Repository navigation
feat(mxc): relay ingress and egress through an AppContainer proxy peer - #4330
Open
pkhodade-NV wants to merge 2 commits into
Open
pkhodade-NV wants to merge 2 commits into
pkhodade-NV wants to merge 2 commits into
Conversation
Add an opt-in "proxy-peer" mode to the MXC ProcessContainer driver for sandboxes running with MXC networkProxy, where in-sandbox loopback dials are blocked. - Gateway spawns a per-sandbox AppContainer peer (openshell-mxc-peer) that listens on loopback for the MXC networkProxy / allowedProxyPeer and bridges to the gateway over ACL'd named pipes. - Ingress: forward listener backed by the peer (start_peer_relay) with the same nonce-authenticated contract as the control-channel relay. - Egress: peer tunnels proxy connections to the host egress proxy; tunnelled connections are aliased via ForwardedClients so identity resolution works and the per-sandbox password check is skipped. - Supervisor relay keeps the HTTP(S)_PROXY variables MXC injects when it clears the environment for the launched target. - New driver option pc_proxy_peer_path with validation; README section. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: Prashant S Khodade <pkhodade@nvidia.com>
pkhodade-NV
requested review from
a team,
derekwaynecarr,
mrunalp and
sjenning
as code owners
October 8, 2026 12:28
Resolve conflicts with the schema 1.0.0 migration (#4252): drop the peer-specific 0.9.0-alpha schema override (1.0.0 supports allowedProxyPeer), follow the removal of default_configuration_id and the hand-written Default impl, and update the peer config test to the renamed MxcNetwork field. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Signed-off-by: Prashant S Khodade <pkhodade@nvidia.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds an opt-in proxy-peer mode to the MXC ProcessContainer driver for sandboxes that run with MXC
networkProxy, where in-sandbox loopback dials (including the supervisor relay's dial to the target port) are blocked.openshell-mxc-peer, a second bin inopenshell-driver-mxc). The peer listens on loopback for MXC'snetworkProxy/allowedProxyPeerand bridges to the gateway over named pipes with a DACL limited to the user and the peer's AppContainer profile.start_peer_relay) with the same nonce-authenticated contract asstart_control_channel_relay.ForwardedClientsregistry so Windows identity resolution works, and the per-sandbox password check is skipped for them (MXC-injected proxy variables carry no credentials).HTTP(S)_PROXYvariables MXC injects when it clears the environment for the launched target (NO_PROXYis never inherited).pc_proxy_peer_pathwith validation (absolute path,process_containerbackend, requires relay spawner + target port, incompatible withpc_network_allow/pc_allow_local_network). README gains a "Proxy-peer mode" section.Requires MXC schema
0.9.0-alpha(allowedProxyPeer); peer mode rewrites the one-shot config accordingly. Default behavior is unchanged when the option is unset.Testing
cargo test --package openshell-driver-mxc --lib(139 pass),openshell-supervisor-network --lib(1248 pass, 2 ignored), peer bin (2 pass), relay bin (7 pass, 3 new), onx86_64-pc-windows-msvc.EACCES, unrelated host loopbackEACCES, 0 credential rejections, peer process and AppContainer profile cleaned up on delete.Not tested / known limits
main; not built on Linux).openshell-supervisor-relayis rejected by validation.🤖 Generated with Claude Code