lighter 0.11.5
A port a container publishes that the Mac will not give lighter is no longer half open, no longer stays closed after the Mac lets go of it, and no longer fails without telling you.
What went wrong
When a container publishes a port, lighter opens it on the Mac on IPv4 (0.0.0.0) and IPv6 ([::]) separately. macOS refuses lighter a port that another user's program already holds on one of the Mac's addresses, whatever lighter asks for: Tailscale Serve sharing port 9000 on the Mac's tailnet address is one example. When that happened:
- One half opened anyway. The container answered on
localhost, which reaches IPv6, but not on127.0.0.1, and not to other containers throughhost.docker.internal, which is far harder to diagnose than a port that is simply closed. - Only a log file said so.
docker runandcompose upsucceeded,docker pslisted the port as published, and the container reported healthy. - Nothing tried again. Once the other program let go, the port stayed closed until some unrelated container happened to start or stop.
What changed
- A port is opened on every address it was published on, or on none. If the Mac refuses one, lighter closes the other rather than leave it half open.
- lighter tries again by itself, after a second at first and then less often, up to every 30 seconds, so the port opens shortly after whatever held it lets go.
- It tells you.
lighter statuslists each published port it could not open and why, andlighter doctorwarns about them. The log records the failure once, not on every attempt.
The refusal itself is macOS's, and every Docker runtime for the Mac meets it. If something on your Mac needs the same port, give one of them a different port.
Upgrading
brew upgrade lighter
lighter restart
Or lighter update download then lighter upgrade --restart if you installed with the install script. Containers with a restart policy come back by themselves; start the others again, as after any restart.
Also
- Linux remains 6.18.52 (kernel 6225825f, unchanged). The data epoch remains 1.
- Docker still reports success when it starts such a container. Failing the start, as Docker Desktop does, means lighter answering Docker's API itself, and is a change for another release.
Checksums
lighter-0.11.5-arm64.tar.gz: SHA25633f926b3b1ef227acd3ba9f6445b183f38cdf73fc1f051df59069107b3a4df8elighter-0.11.5-arm64(installer bootstrap): SHA2565d96fcf2f01d2432a26adaceb465a55d0a2037d278db7e86ea58e615631c72d0- Kernel 6225825f, rootfs a38cbd65. Notarization 241f1f06 accepted.