Commit Graph
90 Commits
Author SHA1 Message Date
Danny CanterandGitHub 66426acfbb CLI: Defer tty reset immediately (#488)
We were defer closing the IO for run/exec/start fairly late in the
container run cycle which had the downside of that if the container run
failed your tty would be stuck in raw mode. This change just moves the
closing (return tty to origin state) to directly after we create the IO.
2025-08-13 15:04:18 -04:00
Sidhartha ManiandGitHub 3d0c1fee97 Native Builder: Build Cache to use new snapshotter (#492) 2025-08-13 10:46:14 -07:00
Sidhartha ManiandGitHub d2f48982c1 Native Builder: Define Snapshotter protocol (#491)
This PR defines the snapshotter protocol

```swift
    ///Mount a snapshot and all its previous layers
    func prepare(_ snapshot: Snapshot) async throws -> Snapshot

    /// Commit a snapshot, making it permanent.
    func commit(_ snapshot: Snapshot) async throws -> Snapshot

    /// Remove a snapshot from snapshot store
    func remove(_ snapshot: Snapshot) async throws
```

It updates executors to work with this new protocol
2025-08-12 23:30:56 -07:00
Sidhartha ManiandGitHub 0885cdd6a9 Native Builder: DiffKey and Differ Procol (#482)
This PR introduces the `Differ` with methods:

```swift
// Differ protocol
func diff(base: Snapshot?, target: Snapshot) async throws -> Descriptor
func apply(descriptor: Descriptor, to base: Snapshot?) async throws -> Snapshot
```

It also introduces `DiffKey`, which is a MerkeTree based key for fast
diff computations between two dirs
2025-08-12 11:23:55 -07:00
Danny CanterandGitHub adf7186d54 CLI (run): Only ask for stdin for -i (#483)
Today if you asked for a pty and also wanted to detach we'd open stdin
and then immediately close that pipe which would close the guest relay
as well. I don't believe we need stdin open unless it's asked for with
-i. Truthfully there's one extra bit here that is needed which is if -i
and -d are supplied we need to tell the daemon to open stdin, but not
send an fd (as they're client supplied and the client/cli is going to
exit immediately). That will need to be a followup, as it's mainly
useful for attach which we don't have today.
2025-08-11 23:53:53 -04:00
J LoganandGitHub 6242706c66 Fixes for install root and plugin detection. (#467)
- Sets up API server as source of truth for installation root, similarly
to what was done for the data root. `system start` establishes the
install root, setting the environment variable `CONTAINER_INSTALL_ROOT`
when launching the API server.
- The API server propagates the environment variable when launching
helpers, and returns the install root to the CLI via the health check
XPC.
- Includes several fixes for detecting plugins that use app bundle
layout.
2025-08-08 21:44:26 -07:00
J LoganandGitHub d242864e9f Relocate and rename ClientDefaults. (#474)
- Part of #384.
- Rename to reflect that these are not just client defaults.
- Relocate so callers don't need the heavyweight coupling to
ContainerClient to access the type.
2025-08-08 16:04:32 -07:00
J LoganandGitHub edad7dd0df Prevent removal of network with container references. (#470)
- Closes #392.
2025-08-08 13:25:26 -07:00
Kathryn BaldaufandGitHub c21068661f Native builder parser support for EXPOSE (#465)
Closes https://github.com/apple/container/issues/430

Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
2025-08-07 12:17:59 -07:00
J LoganandGitHub 88223d8add Select alternate data path with container system start --app-root path. (#419)
Closes #418.
2025-08-06 14:49:09 -07:00
RajandGitHub b8965cae43 Named Volumes (#362)
Closes #339.

This change adds named volume support to container, providing volume
management CLI commands - `create, delete, list and inspect`. The
implementation uses EXT4 block-based persistent storage with a new
`VolumesService` actor for thread-safe operations, integrates seamlessly
with the existing container mount system through a new `.volume`
filesystem type, and provides atomic volume operations with XPC-based
API communication. Volumes are stored in isolated directories with
configurable sizes (default 512GB) and include proper cleanup and
container usage tracking for safe deletion.

Example Usage:

```
# Create a volume
container volume create mydata

# Use volume in container
container run -v mydata:/data alpine

# List volumes
container volume list

# Inspect volume details
container volume inspect mydata

# Clean up
container volume rm mydata
```
2025-08-05 21:47:42 -07:00
Kathryn BaldaufandGitHub d048ea5201 Native builder: remove option token in favor of string literals (#450)
Remove the option token from the dockerfile tokenizer for the native
builder. This cleans up some of the logic around handling options
depending on if they're instruction options or user provided options to
a command.

Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
2025-08-05 16:33:07 -07:00
Kathryn BaldaufandGitHub 8adb215522 Native Builder: Add parser support for CMD and LABEL instructions (#448)
This PR adds support for CMD and LABEL instructions in the native
builder's parser.

This also changes how options are tokenized. Options now include the raw
string so that when constructing a command for instructions like CMD and
RUN, we can use the exact user input without having to add logic in the
tokenizer to know when we're parsing a command verses other options,
etc.

Closes https://github.com/apple/container/issues/428 and
https://github.com/apple/container/issues/429

Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
2025-08-05 14:34:34 -07:00
Danny CanterandGitHub f2130a9604 Generate /etc/hosts by default (#423)
Closes: #314

This change uses the new `.hosts` config entry
on Containerization's LinuxContainer config to setup a default
/etc/hosts file in the container. Today the two entries are localhost to
127.0.0.1 and the container's IP to its hostname.
2025-08-05 12:44:13 -07:00
Dmitry KovbaandGitHub e7da2d59f1 Do not print task descriptions with disabled progress updates (#444)
Fully resolves https://github.com/apple/container/issues/396.
2025-08-05 12:29:26 -07:00
YR ChenandGitHub ce431b5c8f Optionally resolve wrapper index to single-platform manifest based on com.apple.containerization.index.indirect annotation (#397)
Fixes #212

This PR:
- adds a `package func resolved()` on `ClientImage` that makes use of
the new `com.apple.containerization.index.indirect` annotation to
identify and resolve wrapper indices created by Containerization;
- replace the digest displayed in `container image list` with the one of
the resolved manifest;
- use the resolved manifest for `container image inspect` if the index
is a wrapper.
2025-08-04 11:14:00 -07:00
Dmitry KovbaandGitHub 9e9d056339 Transition to Mutex (#364)
Due to the reduced use of the macro, we can now fully transition to
`Mutex`.
2025-07-31 13:36:18 -07:00
Kathryn BaldaufandGitHub 16f2630126 Add initial native builder code (#399)
We're working on making a pure swift container image build system that
leverages containerization. This PR represents our initial design and
initial work towards this goal.

The native builder is still in active development and most of the
implementation has not been started or completed. We will be opening a
series of issues that represent various (but not necessarily all) pieces
of work that need to be done here.

There are docs included in this PR that describe the overall design of
each component and outline some of our goals. The easiest way to view
the docs by themselves (since this is a massive PR) is to look at the
docs commit in the `Commits` tab.

We'd love any feedback! 

@wlan0

---------

Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
2025-07-31 13:13:20 -07:00
Danny CanterandGitHub 3fcf647c7b Add virtualization support for containers (#377) 2025-07-30 11:14:41 -07:00
Kathryn BaldaufandGitHub 047c1afe96 Fix user arg passthrough for container create (#393)
This matches other container commands that rely on user arguments at the
end, such as `container run`. Closes #395.

Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
2025-07-29 13:54:12 -07:00
Danny CanterandGitHub ccd15edc16 Bump Containerization to 0.5.0 (#363)
0.5.0 introduces a new way to configure the containers and execs. This
is now done all upfront at constructor time in a callback style. I'm
very happy with the config improvements, but because IO can only be
setup at constructor time this makes it so that we need to supply IO at
creation time of the VM or exec, which isn't the end of the world. All
that really changes is `boostrap()` and `createProcess()` now take in IO
instead of slightly later in `process.start()`
2025-07-29 16:02:19 -04:00
Sidhartha ManiandGitHub cc4a85bb09 add support for local build output (#369)
Fixes https://github.com/apple/container/issues/354
2025-07-23 15:59:28 -07:00
J LoganandGitHub f0eda65a20 Applies feedback for PR #352. (#365)
- Forgot to commit the changes to gracefully shut down the event loop
group used by the port forwards.
2025-07-23 12:10:59 -07:00
J LoganandGitHub eea8cb6709 Adds --publish flag for forwarding traffic to container ports. (#352) 2025-07-23 00:28:41 -07:00
Danny CanterandGitHub c0d1f8fb11 CLI: Handle stdin stream if it's a regular file (#322)
readabilityHandler is a bit crummy if it's a regular file. This just
writes our own loop and exits and shuts down the write end of the pipe
if we get to the end of the file.
2025-07-22 13:33:11 -07:00
Kathryn BaldaufandGitHub 8002eec249 Add cause string to error message sent with xpc (#361)
Looks like we've been ignoring the "cause" field for
ContainerizationError when sent over xpc. Add the cause to the
`ContainerXPCError` message field instead of a new `cause` field since
`Error` is not encodable. The goal here is just to preserve information.

Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
2025-07-21 15:04:28 -07:00
J LoganandGitHub 0ef36d470b Use wildcard IP for UDP backend local address. (#359) 2025-07-19 00:15:53 -07:00
Sidhartha ManiandGitHub f68919c137 [Build] fixes for tar output mode (#353)
Fixes https://github.com/apple/container/issues/347
2025-07-18 16:50:11 -07:00
J LoganandGitHub 1de3036f9a Adds TCP and UDP port forwarders. (#338) 2025-07-18 12:08:52 -07:00
J LoganandGitHub 2e1bee1bda Fix subcommand groups in top level help. (#351)
- Closes #349.
2025-07-17 22:10:03 -07:00
Typ0geniusandGitHub 8053e9f16b Make image details public (#335)
I want to access the different variants of an image in my app, which
information is only available in the ImageDetail. Although the function
ClientImage.details() -> ImageDetail and its return type are already
public, its properties aren’t, which prevents access to this
information.
2025-07-16 17:03:46 -07:00
J LoganandGitHub 1707e1b530 Use {install-root}/libexec/container-plugins for plugins. (#341)
- Use a directory that's separate from user data, as user-installed
plugins have a distinct lifecycle.
- Closes #340.
2025-07-15 18:18:38 -07:00
Dmitry KovbaandGitHub f889c1bf76 Use the new @SendablePropertyUnchecked macro (#332)
Changes in this PR require merging
https://github.com/apple/containerization/pull/212 in containerization
and creating a new tag.
2025-07-14 16:57:55 -07:00
Dmitry KovbaandGitHub c41a8883ea Use Mutex for thread-safe access to structs (#325)
Changes in this PR prevent a race caused by an implicit call to a
computed property getter when updating the property value.
2025-07-14 15:23:35 -07:00
Kathryn BaldaufandGitHub f0d82d2032 Handle when keychain query returns an unhandled error (#331)
Depends on https://github.com/apple/containerization/pull/210
Related to https://github.com/apple/container/issues/254

---------

Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
2025-07-14 14:52:12 -07:00
Danny CanterandGitHub 66a6974c6d ProcessIO: Don't error if stdin isn't a pty and !-i (#312)
We don't need to error unless we're supplying io.
2025-07-08 16:29:34 -07:00
J LoganandGitHub f22674156c Flush output when following logs. (#316)
- Closes #315.
2025-07-08 16:01:22 -07:00
Arnav ReddyandGitHub a7799d02e3 Mark SandboxSnapshot init as public for sandbox plugins (#309)
Changed `SandboxSnapshot` initializer from `package init()` to `public
init()` to enable external package consumers to create and use
`SandboxSnapshot` instances in their custom Sandbox plugins.

The `SandboxSnapshot` is used for `container list` functionality
2025-07-08 14:17:17 -07:00
Sidhartha ManiandGitHub 6d804620a5 [Build] Disable rosetta during builds with a UserDefault (#273)
Fixes https://github.com/apple/container/issues/103
2025-07-01 14:52:41 -07:00
J LoganandGitHub 75e92853e3 Assigns default nameserver in sandbox service. (#276)
* Closes #148.
* Storing the default nameserver in the bundle config means that DNS
won't work if the container stops and then restarts later when the
subnet address has changed.
2025-07-01 10:03:23 -07:00
Eliseo MartelliandGitHub 48db62376d Use enum for ClientHealthCheck namespace (#225)
Switch `ClientHealthCheck` from a `struct` to an `enum` to prevent
instantiation.
2025-07-01 12:55:49 -04:00
Aditya RamaniandGitHub 4bfa6c29ec Add unpack strategy to SnapshotStore (#274)
Define a `UnpackStrategy` function type in the `SnapshotStore` to give
more control over how an image is unpacked.

Previously, we were creating a 512 GB sparse block file for the initial
file system of a container, which is overkill.

With this change, the vminit image is unpacked to a smaller block file,
while container images are unpacked to the 512 GB block

Follows the same pattern as
https://github.com/apple/container/blob/main/Sources/Helpers/RuntimeLinux/RuntimeLinuxHelper.swift#L71

Signed-off-by: Aditya Ramani <a_ramani@apple.com>
2025-07-01 11:22:22 -04:00
J LoganandGitHub 3b5c253059 Adds container network for macOS 26. (#243)
See discussion below for example. For multiple network interfaces in a
single container we'll want to integrate against a containerization that
includes apple/containerization#156.

The change bumps the containerization dependency to 0.2.0 and addresses
the breaking API changes.

```console
% container network
OVERVIEW: Manage container networks

USAGE: container network <subcommand>

OPTIONS:
  --version               Show the version.
  -h, --help              Show help information.

SUBCOMMANDS:
  create                  Create a new network
  delete, rm              Delete one or more networks
  list, ls                List networks
  inspect                 Display information about one or more networks

  See 'container help network <subcommand>' for detailed help.
```
2025-06-27 14:12:29 -07:00
Eliseo MartelliandGitHub b5589f7f8c Improve error handling in answerHost (#226)
Refactor `answerHost` to throw descriptive `DNSResolverError` instances
instead of returning nil when IP allocation or parsing fails.
2025-06-27 10:29:25 -07:00
Dmitry KovbaandGitHub de2be705de Remove the support for CURRENT_SDK (#251)
This PR removes the no longer needed support for `CURRENT_SDK`.
2025-06-26 10:40:34 -04:00
Sidhartha ManiandGitHub c7c88c2e34 [Build] Do not use unbounded DispatchIO readers for tar tranfers (#257)
- Addresses https://github.com/apple/container/issues/166
- Memory utilization explodes since there is no mechanism for
backpressure
- Using a synchronous buffered reader seem to provide similar
performance without the memory explosion issue
- 4MB buffer seems to provide the best results

| Metric | 1MB Buffer | 4MB Buffer | Unbounded Zero-Copy |

|--------------------------|------------|------------|---------------------|
| Build Time | 149.33s | 138.57s | 139.79s |
| Max RAM Used | 2.16 GB | 3.02 GB | 3.52 GB |
| Peak Memory Footprint | 8.30 GB | 8.17 GB | 10.21 GB |
| Page Reclaims | 1,085,559 | 1,039,677 | 1,619,943 |
| Page Faults | 115 | 148 | 143 |
| CPU Usage (User+Sys) | 53.71s | 53.12s | 60.44s |
2025-06-25 13:51:51 -07:00
Kathryn BaldaufandGitHub 4a6a1f15d8 Add test that we replace meta args in builder correctly (#255)
Depends on https://github.com/apple/container-builder-shim/pull/24 

Related to https://github.com/apple/container/issues/252

---------

Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
2025-06-24 13:25:58 -07:00
Renee ChangandGitHub a69ed78484 Add socket publishing functionality (#236)
Signed-off-by: renee chang <rchang25@apple.com>
2025-06-20 09:00:47 -07:00
Spencer HeywoodandGitHub a262d8fc6a provide suggestion if xpc 'Connection invalid' error encountered (#179)
Closes https://github.com/apple/container/issues/80

Adds the following help message if you try to run `container` against a
host that hasn't started the container system:

```
❯ /usr/local/bin/container list
Error: internalError: "failed to list containers" (cause: "interrupted: "Connection invalid: ensure container system has been started with `container system start`"")

❯ /usr/local/bin/container run -it --rm docker.io/alpine
Error: interrupted: "Connection invalid: ensure container system has been started with `container system start`"
```
2025-06-19 00:12:57 -07:00
RamsyanaandGitHub 21cfebb475 Fix Race Condition in Container Removal (#130) (#218)
This PR resolves a race condition when removing a container immediately
after stopping it, caused by the `stop` command returning before the
container fully transitions to the stopped state (#130).

**Changes:**
- Enhanced `TestCLIRmRace.swift` with robust test logic and helper
methods (`containerExists`, `safeRemove`).
- Improved error handling to distinguish race conditions from successful
removals.
- Added exponential backoff retry logic for cleanup operations.
- Updated `CLITest.swift` with missing `doRemove` method.
- Fixed `BuilderStart.swift` to handle `.stopping` case.
- Improved error messages with container ID for better debugging.

**Testing:**
-  All tests pass (`make test`, `make integration`).
-  Verified on macOS 26.
-  Race condition test validates success and failure scenarios.
-  Code formatted (`make fmt`).

Hopefully, this will pass the integration tests on GitHub.

Signed-off-by: ramsyana <47033578+ramsyana@users.noreply.github.com>
2025-06-16 23:19:46 -07:00