I have done the following
Steps to reproduce
Inside the sandbox:
$ container list --all -> works
$ container image list -> works
$ container network list -> works (default 192.168.64.0/24)
$ container run --rm docker.io/library/alpine:latest echo hi -> works end to end
$ container system status
apiserver is not running and not registered with launchd
But the apiserver is plainly running:
$ launchctl print gui/501/com.apple.container.apiserver
state = running
program = /opt/homebrew/Cellar/container/1.2.2/libexec/container-apiserver
pid = 47577
Problem description
container system status (Apple container CLI, Homebrew build 1.2.2) reports the apiserver
as not running whenever the CLI is executed inside a macOS Seatbelt sandbox, even though the
apiserver is running and every other CLI command works. Root cause is the CLI's use of the
legacy launchctl list route, which launchd authorizes with the Seatbelt job-creation
capability - a write/job-submission capability that a read-only status probe should not need.
Environment
- macOS on Apple silicon
- container CLI version 1.2.2 (Homebrew, /opt/homebrew/Cellar/container/1.2.2)
- Caller runs under sandbox-exec with a `(deny default)` profile that allows:
mach-lookup com.apple.container.apiserver,
com.apple.container.core.container-core-images,
com.apple.container.core.machine-apiserver,
com.apple.container.network.container-network-vmnet.default
(service names taken from the launchd plists under
~/Library/Application Support/com.apple.container/**/*.plist)
Code of Conduct
I have done the following
Steps to reproduce
Inside the sandbox:
$ container list --all -> works
$ container image list -> works
$ container network list -> works (default 192.168.64.0/24)
$ container run --rm docker.io/library/alpine:latest echo hi -> works end to end
$ container system status
apiserver is not running and not registered with launchd
But the apiserver is plainly running:
$ launchctl print gui/501/com.apple.container.apiserver
state = running
program = /opt/homebrew/Cellar/container/1.2.2/libexec/container-apiserver
pid = 47577
Problem description
container system status(ApplecontainerCLI, Homebrew build 1.2.2) reports the apiserveras not running whenever the CLI is executed inside a macOS Seatbelt sandbox, even though the
apiserver is running and every other CLI command works. Root cause is the CLI's use of the
legacy
launchctl listroute, which launchd authorizes with the Seatbeltjob-creationcapability - a write/job-submission capability that a read-only status probe should not need.
Environment
Code of Conduct