NVIDIA / NVIDIA/OpenShell

Failed peer-binary resolution during policy DENY crashes the supervisor session, tearing down the sandbox's SSH relay

Open
#3,311 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

state:triage-needed
Dominant language
Rust
Stars
8.7k
Forks
1.3k
Avg merge
2d 11h
Merged PRs (30d)
253

Description

Summary

A single correctly denied outbound request — not a bypass attempt, not a policy misconfiguration, just an app trying to reach a host that isn't allowlisted — can kill the whole sandbox. That's a significant reliability/security-usability problem: the failure mode of "policy correctly blocks something" should be "request fails," not "sandbox dies."

Steps to reproduce

  1. openshell sandbox create with a policy that does not allowlist a host the sandbox's main command will try to reach (in our repro: openclaw-start, whose onboarding flow reaches registry.npmjs.org:443, not present in the default policy's nvidia/nvidia_web/github/github_rest_api/gitlab/claude_code network_policies).
  2. Attach to the sandbox over SSH and let the onboarding flow run.
  3. Observe the denied request in openshell logs <name>.
  4. Within ~1 second, observe the supervisor session error/end in the same log, and the SSH client disconnect (client_loop: send disconnect: Broken pipe).
  5. openshell sandbox get <name>Phase: Error, no recovery available.

Logs (two independent reproductions)

Run 1 (sandbox 42449366-d949-4285-b787-aa7415570ccf):

[1789391073.953] NET:OPEN [MED] DENIED -> registry.npmjs.org:443 [reason:failed to resolve peer binary: No ESTABLISHED TCP connection found for 10.200.0.2:46932 -> 10.200.0.1:3128 in /proc/54/net/tcp{,6}]
[1789391074.213] [gateway] [WARN] relay stream: inbound errored
[1789391074.213] [gateway] [WARN] supervisor session: stream error
[1789391074.213] [gateway] [INFO] supervisor session: ended

Run 2 (sandbox 9e489e30-42f3-411a-983d-...):

[1789394150.856] NET:OPEN [MED] DENIED -> registry.npmjs.org:443 [reason:failed to resolve peer binary: No ESTABLISHED TCP connection found for 10.200.0.2:46932 -> 10.200.0.1:3128 in /proc/53/net/tcp{,6}]
[1789394151.798] [gateway] [WARN] relay stream: inbound errored
[1789394151.798] [gateway] [WARN] supervisor session: stream error
[1789394151.798] [gateway] [INFO] supervisor session: ended

Expected

A policy DENY — including one where peer-binary resolution fails — should result in the connection attempt failing cleanly from the sandboxed process's point of view. It should never crash the supervisor session or bring down the sandbox.

Suspected area

The peer-binary resolution path in the OPA-backed network policy engine (openshell_supervisor_network::opa), specifically the branch when no matching entry is found in /proc/<pid>/net/tcp{,6} for the connecting socket — this looks like a race (the connecting process's socket may have already closed/reused by the time policy inspects /proc) that isn't handled gracefully and instead propagates into the supervisor session, killing it.

openshell version: 0.0.116


Related: #3308

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in the OPA-backed network policy engine entry point openshell_supervisor_network::opa, tracing the peer-binary resolution branch that inspects /proc/<pid>/net/tcp{,6}. Reproduce the denied request and follow how a missing matching socket entry reaches the supervisor session; done means the denied connection fails cleanly without ending the relay or moving the sandbox to Error.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
networking, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.