opencode sandbox policy: npm child-process CONNECT denied (ECONNRESET) and no Vertex AI / WIF egress
还没有人认领这个 Issue。
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 74/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- node.js, yaml
调研方向
Start by reading sandboxes/base/policy.yaml and sandboxes/gemini/policy.yaml, then compare the existing npm policies for droid and ollama and the Google host set in the gemini policy. Reproduce the npm install and Vertex AI/WIF requests, and consider the issue done when both policies permit the required npm processes and Google endpoints without breaking the existing sandbox rules.
由索引模型根据 Issue 内容生成。
描述
Summary
The opencode network policy (in both sandboxes/base/policy.yaml and sandboxes/gemini/policy.yaml) has two egress gaps that break real-world OpenCode usage:
-
npm installs fail with
ECONNRESET.registry.npmjs.orgis listed as an endpoint, but thenpmbinary is not in the policy'sbinaries:allowlist. When opencode spawns a backgroundnpm install(arborist), the connecting process is/usr/local/bin/npm(or/usr/bin/npm), not
the allowlisted opencode/node binaries, so its CONNECT toregistry.npmjs.orgis denied. -
No Google / Vertex AI egress. The
opencodepolicy has zero Google hosts, so running OpenCode against agoogle-vertex-*provider (Vertex AI, including Workload Identity Federation) cannot reach the requiredGoogle endpoints.
Environment
- Base image:
nvcr.io/nvidia/base/ubuntu:noble-20251013(Ubuntu 24.04) - Node
22.22.1-1nodesource1, npm11.11.0,opencode-ai@1.2.18(global) - Sandbox invoked non-interactively:
openshell sandbox exec -- sh -c <cmd>
Repro - npm ECONNRESET
- Start an opencode sandbox.
- In a repo whose deps aren't fully installed, trigger opencode's background dependency install (or run
npm installdirectly). - The CONNECT to
registry.npmjs.orgis denied →ECONNRESET.
Expected: npm reaches registry.npmjs.org (endpoint already allowlisted).
Actual: connection reset, because the npm binary isn't in the opencode policy's binaries: list.
Root cause: policy pairs are (binary, endpoint). registry.npmjs.org is a plain CONNECT tunnel (no tls: terminate), so this is not TLS-MITM - it is a binary allowlist gap. droid and ollama already ship dedicated npm policies; opencode never allowlists npm.
Repro - Vertex AI / WIF egress
- Configure opencode with a
google-vertex-anthropic/*model. - Run any request.
- Auth token exchange and inference fail: no route to
sts.googleapis.com,oauth2.googleapis.com, or*-aiplatform.googleapis.com.
Note: the gemini policy ships the Google auth host set but uses service-account impersonation, so it lacks sts.googleapis.com.
GitHub-OIDC Workload Identity Federation additionally requires sts.googleapis.com:443.
Proposed fix
- Add
/usr/local/bin/npmand/usr/bin/npmto theopencodepolicy'sbinaries:(or a shared dedicatednpmpolicy as droid/ollama do). - Add the Vertex AI + Google token hosts (mirroring
gemini, plussts.googleapis.comfor WIF) to theopencodepolicy'sendpoints:.
A PR applying (1) and (2) to the base and gemini policies will follow.
- 主要语言
- Dockerfile
- 星标
- 191
- 派生
- 76
- PR 合并指标
- 30 天内没有已合并 PR
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
NVIDIA/OpenShell-Community 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 68/100
-
难度 2/5 1-3 小时 新手友好度 68/100
-
难度 5/5 一周以上 新手友好度 25/100
-
难度 4/5 3-5 天 新手友好度 45/100
-
难度 4/5 3-5 天 新手友好度 35/100
查看 NVIDIA/OpenShell-Community 的全部 Issue
相似的 Issue
-
kind/bug
难度 2/5 1-3 小时 新手友好度 88/100
kubernetes-sigs/prow#953 · 1 条评论 ·
-
难度 2/5 1-3 小时 新手友好度 78/100
-
agent/security hive/hosted-available-lke648397-260827-5n31 security
难度 2/5 1-3 小时 新手友好度 84/100
-
难度 2/5 1-3 小时 新手友好度 92/100
conceptadev/noir#95 ·
-
automated issue report
难度 2/5 1-3 小时 新手友好度 72/100