Repository navigation
fix(mxc): authorize curl in inference policy - #4199
Merged
shailendra-nv merged 1 commit intoOct 6, 2026
Merged
shailendra-nv merged 1 commit into
shailendra-nv merged 1 commit into
Conversation
Signed-off-by: nv-vankit <nv-vankit@users.noreply.github.com>
nv-vankit
requested review from
a team,
derekwaynecarr,
mrunalp and
sjenning
as code owners
October 5, 2026 12:07
Collaborator
|
/ok to test |
@shailendra-nv, there was an error processing your request: See the following link for more information: https://docs.gha-runners.nvidia.com/cpr/e/1/ |
Collaborator
|
/ok to test 2b89f43 |
shailendra-nv
approved these changes
Oct 5, 2026
shailendra-nv
left a comment
Collaborator
There was a problem hiding this comment.
Reviewed head 2b89f43. The curl.exe authorization matches the Windows socket-owner enforcement model. Local ARM64 MXC validation passed (22 passed, 2 environment-gated skips, 0 failures), and the mirrored Branch Checks and Helm Lint required gates are green.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fix the shipped MXC cloud-inference runner so its network policy authorizes
curl.exe, the process that actually opens the governed socket. The runner previously authorized its parentcmd.exe, causing binary-identity enforcement to reject CONNECT locally with HTTP 403 before the request reached NVIDIA.Authenticated real-MXC qualification passed end to end with a valid NVIDIA API Catalog key: the ProcessContainer sandbox was created, governed TLS egress reached
integrate.api.nvidia.com, and a real completion returned from inside the sandbox withverdict=PASS.Related Issue
Before / after reproduction
Before this change, the rendered workload invoked
C:\WINDOWS\System32\curl.exe, whileinference.used.yamlallowedC:\WINDOWS\System32\cmd.exe. Real MXC created the sandbox, then the enforcing proxy rejected curl's CONNECT with HTTP 403.After this change, the rendered policy allows the resolved
curl.exepath. A real ProcessContainer run established the governed tunnel (HTTP/1.1 200 Connection Established), authenticated with a valid NVIDIA API Catalog credential, and returned a real completion from inside the sandbox.The existing real-MXC CA-bundle test had the same parent/child identity mismatch. Updating its policy to authorize curl changed that test from HTTP 403 failure to PASS.
Changes
__CMD_EXE__to__CURL_EXE__.curl.exepath into the shipped cloud-inference policy.Testing
Passed:
mise run windows:check:x64mise run windows:build:x64mise run windows:test:x64- 5,044 passed, 29 skipped.mise run windows:lint:x64mise run windows:test:unsupported:x64mise run windows:artifactscargo test --release --target x86_64-pc-windows-msvc -p openshell-driver-mxc --test demo_examples- 9 passed.verdict=PASS.version.cargo fmt --all -- --check, SPDX header check, IDE lint, andgit diff --check.--env-from NV_API_KEYpath.Security Impact
This narrows governed egress to the process that actually owns the socket. It does not broaden endpoint, port, method, filesystem, or credential access.
Checklist