Skip to content

[Repo Assist] fix(config): skip port-mapping check for host-networked containers in --validate-env - #14065

Merged
lpcox merged 3 commits into
mainfrom
repo-assist/fix-issue-14053-validate-env-host-network-cab2710ec82ad2ee
Sep 28, 2026
Merged

lpcox merged 3 commits into
mainfrom
repo-assist/fix-issue-14053-validate-env-host-network-cab2710ec82ad2ee

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

🤖 This PR is from Repo Assist, an automated AI assistant for this repository.

Closes #14053

Root Cause

run_containerized.sh's validate_port_mapping already skips port-mapping validation when a container's HostConfig.NetworkMode is "host" (fixed in #7684 for #7647), but the Go validator that run_containerized.sh now delegates to via --validate-env (ValidateContainerizedEnvironmentForRuntime in internal/config/validation_env.go) never got the same exception.

Docker discards published port mappings for --network host containers, so NetworkSettings.Ports is always empty and CheckPortMapping always fails — regressing #7647 for anyone using --validate-env under host networking, exactly as reported in #14053.

Fix

  • Added sys.IsHostNetworkMode(containerID) in internal/sys/docker.go, which inspects HostConfig.NetworkMode the same way run_containerized.sh's bash fix does.
  • ValidateContainerizedEnvironmentForRuntime now checks host networking first and skips the NetworkSettings.Ports validation when detected, treating the port requirement as satisfied (matching the bash-side behavior). Bridge-networked containers are completely unaffected.
  • If the network-mode check itself fails (e.g., docker inspect error), we fall back to running the original port-mapping check and surface a warning, so we never silently skip validation when we can't determine the mode.

Trade-offs

  • No security impact: this exactly mirrors an existing, already-shipped bash-side exception; it does not relax any check for bridge-networked containers.
  • No new dependencies.

Test Status

✅ Build: go build ./... passes
✅ Unit tests: added TestIsHostNetworkMode in internal/sys/docker_test.go (mirrors existing TestCheckPortMapping coverage: empty ID, invalid ID, unreachable docker socket cases); go test ./internal/sys/... ./internal/config/... passes
✅ make agent-finished: full pipeline (format, build, lint, all Go + Rust guard tests) passes clean

Warning

Firewall blocked 4 domains

The following domains were blocked by the firewall during workflow execution:

  • example.com
  • nonexistent.local
  • slow.example.com
  • thishostdoesnotexist12345.com

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "example.com"
    - "nonexistent.local"
    - "slow.example.com"
    - "thishostdoesnotexist12345.com"

See Network Configuration for more information.

Generated by Repo Assist · copilot · auto · 370.9 AIC · ⊞ 18.7K · ◷
Comment /repo-assist to run again

Add this agentic workflow to your repo

To install this agentic workflow, run

gh aw add githubnext/agentics/workflows/repo-assist.md@851905c06e905bf362a9f6cc54f912e3df747d55

… --validate-env

Closes #14053

Root cause: run_containerized.sh's validate_port_mapping already skips
port-mapping validation when a container's HostConfig.NetworkMode is
"host" (fixed in #7684 for #7647), but the Go validator that
run_containerized.sh now delegates to via --validate-env
(ValidateContainerizedEnvironmentForRuntime) never got the same
exception. Docker discards published port mappings for
--network host containers, so NetworkSettings.Ports is always empty
and CheckPortMapping always fails, regressing #7647 for anyone running
the gateway with --validate-env under host networking.

Fix: add sys.IsHostNetworkMode(containerID), which inspects
HostConfig.NetworkMode the same way run_containerized.sh's bash fix
does, and skip the NetworkSettings.Ports check in
ValidateContainerizedEnvironmentForRuntime when host networking is
detected, treating the port as satisfied. Bridge-networked containers
are unaffected.

Trade-offs: matches the existing bash-side exception exactly, so no
new security surface; a failure to determine the network mode falls
back to running the original port-mapping check with a warning
instead of erroring outright.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@lpcox
lpcox marked this pull request as ready for review September 28, 2026 16:43
Copilot AI balanced review requested due to automatic review settings September 28, 2026 16:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The regression-fixing host-network branch lacks direct automated coverage.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Adds host-network awareness to containerized environment validation, preventing false port-mapping failures.

Changes:

  • Detects Docker host-network mode.
  • Skips port validation for host-networked containers.
  • Adds error-path tests for network detection.
File Description
internal/​sys/​docker.go Adds host-network detection.
internal/​sys/​docker_test.go Tests detection error paths.
internal/​config/​validation_env.go Bypasses port checks for host networking.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread internal/config/validation_env.go Outdated
logEnv.Printf("Checking port mapping: port=%s", port)
portMapped, err := sys.CheckPortMapping(containerID, port)
if err != nil {
hostNetwork, netErr := sys.IsHostNetworkMode(containerID)
@lpcox

lpcox commented Sep 28, 2026

Copy link
Copy Markdown
Collaborator

@copilot address review feedback

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>

Copilot AI commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

@copilot address review feedback

Added mocked coverage for host networking, bridge networking, and network-mode inspect failure with port-mapping fallback. Commit: COMMIT_HASH.

Copilot AI requested a review from lpcox September 28, 2026 20:12
@lpcox

lpcox commented Sep 28, 2026

Copy link
Copy Markdown
Collaborator

@copilot merge main and fix conflicts

…-14053-validate-env-host-network-cab2710ec82ad2ee

# Conflicts:
#	internal/config/validation_env.go
#	internal/config/validation_env_test.go

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>

Copilot AI commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

@copilot merge main and fix conflicts

Merged main and resolved the validator/test conflicts using the upstream implementations. The merge commit is 8acf013.

@lpcox
lpcox merged commit c297101 into main Sep 28, 2026
30 checks passed
@lpcox
lpcox deleted the repo-assist/fix-issue-14053-validate-env-host-network-cab2710ec82ad2ee branch September 28, 2026 20:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

--validate-env rejects host-networked gateway containers (regression of #7647 in the Go validator)

3 participants