Skip to content

fix(drivers): validate vendor-agnostic CDI device names - #4306

Merged
alangou merged 1 commit into
mainfrom
fix/2-podman-device-validation/alangou
Oct 8, 2026
Merged

alangou merged 1 commit into
mainfrom
fix/2-podman-device-validation/alangou

Conversation

@alangou

@alangou alangou commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Reject host-device paths and malformed CDI selectors before Docker or Podman container creation, while preserving valid selectors from any vendor. Both drivers use shared CDI qualified-name validation for explicit requests and resolved device IDs.

Related Issue

No issue required: localized validation fix for the existing cdi_devices input.

Administrator-controlled CDI admission is a separate follow-up: #4327. Podman server inventory discovery is also being handled separately.

Changes

  • Add shared validate_cdi_device_names in openshell_core::gpu, using a local is_qualified_name implementation aligned with upstream CDI grammar.
  • Validate explicit selectors through a shared CDI-specific GPU-request wrapper for Docker and Podman, and validate resolved selectors at both drivers' production container-spec construction boundaries. Keep the generic GPU-request validator identifier-agnostic so VM PCI addresses remain valid.
  • Preserve NVIDIA index, UUID, MIG, and all selectors, and accept syntactically valid non-NVIDIA names without claiming additional GPU execution support.
  • Retain Podman create-preflight coverage and add shared parser and Docker/Podman explicit/resolved selector regressions.
  • Update published docs and the cluster debugging skill.
  • Track replacement of the local parser with the public upstream API in container-device-interface-rs PR #177.

Testing

  • mise run pre-commit (repository-wide lint, formatting, and license checks).
  • Changed-crate library tests: 900 passed, 1 ignored across openshell-core, openshell-driver-docker, and openshell-driver-podman.
  • Full VM library suite: 221 passed with e2fsprogs supplied through a temporary Nix shell, including all PCI-address selection regressions.
  • Changed-crate Clippy with all targets and -D warnings.
  • Rust formatting and git diff --check.
  • mise run docs: 0 errors and 3 Fern warnings.
  • Podman GPU E2E: not run locally for this update. Existing PR CI covered Podman E2E and Docker GPU E2E; the pushed revision requires fresh CI results.

Checklist

  • Follows Conventional Commits.
  • New commit is signed off for DCO.
  • Relevant user documentation and skill guidance updated.

@alangou alangou added test:e2e Requires end-to-end coverage test:e2e-gpu Requires GPU end-to-end coverage labels Oct 7, 2026
@alangou
alangou requested a review from a team as a code owner October 7, 2026 15:47
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

Label test:e2e-gpu applied for 20e5f49. Open Branch E2E Checks, find the run for commit 20e5f49, and click Re-run all jobs to execute with the label set. The run will execute GPU E2E after building the required supervisor image once. The matching required CI gate status on this PR will flip green automatically once the run finishes.

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

Label test:e2e applied for 20e5f49. Open the existing run and click Re-run all jobs to execute with the label set. The run will execute the standard E2E suite after building the required gateway, sandbox, and supervisor images once. The matching required CI gate status on this PR will flip green automatically once the run finishes.

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

@elezar

elezar commented Oct 7, 2026

Copy link
Copy Markdown
Member

One thing to note is that CDI is not NVIDIA specific, so we may have to check whether there is another way to perform the required validation or limit device names in some way.

@elezar

elezar commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

The shared CDI qualified-name check is now implemented for Docker and Podman. Both drivers use validate_cdi_gpu_device_request for explicit selectors and validate resolved selectors at their final container-spec construction boundary. The generic validate_specific_gpu_device_request remains identifier-agnostic so VM PCI selectors stay valid. Shared parser and driver regression tests cover host-path rejection and valid vendor-agnostic names.

The local implementation matches upstream's is_qualified_name until its public API is released. I've opened container-device-interface-rs PR #177 to expose is_qualified_name and parse_qualified_name and remove the validation's stdout output.

The follow-ups remain separate from this PR:

  • Draft PR #4329 adds Podman server CDI inventory discovery through the existing /v5.0.0/libpod/info endpoint. It distinguishes authoritative empty inventory from unsupported discovery, preserves legacy path-based fallback, and refreshes before default GPU validation and creation.
  • Issue #4327 covers designing and implementing administrator-controlled CDI device admission.

Podman 6's CDI directories and discovered-device fields were verified live in tmachine with Podman 6.1.1 and a synthetic non-NVIDIA CDI spec; see Podman PR #28712. That verifies discovery, not non-NVIDIA GPU execution. Automatic GPU selection retains its existing NVIDIA policy.

@elezar elezar changed the title fix(podman): validate GPU CDI device names fix(drivers): validate vendor-agnostic CDI device names Oct 8, 2026
Reject host paths and malformed CDI selectors for Docker and Podman
using shared qualified-name validation. Preserve the generic GPU
request checks for drivers using other identifier formats, including
VM PCI addresses.

Validate explicit and resolved CDI selectors, cover vendor-agnostic
names and rejected paths, and update the related documentation.

Signed-off-by: Adrien Langou <alangou@nvidia.com>
Signed-off-by: Evan Lezar <elezar@nvidia.com>
@elezar
elezar force-pushed the fix/2-podman-device-validation/alangou branch from e0eb3d4 to 6eb5f68 Compare October 8, 2026 11:28

@elezar elezar left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @alangou. Since this was a shared effort, please merge if you're happy with my adjustment.

@alangou
alangou added this pull request to the merge queue Oct 8, 2026
Merged via the queue into main with commit 81f712e Oct 8, 2026
115 checks passed
@alangou
alangou deleted the fix/2-podman-device-validation/alangou branch October 8, 2026 12:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

test:e2e Requires end-to-end coverage test:e2e-gpu Requires GPU end-to-end coverage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants