diff --git a/skills/debug-openshell-cluster/SKILL.md b/skills/debug-openshell-cluster/SKILL.md index 441ffa718a..f81416c5ab 100644 --- a/skills/debug-openshell-cluster/SKILL.md +++ b/skills/debug-openshell-cluster/SKILL.md @@ -260,7 +260,7 @@ Common findings: gateway's primary endpoint is reachable from a host-networked container. - Sandbox runtime image exits before printing `openshell-sandbox --version`: verify the configured image contains a static executable at `/openshell-sandbox`. - A sandbox with explicit `protocol: tcp` endpoints fails before workload readiness: confirm the selected isolation backend advertises TCP mediation, then inspect the sandbox and supervisor logs for protected-channel setup or listener failures. A driver that cannot supply the required outer egress fence and authenticated runtime channel must reject the policy before starting the agent. -- Supervisor runtime validation fails: verify `supervisor_image` contains a static `/openshell-supervisor` executable from the same release as the sandbox runtime. +- Supervisor runtime validation fails: verify `supervisor_image` contains an `/openshell-supervisor` executable from the same release as the sandbox runtime, and that the dynamic loader and shared libraries it links against are available inside that image. `docker run --rm --network none --entrypoint /openshell-supervisor --version` should print that release; a `no such file or directory` error for a binary that exists means the loader or a library is missing. The supervisor runs from its own image and does not need to be static; only `/openshell-sandbox` must be. - The sandbox fails its enforcement probe: inspect the sandbox log for the exact nested seccomp user-notification, task-memory, Landlock, loopback DNS, or socket-injection check that failed. Do not add capabilities or switch to an unconfined seccomp profile; use a runtime whose default profile permits the unprivileged probe. - A GPU sandbox fails because Docker reports no discovered NVIDIA CDI devices: verify `.DiscoveredDevices` contains entries such as `nvidia.com/gpu=all`, verify `/etc/cdi` or `/var/run/cdi` contains a generated NVIDIA spec, and check that `nvidia-cdi-refresh.service` and `nvidia-cdi-refresh.path` from NVIDIA Container Toolkit are enabled and healthy. The service is a one-shot unit, so `inactive (dead)` can be normal after a successful run; use `systemctl status` and `journalctl` to distinguish success from a skipped or failed refresh. Restart `nvidia-cdi-refresh.service` to regenerate missing or stale CDI specs, then restart or reload Docker and re-check `docker info`. diff --git a/tasks/scripts/stage-prebuilt-binaries.sh b/tasks/scripts/stage-prebuilt-binaries.sh index ca03b42612..312cec7a91 100755 --- a/tasks/scripts/stage-prebuilt-binaries.sh +++ b/tasks/scripts/stage-prebuilt-binaries.sh @@ -28,9 +28,7 @@ target_triple() { local suffix case "$libc" in musl) suffix=musl ;; - # gnu-static builds the GNU target with +crt-static, so it shares the - # gnu triple. - gnu|gnu-static) suffix=gnu ;; + gnu) suffix=gnu ;; *) echo "unsupported libc: $libc" >&2 exit 1 diff --git a/tasks/scripts/verify-static-binary.sh b/tasks/scripts/verify-static-binary.sh index 006158ca62..070af27c5a 100755 --- a/tasks/scripts/verify-static-binary.sh +++ b/tasks/scripts/verify-static-binary.sh @@ -6,11 +6,12 @@ set -euo pipefail # Verify a binary is a genuine, complete, fully static executable. # -# The supervisor is executed from inside arbitrary sandbox images (Docker -# extraction, Podman image volumes, the Kubernetes copy-self path), so any -# dynamic linkage breaks it on musl-based images and on images whose glibc is -# older than the build host's. Both supported supervisor libc variants (musl -# and glibc-static) must therefore produce a static binary. +# Callers pass binaries that must run without a dynamic loader, such as the +# musl sandbox runtime (openshell-sandbox). It is executed from inside +# arbitrary workload images (Docker extraction, Podman image volumes, the +# Kubernetes copy-self path), so any dynamic linkage breaks it on musl-based +# images and on images whose glibc is older than the build host's. Other +# callers include the release prover and e2e fixtures. # # This check exists because the failure is silent: `zig cc` accepts `-static` # for `*-linux-gnu` targets and emits a dynamically linked binary anyway, so a @@ -57,7 +58,7 @@ if [[ -z $READELF ]]; then host_os="" command -v uname >/dev/null 2>&1 && host_os=$(uname -s 2>/dev/null || true) # Skip only on a host positively identified as non-Linux — e.g. a macOS dev - # cross-building the Linux supervisor via cargo-zigbuild, where mise installs + # cross-building a Linux musl binary via cargo-zigbuild, where mise installs # no binutils. Linux (including CI), or any host whose OS cannot be determined, # fails closed so a missing inspector never silently passes. Static linkage is # still enforced in CI, which runs on Linux.