Repository navigation
fix(companion): allow IPC socket fallback for gVisor/runsc sandboxes - #29597
elberthc-byte wants to merge 5 commits into
Conversation
Summary of ChangesHello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request improves the Gemini CLI's compatibility with sandboxed environments, specifically gVisor (runsc). It addresses network isolation challenges by implementing stdio IPC fallback, allowing host-gateway headers for authentication, and providing clearer diagnostic feedback when connection attempts are blocked by sandbox constraints. Highlights
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here. Footnotes
|
|
📊 PR Size: size/L
|
There was a problem hiding this comment.
Code Review
This pull request improves the IDE companion's compatibility with gVisor (runsc) sandboxing by forwarding additional IDE environment variables to the sandbox container, allowing container-specific host headers, and adding a detailed diagnostic message for connection failures under network isolation. The review feedback points out a critical issue where the GEMINI_SANDBOX environment variable is not forwarded to the container, which would prevent the gVisor detection logic from working inside the sandbox, and provides actionable code suggestions to resolve this in both the implementation and the tests.
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request adds support for passing through additional IDE environment variables into container arguments, improves connection failure messaging under gVisor sandboxing, and allows host.docker.internal and host.containers.internal host headers in the VS Code IDE companion server. Feedback suggests normalizing the incoming Host header to lowercase to prevent case-sensitivity issues and removing a redundant, misleading test in ide-gvisor-sandbox.test.ts that uses an inverted assertion anti-pattern.
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request updates the sandbox utility to propagate additional IDE environment variables (including GEMINI_CLI_IDE_AUTH_TOKEN) into the container, adds gVisor network isolation detection with descriptive error messages, and allows container-specific Host headers (host.docker.internal and host.containers.internal) in the VS Code IDE companion server. However, the review highlights a critical security vulnerability where propagating the sensitive authentication token into an untrusted sandbox, combined with allowing container-to-host communication, enables a complete sandbox escape. To remediate this, it is recommended to avoid passing the token to the sandbox or to enforce strict path validation on the IDE companion server to prevent unauthorized access to host files.
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request adds support for gVisor (runsc) sandboxing by passing additional IDE environment variables to the sandbox container, improving connection failure details when gVisor network isolation is detected, and allowing container-specific host headers (host.docker.internal and host.containers.internal) in the VS Code IDE companion server. The feedback suggests improving the test mocks in ide-gvisor-sandbox.test.ts by making the module-level fs.existsSync mock conditional rather than completely overriding it in individual test cases, preventing fragile test behavior.
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request introduces support for running the IDE companion within gVisor (runsc) and containerized sandboxes by propagating relevant environment variables, allowing container host headers, and providing descriptive error messages upon connection failures. However, two critical issues must be addressed: first, forwarding the sensitive GEMINI_CLI_IDE_AUTH_TOKEN into the sandbox container poses a high security risk of sandbox escape by untrusted code; second, accessing this.currentIde.displayName in ide-client.ts is unsafe and could lead to a runtime TypeError if the property is undefined.
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request adds support for gVisor (runsc) sandboxing constraints by propagating additional IDE environment variables to the sandbox container, updating the IdeClient to provide detailed error messages under network isolation, and allowing container-specific host headers in the companion server. The review feedback highlights a critical missing environment variable, GEMINI_CLI_IDE_AUTH_TOKEN, which must be propagated to the container for proper authentication, along with corresponding test assertions. Additionally, it is recommended to mock fs.promises.open in the sandbox tests to ensure they remain fully hermetic.
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request adds support for running the IDE companion under gVisor (runsc) sandbox constraints by forwarding necessary environment variables to the sandbox container, updating connection failure diagnostics with gVisor-specific details, and allowing container-specific host headers (like host.docker.internal) in the companion server. The review feedback highlights a critical omission: the GEMINI_CLI_IDE_AUTH_TOKEN environment variable must be forwarded to prevent authentication failures, and corresponding test coverage should be added. Additionally, the feedback suggests ensuring GEMINI_SANDBOX is correctly forwarded when configured via settings.json (i.e., when config.command is 'runsc').
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request introduces support for running the IDE companion under gVisor (runsc) sandbox constraints. It forwards additional IDE environment variables to the sandbox container, updates the IDE client to display informative error messages regarding network isolation under gVisor, and allows container-specific host headers in the IDE server. The review feedback correctly identifies that GEMINI_CLI_IDE_AUTH_TOKEN was omitted from the list of propagated environment variables in start_sandbox and its corresponding test, which would cause authentication failures.
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request introduces changes to support running the IDE companion under gVisor (runsc) sandbox constraints. It forwards additional IDE-related environment variables to the sandbox container, allows container-specific host headers (such as host.docker.internal and host.containers.internal) in the VS Code companion server, and improves error reporting when network isolation prevents loopback communication. The review feedback correctly identifies that GEMINI_CLI_IDE_AUTH_TOKEN is missing from the list of forwarded environment variables in sandbox.ts, which is critical to prevent authentication failures (401 Unauthorized) inside the sandbox.
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request introduces support for running the IDE companion under gVisor (runsc) sandbox constraints by forwarding additional environment variables, improving connection failure messages with gVisor-specific details, and allowing container-specific host headers in the IDE server. The review feedback identifies that the GEMINI_CLI_IDE_AUTH_TOKEN environment variable is missing from the forwarded variables list, which would cause authentication failures, and provides suggestions to propagate and test this token.
| for (const envVar of [ | ||
| 'GEMINI_CLI_IDE_SERVER_PORT', | ||
| 'GEMINI_CLI_IDE_WORKSPACE_PATH', | ||
| 'GEMINI_CLI_IDE_SERVER_STDIO_COMMAND', | ||
| 'GEMINI_CLI_IDE_SERVER_STDIO_ARGS', | ||
| 'TERM_PROGRAM', | ||
| 'GEMINI_SANDBOX', | ||
| ]) { |
There was a problem hiding this comment.
The environment variable GEMINI_CLI_IDE_AUTH_TOKEN is missing from the list of forwarded variables. Without propagating this token, the containerized CLI will fail to authenticate with the host companion server (resulting in 401 Unauthorized errors) when attempting to connect via HTTP (e.g., using host.docker.internal). Please add GEMINI_CLI_IDE_AUTH_TOKEN to the list of forwarded environment variables.
for (const envVar of [
'GEMINI_CLI_IDE_SERVER_PORT',
'GEMINI_CLI_IDE_WORKSPACE_PATH',
'GEMINI_CLI_IDE_SERVER_STDIO_COMMAND',
'GEMINI_CLI_IDE_SERVER_STDIO_ARGS',
'GEMINI_CLI_IDE_AUTH_TOKEN',
'TERM_PROGRAM',
'GEMINI_SANDBOX',
]) {| it('should pass through all IDE environment variables into container args', async () => { | ||
| vi.stubEnv('GEMINI_CLI_IDE_SERVER_PORT', '9999'); | ||
| vi.stubEnv('GEMINI_CLI_IDE_WORKSPACE_PATH', '/test/workspace'); | ||
| vi.stubEnv('GEMINI_CLI_IDE_SERVER_STDIO_COMMAND', '/usr/bin/ide-bridge'); | ||
| vi.stubEnv('GEMINI_CLI_IDE_SERVER_STDIO_ARGS', '["--flag"]'); | ||
| vi.stubEnv('TERM_PROGRAM', 'vscode'); | ||
| vi.stubEnv('GEMINI_SANDBOX', 'runsc'); |
There was a problem hiding this comment.
Stub the GEMINI_CLI_IDE_AUTH_TOKEN environment variable in the test to verify its propagation into the container arguments.
| it('should pass through all IDE environment variables into container args', async () => { | |
| vi.stubEnv('GEMINI_CLI_IDE_SERVER_PORT', '9999'); | |
| vi.stubEnv('GEMINI_CLI_IDE_WORKSPACE_PATH', '/test/workspace'); | |
| vi.stubEnv('GEMINI_CLI_IDE_SERVER_STDIO_COMMAND', '/usr/bin/ide-bridge'); | |
| vi.stubEnv('GEMINI_CLI_IDE_SERVER_STDIO_ARGS', '["--flag"]'); | |
| vi.stubEnv('TERM_PROGRAM', 'vscode'); | |
| vi.stubEnv('GEMINI_SANDBOX', 'runsc'); | |
| it('should pass through all IDE environment variables into container args', async () => { | |
| vi.stubEnv('GEMINI_CLI_IDE_SERVER_PORT', '9999'); | |
| vi.stubEnv('GEMINI_CLI_IDE_WORKSPACE_PATH', '/test/workspace'); | |
| vi.stubEnv('GEMINI_CLI_IDE_SERVER_STDIO_COMMAND', '/usr/bin/ide-bridge'); | |
| vi.stubEnv('GEMINI_CLI_IDE_SERVER_STDIO_ARGS', '["--flag"]'); | |
| vi.stubEnv('GEMINI_CLI_IDE_AUTH_TOKEN', 'test-auth-token'); | |
| vi.stubEnv('TERM_PROGRAM', 'vscode'); | |
| vi.stubEnv('GEMINI_SANDBOX', 'runsc'); |
| expect.arrayContaining([ | ||
| '--env', | ||
| 'GEMINI_CLI_IDE_SERVER_PORT=9999', | ||
| '--env', | ||
| 'GEMINI_CLI_IDE_WORKSPACE_PATH=/test/workspace', | ||
| '--env', | ||
| 'GEMINI_CLI_IDE_SERVER_STDIO_COMMAND=/usr/bin/ide-bridge', | ||
| '--env', | ||
| 'GEMINI_CLI_IDE_SERVER_STDIO_ARGS=["--flag"]', | ||
| '--env', | ||
| 'TERM_PROGRAM=vscode', | ||
| '--env', | ||
| 'GEMINI_SANDBOX=runsc', | ||
| ]), |
There was a problem hiding this comment.
Update the assertion to verify that GEMINI_CLI_IDE_AUTH_TOKEN is correctly passed as an environment variable to the container.
expect.arrayContaining([
'--env',
'GEMINI_CLI_IDE_SERVER_PORT=9999',
'--env',
'GEMINI_CLI_IDE_WORKSPACE_PATH=/test/workspace',
'--env',
'GEMINI_CLI_IDE_SERVER_STDIO_COMMAND=/usr/bin/ide-bridge',
'--env',
'GEMINI_CLI_IDE_SERVER_STDIO_ARGS=["--flag"]',
'--env',
'GEMINI_CLI_IDE_AUTH_TOKEN=test-auth-token',
'--env',
'TERM_PROGRAM=vscode',
'--env',
'GEMINI_SANDBOX=runsc',
]),
Summary
Allows IPC fallback and fixes container host/token configuration for sandboxed environments. In gVisor (
GEMINI_SANDBOX=runsc), user-space Netstack isolates the container loopback interface and blocks communication with the host's loopback (127.0.0.1). This PR enables stdio IPC fallback by propagatingGEMINI_CLI_IDE_SERVER_STDIO_*andGEMINI_CLI_IDE_AUTH_TOKENinto sandbox containers, allows container host headers (host.docker.internalandhost.containers.internal) inide-server.ts, and adds informative diagnostic details when running under gVisor instead of misleading the user to reinstall the extension.Details
packages/cli/src/utils/sandbox.tsto forwardGEMINI_CLI_IDE_AUTH_TOKEN,GEMINI_CLI_IDE_SERVER_STDIO_COMMAND, andGEMINI_CLI_IDE_SERVER_STDIO_ARGSalongside existing IDE environment variables.packages/vscode-ide-companion/src/ide-server.tsto allowhost.docker.internal:${this.port}andhost.containers.internal:${this.port}inallowedHosts, enabling containerized environments that support host-gateway routing (e.g. Docker Desktop) to authenticate without receiving HTTP 403 Forbidden.packages/core/src/ide/ide-client.tsto detectrunscsandboxing and report that gVisor's network isolation boundary prevents host loopback communication when connection fails, rather than recommending/ide install.packages/cli/src/utils/sandbox.test.ts: Verifies pass-through of all IDE environment variables into container execution arguments.packages/vscode-ide-companion/src/ide-server.test.ts: Verifies thathost.docker.internalandhost.containers.internalare accepted Host headers.packages/core/src/ide/ide-gvisor-sandbox.test.ts: Verifies Netstack gateway refusal, missing/blocked IPC Unix socket path (--host-uds=none), and gVisor isolation diagnostics.Related Issues
Fixes #21331
How to Validate
Unit Tests
npm test -w @google/gemini-cli-core -- src/ide/ide-gvisor-sandbox.test.ts src/ide/ide-client.test.ts src/ide/ide-connection-utils.test.tsnpm test -w gemini-cli-vscode-ide-companion -- src/ide-server.test.tsnpm test -w @google/gemini-cli -- -t "should pass through all IDE environment variables into container args" src/utils/sandbox.test.tsManual Verification & Reproduction Steps
1. Steps to Reproduce the Issue:
/ide status.Failed to connect to IDE companion extension in VS Code. Please ensure the extension is running. To install the extension, run /ide install., andGEMINI_CLI_IDE_AUTH_TOKENis dropped from the container environment.2. Validate the Solution:
/ide status.Failed to connect to IDE companion extension in VS Code: gVisor (runsc) sandboxing enforces strict network isolation which prevents host loopback communication.Configure a stdio IPC command in the environment:
IdeClientconnects via stdio stream transport.In an environment with
host.docker.internalresolution, connect tohttp://host.docker.internal:${port}/mcp.GEMINI_CLI_IDE_AUTH_TOKEN.Pre-Merge Checklist