Repository navigation
bug(sandbox): network broker logs expected socket races as warnings #3526
Description
Activity
- addedtopic:observabilityLogging, metrics, and observability workLogging, metrics, and observability workarea:sandboxSandbox runtime and isolation workSandbox runtime and isolation workos:linuxIssue affects Linux hostsIssue affects Linux hosts
on Sep 21, 2026 🏗️ build-plan
Implementation Plan
Issue type:
fix
Complexity: Medium
Confidence: High — clear pathSummary
Separate expected seccomp notification races from enforcement rejections and unexpected broker failures in the sandbox network broker. Expected
ENOTCONNandESRCHoutcomes will be debug-level per event and summarized through bounded, periodic aggregate telemetry, while genuine denials and unexpected failures retain distinct warning-level diagnostics and listener-health failures remain errors.Scope
crates/openshell-sandbox/src/network_broker.rs: classify dispatch failures, aggregate transient race counts over a fixed interval, emit semantically distinct diagnostics, and add focused unit/logging tests.architecture/sandbox.md: document the broker's notification-race diagnostic behavior and the separation from enforcement and health failures.
Implementation Steps
- Add a small dispatch-failure classifier that recognizes
ENOTCONNandESRCHas expected target/socket races while separating enforcement errnos from unexpected operational failures. - Add broker-owned, bounded counters keyed by syscall and errno, with a fixed summary interval and deterministic time injection for tests.
- Replace the catch-all warning with category-specific reporting: debug for individual transient races, periodic aggregate informational telemetry, explicit warning text for enforcement rejections, and explicit warning text for unexpected dispatch failures. Preserve the existing error path for listener failure.
- Document the observable logging contract in the sandbox architecture overview.
- Add regression tests for disappearing notification targets, closed/unconnected sockets, aggregation behavior, and warning-level separation.
Test Plan
- Unit tests: In
network_broker.rs, verify errno classification, fixed-window counts/reset behavior, repeatedENOTCONN/ESRCHevents producing no per-event warnings, and enforcement/unexpected errors remaining warning-level and distinguishable. - Integration tests: N/A — this changes broker-local diagnostic handling; the existing seccomp broker tests continue to cover notification response behavior.
- E2E tests: N/A — no
e2e/behavior or deployment contract changes.
Risks & Open Questions
- Tracing tests must avoid global-subscriber races; use a scoped subscriber and test the reporting helper directly.
- Aggregation must remain bounded and must not delay the errno response sent back to the notifying task.
- No stakeholder decision is required: the issue explicitly permits aggregate or rate-limited diagnostics.
Documentation Impact
- Update
architecture/sandbox.mdwith the stable diagnostic-level distinction. - No gateway TOML, driver option, Helm, or published user-workflow documentation changes.
- LSM compatibility is unchanged: the fix does not add procfs access, process-identity resolution, binary execution, or cross-process visibility tests, so SELinux/AppArmor behavior is unaffected.
Revision 1 — initial plan
🏗️ build-from-issue-agent
Implementation Complete
PR: #3569
What was built
The sandbox network broker now classifies expected
ENOTCONNandESRCHnotification races separately from enforcement decisions and unexpected failures. Per-event races are debug-level, sustained races produce one-minute aggregate counts, and listener health failures remain errors.Tests
- Unit: 3 tests added
- Integration: full
mise run testsuite passed - E2E: N/A (no
e2e/changes)
Docs updated
architecture/sandbox.md
The issue will auto-close when the PR is merged.
This issue has had no activity for 14 days and is now marked stale. It may be closed in 7 days if there is no further activity. Comment or remove the state:stale label to keep it open.
- addedstate:staleInactive item at risk of automatic closure.Inactive item at risk of automatic closure.
on Oct 7, 2026
Agent Diagnostic
diagnose, OpenShell repositorycreate-github-issue, and cluster inspection workflows0.0.117-dev.211+g4cd5e5478v0.0.116; the issue reproduces on a newer development build containing the RFC 0012 sandbox runtimev0.0.116, RFC 0012 implementation PR feat(isolation): implement the RFC 0012 sandbox architecture #2942, and currentmainnetwork-broker handlingnetwork notification deniedtext,Socket not connected, and related network/boundary warnings. No matching issue was found. bug(supervisor-network): boundary reconnect is followed by proxy exit and ControlSupervisorExited #3396 concerns a boundary reconnect that becomes fatal; the sandboxes here remained healthy.sandbox network notification deniedwarnings in 12 hours. Nearly all were syscall 52 returningENOTCONN; the remainder were syscall 62 returningESRCH. All pods stayed Ready with zero restarts and there were no error-level runtime logs. Currentmainlogs everydispatch_notificationerror atWARN, regardless of whether it represents an enforcement decision or an expected process/socket race.Description
Actual behavior: The RFC 0012 sandbox network broker emits a
WARNfor every failed seccomp notification dispatch:During a 12-hour observation of six active agent workloads, this produced 4,183 network-broker warnings. The workloads remained Ready, had zero restarts, and recorded no error-level runtime events. A two-hour sample was dominated by 910
ENOTCONNwarnings and 34ESRCHwarnings.The current handler groups all
dispatch_notificationerrors under the messagesandbox network notification denied, even when the returned errno describes a socket/process race rather than an OpenShell policy denial. This makes benign application behavior look like a security or isolation failure and makes genuine broker failures difficult to find.Expected behavior: Expected transient process/socket races should not create one warning per syscall. They should be handled at debug/trace level, aggregated, or rate-limited. Genuine OpenShell policy denials and broker-health failures must remain clearly observable and distinguishable from application-originated errnos.
Reproduction Steps
sandbox network notification deniedmessages.ENOTCONNand syscall 62/ESRCHwarnings while the sandbox remains Ready and functional.Environment
v1.35.7-gke.1222000v0.5.0, v1beta1 API0.0.117-dev.211+g4cd5e54780.0.0-dev, RFC 0012 separate workload and supervisor podsv0.0.116; the tested development build is newerLogs
Acceptance Criteria
ENOTCONNandESRCHprocess/socket races do not emit an unboundedWARNper syscall.