Skip to content

fix: adopt apple/container 1.3.0, replace removed "auto" registry scheme - #133

Merged
henrywang merged 1 commit into
mainfrom
fix/container-1.3.0-scheme-auto
Aug 28, 2026
Merged

fix: adopt apple/container 1.3.0, replace removed "auto" registry scheme#133
henrywang merged 1 commit into
mainfrom
fix/container-1.3.0-scheme-auto

Conversation

@henrywang

Copy link
Copy Markdown
Owner

Closes #129.

What

Adopts apple/container 1.3.0 (and its required containerization 0.41.0).

RequestScheme.auto removal (apple/container#2100)

1.3.0 deletes RequestScheme.auto and the internal-host detection behind it, so
schemeFor now returns https for every host unless the caller already chose
http. Without the old heuristic a plain-HTTP registry on localhost or a
private network is unreachable unless the user ticks "Allow insecure registry".

New RegistrySchemeResolver ports that detection verbatimlocalhost, the
daemon's internal DNS domain, and the RFC 1918 / loopback IPv4 ranges resolve to
http; everything else to https — and drives the paths where Berthly controls
a single host: resolveRegistryConnectionTarget (login), pullImage,
pushImage, recreateContainer.

runRegistryFlags / machineRegistryFlags can't use it: their one
Flags.Registry scheme fans out to the init-image fetch too
(Utility.containerConfigFromFlags), so per-host detection isn't safe there. The
insecure toggle keeps its "force http" meaning and becomes the only path to
http for run / machine create against an untoggled internal registry —
documented as a deliberate gap in PARITY.md (pull then run for the same
result without the toggle).

The vminit base-image pull is hardcoded to .https (Apple's registry, not routed
through the resolver so a user's internal DNS domain can't match it).

containerization 0.41.0

Required by 1.3.0. apple/containerization#783
drops the redundant v8 variant from arm64's Platform.description (matching
Docker/containerd) — one test assertion updated. The Platform equality fix
(#833) doesn't affect
builderPlatform (line 2433 mirrors 1.3.0's own BuilderStart.swift:116
verbatim).

Compatibility floor

Stays at 1.2 — nothing in 1.3.0 adds an API Berthly newly calls, so a 1.2.x
daemon still works. Only the SPM pin moved.

Test plan

  • xcodebuild build — succeeds
  • xcodebuild build-for-testing (all test targets incl. UITests/E2E) — succeeds
  • BerthlyTests — 532 pass, 0 failures (new RegistrySchemeResolverTests,
    runRegistryFlagsDefaultToHTTPS)
  • swiftlint lint --strict — 0 violations
  • Not verified without a local daemon: disk-usage volume-name validation
    (#2107 /
    #2136) on the fetchDiskUsage
    path — stricter input checks, Berthly passes real volume names, no expected impact.

Follow-ups (separate issues)

#130 tmpfs fix verification · #131 k8s PARITY.md rationale · #132 mock kernel fixtures

apple/container#2100 deletes RequestScheme.auto and the internal-host
detection behind it, so every non-toggled registry connection would
default to https and a plain-HTTP registry on localhost or a private
network becomes unreachable.

RegistrySchemeResolver ports that detection verbatim (localhost, the
daemon's internal DNS domain, and the RFC 1918 / loopback IPv4 ranges
resolve to http) and drives the single-host pull, push, recreate and
registry-login paths. run/machine create can't use it: their one
Flags.Registry scheme fans out to the init-image fetch too, so per-host
detection isn't safe there and the insecure toggle becomes the only path
to http for those two.

Also bumps containerization to 0.41.0 (required by 1.3.0), which drops
the redundant v8 variant from arm64's Platform.description
(apple/containerization#783) - the one test assertion updated to match.

Compatibility floor stays at 1.2: nothing in 1.3.0 adds an API Berthly
newly calls.
@henrywang henrywang added this to the v1.3.0 milestone Aug 28, 2026
@henrywang
henrywang merged commit 4caf45e into main Aug 28, 2026
5 checks passed
@henrywang
henrywang deleted the fix/container-1.3.0-scheme-auto branch August 28, 2026 15:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

container 1.3.0: fix RequestScheme.auto removal, bump SPM pin to 1.3.0

1 participant