Skip to content

fix(compose): pass CDI device names through unchanged - #5236

Merged
AkihiroSuda merged 1 commit into
containerd:mainfrom
invenconlabs:fix/compose-cdi-devices
Oct 2, 2026
Merged

AkihiroSuda merged 1 commit into
containerd:mainfrom
invenconlabs:fix/compose-cdi-devices

Conversation

@addemod

@addemod addemod commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Problem

nerdctl compose cannot start a service that requests a CDI device, although the Compose spec allows a CDI qualified name in devices:

services:
  probe:
    image: alpine
    devices:
      - vendor.com/class=name
FATA[0000] failed to parse device "vendor.com/class=name:vendor.com/class=name:rwm": "vendor.com/class=name" is not an absolute path

nerdctl run --device vendor.com/class=name works on current main, and Docker Compose starts the same project.

Cause

The service parser formats every devices entry as --device=<source>:<target>:<permissions>. compose-go fills in the target and permissions for a short entry, so a CDI name gets :vendor.com/class=name:rwm appended. nerdctl run only treats --device as a CDI device when the whole value is a qualified name, so it falls back to parsing a host path and fails.

Fix

When the source is a CDI qualified name (cdiparser.IsQualifiedName), pass it as --device=<name>. Host device entries keep the existing format.

Verification

Built from this branch and from its parent commit, and run with nerdctl compose up against a CDI spec whose device only sets an env var. Tested on containerd 2.2.1 and runc 1.3.3. The same project and spec were run through Docker Compose 5.5.0 on Docker 29.7.2 for comparison.

devices entry unpatched patched Docker Compose
vendor.com/class=name failed to parse device, container never created ran, env from the CDI spec injected ran, env from the CDI spec injected
/dev/null:/dev/probe ran, /dev/probe present ran, /dev/probe present ran, /dev/probe present
/dev/null:/dev/probe:rw ran, /dev/probe present ran, /dev/probe present ran, /dev/probe present

Test

TestParseDevices gains a CDI entry and asserts it becomes --device=vendor.com/class=name.

Compose expanded every devices entry to source:target:permissions, so a CDI qualified name reached nerdctl run as a malformed host path and the container failed to create.

Signed-off-by: Adam Clettborn <a.clettborn@gmail.com>
@AkihiroSuda AkihiroSuda added this to the v2.4.1 milestone Oct 2, 2026

@AkihiroSuda AkihiroSuda left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks

@AkihiroSuda
AkihiroSuda merged commit 277b1c0 into containerd:main Oct 2, 2026
75 of 88 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants