Conversation
…rror The VM driver listens on <state_dir>/run/compute-driver.sock. When that path exceeds the platform's Unix socket limit the driver exits with a bare 'path must be shorter than SUN_LEN' and the gateway can only report the driver's exit status. Check the path in prepare_compute_driver_socket_path before any directory is created, and name the path, its length, the limit and the state_dir setting in the error. The limit is 107 bytes on Linux and 103 elsewhere. Note the constraint in the VM driver configuration docs. Closes NVIDIA#4178 Signed-off-by: Shiju <shiju@nvidia.com>
|
Could we extend the approach from #3544 to the remaining gateway-to-driver The diagnostic here is useful, but users with long state paths still cannot start the gateway. Please allocate a short, gateway-owned socket directory under Please also cover startup with an overlong |
Allocate a private random directory under /tmp and retain it with the managed driver process. Keep persistent VM state at the configured path and cover long-path startup, collision handling, and cleanup. Signed-off-by: Shiju <shiju@nvidia.com>
|
The PR initially focused on giving users a clearer error message. The gateway now creates a private, randomly named directory under /tmp for compute-driver.sock. |
elezar
left a comment
There was a problem hiding this comment.
Maybe a question: Are there other paths where we could expect this to happen? Should we expose a shared check to sanitize these paths?
|
it's all the |
|
Audited source:
|
|
Would the team prefer expanding this PR to cover the other socket paths? I'm thinking of adding shared address validation before filesystem changes or connection retries, and consolidating private short-directory allocation. The validator could live in extension-core and be re-exported from core. VM sandbox sockets would also need compact directory names so long sandbox IDs don’t exceed the limit. Alternatively, I can keep this PR focused and address the broader changes in a follow-up. |
Summary
The gateway gives the VM driver a control socket at
<state_dir>/run/compute-driver.sock. When that path is longer than the platform's Unix socket limit, the driver exits withpath must be shorter than SUN_LENand the gateway can report only the driver's exit status. The gateway now checks the path before it creates directories or starts the driver, and the error names the path, its length, the limit and the setting that moves it.Related Issue
Closes #4178
Changes
crates/openshell-gateway/src/vm.rs: addMAX_UNIX_SOCKET_PATH_LEN(107 bytes on Linux and Android, 103 elsewhere, excluding the terminating NUL, matchingsockaddr_un.sun_pathof 108 and 104 bytes) andcheck_compute_driver_socket_path_len.prepare_compute_driver_socket_pathcalls it first, so a rejected path leaves no directory behind.vm::spawnis the only launcher and the only caller ofprepare_compute_driver_socket_path.vm compute driver socket path '<path>' is <n> bytes, over the <limit>-byte limit for Unix socket paths on this platform; set [openshell.drivers.vm] state_dir to a shorter directory (it defaults to openshell/vm-driver under $XDG_STATE_HOME, or under ~/.local/state when that is unset).docs/how-it-works/gateways/configuration.mdx: one comment onstate_dirin the VM example saying the socket path is<state_dir>/run/compute-driver.sockand that the gateway refuses to start past the limit.Testing
Checklist