From ed173f791ef2e8ea3b44e4ae4cade2bf91fac162 Mon Sep 17 00:00:00 2001 From: Pedro Henrique Penna Date: Tue, 29 Sep 2026 12:32:39 -0700 Subject: [PATCH 1/2] docs: document sandbox network policy options Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --- doc/usage.md | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/doc/usage.md b/doc/usage.md index 2b49c723..7d7b4ee4 100644 --- a/doc/usage.md +++ b/doc/usage.md @@ -367,11 +367,20 @@ python3 scripts/nvx.py sandbox [--hypervisor {auto,whp,kvm,mshv}] [--net IPV4/PREFIX] [--network-profile {portable}] + [--network-egress {allow,deny}] + [--network-ingress {allow,deny}] + [--network-egress-allow CIDR[:PROTOCOL:PORT]]... + [--network-egress-deny CIDR[:PROTOCOL:PORT]]... + [--host-loopback {allow,deny}] + [--network-proxy IPV4:TCP-PORT] + [--host-loopback-forward PROTOCOL:HOST_PORT:GUEST_PORT]... [--outcome-report PATH] [--cmdline TEXT] [--dry-run] ``` +Network policy options configure only the `run` and `provision` launches. + | Option | Default | Description | | --- | --- | --- | | `{run,provision,start,exec,stop,deprovision}` | `run` | Select a one-shot run or a managed lifecycle operation. | @@ -390,6 +399,13 @@ python3 scripts/nvx.py sandbox | `--hypervisor {auto,whp,kvm,mshv}` | `auto` | Select the host hypervisor. | | `--net IPV4/PREFIX` | none | Enable virtio-net with a static guest address. | | `--network-profile {portable}` | none | Select the required cross-platform network behavior contract; must be specified with `--net`. | +| `--network-egress {allow,deny}` | `allow` | Set the default guest egress policy for `run` or `provision`. | +| `--network-ingress {allow,deny}` | `deny` | Set the host ingress policy for `run` or `provision`. The portable profile supports only `deny`. | +| `--network-egress-allow CIDR[:PROTOCOL:PORT]` | none | Allow matching guest egress; repeat to add rules. Requires explicit `--network-egress`. | +| `--network-egress-deny CIDR[:PROTOCOL:PORT]` | none | Deny matching guest egress; repeat to add rules. Requires explicit `--network-egress`; deny rules take precedence. | +| `--host-loopback {allow,deny}` | existing mapping | Control guest access to host loopback services for `run` or `provision`. | +| `--network-proxy IPV4:TCP-PORT` | none | Allow one explicit host TCP proxy endpoint. | +| `--host-loopback-forward PROTOCOL:HOST_PORT:GUEST_PORT` | none | Publish one TCP or UDP localhost port to the guest; repeat to add forwards and set `--host-loopback allow`. | | `--outcome-report PATH` | none | Write a bounded local JSON outcome report for one-shot `run` or managed `exec`. | | `--cmdline TEXT` | empty | Append non-sandbox kernel parameters; `nvx_*` and `tsc=` tokens are reserved. | | `--dry-run` | off | Print the generated OpenVMM microVM command without running it. | From e04a45b526519c0ddb658dfd1d5e28dcc6089dda Mon Sep 17 00:00:00 2001 From: Pedro Henrique Penna Date: Wed, 30 Sep 2026 07:41:04 -0700 Subject: [PATCH 2/2] Update network-proxy option description in usage.md Clarify requirements for network proxy option in usage documentation. Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --- doc/usage.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/doc/usage.md b/doc/usage.md index 7d7b4ee4..619b3abd 100644 --- a/doc/usage.md +++ b/doc/usage.md @@ -404,7 +404,7 @@ Network policy options configure only the `run` and `provision` launches. | `--network-egress-allow CIDR[:PROTOCOL:PORT]` | none | Allow matching guest egress; repeat to add rules. Requires explicit `--network-egress`. | | `--network-egress-deny CIDR[:PROTOCOL:PORT]` | none | Deny matching guest egress; repeat to add rules. Requires explicit `--network-egress`; deny rules take precedence. | | `--host-loopback {allow,deny}` | existing mapping | Control guest access to host loopback services for `run` or `provision`. | -| `--network-proxy IPV4:TCP-PORT` | none | Allow one explicit host TCP proxy endpoint. | +| `--network-proxy IPV4:TCP-PORT` | none | Allow one explicit host TCP proxy endpoint; the IPv4 address must match the guest gateway. | | `--host-loopback-forward PROTOCOL:HOST_PORT:GUEST_PORT` | none | Publish one TCP or UDP localhost port to the guest; repeat to add forwards and set `--host-loopback allow`. | | `--outcome-report PATH` | none | Write a bounded local JSON outcome report for one-shot `run` or managed `exec`. | | `--cmdline TEXT` | empty | Append non-sandbox kernel parameters; `nvx_*` and `tsc=` tokens are reserved. |