Description
nemoclaw onboard fails to start the GPU sandbox because it encounters unresolvable CDI devices nvidia.com/gpu=all.
Docker Desktop v29.4.3 hardcodes /etc/cdi and /var/run/cdi into CDISpecDirs in the docker info output and cannot be disabled. Because OpenShell sees CDISpecDirs is set, the preflight check strictly enforces CDI and demands I generate the nvidia.com/gpu specs.
However, Docker Desktop's WSL distro is physically missing the nvidia-cdi-hook binary. If I follow the CLI's advice and generate the specs, the OpenShell gateway crashes because the binary doesn't exist. Expected Behavior: OpenShell should detect that the CDI hook/binary is missing on Docker Desktop and successfully fall back to the legacy --gpus all path (which I have verified works perfectly on this machine via raw docker run). Currently, users are trapped in a Catch-22 where they cannot reach the working fallback path.
nemoclaw_bug_report.tar.gz
Reproduction Steps
Set up a Windows 10 host with WSL2 (Ubuntu) and Docker Desktop v29.4.3.
Ensure an NVIDIA GPU is present and driver passthrough to WSL is working.
Run nemoclaw onboard to create a new sandbox.
Observe Preflight Failure: The CLI blocks onboarding with the message: "Docker is configured for CDI device injection (CDISpecDirs is set), but no nvidia.com/gpu CDI spec was found on the host."
Follow CLI Suggestion: Run sudo nvidia-ctk cdi generate --output=/etc/cdi/nvidia.yaml exactly as prompted by the preflight warning.
Rerun Onboarding: Run nemoclaw onboard again.
Observe Crash: The gateway/sandbox fails to start with unresolvable CDI devices nvidia.com/gpu=all. This happens because Docker Desktop's WSL distro physically lacks the nvidia-cdi-hook binary required to execute the generated CDI spec
.
Attempt Workaround: Attempt to disable CDI in Docker Desktop by setting "cdi-spec-dirs": [] and "cdi": false in the Docker Engine settings.
Observe Catch-22: Docker Desktop v29.4.3 ignores the override and continues to inject /etc/cdi into the docker info output. This causes OpenShell's preflight check to permanently block the onboarding flow, preventing the system from falling back to the working --gpus all legacy path
.
Environment
Windows 10, WSL2 (Ubuntu), Docker Desktop v29.4.3, RTX 3060.
Debug Output
Logs
I have attached nemoclaw_bug_report.tar.gz which contains the full system diagnostics, Docker state, and gateway logs captured via the nemoclaw debug command The key errors observed in the terminal during this loop are:
Preflight block: OpenShell's gateway start will fail with unresolvable CDI devices nvidia.com/gpu=all (issue #3152).
Sandbox creation crash (after generating specs): unresolvable CDI devices nvidia.com/gpu=all
Checklist
Description
nemoclaw onboard fails to start the GPU sandbox because it encounters unresolvable CDI devices nvidia.com/gpu=all.
Docker Desktop v29.4.3 hardcodes /etc/cdi and /var/run/cdi into CDISpecDirs in the docker info output and cannot be disabled. Because OpenShell sees CDISpecDirs is set, the preflight check strictly enforces CDI and demands I generate the nvidia.com/gpu specs.
However, Docker Desktop's WSL distro is physically missing the nvidia-cdi-hook binary. If I follow the CLI's advice and generate the specs, the OpenShell gateway crashes because the binary doesn't exist. Expected Behavior: OpenShell should detect that the CDI hook/binary is missing on Docker Desktop and successfully fall back to the legacy --gpus all path (which I have verified works perfectly on this machine via raw docker run). Currently, users are trapped in a Catch-22 where they cannot reach the working fallback path.
nemoclaw_bug_report.tar.gz
Reproduction Steps
Set up a Windows 10 host with WSL2 (Ubuntu) and Docker Desktop v29.4.3.
Ensure an NVIDIA GPU is present and driver passthrough to WSL is working.
Run nemoclaw onboard to create a new sandbox.
Observe Preflight Failure: The CLI blocks onboarding with the message: "Docker is configured for CDI device injection (CDISpecDirs is set), but no nvidia.com/gpu CDI spec was found on the host."
Follow CLI Suggestion: Run sudo nvidia-ctk cdi generate --output=/etc/cdi/nvidia.yaml exactly as prompted by the preflight warning.
Rerun Onboarding: Run nemoclaw onboard again.
Observe Crash: The gateway/sandbox fails to start with unresolvable CDI devices nvidia.com/gpu=all. This happens because Docker Desktop's WSL distro physically lacks the nvidia-cdi-hook binary required to execute the generated CDI spec
.
Attempt Workaround: Attempt to disable CDI in Docker Desktop by setting "cdi-spec-dirs": [] and "cdi": false in the Docker Engine settings.
Observe Catch-22: Docker Desktop v29.4.3 ignores the override and continues to inject /etc/cdi into the docker info output. This causes OpenShell's preflight check to permanently block the onboarding flow, preventing the system from falling back to the working --gpus all legacy path
.
Environment
Windows 10, WSL2 (Ubuntu), Docker Desktop v29.4.3, RTX 3060.
Debug Output
Logs
Checklist