feat(vmm): enforce bridge MAC identity with netd - #836
Closed
kvinwang wants to merge 4 commits into
Closed
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stack
Summary
dstack-vmm netd, a separate root networking backend with a bounded JSON-over-UDS protocol andSO_PEERCREDUID authorizationlocked, BPDU guard, root blocking, optional port isolation, and one static FDB MAC entry-netdev tap,ifname=...,script=no,downscript=no,vhost=offSecurity invariant delivered
When
anti_spoof = true, QEMU cannot start until every bridge NIC has a daemon-owned deterministic TAP with host-enforced MAC/L2 policy. The VMM itself does not receiveCAP_NET_ADMIN. If preparation or restart reconciliation fails, the guest remains stopped rather than running on an unprotected bridge port.Cleanup intentionally depends on deterministic identity plus the exact ownership alias, not on the old bridge still existing or remaining allowlisted. This permits safe orphan cleanup after an administrator changes bridge policy while still refusing to modify foreign interfaces.
Configuration
Start the backend before the VMM:
The feature remains opt-in so #835 can merge without changing existing bridge deployments.
Verification
cargo test -p dstack-vmm— 63 passedcargo clippy -p dstack-vmm --all-targets -- -D warningsgit diff --check feat/secure-bridge-networking...HEADlocked/guard/root_block/isolated, static FDB, and netdev ingress rules accepteddstack-vmm netdpreparecreates TAP/FDB/nft policycheckproves enforcement stateremovequiesces and deletes all owned resources