git clone over HTTPS fails with socket error while node's HTTPS to the same host succeeds (secure-exec VM)
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 48/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- git, node.js, rust
- Lĩnh vực
- devtools, networking
Hướng nghiên cứu
Bắt đầu bằng cách tái hiện lỗi với vm.exec bằng git clone và probe TCP/HTTPS của Node cho kết quả thành công, sau đó đọc registry/native/crates/libs/git/README.md và kiểm tra hành vi truyền tải của package đã được publish. Xác định liệu việc clone qua HTTPS có được hỗ trợ hay không, errno 21 đại diện cho điều gì trong đường dẫn này và liệu các subcommand được báo cáo có phải là chủ đích hay không; hoàn tất khi hành vi truyền tải và các lỗi được giải thích hoặc sửa chữa.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Summary
git clone over HTTPS fails inside the secure-exec VM with a socket error, while node's own TCP and HTTPS reach the same host from the same VM in the same session. Network egress is permitted to github.com, so this looks like the git transport rather than the sandbox policy.
$ git clone https://github.com/octocat/Hello-World.git /tmp/repo
exit=128
Cloning into '/tmp/repo'...
fatal: fetch info/refs failed: socket error: connect(github.com:443) failed: errno 21
Immediately afterwards, in the same VM:
same VM, node stdlib to the same host:
TCP ok
HTTPS 200
Environment
@rivet-dev/agentos |
0.2.15 |
@agentos-software/git |
0.3.3 |
@agentos-software/common |
0.2.15 |
| engine | rivetdev/engine:2.3.9 (self-hosted) |
| worker base | node:24-slim |
VM permissions are default: deny with an explicit allowlist; github.com is allowed for both tcp://github.com:* and dns://github.com. A denied host fails differently and says so explicitly (EACCES … blocked by network.http policy), which is how we ruled the policy out — the message above is a socket error with no policy mention.
Reproduction
const vm = client.vm.getOrCreate("repro-" + Date.now());
// fails
await vm.exec("git clone https://github.com/octocat/Hello-World.git /tmp/repo");
// succeeds, same VM, same host
const probe = `
const net = require('net'), https = require('https');
net.connect({host:'github.com', port:443}, function(){ console.log('TCP ok'); this.destroy(); });
https.get({host:'github.com', path:'/', headers:{'User-Agent':'p'}}, r => { console.log('HTTPS ' + r.statusCode); r.destroy(); });
`;
await vm.exec(`node -e "eval(Buffer.from('${Buffer.from(probe).toString("base64")}','base64').toString())"`);
Questions
- Is HTTPS a supported clone transport for
@agentos-software/git? The error text points atregistry/native/crates/libs/git/README.md, which I can't see from the published package — the.aospkgdoes containgit://,ssh://andhttps://strings, so it reads as intended-but-not-working rather than unsupported. - If HTTPS is supported, does the git transport use a different egress path from node's stdlib — one that needs allowlisting separately from
tcp://host:port? That would explain a socket error while node succeeds. - What does
errno 21mean here? Other in-VM errors use WASI numbering (os error 44for ENOENT), which would make 21EFAULTand doesn't obviously fit aconnect().
Also, minor
A few subcommands report as unimplemented — flagging in case the list is unintentional rather than by design:
git --version→GitSubcommandUnsupportedgit log→GitSubcommandUnsupportedgit clone --depth 1 <url> <dest>→fatal: usage: git clone <source> [<destination>]
--version in particular is a common probe for "is git usable here", so it failing makes capability detection awkward.
Workaround
Fetching the repository as a tarball from codeload.github.com over plain HTTPS and unpacking with tar from @agentos-software/common, which works. Posting mainly because a working clone would give us verbatim transport output and ref handling that the tarball path doesn't.
- Ngôn ngữ chính
- Rust
- Star
- 4.7k
- Fork
- 263
- Merge trung bình
- 9 giờ 43 phút
- Pull request đã merge (30 ngày)
- 27
Chuẩn bị môi trường
Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của rivet-dev/agentos
-
Python edits to filesystem.writeFile-created files are reverted by shadow reconciliationCó thể đã có người làm @ankssjain đã nhận 2 ngày trước. Đang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 20/100
rivet-dev/agentos#2022 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 3/5 Nửa ngày Mức phù hợp với người mới 32/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Python launched through guest shell stalls on queued filesystem RPCsCó thể đã có người làm @ankssjain đã nhận 8 ngày trước. Đang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 52/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 66/100
rivet-dev/agentos#1994 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của rivet-dev/agentos
Issue tương tự
-
documentation enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
adorsys/status-list-server#619 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
batch-backport only backports the first 30 matching PRsCó thể đã có người làm @DvirDukhan đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 5 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 77/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
equinor/septic-config-generator#481 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
Maintainer thường phản hồi trong vòng 1 ngày