Conversation
Signed-off-by: Evan Lezar <elezar@nvidia.com>
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
|
🌿 Preview your docs: https://nvidia-preview-pr-3970.docs.buildwithfern.com/openshell |
| the check. Image-pull and container-start failures mean the check could not | ||
| verify connectivity. Remote Docker endpoints skip this test; run it on the | ||
| gateway host. | ||
|
|
| use std::time::Duration; | ||
| use tokio::process::Command; | ||
|
|
||
| const PROBE_IMAGE: &str = "alpine:3.23"; |
There was a problem hiding this comment.
how about we sync this with the default image the sandbox uses
|
|
||
| The gateway reads `~/.config/openshell/gateway.toml` if it exists, otherwise the Homebrew config at `$(brew --prefix)/var/openshell/gateway.toml`. | ||
|
|
||
| For Docker Desktop, enable host networking and disable Enhanced Container Isolation. Run `openshell doctor check` to verify container-to-host loopback connectivity before creating a sandbox. The check may pull a small Alpine probe image. |
There was a problem hiding this comment.
just move this to requirements on line 72 above
| // SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. | ||
| // SPDX-License-Identifier: Apache-2.0 | ||
|
|
||
| //! Docker prerequisites, including Docker Desktop's container-to-host route. |
There was a problem hiding this comment.
This whole file is Docker-oriented, and does not seem extendable to add e.g. Podman, but the file is called doctor.rs. I feel like this is begging for a different design. I get that doctor_check() from before only did Docker, but we shouldn't maintain the status quo.
There was a problem hiding this comment.
yea, thats a good call. this feels a little too specific for the driver/problem.
Signed-off-by: Evan Lezar <elezar@nvidia.com>
Summary
openshell doctor checkreports success when Docker Desktop is running but host networking cannot reach the macOS gateway. Check container-to-host loopback connectivity and return an actionable error before sandbox provisioning.Related Issue
No issue required: localized diagnostic bug fix for an unmet documented Docker Desktop prerequisite. Runtime routing, listener configuration, and gateway defaults remain unchanged.
Changes
Testing
mise run pre-commitpasses: attempted; blocked by the existing localsccachepermission error during Cargo metadata/lockfile checks.RUSTC_WRAPPER=.RUSTC_WRAPPER=. Formatting, Markdown lint, and license checks passed.Host networking .... FAILEDand returns exit code 1 using the default sandbox image.127.0.0.1with connection refused and connects successfully throughhost.docker.internalto the same temporary listener. Test containers are removed.mise run testandmise run ciwere attempted; local checks remain blocked by the samesccacheerror.Checklist