Skip to content

Commit 8af79a7

Browse files
authored
fix(podman): resolve macOS Podman socket dynamically (#3135)
* docs(podman): document macOS socket path mismatch and dynamic lookup On macOS, Homebrew-installed Podman does not create the default socket path that the Podman driver probes. Document the OPENSHELL_PODMAN_SOCKET override and the podman machine inspect lookup in both the compute drivers reference and the debug-openshell-cluster skill. Fixes #1690 Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com> * fix(podman): resolve macOS Podman socket dynamically Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com> * chore: restore debug skill file Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com> * chore: drop legacy debug skill path Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com> * fix(podman): trim unrelated e2e changes Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com> * fix(e2e): harden shell array expansion Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com> * chore: remove unrelated skill note * ci: retrigger checks Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com> --------- Signed-off-by: Gaizka Menendez Hernandez <gmenende@redhat.com>
1 parent 3693b32 commit 8af79a7

5 files changed

Lines changed: 42 additions & 40 deletions

File tree

‎docs/reference/sandbox-compute-drivers.mdx‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -255,6 +255,26 @@ For maintainer-level implementation details, refer to the [Podman driver README]
255255

256256
Select Podman with `compute_drivers = ["podman"]` in `[openshell.gateway]`. Configure Podman driver values such as `socket_path`, `network_name`, `supervisor_image`, `stop_timeout_secs`, `image_pull_policy`, `grpc_endpoint`, `host_gateway_ip`, `sandbox_ssh_socket_path`, `sandbox_pids_limit`, and `guest_tls_*` in `[openshell.drivers.podman]`.
257257

258+
### macOS Podman Socket Path
259+
260+
On macOS, Homebrew-installed Podman does not create the default socket path
261+
that the driver probes (`~/.local/share/containers/podman/machine/podman.sock`).
262+
The actual API socket lives under `/var/folders/` in a path that macOS can
263+
rotate after a reboot.
264+
265+
If the gateway fails with `Podman socket not found; is podman machine running?`
266+
while `podman machine list` shows a running machine, set the
267+
`OPENSHELL_PODMAN_SOCKET` environment variable to the dynamic socket path:
268+
269+
```shell
270+
export OPENSHELL_PODMAN_SOCKET="$(podman machine inspect --format '{{.ConnectionInfo.PodmanSocket.Path}}')"
271+
```
272+
273+
Add this to your shell profile or gateway launch environment so it resolves
274+
correctly after each reboot. Alternatively, set `socket_path` in
275+
`[openshell.drivers.podman]` to the current path, but note that the path may
276+
change when macOS rotates `/var/folders/`.
277+
258278
Podman sandboxes default to a 45-second graceful stop window before Podman escalates from `SIGTERM` to `SIGKILL`. Set `stop_timeout_secs` in gateway config, or `OPENSHELL_STOP_TIMEOUT` for the standalone driver, when a local runtime needs a different teardown window.
259279

260280
Stop stops the existing Podman container while retaining its named workspace

‎e2e/rust/tests/driver_config_volume.rs‎

Lines changed: 6 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -458,7 +458,7 @@ async fn connect_container_api(driver: &str) -> Result<Docker, String> {
458458
"docker" => Docker::connect_with_local_defaults()
459459
.map_err(|err| format!("connect to Docker API: {err}"))?,
460460
"podman" => {
461-
let socket = podman_socket_path();
461+
let socket = podman_socket_path()?;
462462
let socket_display = socket.display().to_string();
463463
Docker::connect_with_unix(
464464
socket
@@ -478,36 +478,11 @@ async fn connect_container_api(driver: &str) -> Result<Docker, String> {
478478
Ok(docker)
479479
}
480480

481-
fn podman_socket_path() -> PathBuf {
482-
if let Some(path) = std::env::var_os("OPENSHELL_PODMAN_SOCKET") {
483-
return PathBuf::from(path);
484-
}
485-
486-
#[cfg(target_os = "macos")]
487-
{
488-
let home = std::env::var_os("HOME").unwrap_or_default();
489-
PathBuf::from(home).join(".local/share/containers/podman/machine/podman.sock")
490-
}
491-
#[cfg(target_os = "linux")]
492-
{
493-
std::env::var_os("XDG_RUNTIME_DIR").map_or_else(
494-
|| {
495-
let uid = std::process::Command::new("id")
496-
.arg("-u")
497-
.output()
498-
.ok()
499-
.and_then(|output| {
500-
String::from_utf8(output.stdout)
501-
.ok()
502-
.map(|value| value.trim().to_string())
503-
})
504-
.filter(|value| !value.is_empty())
505-
.unwrap_or_else(|| "1000".to_string());
506-
PathBuf::from(format!("/run/user/{uid}/podman/podman.sock"))
507-
},
508-
|xdg| PathBuf::from(xdg).join("podman/podman.sock"),
509-
)
510-
}
481+
fn podman_socket_path() -> Result<PathBuf, String> {
482+
let path = std::env::var_os("OPENSHELL_PODMAN_SOCKET").ok_or_else(|| {
483+
"OPENSHELL_PODMAN_SOCKET must be set by e2e/with-podman-gateway.sh".to_string()
484+
})?;
485+
Ok(PathBuf::from(path))
511486
}
512487

513488
fn unique_volume_name(driver: &str) -> String {

‎e2e/support/gateway-common.sh‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -218,11 +218,11 @@ e2e_build_gateway_binaries() {
218218
if [ -z "${OPENSHELL_GATEWAY_BIN:-}" ]; then
219219
echo "Building openshell-gateway..."
220220
if [ "${OPENSHELL_E2E_EXTERNAL_COMPUTE_DRIVER:-0}" = "1" ]; then
221-
cargo build "${jobs[@]}" \
221+
cargo build ${jobs[@]+"${jobs[@]}"} \
222222
-p openshell-gateway --bin openshell-gateway \
223223
--no-default-features --features telemetry
224224
else
225-
cargo build "${jobs[@]}" \
225+
cargo build ${jobs[@]+"${jobs[@]}"} \
226226
-p openshell-gateway --bin openshell-gateway
227227
fi
228228
else
@@ -231,7 +231,7 @@ e2e_build_gateway_binaries() {
231231

232232
if [ -z "${OPENSHELL_BIN:-}" ]; then
233233
echo "Building openshell-cli..."
234-
cargo build "${jobs[@]}" \
234+
cargo build ${jobs[@]+"${jobs[@]}"} \
235235
-p openshell-cli
236236
else
237237
echo "Using prebuilt openshell CLI at ${OPENSHELL_BIN}"
@@ -265,7 +265,7 @@ e2e_build_external_driver() {
265265
else
266266
printf -v "${output_var}" '%s' "${target_dir}/debug/${binary}"
267267
echo "Building external ${binary}..."
268-
cargo build "${jobs[@]}" -p "${package}" --bin "${binary}"
268+
cargo build ${jobs[@]+"${jobs[@]}"} -p "${package}" --bin "${binary}"
269269
fi
270270
if [ ! -x "${!output_var}" ]; then
271271
echo "ERROR: expected external driver binary at ${!output_var}" >&2

‎e2e/with-podman-gateway.sh‎

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -80,7 +80,11 @@ with_podman_config() {
8080
}
8181

8282
podman_cmd() {
83-
with_podman_config podman "$@"
83+
if [ -n "${OPENSHELL_PODMAN_SOCKET:-}" ]; then
84+
with_podman_config podman --url "unix://${OPENSHELL_PODMAN_SOCKET}" "$@"
85+
else
86+
with_podman_config podman "$@"
87+
fi
8488
}
8589

8690
WORKDIR_PARENT="${TMPDIR:-/tmp}"
@@ -234,15 +238,17 @@ default_podman_socket_path() {
234238

235239
ensure_podman_api_socket() {
236240
if [ -n "${OPENSHELL_PODMAN_SOCKET:-}" ]; then
241+
export CONTAINER_HOST="${CONTAINER_HOST:-unix://${OPENSHELL_PODMAN_SOCKET}}"
237242
return 0
238243
fi
239244

240245
local default_socket
241246
default_socket="$(default_podman_socket_path || true)"
242247
if [ -n "${default_socket}" ] \
243248
&& [ -S "${default_socket}" ] \
244-
&& podman_cmd --url "unix://${default_socket}" info >/dev/null 2>&1; then
249+
&& with_podman_config podman --url "unix://${default_socket}" info >/dev/null 2>&1; then
245250
export OPENSHELL_PODMAN_SOCKET="${default_socket}"
251+
export CONTAINER_HOST="${CONTAINER_HOST:-unix://${OPENSHELL_PODMAN_SOCKET}}"
246252
return 0
247253
fi
248254

@@ -266,12 +272,13 @@ ensure_podman_api_socket() {
266272
>"${PODMAN_SERVICE_LOG}" 2>&1 &
267273
PODMAN_SERVICE_PID=$!
268274
export OPENSHELL_PODMAN_SOCKET="${PODMAN_SOCKET}"
275+
export CONTAINER_HOST="${CONTAINER_HOST:-unix://${OPENSHELL_PODMAN_SOCKET}}"
269276

270277
local elapsed=0
271278
local timeout=30
272279
while [ "${elapsed}" -lt "${timeout}" ]; do
273280
if [ -S "${PODMAN_SOCKET}" ] \
274-
&& podman_cmd --url "unix://${PODMAN_SOCKET}" info >/dev/null 2>&1; then
281+
&& podman_cmd info >/dev/null 2>&1; then
275282
return 0
276283
fi
277284

@@ -375,12 +382,12 @@ if ! command -v podman >/dev/null 2>&1; then
375382
echo "ERROR: podman CLI is required to run Podman-backed e2e tests" >&2
376383
exit 2
377384
fi
385+
ensure_podman_api_socket
378386
if ! podman_cmd info >/dev/null 2>&1; then
379387
echo "ERROR: podman service is not reachable (podman info failed)" >&2
380388
echo " Start it with 'podman machine start' on macOS, or the user service on Linux." >&2
381389
exit 2
382390
fi
383-
ensure_podman_api_socket
384391

385392
e2e_build_gateway_binaries "${ROOT}" TARGET_DIR GATEWAY_BIN CLI_BIN
386393
export OPENSHELL_BIN="${CLI_BIN}"

‎tasks/scripts/stage-prebuilt-binaries.sh‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -254,7 +254,7 @@ build_component_for_arch() {
254254
if [[ -n "$build_rustflags" ]]; then
255255
export RUSTFLAGS="$build_rustflags"
256256
fi
257-
CARGO_INCREMENTAL=0 mise x -- "${cargo_env[@]}" "${cargo_subcommand[@]}" "${args[@]}"
257+
CARGO_INCREMENTAL=0 mise x -- ${cargo_env[@]+"${cargo_env[@]}"} "${cargo_subcommand[@]}" "${args[@]}"
258258
)
259259

260260
binary_path="${ROOT}/target/${target}/release/${binary}"

0 commit comments

Comments
 (0)