Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
slonopotamus
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
slonopotamus
3y ago
If you want to follow my upstream attempts, subscribe to https://github.com/moby/buildkit/pull/4059 https://github.com/moby/moby/pull/46558
2.
▲
by
slonopotamus
3y ago
You mean, Earthly has macOS arm64 runners? I am failing to find any info on its website.
3.
▲
by
slonopotamus
3y ago
Okay, let's call them "labeled code snapshots")
4.
▲
by
slonopotamus
3y ago
Haha, what a mess)
5.
▲
by
slonopotamus
3y ago
Yeah, I undestand the situation with #8789.
6.
▲
by
slonopotamus
3y ago
It's not me, it's containerd "native" snapshotter. It turns to be efficient on macOS thanks to `clonefile` syscall.
7.
▲
by
slonopotamus
3y ago
> Technical limitations aren’t excuses for a bad design. Tomorrow Apple might decide it is safe to chroot with SIP enabled (I actually do not understand why they restrict it, chroot is a tool to increase security). Does that suddenly c
8.
▲
by
slonopotamus
3y ago
One might develop a game that by some kind of a miracle releases for macOS too. So they way to run CI tests on macOS. Or they might target iOS. And use macOS build machines to produce builds. The world is not only about web, you know?
9.
▲
by
slonopotamus
3y ago
OrbStack is about Linux containers. What we're talking about in this topic is the only software in the world for macOS containers.
10.
▲
by
slonopotamus
3y ago
> My preferred course of action in such situations is not specify a version at all. This doesn't work because, well, I do make releases and they need some numbers)
11.
▲
by
slonopotamus
3y ago
FUSE is only used for bind mounts. If you write to a directory that belongs to container, you get the raw speed of host OS.
12.
▲
by
slonopotamus
3y ago
I believe that could be optimized in the future. At least, by splitting amd64/arm64 code.
13.
▲
by
slonopotamus
3y ago
This is a failed attempt to upstream part of containerd changes: https://github.com/containerd/containerd/pull/8789 Other part of containerd changes waits for gods-know-what: https://github.com
14.
▲
by
slonopotamus
3y ago
> macOS doesn't provide a stable system call API I'm really wondering, do you have any links about macOS syscall stability over versions?
15.
▲
by
slonopotamus
3y ago
SIP won't save you from wrong file permissions. And SIP doesn't defend you from editing files in /bin. They are guarded by the fact that root filesystem is mounted read-only.
16.
▲
by
slonopotamus
3y ago
Original author here. I wanted to clearly indicate early-prealpha-unstable-not-for-production-yet state of this software. Using "1.0.0" and even "1.0.0-alpha" would give false expectations about maturity of this project.
17.
▲
by
slonopotamus
3y ago
No. For the same reason you cannot run Windows containers on Linux. You need a working macOS kernel.
18.
▲
by
slonopotamus
3y ago
> But most it’s still very niche. I'd say that the whole containerization topic is niche > Is there a way to make a separate partition of MacOS and have one copy with SIP and one without? I think you can install macOS VM on your
19.
▲
by
slonopotamus
3y ago
> Who would use that and for what? I believe this project can be useful for CI and testing scenarios. > On MacOS desktop software distribution is largely a solved problem since ages Are you talking about App Store? Or Homebrew? Or Mac
20.
▲
by
slonopotamus
3y ago
> Also not sure if it can be dynamically set by a parent process for a child? Yes, it can. See sandbox-exec tool. And I actually plan to use it: https://github.com/macOScontainers/rund/issues/15
21.
▲
by
slonopotamus
3y ago
I didn't want to use "jail" term because it is mostly unheard of outside of FreeBSD. Container definition is very stretched nowadays. Look at Windows HostProcesses in Kubernetes [1]. They don't have neither process, netw
22.
▲
by
slonopotamus
3y ago
What exactly attack vectors you think are possible against macOS without SIP but not possible against Linux?
23.
▲
by
slonopotamus
3y ago
> this doesn't give me anything extra to what using docker would do on macos You're missing the point. This project DOES use docker.
24.
▲
by
slonopotamus
3y ago
You can just mount it readonly.
25.
▲
by
slonopotamus
3y ago
> And that’s a good thing? That's a technical limitation.
26.
▲
by
slonopotamus
3y ago
> What's the licensing situation on this? 1. This project didn't take explicit permission from Apple to redistribute binaries 2. There are multiple jurisdictions where you don't need to explicitly have such permission, it
27.
▲
by
slonopotamus
3y ago
> CI/CD workflows most likely Yep, this is primary goal of this project.
28.
▲
by
slonopotamus
3y ago
It is the same for any OS. Virtual machine boots a separate instance of the whole OS. This is slow, this is often too much isolated (you can't easily/effectively share files between host and guest), you need to set artificial limi
29.
▲
by
slonopotamus
3y ago
Nope, that PR was an attempt to upstream my changes: https://github.com/macOScontainers/containerd/commits/macos Vanilla containerd cannot mount anything on macos. > If you really want good adoption, you’l
30.
▲
by
slonopotamus
3y ago
Original author here. > So essentially a chroot with a bit of make-up Well. 1. It is not trivial to properly set up a chroot on macOS. If you try to find a working guide/tool that works with modern macOS, I doubt you'll find an
More ›