bug(vm): per-sandbox Unix socket paths exceed macOS sun_path limit
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 55/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- macos, rust
调研方向
从 VM compute driver 的每个 sandbox 的 socket 路径构造开始,使用默认的 state_dir 复现 macOS bind 失败。跟踪 sandbox 目录的创建和恢复过程,然后验证修订后的路径仍在 macOS 限制范围内,保留发现和持久化,并且 run/compute-driver.sock 保持不变。
由索引模型根据 Issue 内容生成。
描述
User Story
As a developer running the VM compute driver on macOS, I want per-sandbox Unix socket paths to fit within the OS sun_path limit so that sandbox creation does not fail with a socket bind error.
Problem Statement
The VM driver constructs per-sandbox Unix socket paths by joining {state_dir}/sandboxes/{sandbox_id}/{socket_name}. Sandbox IDs are UUID v4 strings (36 chars), and state_dir depends on the user's home directory. On macOS, struct sockaddr_un.sun_path is 104 bytes (103 usable). With the default state_dir (~/.local/state/openshell/vm-driver), the resulting socket path reaches 107 bytes — 3 bytes over the limit — and bind() fails.
/Users/benoitf/.local/state/openshell/vm-driver/sandboxes/3eb2ad45-bead-4c2e-bd10-1a4a7f3a2721/control.sock
└─────────────────────────────────── 107 bytes ──────────────────────────────────────┘
Path length breakdown:
/Users/benoitf/.local/state/openshell/vm-driver (47)
/sandboxes/ (11)
3eb2ad45-bead-4c2e-bd10-1a4a7f3a2721 (36)
/control.sock (13)
total = 107 bytes
macOS limit = 104 bytes
over by 3 bytes
Impact / Why This Matters
When this happens, VM sandbox creation fails at the control socket bind step. The error surfaces as a low-level socket error, not as a clear path-length diagnostic.
The current workaround is to manually configure a short state_dir (e.g. /tmp/os-vm). or rename control.sock for ctl.sock for my case (as I reduced 3 extra chars)
This is non-obvious, fragile, and breaks persistence expectations. Any user whose home directory path is longer than /Users/benoitf (15 chars) would be even further over the limit.
Linux is less affected (108-byte limit) but not immune with deep state directories or longer usernames.
Acceptance Criteria
- Per-sandbox Unix socket paths fit within 103 usable bytes on macOS for any reasonable
state_dir - The fix does not break sandbox state directory layout or persistence/restore
- Existing sandbox directories remain discoverable (sandbox ID must still be recoverable from the filesystem)
- The gateway compute-driver socket path (
run/compute-driver.sock) remains unaffected
Reproduction Steps
- On macOS, start the gateway with
--compute-driver vmusing the defaultstate_dir(~/.local/state/openshell/vm-driver) - Run
openshell sandbox create --name test --from ubuntu:24.04 - Observe the sandbox creation fails at the control socket bind
Environment
- OpenShell: development build (current main branch)
- OS: macOS (Apple Silicon) —
sun_pathis 104 bytes - Runtime: VM compute driver (libkrun)
Logs
Error: bind() failed for /Users/benoitf/.local/state/openshell/vm-driver/sandboxes/3eb2ad45-bead-4c2e-bd10-1a4a7f3a2721/control.sock
- 主要语言
- Rust
- 星标
- 8.7k
- 派生
- 1.3k
- 平均合并
- 1 天 21 小时
- 30 天内合并 PR
- 312
环境准备
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
NVIDIA/OpenShell 的其他 Issue
-
area:docs
难度 1/5 1 小时以内 新手友好度 88/100
维护者通常 1 天内回复
-
state:triage-needed
难度 2/5 1-3 小时 新手友好度 82/100
NVIDIA/OpenShell#3400 · 1 条评论 ·
维护者通常 1 天内回复
-
area:cli state:validated
难度 2/5 1-3 小时 新手友好度 72/100
NVIDIA/OpenShell#2888 · 1 条评论 ·
维护者通常 1 天内回复
-
state:triage-needed
难度 1/5 1 小时以内 新手友好度 90/100
维护者通常 1 天内回复
-
area:build spike state:review-ready state:stale
难度 2/5 半天 新手友好度 68/100
NVIDIA/OpenShell#2401 · 1 条评论 ·
维护者通常 1 天内回复
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 84/100
-
area: cli bug priority: P2 ready-for-agent
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 74/100
维护者通常 2 天内回复
-
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 2 天内回复
-
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复