- closes#2043
- introduces the k8s plugin, allowing users to make single
node clusters with the kind base image
- other functionality is included as well such as creation,
deletion, and loading custom images
- When pulling warmup images for concurrent tests, save
the images to a cache directory under the application root.
- Serial tests that aren't testing pull can save time by restoring
a cached warmup image.
- When container is not running, the runtime helper
traverses the container's root fs and writes it to the
specified tar archive or stdout.
- When the container is running, the helper performs
the same operation but wraps it in freeze/thaw
to ensure data integrity for the resulting archive.
- Closes#2001.
- Handle "container exists" error gracefully instead
of failing, when trying to start the buildkit container.
- Move build tests to parallel suites, while the builder
lifecycle tests remain serial. Parallel builds don't
use the fixture lock that deletes and restarts the
builder and runs a build block in isolation.
Closes https://github.com/apple/container/issues/1687
The default kernel archive is downloaded from a remote release URL
during first-run setup and via `container system kernel set
--recommended`. Previously, the archive contents were not verified after
download, so integrity depended on HTTPS and the release artifact
remaining unchanged.
This change adds digest verification for kernel archives. The
recommended/default kernel now has pinned digest metadata using an
algorithm-prefixed value such as `sha256:<hex>`. `container system
kernel set --tar` accepts `--digest`; remote tar URLs require it, and
local tar archives can also be verified before unpacking and
installation.
The system config also supports `kernel.digest`, and a custom
`kernel.url` must provide a digest for that archive.
- This fixes the LLVM coverage data not properly being emitted for XPC
services. It requires piping the `LLVM_PROFILE_FILE` environment
variable through to all the services and plugins. The variable itself
also required the "%c" formatter to ensure that it continuously emits
coverage data, otherwise when XPC services are killed via "bootout" they
do not emit coverage.
- Part of #1833.
- CLI progress and registry test migrations were inadventently reverted
by #1857.
- Migrate TestCLINoParallelCases to TestCLIImagePruneSerial and
TestCLINetworkPruneSerial.
- Clean up test selection patterns in Makefile.
- Remove all legacy CLITests files.
- Use swift-testing `withKnownIssue` to run but ignore failures on flaky
`testCreateNameLongestValid` and `testIsolatedNetwork`.
- Extracts a fixture helper for tests requiring a retry loop.
This PR cleans up some of the new IntegrationTests files to ensure that
each file has a single test suite defined within it and the name of the
file matches the name of the test suite.
Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
- Part of #1833.
- Adds `ContainerFixture` with scoped resource lifecycle and cleanup in
place of implementation inheritance for test support functions. The
fixture also handles resource prefixing and uses a more ergonomic
`CommandResult` in place of a tuple for return values.
- `ImageWarmup` suite pre-pulls well-known images, and
`copyWarmupImage()` tags test-local refs, keeping the canonical image
store untouched.
- Three-phase `integration-new`: warmup, followed by concurrent tests
(managed by the swift test
`--experimental-maximum-parallelization-width` flag), followed by
serialized tests.
- `coverage-new` merges unit + integration-new profraw, replacing
`coverage` in CI as a migration progress indicator.
- Updates GH workflow so non-coverage invokes both the `integration` and
`integration-new` Makefile targets, while coverage runs invoke the
`coverage-new` target.
- Fixes#1801.
- When `container image save` runs without `--output`,
stdout carries the OCI tar archive. The command writes
the archive bytes to stdout and then `print(reference)`s
each saved image reference to stdout afterward,
appending non-archive text after the tar EOF marker,
which will cause strict tar/OCI consumers to fail.
- This routes the saved-reference list to stderr in the
no-`--output` branch, so stdout contains only archive
bytes. When saving to a file via `--output`, stdout is
free, so the references continue to print to stdout
exactly as before.
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
- PRs are backed up. We need to rework the CLI tests
to shorten test time and fix conflicts between tests.
## Testing
- [ ] Tested locally
- [x] Added/updated tests
- [ ] Added/updated docs
Fixes#1738
`container cp` fails when the host source path is relative (e.g.
`container cp file foo:/root/`), because `NSString.standardizingPath`
only canonicalizes paths but does not make them absolute. The unchanged
relative path is then interpreted as `/file` (root-absolute) by
`URL(fileURLWithPath:)` on the runtime side.
Fixed by resolving relative paths against the current working directory
before use, matching the pattern already used by `container export`,
`container image save`, and `container image load`.
The same fix was also applied to the copy-out destination path (line
68), which had the same issue.
## Type of Change
- [x] Bug fix
- [ ] New feature
- [ ] Breaking change
- [ ] Documentation update
## Motivation and Context
`container cp file foo:/root/` fails with `"copyIn: source not found
'/file'"` because the relative path `file` is never expanded to an
absolute path. Using `$PWD/file` works, but relative paths should work
too — every other command in the codebase handles this correctly.
## Testing
- [x] Tested locally — builds and all existing tests pass
- [ ] Added/updated tests
- [ ] Added/updated docs
---------
Co-authored-by: jwhur <57657645+JaewonHur@users.noreply.github.com>
- Closes#1750.
- Applies permission code used for the `--ssh` mount to all
host-to-container socket mounts.
- Adds a user option to the `doExec` test support function.
- Updates the `testRunCommandUnixSocketMount` to install `nc` in the
test container, and check the socket permission, and check the mounted
socket using `nc` as the guest user.
This also includes custom kernels for container machine. Its required
with nested virt as CONFIG_KVM needs to be enabled.
---------
Signed-off-by: michael_crosby <michael_crosby@apple.com>
## Type of Change
- [ ] Bug fix
- [x] New feature
- [ ] Breaking change
- [ ] Documentation update
## Motivation and Context
`container` runs each workload in an ephemeral VM, so there's no
built-in way to keep a persistent Linux environment you can log into and
work in. `container machine` adds one.
A container machine is a lightweight, persistent, and integrated Linux
environments that feel like an extension of your Mac, created from
standard OCI images with a familiar UX. The login user matches your host
account with passwordless `sudo`, your home directory is mounted inside
the VM, and each machine keeps its filesystem and runs the image's own
init system (such as`systemd` or `openrc`).
```bash
container machine create alpine:3.22 --name my-machine
container machine run -n my-machine # interactive shell
container machine set -n my-machine cpus=4 memory=8G
```
Subcommands: `create`, `run`, `list` (`ls`), `inspect`, `set`,
`set-default`, `logs`, `stop`, `delete` (`rm`); `m` aliases `machine`.
Docs added to `docs/command-reference.md` (Machine Management) and
`docs/how-to.md` ("Use container machines").
## Testing
- [x] Tested locally
- [x] Added/updated tests
- [x] Added/updated docs
Signed-off-by: Raj Aryan Singh <rajaryan_singh@apple.com>
Co-authored-by: Jaewon Hur <jaewon_hur@apple.com>
Co-authored-by: John Logan <john_logan@apple.com>
Co-authored-by: Michael Crosby <michael_crosby@apple.com>
Co-authored-by: Eric Ernst <eric_ernst@apple.com>
Co-authored-by: Danny Canter <danny_canter@apple.com>
https://github.com/apple/container/pull/1652 rearranged the JSON output
for image resources and included a duplicate "name" field. After further
discussion, we've decided to remove the duplicate field.
Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
- Closes#1528.
- Several commands (`builder status`, `image list`,
`stats`, `system df`, `system status`) advertised
`--format yaml` and `--format toml` but only handled
`json`, and every other format fell through to the
table. With this PR, we now route them through one
shared renderer with an exhaustive switch over the
format enum, so a missing format would now be a
compile error, and not just fail silently.
- Since TOML has no top level array, TOML output
now wraps list payloads under an `items` key,
because otherwise it was returning nothing for lists.
- `stats` now prints one static result for machine
readable formats instead of opening its live table
view.
- `builder status` now returns an empty list for
json/yaml/toml when no builder is running, instead
of the unparseable "builder is not running" text.
The table view keeps the message.
- with `--quiet` and no builder it now exits 0 with
no output, earlier it exited non-zero.
- Closes#1647.
- `id` will become a system assigned (Docker-like) identifier
for the managed resource, and `configuration.name` is the
user-assigned name.