Repository navigation
[Repo Assist] fix(config): skip port-mapping check for host-networked containers in --validate-env - #14065
Conversation
… --validate-env Closes #14053 Root cause: run_containerized.sh's validate_port_mapping already skips port-mapping validation when a container's HostConfig.NetworkMode is "host" (fixed in #7684 for #7647), but the Go validator that run_containerized.sh now delegates to via --validate-env (ValidateContainerizedEnvironmentForRuntime) never got the same exception. Docker discards published port mappings for --network host containers, so NetworkSettings.Ports is always empty and CheckPortMapping always fails, regressing #7647 for anyone running the gateway with --validate-env under host networking. Fix: add sys.IsHostNetworkMode(containerID), which inspects HostConfig.NetworkMode the same way run_containerized.sh's bash fix does, and skip the NetworkSettings.Ports check in ValidateContainerizedEnvironmentForRuntime when host networking is detected, treating the port as satisfied. Bridge-networked containers are unaffected. Trade-offs: matches the existing bash-side exception exactly, so no new security surface; a failure to determine the network mode falls back to running the original port-mapping check with a warning instead of erroring outright. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The regression-fixing host-network branch lacks direct automated coverage.
Review effort: Balanced
Findings: 1
What changed in this PR
Adds host-network awareness to containerized environment validation, preventing false port-mapping failures.
Changes:
- Detects Docker host-network mode.
- Skips port validation for host-networked containers.
- Adds error-path tests for network detection.
| File | Description |
|---|---|
internal/sys/docker.go |
Adds host-network detection. |
internal/sys/docker_test.go |
Tests detection error paths. |
internal/config/validation_env.go |
Bypasses port checks for host networking. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| logEnv.Printf("Checking port mapping: port=%s", port) | ||
| portMapped, err := sys.CheckPortMapping(containerID, port) | ||
| if err != nil { | ||
| hostNetwork, netErr := sys.IsHostNetworkMode(containerID) |
|
@copilot address review feedback |
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Added mocked coverage for host networking, bridge networking, and network-mode inspect failure with port-mapping fallback. Commit: |
|
@copilot merge main and fix conflicts |
…-14053-validate-env-host-network-cab2710ec82ad2ee # Conflicts: # internal/config/validation_env.go # internal/config/validation_env_test.go Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Merged |

🤖 This PR is from Repo Assist, an automated AI assistant for this repository.
Closes #14053
Root Cause
run_containerized.sh'svalidate_port_mappingalready skips port-mapping validation when a container'sHostConfig.NetworkModeis"host"(fixed in #7684 for #7647), but the Go validator thatrun_containerized.shnow delegates to via--validate-env(ValidateContainerizedEnvironmentForRuntimeininternal/config/validation_env.go) never got the same exception.Docker discards published port mappings for
--network hostcontainers, soNetworkSettings.Portsis always empty andCheckPortMappingalways fails — regressing #7647 for anyone using--validate-envunder host networking, exactly as reported in #14053.Fix
sys.IsHostNetworkMode(containerID)ininternal/sys/docker.go, which inspectsHostConfig.NetworkModethe same wayrun_containerized.sh's bash fix does.ValidateContainerizedEnvironmentForRuntimenow checks host networking first and skips theNetworkSettings.Portsvalidation when detected, treating the port requirement as satisfied (matching the bash-side behavior). Bridge-networked containers are completely unaffected.Trade-offs
Test Status
✅ Build:
go build ./...passes✅ Unit tests: added
TestIsHostNetworkModeininternal/sys/docker_test.go(mirrors existingTestCheckPortMappingcoverage: empty ID, invalid ID, unreachable docker socket cases);go test ./internal/sys/... ./internal/config/...passes✅ make agent-finished: full pipeline (format, build, lint, all Go + Rust guard tests) passes clean
Warning
Firewall blocked 4 domains
The following domains were blocked by the firewall during workflow execution:
example.comnonexistent.localslow.example.comthishostdoesnotexist12345.comTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.
Add this agentic workflow to your repo
To install this agentic workflow, run