Skip to content

fix(mxc): refresh stale demo gateway aliases - #4192

Open
nv-vankit wants to merge 1 commit into
NVIDIA:windowsfrom
nv-vankit:fix/mxc-refresh-stale-gateway-alias-6870039
Open

nv-vankit wants to merge 1 commit into
NVIDIA:windowsfrom
nv-vankit:fix/mxc-refresh-stale-gateway-alias-6870039

Conversation

@nv-vankit

@nv-vankit nv-vankit commented Oct 5, 2026 •

Copy link
Copy Markdown

Summary

Fix the shipped MXC E2E and OCSF-audit runners when their gateway alias already exists. The runners previously ignored any already exists failure, so a stale alias silently sent subsequent CLI commands to the wrong gateway.

Related Issue

  • NVIDIA NVBug 6870039
  • No public GitHub issue required: localized Windows MXC example-runner bug.

Before / after reproduction

Before this change, bug6870039-e2e was seeded at http://127.0.0.1:18000 and the E2E runner started its gateway on port 17671. Registration reported that the alias already existed, the CLI continued using port 18000, and the run ended with PASS=0 FAIL=4.

After this change, both runners inspect the existing registration. A matching alias is reused, while a stale alias is removed and recreated for the current run.

Validated the full registration matrix:

  • E2E alias absent on port 17675: PASS=4 FAIL=0.
  • E2E alias already matching port 17675: reused, PASS=4 FAIL=0.
  • E2E alias stale at 17675 with the run on 17676: replaced, PASS=4 FAIL=0.
  • OCSF mock alias absent on port 17677: passed.
  • OCSF mock alias already matching port 17677: reused and passed.
  • OCSF mock alias stale at 17677 with the run on 17678: replaced and passed.

Changes

  • Capture native stdout separately so gateway-list JSON can be parsed without stderr contamination.
  • Clear an inherited blank OPENSHELL_GATEWAY override before registration.
  • Query the existing named gateway when gateway add fails.
  • Reuse a matching endpoint and replace a stale endpoint.
  • Fail with the underlying CLI diagnostics if list, JSON parsing, removal, or re-registration fails.

Testing

  • mise run windows:check:x64
  • mise run windows:test:x64 - 5,044 passed, 29 skipped.
  • mise run windows:artifacts
  • E2E missing/matching/stale alias matrix - all three runs PASS=4 FAIL=0.
  • OCSF mock missing/matching/stale alias matrix - all three runs passed.
  • PowerShell parser validation for both changed scripts.
  • IDE lint and git diff --check.
  • mise run windows:test:mxc-real:x64 - 13 passed, 2 unrelated existing failures: a stale IsolationSession request without schema version, and an HTTPS proxy probe returning HTTP 403 due to socket-owner/binary identity behavior.
  • Live OCSF event qualification - stale-alias replacement and sandbox creation passed, but this x64 host emitted 0/8 expected Sandboxing ETW event types. Three OCSF records were written; none had the expected event types.

Checklist

  • Follows Conventional Commits
  • Commit is signed off (DCO)

Signed-off-by: nv-vankit <nv-vankit@users.noreply.github.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 5, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

All contributors have signed the DCO ✍️ ✅
Posted by the DCO Assistant Lite bot.

@nv-vankit

Copy link
Copy Markdown
Author

I have read the DCO document and I hereby sign the DCO.

@nv-vankit nv-vankit changed the title fix(mxc): refresh stale demo gateway aliases (NVBug 6870039) fix(mxc): refresh stale demo gateway aliases Oct 5, 2026

@shailendra-nv shailendra-nv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes for two safety issues in the stale-alias recovery path.

  1. The runners can delete and replace an arbitrary persistent user gateway registration named by -GatewayName, including stored auth state, and do not restore the prior registration or active selection. Isolate CLI state per run or preserve and restore it.
  2. Clearing only OPENSHELL_GATEWAY leaves the higher-precedence OPENSHELL_GATEWAY_ENDPOINT override active, so sandbox create/delete operations can still target the wrong gateway. Clear and restore both overrides or explicitly bind every operational command to the expected endpoint.

Please add regression coverage that preserves a sentinel existing registration and active selection, and that runs with a nonblank OPENSHELL_GATEWAY_ENDPOINT.

$normalizedExpected = $expectedEndpoint.TrimEnd('/')
if ($existingEndpoint -ne $normalizedExpected) {
Info "'$GatewayName' points at '$existingEndpoint' instead of '$normalizedExpected'; replacing the stale registration"
$removeResult = Invoke-NativeCaptured $cli @("gateway", "remove", $GatewayName)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] This removes any user registration matching $GatewayName, including stored OIDC/edge credentials and the active selection, then replaces it with a plaintext test registration without restoring the old state. Run the CLI under a per-run XDG_CONFIG_HOME or preserve and restore the exact prior registration and active gateway. The OCSF runner has the same issue.

Step "Register CLI -> gateway"
$env:OPENSHELL_GATEWAY = ""
$gatewayAdd = Invoke-Cli @("gateway", "add", "http://127.0.0.1:$Port", "--local", "--name", $GatewayName) -AllowFailure
Remove-Item Env:OPENSHELL_GATEWAY -ErrorAction SilentlyContinue

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] OPENSHELL_GATEWAY_ENDPOINT has higher routing precedence and remains inherited here. Later create/delete calls can therefore operate on that endpoint; because this runner deletes fixed names such as ocsf1 even after a failed create, it can delete an existing sandbox on the wrong gateway. Clear and restore both overrides or explicitly bind every operational call to the expected endpoint. The E2E runner has the same precedence gap.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants