Skip to content

fix(ide): surface explicit gVisor sandbox network isolation error - #29665

Closed
elberthc-byte wants to merge 6 commits into
google-gemini:mainfrom
elberthc-byte:b-561554893-fix
Closed

elberthc-byte wants to merge 6 commits into
google-gemini:mainfrom
elberthc-byte:b-561554893-fix

Conversation

@elberthc-byte

@elberthc-byte elberthc-byte commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

When Gemini CLI runs inside a gVisor (runsc) sandbox, the IDE companion server on the host can't be reached: gVisor's user-space network stack isolates the container from the host loopback interface. Today the CLI reports the generic … To install the extension, run /ide install., which is misleading (the extension is installed and running) and sends users down the wrong debugging path.

This PR makes the CLI name the actual cause and the remedy, and documents the limitation. It is intentionally a diagnostic + documentation fix; it does not try to bridge the sandbox network (see Non-goals).

Details

  1. packages/cli/src/utils/sandbox.ts — when the sandbox command is runsc, inject GEMINI_SANDBOX=runsc into the container so the CLI inside knows which runtime launched it. This mirrors the macOS sandbox-exec path, which already forwards GEMINI_SANDBOX. It can't trigger nested sandboxing: getSandboxCommand() returns early whenever SANDBOX is set inside a container. No other environment variables are added, and GEMINI_CLI_IDE_AUTH_TOKEN is still never forwarded.
  2. packages/core/src/ide/ide-connection-utils.ts — new isGvisorSandbox() with a single documented signal (GEMINI_SANDBOX, normalized, equals runsc).
  3. packages/core/src/ide/ide-client.ts — connect() now reports
    Failed to connect to IDE companion extension in <IDE>: gVisor (runsc) sandboxing isolates the container network stack, so the IDE companion server on the host is unreachable. To use IDE integration, run Gemini CLI without the runsc sandbox.
    when running under gVisor and (a) the HTTP/stdio connection attempts fail, or (b) no workspace path reaches the sandbox (the case that previously produced the /ide install advice). Directory mismatch and open a workspace folder errors are unchanged, and connection attempts are still made, so a reachable companion still connects.
  4. Docs — docs/cli/sandbox.md (runsc limitations) and docs/ide-integration/index.md (sandboxing note and troubleshooting entry).

Non-goals / follow-ups

  • Making IDE integration work under runsc. That needs a host-side bridge or forwarding the IDE auth token into the sandbox; the latter was rejected for security reasons (fix(cli): forward IDE auth token and accept container host header for sandboxed IDE connections #29653).
  • IDE integration inside plain Docker/Podman containers is also not functional on Linux today, independently of gVisor: the companion binds 127.0.0.1 only (so host.docker.internal → host-gateway is refused), the auth token is never forwarded, and the companion's Host allowlist rejects container origins. The docs/ide-integration/index.md claim that it "can still connect" is stale. This is pre-existing and will be tracked in a separate issue.

Related Issues

Fixes #21331

How to Validate

  1. Unit tests (no Docker or runsc needed):
    # core: mocked connect() matrix, isGvisorSandbox() table, and a real-socket regression test
    npx vitest run --dir packages/core src/ide/ide-client.test.ts src/ide/ide-connection-utils.test.ts src/ide/ide-gvisor-sandbox.test.ts
    # cli: GEMINI_SANDBOX=runsc is injected only for runsc; auth token and stdio command are never forwarded
    npx vitest run --dir packages/cli src/utils/sandbox.test.ts -t "gVisor"
    src/ide/ide-gvisor-sandbox.test.ts fails on main with … run /ide install. and passes with this PR.
  2. Manual, simulating the sandbox environment on the host (SANDBOX set prevents a relaunch; port 1 is a refused loopback port):
    TMPDIR=$(mktemp -d) SANDBOX=runsc GEMINI_SANDBOX=runsc TERM_PROGRAM=vscode \
      GEMINI_CLI_IDE_WORKSPACE_PATH="$(pwd)" GEMINI_CLI_IDE_SERVER_PORT=1 npm run start
    Then run /ide enable and confirm the status reads 🔴 Disconnected: Failed to connect to IDE companion extension in VS Code: gVisor (runsc) sandboxing isolates the container network stack, …. Repeat with GEMINI_SANDBOX=docker to confirm the generic /ide install message is unchanged.
  3. Manual, real sandbox (requires a working runsc Docker runtime): from a VS Code terminal with the companion installed, run GEMINI_SANDBOX=runsc NODE_ENV=development npm run start, then /ide enable.

Pre-Merge Checklist

  • Updated relevant documentation and README (if needed)
  • Added/updated tests (if needed)
  • Noted breaking changes (if any)
  • Validated on required platforms/methods:
    • MacOS
      • npm run
      • npx
      • Docker
      • Podman
      • Seatbelt
    • Windows
      • npm run
      • npx
      • Docker
    • Linux
      • npm run
      • npx
      • Docker

@elberthc-byte
elberthc-byte requested a review from a team as a code owner October 6, 2026 23:16
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request addresses connectivity issues between the IDE and sandboxed environments, specifically targeting gVisor (runsc) isolation. By ensuring critical environment variables are correctly propagated and updating host header validation, the changes allow for more reliable communication. Additionally, the PR introduces better diagnostics to help users distinguish between configuration errors and inherent sandbox network restrictions.

Highlights

  • IDE Sandbox Connectivity: Improved support for containerized IDE sandboxes by forwarding necessary authentication and environment variables to Docker, Podman, and LXC environments.
  • gVisor Diagnostic Messaging: Implemented explicit error messaging for gVisor (runsc) environments to clarify that network isolation is the cause of connection failures, replacing generic installation prompts.
  • Host Header Validation: Updated the companion server to allow 'host.docker.internal' and 'host.containers.internal' headers, ensuring compatibility with containerized host resolution.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@github-actions github-actions Bot added the size/l A large sized PR label Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

📊 PR Size: size/L

  • Lines changed: 461
  • Additions: +439
  • Deletions: -22
  • Files changed: 9

@gemini-cli gemini-cli Bot added priority/p2 Important but can be addressed in a future release. area/extensions Issues related to Gemini CLI extensions capability 🔒 maintainer only ⛔ Do not contribute. Internal roadmap item. labels Oct 6, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request implements forwarding of IDE mode environment variables to LXC and gVisor (runsc) sandbox environments, updates the VS Code companion server to allow container host headers, and improves error reporting for gVisor network isolation. The review feedback highlights a critical security vulnerability where forwarding the sensitive GEMINI_CLI_IDE_AUTH_TOKEN into the sandbox could allow an untrusted process to escape to the host's IDE companion server. Additionally, it is recommended to centralize the gVisor sandbox detection logic into a helper function to avoid scattering environment variable normalization across multiple files.

Comment thread packages/cli/src/utils/sandbox.ts
Comment thread packages/core/src/ide/ide-client.ts Outdated
@elberthc-byte elberthc-byte changed the title fix(ide): support container sandbox IDE auth and surface gVisor isolation error fix(ide): surface explicit gVisor sandbox network isolation error Oct 6, 2026
@elberthc-byte

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds support for forwarding IDE-related environment variables to LXC and gVisor (runsc) sandboxes, and introduces specific error handling for gVisor network isolation when connecting to the IDE companion. Additionally, it updates the VS Code companion server to allow container host headers. Feedback on the changes includes a style guide violation in the tests where process.env is modified directly instead of using vi.stubEnv.

Comment thread packages/cli/src/utils/sandbox.test.ts Outdated
@elberthc-byte

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request adds support for forwarding IDE mode environment variables (specifically STDIO command and arguments) to LXC and gVisor (runsc) sandboxes. It also handles gVisor's strict network isolation by providing explicit error messages when attempting to connect to the IDE companion extension, and updates the VS Code companion server to allow requests from container host headers (host.docker.internal and host.containers.internal). Comprehensive unit tests have been added to verify these behaviors. I have no feedback to provide as there are no review comments.

Trim PR google-gemini#29665 to the minimal change needed for google-gemini#21331 and harden its tests.

- sandbox.ts: inject GEMINI_SANDBOX=runsc only when the sandbox command is
  runsc; stop forwarding GEMINI_CLI_IDE_SERVER_STDIO_COMMAND/ARGS (host
  paths are meaningless inside the container)
- revert the companion Host allowlist change (unrelated to gVisor; tracked
  as a follow-up with the Linux Docker IDE issues)
- isGvisorSandbox(): single documented signal (GEMINI_SANDBOX), no
  container-name heuristic
- IdeClient.connect(): message now states both cause and remedy
- tests: mocked connect() matrix in ide-client.test.ts (incl. "still
  connects when reachable"), isGvisorSandbox() table, hermetic real-socket
  regression test (refused loopback port + isolated TMPDIR instead of DNS
  and fs mocks), launcher tests assert real --env pairs and that the auth
  token and stdio command are never forwarded
- docs: drop the "use docker instead" recommendation, which is not reliable
  on Linux either
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/extensions Issues related to Gemini CLI extensions capability 🔒 maintainer only ⛔ Do not contribute. Internal roadmap item. priority/p2 Important but can be addressed in a future release. size/l A large sized PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

IDE companion extension fails to connect with gVisor (runsc) sandbox

1 participant