402 Commits
Author SHA1 Message Date
12 05edeac562 Ignore commented-out bootptab reservations (#1358) 2026-09-30 11:32:27 +00:00
edi-oai 917c0b51ed --net-host: use VZVmnetNetworkDeviceAttachment with VMNET_HOST_MODE (#1356) 2026-09-28 22:36:09 +01:00
RKSandYibo Zhuang e3b4f71f77 fix(control-socket): recover from transient accept errors (#1351)
* fix(control-socket): recover from transient accept errors

Keep the control socket alive when Darwin reports a transient fcntl failure while accepting a client connection.

Refs #1346

* test(control-socket): use synchronous pipeline lookup

* test(control-socket): query handler on event loop

* fix(control-socket): preserve channel backpressure

* test(control-socket): exercise accept error recovery

* test(control-socket): verify accepts continue after transient errors

Check that the real server inbound stream yields a client connection after
each simulated accept error. Keep the read-routing and unrelated-error
checks, bound the wait, and close the test connections.

Adapted from the regression test suggested in:
https://github.com/openai/tart/pull/1351#issuecomment-5851285933

---------

Co-authored-by: Yibo Zhuang <yzhuang@openai.com>
2026-09-28 13:22:06 -07:00
RKS e92c3b900f Protect existing VMs during clone (#1331)
* fix(clone): protect existing VMs from overwrite

* fix(clone): preserve incomplete destination directories
2026-09-28 12:58:03 -07:00
edi-oai 5c1c6bd315 tart ip: read /etc/bootptab in addition to /var/db/dhcpd_leases (#1355) 2026-09-28 16:49:06 +01:00
Minh Vu a80ec74a42 Preserve modification date when updating access time (#1292) 2026-09-26 08:45:14 -07:00
RKS 8ac52501c3 fix(storage): preserve running VM delete errors (#1350)
* fix(storage): preserve running VM delete errors

Do not reinterpret RuntimeError.VMIsRunning as a missing VM when the storage wrapper bridges errors through NSError.

Refs #1345

* test(storage): initialize running VM lock file

* test(storage): hold VM lock in a child process

* fix(storage): narrow file-not-found error matching

* test(storage): use Swift error-domain regression coverage
2026-09-26 08:40:20 -07:00
Yoshimasa Niwa bb4acb2468 Fix listing VMs when disk capacity is unavailable (#1349)
* Allow HumanReadableByteCount to represent an unknown byte count

Some byte counts, such as the capacity of an ASIF disk image, can't
always be determined. Accept an optional byte count and render an
unknown value as "-" in text output and as null in JSON output.

* Fix listing and getting VMs when disk capacity is unavailable

For ASIF disk images, the disk capacity is read with "diskutil image
info". The command fails with "Resource temporarily unavailable" while
a running VM holds the disk image open. As a result, "tart list" and
"tart get" fail entirely when any such VM exists.

Treat the disk capacity as unknown when it can't be determined, so
that both commands still show the remaining information.

Fixes #1344

* Remove unused VMDirectory.diskSizeGB()

The method was added together with diskSizeBytes() but has never been
used. "tart list" and "tart get" use diskSizeBytes() directly.
2026-09-25 17:08:34 -07:00
om singhal 65aea029ab Use registry-1.docker.io for Docker Hub's docker.io host (#1332)
* Use registry-1.docker.io for Docker Hub's docker.io host

docker.io doesn't serve the registry API: https://docker.io/v2/ redirects
to https://www.docker.com/, which URLSession follows, getting back an HTML
page with HTTP 200. As a result, pushing fails with
UnexpectedHTTPStatusCode("pushing blob (POST)", 200, ...), pulling fails
to parse the manifest and "tart login docker.io" accepts any credentials,
because ping() never gets an authentication challenge.

Send the API requests for docker.io to registry-1.docker.io instead, while
still using docker.io for the pushed image names and for the credentials
lookup, so that credentials saved with "tart login docker.io" keep working.

Fixes #1275

* Match docker.io case insensitively

* Recognize Docker Hub with an explicit port

* Parse the registry host once and keep it normalized

Using the host exactly as specified for naming and credentials lookup
changed the behavior for other registries too. For example,
"127.0.0.1:05000" used to find credentials stored for "127.0.0.1:5000",
but didn't anymore.

Parse the URL once instead, take the normalized host and port from it
like before, and only replace the URL's host with registry-1.docker.io
for Docker Hub.
2026-09-24 14:00:30 -07:00
12 4e58a2a0b9 Fix export overwrite confirmation on EOF (#1342) 2026-09-23 15:10:01 -07:00
Yibo Zhuang f8ce0f9acb Add an option to disable USB accessories (#1338)
* Add an option to disable USB accessories

* Select USB accessories in platform input factories
2026-09-23 12:14:39 -07:00
Brendan Shanks 89017ff0b3 VMConfig: Save JSON with sorted keys (#1326) 2026-09-16 16:24:50 -07:00
edi-oai acaf3ca7ef ControlSocket: duplicate VirtIO socket connection's file descriptor (#1333) 2026-09-16 11:37:56 +01:00
Sam EstepandClaude Opus 5 9bb2af2434 Run ErrorReportingTask operations on the caller's actor (#1324)
VZVirtualMachine asserts that it is used on the queue it was created with,
which for tart is the main queue. Since #1262 replaced the unstructured Task
in "tart run"'s SIGUSR2 handler with ErrorReportingTask, that assertion fails:
Task.init carries @_inheritActorContext, but ErrorReportingTask.init did not,
so an operation written inside MainActor-isolated Run.runOnMainThread() is formed
in a nonisolated init and runs on the cooperative pool, not the main queue.

The result is that asking a VM to stop gracefully kills it instead. Sending
SIGUSR2, which #842 hooked to requestStop() for exactly this purpose, crashes
the process:

    Thread 1  queue: com.apple.root.default-qos.cooperative
      _dispatch_assert_queue_fail
      dispatch_assert_queue
      -[VZVirtualMachine requestStopWithError:]
      closure in Run.runOnMainThread()
      closure in ErrorReportingTask.init(_:operation:)

The guest then loses power without a chance to flush, and on a Linux guest
with ext4's default delayed allocation that discards whatever had not been
written back yet. The same applies to the requestStop() in
applicationShouldTerminate(), i.e. closing the window of a VM run with a GUI.

Give the operation the same @_inheritActorContext that Task.init has, so that
wrapping a call in ErrorReportingTask no longer changes where it runs.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-09 15:05:42 -07:00
Yibo Zhuang cdb3579c79 Fix control socket paths with special characters (#1328) 2026-09-07 10:40:58 -07:00
Yibo Zhuang 3f15df9e3c Preserve stdout when running Softnet without a control FD (#1329) 2026-09-07 09:37:51 -07:00
Yibo Zhuang 1b4813f210 Preserve running VM directories during replacement (#1321) 2026-09-01 18:20:18 -07:00
Yibo Zhuang 5f8795bd4e Complete stacked disk command support (#1315) 2026-08-17 15:20:50 -07:00
Yibo Zhuang f83cba84af Support stacked VM archive import and export (#1314) 2026-08-17 14:22:18 -07:00
Yibo Zhuang 32a627c8c5 Make stacked content pruning reference-aware (#1313) 2026-08-17 13:05:07 -07:00
Yibo Zhuang 4162ca1831 Fail VM startup when its control socket cannot bind (#1311) 2026-08-17 11:59:39 +01:00
Yibo Zhuang 4ce8a115f7 Add OCI transport and base clone with DiskImageKit (#1304)
* Add OCI transport and base clone with DiskImageKit

* Address stacked OCI pull review feedback

* Stream file digest hashing

* Lock frozen overlays during push
2026-08-12 12:10:28 -07:00
Yibo Zhuang f87b57bbc5 Begin work on adding DiskImageKit to tart (#1303)
This is first of several changes to add support for the new
DiskImageKit ASIF layers to tart VM images.

This change is focused on laying down the OCI media type for
ASIF layers, content addressable store structure, as well
as the VMDirectory structure for supporting layers.

Add DiskImageStack type to model VM image using DiskImage APIs.
2026-08-11 09:13:25 -07:00
edi-oai a438e2d031 tart {list,get}: display humanized byte units (#1301) 2026-08-05 22:11:37 +01:00
Fedor Kororkov cbc160a592 Pass Softnet policy control FD through Tart (#1287)
* Pass Softnet policy control FD through Tart

* Update Softnet control test for policy set
2026-07-21 22:23:08 +01:00
Nikolai TillmannandClaude Fable 5 512c1c3630 Fix busy loop in tart exec -i after piped stdin reaches EOF (#1281)
Unregister the stdin readabilityHandler when availableData returns empty:
a closed pipe fd stays permanently readable, so Foundation re-invokes the
handler in a tight loop (fstat + zero-byte read) at 100% of one core for
the rest of the command's lifetime.

Fixes #1280

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 08:56:27 -04:00
Fedor Kororkov 9e6e59b379 [codex] Publish Tart to openai/homebrew-tools (#1277)
* Publish Tart to openai/homebrew-tools

* Write Tart formula under Formula directory

* Use macOS 26 runners

* docs: install Tart tools from OpenAI tap

* Add required GitHub Actions test check

* Fix hosted tests and notarization credentials
2026-07-16 21:32:18 -04:00
Tor Arne Vestbø 0a01a4430c Fix build warnings (#1262)
* Use let for the immutable disk image storage attachment

* Don't bind the unused error when catching connection-pool failures

* Report errors thrown inside tart run's fire-and-forget tasks

We were discarding any error thrown inside these unstructured tasks,
which silently hid failures to run the control socket or to start and
stop the VM, and which the compiler now warns about.

Wrap them in an ErrorReportingTask, which spawns the task and reports
any thrown error to stderr, rather than repeating a do/catch at every
call site. An unstructured task spawned from a synchronous context (a
signal handler or SwiftUI action) has no parent to propagate the error
to, so reporting it is the best we can do.

* Avoid blocking SwiftNIO calls in async guest agent connections

The gRPC channel setup in "tart exec" and the MAC address resolver
created a dedicated event loop group and tore both it and the channel
down with the blocking syncShutdownGracefully() and wait(), which are
unavailable from async contexts (the former is an error in the Swift 6
language mode).

Factor the connection out into a withGuestAgentChannel() helper that
uses the process-wide singleton event loop group, so there is no group
to shut down, and closes the channel with the async close().get().
2026-06-09 15:29:19 -07:00
Tor Arne Vestbø d1bfda63fc Add --provisioning-opts flag to provision macOS guests on first boot (#1263)
Exposes Apple's macOS 27 guest provisioning API
(VZMacGuestProvisioningOptions) so a macOS guest can be set up
automatically on the first boot after restore.

The flag takes a comma-separated list of key=value pairs mapping 1:1 to
the API properties (fullName, username, password, logsInAutomatically,
enablesRemoteLogin). It is validated to require a macOS 27+ host and a
macOS VM.

The entire user-facing surface is gated behind
'#if arch(arm64) && compiler(>=6.4)' so the flag doesn't appear in help
on toolchains that lack the macOS 27 SDK, while the runtime
'#available(macOS 27, *)' check gates actual use against the host OS.
2026-06-09 15:18:57 -07:00
Tor Arne Vestbø 2e63759c1b Don't run the AppKit run loop nested in Swift's async main (#1260)
When built against the macOS 27 (Xcode 27, Swift 6.4) SDK, "tart run"
brings up the VM window but the guest never boots.

Swift's asynchronous main() entry point implicitly starts an executor
that owns the main thread, and as of Swift 6.4 that executor is no
longer backed by the Dispatch main queue. Running an AppKit/SwiftUI
run loop nested inside it via MainApp.main() leaves the main run loop
unable to drain Swift tasks or DispatchQueue.main, so the task that
starts the VM is never scheduled, even though the window itself
(driven directly by AppKit during launch) still appears.

We now keep Root.main() synchronous, so that a command driving a run
loop can own the main thread at the top level, exactly like a plain
SwiftUI app. With AppKit owning the loop again, MainActor tasks and
the Dispatch main queue drain as before. Such commands opt in through
a new MainThreadCommand protocol; everything else keeps running
asynchronously via a detached task and dispatchMain().

Verified that the guest boots again, and that Ctrl+C still stops the
VM gracefully.
2026-06-09 09:53:06 -07:00
Nikolay Edigaryev 605234b5dd Mention macOS Tahoe everywhere instead of macOS Sequoia (#1208)
* Mention macOS Tahoe everywhere instead of macOS Sequoia

* Fix spurious rename
2026-03-02 08:50:29 -05:00
faa40b6832 Remove disk v1 support (#1204)
* Remove disk v1 support

* fix: address PR review feedback

- add explicit error for legacy disk.v1 media type during pull
- include actionable re-push guidance in runtime error

🤖 Generated with [Codex](https://chatgpt.com/codex)

Co-Authored-By: Codex <codex@openai.com>

* Re-use legacyDiskV1MediaType in error message

---------

Co-authored-by: Codex <codex@openai.com>
Co-authored-by: Nikolay Edigaryev <edigaryev@gmail.com>
2026-02-25 14:34:25 +00:00
Nikolay Edigaryev d45ef38cf7 StdinCredentials: increase maxCharacters to 8,192 (#1203) 2026-02-23 18:55:52 +01:00
Nikolay Edigaryev e26b376d51 tart list: remove "SizeOnDisk" and add "Accessed" field (#1202)
* tart list: introduce "Accessed" field to show last accessed date of a VM

* tart list: remove "SizeOnDisk" field as it's unused
2026-02-23 18:55:36 +01:00
Nikolay Edigaryev 863e3c2925 Bind and connect to Unix domain sockets using relative paths (#1192) 2026-02-05 15:51:14 +01:00
Nikolay Edigaryev f1aa591935 OpenTelemetry: set default resources, service.name and service.version (#1184)
* OpenTelemetry: set default resources, service.name and service.version

* Ensure that service name and version resources are set
2026-01-27 16:17:05 +01:00
Fedor KorotkovandClaude Opus 4.5 6189dc23af Fix VM window not appearing on tart run (#1183)
Restore the applicationDidFinishLaunching method that was accidentally
removed in commit b1e88e1 ("tart run: do not remove 'Edit' menu as its
not present anymore").

That commit intended to remove the Edit menu removal code (since the
menu no longer exists), but also removed the crucial activation code:
- setActivationPolicy(.regular) - tells macOS this is a GUI app
- activate(ignoringOtherApps:) - brings the window to the foreground

Without these calls, the VM runs fine (SSH works) but no window appears
on screen.

Fixes #1181

Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-23 15:16:33 -05:00
Nikolay Edigaryev e0147448a8 OpenTelemetry: only initialize tracing when TRACEPARENT env. var. is set (#1182) 2026-01-23 14:57:53 +01:00
Nikolay Edigaryev 7038c45f8b Switch to OpenTelemetry (#1179)
* Switch to OpenTelemetry

* Integration tests in Golang
2026-01-23 12:04:21 +01:00
Nikolay Edigaryev 44892c5def Refactor "diskutil create" and "diskutil info" into a separate class (#1172)
* Show true ASIF disk sizes

* Use older sizeGB()
2026-01-22 13:00:27 +01:00
Nikolay Edigaryev 20dcfc83f2 Disable Sentry's app launch profiling (#1164)
And access SentrySDK only when SENTRY_DSN is set.
2025-11-10 23:50:32 +04:00
Nikolay Edigaryev 68ffa6c5e4 tart set: support optional "pt" and "px" units for "--display" argument (#1155)
* tart set: support optional "pt" and "px" units for "--display" argument

* Don't forget to update "unit" too
2025-10-21 21:35:42 -04:00
Nikolay Edigaryev 1b091e9db0 tart run: introduce new "--net-softnet-block" command-line argument (#1156) 2025-10-21 21:14:43 +04:00
Eric Kolve 90d9500133 chore: adding no-keyboard, no-pointer options for run (#1091) 2025-10-09 15:29:28 -04:00
Nikolay Edigaryev d762fe6fc1 tart run: do not recommend running "tart run" as root (#1147) 2025-10-08 12:44:05 +00:00
Stefan MitterrutznerandNikolay Edigaryev eff964b62a Avoid duplicate progress updates in CI logs (#1140)
* Avoid duplicate progress updates in CI logs

* Update Sources/tart/Logging/ProgressObserver.swift

Co-authored-by: Nikolay Edigaryev <edigaryev@gmail.com>

---------

Co-authored-by: Nikolay Edigaryev <edigaryev@gmail.com>
2025-09-29 15:57:39 +04:00
Nikolay Edigaryev e3ee2da2fd Validate custom TART_HOME and provide a human-friendly error message (#1138)
* Validate custom TART_HOME and provide a human-friendly error message

* Safer way to calculate "descendingURLs"
2025-09-25 20:44:57 +04:00
Nikolay Edigaryev df100f1ca2 Improve credential provider errors (#1133) 2025-09-22 22:57:05 +04:00
Fedor Korotkov 02bf5651e7 tart clone: make pruning limit configurable (#1126)
* tart clone: make pruning limit configurable

* Fixed compilation
2025-09-14 12:38:57 -04:00
Fedor Korotkov 96c89ad76e tart clone: cap automatic pruning at 100 GB (#1124) 2025-09-14 09:40:58 -04:00