Skip to content

[release/0.4]Backport RuntimeClass.handler support - #579

Draft
chenyaooo wants to merge 2 commits into
Mirantis:release/0.4from
chenyaooo:runtimeclass
Draft

chenyaooo wants to merge 2 commits into
Mirantis:release/0.4from
chenyaooo:runtimeclass

Conversation

@chenyaooo

@chenyaooo chenyaooo commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Backport RuntimeClass.handler support to release/0.4

Cherry-pick of #350
This feature already shipped in v0.4.0 and v0.4.1
git tag --contains 57af35d2 returns:
v0.4.0 v0.4.1

It is missing from v0.4.2 and later because release/0.4 was branched from
release/0.3 rather than from master

What it does

cri-dockerd currently rejects any pod whose RuntimeClass specifies a handler:
RuntimeHandler nvidia not supported

With this change, the handler from RuntimeClass is mapped onto Docker's
per-container runtime:

  • The handler name is validated against the runtimes reported by docker info,
    and an unknown handler fails with a clear error instead of silently falling
    back.
  • The validated handler is set as the sandbox container's runtime, and workload
    containers inherit the runtime selected for their sandbox.
  • PodSandboxStatus reports the runtime actually in use.
  • An empty handler and the handler docker continue to use Docker's default
    runtime, so existing workloads are unaffected.

Why backport to release/0.4

The NVIDIA GPU Operator requires this. From v25.10.0 it enables CDI by default
and sets runtimeClassName: nvidia on its operands, creating the
nvidia, nvidia-cdi, and nvidia-legacy RuntimeClasses. On a node running
cri-dockerd from the 0.4 line, every one of those pods fails to start with
FailedCreatePodSandBox, so the GPU Operator cannot be used at all. With this
change the handlers resolve against the runtimes the NVIDIA container toolkit
installs in daemon.json and the operands schedule normally.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The updated call-sequence expectations omit the new sandbox inspection, causing the affected tests to fail.

Review effort: Balanced
Findings: 1 High severity · 1 Low severity

Open (2)
What changed in this PR

Backports Docker runtime-handler support so RuntimeClass handlers select and propagate per-container runtimes.

Changes:

  • Validates requested handlers against Docker runtimes.
  • Propagates sandbox runtimes to workload containers and status.
  • Updates fakes and tests for runtime inheritance.
File Description
core/​container_create.go Inherits the sandbox runtime.
core/​container_test.go Uses real test sandboxes.
core/​docker_service.go Adds placeholder runtime-lock commentary.
core/​docker_service_test.go Synchronizes checkpoint test state.
core/​sandbox_helpers.go Validates configured Docker runtimes.
core/​sandbox_helpers_test.go Tests runtime selection and inheritance.
core/​sandbox_run.go Applies validated runtime handlers.
core/​sandbox_status.go Reports the sandbox runtime.
libdocker/​fake_client.go Updates Docker API types and default runtime data.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread core/container_test.go
randomError := fmt.Errorf("random error")

// sandBox run called "inspect_image", "pull", "create", "start", "inspect_container",
sandBoxCalls := []string{"inspect_image", "pull", "create", "start", "inspect_container"}
Comment thread core/container_create.go
Comment on lines +67 to +70
sandboxInfo, err := ds.client.InspectContainer(r.GetPodSandboxId())
if err != nil {
return nil, fmt.Errorf("unable to get container's sandbox ID: %v", err)
}
@chenyaooo
chenyaooo marked this pull request as draft October 1, 2026 21:57

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants