Skip to content

Catch-22 on Windows Docker Desktop: Cannot bypass Issue #3152 workaround #3496

Description

@ahgo3

Description

nemoclaw onboard fails to start the GPU sandbox because it encounters unresolvable CDI devices nvidia.com/gpu=all.
Docker Desktop v29.4.3 hardcodes /etc/cdi and /var/run/cdi into CDISpecDirs in the docker info output and cannot be disabled. Because OpenShell sees CDISpecDirs is set, the preflight check strictly enforces CDI and demands I generate the nvidia.com/gpu specs.
However, Docker Desktop's WSL distro is physically missing the nvidia-cdi-hook binary. If I follow the CLI's advice and generate the specs, the OpenShell gateway crashes because the binary doesn't exist. Expected Behavior: OpenShell should detect that the CDI hook/binary is missing on Docker Desktop and successfully fall back to the legacy --gpus all path (which I have verified works perfectly on this machine via raw docker run). Currently, users are trapped in a Catch-22 where they cannot reach the working fallback path.

nemoclaw_bug_report.tar.gz

Reproduction Steps

Set up a Windows 10 host with WSL2 (Ubuntu) and Docker Desktop v29.4.3.
Ensure an NVIDIA GPU is present and driver passthrough to WSL is working.
Run nemoclaw onboard to create a new sandbox.
Observe Preflight Failure: The CLI blocks onboarding with the message: "Docker is configured for CDI device injection (CDISpecDirs is set), but no nvidia.com/gpu CDI spec was found on the host."
Follow CLI Suggestion: Run sudo nvidia-ctk cdi generate --output=/etc/cdi/nvidia.yaml exactly as prompted by the preflight warning.
Rerun Onboarding: Run nemoclaw onboard again.
Observe Crash: The gateway/sandbox fails to start with unresolvable CDI devices nvidia.com/gpu=all. This happens because Docker Desktop's WSL distro physically lacks the nvidia-cdi-hook binary required to execute the generated CDI spec
.
Attempt Workaround: Attempt to disable CDI in Docker Desktop by setting "cdi-spec-dirs": [] and "cdi": false in the Docker Engine settings.
Observe Catch-22: Docker Desktop v29.4.3 ignores the override and continues to inject /etc/cdi into the docker info output. This causes OpenShell's preflight check to permanently block the onboarding flow, preventing the system from falling back to the working --gpus all legacy path
.

Environment

Windows 10, WSL2 (Ubuntu), Docker Desktop v29.4.3, RTX 3060.

Debug Output

Logs

I have attached nemoclaw_bug_report.tar.gz which contains the full system diagnostics, Docker state, and gateway logs captured via the nemoclaw debug command The key errors observed in the terminal during this loop are:
Preflight block: OpenShell's gateway start will fail with unresolvable CDI devices nvidia.com/gpu=all (issue #3152).
Sandbox creation crash (after generating specs): unresolvable CDI devices nvidia.com/gpu=all

Checklist

  • I confirmed this bug is reproducible
  • I searched existing issues and this is not a duplicate

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area: sandboxOpenShell sandbox lifecycle, runtime, config, or recoveryplatform: containerAffects Docker, containerd, Podman, or imagesplatform: windowsAffects native Windows environmentsplatform: wslAffects Windows Subsystem for Linux

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions