@@ -50,8 +50,12 @@ or MCP rules, the prover reports that it cannot check the policy instead of
5050ignoring those rules. [ What the Boundary Check
5151Covers] ( #what-the-boundary-check-covers ) describes each part and its limits.
5252
53- The ` openshell-prover ` CLI is installed with OpenShell. It reads policy files on
54- your machine, does not need a gateway, and does not apply or approve policies.
53+ The Homebrew, Debian, and RPM packages install the ` openshell-prover ` CLI. The
54+ snap package does not include it, so on a snap installation, download the
55+ ` openshell-prover ` archive for your platform from the [ OpenShell
56+ releases] ( https://github.com/NVIDIA/OpenShell/releases ) . The CLI reads policy
57+ files on your machine, does not need a gateway, and does not apply or approve
58+ policies.
5559
5660Create ` boundary.yaml ` , a boundary that allows reading ` /usr ` and ` /etc ` :
5761
@@ -85,7 +89,7 @@ result: within_boundary
8589coverage: domains=filesystem,network_l4,network_rest,process,landlock
8690` ` `
8791
88- The `coverage` line lists the parts of the policy that the prover checked . Now
92+ The `coverage` line lists the parts of a policy that the prover can check . Now
8993change the candidate so that it also allows writing to `/tmp`, which the
9094boundary does not allow :
9195
@@ -117,8 +121,9 @@ openshell sandbox get my-sandbox --policy-only > candidate.yaml
117121openshell-prover check candidate.yaml --boundary boundary.yaml
118122` ` `
119123
120- The effective policy includes rules from attached providers, so the check covers
121- everything the sandbox can reach. The prover does not add provider rules itself.
124+ The effective policy includes rules from attached providers, so the check
125+ includes network access that providers add. The prover does not add provider
126+ rules itself.
122127To check a change before you apply it, give the prover the complete effective
123128policy as it would be after the change.
124129
@@ -206,8 +211,13 @@ The prover returns `unsupported` in these cases:
206211 glob, such as `/usr/bin/curl` under `/usr/bin/*`. A symlink in the sandbox
207212 image could make the exact path refer to an executable outside the glob. Use
208213 the same exact paths in both policies when you can.
209- - Endpoints that could match the same host and port, including wildcard hosts,
210- set different `allowed_ips`.
214+ - Endpoints on the same port set different `allowed_ips`, and their hosts are
215+ the same or one of them is a wildcard. The prover treats a wildcard host as
216+ overlapping every host on its port.
217+ - An exact host and a wildcard host share a port and neither sets
218+ ` allowed_ips` , such as `github.com` and `*.githubusercontent.com` on port 443.
219+ - An endpoint omits `host`, sets both `port` and `ports`, or uses an IPv6
220+ address as its host.
211221- A host, path, method, or binary contains non-ASCII characters.
212222
213223# ## REST Requests
@@ -216,5 +226,6 @@ The prover compares method and path allow and deny rules on endpoints with
216226`protocol : rest`. These endpoints must use `enforcement: enforce`. An endpoint
217227in audit mode returns `unsupported`, because it does not block requests. A host
218228and port that has both a REST endpoint and an endpoint without request rules
219- also returns `unsupported`. Other request protocols, such as WebSocket, GraphQL,
220- MCP, and JSON-RPC, return `unsupported`.
229+ also returns `unsupported`, as do REST rules that match query parameters or use
230+ ` ?` or bracket expressions in paths. Other request protocols, such as WebSocket,
231+ GraphQL, MCP, and JSON-RPC, return `unsupported`.
0 commit comments