Skip to content

limayaml: do not default containerd.user=true on non-Linux guests - #5090

Merged
AkihiroSuda merged 3 commits into
lima-vm:masterfrom
gaurav0107:fix/5037-filldefault-enables-containerd-user-for
Jun 10, 2026
Merged

AkihiroSuda merged 3 commits into
lima-vm:masterfrom
gaurav0107:fix/5037-filldefault-enables-containerd-user-for

Conversation

@gaurav0107

Copy link
Copy Markdown
Contributor

What

FillDefault in pkg/limayaml/defaults.go enabled containerd.user=true whenever the guest architecture was x86_64 or aarch64, with no check on the guest OS. macOS (os: Darwin) and FreeBSD guests therefore defaulted to containerd.user=true even though nerdctl is a Linux-only runtime, causing the ~250 MiB nerdctl archive to be downloaded unnecessarily.

How

Gate the true default on *y.OS == limatype.LINUX:

if y.Containerd.User == nil {
    if *y.OS == limatype.LINUX {
        switch *y.Arch {
        case limatype.X8664, limatype.AARCH64:
            y.Containerd.User = ptr.Of(true)
        default:
            y.Containerd.User = ptr.Of(false)
        }
    } else {
        y.Containerd.User = ptr.Of(false)
    }
}

y.OS is already resolved earlier in FillDefault (line 157 via ResolveOS), so dereferencing is safe.

Behavior

  • Linux + x86_64 / aarch64 → true (unchanged)
  • Linux + riscv64 / armv7l / ppc64le / s390x → false (unchanged)
  • Darwin + any arch → false (was true for x86_64 / aarch64; this is the fix)
  • FreeBSD + any arch → false (was true for x86_64 / aarch64; this is the fix)
  • Explicit containerd.user: true in user YAML → preserved (override path runs before this block)

Tests

  • TestContainerdUserDefaultPerOS — table-driven test covering Linux/Darwin/FreeBSD across x86_64, aarch64, riscv64, armv7l.
  • TestContainerdUserExplicitOverride — verifies an explicit containerd.user: true is preserved on a Darwin guest.

Existing TestFillDefault already pins Linux + host arch and continues to pass.

ok  github.com/lima-vm/lima/v2/pkg/limayaml  0.342s

Fixes #5037

FillDefault enabled containerd.user=true whenever the guest arch was
x86_64 or aarch64, with no check on the guest OS. macOS (os: Darwin)
and FreeBSD guests therefore defaulted to containerd.user=true even
though nerdctl is a Linux-only runtime, causing the ~250 MiB nerdctl
archive to be downloaded unnecessarily.

Gate the true default on *y.OS == limatype.LINUX. Behavior for Linux
guests is unchanged; non-Linux guests now default to
containerd.user=false on every architecture. Explicit
containerd.user=true in user YAML is preserved.

Add TestContainerdUserDefaultPerOS covering the Linux/Darwin/FreeBSD
matrix and TestContainerdUserExplicitOverride to lock the override
path.

Fixes lima-vm#5037

Signed-off-by: gaurav0107 <gauravdubey0107@gmail.com>
@gaurav0107
gaurav0107 marked this pull request as ready for review June 6, 2026 19:49

@jandubois jandubois left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Needs an update to templates/default.yaml too:

  # Enable user-scoped (aka rootless) containerd and its dependencies
  # 🟢 Builtin default: true (for x86_64 and aarch64)
  user: null

Comment thread pkg/limayaml/defaults_test.go Outdated
}

// TestContainerdUserDefaultPerOS verifies that FillDefault only enables
// containerd.user=true on Linux guests. nerdctl is a Linux-only runtime,

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
// containerd.user=true on Linux guests. nerdctl is a Linux-only runtime,
// containerd.user=true on Linux guests for x86_64 and aarch64. nerdctl is a Linux-only runtime,

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Applied in 19fab75. Thanks for the review.

Update the doc comment in templates/default.yaml to reflect the
behavior change in this PR: the user-scoped containerd default of
true now applies only to Linux x86_64 and aarch64 guests; non-Linux
guests default to false.

Addresses review feedback from @jandubois on PR lima-vm#5090.

Signed-off-by: gaurav0107 <gauravdubey0107@gmail.com>
@gaurav0107

Copy link
Copy Markdown
Contributor Author

Thanks for the review! Updated templates/default.yaml in 6791581 to reflect the new behavior:

  # Enable user-scoped (aka rootless) containerd and its dependencies
  # 🟢 Builtin default: true for Linux x86_64 and aarch64 guests, false otherwise
  user: null

Followed the wording pattern from 3fc5e85 (vz: disable ssh.overVsock by default for non-Linux guests). PTAL.

@jandubois

Copy link
Copy Markdown
Member

Thanks, but please squash commits

Apply review suggestion from @jandubois: tighten the doc comment to
state that the default of containerd.user=true is enabled only for
x86_64 and aarch64 on Linux guests, matching the actual FillDefault
behavior.

Addresses review feedback from @jandubois on PR lima-vm#5090.

Signed-off-by: gaurav0107 <gauravdubey0107@gmail.com>
@gaurav0107

Copy link
Copy Markdown
Contributor Author

@jandubois The templates/default.yaml comment was updated in 6791581 ("limayaml: clarify containerd.user default is Linux-only in default.yaml") earlier in this branch, and the test-comment suggestion is applied in 19fab75. Both review items should be addressed now — please re-review when convenient.

@AkihiroSuda AkihiroSuda added this to the v2.2.0 milestone Jun 10, 2026

@AkihiroSuda AkihiroSuda left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks

@AkihiroSuda
AkihiroSuda merged commit 9b3195b into lima-vm:master Jun 10, 2026
35 checks passed
@AkihiroSuda

Copy link
Copy Markdown
Member

Next time please make sure to squash the commits

AkihiroSuda pushed a commit that referenced this pull request Jun 19, 2026
Update the doc comment in templates/default.yaml to reflect the
behavior change in this PR: the user-scoped containerd default of
true now applies only to Linux x86_64 and aarch64 guests; non-Linux
guests default to false.

Addresses review feedback from @jandubois on PR #5090.

Signed-off-by: gaurav0107 <gauravdubey0107@gmail.com>
(cherry picked from commit 6791581)
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
AkihiroSuda pushed a commit that referenced this pull request Jun 19, 2026
Apply review suggestion from @jandubois: tighten the doc comment to
state that the default of containerd.user=true is enabled only for
x86_64 and aarch64 on Linux guests, matching the actual FillDefault
behavior.

Addresses review feedback from @jandubois on PR #5090.

Signed-off-by: gaurav0107 <gauravdubey0107@gmail.com>
(cherry picked from commit 19fab75)
Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
tmeijn pushed a commit to tmeijn/dotfiles that referenced this pull request Jul 9, 2026
This MR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [lima-vm/lima](https://github.com/lima-vm/lima) | patch | `v2.1.2` → `v2.1.4` |

MR created with the help of [el-capitano/tools/renovate-bot](https://gitlab.com/el-capitano/tools/renovate-bot).

**Proposed changes to behavior should be submitted there as MRs.**

---

### Release Notes

<details>
<summary>lima-vm/lima (lima-vm/lima)</summary>

### [`v2.1.4`](https://github.com/lima-vm/lima/releases/tag/v2.1.4)

[Compare Source](lima-vm/lima@v2.1.3...v2.1.4)

#### Changes

- Cherry-picks from `master` to `release/2.1`
  - Only add xorrisofs flag to the xorrisofs command  ([#&#8203;5129](lima-vm/lima#5129), thanks to [@&#8203;afbjorklund](https://github.com/afbjorklund))
  - fix(qemu): fallback from hvf to tcg on macOS ([#&#8203;5137](lima-vm/lima#5137), thanks to [@&#8203;kavirakesh14](https://github.com/kavirakesh14))
  - nerdctl: update from v2.3.3 to [v2.3.4](https://github.com/containerd/nerdctl/releases/tag/v2.3.4) ([#&#8203;5169](lima-vm/lima#5169))
  - templates: update ([#&#8203;5170](lima-vm/lima#5170))
  - templates/freebsd-15: support 9p mounts ([#&#8203;5172](lima-vm/lima#5172))
  - cmd/limactl: include name in network list `--json` output ([#&#8203;5179](lima-vm/lima#5179), thanks to [@&#8203;coulof](https://github.com/coulof))

Full changes: <https://github.com/lima-vm/lima/milestone/73?closed=1>

#### Usage

```console
$ limactl create
$ limactl start
...
INFO[0029] READY. Run `lima` to open the shell.

$ lima uname
Linux
```

***

The binaries were built automatically on GitHub Actions.
The build log is available for 90 days: <https://github.com/lima-vm/lima/actions/runs/28630554371>

The sha256sum of the SHA256SUMS file itself is `8bd82f03bc23acafc7e129fdbcbd9401b50eee2723817b8127f16dee3aebef92` .

***

Release manager: [@&#8203;AkihiroSuda](https://github.com/AkihiroSuda)

### [`v2.1.3`](https://github.com/lima-vm/lima/releases/tag/v2.1.3)

[Compare Source](lima-vm/lima@v2.1.2...v2.1.3)

- Cherry-picks from `master` to `release/2.1` ([#&#8203;5131](lima-vm/lima#5131))
  - limayaml: do not default containerd.user=true on non-Linux guests ([#&#8203;5090](lima-vm/lima#5090), thanks to [@&#8203;gaurav0107](https://github.com/gaurav0107))
  - fix(copytool): fallback to scp for remote source and destination in auto mode ([#&#8203;5097](lima-vm/lima#5097), thanks to [@&#8203;unsuman](https://github.com/unsuman))
  - templates: switch the default image from ubuntu-25.10 to ubuntu-26.04 ([#&#8203;5106](lima-vm/lima#5106))
  - krunkit: disable ssh.overVsock by default ([#&#8203;5123](lima-vm/lima#5123))
  - fix(makefile): propagate build failure for additional drivers ([#&#8203;5125](lima-vm/lima#5125), thanks to [@&#8203;unsuman](https://github.com/unsuman))
  - templates: update ([#&#8203;5130](lima-vm/lima#5130))
  - nerdctl: update from v2.2.2 to v2.3.3 ([#&#8203;5134](lima-vm/lima#5134))
    - [v2.3.0 release note](https://github.com/containerd/nerdctl/releases/tag/v2.3.0)
    - [v2.3.1 release note](https://github.com/containerd/nerdctl/releases/tag/v2.3.1)
    - [v2.3.2 release note](https://github.com/containerd/nerdctl/releases/tag/v2.3.2)
    - [v2.3.3 release note](https://github.com/containerd/nerdctl/releases/tag/v2.3.3)
      - nerdctl v2.3.3 contains [containerd v2.3.2](https://github.com/containerd/containerd/releases/tag/v2.3.2), which fixes CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262

- Fix CVE-2026-53657 (GHSA-2j9v-p4xj-cjw2) "An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket"

Full changes: <https://github.com/lima-vm/lima/milestone/72>

#### Usage

```console
$ limactl create
$ limactl start
...
INFO[0029] READY. Run `lima` to open the shell.

$ lima uname
Linux
```

***

The binaries were built automatically on GitHub Actions.
The build log is available for 90 days: <https://github.com/lima-vm/lima/actions/runs/27824357138>

The sha256sum of the SHA256SUMS file itself is `ddaf499316c159493ccf853393e35c93d69e8c1f85cb041f6f7e918157625c6c` .

***

Release manager: [@&#8203;AkihiroSuda](https://github.com/AkihiroSuda)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this MR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box

---

This MR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTYuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI1Ni4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJSZW5vdmF0ZSBCb3QiLCJhdXRvbWF0aW9uOmJvdC1hdXRob3JlZCIsImRlcGVuZGVuY3ktdHlwZTo6cGF0Y2giXX0=-->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

FillDefault enables containerd.user for macOS guests on aarch64 — nerdctl unnecessarily downloaded

3 participants