User Story
As a developer running the VM compute driver on macOS, I want per-sandbox Unix socket paths to fit within the OS sun_path limit so that sandbox creation does not fail with a socket bind error.
Problem Statement
The VM driver constructs per-sandbox Unix socket paths by joining {state_dir}/sandboxes/{sandbox_id}/{socket_name}. Sandbox IDs are UUID v4 strings (36 chars), and state_dir depends on the user's home directory. On macOS, struct sockaddr_un.sun_path is 104 bytes (103 usable). With the default state_dir (~/.local/state/openshell/vm-driver), the resulting socket path reaches 107 bytes — 3 bytes over the limit — and bind() fails.
/Users/benoitf/.local/state/openshell/vm-driver/sandboxes/3eb2ad45-bead-4c2e-bd10-1a4a7f3a2721/control.sock
└─────────────────────────────────── 107 bytes ──────────────────────────────────────┘
Path length breakdown:
/Users/benoitf/.local/state/openshell/vm-driver (47)
/sandboxes/ (11)
3eb2ad45-bead-4c2e-bd10-1a4a7f3a2721 (36)
/control.sock (13)
total = 107 bytes
macOS limit = 104 bytes
over by 3 bytes
Impact / Why This Matters
When this happens, VM sandbox creation fails at the control socket bind step. The error surfaces as a low-level socket error, not as a clear path-length diagnostic.
The current workaround is to manually configure a short state_dir (e.g. /tmp/os-vm). or rename control.sock for ctl.sock for my case (as I reduced 3 extra chars)
This is non-obvious, fragile, and breaks persistence expectations. Any user whose home directory path is longer than /Users/benoitf (15 chars) would be even further over the limit.
Linux is less affected (108-byte limit) but not immune with deep state directories or longer usernames.
Acceptance Criteria
Reproduction Steps
- On macOS, start the gateway with
--compute-driver vm using the default state_dir (~/.local/state/openshell/vm-driver)
- Run
openshell sandbox create --name test --from ubuntu:24.04
- Observe the sandbox creation fails at the control socket bind
Environment
- OpenShell: development build (current main branch)
- OS: macOS (Apple Silicon) —
sun_path is 104 bytes
- Runtime: VM compute driver (libkrun)
Logs
Error: bind() failed for /Users/benoitf/.local/state/openshell/vm-driver/sandboxes/3eb2ad45-bead-4c2e-bd10-1a4a7f3a2721/control.sock
User Story
As a developer running the VM compute driver on macOS, I want per-sandbox Unix socket paths to fit within the OS
sun_pathlimit so that sandbox creation does not fail with a socket bind error.Problem Statement
The VM driver constructs per-sandbox Unix socket paths by joining
{state_dir}/sandboxes/{sandbox_id}/{socket_name}. Sandbox IDs are UUID v4 strings (36 chars), andstate_dirdepends on the user's home directory. On macOS,struct sockaddr_un.sun_pathis 104 bytes (103 usable). With the defaultstate_dir(~/.local/state/openshell/vm-driver), the resulting socket path reaches 107 bytes — 3 bytes over the limit — andbind()fails.Path length breakdown:
Impact / Why This Matters
When this happens, VM sandbox creation fails at the control socket bind step. The error surfaces as a low-level socket error, not as a clear path-length diagnostic.
The current workaround is to manually configure a short
state_dir(e.g./tmp/os-vm). or renamecontrol.sockforctl.sockfor my case (as I reduced 3 extra chars)This is non-obvious, fragile, and breaks persistence expectations. Any user whose home directory path is longer than
/Users/benoitf(15 chars) would be even further over the limit.Linux is less affected (108-byte limit) but not immune with deep state directories or longer usernames.
Acceptance Criteria
state_dirrun/compute-driver.sock) remains unaffectedReproduction Steps
--compute-driver vmusing the defaultstate_dir(~/.local/state/openshell/vm-driver)openshell sandbox create --name test --from ubuntu:24.04Environment
sun_pathis 104 bytesLogs