Skip to content

Releases: stoopid-computers/luhmen

v0.1.0 development preview

Pre-release

Choose a tag to compare

@Geektrovert Geektrovert released this 11 Sep 18:32

Install through Homebrew on Apple Silicon Macs running macOS 14 or newer:

brew install Geektrovert/tap/luhmen

This installs the release binary and its runtime dependencies. Follow the one-time Docker plugin setup before running luhmen doctor.

luhmen v0.1.0 development preview

luhmen runs Docker Engine in a dedicated Linux VM on Apple Silicon Macs. Its Rust CLI manages Lima through Apple's Virtualization.framework. This first preview is for local development; commands, saved configuration, and JSON output can change before a stable release.

The CLI creates, starts, inspects, restarts, and stops the VM. Docker CLI, Compose, Buildx, and SDK clients connect through its luhmen Docker context. The wrapper keeps Docker's active context unchanged and uses a separate Buildx store. Images, containers, and named volumes persist across stops and restarts. New VMs enable Docker live restore so containers can keep running while the guest service recovers from a Docker daemon failure. Storage reports and an optional local HTTPS proxy are included.

Requirements and installation

Use an Apple Silicon Mac with macOS 14 or newer, at least 15 GiB of free space for VM creation, and internet access for image and package downloads. Lima must be exactly 2.2.0. The selected host client versions are Docker CLI 29.4.0, Compose 5.1.2, and Buildx 0.33.0. Docker Desktop is not required.

Release assets are separate:

  • luhmen-0.1.0-aarch64-apple-darwin.tar.gz contains the executable, documentation, and dependency license texts.
  • luhmen-0.1.0-source.tar.gz contains the source and build scripts. Building requires Rust 1.95.0, Apple's Command Line Tools, and Python 3.11 or newer.
  • SHA256SUMS contains the archive checksums. Verify the matching checksum before extracting an archive.

Install Lima and the Docker client plugins separately. The archives do not include them or a VM disk. The source archive includes scripts/install-lima.sh for installing the pinned Lima version; using that script does not require compiling luhmen. The binary has no Apple Developer ID signature or notarization. See the installation guide and quickstart.

Known limits

  • macOS 14 is the deployment minimum, but live VM behavior on macOS 14 and installation on a second machine remain unverified.
  • Containers use Linux arm64. Rosetta and x86 emulation are disabled.
  • CPU, memory, disk, and mount settings are fixed at VM creation. VM upgrades, data migration, backups, and disk reclamation are manual. Updating the CLI does not patch an existing guest.
  • Lima forwards host file changes as IN_ATTRIB notifications. Applications that require IN_MODIFY or exact create/rename/delete events need polling.
  • Live restore does not keep containers running through a VM shutdown or guarantee recovery after daemon configuration changes.
  • The pinned Ubuntu login service uses a workaround for a session-cleanup CPU spin. It retains its existing syscall restrictions. Sessions for which logind would open a pidfd use numeric PID/session FIFO tracking instead, losing pidfd-based protection against PID reuse. PAM can still supply a live pidfd. The workaround applies only to systemd 255.4-1ubuntu8.17; see runtime behavior.
  • Local HTTPS buffers HTTP/1 exchanges, needs manual certificate trust, and does not support WebSockets, CONNECT, or streaming.
  • VPN transitions, split DNS, authenticated proxies, IPv6, UDP forwarding, and sleep/wake behavior remain unverified.

See support limits. Report bugs through issues and vulnerabilities through the security policy. luhmen is licensed under Apache-2.0.

Verification

Source commit: bda529524b0ac1de03466f0f0443840615e7d6f8, matching the packaged executable's build-info.json.

  • macOS 14 and Ubuntu 24.04 CI passed. The dependency audit passed with no warnings; Cargo.toml, Cargo.lock, and the audit workflow are byte-identical to that audited commit.
  • The extracted source passed 52 Rust tests and 5 packaging tests, installed without Git, and included license texts for all 98 target dependencies.
  • Two fresh release builds produced identical source and binary archives with the same source commit, toolchain, SDK, and source timestamp. Cross-checkout byte equality is not claimed; an additional check found differences in Mach-O UUID and signature metadata.
  • The packaged executable passed real Buildx target-selection checks with default and custom external stores, including saved remote builders and a conflicting builder name. Both external stores stayed unchanged. These isolation checks used an intentionally unavailable Engine socket; actual build execution is covered separately by the VM checks below.
  • Packaged documentation passed 31 relative-link and anchor checks and syntax checks for 19 shell examples. The full-history secret scan reported no findings across twelve source commits.
  • Live VM checks passed on macOS 26.6.2 with Lima 2.2.0, Docker CLI 29.4.0, Compose 5.1.2, Buildx 0.33.0, and guest Docker Engine 29.8.0. The fresh guest used 2 CPUs, 2 GiB RAM, and a 20 GiB sparse disk. First boot reached Docker readiness in 39.3 seconds, and hello-world passed. VM creation reused the verified base-image cache; a prior uncached run verified the pinned NJU mirror download.
  • The integration suite passed Compose builds and HTTP, container limits, bidirectional file coherence, localhost port lifecycle, DNS, HTTP proxy fixtures, and Buildx caching. VM restart preserved volume data, mounts, and HTTP service in 40.0 seconds. A forced Docker daemon crash recovered in 2.8 seconds with live restore. The packaged wrapper also built, loaded, and ran an image successfully.
  • The suite recorded 36 passed results, five file-notification limitations described above, and eleven checks not run: VPN, split DNS, DNS TCP fallback, authenticated proxies, HTTPS CONNECT proxies, registry proxies, container NO_PROXY, external-peer port exposure, UDP, IPv6, and sleep/wake.
  • The login-service check passed 12 fresh SSH sessions, closing and reopening the owned persistent SSH connection, and a five-second idle CPU sample with zero CPU ticks and no dead pidfd. An initial diagnostic incorrectly required all pidfds to be absent; PAM can supply live pidfds. The corrected check verifies cleanup and CPU behavior. Closing the SSH master also closed its Docker socket forwarding; a normal VM restart restored it before the integration suite.
  • Fresh-guest checks used the executable packaged at 35e901a. The final documentation-only commit produced the identical executable, SHA-256 d353df62c7752d38c454af49c98e5f24c9345d4b807b4a6222223e58a04a5c0b. The final archive's executable passed the wrapper build and readiness checks. The dedicated test VM was stopped and removed after verification.
  • Private vulnerability reporting is enabled. The public advisory page exposes the reporting link, and the report route takes signed-out visitors to GitHub sign-in. No test report was submitted.