Skip to content

bug: openshell doctor check doesn't verify Docker Desktop prerequisites (Landlock kernel, host networking) #4133

Description

@tech4242

User Story

I'm trying OpenShell on my Mac (Apple Silicon, Docker Desktop) because I'm looking at adding aquaman, a credential isolation proxy I maintain, as an external credential driver. openshell doctor check passed on every setup I tried, but openshell sandbox create failed on two of them, with errors that don't name the missing prerequisite.

Problem Statement

doctor check only verifies that Docker responds. It doesn't check the documented Docker Desktop prerequisites, a Landlock ABI 3+ kernel in the Docker VM and host networking enabled, so it reports "All checks passed" on setups where every sandbox fails.

Landlock example, Docker Desktop 4.55.0 (VM kernel 6.12.54-linuxkit, # CONFIG_SECURITY_LANDLOCK is not set):

Error:   × fully incompatible access-rights: BitFlags<AccessFs>(...)
Error:   × Landlock allow/deny probe
  ╰─▶ Landlock probe child exited with status exit status: 1

The error doesn't say that the kernel has Landlock disabled or point to the Kernel Requirements.

Host networking: on Docker Desktop 4.93.0 with host networking off, startup fails with failed to connect to OpenShell server, and enabling host networking fixes it. That case and its error message are covered in #3880, so I'm only listing it here as a second prerequisite doctor could check.

In all of these setups doctor check printed:

Docker ............. ok
DOCKER_HOST ........ (not set, using default socket)

All checks passed.

Impact / Why This Matters

macOS with Docker Desktop is the documented path for Mac users. Older Docker Desktop versions can never meet the Landlock requirement and host networking is off by default, so a new user gets a green doctor and then a startup error that takes kernel config or network debugging to explain. Docker Desktop's kernel can't be replaced on macOS, so updating Docker Desktop is the only fix for the Landlock case, and nothing tells the user that.

Acceptance Criteria

  • doctor check fails with a clear message when the Docker VM kernel lacks Landlock ABI 3+.
  • doctor check fails with a clear message when Docker Desktop host networking is off.
  • The Landlock baseline startup error says the kernel has Landlock disabled or too old and links to the Kernel Requirements.
  • The support matrix names a minimum Docker Desktop version for macOS (4.55.0 has no Landlock, 4.93.0 has it).

Reproduction Steps

  1. macOS on Apple Silicon with Docker Desktop 4.55.0.
  2. Start a gateway with the Docker compute driver.
  3. Run openshell doctor check: all checks passed.
  4. Run openshell sandbox create --name demo -- true: fails with the Landlock error above.

Suggested UX (if applicable)

openshell doctor check

  Docker ............. ok (version 29.1.3)
  DOCKER_HOST ........ (not set, using default socket)
  Landlock ........... FAILED (disabled in the Docker VM kernel 6.12.54-linuxkit; ABI 3+ required)
  Host networking .... ok

1 check failed. See https://docs.nvidia.com/openshell/latest/about/support-matrix#kernel-requirements

Environment

  • OpenShell 0.1.2 (CLI and standalone gateway from the GitHub release), Docker compute driver
  • macOS 26.4.1 (25E253), Apple Silicon
  • Docker Desktop 4.55.0 (engine 29.1.3, kernel 6.12.54-linuxkit) and 4.93.0 (engine 29.8.1, kernel 7.0.14-linuxkit)

Logs

Error:   × sandbox entered error phase while provisioning:
  │ ControlSupervisorStartFailed: Docker sandbox exited before supervisor
  │ became ready; sandbox log tail: Error:   × fully incompatible access-
  │ rights: BitFlags<AccessFs>(0b111111111111111, ...)
  │ Error:   × Landlock allow/deny probe
  │   ╰─▶ Landlock probe child exited with status exit status: 1

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    state:triage-neededOpened without agent diagnostics and needs triage

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions