fix(compose): pass CDI device names through unchanged - #5236
Merged
Merged
Conversation
Compose expanded every devices entry to source:target:permissions, so a CDI qualified name reached nerdctl run as a malformed host path and the container failed to create. Signed-off-by: Adam Clettborn <a.clettborn@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
nerdctl composecannot start a service that requests a CDI device, although the Compose spec allows a CDI qualified name indevices:nerdctl run --device vendor.com/class=nameworks on current main, and Docker Compose starts the same project.Cause
The service parser formats every
devicesentry as--device=<source>:<target>:<permissions>. compose-go fills in the target and permissions for a short entry, so a CDI name gets:vendor.com/class=name:rwmappended.nerdctl runonly treats--deviceas a CDI device when the whole value is a qualified name, so it falls back to parsing a host path and fails.Fix
When the source is a CDI qualified name (
cdiparser.IsQualifiedName), pass it as--device=<name>. Host device entries keep the existing format.Verification
Built from this branch and from its parent commit, and run with
nerdctl compose upagainst a CDI spec whose device only sets an env var. Tested on containerd 2.2.1 and runc 1.3.3. The same project and spec were run through Docker Compose 5.5.0 on Docker 29.7.2 for comparison.devicesentryvendor.com/class=namefailed to parse device, container never created/dev/null:/dev/probe/dev/probepresent/dev/probepresent/dev/probepresent/dev/null:/dev/probe:rw/dev/probepresent/dev/probepresent/dev/probepresentTest
TestParseDevicesgains a CDI entry and asserts it becomes--device=vendor.com/class=name.