Repository navigation
Add a loopback proxy, forwarded ports, and exec environments to the native-host backend - #420
Closed
Enrique Saurez (esaurez) wants to merge 1 commit into
Closed
Enrique Saurez (esaurez) wants to merge 1 commit into
Enrique Saurez (esaurez) wants to merge 1 commit into
Conversation
The native-host backend accepts two more provision options. A runtimeConfig.networkProxy names an HTTP or HTTPS proxy on host loopback; it must be the guest's only way out, so the network policy denies egress without rules. The guest reaches the proxy over TCP at its gateway, and every workload gets HTTP_PROXY, HTTPS_PROXY, and NO_PROXY in both cases, pointing there. microvm.provision.hostLoopbackForwards publishes guest TCP and UDP ports on host loopback; forwarded ports need hostLoopback allow and an egress default of allow, because the guest's replies pass the egress filter. Executions may now set a working directory and environment variables layered over the guest's defaults (inheritDefaultEnv). Callers can never set the proxy variables. ExecuteCommandRequest gains working_directory and environment, and the guest runtime ABI moves to microvm-abi-v2-edge-ramfs-v3. New guest tests prove that the proxy is the only way out, that forwarded TCP and UDP ports reach guest listeners, and that the largest accepted environment reaches the workload. The example gains matching options. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This was referenced Oct 7, 2026
Contributor
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replaces #414 on the rebased stack. Stacked on #419. Adds a host-loopback proxy, forwarded ports, and exec environments to the opt-in native-host backend.
Summary
runtimeConfig.networkProxy(ProvisionRequest::with_network_proxy) names anhttporhttpsproxy on host loopback with an explicit port. As in MXC's schema, the proxy is the guest's only way out, so the network policy must deny egress without allow or deny rules. The guest's only reachable destination is TCP to its gateway at the proxy's port, which OpenVMM connects to the proxy. Every workload getsHTTP_PROXY,HTTPS_PROXY,http_proxy, andhttps_proxynaming the proxy at the gateway, plusNO_PROXYandno_proxyset tolocalhost,127.0.0.1. Callers can never set these variables, with or without a proxy.microvm.provision.hostLoopbackForwards(ProvisionRequest::with_host_loopback_forward) publishes up to 64 guest TCP or UDP ports on host loopback. Forwarded ports neednetwork.ingress.hostLoopback: allow, an egress default ofallow, and no deny rule that covers the guest network, because OpenVMM filters the guest's replies. In OpenVMM,hostLoopback: allowalso lets the guest reach host loopback services through its gateway.allowwithout forwarded ports is still rejected, and a proxy and forwarded ports cannot be combined.process.cwdandprocess.envwithinheritDefaultEnv: truenow apply, layered over the guest's defaultPATH(at most 256 entries and 32 KiB). Replacing the default environment still fails withpolicy_validation.ExecuteCommandRequestgainsworking_directoryandenvironment.NetworkCapabilitiesgainsnetwork_proxyandhost_loopback_forwards; validation acceptshostLoopback: allowonly together with forwarded ports. The private library plans every combination rule, so an unenforceable policy fails provision withpolicy_validation.microvm-abi-v2-edge-ramfs-v3.a_loopback_proxy_is_the_only_way_out,forwarded_ports_publish_guest_listeners_on_host_loopback, andexec_environments_layer_over_the_guest_defaults. The example takes--network-proxy,--host-loopback,--host-loopback-forward,--env, and--cwd.Dependencies
--network-proxy,--host-loopback, and--host-loopback-forward.Changes since #414
None: the commit replays onto the rebased stack unchanged.
Validation
cargo test --all-featuresand Clippy with-D warningson all targets with--all-features, on Windows with Rust 1.93 (135, 137, 139, 139, and 140 unit tests).5b0a315), on Windows and on Linux with Rust 1.93: the crate's CI checks, which are fmt, Clippy with--all-featuresand with--no-default-features, tests with--all-featuresand with default features, docs with-D warnings,cargo +1.89 check, and, on Linux, the macOS build check. The pinned library test passes against freshly builtnvxhost.dllandlibnvxhost.so.--release --test-threads=1, each checking that no OpenVMM process outlives its sandbox, withdev's Linux 6.18.38 kernel:amd.milan.v1serves: all pass, in about 100 s, and again with a host profile;The new tests check, among others, that the six proxy variables are exactly the gateway URL and
localhost,127.0.0.1; that TCP to the proxy's port reaches the host proxy while UDP to the same port, another host loopback port, and a host service are blocked; that forwarded TCP and UDP ports reach guest listeners; and that the largest accepted environment (240 entries of control characters, 32,640 bytes) reaches the workload.Notes