Skip to content

Commit c9257c8

Browse files
authored
fix(policy): restore policy.local and proposal conformance (#3689)
* fix(policy): restore policy.local and proposal conformance Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com> * test(conformance): select policy scenarios by name Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com> * test(conformance): reduce policy scenario timing flakes Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com> * test(conformance): assert proposals target Bash Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com> --------- Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
1 parent 5448fb4 commit c9257c8

23 files changed

Lines changed: 1031 additions & 177 deletions

File tree

‎CI.md‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,21 @@ The GitHub ruleset should require the `OpenShell / ...` statuses published by
4040
`Required CI Gates` plus the direct `OpenShell / Trivy Changes` result, not the
4141
push-triggered workflow jobs themselves.
4242

43+
### Run only the policy advisor conformance tests
44+
45+
Manually dispatch `Integration Tests` on the candidate branch with an
46+
`artifact-run-id` from a build of the same commit. Set `category` to
47+
`policy-advisor` and `test-matrix` to:
48+
49+
```json
50+
[{"environment":"ubuntu-docker-rootful","installer":"binaries","testsuite":"policy-advisor"}]
51+
```
52+
53+
This runs the `mechanistic-proposal` and `policy-local` conformance tests in the
54+
installed-artifact suite. The artifact run must contain the candidate CLI and
55+
gateway binaries and runtime images. This manual run does not replace the
56+
required PR E2E gate.
57+
4358
## Informational security reports
4459

4560
Security workflow compute runs directly on GitHub-hosted runners instead of

‎TESTING.md‎

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -181,8 +181,11 @@ lifecycle management, output parsing, and cleanup.
181181
Suites:
182182

183183
- Common suite (`--features e2e`) - driver-neutral CLI behavior, sandbox lifecycle, sync, port forwarding, policy, and provider tests.
184-
- CLI conformance (`openshell-conformance`) - the portable deployment smoke
185-
scenario plus focused tests for its reusable command runner.
184+
- CLI conformance (`openshell-conformance`) - named scenarios for lifecycle,
185+
mechanistic drafts, and the sandbox-local API, including agent-authored
186+
permission requests. Driver E2E wrappers run every scenario. The
187+
installed-artifact conformance suite runs all scenarios and offers a focused
188+
`policy-advisor` testsuite for manual integration runs.
186189
- Driver suites (`--features e2e-docker`, `e2e-podman`, `e2e-kubernetes`, or
187190
`e2e-vm`) - CLI conformance plus the common and driver-specific coverage for
188191
the selected deployment.

‎architecture/sandbox.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -321,6 +321,16 @@ captured before the bypass fence, mapped back to its workload process, authorize
321321
through the same egress pipeline, and dialed only through the pinned addresses.
322322
Omitted protocol endpoints retain explicit-proxy behavior.
323323

324+
Policy DNS reserves `policy.local` inside each sandbox without requiring an
325+
authored network endpoint or a trusted external lookup. The source-backed TCP
326+
boundary routes plain HTTP on the reserved address and port 80 to the
327+
supervisor's sandbox-local policy API; it does not open an upstream connection.
328+
The API checks the effective agent proposal setting for every request. Policy
329+
denials at the staged TCP authorization gate enter the supervisor's denial
330+
aggregator with the resolved binary and destination, so the mechanistic mapper
331+
can propose a scoped rule. Invalid mappings and destination validation failures
332+
do not become policy proposals.
333+
324334
Provider credential placeholders are resolved through the live provider state
325335
for each HTTP request, after destination and L7 policy admission. A static
326336
credential resolves only when the request host, port, and path match an endpoint

‎crates/openshell-conformance-cli/src/main.rs‎

Lines changed: 17 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -91,7 +91,7 @@ fn list(output: OutputFormat) -> Result<(), String> {
9191
match output {
9292
OutputFormat::Text => {
9393
for candidate in scenarios() {
94-
println!("{:<16} {}", candidate.name, candidate.description);
94+
println!("{:<24} {}", candidate.name, candidate.description);
9595
}
9696
}
9797
OutputFormat::Json => {
@@ -231,6 +231,22 @@ mod tests {
231231
assert!(error.contains("openshell-conformance list"));
232232
}
233233

234+
#[test]
235+
fn selects_named_policy_scenarios() {
236+
let selected = select_scenarios(&[
237+
"mechanistic-proposal".to_string(),
238+
"policy-local".to_string(),
239+
])
240+
.unwrap();
241+
assert_eq!(
242+
selected
243+
.iter()
244+
.map(|scenario| scenario.name)
245+
.collect::<Vec<_>>(),
246+
["mechanistic-proposal", "policy-local"]
247+
);
248+
}
249+
234250
#[test]
235251
fn parses_binary_override_and_json_output() {
236252
let cli = Cli::try_parse_from([

‎crates/openshell-conformance/Cargo.toml‎

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -14,10 +14,8 @@ repository.workspace = true
1414
rand.workspace = true
1515
serde.workspace = true
1616
serde_json.workspace = true
17-
tokio.workspace = true
18-
19-
[dev-dependencies]
2017
tempfile = "3"
18+
tokio.workspace = true
2119

2220
[lints]
2321
workspace = true

‎crates/openshell-conformance/src/executor.rs‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -50,6 +50,7 @@ impl CliExecutor for ProcessCli {
5050
process
5151
.args(&args)
5252
.envs(environment)
53+
.env("NO_COLOR", "1")
5354
.stdout(Stdio::piped())
5455
.stderr(Stdio::piped())
5556
.kill_on_drop(true);

‎crates/openshell-conformance/src/lib.rs‎

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,10 @@ use tokio::time::sleep;
2323

2424
use self::executor::{CliExecutionError, CliExecutor, ProcessCli};
2525

26-
pub use scenarios::{SANDBOX_LIFECYCLE_SCENARIO, SMOKE_SCENARIO};
26+
pub use scenarios::{
27+
MECHANISTIC_PROPOSAL_SCENARIO, POLICY_LOCAL_SCENARIO, SANDBOX_LIFECYCLE_SCENARIO,
28+
SMOKE_SCENARIO,
29+
};
2730

2831
/// An installed conformance scenario.
2932
#[derive(Debug)]
@@ -41,7 +44,12 @@ impl Scenario {
4144
}
4245
}
4346

44-
const SCENARIOS: &[Scenario] = &[SMOKE_SCENARIO, SANDBOX_LIFECYCLE_SCENARIO];
47+
const SCENARIOS: &[Scenario] = &[
48+
SMOKE_SCENARIO,
49+
SANDBOX_LIFECYCLE_SCENARIO,
50+
MECHANISTIC_PROPOSAL_SCENARIO,
51+
POLICY_LOCAL_SCENARIO,
52+
];
4553

4654
/// Returns every scenario compiled into this distribution.
4755
pub fn scenarios() -> &'static [Scenario] {

‎crates/openshell-conformance/src/scenarios/mod.rs‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,8 +3,10 @@
33

44
//! Registered, portable conformance scenarios.
55
6+
mod policy_behavior;
67
mod sandbox_lifecycle;
78
mod smoke;
89

10+
pub use policy_behavior::{MECHANISTIC_PROPOSAL_SCENARIO, POLICY_LOCAL_SCENARIO};
911
pub use sandbox_lifecycle::SANDBOX_LIFECYCLE_SCENARIO;
1012
pub use smoke::SMOKE_SCENARIO;

0 commit comments

Comments
 (0)