Skip to content

fix(vm-driver): find Docker Desktop's socket when looking up local images - #4183

Open
shiju-nv wants to merge 2 commits into
NVIDIA:mainfrom
shiju-nv:fix/vm-driver-docker-desktop-socket-4155
Open

shiju-nv wants to merge 2 commits into
NVIDIA:mainfrom
shiju-nv:fix/vm-driver-docker-desktop-socket-4155

Conversation

@shiju-nv

@shiju-nv shiju-nv commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator

Summary

The MicroVM driver looks for a local container engine through DOCKER_HOST and /var/run/docker.sock only, then Podman. Docker Desktop for macOS can expose just ~/.docker/run/docker.sock, so the driver reports "no local container engine available" and silently pulls the image from a registry. This adds a second lookup step that reuses the Docker driver's existing socket discovery, which already probes Docker Desktop's per-user socket.

Related Issue

Refs #4155. This PR fixes the lookup, which is the first complaint in the issue. The misleading Not authorized outcome and the fallback message are unchanged, so it does not close the issue.

Changes

  • connect_local_container_engine now delegates to connect_container_engine, which tries three steps in order: connect_with_local_defaults (kept first because it honours tcp:// and ssh:// DOCKER_HOST values that the Docker driver's discovery does not), then the socket found by openshell_driver_docker::detect_socket, then the Podman socket as before. A failed DOCKER_HOST does not stop the search, in the same way it already did not stop the Podman fallback.
  • The two socket detectors are parameters of connect_container_engine so tests can control them without depending on the engines a host runs. Production callers pass the real detectors.
  • openshell-driver-vm gains an optional openshell-driver-docker dependency, enabled by its compute-driver feature, beside the existing openshell-driver-podman dependency. It adds no dependency cycle, and the lockfile gains one edge. It also adds the Docker driver library and the toml crate family (toml, toml_edit, toml_datetime, toml_write, serde_spanned, winnow) to the VM driver's build, about ten more entries in its dependency tree. The gateway does not link the VM driver, so the gateway binary is unaffected. If maintainers prefer not to take that cost, the alternative is moving the roughly ten-line candidate list into openshell-core, where the socket probe helper already lives.
  • Five unit tests cover the new step, the ordering and the production wiring, using a fake Docker /_ping server on a temporary Unix socket.

Testing

  • Checks appropriate to the affected code and behavior pass (locally, below; hosted CI runs on this PR)
  • Unit tests added/updated (if applicable)
  • E2E tests added/updated (if applicable): none added

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable): not applicable

…ages

The VM driver looked for a local container engine through DOCKER_HOST and /var/run/docker.sock only, then Podman. Docker Desktop for macOS can expose just ~/.docker/run/docker.sock, so the driver found no engine and silently fell back to pulling the image from a registry.

Try the Docker driver's existing socket discovery between the default connection and the Podman fallback. connect_with_local_defaults stays first because it honours tcp:// and ssh:// DOCKER_HOST values that discovery does not. The detectors are parameters so tests control the ordering without depending on the engines a host runs.

This fixes the lookup only. The registry fallback and its error are unchanged.

Refs NVIDIA#4155

Signed-off-by: Shiju <shiju@nvidia.com>
Comment thread crates/openshell-driver-vm/Cargo.toml Outdated
openshell-sandbox-backend = { path = "../openshell-sandbox-backend" }
openshell-otel = { path = "../openshell-otel", optional = true }
openshell-policy = { path = "../openshell-policy", optional = true }
openshell-driver-docker = { path = "../openshell-driver-docker", optional = true }

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we cannot add a dep on the docker driver to the vm driver

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I used the existing openshell-driver-podman dependency as precedent. Docker socket discovery now lives in openshell-core. Should we move Podman discovery there too and remove that driver dependency?

Move the existing Docker socket detector beside the core socket probe and
keep the Docker driver's public wrapper. Let the VM driver call core and
remove its dependency on the Docker driver.

Preserve the socket candidates, response filters, and local-defaults then
Docker then Podman connection order.

Refs NVIDIA#4155

Signed-off-by: Shiju <shiju@nvidia.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants