Skip to content

feat(gateway): check VM host tools during config preflight - #4037

Draft
shiju-nv wants to merge 3 commits into
mainfrom
fix/3951-vm-config-preflight
Draft

shiju-nv wants to merge 3 commits into
mainfrom
fix/3951-vm-config-preflight

Conversation

@shiju-nv

@shiju-nv shiju-nv commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Summary

openshell-gateway config preflight checks host filesystem tools for an explicitly selected local VM driver, so an unusable e2fsprogs installation fails before provisioning. The command reports selected paths and versions or a corrective error without creating runtime state.

Related Issue

Fixes #3951. Part of #3955.

Changes

  • Run bounded host-tool probes after the existing pure configuration validator. Remote driver endpoints report that host checks were not performed; other drivers do not require VM tools.
  • Share tool resolution between the gateway and VM image operations through openshell-core, preserving the independent VM driver binary. Resolve mke2fs or mkfs.ext4, debugfs, and e2fsck from the gateway's environment and existing package prefixes, and retain a selected tool's execution failure.
  • Document operator installation and checking the gateway service's account and environment, including restricted PATH values. Package installation remains with the operator; this change adds no package dependency or service environment changes.

Testing

Branch Checks passed for signed head 8bd564bf637e: all 23 jobs succeeded. Rust lint, tests, and build modes passed on macOS aarch64, Linux aarch64, and Linux x86_64. The gateway feature checks and SDK jobs also passed.

  • mise run pre-commit passes.
  • Unit tests added/updated.
  • E2E tests added/updated (if applicable).

Checklist

  • Follows Conventional Commits. The implementation commit uses feat(gateway): validate VM filesystem tools during preflight.
  • Commits are signed off (DCO). The implementation and both corrections have sign-off trailers and verified SSH signatures.
  • Architecture docs updated (if applicable). The configuration reference and VM troubleshooting guidance describe the operator workflow.

Check required local VM tools through config preflight and share executable
resolution with VM image operations. Report selected paths and actionable
errors without creating gateway or sandbox state.

Bound probe output and execution time, and clean up probe descendants on
interruption. Preserve pure static validation and skip local tool checks
for remote driver endpoints and unrelated drivers.

Fixes #3951
Related to #3955

Signed-off-by: Shiju <shiju@nvidia.com>
Combine identical filesystem-tool error arms and normalize rendered
diagnostics in command tests so terminal wrapping preserves assertions.
Describe driver TLS validation without depending on removed guest fields.

Signed-off-by: Shiju <shiju@nvidia.com>
Keep temporary paths quoted and escaped through the TOML serializer
instead of relying on Rust Debug formatting.

Signed-off-by: Shiju <shiju@nvidia.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Detect missing microVM host tools before sandbox creation

1 participant