Skip to content

feat(net): expose gvproxy services + /tunnel via NetworkBackend - #949

Merged
DorianZheng merged 14 commits into
mainfrom
feat/gvproxy-services-control
Jul 9, 2026
Merged

DorianZheng merged 14 commits into
mainfrom
feat/gvproxy-services-control

Conversation

@DorianZheng

@DorianZheng DorianZheng commented Jul 8, 2026 •

Copy link
Copy Markdown
Member

What

Reworks the gvproxy network backend into a single NetworkBackend seam and exposes every gvproxy ServicesMux service, plus the /tunnel data plane.

  • Config vs spec: split NetworkBackendConfig (core-side create input) from NetworkBackendSpec (the wire blob the shim consumes). The factory does create() only; the backend owns spec(), stats(), runtime control, and tunnel().
  • One backend per box: created in vmm_spawn (start/restart) or vmm_attach (reattach) and threaded into LiveState.
  • All ServicesMux services: forwarder (expose / unexpose / list), DNS, DHCP leases, /stats, /cam, and the /tunnel data plane.
  • Typed stats: stats() -> NetworkBackendStats (typed getters), mapped from gvproxy's /stats.
  • BoxTunnel: a raw byte tunnel to a guest ip:port backed by an enum-of-transports (TunnelStream); it is AsyncRead + AsyncWrite, and into_fd() -> Option<OwnedFd> gives an SDK a safe fd handoff.
  • Renames: GvisorTapBackend -> GvproxyBackend; boxlite_shared::Transport -> BoxTransport (host↔guest address descriptor, distinct from the tunnel's live TunnelStream).
  • Removes the dead libslirp backend and feature.

The backend stays internal (no public LiteBox/SDK/CLI surface yet); serde variant names are unchanged, so the BoxTransport rename is wire-compatible.

Also folds in one unrelated preexisting-failure fix that was blocking the macOS pre-push matrix — test(jailer): make the seccomp preset assert platform-aware (the test asserted seccomp_enabled unconditionally, but SecurityOptions::default gates it on cfg(target_os = "linux")).

Testing

  • cargo check (gvproxy on/off + shim), clippy -D warnings, cargo fmt --check — clean.
  • Unit + live e2e over a real gvproxy: expose_unexpose_roundtrip, tunnel_handshake, /stats -> typed mapping, BoxTunnel byte-pipe over a socketpair; net / network / vmm suites green.

https://claude.ai/code/session_011tem3aFVb16xNaMz4Wf2jj

Summary by CodeRabbit

  • New Features

    • Added richer box networking control via gvproxy, including forwarding management, DNS/DHCP/CAM queries, typed stats, and tunnel support.
    • Networking backend is now persisted and reused across detach/reattach flows for more reliable runtime networking.
  • Bug Fixes

    • Unified transport handling across components for more consistent connection behavior.
    • Strengthened MITM CA certificate/key storage to prevent unsafe reload/overwrite scenarios.
    • Improved platform-specific behavior for the “maximum” Linux security preset.
  • Deprecations

    • Removed the legacy libslirp networking backend.

Rework the gvproxy backend into one NetworkBackend seam and expose every
ServicesMux service, plus the /tunnel data plane.

- split NetworkBackendConfig (core create-input) from NetworkBackendSpec
  (the wire blob the shim consumes); the factory does create() only, and the
  backend owns spec(), stats(), runtime control, and tunnel()
- one backend per box (vmm_spawn/vmm_attach), threaded into LiveState
- typed stats() -> NetworkBackendStats; expose forwarder/dns/dhcp/stats/cam
- BoxTunnel: raw byte tunnel to a guest ip:port over an enum-of-transports
  (TunnelStream); into_fd() -> Option<OwnedFd> gives an SDK a safe fd handoff
- rename GvisorTapBackend -> GvproxyBackend; Transport -> BoxTransport
- remove the dead libslirp backend

Claude-Session: https://claude.ai/code/session_011tem3aFVb16xNaMz4Wf2jj
builder_preset_shortcuts_pick_known_profiles asserted seccomp_enabled
unconditionally, but SecurityOptions::default gates it on
cfg(target_os = "linux"). The maximum profile correctly leaves seccomp off
on macOS, so assert it matches the platform — this also verifies seccomp is
off where unsupported, and unblocks the pre-push test matrix on macOS.

Claude-Session: https://claude.ai/code/session_011tem3aFVb16xNaMz4Wf2jj
@DorianZheng
DorianZheng requested a review from a team July 8, 2026 12:06
@boxlite-agent

boxlite-agent Bot commented Jul 8, 2026 •

Copy link
Copy Markdown

📦 BoxLite review — couldn't complete

bad review output: no JSON object in model output

powered by BoxLite

@coderabbitai

coderabbitai Bot commented Jul 8, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 92d83c74-46b2-4459-9f01-a90888bec759

📥 Commits

Reviewing files that changed from the base of the PR and between 47e7fa0 and 8df9ff5.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (5)
  • src/boxlite/Cargo.toml
  • src/boxlite/src/net/gvproxy/services.rs
  • src/boxlite/tests/gvproxy_backend.rs
  • src/boxlite/tests/network.rs
  • src/boxlite/tests/network_spec.rs
🚧 Files skipped from review as they are similar to previous changes (3)
  • src/boxlite/Cargo.toml
  • src/boxlite/tests/network.rs
  • src/boxlite/src/net/gvproxy/services.rs

📝 Walkthrough

Walkthrough

This PR redesigns boxlite networking around a gvproxy control backend, migrates shared transport handling from Transport to BoxTransport, and expands Codex-based commit/push auditing with hash-bound artifacts and hook enforcement.

Changes

Networking backend redesign

Layer / File(s) Summary
Core network types and factory
src/boxlite/src/net/mod.rs, src/boxlite/src/net/ca.rs, src/boxlite/Cargo.toml, src/boxlite/tests/network.rs, src/boxlite/tests/secret_substitution.rs, src/boxlite/tests/gvproxy_debug_redaction.rs
Redefines NetworkBackendConfig/NetworkBackendSpec, adds the async NetworkBackend control trait, BoxTunnel, NetworkBackendFactory/NoBackendFactory/default_factory, hardens CA dir/key persistence, and updates tests/deps.
Gvproxy services backend and control socket
src/boxlite/src/net/gvproxy/*, src/deps/libgvproxy-sys/gvproxy-bridge/main.go
Adds GvproxyBackend/GvproxyFactory over HTTP/1.1 on a Unix control socket, derives control_socket_path, removes libslirp/stats logging, and updates the Go bridge to serve and clean up the ServicesMux endpoint.
Init, runtime, and shim wiring
src/boxlite/src/litebox/*, src/boxlite/src/runtime/rt_impl.rs, src/boxlite/src/vmm/*, src/shim/src/main.rs
Threads the created network backend through live state, init context, spawn/attach flows, RuntimeImpl.network_factory, and InstanceSpec.network_backend_spec.

Transport renamed to BoxTransport

Layer / File(s) Summary
BoxTransport type and re-export
src/shared/src/transport.rs, src/shared/src/lib.rs
Renames Transport to BoxTransport, updating constructors, URI helpers, trait impls, and the crate re-export.
BoxTransport call-site updates
src/boxlite/src/litebox/config.rs, src/boxlite/src/litebox/init/tasks/*, src/boxlite/src/portal/*, src/boxlite/src/vmm/krun/engine.rs, src/boxlite/src/vmm/controller/shim.rs, src/guest/src/service/server.rs, src/shim/src/main.rs, src/boxlite/src/jailer/builder.rs
Updates transport construction/matching sites to use BoxTransport variants, and adjusts the jailer seccomp preset test for Linux-only behavior.

Codex preflight audit hook

Layer / File(s) Summary
Audit script and hook wiring
.claude/hooks/*, .claude/agents/commit-push-auditor.md, .githooks/commit-msg, .githooks/pre-commit, .githooks/pre-push, .codex/hooks.json
Adds an audit JSON schema and run-commit-push-audit.sh producer, binds audits to diff/command/subject hashes, adds handoff artifacts, and updates git hooks to validate and consume audits.
Preflight hook test coverage
.claude/hooks/preflight-commit-push.test.sh, .githooks/githooks.test.sh
Adds hash helpers, synthetic audit fixtures, and extensive Codex commit/push scenario tests including malformed output, secret detection, and delegation-guard cases.

Estimated code review effort: 5 (Critical) | ~120 minutes

Possibly related PRs

  • boxlite-ai/boxlite#652: Overlaps with the jailer builder security preset seccomp test adjustment tied to preset handling.
  • boxlite-ai/boxlite#742: Overlaps with the BoxConfig transport/guest-connect refactor now migrated to BoxTransport.
  • boxlite-ai/boxlite#874: Both modify src/shim/src/main.rs's seccomp gating condition tied to network backend presence.

Suggested reviewers: G4614

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title is concise and accurately summarizes the main gvproxy/NetworkBackend change.
Description check ✅ Passed The description covers the main changes and verification steps, with only template headings and an optional risks section not followed exactly.
Docstring Coverage ✅ Passed Docstring coverage is 95.92% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/gvproxy-services-control

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Jul 8, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@G4614

G4614 commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

Good, #898 will base on that

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.claude/hooks/run-commit-push-audit.sh:
- Around line 61-82: The secret scan in check_diff_text is matching any diff
line because the grep expression starts with a generic line anchor, so removed
or context lines can trigger false positives. Update the pattern in
check_diff_text to only inspect added diff lines by anchoring the match to lines
beginning with plus, and keep the existing secret_pattern check and add_finding
behavior unchanged.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 37fa7972-8265-48c2-a1f3-26c45e071891

📥 Commits

Reviewing files that changed from the base of the PR and between 0fa1eee and bd54169.

📒 Files selected for processing (8)
  • .claude/hooks/preflight-commit-push.sh
  • .claude/hooks/preflight-commit-push.test.sh
  • .claude/hooks/run-commit-push-audit.sh
  • .codex/hooks.json
  • src/boxlite/src/net/gvproxy/services.rs
  • src/boxlite/src/net/mod.rs
  • src/boxlite/tests/network.rs
  • src/shared/src/transport.rs
🚧 Files skipped from review as they are similar to previous changes (2)
  • src/boxlite/src/net/gvproxy/services.rs
  • src/boxlite/src/net/mod.rs

Comment thread .claude/hooks/run-commit-push-audit.sh
@DorianZheng DorianZheng added the e2e-local Triggers the local (in-process) E2E suite on the self-hosted runner label Jul 8, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.claude/hooks/run-commit-push-audit.sh:
- Around line 446-488: The temporary directory cleanup in run_agentic_audit()
only uses a RETURN trap, so any write_fail() path that exits will leak tmp_dir.
Update the trap setup to also clean up on EXIT (while keeping RETURN for normal
function exit) so the generated tmp_dir is removed even when find_codex_bin,
schema checks, or normalize_agentic_output() fail.

In @.githooks/githooks.test.sh:
- Line 346: The fixture setup commit in githooks.test.sh is running with the
caller’s ambient environment, which can trigger .githooks/pre-commit checks and
break the test state. Update the affected git commit steps to use env -i with
PATH and HOME preserved, matching the other isolated fixture setup commands, and
apply the same pattern to the commit sites in the test script that use plain git
commit.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 42178f9b-1092-494e-b128-1fd81f3f3035

📥 Commits

Reviewing files that changed from the base of the PR and between bd54169 and eb4e193.

📒 Files selected for processing (13)
  • .claude/agents/commit-push-auditor.md
  • .claude/hooks/commit-push-audit.schema.json
  • .claude/hooks/preflight-commit-push.sh
  • .claude/hooks/preflight-commit-push.test.sh
  • .claude/hooks/run-commit-push-audit.sh
  • .githooks/commit-msg
  • .githooks/githooks.test.sh
  • .githooks/pre-commit
  • .githooks/pre-push
  • sdks/c/Cargo.toml
  • sdks/node/Cargo.toml
  • sdks/python/Cargo.toml
  • src/cli/Cargo.toml
✅ Files skipped from review due to trivial changes (1)
  • sdks/c/Cargo.toml

Comment thread .claude/hooks/run-commit-push-audit.sh
Comment thread .githooks/githooks.test.sh
@DorianZheng

Copy link
Copy Markdown
Member Author

@boxlite-agent review

14 similar comments
@DorianZheng

Copy link
Copy Markdown
Member Author

@boxlite-agent review

@DorianZheng

Copy link
Copy Markdown
Member Author

@boxlite-agent review

@DorianZheng

Copy link
Copy Markdown
Member Author

@boxlite-agent review

@DorianZheng

Copy link
Copy Markdown
Member Author

@boxlite-agent review

@DorianZheng

Copy link
Copy Markdown
Member Author

@boxlite-agent review

@DorianZheng

Copy link
Copy Markdown
Member Author

@boxlite-agent review

@DorianZheng

Copy link
Copy Markdown
Member Author

@boxlite-agent review

@DorianZheng

Copy link
Copy Markdown
Member Author

@boxlite-agent review

@DorianZheng

Copy link
Copy Markdown
Member Author

@boxlite-agent review

@DorianZheng

Copy link
Copy Markdown
Member Author

@boxlite-agent review

@DorianZheng

Copy link
Copy Markdown
Member Author

@boxlite-agent review

@DorianZheng

Copy link
Copy Markdown
Member Author

@boxlite-agent review

@DorianZheng

Copy link
Copy Markdown
Member Author

@boxlite-agent review

@DorianZheng

Copy link
Copy Markdown
Member Author

@boxlite-agent review

@DorianZheng

Copy link
Copy Markdown
Member Author

@boxlite-agent review

Post-deploy verification 2026-07-09T01:40Z

@boxlite-agent boxlite-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📦 BoxLite review — 1 issues

Comment thread .githooks/pre-commit
@DorianZheng

Copy link
Copy Markdown
Member Author

@boxlite-agent review

Post-cleanup-fix verification 2026-07-09T01:52Z

@boxlite-agent boxlite-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📦 BoxLite review — 1 issue

Comment thread .claude/hooks/preflight-commit-push.sh

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.claude/agents/commit-push-auditor.md (1)

40-44: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Support -F commit messages in commit_subject_hash.
commit_subject_hash only covers inline -m / --message subjects, but commit audits also accept -F. Hash the parsed -F message when present, and only fail when no commit subject can be extracted.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/agents/commit-push-auditor.md around lines 40 - 44, Update the
commit audit logic so commit_subject_hash also handles commit commands using -F,
not just inline -m / --message subjects. In the commit-push-auditor flow, extend
the subject extraction used before hashing to parse the -F message content when
present, then compute the SHA-256 hash from that parsed subject. Keep returning
FAIL only when no commit subject can be extracted at all; preserve the
empty-string behavior only for push commands.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/boxlite/src/net/ca.rs`:
- Around line 93-101: The CA directory normalization in ensure_ca_dir only masks
to owner-restrictive bits, so directories created with an overly restrictive
umask can remain unusable for temp-file creation. Update the permission fix in
the ensure_ca_dir logic to force the directory to 0700 explicitly using the
existing path/metadata flow, and keep the error handling in the set_permissions
branch via BoxliteError::Network so failures are still surfaced clearly.

---

Outside diff comments:
In @.claude/agents/commit-push-auditor.md:
- Around line 40-44: Update the commit audit logic so commit_subject_hash also
handles commit commands using -F, not just inline -m / --message subjects. In
the commit-push-auditor flow, extend the subject extraction used before hashing
to parse the -F message content when present, then compute the SHA-256 hash from
that parsed subject. Keep returning FAIL only when no commit subject can be
extracted at all; preserve the empty-string behavior only for push commands.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro Plus

Run ID: 290af0e7-ef18-4139-a643-967ae6041bfc

📥 Commits

Reviewing files that changed from the base of the PR and between eb4e193 and 47e7fa0.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (14)
  • .claude/agents/commit-push-auditor.md
  • .claude/hooks/run-commit-push-audit.sh
  • .githooks/githooks.test.sh
  • sdks/node/lib/browserbox.ts
  • sdks/node/lib/simplebox.ts
  • src/boxlite/Cargo.toml
  • src/boxlite/src/litebox/init/tasks/vmm_spawn.rs
  • src/boxlite/src/net/ca.rs
  • src/boxlite/src/net/gvproxy/mod.rs
  • src/boxlite/src/net/gvproxy/services.rs
  • src/boxlite/src/net/mod.rs
  • src/boxlite/tests/gvproxy_debug_redaction.rs
  • src/boxlite/tests/network.rs
  • src/boxlite/tests/secret_substitution.rs
💤 Files with no reviewable changes (1)
  • src/boxlite/tests/secret_substitution.rs
✅ Files skipped from review due to trivial changes (3)
  • sdks/node/lib/simplebox.ts
  • sdks/node/lib/browserbox.ts
  • src/boxlite/tests/gvproxy_debug_redaction.rs
🚧 Files skipped from review as they are similar to previous changes (7)
  • src/boxlite/src/litebox/init/tasks/vmm_spawn.rs
  • src/boxlite/tests/network.rs
  • .githooks/githooks.test.sh
  • src/boxlite/src/net/gvproxy/mod.rs
  • .claude/hooks/run-commit-push-audit.sh
  • src/boxlite/src/net/mod.rs
  • src/boxlite/src/net/gvproxy/services.rs

Comment thread src/boxlite/src/net/ca.rs
@G4614
G4614 enabled auto-merge July 9, 2026 10:35
@G4614

G4614 commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

CAN

@cla-assistant

cla-assistant Bot commented Jul 9, 2026

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you all sign our Contributor License Agreement before we can accept your contribution.
1 out of 2 committers have signed the CLA.

✅ DorianZheng
❌ tester


tester seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

1 similar comment
@cla-assistant

cla-assistant Bot commented Jul 9, 2026

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you all sign our Contributor License Agreement before we can accept your contribution.
1 out of 2 committers have signed the CLA.

✅ DorianZheng
❌ tester


tester seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

e2e-local Triggers the local (in-process) E2E suite on the self-hosted runner

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants