Skip to content

Make HTTP support optional at compile time - #281

Open
congwang-mk wants to merge 3 commits into
mainfrom
optional-http-features
Open

congwang-mk wants to merge 3 commits into
mainfrom
optional-http-features

Conversation

@congwang-mk

Copy link
Copy Markdown
Contributor

Summary

  • Add an optional feature, enabled by default, covering the HTTP ACL proxy, credentials, and network image transports.
  • Forward the feature through the CLI, FFI, and OCI crates; reject configured HTTP functionality clearly when disabled.
  • Keep working without HTTP support and add CI coverage for the minimal build.

Validation

  • Remote CI passed on the branch, including the no-default-features workspace test job.

More than half of sandlock-core's dependency graph (hyper, rustls,
rcgen, bollard and what they pull in) exists only for the HTTP ACL
proxy, credential injection and pulling images from a registry or the
Docker daemon. Users who only need the syscall sandbox want to build
without it, the way a kernel config drops subsystems it does not use.

The http feature is on by default, so nothing changes unless a build
opts out. Without it, a stub module stands in for the proxy and for
credential injection, so call sites need no cfg, and the builder
refuses any HTTP option rather than dropping a network restriction
without a word. Networked image references fail with the same error,
while oci: and oci-archive: images keep working.

Signed-off-by: Cong Wang <cwang@multikernel.io>
Each crate took sandlock-core with its default features, so a build
of the CLI, the C library or the OCI shim could never leave the HTTP
stack out. They now depend on the core without defaults and expose
the same http feature, on by default.

learn always installed an HTTP request logger, which needs the proxy,
so without the feature it would fail at policy build. It now records
everything but HTTP requests in that case, and the tests that check
HTTP capture only run when the feature is enabled.

Signed-off-by: Cong Wang <cwang@multikernel.io>
The existing jobs only build the default feature set, so a cfg slip
in the minimal build would go unnoticed. The new job asserts the
minimal build pulls in no HTTP stack and runs the full test suite
without the http feature.

Signed-off-by: Cong Wang <cwang@multikernel.io>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant