Podman sandboxes cannot reach host.openshell.internal
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 45/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- docker, linux, rust
- 領域
- backend, devops, networking
調査の方向性
The issue is in the Podman driver's network configuration for sandboxes. Look at the supervisor's DNS setup and how the host gateway address is passed in the runtime descriptor. Start by examining the Podman driver code and the networking isolation logic. The acceptance criteria include writing an automated Podman end-to-end test, so check existing test suites for networking. 'Done' means host.openshell.internal resolves and connects in a Podman sandbox after restart, with all mediation intact.
索引モデルが issue の本文から書いたものです。
説明
User Story
As an OpenShell user running sandboxes with the Podman driver, I want workloads to access services on the host through host.openshell.internal so that host access behaves consistently across supported local
compute drivers.
Problem Statement
Podman-backed sandboxes cannot reliably resolve and connect to host.openshell.internal.
OpenShell workloads use an isolated network namespace and rely on the supervisor for mediated network access. The Podman driver does not currently provide the workload with the expected supervisor DNS
configuration or pass the trusted host gateway address into the supervisor runtime descriptor. As a result, the host alias is unavailable even when the sandbox policy permits the connection.
Impact / Why This Matters
This prevents Podman users from accessing host-local development services, test fixtures, and other explicitly permitted endpoints through OpenShell’s standard host alias.
The current workaround is to use driver-specific host addresses or change the workload’s networking configuration. That workaround is insufficient because it is platform-dependent, bypasses the portable
host.openshell.internal contract, and may weaken the intended mediated-networking boundary.
Acceptance Criteria
- A Podman sandbox can resolve host.openshell.internal.
- A policy-authorized TCP connection through that alias reaches a service listening on the host.
- The connection continues to work after the sandbox is stopped and restarted.
- Workloads continue to use isolated networking and reach the host only through supervisor mediation.
- The configured host gateway address is validated before use.
- Driver-owned resolver resources are cleaned up on failed creation and sandbox deletion.
- An automated Podman end-to-end test covers initial creation and restart.
- Relevant architecture, networking, and gateway configuration documentation is updated.
Reproduction Steps
-
Start OpenShell with the Podman compute driver.
-
Start an HTTP server bound to a host-reachable loopback address and note its port.
-
Create a sandbox whose policy permits TCP access to host.openshell.internal:.
-
From the sandbox, attempt to connect to that address:
exec 3<>/dev/tcp/host.openshell.internal/
printf 'GET / HTTP/1.0\r\n\r\n' >&3
cat <&3 -
Observe that DNS resolution or the connection fails.
The same behavior should also be checked after stopping and restarting the sandbox
Environment
- Compute driver: Podman
- Host operating system: Linux
- Workload networking: isolated (network=none)
- Connection target: host.openshell.internal
Logs
- 主要言語
- Rust
- スター
- 8.7k
- フォーク
- 1.3k
- 平均マージ
- 2日 6時間
- マージ済み PR(30日)
- 297
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
NVIDIA/OpenShell のほかの issue
-
area:docs
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
-
state:triage-needed
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
-
area:cli state:validated
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
-
state:triage-needed
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
-
area:build spike state:review-ready state:stale
難易度 2/5 半日 初心者へのやさしさ 68/100
NVIDIA/OpenShell の issue をすべて見る
似ている issue
-
bug github_actions
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
registrystack/registry-stack#1393 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
longbridge/gpui-kit#3223 ·
-
bug engine
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
rocky-data/rocky#2181 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
oasisprotocol/oasis-sdk#2523 ·
-
[indexer] [QA] Add a focused test for the new NonRetryableError / assertSocketAlive() behavior. オープンbot:ai-assisted component:indexer QA-roadmap status:untriaged
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
midnightntwrk/midnight-indexer#1557 ·