Skip to content

[code-documentation] Document sandbox network policy options - #262

Merged
Pedro Henrique Penna (ppenna) merged 2 commits into
devfrom
code-documentation/docs/sandbox-network-policy-785dc1bebfb772d8
Sep 30, 2026
Merged

Pedro Henrique Penna (ppenna) merged 2 commits into
devfrom
code-documentation/docs/sandbox-network-policy-785dc1bebfb772d8

Conversation

@ppenna

Copy link
Copy Markdown
Contributor

Correction

The sandbox section of doc/usage.md omitted the existing directional and
host-loopback network policy options from both its synopsis and option table.
It now documents all seven options, their defaults and dependencies, and that
they configure only run and provision launches.

The source of truth is the parser in scripts/nvx.py:790-798, the shared
forwarding helper in scripts/nvx.py:266-282, and the run/provision
handling in scripts/nvx.py:396-416 and scripts/nvx.py:460-486.
python3 scripts/nvx.py sandbox --help exposes the same option surface.

This is not duplicate or rejected work. Merged #51 implemented sandbox
directional policy and documented its behavior in doc/run.md; merged #220
documented the equivalent run command options, but neither updated the
sandbox command reference. Related #243 and #255 changed validation and
shared forwarding implementation without documenting this omission. Open
#110 changes other doc/usage.md sections, and active #250, #259, and #260 do
not touch this documentation concern.

Scope

  • Changed doc/usage.md.
  • 16 total added-plus-deleted lines (16 additions, 0 deletions).
  • Checked command: python3 scripts/nvx.py sandbox --help.
  • Checked paths: doc/usage.md, doc/run.md, scripts/nvx.py, and
    scripts/test_nvx_tools.py.
  • No links were added or changed.

Validation

  • python3 scripts/nvx.py sandbox --help - passed; all seven documented
    options are present.
  • grep -E -- '--network-egress|--network-ingress|--host-loopback|--network-proxy' /tmp/gh-aw/agent/sandbox-help.txt
    • passed.
  • python3 -m unittest scripts.test_nvx_tools.CliTests.test_run_and_sandbox_forward_network_arguments -v
    • passed (1 test).
  • git diff --check - passed.
  • git diff --numstat / git diff --raw - confirmed one regular Markdown
    file, 16 changed lines, and no gitlink.

No dependency, public API/CLI/ABI, gitlink, or OpenVMM change was made.

Generated by code-documentation · copilot · gpt56 · 121.8 AIC · ⌖ 32 AIC · ⊞ 16.3K · ◷

  • expires on Oct 13, 2026, 7:32 PM UTC

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 29, 2026 19:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The proxy option omits the requirement that its IPv4 address match the guest gateway.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Documents sandbox network-policy options and their lifecycle scope.

Changes:

  • Adds seven network-policy options to the sandbox synopsis and reference table.
  • Documents defaults, dependencies, and applicable operations.
File Description
doc/​usage.md Expands the sandbox CLI network-policy reference.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread doc/usage.md Outdated
@ppenna
Pedro Henrique Penna (ppenna) marked this pull request as ready for review September 30, 2026 05:40
Clarify requirements for network proxy option in usage documentation.

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 14:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The documentation omits the required --net and --network-profile dependency.

Review effort: Balanced
Findings: None

Resolved since last review (1)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Network policy flags fail without required network configuration

doc/​usage.md:382

The common --net dependency is missing. OpenVMM rejects every listed policy flag when no network is configured (microVM network policy requires --net or a networked snapshot restore), and the sandbox command also requires --network-profile alongside --net. As written, a documented invocation such as sandbox --network-egress deny reaches a launch-time error.

@ppenna
Pedro Henrique Penna (ppenna) merged commit 1004b14 into dev Sep 30, 2026
20 checks passed
@ppenna
Pedro Henrique Penna (ppenna) deleted the code-documentation/docs/sandbox-network-policy-785dc1bebfb772d8 branch September 30, 2026 14:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants