Uh oh!
There was an error while loading. Please reload this page.
[container-run-create]: add support for --network none - #739
Conversation
Uh oh!
There was an error while loading. Please reload this page.
jglogan
commented
Oct 9, 2025
Hi @saehejkang! I think that the preference on the issue was to define Could you revise the PR to use |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
96a4272 to
392d5aaCompare392d5aa to
ad90b43Comparead90b43 to
ab78d7aCompare
jglogan
left a comment
There was a problem hiding this comment.
@saehejkang this looks great, sorry for the follow delay and sorry to trouble you with one tiny stylistic nit and then it should be good to go
I'll kick off the workflow on this one though, please check it just in case make fmt needs to be run with the little fix.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
jglogan
commented
Oct 21, 2025
@saehejkang Merged, thank you! |
Two changes addressing review feedback from apple/containerization#739 and apple#1512 (comment): 1. Adopt the new `Containerization.LinuxBlockIO` wrapper added in containerization PR apple#739 (pin advanced to 3d009df). The wire format in `ContainerConfiguration.Resources.blockIO` stays as the Codable `ContainerizationOCI.LinuxBlockIO`; `RuntimeService.configureContainer` converts to the wrapper at the boundary via the new `toContainerizationBlockIO` helper. 2. Replace the six separate `--blkio-*` / `--device-*` flags with a single repeatable `--blkio` flag using key=value[,key=value] syntax, per apple#1512 (comment): --blkio weight=500 --blkio device=/dev/sda,weight=700,leaf-weight=300 --blkio device=/dev/sda,read-bps=1048576,write-bps=1048576 --blkio device=/dev/sda,read-iops=1000,write-iops=1000 Device values accept either an absolute host path (resolved via stat(2)) or a literal `<major>:<minor>`. Parser rejects unknown keys, conflicting global weights, and global-only keys appearing on device-less specs. Tests cover the combined spec, major:minor literal, invalid-weight, unknown-key, and global-only-on-device-spec error paths.
Two changes addressing review feedback from apple/containerization#739 and apple#1512 (comment): 1. Adopt the new `Containerization.LinuxBlockIO` wrapper added in containerization PR apple#739 (pin advanced to 3d009df). The wire format in `ContainerConfiguration.Resources.blockIO` stays as the Codable `ContainerizationOCI.LinuxBlockIO`; `RuntimeService.configureContainer` converts to the wrapper at the boundary via the new `toContainerizationBlockIO` helper. 2. Replace the six separate `--blkio-*` / `--device-*` flags with a single repeatable `--blkio` flag using key=value[,key=value] syntax, per apple#1512 (comment): --blkio weight=500 --blkio device=/dev/sda,weight=700,leaf-weight=300 --blkio device=/dev/sda,read-bps=1048576,write-bps=1048576 --blkio device=/dev/sda,read-iops=1000,write-iops=1000 Device values accept either an absolute host path (resolved via stat(2)) or a literal `<major>:<minor>`. Parser rejects unknown keys, conflicting global weights, and global-only keys appearing on device-less specs. Tests cover the combined spec, major:minor literal, invalid-weight, unknown-key, and global-only-on-device-spec error paths.
…imeData Addresses jglogan review feedback on PR apple#1595: 1. Move `blockIO` field out of the cross-platform `ContainerConfiguration.Resources` and into the Linux-specific `LinuxRuntimeData`. The CLI now encodes `LinuxRuntimeData(blockIO: …)` into the opaque `RuntimeConfiguration.runtimeData` field, and the Linux runtime decodes it inside `configureContainer` before applying the OCI `LinuxBlockIO` to `czConfig.blockIO`. Keeps OS-specific options out of the generic container config type. 2. Move the `--blkio` flag from `Flags.Resource` to `Flags.Management` and simplify its help to a single line pointing at the command reference, in the spirit of the existing generic options pattern. The structured key=value parsing/validation in `Parser.blockIO` is unchanged. 3. `Parser.resources` no longer takes `blkio`; `Parser.blockIO` stays public and is now invoked by `ContainerRun` / `ContainerCreate` directly. Tests rewritten to exercise `Parser.blockIO` directly. `swift build` clean; `swift test --filter ParserTest` 105 tests pass, `RuntimeConfiguration` tests pass, `container run --help` shows `--blkio` under MANAGEMENT OPTIONS. Deferred (per PR body): Package.swift / Package.resolved still pin containerization to apple/containerization#739's branch because that upstream PR is still open. Those will revert to apple/containerization at merge time, once apple#739 lands.
The branch pin to full-chaos/containerization@feat/chaos-1380-blkio-runtime was a temporary measure while apple/containerization#739 was in flight. Revert to the upstream pin so this PR can be merged independently of apple#739. Note: the runtime plumbing in RuntimeService.swift still references Containerization.LinuxBlockIO and czConfig.blockIO, which only exist on the apple#739 branch. The build will be temporarily broken until apple#739 lands upstream and the pin is bumped to whatever release contains it.
Two changes addressing review feedback from apple/containerization#739 and apple#1512 (comment): 1. Adopt the new `Containerization.LinuxBlockIO` wrapper added in containerization PR apple#739 (pin advanced to 3d009df). The wire format in `ContainerConfiguration.Resources.blockIO` stays as the Codable `ContainerizationOCI.LinuxBlockIO`; `RuntimeService.configureContainer` converts to the wrapper at the boundary via the new `toContainerizationBlockIO` helper. 2. Replace the six separate `--blkio-*` / `--device-*` flags with a single repeatable `--blkio` flag using key=value[,key=value] syntax, per apple#1512 (comment): --blkio weight=500 --blkio device=/dev/sda,weight=700,leaf-weight=300 --blkio device=/dev/sda,read-bps=1048576,write-bps=1048576 --blkio device=/dev/sda,read-iops=1000,write-iops=1000 Device values accept either an absolute host path (resolved via stat(2)) or a literal `<major>:<minor>`. Parser rejects unknown keys, conflicting global weights, and global-only keys appearing on device-less specs. Tests cover the combined spec, major:minor literal, invalid-weight, unknown-key, and global-only-on-device-spec error paths.
…imeData Addresses jglogan review feedback on PR apple#1595: 1. Move `blockIO` field out of the cross-platform `ContainerConfiguration.Resources` and into the Linux-specific `LinuxRuntimeData`. The CLI now encodes `LinuxRuntimeData(blockIO: …)` into the opaque `RuntimeConfiguration.runtimeData` field, and the Linux runtime decodes it inside `configureContainer` before applying the OCI `LinuxBlockIO` to `czConfig.blockIO`. Keeps OS-specific options out of the generic container config type. 2. Move the `--blkio` flag from `Flags.Resource` to `Flags.Management` and simplify its help to a single line pointing at the command reference, in the spirit of the existing generic options pattern. The structured key=value parsing/validation in `Parser.blockIO` is unchanged. 3. `Parser.resources` no longer takes `blkio`; `Parser.blockIO` stays public and is now invoked by `ContainerRun` / `ContainerCreate` directly. Tests rewritten to exercise `Parser.blockIO` directly. `swift build` clean; `swift test --filter ParserTest` 105 tests pass, `RuntimeConfiguration` tests pass, `container run --help` shows `--blkio` under MANAGEMENT OPTIONS. Deferred (per PR body): Package.swift / Package.resolved still pin containerization to apple/containerization#739's branch because that upstream PR is still open. Those will revert to apple/containerization at merge time, once apple#739 lands.
The branch pin to full-chaos/containerization@feat/chaos-1380-blkio-runtime was a temporary measure while apple/containerization#739 was in flight. Revert to the upstream pin so this PR can be merged independently of apple#739. Note: the runtime plumbing in RuntimeService.swift still references Containerization.LinuxBlockIO and czConfig.blockIO, which only exist on the apple#739 branch. The build will be temporarily broken until apple#739 lands upstream and the pin is bumped to whatever release contains it.
Two changes addressing review feedback from apple/containerization#739 and apple#1512 (comment): 1. Adopt the new `Containerization.LinuxBlockIO` wrapper added in containerization PR apple#739 (pin advanced to 3d009df). The wire format in `ContainerConfiguration.Resources.blockIO` stays as the Codable `ContainerizationOCI.LinuxBlockIO`; `RuntimeService.configureContainer` converts to the wrapper at the boundary via the new `toContainerizationBlockIO` helper. 2. Replace the six separate `--blkio-*` / `--device-*` flags with a single repeatable `--blkio` flag using key=value[,key=value] syntax, per apple#1512 (comment): --blkio weight=500 --blkio device=/dev/sda,weight=700,leaf-weight=300 --blkio device=/dev/sda,read-bps=1048576,write-bps=1048576 --blkio device=/dev/sda,read-iops=1000,write-iops=1000 Device values accept either an absolute host path (resolved via stat(2)) or a literal `<major>:<minor>`. Parser rejects unknown keys, conflicting global weights, and global-only keys appearing on device-less specs. Tests cover the combined spec, major:minor literal, invalid-weight, unknown-key, and global-only-on-device-spec error paths.
…imeData Addresses jglogan review feedback on PR apple#1595: 1. Move `blockIO` field out of the cross-platform `ContainerConfiguration.Resources` and into the Linux-specific `LinuxRuntimeData`. The CLI now encodes `LinuxRuntimeData(blockIO: …)` into the opaque `RuntimeConfiguration.runtimeData` field, and the Linux runtime decodes it inside `configureContainer` before applying the OCI `LinuxBlockIO` to `czConfig.blockIO`. Keeps OS-specific options out of the generic container config type. 2. Move the `--blkio` flag from `Flags.Resource` to `Flags.Management` and simplify its help to a single line pointing at the command reference, in the spirit of the existing generic options pattern. The structured key=value parsing/validation in `Parser.blockIO` is unchanged. 3. `Parser.resources` no longer takes `blkio`; `Parser.blockIO` stays public and is now invoked by `ContainerRun` / `ContainerCreate` directly. Tests rewritten to exercise `Parser.blockIO` directly. `swift build` clean; `swift test --filter ParserTest` 105 tests pass, `RuntimeConfiguration` tests pass, `container run --help` shows `--blkio` under MANAGEMENT OPTIONS. Deferred (per PR body): Package.swift / Package.resolved still pin containerization to apple/containerization#739's branch because that upstream PR is still open. Those will revert to apple/containerization at merge time, once apple#739 lands.
The branch pin to full-chaos/containerization@feat/chaos-1380-blkio-runtime was a temporary measure while apple/containerization#739 was in flight. Revert to the upstream pin so this PR can be merged independently of apple#739. Note: the runtime plumbing in RuntimeService.swift still references Containerization.LinuxBlockIO and czConfig.blockIO, which only exist on the apple#739 branch. The build will be temporarily broken until apple#739 lands upstream and the pin is bumped to whatever release contains it.
Two changes addressing review feedback from apple/containerization#739 and apple#1512 (comment): 1. Adopt the new `Containerization.LinuxBlockIO` wrapper added in containerization PR apple#739 (pin advanced to 3d009df). The wire format in `ContainerConfiguration.Resources.blockIO` stays as the Codable `ContainerizationOCI.LinuxBlockIO`; `RuntimeService.configureContainer` converts to the wrapper at the boundary via the new `toContainerizationBlockIO` helper. 2. Replace the six separate `--blkio-*` / `--device-*` flags with a single repeatable `--blkio` flag using key=value[,key=value] syntax, per apple#1512 (comment): --blkio weight=500 --blkio device=/dev/sda,weight=700,leaf-weight=300 --blkio device=/dev/sda,read-bps=1048576,write-bps=1048576 --blkio device=/dev/sda,read-iops=1000,write-iops=1000 Device values accept either an absolute host path (resolved via stat(2)) or a literal `<major>:<minor>`. Parser rejects unknown keys, conflicting global weights, and global-only keys appearing on device-less specs. Tests cover the combined spec, major:minor literal, invalid-weight, unknown-key, and global-only-on-device-spec error paths.
…imeData Addresses jglogan review feedback on PR apple#1595: 1. Move `blockIO` field out of the cross-platform `ContainerConfiguration.Resources` and into the Linux-specific `LinuxRuntimeData`. The CLI now encodes `LinuxRuntimeData(blockIO: …)` into the opaque `RuntimeConfiguration.runtimeData` field, and the Linux runtime decodes it inside `configureContainer` before applying the OCI `LinuxBlockIO` to `czConfig.blockIO`. Keeps OS-specific options out of the generic container config type. 2. Move the `--blkio` flag from `Flags.Resource` to `Flags.Management` and simplify its help to a single line pointing at the command reference, in the spirit of the existing generic options pattern. The structured key=value parsing/validation in `Parser.blockIO` is unchanged. 3. `Parser.resources` no longer takes `blkio`; `Parser.blockIO` stays public and is now invoked by `ContainerRun` / `ContainerCreate` directly. Tests rewritten to exercise `Parser.blockIO` directly. `swift build` clean; `swift test --filter ParserTest` 105 tests pass, `RuntimeConfiguration` tests pass, `container run --help` shows `--blkio` under MANAGEMENT OPTIONS. Deferred (per PR body): Package.swift / Package.resolved still pin containerization to apple/containerization#739's branch because that upstream PR is still open. Those will revert to apple/containerization at merge time, once apple#739 lands.
The branch pin to full-chaos/containerization@feat/chaos-1380-blkio-runtime was a temporary measure while apple/containerization#739 was in flight. Revert to the upstream pin so this PR can be merged independently of apple#739. Note: the runtime plumbing in RuntimeService.swift still references Containerization.LinuxBlockIO and czConfig.blockIO, which only exist on the apple#739 branch. The build will be temporarily broken until apple#739 lands upstream and the pin is bumped to whatever release contains it.
Type of Change
Motivation and Context
Closes#386
Testing