Skip to content

Allow custom kernel boot args via --kernel-arg - #1744

Merged
crosbymichael merged 1 commit into
apple:mainfrom
arirubinstein:kernel-arg-boot-args
Jul 27, 2026
Merged

Allow custom kernel boot args via --kernel-arg#1744
crosbymichael merged 1 commit into
apple:mainfrom
arirubinstein:kernel-arg-boot-args

Conversation

@arirubinstein

@arirubinsteinarirubinstein commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update

What

Adds a repeatable --kernel-arg flag to container run/container create for appending arbitrary boot arguments to the kernel command line.

container run --kernel /path/to/custom-bzImage \
--kernel-arg lsm=lockdown,capability,landlock,yama,apparmor,bpf \
...

Why

The runtime hardcodes lsm=lockdown,capability,landlock,yama,apparmor (and oops=panic) onto every kernel command line in RuntimeService.bootstrap. With a custom kernel there is no way to adjust this — e.g. to enable BPF LSM you need lsm=...,bpf, which is currently impossible. More generally there is no escape hatch for any boot-time kernel argument.

How

  • New --kernel-arg <arg> option (repeatable) on Flags.Management.
  • Utility.getKernel appends the user args onto kernel.commandLine.kernelArgs, which is persisted into the container bundle.
  • RuntimeService.bootstrap now applies its built-in defaults per-key, skipping any default whose key the user already supplied. Defaults are expressed as a small keyed table, so this also lets oops= be overridden and makes future defaults easy to add.

Default behavior is unchanged for anyone who does not pass --kernel-arg — the same oops=panic and lsm=... args are applied.

Testing

  • swift build clean.
  • container run --help renders the new flag.

@noah-thor

Copy link
Copy Markdown
Contributor

Can you please sign the commit: https://docs.github.com/en/authentication/managing-commit-signature-verification/signing-commits

Actual code change looks good to me

Add a repeatable --kernel-arg flag to plumb arbitrary boot arguments
onto the kernel command line. User-supplied args are persisted on the
kernel in the bundle, and the runtime's built-in defaults (oops=panic,
lsm=...) are now applied per-key only when the user has not already
supplied that key. This lets custom kernels override the LSM stack,
e.g. to enable BPF LSM with:
--kernel-arg lsm=lockdown,capability,landlock,yama,apparmor,bpf
Signed-off-by: Ari Rubinstein <22369+arirubinstein@users.noreply.github.com>
@arirubinstein

Copy link
Copy Markdown
ContributorAuthor

Signed and rebased

@github-actions

Copy link
Copy Markdown

Code Coverage

TierLine Coverage
Unit23.38%
Integration66.49%
Combined75.44%

@crosbymichael
crosbymichael merged commit b229cec into apple:mainJul 27, 2026
3 checks passed
andrewkomkov added a commit to getgantry/gantry that referenced this pull request Aug 1, 2026
…ot args (#14)
apple/container **1.2.0** is out (previously tracked: `1.1.0`).
Upstream notes: https://github.com/apple/container/releases/tag/1.2.0 —
mirrored in `docs/upstream/apple-container-1.2.0.md`.
## Review checklist
- [ ] New or changed CLI flags Gantry should surface (`container
run/create/machine/build`)
- [ ] Changed `--format json` shapes the DockerKit apple transport
decodes
- [ ] Fixed upstream bugs Gantry currently works around
- [ ] `ContainerTooling.recommendedVersion` / feature gates need moving
to `1.2.0`
- [ ] MCP tools and App Intents that expose the affected commands
- [ ] README and CHANGELOG entries for whatever is adopted
Merging records the version as reviewed. Implement the adopted parts on
this branch, or merge as-is and open follow-ups.
---
<details><summary>Upstream release notes</summary>
## What's Changed
* Add TestCLISystemLogs and TestCLITermIO integration tests in new
integration test suite by @katiewasnothere in
apple/container#1879
* Restore reverted migrations, migrate last tests. by @jglogan in
apple/container#1880
* Removes obsolete CLITests directory. by @jglogan in
apple/container#1886
* Integration coverage xpc helpers by @noah-thor in
apple/container#1551
* Upgrade grpc-swift-nio-transport to 2.9.0 and remove HTTP2ConnectBuff…
by @adityabagchi24 in apple/container#1790
* Updates containerization to 0.36.0. by @jglogan in
apple/container#1912
* Use containerization version 0.37.0 by @adityaramani in
apple/container#1932
* Verify kernel archive integrity by @haoruilee in
apple/container#1703
* Add commit/issue alert to PR template. by @jglogan in
apple/container#1945
* Remove `--skip-build` from test Makefile target. by @jglogan in
apple/container#1951
* Restore `--skip-build`, enable `import testable` for release builds.
by @jglogan in apple/container#1955
* [package]: bump container-builder-shim to 0.13.0 by @saehejkang in
apple/container#1953
* Validate container ID from XPC requests by @katiewasnothere in
apple/container#1956
* Remove force unwraps on XPC error set/get by @katiewasnothere in
apple/container#1958
* Do not follow destination symlink when copying user configuration by
@katiewasnothere in apple/container#1957
* Fix machine ID length test. by @jglogan in
apple/container#1971
* Address flaky TestCLIKernelSetSerial suite. by @jglogan in
apple/container#1976
* [gitignore]: ignore vscode workspace files by @saehejkang in
apple/container#1966
* Update containerization dependency with new EXT4Unpacker func
definition by @katiewasnothere in
apple/container#1973
* Periodic dependency updates. by @jglogan in
apple/container#1981
* Use ordered journal mode for unpacked images. by @jglogan in
apple/container#1974
* Reword DNS container name resolution doc information by
@katiewasnothere in apple/container#1960
* ci: bump the github-actions group across 1 directory with 3 updates by
@dependabot[bot] in apple/container#1983
* Pass build config in when building protoc dependencies by
@katiewasnothere in apple/container#1972
* Container test fixture package by @katiewasnothere in
apple/container#1887
* Downgrade swift-collections to 1.5.1. by @jglogan in
apple/container#1984
* Use `enum` for warmup images. by @jglogan in
apple/container#1990
* Add missing dependencies to new ContainerTestSupport package by
@katiewasnothere in apple/container#1994
* Add OCI maskedPaths and readonlyPaths support to Container API. by
@jglogan in apple/container#1996
* Integration test - miscellaneous fixture and test refinements. by
@jglogan in apple/container#1993
* Use log instead of print for system start status messages by
@adityabagchi24 in apple/container#1889
* Fix BuilderStart race, parallelize `container build` tests. by
@jglogan in apple/container#2002
* Allow custom kernel boot args via --kernel-arg by @arirubinstein in
apple/container#1744
* fix: Increase XPC timeout for Machine API operations by @dev-kvt in
apple/container#2006
* Update containerization import to latest 0.40.0 by @katiewasnothere in
apple/container#2028
* Fix image env vars, build context checks, TCP/UDP port forward buffer,
and validate plugin name by @katiewasnothere in
apple/container#2027
* Update containerization import to 0.40.1 by @katiewasnothere in
apple/container#2038
## New Contributors
* @haoruilee made their first contribution in
apple/container#1703
* @arirubinstein made their first contribution in
apple/container#1744
* @dev-kvt made their first contribution in
apple/container#2006
**Full Changelog**:
apple/container@1.1.0...1.2.0
</details>
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Andrew <Andrew.Komkov@gmail.com>
henrywang added a commit to henrywang/Berthly that referenced this pull request Aug 4, 2026
## Summary
- container 1.2.0 added a repeatable `--kernel-arg` flag
(apple/container#1744) for appending raw boot arguments to the kernel
command line — e.g. adding `bpf` to the runtime's hardcoded LSM list to
enable BPF LSM, previously impossible. `Flags.Management` gained a
required `kernelArgs` parameter in the same release, confirming the API
is reachable from Berthly's native XPC calls, not just the CLI.
- `RunOptions` gained `kernelArgs: [String]`, threaded through
`LiveContainerService.runManagementFlags(for:)` into
`Flags.Management.kernelArgs`.
- New "Kernel boot arguments" `StringListEditor` on the Run/Create
sheet's Security tab, alongside the existing capAdd/capDrop editors it
mirrors.
- `PARITY.md`'s flag-surface list updated in the same commit.
- `Localizable.xcstrings` synced for the new field's string.
## Why
Part of the container 1.2.0 milestone (#78) — the SPM bump (#75)
surfaced this as a newly-required parameter, confirming the feature is
implementable at the API level Berthly actually calls.
Closes#78
## Test plan
- [x] `xcodebuild build` succeeds
- [x] `xcodebuild test -only-testing:BerthlyTests` — full suite passes,
including new coverage for `kernelArgs` in
`managementFlagsMapInteractiveVirtualizationCapsAndCidFile`
- [x] `swiftlint lint --strict` — 0 violations
- [x] Verified visually via Xcode's live preview renderer — confirmed
the new field renders on the Security tab using the working `capAdd`
pattern
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@arirubinstein@noah-thor@crosbymichael
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Allow custom kernel boot args via --kernel-arg by arirubinstein · Pull Request #1744 · apple/container · GitHub
Skip to content

Allow custom kernel boot args via --kernel-arg - #1744

Merged
crosbymichael merged 1 commit into
apple:mainfrom
arirubinstein:kernel-arg-boot-args
Jul 27, 2026
Merged

Allow custom kernel boot args via --kernel-arg#1744
crosbymichael merged 1 commit into
apple:mainfrom
arirubinstein:kernel-arg-boot-args

Conversation

@arirubinstein

@arirubinsteinarirubinstein commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update

What

Adds a repeatable --kernel-arg flag to container run/container create for appending arbitrary boot arguments to the kernel command line.

container run --kernel /path/to/custom-bzImage \
--kernel-arg lsm=lockdown,capability,landlock,yama,apparmor,bpf \
...

Why

The runtime hardcodes lsm=lockdown,capability,landlock,yama,apparmor (and oops=panic) onto every kernel command line in RuntimeService.bootstrap. With a custom kernel there is no way to adjust this — e.g. to enable BPF LSM you need lsm=...,bpf, which is currently impossible. More generally there is no escape hatch for any boot-time kernel argument.

How

  • New --kernel-arg <arg> option (repeatable) on Flags.Management.
  • Utility.getKernel appends the user args onto kernel.commandLine.kernelArgs, which is persisted into the container bundle.
  • RuntimeService.bootstrap now applies its built-in defaults per-key, skipping any default whose key the user already supplied. Defaults are expressed as a small keyed table, so this also lets oops= be overridden and makes future defaults easy to add.

Default behavior is unchanged for anyone who does not pass --kernel-arg — the same oops=panic and lsm=... args are applied.

Testing

  • swift build clean.
  • container run --help renders the new flag.

@noah-thor

Copy link
Copy Markdown
Contributor

Can you please sign the commit: https://docs.github.com/en/authentication/managing-commit-signature-verification/signing-commits

Actual code change looks good to me

Add a repeatable --kernel-arg flag to plumb arbitrary boot arguments
onto the kernel command line. User-supplied args are persisted on the
kernel in the bundle, and the runtime's built-in defaults (oops=panic,
lsm=...) are now applied per-key only when the user has not already
supplied that key. This lets custom kernels override the LSM stack,
e.g. to enable BPF LSM with:
--kernel-arg lsm=lockdown,capability,landlock,yama,apparmor,bpf
Signed-off-by: Ari Rubinstein <22369+arirubinstein@users.noreply.github.com>
@arirubinstein

Copy link
Copy Markdown
ContributorAuthor

Signed and rebased

@github-actions

Copy link
Copy Markdown

Code Coverage

TierLine Coverage
Unit23.38%
Integration66.49%
Combined75.44%

@crosbymichael
crosbymichael merged commit b229cec into apple:mainJul 27, 2026
3 checks passed
andrewkomkov added a commit to getgantry/gantry that referenced this pull request Aug 1, 2026
…ot args (#14)
apple/container **1.2.0** is out (previously tracked: `1.1.0`).
Upstream notes: https://github.com/apple/container/releases/tag/1.2.0 —
mirrored in `docs/upstream/apple-container-1.2.0.md`.
## Review checklist
- [ ] New or changed CLI flags Gantry should surface (`container
run/create/machine/build`)
- [ ] Changed `--format json` shapes the DockerKit apple transport
decodes
- [ ] Fixed upstream bugs Gantry currently works around
- [ ] `ContainerTooling.recommendedVersion` / feature gates need moving
to `1.2.0`
- [ ] MCP tools and App Intents that expose the affected commands
- [ ] README and CHANGELOG entries for whatever is adopted
Merging records the version as reviewed. Implement the adopted parts on
this branch, or merge as-is and open follow-ups.
---
<details><summary>Upstream release notes</summary>
## What's Changed
* Add TestCLISystemLogs and TestCLITermIO integration tests in new
integration test suite by @katiewasnothere in
apple/container#1879
* Restore reverted migrations, migrate last tests. by @jglogan in
apple/container#1880
* Removes obsolete CLITests directory. by @jglogan in
apple/container#1886
* Integration coverage xpc helpers by @noah-thor in
apple/container#1551
* Upgrade grpc-swift-nio-transport to 2.9.0 and remove HTTP2ConnectBuff…
by @adityabagchi24 in apple/container#1790
* Updates containerization to 0.36.0. by @jglogan in
apple/container#1912
* Use containerization version 0.37.0 by @adityaramani in
apple/container#1932
* Verify kernel archive integrity by @haoruilee in
apple/container#1703
* Add commit/issue alert to PR template. by @jglogan in
apple/container#1945
* Remove `--skip-build` from test Makefile target. by @jglogan in
apple/container#1951
* Restore `--skip-build`, enable `import testable` for release builds.
by @jglogan in apple/container#1955
* [package]: bump container-builder-shim to 0.13.0 by @saehejkang in
apple/container#1953
* Validate container ID from XPC requests by @katiewasnothere in
apple/container#1956
* Remove force unwraps on XPC error set/get by @katiewasnothere in
apple/container#1958
* Do not follow destination symlink when copying user configuration by
@katiewasnothere in apple/container#1957
* Fix machine ID length test. by @jglogan in
apple/container#1971
* Address flaky TestCLIKernelSetSerial suite. by @jglogan in
apple/container#1976
* [gitignore]: ignore vscode workspace files by @saehejkang in
apple/container#1966
* Update containerization dependency with new EXT4Unpacker func
definition by @katiewasnothere in
apple/container#1973
* Periodic dependency updates. by @jglogan in
apple/container#1981
* Use ordered journal mode for unpacked images. by @jglogan in
apple/container#1974
* Reword DNS container name resolution doc information by
@katiewasnothere in apple/container#1960
* ci: bump the github-actions group across 1 directory with 3 updates by
@dependabot[bot] in apple/container#1983
* Pass build config in when building protoc dependencies by
@katiewasnothere in apple/container#1972
* Container test fixture package by @katiewasnothere in
apple/container#1887
* Downgrade swift-collections to 1.5.1. by @jglogan in
apple/container#1984
* Use `enum` for warmup images. by @jglogan in
apple/container#1990
* Add missing dependencies to new ContainerTestSupport package by
@katiewasnothere in apple/container#1994
* Add OCI maskedPaths and readonlyPaths support to Container API. by
@jglogan in apple/container#1996
* Integration test - miscellaneous fixture and test refinements. by
@jglogan in apple/container#1993
* Use log instead of print for system start status messages by
@adityabagchi24 in apple/container#1889
* Fix BuilderStart race, parallelize `container build` tests. by
@jglogan in apple/container#2002
* Allow custom kernel boot args via --kernel-arg by @arirubinstein in
apple/container#1744
* fix: Increase XPC timeout for Machine API operations by @dev-kvt in
apple/container#2006
* Update containerization import to latest 0.40.0 by @katiewasnothere in
apple/container#2028
* Fix image env vars, build context checks, TCP/UDP port forward buffer,
and validate plugin name by @katiewasnothere in
apple/container#2027
* Update containerization import to 0.40.1 by @katiewasnothere in
apple/container#2038
## New Contributors
* @haoruilee made their first contribution in
apple/container#1703
* @arirubinstein made their first contribution in
apple/container#1744
* @dev-kvt made their first contribution in
apple/container#2006
**Full Changelog**:
apple/container@1.1.0...1.2.0
</details>
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Andrew <Andrew.Komkov@gmail.com>
henrywang added a commit to henrywang/Berthly that referenced this pull request Aug 4, 2026
## Summary
- container 1.2.0 added a repeatable `--kernel-arg` flag
(apple/container#1744) for appending raw boot arguments to the kernel
command line — e.g. adding `bpf` to the runtime's hardcoded LSM list to
enable BPF LSM, previously impossible. `Flags.Management` gained a
required `kernelArgs` parameter in the same release, confirming the API
is reachable from Berthly's native XPC calls, not just the CLI.
- `RunOptions` gained `kernelArgs: [String]`, threaded through
`LiveContainerService.runManagementFlags(for:)` into
`Flags.Management.kernelArgs`.
- New "Kernel boot arguments" `StringListEditor` on the Run/Create
sheet's Security tab, alongside the existing capAdd/capDrop editors it
mirrors.
- `PARITY.md`'s flag-surface list updated in the same commit.
- `Localizable.xcstrings` synced for the new field's string.
## Why
Part of the container 1.2.0 milestone (#78) — the SPM bump (#75)
surfaced this as a newly-required parameter, confirming the feature is
implementable at the API level Berthly actually calls.
Closes#78
## Test plan
- [x] `xcodebuild build` succeeds
- [x] `xcodebuild test -only-testing:BerthlyTests` — full suite passes,
including new coverage for `kernelArgs` in
`managementFlagsMapInteractiveVirtualizationCapsAndCidFile`
- [x] `swiftlint lint --strict` — 0 violations
- [x] Verified visually via Xcode's live preview renderer — confirmed
the new field renders on the Security tab using the working `capAdd`
pattern
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@arirubinstein@noah-thor@crosbymichael
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Allow custom kernel boot args via --kernel-arg by arirubinstein · Pull Request #1744 · apple/container · GitHub
Skip to content

Allow custom kernel boot args via --kernel-arg - #1744

Merged
crosbymichael merged 1 commit into
apple:mainfrom
arirubinstein:kernel-arg-boot-args
Jul 27, 2026
Merged

Allow custom kernel boot args via --kernel-arg#1744
crosbymichael merged 1 commit into
apple:mainfrom
arirubinstein:kernel-arg-boot-args

Conversation

@arirubinstein

@arirubinsteinarirubinstein commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update

What

Adds a repeatable --kernel-arg flag to container run/container create for appending arbitrary boot arguments to the kernel command line.

container run --kernel /path/to/custom-bzImage \
--kernel-arg lsm=lockdown,capability,landlock,yama,apparmor,bpf \
...

Why

The runtime hardcodes lsm=lockdown,capability,landlock,yama,apparmor (and oops=panic) onto every kernel command line in RuntimeService.bootstrap. With a custom kernel there is no way to adjust this — e.g. to enable BPF LSM you need lsm=...,bpf, which is currently impossible. More generally there is no escape hatch for any boot-time kernel argument.

How

  • New --kernel-arg <arg> option (repeatable) on Flags.Management.
  • Utility.getKernel appends the user args onto kernel.commandLine.kernelArgs, which is persisted into the container bundle.
  • RuntimeService.bootstrap now applies its built-in defaults per-key, skipping any default whose key the user already supplied. Defaults are expressed as a small keyed table, so this also lets oops= be overridden and makes future defaults easy to add.

Default behavior is unchanged for anyone who does not pass --kernel-arg — the same oops=panic and lsm=... args are applied.

Testing

  • swift build clean.
  • container run --help renders the new flag.

@noah-thor

Copy link
Copy Markdown
Contributor

Can you please sign the commit: https://docs.github.com/en/authentication/managing-commit-signature-verification/signing-commits

Actual code change looks good to me

Add a repeatable --kernel-arg flag to plumb arbitrary boot arguments
onto the kernel command line. User-supplied args are persisted on the
kernel in the bundle, and the runtime's built-in defaults (oops=panic,
lsm=...) are now applied per-key only when the user has not already
supplied that key. This lets custom kernels override the LSM stack,
e.g. to enable BPF LSM with:
--kernel-arg lsm=lockdown,capability,landlock,yama,apparmor,bpf
Signed-off-by: Ari Rubinstein <22369+arirubinstein@users.noreply.github.com>
@arirubinstein

Copy link
Copy Markdown
ContributorAuthor

Signed and rebased

@github-actions

Copy link
Copy Markdown

Code Coverage

TierLine Coverage
Unit23.38%
Integration66.49%
Combined75.44%

@crosbymichael
crosbymichael merged commit b229cec into apple:mainJul 27, 2026
3 checks passed
andrewkomkov added a commit to getgantry/gantry that referenced this pull request Aug 1, 2026
…ot args (#14)
apple/container **1.2.0** is out (previously tracked: `1.1.0`).
Upstream notes: https://github.com/apple/container/releases/tag/1.2.0 —
mirrored in `docs/upstream/apple-container-1.2.0.md`.
## Review checklist
- [ ] New or changed CLI flags Gantry should surface (`container
run/create/machine/build`)
- [ ] Changed `--format json` shapes the DockerKit apple transport
decodes
- [ ] Fixed upstream bugs Gantry currently works around
- [ ] `ContainerTooling.recommendedVersion` / feature gates need moving
to `1.2.0`
- [ ] MCP tools and App Intents that expose the affected commands
- [ ] README and CHANGELOG entries for whatever is adopted
Merging records the version as reviewed. Implement the adopted parts on
this branch, or merge as-is and open follow-ups.
---
<details><summary>Upstream release notes</summary>
## What's Changed
* Add TestCLISystemLogs and TestCLITermIO integration tests in new
integration test suite by @katiewasnothere in
apple/container#1879
* Restore reverted migrations, migrate last tests. by @jglogan in
apple/container#1880
* Removes obsolete CLITests directory. by @jglogan in
apple/container#1886
* Integration coverage xpc helpers by @noah-thor in
apple/container#1551
* Upgrade grpc-swift-nio-transport to 2.9.0 and remove HTTP2ConnectBuff…
by @adityabagchi24 in apple/container#1790
* Updates containerization to 0.36.0. by @jglogan in
apple/container#1912
* Use containerization version 0.37.0 by @adityaramani in
apple/container#1932
* Verify kernel archive integrity by @haoruilee in
apple/container#1703
* Add commit/issue alert to PR template. by @jglogan in
apple/container#1945
* Remove `--skip-build` from test Makefile target. by @jglogan in
apple/container#1951
* Restore `--skip-build`, enable `import testable` for release builds.
by @jglogan in apple/container#1955
* [package]: bump container-builder-shim to 0.13.0 by @saehejkang in
apple/container#1953
* Validate container ID from XPC requests by @katiewasnothere in
apple/container#1956
* Remove force unwraps on XPC error set/get by @katiewasnothere in
apple/container#1958
* Do not follow destination symlink when copying user configuration by
@katiewasnothere in apple/container#1957
* Fix machine ID length test. by @jglogan in
apple/container#1971
* Address flaky TestCLIKernelSetSerial suite. by @jglogan in
apple/container#1976
* [gitignore]: ignore vscode workspace files by @saehejkang in
apple/container#1966
* Update containerization dependency with new EXT4Unpacker func
definition by @katiewasnothere in
apple/container#1973
* Periodic dependency updates. by @jglogan in
apple/container#1981
* Use ordered journal mode for unpacked images. by @jglogan in
apple/container#1974
* Reword DNS container name resolution doc information by
@katiewasnothere in apple/container#1960
* ci: bump the github-actions group across 1 directory with 3 updates by
@dependabot[bot] in apple/container#1983
* Pass build config in when building protoc dependencies by
@katiewasnothere in apple/container#1972
* Container test fixture package by @katiewasnothere in
apple/container#1887
* Downgrade swift-collections to 1.5.1. by @jglogan in
apple/container#1984
* Use `enum` for warmup images. by @jglogan in
apple/container#1990
* Add missing dependencies to new ContainerTestSupport package by
@katiewasnothere in apple/container#1994
* Add OCI maskedPaths and readonlyPaths support to Container API. by
@jglogan in apple/container#1996
* Integration test - miscellaneous fixture and test refinements. by
@jglogan in apple/container#1993
* Use log instead of print for system start status messages by
@adityabagchi24 in apple/container#1889
* Fix BuilderStart race, parallelize `container build` tests. by
@jglogan in apple/container#2002
* Allow custom kernel boot args via --kernel-arg by @arirubinstein in
apple/container#1744
* fix: Increase XPC timeout for Machine API operations by @dev-kvt in
apple/container#2006
* Update containerization import to latest 0.40.0 by @katiewasnothere in
apple/container#2028
* Fix image env vars, build context checks, TCP/UDP port forward buffer,
and validate plugin name by @katiewasnothere in
apple/container#2027
* Update containerization import to 0.40.1 by @katiewasnothere in
apple/container#2038
## New Contributors
* @haoruilee made their first contribution in
apple/container#1703
* @arirubinstein made their first contribution in
apple/container#1744
* @dev-kvt made their first contribution in
apple/container#2006
**Full Changelog**:
apple/container@1.1.0...1.2.0
</details>
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Andrew <Andrew.Komkov@gmail.com>
henrywang added a commit to henrywang/Berthly that referenced this pull request Aug 4, 2026
## Summary
- container 1.2.0 added a repeatable `--kernel-arg` flag
(apple/container#1744) for appending raw boot arguments to the kernel
command line — e.g. adding `bpf` to the runtime's hardcoded LSM list to
enable BPF LSM, previously impossible. `Flags.Management` gained a
required `kernelArgs` parameter in the same release, confirming the API
is reachable from Berthly's native XPC calls, not just the CLI.
- `RunOptions` gained `kernelArgs: [String]`, threaded through
`LiveContainerService.runManagementFlags(for:)` into
`Flags.Management.kernelArgs`.
- New "Kernel boot arguments" `StringListEditor` on the Run/Create
sheet's Security tab, alongside the existing capAdd/capDrop editors it
mirrors.
- `PARITY.md`'s flag-surface list updated in the same commit.
- `Localizable.xcstrings` synced for the new field's string.
## Why
Part of the container 1.2.0 milestone (#78) — the SPM bump (#75)
surfaced this as a newly-required parameter, confirming the feature is
implementable at the API level Berthly actually calls.
Closes#78
## Test plan
- [x] `xcodebuild build` succeeds
- [x] `xcodebuild test -only-testing:BerthlyTests` — full suite passes,
including new coverage for `kernelArgs` in
`managementFlagsMapInteractiveVirtualizationCapsAndCidFile`
- [x] `swiftlint lint --strict` — 0 violations
- [x] Verified visually via Xcode's live preview renderer — confirmed
the new field renders on the Security tab using the working `capAdd`
pattern
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@arirubinstein@noah-thor@crosbymichael
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Allow custom kernel boot args via --kernel-arg by arirubinstein · Pull Request #1744 · apple/container · GitHub
Skip to content

Allow custom kernel boot args via --kernel-arg - #1744

Merged
crosbymichael merged 1 commit into
apple:mainfrom
arirubinstein:kernel-arg-boot-args
Jul 27, 2026
Merged

Allow custom kernel boot args via --kernel-arg#1744
crosbymichael merged 1 commit into
apple:mainfrom
arirubinstein:kernel-arg-boot-args

Conversation

@arirubinstein

@arirubinsteinarirubinstein commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update

What

Adds a repeatable --kernel-arg flag to container run/container create for appending arbitrary boot arguments to the kernel command line.

container run --kernel /path/to/custom-bzImage \
--kernel-arg lsm=lockdown,capability,landlock,yama,apparmor,bpf \
...

Why

The runtime hardcodes lsm=lockdown,capability,landlock,yama,apparmor (and oops=panic) onto every kernel command line in RuntimeService.bootstrap. With a custom kernel there is no way to adjust this — e.g. to enable BPF LSM you need lsm=...,bpf, which is currently impossible. More generally there is no escape hatch for any boot-time kernel argument.

How

  • New --kernel-arg <arg> option (repeatable) on Flags.Management.
  • Utility.getKernel appends the user args onto kernel.commandLine.kernelArgs, which is persisted into the container bundle.
  • RuntimeService.bootstrap now applies its built-in defaults per-key, skipping any default whose key the user already supplied. Defaults are expressed as a small keyed table, so this also lets oops= be overridden and makes future defaults easy to add.

Default behavior is unchanged for anyone who does not pass --kernel-arg — the same oops=panic and lsm=... args are applied.

Testing

  • swift build clean.
  • container run --help renders the new flag.

@noah-thor

Copy link
Copy Markdown
Contributor

Can you please sign the commit: https://docs.github.com/en/authentication/managing-commit-signature-verification/signing-commits

Actual code change looks good to me

Add a repeatable --kernel-arg flag to plumb arbitrary boot arguments
onto the kernel command line. User-supplied args are persisted on the
kernel in the bundle, and the runtime's built-in defaults (oops=panic,
lsm=...) are now applied per-key only when the user has not already
supplied that key. This lets custom kernels override the LSM stack,
e.g. to enable BPF LSM with:
--kernel-arg lsm=lockdown,capability,landlock,yama,apparmor,bpf
Signed-off-by: Ari Rubinstein <22369+arirubinstein@users.noreply.github.com>
@arirubinstein

Copy link
Copy Markdown
ContributorAuthor

Signed and rebased

@github-actions

Copy link
Copy Markdown

Code Coverage

TierLine Coverage
Unit23.38%
Integration66.49%
Combined75.44%

@crosbymichael
crosbymichael merged commit b229cec into apple:mainJul 27, 2026
3 checks passed
andrewkomkov added a commit to getgantry/gantry that referenced this pull request Aug 1, 2026
…ot args (#14)
apple/container **1.2.0** is out (previously tracked: `1.1.0`).
Upstream notes: https://github.com/apple/container/releases/tag/1.2.0 —
mirrored in `docs/upstream/apple-container-1.2.0.md`.
## Review checklist
- [ ] New or changed CLI flags Gantry should surface (`container
run/create/machine/build`)
- [ ] Changed `--format json` shapes the DockerKit apple transport
decodes
- [ ] Fixed upstream bugs Gantry currently works around
- [ ] `ContainerTooling.recommendedVersion` / feature gates need moving
to `1.2.0`
- [ ] MCP tools and App Intents that expose the affected commands
- [ ] README and CHANGELOG entries for whatever is adopted
Merging records the version as reviewed. Implement the adopted parts on
this branch, or merge as-is and open follow-ups.
---
<details><summary>Upstream release notes</summary>
## What's Changed
* Add TestCLISystemLogs and TestCLITermIO integration tests in new
integration test suite by @katiewasnothere in
apple/container#1879
* Restore reverted migrations, migrate last tests. by @jglogan in
apple/container#1880
* Removes obsolete CLITests directory. by @jglogan in
apple/container#1886
* Integration coverage xpc helpers by @noah-thor in
apple/container#1551
* Upgrade grpc-swift-nio-transport to 2.9.0 and remove HTTP2ConnectBuff…
by @adityabagchi24 in apple/container#1790
* Updates containerization to 0.36.0. by @jglogan in
apple/container#1912
* Use containerization version 0.37.0 by @adityaramani in
apple/container#1932
* Verify kernel archive integrity by @haoruilee in
apple/container#1703
* Add commit/issue alert to PR template. by @jglogan in
apple/container#1945
* Remove `--skip-build` from test Makefile target. by @jglogan in
apple/container#1951
* Restore `--skip-build`, enable `import testable` for release builds.
by @jglogan in apple/container#1955
* [package]: bump container-builder-shim to 0.13.0 by @saehejkang in
apple/container#1953
* Validate container ID from XPC requests by @katiewasnothere in
apple/container#1956
* Remove force unwraps on XPC error set/get by @katiewasnothere in
apple/container#1958
* Do not follow destination symlink when copying user configuration by
@katiewasnothere in apple/container#1957
* Fix machine ID length test. by @jglogan in
apple/container#1971
* Address flaky TestCLIKernelSetSerial suite. by @jglogan in
apple/container#1976
* [gitignore]: ignore vscode workspace files by @saehejkang in
apple/container#1966
* Update containerization dependency with new EXT4Unpacker func
definition by @katiewasnothere in
apple/container#1973
* Periodic dependency updates. by @jglogan in
apple/container#1981
* Use ordered journal mode for unpacked images. by @jglogan in
apple/container#1974
* Reword DNS container name resolution doc information by
@katiewasnothere in apple/container#1960
* ci: bump the github-actions group across 1 directory with 3 updates by
@dependabot[bot] in apple/container#1983
* Pass build config in when building protoc dependencies by
@katiewasnothere in apple/container#1972
* Container test fixture package by @katiewasnothere in
apple/container#1887
* Downgrade swift-collections to 1.5.1. by @jglogan in
apple/container#1984
* Use `enum` for warmup images. by @jglogan in
apple/container#1990
* Add missing dependencies to new ContainerTestSupport package by
@katiewasnothere in apple/container#1994
* Add OCI maskedPaths and readonlyPaths support to Container API. by
@jglogan in apple/container#1996
* Integration test - miscellaneous fixture and test refinements. by
@jglogan in apple/container#1993
* Use log instead of print for system start status messages by
@adityabagchi24 in apple/container#1889
* Fix BuilderStart race, parallelize `container build` tests. by
@jglogan in apple/container#2002
* Allow custom kernel boot args via --kernel-arg by @arirubinstein in
apple/container#1744
* fix: Increase XPC timeout for Machine API operations by @dev-kvt in
apple/container#2006
* Update containerization import to latest 0.40.0 by @katiewasnothere in
apple/container#2028
* Fix image env vars, build context checks, TCP/UDP port forward buffer,
and validate plugin name by @katiewasnothere in
apple/container#2027
* Update containerization import to 0.40.1 by @katiewasnothere in
apple/container#2038
## New Contributors
* @haoruilee made their first contribution in
apple/container#1703
* @arirubinstein made their first contribution in
apple/container#1744
* @dev-kvt made their first contribution in
apple/container#2006
**Full Changelog**:
apple/container@1.1.0...1.2.0
</details>
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Andrew <Andrew.Komkov@gmail.com>
henrywang added a commit to henrywang/Berthly that referenced this pull request Aug 4, 2026
## Summary
- container 1.2.0 added a repeatable `--kernel-arg` flag
(apple/container#1744) for appending raw boot arguments to the kernel
command line — e.g. adding `bpf` to the runtime's hardcoded LSM list to
enable BPF LSM, previously impossible. `Flags.Management` gained a
required `kernelArgs` parameter in the same release, confirming the API
is reachable from Berthly's native XPC calls, not just the CLI.
- `RunOptions` gained `kernelArgs: [String]`, threaded through
`LiveContainerService.runManagementFlags(for:)` into
`Flags.Management.kernelArgs`.
- New "Kernel boot arguments" `StringListEditor` on the Run/Create
sheet's Security tab, alongside the existing capAdd/capDrop editors it
mirrors.
- `PARITY.md`'s flag-surface list updated in the same commit.
- `Localizable.xcstrings` synced for the new field's string.
## Why
Part of the container 1.2.0 milestone (#78) — the SPM bump (#75)
surfaced this as a newly-required parameter, confirming the feature is
implementable at the API level Berthly actually calls.
Closes#78
## Test plan
- [x] `xcodebuild build` succeeds
- [x] `xcodebuild test -only-testing:BerthlyTests` — full suite passes,
including new coverage for `kernelArgs` in
`managementFlagsMapInteractiveVirtualizationCapsAndCidFile`
- [x] `swiftlint lint --strict` — 0 violations
- [x] Verified visually via Xcode's live preview renderer — confirmed
the new field renders on the Security tab using the working `capAdd`
pattern
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@arirubinstein@noah-thor@crosbymichael
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Allow custom kernel boot args via --kernel-arg by arirubinstein · Pull Request #1744 · apple/container · GitHub
Skip to content

Allow custom kernel boot args via --kernel-arg - #1744

Merged
crosbymichael merged 1 commit into
apple:mainfrom
arirubinstein:kernel-arg-boot-args
Jul 27, 2026
Merged

Allow custom kernel boot args via --kernel-arg#1744
crosbymichael merged 1 commit into
apple:mainfrom
arirubinstein:kernel-arg-boot-args

Conversation

@arirubinstein

@arirubinsteinarirubinstein commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update

What

Adds a repeatable --kernel-arg flag to container run/container create for appending arbitrary boot arguments to the kernel command line.

container run --kernel /path/to/custom-bzImage \
--kernel-arg lsm=lockdown,capability,landlock,yama,apparmor,bpf \
...

Why

The runtime hardcodes lsm=lockdown,capability,landlock,yama,apparmor (and oops=panic) onto every kernel command line in RuntimeService.bootstrap. With a custom kernel there is no way to adjust this — e.g. to enable BPF LSM you need lsm=...,bpf, which is currently impossible. More generally there is no escape hatch for any boot-time kernel argument.

How

  • New --kernel-arg <arg> option (repeatable) on Flags.Management.
  • Utility.getKernel appends the user args onto kernel.commandLine.kernelArgs, which is persisted into the container bundle.
  • RuntimeService.bootstrap now applies its built-in defaults per-key, skipping any default whose key the user already supplied. Defaults are expressed as a small keyed table, so this also lets oops= be overridden and makes future defaults easy to add.

Default behavior is unchanged for anyone who does not pass --kernel-arg — the same oops=panic and lsm=... args are applied.

Testing

  • swift build clean.
  • container run --help renders the new flag.

@noah-thor

Copy link
Copy Markdown
Contributor

Can you please sign the commit: https://docs.github.com/en/authentication/managing-commit-signature-verification/signing-commits

Actual code change looks good to me

Add a repeatable --kernel-arg flag to plumb arbitrary boot arguments
onto the kernel command line. User-supplied args are persisted on the
kernel in the bundle, and the runtime's built-in defaults (oops=panic,
lsm=...) are now applied per-key only when the user has not already
supplied that key. This lets custom kernels override the LSM stack,
e.g. to enable BPF LSM with:
--kernel-arg lsm=lockdown,capability,landlock,yama,apparmor,bpf
Signed-off-by: Ari Rubinstein <22369+arirubinstein@users.noreply.github.com>
@arirubinstein

Copy link
Copy Markdown
ContributorAuthor

Signed and rebased

@github-actions

Copy link
Copy Markdown

Code Coverage

TierLine Coverage
Unit23.38%
Integration66.49%
Combined75.44%

@crosbymichael
crosbymichael merged commit b229cec into apple:mainJul 27, 2026
3 checks passed
andrewkomkov added a commit to getgantry/gantry that referenced this pull request Aug 1, 2026
…ot args (#14)
apple/container **1.2.0** is out (previously tracked: `1.1.0`).
Upstream notes: https://github.com/apple/container/releases/tag/1.2.0 —
mirrored in `docs/upstream/apple-container-1.2.0.md`.
## Review checklist
- [ ] New or changed CLI flags Gantry should surface (`container
run/create/machine/build`)
- [ ] Changed `--format json` shapes the DockerKit apple transport
decodes
- [ ] Fixed upstream bugs Gantry currently works around
- [ ] `ContainerTooling.recommendedVersion` / feature gates need moving
to `1.2.0`
- [ ] MCP tools and App Intents that expose the affected commands
- [ ] README and CHANGELOG entries for whatever is adopted
Merging records the version as reviewed. Implement the adopted parts on
this branch, or merge as-is and open follow-ups.
---
<details><summary>Upstream release notes</summary>
## What's Changed
* Add TestCLISystemLogs and TestCLITermIO integration tests in new
integration test suite by @katiewasnothere in
apple/container#1879
* Restore reverted migrations, migrate last tests. by @jglogan in
apple/container#1880
* Removes obsolete CLITests directory. by @jglogan in
apple/container#1886
* Integration coverage xpc helpers by @noah-thor in
apple/container#1551
* Upgrade grpc-swift-nio-transport to 2.9.0 and remove HTTP2ConnectBuff…
by @adityabagchi24 in apple/container#1790
* Updates containerization to 0.36.0. by @jglogan in
apple/container#1912
* Use containerization version 0.37.0 by @adityaramani in
apple/container#1932
* Verify kernel archive integrity by @haoruilee in
apple/container#1703
* Add commit/issue alert to PR template. by @jglogan in
apple/container#1945
* Remove `--skip-build` from test Makefile target. by @jglogan in
apple/container#1951
* Restore `--skip-build`, enable `import testable` for release builds.
by @jglogan in apple/container#1955
* [package]: bump container-builder-shim to 0.13.0 by @saehejkang in
apple/container#1953
* Validate container ID from XPC requests by @katiewasnothere in
apple/container#1956
* Remove force unwraps on XPC error set/get by @katiewasnothere in
apple/container#1958
* Do not follow destination symlink when copying user configuration by
@katiewasnothere in apple/container#1957
* Fix machine ID length test. by @jglogan in
apple/container#1971
* Address flaky TestCLIKernelSetSerial suite. by @jglogan in
apple/container#1976
* [gitignore]: ignore vscode workspace files by @saehejkang in
apple/container#1966
* Update containerization dependency with new EXT4Unpacker func
definition by @katiewasnothere in
apple/container#1973
* Periodic dependency updates. by @jglogan in
apple/container#1981
* Use ordered journal mode for unpacked images. by @jglogan in
apple/container#1974
* Reword DNS container name resolution doc information by
@katiewasnothere in apple/container#1960
* ci: bump the github-actions group across 1 directory with 3 updates by
@dependabot[bot] in apple/container#1983
* Pass build config in when building protoc dependencies by
@katiewasnothere in apple/container#1972
* Container test fixture package by @katiewasnothere in
apple/container#1887
* Downgrade swift-collections to 1.5.1. by @jglogan in
apple/container#1984
* Use `enum` for warmup images. by @jglogan in
apple/container#1990
* Add missing dependencies to new ContainerTestSupport package by
@katiewasnothere in apple/container#1994
* Add OCI maskedPaths and readonlyPaths support to Container API. by
@jglogan in apple/container#1996
* Integration test - miscellaneous fixture and test refinements. by
@jglogan in apple/container#1993
* Use log instead of print for system start status messages by
@adityabagchi24 in apple/container#1889
* Fix BuilderStart race, parallelize `container build` tests. by
@jglogan in apple/container#2002
* Allow custom kernel boot args via --kernel-arg by @arirubinstein in
apple/container#1744
* fix: Increase XPC timeout for Machine API operations by @dev-kvt in
apple/container#2006
* Update containerization import to latest 0.40.0 by @katiewasnothere in
apple/container#2028
* Fix image env vars, build context checks, TCP/UDP port forward buffer,
and validate plugin name by @katiewasnothere in
apple/container#2027
* Update containerization import to 0.40.1 by @katiewasnothere in
apple/container#2038
## New Contributors
* @haoruilee made their first contribution in
apple/container#1703
* @arirubinstein made their first contribution in
apple/container#1744
* @dev-kvt made their first contribution in
apple/container#2006
**Full Changelog**:
apple/container@1.1.0...1.2.0
</details>
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Andrew <Andrew.Komkov@gmail.com>
henrywang added a commit to henrywang/Berthly that referenced this pull request Aug 4, 2026
## Summary
- container 1.2.0 added a repeatable `--kernel-arg` flag
(apple/container#1744) for appending raw boot arguments to the kernel
command line — e.g. adding `bpf` to the runtime's hardcoded LSM list to
enable BPF LSM, previously impossible. `Flags.Management` gained a
required `kernelArgs` parameter in the same release, confirming the API
is reachable from Berthly's native XPC calls, not just the CLI.
- `RunOptions` gained `kernelArgs: [String]`, threaded through
`LiveContainerService.runManagementFlags(for:)` into
`Flags.Management.kernelArgs`.
- New "Kernel boot arguments" `StringListEditor` on the Run/Create
sheet's Security tab, alongside the existing capAdd/capDrop editors it
mirrors.
- `PARITY.md`'s flag-surface list updated in the same commit.
- `Localizable.xcstrings` synced for the new field's string.
## Why
Part of the container 1.2.0 milestone (#78) — the SPM bump (#75)
surfaced this as a newly-required parameter, confirming the feature is
implementable at the API level Berthly actually calls.
Closes#78
## Test plan
- [x] `xcodebuild build` succeeds
- [x] `xcodebuild test -only-testing:BerthlyTests` — full suite passes,
including new coverage for `kernelArgs` in
`managementFlagsMapInteractiveVirtualizationCapsAndCidFile`
- [x] `swiftlint lint --strict` — 0 violations
- [x] Verified visually via Xcode's live preview renderer — confirmed
the new field renders on the Security tab using the working `capAdd`
pattern
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@arirubinstein@noah-thor@crosbymichael
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Allow custom kernel boot args via --kernel-arg by arirubinstein · Pull Request #1744 · apple/container · GitHub
Skip to content

Allow custom kernel boot args via --kernel-arg - #1744

Merged
crosbymichael merged 1 commit into
apple:mainfrom
arirubinstein:kernel-arg-boot-args
Jul 27, 2026
Merged

Allow custom kernel boot args via --kernel-arg#1744
crosbymichael merged 1 commit into
apple:mainfrom
arirubinstein:kernel-arg-boot-args

Conversation

@arirubinstein

@arirubinsteinarirubinstein commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update

What

Adds a repeatable --kernel-arg flag to container run/container create for appending arbitrary boot arguments to the kernel command line.

container run --kernel /path/to/custom-bzImage \
--kernel-arg lsm=lockdown,capability,landlock,yama,apparmor,bpf \
...

Why

The runtime hardcodes lsm=lockdown,capability,landlock,yama,apparmor (and oops=panic) onto every kernel command line in RuntimeService.bootstrap. With a custom kernel there is no way to adjust this — e.g. to enable BPF LSM you need lsm=...,bpf, which is currently impossible. More generally there is no escape hatch for any boot-time kernel argument.

How

  • New --kernel-arg <arg> option (repeatable) on Flags.Management.
  • Utility.getKernel appends the user args onto kernel.commandLine.kernelArgs, which is persisted into the container bundle.
  • RuntimeService.bootstrap now applies its built-in defaults per-key, skipping any default whose key the user already supplied. Defaults are expressed as a small keyed table, so this also lets oops= be overridden and makes future defaults easy to add.

Default behavior is unchanged for anyone who does not pass --kernel-arg — the same oops=panic and lsm=... args are applied.

Testing

  • swift build clean.
  • container run --help renders the new flag.

@noah-thor

Copy link
Copy Markdown
Contributor

Can you please sign the commit: https://docs.github.com/en/authentication/managing-commit-signature-verification/signing-commits

Actual code change looks good to me

Add a repeatable --kernel-arg flag to plumb arbitrary boot arguments
onto the kernel command line. User-supplied args are persisted on the
kernel in the bundle, and the runtime's built-in defaults (oops=panic,
lsm=...) are now applied per-key only when the user has not already
supplied that key. This lets custom kernels override the LSM stack,
e.g. to enable BPF LSM with:
--kernel-arg lsm=lockdown,capability,landlock,yama,apparmor,bpf
Signed-off-by: Ari Rubinstein <22369+arirubinstein@users.noreply.github.com>
@arirubinstein

Copy link
Copy Markdown
ContributorAuthor

Signed and rebased

@github-actions

Copy link
Copy Markdown

Code Coverage

TierLine Coverage
Unit23.38%
Integration66.49%
Combined75.44%

@crosbymichael
crosbymichael merged commit b229cec into apple:mainJul 27, 2026
3 checks passed
andrewkomkov added a commit to getgantry/gantry that referenced this pull request Aug 1, 2026
…ot args (#14)
apple/container **1.2.0** is out (previously tracked: `1.1.0`).
Upstream notes: https://github.com/apple/container/releases/tag/1.2.0 —
mirrored in `docs/upstream/apple-container-1.2.0.md`.
## Review checklist
- [ ] New or changed CLI flags Gantry should surface (`container
run/create/machine/build`)
- [ ] Changed `--format json` shapes the DockerKit apple transport
decodes
- [ ] Fixed upstream bugs Gantry currently works around
- [ ] `ContainerTooling.recommendedVersion` / feature gates need moving
to `1.2.0`
- [ ] MCP tools and App Intents that expose the affected commands
- [ ] README and CHANGELOG entries for whatever is adopted
Merging records the version as reviewed. Implement the adopted parts on
this branch, or merge as-is and open follow-ups.
---
<details><summary>Upstream release notes</summary>
## What's Changed
* Add TestCLISystemLogs and TestCLITermIO integration tests in new
integration test suite by @katiewasnothere in
apple/container#1879
* Restore reverted migrations, migrate last tests. by @jglogan in
apple/container#1880
* Removes obsolete CLITests directory. by @jglogan in
apple/container#1886
* Integration coverage xpc helpers by @noah-thor in
apple/container#1551
* Upgrade grpc-swift-nio-transport to 2.9.0 and remove HTTP2ConnectBuff…
by @adityabagchi24 in apple/container#1790
* Updates containerization to 0.36.0. by @jglogan in
apple/container#1912
* Use containerization version 0.37.0 by @adityaramani in
apple/container#1932
* Verify kernel archive integrity by @haoruilee in
apple/container#1703
* Add commit/issue alert to PR template. by @jglogan in
apple/container#1945
* Remove `--skip-build` from test Makefile target. by @jglogan in
apple/container#1951
* Restore `--skip-build`, enable `import testable` for release builds.
by @jglogan in apple/container#1955
* [package]: bump container-builder-shim to 0.13.0 by @saehejkang in
apple/container#1953
* Validate container ID from XPC requests by @katiewasnothere in
apple/container#1956
* Remove force unwraps on XPC error set/get by @katiewasnothere in
apple/container#1958
* Do not follow destination symlink when copying user configuration by
@katiewasnothere in apple/container#1957
* Fix machine ID length test. by @jglogan in
apple/container#1971
* Address flaky TestCLIKernelSetSerial suite. by @jglogan in
apple/container#1976
* [gitignore]: ignore vscode workspace files by @saehejkang in
apple/container#1966
* Update containerization dependency with new EXT4Unpacker func
definition by @katiewasnothere in
apple/container#1973
* Periodic dependency updates. by @jglogan in
apple/container#1981
* Use ordered journal mode for unpacked images. by @jglogan in
apple/container#1974
* Reword DNS container name resolution doc information by
@katiewasnothere in apple/container#1960
* ci: bump the github-actions group across 1 directory with 3 updates by
@dependabot[bot] in apple/container#1983
* Pass build config in when building protoc dependencies by
@katiewasnothere in apple/container#1972
* Container test fixture package by @katiewasnothere in
apple/container#1887
* Downgrade swift-collections to 1.5.1. by @jglogan in
apple/container#1984
* Use `enum` for warmup images. by @jglogan in
apple/container#1990
* Add missing dependencies to new ContainerTestSupport package by
@katiewasnothere in apple/container#1994
* Add OCI maskedPaths and readonlyPaths support to Container API. by
@jglogan in apple/container#1996
* Integration test - miscellaneous fixture and test refinements. by
@jglogan in apple/container#1993
* Use log instead of print for system start status messages by
@adityabagchi24 in apple/container#1889
* Fix BuilderStart race, parallelize `container build` tests. by
@jglogan in apple/container#2002
* Allow custom kernel boot args via --kernel-arg by @arirubinstein in
apple/container#1744
* fix: Increase XPC timeout for Machine API operations by @dev-kvt in
apple/container#2006
* Update containerization import to latest 0.40.0 by @katiewasnothere in
apple/container#2028
* Fix image env vars, build context checks, TCP/UDP port forward buffer,
and validate plugin name by @katiewasnothere in
apple/container#2027
* Update containerization import to 0.40.1 by @katiewasnothere in
apple/container#2038
## New Contributors
* @haoruilee made their first contribution in
apple/container#1703
* @arirubinstein made their first contribution in
apple/container#1744
* @dev-kvt made their first contribution in
apple/container#2006
**Full Changelog**:
apple/container@1.1.0...1.2.0
</details>
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Andrew <Andrew.Komkov@gmail.com>
henrywang added a commit to henrywang/Berthly that referenced this pull request Aug 4, 2026
## Summary
- container 1.2.0 added a repeatable `--kernel-arg` flag
(apple/container#1744) for appending raw boot arguments to the kernel
command line — e.g. adding `bpf` to the runtime's hardcoded LSM list to
enable BPF LSM, previously impossible. `Flags.Management` gained a
required `kernelArgs` parameter in the same release, confirming the API
is reachable from Berthly's native XPC calls, not just the CLI.
- `RunOptions` gained `kernelArgs: [String]`, threaded through
`LiveContainerService.runManagementFlags(for:)` into
`Flags.Management.kernelArgs`.
- New "Kernel boot arguments" `StringListEditor` on the Run/Create
sheet's Security tab, alongside the existing capAdd/capDrop editors it
mirrors.
- `PARITY.md`'s flag-surface list updated in the same commit.
- `Localizable.xcstrings` synced for the new field's string.
## Why
Part of the container 1.2.0 milestone (#78) — the SPM bump (#75)
surfaced this as a newly-required parameter, confirming the feature is
implementable at the API level Berthly actually calls.
Closes#78
## Test plan
- [x] `xcodebuild build` succeeds
- [x] `xcodebuild test -only-testing:BerthlyTests` — full suite passes,
including new coverage for `kernelArgs` in
`managementFlagsMapInteractiveVirtualizationCapsAndCidFile`
- [x] `swiftlint lint --strict` — 0 violations
- [x] Verified visually via Xcode's live preview renderer — confirmed
the new field renders on the Security tab using the working `capAdd`
pattern
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@arirubinstein@noah-thor@crosbymichael
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Allow custom kernel boot args via --kernel-arg by arirubinstein · Pull Request #1744 · apple/container · GitHub
Skip to content

Allow custom kernel boot args via --kernel-arg - #1744

Merged
crosbymichael merged 1 commit into
apple:mainfrom
arirubinstein:kernel-arg-boot-args
Jul 27, 2026
Merged

Allow custom kernel boot args via --kernel-arg#1744
crosbymichael merged 1 commit into
apple:mainfrom
arirubinstein:kernel-arg-boot-args

Conversation

@arirubinstein

@arirubinsteinarirubinstein commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update

What

Adds a repeatable --kernel-arg flag to container run/container create for appending arbitrary boot arguments to the kernel command line.

container run --kernel /path/to/custom-bzImage \
--kernel-arg lsm=lockdown,capability,landlock,yama,apparmor,bpf \
...

Why

The runtime hardcodes lsm=lockdown,capability,landlock,yama,apparmor (and oops=panic) onto every kernel command line in RuntimeService.bootstrap. With a custom kernel there is no way to adjust this — e.g. to enable BPF LSM you need lsm=...,bpf, which is currently impossible. More generally there is no escape hatch for any boot-time kernel argument.

How

  • New --kernel-arg <arg> option (repeatable) on Flags.Management.
  • Utility.getKernel appends the user args onto kernel.commandLine.kernelArgs, which is persisted into the container bundle.
  • RuntimeService.bootstrap now applies its built-in defaults per-key, skipping any default whose key the user already supplied. Defaults are expressed as a small keyed table, so this also lets oops= be overridden and makes future defaults easy to add.

Default behavior is unchanged for anyone who does not pass --kernel-arg — the same oops=panic and lsm=... args are applied.

Testing

  • swift build clean.
  • container run --help renders the new flag.

@noah-thor

Copy link
Copy Markdown
Contributor

Can you please sign the commit: https://docs.github.com/en/authentication/managing-commit-signature-verification/signing-commits

Actual code change looks good to me

Add a repeatable --kernel-arg flag to plumb arbitrary boot arguments
onto the kernel command line. User-supplied args are persisted on the
kernel in the bundle, and the runtime's built-in defaults (oops=panic,
lsm=...) are now applied per-key only when the user has not already
supplied that key. This lets custom kernels override the LSM stack,
e.g. to enable BPF LSM with:
--kernel-arg lsm=lockdown,capability,landlock,yama,apparmor,bpf
Signed-off-by: Ari Rubinstein <22369+arirubinstein@users.noreply.github.com>
@arirubinstein

Copy link
Copy Markdown
ContributorAuthor

Signed and rebased

@github-actions

Copy link
Copy Markdown

Code Coverage

TierLine Coverage
Unit23.38%
Integration66.49%
Combined75.44%

@crosbymichael
crosbymichael merged commit b229cec into apple:mainJul 27, 2026
3 checks passed
andrewkomkov added a commit to getgantry/gantry that referenced this pull request Aug 1, 2026
…ot args (#14)
apple/container **1.2.0** is out (previously tracked: `1.1.0`).
Upstream notes: https://github.com/apple/container/releases/tag/1.2.0 —
mirrored in `docs/upstream/apple-container-1.2.0.md`.
## Review checklist
- [ ] New or changed CLI flags Gantry should surface (`container
run/create/machine/build`)
- [ ] Changed `--format json` shapes the DockerKit apple transport
decodes
- [ ] Fixed upstream bugs Gantry currently works around
- [ ] `ContainerTooling.recommendedVersion` / feature gates need moving
to `1.2.0`
- [ ] MCP tools and App Intents that expose the affected commands
- [ ] README and CHANGELOG entries for whatever is adopted
Merging records the version as reviewed. Implement the adopted parts on
this branch, or merge as-is and open follow-ups.
---
<details><summary>Upstream release notes</summary>
## What's Changed
* Add TestCLISystemLogs and TestCLITermIO integration tests in new
integration test suite by @katiewasnothere in
apple/container#1879
* Restore reverted migrations, migrate last tests. by @jglogan in
apple/container#1880
* Removes obsolete CLITests directory. by @jglogan in
apple/container#1886
* Integration coverage xpc helpers by @noah-thor in
apple/container#1551
* Upgrade grpc-swift-nio-transport to 2.9.0 and remove HTTP2ConnectBuff…
by @adityabagchi24 in apple/container#1790
* Updates containerization to 0.36.0. by @jglogan in
apple/container#1912
* Use containerization version 0.37.0 by @adityaramani in
apple/container#1932
* Verify kernel archive integrity by @haoruilee in
apple/container#1703
* Add commit/issue alert to PR template. by @jglogan in
apple/container#1945
* Remove `--skip-build` from test Makefile target. by @jglogan in
apple/container#1951
* Restore `--skip-build`, enable `import testable` for release builds.
by @jglogan in apple/container#1955
* [package]: bump container-builder-shim to 0.13.0 by @saehejkang in
apple/container#1953
* Validate container ID from XPC requests by @katiewasnothere in
apple/container#1956
* Remove force unwraps on XPC error set/get by @katiewasnothere in
apple/container#1958
* Do not follow destination symlink when copying user configuration by
@katiewasnothere in apple/container#1957
* Fix machine ID length test. by @jglogan in
apple/container#1971
* Address flaky TestCLIKernelSetSerial suite. by @jglogan in
apple/container#1976
* [gitignore]: ignore vscode workspace files by @saehejkang in
apple/container#1966
* Update containerization dependency with new EXT4Unpacker func
definition by @katiewasnothere in
apple/container#1973
* Periodic dependency updates. by @jglogan in
apple/container#1981
* Use ordered journal mode for unpacked images. by @jglogan in
apple/container#1974
* Reword DNS container name resolution doc information by
@katiewasnothere in apple/container#1960
* ci: bump the github-actions group across 1 directory with 3 updates by
@dependabot[bot] in apple/container#1983
* Pass build config in when building protoc dependencies by
@katiewasnothere in apple/container#1972
* Container test fixture package by @katiewasnothere in
apple/container#1887
* Downgrade swift-collections to 1.5.1. by @jglogan in
apple/container#1984
* Use `enum` for warmup images. by @jglogan in
apple/container#1990
* Add missing dependencies to new ContainerTestSupport package by
@katiewasnothere in apple/container#1994
* Add OCI maskedPaths and readonlyPaths support to Container API. by
@jglogan in apple/container#1996
* Integration test - miscellaneous fixture and test refinements. by
@jglogan in apple/container#1993
* Use log instead of print for system start status messages by
@adityabagchi24 in apple/container#1889
* Fix BuilderStart race, parallelize `container build` tests. by
@jglogan in apple/container#2002
* Allow custom kernel boot args via --kernel-arg by @arirubinstein in
apple/container#1744
* fix: Increase XPC timeout for Machine API operations by @dev-kvt in
apple/container#2006
* Update containerization import to latest 0.40.0 by @katiewasnothere in
apple/container#2028
* Fix image env vars, build context checks, TCP/UDP port forward buffer,
and validate plugin name by @katiewasnothere in
apple/container#2027
* Update containerization import to 0.40.1 by @katiewasnothere in
apple/container#2038
## New Contributors
* @haoruilee made their first contribution in
apple/container#1703
* @arirubinstein made their first contribution in
apple/container#1744
* @dev-kvt made their first contribution in
apple/container#2006
**Full Changelog**:
apple/container@1.1.0...1.2.0
</details>
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Andrew <Andrew.Komkov@gmail.com>
henrywang added a commit to henrywang/Berthly that referenced this pull request Aug 4, 2026
## Summary
- container 1.2.0 added a repeatable `--kernel-arg` flag
(apple/container#1744) for appending raw boot arguments to the kernel
command line — e.g. adding `bpf` to the runtime's hardcoded LSM list to
enable BPF LSM, previously impossible. `Flags.Management` gained a
required `kernelArgs` parameter in the same release, confirming the API
is reachable from Berthly's native XPC calls, not just the CLI.
- `RunOptions` gained `kernelArgs: [String]`, threaded through
`LiveContainerService.runManagementFlags(for:)` into
`Flags.Management.kernelArgs`.
- New "Kernel boot arguments" `StringListEditor` on the Run/Create
sheet's Security tab, alongside the existing capAdd/capDrop editors it
mirrors.
- `PARITY.md`'s flag-surface list updated in the same commit.
- `Localizable.xcstrings` synced for the new field's string.
## Why
Part of the container 1.2.0 milestone (#78) — the SPM bump (#75)
surfaced this as a newly-required parameter, confirming the feature is
implementable at the API level Berthly actually calls.
Closes#78
## Test plan
- [x] `xcodebuild build` succeeds
- [x] `xcodebuild test -only-testing:BerthlyTests` — full suite passes,
including new coverage for `kernelArgs` in
`managementFlagsMapInteractiveVirtualizationCapsAndCidFile`
- [x] `swiftlint lint --strict` — 0 violations
- [x] Verified visually via Xcode's live preview renderer — confirmed
the new field renders on the Security tab using the working `capAdd`
pattern
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@arirubinstein@noah-thor@crosbymichael
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); Allow custom kernel boot args via --kernel-arg by arirubinstein · Pull Request #1744 · apple/container · GitHub
Skip to content

Allow custom kernel boot args via --kernel-arg - #1744

Merged
crosbymichael merged 1 commit into
apple:mainfrom
arirubinstein:kernel-arg-boot-args
Jul 27, 2026
Merged

Allow custom kernel boot args via --kernel-arg#1744
crosbymichael merged 1 commit into
apple:mainfrom
arirubinstein:kernel-arg-boot-args

Conversation

@arirubinstein

@arirubinsteinarirubinstein commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Documentation update

What

Adds a repeatable --kernel-arg flag to container run/container create for appending arbitrary boot arguments to the kernel command line.

container run --kernel /path/to/custom-bzImage \
--kernel-arg lsm=lockdown,capability,landlock,yama,apparmor,bpf \
...

Why

The runtime hardcodes lsm=lockdown,capability,landlock,yama,apparmor (and oops=panic) onto every kernel command line in RuntimeService.bootstrap. With a custom kernel there is no way to adjust this — e.g. to enable BPF LSM you need lsm=...,bpf, which is currently impossible. More generally there is no escape hatch for any boot-time kernel argument.

How

  • New --kernel-arg <arg> option (repeatable) on Flags.Management.
  • Utility.getKernel appends the user args onto kernel.commandLine.kernelArgs, which is persisted into the container bundle.
  • RuntimeService.bootstrap now applies its built-in defaults per-key, skipping any default whose key the user already supplied. Defaults are expressed as a small keyed table, so this also lets oops= be overridden and makes future defaults easy to add.

Default behavior is unchanged for anyone who does not pass --kernel-arg — the same oops=panic and lsm=... args are applied.

Testing

  • swift build clean.
  • container run --help renders the new flag.

@noah-thor

Copy link
Copy Markdown
Contributor

Can you please sign the commit: https://docs.github.com/en/authentication/managing-commit-signature-verification/signing-commits

Actual code change looks good to me

Add a repeatable --kernel-arg flag to plumb arbitrary boot arguments
onto the kernel command line. User-supplied args are persisted on the
kernel in the bundle, and the runtime's built-in defaults (oops=panic,
lsm=...) are now applied per-key only when the user has not already
supplied that key. This lets custom kernels override the LSM stack,
e.g. to enable BPF LSM with:
--kernel-arg lsm=lockdown,capability,landlock,yama,apparmor,bpf
Signed-off-by: Ari Rubinstein <22369+arirubinstein@users.noreply.github.com>
@arirubinstein

Copy link
Copy Markdown
ContributorAuthor

Signed and rebased

@github-actions

Copy link
Copy Markdown

Code Coverage

TierLine Coverage
Unit23.38%
Integration66.49%
Combined75.44%

@crosbymichael
crosbymichael merged commit b229cec into apple:mainJul 27, 2026
3 checks passed
andrewkomkov added a commit to getgantry/gantry that referenced this pull request Aug 1, 2026
…ot args (#14)
apple/container **1.2.0** is out (previously tracked: `1.1.0`).
Upstream notes: https://github.com/apple/container/releases/tag/1.2.0 —
mirrored in `docs/upstream/apple-container-1.2.0.md`.
## Review checklist
- [ ] New or changed CLI flags Gantry should surface (`container
run/create/machine/build`)
- [ ] Changed `--format json` shapes the DockerKit apple transport
decodes
- [ ] Fixed upstream bugs Gantry currently works around
- [ ] `ContainerTooling.recommendedVersion` / feature gates need moving
to `1.2.0`
- [ ] MCP tools and App Intents that expose the affected commands
- [ ] README and CHANGELOG entries for whatever is adopted
Merging records the version as reviewed. Implement the adopted parts on
this branch, or merge as-is and open follow-ups.
---
<details><summary>Upstream release notes</summary>
## What's Changed
* Add TestCLISystemLogs and TestCLITermIO integration tests in new
integration test suite by @katiewasnothere in
apple/container#1879
* Restore reverted migrations, migrate last tests. by @jglogan in
apple/container#1880
* Removes obsolete CLITests directory. by @jglogan in
apple/container#1886
* Integration coverage xpc helpers by @noah-thor in
apple/container#1551
* Upgrade grpc-swift-nio-transport to 2.9.0 and remove HTTP2ConnectBuff…
by @adityabagchi24 in apple/container#1790
* Updates containerization to 0.36.0. by @jglogan in
apple/container#1912
* Use containerization version 0.37.0 by @adityaramani in
apple/container#1932
* Verify kernel archive integrity by @haoruilee in
apple/container#1703
* Add commit/issue alert to PR template. by @jglogan in
apple/container#1945
* Remove `--skip-build` from test Makefile target. by @jglogan in
apple/container#1951
* Restore `--skip-build`, enable `import testable` for release builds.
by @jglogan in apple/container#1955
* [package]: bump container-builder-shim to 0.13.0 by @saehejkang in
apple/container#1953
* Validate container ID from XPC requests by @katiewasnothere in
apple/container#1956
* Remove force unwraps on XPC error set/get by @katiewasnothere in
apple/container#1958
* Do not follow destination symlink when copying user configuration by
@katiewasnothere in apple/container#1957
* Fix machine ID length test. by @jglogan in
apple/container#1971
* Address flaky TestCLIKernelSetSerial suite. by @jglogan in
apple/container#1976
* [gitignore]: ignore vscode workspace files by @saehejkang in
apple/container#1966
* Update containerization dependency with new EXT4Unpacker func
definition by @katiewasnothere in
apple/container#1973
* Periodic dependency updates. by @jglogan in
apple/container#1981
* Use ordered journal mode for unpacked images. by @jglogan in
apple/container#1974
* Reword DNS container name resolution doc information by
@katiewasnothere in apple/container#1960
* ci: bump the github-actions group across 1 directory with 3 updates by
@dependabot[bot] in apple/container#1983
* Pass build config in when building protoc dependencies by
@katiewasnothere in apple/container#1972
* Container test fixture package by @katiewasnothere in
apple/container#1887
* Downgrade swift-collections to 1.5.1. by @jglogan in
apple/container#1984
* Use `enum` for warmup images. by @jglogan in
apple/container#1990
* Add missing dependencies to new ContainerTestSupport package by
@katiewasnothere in apple/container#1994
* Add OCI maskedPaths and readonlyPaths support to Container API. by
@jglogan in apple/container#1996
* Integration test - miscellaneous fixture and test refinements. by
@jglogan in apple/container#1993
* Use log instead of print for system start status messages by
@adityabagchi24 in apple/container#1889
* Fix BuilderStart race, parallelize `container build` tests. by
@jglogan in apple/container#2002
* Allow custom kernel boot args via --kernel-arg by @arirubinstein in
apple/container#1744
* fix: Increase XPC timeout for Machine API operations by @dev-kvt in
apple/container#2006
* Update containerization import to latest 0.40.0 by @katiewasnothere in
apple/container#2028
* Fix image env vars, build context checks, TCP/UDP port forward buffer,
and validate plugin name by @katiewasnothere in
apple/container#2027
* Update containerization import to 0.40.1 by @katiewasnothere in
apple/container#2038
## New Contributors
* @haoruilee made their first contribution in
apple/container#1703
* @arirubinstein made their first contribution in
apple/container#1744
* @dev-kvt made their first contribution in
apple/container#2006
**Full Changelog**:
apple/container@1.1.0...1.2.0
</details>
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Andrew <Andrew.Komkov@gmail.com>
henrywang added a commit to henrywang/Berthly that referenced this pull request Aug 4, 2026
## Summary
- container 1.2.0 added a repeatable `--kernel-arg` flag
(apple/container#1744) for appending raw boot arguments to the kernel
command line — e.g. adding `bpf` to the runtime's hardcoded LSM list to
enable BPF LSM, previously impossible. `Flags.Management` gained a
required `kernelArgs` parameter in the same release, confirming the API
is reachable from Berthly's native XPC calls, not just the CLI.
- `RunOptions` gained `kernelArgs: [String]`, threaded through
`LiveContainerService.runManagementFlags(for:)` into
`Flags.Management.kernelArgs`.
- New "Kernel boot arguments" `StringListEditor` on the Run/Create
sheet's Security tab, alongside the existing capAdd/capDrop editors it
mirrors.
- `PARITY.md`'s flag-surface list updated in the same commit.
- `Localizable.xcstrings` synced for the new field's string.
## Why
Part of the container 1.2.0 milestone (#78) — the SPM bump (#75)
surfaced this as a newly-required parameter, confirming the feature is
implementable at the API level Berthly actually calls.
Closes#78
## Test plan
- [x] `xcodebuild build` succeeds
- [x] `xcodebuild test -only-testing:BerthlyTests` — full suite passes,
including new coverage for `kernelArgs` in
`managementFlagsMapInteractiveVirtualizationCapsAndCidFile`
- [x] `swiftlint lint --strict` — 0 violations
- [x] Verified visually via Xcode's live preview renderer — confirmed
the new field renders on the Security tab using the working `capAdd`
pattern
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@arirubinstein@noah-thor@crosbymichael