Repository navigation
fix(ide): surface explicit gVisor sandbox network isolation error - #29665
elberthc-byte wants to merge 5 commits into
Conversation
Summary of ChangesHello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request addresses connectivity issues between the IDE and sandboxed environments, specifically targeting gVisor (runsc) isolation. By ensuring critical environment variables are correctly propagated and updating host header validation, the changes allow for more reliable communication. Additionally, the PR introduces better diagnostics to help users distinguish between configuration errors and inherent sandbox network restrictions. Highlights
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here. Footnotes
|
|
📊 PR Size: size/L
|
There was a problem hiding this comment.
Code Review
This pull request implements forwarding of IDE mode environment variables to LXC and gVisor (runsc) sandbox environments, updates the VS Code companion server to allow container host headers, and improves error reporting for gVisor network isolation. The review feedback highlights a critical security vulnerability where forwarding the sensitive GEMINI_CLI_IDE_AUTH_TOKEN into the sandbox could allow an untrusted process to escape to the host's IDE companion server. Additionally, it is recommended to centralize the gVisor sandbox detection logic into a helper function to avoid scattering environment variable normalization across multiple files.
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request adds support for forwarding IDE-related environment variables to LXC and gVisor (runsc) sandboxes, and introduces specific error handling for gVisor network isolation when connecting to the IDE companion. Additionally, it updates the VS Code companion server to allow container host headers. Feedback on the changes includes a style guide violation in the tests where process.env is modified directly instead of using vi.stubEnv.
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request adds support for forwarding IDE mode environment variables (specifically STDIO command and arguments) to LXC and gVisor (runsc) sandboxes. It also handles gVisor's strict network isolation by providing explicit error messages when attempting to connect to the IDE companion extension, and updates the VS Code companion server to allow requests from container host headers (host.docker.internal and host.containers.internal). Comprehensive unit tests have been added to verify these behaviors. I have no feedback to provide as there are no review comments.
Summary
Surfaces a clear, actionable diagnostic message when IDE companion connection fails inside a gVisor (
runsc) sandbox where network isolation blocks host loopback communication—instead of misleadingly instructing the user to run/ide install—and documents this limitation in the sandboxing and IDE integration guides.Details
Forward Sandbox & Stdio Environment Variables (
packages/cli/src/utils/sandbox.ts):GEMINI_CLI_IDE_SERVER_STDIO_COMMANDandGEMINI_CLI_IDE_SERVER_STDIO_ARGSinto both Docker/Podman/gVisor (start_sandbox) and LXC (start_lxc_sandbox) containers alongsideGEMINI_CLI_IDE_SERVER_PORTandGEMINI_CLI_IDE_WORKSPACE_PATH(while keepingGEMINI_CLI_IDE_AUTH_TOKENunexposed inside the untrusted sandbox environment).GEMINI_SANDBOXinto the container (ensuringGEMINI_SANDBOX=runscis set wheneverconfig.command === 'runsc').Allow Container Host Headers in Companion Server (
packages/vscode-ide-companion/src/ide-server.ts):host.docker.internal:${this.port}andhost.containers.internal:${this.port}(matched case-insensitively) toallowedHostsinIDEServer, matching the host resolution performed bygetIdeServerHost()inside containers.Centralized gVisor (
runsc) Detection & Diagnostic (packages/core/src/ide/ide-connection-utils.ts,packages/core/src/ide/ide-client.ts):isGvisorSandbox()helper inide-connection-utils.tsinspectingSANDBOXandGEMINI_SANDBOX.IdeClient.connect()both whenworkspacePathisundefined(e.g., when the host's/tmp/gemini/idediscovery directory is unmounted inside therunsccontainer andGEMINI_CLI_IDE_WORKSPACE_PATHis unset) and when HTTP/stdio connection attempts fail underrunsc, while preserving specific workspace validation messages (Directory mismatch.andplease open a workspace folder).Documentation (
docs/cli/sandbox.md,docs/ide-integration/index.md):runsc) IDE companion limitation and troubleshooting guidance.Related Issues
Fixes #21331
How to Validate
core,cli, andvscode-ide-companion:npx vitest run --dir packages/core src/ide/ide-gvisor-sandbox.test.ts npx vitest run --dir packages/cli src/utils/sandbox.test.ts -t "gVisor|IDE mode" npx vitest run --dir packages/vscode-ide-companion src/ide-server.test.tsrunsc) and Docker connection scenarios against the compiledIdeClient:GEMINI_SANDBOX=runscwith port and matching workspace path): ReportsFailed to connect to IDE companion extension in VS Code: gVisor (runsc) sandboxing enforces strict network isolation which prevents host loopback communication.SANDBOXenv var containsrunsc): Reports the explicit gVisor network isolation message.GEMINI_SANDBOX=runscwithGEMINI_CLI_IDE_WORKSPACE_PATHunset / host/tmp/gemini/ideport file unmounted in container): Reports the explicit gVisor network isolation message instead of/ide install.GEMINI_SANDBOX=runscwith directory mismatch): PreservesDirectory mismatch.error.GEMINI_SANDBOX=runscwith empty workspace""): PreservesTo use this feature, please open a workspace folder in your IDE and try again.GEMINI_SANDBOX=dockerwhen companion server is unreachable): Preserves standard/ide installguidance.Pre-Merge Checklist