Validate volume name in volume disk usage call - #2107
Merged
katiewasnothere merged 1 commit intoAug 10, 2026
Conversation
Signed-off-by: Kathryn Baldauf <k_baldauf@apple.com>
Code Coverage
|
realrajaryan
approved these changes
Aug 10, 2026
This was referenced Aug 28, 2026
henrywang
added a commit
to henrywang/Berthly
that referenced
this pull request
Aug 28, 2026
…eme (#133) Closes #129. ## What Adopts apple/container **1.3.0** (and its required containerization **0.41.0**). ### `RequestScheme.auto` removal ([apple/container#2100](apple/container#2100)) 1.3.0 deletes `RequestScheme.auto` and the internal-host detection behind it, so `schemeFor` now returns `https` for every host unless the caller already chose `http`. Without the old heuristic a plain-HTTP registry on `localhost` or a private network is unreachable unless the user ticks "Allow insecure registry". New `RegistrySchemeResolver` ports that detection **verbatim** — `localhost`, the daemon's internal DNS domain, and the RFC 1918 / loopback IPv4 ranges resolve to `http`; everything else to `https` — and drives the paths where Berthly controls a single host: `resolveRegistryConnectionTarget` (login), `pullImage`, `pushImage`, `recreateContainer`. `runRegistryFlags` / `machineRegistryFlags` can't use it: their one `Flags.Registry` scheme fans out to the init-image fetch too (`Utility.containerConfigFromFlags`), so per-host detection isn't safe there. The insecure toggle keeps its "force http" meaning and becomes the only path to `http` for `run` / `machine create` against an untoggled internal registry — documented as a deliberate gap in `PARITY.md` (`pull` then `run` for the same result without the toggle). The vminit base-image pull is hardcoded to `.https` (Apple's registry, not routed through the resolver so a user's internal DNS domain can't match it). ### containerization 0.41.0 Required by 1.3.0. [apple/containerization#783](apple/containerization#783) drops the redundant `v8` variant from arm64's `Platform.description` (matching Docker/containerd) — one test assertion updated. The `Platform` equality fix ([#833](apple/containerization#833)) doesn't affect `builderPlatform` (line 2433 mirrors 1.3.0's own `BuilderStart.swift:116` verbatim). ### Compatibility floor Stays at 1.2 — nothing in 1.3.0 adds an API Berthly newly calls, so a 1.2.x daemon still works. Only the SPM pin moved. ## Test plan - [x] `xcodebuild build` — succeeds - [x] `xcodebuild build-for-testing` (all test targets incl. UITests/E2E) — succeeds - [x] `BerthlyTests` — 532 pass, 0 failures (new `RegistrySchemeResolverTests`, `runRegistryFlagsDefaultToHTTPS`) - [x] `swiftlint lint --strict` — 0 violations - [ ] Not verified without a local daemon: disk-usage volume-name validation ([#2107](apple/container#2107) / [#2136](apple/container#2136)) on the `fetchDiskUsage` path — stricter input checks, Berthly passes real volume names, no expected impact. ## Follow-ups (separate issues) #130 tmpfs fix verification · #131 k8s PARITY.md rationale · #132 mock kernel fixtures
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Type of Change
Motivation and Context
Align the volume disk usage call with other volume API calls by validating the volume name given over XPC.
Testing