fix(ssh): persist sandbox host identities - #4027
Closed
quocanh261997 wants to merge 1 commit into
Closed
quocanh261997 wants to merge 1 commit into
quocanh261997 wants to merge 1 commit into
Conversation
Store each sandbox's Ed25519 host key in the gateway credential store and deliver it only to the supervisor. Preserve identity across restarts, delete owned credentials with the sandbox, and expose the public SHA256 fingerprint through sandbox and SSH-session APIs and client SDKs. Cover credential ownership, cancellation, deletion retries, client compatibility, and pinned SSH connections through lifecycle transitions. Closes NVIDIA#3835 Signed-off-by: Mike Nguyen <miken@nvidia.com>
|
Thank you for your interest in contributing to OpenShell, @quocanh261997. This project uses a vouch system for first-time contributors. Before submitting a pull request, you need to be vouched by a maintainer. To get vouched:
See CONTRIBUTING.md for details. |
|
All contributors have signed the DCO ✍️ ✅ |
Author
|
I have read the DCO document and I hereby sign the DCO. |
Author
|
recheck |
6 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Sandbox SSH host keys currently change when the supervisor restarts, so clients cannot reliably recognize the same sandbox. Give each sandbox ID one Ed25519 host key and expose its public SHA256 fingerprint. Keep the private key in the configured gateway credential store and deliver it only to the supervisor.
Related Issue
Closes #3835
Changes
Testing
mise run pre-commitpasses.mise run ci— passed, including workspace and gateway Rust tests, Python tests, Go checks, TypeScript tests, formatting, lint, and compile checks.mise run sdk:ts:ci— passed, including 142 tests, coverage, and build validation.mise run go:ci— passed.ssh_host_identity— passed.Rust checks used
LIBRARY_PATH=/opt/homebrew/libfor Homebrew Z3 on macOS. Installede2fsprogsfor the existing VM filesystem tests.The stock Docker E2E launcher failed locally because its container-side
127.0.0.1endpoint cannot reach the macOS gateway. The successful conformance run uses an ignored copy of the launcher withhost.docker.internalas the supervisor endpoint and the temporary mTLS gateway bound on all interfaces. This local launcher adjustment is excluded from the PR.Added tests cover credential-store reconstruction, concurrent candidates, interrupted preparation, deletion retries, failed candidate cleanup, inconsistent published identity, secret redaction, older bootstrap bundles, client conversion, fingerprint responses, and real SSH handshakes with direct and relayed streams after listener restart. A live sandbox test checks Get/List fingerprints, a remembered OpenSSH host key through stop/start and gateway restart, workload access restrictions, and recreation under the same name.
The live test uses the Docker driver. Kubernetes pod rescheduling and other compute-driver lanes have not been exercised locally.
Checklist