Vendor apple/containerization with a VM-extensions forwarding patch

Switch the containerization dependency from the github URL to a vendored copy
(third_party/containerization, upstream commit 6b7b42ca) referenced by path, so
we can carry a small local patch that upstream lacks: LinuxContainer.Configuration
gains a `vmExtensions` field forwarded into VMConfiguration.extensions. Upstream
already supports VMConfiguration.extensions + the VZInstanceExtension hook, but
LinuxContainer — our only entry point — never forwarded them, so there was no way
to attach a device (e.g. a memory balloon) to a container's VM.

Tests/, docs/, examples/, images/ and the corresponding test targets are trimmed
for footprint (we never build the dependency's tests). See PATCHES.md for the full
diff vs. upstream and the re-vendoring procedure. Also adds the ContainerizationExtras
product to NucleicCore (AddressAllocator, named in the configureVZ signature).

Co-Authored-By: Claude Opus 4.8 <[email protected]>
This commit is contained in:
Nucleic
2026-06-21 20:22:21 -07:00
co-authored by Claude Opus 4.8
commit 11b9825e09
280 changed files with 75699 additions and 0 deletions
+58
View File
@@ -0,0 +1,58 @@
#!/bin/bash
# Copyright © 2025-2026 Apple Inc. and the Containerization project authors.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# https://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
# Script to scan the VM boot logs from the integration tests for kernel panics.
# Looks for common kernel panic messages like "attempted to kill init" or "Kernel panic".
GIT_ROOT=$(git rev-parse --show-toplevel 2>/dev/null)
if [ -z "$GIT_ROOT" ]; then
echo "Error: Not in a git repository"
exit 1
fi
BOOT_LOGS_DIR="$GIT_ROOT/bin/integration-bootlogs"
if [ ! -d "$BOOT_LOGS_DIR" ]; then
echo "Error: Boot logs directory not found: $BOOT_LOGS_DIR"
exit 1
fi
echo "Scanning boot logs in: $BOOT_LOGS_DIR"
echo "========================================"
echo ""
PANIC_FOUND=0
for logfile in "$BOOT_LOGS_DIR"/*; do
if [ -f "$logfile" ]; then
if grep -qi "attempted to kill init\|Kernel panic\|end Kernel panic\|Attempted to kill the idle task\|Oops:" "$logfile"; then
echo "🚨 PANIC DETECTED in: $(basename "$logfile")"
echo "---"
grep -i -B 5 -A 10 "attempted to kill init\|Kernel panic\|end Kernel panic\|Attempted to kill the idle task\|Oops:" "$logfile" | head -30
echo ""
echo "========================================"
echo ""
PANIC_FOUND=1
fi
fi
done
if [ $PANIC_FOUND -eq 0 ]; then
echo "✅ No kernel panics detected in boot logs"
else
echo "❌ Found kernel panics - Virtual machine(s) crashed during integration tests"
fi
exit $PANIC_FOUND
+11
View File
@@ -0,0 +1,11 @@
[SWIFT_STYLE]
firstLine = '//===----------------------------------------------------------------------===//'
endLine = "//===----------------------------------------------------------------------===//\n"
beforeEachLine = '// '
afterEachLine = ''
allowBlankLines = false
multipleLines = true
padLines = false
firstLineDetectionPattern = '//\s?==='
lastLineDetectionPattern = '//\s?==='
skipLinePattern = '// swift-tools-version'
+24
View File
@@ -0,0 +1,24 @@
#!/usr/bin/env bash
# Copyright © 2025-2026 Apple Inc. and the Containerization project authors.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# https://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
echo "Checking existence of hawkeye..."
if command -v .local/bin/hawkeye >/dev/null 2>&1; then
echo "hawkeye found!"
else
echo "hawkeye not found in PATH"
echo "please install hawkeye. For convenience, you can run scripts/install-hawkeye.sh"
exit 1
fi
+22
View File
@@ -0,0 +1,22 @@
#!/usr/bin/env bash
# Copyright © 2025-2026 Apple Inc. and the Containerization project authors.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# https://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
if command -v .local/bin/hawkeye >/dev/null 2>&1; then
echo "hawkeye already installed"
else
echo "Installing hawkeye"
export VERSION=v6.5.1
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/korandoru/hawkeye/releases/download/${VERSION}/hawkeye-installer.sh | CARGO_HOME=.local sh -s -- --no-modify-path
fi
+13
View File
@@ -0,0 +1,13 @@
Copyright ©{{ " " }}{%- set created = attrs.git_file_created_year or attrs.disk_file_created_year -%}{%- set modified = attrs.git_file_modified_year or created -%}{%- if created != modified -%} {{created}}-{{modified}}{%- else -%}{{created}}{%- endif -%}{{ " " }}{{ props["copyrightOwner"] }}.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
https://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
+52
View File
@@ -0,0 +1,52 @@
#! /bin/bash -e
# Copyright © 2025-2026 Apple Inc. and the Containerization project authors.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# https://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
opts=()
opts+=("--allow-writing-to-directory" "$1")
opts+=("generate-documentation")
opts+=("--target" "Containerization")
opts+=("--target" "ContainerizationArchive")
opts+=("--target" "ContainerizationError")
opts+=("--target" "ContainerizationEXT4")
opts+=("--target" "ContainerizationExtras")
opts+=("--target" "ContainerizationIO")
opts+=("--target" "ContainerizationNetlink")
opts+=("--target" "ContainerizationOCI")
opts+=("--target" "ContainerizationOS")
opts+=("--output-path" "$1")
opts+=("--disable-indexing")
opts+=("--transform-for-static-hosting")
opts+=("--enable-experimental-combined-documentation")
opts+=("--experimental-documentation-coverage")
if [ ! -z "$2" ] ; then
opts+=("--hosting-base-path" "$2")
fi
/usr/bin/swift package ${opts[@]}
echo '{}' > "$1/theme-settings.json"
cat > "$1/index.html" <<'EOF'
<html lang="en-US">
<head>
<meta charset="utf-8">
<meta http-equiv="refresh" content="0; url=./documentation/">
</head>
<body>
<p>If you are not redirected automatically, <a href="./documentation/">click here</a>.</p>
</body>
</html>
EOF
+16
View File
@@ -0,0 +1,16 @@
#! /bin/bash -e
setup_error() {
echo failed to run: $1 1>&2
echo run '"make pre-commit"' and try again 1>&2
exit 1
}
if [ ! -z "${PRECOMMIT_NOFMT}" ] ; then
exit 0
fi
echo checking formatting and licenses 1>&2
project_pathname=$(git rev-parse --show-toplevel)
cd "${project_pathname}"
make check