limayaml: do not default containerd.user=true on non-Linux guests - #5090
AkihiroSuda merged 3 commits into
Conversation
FillDefault enabled containerd.user=true whenever the guest arch was x86_64 or aarch64, with no check on the guest OS. macOS (os: Darwin) and FreeBSD guests therefore defaulted to containerd.user=true even though nerdctl is a Linux-only runtime, causing the ~250 MiB nerdctl archive to be downloaded unnecessarily. Gate the true default on *y.OS == limatype.LINUX. Behavior for Linux guests is unchanged; non-Linux guests now default to containerd.user=false on every architecture. Explicit containerd.user=true in user YAML is preserved. Add TestContainerdUserDefaultPerOS covering the Linux/Darwin/FreeBSD matrix and TestContainerdUserExplicitOverride to lock the override path. Fixes lima-vm#5037 Signed-off-by: gaurav0107 <gauravdubey0107@gmail.com>
jandubois
left a comment
There was a problem hiding this comment.
Needs an update to templates/default.yaml too:
# Enable user-scoped (aka rootless) containerd and its dependencies
# 🟢 Builtin default: true (for x86_64 and aarch64)
user: null| } | ||
|
|
||
| // TestContainerdUserDefaultPerOS verifies that FillDefault only enables | ||
| // containerd.user=true on Linux guests. nerdctl is a Linux-only runtime, |
There was a problem hiding this comment.
| // containerd.user=true on Linux guests. nerdctl is a Linux-only runtime, | |
| // containerd.user=true on Linux guests for x86_64 and aarch64. nerdctl is a Linux-only runtime, |
There was a problem hiding this comment.
Applied in 19fab75. Thanks for the review.
Update the doc comment in templates/default.yaml to reflect the behavior change in this PR: the user-scoped containerd default of true now applies only to Linux x86_64 and aarch64 guests; non-Linux guests default to false. Addresses review feedback from @jandubois on PR lima-vm#5090. Signed-off-by: gaurav0107 <gauravdubey0107@gmail.com>
|
Thanks for the review! Updated # Enable user-scoped (aka rootless) containerd and its dependencies
# 🟢 Builtin default: true for Linux x86_64 and aarch64 guests, false otherwise
user: nullFollowed the wording pattern from 3fc5e85 ( |
|
Thanks, but please squash commits |
Apply review suggestion from @jandubois: tighten the doc comment to state that the default of containerd.user=true is enabled only for x86_64 and aarch64 on Linux guests, matching the actual FillDefault behavior. Addresses review feedback from @jandubois on PR lima-vm#5090. Signed-off-by: gaurav0107 <gauravdubey0107@gmail.com>
|
@jandubois The |
|
Next time please make sure to squash the commits |
Update the doc comment in templates/default.yaml to reflect the behavior change in this PR: the user-scoped containerd default of true now applies only to Linux x86_64 and aarch64 guests; non-Linux guests default to false. Addresses review feedback from @jandubois on PR #5090. Signed-off-by: gaurav0107 <gauravdubey0107@gmail.com> (cherry picked from commit 6791581) Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
Apply review suggestion from @jandubois: tighten the doc comment to state that the default of containerd.user=true is enabled only for x86_64 and aarch64 on Linux guests, matching the actual FillDefault behavior. Addresses review feedback from @jandubois on PR #5090. Signed-off-by: gaurav0107 <gauravdubey0107@gmail.com> (cherry picked from commit 19fab75) Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
This MR contains the following updates: | Package | Update | Change | |---|---|---| | [lima-vm/lima](https://github.com/lima-vm/lima) | patch | `v2.1.2` → `v2.1.4` | MR created with the help of [el-capitano/tools/renovate-bot](https://gitlab.com/el-capitano/tools/renovate-bot). **Proposed changes to behavior should be submitted there as MRs.** --- ### Release Notes <details> <summary>lima-vm/lima (lima-vm/lima)</summary> ### [`v2.1.4`](https://github.com/lima-vm/lima/releases/tag/v2.1.4) [Compare Source](lima-vm/lima@v2.1.3...v2.1.4) #### Changes - Cherry-picks from `master` to `release/2.1` - Only add xorrisofs flag to the xorrisofs command ([#​5129](lima-vm/lima#5129), thanks to [@​afbjorklund](https://github.com/afbjorklund)) - fix(qemu): fallback from hvf to tcg on macOS ([#​5137](lima-vm/lima#5137), thanks to [@​kavirakesh14](https://github.com/kavirakesh14)) - nerdctl: update from v2.3.3 to [v2.3.4](https://github.com/containerd/nerdctl/releases/tag/v2.3.4) ([#​5169](lima-vm/lima#5169)) - templates: update ([#​5170](lima-vm/lima#5170)) - templates/freebsd-15: support 9p mounts ([#​5172](lima-vm/lima#5172)) - cmd/limactl: include name in network list `--json` output ([#​5179](lima-vm/lima#5179), thanks to [@​coulof](https://github.com/coulof)) Full changes: <https://github.com/lima-vm/lima/milestone/73?closed=1> #### Usage ```console $ limactl create $ limactl start ... INFO[0029] READY. Run `lima` to open the shell. $ lima uname Linux ``` *** The binaries were built automatically on GitHub Actions. The build log is available for 90 days: <https://github.com/lima-vm/lima/actions/runs/28630554371> The sha256sum of the SHA256SUMS file itself is `8bd82f03bc23acafc7e129fdbcbd9401b50eee2723817b8127f16dee3aebef92` . *** Release manager: [@​AkihiroSuda](https://github.com/AkihiroSuda) ### [`v2.1.3`](https://github.com/lima-vm/lima/releases/tag/v2.1.3) [Compare Source](lima-vm/lima@v2.1.2...v2.1.3) - Cherry-picks from `master` to `release/2.1` ([#​5131](lima-vm/lima#5131)) - limayaml: do not default containerd.user=true on non-Linux guests ([#​5090](lima-vm/lima#5090), thanks to [@​gaurav0107](https://github.com/gaurav0107)) - fix(copytool): fallback to scp for remote source and destination in auto mode ([#​5097](lima-vm/lima#5097), thanks to [@​unsuman](https://github.com/unsuman)) - templates: switch the default image from ubuntu-25.10 to ubuntu-26.04 ([#​5106](lima-vm/lima#5106)) - krunkit: disable ssh.overVsock by default ([#​5123](lima-vm/lima#5123)) - fix(makefile): propagate build failure for additional drivers ([#​5125](lima-vm/lima#5125), thanks to [@​unsuman](https://github.com/unsuman)) - templates: update ([#​5130](lima-vm/lima#5130)) - nerdctl: update from v2.2.2 to v2.3.3 ([#​5134](lima-vm/lima#5134)) - [v2.3.0 release note](https://github.com/containerd/nerdctl/releases/tag/v2.3.0) - [v2.3.1 release note](https://github.com/containerd/nerdctl/releases/tag/v2.3.1) - [v2.3.2 release note](https://github.com/containerd/nerdctl/releases/tag/v2.3.2) - [v2.3.3 release note](https://github.com/containerd/nerdctl/releases/tag/v2.3.3) - nerdctl v2.3.3 contains [containerd v2.3.2](https://github.com/containerd/containerd/releases/tag/v2.3.2), which fixes CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262 - Fix CVE-2026-53657 (GHSA-2j9v-p4xj-cjw2) "An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket" Full changes: <https://github.com/lima-vm/lima/milestone/72> #### Usage ```console $ limactl create $ limactl start ... INFO[0029] READY. Run `lima` to open the shell. $ lima uname Linux ``` *** The binaries were built automatically on GitHub Actions. The build log is available for 90 days: <https://github.com/lima-vm/lima/actions/runs/27824357138> The sha256sum of the SHA256SUMS file itself is `ddaf499316c159493ccf853393e35c93d69e8c1f85cb041f6f7e918157625c6c` . *** Release manager: [@​AkihiroSuda](https://github.com/AkihiroSuda) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this MR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box --- This MR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTYuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI1Ni4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJSZW5vdmF0ZSBCb3QiLCJhdXRvbWF0aW9uOmJvdC1hdXRob3JlZCIsImRlcGVuZGVuY3ktdHlwZTo6cGF0Y2giXX0=-->
What
FillDefaultinpkg/limayaml/defaults.goenabledcontainerd.user=truewhenever the guest architecture wasx86_64oraarch64, with no check on the guest OS. macOS (os: Darwin) and FreeBSD guests therefore defaulted tocontainerd.user=trueeven though nerdctl is a Linux-only runtime, causing the ~250 MiB nerdctl archive to be downloaded unnecessarily.How
Gate the
truedefault on*y.OS == limatype.LINUX:y.OSis already resolved earlier inFillDefault(line 157 viaResolveOS), so dereferencing is safe.Behavior
true(unchanged)false(unchanged)false(wastruefor x86_64 / aarch64; this is the fix)false(wastruefor x86_64 / aarch64; this is the fix)containerd.user: truein user YAML → preserved (override path runs before this block)Tests
TestContainerdUserDefaultPerOS— table-driven test covering Linux/Darwin/FreeBSD acrossx86_64,aarch64,riscv64,armv7l.TestContainerdUserExplicitOverride— verifies an explicitcontainerd.user: trueis preserved on a Darwin guest.Existing
TestFillDefaultalready pins Linux + host arch and continues to pass.Fixes #5037