You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The sandbox section of doc/usage.md omitted the existing directional and
host-loopback network policy options from both its synopsis and option table.
It now documents all seven options, their defaults and dependencies, and that
they configure only run and provision launches.
The source of truth is the parser in scripts/nvx.py:790-798, the shared
forwarding helper in scripts/nvx.py:266-282, and the run/provision
handling in scripts/nvx.py:396-416 and scripts/nvx.py:460-486. python3 scripts/nvx.py sandbox --help exposes the same option surface.
This is not duplicate or rejected work. Merged #51 implemented sandbox
directional policy and documented its behavior in doc/run.md; merged #220
documented the equivalent run command options, but neither updated the sandbox command reference. Related #243 and #255 changed validation and
shared forwarding implementation without documenting this omission. Open #110 changes other doc/usage.md sections, and active #250, #259, and #260 do
not touch this documentation concern.
Scope
Changed doc/usage.md.
16 total added-plus-deleted lines (16 additions, 0 deletions).
Clarify requirements for network proxy option in usage documentation.
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Network policy flags fail without required network configuration
doc/usage.md:382
The common --net dependency is missing. OpenVMM rejects every listed policy flag when no network is configured (microVM network policy requires --net or a networked snapshot restore), and the sandbox command also requires --network-profile alongside --net. As written, a documented invocation such as sandbox --network-egress deny reaches a launch-time error.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Correction
The
sandboxsection ofdoc/usage.mdomitted the existing directional andhost-loopback network policy options from both its synopsis and option table.
It now documents all seven options, their defaults and dependencies, and that
they configure only
runandprovisionlaunches.The source of truth is the parser in
scripts/nvx.py:790-798, the sharedforwarding helper in
scripts/nvx.py:266-282, and therun/provisionhandling in
scripts/nvx.py:396-416andscripts/nvx.py:460-486.python3 scripts/nvx.py sandbox --helpexposes the same option surface.This is not duplicate or rejected work. Merged #51 implemented sandbox
directional policy and documented its behavior in
doc/run.md; merged #220documented the equivalent
runcommand options, but neither updated thesandboxcommand reference. Related #243 and #255 changed validation andshared forwarding implementation without documenting this omission. Open
#110 changes other
doc/usage.mdsections, and active #250, #259, and #260 donot touch this documentation concern.
Scope
doc/usage.md.python3 scripts/nvx.py sandbox --help.doc/usage.md,doc/run.md,scripts/nvx.py, andscripts/test_nvx_tools.py.Validation
python3 scripts/nvx.py sandbox --help- passed; all seven documentedoptions are present.
grep -E -- '--network-egress|--network-ingress|--host-loopback|--network-proxy' /tmp/gh-aw/agent/sandbox-help.txtpython3 -m unittest scripts.test_nvx_tools.CliTests.test_run_and_sandbox_forward_network_arguments -vgit diff --check- passed.git diff --numstat/git diff --raw- confirmed one regular Markdownfile, 16 changed lines, and no gitlink.
No dependency, public API/CLI/ABI, gitlink, or OpenVMM change was made.