- The protobuf makefile relies on being able to find
the built protoc dependencies under the build
directory. Since we were not passing the build
configuration to the swift command to build those
dependencies, the built binaries were going into
the debug build folder. If make protos was run
when `BUILD_CONFIGURATION=release`, then
we'd fail to find the dependencies since the build
folder should now be the release build folder.
This PR fixes that.
Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
Closes https://github.com/apple/container/issues/1687
The default kernel archive is downloaded from a remote release URL
during first-run setup and via `container system kernel set
--recommended`. Previously, the archive contents were not verified after
download, so integrity depended on HTTPS and the release artifact
remaining unchanged.
This change adds digest verification for kernel archives. The
recommended/default kernel now has pinned digest metadata using an
algorithm-prefixed value such as `sha256:<hex>`. `container system
kernel set --tar` accepts `--digest`; remote tar URLs require it, and
local tar archives can also be verified before unpacking and
installation.
The system config also supports `kernel.digest`, and a custom
`kernel.url` must provide a digest for that archive.
- Fixes#1789.
- Release 2.9.0 of `grpc-swift-nio-transport` fixes
an HTTP/2 initialization race where the server could
send SETTINGS before gRPC handlers are added to
the pipeline, causing the client to hang. The new
`WrappedChannel.wrapping(config:serviceConfig:makeChannel:)`
API calls `configure(channel)` inside the channel
initializer, ensuring the pipeline is set up before any inbound
bytes arrive. This eliminates the need for the custom
`HTTP2ConnectBufferingHandler` workaround.
- This fixes the LLVM coverage data not properly being emitted for XPC
services. It requires piping the `LLVM_PROFILE_FILE` environment
variable through to all the services and plugins. The variable itself
also required the "%c" formatter to ensure that it continuously emits
coverage data, otherwise when XPC services are killed via "bootout" they
do not emit coverage.
- Part of #1833.
- CLI progress and registry test migrations were inadventently reverted
by #1857.
- Migrate TestCLINoParallelCases to TestCLIImagePruneSerial and
TestCLINetworkPruneSerial.
- Clean up test selection patterns in Makefile.
- Remove all legacy CLITests files.
- Use swift-testing `withKnownIssue` to run but ignore failures on flaky
`testCreateNameLongestValid` and `testIsolatedNetwork`.
- Extracts a fixture helper for tests requiring a retry loop.
- Part of #1833.
- Replace old targets with new ones.
- Try increased parallelism after test tweaks in #1857.
- Exclude test files from coverage analysis.
This PR cleans up some of the new IntegrationTests files to ensure that
each file has a single test suite defined within it and the name of the
file matches the name of the test suite.
Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
- Part of #1833.
- Adds `ContainerFixture` with scoped resource lifecycle and cleanup in
place of implementation inheritance for test support functions. The
fixture also handles resource prefixing and uses a more ergonomic
`CommandResult` in place of a tuple for return values.
- `ImageWarmup` suite pre-pulls well-known images, and
`copyWarmupImage()` tags test-local refs, keeping the canonical image
store untouched.
- Three-phase `integration-new`: warmup, followed by concurrent tests
(managed by the swift test
`--experimental-maximum-parallelization-width` flag), followed by
serialized tests.
- `coverage-new` merges unit + integration-new profraw, replacing
`coverage` in CI as a migration progress indicator.
- Updates GH workflow so non-coverage invokes both the `integration` and
`integration-new` Makefile targets, while coverage runs invoke the
`coverage-new` target.
- Fixes#1801.
- When `container image save` runs without `--output`,
stdout carries the OCI tar archive. The command writes
the archive bytes to stdout and then `print(reference)`s
each saved image reference to stdout afterward,
appending non-archive text after the tar EOF marker,
which will cause strict tar/OCI consumers to fail.
- This routes the saved-reference list to stderr in the
no-`--output` branch, so stdout contains only archive
bytes. When saving to a file via `--output`, stdout is
free, so the references continue to print to stdout
exactly as before.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- Updates `actions/checkout` from 6.0.3 to 7.0.0
- Updates `softprops/action-gh-release` from 3.0.0 to 3.0.1
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
- `SystemStart` used `try!` when creating the apiserver
data directory. File system operations can fail for
legitimate reasons: insufficient permissions, disk full,
read-only volume. Crashing the process in these cases
gives the user no actionable error message.
- Replaced with `try` so the error propagates up and is
surfaced cleanly.
- Closes#1812.
- The network plugin is the source of truth for the variant, if any,
that applies to the network. Resolving a missing variant configuration
option in the API server can create a situation where the variant the
runtime uses for interface selection is incorrect.
- Adds serial suites trait to tests to see whether it helps current CI
issues.
## Type of Change
- [x] Bug fix
- [ ] New feature
- [ ] Breaking change
- [ ] Documentation update
## Motivation and Context
Fixes a flaw in our interface strategy logic.
## Testing
- [x] Tested locally
- [ ] Added/updated tests
- [ ] Added/updated docs
- `swift-argument-parser` enforces that `arguments` is
non-empty before `run()` is invoked, so the force-unwrap
of `arguments.first!` is not reachable in practice. However,
the guard makes the invariant explicit in the code itself,
removes reliance on ArgumentParser's implicit
enforcement, and would satisfy force-unwrap lint rules
if enabled in the future.
- PRs are backed up. We need to rework the CLI tests
to shorten test time and fix conflicts between tests.
## Testing
- [ ] Tested locally
- [x] Added/updated tests
- [ ] Added/updated docs