Skip to content

fix(docker): pin Docker Desktop host gateway - #4404

Open
senthilr-nv wants to merge 1 commit into
NVIDIA:mainfrom
senthilr-nv:fix/4403-docker-desktop-host-gateway/senthilr-nv
Open

senthilr-nv wants to merge 1 commit into
NVIDIA:mainfrom
senthilr-nv:fix/4403-docker-desktop-host-gateway/senthilr-nv

Conversation

@senthilr-nv

Copy link
Copy Markdown

Summary

Pin Docker Desktop's daemon-owned host-gateway address when the Docker supervisor reaches the gateway through host.docker.internal. This lets an explicitly allowed host.openshell.internal endpoint pass the supervisor's trusted-gateway policy check without enabling host networking or weakening DNS trust.

Related Issue

Closes #4403

Related to #3880 and completes the named-endpoint host-service limitation documented in #3924.

Changes

  • Resolve Docker's host-gateway token through a short-lived, sandbox-labeled helper container only when grpc_endpoint uses host.docker.internal.
  • Run the resolver with no network, all capabilities dropped, no privilege escalation, a read-only root filesystem, and the existing immutable supervisor image.
  • Parse the engine-written /etc/hosts entry into one concrete address and reject missing, ambiguous, malformed, unspecified, multicast, broadcast, and metadata addresses.
  • Pass the verified address into the existing host.openshell.internal trust pin while preserving literal, loopback, and unrelated named-endpoint behavior.
  • Remove the resolver after success or failure and add focused unit plus opt-in live Docker coverage.

No configuration, default, CLI, or policy-schema contract changes. Existing documentation and agent workflows remain accurate.

Testing

  • Checks appropriate to the affected code and behavior pass
    • cargo test -p openshell-driver-docker --lib: 139 passed, 1 ignored
    • Focused Clippy for openshell-driver-docker: passed
    • git diff --check origin/main...HEAD: passed
  • Unit tests added/updated
    • Resolver confinement and host-gateway mapping
    • Unique IPv4 selection and unsafe/ambiguous address rejection
  • E2E tests added/updated (not applicable; no repository E2E target was added)
  • Ignored live Docker Desktop resolver test passed against the local daemon and immutable supervisor image
  • Full macOS consumer canary passed
    • SwiftUI setup and authenticated machine health
    • Outlook authorization and tool use
    • Hermes inference and chat through the policy-approved host endpoint
    • App relaunch and exact chat resume
    • Exact Fleet uninstall

The full canary bundled e7c8a1025. The signed publication commit dca78bdd1 changes only commit-signature metadata; both commits have tree 5c817db43e74b4c44003f6e1feac741b187a77db.

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (not applicable; no architecture or public configuration contract changed)

Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
@github-actions

github-actions Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

All contributors have signed the DCO ✍️ ✅
Posted by the DCO Assistant Lite bot.

@senthilr-nv

Copy link
Copy Markdown
Author

I have read the DCO document and I hereby sign the DCO.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(docker): trusted host alias is unavailable with Docker Desktop gateway endpoint

1 participant