fix: address code review — TMPDIR path, platform guard, Podman extra_hosts

- Fix TMPDIR concatenation when TMPDIR has no trailing slash
- Guard podman machine inspect behind sys.platform == "darwin"
- Skip extra_hosts for Podman (host-gateway compat added in v4.7)
- Restore type-check in make check-all

Made with Love
This commit is contained in:
Carsten Meininger 2026-05-28 13:44:38 +02:00
parent 370f489904
commit 782abffead
4 changed files with 18 additions and 6 deletions

View file

@ -56,7 +56,7 @@ test:
uv run pytest tests/ -v
@echo "✅ All tests passed!"
check-all: format lint security test
check-all: format lint type-check security test
@echo "✅ All code quality checks passed!"
pre-commit:

View file

@ -4,6 +4,7 @@ from __future__ import annotations
import logging
import os
import sys
from collections.abc import Awaitable, Callable
from pathlib import Path
from typing import TYPE_CHECKING, Any
@ -82,7 +83,8 @@ def _podman_socket_candidates() -> list[str]:
candidates: list[str] = []
# -- macOS podman machine (applehv / libkrun) --
candidates.extend(_macos_podman_machine_sockets())
if sys.platform == "darwin":
candidates.extend(_macos_podman_machine_sockets())
# -- Linux rootless --
xdg_runtime = os.environ.get("XDG_RUNTIME_DIR")
@ -100,7 +102,7 @@ def _podman_socket_candidates() -> list[str]:
# -- macOS podman machine temp-dir fallback --
tmpdir = os.environ.get("TMPDIR")
if tmpdir:
candidates.append(f"unix://{tmpdir}podman/podman-machine-default-api.sock")
candidates.append(f"unix://{tmpdir.rstrip('/')}/podman/podman-machine-default-api.sock")
return candidates

View file

@ -114,8 +114,13 @@ class StrixDockerSandboxClient(DockerSandboxClient):
if cap not in cap_add:
cap_add.append(cap)
extra_hosts = create_kwargs.setdefault("extra_hosts", {})
extra_hosts[self._host_gateway_hostname] = "host-gateway"
# Docker requires an explicit host-gateway mapping for
# host.docker.internal. Podman resolves host.containers.internal
# via its built-in DNS and the compat API's host-gateway support
# only arrived in v4.7, so skip extra_hosts for Podman.
if self._host_gateway_hostname == "host.docker.internal":
extra_hosts = create_kwargs.setdefault("extra_hosts", {})
extra_hosts[self._host_gateway_hostname] = "host-gateway"
logger.debug(
"Creating sandbox container: image=%s caps=%s exposed_ports=%s",

View file

@ -135,11 +135,16 @@ class TestPodmanSocketCandidates:
uid = os.getuid()
assert f"unix:///run/user/{uid}/podman/podman.sock" in candidates
def test_includes_tmpdir_when_set(self) -> None:
def test_includes_tmpdir_when_set_with_trailing_slash(self) -> None:
os.environ["TMPDIR"] = "/tmp/"
candidates = _podman_socket_candidates()
assert "unix:///tmp/podman/podman-machine-default-api.sock" in candidates
def test_includes_tmpdir_when_set_without_trailing_slash(self) -> None:
os.environ["TMPDIR"] = "/tmp"
candidates = _podman_socket_candidates()
assert "unix:///tmp/podman/podman-machine-default-api.sock" in candidates
def test_no_tmpdir_entry_when_not_set(self) -> None:
candidates = _podman_socket_candidates()
tmpdir_candidates = [c for c in candidates if "podman-machine-default-api" in c]