Repository navigation
Add a loopback proxy, forwarded ports, and exec environments to the native-host backend - #414
Closed
Enrique Saurez (esaurez) wants to merge 1 commit into
Closed
Enrique Saurez (esaurez) wants to merge 1 commit into
Enrique Saurez (esaurez) wants to merge 1 commit into
Conversation
The native-host backend accepts two more provision options. A runtimeConfig.networkProxy names an HTTP or HTTPS proxy on host loopback; it must be the guest's only way out, so the network policy denies egress without rules. The guest reaches the proxy over TCP at its gateway, and every workload gets HTTP_PROXY, HTTPS_PROXY, and NO_PROXY in both cases, pointing there. microvm.provision.hostLoopbackForwards publishes guest TCP and UDP ports on host loopback; forwarded ports need hostLoopback allow and an egress default of allow, because the guest's replies pass the egress filter. Executions may now set a working directory and environment variables layered over the guest's defaults (inheritDefaultEnv). Callers can never set the proxy variables. ExecuteCommandRequest gains working_directory and environment, and the guest runtime ABI moves to microvm-abi-v2-edge-ramfs-v3. New guest tests prove that the proxy is the only way out, that forwarded TCP and UDP ports reach guest listeners, and that the largest accepted environment reaches the workload. The example gains matching options. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This was referenced Oct 6, 2026
Contributor
Author
|
Superseded by #418, which carries this change on |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Stacked on #407. Adds a host-loopback proxy, forwarded ports, and exec environments to the opt-in native-host backend.
runtimeConfig.networkProxy(ProvisionRequest::with_network_proxy) names anhttporhttpsproxy on host loopback with an explicit port. As in MXC's schema, the proxy is the guest's only way out, so the network policy must deny egress without allow or deny rules. The guest's only reachable destination is TCP to its gateway at the proxy's port, which OpenVMM connects to the proxy. Every workload getsHTTP_PROXY,HTTPS_PROXY,http_proxy, andhttps_proxynaming the proxy at the gateway, plusNO_PROXYandno_proxyset tolocalhost,127.0.0.1. Callers can never set these variables, with or without a proxy.microvm.provision.hostLoopbackForwards(ProvisionRequest::with_host_loopback_forward) publishes up to 64 guest TCP or UDP ports on host loopback. Forwarded ports neednetwork.ingress.hostLoopback: allow, an egress default ofallow, and no deny rule that covers the guest network, because OpenVMM filters the guest's replies. In OpenVMM,hostLoopback: allowalso lets the guest reach host loopback services through its gateway.allowwithout forwarded ports is still rejected, and a proxy and forwarded ports cannot be combined.process.cwdandprocess.envwithinheritDefaultEnv: truenow apply, layered over the guest's defaultPATH(at most 256 entries and 32 KiB). Replacing the default environment still fails withpolicy_validation.ExecuteCommandRequestgainsworking_directoryandenvironment.NetworkCapabilitiesgainsnetwork_proxyandhost_loopback_forwards; validation acceptshostLoopback: allowonly together with forwarded ports. The private library plans every combination rule, so an unenforceable policy fails provision withpolicy_validation.microvm-abi-v2-edge-ramfs-v3.a_loopback_proxy_is_the_only_way_out,forwarded_ports_publish_guest_listeners_on_host_loopback, andexec_environments_layer_over_the_guest_defaults. The example takes--network-proxy,--host-loopback,--host-loopback-forward,--env, and--cwd.Dependencies
9524065already provides--network-proxy,--host-loopback, and--host-loopback-forward.Validation (head
f8eec4c)cargo test --features nvxhost,testing,async(136 unit tests plus every integration suite) and the defaultcargo test(102 unit tests); Clippy with-D warningson all targets for both configurations;cargo +1.89 checkfor both.--release --test-threads=1, each checking that no OpenVMM process outlives its sandbox:localhost,127.0.0.1; TCP to the proxy's port reaches the host proxy, while UDP to the same port, another host loopback port, and a host service are blocked; a proxy with egress rules or with egressallow, a remote or IPv6 proxy, a proxy without a port, and an exec that sets a proxy variable all fail withpolicy_validation;denyfail withpolicy_validation;PATHcan be replaced, a missing directory ends the command with 126 andNVX-EDGE-STAGE-ERROR, and the largest accepted environment (240 entries of control characters, 32,640 bytes) reaches the workload./tmp, prints/tmpandB|two words|http://10.0.0.1:3128|localhost,127.0.0.1.Notes
execve's per-string limit once encoded (the new environment test failed with the earlier guest); the forwarding test bounds its waits and retries a start when another process takes a released port; and a doc comment was reworded. It also noted that stored plans are revalidated but not authenticated. That is the existing trust model; the README now says that the plan also decides the proxy port and forwarded ports.