Skip to content

feat(cli): harden Docker and Podman doctor probes - #4

Draft
kvnloo wants to merge 18 commits into
review/3694-runtime-probe-basefrom
feat/3694-runtime-probe-hardening
Draft

kvnloo wants to merge 18 commits into
review/3694-runtime-probe-basefrom
feat/3694-runtime-probe-hardening

Conversation

@kvnloo

@kvnloo kvnloo commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Summary

Implements the scoped NVIDIA#3694 runtime-doctor design on a fresh branch based on NVIDIA/OpenShell main at b8ffe5244cb244a1d74a4a03d69afe3da07e5f08.

Closes #5. Long-term shared discovery/diagnostic architecture is tracked separately in #6.

Behavior

  • openshell doctor check: probes installed Docker and Podman candidates concurrently; succeeds when at least one is ready.
  • openshell doctor check --driver docker|podman: selected runtime is authoritative.
  • Docker retains the existing docker info --format {{.ServerVersion}} readiness check.
  • Podman is checked as an API service:
    • explicit OPENSHELL_PODMAN_SOCKET -> podman --url unix://... version --format {{.Server.Version}}
    • no override -> podman --remote version --format {{.Server.Version}}
  • Empty OPENSHELL_PODMAN_SOCKET is rejected explicitly.
  • Each subprocess has a five-second deadline.
  • Default Docker/Podman probes run concurrently.

Tests

Deterministic fake-runtime coverage includes:

  • Docker-only and Podman-only hosts
  • neither installed / both unhealthy / both healthy
  • mixed runtime health
  • authoritative --driver
  • empty Podman socket
  • Podman remote-service invocation
  • exact OpenShell socket -> --url
  • timeout and concurrent wall-clock behavior

Also adds a real e2e-podman doctor test against the harness-exported OPENSHELL_PODMAN_SOCKET.

GitHub Actions validation

The fork inherits NVIDIA workflows that depend on NVIDIA self-hosted runner labels, so those jobs cannot provide a complete fork-side signal. A validation-only pull-request/4 mirror runs the relevant checks on GitHub-hosted ubuntu-latest without adding CI-only files to this PR.

Current validation includes:

  • cargo fmt --all -- --check
  • cargo check -p openshell-cli
  • cargo build -p openshell-cli
  • deterministic docker_preflight doctor matrix
  • real Docker doctor probe
  • real Podman API service + doctor probe

Validation run: https://github.com/kvnloo/OpenShell/actions/runs/36690027304

References

Draft until the full validation lane is green and the final architecture audit is complete.

Signed-off-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com>
Probe Podman through its API service, bound each runtime check to five seconds, and run default probes concurrently.

Signed-off-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com>
Isolate PATH, verify Podman remote-service arguments, cover mixed runtime health, and assert concurrent five-second probe bounds.

Signed-off-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com>
Signed-off-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com>
Signed-off-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com>
Signed-off-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com>
Signed-off-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com>
Signed-off-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com>
Signed-off-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown

Label test:e2e applied for 7ff6ed3. Open the existing run and click Re-run all jobs to execute with the label set. The run will execute the standard E2E suite after building the required gateway, sandbox, and supervisor images once. The matching required CI gate status on this PR will flip green automatically once the run finishes.

Signed-off-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com>
Signed-off-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com>
Signed-off-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com>
Signed-off-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com>
Reject unrelated Podman remotes by resolving the same host-local Unix API socket used by the Podman driver, while keeping the total probe budget bounded.

Signed-off-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com>
Replace the generic remote-service assertion with local-socket discovery coverage and a regression for unrelated SSH remotes.

Signed-off-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com>
Signed-off-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com>
Signed-off-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com>
Signed-off-by: Kevin Rajan <7121943+kvnloo@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant