Fixes#85
The virtualization bool on LinuxContainer mostly just forwards to
VZVirtualMachineInstance which today would silently take your boolean
and do nothing if the underlying platform doesn't have support for it.
This is (to me) arguably worse than erroring, as it gives the client a
false security that the setting is on, and they should have virt
capabilities in the container/guest now.
This change makes it so that we throw a ContainerizationError for this
case, with a code of .unsupported so it's checkable by a user if they
want more information on the "why".
Remove Latin abbreviations from the documentation in accordance with the
[Apple Style Guide](https://help.apple.com/applestyleguide/). This
change does not impact any abbreviations used in code comments since
those are not covered by the style guide.
## Issue
When pulling images, the download speed appears to be slower compared to
Docker.
I found that parallel chunk generation was being performed during the
layer download process.
While individual chunks allow parallel download operations, the overall
process remains sequential between chunks.
This results less performance when chunks contain both small and large
layers mixed together.
## Changes
Discontinued chunk-based segmentation to enable more efficient parallel
downloads.
## Results(in my local env)
| image | layers | old | new |
| ---|---|---|---|
| node:latest | 12 | 1m15s | 1m10s |
| ghcr.io/norio-nomura/swift_discord_bot:main | 54 | 2m45s | 2m30s |
<details>
<summary>raw terminal log</summary>
```
❯ rm -rf ~/Library/Application\ Support/com.apple.containerization && time bin/cctl_old images pull docker.io/library/node:latest
image pulled
bin/cctl_old images pull docker.io/library/node:latest 42.37s user 6.60s system 64% cpu 1:15.94 total
❯ rm -rf ~/Library/Application\ Support/com.apple.containerization && time bin/cctl_new images pull docker.io/library/node:latest
image pulled
bin/cctl_new images pull docker.io/library/node:latest 42.27s user 6.72s system 69% cpu 1:10.58 total
❯ rm -rf ~/Library/Application\ Support/com.apple.containerization && time bin/cctl_old images pull docker.io/library/node:latest
image pulled
bin/cctl_old images pull docker.io/library/node:latest 45.65s user 7.36s system 70% cpu 1:15.64 total
❯ rm -rf ~/Library/Application\ Support/com.apple.containerization && time bin/cctl_new images pull docker.io/library/node:latest
image pulled
bin/cctl_new images pull docker.io/library/node:latest 39.76s user 6.32s system 65% cpu 1:10.50 total
❯ rm -rf ~/Library/Application\ Support/com.apple.containerization && time bin/cctl_old images pull docker.io/library/node:latest
image pulled
bin/cctl_old images pull docker.io/library/node:latest 42.47s user 6.75s system 65% cpu 1:14.72 total
❯ rm -rf ~/Library/Application\ Support/com.apple.containerization && time bin/cctl_new images pull docker.io/library/node:latest
image pulled
bin/cctl_new images pull docker.io/library/node:latest 42.28s user 6.65s system 69% cpu 1:09.93 total
❯ rm -rf ~/Library/Application\ Support/com.apple.containerization && time bin/cctl_new images pull ghcr.io/norio-nomura/swift_discord_bot:main
image pulled
bin/cctl_new images pull ghcr.io/norio-nomura/swift_discord_bot:main 103.83s user 18.71s system 81% cpu 2:30.02 total
❯ rm -rf ~/Library/Application\ Support/com.apple.containerization && time bin/cctl_old images pull ghcr.io/norio-nomura/swift_discord_bot:main
image pulled
bin/cctl_old images pull ghcr.io/norio-nomura/swift_discord_bot:main 120.79s user 20.70s system 85% cpu 2:45.26 total
```
</details>
<details>
<summary>patch for download only</summary>
```diff
diff --git a/Sources/cctl/ImageCommand.swift b/Sources/cctl/ImageCommand.swift
index 84c5218..4aa4bb8 100644
--- a/Sources/cctl/ImageCommand.swift
+++ b/Sources/cctl/ImageCommand.swift
@@ -127,6 +127,7 @@ extension Application {
}
print("image pulled")
+ return
let tempDir = FileManager.default.uniqueTemporaryDirectory(create: true)
if let platform {
```
</details>
This PR improves **safety and consistency** of the GitHub Actions
workflow (build-test-images.yml) file by:
- Using **[[ ... ]]** **instea**d of **[ ... ]** for conditionals.
- Adding **double quotes** around inputs and refs to **avoid**
evaluation issues.
This helps prevent bugs in **shell parsing**, especially with **empty or
misinterpreted** input values.
@katiewasnothere @wlan0
#70 Made it clearer as I wasn't sure if the API allows us to run x64
binaries or also run such Docker images.
---------
Signed-off-by: Aviram Hassan <aviramyhassan@gmail.com>
Co-authored-by: Danny Canter <danny_canter@apple.com>
## Summary
Corrects a grammatical error in CONTRIBUTING.md line 36.
## Change
**Line 36**: `speed of which` → `speed at which`
The preposition "of" is incorrect when connecting the noun "speed" with
the relative pronoun "which". Standard English requires "at" (e.g., "the
speed at which", "the rate at which").
**Before:**
```
This will greatly help the priority setting and speed of which maintainers can get to your issue.
```
**After:**
```
This will greatly help the priority setting and speed at which maintainers can get to your issue.
```
I think it is config-arm64 that you are using, so I have created a PR to
avoid confusion.
If you don't need it, please let me know so that I can Close it.
This removes two image push tests. We cannot have the CI push to our
ghcr registry since external users do not have write access for pushing
the image. We will explore a better solution.
Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
We eventually only want to support building docs from release branches
and tags, however, while we're working to initially set up the docs, we
may have some churn. So we want to be able to publish from main during
that churn.
Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
If we split this out, it'll be easier to point developers at specific
parts for setting up their build environment, versus building and
testing.
Signed-off-by: Eric Ernst <eric_ernst@apple.com>
- The kqueue handlers for stdio didn't have logic to exit on zero byte
reads.
- The agent wasn't getting closed explicitly in .delete()
- In LinuxContainer we should call delete just for sanity, if for
nothing more than ensuring the agent vsock fd is closed.
Signed-off-by: Danny Canter <danny_canter@apple.com>
Some updates to the documentation:
* Replace code-of-conduct with organization one.
* Cleanup `CONTRIBUTING.md`, `README.md` and `SECURITY.md` markdown.
* Remove `.txt` extension from `LICENSE` for consistency across repos.
This is something I forgot to update ages ago. The field names, while
they do make sense, were different than the constructor names that
eventually set the fields themselves. This is kind of awkward, and I'd
much rather fix this now while it's much easier.
We'll need to update `container` after this
Signed-off-by: Danny Canter <danny_canter@apple.com>
This creates an allocator based on a FIFO that will allocate through the
range before reusing previously released allocations.
Signed-off-by: michael crosby <michael_crosby@apple.com>
Resolves the warning
```
LocalOCILayoutClient.swift:87:37: warning: capture of non-sendable type 'T.AsyncIterator.Type' in an isolated closure
87 | for try await buffer in input {
| `- warning: capture of non-sendable type 'T.AsyncIterator.Type' in an isolated closure
88 | wrote += buffer.readableBytes
89 | try buffer.withUnsafeReadableBytes { pointer in
```
Signed-off-by: Aditya Ramani <a_ramani@apple.com>