Skip to content

fix(vm): populate an empty guest /etc/hosts with loopback names - #4182

Open
shiju-nv wants to merge 1 commit into
NVIDIA:mainfrom
shiju-nv:fix/vm-guest-etc-hosts-3934
Open

shiju-nv wants to merge 1 commit into
NVIDIA:mainfrom
shiju-nv:fix/vm-guest-etc-hosts-3934

Conversation

@shiju-nv

@shiju-nv shiju-nv commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

A MicroVM sandbox started from an OCI image that ships an empty /etc/hosts keeps that empty file, so localhost does not resolve inside the guest. The guest init now writes the loopback names when the file is missing or empty. It leaves a non-empty file and a symlink alone.

The change covers empty or missing files only. An image that ships a non-empty hosts file with no localhost line, or only comments, is still left as the author wrote it, so localhost can still fail to resolve for those images.

Related Issue

Closes #3934.

Changes

  • crates/openshell-driver-vm/scripts/openshell-vm-sandbox-init.sh: add configure_hosts, called right after configure_hostname in run_post_overlay_setup. It returns without writing when /etc/hosts is a symlink (logging a warning) or is non-empty. Otherwise it writes 127.0.0.1 localhost and ::1 localhost ip6-localhost ip6-loopback. A write failure logs a warning, lets the shell's own error reach the console, and boot continues, because missing loopback names degrade the workload but do not weaken isolation.
  • crates/openshell-driver-vm/src/rootfs.rs: two tests. guest_init_populates_missing_or_empty_hosts_and_keeps_image_hosts cuts the real configure_hosts out of the shipped script and runs it under bash against a temporary root for a missing file, an empty file, an image-authored file, and a symlink to a file outside the root. guest_init_boot_path_configures_hosts_after_the_account_and_before_networking checks that run_post_overlay_setup itself calls configure_hosts after reconcile_sandbox_account and before the network step.

Testing

  • Checks appropriate to the affected code and behavior pass locally: focused checks and the repo's pre-commit hook pass
  • Unit tests added/updated (if applicable)
  • E2E tests added/updated (if applicable)

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

OCI images commonly ship an empty /etc/hosts and rely on the container runtime to bind-mount a generated one. The VM driver does not, and guest init wrote /etc/hostname and /etc/resolv.conf but never /etc/hosts, so localhost did not resolve: the guest resolver is the loopback relay, which has no record for it.

Add configure_hosts to guest init, called after configure_hostname. It writes IPv4 and IPv6 localhost entries when the file is missing or empty, keeps a non-empty file and leaves a symlink alone, because an absolute link target would resolve against init's own root. A write failure logs a warning and boot continues.

Cover the file states and the boot-path call site with tests that run the shipped init function under bash.

Closes NVIDIA#3934

Signed-off-by: Shiju <shiju@nvidia.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

vm driver: /etc/hosts is empty in a MicroVM sandbox, so localhost does not resolve

1 participant