Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

Podman sandboxes cannot reach host.openshell.internal

Offen
#3,605 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Anfängerfreundlichkeit
45/100
Issue-Typ
Bug
Klarheit
Klar beschrieben
Aktivitätsstatus
Aktiv
Tech-Stack
docker, linux, rust

Rechercherichtung

The issue is in the Podman driver's network configuration for sandboxes. Look at the supervisor's DNS setup and how the host gateway address is passed in the runtime descriptor. Start by examining the Podman driver code and the networking isolation logic. The acceptance criteria include writing an automated Podman end-to-end test, so check existing test suites for networking. 'Done' means host.openshell.internal resolves and connects in a Podman sandbox after restart, with all mediation intact.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

state:triage-needed
User Story

As an OpenShell user running sandboxes with the Podman driver, I want workloads to access services on the host through host.openshell.internal so that host access behaves consistently across supported local
compute drivers.

Problem Statement

Podman-backed sandboxes cannot reliably resolve and connect to host.openshell.internal.

OpenShell workloads use an isolated network namespace and rely on the supervisor for mediated network access. The Podman driver does not currently provide the workload with the expected supervisor DNS
configuration or pass the trusted host gateway address into the supervisor runtime descriptor. As a result, the host alias is unavailable even when the sandbox policy permits the connection.

Impact / Why This Matters

This prevents Podman users from accessing host-local development services, test fixtures, and other explicitly permitted endpoints through OpenShell’s standard host alias.

The current workaround is to use driver-specific host addresses or change the workload’s networking configuration. That workaround is insufficient because it is platform-dependent, bypasses the portable
host.openshell.internal contract, and may weaken the intended mediated-networking boundary.

Acceptance Criteria
  • A Podman sandbox can resolve host.openshell.internal.
  • A policy-authorized TCP connection through that alias reaches a service listening on the host.
  • The connection continues to work after the sandbox is stopped and restarted.
  • Workloads continue to use isolated networking and reach the host only through supervisor mediation.
  • The configured host gateway address is validated before use.
  • Driver-owned resolver resources are cleaned up on failed creation and sandbox deletion.
  • An automated Podman end-to-end test covers initial creation and restart.
  • Relevant architecture, networking, and gateway configuration documentation is updated.
Reproduction Steps
  1. Start OpenShell with the Podman compute driver.

  2. Start an HTTP server bound to a host-reachable loopback address and note its port.

  3. Create a sandbox whose policy permits TCP access to host.openshell.internal:.

  4. From the sandbox, attempt to connect to that address:

    exec 3<>/dev/tcp/host.openshell.internal/
    printf 'GET / HTTP/1.0\r\n\r\n' >&3
    cat <&3

  5. Observe that DNS resolution or the connection fails.

The same behavior should also be checked after stopping and restarting the sandbox

Environment
  • Compute driver: Podman
  • Host operating system: Linux
  • Workload networking: isolated (network=none)
  • Connection target: host.openshell.internal
Logs

Vorherrschende Sprache
Rust
Sterne
8.7k
Forks
1.3k
Ø Merge
2 T. 6 Std.
Gemergte PRs (30 T.)
297

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus NVIDIA/OpenShell

Alle Issues in NVIDIA/OpenShell

Ähnliche Issues

Weitere Issues zu Rust

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.