Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

opencode sandbox policy: npm child-process CONNECT denied (ECONNRESET) and no Vertex AI / WIF egress

Open
#91 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
74/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
node.js, yaml

Research direction

Start by reading sandboxes/base/policy.yaml and sandboxes/gemini/policy.yaml, then compare the existing npm policies for droid and ollama and the Google host set in the gemini policy. Reproduce the npm install and Vertex AI/WIF requests, and consider the issue done when both policies permit the required npm processes and Google endpoints without breaking the existing sandbox rules.

Written by the indexing model from the issue text.

Description

Summary

The opencode network policy (in both sandboxes/base/policy.yaml and sandboxes/gemini/policy.yaml) has two egress gaps that break real-world OpenCode usage:

  1. npm installs fail with ECONNRESET. registry.npmjs.org is listed as an endpoint, but the npm binary is not in the policy's binaries: allowlist. When opencode spawns a background npm install (arborist), the connecting process is /usr/local/bin/npm (or /usr/bin/npm), not
    the allowlisted opencode/node binaries, so its CONNECT to registry.npmjs.org is denied.

  2. No Google / Vertex AI egress. The opencode policy has zero Google hosts, so running OpenCode against a google-vertex-* provider (Vertex AI, including Workload Identity Federation) cannot reach the requiredGoogle endpoints.

Environment
  • Base image: nvcr.io/nvidia/base/ubuntu:noble-20251013 (Ubuntu 24.04)
  • Node 22.22.1-1nodesource1, npm 11.11.0, opencode-ai@1.2.18 (global)
  • Sandbox invoked non-interactively: openshell sandbox exec -- sh -c <cmd>
Repro - npm ECONNRESET
  1. Start an opencode sandbox.
  2. In a repo whose deps aren't fully installed, trigger opencode's background dependency install (or run npm install directly).
  3. The CONNECT to registry.npmjs.org is denied → ECONNRESET.

Expected: npm reaches registry.npmjs.org (endpoint already allowlisted).
Actual: connection reset, because the npm binary isn't in the opencode policy's binaries: list.

Root cause: policy pairs are (binary, endpoint). registry.npmjs.org is a plain CONNECT tunnel (no tls: terminate), so this is not TLS-MITM - it is a binary allowlist gap. droid and ollama already ship dedicated npm policies; opencode never allowlists npm.

Repro - Vertex AI / WIF egress
  1. Configure opencode with a google-vertex-anthropic/* model.
  2. Run any request.
  3. Auth token exchange and inference fail: no route to sts.googleapis.com, oauth2.googleapis.com, or *-aiplatform.googleapis.com.

Note: the gemini policy ships the Google auth host set but uses service-account impersonation, so it lacks sts.googleapis.com.
GitHub-OIDC Workload Identity Federation additionally requires sts.googleapis.com:443.

Proposed fix
  1. Add /usr/local/bin/npm and /usr/bin/npm to the opencode policy's binaries: (or a shared dedicated npm policy as droid/ollama do).
  2. Add the Vertex AI + Google token hosts (mirroring gemini, plus sts.googleapis.com for WIF) to the opencode policy's endpoints:.

A PR applying (1) and (2) to the base and gemini policies will follow.

Dominant language
Dockerfile
Stars
191
Forks
76
PR merge metrics
No merged PRs in 30d

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from NVIDIA/OpenShell-Community

All issues in NVIDIA/OpenShell-Community

Similar issues

More DevOps issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.