Skip to content

[shim] Don't check image downloaded size - #2903

Merged
un-def merged 1 commit into
masterfrom
issue_2503_shim_fix_pull_error_image_size_mismatch
Jul 15, 2025
Merged

[shim] Don't check image downloaded size#2903
un-def merged 1 commit into
masterfrom
issue_2503_shim_fix_pull_error_image_size_mismatch

Conversation

@un-def

@un-def un-def commented Jul 14, 2025

Copy link
Copy Markdown
Collaborator

Sometimes dockerd emits less "Download complete" messages than expected, but the image is pulled successfully.
The reason is unclear, but, anyway, this check is redundant since we also rely on the status message, which is emitted only in the case of succesfull pull.

In addition, this patch adds/changes the following:

  • Write dockerd pull stream (JSON Lines) to {runnerDir}/pull.log — useful for debugging (in conjunction with DSTACK_SERVER_KEEP_SHIM_TASKS=1)
  • Use errorDetail.message instead of deprecated error
  • Move ctx.Err() check upper, otherwise it's shadowed by pull errors

Fixes: #2503

Sometimes dockerd emits less "Download complete" messages than
expected, but the image is pulled successfully.
The reason is unclear, but, anyway, this check is redundant since
we also rely on the status message, which is emitted only
in the case of succesfull pull.

In addition, this patch adds/changes the following:

* Write dockerd pull stream (JSON Lines) to {runnerDir}/pull.log —
  useful for debugging (in conjunction with
  DSTACK_SERVER_KEEP_SHIM_TASKS=1)
* Use `errorDetail.message` instead of deprecated `error`
* Move `ctx.Err()` check upper, otherwise it's shadowed by pull errors

Fixes: #2503
@un-def
un-def requested a review from r4victor July 14, 2025 17:52
@un-def
un-def merged commit e3b292d into master Jul 15, 2025
26 checks passed
@un-def
un-def deleted the issue_2503_shim_fix_pull_error_image_size_mismatch branch July 15, 2025 07:20
un-def added a commit that referenced this pull request Aug 28, 2026
`~/.dstack/runners/<name>` is mounted into the task container as
`/tmp/runner`. It used to hold runner's files only, but shim now keeps
its own files there as well -- the image pull log since #2903 and the
task state file since #4220 -- sharing them with the runner and the user
workload, which may corrupt or delete them. Nothing sensitive is stored
there today, but the approach is unsafe: nothing stops a contributor
from putting a secret into a file the container can read.

That dir is now the task dir, private to shim, and only its new `runner`
subdir is mounted into the container:

    ~/.dstack/runners/<container-name>/  0700, shim only
      task.json
      pull.log
      runner/                           0755, mounted as /tmp/runner

* `runnerDir`/`runnersDir` are renamed to `taskDir`/`tasksDir`
  throughout, including the `DockerParameters` methods, to signal that
  the dir is managed by shim rather than by runner. The `runners` path
  itself is kept: an upgraded shim must find the dirs of the tasks
  created by the previous version.
* The dir of a restored task is no longer derived from the container
  mounts, which now point at the `runner` subdir, but from the task ID
  in its state file. The tasks dir is scanned once on start, and the
  result is shared by the restore and the orphan sweep, which used to
  scan the dir a second time.
* A task started by a shim version that did not write state files cannot
  be found by its state file, so its dir, named after the container, is
  looked up by name and, as before, removed along with the task.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: pullImage error when the image is actually pulled successfully

2 participants