Skip to content
CAI
Software that uses CAICheck a score

apple/containerization

61.5

Adequate · 27 September 2026

49.2k

lines of production code

Swift

with C

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Swift-based containerization framework that manages the lifecycle of Linux containers and micro-VMs on macOS. It provides low-level primitives for process isolation, OCI-compliant image handling, and secure filesystem operations, while integrating with Cloud Hypervisor for virtualization. The project also includes a CLI tool for interacting with these workloads and experimental utilities for running AI agents in sandboxed environments.

How it got here

2025 — Initial containerization framework scaffolding

46 changes.

The project established its foundational infrastructure by initializing the repository, configuring CI tooling, and implementing core Swift libraries for Linux container management. This period focused on building essential components such as OCI compliance, EXT4 image unpacking, and Cloud Hypervisor integration, while simultaneously removing legacy agent implementations. Comprehensive test coverage and security hardening were added to support the new container lifecycle and networking primitives.

2026 — vminitd architecture and sandboxy tooling

5 changes.

The vminitd core library was restructured to introduce a robust process management and I/O relay architecture, enabling better container lifecycle control and API exposure. Concurrently, the project introduced Sandboxy, an experimental tool for running AI coding agents in isolated Linux VMs, while enhancing the development environment with cross-compilation support for aarch64 hosts.

Features

Add macOS container example with build and run instructions

A new example project (ctr-example) has been added to demonstrate launching a Linux container using the Containerization framework on macOS. This includes a Swift-based executable, a Makefile for building and running the example, and documentation (README.md, lab.md) guiding users through fetching the kernel, building the tool, and running a container (e.g., Alpine). The example also includes an entitlements file for virtualization access.

examples/ctr-example · high confidence

Added Linux syscall wrappers for container namespace and resource management

The LCShim library now includes C wrappers for several Linux-specific syscalls and constants, enabling better interoperability with Swift. These additions include pidfd support (pidfd\_open, pidfd\_getfd), namespace manipulation (setns, unshare with CLONE\NEW\ flags), process control (prctl for no\_new\_privs and sub-reaper), and resource limits (setrlimit with plain integer resources). It also provides a Swift-compatible statfs wrapper (CZ\_statfs) that extracts filesystem statistics into plain integer fields, bypassing struct import issues in Swift across different targets.

vminitd/Sources/LCShim · high confidence

ContainerizationOS: New file descriptor confinement utilities and command process attributes

This update introduces several new capabilities and behavioral changes to the ContainerizationOS module. It adds \FileDescriptorOps\ for secure, symlink-safe filesystem operations (mkdir, recursive unlink, enumeration) anchored to file descriptors to prevent path traversal, and \RootfsResolver\ for Linux-specific confinement using \openat2\ with \RESOLVE\_IN\_ROOT\. A new \Stat\ struct provides detailed file metadata, while \FilePathOps\ offers lexical path normalization. The \Command\ API now supports \pdeathSignal\ to send a signal to a child process upon parent death, \setForegroundPGroup\ to set the foreground process group, and improved \/dev/null\ handling for stdin/stdout/stderr. Additionally, the \User\ type has been reworked to expose public properties and a \shell\ field, and the custom \RWLock\ has been removed.

Sources/ContainerizationOS · high confidence

Expanded Linux shim headers for container capabilities and process control

The CShim include directory now provides a broader set of Linux-specific wrappers and definitions to support advanced container features. New headers introduce direct syscall bindings for Linux capabilities (capget/capset), process attribute management via prctl (keepcaps, capability sets, ambient capabilities), and the openat2 syscall with RESOLVE\_IN\_ROOT support for secure path resolution. Additionally, the exec\_command interface now exposes parent death signal and foreground process group settings, while new headers define TAP network interface creation, socket helper macros for Swift interoperability, and essential Linux system headers previously missing from Swift's modulemap.

Sources/CShim/include · high confidence

Expanded Linux system call shims and process management capabilities

The CShim library now provides a broader set of low-level Linux wrappers to support advanced container and VM initialization. New files add direct syscall bindings for \openat2\ (for secure path resolution), TAP network interface creation, and various \prctl\ operations including capability bounding set management and ambient capability handling. The core \exec\_command\ logic has been updated to support setting a parent-death signal, managing foreground process groups for TTY access, and efficiently marking file descriptors as close-on-exec using the Linux \close\_range\ syscall. Additionally, capability retrieval and setting functions have been consolidated into a dedicated module.

Sources/CShim · high confidence

Expanded container management API with file operations, statistics, and process control

The SandboxContext gRPC service has been significantly extended to support richer container interaction. New RPCs allow writing files (\WriteFile\), copying files or directories between host and guest (\Copy\), and retrieving filesystem metadata (\Stat\). Process management now includes closing stdin (\CloseProcessStdin\) and returning exit timestamps in wait responses. The service also exposes container statistics (\ContainerStatistics\) and introduces filesystem operations like trimming and freezing. Additionally, network configuration is enhanced with \ConfigureHosts\ for managing \/etc/hosts\, and \CreateProcess\ now supports specifying an OCI runtime path.

Sources/Containerization/SandboxContext · high confidence

Initial repository scaffolding and developer tooling configuration

The repository is initialized with essential configuration files to support development and CI workflows. A \.gitignore\ is added to exclude build artifacts, editor files, and generated binaries. Swift tooling is configured via \.swift-format\ and \.swift-format-nolint\ for code style enforcement, and \.swift-version\ pins the Swift version to 6.3.0. The Swift Package Index is configured via \.spi.yml\ to build documentation for specific targets using Swift 6.2. A \CLAUDE.md\ file provides comprehensive guidance for AI assistants and developers on building, testing, and understanding the architecture. Documentation and maintenance are updated with \CONTRIBUTING.md\ (including AI guidelines and commit signing requirements), \MAINTAINERS.txt\ (replacing \CONTRIBUTORS.txt\), and a \LICENSE\ file. The \Makefile\ and \Protobuf.Makefile\ are updated to support building on Linux via a dev container, handling kernel fetching, and managing dependencies like cloud-hypervisor and runc.

(repo-wide) · high confidence

Introduce Cgroup2Manager for Linux cgroup v2 operations

Added a new Cgroup2Manager component in the vminitd Cgroup module to handle cgroup v2 management on Linux. This implementation provides capabilities to create cgroup hierarchies, toggle subtree controllers (such as memory, CPU, and PIDs), add processes to cgroups, and load existing cgroup contexts from process IDs, enabling vminitd to enforce resource limits and isolation for its workloads.

vminitd/Sources/Cgroup · high confidence

Introduce CloudHypervisor library and Linux bridge networking support

This change adds a new standalone Swift library, CloudHypervisor, for driving the Cloud Hypervisor REST API over a Unix domain socket, providing clients for VM lifecycle management (create, boot, shutdown, pause, resume) and hotplugging devices (disks, filesystems, network, vsock). It also introduces Linux-specific bridge networking support via BridgeManager, which handles bridge creation, configuration, and optional NAT (iptables MASQUERADE/FORWARD) with idempotent state management.

Sources/Containerization · high confidence

Introduce Sandboxy, an experimental tool for running AI coding agents in sandboxed Linux VMs

This change adds the \sandboxy\ example application, a command-line tool that runs AI coding agents (such as Claude Code and Pi) inside isolated Linux Micro VMs on macOS. The tool provides a \sandboxy run\ command to launch agents with isolated network access (filtered via a host-side HTTP proxy), shared host workspaces via virtio-fs, and persistent or ephemeral instance states. It includes built-in agent definitions, a caching system for kernels and root filesystems to ensure fast subsequent runs, and configuration commands (\sandboxy config\, \sandboxy cache\) to manage agent definitions and cached environments.

examples/sandboxy · high confidence

Linux containerization support: capabilities, binfmt, and epoll rework

This update introduces Linux-specific containerization primitives. A new Capabilities module allows parsing and managing Linux capability sets (bounding, effective, inheritable, permitted, ambient) and names (e.g., CAP\_NET\_ADMIN, CAP\_SYS\_ADMIN) with case-insensitive matching. The Binfmt utility is enhanced with better documentation, updated license headers, and a renamed deregister method for binfmt\_misc entries. The Epoll implementation is significantly refactored: it now uses a struct-based Mask and Event model instead of handler closures, supports edge-triggered monitoring, and uses an eventfd for shutdown signaling instead of a pipe, improving reliability and type safety.

Sources/ContainerizationOS/Linux · high confidence

New EXT4-based container image unpacker with zstd support and progress tracking

The containerization module now includes an EXT4Unpacker that extracts container image layers directly into an EXT4 filesystem block device. This implementation adds support for zstd-compressed layers, allows optional journaling configuration for the resulting filesystem, and provides a progress handler to monitor unpacking status. The unpacker resolves image layers upfront, scans archive headers to report total size and item counts, and ensures cleanup of temporary files if unpacking fails.

Sources/Containerization/Image/Unpacker · high confidence

New ctr-example demonstrating container lifecycle management

Added a new Swift-based example application (ctr-example) that demonstrates how to use the Containerization library to create, start, and manage a Linux container. The example fetches a specific initfs image (ghcr.io/apple/containerization/vminit:0.26.5) and a kernel binary, configures a container with 2 CPUs and 512 MiB of memory, attaches a terminal for interactive shell access, and handles the full lifecycle including cleanup.

examples/ctr-example/Sources · high confidence

New networking primitives and concurrency utilities in ContainerizationExtras

This update introduces a suite of new types to the ContainerizationExtras module to support container networking and safer concurrency. It adds type-safe, Codable-compliant models for IP addresses (IPv4 and IPv6, including zone identifiers and IPv4-mapped notation), CIDR blocks (with containment checks and range calculations), and MAC addresses, alongside a NetworkConfiguration model for interface addresses and routes. Additionally, it provides an AsyncMutex actor for safe async locking to prevent actor reentrancy issues, and a ProxyUtils utility to resolve HTTP/HTTPS proxy settings from environment variables while correctly handling NO\_PROXY bypass rules.

Sources/ContainerizationExtras · high confidence

New x86\_64 build infrastructure and developer tooling scripts

This change introduces a comprehensive set of build scripts to support cross-compiling the deployment tarball for x86\_64 hosts from an aarch64 Linux dev container. It adds \build-dist-x86\_64.sh\ to orchestrate the cross-compilation of \cctl\, \vminitd\, \cloud-hypervisor\, and \virtiofsd\, alongside \build-musl-x86\_64-deps.sh\ and \build-glibc-x86\_64-deps.sh\ to prepare the necessary static and dynamic C library dependencies. The \build-initfs.sh\ script is added to construct the guest init filesystem, while \check-integration-test-vm-panics.sh\ provides automated detection of kernel panics in test logs. Additionally, \install-hawkeye.sh\ is updated to v6.5.1 with SHA-256 checksum verification, and the license header template is updated to remove the "All rights reserved" phrase and support dynamic year ranges.

scripts · high confidence

vminitd core library introduces new process management and I/O relay architecture

The VminitdCore library has been restructured to provide a foundational runtime for the vminitd agent, introducing a new \AgentCommand\ entry point that bootstraps the environment (mounts, cgroups, memory monitoring) and serves the API over vsock port 1024. This change adds a robust \ProcessSupervisor\ for managing container lifecycles, including zombie reaping and file descriptor monitoring via epoll, and introduces a \CommandRunner\ abstraction with a \ReaperCommandRunner\ for handling process exits. A new \IOPair\ class implements buffered, non-blocking I/O relay for container streams, while \ManagedContainer\ and \ManagedProcess\ provide the core logic for launching and managing container processes (supporting both runc and vmexec backends). The update also includes a \MemoryMonitor\ for cgroup-based memory threshold alerts, a minimal \InitCommand\ for signal forwarding and zombie reaping, and a \PauseCommand\ for holding the container state.

vminitd/Sources/VminitdCore · high confidence

vminitd now exposes build version details

The vminitd component now includes a new C source file and header that expose the Git commit hash, Git tag, and build timestamp via dedicated accessor functions. This allows the service to report its specific build identity, with fallback values used when these details are not available at compile time.

vminitd/Sources/CVersion · high confidence

Removals

Removal of @SendableProperty macro implementation

The \@SendableProperty\ macro, which previously generated thread-safe storage using \Mutex\ and accessor wrappers to maintain \Sendable\ conformance, has been removed from the \Sources/SendablePropertyMacros\ module. This change eliminates the automatic generation of peer properties and accessors for variables marked with this attribute.

Sources/SendablePropertyMacros · high confidence

Removal of Vminitd guest agent implementation

The Vminitd.swift file, which provided the remote connection and implementation for the Linux guest agent (Vminitd) used to modify the sandbox runtime environment, has been deleted. This change removes the ability to perform operations such as mounting filesystems, creating processes, and managing process signals via the Vminitd protocol within this agent component.

Sources/Containerization/Agent · high confidence

Security

Security hardening and memory safety improvements in the OCI content store

The content store now enforces strict validation on all digest strings to prevent path traversal attacks, rejecting any input that is not a well-formed \sha256:\<hex\>\ string and ensuring only lowercase hex characters are used. To prevent memory exhaustion, reading content via \data()\ or \decode()\ is now bounded to a maximum of 4 MiB for documents, and file access is secured by opening descriptors with \O\_NOFOLLOW\ to refuse symlinks. Additionally, writing content is performed in 1 MiB chunks to manage memory usage during large transfers, and the \ContentStore\ protocol now exposes a \totalAllocatedSize\ method to report disk usage.

Sources/ContainerizationOCI/Content · high confidence

Behavioural changes

The NetlinkSession API now allows setting the Maximum Transmission Unit (MTU) when bringing an interface up or down via the updated linkSet method, which accepts an optional mtu parameter. Additionally, a new linkSetAttributes method has been added to allow updating interface properties such as the MAC address and bridge master assignment. The implementation also adds support for the Glibc C library on Linux hosts and updates copyright headers to reflect the 2025-2026 period.

Sources/ContainerizationNetlink · high confidence

ContainerizationError now conforms to LocalizedError with cause chain support

The core \ContainerizationError\ type now conforms to Swift's \LocalizedError\ protocol, providing an \errorDescription\ that includes the original cause if one is present (e.g., "message (cause: "cause message")"). This change enhances error reporting for users by exposing the underlying error chain in localized descriptions. Additionally, the error's \description\ property has been updated to include the cause in its output, and a minor fix lowercases a fatal error message for invalid code values.

Sources/ContainerizationError · high confidence

Dev container now supports cross-compiling x86\_64 Linux binaries from aarch64 hosts

The Linux development Docker image has been updated to include tooling for building x86\_64 Linux artifacts (such as vminitd, initfs, and cloud-hypervisor) directly from an aarch64 host. This is achieved by installing Zig as a cross-compiler and deploying wrapper scripts that emulate standard x86\_64 toolchains (gcc, g++, ar, etc.) for both musl and glibc targets. These wrappers intercept build-system calls to ensure compatibility with Rust's cc-rs and autotools, enabling seamless cross-compilation without requiring a separate x86\_64 build environment.

images · high confidence

EXT4 support gains journaling, expanded I/O, and improved unpacking reliability

The ContainerizationEXT4 module now supports creating ext4 images with a JBD2 journal, configurable via a new \journal\ parameter on the \EXT4.Formatter\. It introduces new public APIs for reading ext4 devices, including \EXT4Reader\ methods to list directories, read file contents, and resolve paths, alongside a new \PathIOError\ type. Unpacking reliability is improved by enforcing progress event value types, creating missing parent directories for hardlinks, and preventing infinite loops and disk space leaks when unpacking corrupt or zstd-compressed layers. Additionally, the module fixes several behavioral issues: it now correctly handles 32-bit UIDs/GIDs by combining high and low bits, rejects '..' path components that escape the image root, rejects non-ASCII xattr names, and fixes date/time handling and xattr read loop bounds.

Sources/ContainerizationEXT4 · high confidence

Enhanced container process execution and environment enforcement

The vmexec component now provides stricter adherence to the OCI runtime specification. It enforces masked and read-only paths by bind-mounting /dev/null or tmpfs as appropriate, and supports read-only root filesystems. Process execution now correctly resolves relative executable paths against the working directory, creates missing working directories, and applies user-specified permissions to standard I/O file descriptors. Additionally, exec processes now join the container's IPC namespace to ensure correct visibility of IPC objects, and the system supports a broader range of resource limits (rlimits).

vminitd/Sources/vmexec · high confidence

IO Writer protocol gains close method

The Writer protocol in the Containerization IO module now includes a close() method, allowing consumers to explicitly signal the end of a write stream. This change also updates copyright headers across the affected files to reflect the 2025-2026 period.

Sources/Containerization/IO · high confidence

Image unpacking refactored to use EXT4Unpacker and improved digest validation

The \Image\ and \InitImage\ types in the Containerization module have been updated to improve robustness and clarity. The \Image\ struct now validates digests using \validatedDigestEncoding()\ instead of \trimmingDigestPrefix\, ensuring that malformed digests are treated as errors rather than silently producing partial reference lists during garbage collection. Additionally, the macOS-specific \unpack\ method has been removed from \Image\ and replaced with a dedicated \EXT4Unpacker\ component; \InitImage\ now uses this unpacker with a parameter renamed from \blockSizeInBytes\ to \capacityInBytes\ for better semantic accuracy. Error messages have also been standardized to lowercase.

Sources/Containerization/Image · high confidence

ImageStore API improvements: public types, configurable concurrency, and safer state management

The ImageStore module now exposes previously internal types (ExportOperation, ImportOperation) and methods (create, get with pull-on-miss) as public, allowing external code to manage image exports and imports directly. Import operations now support configurable concurrent layer downloads (defaulting to 3) to improve pull performance. State persistence is hardened: state.json is written atomically to prevent corruption, and the reference manager tolerates malformed descriptor entries by skipping them rather than failing the entire store load. Additionally, the store provides a new calculateOrphanedBlobsSize() method to inspect disk usage without deletion, and the default store is now accessible via a static default property.

Sources/Containerization/Image/ImageStore · high confidence

Improved mount target resolution and cross-platform flag support

The Mount API now resolves mount targets securely within the container's rootfs, preventing symlink escapes and automatically creating missing directories or files at the mount point. Additionally, the internal mount flag type is now adapted to the platform (Int for glibc, Int32 otherwise) to ensure correct flag sizes, and the module has been updated to optionally import FoundationEssentials.

Sources/ContainerizationOS/Mount · high confidence

Keychain API refactored with access group support and new listing capability

The Keychain helper APIs have been updated to support keychain access groups, allowing callers to specify an optional access group when saving, deleting, or retrieving entries. The API surface has also been renamed for clarity: the \save\, \delete\, and \get\ methods now use \securityDomain\, \hostname\, \username\, and \password\ parameters instead of the previous \id\, \host\, \user\, and \token\ naming. Additionally, a new \list\ function has been added to retrieve metadata for all keychain entries within a specific security domain, and a new \RegistryInfo\ struct has been introduced to hold this metadata. The \KeychainQueryResult\ struct has been updated to expose \username\ and \password\ fields instead of \account\ and \data\.

Sources/ContainerizationOS/Keychain · high confidence

OCI Registry client adds catalog listing, referrers API, and security hardening

The RegistryClient now supports listing repositories via the OCI catalog API (GET /v2/\_catalog) with optional prefix filtering and pagination, and querying for referrers using the OCI 1.1 referrers API with a fallback to the tag-based schema when the API is unavailable. Authentication flows are hardened to prevent insecure credential exchanges by validating that token requests stay within the same registrable domain and use HTTPS, and by rejecting redirects or nested authentication challenges. Local OCI layout handling is secured by enforcing that control files are regular files (no symlinks) and enforcing a size limit to prevent memory exhaustion. The KeychainHelper has been renamed and refactored to support access groups and list operations, and error messages are standardized to lowercase with improved context from registry error responses.

Sources/ContainerizationOCI/Client · high confidence

OCI spec compliance, security hardening, and platform normalization

This update brings the OCI implementation closer to the OCI Image and Runtime specifications while improving security and platform handling. Security is strengthened by redacting environment variable values in debug logs (Spec+Redaction.swift) and validating content digests to prevent path traversal attacks during descriptor decoding (Descriptor.swift). OCI 1.1 support is added by introducing \subject\ and \artifactType\ fields to Index, Manifest, and Descriptor structs, and by adding a \com.apple.containerization.index.indirect\ annotation key. Platform handling is refined: \Platform\ now normalizes architecture strings (e.g., \aarch64\ to \arm64\) and omits the redundant \v8\ variant in descriptions for \arm64\, ensuring consistent equality and hashing. The runtime spec \hooks\ field is changed from a single \Hook\ to a \Hooks\ collection. Seccomp profile decoding now explicitly rejects Docker-format profiles to prevent silent permission escalation. Bundle deletion on Linux now safely checks if the rootfs is a mountpoint before attempting to unmount. Reference name length limits are raised to 255 to match the OCI spec, and error messages are standardized to lowercase.

Sources/ContainerizationOCI · high confidence

Refactor archive I/O to support zstd decompression and simplified file writing

The \ContainerizationArchive\ module has been refactored to improve performance and simplify the API. It now supports reading archives compressed with zstd by introducing a new \ZstdArchiveSource\ that decompresses data in-memory via libarchive callbacks, avoiding temporary disk files. The previous delegate-based writing architecture (\ArchiveWriterDelegate\, \FileArchiveWriterDelegate\) has been removed in favor of direct file and file descriptor operations on \ArchiveWriter\, making it easier to create archives. Additionally, error messages have been standardized to lowercase, and the \ArchiveReader\ now exposes a streaming iterator for more efficient memory usage when processing large archives.

Sources/ContainerizationArchive · high confidence

Refactored kernel build system and updated arm64 configuration

The kernel build process has been refactored to use a containerized approach via a new \build.sh\ script and updated \Makefile\, replacing the previous direct build steps. The arm64 kernel configuration (\config-arm64\) has been updated to enable CIFS/SMB support, enable memory cgroup v1 and cpuset v1, and disable the vsockets loopback and virtio-gpu drivers. Additionally, a new x86\_64 kernel configuration (\config-x86\_64\) has been added, and the build infrastructure now supports cross-compilation for x86\_64 from an arm64 host.

kernel · high confidence

Standardizes ReadStream property names and exposes Error enum

The ReadStream class in the ContainerizationIO module has been refactored to standardize internal property naming by removing the leading underscore prefix from private variables (e.g., \_buffSize, \_data, \_url). Additionally, the nested Error enum and its description property have been made public, allowing external code to explicitly handle or inspect stream-related errors.

Sources/ContainerizationIO · high confidence

Thread-safe socket operations and new bidirectional relay

The Socket class now uses a Mutex to protect its internal state, ensuring thread-safe access for operations like connect, listen, and close, replacing the previous SendableProperty-based synchronization. Additionally, a new BidirectionalRelay class has been introduced to manage data relay between two file descriptors using non-blocking I/O with backpressure, preventing head-of-line blocking and resource leaks. The UnixType socket implementation also now correctly limits the socket path length on Linux to prevent buffer overflows, aligning with the sun\_path size.

Sources/ContainerizationOS/Socket · high confidence

cctl CLI: New Linux bridge management, enhanced image pull/unpack, and expanded container run options

The cctl CLI now includes a new \bridge\ command on Linux for creating and deleting the host network bridge and NAT plumbing used by \cctl run\. Image pulling has been improved with an \--unpack-path\ option to specify a custom directory for unpacking images, and the command now reports pull and unpack durations. The \login\ command now enforces HTTPS for authentication and uses platform-specific keychain helpers. The \rootfs create\ command has been simplified to accept a prebuilt rootfs tar archive instead of requiring separate vminitd and vmexec binaries. The \run\ command now supports block device attachments via \--block\ (including NBD), read-only root filesystems, custom seccomp profiles, capability additions, and entrypoint overrides.

Sources/cctl · high confidence

vminitd restructured into a modular CLI with removed legacy container management components

The vminitd application has been refactored from a monolithic server into a modular command-line tool using ArgumentParser, introducing subcommands for Agent, Init, and Pause operations. This change removes the legacy ManagedContainer, ManagedProcess, ProcessSupervisor, and associated IO handlers (StandardIO, TerminalIO) that previously handled container lifecycle and I/O relay, replacing them with a new architecture centered around VminitdCore. The entry point now supports invocation as .cz-init for direct init mode, mounts /proc if necessary, and retrieves command-line arguments from /proc/self/cmdline to handle edge cases in PID 1 environments.

vminitd/Sources/vminitd · high confidence

Test coverage

Added tests for CloudHypervisor client, containerization networking, and DNS validation; Added tests for ContainerizationExtras concurrency primitives and networking types; Added tests for EXT4 filesystem operations and security hardening; Added tests for EXT4 unpacking, export security, and image store operations; Added tests for archive reader security and directory archiving; Added tests for cctl block argument parsing and run command resolution; Added unit tests for ContainerizationOS and VminitdCore components; Expanded test coverage for ContainerizationOCI security and content handling; Expanded test coverage for Netlink session operations and data types; Integration tests for cctl run command resolution and runc-backed containers/pods; Removed SendableProperty macro tests; Removed SendablePropertyMacrosTests.

Dependencies

Dependency upgrades and example package additions

The project dependencies have been updated across multiple manifests: the main package and vminitd now use grpc-swift-2 (2.4.2) instead of grpc-swift (1.26.0), alongside upgrades to swift-nio (2.101.3), swift-log (1.14.0), swift-argument-parser (1.8.2), swift-crypto (3.15.1), and others. The main package also adds zstd (1.5.7) and swift-certificates. Two new example packages, ctr-example and sandboxy, have been added with their own dependency pins (ctr-example uses containerization 0.33.4 and grpc-swift-2 2.4.1; sandboxy uses containerization 0.30.0 and grpc-swift 1.27.4).

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 49 → 62 (+12.8)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 85 (-15.4)
  • Architecture 98 (new)
  • Maturity 65 → 72 (+6.4)
  • Readiness 26 → 54 (+28.1)
  • Security 66 → 56 (-9.4)

Resolved (23)

  • Dimension evaluation failed
  • High IaC: DS-0002 (Tests/TestImages/dockermanifestimage/Dockerfile)
  • High IaC: DS-0002 (Tests/TestImages/emptyimage/Dockerfile)
  • High IaC: DS-0002 (vminitd/.devcontainer/Dockerfile)
  • High IaC: DS-0021 (vminitd/.devcontainer/Dockerfile)
  • High IaC: DS-0029 (kernel/image/Dockerfile)
  • High IaC: DS-0029 (kernel/image/Dockerfile)
  • High IaC: DS-0029 (vminitd/.devcontainer/Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • Low IaC: DS-0005 (Tests/TestImages/dockermanifestimage/Dockerfile)
  • Low IaC: DS-0005 (Tests/TestImages/emptyimage/Dockerfile)
  • Low IaC: DS-0026 (Tests/TestImages/dockermanifestimage/Dockerfile)
  • Low IaC: DS-0026 (Tests/TestImages/emptyimage/Dockerfile)
  • Low IaC: DS-0026 (images/linux-dev/Dockerfile)
  • Low IaC: DS-0026 (kernel/image/Dockerfile)
  • Low IaC: DS-0026 (vminitd/.devcontainer/Dockerfile)
  • No automated tests
  • …and 3 more

New (297)

  • ArchiveReader.extractEntry (cognitive 16) (Sources/ContainerizationArchive/ArchiveReader.swift)
  • ArchiveWriter.archive (cognitive 22) (Sources/ContainerizationArchive/ArchiveWriter.swift)
  • BidirectionalRelay.copy (cognitive 29) (Sources/ContainerizationOS/Socket/BidirectionalRelay.swift)
  • CHHotplugProvider.releaseVirtioFS (cognitive 18) (Sources/Containerization/CHHotplugProvider.swift)
  • CHStdioPortSlot.acceptLoop (cognitive 28) (Sources/Containerization/CHStdioPortSlot.swift)
  • CHStdioPortSlot.acceptLoop (cyclomatic 17) (Sources/Containerization/CHStdioPortSlot.swift)
  • CHVirtualMachineInstance.buildVmConfig (cognitive 28) (Sources/Containerization/CHVirtualMachineInstance.swift)
  • CHVirtualMachineInstance.buildVmConfig (cyclomatic 18) (Sources/Containerization/CHVirtualMachineInstance.swift)
  • Cgroup2Manager.readIOStats (cognitive 20) (vminitd/Sources/Cgroup/Cgroup2Manager.swift)
  • Cgroup2Manager.readIOStats (cyclomatic 17) (vminitd/Sources/Cgroup/Cgroup2Manager.swift)
  • Cgroup2Manager.removeChildCgroups (cognitive 16) (vminitd/Sources/Cgroup/Cgroup2Manager.swift)
  • Change coupling: ExecCommand.swift ↔ RunCommand.swift (vminitd/Sources/vmexec/ExecCommand.swift)
  • Change coupling: Package.swift ↔ Package.swift (Package.swift)
  • Change coupling: Suite.swift ↔ RunCommand.swift (Sources/Integration/Suite.swift)
  • ClassTooLong: IntegrationSuite (Sources/Integration/Suite.swift)
  • ClassTooLong: NetlinkSession (Sources/ContainerizationNetlink/NetlinkSession.swift)
  • Configuration.toVZ (cognitive 31) (Sources/Containerization/CHVirtualMachineInstance.swift)
  • Configuration.toVZ (cyclomatic 20) (Sources/Containerization/CHVirtualMachineInstance.swift)
  • Coverage not measured — Swift suite
  • Duplicated block (10 lines × 2) (Sources/Containerization/LinuxContainer.swift)
  • …and 277 more

Changes since last survey

  • 31 commits — 27 feature/other, 4 fixes

By area

  • Sources/Containerization — 12 commits
  • Sources/ContainerizationOCI — 4 commits
  • Sources/Integration — 4 commits
  • Sources/ContainerizationEXT4 — 3 commits
  • (root) — 2 commits
  • vminitd/Sources — 2 commits
  • Sources/ContainerizationArchive — 1 commit
  • Sources/ContainerizationExtras — 1 commit
  • Sources/ContainerizationOS — 1 commit
  • examples/sandboxy — 1 commit

Notable commits

  • fix: Fix TokenResponse serialization (#919)
  • fix: Fix socket forwarding hangs and shared I/O stalls (#933)
  • fix: chore: fix docs (#920)
  • fix: fix: efsck searching for external journal (#856)
  • change: Add Pi agent support to sandboxy (#850)
  • change: Add filesystem stats in ContainerStatistics (#930)
  • change: Add logic to cctl to enable NBD mounts (#903)
  • change: Align CIDR containment and bounds with CIDRv4 and CIDRv6 (#827)
  • change: Allow a LinuxPod to launch its containers with an OCI runtime (#936)
  • change: Confine vminitd copy/stat path resolution to the container rootfs
  • change: Do not free an inode that still has other hard links (#928)
  • change: Do not overflow socket sun_path on macOS
  • change: EXT4: reject '..' components that escape the image root during unpack (#897)
  • change: Ensure oci-layout and index.json files are regular files
  • change: ImageStore: write state.json atomically (#835)
  • change: Improve security across containerization (#898)
  • change: LinuxContainer: finish the copyOut metadata stream on every path (#837)
  • change: LinuxContainer: stop the VM when setup fails after start (#836)
  • change: Remove security markdown in favor of inherited security guidelines (#915)
  • change: Route a Logger through ContainerManager (#843)
  • …and 11 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

apple/containerization was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit bc994b88df46207fad7775b0eabc51947e315881 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.