Skip to content

macOS guests 2/6: OCI machine-image integration - #499

Draft
chruffins wants to merge 1 commit into
spike/macos-guestsfrom
feat/macos-oci-images
Draft

chruffins wants to merge 1 commit into
spike/macos-guestsfrom
feat/macos-oci-images

Conversation

@chruffins

@chruffins chruffins commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Stack

PR 2/6 of the macOS guest integration stack. Depends on #498; kept draft while the machine-image schema and Windows integration are reconciled.

Summary

  • Accept complete darwin/arm64 machine bundles through the existing OCI image manager, rather than treating them as Linux root filesystems.
  • Validate version/kind/disk format, confined payload paths, matching auxiliary storage and platform configuration before marking an image ready.
  • Materialize the boot disk and auxiliary storage, preserve platform/identity metadata, and enforce requested-platform matching on cached reuse.
  • Support additional tags within the same repository; reject cross-repository promotion until all machine components are handled safely.
  • Add synthetic loopback registry round-trip/negative tests and document the experimental schema.

No Geranos dependency, new runtime transport, image delta format, or concurrent clone/rekey guarantee.

Validation

Passed focused tests:

  • TestMacOSMachineValidation and TestMacOSMachineOCIRoundTrip: reconstructed disk/aux hashes, manifest digest, config identity, cache reuse, same-repository tag and wrong-platform rejection.
  • Platform-resolution and existing TestTagImage* regressions.
  • Formatting and diff checks.

The test registry's PATCH path buffers uploads in memory, even with disk storage. The test seeds blobs through its streaming disk handler, publishes a manifest, then pulls through the normal HTTP image manager. This tests pull/materialization, not streaming OCI push.

Remaining draft gates

  • Real stopped-bundle round-trip and normal HTTP API pull-to-boot. The first real test was killed during the test registry upload, before Hypeman pull; no real round-trip or boot success is claimed.
  • Shared machine-image schema alignment with Windows work (Add OCI Windows machine images #429).
  • Broader auth/cancellation/failure/GC and Linux regression coverage; sparse storage measurements and cross-repository promotion.
  • Independent automated review is blocked by reviewer authentication (401), not reported as clean.

No live VM/API changes or committed VM images, credentials, benchmark tasks, traces, or private planning notes.


Note

Medium Risk
Changes image pull, conversion, and on-disk layout for darwin/arm64 artifacts and path validation for bundled files; Linux rootfs export is unchanged when labels do not denote a machine image.

Overview
Registry pulls for darwin/arm64 complete machine bundles now go through the normal image manager instead of being rejected as “local import only.” Manifests are recognized via experimental io.hypeman.machine-image.* labels; the build path validates confined disk/aux/platform paths, copies the raw boot disk (no Linux rootfs export), installs aux.img, and stores MacOS platform metadata on finalize.

Platform and tagging behavior loosens: resolveManifestPlatform accepts darwin/arm64 manifests, CreateImage checks cached ready images against an explicit --platform, and same-repository tags work for macOS bundles while cross-repository promotion stays blocked.

New parseMacOSMachine logic and OCI round-trip tests (synthetic loopback registry) cover validation and pull/materialization; docs describe the experimental OCI bundle schema and updated import vs registry capabilities.

Reviewed by Cursor Bugbot for commit fdc003f. Configure here.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit fdc003f. Configure here.

Comment thread lib/images/manager.go
if err != nil || !platform.Matches(actual) {
return nil, fmt.Errorf("%w: requested %s but cached manifest is %s", ErrInvalidPlatform, platform, cached.Platform)
}
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Empty platform fails cache reuse

Medium Severity

The new cached-reuse check calls ParsePlatform on stored cached.Platform and treats any parse error as a mismatch. Ready images from before platform tracking store an empty platform and are otherwise treated as the host. An explicit platform on CreateImage or instance create now fails reuse of those images with ErrInvalidPlatform instead of matching them as host-native.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit fdc003f. Configure here.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant