Docker not able to access device "/dev/kfd" when running without root

Hey forum,

kinda at my wits end here. Been trying to put my 7900XTX to good use, but have been failing at getting a simple development environment up and running. I strongly believe I have over-read something important along the way, but cannot figure out what.

Spun up a fresh Ubuntu 24.04.3 LTS running ZFS with Encryption.

Installed rocm through the official AMD quickstart-guide

wget https://repo.radeon.com/amdgpu-install/7.1.1/ubuntu/noble/amdgpu-install_7.1.1.70101-1_all.deb
sudo apt install ./amdgpu-install_7.1.1.70101-1_all.deb
sudo apt update
sudo apt install python3-setuptools python3-wheel
sudo usermod -a -G render,video $LOGNAME # Add the current user to the render and video groups
sudo apt install rocm

wget https://repo.radeon.com/amdgpu-install/7.1.1/ubuntu/noble/amdgpu-install_7.1.1.70101-1_all.deb
sudo apt install ./amdgpu-install_7.1.1.70101-1_all.deb
sudo apt update
sudo apt install "linux-headers-$(uname -r)" "linux-modules-extra-$(uname -r)"
sudo apt install amdgpu-dkms

Then followed the tutorial on getting pytorch up and running in docker. Installed docker:

# Add Docker's official GPG key:
sudo apt update
sudo apt install ca-certificates curl
sudo install -m 0755 -d /etc/apt/keyrings
sudo curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc
sudo chmod a+r /etc/apt/keyrings/docker.asc

# Add the repository to Apt sources:
sudo tee /etc/apt/sources.list.d/docker.sources <<EOF
Types: deb
URIs: https://download.docker.com/linux/ubuntu
Suites: $(. /etc/os-release && echo "${UBUNTU_CODENAME:-$VERSION_CODENAME}")
Components: stable
Signed-By: /etc/apt/keyrings/docker.asc
EOF

sudo apt update

sudo apt install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin

# Check running
sudo systemctl status docker

# Download and install Docker Desktop
sudo apt-get update
sudo apt install ./docker-desktop-amd64.deb

Then head on over to the pytorch rocm guide

docker pull rocm/pytorch:latest

docker run -it \
    --cap-add=SYS_PTRACE \
    --security-opt seccomp=unconfined \
    --device=/dev/kfd \
    --device=/dev/dri \
    --group-add video \
    --ipc=host \
    --shm-size 8G \
    rocm/pytorch:latest

And herein lies the crux of the issue. Specifically with /dev/kfd which docker won’t get access to when run without sudo.

docker: Error response from daemon: error gathering device information while adding custom device "/dev/kfd": no such file or directory

Since I’m trying to spin up a VSCode Dev Container to use for development I found a guide which converted the docker run command into a devcontainer.json. However since VSCode runs docker run as none root the same issue appears.

ls -la /dev/kfd
crw-rw---- 1 root render 235, 0 Jan 18 21:14 /dev/kfd

I believe the fix would be easy in giving docker access to /dev/kfd which currently only the root & render group have, however I’m currently failing at doing so and haven’t been able to find info or a guide from AMD on how to go about this. Looking at the how-to on running docker containers by AMD, I cannot find a single mention of this.

In general I do not understand how AMD envisions users to use their rocm stack right now.

Any help would be greatly appreciated.

I see you have only the video group in the --group-add option, can you also include the render group in there? Or who knows, maybe just reboot the computer?

Ye probably just needs to add the render group and i believe also the linux user under which the docker container is running have to be part of that group

I was just about to suggest that @leucht add the user who runs the Docker container to the render group.

1 Like

@Vishal_Rao @wUFr @Shadowbane

sorry for the delayed response, time-zone are a fun thing

had actually tried adding both options late last night, before heading to bed but sadly not luck, after I noticed both the official AMD tutorial and the guide only required the --groud-add video be present (full example below).

I just tried it again, just for my own sanity and no dice. Also the system has been rebooted at least twice since now and then.

the user running the docker container should have been taken care off by an additional step in the official guide

sudo usermod -a -G render,video $LOGNAME

which I just copy and pasted upon setup.

docker run -it \
    --name=dev \
    --cap-add=SYS_PTRACE \
    --security-opt seccomp=unconfined \
    --device=/dev/kfd \
    --device=/dev/dri \
    --group-add video \
    --group-add render \
    --ipc=host \
    --shm-size 8G \
    rocm/pytorch:latest

Hi,
I had Docker Desktop installed and running. After a logging out and not starting Docker Desktop again i was able to run the container with /dev/kdf just fine.

However, when Docker Desktop was running, I received the same error.

Hopefully this helps :slight_smile:

3 Likes

That actually seems to be it, wtf. So having docker desktop running causes the fault.

Thank you very much for the suggestion. I would have probably never thought to try that.

4 Likes