Failed peer-binary resolution during policy DENY crashes the supervisor session, tearing down the sandbox's SSH relay

Aperta
#3,311 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
48/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
rust

Direzione di ricerca

Inizia dal punto di ingresso del motore delle policy di rete basato su OPA, openshell_supervisor_network::opa, seguendo il ramo di risoluzione del peer-binary che esamina /proc/<pid>/net/tcp{,6}. Riproduci la richiesta negata e segui il percorso con cui una voce socket corrispondente mancante raggiunge la sessione del supervisor; il lavoro è completato quando la connessione negata fallisce correttamente senza terminare il relay né spostare la sandbox in Error.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

state:triage-needed

Summary

A single correctly denied outbound request — not a bypass attempt, not a policy misconfiguration, just an app trying to reach a host that isn't allowlisted — can kill the whole sandbox. That's a significant reliability/security-usability problem: the failure mode of "policy correctly blocks something" should be "request fails," not "sandbox dies."

Steps to reproduce

  1. openshell sandbox create with a policy that does not allowlist a host the sandbox's main command will try to reach (in our repro: openclaw-start, whose onboarding flow reaches registry.npmjs.org:443, not present in the default policy's nvidia/nvidia_web/github/github_rest_api/gitlab/claude_code network_policies).
  2. Attach to the sandbox over SSH and let the onboarding flow run.
  3. Observe the denied request in openshell logs <name>.
  4. Within ~1 second, observe the supervisor session error/end in the same log, and the SSH client disconnect (client_loop: send disconnect: Broken pipe).
  5. openshell sandbox get <name>Phase: Error, no recovery available.

Logs (two independent reproductions)

Run 1 (sandbox 42449366-d949-4285-b787-aa7415570ccf):

[1789391073.953] NET:OPEN [MED] DENIED -> registry.npmjs.org:443 [reason:failed to resolve peer binary: No ESTABLISHED TCP connection found for 10.200.0.2:46932 -> 10.200.0.1:3128 in /proc/54/net/tcp{,6}]
[1789391074.213] [gateway] [WARN] relay stream: inbound errored
[1789391074.213] [gateway] [WARN] supervisor session: stream error
[1789391074.213] [gateway] [INFO] supervisor session: ended

Run 2 (sandbox 9e489e30-42f3-411a-983d-...):

[1789394150.856] NET:OPEN [MED] DENIED -> registry.npmjs.org:443 [reason:failed to resolve peer binary: No ESTABLISHED TCP connection found for 10.200.0.2:46932 -> 10.200.0.1:3128 in /proc/53/net/tcp{,6}]
[1789394151.798] [gateway] [WARN] relay stream: inbound errored
[1789394151.798] [gateway] [WARN] supervisor session: stream error
[1789394151.798] [gateway] [INFO] supervisor session: ended

Expected

A policy DENY — including one where peer-binary resolution fails — should result in the connection attempt failing cleanly from the sandboxed process's point of view. It should never crash the supervisor session or bring down the sandbox.

Suspected area

The peer-binary resolution path in the OPA-backed network policy engine (openshell_supervisor_network::opa), specifically the branch when no matching entry is found in /proc/<pid>/net/tcp{,6} for the connecting socket — this looks like a race (the connecting process's socket may have already closed/reused by the time policy inspects /proc) that isn't handled gracefully and instead propagates into the supervisor session, killing it.

openshell version: 0.0.116


Related: #3308

Lingua principale
Rust
Stelle
8.7k
Fork
1.3k
Merge medio
2g 7h
PR unite (30g)
243

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di NVIDIA/OpenShell

Tutte le issue di NVIDIA/OpenShell

Issue simili

Altre issue su Rust

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.