Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Podman Desktop on Mac uses weird user-pace IP stack which does direct socket allocations on the MAcOS host itself.

Additionally, Podman Desktop on Mac always return on ICMP echo, try running `ping 5.5.5.5` or any other non-ping-able IP and see it yourself.



Can you elaborate on the direct socket allocations?


You can see `tcp` sessions of the container using `netstat` on the host MacOS if you use Podman Desktop.

That's not the case if podman runs on a Linux VM on UTM for example. Additionally, ICMP behaves correctly in the later case.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: