Skip to content

feat(mxc): relay ingress and egress through an AppContainer proxy peer - #4330

Open
pkhodade-NV wants to merge 2 commits into
windowsfrom
feat/mxc-proxy-peer-relay
Open

pkhodade-NV wants to merge 2 commits into
windowsfrom
feat/mxc-proxy-peer-relay

Conversation

@pkhodade-NV

Copy link
Copy Markdown
Collaborator

Summary

Adds an opt-in proxy-peer mode to the MXC ProcessContainer driver for sandboxes that run with MXC networkProxy, where in-sandbox loopback dials (including the supervisor relay's dial to the target port) are blocked.

  • The gateway spawns a per-sandbox AppContainer peer (openshell-mxc-peer, a second bin in openshell-driver-mxc). The peer listens on loopback for MXC's networkProxy / allowedProxyPeer and bridges to the gateway over named pipes with a DACL limited to the user and the peer's AppContainer profile.
  • Ingress: a peer-backed forward listener (start_peer_relay) with the same nonce-authenticated contract as start_control_channel_relay.
  • Egress: the peer tunnels proxy connections to the host egress proxy. Tunnelled connections are aliased through a new ForwardedClients registry so Windows identity resolution works, and the per-sandbox password check is skipped for them (MXC-injected proxy variables carry no credentials).
  • Supervisor relay: keeps the HTTP(S)_PROXY variables MXC injects when it clears the environment for the launched target (NO_PROXY is never inherited).
  • New driver option pc_proxy_peer_path with validation (absolute path, process_container backend, requires relay spawner + target port, incompatible with pc_network_allow / pc_allow_local_network). README gains a "Proxy-peer mode" section.

Requires MXC schema 0.9.0-alpha (allowedProxyPeer); peer mode rewrites the one-shot config accordingly. Default behavior is unchanged when the option is unset.

Testing

  • cargo test --package openshell-driver-mxc --lib (139 pass), openshell-supervisor-network --lib (1248 pass, 2 ignored), peer bin (2 pass), relay bin (7 pass, 3 new), on x86_64-pc-windows-msvc.
  • End-to-end on Windows x64: OpenShell + MXC ProcessContainer running OpenClaw, host health check through the forwarded port: PASS in both ingress-only and ingress+egress modes. Egress proof: allowed host via proxy 200, denied host blocked, direct internet bypass EACCES, unrelated host loopback EACCES, 0 credential rejections, peer process and AppContainer profile cleaned up on delete.

Not tested / known limits

  • Large transfers and many concurrent connections.
  • Linux build of the workspace (the peer bin has a non-Windows stub main; not built on Linux).
  • Peer lifetime on sandbox stop (it lives until delete); a hard-killed gateway leaves the peer's AppContainer profile registered.
  • Peer mode without openshell-supervisor-relay is rejected by validation.
  • OCSF events still show the gateway bridge address as the source for tunnelled egress.

🤖 Generated with Claude Code

Add an opt-in "proxy-peer" mode to the MXC ProcessContainer driver for
sandboxes running with MXC networkProxy, where in-sandbox loopback dials
are blocked.

- Gateway spawns a per-sandbox AppContainer peer (openshell-mxc-peer)
  that listens on loopback for the MXC networkProxy / allowedProxyPeer
  and bridges to the gateway over ACL'd named pipes.
- Ingress: forward listener backed by the peer (start_peer_relay) with
  the same nonce-authenticated contract as the control-channel relay.
- Egress: peer tunnels proxy connections to the host egress proxy;
  tunnelled connections are aliased via ForwardedClients so identity
  resolution works and the per-sandbox password check is skipped.
- Supervisor relay keeps the HTTP(S)_PROXY variables MXC injects when
  it clears the environment for the launched target.
- New driver option pc_proxy_peer_path with validation; README section.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Signed-off-by: Prashant S Khodade <pkhodade@nvidia.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 8, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

Resolve conflicts with the schema 1.0.0 migration (#4252): drop the
peer-specific 0.9.0-alpha schema override (1.0.0 supports
allowedProxyPeer), follow the removal of default_configuration_id and
the hand-written Default impl, and update the peer config test to the
renamed MxcNetwork field.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Signed-off-by: Prashant S Khodade <pkhodade@nvidia.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant