Repository navigation
feat(net): expose gvproxy services + /tunnel via NetworkBackend - #949
Conversation
Rework the gvproxy backend into one NetworkBackend seam and expose every ServicesMux service, plus the /tunnel data plane. - split NetworkBackendConfig (core create-input) from NetworkBackendSpec (the wire blob the shim consumes); the factory does create() only, and the backend owns spec(), stats(), runtime control, and tunnel() - one backend per box (vmm_spawn/vmm_attach), threaded into LiveState - typed stats() -> NetworkBackendStats; expose forwarder/dns/dhcp/stats/cam - BoxTunnel: raw byte tunnel to a guest ip:port over an enum-of-transports (TunnelStream); into_fd() -> Option<OwnedFd> gives an SDK a safe fd handoff - rename GvisorTapBackend -> GvproxyBackend; Transport -> BoxTransport - remove the dead libslirp backend Claude-Session: https://claude.ai/code/session_011tem3aFVb16xNaMz4Wf2jj
builder_preset_shortcuts_pick_known_profiles asserted seccomp_enabled unconditionally, but SecurityOptions::default gates it on cfg(target_os = "linux"). The maximum profile correctly leaves seccomp off on macOS, so assert it matches the platform — this also verifies seccomp is off where unsupported, and unblocks the pre-push test matrix on macOS. Claude-Session: https://claude.ai/code/session_011tem3aFVb16xNaMz4Wf2jj
📦 BoxLite review — couldn't completepowered by BoxLite |
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (5)
🚧 Files skipped from review as they are similar to previous changes (3)
📝 WalkthroughWalkthroughThis PR redesigns boxlite networking around a gvproxy control backend, migrates shared transport handling from ChangesNetworking backend redesign
Transport renamed to BoxTransport
Codex preflight audit hook
Estimated code review effort: 5 (Critical) | ~120 minutes Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
Good, #898 will base on that |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.claude/hooks/run-commit-push-audit.sh:
- Around line 61-82: The secret scan in check_diff_text is matching any diff
line because the grep expression starts with a generic line anchor, so removed
or context lines can trigger false positives. Update the pattern in
check_diff_text to only inspect added diff lines by anchoring the match to lines
beginning with plus, and keep the existing secret_pattern check and add_finding
behavior unchanged.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 37fa7972-8265-48c2-a1f3-26c45e071891
📒 Files selected for processing (8)
.claude/hooks/preflight-commit-push.sh.claude/hooks/preflight-commit-push.test.sh.claude/hooks/run-commit-push-audit.sh.codex/hooks.jsonsrc/boxlite/src/net/gvproxy/services.rssrc/boxlite/src/net/mod.rssrc/boxlite/tests/network.rssrc/shared/src/transport.rs
🚧 Files skipped from review as they are similar to previous changes (2)
- src/boxlite/src/net/gvproxy/services.rs
- src/boxlite/src/net/mod.rs
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.claude/hooks/run-commit-push-audit.sh:
- Around line 446-488: The temporary directory cleanup in run_agentic_audit()
only uses a RETURN trap, so any write_fail() path that exits will leak tmp_dir.
Update the trap setup to also clean up on EXIT (while keeping RETURN for normal
function exit) so the generated tmp_dir is removed even when find_codex_bin,
schema checks, or normalize_agentic_output() fail.
In @.githooks/githooks.test.sh:
- Line 346: The fixture setup commit in githooks.test.sh is running with the
caller’s ambient environment, which can trigger .githooks/pre-commit checks and
break the test state. Update the affected git commit steps to use env -i with
PATH and HOME preserved, matching the other isolated fixture setup commands, and
apply the same pattern to the commit sites in the test script that use plain git
commit.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 42178f9b-1092-494e-b128-1fd81f3f3035
📒 Files selected for processing (13)
.claude/agents/commit-push-auditor.md.claude/hooks/commit-push-audit.schema.json.claude/hooks/preflight-commit-push.sh.claude/hooks/preflight-commit-push.test.sh.claude/hooks/run-commit-push-audit.sh.githooks/commit-msg.githooks/githooks.test.sh.githooks/pre-commit.githooks/pre-pushsdks/c/Cargo.tomlsdks/node/Cargo.tomlsdks/python/Cargo.tomlsrc/cli/Cargo.toml
✅ Files skipped from review due to trivial changes (1)
- sdks/c/Cargo.toml
|
@boxlite-agent review |
14 similar comments
|
@boxlite-agent review |
|
@boxlite-agent review |
|
@boxlite-agent review |
|
@boxlite-agent review |
|
@boxlite-agent review |
|
@boxlite-agent review |
|
@boxlite-agent review |
|
@boxlite-agent review |
|
@boxlite-agent review |
|
@boxlite-agent review |
|
@boxlite-agent review |
|
@boxlite-agent review |
|
@boxlite-agent review |
|
@boxlite-agent review |
|
@boxlite-agent review Post-deploy verification 2026-07-09T01:40Z |
|
@boxlite-agent review Post-cleanup-fix verification 2026-07-09T01:52Z |
There was a problem hiding this comment.
Actionable comments posted: 1
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
.claude/agents/commit-push-auditor.md (1)
40-44: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick winSupport
-Fcommit messages incommit_subject_hash.
commit_subject_hashonly covers inline-m/--messagesubjects, but commit audits also accept-F. Hash the parsed-Fmessage when present, and only fail when no commit subject can be extracted.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.claude/agents/commit-push-auditor.md around lines 40 - 44, Update the commit audit logic so commit_subject_hash also handles commit commands using -F, not just inline -m / --message subjects. In the commit-push-auditor flow, extend the subject extraction used before hashing to parse the -F message content when present, then compute the SHA-256 hash from that parsed subject. Keep returning FAIL only when no commit subject can be extracted at all; preserve the empty-string behavior only for push commands.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/boxlite/src/net/ca.rs`:
- Around line 93-101: The CA directory normalization in ensure_ca_dir only masks
to owner-restrictive bits, so directories created with an overly restrictive
umask can remain unusable for temp-file creation. Update the permission fix in
the ensure_ca_dir logic to force the directory to 0700 explicitly using the
existing path/metadata flow, and keep the error handling in the set_permissions
branch via BoxliteError::Network so failures are still surfaced clearly.
---
Outside diff comments:
In @.claude/agents/commit-push-auditor.md:
- Around line 40-44: Update the commit audit logic so commit_subject_hash also
handles commit commands using -F, not just inline -m / --message subjects. In
the commit-push-auditor flow, extend the subject extraction used before hashing
to parse the -F message content when present, then compute the SHA-256 hash from
that parsed subject. Keep returning FAIL only when no commit subject can be
extracted at all; preserve the empty-string behavior only for push commands.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 290af0e7-ef18-4139-a643-967ae6041bfc
⛔ Files ignored due to path filters (1)
Cargo.lockis excluded by!**/*.lock
📒 Files selected for processing (14)
.claude/agents/commit-push-auditor.md.claude/hooks/run-commit-push-audit.sh.githooks/githooks.test.shsdks/node/lib/browserbox.tssdks/node/lib/simplebox.tssrc/boxlite/Cargo.tomlsrc/boxlite/src/litebox/init/tasks/vmm_spawn.rssrc/boxlite/src/net/ca.rssrc/boxlite/src/net/gvproxy/mod.rssrc/boxlite/src/net/gvproxy/services.rssrc/boxlite/src/net/mod.rssrc/boxlite/tests/gvproxy_debug_redaction.rssrc/boxlite/tests/network.rssrc/boxlite/tests/secret_substitution.rs
💤 Files with no reviewable changes (1)
- src/boxlite/tests/secret_substitution.rs
✅ Files skipped from review due to trivial changes (3)
- sdks/node/lib/simplebox.ts
- sdks/node/lib/browserbox.ts
- src/boxlite/tests/gvproxy_debug_redaction.rs
🚧 Files skipped from review as they are similar to previous changes (7)
- src/boxlite/src/litebox/init/tasks/vmm_spawn.rs
- src/boxlite/tests/network.rs
- .githooks/githooks.test.sh
- src/boxlite/src/net/gvproxy/mod.rs
- .claude/hooks/run-commit-push-audit.sh
- src/boxlite/src/net/mod.rs
- src/boxlite/src/net/gvproxy/services.rs
|
CAN |
|
tester seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account. You have signed the CLA already but the status is still pending? Let us recheck it. |
1 similar comment
|
tester seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account. You have signed the CLA already but the status is still pending? Let us recheck it. |
What
Reworks the gvproxy network backend into a single
NetworkBackendseam and exposes every gvproxy ServicesMux service, plus the/tunneldata plane.NetworkBackendConfig(core-side create input) fromNetworkBackendSpec(the wire blob the shim consumes). The factory doescreate()only; the backend ownsspec(),stats(), runtime control, andtunnel().vmm_spawn(start/restart) orvmm_attach(reattach) and threaded intoLiveState./stats,/cam, and the/tunneldata plane.stats() -> NetworkBackendStats(typed getters), mapped from gvproxy's/stats.BoxTunnel: a raw byte tunnel to a guestip:portbacked by an enum-of-transports (TunnelStream); it isAsyncRead + AsyncWrite, andinto_fd() -> Option<OwnedFd>gives an SDK a safe fd handoff.GvisorTapBackend -> GvproxyBackend;boxlite_shared::Transport -> BoxTransport(host↔guest address descriptor, distinct from the tunnel's liveTunnelStream).libslirpbackend and feature.The backend stays internal (no public LiteBox/SDK/CLI surface yet); serde variant names are unchanged, so the
BoxTransportrename is wire-compatible.Also folds in one unrelated preexisting-failure fix that was blocking the macOS pre-push matrix —
test(jailer): make the seccomp preset assert platform-aware(the test assertedseccomp_enabledunconditionally, butSecurityOptions::defaultgates it oncfg(target_os = "linux")).Testing
cargo check(gvproxy on/off + shim),clippy -D warnings,cargo fmt --check— clean.expose_unexpose_roundtrip,tunnel_handshake,/stats-> typed mapping,BoxTunnelbyte-pipe over a socketpair; net / network / vmm suites green.https://claude.ai/code/session_011tem3aFVb16xNaMz4Wf2jj
Summary by CodeRabbit
New Features
Bug Fixes
Deprecations