Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions cmd/cdi/cmd/validate.go
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ import (
"github.com/spf13/cobra"

"tags.cncf.io/container-device-interface/pkg/cdi"
"tags.cncf.io/container-device-interface/specs-go"
)

// validateCmd is our CDI command for validating CDI Spec files in the cache.
Expand All @@ -49,6 +50,15 @@ were reported by the cache.`,
fmt.Printf(" %2d: %v\n", idx, strings.TrimSpace(err.Error()))
}
}

for _, v := range cache.ListVendors() {
for _, s := range cache.GetVendorSpecs(v) {
if err := specs.ValidateVersion(s.Spec); err != nil {
fmt.Printf("Spec file %s failed version validation: %v\n", s.GetPath(), err)
}
}
}

os.Exit(1)
},
}
Expand Down
2 changes: 1 addition & 1 deletion cmd/cdi/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ require (
sigs.k8s.io/yaml v1.4.0
tags.cncf.io/container-device-interface v1.0.1
tags.cncf.io/container-device-interface/schema v0.0.0
tags.cncf.io/container-device-interface/specs-go v1.0.0
)

require (
Expand All @@ -22,7 +23,6 @@ require (
github.com/xeipuuv/gojsonschema v1.2.0 // indirect
golang.org/x/mod v0.19.0 // indirect
golang.org/x/sys v0.19.0 // indirect
tags.cncf.io/container-device-interface/specs-go v1.0.0 // indirect
)

replace (
Expand Down
79 changes: 79 additions & 0 deletions pkg/cdi/container-edits.go
Original file line number Diff line number Diff line change
Expand Up @@ -113,6 +113,14 @@ func (e *ContainerEdits) Apply(spec *oci.Spec) error {
}
}

if e.NetDevices != nil {
// specgen is currently missing functionality to set Linux NetDevices,
// so we use a locally rolled function for now.
for _, dev := range e.NetDevices {
specgenAddLinuxNetDevice(&specgen, dev.HostIf, (&LinuxNetDevice{dev}).toOCI())
}
}

if len(e.Mounts) > 0 {
for _, m := range e.Mounts {
specgen.RemoveMount(m.ContainerPath)
Expand Down Expand Up @@ -162,6 +170,24 @@ func (e *ContainerEdits) Apply(spec *oci.Spec) error {
return nil
}

func specgenAddLinuxNetDevice(specgen *ocigen.Generator, hostIf string, netDev *oci.LinuxNetDevice) {
if specgen == nil || netDev == nil {
return
}
ensureLinuxNetDevices(specgen.Config)
specgen.Config.Linux.NetDevices[hostIf] = *netDev
}

// Ensure OCI Spec Linux NetDevices map is not nil.
func ensureLinuxNetDevices(spec *oci.Spec) {
if spec.Linux == nil {
spec.Linux = &oci.Linux{}
}
if spec.Linux.NetDevices == nil {
spec.Linux.NetDevices = map[string]oci.LinuxNetDevice{}
}
}

// Validate container edits.
func (e *ContainerEdits) Validate() error {
if e == nil || e.ContainerEdits == nil {
Expand Down Expand Up @@ -191,6 +217,9 @@ func (e *ContainerEdits) Validate() error {
return err
}
}
if err := ValidateNetDevices(e.NetDevices); err != nil {
return err
}

return nil
}
Expand All @@ -210,6 +239,7 @@ func (e *ContainerEdits) Append(o *ContainerEdits) *ContainerEdits {

e.Env = append(e.Env, o.Env...)
e.DeviceNodes = append(e.DeviceNodes, o.DeviceNodes...)
e.NetDevices = append(e.NetDevices, o.NetDevices...)
e.Hooks = append(e.Hooks, o.Hooks...)
e.Mounts = append(e.Mounts, o.Mounts...)
if o.IntelRdt != nil {
Expand Down Expand Up @@ -244,6 +274,9 @@ func (e *ContainerEdits) isEmpty() bool {
if e.IntelRdt != nil {
return false
}
if e.NetDevices != nil {
return false
}
return true
}

Expand All @@ -257,6 +290,52 @@ func ValidateEnv(env []string) error {
return nil
}

// ValidateNetDevices validates the given net devices.
func ValidateNetDevices(devices []*cdi.LinuxNetDevice) error {
var (
hostSeen = map[string]string{}
nameSeen = map[string]string{}
)

for _, dev := range devices {
if dev.HostIf == "" {
return fmt.Errorf("invalid linux net device, empty HostIf for %q", dev.Name)
}
if dev.Name == "" {
return fmt.Errorf("invalid linux net device, empty Name for %q", dev.HostIf)
}
if other, ok := hostSeen[dev.HostIf]; ok {
return fmt.Errorf("invalid linux net device, duplicate HostIf %q with names %q and %q",
dev.HostIf, dev.Name, other)
}
hostSeen[dev.HostIf] = dev.Name

if other, ok := nameSeen[dev.Name]; ok {
return fmt.Errorf("invalid linux net device, duplicate Name %q with HostIf %q and %q",
dev.Name, dev.HostIf, other)
}
nameSeen[dev.Name] = dev.HostIf
}

return nil
}

// LinuxNetDevice is a CDI Spec LinuxNetDevice wrapper, used for OCI conversion and validating.
type LinuxNetDevice struct {
*cdi.LinuxNetDevice
}

// Validate LinuxNetDevice.
func (d *LinuxNetDevice) Validate() error {
if d.HostIf == "" {
return errors.New("invalid linux net device, empty HostIf")
}
if d.Name == "" {
return errors.New("invalid linux net device, empty Name")
}
return nil
}

// DeviceNode is a CDI Spec DeviceNode wrapper, used for validating DeviceNodes.
type DeviceNode struct {
*cdi.DeviceNode
Expand Down
99 changes: 99 additions & 0 deletions pkg/cdi/container-edits_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -298,6 +298,41 @@ func TestValidateContainerEdits(t *testing.T) {
},
invalid: true,
},
{
name: "valid Linux net device",
edits: &cdi.ContainerEdits{
NetDevices: []*cdi.LinuxNetDevice{
{
HostIf: "eno1",
Name: "netdev0",
},
},
},
},
{
name: "invalid Linux net device, empty host interface name",
edits: &cdi.ContainerEdits{
NetDevices: []*cdi.LinuxNetDevice{
{
HostIf: "",
Name: "netdev0",
},
},
},
invalid: true,
},
{
name: "invalid Linux net device, empty container interface name",
edits: &cdi.ContainerEdits{
NetDevices: []*cdi.LinuxNetDevice{
{
HostIf: "eno1",
Name: "",
},
},
},
invalid: true,
},
} {
t.Run(tc.name, func(t *testing.T) {
edits := ContainerEdits{tc.edits}
Expand Down Expand Up @@ -581,6 +616,70 @@ func TestApplyContainerEdits(t *testing.T) {
},
},
},
{
name: "empty spec, Linux net devices",
spec: &oci.Spec{},
edits: &cdi.ContainerEdits{
NetDevices: []*cdi.LinuxNetDevice{
{
HostIf: "eno1",
Name: "netdev0",
},
{
HostIf: "eno2",
Name: "netdev1",
},
},
},
result: &oci.Spec{
Linux: &oci.Linux{
NetDevices: map[string]oci.LinuxNetDevice{
"eno1": {
Name: "netdev0",
},
"eno2": {
Name: "netdev1",
},
},
},
},
},
{
name: "non-empty spec, overriding Linux net devices",
spec: &oci.Spec{
Linux: &oci.Linux{
NetDevices: map[string]oci.LinuxNetDevice{
"eno1": {
Name: "netdev1",
},
},
},
},
edits: &cdi.ContainerEdits{
NetDevices: []*cdi.LinuxNetDevice{
{
HostIf: "eno1",
Name: "netdev2",
},
{
HostIf: "eno2",
Name: "netdev1",
},
},
},
result: &oci.Spec{
Linux: &oci.Linux{
NetDevices: map[string]oci.LinuxNetDevice{
"eno1": {
Name: "netdev2",
},
"eno2": {
Name: "netdev1",
},
},
},
},
},
{
name: "additional GIDs are applied",
spec: &oci.Spec{},
Expand Down
7 changes: 7 additions & 0 deletions pkg/cdi/oci.go
Original file line number Diff line number Diff line change
Expand Up @@ -63,3 +63,10 @@ func (i *IntelRdt) toOCI() *spec.LinuxIntelRdt {
EnableMonitoring: i.EnableMonitoring,
}
}

// toOCI returns the opencontainers runtime Spec LinuxNetDevice for this LinuxNetDevice.
func (d *LinuxNetDevice) toOCI() *spec.LinuxNetDevice {
return &spec.LinuxNetDevice{
Name: d.Name,
}
}
24 changes: 24 additions & 0 deletions schema/defs.json
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,9 @@
"Env": {
"$ref": "#/definitions/ArrayOfStrings"
},
"InterfaceName": {
"type": "string"
},
"mapStringString": {
"type": "object",
"patternProperties": {
Expand Down Expand Up @@ -111,6 +114,21 @@
"path"
]
},
"LinuxNetDevice": {
"type": "object",
"properties": {
"hostIf": {
"$ref": "#/definitions/InterfaceName"
},
"name": {
"$ref": "#/definitions/InterfaceName"
}
},
"required": [
"hostIf",
"name"
]
},
"containerEdits": {
"type": "object",
"properties": {
Expand All @@ -126,6 +144,12 @@
"$ref": "#/definitions/DeviceNode"
}
},
"netDevices": {
"type": "array",
"items": {
"$ref": "#/definitions/LinuxNetDevice"
}
},
"mounts": {
"type": "array",
"items": {
Expand Down
19 changes: 13 additions & 6 deletions specs-go/config.go
Original file line number Diff line number Diff line change
Expand Up @@ -24,12 +24,13 @@ type Device struct {

// ContainerEdits are edits a container runtime must make to the OCI spec to expose the device.
type ContainerEdits struct {
Env []string `json:"env,omitempty" yaml:"env,omitempty"`
DeviceNodes []*DeviceNode `json:"deviceNodes,omitempty" yaml:"deviceNodes,omitempty"`
Hooks []*Hook `json:"hooks,omitempty" yaml:"hooks,omitempty"`
Mounts []*Mount `json:"mounts,omitempty" yaml:"mounts,omitempty"`
IntelRdt *IntelRdt `json:"intelRdt,omitempty" yaml:"intelRdt,omitempty"` // Added in v0.7.0
AdditionalGIDs []uint32 `json:"additionalGids,omitempty" yaml:"additionalGids,omitempty"` // Added in v0.7.0
Env []string `json:"env,omitempty" yaml:"env,omitempty"`
DeviceNodes []*DeviceNode `json:"deviceNodes,omitempty" yaml:"deviceNodes,omitempty"`
NetDevices []*LinuxNetDevice `json:"netDevices,omitempty" yaml:"netDevices,omitempty"` // Added in v1.1.0
Hooks []*Hook `json:"hooks,omitempty" yaml:"hooks,omitempty"`
Mounts []*Mount `json:"mounts,omitempty" yaml:"mounts,omitempty"`
IntelRdt *IntelRdt `json:"intelRdt,omitempty" yaml:"intelRdt,omitempty"` // Added in v0.7.0
AdditionalGIDs []uint32 `json:"additionalGids,omitempty" yaml:"additionalGids,omitempty"` // Added in v0.7.0
}

// DeviceNode represents a device node that needs to be added to the OCI spec.
Expand Down Expand Up @@ -70,3 +71,9 @@ type IntelRdt struct {
Schemata []string `json:"schemata,omitempty" yaml:"schemata,omitempty"`
EnableMonitoring bool `json:"enableMonitoring,omitempty" yaml:"enableMonitoring,omitempty"`
}

// LinuxNetDevice represents an OCI LinuxNetDevice to be added to the OCI Spec.
type LinuxNetDevice struct {
HostIf string `json:"hostIf" yaml:"hostIf"`
Name string `json:"name" yaml:"name"`
}
10 changes: 9 additions & 1 deletion specs-go/version.go
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ import (

const (
// CurrentVersion is the current version of the Spec.
CurrentVersion = "1.0.0"
CurrentVersion = "1.1.0"

// vCurrent is the current version as a semver-comparable type
vCurrent version = "v" + CurrentVersion
Expand Down Expand Up @@ -150,12 +150,20 @@ func requiresV110(spec *Spec) bool {
}
}

if len(spec.ContainerEdits.NetDevices) != 0 {
return true
}

for _, dev := range spec.Devices {
if i := dev.ContainerEdits.IntelRdt; i != nil {
if i.Schemata != nil || i.EnableMonitoring {
return true
}
}

if len(dev.ContainerEdits.NetDevices) != 0 {
return true
}
}

return false
Expand Down