + } + } + + public func lock(_ fn: () throws -> T) rethrows -> T { + self.lock() + defer { self.unlock() } + + return try fn() + } + + public func rlock(_ fn: () throws -> T) rethrows -> T { + self.rlock() + defer { self.unlock() } + + return try fn() + } + + public func lock() { + withUnsafeMutablePointer(to: &self.rwlock) { ptr in + guard pthread_rwlock_wrlock(ptr) == 0 else { + preconditionFailure("pthread rwlock wrlock failed") + } + } + } + + public func rlock() { + withUnsafeMutablePointer(to: &self.rwlock) { ptr in + guard pthread_rwlock_rdlock(ptr) == 0 else { + preconditionFailure("pthread rwlock rdlock failed") + } + } + } + + public func unlock() { + withUnsafeMutablePointer(to: &self.rwlock) { ptr in + guard pthread_rwlock_unlock(ptr) == 0 else { + preconditionFailure("pthread rwlock unlock failed") + } + } + } +} diff --git a/Sources/ContainerizationOS/Reaper.swift b/Sources/ContainerizationOS/Reaper.swift new file mode 100644 index 00000000..f8a117cb --- /dev/null +++ b/Sources/ContainerizationOS/Reaper.swift @@ -0,0 +1,49 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +/// A process reaper that returns exited processes along +/// with their exit status. +public struct Reaper { + /// Process's pid and exit status. + typealias Exit = (pid: Int32, status: Int32) + + /// Reap all pending processes and return the pid and exit status. + public static func reap() -> [Int32: Int32] { + var reaped = [Int32: Int32]() + while true { + guard let exit = wait() else { + return reaped + } + reaped[exit.pid] = exit.status + } + return reaped + } + + /// Returns the exit status of the last process that exited. + /// nil is returned when no pending processes exist. + private static func wait() -> Exit? { + var rus = rusage() + var ws = Int32() + + let pid = wait4(-1, &ws, WNOHANG, &rus) + if pid <= 0 { + return nil + } + return (pid: pid, status: Command.toExitStatus(ws)) + } +} diff --git a/Sources/ContainerizationOS/Signals.swift b/Sources/ContainerizationOS/Signals.swift new file mode 100644 index 00000000..7cceb432 --- /dev/null +++ b/Sources/ContainerizationOS/Signals.swift @@ -0,0 +1,135 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +public struct Signals { + public static func allNumeric() -> [Int32] { + Array(Signals.all.values) + } + + public static func parseSignal(_ signal: String) throws -> Int32 { + if let sig = Int32(signal) { + if !Signals.all.values.contains(sig) { + throw Error.invalidSignal(signal) + } + return sig + } + var signalUpper = signal.uppercased() + signalUpper.trimPrefix("SIG") + guard let sig = Signals.all[signalUpper] else { + throw Error.invalidSignal(signal) + } + return sig + } + + public enum Error: Swift.Error, CustomStringConvertible { + case invalidSignal(String) + + public var description: String { + switch self { + case .invalidSignal(let sig): + return "invalid signal: \(sig)" + } + } + } +} + +#if os(macOS) + +extension Signals { + /// all returns all signals for the current platform. + public static let all: [String: Int32] = [ + "ABRT": SIGABRT, + "ALRM": SIGALRM, + "BUS": SIGBUS, + "CHLD": SIGCHLD, + "CONT": SIGCONT, + "EMT": SIGEMT, + "FPE": SIGFPE, + "HUP": SIGHUP, + "ILL": SIGILL, + "INFO": SIGINFO, + "INT": SIGINT, + "IO": SIGIO, + "IOT": SIGIOT, + "KILL": SIGKILL, + "PIPE": SIGPIPE, + "PROF": SIGPROF, + "QUIT": SIGQUIT, + "SEGV": SIGSEGV, + "STOP": SIGSTOP, + "SYS": SIGSYS, + "TERM": SIGTERM, + "TRAP": SIGTRAP, + "TSTP": SIGTSTP, + "TTIN": SIGTTIN, + "TTOU": SIGTTOU, + "URG": SIGURG, + "USR1": SIGUSR1, + "USR2": SIGUSR2, + "VTALRM": SIGVTALRM, + "WINCH": SIGWINCH, + "XCPU": SIGXCPU, + "XFSZ": SIGXFSZ, + ] +} + +#endif + +#if os(Linux) + +extension Signals { + /// all returns all signals for the current platform. + public static let all: [String: Int32] = [ + "ABRT": SIGABRT, + "ALRM": SIGALRM, + "BUS": SIGBUS, + "CHLD": SIGCHLD, + "CLD": SIGCHLD, + "CONT": SIGCONT, + "FPE": SIGFPE, + "HUP": SIGHUP, + "ILL": SIGILL, + "INT": SIGINT, + "IO": SIGIO, + "IOT": SIGIOT, + "KILL": SIGKILL, + "PIPE": SIGPIPE, + "POLL": SIGPOLL, + "PROF": SIGPROF, + "PWR": SIGPWR, + "QUIT": SIGQUIT, + "SEGV": SIGSEGV, + "STKFLT": SIGSTKFLT, + "STOP": SIGSTOP, + "SYS": SIGSYS, + "TERM": SIGTERM, + "TRAP": SIGTRAP, + "TSTP": SIGTSTP, + "TTIN": SIGTTIN, + "TTOU": SIGTTOU, + "URG": SIGURG, + "USR1": SIGUSR1, + "USR2": SIGUSR2, + "VTALRM": SIGVTALRM, + "WINCH": SIGWINCH, + "XCPU": SIGXCPU, + "XFSZ": SIGXFSZ, + ] +} + +#endif diff --git a/Sources/ContainerizationOS/Socket/Socket.swift b/Sources/ContainerizationOS/Socket/Socket.swift new file mode 100644 index 00000000..9a3458f9 --- /dev/null +++ b/Sources/ContainerizationOS/Socket/Socket.swift @@ -0,0 +1,382 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation +import SendableProperty + +#if canImport(Musl) +import Musl +#elseif canImport(Glibc) +import Glibc +#elseif canImport(Darwin) +import Darwin +#else +#error("Socket not supported on this platform.") +#endif + +#if !os(Windows) +let sysFchmod = fchmod +let sysRead = read +let sysUnlink = unlink +let sysSend = send +let sysClose = close +let sysShutdown = shutdown +let sysBind = bind +let sysSocket = socket +let sysSetsockopt = setsockopt +let sysGetsockopt = getsockopt +let sysListen = listen +let sysAccept = accept +let sysConnect = connect +let sysIoctl: @convention(c) (CInt, CUnsignedLong, UnsafeMutableRawPointer) -> CInt = ioctl +#endif + +public final class Socket: Sendable { + public enum TimeoutOption { + case send + case receive + } + + public enum ShutdownOption { + case read + case write + case readWrite + } + + private enum SocketState { + case created + case connected + case listening + } + + private struct State { + let socketState: SocketState + let handle: FileHandle? + let type: SocketType + let acceptSource: DispatchSourceRead? + } + + private let _closeOnDeinit: Bool + private let _queue: DispatchQueue + + @SendableProperty + private var _state: State + + public var fileDescriptor: Int32 { + guard let handle = _state.handle else { + return -1 + } + return handle.fileDescriptor + } + + public convenience init(type: SocketType, closeOnDeinit: Bool = true) throws { + let sockFD = sysSocket(type.domain, type.type, 0) + if sockFD < 0 { + throw SocketError.withErrno("failed to create socket: \(sockFD)", errno: errno) + } + self.init(fd: sockFD, type: type, closeOnDeinit: closeOnDeinit) + } + + init(fd: Int32, type: SocketType, closeOnDeinit: Bool) { + _queue = DispatchQueue(label: "com.apple.containerization.socket") + _closeOnDeinit = closeOnDeinit + _state = State( + socketState: .created, + handle: FileHandle(fileDescriptor: fd, closeOnDealloc: false), + type: type, + acceptSource: nil + ) + } + + deinit { + if _closeOnDeinit { + try? close() + } + } +} + +extension Socket { + static func errnoToError(msg: String) -> SocketError { + SocketError.withErrno("\(msg) (\(_errnoString(errno)))", errno: errno) + } + + public func connect() throws { + guard let handle = _state.handle else { + throw SocketError.closed + } + + guard _state.socketState == .created else { + throw SocketError.invalidOperationOnSocket("connect") + } + + var res: Int32 = 0 + try _state.type.withSockAddr { (ptr, length) in + res = Syscall.retrying { + sysConnect(handle.fileDescriptor, ptr, length) + } + } + if res == -1 { + throw Socket.errnoToError(msg: "could not connect to socket \(_state.type)") + } + _state = State( + socketState: .connected, + handle: handle, + type: _state.type, + acceptSource: _state.acceptSource + ) + } + + public func listen() throws { + guard let handle = _state.handle else { + throw SocketError.closed + } + guard _state.socketState == .created else { + throw SocketError.invalidOperationOnSocket("listen") + } + + try _state.type.beforeBind(fd: handle.fileDescriptor) + + var rc: Int32 = 0 + try _state.type.withSockAddr { (ptr, length) in + rc = sysBind(handle.fileDescriptor, ptr, length) + } + if rc < 0 { + throw Socket.errnoToError(msg: "could not bind to \(_state.type)") + } + + try _state.type.beforeListen(fd: handle.fileDescriptor) + if sysListen(handle.fileDescriptor, SOMAXCONN) < 0 { + throw Socket.errnoToError(msg: "listen failed on \(_state.type)") + } + _state = State( + socketState: .listening, + handle: handle, + type: _state.type, + acceptSource: _state.acceptSource + ) + } + + public func close() throws { + // Already closed. + guard let handle = _state.handle else { + return + } + if let acceptSource = _state.acceptSource { + acceptSource.cancel() + } + try handle.close() + _state = State( + socketState: _state.socketState, + handle: nil, + type: _state.type, + acceptSource: nil + ) + } + + public func write(data: any DataProtocol) throws -> Int { + guard _state.socketState == .connected else { + throw SocketError.invalidOperationOnSocket("write") + } + + guard let handle = _state.handle else { + throw SocketError.closed + } + + if data.isEmpty { + return 0 + } + + try handle.write(contentsOf: data) + return data.count + } + + public func acceptStream(closeOnDeinit: Bool = true) throws -> AsyncThrowingStream { + guard _state.socketState == .listening else { + throw SocketError.invalidOperationOnSocket("accept") + } + + guard let handle = _state.handle else { + throw SocketError.closed + } + + guard _state.acceptSource == nil else { + throw SocketError.acceptStreamExists + } + + let source = DispatchSource.makeReadSource( + fileDescriptor: handle.fileDescriptor, + queue: _queue + ) + _state = State( + socketState: _state.socketState, + handle: handle, + type: _state.type, + acceptSource: source + ) + + return AsyncThrowingStream { cont in + source.setCancelHandler { + cont.finish() + } + source.setEventHandler(handler: { + if source.data == 0 { + source.cancel() + return + } + + do { + let connection = try self.accept(closeOnDeinit: closeOnDeinit) + cont.yield(connection) + } catch SocketError.closed { + source.cancel() + } catch { + cont.yield(with: .failure(error)) + source.cancel() + } + }) + source.activate() + } + } + + public func accept(closeOnDeinit: Bool = true) throws -> Socket { + guard _state.socketState == .listening else { + throw SocketError.invalidOperationOnSocket("accept") + } + + guard let handle = _state.handle else { + throw SocketError.closed + } + + let (clientFD, socketType) = try _state.type.accept(fd: handle.fileDescriptor) + return Socket( + fd: clientFD, + type: socketType, + closeOnDeinit: closeOnDeinit + ) + } + + public func read(buffer: inout Data) throws -> Int { + guard _state.socketState == .connected else { + throw SocketError.invalidOperationOnSocket("read") + } + + guard let handle = _state.handle else { + throw SocketError.closed + } + + var bytesRead = 0 + let bufferSize = buffer.count + try buffer.withUnsafeMutableBytes { pointer in + guard let baseAddress = pointer.baseAddress else { + throw SocketError.missingBaseAddress + } + + bytesRead = Syscall.retrying { + sysRead(handle.fileDescriptor, baseAddress, bufferSize) + } + if bytesRead < 0 { + throw Socket.errnoToError(msg: "Error reading from connection") + } else if bytesRead == 0 { + throw SocketError.closed + } + } + return bytesRead + } + + public func shutdown(how: ShutdownOption) throws { + guard let handle = _state.handle else { + throw SocketError.closed + } + + var howOpt: Int32 = 0 + switch how { + case .read: + howOpt = Int32(SHUT_RD) + case .write: + howOpt = Int32(SHUT_WR) + case .readWrite: + howOpt = Int32(SHUT_RDWR) + } + + if sysShutdown(handle.fileDescriptor, howOpt) < 0 { + throw Socket.errnoToError(msg: "shutdown failed") + } + } + + public func setSockOpt(sockOpt: Int32 = 0, ptr: UnsafeRawPointer, stride: UInt32) throws { + guard let handle = _state.handle else { + throw SocketError.closed + } + if setsockopt(handle.fileDescriptor, SOL_SOCKET, sockOpt, ptr, stride) < 0 { + throw Socket.errnoToError(msg: "failed to set sockopt") + } + } + + public func setTimeout(option: TimeoutOption, seconds: Int) throws { + guard let handle = _state.handle else { + throw SocketError.closed + } + + var sockOpt: Int32 = 0 + switch option { + case .receive: + sockOpt = SO_RCVTIMEO + case .send: + sockOpt = SO_SNDTIMEO + } + + var timer = timeval() + timer.tv_sec = seconds + timer.tv_usec = 0 + + if setsockopt( + handle.fileDescriptor, + SOL_SOCKET, + sockOpt, + &timer, + socklen_t(MemoryLayout.size) + ) < 0 { + throw Socket.errnoToError(msg: "failed to set read timeout") + } + } + + static func _errnoString(_ err: Int32?) -> String { + String(validatingCString: strerror(errno)) ?? "error: \(errno)" + } +} + +public enum SocketError: Error, Equatable, CustomStringConvertible { + case closed + case acceptStreamExists + case invalidOperationOnSocket(String) + case missingBaseAddress + case withErrno(_ msg: String, errno: Int32) + + public var description: String { + switch self { + case .closed: + return "socket: closed" + case .acceptStreamExists: + return "accept stream already exists" + case .invalidOperationOnSocket(let operation): + return "socket: invalid operation on socket '\(operation)'" + case .missingBaseAddress: + return "socket: missing base address" + case .withErrno(let msg, _): + return "socket: error \(msg)" + } + } +} diff --git a/Sources/ContainerizationOS/Socket/SocketType.swift b/Sources/ContainerizationOS/Socket/SocketType.swift new file mode 100644 index 00000000..563334e9 --- /dev/null +++ b/Sources/ContainerizationOS/Socket/SocketType.swift @@ -0,0 +1,45 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +#if canImport(Musl) +import Musl +#elseif canImport(Glibc) +import Glibc +#elseif canImport(Darwin) +import Darwin +#else +#error("SocketType not supported on this platform.") +#endif + +public protocol SocketType: Sendable, CustomStringConvertible { + var domain: Int32 { get } + var type: Int32 { get } + + // Different socket types may want to expose things to do + // before bind and listen. UDS for example may want to change + // the permissions of the socket prior to bind/listen and also + // possibly unlink an existing socket before bind. + func beforeBind(fd: Int32) throws + func beforeListen(fd: Int32) throws + + func accept(fd: Int32) throws -> (Int32, SocketType) + func withSockAddr(_ closure: (_ ptr: UnsafePointer, _ len: UInt32) throws -> Void) throws +} + +extension SocketType { + public func beforeBind(fd: Int32) {} + public func beforeListen(fd: Int32) {} +} diff --git a/Sources/ContainerizationOS/Socket/UnixType.swift b/Sources/ContainerizationOS/Socket/UnixType.swift new file mode 100644 index 00000000..913582c5 --- /dev/null +++ b/Sources/ContainerizationOS/Socket/UnixType.swift @@ -0,0 +1,158 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +#if canImport(Musl) +import Musl +let _SOCK_STREAM = SOCK_STREAM +#elseif canImport(Glibc) +import Glibc +let _SOCK_STREAM = Int32(SOCK_STREAM.rawValue) +#elseif canImport(Darwin) +import Darwin +let _SOCK_STREAM = SOCK_STREAM +#else +#error("UnixType not supported on this platform.") +#endif + +public struct UnixType: SocketType, Sendable, CustomStringConvertible { + public var domain: Int32 { AF_UNIX } + public var type: Int32 { _SOCK_STREAM } + public var description: String { + path + } + + public let path: String + public let perms: mode_t? + private let _addr: sockaddr_un + private let _unlinkExisting: Bool + + private init(sockaddr: sockaddr_un) { + let pathname: String = withUnsafePointer(to: sockaddr.sun_path) { ptr in + let charPtr = UnsafeRawPointer(ptr).assumingMemoryBound(to: CChar.self) + return String(cString: charPtr) + } + self._addr = sockaddr + self.path = pathname + self._unlinkExisting = false + self.perms = nil + } + + /// Mode and unlinkExisting only used if the socket is going to be a listening socket. + public init( + path: String, + perms: mode_t? = nil, + unlinkExisting: Bool = false + ) throws { + self.path = path + self.perms = perms + self._unlinkExisting = unlinkExisting + var addr = sockaddr_un() + addr.sun_family = sa_family_t(AF_UNIX) + + let socketName = path + let nameLength = socketName.utf8.count + + #if os(macOS) + // Funnily enough, this isn't limited by sun path on macOS even though + // it's stated as so. + let lengthLimit = 253 + #elseif os(Linux) + let lengthLimit = MemoryLayout.size(ofValue: addr.sun_path) + #endif + + guard nameLength < lengthLimit else { + throw Error.nameTooLong(path) + } + + _ = withUnsafeMutablePointer(to: &addr.sun_path.0) { ptr in + socketName.withCString { strncpy(ptr, $0, nameLength) } + } + + #if os(macOS) + addr.sun_len = UInt8(MemoryLayout.size + MemoryLayout.size + socketName.utf8.count + 1) + #endif + self._addr = addr + } + + public func accept(fd: Int32) throws -> (Int32, SocketType) { + var clientFD: Int32 = -1 + var addr = sockaddr_un() + + clientFD = Syscall.retrying { + var size = socklen_t(MemoryLayout.stride) + return withUnsafeMutablePointer(to: &addr) { pointer in + pointer.withMemoryRebound(to: sockaddr.self, capacity: 1) { pointer in + sysAccept(fd, pointer, &size) + } + } + } + if clientFD < 0 { + throw Socket.errnoToError(msg: "accept failed") + } + + return (clientFD, UnixType(sockaddr: addr)) + } + + public func beforeBind(fd: Int32) throws { + #if os(Linux) + // Only Linux supports setting the mode of a socket before binding. + if let perms = self.perms { + guard fchmod(fd, perms) == 0 else { + throw Socket.errnoToError(msg: "fchmod failed") + } + } + #endif + + var rc: Int32 = 0 + if self._unlinkExisting { + rc = sysUnlink(self.path) + if rc != 0 && errno != ENOENT { + throw Socket.errnoToError(msg: "failed to remove old socket at \(self.path)") + } + } + } + + public func beforeListen(fd: Int32) throws { + #if os(macOS) + if let perms = self.perms { + guard chmod(self.path, perms) == 0 else { + throw Socket.errnoToError(msg: "chmod failed") + } + } + #endif + } + + public func withSockAddr(_ closure: (UnsafePointer, UInt32) throws -> Void) throws { + var addr = self._addr + try withUnsafePointer(to: &addr) { + let addrBytes = UnsafeRawPointer($0).assumingMemoryBound(to: sockaddr.self) + try closure(addrBytes, UInt32(MemoryLayout.stride)) + } + } +} + +extension UnixType { + public enum Error: Swift.Error, CustomStringConvertible { + case nameTooLong(_: String) + + public var description: String { + switch self { + case .nameTooLong(let name): + return "\(name) is too long for a Unix Domain Socket path" + } + } + } +} diff --git a/Sources/ContainerizationOS/Socket/VsockType.swift b/Sources/ContainerizationOS/Socket/VsockType.swift new file mode 100644 index 00000000..17174e70 --- /dev/null +++ b/Sources/ContainerizationOS/Socket/VsockType.swift @@ -0,0 +1,107 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import CShim + +#if canImport(Musl) +import Musl +#elseif canImport(Glibc) +import Glibc +#elseif canImport(Darwin) +import Darwin +#else +#error("VsockType not supported on this platform.") +#endif + +public struct VsockType: SocketType, Sendable { + public var domain: Int32 { AF_VSOCK } + public var type: Int32 { _SOCK_STREAM } + public var description: String { + "\(cid):\(port)" + } + + public static let anyCID: UInt32 = UInt32(bitPattern: -1) + public static let hypervisorCID: UInt32 = 0x0 + // Supported on Linux 5.6+, otherwise will need to use getLocalCID(). + public static let localCID: UInt32 = 0x1 + public static let hostCID: UInt32 = 0x2 + + // socketFD is unused on Linux. + public static func getLocalCID(socketFD: Int32) throws -> UInt32 { + let request = VsockLocalCIDIoctl + #if os(Linux) + let fd = open("/dev/vsock", O_RDONLY | O_CLOEXEC) + if fd == -1 { + throw Socket.errnoToError(msg: "failed to open /dev/vsock") + } + defer { close(fd) } + #else + let fd = socketFD + #endif + var cid: UInt32 = 0 + guard sysIoctl(fd, numericCast(request), &cid) != -1 else { + throw Socket.errnoToError(msg: "failed to get local cid") + } + return cid + } + + public let port: UInt32 + public let cid: UInt32 + + private let _addr: sockaddr_vm + + public init(port: UInt32, cid: UInt32) { + self.cid = cid + self.port = port + var sockaddr = sockaddr_vm() + sockaddr.svm_family = sa_family_t(AF_VSOCK) + sockaddr.svm_cid = cid + sockaddr.svm_port = port + self._addr = sockaddr + } + + private init(sockaddr: sockaddr_vm) { + self._addr = sockaddr + self.cid = sockaddr.svm_cid + self.port = sockaddr.svm_port + } + + public func accept(fd: Int32) throws -> (Int32, SocketType) { + var clientFD: Int32 = -1 + var addr = sockaddr_vm() + + while clientFD < 0 { + var size = socklen_t(MemoryLayout.stride) + clientFD = withUnsafeMutablePointer(to: &addr) { pointer in + pointer.withMemoryRebound(to: sockaddr.self, capacity: 1) { pointer in + sysAccept(fd, pointer, &size) + } + } + if clientFD < 0 && errno != EINTR { + throw Socket.errnoToError(msg: "accept failed") + } + } + return (clientFD, VsockType(sockaddr: addr)) + } + + public func withSockAddr(_ closure: (UnsafePointer, UInt32) throws -> Void) throws { + var addr = self._addr + try withUnsafePointer(to: &addr) { + let addrBytes = UnsafeRawPointer($0).assumingMemoryBound(to: sockaddr.self) + try closure(addrBytes, UInt32(MemoryLayout.stride)) + } + } +} diff --git a/Sources/ContainerizationOS/Syscall.swift b/Sources/ContainerizationOS/Syscall.swift new file mode 100644 index 00000000..7eb49622 --- /dev/null +++ b/Sources/ContainerizationOS/Syscall.swift @@ -0,0 +1,38 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +#if canImport(Musl) +import Musl +#elseif canImport(Glibc) +import Glibc +#elseif canImport(Darwin) +import Darwin +#else +#error("retryingSyscall not supported on this platform.") +#endif + +public struct Syscall { + /// Retry a syscall on EINTR. + public static func retrying(_ closure: () -> T) -> T { + while true { + let res = closure() + if res == -1 && errno == EINTR { + continue + } + return res + } + } +} diff --git a/Sources/ContainerizationOS/Sysctl.swift b/Sources/ContainerizationOS/Sysctl.swift new file mode 100644 index 00000000..504b90c7 --- /dev/null +++ b/Sources/ContainerizationOS/Sysctl.swift @@ -0,0 +1,31 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +public struct Sysctl { + #if os(macOS) + /// Simple `sysctlbyname` wrapper. + public static func byName(_ name: String) throws -> Int64 { + var num: Int64 = 0 + var size = MemoryLayout.size + if sysctlbyname(name, &num, &size, nil, 0) != 0 { + throw POSIXError.fromErrno() + } + return num + } + #endif +} diff --git a/Sources/ContainerizationOS/Terminal.swift b/Sources/ContainerizationOS/Terminal.swift new file mode 100644 index 00000000..65125c9d --- /dev/null +++ b/Sources/ContainerizationOS/Terminal.swift @@ -0,0 +1,207 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +public struct Terminal: Sendable { + private let initState: termios? + + private var descriptor: Int32 { + handle.fileDescriptor + } + public let handle: FileHandle + + public init(descriptor: Int32, setInitState: Bool = true) throws { + if setInitState { + self.initState = try Self.getattr(descriptor) + } else { + initState = nil + } + self.handle = .init(fileDescriptor: descriptor, closeOnDealloc: false) + } + + /// Write the provided data to the tty device. + public func write(_ data: Data) throws { + try handle.write(contentsOf: data) + } + + /// the winsize for a pty + public struct Size: Sendable { + let size: winsize + + /// width or `col` of the pty + public var width: UInt16 { + size.ws_col + } + /// height or `rows` of the pty + public var height: UInt16 { + size.ws_row + } + + init(_ size: winsize) { + self.size = size + } + + /// set the size for use with a pty + public init(width cols: UInt16, height rows: UInt16) { + self.size = winsize(ws_row: rows, ws_col: cols, ws_xpixel: 0, ws_ypixel: 0) + } + } + + /// return the current pty attached to any of the STDIO descriptors + public static var current: Terminal { + get throws { + for i in [STDERR_FILENO, STDOUT_FILENO, STDIN_FILENO] { + do { + return try Terminal(descriptor: i) + } catch {} + } + throw Error.notAPty + } + } + + /// the current window size for the pty + public var size: Size { + get throws { + var ws = winsize() + try fromSyscall(ioctl(descriptor, UInt(TIOCGWINSZ), &ws)) + return Size(ws) + } + } + + /// create a new pty pair + /// + /// - Parameter initialSize: initial size of the child pty + public static func create(initialSize: Size? = nil) throws -> (parent: Terminal, child: Terminal) { + var parent: Int32 = 0 + var child: Int32 = 0 + let size = initialSize ?? Size(width: 120, height: 40) + var ws = size.size + + try fromSyscall(openpty(&parent, &child, nil, nil, &ws)) + return ( + parent: try Terminal(descriptor: parent, setInitState: false), + child: try Terminal(descriptor: child, setInitState: false) + ) + } +} + +// MARK: Errors + +extension Terminal { + public enum Error: Swift.Error, CustomStringConvertible { + case notAPty + + public var description: String { + switch self { + case .notAPty: + return "the provided fd is not a pty" + } + } + } +} + +extension Terminal { + /// resize the current pty from the size of the provided pty + /// + /// - Parameter from: a pty to resize from + public func resize(from pty: Terminal) throws { + var ws = try pty.size + try fromSyscall(ioctl(descriptor, UInt(TIOCSWINSZ), &ws)) + } + + /// resize the pty to the provided window size + /// + /// - Parameter size: window size for a pty + public func resize(size: Size) throws { + var ws = size.size + try fromSyscall(ioctl(descriptor, UInt(TIOCSWINSZ), &ws)) + } + + /// resize the pty to the provided window size + /// + /// - Parameter width: width or cols of the terminal + /// - Parameter height: height or rows of the terminal + public func resize(width: UInt16, height: UInt16) throws { + var ws = Size(width: width, height: height) + try fromSyscall(ioctl(descriptor, UInt(TIOCSWINSZ), &ws)) + } +} + +extension Terminal { + /// enable raw mode for the pty + public func setraw() throws { + var attr = try Self.getattr(descriptor) + cfmakeraw(&attr) + attr.c_oflag = attr.c_oflag | tcflag_t(OPOST) + try fromSyscall(tcsetattr(descriptor, TCSANOW, &attr)) + } + + /// enable echo support + /// + /// chars typed WILL be displayed to the term + public func enableEcho() throws { + var attr = try Self.getattr(descriptor) + attr.c_iflag &= ~tcflag_t(ICRNL) + attr.c_lflag &= ~tcflag_t(ICANON | ECHO) + try fromSyscall(tcsetattr(descriptor, TCSANOW, &attr)) + } + + /// disable echo support + /// + /// chars typed WILL NOT be displayed back to the term + public func disableEcho() throws { + var attr = try Self.getattr(descriptor) + attr.c_lflag &= ~tcflag_t(ECHO) + try fromSyscall(tcsetattr(descriptor, TCSANOW, &attr)) + } + + private static func getattr(_ fd: Int32) throws -> termios { + var attr = termios() + try fromSyscall(tcgetattr(fd, &attr)) + return attr + } +} + +// MARK: reset + +extension Terminal { + /// close this pty's file descriptor + public func close() throws { + try fromSyscall(Foundation.close(self.descriptor)) + } + + /// reset the pty to its initial state + public func reset() throws { + if var attr = initState { + try fromSyscall(tcsetattr(descriptor, TCSANOW, &attr)) + } + } + + /// reset the pty to its initial state masking any errors + /// + /// This is commonly used in a `defer` to reset the current Pty + /// where the error code is not generally useful. + public func tryReset() { + try? reset() + } +} + +private func fromSyscall(_ status: Int32) throws { + guard status == 0 else { + throw POSIXError(.init(rawValue: errno)!) + } +} diff --git a/Sources/ContainerizationOS/URL+Extensions.swift b/Sources/ContainerizationOS/URL+Extensions.swift new file mode 100644 index 00000000..c0c5ac86 --- /dev/null +++ b/Sources/ContainerizationOS/URL+Extensions.swift @@ -0,0 +1,53 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +/// The `resolvingSymlinksInPath` method of the `URL` struct does not resolve the symlinks +/// for directories under `/private` which include`tmp`, `var` and `etc` +/// hence adding a method to build up on the existing `resolvingSymlinksInPath` that prepends `/private` to those paths +extension URL { + /// returns the unescaped absolutePath of a URL joined by separator + func absolutePath(_ separator: String = "/") -> String { + self.pathComponents + .joined(separator: separator) + .dropFirst("/".count) + .description + } + + public func resolvingSymlinksInPathWithPrivate() -> URL { + let url = self.resolvingSymlinksInPath() + #if os(macOS) + let parts = url.pathComponents + if parts.count > 1 { + if (parts.first == "/") && ["tmp", "var", "etc"].contains(parts[1]) { + if let resolved = NSURL.fileURL(withPathComponents: ["/", "private"] + parts[1...]) { + return resolved + } + } + } + #endif + return url + } + + public var isDirectory: Bool { + (try? resourceValues(forKeys: [.isDirectoryKey]))?.isDirectory == true + } + + public var isSymlink: Bool { + (try? resourceValues(forKeys: [.isSymbolicLinkKey]))?.isSymbolicLink == true + } +} diff --git a/Sources/ContainerizationOS/User.swift b/Sources/ContainerizationOS/User.swift new file mode 100644 index 00000000..ee306b7e --- /dev/null +++ b/Sources/ContainerizationOS/User.swift @@ -0,0 +1,220 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationError +import Foundation + +public enum User { + private static let passwdFile = "/etc/passwd" + private static let groupFile = "/etc/group" + + public struct ExecUser: Sendable { + public var uid: UInt32 + public var gid: UInt32 + public var sgids: [UInt32] + public var home: String + } + + private struct User { + let name: String + let password: String + let uid: UInt32 + let gid: UInt32 + let gecos: String + let home: String + let shell: String + + /// The argument `rawString` must follow the below format. + /// Name:Password:Uid:Gid:Gecos:Home:Shell + init(rawString: String) throws { + let args = rawString.split(separator: ":", omittingEmptySubsequences: false) + guard args.count == 7 else { + throw ContainerizationError.init(.invalidArgument, message: "Cannot parse User from '\(rawString)'") + } + guard let uid = UInt32(args[2]) else { + throw ContainerizationError.init(.invalidArgument, message: "Cannot parse uid from '\(args[2])'") + } + guard let gid = UInt32(args[3]) else { + throw ContainerizationError.init(.invalidArgument, message: "Cannot parse gid from '\(args[3])'") + } + self.name = String(args[0]) + self.password = String(args[1]) + self.uid = uid + self.gid = gid + self.gecos = String(args[4]) + self.home = String(args[5]) + self.shell = String(args[6]) + } + } + + private struct Group { + let name: String + let password: String + let gid: UInt32 + let users: [String] + + /// The argument `rawString` must follow the below format. + /// Name:Password:Gid:user1,user2 + init(rawString: String) throws { + let args = rawString.split(separator: ":", omittingEmptySubsequences: false) + guard args.count == 4 else { + throw ContainerizationError.init(.invalidArgument, message: "Cannot parse Group from '\(rawString)'") + } + guard let gid = UInt32(args[2]) else { + throw ContainerizationError.init(.invalidArgument, message: "Cannot parse gid from '\(args[2])'") + } + self.name = String(args[0]) + self.password = String(args[1]) + self.gid = gid + self.users = args[3].split(separator: ",").map { String($0) } + } + } +} + +// MARK: Private methods + +extension User { + /// Parse the contents of the passwd file + private static func parsePasswd(passwdFile: URL) throws -> [User] { + var users: [User] = [] + try self.parse(file: passwdFile) { line in + let user = try User(rawString: line) + users.append(user) + } + return users + } + + /// Parse the contents of the group file + private static func parseGroup(groupFile: URL) throws -> [Group] { + var groups: [Group] = [] + try self.parse(file: groupFile) { line in + let group = try Group(rawString: line) + groups.append(group) + } + return groups + } + + private static func parse(file: URL, handler: (_ line: String) throws -> Void) throws { + let fm = FileManager.default + guard fm.fileExists(atPath: file.absolutePath()) else { + throw ContainerizationError(.notFound, message: "File \(file.absolutePath()) does not exist") + } + let content = try String(contentsOf: file, encoding: .ascii) + let lines = content.components(separatedBy: .newlines) + for line in lines { + guard !line.isEmpty else { + continue + } + try handler(line.trimmingCharacters(in: .whitespaces)) + } + } +} + +// MARK: Public methods + +extension User { + public static func parseUser(root: String, userString: String) throws -> ExecUser { + let defaultUser = ExecUser(uid: 0, gid: 0, sgids: [], home: "/") + guard !userString.isEmpty else { + return defaultUser + } + + let passwdPath = URL(filePath: root).appending(path: Self.passwdFile) + let groupPath = URL(filePath: root).appending(path: Self.groupFile) + let parts = userString.split(separator: ":", maxSplits: 1, omittingEmptySubsequences: false) + + let userArg = String(parts[0]) + let userIdArg = Int(userArg) + + guard FileManager.default.fileExists(atPath: passwdPath.absolutePath()) else { + guard let userIdArg else { + throw ContainerizationError(.internalError, message: "Cannot parse username \(userArg)") + } + let uid = UInt32(userIdArg) + guard parts.count > 1 else { + return ExecUser(uid: uid, gid: uid, sgids: [], home: "/") + } + guard let gid = UInt32(String(parts[1])) else { + throw ContainerizationError(.internalError, message: "Cannot parse user group from \(userString)") + } + return ExecUser(uid: uid, gid: gid, sgids: [], home: "/") + } + + let registeredUsers = try parsePasswd(passwdFile: passwdPath) + guard registeredUsers.count > 0 else { + throw ContainerizationError(.internalError, message: "No users configured in passwd file.") + } + let matches = registeredUsers.filter { registeredUser in + // Check for a match (either uid/name) against the configured users from the passwd file. + // We have to check both the uid and the name cause we dont know the type of `userString` + registeredUser.name == userArg || registeredUser.uid == (userIdArg ?? -1) + } + guard let match = matches.first else { + // We did not find a matching uid/username in the passwd file + throw ContainerizationError(.internalError, message: "Cannot find User '\(userArg)' in passwd file.") + } + + var user = ExecUser(uid: match.uid, gid: match.gid, sgids: [match.gid], home: match.home) + + guard !match.name.isEmpty else { + return user + } + let matchedUser = match.name + var groupArg = "" + var groupIdArg: Int? = nil + if parts.count > 1 { + groupArg = String(parts[1]) + groupIdArg = Int(groupArg) + } + + let registeredGroups: [Group] = { + do { + // Parse the /etc/group file for a list of registered groups. + // If the file is missing / malformed, we bail out + return try parseGroup(groupFile: groupPath) + } catch { + return [] + } + }() + guard registeredGroups.count > 0 else { + return user + } + let matchingGroups = registeredGroups.filter { registeredGroup in + if !groupArg.isEmpty { + return registeredGroup.gid == (groupIdArg ?? -1) || registeredGroup.name == groupArg + } + return registeredGroup.users.contains(matchedUser) || registeredGroup.gid == match.gid + } + guard matchingGroups.count > 0 else { + throw ContainerizationError(.internalError, message: "Cannot find Group '\(groupArg)' in groups file.") + } + // We have found a list of groups that match the group specified in the argument `userString`. + // Set the matched groups as the supplement groups for the user + if !groupArg.isEmpty { + // Reassign the user's group only we were explicitly asked for a group + user.gid = matchingGroups.first!.gid + user.sgids = matchingGroups.map { group in + group.gid + } + } else { + user.sgids.append( + contentsOf: matchingGroups.map { group in + group.gid + }) + } + return user + } +} diff --git a/Sources/Integration/ProcessTests.swift b/Sources/Integration/ProcessTests.swift new file mode 100644 index 00000000..794e2988 --- /dev/null +++ b/Sources/Integration/ProcessTests.swift @@ -0,0 +1,220 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ArgumentParser +import Containerization +import ContainerizationOCI +import Foundation +import Logging + +extension IntegrationSuite { + func testProcessTrue() async throws { + let id = "test-process-true" + + let bs = try await bootstrap() + let container = LinuxContainer( + id, + rootfs: bs.rootfs, + vmm: bs.vmm + ) + container.arguments = ["/bin/true"] + + try await container.create() + try await container.start() + + let status = try await container.wait() + try await container.stop() + + guard status == 0 else { + throw IntegrationError.assert(msg: "process status \(status) != 0") + } + } + + func testProcessFalse() async throws { + let id = "test-process-false" + + let bs = try await bootstrap() + let container = LinuxContainer(id, rootfs: bs.rootfs, vmm: bs.vmm) + container.arguments = ["/bin/false"] + + try await container.create() + try await container.start() + + let status = try await container.wait() + try await container.stop() + + guard status == 1 else { + throw IntegrationError.assert(msg: "process status \(status) != 1") + } + } + + final class BufferWriter: Writer { + nonisolated(unsafe) var data = Data() + + func write(_ data: Data) throws { + guard data.count > 0 else { + return + } + self.data.append(data) + } + } + + func testProcessEchoHi() async throws { + let id = "test-process-echo-hi" + let bs = try await bootstrap() + let container = LinuxContainer(id, rootfs: bs.rootfs, vmm: bs.vmm) + container.arguments = ["/bin/echo", "hi"] + + let buffer = BufferWriter() + container.stdout = buffer + + do { + try await container.create() + try await container.start() + + let status = try await container.wait() + try await container.stop() + + guard status == 0 else { + throw IntegrationError.assert(msg: "process status \(status) != 1") + } + + guard String(data: buffer.data, encoding: .utf8) == "hi\n" else { + throw IntegrationError.assert( + msg: "process should have returned on stdout 'hi' != '\(String(data: buffer.data, encoding: .utf8)!)") + } + } catch { + try? await container.stop() + throw error + } + } + + func testMultipleConcurrentProcesses() async throws { + let id = "test-concurrent-processes" + + let bs = try await bootstrap() + let container = LinuxContainer( + id, + rootfs: bs.rootfs, + vmm: bs.vmm + ) + container.arguments = ["/bin/sleep", "1000"] + + do { + try await container.create() + try await container.start() + + let execConfig = ContainerizationOCI.Process( + args: ["/bin/true"], + env: ["PATH=\(LinuxContainer.defaultPath)"] + ) + + try await withThrowingTaskGroup(of: Void.self) { group in + for i in 0...80 { + let exec = try await container.exec( + "exec-\(i)", + configuration: execConfig + ) + + group.addTask { + try await exec.start() + let status = try await exec.wait() + if status != 0 { + throw IntegrationError.assert(msg: "process status \(status) != 0") + } + try await exec.delete() + } + } + + // wait for all the exec'd processes. + try await group.waitForAll() + print("all group processes exit") + + // kill the init process. + try await container.kill(SIGKILL) + let status = try await container.wait() + try await container.stop() + print("\(status)") + } + } catch { + throw error + } + } + + func testProcessUser() async throws { + let id = "test-process-user" + + let bs = try await bootstrap() + let container = LinuxContainer( + id, + rootfs: bs.rootfs, + vmm: bs.vmm + ) + container.arguments = ["/usr/bin/id"] + container.user = .init(uid: 1, gid: 1, additionalGids: [1]) + + let buffer = BufferWriter() + container.stdout = buffer + + try await container.create() + try await container.start() + + let status = try await container.wait() + try await container.stop() + + guard status == 0 else { + throw IntegrationError.assert(msg: "process status \(status) != 0") + } + let expected = "uid=1(bin) gid=1(bin) groups=1(bin)" + + guard String(data: buffer.data, encoding: .utf8) == "\(expected)\n" else { + throw IntegrationError.assert( + msg: "process should have returned on stdout '\(expected)' != '\(String(data: buffer.data, encoding: .utf8)!)") + } + } + + func testHostname() async throws { + let id = "test-container-hostname" + + let bs = try await bootstrap() + let container = LinuxContainer( + id, + rootfs: bs.rootfs, + vmm: bs.vmm + ) + container.arguments = ["/bin/hostname"] + container.hostname = "foo-bar" + + let buffer = BufferWriter() + container.stdout = buffer + + try await container.create() + try await container.start() + + let status = try await container.wait() + try await container.stop() + + guard status == 0 else { + throw IntegrationError.assert(msg: "process status \(status) != 0") + } + let expected = "foo-bar" + + guard String(data: buffer.data, encoding: .utf8) == "\(expected)\n" else { + throw IntegrationError.assert( + msg: "process should have returned on stdout '\(expected)' != '\(String(data: buffer.data, encoding: .utf8)!)") + } + } +} diff --git a/Sources/Integration/Suite.swift b/Sources/Integration/Suite.swift new file mode 100644 index 00000000..db953068 --- /dev/null +++ b/Sources/Integration/Suite.swift @@ -0,0 +1,232 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ArgumentParser +import Containerization +import ContainerizationError +import ContainerizationExtras +import ContainerizationOCI +import ContainerizationOS +import Foundation +import Logging +import NIOCore + +let log = { + LoggingSystem.bootstrap(StreamLogHandler.standardError) + var log = Logger(label: "com.apple.containerization") + log.logLevel = .debug + return log +}() + +enum IntegrationError: Swift.Error { + case assert(msg: String) + case noOutput +} + +@main +struct IntegrationSuite: AsyncParsableCommand { + static let appRoot: URL = { + FileManager.default.urls( + for: .applicationSupportDirectory, + in: .userDomainMask + ).first! + .appendingPathComponent("com.apple.containerization") + }() + + private static let _contentStore: ContentStore = { + try! LocalContentStore(path: appRoot.appending(path: "content")) + }() + + private static var authentication: Authentication? { + guard let password = ProcessInfo.processInfo.environment["REGISTRY_TOKEN"], + let username = ProcessInfo.processInfo.environment["REGISTRY_USERNAME"] + else { + return nil + } + return BasicAuthentication(username: username, password: password) + } + + private static let _imageStore: ImageStore = { + try! ImageStore( + path: appRoot, + contentStore: contentStore + ) + }() + + static let _testDir: URL = { + FileManager.default.uniqueTemporaryDirectory(create: true) + }() + + static var testDir: URL { + _testDir + } + + static var imageStore: ImageStore { + _imageStore + } + + static var contentStore: ContentStore { + _contentStore + } + + static let kernelImage = "ghcr.io/apple-uat/kernel/linux:v6.1.68-1" + + static let initImage = "vminit:latest" + + @Option(name: .shortAndLong, help: "Path to a log file") + var bootlog: String + + static func binPath(name: String) -> URL { + URL(fileURLWithPath: FileManager.default.currentDirectoryPath) + .appendingPathComponent("bin") + .appendingPathComponent(name) + } + + func bootstrap() async throws -> (rootfs: Containerization.Mount, vmm: VirtualMachineManager) { + let reference = "ghcr.io/apple-uat/test-images/alpine:3.21" + let store = Self.imageStore + let kernelImage = try await store.getKernel(reference: Self.kernelImage, auth: Self.authentication) + var kernel = try await kernelImage.kernel(for: .linuxArm) + + let initImage = try await store.getInitImage(reference: Self.initImage) + let initfs = try await { + let p = Self.binPath(name: "init.block") + do { + return try await initImage.initBlock(at: p, for: .linuxArm) + } catch let err as ContainerizationError { + guard err.code == .exists else { + throw err + } + return .block( + format: "ext4", + source: p.absolutePath(), + destination: "/", + options: ["ro"] + ) + } + }() + + kernel.commandLine.addDebug() + let image = try await Self.fetchImage(reference: reference, store: store) + let platform = Platform(arch: "arm64", os: "linux", variant: "v8") + + let fs: Containerization.Mount = try await { + let fsPath = Self.testDir.appending(component: "rootfs.ext4") + do { + return try await image.unpack(for: platform, at: fsPath) + } catch let err as ContainerizationError { + if err.code == .exists { + return .block( + format: "ext4", + source: fsPath.absolutePath(), + destination: "/", + options: [] + ) + } + throw err + } + }() + + let clPath = Self.testDir.appending(component: "rn.ext4").absolutePath() + try? FileManager.default.removeItem(atPath: clPath) + + let cl = try fs.clone(to: clPath) + return ( + cl, + VZVirtualMachineManager( + kernel: kernel, + initialFilesystem: initfs, + bootlog: bootlog + ) + ) + } + + static func fetchImage(reference: String, store: ImageStore) async throws -> Containerization.Image { + do { + return try await store.get(reference: reference) + } catch let error as ContainerizationError { + if error.code == .notFound { + return try await store.pull(reference: reference, auth: Self.authentication) + } + throw error + } + } + + static func adjustLimits() throws { + var limits = rlimit() + guard getrlimit(RLIMIT_NOFILE, &limits) == 0 else { + throw POSIXError(.init(rawValue: errno)!) + } + limits.rlim_cur = 65536 + limits.rlim_max = 65536 + + guard setrlimit(RLIMIT_NOFILE, &limits) == 0 else { + throw POSIXError(.init(rawValue: errno)!) + } + } + + // Why does this exist? + // + // We need the virtualization entitlement to execute these tests. + // There currently does not exist a strightforward way to do this + // in a pure swift package. + // + // In order to not have a dependency on xcode, we create an executable + // for our integration tests that can be signed then ran. + // + // We also can't import Testing as it expects to be run from a runner. + // Hopefully this improves over time. + func run() async throws { + try Self.adjustLimits() + let suiteStarted = CFAbsoluteTimeGetCurrent() + log.info("starting integration suite\n") + + let tests: [String: () async throws -> Void] = [ + "process true": testProcessTrue, + "process false": testProcessFalse, + "process echo hi": testProcessEchoHi, + "process user": testProcessUser, + "test multiple concurrent processes": testMultipleConcurrentProcesses, + "test container hostname": testHostname, + "test container mount": testMounts, + "test nested virt": testNestedVirtualizationEnabled, + ] + + var passed = 0 + for (name, test) in tests { + do { + log.info("test \(name) started...") + + let started = CFAbsoluteTimeGetCurrent() + try await test() + let lasted = CFAbsoluteTimeGetCurrent() - started + log.info("✅ test \(name) complete in \(lasted)s.") + passed += 1 + } catch { + log.error("❌ test \(name) failed: \(error)") + } + } + + let ended = CFAbsoluteTimeGetCurrent() - suiteStarted + log.info("\nintegration suite completed in \(ended)s with \(passed)/\(tests.count) passed!") + + if passed < tests.count { + log.error("❌") + throw ExitCode(1) + } + try? FileManager.default.removeItem(at: Self.testDir) + } +} diff --git a/Sources/Integration/VMTests.swift b/Sources/Integration/VMTests.swift new file mode 100644 index 00000000..b558df4a --- /dev/null +++ b/Sources/Integration/VMTests.swift @@ -0,0 +1,87 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ArgumentParser +import Containerization +import ContainerizationOCI +import Foundation +import Logging + +extension IntegrationSuite { + func testMounts() async throws { + let id = "test-cat-mount" + + let bs = try await bootstrap() + let container = LinuxContainer( + id, + rootfs: bs.rootfs, + vmm: bs.vmm + ) + let directory = try createMountDirectory() + container.mounts.append(.share(source: directory.path, destination: "/mnt")) + container.arguments = ["/bin/cat", "/mnt/hi.txt"] + + let buffer = BufferWriter() + container.stdout = buffer + + try await container.create() + try await container.start() + + let status = try await container.wait() + try await container.stop() + + guard status == 0 else { + throw IntegrationError.assert(msg: "process status \(status) != 0") + } + + let value = String(data: buffer.data, encoding: .utf8) + guard value == "hello" else { + throw IntegrationError.assert( + msg: "process should have returned from file 'hello' != '\(String(data: buffer.data, encoding: .utf8)!)") + + } + } + + func testNestedVirtualizationEnabled() async throws { + let id = "test-nested-virt" + + let bs = try await bootstrap() + let container = LinuxContainer( + id, + rootfs: bs.rootfs, + vmm: bs.vmm + ) + container.arguments = ["/bin/true"] + + container.virtualization = true + + try await container.create() + try await container.start() + + let status = try await container.wait() + try await container.stop() + + guard status == 0 else { + throw IntegrationError.assert(msg: "process status \(status) != 0") + } + } + + private func createMountDirectory() throws -> URL { + let dir = FileManager.default.uniqueTemporaryDirectory(create: true) + try "hello".write(to: dir.appendingPathComponent("hi.txt"), atomically: true, encoding: .utf8) + return dir + } +} diff --git a/Sources/SendableProperty/SendableProperty.swift b/Sources/SendableProperty/SendableProperty.swift new file mode 100644 index 00000000..1aae0db4 --- /dev/null +++ b/Sources/SendableProperty/SendableProperty.swift @@ -0,0 +1,23 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// `Synchronization` will be automatically imported with `SendableProperty` +@_exported import Synchronization + +// A declaration of the `@SendableProperty` macro. +@attached(peer, names: arbitrary) +@attached(accessor) +public macro SendableProperty() = #externalMacro(module: "SendablePropertyMacros", type: "SendablePropertyMacro") diff --git a/Sources/SendablePropertyMacros/SendablePropertyError.swift b/Sources/SendablePropertyMacros/SendablePropertyError.swift new file mode 100644 index 00000000..9875f6aa --- /dev/null +++ b/Sources/SendablePropertyMacros/SendablePropertyError.swift @@ -0,0 +1,28 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +/// Errors that can be thrown by `@SendableProperty`. +enum SendablePropertyError: CustomStringConvertible, Error { + case unexpectedError + case onlyApplicableToVar + + var description: String { + switch self { + case .unexpectedError: return "@SendableProperty encountered an unexpected error" + case .onlyApplicableToVar: return "@SendableProperty can only be applied to a variable" + } + } +} diff --git a/Sources/SendablePropertyMacros/SendablePropertyMacro.swift b/Sources/SendablePropertyMacros/SendablePropertyMacro.swift new file mode 100644 index 00000000..511d677c --- /dev/null +++ b/Sources/SendablePropertyMacros/SendablePropertyMacro.swift @@ -0,0 +1,112 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation +import SwiftCompilerPlugin +import SwiftParser +import SwiftSyntax +import SwiftSyntaxBuilder +import SwiftSyntaxMacros +import Synchronization + +/// A macro that allows to make a property thread-safe keeping the `Sendable` conformance of the type. +public struct SendablePropertyMacro: PeerMacro { + private static func peerPropertyName(for propertyName: String) -> String { + "_" + propertyName + } + + /// The macro expansion that introduces a `Sendable`-conforming "peer" declaration for a thread-safe storage for the value of the given declaration of a variable. + /// - Parameters: + /// - node: The given attribute node. + /// - declaration: The given declaration. + /// - context: The macro expansion context. + public static func expansion( + of node: SwiftSyntax.AttributeSyntax, providingPeersOf declaration: some SwiftSyntax.DeclSyntaxProtocol, in context: some SwiftSyntaxMacros.MacroExpansionContext + ) throws -> [SwiftSyntax.DeclSyntax] { + guard let varDecl = declaration.as(VariableDeclSyntax.self), + let binding = varDecl.bindings.first, + let pattern = binding.pattern.as(IdentifierPatternSyntax.self) + else { + throw SendablePropertyError.onlyApplicableToVar + } + + let propertyName = pattern.identifier.text + let hasInitializer = binding.initializer != nil + let initializerValue = binding.initializer?.value.description ?? "nil" + + var genericTypeAnnotation = "" + if let typeAnnotation = binding.typeAnnotation { + let typeName = typeAnnotation.type.description.trimmingCharacters(in: CharacterSet.whitespacesAndNewlines) + genericTypeAnnotation = "<\(typeName)\(hasInitializer ? "" : "?")>" + } + + // Create a peer property + let peerPropertyName = self.peerPropertyName(for: propertyName) + // `Mutex` (requires macOS 15) and `OSAllocationUnfairLock` (requires macOS 13, unsupported on Linux) are more effective than `NSLock`. + let peerProperty: DeclSyntax = + """ + private let \(raw: peerPropertyName) = Mutex\(raw: genericTypeAnnotation)(\(raw: initializerValue)) + """ + return [peerProperty] + } +} + +extension SendablePropertyMacro: AccessorMacro { + /// The macro expansion that adds `Sendable`-conforming accessors to the given declaration of a variable. + /// - Parameters: + /// - node: The given attribute node. + /// - declaration: The given declaration. + /// - context: The macro expansion context. + public static func expansion( + of node: SwiftSyntax.AttributeSyntax, providingAccessorsOf declaration: some SwiftSyntax.DeclSyntaxProtocol, in context: some SwiftSyntaxMacros.MacroExpansionContext + ) throws -> [SwiftSyntax.AccessorDeclSyntax] { + guard let varDecl = declaration.as(VariableDeclSyntax.self), + let binding = varDecl.bindings.first, + let pattern = binding.pattern.as(IdentifierPatternSyntax.self) + else { + throw SendablePropertyError.onlyApplicableToVar + } + + let propertyName = pattern.identifier.text + let hasInitializer = binding.initializer != nil + + // Replace the property with an accessor + let peerPropertyName = Self.peerPropertyName(for: propertyName) + + let accessorGetter: AccessorDeclSyntax = + """ + get { + \(raw: peerPropertyName).withLock { $0\(raw: hasInitializer ? "" : "!") } + } + """ + // The `Sending` class is used as a temporary workaround for the error: "'inout sending' parameter '$0' cannot be task-isolated at end of function." + let accessorSetter: AccessorDeclSyntax = + """ + set { + class Sending: @unchecked Sendable { + let wrappedValue: T + init(_ value: T) { + wrappedValue = value + } + } + let newValue = Sending(newValue) + \(raw: peerPropertyName).withLock { $0 = newValue.wrappedValue } + } + """ + + return [accessorGetter, accessorSetter] + } +} diff --git a/Sources/SendablePropertyMacros/SendablePropertyPlugin.swift b/Sources/SendablePropertyMacros/SendablePropertyPlugin.swift new file mode 100644 index 00000000..58b42633 --- /dev/null +++ b/Sources/SendablePropertyMacros/SendablePropertyPlugin.swift @@ -0,0 +1,26 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import SwiftCompilerPlugin +import SwiftSyntaxMacros + +/// A plugin that registers the `SendablePropertyMacro`. +@main +struct SendablePropertyPlugin: CompilerPlugin { + let providingMacros: [Macro.Type] = [ + SendablePropertyMacro.self + ] +} diff --git a/Sources/cctl/ContainerStore.swift b/Sources/cctl/ContainerStore.swift new file mode 100644 index 00000000..aeae7878 --- /dev/null +++ b/Sources/cctl/ContainerStore.swift @@ -0,0 +1,151 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Containerization +import ContainerizationError +import ContainerizationOCI +import ContainerizationOS +import Foundation + +#if os(macOS) + +import Crypto + +extension String { + fileprivate func hash() throws -> String { + guard let data = self.data(using: .utf8) else { + fatalError("\(self) could not be converted to Data") + } + return String(SHA256.hash(data: data).encoded.prefix(36)) + } +} + +#endif + +public final class ContainerStore: Sendable { + private static let kernelImageReference: String = "ghcr.io/apple-uat/kernel/linux:v6.1.68-1" + private static let initImage = "vminit:latest" + + private let content: ContentStore + private let image: ImageStore + private let root: URL + + public let kernel: Kernel + + public init(root: URL, kernel: Kernel?) async throws { + self.root = root + let content = try LocalContentStore( + path: root.appendingPathComponent("content") + ) + self.content = content + self.image = try ImageStore( + path: root, + contentStore: content + ) + if let kernel { + self.kernel = kernel + } else { + self.kernel = try await Self.loadKernel(store: self.image) + } + } + + private static func loadKernel(store: ImageStore) async throws -> Kernel { + let kernelImage = try await store.getKernel( + reference: Self.kernelImageReference + ) + return try await kernelImage.kernel(for: .linuxArm) + } + + public func fetch(reference: String) async throws -> Containerization.Image { + do { + return try await self.image.get(reference: reference) + } catch let error as ContainerizationError { + if error.code == .notFound { + return try await self.image.pull(reference: reference) + } + throw error + } + } + + static func binPath(name: String) -> URL { + URL(fileURLWithPath: FileManager.default.currentDirectoryPath) + .appendingPathComponent("bin") + .appendingPathComponent(name) + } + + public func create(id: String, reference: String, fsSizeInBytes: UInt64) async throws -> LinuxContainer { + let initImage = try await image.getInitImage(reference: Self.initImage) + let initfs = try await { + let p = Self.binPath(name: "init.block") + do { + return try await initImage.initBlock(at: p, for: .linuxArm) + } catch let err as ContainerizationError { + guard err.code == .exists else { + throw err + } + return .block( + format: "ext4", + source: p.absolutePath(), + destination: "/", + options: ["ro"] + ) + } + }() + + let blockName = try reference.hash() + ".ext4" + let image = try await fetch(reference: reference) + let imageConfig = try await image.config(for: .current).config + + let imageBlock: Containerization.Mount = try await { + let source = self.root.appendingPathComponent(blockName) + do { + return try await image.unpack( + for: .current, + at: source, + blockSizeInBytes: fsSizeInBytes + ) + } catch let err as ContainerizationError { + if err.code == .exists { + return .block( + format: "ext4", + source: source.absolutePath(), + destination: "/", + options: [] + ) + } + throw err + } catch { + throw error + } + }() + + let vmm = VZVirtualMachineManager( + kernel: kernel, + initialFilesystem: initfs, + bootlog: "cctl.log" + ) + + let linuxContainer = LinuxContainer( + id, + rootfs: imageBlock, + vmm: vmm + ) + if let imageConfig { + linuxContainer.setProcessConfig(from: imageConfig) + } + return linuxContainer + } +} diff --git a/Sources/cctl/ImageCommand.swift b/Sources/cctl/ImageCommand.swift new file mode 100644 index 00000000..ede451e9 --- /dev/null +++ b/Sources/cctl/ImageCommand.swift @@ -0,0 +1,270 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ArgumentParser +import Containerization +import ContainerizationArchive +import ContainerizationError +import ContainerizationExtras +import ContainerizationOCI +import Foundation + +extension Application { + struct Images: AsyncParsableCommand { + static let configuration = CommandConfiguration( + commandName: "images", + abstract: "Manage images", + subcommands: [ + Get.self, + Delete.self, + Pull.self, + Tag.self, + Push.self, + Save.self, + Load.self, + ] + ) + + func run() async throws { + let store = Application.imageStore + let images = try await store.list() + + print("REFERENCE\tMEDIA TYPE\tDIGEST") + for image in images { + print("\(image.reference)\t\(image.mediaType)\t\(image.digest)") + } + } + + struct Delete: AsyncParsableCommand { + @Argument var reference: String + + func run() async throws { + let store = Application.imageStore + try await store.delete(reference: reference) + } + } + + struct Tag: AsyncParsableCommand { + @Argument var old: String + @Argument var new: String + + func run() async throws { + let store = Application.imageStore + _ = try await store.tag(existing: old, new: new) + } + } + + struct Get: AsyncParsableCommand { + @Argument var reference: String + + func run() async throws { + let store = Application.imageStore + let image = try await store.get(reference: reference) + + let index = try await image.index() + + let enc = JSONEncoder() + enc.outputFormatting = .prettyPrinted + let data = try enc.encode(ImageDisplay(reference: image.reference, index: index)) + print(String(data: data, encoding: .utf8)!) + } + } + + struct ImageDisplay: Codable { + let reference: String + let index: Index + } + + struct Pull: AsyncParsableCommand { + static let configuration = CommandConfiguration( + commandName: "pull", + abstract: "Pull an image's contents into a content store" + ) + + @Argument var ref: String + + @Option(name: .customLong("platform"), help: "Platform string in the form 'os/arch/variant'. Example 'linux/arm64/v8', 'linux/amd64'") var platformString: String? + + @Flag(help: "Pull via plain text http") var http: Bool = false + + func run() async throws { + let imageStore = Application.imageStore + let platform: Platform? = try { + if let platformString { + return try Platform(from: platformString) + } + return nil + }() + + let reference = try Reference.parse(ref) + reference.normalize() + let normalizedReference = reference.description + if normalizedReference != ref { + print("Reference resolved to \(reference.description)") + } + + let image = try await Images.withAuthentication(ref: normalizedReference) { auth in + try await imageStore.pull(reference: normalizedReference, platform: platform, insecure: http, auth: auth) + } + + guard let image else { + print("image pull failed") + Application.exit(withError: POSIXError(.EACCES)) + } + + print("image pulled") + + let tempDir = FileManager.default.uniqueTemporaryDirectory(create: true) + if let platform { + let name = platform.description.replacingOccurrences(of: "/", with: "-") + let _ = try await image.unpack(for: platform, at: tempDir.appending(component: name)) + } else { + for descriptor in try await image.index().manifests { + if let referenceType = descriptor.annotations?["vnd.docker.reference.type"], referenceType == "attestation-manifest" { + continue + } + guard let descPlatform = descriptor.platform else { + continue + } + let name = descPlatform.description.replacingOccurrences(of: "/", with: "-") + let _ = try await image.unpack(for: descPlatform, at: tempDir.appending(component: name)) + print("created snapshot for platform \(descPlatform.description)") + } + } + try? FileManager.default.removeItem(at: tempDir) + } + } + + struct Push: AsyncParsableCommand { + static let configuration = CommandConfiguration( + commandName: "push", + abstract: "Push an image to a remote registry" + ) + + @Option(help: "Platform string in the form 'os/arch/variant'. Example 'linux/arm64/v8', 'linux/amd64'") var platformString: String? + + @Flag(help: "Push via plain text http") var http: Bool = false + + @Argument var ref: String + + func run() async throws { + let imageStore = Application.imageStore + let platform: Platform? = try { + if let platformString { + return try Platform(from: platformString) + } + return nil + }() + + let reference = try Reference.parse(ref) + reference.normalize() + let normalizedReference = reference.description + if normalizedReference != ref { + print("Reference resolved to \(reference.description)") + } + + try await Images.withAuthentication(ref: normalizedReference) { auth in + try await imageStore.push(reference: normalizedReference, platform: platform, insecure: http, auth: auth) + } + print("image pushed") + } + } + + struct Save: AsyncParsableCommand { + static let configuration = CommandConfiguration( + commandName: "save", + abstract: "Save one or more images to a tar archive" + ) + + @Option(help: "Platform string in the form 'os/arch/variant'. Example 'linux/arm64/v8', 'linux/amd64'") var platform: String? + + @Option(name: .shortAndLong, help: "Path to tar archive") + var output: String + + @Argument var reference: [String] + + func run() async throws { + var p: Platform? = nil + if let platform { + p = try Platform(from: platform) + } + let store = Application.imageStore + let tempDir = FileManager.default.uniqueTemporaryDirectory() + defer { + try? FileManager.default.removeItem(at: tempDir) + } + try await store.save(references: reference, out: tempDir, platform: p) + let writer = try ArchiveWriter(format: .pax, filter: .none, file: URL(filePath: output)) + try writer.archiveDirectory(tempDir) + try writer.finishEncoding() + print("image exported") + } + } + + struct Load: AsyncParsableCommand { + static let configuration = CommandConfiguration( + commandName: "load", + abstract: "Load one or more images from a tar archive" + ) + + @Option(name: .shortAndLong, help: "Path to tar archive") + var input: String + + func run() async throws { + let store = Application.imageStore + let tarFile = URL(fileURLWithPath: input) + let reader = try ArchiveReader(file: tarFile.absoluteURL) + let tempDir = FileManager.default.uniqueTemporaryDirectory() + defer { + try? FileManager.default.removeItem(at: tempDir) + } + try reader.extractContents(to: tempDir) + let imported = try await store.load(from: tempDir) + for image in imported { + print("imported \(image.reference)") + } + } + } + + private static func withAuthentication( + ref: String, _ body: @Sendable @escaping (_ auth: Authentication?) async throws -> T? + ) async throws -> T? { + var authentication: Authentication? + let ref = try Reference.parse(ref) + guard let host = ref.resolvedDomain else { + throw ContainerizationError(.invalidArgument, message: "No host specified in image reference") + } + authentication = Self.authenticationFromEnv(host: host) + if let authentication { + return try await body(authentication) + } + let keychain = KeychainHelper(id: Application.keychainID) + authentication = try? keychain.lookup(domain: host) + return try await body(authentication) + } + + private static func authenticationFromEnv(host: String) -> Authentication? { + let env = ProcessInfo.processInfo.environment + guard env["REGISTRY_HOST"] == host else { + return nil + } + guard let user = env["REGISTRY_USERNAME"], let password = env["REGISTRY_TOKEN"] else { + return nil + } + return BasicAuthentication(username: user, password: password) + } + } +} diff --git a/Sources/cctl/KernelCommand.swift b/Sources/cctl/KernelCommand.swift new file mode 100644 index 00000000..5e833f53 --- /dev/null +++ b/Sources/cctl/KernelCommand.swift @@ -0,0 +1,81 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ArgumentParser +import Containerization +import Foundation + +extension Application { + struct KernelCommand: AsyncParsableCommand { + static let configuration = CommandConfiguration( + commandName: "kernel", + abstract: "Manage kernel images", + subcommands: [ + Create.self + ] + ) + + struct Create: AsyncParsableCommand { + @Option(name: .shortAndLong, help: "Name for the kernel image") + var name: String + + @Option(name: .long, help: "Labels to add to the built image of the form =, [=,...]") + var labels: [String] = [] + + @Argument var kernels: [String] + + func run() async throws { + let imageStore = Application.imageStore + let contentStore = Application.contentStore + let labels = Application.parseKeyValuePairs(from: labels) + let binaries = try parseBinaries() + _ = try await KernelImage.create( + reference: name, + binaries: binaries, + labels: labels, + imageStore: imageStore, + contentStore: contentStore + ) + } + + func parseBinaries() throws -> [Kernel] { + var binaries = [Kernel]() + for rawBinary in kernels { + let parts = rawBinary.split(separator: ":") + guard parts.count == 2 else { + throw "Invalid binary format: \(rawBinary)" + } + let platform: SystemPlatform + switch parts[1] { + case "arm64": + platform = .linuxArm + case "amd64": + platform = .linuxAmd + default: + fatalError("unsupported platform \(parts[1])") + } + binaries.append( + .init( + path: URL(fileURLWithPath: String(parts[0])), + platform: platform + ) + ) + } + return binaries + } + } + } +} diff --git a/Sources/cctl/LoginCommand.swift b/Sources/cctl/LoginCommand.swift new file mode 100644 index 00000000..5e12245f --- /dev/null +++ b/Sources/cctl/LoginCommand.swift @@ -0,0 +1,84 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ArgumentParser +import Containerization +import ContainerizationError +import ContainerizationOCI +import Foundation + +extension Application { + struct Login: AsyncParsableCommand { + + static let configuration = CommandConfiguration( + commandName: "login", + abstract: "Login to a registry" + ) + + @OptionGroup() var application: Application + + @Option(name: .shortAndLong, help: "Username") + var username: String = "" + + @Flag(help: "Take the password from stdin") + var passwordStdin: Bool = false + + @Argument(help: "Registry server name") + var server: String + + @Flag(help: "Use plain text http to authenticate") var http: Bool = false + + func run() async throws { + var username = self.username + var password = "" + if passwordStdin { + if username == "" { + throw ContainerizationError(.invalidArgument, message: "must provide --username with --password-stdin") + } + guard let passwordData = try FileHandle.standardInput.readToEnd() else { + throw ContainerizationError(.invalidArgument, message: "failed to read password from stdin") + } + password = String(decoding: passwordData, as: UTF8.self).trimmingCharacters(in: .whitespacesAndNewlines) + } + let keychain = KeychainHelper(id: Application.keychainID) + if username == "" { + username = try keychain.userPrompt(domain: server) + } + if password == "" { + password = try keychain.passwordPrompt() + print() + } + + let server = Reference.resolveDomain(domain: self.server) + let scheme = http ? "http" : "https" + let client = RegistryClient( + host: server, + scheme: scheme, + authentication: BasicAuthentication(username: username, password: password), + retryOptions: .init( + maxRetries: 10, + retryInterval: 300_000_000, + shouldRetry: ({ response in + response.status.code >= 500 + }) + ) + ) + try await client.ping() + try keychain.save(domain: server, username: username, password: password) + print("Login succeeded") + } + } +} diff --git a/Sources/cctl/RootfsCommand.swift b/Sources/cctl/RootfsCommand.swift new file mode 100644 index 00000000..b1801a00 --- /dev/null +++ b/Sources/cctl/RootfsCommand.swift @@ -0,0 +1,116 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ArgumentParser +import Containerization +import ContainerizationArchive +import ContainerizationEXT4 +import ContainerizationError +import ContainerizationOCI +import ContainerizationOS +import Foundation + +extension Application { + struct Rootfs: AsyncParsableCommand { + static let configuration = CommandConfiguration( + commandName: "rootfs", + abstract: "Manage the root filesystem for a container", + subcommands: [ + Create.self + ] + ) + + struct Create: AsyncParsableCommand { + @Option(name: .long, help: "Path to vminitd") + var vminitd: String + + @Option(name: .long, help: "Path to vmexec") + var vmexec: String + + @Option(name: .long, help: "Platform of the built binaries being packaged into the block") + var platformString: String = Platform.current.description + + @Option(name: .long, help: "Labels to add to the built image of the form =, [=,...]") + var labels: [String] = [] + + @Argument var rootfsPath: String + + @Argument var tag: String + + private static let directories = [ + "bin", + "sbin", + "dev", + "sys", + "proc/self", // hack for swift init's booting + "run", + "tmp", + "mnt", + "var", + ] + + func run() async throws { + try await writeArchive() + let p = try Platform(from: platformString) + let rootfs = URL(filePath: rootfsPath) + let labels = Application.parseKeyValuePairs(from: labels) + _ = try await InitImage.create( + reference: tag, rootfs: rootfs, + platform: p, labels: labels, + imageStore: Application.imageStore, + contentStore: Application.contentStore) + } + + private func writeArchive() async throws { + let writer = try ArchiveWriter(format: .pax, filter: .gzip, file: URL(filePath: rootfsPath)) + let ts = Date() + let entry = WriteEntry() + entry.permissions = 0o755 + entry.modificationDate = ts + entry.creationDate = ts + entry.group = 0 + entry.owner = 0 + entry.fileType = .directory + // create the initial directory structure. + for dir in Self.directories { + entry.path = dir + try writer.writeEntry(entry: entry, data: nil) + } + + entry.fileType = .regular + entry.path = "sbin/vminitd" + + var src = URL(fileURLWithPath: vminitd) + var data = try Data(contentsOf: src) + entry.size = Int64(data.count) + try writer.writeEntry(entry: entry, data: data) + + src = URL(fileURLWithPath: vmexec) + data = try Data(contentsOf: src) + entry.path = "sbin/vmexec" + entry.size = Int64(data.count) + try writer.writeEntry(entry: entry, data: data) + + entry.fileType = .symbolicLink + entry.path = "proc/self/exe" + entry.symlinkTarget = "sbin/vminitd" + entry.size = nil + try writer.writeEntry(entry: entry, data: data) + try writer.finishEncoding() + } + } + } +} diff --git a/Sources/cctl/RunCommand.swift b/Sources/cctl/RunCommand.swift new file mode 100644 index 00000000..1aa41427 --- /dev/null +++ b/Sources/cctl/RunCommand.swift @@ -0,0 +1,169 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ArgumentParser +import Containerization +import ContainerizationError +import ContainerizationOCI +import ContainerizationOS +import Foundation + +extension Application { + struct Run: AsyncParsableCommand { + static let configuration = CommandConfiguration( + commandName: "run", + abstract: "Run a container" + ) + + @Option(name: [.customLong("image"), .customShort("i")], help: "image reference to base the container on") + var imageReference: String = "docker.io/library/alpine:3.16" + + @Option(name: .long, help: "id for the container") + var id: String = "cctl" + + @Option(name: [.customLong("cpus"), .customShort("c")], help: "Number of CPUs to allocate to the container") + var cpus: Int = 2 + + @Option(name: [.customLong("memory"), .customShort("m")], help: "Amount of memory in megabytes") + var memory: UInt64 = 1024 + + @Option(name: .customLong("fs-size"), help: "The size to create the block filesystem as") + var fsSizeInMB: UInt64 = 2048 + + @Option(name: .customLong("mount"), help: "directory to share into the container (Example: /foo:/bar)") + var mounts: [String] = [] + + @Option(name: .long, help: "ip address with subnet") + var ip: String? + + @Option(name: .long, help: "gateway address") + var gateway: String? + + @Option(name: .customLong("ns"), help: "nameserver addresses") + var nameservers: [String] = [] + + @Option( + name: [.customLong("kernel"), .customShort("k")], help: "Kernel binary path", completion: .file(), + transform: { str in + URL(fileURLWithPath: str, relativeTo: .currentDirectory()).absoluteURL.path(percentEncoded: false) + }) + public var kernel: String? + + @Argument var arguments: [String] = ["/bin/sh"] + + func run() async throws { + let store = try await ContainerStore( + root: Self.appRoot, + kernel: processKernel() + ) + let sigwinch = setupSigwinchHandler() + + let current = try Terminal.current + try current.setraw() + defer { current.tryReset() } + + let container = try await store.create( + id: id, + reference: imageReference, + fsSizeInBytes: fsSizeInMB.mib() + ) + container.cpus = cpus + container.memoryInBytes = memory.mib() + + container.terminalDevice = current + container.arguments = arguments + container.environment.append(contentsOf: [ + "HOME=/", + "TERM=xterm", + ]) + + for mount in self.mounts { + let paths = mount.split(separator: ":") + if paths.count != 2 { + throw ContainerizationError( + .invalidArgument, + message: "incorrect mount format detected: \(mount)" + ) + } + let host = String(paths[0]) + let guest = String(paths[1]) + let czMount = Containerization.Mount.share( + source: host, + destination: guest + ) + container.mounts.append(czMount) + } + + container.terminalDevice = current + if let ip { + guard let gateway else { + throw ContainerizationError(.invalidArgument, message: "gateway must be specified") + } + container.interfaces.append(NATInterface(address: ip, gateway: gateway)) + container.dns = .init(nameservers: [gateway]) + if nameservers.count > 0 { + container.dns = .init(nameservers: nameservers) + } + } + + try await container.create() + try await container.start() + + // Resize the containers pty to the current terminal window. + try? await container.resize(to: try current.size) + + try await withThrowingTaskGroup(of: Void.self) { group in + group.addTask { + for await _ in sigwinch { + try await container.resize(to: try current.size) + } + } + + try await container.wait() + group.cancelAll() + + try await container.stop() + } + } + + private func setupSigwinchHandler() -> AsyncStream { + let sigwinch = DispatchSource.makeSignalSource(signal: SIGWINCH) + let stream = AsyncStream { cont in + sigwinch.setEventHandler { + cont.yield() + } + } + sigwinch.resume() + return stream + } + + private func processKernel() -> Kernel? { + guard let kernel else { return nil } + return Kernel( + path: URL(fileURLWithPath: kernel), + platform: .linuxArm + ) + } + + private static let appRoot: URL = { + FileManager.default.urls( + for: .applicationSupportDirectory, + in: .userDomainMask + ).first! + .appendingPathComponent("com.apple.containerization") + }() + } +} diff --git a/Sources/cctl/cctl+Utils.swift b/Sources/cctl/cctl+Utils.swift new file mode 100644 index 00000000..89d317f9 --- /dev/null +++ b/Sources/cctl/cctl+Utils.swift @@ -0,0 +1,60 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Containerization +import ContainerizationError +import ContainerizationOCI +import Foundation + +extension Application { + static func fetchKernel(reference: String, store: ImageStore) async throws -> Kernel { + let image = try await store.getKernel(reference: reference) + var kernel = try await image.kernel(for: .linuxArm) + kernel.commandLine.addDebug() + return kernel + } + + static func fetchImage(reference: String, store: ImageStore) async throws -> Containerization.Image { + do { + return try await store.get(reference: reference) + } catch let error as ContainerizationError { + if error.code == .notFound { + return try await store.pull(reference: reference) + } + throw error + } + } + + static func parseKeyValuePairs(from items: [String]) -> [String: String] { + var parsedLabels: [String: String] = [:] + for item in items { + let parts = item.split(separator: "=", maxSplits: 1) + guard parts.count == 2 else { + continue + } + let key = String(parts[0]) + let val = String(parts[1]) + parsedLabels[key] = val + } + return parsedLabels + } +} + +extension ContainerizationOCI.Platform { + static var arm64: ContainerizationOCI.Platform { + .init(arch: "arm64", os: "linux", variant: "v8") + } +} diff --git a/Sources/cctl/cctl.swift b/Sources/cctl/cctl.swift new file mode 100644 index 00000000..b716ea4a --- /dev/null +++ b/Sources/cctl/cctl.swift @@ -0,0 +1,82 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ArgumentParser +import Containerization +import ContainerizationOCI +import Foundation +import Logging + +let log = { + LoggingSystem.bootstrap(StreamLogHandler.standardError) + var log = Logger(label: "com.apple.containerization") + log.logLevel = .debug + return log +}() + +@main +struct Application: AsyncParsableCommand { + static let keychainID = "com.apple.containerization" + static let appRoot: URL = { + FileManager.default.urls( + for: .applicationSupportDirectory, + in: .userDomainMask + ).first! + .appendingPathComponent("com.apple.containerization") + }() + + private static let _contentStore: ContentStore = { + try! LocalContentStore(path: appRoot.appendingPathComponent("content")) + }() + + private static let _imageStore: ImageStore = { + try! ImageStore( + path: appRoot, + contentStore: contentStore + ) + }() + + static var imageStore: ImageStore { + _imageStore + } + + static var contentStore: ContentStore { + _contentStore + } + + static let configuration = CommandConfiguration( + commandName: "cctl", + abstract: "Utility CLI for Containerization", + version: "2.0.0", + subcommands: [ + Images.self, + KernelCommand.self, + Login.self, + Rootfs.self, + Run.self, + ] + ) +} + +extension String { + var absoluteURL: URL { + URL(fileURLWithPath: self).absoluteURL + } +} + +extension String: Swift.Error { + +} diff --git a/Tests/ContainerizationArchiveTests/ArchiveTests.swift b/Tests/ContainerizationArchiveTests/ArchiveTests.swift new file mode 100644 index 00000000..2a060ea0 --- /dev/null +++ b/Tests/ContainerizationArchiveTests/ArchiveTests.swift @@ -0,0 +1,183 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// + +import Foundation +import Testing + +@testable import ContainerizationArchive + +struct ArchiveTests { + func helperEntry(path: String, data: Data) -> WriteEntry { + let entry = WriteEntry() + entry.permissions = 0o644 + entry.fileType = .regular + entry.path = path + entry.size = numericCast(data.count) + entry.owner = 1 + entry.group = 2 + entry.xattrs = ["user.data": Data([1, 2, 3])] + return entry + } + + @Test func tarUTF8() throws { + let testDirectory = createTemporaryDirectory(baseName: "ArchiveTests.testTarUTF8")! + let archiveURL = testDirectory.appendingPathComponent("test.tgz") + + defer { + let fileManager = FileManager.default + try? fileManager.removeItem(at: testDirectory) + } + + // this test would failed with ArchiveWriterConfiguration.locale was not set to "en_US.UTF-8" + let archiver = try ArchiveWriter(format: .paxRestricted, filter: .gzip, file: archiveURL) + + let data = "blablabla".data(using: .utf8)! + + let normalPathEntry = helperEntry(path: "r", data: data) + #expect(throws: Never.self) { + try archiver.writeEntry(entry: normalPathEntry, data: data) + } + + let weirdPathEntry = helperEntry(path: "ʀ", data: data) + #expect(throws: Never.self) { + try archiver.writeEntry(entry: weirdPathEntry, data: data) + } + } + + @Test func tarGzipWithOpenfile() throws { + let testDirectory = createTemporaryDirectory(baseName: "ArchiveTests.testTarGzipWithOpenfile")! + let archiveURL = testDirectory.appendingPathComponent("test.tgz") + + defer { + let fileManager = FileManager.default + try? fileManager.removeItem(at: testDirectory) + } + + let configuration = ArchiveWriterConfiguration( + format: .paxRestricted, + filter: .gzip + ) + let archiver = try ArchiveWriter(configuration: configuration) + try archiver.open(file: archiveURL) + + let data = "foo".data(using: .utf8)! + + let normalPathEntry = helperEntry(path: "bar", data: data) + #expect(throws: Never.self) { + try archiver.writeEntry(entry: normalPathEntry, data: data) + } + + try archiver.finishEncoding() + } + + @Test func writingZip() throws { + let testDirectory = createTemporaryDirectory(baseName: "ArchiveTests.testWritingZip")! + let archiveURL = testDirectory.appendingPathComponent("test.zip") + + defer { + let fileManager = FileManager.default + try? fileManager.removeItem(at: testDirectory) + } + + // When + let archiver = try ArchiveWriter(format: .zip, filter: .none, file: archiveURL) + + var data = "foo".data(using: .utf8)! + var entry = helperEntry(path: "foo.txt", data: data) + try archiver.writeEntry(entry: entry, data: data) + + data = "bar".data(using: .utf8)! + entry = helperEntry(path: "bar.txt", data: data) + try archiver.writeEntry(entry: entry, data: data) + + data = Data() + entry = helperEntry(path: "empty", data: data) + try archiver.writeEntry(entry: entry, data: data) + + try archiver.finishEncoding() + + // Then + let unarchiver = try ArchiveReader(format: .zip, filter: .none, file: archiveURL) + for (index, (entry, data)) in unarchiver.enumerated() { + #expect(entry.owner == 1) + #expect(entry.group == 2) + switch index { + case 0: + #expect(entry.path == "foo.txt") + #expect(String(data: data, encoding: .utf8) == "foo") + case 1: + #expect(entry.path == "bar.txt") + #expect(String(data: data, encoding: .utf8) == "bar") + case 2: + #expect(entry.path == "empty") + #expect(data.isEmpty) + default: + Issue.record() + } + } + } + + @Test func unarchiving_0bytesEntry() throws { + let data = Data(base64Encoded: surveyBundleBase64Encoded)! + let unarchiver = try ArchiveReader(name: "survey.zip", bundle: data) + for (index, (entry, data)) in unarchiver.enumerated() { + switch index { + case 0: + #expect(entry.path == "healthinvolvement.js") + #expect(!data.isEmpty) + case 1: + #expect(entry.path == "__MACOSX/") + #expect(data.isEmpty) + case 2: + #expect(entry.path == "__MACOSX/._healthinvolvement.js") + #expect(!data.isEmpty) + default: + Issue.record() + } + } + } + + @Test func writingReadingTar() throws { + let testDirectory = createTemporaryDirectory(baseName: "ArchiveTests.testWritingReadingTar")! + let archiveURL = testDirectory.appendingPathComponent("test.tar.gz") + defer { + let fileManager = FileManager.default + try? fileManager.removeItem(at: testDirectory) + } + + let archiver = try ArchiveWriter(format: .pax, filter: .gzip, file: archiveURL) + let data = "foo".data(using: .utf8)! + let entry = helperEntry(path: "foo.txt", data: data) + try archiver.writeEntry(entry: entry, data: data) + try archiver.finishEncoding() + + let unarchiver = try ArchiveReader(format: .pax, filter: .gzip, file: archiveURL) + for (entry, _) in unarchiver { + let attrs = entry.xattrs + guard let val = attrs["user.data"] else { + Issue.record("missing extended attribute [user.data] in file") + return + } + #expect([UInt8](val) == [1, 2, 3]) + } + } +} + +private let surveyBundleBase64Encoded = """ + UEsDBBQACAAIAA17o04AAAAAAAAAAAAAAAAUABAAaGVhbHRoaW52b2x2ZW1lbnQuanNVWAwAQ8XMXJm/zFz1ARQAnVVRa9swEH73rzjylMLwmu3NJexhDLqxroPAYIxRFPsca5UlT5LteSH/fSdZdu02LqMiEEl3uvv06e5zwzRwyS1n4q4qmEHYwjECGn6VwKrSXGluu9Urv50rXSbBxWBquZImgR9+/Wgcz226IVTKBP+L2We2R0E5rlULrapFBp2qYY/GQoYm1XyPbsdBbJRosERpaQ7cmBoNaBTMYgZW9V4FMmGLdwBfBbqrpIVS9KckxgH9mXGPHSGYJFh2ZdK0qJPli9mucpTtuDwIfF8onuJytNTbl8ibj+NTzr4oC4x+QgzsZDHcdIGElGmESquGZ6gh45qeykDpyAgeI3s9mcQQNEzUhP8STougn4W0UyW2BbMTQB8h9e9KD5kpogVKRcDowUom2QGhHABP8m9emv8b6m6W29KacrVK3wMzwMAiK6HldPvyPFPPI3vzUmQf/lhNxSXm8FQrH9JQdWVA6JgEljUUwKJrNnIwKPIJiLf/BeLnksvyYW5uK9fPjBDnTBg853h6vNknOkWnKMpr6QUB0EGlC6yxoYa6CA3TkNYMGuMNsV9dRd7Kc1gH63brGtKL0upi0m0aba3lXK9C9mhiP47alVHrrxaw3Wk0FYkXmvU4G5KFQOP+LADVyoEsZn65cOR2/4s6LSZRCfb4IXgsUB7ooV/DxgV0dPymznNBJaMOHaWXKlFannOnNatUlTFLWxRCUtJ4diLuS+epeFluhSPgxtWya7vvTh+vvXdw6QXWP7hTYG/q4BP5SexgV+sGB81vUJvebRNfDt+BQEcyEtrvh5XSyRmme5eBwGScOTqi2c2uon9QSwcIxOijbWkCAACaBgAAUEsDBAoAAAAAAFV+o04AAAAAAAAAAAAAAAAJABAAX19NQUNPU1gvVVgMAMHFzFzBxcxc9QEUAFBLAwQUAAgACAANe6NOAAAAAAAAAAAAAAAAHwAQAF9fTUFDT1NYLy5faGVhbHRoaW52b2x2ZW1lbnQuanNVWAwAQ8XMXJm/zFz1ARQAjY/NSsNAEMcnRfHjVBA9eLGiHjy0m5qkDa2XtGlrwVKxAUUUWZMpiW4+mmzrxZtP4pOINw8efQXx6BMIbmigUBAd2P/MDr8/MwOLG0uQA+hRu9AfFM4LWaQ9WBHvAED6Eln8c9vwrzAs63RapQ5pVxTfc8hC1s8DbNqhX6JRxLDEaMLHCToO5bhzMpiikipEA9ifcT5yKhhau+uZXY6+Gd4HLKQOOqZwph5PyAPA3u+eMxdjbMehn6T8h5BDgPUZPxrTmAbcCxDen98u002cz9dymm8i5iVclp8kxXghV7j1eLO8mi0rZQfm5g5em5mu8z2X8yipERJhFGFsu5RnU8V8MvQYJqRMNLVK/LDV71iMWW583OyY5Agp4243mIRsgj4GvHSb/Dn7YkRkWVfqmk1RV3RaH9Ahjb16y6hUKxVNK8rtcqOo6kIastooNlXT1IyWoTYVA34AUEsHCAK+cV1ZAQAAIQIAAFBLAQIVAxQACAAIAA17o07E6KNtaQIAAJoGAAAUAAwAAAAAAAAAAECkgQAAAABoZWFsdGhpbnZvbHZlbWVudC5qc1VYCABDxcxcmb/MXFBLAQIVAwoAAAAAAFV+o04AAAAAAAAAAAAAAAAJAAwAAAAAAAAAAED9QbsCAABfX01BQ09TWC9VWAgAwcXMXMHFzFxQSwECFQMUAAgACAANe6NOAr5xXVkBAAAhAgAAHwAMAAAAAAAAAABApIHyAgAAX19NQUNPU1gvLl9oZWFsdGhpbnZvbHZlbWVudC5qc1VYCABDxcxcmb/MXFBLBQYAAAAAAwADAOoAAACoBAAAAAA= + """ diff --git a/Tests/ContainerizationEXT4Tests/Resources/content/blobs/sha256/48a06049d3738991b011ca8b12473d712b7c40666a1462118dae3c403676afc2 b/Tests/ContainerizationEXT4Tests/Resources/content/blobs/sha256/48a06049d3738991b011ca8b12473d712b7c40666a1462118dae3c403676afc2 new file mode 100644 index 00000000..82f5a652 --- /dev/null +++ b/Tests/ContainerizationEXT4Tests/Resources/content/blobs/sha256/48a06049d3738991b011ca8b12473d712b7c40666a1462118dae3c403676afc2 @@ -0,0 +1,21 @@ +{ + "schemaVersion": 2, + "mediaType": "application/vnd.oci.image.manifest.v1+json", + "config": { + "mediaType": "application/vnd.oci.image.config.v1+json", + "digest": "sha256:8e2eb240a6cd7be1a0d308125afe0060b020e89275ced2e729eda7d4eeff62a2", + "size": 824 + }, + "layers": [ + { + "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip", + "digest": "sha256:c6b39de5b33961661dc939b997cc1d30cda01e38005a6c6625fd9c7e748bab44", + "size": 3333361 + }, + { + "mediaType": "application/vnd.oci.image.layer.v1.tar+gzip", + "digest": "sha256:4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1", + "size": 32 + } + ] +} \ No newline at end of file diff --git a/Tests/ContainerizationEXT4Tests/Resources/content/blobs/sha256/4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1 b/Tests/ContainerizationEXT4Tests/Resources/content/blobs/sha256/4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1 new file mode 100644 index 00000000..8de86822 Binary files /dev/null and b/Tests/ContainerizationEXT4Tests/Resources/content/blobs/sha256/4f4fb700ef54461cfa02571ae0db9a0dc1e0cdb5577484a6d75e68dc38e8acc1 differ diff --git a/Tests/ContainerizationEXT4Tests/Resources/content/blobs/sha256/8e2eb240a6cd7be1a0d308125afe0060b020e89275ced2e729eda7d4eeff62a2 b/Tests/ContainerizationEXT4Tests/Resources/content/blobs/sha256/8e2eb240a6cd7be1a0d308125afe0060b020e89275ced2e729eda7d4eeff62a2 new file mode 100644 index 00000000..bb7c410c --- /dev/null +++ b/Tests/ContainerizationEXT4Tests/Resources/content/blobs/sha256/8e2eb240a6cd7be1a0d308125afe0060b020e89275ced2e729eda7d4eeff62a2 @@ -0,0 +1 @@ +{"architecture":"arm64","config":{"Env":["PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"],"Cmd":["/bin/sh"],"OnBuild":null},"created":"2024-03-16T00:09:03.929767682Z","history":[{"created":"2024-01-26T23:44:55.650290626Z","created_by":"/bin/sh -c #(nop) ADD file:6dc287a22d6cc7723b0576dd3a9a644468d133c54d42c8a8eda403e3117648f7 in / "},{"created":"2024-01-26T23:44:55.750082605Z","created_by":"/bin/sh -c #(nop) CMD [\"/bin/sh\"]","empty_layer":true},{"created":"2024-03-16T00:09:03.929767682Z","created_by":"RUN /bin/sh -c echo \"test\" # buildkit","comment":"buildkit.dockerfile.v0"}],"os":"linux","rootfs":{"type":"layers","diff_ids":["sha256:7c504f21be85c8ade51b7ade32a39a4269bcbcf0e593352923f1b8ea6278e5ef","sha256:5f70bf18a086007016e948b04aed3b82103a36bea41755b6cddfaf10ace3c6ef"]},"variant":"v8"} \ No newline at end of file diff --git a/Tests/ContainerizationEXT4Tests/Resources/content/blobs/sha256/ad59e9f71edceca7b1ac7c642410858489b743c97233b0a26a5e2098b1443762 b/Tests/ContainerizationEXT4Tests/Resources/content/blobs/sha256/ad59e9f71edceca7b1ac7c642410858489b743c97233b0a26a5e2098b1443762 new file mode 100644 index 00000000..32111e37 --- /dev/null +++ b/Tests/ContainerizationEXT4Tests/Resources/content/blobs/sha256/ad59e9f71edceca7b1ac7c642410858489b743c97233b0a26a5e2098b1443762 @@ -0,0 +1 @@ +{"schemaVersion":2,"mediaType":"application/vnd.oci.image.index.v1+json","manifests":[{"mediaType":"application/vnd.oci.image.manifest.v1+json","digest":"sha256:48a06049d3738991b011ca8b12473d712b7c40666a1462118dae3c403676afc2","size":667,"annotations":{"com.apple.container.sign.v1.certificate/ptr":"mac-Q5W6919KP6:41FB3AB2-E9B9-45CE-8252-8C17C8038670:wlan0","com.apple.container.sign.v1.signature":"MEUCIEX3psgFczBpby6sMdzBk5FF5ID5UbqM4nOpqfiVbkseAiEAlDLBr9ajHiswl8/rOyVmYdN98lakuK+dKyABEBXRXeQ="},"platform":{"architecture":"arm64","os":"linux"}}],"annotations":{"com.apple.container.info.v1.dockerfile-sha256sum":"d95983c2a8acbd4cf861c7d3b9117d3e722aebc3768ca682ddf2a427e2fd6583","com.apple.container.sign.v1.certificate/mac-Q5W6919KP6:41FB3AB2-E9B9-45CE-8252-8C17C8038670:wlan0":"LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSURjekNDQXhpZ0F3SUJBZ0lJRW9tR0duRkFGTnd3Q2dZSUtvWkl6ajBFQXdJd2FqRWtNQ0lHQTFVRUF3d2INClFYQndiR1VnUTI5eWNHOXlZWFJsSUZCTFNVNUpWQ0JEUVNBeU1TQXdIZ1lEVlFRTERCZERaWEowYVdacFkyRjANCmFXOXVJRUYxZEdodmNtbDBlVEVUTUJFR0ExVUVDZ3dLUVhCd2JHVWdTVzVqTGpFTE1Ba0dBMVVFQmhNQ1ZWTXcNCkhoY05Nakl4TWpJd01Ua3hOREl3V2hjTk1qVXdNVEU0TVRreE5ERTVXakNCcGpFYU1CZ0dDZ21TSm9tVDhpeGsNCkFRRU1DakkzTURFd09UVTRPVFV4UWpCQUJnTlZCQU1NT1cxaFl5MVJOVmMyT1RFNVMxQTJPalF4UmtJelFVSXkNCkxVVTVRamt0TkRWRFJTMDRNalV5TFRoRE1UZERPREF6T0RZM01EcDNiR0Z1TURFVk1CTUdBMVVFQ3d3TVFYQncNCmJHVkRiMjV1WldOME1STXdFUVlEVlFRS0RBcEJjSEJzWlNCSmJtTXVNUmd3RmdZS0NaSW1pWlB5TEdRQkdSWUkNClNVUk5VeTFUVTA4d1dUQVRCZ2NxaGtqT1BRSUJCZ2dxaGtqT1BRTUJCd05DQUFTcW5tSjZ3cFluWWlKRkdRaDENCjlOcGkyVnp3M1I3UFlMOXY3MnNiUDZsNy83VUt3YXV4aVk1ZkdEL29yTnhwbWNScFdPRk5mNW1JUWpFcHByMDMNCkpYUXpvNElCYVRDQ0FXVXdEQVlEVlIwVEFRSC9CQUl3QURBZkJnTlZIU01FR0RBV2dCVEx3K0x0QUcxai8rV1QNCkpsLzJJVDVVMEJ6WEZUQkVCZ2dyQmdFRkJRY0JBUVE0TURZd05BWUlLd1lCQlFVSE1BR0dLR2gwZEhBNkx5OXYNClkzTndMbUZ3Y0d4bExtTnZiUzl2WTNOd01ETXRjR3RwYm1sMFkyRXlNREV3VGdZRFZSMFJCRWN3UmFCREJnWXINCkJnRUZBZ0tnT1RBM29CZ2JGa0ZRVUV4RlEwOU9Ua1ZEVkM1QlVGQk1SUzVEVDAyaEd6QVpvQU1DQVFDaEVqQVENCkd3NXphV1JvWVhKMGFHRmZiV0Z1YVRBb0JnTlZIU1VFSVRBZkJnZ3JCZ0VGQlFjREFnWUtLd1lCQkFHQ054UUMNCkFnWUhLd1lCQlFJREJEQXpCZ05WSFI4RUxEQXFNQ2lnSnFBa2hpSm9kSFJ3T2k4dlkzSnNMbUZ3Y0d4bExtTnYNCmJTOXdhMmx1YVhSallUSXVZM0pzTUIwR0ExVWREZ1FXQkJTRlIxOExjWkgxY1laNHlEajVyWXkwMmZNeTREQU8NCkJnTlZIUThCQWY4RUJBTUNCNEF3RUFZSktvWklodmRqWkFZcEJBTU1BVEl3Q2dZSUtvWkl6ajBFQXdJRFNRQXcNClJnSWhBSk9YTnBEWE43QjhHZFZIVE1WdmEzSForeXlCTDlMcm1hZTJkeFpUUUVoekFpRUF4b25CRjhnMTNQeXYNCkhCRFVSY0p0ZURUYVdQdnJyUW9HUi9KZXQzb3B5R1U9Ci0tLS0tRU5EIENFUlRJRklDQVRFLS0tLS0K"}} \ No newline at end of file diff --git a/Tests/ContainerizationEXT4Tests/Resources/content/blobs/sha256/c6b39de5b33961661dc939b997cc1d30cda01e38005a6c6625fd9c7e748bab44 b/Tests/ContainerizationEXT4Tests/Resources/content/blobs/sha256/c6b39de5b33961661dc939b997cc1d30cda01e38005a6c6625fd9c7e748bab44 new file mode 100644 index 00000000..72831f77 Binary files /dev/null and b/Tests/ContainerizationEXT4Tests/Resources/content/blobs/sha256/c6b39de5b33961661dc939b997cc1d30cda01e38005a6c6625fd9c7e748bab44 differ diff --git a/Tests/ContainerizationEXT4Tests/TestEXT4ExtendedAttributes.swift b/Tests/ContainerizationEXT4Tests/TestEXT4ExtendedAttributes.swift new file mode 100644 index 00000000..c94b8536 --- /dev/null +++ b/Tests/ContainerizationEXT4Tests/TestEXT4ExtendedAttributes.swift @@ -0,0 +1,86 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// swiftlint:disable force_try + +import Foundation +import Testing + +@testable import ContainerizationEXT4 + +struct TestEXT4ExtendedAttribute { + @Test func compressName() { + struct TestCase { + let input: String + let expectedId: UInt8 + let expectedStr: String + init(_ input: String, _ expectedId: UInt8, _ expectedStr: String) { + self.input = input + self.expectedId = expectedId + self.expectedStr = expectedStr + } + } + let tests: [TestCase] = [ + .init("my.test.xattr", 0, "my.test.xattr"), + .init("user.fubar", 1, "fubar"), + .init("system.posix_acl_access.denied_su", 2, ".denied_su"), + .init("system.posix_acl_default_failed", 3, "_failed"), + .init("trusted.user", 4, "user"), + .init("trusted_user", 0, "trusted_user"), + .init("security.auth", 6, "auth"), + .init("system.admin", 7, "admin"), + .init("system.richacl.denied", 8, ".denied"), + ] + for test in tests { + let ret = EXT4.ExtendedAttribute.compressName(test.input) + #expect(ret.0 == test.expectedId) + #expect(ret.1 == test.expectedStr) + } + } + + @Test func encodeDecodeAttributes() { + let xattrs: [String: Data] = [ + "foo.bar": Data([1, 2, 3]), + "bar": Data([0, 0, 0]), + "system.richacl.bar": Data([99, 1, 9, 1]), + "foobar.user": Data([71, 2, 45]), + "test.xattr.cap": Data([1, 32, 3]), + "testing123": Data([12, 24, 45]), + "sys.admin": Data([16, 23, 13]), + "test.123": Data([15, 26, 54]), + "extendedattribute.test": Data([15, 26, 54, 1, 2, 4, 6, 7, 7]), + ] + let blockSize = 4096 + var state = EXT4.FileXattrsState( + inode: 1, inodeXattrCapacity: EXT4.InodeExtraSize, blockCapacity: UInt32(blockSize)) + for (s, d) in xattrs { + let attribute = EXT4.ExtendedAttribute(name: s, value: [UInt8](d)) + try! state.add(attribute) + } + var inlineAttrBuffer: [UInt8] = .init(repeating: 0, count: Int(EXT4.InodeExtraSize)) + var blockAttrBuffer: [UInt8] = .init(repeating: 0, count: blockSize) + try! state.writeInlineAttributes(buffer: &inlineAttrBuffer) + try! state.writeBlockAttributes(buffer: &blockAttrBuffer) + let gotInlineXattrs = try! EXT4.EXT4Reader.readInlineExtenedAttributes(from: inlineAttrBuffer) + let gotBlockXattrs = try! EXT4.EXT4Reader.readBlockExtenedAttributes(from: blockAttrBuffer) + + var gotXattrs: [String: Data] = [:] + for attr in gotBlockXattrs + gotInlineXattrs { + gotXattrs[attr.fullName] = Data(attr.value) + } + #expect(gotXattrs == xattrs) + } +} diff --git a/Tests/ContainerizationEXT4Tests/TestEXT4Format+Create.swift b/Tests/ContainerizationEXT4Tests/TestEXT4Format+Create.swift new file mode 100644 index 00000000..f48bd361 --- /dev/null +++ b/Tests/ContainerizationEXT4Tests/TestEXT4Format+Create.swift @@ -0,0 +1,80 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// + +import Foundation +import SystemPackage +import Testing + +@testable import ContainerizationEXT4 + +struct Ext4FormatCreateTests { + @Test func fileReplace() throws { + let fsPath = FilePath( + FileManager.default.temporaryDirectory + .appendingPathComponent(UUID().uuidString, isDirectory: false)) + defer { try? FileManager.default.removeItem(at: fsPath.url) } + + let formatter = try EXT4.Formatter(fsPath, minDiskSize: 32.kib()) + defer { try? formatter.close() } + try formatter.create(path: FilePath("/file"), mode: EXT4.Inode.Mode(.S_IFREG, 0o755), buf: nil) // create a regular file + #expect(throws: Never.self) { + try formatter.create(path: FilePath("/file"), mode: EXT4.Inode.Mode(.S_IFREG, 0o755), buf: nil) + } // overwrite it with a regular file + #expect(throws: Error.self) { try formatter.create(path: FilePath("/file"), mode: EXT4.Inode.Mode(.S_IFDIR, 0o700)) } // overwrite it with a directory + } + + @Test func dirReplace() throws { + let fsPath = FilePath( + FileManager.default.temporaryDirectory + .appendingPathComponent(UUID().uuidString, isDirectory: false)) + defer { try? FileManager.default.removeItem(at: fsPath.url) } + + let formatter = try EXT4.Formatter(fsPath, minDiskSize: 32.kib()) + defer { try? formatter.close() } + try formatter.create(path: FilePath("/dir"), mode: EXT4.Inode.Mode(.S_IFDIR, 0o700)) // create a directory + #expect(throws: Never.self) { + try formatter.create(path: FilePath("/dir"), mode: EXT4.Inode.Mode(.S_IFDIR, 0o700)) + } // overwrite it with a directory + #expect(throws: Error.self) { try formatter.create(path: FilePath("/dir"), mode: EXT4.Inode.Mode(.S_IFREG, 0o755)) } // overwrite it with a file + } + + @Test func fileParentFails() throws { + let fsPath = FilePath( + FileManager.default.temporaryDirectory + .appendingPathComponent(UUID().uuidString, isDirectory: false)) + defer { try? FileManager.default.removeItem(at: fsPath.url) } + + let formatter = try EXT4.Formatter(fsPath, minDiskSize: 32.kib()) + defer { try? formatter.close() } + try formatter.create(path: FilePath("/file"), mode: EXT4.Inode.Mode(.S_IFREG, 0o755), buf: nil) // create a regular file + #expect(throws: Error.self) { try formatter.create(path: FilePath("/file/dir"), mode: EXT4.Inode.Mode(.S_IFDIR, 0o700)) } // create a subdir in a file? + } + + @Test func createParentAutomatically() throws { + let fsPath = FilePath( + FileManager.default.temporaryDirectory + .appendingPathComponent(UUID().uuidString, isDirectory: false)) + defer { try? FileManager.default.removeItem(at: fsPath.url) } + + let formatter = try EXT4.Formatter(fsPath, minDiskSize: 32.kib()) + defer { try? formatter.close() } + #expect(throws: Never.self) { + try formatter.create(path: FilePath("/parent/file"), mode: EXT4.Inode.Mode(.S_IFREG, 0o755), buf: nil) + } // should create /parent automatically + } +} diff --git a/Tests/ContainerizationEXT4Tests/TestEXT4Format.swift b/Tests/ContainerizationEXT4Tests/TestEXT4Format.swift new file mode 100644 index 00000000..94dc5ac7 --- /dev/null +++ b/Tests/ContainerizationEXT4Tests/TestEXT4Format.swift @@ -0,0 +1,221 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// swiftlint: disable force_try shorthand_operator static_over_final_class + +import Foundation +import SystemPackage +import Testing + +@testable import ContainerizationEXT4 + +struct Ext4FormatTests: ~Copyable { + let fsPath = FilePath( + FileManager.default.uniqueTemporaryDirectory() + .appendingPathComponent("ext4.img.delme.format", isDirectory: false)) + + // This test creates a file named "ext4.img.delme" + // Since there are no tools yet in osx/swift to test the created filesystem, + // the tests below perform the same checks as the following manual commands + // + // From project root + // $> backpack run -it -v SwiftExt4/Tests/SwiftExt4Tests/:/test -w test ubuntu:latest + // $> ls -lrth ext4.img.delme # should be only 44K + // $> e2fsck ext4.img.delme # should return 0 + // $> dumpe2fs ext4.img.delme # should print info and return 0 + // $> debugfs ext4.img.delme # should open the fs + // debugfs 1.46.5 (30-Dec-2021) + // debugfs: ls + // 2 (12) . 2 (12) .. 15 (12) x 11 (20) lost+found 12 (12) ase + // 16 (12) y 0 (4016) + // + // # check directory + // + // debugfs: stat /test + // Inode: 12 Type: directory Mode: 01274 Flags: 0xc0000 + // Generation: 0 Version: 0x00000000:00000000 + // User: 0 Group: 0 Size: 4096 + // File ACL: 0 + // Links: 3 Blockcount: 1 + // Fragment: Address: 0 Number: 0 Size: 0 + // ctime: 0x6614b59f:8cdf6a34 -- Tue Apr 9 03:27:27 2024 + // atime: 0x6614b59f:8cdf6a34 -- Tue Apr 9 03:27:27 2024 + // mtime: 0x6614b59f:8cdf6a34 -- Tue Apr 9 03:27:27 2024 + // crtime: 0x6614b59f:8cdf6a34 -- Tue Apr 9 03:27:27 2024 + // Size of extra inode fields: 24 + // EXTENTS: + // (0):5 + // + // # check regular file + // + // debugfs: stat /test/foo/bar/x + // Inode: 15 Type: regular Mode: 01363 Flags: 0xc0000 + // Generation: 0 Version: 0x00000000:00000000 + // User: 0 Group: 0 Size: 4 + // File ACL: 0 + // Links: 2 Blockcount: 1 + // Fragment: Address: 0 Number: 0 Size: 0 + // ctime: 0x6614b59f:8ce91ef8 -- Tue Apr 9 03:27:27 2024 + // atime: 0x6614b59f:8ce91ef8 -- Tue Apr 9 03:27:27 2024 + // mtime: 0x6614b59f:8ce91ef8 -- Tue Apr 9 03:27:27 2024 + // crtime: 0x6614b59f:8ce91ef8 -- Tue Apr 9 03:27:27 2024 + // Size of extra inode fields: 24 + // EXTENTS: + // (0):2 + // + // # check symlink + // + // debugfs: stat /y + // Inode: 16 Type: symlink Mode: 01675 Flags: 0x0 + // Generation: 0 Version: 0x00000000:00000000 + // User: 0 Group: 0 Size: 19 + // File ACL: 0 + // Links: 1 Blockcount: 0 + // Fragment: Address: 0 Number: 0 Size: 0 + // ctime: 0x6614b59f:8cf052fc -- Tue Apr 9 03:27:27 2024 + // atime: 0x6614b59f:8cf052fc -- Tue Apr 9 03:27:27 2024 + // mtime: 0x6614b59f:8cf052fc -- Tue Apr 9 03:27:27 2024 + // crtime: 0x6614b59f:8cf052fc -- Tue Apr 9 03:27:27 2024 + // Size of extra inode fields: 24 + // Fast link dest: "test/foo" + // + // # check hard link + // + // debugfs: stat x + // Inode: 15 Type: regular Mode: 01363 Flags: 0xc0000 + // Generation: 0 Version: 0x00000000:00000000 + // User: 0 Group: 0 Size: 4 + // File ACL: 0 + // Links: 2 Blockcount: 1 + // Fragment: Address: 0 Number: 0 Size: 0 + // ctime: 0x6614b59f:8ce91ef8 -- Tue Apr 9 03:27:27 2024 + // atime: 0x6614b59f:8ce91ef8 -- Tue Apr 9 03:27:27 2024 + // mtime: 0x6614b59f:8ce91ef8 -- Tue Apr 9 03:27:27 2024 + // crtime: 0x6614b59f:8ce91ef8 -- Tue Apr 9 03:27:27 2024 + // Size of extra inode fields: 24 + // EXTENTS: + // (0):2 + // + // Mount and check + // + // $> mkdir -p mntpnt + // $> mount -t ext4 ext4.img.delme mntpnt + // $> # explore file tree + init() throws { + let formatter = try EXT4.Formatter(fsPath, minDiskSize: 32.kib()) + try formatter.create(path: FilePath("/test"), mode: EXT4.Inode.Mode(.S_IFDIR, 0o700)) + try formatter.create(path: FilePath("/test/foo"), mode: EXT4.Inode.Mode(.S_IFDIR, 0o700)) + try formatter.create(path: FilePath("/test/foo/bar"), mode: EXT4.Inode.Mode(.S_IFDIR, 0o700)) + let inputStream = InputStream(data: "test".data(using: .utf8)!) + inputStream.open() + try formatter.create( + path: FilePath("/test/foo/bar/x"), mode: EXT4.Inode.Mode(.S_IFREG, 0o755), + buf: inputStream) // create a regular file + inputStream.close() + try formatter.link(link: FilePath("/x"), target: FilePath("/test/foo/bar/x")) + try formatter.create( + path: FilePath("/y"), link: FilePath("test/foo"), mode: EXT4.Inode.Mode(.S_IFLNK, 0o700)) // create a symlink + + try formatter.close() + } + + deinit { + try? FileManager.default.removeItem(at: fsPath.url) + } + + /// This test checks that the size of the FS at fsPath is the minimum possible + /// for its data + metadata. It should be 44 kib or 11 blocks, expanded to accommodate + /// data requiring > 32KiB of space + @Test func fileSize() throws { + let f = try FileHandle(forReadingFrom: fsPath.url) + let size = try f.seekToEnd() + #expect(size == 128.mib()) + } + + /// This test checks that the superblock was created correctly + @Test func superblock() throws { + let f = try EXT4.EXT4Reader(blockDevice: fsPath) + #expect(f.superBlock.blocksCountLow == 32768) + #expect(f.superBlock.freeBlocksCountLow == 32246) // total - 512 inode blocks + } + + /// This test checks that the group descriptor has been set correctly + @Test func groupDescriptors() throws { + let f = try EXT4.EXT4Reader(blockDevice: fsPath) + let gd = try f.getGroupDescriptor(0) + #expect(gd.blockBitmapLow == 551) // move over by 512 blocks (for inodes) + #expect(gd.inodeBitmapLow == 552) // move over by 512 blocks (for inodes) + #expect(gd.inodeTableLow == 39) + #expect(gd.freeBlocksCountLow == 32246) // 512 block used by larger inode table per block group + #expect(gd.freeInodesCountLow == 8176) // 512 times the inodes + #expect(gd.usedDirsCountLow == 5) + } + + /// This test checks that the block bitmap has been set correctly + @Test func blockBitmap() throws { + let ext4 = try EXT4.EXT4Reader(blockDevice: fsPath) + let gd = try ext4.getGroupDescriptor(1) + let blockBitmapOffset = gd.blockBitmapLow + let f = try #require(FileHandle(forReadingFrom: fsPath)) + try f.seek(toOffset: ext4.blockSize * blockBitmapOffset) + let bitmapSize = ext4.superBlock.blocksPerGroup / 8 + #expect(bitmapSize == 4096) + let _ = try f.read( + upToCount: Int(ext4.superBlock.blocksCountLow - ext4.superBlock.freeBlocksCountLow - 1) / 8 + 1) + } + + /// This test checks that the inode bitmap has been set correctly + @Test func inodeBitmap() throws { + let ext4 = try EXT4.EXT4Reader(blockDevice: fsPath) + let gd = try ext4.getGroupDescriptor(1) + let inodeBitmapOffset = gd.inodeBitmapLow + let f = try #require(FileHandle(forReadingFrom: fsPath)) + try f.seek(toOffset: ext4.blockSize * inodeBitmapOffset) + let bitmapSize = ext4.superBlock.inodesPerGroup / 8 + #expect(bitmapSize == 1024) + } + + /// This test checks that the inode table has been set correctly + @Test func inodeTable() throws { + let ext4 = try EXT4.EXT4Reader(blockDevice: fsPath) + let gd = try ext4.getGroupDescriptor(0) + let inodeTableOffset = gd.inodeTableLow + let f = try #require(FileHandle(forReadingFrom: fsPath)) + try f.seek(toOffset: ext4.blockSize * inodeTableOffset) + let inodeTableSize = ext4.superBlock.inodesPerGroup * UInt32(ext4.superBlock.inodeSize) + #expect(inodeTableSize == 2_097_152) + let inodeTableData = try #require(try f.read(upToCount: Int(inodeTableSize))) + let inodeAt: (Int) -> EXT4.Inode = { inodeNum in + var inodeBytes: [UInt8] = .init(repeating: 0, count: Int(ext4.superBlock.inodeSize)) + let inodeStart = Int(ext4.superBlock.inodeSize) * (inodeNum - 1) + var j: Int = 0 + for i in inodeStart.. WriteEntry { + let entry = WriteEntry() + entry.path = path + entry.fileType = .directory + entry.permissions = permissions + return entry + } + + static func file(path: String, permissions: UInt16, size: Int64? = nil, xattrs: [String: Data]? = nil) -> WriteEntry { + let entry = WriteEntry() + entry.path = path + entry.fileType = .regular + entry.permissions = permissions + entry.size = size + if let xattrs { + entry.xattrs = xattrs + } + return entry + } + + static func link(path: String, permissions: UInt16, target: String) -> WriteEntry { + let entry = WriteEntry() + entry.path = path + entry.fileType = .symbolicLink + entry.symlinkTarget = target + return entry + } +} + +extension EXT4.EXT4Reader { + fileprivate func getXattrsForInode(inode: EXT4.Inode) throws -> [String: Data] { + var attributes: [EXT4.ExtendedAttribute] = [] + let buffer: [UInt8] = EXT4.tupleToArray(inode.inlineXattrs) + try attributes.append(contentsOf: Self.readInlineExtenedAttributes(from: buffer)) + let block = inode.xattrBlockLow + try self.seek(block: block) + let buf = try self.handle.read(upToCount: Int(self.blockSize))! + try attributes.append(contentsOf: Self.readBlockExtenedAttributes(from: [UInt8](buf))) + var xattrs: [String: Data] = [:] + for attribute in attributes { + guard attribute.fullName != "system.data" else { + continue + } + xattrs[attribute.fullName] = Data(attribute.value) + } + return xattrs + } +} +#endif diff --git a/Tests/ContainerizationExtrasTests/TestCIDRAddress.swift b/Tests/ContainerizationExtrasTests/TestCIDRAddress.swift new file mode 100644 index 00000000..05fe04b9 --- /dev/null +++ b/Tests/ContainerizationExtrasTests/TestCIDRAddress.swift @@ -0,0 +1,211 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// +// swiftlint:disable force_try +// + +import Foundation +import Testing + +@testable import ContainerizationExtras + +final class TestCIDRAddress { + @Test + func testMissingSplitError() { + let cidr = "192.168.64.0" + do { + _ = try CIDRAddress(cidr) + #expect(Bool(false), "Expected AddressError.invalidCIDR to be thrown") + } catch { + #expect(error as? NetworkAddressError == .invalidCIDR(cidr: cidr), "Unexpected error thrown: \(error)") + } + } + + @Test + func testInvalidIPError() { + let cidr = "192.168.256.1/24" + do { + _ = try CIDRAddress(cidr) + #expect(Bool(false), "Expected AddressError.invalidCIDR to be thrown") + } catch { + #expect( + error as? NetworkAddressError == .invalidStringAddress(address: "192.168.256.1"), + "Unexpected error thrown: \(error)") + } + } + + @Test + func testInvalidSubnetTypeError() { + let cidr = "192.168.64.0/foo" + do { + _ = try CIDRAddress(cidr) + #expect(Bool(false), "Expected AddressError.invalidCIDR to be thrown") + } catch { + #expect(error as? NetworkAddressError == .invalidCIDR(cidr: cidr), "Unexpected error thrown: \(error)") + } + } + + @Test + func testInvalidPrefixTooLargeError() { + let cidr = "192.168.64.0/33" + do { + _ = try CIDRAddress(cidr) + #expect(Bool(false), "Expected AddressError.invalidCIDR to be thrown") + } catch { + #expect(error as? NetworkAddressError == .invalidCIDR(cidr: cidr), "Unexpected error thrown: \(error)") + } + } + + @Test + func testInvalidPrefixTooSmallError() { + let cidr = "192.168.64.0/-1" + do { + _ = try CIDRAddress(cidr) + #expect(Bool(false), "Expected AddressError.invalidCIDR to be thrown") + } catch { + #expect(error as? NetworkAddressError == .invalidCIDR(cidr: cidr), "Unexpected error thrown: \(error)") + } + } + + @Test + func testComparison() async throws { + let cidr64_1 = try! CIDRAddress("192.168.64.1/24") + let cidr64_1a = try! CIDRAddress("192.168.64.1/24") + #expect(cidr64_1 == cidr64_1a) + #expect(cidr64_1.contains(cidr: cidr64_1a)) + #expect(cidr64_1a.contains(cidr: cidr64_1)) + #expect(cidr64_1.overlaps(cidr: cidr64_1a)) + #expect(cidr64_1a.overlaps(cidr: cidr64_1)) + + let cidr64_2 = try! CIDRAddress("192.168.64.2/24") + #expect(cidr64_1 != cidr64_2) + + let addr63_255 = try! IPv4Address("192.168.63.255") + #expect(!cidr64_1.contains(ipv4: addr63_255)) + + let addr64_0 = try! IPv4Address("192.168.64.0") + #expect(cidr64_1.contains(ipv4: addr64_0)) + + let addr64_255 = try! IPv4Address("192.168.64.255") + #expect(cidr64_1.contains(ipv4: addr64_255)) + + let addr65_0 = try! IPv4Address("192.168.65.0") + #expect(!cidr64_1.contains(ipv4: addr65_0)) + + let cidr64_prefix25 = try! CIDRAddress("192.168.64.0/25") + #expect(cidr64_1.contains(cidr: cidr64_prefix25)) + #expect(!cidr64_prefix25.contains(cidr: cidr64_1)) + #expect(cidr64_1.overlaps(cidr: cidr64_prefix25)) + #expect(cidr64_prefix25.overlaps(cidr: cidr64_1)) + + let cidr64_prefix25a = try! CIDRAddress("192.168.64.128/25") + #expect(cidr64_1.contains(cidr: cidr64_prefix25a)) + #expect(!cidr64_prefix25a.contains(cidr: cidr64_1)) + #expect(cidr64_1.overlaps(cidr: cidr64_prefix25a)) + #expect(cidr64_prefix25a.overlaps(cidr: cidr64_1)) + + let cidr63_prefix24 = try! CIDRAddress("192.168.63.0/24") + #expect(!cidr64_1.contains(cidr: cidr63_prefix24)) + #expect(!cidr63_prefix24.contains(cidr: cidr64_1)) + #expect(!cidr64_1.overlaps(cidr: cidr63_prefix24)) + #expect(!cidr63_prefix24.overlaps(cidr: cidr64_1)) + + let cidr65_prefix24 = try! CIDRAddress("192.168.65.0/24") + #expect(!cidr64_1.contains(cidr: cidr65_prefix24)) + #expect(!cidr65_prefix24.contains(cidr: cidr64_1)) + #expect(!cidr64_1.overlaps(cidr: cidr65_prefix24)) + #expect(!cidr65_prefix24.overlaps(cidr: cidr64_1)) + } + + @Test + func testBiggestSubnet() throws { + let cidr = "1.2.3.4/0" + let subnet = try CIDRAddress(cidr) + #expect(try! IPv4Address("0.0.0.0") == subnet.lower) + #expect(try! IPv4Address("1.2.3.4") == subnet.address) + #expect(try! IPv4Address("255.255.255.255") == subnet.upper) + #expect(0 == subnet.prefixLength) + #expect(cidr == subnet.description) + } + + @Test + func testSmallestSubnet() throws { + let cidr = "255.255.255.255/32" + let subnet = try CIDRAddress(cidr) + #expect(try! IPv4Address("255.255.255.255") == subnet.lower) + #expect(try! IPv4Address("255.255.255.255") == subnet.address) + #expect(try! IPv4Address("255.255.255.255") == subnet.upper) + #expect(32 == subnet.prefixLength) + #expect(cidr == subnet.description) + } + + @Test + func testJustRightSubnet() throws { + let cidr = "192.168.64.10/24" + let subnet = try CIDRAddress(cidr) + #expect(try! IPv4Address("192.168.64.0") == subnet.lower) + #expect(try! IPv4Address("192.168.64.10") == subnet.address) + #expect(try! IPv4Address("192.168.64.255") == subnet.upper) + #expect(24 == subnet.prefixLength) + #expect(cidr == subnet.description) + } + + @Test + func testBiggestRangedSubnet() throws { + let lower = try IPv4Address("127.255.255.255") + let upper = try IPv4Address("128.0.0.0") + let subnet = try CIDRAddress(lower: lower, upper: upper) + #expect(try! IPv4Address("0.0.0.0") == subnet.lower) + #expect(try! IPv4Address("127.255.255.255") == subnet.address) + #expect(try! IPv4Address("255.255.255.255") == subnet.upper) + #expect(0 == subnet.prefixLength) + #expect("\(lower)/0" == subnet.description) + } + + @Test + func testSmallestRangedSubnet() throws { + let lower = try IPv4Address("255.255.255.255") + let subnet = try CIDRAddress(lower: lower, upper: lower) + #expect(lower == subnet.lower) + #expect(lower == subnet.address) + #expect(lower == subnet.upper) + #expect(32 == subnet.prefixLength) + #expect("\(lower)/32" == subnet.description) + } + + @Test + func testJustRightRangedSubnet() throws { + let lower = try IPv4Address("192.168.64.10") + let upper = try IPv4Address("192.168.64.254") + let subnet = try CIDRAddress(lower: lower, upper: upper) + #expect(try! IPv4Address("192.168.64.0") == subnet.lower) + #expect(try! IPv4Address("192.168.64.10") == subnet.address) + #expect(try! IPv4Address("192.168.64.255") == subnet.upper) + #expect(24 == subnet.prefixLength) + #expect("\(lower)/24" == subnet.description) + _ = 16 >> PrefixLength(2) + } + + @Test + func testCoding() async throws { + let text = "200.100.50.25/12" + let expected: CIDRAddress = try CIDRAddress(text) + let data = try JSONEncoder().encode(expected) + let actual = try JSONDecoder().decode(CIDRAddress.self, from: data) + #expect(expected == actual) + } +} diff --git a/Tests/ContainerizationExtrasTests/TestIPAddress.swift b/Tests/ContainerizationExtrasTests/TestIPAddress.swift new file mode 100644 index 00000000..0fa7d2b0 --- /dev/null +++ b/Tests/ContainerizationExtrasTests/TestIPAddress.swift @@ -0,0 +1,90 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// + +import Foundation +import Testing + +@testable import ContainerizationExtras + +final class TestIPv4Address { + @Test + func testUintMask() { + #expect(0xffff_ffff == PrefixLength(0).suffixMask32) + #expect(0x0000_7fff == PrefixLength(17).suffixMask32) + #expect(0x0000_0000 == PrefixLength(32).suffixMask32) + #expect(0x0000_0000 == PrefixLength(33).suffixMask32) + #expect(0x0000_0000 == PrefixLength(0).prefixMask32) + #expect(0xfffe_0000 == PrefixLength(15).prefixMask32) + #expect(0xffff_ffff == PrefixLength(32).prefixMask32) + #expect(0xffff_ffff == PrefixLength(33).prefixMask32) + } + + @Test + func testOctetCountError() { + let ipAddressValue = "192.168.64" + do { + _ = try IPv4Address(ipAddressValue) + #expect(Bool(false), "Expected AddressError.invalidStringAddress to be thrown") + } catch { + #expect( + error as? NetworkAddressError == .invalidStringAddress(address: ipAddressValue), + "Unexpected error thrown: \(error)") + } + } + + @Test + func testOctetInvalidError() { + let ipAddressValue = "192.168.256.255" + do { + _ = try IPv4Address(ipAddressValue) + #expect(Bool(false), "Expected AddressError.invalidStringAddress to be thrown") + } catch { + #expect( + error as? NetworkAddressError == .invalidStringAddress(address: ipAddressValue), + "Unexpected error thrown: \(error)") + } + } + + @Test + func testAddressFromString() throws { + let ipAddressValue = "192.168.64.25" + let ipAddress = try IPv4Address(ipAddressValue) + #expect(ipAddressValue == ipAddress.description) + #expect(UInt32(0xc0a8_4019) == ipAddress.value) + #expect([192, 168, 64, 25] == ipAddress.networkBytes) + } + + @Test + func testAddressPrefix() throws { + let ipAddressValue = "172.18.204.85" + let ipAddress = try IPv4Address(ipAddressValue) + #expect(0x0000_0000 == ipAddress.prefix(prefixLength: 0).value) + #expect(0xac12_cc55 == ipAddress.prefix(prefixLength: 32).value) + #expect(0xac12_cc55 == ipAddress.prefix(prefixLength: 33).value) + #expect(0xac10_0000 == ipAddress.prefix(prefixLength: 14).value) + } + + @Test + func testCoding() async throws { + let text = "200.100.50.25" + let expected = try IPv4Address(text) + let data = try JSONEncoder().encode(expected) + let actual = try JSONDecoder().decode(IPv4Address.self, from: data) + #expect(expected == actual) + } +} diff --git a/Tests/ContainerizationExtrasTests/TestNetworkAddress+Allocator.swift b/Tests/ContainerizationExtrasTests/TestNetworkAddress+Allocator.swift new file mode 100644 index 00000000..05a3a350 --- /dev/null +++ b/Tests/ContainerizationExtrasTests/TestNetworkAddress+Allocator.swift @@ -0,0 +1,184 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// + +import ContainerizationExtras +import Testing + +@testable import ContainerizationExtras + +final class TestAddressAllocators { + @Test + func testIPv4AddressAllocatorZeroSize() throws { + _ = try IPv4Address.allocator(lower: 0xffff_ffff, size: 1) + do { + _ = try IPv4Address.allocator(lower: 0xffff_ffff, size: 0) + #expect(Bool(false), "Expected AllocatorError.rangeExceeded to be thrown") + } catch { + #expect(error as? AllocatorError == .rangeExceeded, "Unexpected error thrown: \(error)") + } + } + + @Test + func testIPv4AddressAllocatorOverflow() throws { + _ = try IPv4Address.allocator(lower: 0xffff_ff00, size: 256) + do { + _ = try IPv4Address.allocator(lower: 0xffff_ff00, size: 257) + #expect(Bool(false), "Expected AllocatorError.rangeExceeded to be thrown") + } catch { + #expect(error as? AllocatorError == .rangeExceeded, "Unexpected error thrown: \(error)") + } + } + + @Test + func testUInt16AllocatorOverflow() throws { + _ = try UInt16.allocator(lower: 0xfff0, size: 16) + do { + _ = try UInt16.allocator(lower: 0xfff0, size: 17) + #expect(Bool(false), "Expected AllocatorError.rangeExceeded to be thrown") + } catch { + #expect(error as? AllocatorError == .rangeExceeded, "Unexpected error thrown: \(error)") + } + } + + @Test + func testUInt32AllocatorOverflow() throws { + _ = try UInt32.allocator(lower: 0xffff_fff0, size: 16) + do { + _ = try UInt32.allocator(lower: 0xffff_fff0, size: 17) + #expect(Bool(false), "Expected AllocatorError.rangeExceeded to be thrown") + } catch { + #expect(error as? AllocatorError == .rangeExceeded, "Unexpected error thrown: \(error)") + } + } + + @Test + func testFreeUnallocated() throws { + let allocator = try IPv4Address.allocator( + lower: 0xc0a8_4000, size: 256) + do { + _ = try allocator.release(IPv4Address("192.168.64.2")) + #expect(Bool(false), "Expected AllocatorError.notAllocated to be thrown") + } catch { + #expect(error as? AllocatorError == .notAllocated("192.168.64.2"), "Unexpected error thrown: \(error)") + } + } + + @Test + func testChoose() throws { + let allocator = try IPv4Address.allocator( + lower: 0xc0a8_4000, size: 2) + try allocator.reserve(IPv4Address("192.168.64.1")) + do { + _ = try allocator.reserve(IPv4Address("192.168.64.1")) + #expect(Bool(false), "Expected AllocatorError.alreadyAllocated to be thrown") + } catch { + #expect(error as? AllocatorError == .alreadyAllocated("192.168.64.1"), "Unexpected error thrown: \(error)") + } + } + + @Test + func testipv4AddressAllocator() throws { + var allocations = Set() + let lower = try IPv4Address("192.168.64.1").prefix(prefixLength: 24).value + let allocator = try IPv4Address.allocator( + lower: lower, size: 3) + allocations.insert(try allocator.allocate().value) + allocations.insert(try allocator.allocate().value) + allocations.insert(try allocator.allocate().value) + do { + _ = try allocator.allocate() + #expect(Bool(false), "Expected AllocatorError.allocatorFull to be thrown") + } catch { + #expect(error as? AllocatorError == .allocatorFull, "Unexpected error thrown: \(error)") + } + + let address = try IPv4Address("192.168.64.2") + try allocator.release(address) + + let value = try allocator.allocate() + #expect(value == address) + } + + @Test + func testHighestIPv4AddressAllocator() throws { + var allocations = Set() + let lower = try IPv4Address("255.255.255.255").prefix(prefixLength: 32).value + let allocator = try IPv4Address.allocator( + lower: lower, size: 1) + allocations.insert(try allocator.allocate().value) + do { + _ = try allocator.allocate() + #expect(Bool(false), "Expected AllocatorError.allocatorFull to be thrown") + } catch { + #expect(error as? AllocatorError == .allocatorFull, "Unexpected error thrown: \(error)") + } + + let address = try IPv4Address("255.255.255.255") + try allocator.release(address) + let value = try allocator.allocate() + #expect(value == address) + } + + @Test + func testLargestIPv4AddressAllocator() throws { + // NOTE: This allocator should consume about 16MB + _ = try IPv4Address.allocator(lower: 0, size: 1 << 32) + } + + @Test + func testUInt16PortAllocator() throws { + var allocations = Set() + let lower = UInt16(1024) + let allocator = try UInt16.allocator(lower: lower, size: 3) + allocations.insert(try allocator.allocate()) + allocations.insert(try allocator.allocate()) + allocations.insert(try allocator.allocate()) + do { + _ = try allocator.allocate() + #expect(Bool(false), "Expected AllocatorError.allocatorFull to be thrown") + } catch { + #expect(error as? AllocatorError == .allocatorFull, "Unexpected error thrown: \(error)") + } + + let address = UInt16(1025) + try allocator.release(address) + let value = try allocator.allocate() + #expect(value == address) + } + + @Test + func testUInt32PortAllocator() throws { + var allocations = Set() + let lower = UInt32(5000) + let allocator = try UInt32.allocator(lower: lower, size: 3) + allocations.insert(try allocator.allocate()) + allocations.insert(try allocator.allocate()) + allocations.insert(try allocator.allocate()) + do { + _ = try allocator.allocate() + #expect(Bool(false), "Expected AllocatorError.allocatorFull to be thrown") + } catch { + #expect(error as? AllocatorError == .allocatorFull, "Unexpected error thrown: \(error)") + } + + let address = UInt32(5001) + try allocator.release(address) + let value = try allocator.allocate() + #expect(value == address) + } +} diff --git a/Tests/ContainerizationExtrasTests/UInt8+DataBindingTest.swift b/Tests/ContainerizationExtrasTests/UInt8+DataBindingTest.swift new file mode 100644 index 00000000..b2441a04 --- /dev/null +++ b/Tests/ContainerizationExtrasTests/UInt8+DataBindingTest.swift @@ -0,0 +1,92 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Testing + +@testable import ContainerizationNetlink + +struct BufferTest { + @Test func testBufferBind() throws { + let expectedValue: UInt64 = 0x0102_0304_0506_0708 + let expectedBuffer: [UInt8] = [ + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x08, 0x07, 0x06, 0x05, 0x04, 0x03, 0x02, 0x01, + ] + var buffer = [UInt8](repeating: 0, count: 3 * MemoryLayout.size) + guard let ptr = buffer.bind(as: UInt64.self, offset: 2 * MemoryLayout.size) else { + // NOTE: This does not work: + // let ptr: UnsafeMutablePointer = #require(buffer.bind(as: UInt64.self, offset: MemoryLayout.size), "could not bind value to buffer") + // it fails with the error: + // cannot use mutating member on immutable value: '$0' is immutable + // $0.bind(as: $1, offset: $2) + #expect(Bool(false), "could not bind value to buffer") + return + } + + ptr.pointee = expectedValue + #expect(buffer == expectedBuffer) + } + + @Test func testBufferBindRangeError() throws { + var buffer = [UInt8](repeating: 0, count: 3 * MemoryLayout.size) + #expect(buffer.bind(as: UInt64.self, offset: 2 * MemoryLayout.size + 1) == nil) + } + + @Test func testBufferCopy() throws { + let inputBuffer: [UInt8] = [0x01, 0x02, 0x03] + var buffer = [UInt8](repeating: 0, count: 9) + + guard let offset = buffer.copyIn(buffer: inputBuffer, offset: 4) else { + #expect(Bool(false), "could not copy to buffer") + return + } + #expect(offset == 7) + + guard let offset = buffer.copyIn(buffer: inputBuffer, offset: 6) else { + #expect(Bool(false), "could not copy to buffer") + return + } + #expect(offset == 9) + + let expectedBuffer: [UInt8] = [ + 0x00, 0x00, 0x00, 0x00, 0x01, 0x02, 0x01, 0x02, 0x03, + ] + #expect(expectedBuffer == buffer) + + var outputBuffer = [UInt8](repeating: 0, count: 3) + guard let offset = buffer.copyOut(buffer: &outputBuffer, offset: 6) else { + #expect(Bool(false), "could not copy to buffer") + return + } + #expect(offset == 9) + + let expectedOutputBuffer: [UInt8] = [ + 0x01, 0x02, 0x03, + ] + #expect(expectedOutputBuffer == outputBuffer) + } + + @Test func testBufferCopyRangeError() throws { + let inputBuffer: [UInt8] = [0x01, 0x02, 0x03] + var buffer = [UInt8](repeating: 0, count: 9) + + #expect(buffer.copyIn(buffer: inputBuffer, offset: 7) == nil) + + var outputBuffer = [UInt8](repeating: 0, count: 3) + #expect(buffer.copyOut(buffer: &outputBuffer, offset: 7) == nil) + } +} diff --git a/Tests/ContainerizationNetlinkTests/MockNetlinkSocket.swift b/Tests/ContainerizationNetlinkTests/MockNetlinkSocket.swift new file mode 100644 index 00000000..0b5a56ef --- /dev/null +++ b/Tests/ContainerizationNetlinkTests/MockNetlinkSocket.swift @@ -0,0 +1,57 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// + +@testable import ContainerizationNetlink + +class MockNetlinkSocket: NetlinkSocket { + static let ENOMEM: Int32 = 12 + static let EOVERFLOW: Int32 = 75 + + var pid: UInt32 = 0 + + var requests: [[UInt8]] = [] + var responses: [[UInt8]] = [] + + var responseIndex = 0 + + public init() throws {} + + public func send(buf: UnsafeRawPointer!, len: Int, flags: Int32) throws -> Int { + let ptr = buf.bindMemory(to: UInt8.self, capacity: len) + requests.append(Array(UnsafeBufferPointer(start: ptr, count: len))) + return len + } + + public func recv(buf: UnsafeMutableRawPointer!, len: Int, flags: Int32) throws -> Int { + guard responseIndex < responses.count else { + throw NetlinkSocketError.recvFailure(rc: Self.ENOMEM) + } + + let response = responses[responseIndex] + guard len >= response.count else { + throw NetlinkSocketError.recvFailure(rc: 75) + } + + response.withUnsafeBytes { bytes in + buf.copyMemory(from: bytes.baseAddress!, byteCount: response.count) + } + + responseIndex += 1 + return response.count + } +} diff --git a/Tests/ContainerizationNetlinkTests/NetlinkSessionTest.swift b/Tests/ContainerizationNetlinkTests/NetlinkSessionTest.swift new file mode 100644 index 00000000..7b8e1de3 --- /dev/null +++ b/Tests/ContainerizationNetlinkTests/NetlinkSessionTest.swift @@ -0,0 +1,255 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationOS +import Testing + +@testable import ContainerizationNetlink + +struct NetlinkSessionTest { + @Test func testNetworkLinkDown() throws { + let mockSocket = try MockNetlinkSocket() + mockSocket.pid = 0xc00c_c00c + + // Lookup interface by name, truncated response with no attributes (not needed at present). + let expectedLookupRequest = + "3400000012000100000000000cc00cc0110000000000000001000000ffffffff08001d00090000000c0003006574683000000000" + mockSocket.responses.append([ + 0x20, 0x00, 0x00, 0x00, 0x10, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x0c, 0xc0, 0x0c, 0xc0, + 0x00, 0x00, 0x01, 0x00, 0x02, 0x00, 0x00, 0x00, + 0x43, 0x10, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, + ]) + + // Network down for interface. + let expectedDownRequest = "2000000010000500000000000cc00cc0110000000200000000000000ffffffff" + mockSocket.responses.append([ + 0x24, 0x00, 0x00, 0x00, 0x02, 0x00, 0x00, 0x01, + 0x00, 0x00, 0x00, 0x00, 0x0c, 0xc0, 0x0c, 0xc0, + 0x00, 0x00, 0x00, 0x00, 0x20, 0x00, 0x00, 0x00, + 0x10, 0x00, 0x05, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x0c, 0x00, 0x00, 0x00, + ]) + + let session = NetlinkSession(socket: mockSocket) + try session.linkSet(interface: "eth0", up: false) + + #expect(mockSocket.requests.count == 2) + #expect(mockSocket.responseIndex == 2) + mockSocket.requests[0][8..<12] = [0, 0, 0, 0] + #expect(expectedLookupRequest == mockSocket.requests[0].hexEncodedString()) + mockSocket.requests[1][8..<12] = [0, 0, 0, 0] + #expect(expectedDownRequest == mockSocket.requests[1].hexEncodedString()) + } + + @Test func testNetworkLinkUp() throws { + let mockSocket = try MockNetlinkSocket() + mockSocket.pid = 0x0cc0_0cc0 + + // Lookup interface by name, truncated response with no attributes (not needed at present). + let expectedLookupRequest = + "340000001200010000000000c00cc00c110000000000000001000000ffffffff08001d00090000000c0003006574683000000000" + mockSocket.responses.append([ + 0x20, 0x00, 0x00, 0x00, 0x10, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0xc0, 0x0c, 0xc0, 0x0c, + 0x00, 0x00, 0x01, 0x00, 0x02, 0x00, 0x00, 0x00, + 0x43, 0x10, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, + ]) + + // Network up for interface. + let expectedUpRequest = "200000001000050000000000c00cc00c110000000200000001000000ffffffff" + mockSocket.responses.append([ + 0x24, 0x00, 0x00, 0x00, 0x02, 0x00, 0x00, 0x01, + 0x00, 0x00, 0x00, 0x00, 0xc0, 0x0c, 0xc0, 0x0c, + 0x00, 0x00, 0x00, 0x00, 0x20, 0x00, 0x00, 0x00, + 0x10, 0x00, 0x05, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x11, 0x00, 0x00, 0x00, + ]) + + let session = NetlinkSession(socket: mockSocket) + try session.linkSet(interface: "eth0", up: true) + + #expect(mockSocket.requests.count == 2) + #expect(mockSocket.responseIndex == 2) + mockSocket.requests[0][8..<12] = [0, 0, 0, 0] + #expect(expectedLookupRequest == mockSocket.requests[0].hexEncodedString()) + mockSocket.requests[1][8..<12] = [0, 0, 0, 0] + #expect(expectedUpRequest == mockSocket.requests[1].hexEncodedString()) + } + + @Test func testNetworkLinkGetEth0() throws { + let mockSocket = try MockNetlinkSocket() + mockSocket.pid = 0x1234_5678 + + // Lookup interface by name, truncated response with three attributes. + let expectedLookupRequest = + "34000000120001000000000078563412110000000000000001000000ffffffff08001d00090000000c0003006574683000000000" + mockSocket.responses.append([ + 0x3c, 0x00, 0x00, 0x00, 0x10, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x78, 0x56, 0x34, 0x12, + 0x00, 0x00, 0x01, 0x00, 0x02, 0x00, 0x00, 0x00, + 0x43, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x09, 0x00, 0x03, 0x00, 0x65, 0x74, 0x68, 0x30, + 0x00, 0x00, 0x00, 0x00, 0x08, 0x00, 0x0d, 0x00, + 0xe8, 0x03, 0x00, 0x00, 0x05, 0x00, 0x10, 0x00, + 0x06, 0x00, 0x00, 0x00, + ]) + + let session = NetlinkSession(socket: mockSocket) + let links = try session.linkGet(interface: "eth0") + + #expect(mockSocket.requests.count == 1) + #expect(mockSocket.responseIndex == 1) + mockSocket.requests[0][8..<12] = [0, 0, 0, 0] + #expect(expectedLookupRequest == mockSocket.requests[0].hexEncodedString()) + try #require(links.count == 1) + + #expect(links[0].interfaceIndex == 2) + try #require(links[0].attrDatas.count == 3) + #expect(links[0].attrDatas[0].attribute.type == 0x0003) + #expect(links[0].attrDatas[0].attribute.len == 0x0009) + #expect(links[0].attrDatas[0].data == [0x65, 0x74, 0x68, 0x30, 0x00]) + #expect(links[0].attrDatas[1].attribute.type == 0x000d) + #expect(links[0].attrDatas[1].attribute.len == 0x0008) + #expect(links[0].attrDatas[1].data == [0xe8, 0x03, 0x00, 0x00]) + #expect(links[0].attrDatas[2].attribute.type == 0x0010) + #expect(links[0].attrDatas[2].attribute.len == 0x0005) + #expect(links[0].attrDatas[2].data == [0x06]) + } + + @Test func testNetworkLinkGet() throws { + let mockSocket = try MockNetlinkSocket() + mockSocket.pid = 0x8765_4321 + + // Lookup all interfaces, responses with only the interface name attribute. + let expectedLookupRequest = "28000000120001030000000021436587110000000000000001000000ffffffff08001d0009000000" + mockSocket.responses.append([ + 0x28, 0x00, 0x00, 0x00, 0x10, 0x00, 0x02, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x21, 0x43, 0x65, 0x87, + 0x00, 0x00, 0x04, 0x03, 0x01, 0x00, 0x00, 0x00, + 0x49, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x07, 0x00, 0x03, 0x00, 0x6c, 0x6f, 0x00, 0x00, + ]) + mockSocket.responses.append([ + 0x2c, 0x00, 0x00, 0x00, 0x10, 0x00, 0x02, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x21, 0x43, 0x65, 0x87, + 0x00, 0x00, 0x00, 0x03, 0x04, 0x00, 0x00, 0x00, + 0x80, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x0a, 0x00, 0x03, 0x00, 0x74, 0x75, 0x6e, 0x6c, + 0x30, 0x00, 0x00, 0x00, + ]) + mockSocket.responses.append([ + 0x14, 0x00, 0x00, 0x00, 0x03, 0x00, 0x02, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x21, 0x43, 0x65, 0x87, + 0x00, 0x00, 0x00, 0x00, + ]) + + let session = NetlinkSession(socket: mockSocket) + let links = try session.linkGet() + + #expect(mockSocket.requests.count == 1) + #expect(mockSocket.responseIndex == 3) + mockSocket.requests[0][8..<12] = [0, 0, 0, 0] + #expect(expectedLookupRequest == mockSocket.requests[0].hexEncodedString()) + try #require(links.count == 2) + + #expect(links[0].interfaceIndex == 1) + try #require(links[0].attrDatas.count == 1) + #expect(links[0].attrDatas[0].attribute.type == 0x0003) + #expect(links[0].attrDatas[0].attribute.len == 0x0007) + #expect(links[0].attrDatas[0].data == [0x6c, 0x6f, 0x00]) + + #expect(links[1].interfaceIndex == 4) + try #require(links[1].attrDatas.count == 1) + #expect(links[1].attrDatas[0].attribute.type == 0x0003) + #expect(links[1].attrDatas[0].attribute.len == 0x000a) + #expect(links[1].attrDatas[0].data == [0x74, 0x75, 0x6e, 0x6c, 0x30, 0x00]) + } + + @Test func testNetworkAddressAdd() throws { + let mockSocket = try MockNetlinkSocket() + mockSocket.pid = 0xc00c_c00c + + // Lookup interface by name, truncated response with no attributes (not needed at present). + let expectedLookupRequest = + "3400000012000100000000000cc00cc0110000000000000001000000ffffffff08001d00090000000c0003006574683000000000" + mockSocket.responses.append([ + 0x20, 0x00, 0x00, 0x00, 0x10, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x0c, 0xc0, 0x0c, 0xc0, + 0x00, 0x00, 0x01, 0x00, 0x02, 0x00, 0x00, 0x00, + 0x43, 0x10, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, + ]) + + // Network down for interface. + let expectedAddRequest = "2800000014000506000000000cc00cc0021800000200000008000200c0a840fa08000100c0a840fa" + mockSocket.responses.append([ + 0x24, 0x00, 0x00, 0x00, 0x02, 0x00, 0x00, 0x01, + 0x00, 0x00, 0x00, 0x00, 0x0c, 0xc0, 0x0c, 0xc0, + 0x00, 0x00, 0x00, 0x00, 0x28, 0x00, 0x00, 0x00, + 0x14, 0x00, 0x05, 0x06, 0x00, 0x00, 0x00, 0x00, + 0x1f, 0x00, 0x00, 0x00, + ]) + + let session = NetlinkSession(socket: mockSocket) + try session.addressAdd(interface: "eth0", address: "192.168.64.250/24") + + #expect(mockSocket.requests.count == 2) + #expect(mockSocket.responseIndex == 2) + mockSocket.requests[0][8..<12] = [0, 0, 0, 0] + #expect(expectedLookupRequest == mockSocket.requests[0].hexEncodedString()) + #expect(expectedAddRequest == mockSocket.requests[1].hexEncodedString()) + } + + @Test func testNetworkRouteAddIpLink() throws { + let mockSocket = try MockNetlinkSocket() + mockSocket.pid = 0xc00c_c00c + + // Lookup interface by name, truncated response with no attributes (not needed at present). + let expectedLookupRequest = + "3400000012000100000000000cc00cc0110000000000000001000000ffffffff08001d00090000000c0003006574683000000000" + mockSocket.responses.append([ + 0x20, 0x00, 0x00, 0x00, 0x10, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x0c, 0xc0, 0x0c, 0xc0, + 0x00, 0x00, 0x01, 0x00, 0x02, 0x00, 0x00, 0x00, + 0x43, 0x10, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, + ]) + + // Add link route. + let expectedAddRequest = + "3400000018000506000000000cc00cc002180000fe02fd010000000008000100c0a8400008000700c0a840030800040002000000" + mockSocket.responses.append([ + 0x24, 0x00, 0x00, 0x00, 0x02, 0x00, 0x00, 0x01, + 0x00, 0x00, 0x00, 0x00, 0x0c, 0xc0, 0x0c, 0xc0, + 0x00, 0x00, 0x00, 0x00, 0x28, 0x00, 0x00, 0x00, + 0x14, 0x00, 0x05, 0x06, 0x00, 0x00, 0x00, 0x00, + 0x1f, 0x00, 0x00, 0x00, + ]) + + let session = NetlinkSession(socket: mockSocket) + try session.routeAdd( + interface: "eth0", + destinationAddress: "192.168.64.0/24", + srcAddr: "192.168.64.3" + ) + + #expect(mockSocket.requests.count == 2) + #expect(mockSocket.responseIndex == 2) + mockSocket.requests[0][8..<12] = [0, 0, 0, 0] + #expect(expectedLookupRequest == mockSocket.requests[0].hexEncodedString()) + mockSocket.requests[1][8..<12] = [0, 0, 0, 0] + #expect(expectedAddRequest == mockSocket.requests[1].hexEncodedString()) + } +} diff --git a/Tests/ContainerizationNetlinkTests/TypesTest.swift b/Tests/ContainerizationNetlinkTests/TypesTest.swift new file mode 100644 index 00000000..574c821a --- /dev/null +++ b/Tests/ContainerizationNetlinkTests/TypesTest.swift @@ -0,0 +1,111 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// + +import Testing + +@testable import ContainerizationNetlink + +struct TypesTest { + @Test func testNetlinkMessageHeader() throws { + let expectedValue = NetlinkMessageHeader( + len: 0x1234_5678, type: 0x9abc, flags: 0xdef0, seq: 0x1122_3344, pid: 0x5566_7788) + let expectedBuffer: [UInt8] = [ + 0x78, 0x56, 0x34, 0x12, + 0xbc, 0x9a, 0xf0, 0xde, + 0x44, 0x33, 0x22, 0x11, + 0x88, 0x77, 0x66, 0x55, + ] + var buffer = [UInt8](repeating: 0, count: NetlinkMessageHeader.size) + let offset = try expectedValue.appendBuffer(&buffer, offset: 0) + #expect(NetlinkMessageHeader.size == offset) + #expect(expectedBuffer == buffer) + guard let (offset, value) = buffer.copyOut(as: NetlinkMessageHeader.self) else { + #expect(Bool(false), "could not bind value to buffer") + return + + } + + #expect(offset == NetlinkMessageHeader.size) + #expect(expectedValue == value) + } + + @Test func testInterfaceInfo() throws { + let expectedValue = InterfaceInfo( + family: UInt8(AddressFamily.AF_NETLINK), type: 0x1234, index: 0x1234_5678, flags: 0x9abc_def0, + change: 0x0fed_cba9 + ) + let expectedBuffer: [UInt8] = [ + 0x10, 0x00, 0x34, 0x12, + 0x78, 0x56, 0x34, 0x12, + 0xf0, 0xde, 0xbc, 0x9a, + 0xa9, 0xcb, 0xed, 0x0f, + ] + var buffer = [UInt8](repeating: 0, count: InterfaceInfo.size) + let offset = try expectedValue.appendBuffer(&buffer, offset: 0) + #expect(InterfaceInfo.size == offset) + #expect(expectedBuffer == buffer) + guard let (offset, value) = buffer.copyOut(as: InterfaceInfo.self) else { + #expect(Bool(false), "could not bind value to buffer") + return + + } + + #expect(offset == InterfaceInfo.size) + #expect(expectedValue == value) + } + + @Test func testAddressInfo() throws { + let expectedValue = AddressInfo( + family: UInt8(AddressFamily.AF_INET), prefixLength: 24, flags: 0x5a, scope: 0xa5, index: 0xdead_beef) + let expectedBuffer: [UInt8] = [ + 0x02, 0x18, 0x5a, 0xa5, + 0xef, 0xbe, 0xad, 0xde, + ] + var buffer = [UInt8](repeating: 0, count: AddressInfo.size) + let offset = try expectedValue.appendBuffer(&buffer, offset: 0) + #expect(AddressInfo.size == offset) + #expect(expectedBuffer == buffer) + guard let (offset, value) = buffer.copyOut(as: AddressInfo.self) else { + #expect(Bool(false), "could not bind value to buffer") + return + + } + + #expect(offset == AddressInfo.size) + #expect(expectedValue == value) + } + + @Test func testRTAttribute() throws { + let expectedValue = RTAttribute(len: 0x1234, type: 0x5678) + let expectedBuffer: [UInt8] = [ + 0x34, 0x12, 0x78, 0x56, + ] + var buffer = [UInt8](repeating: 0, count: RTAttribute.size) + let offset = try expectedValue.appendBuffer(&buffer, offset: 0) + #expect(RTAttribute.size == offset) + #expect(expectedBuffer == buffer) + guard let (offset, value) = buffer.copyOut(as: RTAttribute.self) else { + #expect(Bool(false), "could not bind value to buffer") + return + + } + + #expect(offset == RTAttribute.size) + #expect(expectedValue == value) + } +} diff --git a/Tests/ContainerizationOCITests/OCIImageTests.swift b/Tests/ContainerizationOCITests/OCIImageTests.swift new file mode 100644 index 00000000..0c0c769d --- /dev/null +++ b/Tests/ContainerizationOCITests/OCIImageTests.swift @@ -0,0 +1,65 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// + +import Testing + +@testable import ContainerizationOCI + +struct OCITests { + @Test func config() { + let config = ContainerizationOCI.ImageConfig() + let rootfs = ContainerizationOCI.Rootfs(type: "foo", diffIDs: ["diff1", "diff2"]) + let history = ContainerizationOCI.History() + + let image = ContainerizationOCI.Image(architecture: "arm64", os: "linux", config: config, rootfs: rootfs, history: [history]) + #expect(image.rootfs.type == "foo") + } + + @Test func descriptor() { + let platform = ContainerizationOCI.Platform(arch: "arm64", os: "linux") + let descriptor = ContainerizationOCI.Descriptor(mediaType: MediaTypes.descriptor, digest: "123", size: 0, platform: platform) + + #expect(descriptor.platform?.architecture == "arm64") + #expect(descriptor.platform?.os == "linux") + } + + @Test func index() { + var desciptors: [ContainerizationOCI.Descriptor] = [] + for i in 0..<5 { + let descriptor = ContainerizationOCI.Descriptor(mediaType: MediaTypes.descriptor, digest: "\(i)", size: Int64(i)) + desciptors.append(descriptor) + } + + let index = ContainerizationOCI.Index(schemaVersion: 1, manifests: desciptors) + #expect(index.manifests.count == 5) + } + + @Test func manifests() { + var desciptors: [ContainerizationOCI.Descriptor] = [] + for i in 0..<5 { + let descriptor = ContainerizationOCI.Descriptor(mediaType: MediaTypes.descriptor, digest: "\(i)", size: Int64(i)) + desciptors.append(descriptor) + } + + let config = ContainerizationOCI.Descriptor(mediaType: MediaTypes.descriptor, digest: "123", size: 0) + + let manifest = ContainerizationOCI.Manifest(schemaVersion: 1, config: config, layers: desciptors) + #expect(manifest.config.digest == "123") + #expect(manifest.layers.count == 5) + } +} diff --git a/Tests/ContainerizationOCITests/OCIPlatformTests.swift b/Tests/ContainerizationOCITests/OCIPlatformTests.swift new file mode 100644 index 00000000..b969f326 --- /dev/null +++ b/Tests/ContainerizationOCITests/OCIPlatformTests.swift @@ -0,0 +1,69 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// + +import Testing + +@testable import ContainerizationOCI + +struct OCIPlatformTests { + @Test func identicalPlatforms() { + let amd64lhs = Platform(arch: "amd64", os: "linux") + let amd64rhs = Platform(arch: "amd64", os: "linux") + #expect(amd64lhs == amd64rhs, "amd64 platforms should be equal") + + let arm64lhs = Platform(arch: "arm64", os: "linux") + let arm64rhs = Platform(arch: "arm64", os: "linux") + #expect(arm64lhs == arm64rhs, "arm64 platforms should be equal") + } + + @Test func differentOS() { + let lhs = Platform(arch: "arm64", os: "linux") + let rhs = Platform(arch: "arm64", os: "darwin") + #expect(lhs != rhs, "Different OS should not be equal") + } + + @Test func differentArch() { + let lhs = Platform(arch: "amd64", os: "linux") + let rhs = Platform(arch: "arm64", os: "linux") + #expect(lhs != rhs, "Different arch should not be equal") + } + + @Test func arm64_sameVariant() { + let lhs = Platform(arch: "arm64", os: "linux", variant: "v8") + let rhs = Platform(arch: "arm64", os: "linux", variant: "v8") + #expect(lhs == rhs, "Both OS arm64, same arch, same variant => equal") + } + + @Test func arm64_nilAndV8() { + let lhs = Platform(arch: "arm64", os: "linux", variant: nil) + let rhs = Platform(arch: "arm64", os: "linux", variant: "v8") + #expect(lhs == rhs, "One variant nil and other v8 => equal under special arm64 rule") + } + + @Test func arm64_nilAndV7() { + let lhs = Platform(arch: "arm64", os: "linux", variant: nil) + let rhs = Platform(arch: "arm64", os: "linux", variant: "v7") + #expect(lhs != rhs, "nil vs v7 is not covered by the special rule => not equal") + } + + @Test func arm64_bothNil() { + let lhs = Platform(arch: "arm64", os: "linux", variant: nil) + let rhs = Platform(arch: "arm64", os: "linux", variant: nil) + #expect(lhs == rhs, "Both nil variants => variantEqual is true => overall equal") + } +} diff --git a/Tests/ContainerizationOCITests/ReferenceTests.swift b/Tests/ContainerizationOCITests/ReferenceTests.swift new file mode 100644 index 00000000..8c289f2c --- /dev/null +++ b/Tests/ContainerizationOCITests/ReferenceTests.swift @@ -0,0 +1,106 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// swiftlint:disable force_cast large_tuple + +import ContainerizationError +import Foundation +import Testing + +@testable import ContainerizationOCI + +@Suite("Reference Parse Tests") +struct ReferenceParseTests { + internal struct ReferenceParseTestCase: Sendable { + let input: String + let domain: String? + let path: String + let tag: String? + let digest: String? + init(input: String, domain: String? = nil, path: String, tag: String? = nil, digest: String? = nil) { + self.input = input + self.domain = domain + self.path = path + self.tag = tag + self.digest = digest + } + } + + @Test(arguments: [ + ReferenceParseTestCase(input: "tensorflow/tensorflow", path: "tensorflow/tensorflow"), + ReferenceParseTestCase(input: "debian", path: "debian"), + ReferenceParseTestCase(input: "repo_with_underscore", path: "repo_with_underscore"), + ReferenceParseTestCase(input: "swift5.10:alpine", path: "swift5.10", tag: "alpine"), + ReferenceParseTestCase(input: "registry.com.with.port:5000/no_tag", domain: "registry.com.with.port:5000", path: "no_tag"), + ReferenceParseTestCase(input: "registry.com.with.port:5000/name/foo/bar:tag23", domain: "registry.com.with.port:5000", path: "name/foo/bar", tag: "tag23"), + ReferenceParseTestCase(input: "some-repo-with-dashes/name", path: "some-repo-with-dashes/name"), + ReferenceParseTestCase(input: "domain.with-dashes/cool-image:foo", domain: "domain.with-dashes", path: "cool-image", tag: "foo"), + ReferenceParseTestCase(input: "localhost:8080/123:latest", domain: "localhost:8080", path: "123", tag: "latest"), + ReferenceParseTestCase( + input: "localhost/123@sha256:\(String(repeating: "a", count: 64))", domain: "localhost", path: "123", digest: "sha256:\(String(repeating: "a", count: 64))"), + ReferenceParseTestCase( + input: "registry.com.with.port:1254/foo/bar/baz@sha256:\(String(repeating: "abcd", count: 16))", domain: "registry.com.with.port:1254", path: "foo/bar/baz", + digest: "sha256:\(String(repeating: "abcd", count: 16))"), + ReferenceParseTestCase(input: "192.168.1.1:5544/local/swift:6.0", domain: "192.168.1.1:5544", path: "local/swift", tag: "6.0"), + ReferenceParseTestCase(input: "[abc12::4]:5683/swift", domain: "[abc12::4]:5683", path: "swift"), + ]) + func validReferenceParse(testCase: ReferenceParseTestCase) async throws { + #expect(throws: Never.self) { + let parsed = try Reference.parse(testCase.input) + #expect(parsed.path == testCase.path) + #expect(parsed.domain == testCase.domain) + #expect(parsed.digest == testCase.digest) + #expect(parsed.tag == testCase.tag) + } + } + + @Test(arguments: [ + "localhost:8080", + "localhost/123@sha256:\(String(repeating: "a", count: 200))", + "https://github.com/apple/containerization", + "", + "-testString", + "-testString/image", + "-testString.com/image/release", + "foo///bar", + "mostly.valid/image/but/Caps", + "[abc12::4]", + "[abc12::4]:abc12::4", + "[2001:db8:3:4::192.0.2.33]:5000/debian", + "1a3f5e7d9c1b3a5f7e9d1c3b5a7f9e1d3c5b7a9f1e3d5d7c9b1a3f5e7d9c1b3a", + ]) + func invalidReferenceParse(input: String) async throws { + #expect(throws: ContainerizationError.self) { + try Reference.parse(input) + } + } + + @Test(arguments: [ + ReferenceParseTestCase(input: "only_name", path: "only_name", tag: "latest"), + ReferenceParseTestCase(input: "docker.io/alpine", domain: "docker.io", path: "library/alpine", tag: "latest"), + ReferenceParseTestCase(input: "ghcr.io/myrepo/alpine", domain: "ghcr.io", path: "myrepo/alpine", tag: "latest"), + ReferenceParseTestCase(input: "name@sha256:" + String(repeating: "1", count: 64), path: "name", digest: "sha256:" + String(repeating: "1", count: 64)), + ReferenceParseTestCase(input: "registry-1.docker.io/testrepo/myname:v2", domain: "registry-1.docker.io", path: "testrepo/myname", tag: "v2"), + ]) + func testNormalize(testCase: ReferenceParseTestCase) throws { + let parsed = try Reference.parse(testCase.input) + parsed.normalize() + #expect(parsed.path == testCase.path) + #expect(parsed.domain == testCase.domain) + #expect(parsed.digest == testCase.digest) + #expect(parsed.tag == testCase.tag) + } +} diff --git a/Tests/ContainerizationOCITests/RegistryClientTests.swift b/Tests/ContainerizationOCITests/RegistryClientTests.swift new file mode 100644 index 00000000..2f8bf211 --- /dev/null +++ b/Tests/ContainerizationOCITests/RegistryClientTests.swift @@ -0,0 +1,368 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// + +import ContainerizationError +import ContainerizationIO +import Crypto +import Foundation +import NIO +import Synchronization +import Testing + +@testable import ContainerizationOCI + +struct OCIClientTests: ~Copyable { + private var contentPath: URL + private let fileManager = FileManager.default + private var encoder = JSONEncoder() + + init() async throws { + let testDir = fileManager.uniqueTemporaryDirectory() + let contentPath = testDir.appendingPathComponent("content") + try fileManager.createDirectory(at: contentPath, withIntermediateDirectories: true) + self.contentPath = contentPath + + encoder.outputFormatting = .prettyPrinted + } + + deinit { + try? fileManager.removeItem(at: contentPath) + } + + private static var arch: String? { + var uts = utsname() + let result = uname(&uts) + guard result == EXIT_SUCCESS else { + return nil + } + + let machine = Data(bytes: &uts.machine, count: 256) + guard let arch = String(bytes: machine, encoding: .utf8) else { + return nil + } + + switch arch.lowercased().trimmingCharacters(in: .controlCharacters) { + case "arm64": + return "arm64" + default: + return "amd64" + } + } + + @Test(.enabled(if: hasRegistryCredentials)) + func fetchToken() async throws { + let client = RegistryClient(host: "ghcr.io", authentication: Self.authentication) + let request = TokenRequest(realm: "https://ghcr.io/token", service: "ghcr.io", clientId: "tests", scope: nil) + let response = try await client.fetchToken(request: request) + #expect(response.getToken() != nil) + } + + @Test func ping() async throws { + let client = RegistryClient(host: "registry-1.docker.io") + try await client.ping() + } + + @Test func pingWithInvalidCredentials() async throws { + let authentication = BasicAuthentication(username: "foo", password: "bar") + let client = RegistryClient(host: "ghcr.io", authentication: authentication) + let error = await #expect(throws: RegistryClient.Error.self) { try await client.ping() } + if case .invalidStatus = error { + } else { + Issue.record("encountered unexpected error \(error)") + } + } + + @Test(.enabled(if: hasRegistryCredentials)) + func pingWithCredentials() async throws { + let client = RegistryClient(host: "ghcr.io", authentication: Self.authentication) + try await client.ping() + } + + @Test(.enabled(if: hasRegistryCredentials)) + func resolve() async throws { + let client = RegistryClient(host: "ghcr.io", authentication: Self.authentication) + let descriptor = try await client.resolve(name: "apple-uat/test-images/alpine-arm64", tag: "v1") + #expect(descriptor.mediaType == MediaTypes.dockerManifest) + #expect(descriptor.size != 0) + #expect(!descriptor.digest.isEmpty) + } + + @Test(.enabled(if: hasRegistryCredentials)) + func resolveSha() async throws { + let client = RegistryClient(host: "ghcr.io", authentication: Self.authentication) + let descriptor = try await client.resolve(name: "apple-uat/test-images/alpine-arm64", tag: "sha256:d93f3925c65439895956e30e5944c79b2e3260ea7769ef0077e1568699f76e4e") + let namedDescriptor = try await client.resolve(name: "apple-uat/test-images/alpine-arm64", tag: "v1") + #expect(descriptor == namedDescriptor) + #expect(descriptor.mediaType == MediaTypes.dockerManifest) + #expect(descriptor.size != 0) + #expect(!descriptor.digest.isEmpty) + } + + @Test(.enabled(if: hasRegistryCredentials)) + func fetchManifest() async throws { + let client = RegistryClient(host: "ghcr.io", authentication: Self.authentication) + let descriptor = try await client.resolve(name: "apple-uat/test-images/alpine-arm64", tag: "v1") + let manifest: Manifest = try await client.fetch(name: "apple-uat/test-images/alpine-arm64", descriptor: descriptor) + #expect(manifest.schemaVersion == 2) + #expect(manifest.layers.count == 1) + } + + @Test(.enabled(if: hasRegistryCredentials)) + func fetchManifestAsData() async throws { + let client = RegistryClient(host: "ghcr.io", authentication: Self.authentication) + let descriptor = try await client.resolve(name: "apple-uat/test-images/alpine-arm64", tag: "v1") + let manifestData = try await client.fetchData(name: "apple-uat/test-images/alpine-arm64", descriptor: descriptor) + let checksum = SHA256.hash(data: manifestData) + #expect(descriptor.digest == checksum.digest) + } + + @Test(.enabled(if: hasRegistryCredentials)) + func fetchConfig() async throws { + let client = RegistryClient(host: "ghcr.io", authentication: Self.authentication) + let descriptor = try await client.resolve(name: "apple-uat/test-images/alpine-arm64", tag: "v1") + let manifest: Manifest = try await client.fetch(name: "apple-uat/test-images/alpine-arm64", descriptor: descriptor) + let image: Image = try await client.fetch(name: "apple-uat/test-images/alpine-arm64", descriptor: manifest.config) + // This is an alpine image - lets check its cmd and verify its set to /bin/sh + #expect(image.config?.cmd == ["/bin/sh"]) + #expect(image.rootfs.diffIDs.count == 1) + } + + @Test(.enabled(if: hasRegistryCredentials)) + func fetchBlob() async throws { + let client = RegistryClient(host: "ghcr.io", authentication: Self.authentication) + let descriptor = try await client.resolve(name: "apple-uat/test-images/alpine-arm64", tag: "v1") + let manifest: Manifest = try await client.fetch(name: "apple-uat/test-images/alpine-arm64", descriptor: descriptor) + var called = false + var done = false + try await client.fetchBlob(name: "apple-uat/test-images/alpine-arm64", descriptor: manifest.layers.first!) { (expected, body) in + called = true + #expect(expected != 0) + var received = 0 + for try await buffer in body { + received += buffer.readableBytes + if received == expected { + done = true + } + } + } + #expect(called) + #expect(done) + } + + @Test(.enabled(if: hasRegistryCredentials)) + func pushIndex() async throws { + let client = RegistryClient(host: "ghcr.io", authentication: Self.authentication) + let indexDescriptor = try await client.resolve(name: "apple-uat/test-images/alpine", tag: "3.21") + let index: Index = try await client.fetch(name: "apple-uat/test-images/alpine", descriptor: indexDescriptor) + + let arch = Self.arch ?? "arm64" + let variant: String? = (arch == "arm64") ? "v8" : nil + let platform = Platform(arch: arch, os: "linux", variant: variant) + + var manifestDescriptor: Descriptor? + for m in index.manifests where m.platform == platform { + manifestDescriptor = m + break + } + + #expect(manifestDescriptor != nil) + + let manifest: Manifest = try await client.fetch(name: "apple-uat/test-images/alpine", descriptor: manifestDescriptor!) + let imgConfig: Image = try await client.fetch(name: "apple-uat/test-images/alpine", descriptor: manifest.config) + + let layer = try #require(manifest.layers.first) + let blobPath = contentPath.appendingPathComponent(layer.digest) + let outputStream = OutputStream(toFileAtPath: blobPath.path, append: false) + #expect(outputStream != nil) + + try await outputStream!.withThrowingOpeningStream { + try await client.fetchBlob(name: "apple-uat/test-images/alpine", descriptor: layer) { (expected, body) in + var received: Int64 = 0 + for try await buffer in body { + received += Int64(buffer.readableBytes) + + buffer.withUnsafeReadableBytes { pointer in + let unsafeBufferPointer = pointer.bindMemory(to: UInt8.self) + if let addr = unsafeBufferPointer.baseAddress { + outputStream!.write(addr, maxLength: buffer.readableBytes) + } + } + } + + #expect(received == expected) + } + } + + let name = "apple-uat/test-images/image-push" + let ref = "latest" + + // Push the layer first. + do { + let content = try LocalContent(path: blobPath) + let generator = { + let stream = try ReadStream(url: content.path) + try stream.reset() + return stream.stream + } + try await client.push(name: name, ref: ref, descriptor: layer, streamGenerator: generator, progress: nil) + } catch let err as ContainerizationError { + guard err.code == .exists else { + throw err + } + } + + // Push the image configuration. + var imgConfigDesc: Descriptor? + do { + imgConfigDesc = try await self.pushDescriptor( + client: client, + name: name, + ref: ref, + content: imgConfig, + baseDescriptor: manifest.config + ) + } catch let err as ContainerizationError { + guard err.code != .exists else { + return + } + throw err + } + + // Push the image manifest. + let newManifest = Manifest( + schemaVersion: manifest.schemaVersion, + mediaType: manifest.mediaType!, + config: imgConfigDesc!, + layers: manifest.layers, + annotations: manifest.annotations + ) + let manifestDesc = try await self.pushDescriptor( + client: client, + name: name, + ref: ref, + content: newManifest, + baseDescriptor: manifestDescriptor! + ) + + // Push the index. + let newIndex = Index( + schemaVersion: index.schemaVersion, + mediaType: index.mediaType, + manifests: [manifestDesc], + annotations: index.annotations + ) + try await self.pushDescriptor( + client: client, + name: name, + ref: ref, + content: newIndex, + baseDescriptor: indexDescriptor + ) + } + + @Test(.enabled(if: hasRegistryCredentials)) + func resolveWithRetry() async throws { + let counter = Mutex(0) + let client = RegistryClient( + host: "ghcr.io", + authentication: Self.authentication, + retryOptions: RetryOptions( + maxRetries: 3, + retryInterval: 500_000_000, + shouldRetry: ({ response in + if response.status == .notFound { + counter.withLock { $0 += 1 } + return true + } + return false + }) + ) + ) + do { + _ = try await client.resolve(name: "conatinerization/not-exists", tag: "foo") + } catch { + #expect(counter.withLock { $0 } <= 3) + } + } + + // MARK: private functions + + static var hasRegistryCredentials: Bool { + authentication != nil + } + + static var authentication: Authentication? { + let env = ProcessInfo.processInfo.environment + guard let password = ProcessInfo.processInfo.environment["REGISTRY_TOKEN"], + let username = ProcessInfo.processInfo.environment["REGISTRY_USERNAME"] + else { + return nil + } + return BasicAuthentication(username: username, password: password) + } + + @discardableResult + private func pushDescriptor( + client: RegistryClient, + name: String, + ref: String, + content: T, + baseDescriptor: Descriptor + ) async throws -> Descriptor { + let encoded = try self.encoder.encode(content) + let digest = SHA256.hash(data: encoded) + let descriptor = Descriptor( + mediaType: baseDescriptor.mediaType, + digest: digest.digest, + size: Int64(encoded.count), + urls: baseDescriptor.urls, + annotations: baseDescriptor.annotations, + platform: baseDescriptor.platform + ) + let generator = { + let stream = ReadStream(data: encoded) + try stream.reset() + return stream.stream + } + + try await client.push( + name: name, + ref: ref, + descriptor: descriptor, + streamGenerator: generator, + progress: nil + ) + return descriptor + } +} + +extension OutputStream { + fileprivate func withThrowingOpeningStream(_ closure: () async throws -> Void) async throws { + self.open() + defer { self.close() } + + try await closure() + } +} + +extension SHA256.Digest { + fileprivate var digest: String { + let parts = self.description.split(separator: ": ") + return "sha256:\(parts[1])" + } +} diff --git a/Tests/ContainerizationOSTests/KeychainQueryTests.swift b/Tests/ContainerizationOSTests/KeychainQueryTests.swift new file mode 100644 index 00000000..9a54bd3a --- /dev/null +++ b/Tests/ContainerizationOSTests/KeychainQueryTests.swift @@ -0,0 +1,51 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// + +import Foundation +import Testing + +@testable import ContainerizationOS + +struct KeychainQueryTests { + let id = "com.example.container-testing-keychain" + let domain = "testing-keychain.example.com" + let user = "containerization-test" + + let kq = KeychainQuery() + + @Test(.enabled(if: !isCI)) + func keychainQuery() throws { + defer { try? kq.delete(id: id, host: domain) } + + do { + try kq.save(id: id, host: domain, user: user, token: "foobar") + #expect(try kq.exists(id: id, host: domain)) + + let fetched = try kq.get(id: id, host: domain) + let result = try #require(fetched) + #expect(result.account == user) + #expect(result.data == "foobar") + } catch KeychainQuery.Error.unhandledError(status: -25308) { + // ignore errSecInteractionNotAllowed + } + } + + private static var isCI: Bool { + ProcessInfo.processInfo.environment["CI"] != nil + } +} diff --git a/Tests/ContainerizationOSTests/UserTests.swift b/Tests/ContainerizationOSTests/UserTests.swift new file mode 100644 index 00000000..05a854e8 --- /dev/null +++ b/Tests/ContainerizationOSTests/UserTests.swift @@ -0,0 +1,164 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationError +import ContainerizationExtras +import Foundation +import Testing + +@testable import ContainerizationOS + +@Suite("User/Group parse tests") +final class UsersTests { + struct TestCase: Sendable { + let userString: String + let expect: User.ExecUser + let shouldThrow: Bool + + init(_ userString: String, _ expect: User.ExecUser, _ shouldThrow: Bool) { + self.userString = userString + self.expect = expect + self.shouldThrow = shouldThrow + } + } + + static func createFile(path: URL, content: Data) throws { + let parent = path.deletingLastPathComponent() + let fileManager = FileManager.default + try fileManager.createDirectory(at: parent, withIntermediateDirectories: true) + try content.write(to: path) + } + + @Test + func testOnlyPasswd() throws { + let passwordContent = """ + root:x:0:0:root:/root:/bin/bash + daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin + bin:x:2:2:bin:/bin:/usr/sbin/nologin + sys:x:3:3:sys:/dev:/usr/sbin/nologin + nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin + platform:x:1000:1000:Platform:/home/platform:/bin/sh + """ + + let fileManager = FileManager.default + let tempDir = fileManager.uniqueTemporaryDirectory() + defer { try? fileManager.removeItem(at: tempDir) } + let passwdPath = tempDir.appending(path: "etc/passwd") + try Self.createFile(path: passwdPath, content: passwordContent.data(using: .ascii)!) + + let testCases: [TestCase] = [ + .init("root", .init(uid: 0, gid: 0, sgids: [0], home: "/root"), false), + .init("0:0", .init(uid: 0, gid: 0, sgids: [0], home: "/root"), false), + .init("platform", .init(uid: 1000, gid: 1000, sgids: [1000], home: "/home/platform"), false), + .init("65534", .init(uid: 65534, gid: 65534, sgids: [65534], home: "/nonexistent"), false), + .init("should_fail", .init(uid: 456, gid: 123, sgids: [9999], home: "/undefined"), true), + .init(":nouser", .init(uid: 456, gid: 123, sgids: [9999], home: "/undefined"), true), + ] + + for testCase in testCases { + if testCase.shouldThrow { + #expect(throws: ContainerizationError.self) { + try User.parseUser(root: tempDir.absolutePath(), userString: testCase.userString) + } + continue + } + let user = try User.parseUser(root: tempDir.absolutePath(), userString: testCase.userString) + #expect(testCase.expect.uid == user.uid) + #expect(testCase.expect.gid == user.gid) + #expect(testCase.expect.home == user.home) + #expect(testCase.expect.sgids == user.sgids) + } + } + + @Test(arguments: [ + TestCase("foobar", .init(uid: 0, gid: 0, sgids: [0], home: "/root"), true), + TestCase("101:101", .init(uid: 101, gid: 101, sgids: [], home: "/"), false), + TestCase("1025:must-fail", .init(uid: 0, gid: 0, sgids: [], home: "/"), true), + ]) + func testNoPasswd(testCase: TestCase) throws { + let fileManager = FileManager.default + let tempDir = fileManager.uniqueTemporaryDirectory() + defer { + try? fileManager.removeItem(at: tempDir) + } + if testCase.shouldThrow { + #expect(throws: ContainerizationError.self) { + try User.parseUser(root: tempDir.absolutePath(), userString: testCase.userString) + } + } else { + let parsed = try User.parseUser(root: tempDir.absolutePath(), userString: testCase.userString) + #expect(testCase.expect.uid == parsed.uid) + #expect(testCase.expect.gid == parsed.gid) + #expect(testCase.expect.home == parsed.home) + #expect(testCase.expect.sgids == parsed.sgids) + } + } + + @Test + func testPasswdGroup() throws { + let passwordContent = """ + root:x:0:0:root:/root:/bin/bash + daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin + bin:x:2:2:bin:/bin:/usr/sbin/nologin + sys:x:3:3:sys:/dev:/usr/sbin/nologin + backup:x:34:34:backup:/var/backups:/usr/sbin/nologin + nobody:x:65534:65534:nobody:/nonexistent:/usr/sbin/nologin + platform:x:1000:1000:platform:/home/platform:/bin/bash + """ + + let groupContent = """ + root:x:0: + daemon:x:1: + bin:x:2: + adm:x:4:platform + tape:x:26: + sudo:x:27:platform + audio:x:29:platform + video:x:44:platform + nogroup:x:65534: + platform:x:1000: + """ + + let fileManager = FileManager.default + let tempDir = fileManager.uniqueTemporaryDirectory() + defer { try? fileManager.removeItem(at: tempDir) } + let passwdPath = tempDir.appending(path: "etc/passwd") + let groupPath = tempDir.appending(path: "etc/group") + try Self.createFile(path: passwdPath, content: passwordContent.data(using: .ascii)!) + try Self.createFile(path: groupPath, content: groupContent.data(using: .ascii)!) + + let testCases: [TestCase] = [ + .init("root:bin", .init(uid: 0, gid: 2, sgids: [2], home: "/root"), false), + .init("daemon:platform", .init(uid: 1, gid: 1000, sgids: [1000], home: "/usr/sbin"), false), + .init("platform", .init(uid: 1000, gid: 1000, sgids: [4, 27, 29, 44, 1000], home: "/home/platform"), false), + .init("nobody", .init(uid: 65534, gid: 65534, sgids: [65534], home: "/nonexistent"), false), + .init("2:1000", .init(uid: 2, gid: 1000, sgids: [1000], home: "/bin"), false), + ] + + for testCase in testCases { + if testCase.shouldThrow { + #expect(throws: ContainerizationError.self) { + try User.parseUser(root: tempDir.absolutePath(), userString: testCase.userString) + } + } + let user = try User.parseUser(root: tempDir.absolutePath(), userString: testCase.userString) + #expect(testCase.expect.uid == user.uid) + #expect(testCase.expect.gid == user.gid) + #expect(testCase.expect.home == user.home) + #expect(Set(testCase.expect.sgids) == Set(user.sgids)) + } + } +} diff --git a/Tests/ContainerizationTests/ImageTests/ContainsAuth.swift b/Tests/ContainerizationTests/ImageTests/ContainsAuth.swift new file mode 100644 index 00000000..60512252 --- /dev/null +++ b/Tests/ContainerizationTests/ImageTests/ContainsAuth.swift @@ -0,0 +1,38 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationOCI +import Foundation + +internal protocol ContainsAuth { + +} + +extension ContainsAuth { + static var hasRegistryCredentials: Bool { + authentication != nil + } + + static var authentication: Authentication? { + let env = ProcessInfo.processInfo.environment + guard let password = ProcessInfo.processInfo.environment["REGISTRY_TOKEN"], + let username = ProcessInfo.processInfo.environment["REGISTRY_USERNAME"] + else { + return nil + } + return BasicAuthentication(username: username, password: password) + } +} diff --git a/Tests/ContainerizationTests/ImageTests/ImageStoreImagePullTests.swift b/Tests/ContainerizationTests/ImageTests/ImageStoreImagePullTests.swift new file mode 100644 index 00000000..1fa85024 --- /dev/null +++ b/Tests/ContainerizationTests/ImageTests/ImageStoreImagePullTests.swift @@ -0,0 +1,181 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// + +import ContainerizationOCI +import Crypto +import Foundation +import NIO +import Testing + +@testable import Containerization + +@Suite +final class ImageStoreImagePullTests: ContainsAuth { + let store: ImageStore + let dir: URL + let contentStore: ContentStore + + public init() { + let dir = FileManager.default.uniqueTemporaryDirectory(create: true) + let cs = try! LocalContentStore(path: dir) + let store = try! ImageStore(path: dir, contentStore: cs) + self.dir = dir + self.store = store + self.contentStore = cs + } + + deinit { + try! FileManager.default.removeItem(at: self.dir) + } + + @Test(.enabled(if: hasRegistryCredentials)) + func testPullImageWithoutIndex() async throws { + let img = try await self.store.pull(reference: "ghcr.io/apple-uat/test-images/alpine-arm64:v1", auth: Self.authentication) + + let rootDescriptor = img.descriptor + let index: ContainerizationOCI.Index = try await contentStore.get(digest: rootDescriptor.digest)! + + #expect(index.manifests.count == 1) + let desc = index.manifests.first! + #expect(desc.platform!.architecture == "arm64") + + await #expect(throws: Never.self) { + let manifest: ContainerizationOCI.Manifest = try await self.contentStore.get(digest: desc.digest)! + let _: ContainerizationOCI.Image = try await self.contentStore.get(digest: manifest.config.digest)! + for layer in manifest.layers { + _ = try await self.contentStore.get(digest: layer.digest)! + } + } + } + + @Test( + .enabled(if: hasRegistryCredentials), + arguments: [ + (Platform(arch: "arm64", os: "linux", variant: "v8"), imagePullArm64Layers), + (Platform(arch: "amd64", os: "linux"), imagePullAmd64Layers), + (nil, imagePullTestAllLayers), + ]) + func testPullSinglePlatform(platform: Platform?, expectLayers: [String]) async throws { + let img = try await self.store.pull(reference: "ghcr.io/apple-uat/test-images/alpine:3.21", platform: platform, auth: Self.authentication) + let rootDescriptor = img.descriptor + let index: ContainerizationOCI.Index = try await contentStore.get(digest: rootDescriptor.digest)! + var foundMatch = false + for desc in index.manifests { + if let platform { + if desc.platform != platform { + continue + } + } + foundMatch = true + await #expect(throws: Never.self) { + let manifest: ContainerizationOCI.Manifest = try await self.contentStore.get(digest: desc.digest)! + let _: ContainerizationOCI.Image = try await self.contentStore.get(digest: manifest.config.digest)! + for layer in manifest.layers { + _ = try await self.contentStore.get(digest: layer.digest)! + } + } + } + #expect(foundMatch) + let contentPath = dir.appendingPathComponent("blobs/sha256") + let filesOnDisk = try FileManager.default.contentsOfDirectory(at: contentPath, includingPropertiesForKeys: nil).map { + $0.lastPathComponent + }.sorted() + #expect(filesOnDisk == expectLayers) + } + + @Test(.enabled(if: hasRegistryCredentials)) + func testPullWithSha() async throws { + let sha = "sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c" + let r = "ghcr.io/apple-uat/test-images/alpine:3.21@\(sha)" + let img = try await self.store.pull(reference: r, platform: .current, auth: Self.authentication) + #expect(img.descriptor.digest == sha) + } +} + +let imagePullTestAllLayers = [ + "09c8ec8bf0d43a250ba7fed2eb6f242935b2987be5ed921ee06c93008558f980", + "09de0793c07346ac2912153f6569af631291a9874dc94167d534cefc9c2d9c14", + "11c83b29fa7f49deca4c4c597571e882adce0146997c31c99461918816e4c420", + "159d7ed29e1fd01cbe33ccbfda619dfa93ff08349d2841e422b7c9e2d522c645", + "184b14480d317057da092a0994ad6baf4b2df588108f43969f8fd56f021af2c6", + "1960ae9fcc9fba89375bec92e8cbed41d5e4fab7e376ccad186084bbabf9db82", + "1bb6442072bc5b25e4cefeaab9aecb82267e5d7dbac412be934c416e68576534", + "1c4eef651f65e2f7daee7ee785882ac164b02b78fb74503052a26dc061c90474", + "1de5eb4a9a6735adb46b2c9c88674c0cfba3444dd4ac2341b3babf1261700529", + "2436f2b3b7d2537f4c5b622d7a820f00aaea1b6bd14c898142472947d5f02abe", + "2dbd13a29595c6492a46119969dcda7d2ac35daef926e45ab62c02adb12b5173", + "43c891410a7570c3f4ed3c1651b5e1aadd530c2d9bbc9c301ee4cb25c27d8d2f", + "45f2dc24282db1bb78967201087c1c0699411c580555a98d20107c26e0d915e5", + "491b6373df29cf24cfa36697aa6dd77baf5055cc7de7b7190fb07739836b2bb5", + "51dd5201df48b2831f5894c4a9f615aaba37c5dfed453a0335018807d4b390bf", + "5d2b0d8b1d1edede60a8e220f7b2f496b3e5341e939cf9f6d097ac1756066327", + "64cf7d2b5187c0a2d7cb5c7216edf3e6a691753b99f92f1c0d705799ab7df452", + "69aa61ccf55e5bf8e7a069b89e8afb42b4f3443b3785868795af8046d810d608", + "6e771e15690e2fabf2332d3a3b744495411d6e0b00b2aea64419b58b0066cf81", + "757d680068d77be46fd1ea20fb21db16f150468c5e7079a08a2e4705aec096ac", + "76099982f06682e28a60c3b774ef20931d07b0a2f551203484e633d8c0361ee7", + "7df33f7ad8beb367ac09bdd1b2f220db3ee2bbdda14a6310d1340e5628b5ba88", + "85f3b18f9f5a8655db86c6dfb02bb01011ffef63d10a173843c5c65c3e9137b7", + "8aa577c360a5f9b9dc36fddeace36e6c67f778d234b7fb8e8c9054a896d9ed66", + "8d591b0b7dea080ea3be9e12ae563eebf9869168ffced1cb25b2470a3d9fe15e", + "903bfe2ae9942c3e1520ef3b4085d3ed0ae7aa04d5b084a6b5f20c3a2bf54d37", + "92f735dd3e28788117021933ebab6e96ebdcce599d4afa971f178e23d79c2756", + "961e545c33866e778e904903540013b883da6d04e64ea40008ec6e0da9744d00", + "9c2d245b3c01c4d7da0d3319d278e7aa4dd899076721abd205b595b2d3b2383b", + "9ed449c437bfd0ca00973dbbc086fa310e8f7747d5ce78596ceeea177fdd61c8", + "9ed53fd3b83120f78b33685d930ce9bf5aa481f6e2d165c42cbbddbeaa196f6f", + "9fcbb9b67bffff680327c37206091da5606ca6e275adb6cfb676a3dde51255ef", + "a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c", + "aded1e1a5b3705116fa0a92ba074a5e0b0031647d9c315983ccba2ee5428ec8b", + "ae871ff1c416b2496ea95b81b00ae446468c9cca84760a9c3fc29282268cec29", + "af368b80f6520eb3f1ea2686e4afd01ee6b827b232120e18c1d37ae13034985d", + "b5a8664a8878e813029c3f3601ba22443c4b8b4fdf18b0e7ef427103292a034a", + "c1a599607158512214777614f916f8193d29fd34b656d47dfc26314af01e2af4", + "c646c0556ac0609f784a201a810cc351dd3fd288e19cdd122f7c0674b207278a", + "c6ea79a5a9bfa5cfc32d338e81b456ccf9d96498ce6868fd15818fc8a2406221", + "cf2b3ffa5b1c87b26944dfe2005c7b9866ab5f3a91867e741e3a2e9a6f8c4152", + "cfc6f569b62a275453b0be6e36b09ffb5cccb3c692a1189ef9d046f9b354f40a", + "d0ec9a4a1b9b94293da606179cebe161abdecc29878e1fe9746b57c2a513c1c3", + "d16ce3c92d1f6191fe367beac3a22940c5fab48ebb4eed5d17a63db4e9afc3f0", + "d206c2e81af4647ceee34c716e73733e7eb60818b3ead7da067bc0825c50378c", + "d3219e1bef3a6bdf3fe0ee09abb1402a119b4ae596e287e876fce2efa9e777c7", + "d50b00ed88df2fd2cf92e5a9277529612d5b82156786c720efa2b13a638c8da6", + "d524c610e0d70e2c437be31245bad77dacc2584f5cdcbdee5e059b6e6a90ad87", + "db0ed8d0d16f8c62e6bb16440fb51de09b312c97998090fc5d13319bd7255920", + "e219d195bcda8c6cc772c55b0a253356f1474d07b747dfeaf236b720bafcde50", + "f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870", + "f2e784527661153e36bcd9ec666145b92690614eb3ec0e78275c463de118aeba", + "f5fb419236878e25e11358970412e1aa64413c412398739d747e1333d3e1f6d1", + "f9e950c3f91815fdba813dad362a3b4e508b964c9128817737b6bbde89c7ed31", + "fe0dcdd1f78341a54b6d08d0f45d91ae93eb212667d970ad15213a3168c410ee", + "fea1779822bb485f4f88c7736e39baf15e981e3423e7583af4852db45e3c04bb", +] + +let imagePullArm64Layers = [ + "6e771e15690e2fabf2332d3a3b744495411d6e0b00b2aea64419b58b0066cf81", + "757d680068d77be46fd1ea20fb21db16f150468c5e7079a08a2e4705aec096ac", + "8d591b0b7dea080ea3be9e12ae563eebf9869168ffced1cb25b2470a3d9fe15e", + "a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c", +] + +let imagePullAmd64Layers = [ + "1c4eef651f65e2f7daee7ee785882ac164b02b78fb74503052a26dc061c90474", + "a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c", + "aded1e1a5b3705116fa0a92ba074a5e0b0031647d9c315983ccba2ee5428ec8b", + "f18232174bc91741fdf3da96d85011092101a032a93a388b79e99e69c2d5c870", +] diff --git a/Tests/ContainerizationTests/ImageTests/ImageStoreTests.swift b/Tests/ContainerizationTests/ImageTests/ImageStoreTests.swift new file mode 100644 index 00000000..e89d9374 --- /dev/null +++ b/Tests/ContainerizationTests/ImageTests/ImageStoreTests.swift @@ -0,0 +1,82 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// + +import ContainerizationArchive +import ContainerizationExtras +import ContainerizationOCI +import Foundation +import Testing + +@testable import Containerization + +@Suite +public class ImageStoreTests: ContainsAuth { + let store: ImageStore + let dir: URL + + public init() { + let dir = FileManager.default.uniqueTemporaryDirectory(create: true) + let cs = try! LocalContentStore(path: dir) + let store = try! ImageStore(path: dir, contentStore: cs) + self.dir = dir + self.store = store + } + + deinit { + try! FileManager.default.removeItem(at: self.dir) + } + + @Test func testImageStoreOperation() async throws { + let fileManager = FileManager.default + let tempDir = fileManager.uniqueTemporaryDirectory() + defer { + try? fileManager.removeItem(at: tempDir) + } + + let tarPath = Foundation.Bundle.module.url(forResource: "scratch", withExtension: "tar")! + let reader = try ArchiveReader(format: .pax, filter: .none, file: tarPath) + try reader.extractContents(to: tempDir) + + let _ = try await self.store.load(from: tempDir) + let loaded = try await self.store.load(from: tempDir) + let expectedLoadedImage = "registry.local/integration-tests/scratch:latest" + #expect(loaded.first!.reference == "registry.local/integration-tests/scratch:latest") + + guard let authentication = Self.authentication else { + return + } + let imageReference = "ghcr.io/apple-uat/test-images/busybox:1.37" + let busyboxImage = try await self.store.pull(reference: imageReference, auth: Self.authentication) + + let got = try await self.store.get(reference: imageReference) + #expect(got.descriptor == busyboxImage.descriptor) + + let newTag = "registry.local/integration-tests/busybox:latest" + let _ = try await self.store.tag(existing: imageReference, new: newTag) + + let tempFile = self.dir.appending(path: "export.tar") + try await self.store.save(references: [imageReference, expectedLoadedImage], out: tempFile) + + let remoteImageName = "ghcr.io/apple-uat/test-images/image-push" + let epoch = Int(Date().timeIntervalSince1970.description) + let tag = epoch != nil ? String(epoch!) : "latest" + let upstreamTag = "\(remoteImageName):\(tag)" + let _ = try await self.store.tag(existing: imageReference, new: upstreamTag) + try await self.store.push(reference: upstreamTag, auth: authentication) + } +} diff --git a/Tests/ContainerizationTests/ImageTests/Resources/scratch.tar b/Tests/ContainerizationTests/ImageTests/Resources/scratch.tar new file mode 100644 index 00000000..077d14a6 Binary files /dev/null and b/Tests/ContainerizationTests/ImageTests/Resources/scratch.tar differ diff --git a/Tests/ContainerizationTests/KernelTests.swift b/Tests/ContainerizationTests/KernelTests.swift new file mode 100644 index 00000000..ca5a5b0d --- /dev/null +++ b/Tests/ContainerizationTests/KernelTests.swift @@ -0,0 +1,42 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// + +import Foundation +import Testing + +@testable import Containerization + +final class KernelTests { + @Test func kernelArgs() { + let commandLine = Kernel.CommandLine(debug: false, panic: 0) + let kernel = Kernel(path: .init(fileURLWithPath: ""), platform: .linuxArm, commandline: commandLine) + + let expected = "console=hvc0 tsc=reliable panic=0" + let cmdline = kernel.commandLine.kernelArgs.joined(separator: " ") + #expect(cmdline == expected) + } + + @Test func kernelDebugArgs() { + let cmdLine = Kernel.CommandLine(debug: true, panic: 0) + let kernel = Kernel(path: .init(fileURLWithPath: ""), platform: .linuxArm, commandline: cmdLine) + + let expected = "console=hvc0 tsc=reliable debug panic=0" + let cmdline = kernel.commandLine.kernelArgs.joined(separator: " ") + #expect(cmdline == expected) + } +} diff --git a/Tests/SendablePropertyMacrosTests/SendablePropertyMacrosTests.swift b/Tests/SendablePropertyMacrosTests/SendablePropertyMacrosTests.swift new file mode 100644 index 00000000..c435f0bd --- /dev/null +++ b/Tests/SendablePropertyMacrosTests/SendablePropertyMacrosTests.swift @@ -0,0 +1,159 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation +import SwiftSyntax +import SwiftSyntaxBuilder +import SwiftSyntaxMacros +import SwiftSyntaxMacrosTestSupport +import XCTest + +// Macro implementations build for the host, so the corresponding module is not available when cross-compiling. Cross-compiled tests may still make use of the macro itself in end-to-end tests. +#if canImport(SendablePropertyMacros) +import SendablePropertyMacros + +let testMacros: [String: Macro.Type] = [ + "SendableProperty": SendablePropertyMacro.self +] +#endif + +final class SendablePropertyMacrosTests: XCTestCase { + func testMacroExpansionWithTypeAnnotation() throws { + #if canImport(SendablePropertyMacros) + assertMacroExpansion( + """ + final class TestMacro: Sendable { + @SendableProperty + var value: Int + } + """, + expandedSource: + """ + final class TestMacro: Sendable { + var value: Int { + get { + _value.withLock { + $0! + } + } + set { + class Sending: @unchecked Sendable { + let wrappedValue: T + init(_ value: T) { + wrappedValue = value + } + } + let newValue = Sending(newValue) + _value.withLock { + $0 = newValue.wrappedValue + } + } + } + + private let _value = Mutex(nil) + } + """, + macros: testMacros + ) + #else + throw XCTSkip("macros are only supported when running tests for the host platform") + #endif + } + + func testMacroExpansionWithInitialValue() throws { + #if canImport(SendablePropertyMacros) + assertMacroExpansion( + """ + final class TestMacro: Sendable { + @SendableProperty + var value = 0 + } + """, + expandedSource: + """ + final class TestMacro: Sendable { + var value { + get { + _value.withLock { + $0 + } + } + set { + class Sending: @unchecked Sendable { + let wrappedValue: T + init(_ value: T) { + wrappedValue = value + } + } + let newValue = Sending(newValue) + _value.withLock { + $0 = newValue.wrappedValue + } + } + } + + private let _value = Mutex(0) + } + """, + macros: testMacros + ) + #else + throw XCTSkip("macros are only supported when running tests for the host platform") + #endif + } + + func testMacroExpansionWithTypeAnnotationAndInitialValue() throws { + #if canImport(SendablePropertyMacros) + assertMacroExpansion( + """ + final class TestMacro: Sendable { + @SendableProperty + var value: Int = 0 + } + """, + expandedSource: + """ + final class TestMacro: Sendable { + var value: Int { + get { + _value.withLock { + $0 + } + } + set { + class Sending: @unchecked Sendable { + let wrappedValue: T + init(_ value: T) { + wrappedValue = value + } + } + let newValue = Sending(newValue) + _value.withLock { + $0 = newValue.wrappedValue + } + } + } + + private let _value = Mutex(0) + } + """, + macros: testMacros + ) + #else + throw XCTSkip("macros are only supported when running tests for the host platform") + #endif + } +} diff --git a/Tests/SendablePropertyTests/SendablePropertyTests.swift b/Tests/SendablePropertyTests/SendablePropertyTests.swift new file mode 100644 index 00000000..3f53da12 --- /dev/null +++ b/Tests/SendablePropertyTests/SendablePropertyTests.swift @@ -0,0 +1,79 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation +import SendableProperty +import XCTest + +final class SendablePropertyTests: XCTestCase { + func testMacroWithTypeAnnotation() throws { + final class TestMacro: Sendable { + @SendableProperty + var value: Int + } + + let testMacro = TestMacro() + testMacro.value = 42 + XCTAssertTrue(testMacro.value == 42) + } + + func testMacroWithInitialValue() throws { + final class TestMacro: Sendable { + @SendableProperty + var value = 0 + } + + let testMacro = TestMacro() + XCTAssertTrue(type(of: testMacro.value) == Int.self) + XCTAssertTrue(testMacro.value == 0) + testMacro.value = 42 + XCTAssertTrue(testMacro.value == 42) + } + + func testMacroWithTypeAnnotationAndInitialValue() throws { + final class TestMacro: Sendable { + @SendableProperty + var value: Int = 0 + } + + let testMacro = TestMacro() + testMacro.value = 42 + XCTAssertTrue(testMacro.value == 42) + } + + func testMacroInConcurrentThreads() throws { + final class TestMacro: Sendable { + @SendableProperty + var value = "" + } + + let testMacro = TestMacro() + let loremIpsum = + "Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum." + + let numberOfIterations = 100_000 + let queue = DispatchQueue(label: "com.apple.sendable-property-tests", attributes: .concurrent) + let dispatchGroup = DispatchGroup() + for i in 0../dev/null 2>&1; then + echo "hawkeye found!" +else + echo "hawkeye not found in PATH" + echo "please install hawkeye. For convenience, you can run scripts/install-hawkeye.sh" + exit 1 +fi diff --git a/scripts/install-hawkeye.sh b/scripts/install-hawkeye.sh new file mode 100755 index 00000000..7b271b2c --- /dev/null +++ b/scripts/install-hawkeye.sh @@ -0,0 +1,22 @@ +#!/usr/bin/env bash +# Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# https://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +if command -v .local/bin/hawkeye >/dev/null 2>&1; then + echo "hawkeye already installed" +else + echo "Installing hawkeye" + export VERSION=v6.0.0 + curl --proto '=https' --tlsv1.2 -LsSf https://github.com/korandoru/hawkeye/releases/download/v6.0.0/hawkeye-installer.sh | CARGO_HOME=.local sh -s -- --no-modify-path +fi diff --git a/scripts/license-header.txt b/scripts/license-header.txt new file mode 100644 index 00000000..b26825ef --- /dev/null +++ b/scripts/license-header.txt @@ -0,0 +1,13 @@ +Copyright ©{{ " " }}{%- if attrs.git_file_modified_year != attrs.git_file_created_year -%}{{ attrs.git_file_created_year }}-{{ attrs.git_file_modified_year }}{%- else -%}{{ attrs.git_file_created_year }}{%- endif -%}{{ " " }}{{ props["copyrightOwner"] }}. All rights reserved. + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + + https://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. \ No newline at end of file diff --git a/scripts/make-docs.sh b/scripts/make-docs.sh new file mode 100755 index 00000000..7b95faeb --- /dev/null +++ b/scripts/make-docs.sh @@ -0,0 +1,44 @@ +#! /bin/bash -e +# Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# https://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + + +opts=() +if [ ! -z "${CURRENT_SDK}" ] ; then + opts+=("-Xswiftc" "-DCURRENT_SDK") +fi +opts+=("--allow-writing-to-directory" "$1") +opts+=("generate-documentation") +opts+=("--target" "Containerization") +opts+=("--target" "ContainerizationArchive") +opts+=("--target" "ContainerizationError") +opts+=("--target" "ContainerizationEXT4") +opts+=("--target" "ContainerizationExtras") +opts+=("--target" "ContainerizationIO") +opts+=("--target" "ContainerizationNetlink") +opts+=("--target" "ContainerizationOCI") +opts+=("--target" "ContainerizationOS") +opts+=("--output-path" "$1") +opts+=("--disable-indexing") +opts+=("--transform-for-static-hosting") +opts+=("--enable-experimental-combined-documentation") +opts+=("--experimental-documentation-coverage") + +if [ ! -z "$2" ] ; then + opts+=("--hosting-base-path" "$2") +fi + +/usr/bin/swift package ${opts[@]} + +echo '{}' > "$1/theme-settings.json" diff --git a/signing/vz.entitlements b/signing/vz.entitlements new file mode 100644 index 00000000..d7d0d6e8 --- /dev/null +++ b/signing/vz.entitlements @@ -0,0 +1,8 @@ + + + + + com.apple.security.virtualization + + + diff --git a/vminitd/Makefile b/vminitd/Makefile new file mode 100644 index 00000000..ee5c84fc --- /dev/null +++ b/vminitd/Makefile @@ -0,0 +1,85 @@ +# Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# https://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. + +BUILD_CONFIGURATION := debug +SWIFT_CONFIGURATION := --swift-sdk aarch64-swift-linux-musl + +# The Static Linux SDK version should match the latest released version on https://www.swift.org/install/macos/ +SWIFT_SDK_URL = https://download.swift.org/swift-6.1-release/static-sdk/swift-6.1-RELEASE/swift-6.1-RELEASE_static-linux-0.0.1.artifactbundle.tar.gz +SWIFT_SDK_CHECKSUM = 111c6f7d280a651208b8c74c0521dd99365d785c1976a6e23162f55f65379ac6 +SWIFT_SDK_PATH = /tmp/$(notdir $(SWIFT_SDK_URL)) + +SWIFTLY_URL := https://download.swift.org/swiftly/darwin/swiftly.pkg +SWIFTLY_FILENAME = $(notdir $(SWIFTLY_URL)) +VMINITD_BIN_PATH := $(shell swift build -c $(BUILD_CONFIGURATION) $(SWIFT_CONFIGURATION) --show-bin-path) + +MACOS_VERSION := $(shell sw_vers -productVersion) +MACOS_MAJOR := $(shell echo $(MACOS_VERSION) | cut -d. -f1) +MACOS_RELEASE_TYPE := $(shell sw_vers | grep ReleaseType) + +.DEFAULT_GOAL := all + +.PHONY: all +all: + @echo Building vminitd and vmexec... + @mkdir -p ./bin/ + @rm -f ./bin/vminitd + @rm -f ./bin/vmexec + @swift build -c $(BUILD_CONFIGURATION) $(SWIFT_CONFIGURATION) + @install $(VMINITD_BIN_PATH)/vminitd ./bin/vminitd + @install $(VMINITD_BIN_PATH)/vmexec ./bin/vmexec + +.PHONY: cross-prep +cross-prep: swiftly linux-sdk macos-sdk + +.PHONY: swiftly +swiftly: + @curl -o /var/tmp/$(SWIFTLY_FILENAME) $(SWIFTLY_URL) && \ + installer -pkg /var/tmp/$(SWIFTLY_FILENAME) -target CurrentUserHomeDirectory && \ + ~/.swiftly/bin/swiftly init --quiet-shell-followup && \ + . ~/.swiftly/env.sh && \ + hash -r + @rm /var/tmp/$(SWIFTLY_FILENAME) + @~/.swiftly/bin/swiftly install 6.1.0 + +.PHONY: linux-sdk +linux-sdk: + @echo Installing Static Linux SDK... + @curl -L -o $(SWIFT_SDK_PATH) $(SWIFT_SDK_URL) + -@swift sdk install $(SWIFT_SDK_PATH) --checksum $(SWIFT_SDK_CHECKSUM) + @rm $(SWIFT_SDK_PATH) + +.PHONY: macos-sdk +macos-sdk: + @if [ $(MACOS_MAJOR) -gt 15 ] && [ "$(MACOS_RELEASE_TYPE)" = "" ]; then \ + "$(MAKE)" xcode-cli; \ + else \ + "$(MAKE)" xcode; \ + fi + +.PHONY: xcode-cli +xcode-cli: + @echo Activating Xcode Command Line Tools... + @sudo xcode-select --switch /Library/Developer/CommandLineTools + +.PHONY: xcode +xcode: + @echo Please install the latest version of Xcode 17. + +.PHONY: clean +clean: + @echo Cleaning the vminitd build files... + @rm -f ./bin/vminitd + @rm -f ./bin/vmexec + @swift package clean $(SWIFT_CONFIGURATION) diff --git a/vminitd/Package.resolved b/vminitd/Package.resolved new file mode 100644 index 00000000..382a1b1f --- /dev/null +++ b/vminitd/Package.resolved @@ -0,0 +1,186 @@ +{ + "originHash" : "744e42a8f08c09385becd071aa359d76bb4c5cbd741ff3cf1f6db2669dce9f69", + "pins" : [ + { + "identity" : "async-http-client", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swift-server/async-http-client", + "state" : { + "revision" : "333f51104b75d1a5b94cb3b99e4c58a3b442c9f7", + "version" : "1.25.2" + } + }, + { + "identity" : "grpc-swift", + "kind" : "remoteSourceControl", + "location" : "https://github.com/grpc/grpc-swift", + "state" : { + "revision" : "67ae0617e1be215ca8cb4a8df5b4af940095c818", + "version" : "1.26.0" + } + }, + { + "identity" : "swift-algorithms", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-algorithms.git", + "state" : { + "revision" : "87e50f483c54e6efd60e885f7f5aa946cee68023", + "version" : "1.2.1" + } + }, + { + "identity" : "swift-argument-parser", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-argument-parser", + "state" : { + "revision" : "41982a3656a71c768319979febd796c6fd111d5c", + "version" : "1.5.0" + } + }, + { + "identity" : "swift-asn1", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-asn1.git", + "state" : { + "revision" : "ae33e5941bb88d88538d0a6b19ca0b01e6c76dcf", + "version" : "1.3.1" + } + }, + { + "identity" : "swift-atomics", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-atomics.git", + "state" : { + "revision" : "cd142fd2f64be2100422d658e7411e39489da985", + "version" : "1.2.0" + } + }, + { + "identity" : "swift-collections", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-collections.git", + "state" : { + "revision" : "671108c96644956dddcd89dd59c203dcdb36cec7", + "version" : "1.1.4" + } + }, + { + "identity" : "swift-crypto", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-crypto.git", + "state" : { + "revision" : "a6ce32a18b81b04ce7e897d1d98df6eb2da04786", + "version" : "3.12.2" + } + }, + { + "identity" : "swift-http-structured-headers", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-http-structured-headers.git", + "state" : { + "revision" : "d01361d32e14ae9b70ea5bd308a3794a198a2706", + "version" : "1.2.0" + } + }, + { + "identity" : "swift-http-types", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-http-types", + "state" : { + "revision" : "ef18d829e8b92d731ad27bb81583edd2094d1ce3", + "version" : "1.3.1" + } + }, + { + "identity" : "swift-log", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-log.git", + "state" : { + "revision" : "96a2f8a0fa41e9e09af4585e2724c4e825410b91", + "version" : "1.6.2" + } + }, + { + "identity" : "swift-nio", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-nio", + "state" : { + "revision" : "0f54d58bb5db9e064f332e8524150de379d1e51c", + "version" : "2.82.1" + } + }, + { + "identity" : "swift-nio-extras", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-nio-extras.git", + "state" : { + "revision" : "00f3f72d2f9942d0e2dc96057ab50a37ced150d4", + "version" : "1.25.0" + } + }, + { + "identity" : "swift-nio-http2", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-nio-http2.git", + "state" : { + "revision" : "4281466512f63d1bd530e33f4aa6993ee7864be0", + "version" : "1.36.0" + } + }, + { + "identity" : "swift-nio-ssl", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-nio-ssl.git", + "state" : { + "revision" : "0cc3528ff48129d64ab9cab0b1cd621634edfc6b", + "version" : "2.29.3" + } + }, + { + "identity" : "swift-nio-transport-services", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-nio-transport-services.git", + "state" : { + "revision" : "cd1e89816d345d2523b11c55654570acd5cd4c56", + "version" : "1.24.0" + } + }, + { + "identity" : "swift-numerics", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-numerics.git", + "state" : { + "revision" : "e0ec0f5f3af6f3e4d5e7a19d2af26b481acb6ba8", + "version" : "1.0.3" + } + }, + { + "identity" : "swift-protobuf", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-protobuf.git", + "state" : { + "revision" : "d72aed98f8253ec1aa9ea1141e28150f408cf17f", + "version" : "1.29.0" + } + }, + { + "identity" : "swift-syntax", + "kind" : "remoteSourceControl", + "location" : "https://github.com/swiftlang/swift-syntax.git", + "state" : { + "revision" : "0687f71944021d616d34d922343dcef086855920", + "version" : "600.0.1" + } + }, + { + "identity" : "swift-system", + "kind" : "remoteSourceControl", + "location" : "https://github.com/apple/swift-system", + "state" : { + "revision" : "c8a44d836fe7913603e246acab7c528c2e780168", + "version" : "1.4.0" + } + } + ], + "version" : 3 +} diff --git a/vminitd/Package.swift b/vminitd/Package.swift new file mode 100644 index 00000000..fd2b2f42 --- /dev/null +++ b/vminitd/Package.swift @@ -0,0 +1,62 @@ +// swift-tools-version: 6.0 +//===----------------------------------------------------------------------===// +// Copyright © 2024-2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +// The swift-tools-version declares the minimum version of Swift required to build this package. + +import PackageDescription + +let package = Package( + name: "swift-vminitd", + platforms: [.macOS("15")], + products: [ + .executable(name: "vminitd", targets: ["vminitd"]), + .executable(name: "vmexec", targets: ["vmexec"]), + ], + dependencies: [ + .package(url: "https://github.com/apple/swift-argument-parser", from: "1.3.0"), + .package(url: "https://github.com/apple/swift-log.git", from: "1.0.0"), + .package(url: "https://github.com/apple/swift-nio", from: "2.80.0"), + .package(name: "containerization", path: "../"), + ], + targets: [ + .target( + name: "LCShim" + ), + .executableTarget( + name: "vminitd", + dependencies: [ + .product(name: "Logging", package: "swift-log"), + .product(name: "_NIOFileSystem", package: "swift-nio"), + .product(name: "Containerization", package: "containerization"), + .product(name: "ContainerizationNetlink", package: "containerization"), + .product(name: "ContainerizationIO", package: "containerization"), + .product(name: "ContainerizationOS", package: "containerization"), + "LCShim", + ] + ), + .executableTarget( + name: "vmexec", + dependencies: [ + .product(name: "Logging", package: "swift-log"), + .product(name: "ArgumentParser", package: "swift-argument-parser"), + .product(name: "Containerization", package: "containerization"), + .product(name: "ContainerizationOS", package: "containerization"), + "LCShim", + ] + ), + ] +) diff --git a/vminitd/Sources/LCShim/include/syscall2.h b/vminitd/Sources/LCShim/include/syscall2.h new file mode 100644 index 00000000..edab5846 --- /dev/null +++ b/vminitd/Sources/LCShim/include/syscall2.h @@ -0,0 +1,26 @@ +/* + * Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * https://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +// + +#ifndef __SYSCALL2_H +#define __SYSCALL2_H + +int syscall2(long number, void *arg1, void *arg2); + +int set_sub_reaper(); + +#endif diff --git a/vminitd/Sources/LCShim/syscall2.c b/vminitd/Sources/LCShim/syscall2.c new file mode 100644 index 00000000..65168267 --- /dev/null +++ b/vminitd/Sources/LCShim/syscall2.c @@ -0,0 +1,27 @@ +/* + * Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. + * + * Licensed under the Apache License, Version 2.0 (the "License"); + * you may not use this file except in compliance with the License. + * You may obtain a copy of the License at + * + * https://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ + +#include +#include +#include + +#include "syscall2.h" + +int syscall2(long number, void *arg1, void *arg2) { + return syscall(number, arg1, arg2); +} + +int set_sub_reaper() { return prctl(PR_SET_CHILD_SUBREAPER, 1); } diff --git a/vminitd/Sources/vmexec/ExecCommand.swift b/vminitd/Sources/vmexec/ExecCommand.swift new file mode 100644 index 00000000..8a46768f --- /dev/null +++ b/vminitd/Sources/vmexec/ExecCommand.swift @@ -0,0 +1,131 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ArgumentParser +import Containerization +import ContainerizationError +import ContainerizationOCI +import ContainerizationOS +import Foundation +import LCShim +import Logging +import Musl + +struct ExecCommand: ParsableCommand { + static let configuration = CommandConfiguration( + commandName: "exec", + abstract: "Exec in a container" + ) + + @Option(name: .long, help: "path to an OCI runtime spec process configuration") + var processPath: String + + @Option(name: .long, help: "pid of the init process for the container") + var parentPid: Int + + func run() throws { + LoggingSystem.bootstrap(App.standardError) + let log = Logger(label: "vmexec") + + let src = URL(fileURLWithPath: processPath) + let processBytes = try Data(contentsOf: src) + let process = try JSONDecoder().decode( + ContainerizationOCI.Process.self, + from: processBytes + ) + try execInNamespaces(process: process, log: log) + } + + static func enterNS(path: String, nsType: Int32) throws { + let fd = open(path, O_RDONLY) + if fd <= 0 { + throw App.Errno(stage: "open(ns)") + } + defer { close(fd) } + + guard setns(fd, nsType) == 0 else { + throw App.Errno(stage: "setns(fd)") + } + } + + private func execInNamespaces( + process: ContainerizationOCI.Process, + log: Logger + ) throws { + // CLOEXEC the pipe fd that signals process readiness. + let syncfd = FileHandle(fileDescriptor: 3) + if fcntl(3, F_SETFD, FD_CLOEXEC) == -1 { + throw App.Errno(stage: "cloexec(syncfd)") + } + + try Self.enterNS(path: "/proc/\(self.parentPid)/ns/cgroup", nsType: CLONE_NEWCGROUP) + try Self.enterNS(path: "/proc/\(self.parentPid)/ns/pid", nsType: CLONE_NEWPID) + try Self.enterNS(path: "/proc/\(self.parentPid)/ns/uts", nsType: CLONE_NEWUTS) + try Self.enterNS(path: "/proc/\(self.parentPid)/ns/mnt", nsType: CLONE_NEWNS) + + let childPipe = Pipe() + try childPipe.setCloexec() + let processID = fork() + + guard processID != -1 else { + try? childPipe.fileHandleForReading.close() + try? childPipe.fileHandleForWriting.close() + try? syncfd.close() + + throw App.Errno(stage: "fork") + } + + if processID == 0 { // child + try childPipe.fileHandleForReading.close() + try syncfd.close() + + guard setsid() != -1 else { + throw App.Errno(stage: "setsid()") + } + + // Apply O_CLOEXEC to all file descriptors except stdio. + // This ensures that all unwanted fds we may have accidentally + // inherited are marked close-on-exec so they stay out of the + // container. + try App.applyCloseExecOnFDs() + try App.setRLimits(rlimits: process.rlimits) + + // set uid, gid, and supplementary groups + try App.setPermissions(user: process.user) + + if process.terminal { + guard ioctl(0, UInt(TIOCSCTTY), 0) != -1 else { + throw App.Errno(stage: "setctty()") + } + } + + try App.exec(process: process) + } else { // parent process + try childPipe.fileHandleForWriting.close() + + // wait until the pipe is closed then carry on. + _ = try childPipe.fileHandleForReading.readToEnd() + try childPipe.fileHandleForReading.close() + + // send our child's pid to our parent before we exit. + var childPid = processID + let data = Data(bytes: &childPid, count: MemoryLayout.size(ofValue: childPid)) + + try syncfd.write(contentsOf: data) + try syncfd.close() + } + } +} diff --git a/vminitd/Sources/vmexec/Mount.swift b/vminitd/Sources/vmexec/Mount.swift new file mode 100644 index 00000000..b03c71e7 --- /dev/null +++ b/vminitd/Sources/vmexec/Mount.swift @@ -0,0 +1,67 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationOCI +import ContainerizationOS +import Foundation +import Musl + +struct ContainerMount { + private let mounts: [ContainerizationOCI.Mount] + private let rootfs: String + + init(rootfs: String, mounts: [ContainerizationOCI.Mount]) { + self.rootfs = rootfs + self.mounts = mounts + } + + func mountToRootfs() throws { + for m in self.mounts { + let osMount = m.toOSMount() + try osMount.mount(root: self.rootfs) + } + } + + func configureConsole() throws { + let ptmx = self.rootfs.standardizingPath.appendingPathComponent("/dev/ptmx") + + guard remove(ptmx) == 0 else { + throw App.Errno(stage: "remove(ptmx)") + } + guard symlink("pts/ptmx", ptmx) == 0 else { + throw App.Errno(stage: "symlink(pts/ptmx)") + } + } + + private func mkdirAll(_ name: String, _ perm: Int16) throws { + try FileManager.default.createDirectory( + atPath: name, + withIntermediateDirectories: true, + attributes: [.posixPermissions: perm] + ) + } +} + +extension ContainerizationOCI.Mount { + func toOSMount() -> ContainerizationOS.Mount { + ContainerizationOS.Mount( + type: self.type, + source: self.source, + target: self.destination, + options: self.options + ) + } +} diff --git a/vminitd/Sources/vmexec/RunCommand.swift b/vminitd/Sources/vmexec/RunCommand.swift new file mode 100644 index 00000000..4dea5854 --- /dev/null +++ b/vminitd/Sources/vmexec/RunCommand.swift @@ -0,0 +1,259 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ArgumentParser +import Containerization +import ContainerizationError +import ContainerizationOCI +import ContainerizationOS +import Foundation +import LCShim +import Logging +import Musl + +struct RunCommand: ParsableCommand { + static let configuration = CommandConfiguration( + commandName: "run", + abstract: "Run a container" + ) + + @Option(name: .long, help: "path to an OCI bundle") + var bundlePath: String + + mutating func run() throws { + LoggingSystem.bootstrap(App.standardError) + let log = Logger(label: "vmexec") + + let bundle = try ContainerizationOCI.Bundle.load(path: URL(filePath: bundlePath)) + let ociSpec = try bundle.loadConfig() + try execInNamespace(spec: ociSpec, log: log) + } + + private func childRootSetup(rootfs: ContainerizationOCI.Root, mounts: [ContainerizationOCI.Mount], log: Logger) throws { + // setup rootfs + try prepareRoot(rootfs: rootfs.path) + try mountRootfs(rootfs: rootfs.path, mounts: mounts) + try setDevSymlinks(rootfs: rootfs.path) + + try pivotRoot(rootfs: rootfs.path) + try reOpenDevNull() + } + + private func execInNamespace(spec: ContainerizationOCI.Spec, log: Logger) throws { + guard let process = spec.process else { + fatalError("no process configuration found in runtime spec") + } + guard let root = spec.root else { + fatalError("no root found in runtime spec") + } + + let syncfd = FileHandle(fileDescriptor: 3) + if fcntl(3, F_SETFD, FD_CLOEXEC) == -1 { + throw App.Errno(stage: "cloexec(syncfd)") + } + + guard unshare(CLONE_NEWPID | CLONE_NEWNS | CLONE_NEWUTS) == 0 else { + throw App.Errno(stage: "unshare(pid|mnt|uts)") + } + + let childPipe = Pipe() + try childPipe.setCloexec() + let processID = fork() + + guard processID != -1 else { + try? childPipe.fileHandleForReading.close() + try? childPipe.fileHandleForWriting.close() + try? syncfd.close() + + throw App.Errno(stage: "fork") + } + + if processID == 0 { // child + try childPipe.fileHandleForReading.close() + try syncfd.close() + + guard unshare(CLONE_NEWCGROUP) == 0 else { + throw App.Errno(stage: "unshare(cgroup)") + } + + guard setsid() != -1 else { + throw App.Errno(stage: "setsid()") + } + + try childRootSetup(rootfs: root, mounts: spec.mounts, log: log) + + if !spec.hostname.isEmpty { + let errCode = spec.hostname.withCString { ptr in + Musl.sethostname(ptr, spec.hostname.count) + } + guard errCode == 0 else { + throw App.Errno(stage: "sethostname()") + } + } + + // Apply O_CLOEXEC to all file descriptors except stdio. + // This ensures that all unwanted fds we may have accidentally + // inherited are marked close-on-exec so they stay out of the + // container. + try App.applyCloseExecOnFDs() + + try App.setRLimits(rlimits: process.rlimits) + + // set uid, gid, and supplementary groups + try App.setPermissions(user: process.user) + + if process.terminal { + guard ioctl(0, UInt(TIOCSCTTY), 0) != -1 else { + throw App.Errno(stage: "setctty()") + } + } + + try App.exec(process: process) + } else { // parent process + try childPipe.fileHandleForWriting.close() + + // wait until the pipe is closed then carry on. + _ = try childPipe.fileHandleForReading.readToEnd() + try childPipe.fileHandleForReading.close() + + // send our child's pid to our parent before we exit. + var childPid = processID + let data = Data(bytes: &childPid, count: MemoryLayout.size(ofValue: childPid)) + + try syncfd.write(contentsOf: data) + try syncfd.close() + } + } + + private func mountRootfs(rootfs: String, mounts: [ContainerizationOCI.Mount]) throws { + let containerMount = ContainerMount(rootfs: rootfs, mounts: mounts) + try containerMount.mountToRootfs() + try containerMount.configureConsole() + } + + private func prepareRoot(rootfs: String) throws { + guard mount("", "/", "", UInt(MS_SLAVE | MS_REC), nil) == 0 else { + throw App.Errno(stage: "mount(slave|rec)") + } + + guard mount(rootfs, rootfs, "bind", UInt(MS_BIND | MS_REC), nil) == 0 else { + throw App.Errno(stage: "mount(bind|rec)") + } + } + + private func setDevSymlinks(rootfs: String) throws { + let links: [(src: String, dst: String)] = [ + ("/proc/self/fd", "/dev/fd"), + ("/proc/self/fd/0", "/dev/stdin"), + ("/proc/self/fd/1", "/dev/stdout"), + ("/proc/self/fd/2", "/dev/stderr"), + ] + + let rootfsURL = URL(fileURLWithPath: rootfs) + for (src, dst) in links { + let dest = rootfsURL.appendingPathComponent(dst) + guard symlink(src, dest.path) == 0 else { + if errno == EEXIST { + continue + } + throw App.Errno(stage: "symlink()") + } + } + } + + private func reOpenDevNull() throws { + let file = open("/dev/null", O_RDWR) + guard file != -1 else { + throw App.Errno(stage: "open(/dev/null)") + } + defer { close(file) } + + var devNullStat = stat() + try withUnsafeMutablePointer(to: &devNullStat) { pointer in + guard fstat(file, pointer) == 0 else { + throw App.Errno(stage: "fstat(/dev/null)") + } + } + + for fd: Int32 in 0...2 { + var fdStat = stat() + try withUnsafeMutablePointer(to: &fdStat) { pointer in + guard fstat(fd, pointer) == 0 else { + throw App.Errno(stage: "fstat(fd)") + } + } + + if fdStat.st_rdev == devNullStat.st_rdev { + guard dup3(file, fd, 0) != -1 else { + throw App.Errno(stage: "dup3(null)") + } + } + } + } + + /// Pivots the rootfs of the calling process in the namespace to the provided + /// rootfs in the argument. + /// + /// The pivot_root(".", ".") and unmount old root approach is exactly the same + /// as runc's pivot root implementation in: + /// https://github.com/opencontainers/runc/blob/main/libcontainer/rootfs_linux.go + private func pivotRoot(rootfs: String) throws { + let oldRoot = open("/", O_RDONLY | O_DIRECTORY) + if oldRoot <= 0 { + throw App.Errno(stage: "open(oldroot)") + } + defer { close(oldRoot) } + + let newRoot = open(rootfs, O_RDONLY | O_DIRECTORY) + if newRoot <= 0 { + throw App.Errno(stage: "open(newroot)") + } + + defer { close(newRoot) } + + // change cwd to the new root + guard fchdir(newRoot) == 0 else { + throw App.Errno(stage: "fchdir(newroot)") + } + guard syscall2(Int(SYS_pivot_root), toCString("."), toCString(".")) == 0 else { + throw App.Errno(stage: "pivot_root()") + } + // change cwd to the old root + guard fchdir(oldRoot) == 0 else { + throw App.Errno(stage: "fchdir(oldroot)") + } + // mount old root rslave so that unmount doesn't propagate back to outside + // the namespace + guard mount("", ".", "", UInt(MS_SLAVE | MS_REC), nil) == 0 else { + throw App.Errno(stage: "mount(., slave|rec)") + } + // unmount old root + guard umount2(".", Int32(MNT_DETACH)) == 0 else { + throw App.Errno(stage: "umount(.)") + } + // switch cwd to the new root + guard chdir("/") == 0 else { + throw App.Errno(stage: "chdir(/)") + } + } + + private func toCString(_ str: String) -> UnsafeMutablePointer? { + let cString = str.utf8CString + let cStringCopy = UnsafeMutableBufferPointer.allocate(capacity: cString.count) + _ = cStringCopy.initialize(from: cString) + return UnsafeMutablePointer(cStringCopy.baseAddress) + } +} diff --git a/vminitd/Sources/vmexec/vmexec.swift b/vminitd/Sources/vmexec/vmexec.swift new file mode 100644 index 00000000..2a17424c --- /dev/null +++ b/vminitd/Sources/vmexec/vmexec.swift @@ -0,0 +1,148 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +/// NOTE: This binary implements a very small subset of the OCI runtime spec, mostly just +/// the process configurations. Mounts are somewhat functional, but masked and read only paths +/// aren't checked today. Today the namespaces are also ignored, and we always spawn a new pid +/// and mount namespace. + +import ArgumentParser +import Containerization +import ContainerizationError +import ContainerizationOCI +import ContainerizationOS +import Foundation +import LCShim +import Logging +import Musl + +@main +struct App: ParsableCommand { + static let configuration = CommandConfiguration( + commandName: "vmexec", + version: "0.1.0", + subcommands: [ + ExecCommand.self, + RunCommand.self, + ] + ) + + static let standardErrorLock = NSLock() + + @Sendable + static func standardError(label: String) -> StreamLogHandler { + standardErrorLock.withLock { + StreamLogHandler.standardError(label: label) + } + } +} + +extension App { + /// Applies O_CLOEXEC to all file descriptors currently open for + /// the process except the stdio fd values + static func applyCloseExecOnFDs() throws { + let minFD = 2 // stdin, stdout, stderr should be preserved + + let fdList = try FileManager.default.contentsOfDirectory(atPath: "/proc/self/fd") + + for fdStr in fdList { + guard let fd = Int(fdStr) else { + continue + } + if fd <= minFD { + continue + } + + _ = fcntl(Int32(fd), F_SETFD, FD_CLOEXEC) + } + } + + static func exec(process: ContainerizationOCI.Process) throws { + let executable = strdup(process.args[0]) + var argv = process.args.map { strdup($0) } + argv += [nil] + + let env = process.env.map { strdup($0) } + [nil] + let cwd = process.cwd + + // switch cwd + guard chdir(cwd) == 0 else { + throw App.Errno(stage: "chdir(cwd)", info: "Failed to change directory to '\(cwd)'") + } + + guard execvpe(executable, argv, env) != -1 else { + throw App.Errno(stage: "execvpe(\(String(describing: executable)))", info: "Failed to exec [\(process.args[1...].joined(separator: " "))]") + } + fatalError("execvpe failed") + } + + static func setPermissions(user: ContainerizationOCI.User) throws { + if user.additionalGids.count > 0 { + guard setgroups(user.additionalGids.count, user.additionalGids) == 0 else { + throw App.Errno(stage: "setgroups()") + } + } + guard setgid(user.gid) == 0 else { + throw App.Errno(stage: "setgid()") + } + // NOTE: setuid has to be done last because once the uid has been + // changed, then the process will lose privilege to set the group + // and supplementary groups + guard setuid(user.uid) == 0 else { + throw App.Errno(stage: "setuid()") + } + } + + static func setRLimits(rlimits: [ContainerizationOCI.POSIXRlimit]) throws { + for rl in rlimits { + var limit = rlimit(rlim_cur: rl.soft, rlim_max: rl.hard) + let resource: Int32 + switch rl.type { + case "RLIMIT_AS": + resource = RLIMIT_AS + case "RLIMIT_CORE": + resource = RLIMIT_CORE + case "RLIMIT_CPU": + resource = RLIMIT_CPU + case "RLIMIT_DATA": + resource = RLIMIT_DATA + case "RLIMIT_FSIZE": + resource = RLIMIT_FSIZE + case "RLIMIT_NOFILE": + resource = RLIMIT_NOFILE + case "RLIMIT_STACK": + resource = RLIMIT_STACK + case "RLIMIT_NPROC": + resource = RLIMIT_NPROC + case "RLIMIT_RSS": + resource = RLIMIT_RSS + case "RLIMIT_MEMLOCK": + resource = RLIMIT_MEMLOCK + default: + errno = EINVAL + throw App.Errno(stage: "rlimit key unknown") + } + guard setrlimit(resource, &limit) == 0 else { + throw App.Errno(stage: "setrlimit()") + } + } + } + + static func Errno(stage: String, info: String = "") -> ContainerizationError { + let posix = POSIXError(.init(rawValue: errno)!, userInfo: ["stage": stage]) + return ContainerizationError(.internalError, message: "\(info) \(String(describing: posix))") + } +} diff --git a/vminitd/Sources/vminitd/Application.swift b/vminitd/Sources/vminitd/Application.swift new file mode 100644 index 00000000..82b72e28 --- /dev/null +++ b/vminitd/Sources/vminitd/Application.swift @@ -0,0 +1,123 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Containerization +import ContainerizationError +import ContainerizationOS +import Foundation +import Logging +import NIOCore +import NIOPosix + +#if os(Linux) +import Musl +import LCShim +#endif + +@main +struct Application { + private static let foregroundEnvVar = "FOREGROUND" + private static let vsockPort = 1024 + private static let standardErrorLock = NSLock() + + private static func runInForeground(_ log: Logger) throws { + log.info("running vminitd under pid1") + + var command = Command("/sbin/vminitd") + command.attrs = .init(setsid: true) + command.stdin = .standardInput + command.stdout = .standardOutput + command.stderr = .standardError + command.environment = ["\(foregroundEnvVar)=1"] + + try command.start() + _ = try command.wait() + } + + private static func adjustLimits() throws { + var limits = rlimit() + guard getrlimit(RLIMIT_NOFILE, &limits) == 0 else { + throw POSIXError(.init(rawValue: errno)!) + } + limits.rlim_cur = 65536 + limits.rlim_max = 65536 + guard setrlimit(RLIMIT_NOFILE, &limits) == 0 else { + throw POSIXError(.init(rawValue: errno)!) + } + } + + @Sendable + private static func standardError(label: String) -> StreamLogHandler { + standardErrorLock.withLock { + StreamLogHandler.standardError(label: label) + } + } + + static func main() async throws { + LoggingSystem.bootstrap(standardError) + var log = Logger(label: "vminitd") + + try adjustLimits() + + // when running under debug mode, launch vminitd as a sub process of pid1 + // so that we get a chance to collect better logs and errors before pid1 exists + // and the kernel panics. + #if DEBUG + let environment = ProcessInfo.processInfo.environment + let foreground = environment[Self.foregroundEnvVar] + log.info("checking for shim var \(foregroundEnvVar)=\(String(describing: foreground))") + + if foreground == nil { + try runInForeground(log) + exit(0) + } + + // since we are not running as pid1 in this mode we must set ourselves + // as a subpreaper so that all child processes are reaped by us and not + // passed onto our parent. + set_sub_reaper() + #endif + + signal(SIGPIPE, SIG_IGN) + + // Because the sysctl rpc wouldn't make sense if this didn't always exist, we + // ALWAYS mount /proc. + guard Musl.mount("proc", "/proc", "proc", 0, "") == 0 else { + log.error("failed to mount /proc") + exit(1) + } + guard Musl.mount("tmpfs", "/run", "tmpfs", 0, "") == 0 else { + log.error("failed to mount /run") + exit(1) + } + try Binfmt.mount() + + log.logLevel = .debug + + log.info("vminitd booting...") + let eg = MultiThreadedEventLoopGroup(numberOfThreads: System.coreCount) + let server = Initd(log: log, group: eg) + + do { + log.info("serve vminitd api") + try await server.serve(port: vsockPort) + log.info("vminitd api returned...") + } catch { + log.error("vminitd boot error \(error)") + exit(1) + } + } +} diff --git a/vminitd/Sources/vminitd/HostStdio.swift b/vminitd/Sources/vminitd/HostStdio.swift new file mode 100644 index 00000000..431e000b --- /dev/null +++ b/vminitd/Sources/vminitd/HostStdio.swift @@ -0,0 +1,22 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +struct HostStdio: Sendable { + let stdin: UInt32? + let stdout: UInt32? + let stderr: UInt32? + let terminal: Bool +} diff --git a/vminitd/Sources/vminitd/ManagedContainer.swift b/vminitd/Sources/vminitd/ManagedContainer.swift new file mode 100644 index 00000000..3918f73a --- /dev/null +++ b/vminitd/Sources/vminitd/ManagedContainer.swift @@ -0,0 +1,170 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationError +import ContainerizationOCI +import ContainerizationOS +import Foundation +import Logging + +actor ManagedContainer { + let id: String + let initProcess: ManagedProcess + + private let _log: Logger + private let _bundle: ContainerizationOCI.Bundle + private var _execs: [String: ManagedProcess] = [:] + + var pid: Int32 { + self.initProcess.pid + } + + init( + id: String, + stdio: HostStdio, + spec: ContainerizationOCI.Spec, + log: Logger + ) throws { + let bundle = try ContainerizationOCI.Bundle.create( + path: Self.craftBundlePath(id: id), + spec: spec + ) + log.info("created bundle with spec \(spec)") + + let initProcess = try ManagedProcess( + id: id, + stdio: stdio, + bundle: bundle, + owningPid: nil, + log: log + ) + log.info("created managed init process") + + self.initProcess = initProcess + self.id = id + self._bundle = bundle + self._log = log + } +} + +extension ManagedContainer { + private func ensureExecExists(_ id: String) throws { + if self._execs[id] == nil { + throw ContainerizationError( + .invalidState, + message: "exec \(id) does not exist in container \(self.id)" + ) + } + } + + func createExec( + id: String, + stdio: HostStdio, + process: ContainerizationOCI.Process + ) throws { + // Write the process config to the bundle, and pass this on + // over to ManagedProcess to deal with. + try self._bundle.createExecSpec( + id: id, + process: process + ) + let process = try ManagedProcess( + id: id, + stdio: stdio, + bundle: self._bundle, + owningPid: self.initProcess.pid, + log: self._log + ) + self._execs[id] = process + } + + func getExec(id: String) throws -> ManagedProcess { + guard let exec = self._execs[id] else { + throw ContainerizationError( + .invalidState, + message: "exec \(id) does not exist in container \(self.id)" + ) + } + return exec + } + + func start() throws -> Int32 { + try self.initProcess.start() + } + + func wait() async -> Int32 { + await self.initProcess.wait() + } + + func kill(_ signal: Int32) throws { + try self.initProcess.kill(signal) + } + + func resize(size: Terminal.Size) throws { + try self.initProcess.resize(size: size) + } + + func close() throws { + try self.initProcess.close() + } + + func deleteExec(id: String) throws { + try ensureExecExists(id) + do { + try self._bundle.deleteExecSpec(id: id) + } catch { + self._log.error("failed to remove exec spec from filesystem: \(error)") + } + self._execs.removeValue(forKey: id) + } + + func delete() throws { + try self._bundle.delete() + } +} + +extension ContainerizationOCI.Bundle { + func createExecSpec(id: String, process: ContainerizationOCI.Process) throws { + let specDir = self.path.appending(path: "execs/\(id)") + + let fm = FileManager.default + try fm.createDirectory( + atPath: specDir.path, + withIntermediateDirectories: true + ) + + let specData = try JSONEncoder().encode(process) + let processConfigPath = specDir.appending(path: "process.json") + try specData.write(to: processConfigPath) + } + + func getExecSpecPath(id: String) -> URL { + self.path.appending(path: "execs/\(id)/process.json") + } + + func deleteExecSpec(id: String) throws { + let specDir = self.path.appending(path: "execs/\(id)") + + let fm = FileManager.default + try fm.removeItem(at: specDir) + } +} + +extension ManagedContainer { + static func craftBundlePath(id: String) -> URL { + URL(fileURLWithPath: "/run/container").appending(path: id) + } +} diff --git a/vminitd/Sources/vminitd/ManagedProcess.swift b/vminitd/Sources/vminitd/ManagedProcess.swift new file mode 100644 index 00000000..46e747bb --- /dev/null +++ b/vminitd/Sources/vminitd/ManagedProcess.swift @@ -0,0 +1,223 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Containerization +import ContainerizationError +import ContainerizationOCI +import ContainerizationOS +import Foundation +import GRPC +import Logging +import NIOCore +import NIOPosix + +class ManagedProcess: @unchecked Sendable { + let id: String + + private let log: Logger + private let io: IO + private let process: Command + + private var waiters: [CheckedContinuation] + private var exitStatus: Int32? + private var closed: Bool + private let lock = NSLock() + private let syncfd: Pipe + private let owningPid: Int32? + private var _pid: Int32 = 0 + + var pid: Int32 { + self.lock.lock { + _pid + } + } + + // swiftlint: disable type_name + protocol IO { + func start() throws + func closeAfterExec() throws + func resize(size: Terminal.Size) throws + func close() throws + } + // swiftlint: enable type_name + + static func localizeLogger(log: inout Logger, id: String) { + log[metadataKey: "id"] = "\(id)" + } + + init( + id: String, + stdio: HostStdio, + bundle: ContainerizationOCI.Bundle, + owningPid: Int32? = nil, + log: Logger + ) throws { + self.id = id + var log = log + Self.localizeLogger(log: &log, id: id) + self.log = log + self.owningPid = owningPid + + let syncfd = Pipe() + try syncfd.setCloexec() + self.syncfd = syncfd + + let args: [String] + if let owningPid { + args = [ + "exec", + "--parent-pid", + "\(owningPid)", + "--process-path", + bundle.getExecSpecPath(id: id).path, + ] + } else { + args = ["run", "--bundle-path", bundle.path.path] + } + + var process = Command( + "/sbin/vmexec", + arguments: args, + extraFiles: [syncfd.fileHandleForWriting] + ) + + var io: IO + if stdio.terminal { + log.info("setting up terminal IO") + let attrs = Command.Attrs(setsid: false, setctty: false) + process.attrs = attrs + process.environment.append("TERM=xterm") + io = try TerminalIO( + process: &process, + stdio: stdio, + log: log + ) + } else { + process.attrs = .init(setsid: false) + io = StandardIO( + process: &process, + stdio: stdio, + log: log + ) + } + + log.info("starting io") + // Setup IO early. We expect the host to be listening already. + try io.start() + + self.io = io + self.process = process + self.waiters = [] + self.closed = false + } +} + +extension ManagedProcess { + func start() throws -> Int32 { + try self.lock.lock { + log.debug("starting managed process") + + // Start the underlying process. + try process.start() + + // Close our side of any pipes. + try syncfd.fileHandleForWriting.close() + try io.closeAfterExec() + + guard let piddata = try syncfd.fileHandleForReading.readToEnd() else { + throw ContainerizationError(.internalError, message: "no pid data from sync pipe") + } + + let i = piddata.withUnsafeBytes { ptr in + ptr.load(as: Int32.self) + } + + log.info("got back pid data \(i)") + self._pid = i + + log.debug( + "started managed process", + metadata: [ + "pid": "\(_pid)" + ]) + return i + } + } + + func setExit(_ status: Int32) { + self.lock.lock { + self.log.debug( + "managed process exit", + metadata: [ + "status": "\(status)" + ]) + + self.exitStatus = status + + for waiter in self.waiters { + waiter.resume(returning: status) + } + + self.log.debug("\(self.waiters.count) managed process waiters signaled") + self.waiters.removeAll() + } + } + + /// Wait on the process to exit + func wait() async -> Int32 { + await withCheckedContinuation { cont in + self.lock.lock { + if let status = exitStatus { + cont.resume(returning: status) + return + } + self.waiters.append(cont) + } + } + } + + func kill(_ signal: Int32) throws { + try self.lock.lock { + guard exitStatus == nil else { + return + } + + self.log.info("sending signal \(signal) to process \(_pid)") + guard Foundation.kill(_pid, signal) == 0 else { + throw POSIXError.fromErrno() + } + } + } + + func resize(size: Terminal.Size) throws { + try self.lock.lock { + if self.closed { + return + } + try self.io.resize(size: size) + } + } + + func close() throws { + try self.lock.lock { + if self.closed { + return + } + try self.io.close() + self.closed = true + } + } +} diff --git a/vminitd/Sources/vminitd/OSFile+Splice.swift b/vminitd/Sources/vminitd/OSFile+Splice.swift new file mode 100644 index 00000000..5f53a751 --- /dev/null +++ b/vminitd/Sources/vminitd/OSFile+Splice.swift @@ -0,0 +1,101 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +extension OSFile { + struct SpliceFile: Sendable { + var file: OSFile + var offset: Int + let pipe = Pipe() + + var fileDescriptor: Int32 { + file.fileDescriptor + } + + var reader: Int32 { + pipe.fileHandleForReading.fileDescriptor + } + + var writer: Int32 { + pipe.fileHandleForWriting.fileDescriptor + } + + init(fd: Int32) { + self.file = OSFile(fd: fd) + self.offset = 0 + } + + init(handle: FileHandle) { + self.file = OSFile(handle: handle) + self.offset = 0 + } + + init(from: OSFile, withOffset: Int = 0) { + self.file = from + self.offset = withOffset + } + + func close() throws { + try self.file.close() + } + } + + static func splice(from: inout SpliceFile, to: inout SpliceFile, count: Int = 1 << 16) throws -> (read: Int, wrote: Int, action: IOAction) { + let fromOffset = from.offset + let toOffset = to.offset + + while true { + while (from.offset - to.offset) < count { + let toRead = count - (from.offset - to.offset) + let bytesRead = Foundation.splice(from.fileDescriptor, nil, to.writer, nil, toRead, UInt32(bitPattern: SPLICE_F_MOVE | SPLICE_F_NONBLOCK)) + if bytesRead == -1 { + if errno != EAGAIN && errno != EIO { + throw POSIXError(.init(rawValue: errno)!) + } + break + } + if bytesRead == 0 { + return (0, 0, .eof) + } + from.offset += bytesRead + if bytesRead < toRead { + break + } + } + if from.offset == to.offset { + return (from.offset - fromOffset, to.offset - toOffset, .success) + } + while to.offset < from.offset { + let toWrite = from.offset - to.offset + let bytesWrote = Foundation.splice(to.reader, nil, to.fileDescriptor, nil, toWrite, UInt32(bitPattern: SPLICE_F_MOVE | SPLICE_F_NONBLOCK)) + if bytesWrote == -1 { + if errno != EAGAIN && errno != EIO { + throw POSIXError(.init(rawValue: errno)!) + } + break + } + to.offset += bytesWrote + if bytesWrote == 0 { + return (from.offset - fromOffset, to.offset - toOffset, .brokenPipe) + } + if bytesWrote < toWrite { + break + } + } + } + } +} diff --git a/vminitd/Sources/vminitd/OSFile.swift b/vminitd/Sources/vminitd/OSFile.swift new file mode 100644 index 00000000..ca04b0b2 --- /dev/null +++ b/vminitd/Sources/vminitd/OSFile.swift @@ -0,0 +1,128 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Foundation + +struct OSFile: Sendable { + private let fd: Int32 + + enum IOAction: Equatable { + case eof + case again + case success + case brokenPipe + case error(_ errno: Int32) + } + + var closed: Bool { + Foundation.fcntl(fd, F_GETFD) == -1 && errno == EBADF + } + + var fileDescriptor: Int32 { fd } + + init(fd: Int32) { + self.fd = fd + } + + init(handle: FileHandle) { + self.fd = handle.fileDescriptor + } + + func close() throws { + guard Foundation.close(self.fd) == 0 else { + throw POSIXError(.init(rawValue: errno)!) + } + } + + func read(_ buffer: UnsafeMutableBufferPointer) -> (read: Int, action: IOAction) { + if buffer.count == 0 { + return (0, .success) + } + + var bytesRead: Int = 0 + while true { + let n = Foundation.read( + self.fd, + buffer.baseAddress!.advanced(by: bytesRead), + buffer.count - bytesRead + ) + if n == -1 { + if errno == EAGAIN || errno == EIO { + return (bytesRead, .again) + } + return (bytesRead, .error(errno)) + } + + if n == 0 { + return (bytesRead, .eof) + } + + bytesRead += n + if bytesRead < buffer.count { + continue + } + return (bytesRead, .success) + } + } + + func write(_ buffer: UnsafeMutableBufferPointer) -> (wrote: Int, action: IOAction) { + if buffer.count == 0 { + return (0, .success) + } + + var bytesWrote: Int = 0 + while true { + let n = Foundation.write( + self.fd, + buffer.baseAddress!.advanced(by: bytesWrote), + buffer.count - bytesWrote + ) + if n == -1 { + if errno == EAGAIN || errno == EIO { + return (bytesWrote, .again) + } + return (bytesWrote, .error(errno)) + } + + if n == 0 { + return (bytesWrote, .brokenPipe) + } + + bytesWrote += n + if bytesWrote < buffer.count { + continue + } + return (bytesWrote, .success) + } + } + + static func pipe() -> (read: Self, write: Self) { + let pipe = Pipe() + return (Self(handle: pipe.fileHandleForReading), Self(handle: pipe.fileHandleForWriting)) + } + + static func open(path: String) throws -> Self { + try open(path: path, mode: O_RDONLY | O_CLOEXEC) + } + + static func open(path: String, mode: Int32) throws -> Self { + let fd = Foundation.open(path, mode) + if fd < 0 { + throw POSIXError(.init(rawValue: errno)!) + } + return Self(fd: fd) + } +} diff --git a/vminitd/Sources/vminitd/ProcessSupervisor.swift b/vminitd/Sources/vminitd/ProcessSupervisor.swift new file mode 100644 index 00000000..67604d4a --- /dev/null +++ b/vminitd/Sources/vminitd/ProcessSupervisor.swift @@ -0,0 +1,110 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationOS +import Foundation +import Logging + +actor ProcessSupervisor { + private let queue: DispatchQueue + // `DispatchSourceSignal` is thread-safe. + private nonisolated(unsafe) let source: DispatchSourceSignal + private var processes = [ManagedProcess]() + + var log: Logger? + + func setLog(_ log: Logger?) { + self.log = log + } + + static let `default` = ProcessSupervisor() + + let poller: Epoll + + private init() { + let queue = DispatchQueue(label: "process-supervisor") + self.source = DispatchSource.makeSignalSource(signal: SIGCHLD, queue: queue) + self.queue = queue + self.poller = try! Epoll() + let t = Thread { + try! self.poller.run() + } + t.start() + } + + func ready() { + self.source.setEventHandler { + do { + self.log?.debug("received SIGCHLD, reaping processes") + try self.handleSignal() + } catch { + self.log?.error("reaping processes failed", metadata: ["error": "\(error)"]) + } + } + self.source.resume() + } + + private func handleSignal() throws { + dispatchPrecondition(condition: .onQueue(queue)) + + self.log?.debug("starting to wait4 processes") + let exited = Reaper.reap() + self.log?.debug("finished wait4 of \(exited.count) processes") + + for proc in processes { + let pid = proc.pid + self.log?.debug("checking for exit of managed process", metadata: ["pid": "\(pid)", "exits": "\(exited)"]) + + if pid <= 0 { + continue + } + + if let status = exited[pid] { + self.log?.debug( + "managed process exited", + metadata: [ + "pid": "\(pid)", + "status": "\(status)", + "count": "\(processes.count - 1)", + ]) + + proc.setExit(status) + self.processes.removeAll(where: { $0.pid == pid }) + } + } + } + + func start(process: ManagedProcess) throws -> Int32 { + self.log?.debug("in supervisor lock to start process") + defer { + self.log?.debug("out of supervisor lock to start process") + } + + do { + self.processes.append(process) + + return try process.start() + } catch { + self.log?.error("process start failed \(error)") + throw error + } + } + + deinit { + self.log?.info("process supervisor deinit") + source.cancel() + } +} diff --git a/vminitd/Sources/vminitd/Server+GRPC.swift b/vminitd/Sources/vminitd/Server+GRPC.swift new file mode 100644 index 00000000..75dd728a --- /dev/null +++ b/vminitd/Sources/vminitd/Server+GRPC.swift @@ -0,0 +1,834 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Containerization +import ContainerizationError +import ContainerizationNetlink +import ContainerizationOCI +import ContainerizationOS +import Foundation +import GRPC +import Logging +import NIOCore +import NIOPosix +import _NIOFileSystem + +private let _setenv = Foundation.setenv + +#if canImport(Musl) +import Musl +private let _mount = Musl.mount +private let _umount = Musl.umount2 +private let _kill = Musl.kill +private let _sync = Musl.sync +#elseif canImport(Glibc) +import Glibc +private let _mount = Glibc.mount +private let _umount = Glibc.umount2 +private let _kill = Glibc.kill +private let _sync = Glibc.sync +#endif + +extension Initd: Com_Apple_Containerization_Sandbox_V3_SandboxContextAsyncProvider { + func setTime( + request: Com_Apple_Containerization_Sandbox_V3_SetTimeRequest, + context: GRPC.GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_SetTimeResponse { + log.debug( + "setTime", + metadata: [ + "sec": "\(request.sec)", + "usec": "\(request.usec)", + ]) + + var tv = timeval(tv_sec: time_t(request.sec), tv_usec: suseconds_t(request.usec)) + guard settimeofday(&tv, nil) == 0 else { + let error = swiftErrno("settimeofday") + log.error( + "setTime", + metadata: [ + "error": "\(error)" + ]) + throw GRPCStatus(code: .internalError, message: "failed to settimeofday: \(error)") + } + + return .init() + } + + func setupEmulator( + request: Com_Apple_Containerization_Sandbox_V3_SetupEmulatorRequest, + context: GRPC.GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_SetupEmulatorResponse { + log.debug( + "setupEmulator", + metadata: [ + "request": "\(request)" + ]) + + if !Binfmt.mounted() { + throw GRPCStatus( + code: .internalError, + message: "\(Binfmt.path) is not mounted" + ) + } + + do { + let bfmt = Binfmt.Entry( + name: request.name, + type: request.type, + offset: request.offset, + magic: request.magic, + mask: request.mask, + flags: request.flags + ) + try bfmt.register(binaryPath: request.binaryPath) + } catch { + log.error( + "setupEmulator", + metadata: [ + "error": "\(error)" + ]) + throw GRPCStatus( + code: .internalError, + message: "setupEmulator: failed to register binfmt_misc entry: \(error)" + ) + } + + return .init() + } + + func sysctl( + request: Com_Apple_Containerization_Sandbox_V3_SysctlRequest, + context: GRPC.GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_SysctlResponse { + log.debug( + "sysctl", + metadata: [ + "settings": "\(request.settings)" + ]) + + do { + let sysctlPath = URL(fileURLWithPath: "/proc/sys/") + for (k, v) in request.settings { + guard let data = v.data(using: .ascii) else { + throw GRPCStatus(code: .internalError, message: "failed to convert \(v) to data buffer for sysctl write") + } + + let setting = + sysctlPath + .appendingPathComponent(k.replacingOccurrences(of: ".", with: "/")) + let fh = try FileHandle(forWritingTo: setting) + defer { try? fh.close() } + + try fh.write(contentsOf: data) + } + } catch { + log.error( + "deleteProcess", + metadata: [ + "error": "\(error)" + ]) + throw GRPCStatus( + code: .internalError, + message: "sysctl: failed to set sysctl: \(error)" + ) + } + + return .init() + } + + func proxyVsock( + request: Com_Apple_Containerization_Sandbox_V3_ProxyVsockRequest, + context: GRPC.GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_ProxyVsockResponse { + log.debug( + "proxy vsock", + metadata: [ + "id": "\(request.id)", + "port": "\(request.vsockPort)", + "guestPath": "\(request.guestPath)", + "action": "\(request.action)", + ]) + + do { + let proxy = VsockProxy( + id: request.id, + action: request.action == .into ? .dial : .listen, + port: request.vsockPort, + path: URL(fileURLWithPath: request.guestPath), + udsPerms: request.guestSocketPermissions, + log: log + ) + + try proxy.start() + try await state.add(proxy: proxy) + } catch { + log.error( + "proxyVsock", + metadata: [ + "error": "\(error)" + ]) + throw GRPCStatus( + code: .internalError, + message: "proxyVsock: failed to setup vsock proxy: \(error)" + ) + } + + return .init() + } + + func stopVsockProxy( + request: Com_Apple_Containerization_Sandbox_V3_StopVsockProxyRequest, + context: GRPC.GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_StopVsockProxyResponse { + log.debug( + "stop vsock proxy", + metadata: [ + "id": "\(request.id)" + ]) + + do { + let proxy = try await state.remove(proxy: request.id) + try proxy.close() + } catch { + log.error( + "stopVsockProxy", + metadata: [ + "error": "\(error)" + ]) + throw GRPCStatus( + code: .internalError, + message: "stopVsockProxy: failed to stop vsock proxy: \(error)" + ) + } + + return .init() + } + + func mkdir(request: Com_Apple_Containerization_Sandbox_V3_MkdirRequest, context: GRPC.GRPCAsyncServerCallContext) + async throws -> Com_Apple_Containerization_Sandbox_V3_MkdirResponse + { + log.debug( + "mkdir", + metadata: [ + "path": "\(request.path)", + "all": "\(request.all)", + ]) + + do { + try FileManager.default.createDirectory( + atPath: request.path, + withIntermediateDirectories: request.all + ) + } catch { + log.error( + "mkdir", + metadata: [ + "error": "\(error)" + ]) + throw GRPCStatus(code: .internalError, message: "mkdir: \(error)") + } + + return .init() + } + + func mount(request: Com_Apple_Containerization_Sandbox_V3_MountRequest, context: GRPC.GRPCAsyncServerCallContext) + async throws -> Com_Apple_Containerization_Sandbox_V3_MountResponse + { + log.debug( + "mount", + metadata: [ + "type": "\(request.type)", + "source": "\(request.source)", + "destination": "\(request.destination)", + ]) + + do { + // FIXME: Handle single file mounts. + let mnt = ContainerizationOS.Mount( + type: request.type, + source: request.source, + target: request.destination, + options: request.options + ) + + #if os(Linux) + try mnt.mount(createWithPerms: 0o755) + return .init() + #else + fatalError("mount not supported on platform") + #endif + } catch { + log.error( + "mount", + metadata: [ + "error": "\(error)" + ]) + throw GRPCStatus(code: .internalError, message: "mount: \(error)") + } + } + + func umount(request: Com_Apple_Containerization_Sandbox_V3_UmountRequest, context: GRPC.GRPCAsyncServerCallContext) + async throws -> Com_Apple_Containerization_Sandbox_V3_UmountResponse + { + log.debug( + "unmount", + metadata: [ + "path": "\(request.path)", + "flags": "\(request.flags)", + ]) + + #if os(Linux) + // Best effort EBUSY handle. + for _ in 0...50 { + let result = _umount(request.path, request.flags) + if result == -1 { + if errno == EBUSY { + try await Task.sleep(for: .milliseconds(10)) + continue + } + let error = swiftErrno("umount") + + log.error( + "unmount", + metadata: [ + "error": "\(error)" + ]) + throw GRPCStatus(code: .invalidArgument, message: "umount: \(error)") + } + break + } + return .init() + #else + fatalError("unmount not supported on platform") + #endif + } + + func setenv(request: Com_Apple_Containerization_Sandbox_V3_SetenvRequest, context: GRPC.GRPCAsyncServerCallContext) + async throws -> Com_Apple_Containerization_Sandbox_V3_SetenvResponse + { + log.debug( + "setenv", + metadata: [ + "key": "\(request.key)", + "value": "\(request.value)", + ]) + + guard _setenv(request.key, request.value, 1) == 0 else { + let error = swiftErrno("setenv") + + log.error( + "setEnv", + metadata: [ + "error": "\(error)" + ]) + + throw GRPCStatus(code: .invalidArgument, message: "setenv: \(error)") + } + return .init() + } + + func getenv(request: Com_Apple_Containerization_Sandbox_V3_GetenvRequest, context: GRPC.GRPCAsyncServerCallContext) + async throws -> Com_Apple_Containerization_Sandbox_V3_GetenvResponse + { + log.debug( + "getenv", + metadata: [ + "key": "\(request.key)" + ]) + + let env = ProcessInfo.processInfo.environment[request.key] + return .with { + if let env { + $0.value = env + } + } + } + + func createProcess( + request: Com_Apple_Containerization_Sandbox_V3_CreateProcessRequest, context: GRPC.GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_CreateProcessResponse { + log.debug( + "create process", + metadata: [ + "id": "\(request.id)", + "containerID": "\(request.containerID)", + "stdin": "Port: \(request.stdin)", + "stdout": "Port: \(request.stdout)", + "stderr": "Port: \(request.stderr)", + ]) + + if !request.hasContainerID { + fatalError("processes in the root of the vm not implemented") + } + + do { + var ociSpec = try JSONDecoder().decode( + ContainerizationOCI.Spec.self, + from: request.configuration + ) + + try ociAlterations(ociSpec: &ociSpec) + + guard let process = ociSpec.process else { + throw ContainerizationError( + .invalidArgument, + message: "oci runtime spec missing process configuration" + ) + } + + let stdioPorts = HostStdio( + stdin: request.hasStdin ? request.stdin : nil, + stdout: request.hasStdout ? request.stdout : nil, + stderr: request.hasStderr ? request.stderr : nil, + terminal: process.terminal + ) + + // This is an exec. + if let container = await self.state.containers[request.containerID] { + try await container.createExec( + id: request.id, + stdio: stdioPorts, + process: process + ) + } else { + // We need to make our new fangled container. + // The process ID must match the container ID for this. + guard request.id == request.containerID else { + throw ContainerizationError( + .invalidArgument, + message: "init process id must match container id" + ) + } + + // Write the etc/hostname file in the container rootfs since some init-systems + // depend on it. + let hostname = ociSpec.hostname + if let root = ociSpec.root, !hostname.isEmpty { + let etc = URL(fileURLWithPath: root.path).appendingPathComponent("etc") + try FileManager.default.createDirectory(atPath: etc.path, withIntermediateDirectories: true) + let hostnamePath = etc.appendingPathComponent("hostname") + try hostname.write(toFile: hostnamePath.path, atomically: true, encoding: .utf8) + } + + let ctr = try ManagedContainer( + id: request.id, + stdio: stdioPorts, + spec: ociSpec, + log: self.log + ) + try await self.state.add(container: ctr) + } + + return .init() + } catch { + log.error( + "create managed process", + metadata: [ + "error": "\(error)" + ]) + if error is GRPCStatus { + throw error + } + throw GRPCStatus(code: .internalError, message: "create managed process: \(error)") + } + } + + func killProcess( + request: Com_Apple_Containerization_Sandbox_V3_KillProcessRequest, + context: GRPC.GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_KillProcessResponse { + log.debug( + "kill process", + metadata: [ + "id": "\(request.id)", + "signal": "\(request.signal)", + ]) + + if !request.hasContainerID { + fatalError("processes in the root of the vm not implemented") + } + + let ctr = try await self.state.get(container: request.containerID) + + if request.id == request.containerID { + try await ctr.kill(request.signal) + } else { + let proc = try await ctr.getExec(id: request.id) + try proc.kill(request.signal) + } + + log.debug( + "kill process result", + metadata: [ + "id": "\(request.id)", + "signal": "\(request.signal)", + ]) + + return .init() + } + + func deleteProcess( + request: Com_Apple_Containerization_Sandbox_V3_DeleteProcessRequest, context: GRPC.GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_DeleteProcessResponse { + log.debug("delete process on port \(request.id)") + + if !request.hasContainerID { + fatalError("processes in the root of the vm not implemented") + } + + let ctr = try await self.state.get(container: request.containerID) + + // Are we trying to delete the container itself? + if request.id == request.containerID { + try await ctr.delete() + try await state.remove(container: request.id) + } else { + // Or just a single exec. + try await ctr.deleteExec(id: request.id) + } + + return .init() + } + + func startProcess( + request: Com_Apple_Containerization_Sandbox_V3_StartProcessRequest, context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_StartProcessResponse { + log.debug("starting process \(request.id)") + + if !request.hasContainerID { + fatalError("processes in the root of the vm not implemented") + } + + do { + let ctr = try await self.state.get(container: request.containerID) + + // FIXME: This should just happen inside of ManagedContainer. + let pid: Int32 + if request.id == request.containerID { + let process = ctr.initProcess + pid = try await ProcessSupervisor.default.start(process: process) + } else { + let process = try await ctr.getExec(id: request.id) + pid = try await ProcessSupervisor.default.start(process: process) + } + + return .with { + $0.pid = pid + } + } catch { + log.error( + "startProcess", + metadata: [ + "error": "\(error)" + ]) + throw GRPCStatus( + code: .internalError, + message: "startProcess: failed to start process: \(error)" + ) + } + } + + func resizeProcess( + request: Com_Apple_Containerization_Sandbox_V3_ResizeProcessRequest, context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_ResizeProcessResponse { + log.debug("resizing process pty \(request.id)") + + if !request.hasContainerID { + fatalError("processes in the root of the vm not implemented") + } + + do { + let ctr = try await self.state.get(container: request.containerID) + + let size = Terminal.Size(width: UInt16(request.columns), height: UInt16(request.rows)) + if request.id == request.containerID { + try await ctr.resize(size: size) + } else { + let proc = try await ctr.getExec(id: request.id) + try proc.resize(size: size) + } + } catch { + log.error( + "resizeProcess", + metadata: [ + "error": "\(error)" + ]) + throw GRPCStatus( + code: .internalError, + message: "resizeProcess: failed to resize process: \(error)" + ) + } + + return .init() + } + + func waitProcess( + request: Com_Apple_Containerization_Sandbox_V3_WaitProcessRequest, context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_WaitProcessResponse { + log.debug("waiting on process \(request.id)") + + if !request.hasContainerID { + fatalError("processes in the root of the vm not implemented") + } + + do { + let ctr = try await self.state.get(container: request.containerID) + + let exitCode: Int32 + if request.id == request.containerID { + exitCode = await ctr.wait() + } else { + let proc = try await ctr.getExec(id: request.id) + exitCode = await proc.wait() + } + + return .with { + $0.exitCode = exitCode + } + } catch { + log.error( + "waitProcess", + metadata: [ + "error": "\(error)" + ]) + throw GRPCStatus( + code: .internalError, + message: "waitProcess: failed to wait on process: \(error)" + ) + } + } + + func ipLinkSet( + request: Com_Apple_Containerization_Sandbox_V3_IpLinkSetRequest, context: GRPC.GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_IpLinkSetResponse { + log.debug( + "ip-link-set", + metadata: [ + "interface": "\(request.interface)", + "up": "\(request.up)", + ]) + + do { + let socket = try DefaultNetlinkSocket() + let session = NetlinkSession(socket: socket, log: log) + try session.linkSet(interface: request.interface, up: request.up) + } catch { + log.error( + "ip-link-set", + metadata: [ + "error": "\(error)" + ]) + throw GRPCStatus(code: .internalError, message: "ip-link-set: \(error)") + } + + return .init() + } + + func ipAddrAdd( + request: Com_Apple_Containerization_Sandbox_V3_IpAddrAddRequest, context: GRPC.GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_IpAddrAddResponse { + log.debug( + "ip-addr-add", + metadata: [ + "interface": "\(request.interface)", + "addr": "\(request.address)", + ]) + + do { + let socket = try DefaultNetlinkSocket() + let session = NetlinkSession(socket: socket, log: log) + try session.addressAdd(interface: request.interface, address: request.address) + } catch { + log.error( + "ip-addr-add", + metadata: [ + "error": "\(error)" + ]) + throw GRPCStatus(code: .internalError, message: "ip-addr-add: \(error)") + } + + return .init() + } + + func ipRouteAddLink( + request: Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkRequest, context: GRPC.GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_IpRouteAddLinkResponse { + log.debug( + "ip-route-add-link", + metadata: [ + "interface": "\(request.interface)", + "address": "\(request.address)", + "srcAddr": "\(request.srcAddr)", + ]) + + do { + let socket = try DefaultNetlinkSocket() + let session = NetlinkSession(socket: socket, log: log) + try session.routeAdd( + interface: request.interface, + destinationAddress: request.address, + srcAddr: request.srcAddr + ) + } catch { + log.error( + "ip-route-add-link", + metadata: [ + "error": "\(error)" + ]) + throw GRPCStatus(code: .internalError, message: "ip-route-add-link: \(error)") + } + + return .init() + } + + func ipRouteAddDefault( + request: Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultRequest, + context: GRPC.GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_IpRouteAddDefaultResponse { + log.debug( + "ip-route-add-default", + metadata: [ + "interface": "\(request.interface)", + "gateway": "\(request.gateway)", + ]) + + do { + let socket = try DefaultNetlinkSocket() + let session = NetlinkSession(socket: socket, log: log) + try session.routeAddDefault(interface: request.interface, gateway: request.gateway) + } catch { + log.error( + "ip-route-add-default", + metadata: [ + "error": "\(error)" + ]) + throw GRPCStatus(code: .internalError, message: "ip-route-add-default: \(error)") + } + + return .init() + } + + func configureDns( + request: Com_Apple_Containerization_Sandbox_V3_ConfigureDnsRequest, + context: GRPC.GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_ConfigureDnsResponse { + let domain = request.hasDomain ? request.domain : nil + log.debug( + "configure-dns", + metadata: [ + "location": "\(request.location)", + "nameservers": "\(request.nameservers)", + "domain": "\(domain ?? "")", + ]) + + do { + let etc = URL(fileURLWithPath: request.location).appendingPathComponent("etc") + try FileManager.default.createDirectory(atPath: etc.path, withIntermediateDirectories: true) + let resolvConf = etc.appendingPathComponent("resolv.conf") + let config = DNS( + nameservers: request.nameservers, + domain: domain, + searchDomains: request.searchDomains, + options: request.options + ) + let text = config.resolvConf + log.debug("writing to path \(resolvConf.path) \(text)") + try text.write(toFile: resolvConf.path, atomically: true, encoding: .utf8) + log.debug("wrote resolver configuration", metadata: ["path": "\(resolvConf.path)"]) + } catch { + log.error( + "configure-dns", + metadata: [ + "error": "\(error)" + ]) + throw GRPCStatus(code: .internalError, message: "configure-dns: \(error)") + } + + return .init() + } + + private func swiftErrno(_ msg: Logger.Message) -> POSIXError { + let error = POSIXError(.init(rawValue: errno)!) + log.error( + msg, + metadata: [ + "error": "\(error)" + ]) + return error + } + + func sync( + request: Com_Apple_Containerization_Sandbox_V3_SyncRequest, + context: GRPC.GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_SyncResponse { + log.debug("sync") + + _sync() + return .init() + } + + func kill( + request: Com_Apple_Containerization_Sandbox_V3_KillRequest, + context: GRPCAsyncServerCallContext + ) async throws -> Com_Apple_Containerization_Sandbox_V3_KillResponse { + log.debug( + "kill", + metadata: [ + "pid": "\(request.pid)", + "signal": "\(request.signal)", + ]) + + let r = _kill(request.pid, request.signal) + return .with { + $0.result = r + } + } +} + +extension Initd { + func ociAlterations(ociSpec: inout ContainerizationOCI.Spec) throws { + guard var process = ociSpec.process else { + throw ContainerizationError(.invalidArgument, message: "runtime spec without process field present") + } + guard let root = ociSpec.root else { + throw ContainerizationError(.invalidArgument, message: "runtime spec without root field present") + } + + try FileManager.default.createDirectory( + atPath: root.path, + withIntermediateDirectories: true + ) + + if process.cwd.isEmpty { + process.cwd = "/" + } + + // This is truthfully a Windows field, but it's fairly common for vm runtimes + // to fill this in as a way to defer username lookup until we hit the guest. + let username = process.user.username + if !username.isEmpty { + let parsedUser = try User.parseUser(root: root.path, userString: username) + process.user.uid = parsedUser.uid + process.user.gid = parsedUser.gid + process.user.additionalGids.append(contentsOf: parsedUser.sgids) + if !process.env.contains("HOME") { + process.env.append("HOME=\(parsedUser.home)") + } + } + ociSpec.process = process + } +} diff --git a/vminitd/Sources/vminitd/Server.swift b/vminitd/Sources/vminitd/Server.swift new file mode 100644 index 00000000..e268e55d --- /dev/null +++ b/vminitd/Sources/vminitd/Server.swift @@ -0,0 +1,121 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationError +import Foundation +import GRPC +import Logging +import Musl +import NIOCore +import NIOPosix + +final class Initd: Sendable { + let log: Logger + let state: State + let group: MultiThreadedEventLoopGroup + + actor State { + var containers: [String: ManagedContainer] = [:] + var proxies: [String: VsockProxy] = [:] + + func get(container id: String) throws -> ManagedContainer { + guard let ctr = self.containers[id] else { + throw ContainerizationError( + .notFound, + message: "container \(id) not found" + ) + } + return ctr + } + + func add(container: ManagedContainer) throws { + guard containers[container.id] == nil else { + throw ContainerizationError( + .exists, + message: "container \(container.id) already exists" + ) + } + containers[container.id] = container + } + + func add(proxy: VsockProxy) throws { + guard proxies[proxy.id] == nil else { + throw ContainerizationError( + .exists, + message: "proxy \(proxy.id) already exists" + ) + } + proxies[proxy.id] = proxy + } + + func remove(proxy id: String) throws -> VsockProxy { + guard let proxy = proxies.removeValue(forKey: id) else { + throw ContainerizationError( + .notFound, + message: "proxy \(id) does not exist" + ) + } + return proxy + } + + func remove(container id: String) throws { + guard let _ = containers.removeValue(forKey: id) else { + throw ContainerizationError( + .notFound, + message: "container \(id) does not exist" + ) + } + } + } + + init(log: Logger, group: MultiThreadedEventLoopGroup) { + self.log = log + self.group = group + self.state = State() + } + + func serve(port: Int) async throws { + try await withThrowingTaskGroup(of: Void.self) { group in + log.debug("starting process supervisor") + + await ProcessSupervisor.default.setLog(self.log) + await ProcessSupervisor.default.ready() + + log.debug( + "booting grpc server on vsock", + metadata: [ + "port": "\(port)" + ]) + let server = try await Server.start( + configuration: .default( + target: .vsockAddress(.init(cid: .any, port: .init(port))), + eventLoopGroup: self.group, + serviceProviders: [self]) + ).get() + log.info( + "grpc api serving on vsock", + metadata: [ + "port": "\(port)" + ]) + + group.addTask { + try await server.onClose.get() + } + try await group.next() + group.cancelAll() + } + } +} diff --git a/vminitd/Sources/vminitd/StandardIO.swift b/vminitd/Sources/vminitd/StandardIO.swift new file mode 100644 index 00000000..7fa113ef --- /dev/null +++ b/vminitd/Sources/vminitd/StandardIO.swift @@ -0,0 +1,210 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Containerization +import ContainerizationOS +import Foundation +import Logging +import SendableProperty +import Synchronization + +final class StandardIO: ManagedProcess.IO & Sendable { + private let log: Logger? + + private let stdio: HostStdio + private let stdinPipe: Pipe? + private let stdoutPipe: Pipe? + private let stderrPipe: Pipe? + + @SendableProperty + private var stdinSocket: Socket? + @SendableProperty + private var stdoutSocket: Socket? + @SendableProperty + private var stderrSocket: Socket? + + init( + process: inout Command, + stdio: HostStdio, + log: Logger? + ) { + self.stdio = stdio + self.log = log + + if stdio.stdin != nil { + let inPipe = Pipe() + process.stdin = inPipe.fileHandleForReading + self.stdinPipe = inPipe + } else { + process.stdin = nil + self.stdinPipe = nil + } + + if stdio.stdout != nil { + let outPipe = Pipe() + process.stdout = outPipe.fileHandleForWriting + self.stdoutPipe = outPipe + } else { + process.stdout = nil + self.stdoutPipe = nil + } + + if stdio.stderr != nil { + let errPipe = Pipe() + process.stderr = errPipe.fileHandleForWriting + self.stderrPipe = errPipe + } else { + process.stderr = nil + self.stderrPipe = nil + } + } + + func start() throws { + if let stdinPort = self.stdio.stdin { + let type = VsockType( + port: stdinPort, + cid: VsockType.hostCID + ) + let stdinSocket = try Socket(type: type) + try stdinSocket.connect() + self.stdinSocket = stdinSocket + + try relay( + readFromFd: stdinSocket.fileDescriptor, + writeToFd: self.stdinPipe!.fileHandleForWriting.fileDescriptor + ) + } + + if let stdoutPort = self.stdio.stdout { + let type = VsockType( + port: stdoutPort, + cid: VsockType.hostCID + ) + let stdoutSocket = try Socket(type: type) + try stdoutSocket.connect() + self.stdoutSocket = stdoutSocket + + try relay( + readFromFd: self.stdoutPipe!.fileHandleForReading.fileDescriptor, + writeToFd: stdoutSocket.fileDescriptor + ) + } + + if let stderrPort = self.stdio.stderr { + let type = VsockType( + port: stderrPort, + cid: VsockType.hostCID + ) + let stderrSocket = try Socket(type: type) + try stderrSocket.connect() + self.stderrSocket = stderrSocket + + try relay( + readFromFd: self.stderrPipe!.fileHandleForReading.fileDescriptor, + writeToFd: stderrSocket.fileDescriptor + ) + } + } + + // NOP + func resize(size: Terminal.Size) throws {} + + func relay(readFromFd: Int32, writeToFd: Int32) throws { + let readFrom = OSFile(fd: readFromFd) + let writeTo = OSFile(fd: writeToFd) + // `buf` isn't used concurrently. + nonisolated(unsafe) let buf = UnsafeMutableBufferPointer.allocate(capacity: Int(getpagesize())) + + try ProcessSupervisor.default.poller.add(readFromFd, mask: EPOLLIN) { mask in + if mask.isHangup && !mask.readyToRead { + self.cleanup(readFromFd, buffer: buf, log: self.log) + return + } + + // Loop so that in the case that someone wrote > buf.count down the pipe + // we properly will drain it fully. + while true { + let r = readFrom.read(buf) + if r.read > 0 { + let view = UnsafeMutableBufferPointer( + start: buf.baseAddress, + count: r.read + ) + + let w = writeTo.write(view) + if w.wrote != r.read { + self.log?.error("stopping relay: short write for stdio") + self.cleanup(readFromFd, buffer: buf, log: self.log) + return + } + } + + switch r.action { + case .error(let errno): + self.log?.error("failed with errno \(errno) while reading for fd \(readFromFd)") + fallthrough + case .eof: + self.cleanup(readFromFd, buffer: buf, log: self.log) + self.log?.debug("closing relay for \(readFromFd)") + return + case .again: + // We read all we could, exit. + if mask.isHangup { + self.cleanup(readFromFd, buffer: buf, log: self.log) + } + return + default: + break + } + } + } + } + + func cleanup(_ fd: Int32, buffer: UnsafeMutableBufferPointer, log: Logger?) { + do { + // We could alternatively just allocate buffers in the constructor, and free them + // on close(). + buffer.deallocate() + try ProcessSupervisor.default.poller.delete(fd) + } catch { + self.log?.error("failed to delete pipe fd from epoll \(fd): \(error)") + } + } + + func close() throws { + if let stdin = self.stdinPipe { + try stdin.fileHandleForWriting.close() + } + if let stdout = self.stdoutPipe { + try stdout.fileHandleForReading.close() + } + if let stderr = self.stderrPipe { + try stderr.fileHandleForReading.close() + } + } + + func closeAfterExec() throws { + if let stdin = self.stdinPipe { + try stdin.fileHandleForReading.close() + } + if let stdout = self.stdoutPipe { + try stdout.fileHandleForWriting.close() + } + if let stderr = self.stderrPipe { + try stderr.fileHandleForWriting.close() + } + } +} diff --git a/vminitd/Sources/vminitd/TerminalIO.swift b/vminitd/Sources/vminitd/TerminalIO.swift new file mode 100644 index 00000000..548baf14 --- /dev/null +++ b/vminitd/Sources/vminitd/TerminalIO.swift @@ -0,0 +1,160 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import Containerization +import ContainerizationOS +import Foundation +import Logging +import SendableProperty + +final class TerminalIO: ManagedProcess.IO & Sendable { + private let parent: Terminal + private let child: Terminal + private let log: Logger? + + private let stdio: HostStdio + @SendableProperty + private var stdinSocket: Socket? + @SendableProperty + private var stdoutSocket: Socket? + + init( + process: inout Command, + stdio: HostStdio, + log: Logger? + ) throws { + let pair = try Terminal.create() + self.parent = pair.parent + self.child = pair.child + self.stdio = stdio + self.log = log + + let ptyHandle = child.handle + process.stdin = stdio.stdin != nil ? ptyHandle : nil + + let stdoutHandle = stdio.stdout != nil ? ptyHandle : nil + process.stdout = stdoutHandle + process.stderr = stdoutHandle + } + + func resize(size: Terminal.Size) throws { + if self.stdio.stdin != nil { + try parent.resize(size: size) + } + } + + func start() throws { + if let stdinPort = self.stdio.stdin { + let type = VsockType( + port: stdinPort, + cid: VsockType.hostCID + ) + let stdinSocket = try Socket(type: type) + try stdinSocket.connect() + self.stdinSocket = stdinSocket + + try relay( + readFromFd: stdinSocket.fileDescriptor, + writeToFd: self.parent.handle.fileDescriptor + ) + } + + if let stdoutPort = self.stdio.stdout { + let type = VsockType( + port: stdoutPort, + cid: VsockType.hostCID + ) + let stdoutSocket = try Socket(type: type) + try stdoutSocket.connect() + self.stdoutSocket = stdoutSocket + + try relay( + readFromFd: self.parent.handle.fileDescriptor, + writeToFd: stdoutSocket.fileDescriptor + ) + } + } + + func relay(readFromFd: Int32, writeToFd: Int32) throws { + let readFrom = OSFile(fd: readFromFd) + let writeTo = OSFile(fd: writeToFd) + // `buf` isn't used concurrently. + nonisolated(unsafe) let buf = UnsafeMutableBufferPointer.allocate(capacity: Int(getpagesize())) + + try ProcessSupervisor.default.poller.add(readFromFd, mask: EPOLLIN) { mask in + if mask.isHangup && !mask.readyToRead { + self.cleanup(readFromFd, buffer: buf, log: self.log) + return + } + + // Loop so that in the case that someone wrote > buf.count down the pipe + // we properly will drain it fully. + while true { + let r = readFrom.read(buf) + if r.read > 0 { + let view = UnsafeMutableBufferPointer( + start: buf.baseAddress, + count: r.read + ) + + let w = writeTo.write(view) + if w.wrote != r.read { + self.log?.error("stopping relay: short write for stdio") + self.cleanup(readFromFd, buffer: buf, log: self.log) + return + } + } + + switch r.action { + case .error(let errno): + self.log?.error("failed with errno \(errno) while reading for fd \(readFromFd)") + fallthrough + case .eof: + self.cleanup(readFromFd, buffer: buf, log: self.log) + self.log?.debug("closing relay for \(readFromFd)") + return + case .again: + // We read all we could, exit. + if mask.isHangup { + self.cleanup(readFromFd, buffer: buf, log: self.log) + } + return + default: + break + } + } + } + } + + func cleanup(_ fd: Int32, buffer: UnsafeMutableBufferPointer, log: Logger?) { + do { + // We could alternatively just allocate buffers in the constructor, and free them + // on close(). + buffer.deallocate() + try ProcessSupervisor.default.poller.delete(fd) + } catch { + self.log?.error("failed to delete pipe fd from epoll \(fd): \(error)") + } + } + + func close() throws { + try parent.close() + } + + func closeAfterExec() throws { + try child.close() + } +} diff --git a/vminitd/Sources/vminitd/VsockProxy.swift b/vminitd/Sources/vminitd/VsockProxy.swift new file mode 100644 index 00000000..5aba8f5b --- /dev/null +++ b/vminitd/Sources/vminitd/VsockProxy.swift @@ -0,0 +1,250 @@ +//===----------------------------------------------------------------------===// +// Copyright © 2025 Apple Inc. and the containerization project authors. All rights reserved. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. +//===----------------------------------------------------------------------===// + +import ContainerizationIO +import ContainerizationOS +import Foundation +import Logging +import SendableProperty + +final class VsockProxy: Sendable { + enum Action { + case listen + case dial + } + + private enum SocketType { + case unix + case vsock + } + + init( + id: String, + action: Action, + port: UInt32, + path: URL, + udsPerms: UInt32?, + log: Logger? = nil + ) { + self.id = id + self.action = action + self.port = port + self.path = path + self.udsPerms = udsPerms + self.log = log + } + + public let id: String + private let path: URL + private let action: Action + private let port: UInt32 + private let udsPerms: UInt32? + @SendableProperty + private var listener: Socket? + private let log: Logger? + @SendableProperty + private var t: Task<(), Never>? +} + +extension VsockProxy { + func close() throws { + guard let listener else { + return + } + + try listener.close() + let fm = FileManager.default + if fm.fileExists(atPath: self.path.path) { + try FileManager.default.removeItem(at: self.path) + } + self.t?.cancel() + } + + func start() throws { + switch self.action { + case .dial: + try dialHost() + case .listen: + try dialGuest() + } + } + + private func dialHost() throws { + let fm = FileManager.default + + let parentDir = self.path.deletingLastPathComponent() + try fm.createDirectory( + at: parentDir, + withIntermediateDirectories: true + ) + + let type = try UnixType( + path: self.path.path, + perms: self.udsPerms, + unlinkExisting: true + ) + let uds = try Socket(type: type) + try uds.listen() + self.listener = uds + + try self.acceptLoop(socketType: .unix) + } + + private func dialGuest() throws { + let type = VsockType( + port: self.port, + cid: VsockType.anyCID + ) + let vsock = try Socket(type: type) + try vsock.listen() + self.listener = vsock + + try self.acceptLoop(socketType: .vsock) + } + + private func acceptLoop(socketType: SocketType) throws { + guard let listener else { + return + } + + let stream = try listener.acceptStream() + self.t = Task { + do { + for try await conn in stream { + Task { + do { + try await handleConn( + conn: conn, + connType: socketType + ) + } catch { + self.log?.error("failed to handle connection: \(error)") + } + } + } + } catch { + self.log?.error("failed to accept connection: \(error)") + } + } + } + + private func handleConn( + conn: ContainerizationOS.Socket, + connType: SocketType + ) async throws { + try await withCheckedThrowingContinuation { (c: CheckedContinuation) in + do { + // `relayTo` isn't used concurrently. + nonisolated(unsafe) var relayTo: ContainerizationOS.Socket + + switch connType { + case .unix: + let type = VsockType( + port: self.port, + cid: VsockType.hostCID + ) + relayTo = try Socket( + type: type, + closeOnDeinit: false + ) + case .vsock: + let type = try UnixType(path: self.path.path) + relayTo = try Socket( + type: type, + closeOnDeinit: false + ) + } + + try relayTo.connect() + + // `clientFile` isn't used concurrently. + nonisolated(unsafe) var clientFile = OSFile.SpliceFile(fd: conn.fileDescriptor) + // `serverFile` isn't used concurrently. + nonisolated(unsafe) var serverFile = OSFile.SpliceFile(fd: relayTo.fileDescriptor) + + let cleanup = { @Sendable in + do { + try ProcessSupervisor.default.poller.delete(clientFile.fileDescriptor) + try ProcessSupervisor.default.poller.delete(serverFile.fileDescriptor) + try conn.close() + try relayTo.close() + } catch { + self.log?.error("Failed to clean up vsock proxy: \(error)") + } + c.resume() + } + + try! ProcessSupervisor.default.poller.add(clientFile.fileDescriptor, mask: EPOLLIN | EPOLLOUT) { mask in + if mask.readyToRead { + do { + let (_, _, action) = try OSFile.splice(from: &clientFile, to: &serverFile) + if action == .eof || action == .brokenPipe { + return cleanup() + } + } catch { + return cleanup() + } + } + + if mask.readyToWrite { + do { + let (_, _, action) = try OSFile.splice(from: &serverFile, to: &clientFile) + if action == .eof || action == .brokenPipe { + return cleanup() + } + } catch { + return cleanup() + } + } + + if mask.isHangup { + return cleanup() + } + } + + try! ProcessSupervisor.default.poller.add(serverFile.fileDescriptor, mask: EPOLLIN | EPOLLOUT) { mask in + if mask.readyToRead { + do { + let (_, _, action) = try OSFile.splice(from: &serverFile, to: &clientFile) + if action == .eof || action == .brokenPipe { + return cleanup() + } + } catch { + return cleanup() + } + } + + if mask.readyToWrite { + do { + let (_, _, action) = try OSFile.splice(from: &clientFile, to: &serverFile) + if action == .eof || action == .brokenPipe { + return cleanup() + } + } catch { + return cleanup() + } + } + + if mask.isHangup { + return cleanup() + } + } + } catch { + c.resume(throwing: error) + } + } + } +}