Skip to content

fix(mxc): authorize curl in inference policy - #4199

Merged
shailendra-nv merged 1 commit into
NVIDIA:windowsfrom
nv-vankit:fix/mxc-inference-curl-binary-6863783
Oct 6, 2026
Merged

shailendra-nv merged 1 commit into
NVIDIA:windowsfrom
nv-vankit:fix/mxc-inference-curl-binary-6863783

Conversation

@nv-vankit

@nv-vankit nv-vankit commented Oct 5, 2026 •

Copy link
Copy Markdown

Summary

Fix the shipped MXC cloud-inference runner so its network policy authorizes curl.exe, the process that actually opens the governed socket. The runner previously authorized its parent cmd.exe, causing binary-identity enforcement to reject CONNECT locally with HTTP 403 before the request reached NVIDIA.

Authenticated real-MXC qualification passed end to end with a valid NVIDIA API Catalog key: the ProcessContainer sandbox was created, governed TLS egress reached integrate.api.nvidia.com, and a real completion returned from inside the sandbox with verdict=PASS.

Related Issue

  • NVIDIA NVBug 6863783
  • No public GitHub issue required: localized Windows MXC example-runner bug.

Before / after reproduction

Before this change, the rendered workload invoked C:\WINDOWS\System32\curl.exe, while inference.used.yaml allowed C:\WINDOWS\System32\cmd.exe. Real MXC created the sandbox, then the enforcing proxy rejected curl's CONNECT with HTTP 403.

After this change, the rendered policy allows the resolved curl.exe path. A real ProcessContainer run established the governed tunnel (HTTP/1.1 200 Connection Established), authenticated with a valid NVIDIA API Catalog credential, and returned a real completion from inside the sandbox.

The existing real-MXC CA-bundle test had the same parent/child identity mismatch. Updating its policy to authorize curl changed that test from HTTP 403 failure to PASS.

Changes

  • Rename the inference policy placeholder from __CMD_EXE__ to __CURL_EXE__.
  • Render the resolved inbox curl.exe path into the shipped cloud-inference policy.
  • Require the policy regression test to distinguish the Ollama command identity from the cloud-inference curl identity.
  • Exercise the real HTTPS/CA-bundle test with curl as the authorized socket owner.

Testing

Passed:

  • mise run windows:check:x64
  • mise run windows:build:x64
  • mise run windows:test:x64 - 5,044 passed, 29 skipped.
  • mise run windows:lint:x64
  • mise run windows:test:unsupported:x64
  • mise run windows:artifacts
  • cargo test --release --target x86_64-pc-windows-msvc -p openshell-driver-mxc --test demo_examples - 9 passed.
  • Authenticated real-MXC cloud inference - completion returned from inside the sandbox with verdict=PASS.
  • Real MXC HTTPS/CA-bundle regression - passed after authorizing curl.
  • Real MXC suite - 14 passed; one unrelated stale dry-run schema test still fails because its request omits version.
  • MXC inference, aggregate, provider, OCSF, OpenClaw, and host-probe mock E2Es.
  • PowerShell parser validation, cargo fmt --all -- --check, SPDX header check, IDE lint, and git diff --check.
  • Tested this branch on native Windows x64 with a valid NVIDIA API Catalog credential supplied through the runner's existing --env-from NV_API_KEY path.

Security Impact

This narrows governed egress to the process that actually owns the socket. It does not broaden endpoint, port, method, filesystem, or credential access.

Checklist

  • Follows Conventional Commits
  • Commit is signed off (DCO)
  • Architecture docs updated (not applicable)

Signed-off-by: nv-vankit <nv-vankit@users.noreply.github.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 5, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@nv-vankit nv-vankit changed the title fix(mxc): authorize curl in inference policy (NVBug 6863783) fix(mxc): authorize curl in inference policy Oct 5, 2026
@shailendra-nv

Copy link
Copy Markdown
Collaborator

/ok to test

@copy-pr-bot

copy-pr-bot Bot commented Oct 5, 2026

Copy link
Copy Markdown

/ok to test

@shailendra-nv, there was an error processing your request: E1

See the following link for more information: https://docs.gha-runners.nvidia.com/cpr/e/1/

@shailendra-nv

Copy link
Copy Markdown
Collaborator

/ok to test 2b89f43

@shailendra-nv shailendra-nv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed head 2b89f43. The curl.exe authorization matches the Windows socket-owner enforcement model. Local ARM64 MXC validation passed (22 passed, 2 environment-gated skips, 0 failures), and the mirrored Branch Checks and Helm Lint required gates are green.

@shailendra-nv
shailendra-nv enabled auto-merge (squash) October 6, 2026 15:56
@shailendra-nv
shailendra-nv merged commit f6ecca2 into NVIDIA:windows Oct 6, 2026
64 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants