Commit Graph
95 Commits
Author SHA1 Message Date
Kathryn Baldauf d6f052d206 Update license header on all files to include the current year (#1024)
## Motivation and Context
Now that we're in 2026, we need to update the license headers on all the
files. Unfortunately, Hawkeye doesn't have an attribute for the current
year to help us avoid this in the future. Instead, I had to work around
this by doing the following:

1. Update licenserc.toml with:
     ```
      [properties]
       ... (other properties)
       currentYear = "2026"
     ```
 
2. Update scripts/license-header.txt with
    ```
Copyright ©{{ " " }}{%- set created = attrs.git_file_created_year or
attrs.disk_file_created_year -%}{%- set modified = props["currentYear"]
-%}{%- if created != modified -%} {{created}}-{{modified}}{%- else
-%}{{created}}{%- endif -%}{{ " " }}{{ props["copyrightOwner"] }}.
    ```

Then I removed these two changes before committing. After this PR is
merged, all files will have recently had git updates, so the existing
code for setting the modified year should work as intended.

Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
2026-01-05 13:09:34 -08:00
Danny Canter 20dc0bcfee Parser: Support relative paths for --volume (#1013) 2026-01-04 11:11:09 -08:00
Danny Canter 020949ea2b CLI: Small fixups for implicit envvars (#1014)
We should only inherit from the host if there's no =. Additionally
document the flag a little more to show that we can inherit from the
host.
2026-01-04 10:51:20 -08:00
Amir Alperin df368b790e Fix port validation to allow same port for different protocols (#992) (#1000)
- Fixes: #992 
- Port validation previously rejected valid configurations
  when the same port number was used for different
  protocols (TCP and UDP). For example:
 `-p 1024:1024/udp -p 1024:1024/tcp`
  Although this is a valid and common use case, the
  validation logic treated it as a conflict.

To fix this, I updated the validation key to include the protocol name.
The validation now checks for overlapping port numbers only within the
same protocol, rather than across all protocols.

This change enables binding the same port number for both TCP and UDP,
aligning the validation behavior with real-world networking
requirements.

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [ ] Added/updated docs
2026-01-04 10:49:22 -08:00
Volodymyr BortniakandBortniak Volodymyr 9c239aa36c Add support for reading env from named pipes (#974)
This is a fix for
[issue#956](https://github.com/apple/container/issues/956)

`FileManager.default.contents(atPath:)` returns `nil` for named pipes
(FIFOs)
and process substitutions like `/dev/fd/XX` because:
1. It expects regular files with a known size
2. Named pipes are stream-based and block until data arrives

## Solution
Use `FileHandle(forReadingFrom:)` instead, which:
- Properly handles blocking I/O
- Works with named pipes, process substitutions, and regular files
(mentioned in the
[doc](https://developer.apple.com/documentation/foundation/filehandle))

Co-authored-by: Bortniak Volodymyr <Bortnyak@users.noreply.github.com>
2025-12-19 15:36:02 -08:00
Michael Gathara b1b99809d4 Fix: Kubes Cluster in Container Crashing Container (IS#923) (#930)
- Fixes issue #923 
- I fixed a race condition in `ConnectHandler.swift` where
  an asynchronous network connection could complete
  after the handler had already been removed from the
  pipeline.
- This prevents the EXC_BREAKPOINT crash in
  container-runtime-linux that occurred when kinc
  (Kubernetes in Container) created rapid connections.
- The actual fix was inadvertently applied in #957, so this
  PR contains only the test code.
2025-12-17 18:58:50 -08:00
Saehej Kang 9f4efe0c4c [networks]: add prune command (#914)
- Closes #893
2025-12-17 00:30:33 -08:00
J Logan 4f88725158 Use new IP/CIDR types from Containerization. (#957)
- Part of work for #460.
- With CZ release 0.17.0, the IP and CIDR address
  types changed from String to IPv4Address and
  CIDRv4, respectively. This PR applies the corresponding
  adaptations to container.
2025-12-16 16:34:13 -08:00
karen heckel c22f1289fc Feat: customize console output with env variable (#952)
Fixes apple#915

Added a new feature to support the passing of buildkit colors for
customizing console output.
2025-12-15 21:16:55 -08:00
Saehej Kang 9b7cfd852e [images]: refactor prune command (#941)
- Updates to `image prune` for consistency with how
  other `prune` commands are done. Added missing
  test cases as well for the command
- Relates to the discussion from #914
2025-12-15 17:52:00 -08:00
wangxiaoleiandfatelei a2901e0517 feat: implement version sub command (#911)
- closes #383
- implement version sub command, give more info

---------

Co-authored-by: fatelei <fatelei@fateleis-MacBook-Pro.local>
2025-12-09 23:04:40 -03:00
Saehej Kang 0733a81a6d [volumes]: refactor prune command (#940)
- Refactor the `volume prune` command to follow a client-side approach.
  The `volumeDiskUsage` is calculated in the service file, so it made
  sense to leave that there.
- Relates to the discussion from #914
2025-12-09 15:54:37 -03:00
J Logan a64bd77b15 Fix broken image integration tests. (#944)
- Fixes #943.
- Use images other than alpine:3.20 for image concurrency test so as not
to interfere with tests using that image.
- Rename test files to match suite names.
2025-12-09 14:35:34 -03:00
Santosh BhavaniandClaude f7bcb687fd Add --max-concurrent-downloads flag for parallel layer downloads (#716)
Adds `--max-concurrent-downloads` flag to `container image pull` for
configurable concurrent layer downloads.

Fixes #715
Depends on apple/containerization#311

**Usage**:
```bash
container image pull nginx:latest --max-concurrent-downloads 6
```

**Changes**:
- Add CLI flag (default: 3)
- Thread parameter through XPC stack
- Update to use forked containerization with configurable concurrency

**Performance**: ~1.2-1.3x faster pulls for multi-layer images with
higher concurrency

**Tests**: Included standalone tests verify concurrency behavior and
parameter flow

---------

Co-authored-by: Claude <noreply@anthropic.com>
2025-12-07 15:56:50 -03:00
Raj d327a50219 Add container system df command for disk usage reporting (#902)
- Closes #884. 

## Type of Change
- [ ] Bug fix
- [x] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Motivation and Context
This PR implements the `container system df` command to display disk
usage statistics for images, containers, and volumes, along with their
total count, active count, size, and reclaimable space for each resource
type.

Active resources are determined by container mount references and
running state, while reclaimable space is calculated from inactive or
stopped resources.

Example output:
```
~/container ❯ container system df
TYPE           TOTAL  ACTIVE  SIZE      RECLAIMABLE
Images         4      3       4.42 GB   516.5 MB (11%)
Containers     4      2       2.69 GB   1.51 GB (56%)
Local Volumes  3      2       208.5 MB  66.2 MB (32%)
```

I'll have some follow-on PRs that will add `-v/--verbose` flag for
detailed per-resource information, `--filter` flag for filtering output
by resource type, and a `--debug` flag for debug statistics like block
usage, clone counts etc.

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [ ] Added/updated docs
2025-11-20 09:19:00 -08:00
Danny Canter 266b135da2 Fix container stats build break (#898)
Seems `run` was changed to return a data blob variant of stdout, which
made the function have a tuple of size 4 instead of 3 now. The stats
tests still used the old 3 wide variant which broke the build.
2025-11-18 16:29:24 -08:00
Danny Canter cf0eba495e Implement container stats (#851)
Closes #824

This implements statistics gathering across the various components, but
ultimately this is for implementing a new CLI command: `container
stats`. This shows memory usage, cpu usage, network and block i/o and
the number of processes in the container. The new command can inspect
stats for 1-N containers and by default continuously updates in a `top`
like stream.

## Type of Change
- [ ] Bug fix
- [x] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [x] Added/updated docs
2025-11-18 14:10:05 -08:00
ChengHao Yang 2d07d8ff96 Fix TestCLICreateCommand failing test (#897)
Signed-off-by: ChengHao Yang
2025-11-18 15:47:08 -03:00
Saehej Kang 9b435536f0 [container-build]: Support inline Dockerfile from stdin (#827)
- Closes #727
2025-11-18 12:25:11 -03:00
J Logan 739f5e5a9c Import --publish checks and data representation. (#872)
- Closes #871.
- Simplify and improve port range checks.
- Add count field to `PublishPort` to keep config
  size small for large port ranges.
2025-11-18 10:02:44 -03:00
Saehej Kang a99cb4ad08 [image-save-load]: support for stdin/stdout (#734)
- Closes #559
- Facilitates easy transfer between container applications that can use OCI tarfiles.
2025-11-18 00:42:24 -03:00
Saehej KangandJ Logan e49a563912 [tests]: refactor run function for stdin/stdout support (#830)
When working on test cases for #827 and #734 the following issues
occurred
  1. There was no support to pass in `Data` for `stdin` (input pipe added
    + new argument for the data)
  2. Pipes were getting blocked during the `try process.run()` and
    `process.waitUntilExit()` (order of operations were fixed)
  3. We need the binary data for directly piping the `stdout` data to
    `stdin`, and converting the data to a `string`, returns `""` (added a
    new value to the tuple)

I opened a new PR here for this as I did not want to bloat the other PRs
with so many updates. At first I thought of creating a new function
named `runStdinStdout`, but that seemed redundant as it pretty much was
going to do the same thing as `run`.

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [ ] Added/updated docs

---------

Co-authored-by: J Logan <john_logan@apple.com>
2025-11-14 21:01:31 -03:00
caztanj 8685bb2c23 Add support for publish port ranges (#801)
- Adding many `-p` arguments for each port gets a bit
  annoying. Adding an entire range of ports with one `-p`
  arguments is much nicer.
2025-11-12 19:15:59 -03:00
Danny Canter 14f1df59bf CLI: Implement exec -d (#852)
Surprised we didn't have this already..
2025-11-07 12:46:00 -08:00
Saehej Kang cd7c3a12c8 [options]: Replace --disable-progress-updates with --progress (none | ansi) (#808)
Part 1 of #641
2025-11-01 14:24:50 -07:00
Rado Kubiak | Rado x Tech 745cc1813e Fix container DNS resolution broken by AAAA/IPv6 NXDOMAIN handling (#786)
- In Alpine Linux containers (commonly used as Docker base images),
  standard DNS resolution is provided by **musl**, a lightweight C
  standard library (libc). Musl implements DNS lookups via
  `getaddrinfo()`, which queries AAAA (IPv6) records first.
- Problem: DNS did not work correctly **inside containers**. Any
  system command attempting to resolve hostnames
  (e.g., `ping dynamodb-admin`) **failed** when the DNS server
  responded NXDOMAIN for AAAA records, even if A (IPv4) records
  existed. Explicitly forcing IPv4 (`ping -4dynamodb-admin`) worked
  correctly, showing the issue is specific to musl’s IPv6-first behavior.
- Consequence: In IPv4-only environments, Alpine-based containers
  cannot resolve hostnames using standard tools or libraries.
  Applications relying on `getaddrinfo()` fail with ENOTFOUND,
  breaking networking and inter-container communication.
- Root cause:  Following RFC 8305 / RFC 6724, musl treats NXDOMAIN
  for AAAA as “hostname does not exist” and does not fallback to A
  (IPv4) records.
- Fix: The Apple Container DNS engine now behaves as follows:
  * If an **A record exists**, AAAA queries return **NOERROR with empty
    answer (NODATA)**.
  * If neither **A nor AAAA** exist, NXDOMAIN is returned.
  This ensures that Alpine-based containers in IPv4-only networks can
  correctly resolve hostnames inside containers without modifying
  container images or application code.
2025-10-30 17:03:17 -07:00
Raj 13a2f1a9e3 Update builder-shim to 0.6.3 for metadata only Dockerfile support (#825)
- Fixes #736.
- BuildKit returns nil ref for Dockerfiles containing only metadata
  (`ENV/ARG/LABEL`) directives without filesystem operations
  (`RUN/COPY/ADD`). Previously, this caused builds to fail with "no build
  directives" error.
- Builder-shim 0.6.3 [fixes this](https://github.com/apple/container-builder-shim/pull/47) by
  creating a minimal marker layer when ref is nil but image config is
  valid, satisfying OCI manifest requirements.
- Also, added some tests for this behavior.
2025-10-30 16:27:38 -07:00
Danish Singh Sethi c909cb3a27 Add --mac-address flag to set custom MAC addresses for containers (#753)
- Closes #752.
- Currently, there is no way to specify a custom MAC address for a
container's network interface and the MAC address is auto-generated by
the system.
- Use Cases
  - **Network Testing**: Developers testing network-dependent applications
that need predictable MAC addresses
  - **License Management**: Running containerized software with MAC-based
license keys
  - **Network Automation**: Scripts and tools that expect specific MAC
addresses for configuration
  - **Debugging**: Consistent MAC addresses across container restarts for
easier troubleshooting
2025-10-30 16:26:06 -07:00
Danny Canter 9f8a0fb87d Build: Fallback to Containerfile if Dockerfile not found (#812)
Closes #782 #99

If a Dockerfile can't be found in the context dir, check for the common
alternative Containerfile. This does not implement .containerignore
also, solely Containerfile for now. This also funnily enough fixes us
not checking for the Dockerfile IN the context directory.. woops.

## Type of Change
- [x] Bug fix
- [x] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [x] Added/updated docs
2025-10-27 08:28:29 -07:00
Dmitry Kovba 4944fe1641 Use a consistent capitalization in log and error messages (#806)
Updates the capitalization in log and error messages to be consistent.
2025-10-24 19:18:32 -07:00
Raj b4c3ebfed8 add volume prune command (#783)
- Closes #508.

## Type of Change
- [ ] Bug fix
- [x] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Motivation and Context
Adds a `container volume prune` command that removes volumes with no
container references and reports the amount of disk space reclaimed.
This helps users clean up unused volumes and easily reclaim disk space.

Also updates the `volume delete` documentation to clarify and highlight
how the `--all` flag works.

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [x] Added/updated docs
2025-10-21 16:58:11 -07:00
Danny Canter 2f507fe9d9 Make container start idempotent (#792)
Fixes #772 

Today it fails in bootstrap the second go around, and we also have an
error handler that automatically cleans up the container if bootstrap
failed which is even worse. This change short circuits us first in the
cli if the state is running when we get() the container, and also adds
in a clause to bootstrap to just early return if we already have a
client.
2025-10-21 14:42:32 -07:00
Danny Canter 109d4b4393 Integration: Fix image inspect error message (#795)
container -> image
2025-10-21 13:26:27 -07:00
Raj ce40ffd33d add support for multiple --tag flags in build (#785)
- Closes #732.

## Type of Change
- [ ] Bug fix
- [x] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Motivation and Context
Adds support for specifying multiple `-t` / `--tag` flags with the
`build` command. All specified tags will point to the same built image.

Example:
`container build -t myapp:latest -t myapp:v1.0.0 -t myapp:stable .`

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [x] Added/updated docs
2025-10-21 13:03:46 -07:00
Raj 2f8de3a660 Implicitly create named volumes (#769)
- Closes #690.

## Type of Change
- [ ] Bug fix
- [x] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Motivation and Context
Named volumes are now implicitly created when referenced in container
commands. So, if `myvolume` doesn't exist and you run `container run -v
myvolume:/data alpine`, it is automatically created.

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [x] Added/updated docs
2025-10-16 14:48:57 -07:00
Raj f90f67ccf0 Add support for anonymous volumes (#768)
- Closes #726.

## Type of Change
- [ ] Bug fix
- [x] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Motivation and Context
Adds support for anonymous volumes. Users can now create volumes without
explicit naming using `-v /path` and `--mount type=volume,dst=/path`
syntax.

Usage:
```
# anonymous volume  
container run -v /data alpine
container run -v anon-01k7jpghe4kg4ph5a4vkccksbb:/data alpine

# Multiple anonymous volumes
container run --rm -v /logs -v /cache -v /tmp alpine
```

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [x] Added/updated docs
2025-10-15 17:33:49 -07:00
J Logan bc70b39182 Fix broken proxy configuration for default kernel fetch. (#747)
- Closes #466.

## Type of Change
- [x] Bug fix
- [ ] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Motivation and Context
Proxy logic worked well enough for CI but broken in general.

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [ ] Added/updated docs
2025-10-10 10:17:42 -07:00
Danny Canter 73709232d2 CLI: Fix env-file parsing (#707)
Closes #691

Any envvars that had equal signs in the value would be ommitted today.
This change brings it much more in line with docker's behavior/parser
and adds unit tests to verify this is the case.
2025-10-06 12:12:50 -07:00
J Logan bfc5ca9222 Removes "all rights reserved" from license header. (#711)
Closes #63.
2025-10-03 13:28:16 -07:00
Dmitry Kovba 48230f3804 Update license headers in C files (#693)
## Type of Change
- [x] Bug fix
- [ ] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Motivation and Context
There was a duplicated and outdated license header in some files.

## Testing
- [x] Tested locally
- [ ] Added/updated tests
- [ ] Added/updated docs
2025-10-02 09:42:24 -07:00
J Logan d045e5b0f0 Updates containerization to 0.9.1. (#697)
- Converts client to work with ExitStatus instead of integer error
codes.

## Type of Change
- [ ] Bug fix
- [ ] New feature  
- [x] Breaking change (SandboxClient.wait() returns ExitStatus instead
of Int32, apple/containerization#300)
- [ ] Documentation update

## Motivation and Context
Pick up DNS bug fix, update for breaking API change.

## Testing
- [x] Tested locally
- [x] Added/updated tests (fixed DNS test, using correct `options` now,
apple/containerization#303).
- [ ] Added/updated docs
2025-10-01 10:04:39 -07:00
J Logan 06eab455c8 Clarify memory units in help and documentation. (#657)
Closes #519.

## Type of Change
- [ ] Bug fix
- [ ] New feature  
- [ ] Breaking change
- [x] Documentation update

## Motivation and Context
Clarifies memory units.

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [x] Added/updated docs
2025-09-22 11:05:06 -07:00
Dmitry Kovba 6eaf51b8bc Remove Native Builder from the main branch (#634)
The work on the Native Builder has been moved to a separate branch
`dev/native-builder`. This PR removes it from the `main` branch.
2025-09-20 00:07:57 -07:00
Dmitry Kovba 3e52a3c305 Fix failing network tests (#620)
This PR fixes failing network tests by using lowercased names.
Additionally, it reduces code duplication.
2025-09-17 09:59:43 -07:00
J Logan 449f1d23df Replace scattered defaults subcommands with system property. (#604)
Common subcommands for all defaults.

- Closes #384.
- Replaces `registry default` and `system dns default` subcommands with
`system property`.
- Users can use `system property ls` to see details about each supported
default value.
- `system property set` implements reasonable validation for all
properties.
- NOTE: Probing of the registry for `registry default set` was removed,
which means users will find out about a botched setting when pulling or
pushing.
- Updates docs.

## Type of Change
- [ ] Bug fix
- [x] New feature  
- [x] Breaking change
- [x] Documentation update

## Motivation and Context
See #384.

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [x] Added/updated docs
2025-09-16 13:37:55 -07:00
Kathryn Baldauf 386fd87b5d Enumerate using relative paths to avoid mismatch with symlink resolution of special paths like /tmp (#613)
## Type of Change
- [x] Bug fix
- [ ] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Motivation and Context
Fixes https://github.com/apple/container/issues/588. This PR changes the
archiver compression file enumeration to use the
[enumerator(atPath:)](https://developer.apple.com/documentation/foundation/filemanager/enumerator(atpath:))
version. This version returns relative paths instead of full file paths
from the filesystem. /tmp is symlinked to /private/tmp and some swift
packages will handle that path differently. While a call to Foundation's
`URL.resolvingSymlinksInPath()` will return "/tmp", a call to
`FileManager.enumerator(at:)` will return "/private/tmp". This
difference causes a container image build to fail when the user is using
a path under /tmp or other special case paths as the context directory.

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [ ] Added/updated docs

Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
2025-09-16 10:52:08 -07:00
J Logan a54be363f7 Add --labels for networks. (#600)
- Closes #557.
- Breaking change: removes `.upToNextOption` for labels on volumes as
this is not what is done for containers, and it forces the argument to
precede the options if a label is supplied, which is non-intuitive.

## Type of Change
- [ ] Bug fix
- [x] New feature  
- [x] Breaking change
- [x] Documentation update

## Motivation and Context
Consistent features and UX across managed resources.

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [x] Added/updated docs
2025-09-15 11:27:51 -07:00
J Logan 58e0ddd948 Revert inadvertent pull platform filtering from #545. (#593)
- Reverts an inadvertent "fix" from #545.
- Closes #592.

## Type of Change
- [x] Bug fix
- [ ] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Motivation and Context
See #592 

## Testing
- [x] Tested locally
- [ ] Added/updated tests
- [ ] Added/updated docs
2025-09-10 10:22:55 -07:00
J Logan 0ba2c42d95 Pass DNS integration tests when default domain is set. (#594)
- Closes #547.
- Reduce DNS test count, make tests more readable.

## Type of Change
- [x] Bug fix
- [ ] New feature  
- [ ] Breaking change
- [ ] Documentation update

## Motivation and Context
Painful to have to unset the default domain on a dev system to pass
local integration tests.

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [ ] Added/updated docs
2025-09-10 10:22:34 -07:00
J Logan 6da5ecf838 Remove images alias for image subcommand. (#597)
- Closes #596.

## Type of Change
- [ ] Bug fix
- [ ] New feature  
- [x] Breaking change
- [ ] Documentation update

## Motivation and Context
- Part of UX audit #385.
- All other resource subcommands are singular and have no plural alias.
- `container image` corresponds to `docker image`; `container images`
does not.

## Testing
- [x] Tested locally
- [x] Added/updated tests
- [x] Added/updated docs
2025-09-10 10:06:48 -07:00