Repository navigation
Conversation
-->
✱ stlc build✅ go code · compare
✅ python code · compare
✅ typescript code · compare
Diagnostics: ❗ 0 new / 1 total error, 💡 0 new / 5 total note
Build metadata
This comment is auto-generated by stlc and is kept up to date as you push. |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 4849059. Configure here.
| meta, err := m.loadMetadata(entry.Name()) | ||
| if err != nil { | ||
| return fmt.Errorf("check Mac identity admission: %w", err) | ||
| } |
There was a problem hiding this comment.
Identity admission fails on metadata errors
Medium Severity
checkMacOSIdentityAvailable treats any loadMetadata failure as fatal, including missing metadata for an in-progress create. A concurrent Linux or macOS create that has already made a guest directory but not yet written metadata causes an unrelated macOS start or create to fail admission.
Reviewed by Cursor Bugbot for commit 4849059. Configure here.
| } | ||
| if exit, ok := e.(*exec.ExitError); !ok || exit.ExitCode() != 1 { | ||
| return nil, fmt.Errorf("cannot verify storage is closed: %v", e) | ||
| } |
There was a problem hiding this comment.
lsof probe leaks process groups
Medium Severity
The import lsof probe runs through exec.CommandContext without a dedicated process group and without SIGKILLing that group on every completion path. Context cancel only stops the wrapper, so lsof descendants can leak after success, ErrWaitDelay, or a wrapper that exits first.
Triggered by learned rule: Subprocess binary probes must use process groups and kill on all completion paths
Reviewed by Cursor Bugbot for commit 4849059. Configure here.
- Skip directories without instance metadata during identity admission so an in-progress create or leftover directory cannot block a macOS start. - Fail create when the image lookup errors instead of silently applying Linux disk and network defaults to a macOS guest. - Take the identity lock from a fixed /tmp path so separate server processes with different TMPDIR values contend on the same lock. - Resolve disk and aux storage from one image layout via GetBootStorage. - Remove the destination directory when a spike clone fails partway, so a retry is not blocked by a partial bundle.
macOS instances own independent disk and auxiliary storage cloned at create time and keep their identity in metadata, so start no longer resolves the template image. Deleting an imported image leaves existing instances startable. Reject --with-state combined with --rekey or --new-mac in the spike clone command: saved state is only restorable into the configuration it was saved from.
The image lookup used for instance defaults returned 404 for an uncached image, which skipped the auto-pull path in resolveImageForCreate. Treat not-found as no macOS defaults and let create resolve and pull the image.
legacyImageExists rebuilt the legacy layout and re-read its metadata for a path the caller had already resolved.
The API looked up the image by tag to decide whether to apply Linux disk and network defaults, while the manager resolved the image it actually creates from. A tag that moved, or an uncached image, could make the defaults describe a different guest. Move the Linux defaults (vCPUs, disk I/O, network bandwidth) into the manager, applied after image resolution and before resource reservation. macOS guests keep taking CPU and memory from the image and continue to reject shaping. The API no longer resolves images at all.
|
Live QA of the reviewed combined PR1–3 sources plus PR4 patches on Apple silicon passed normal authenticated HTTP create from a digest-pinned, previously HTTP-pulled installed macOS OCI artifact (registry offline). Verified actual macOS 27.0.1/26A434 cold boot over pinned-key SSH, inherited 4CPU/8GiB template defaults, duplicate-identity HTTP409, live-guest API restart recovery with unchanged guest boot time, HTTP stop/start with fresh boot time and durable guest-only marker, and unchanged full SHA256 of the immutable materialized base disk+aux afterward. Stop/start here used system-agent-disabled fallback, not verified graceful root-agent shutdown. QA used an isolated data dir/slot; original instance/API/storage were untouched and the QA VM/API ended stopped. Runtime issue found: the long QA data directory generated an overlong AF_UNIX socket path. VZ reported VM started, then control listener failed |
- Move the macOS config-disk skip to the start and create call sites instead of checking inside createConfigDisk, so the Linux-only step is decided once by its caller. - Read the locally imported raw disk with a stat in legacyLayout instead of parsing metadata on every layout lookup. - Return real image lookup errors from the macOS-only pre-check rather than reporting them as "not imported". - Skip the Linux overlay limit for macOS boot disks, whose size comes from the imported image. - Return 501 from the instance stat endpoint for macOS instances before dialing the guest, matching exec. - Remove redundant macOS gates in stop, a stale fixture, a no-op TMPDIR setup in the identity lock test, and a misplaced doc comment.
MacOSImage.Validate holds the field checks and the 6-byte Ethernet MAC rule. The local importer previously accepted EUI-64 and InfiniBand addresses that VZ rejects at boot. The OCI machine-image parser will use the same method.
- macOSNetworkConfig pins a networked macOS guest to its preserved MAC and returns its network config, replacing the copies in create and start. - Move the vmnet lease parser out of the darwin-only file. It only reads /var/db/dhcpd_leases, which is absent off macOS, so the non-darwin stub is no longer needed. - Drop the macOS guards on attach and detach volume. Both return "not yet implemented" for every instance, so the guard only added a metadata read.
RestoreInstance rejects macOS guests with ErrInvalidRequest but had no case for it, so the request fell through to the 500 default. Map it to 400 and declare that response in the spec.
… place - Split prepareMacOSRequest into validateMacOSCreate, a pure check over the request, the image and the backend's capabilities, and applyMacOSDefaults. The check no longer reads runtime.GOOS or the backend name, so the rejection list runs on every host with fixture capabilities. - Add Capabilities.SupportsMacOSBoot, set by the vz backend on arm64. - Drop the six pre-lock macOS rejections. Each operation checks the record it already loads for the work, so the instance is read once instead of twice.
macOSNetworkConfig already returns nil for guests without a network, so the callers assign the result directly instead of testing it into a var first.
|
Simplification update at e6e6ab7: shared bounded complete-machine bundle decoding and one macOS request-default preparation; shared concrete create/start network + boot-config preparation. macOS preserves template MAC and avoids Linux allocation/proxy/config-disk dependencies; Linux rollback and request preservation have synthetic tests. Focused instance/API/image race tests passed 3 runs. Identity leases and stopped-storage/export requirements remain. All PRs remain draft. This is source-level/synthetic validation, not a new live boot or production build proof. Default Codex independent review was attempted but is still blocked by authentication (HTTP401). Published atomically after checking reviewer heads with explicit per-ref force-with-lease; prior heads preserved locally. |


Summary
Experimental, administrator-provisioned macOS guests on local Apple silicon, using the normal Hypeman image storage and instance create/list/get/start/stop/delete APIs. This is a spike checkpoint, not production-ready macOS support.
cmd/import-macosimporter for a stopped macvm bundle: APFS-clone disk/aux, hash content/config, publish a local readydarwin/arm64image. No HTTP host-path import or OCI macOS pull.macos_onlystartup, which rejects Linux guests and skips Linux downloads, builders and Caddy/DNS; add a configurable HTTP listen address for loopback-only use.docs/macos-experimental.md.Runtime validation
Performed sequentially on an Apple M5 / 16 GiB host with an installed, configured macOS template (4 CPUs / 8 GiB, 64 GiB logical boot disk). VM bundles, passwords, SSH keys, JWT credentials and local logs/screenshots are not checked in.
GET /images.POST /instancesreturns 201,darwin/arm64, VZ and Running.These are smoke observations, not repeated boot-to-Chrome-ready benchmarks.
Tests / review
containers_image_openpgp.git diff --checkpasses.--mode local) was retried before this commit, but Codex/OpenAI authentication fails with 401. No external clean-review verdict.Explicit limitations / follow-ups
Runningmeans VMM state, not SSH/desktop/application readiness. No automatic Chrome launch.Next slices: Darwin desktop-aware readiness/launch/clean shutdown; consistent API snapshot bundles; clone identity/credential rekey; full Linux regression and platform measurements.
Note
High Risk
Introduces a new VZ macOS boot path, identity admission, and broad instance/API branching; misconfiguration or identity collisions could affect VM lifecycle on Apple silicon hosts.
Overview
Adds experimental local macOS guests on Apple silicon via VZ: offline import of stopped macvm bundles, normal instance create/start/stop/delete, and a dedicated Mac boot path in the hypervisor and
vz-shim(hardware model, machine ID, auxiliary storage). Linux OCI pulls, macOS image tagging, and registry workflows stay blocked; instances clone writable boot disk + aux per guest, use template CPU/RAM defaults, preserved NAT MAC, and DHCP-derived IP.API and lifecycle: macOS instances skip Linux config disk, guest-agent readiness, proportional I/O/network shaping defaults, and TAP-based networking. Unsupported operations (snapshot, fork, standby, restore, update, volumes, vsock/exec) fail explicitly; exec returns 501 before WebSocket upgrade.
macos_onlyconfig skips Linux kernel/initrd downloads, builders, and ingress/Caddy startup; rejects Linux instance creates and CreateBuild / CreateIngress. HTTPlisten_addressallows loopback binding.Safety: Concurrent use of the same Mac machine identifier is blocked in the instance manager and with a process-lifetime flock in
vz-shim. OpenAPI/schema copy and defaults defer Linux-centric defaults when creating from imported macOS images.Also includes
cmd/import-macos,docs/macos-experimental.md, and a standalonespike/macvmprovisioning harness (not wired into the main API).Reviewed by Cursor Bugbot for commit 4849059. Configure here.