Repository navigation
fix(drivers): validate vendor-agnostic CDI device names - #4306
Conversation
|
Label |
|
Label |
|
🌿 Preview your docs: https://nvidia-preview-pr-4306.docs.buildwithfern.com/openshell |
|
One thing to note is that CDI is not NVIDIA specific, so we may have to check whether there is another way to perform the required validation or limit device names in some way. |
|
The shared CDI qualified-name check is now implemented for Docker and Podman. Both drivers use The local implementation matches upstream's The follow-ups remain separate from this PR:
Podman 6's CDI directories and discovered-device fields were verified live in tmachine with Podman 6.1.1 and a synthetic non-NVIDIA CDI spec; see Podman PR #28712. That verifies discovery, not non-NVIDIA GPU execution. Automatic GPU selection retains its existing NVIDIA policy. |
Reject host paths and malformed CDI selectors for Docker and Podman using shared qualified-name validation. Preserve the generic GPU request checks for drivers using other identifier formats, including VM PCI addresses. Validate explicit and resolved CDI selectors, cover vendor-agnostic names and rejected paths, and update the related documentation. Signed-off-by: Adrien Langou <alangou@nvidia.com> Signed-off-by: Evan Lezar <elezar@nvidia.com>
e0eb3d4 to
6eb5f68
Compare
Summary
Reject host-device paths and malformed CDI selectors before Docker or Podman container creation, while preserving valid selectors from any vendor. Both drivers use shared CDI qualified-name validation for explicit requests and resolved device IDs.
Related Issue
No issue required: localized validation fix for the existing
cdi_devicesinput.Administrator-controlled CDI admission is a separate follow-up: #4327. Podman server inventory discovery is also being handled separately.
Changes
validate_cdi_device_namesinopenshell_core::gpu, using a localis_qualified_nameimplementation aligned with upstream CDI grammar.allselectors, and accept syntactically valid non-NVIDIA names without claiming additional GPU execution support.Testing
mise run pre-commit(repository-wide lint, formatting, and license checks).openshell-core,openshell-driver-docker, andopenshell-driver-podman.e2fsprogssupplied through a temporary Nix shell, including all PCI-address selection regressions.-D warnings.git diff --check.mise run docs: 0 errors and 3 Fern warnings.Checklist