Conversation
OCI images commonly ship an empty /etc/hosts and rely on the container runtime to bind-mount a generated one. The VM driver does not, and guest init wrote /etc/hostname and /etc/resolv.conf but never /etc/hosts, so localhost did not resolve: the guest resolver is the loopback relay, which has no record for it. Add configure_hosts to guest init, called after configure_hostname. It writes IPv4 and IPv6 localhost entries when the file is missing or empty, keeps a non-empty file and leaves a symlink alone, because an absolute link target would resolve against init's own root. A write failure logs a warning and boot continues. Cover the file states and the boot-path call site with tests that run the shipped init function under bash. Closes NVIDIA#3934 Signed-off-by: Shiju <shiju@nvidia.com>
shiju-nv
requested review from
a team,
derekwaynecarr,
mrunalp and
sjenning
as code owners
October 4, 2026 12:02
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A MicroVM sandbox started from an OCI image that ships an empty
/etc/hostskeeps that empty file, solocalhostdoes not resolve inside the guest. The guest init now writes the loopback names when the file is missing or empty. It leaves a non-empty file and a symlink alone.The change covers empty or missing files only. An image that ships a non-empty hosts file with no
localhostline, or only comments, is still left as the author wrote it, solocalhostcan still fail to resolve for those images.Related Issue
Closes #3934.
Changes
crates/openshell-driver-vm/scripts/openshell-vm-sandbox-init.sh: addconfigure_hosts, called right afterconfigure_hostnameinrun_post_overlay_setup. It returns without writing when/etc/hostsis a symlink (logging a warning) or is non-empty. Otherwise it writes127.0.0.1 localhostand::1 localhost ip6-localhost ip6-loopback. A write failure logs a warning, lets the shell's own error reach the console, and boot continues, because missing loopback names degrade the workload but do not weaken isolation.crates/openshell-driver-vm/src/rootfs.rs: two tests.guest_init_populates_missing_or_empty_hosts_and_keeps_image_hostscuts the realconfigure_hostsout of the shipped script and runs it underbashagainst a temporary root for a missing file, an empty file, an image-authored file, and a symlink to a file outside the root.guest_init_boot_path_configures_hosts_after_the_account_and_before_networkingchecks thatrun_post_overlay_setupitself callsconfigure_hostsafterreconcile_sandbox_accountand before the network step.Testing
Checklist