Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion skills/debug-openshell-cluster/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -260,7 +260,7 @@ Common findings:
gateway's primary endpoint is reachable from a host-networked container.
- Sandbox runtime image exits before printing `openshell-sandbox --version`: verify the configured image contains a static executable at `/openshell-sandbox`.
- A sandbox with explicit `protocol: tcp` endpoints fails before workload readiness: confirm the selected isolation backend advertises TCP mediation, then inspect the sandbox and supervisor logs for protected-channel setup or listener failures. A driver that cannot supply the required outer egress fence and authenticated runtime channel must reject the policy before starting the agent.
- Supervisor runtime validation fails: verify `supervisor_image` contains a static `/openshell-supervisor` executable from the same release as the sandbox runtime.
- Supervisor runtime validation fails: verify `supervisor_image` contains an `/openshell-supervisor` executable from the same release as the sandbox runtime, and that the dynamic loader and shared libraries it links against are available inside that image. `docker run --rm --network none --entrypoint /openshell-supervisor <supervisor_image> --version` should print that release; a `no such file or directory` error for a binary that exists means the loader or a library is missing. The supervisor runs from its own image and does not need to be static; only `/openshell-sandbox` must be.
- The sandbox fails its enforcement probe: inspect the sandbox log for the exact nested seccomp user-notification, task-memory, Landlock, loopback DNS, or socket-injection check that failed. Do not add capabilities or switch to an unconfined seccomp profile; use a runtime whose default profile permits the unprivileged probe.
- A GPU sandbox fails because Docker reports no discovered NVIDIA CDI devices: verify `.DiscoveredDevices` contains entries such as `nvidia.com/gpu=all`, verify `/etc/cdi` or `/var/run/cdi` contains a generated NVIDIA spec, and check that `nvidia-cdi-refresh.service` and `nvidia-cdi-refresh.path` from NVIDIA Container Toolkit are enabled and healthy. The service is a one-shot unit, so `inactive (dead)` can be normal after a successful run; use `systemctl status` and `journalctl` to distinguish success from a skipped or failed refresh. Restart `nvidia-cdi-refresh.service` to regenerate missing or stale CDI specs, then restart or reload Docker and re-check `docker info`.

Expand Down
4 changes: 1 addition & 3 deletions tasks/scripts/stage-prebuilt-binaries.sh
Original file line number Diff line number Diff line change
Expand Up @@ -28,9 +28,7 @@ target_triple() {
local suffix
case "$libc" in
musl) suffix=musl ;;
# gnu-static builds the GNU target with +crt-static, so it shares the
# gnu triple.
gnu|gnu-static) suffix=gnu ;;
gnu) suffix=gnu ;;
*)
echo "unsupported libc: $libc" >&2
exit 1
Expand Down
13 changes: 7 additions & 6 deletions tasks/scripts/verify-static-binary.sh
Original file line number Diff line number Diff line change
Expand Up @@ -6,11 +6,12 @@ set -euo pipefail

# Verify a binary is a genuine, complete, fully static executable.
#
# The supervisor is executed from inside arbitrary sandbox images (Docker
# extraction, Podman image volumes, the Kubernetes copy-self path), so any
# dynamic linkage breaks it on musl-based images and on images whose glibc is
# older than the build host's. Both supported supervisor libc variants (musl
# and glibc-static) must therefore produce a static binary.
# Callers pass binaries that must run without a dynamic loader, such as the
# musl sandbox runtime (openshell-sandbox). It is executed from inside
# arbitrary workload images (Docker extraction, Podman image volumes, the
# Kubernetes copy-self path), so any dynamic linkage breaks it on musl-based
# images and on images whose glibc is older than the build host's. Other
# callers include the release prover and e2e fixtures.
#
# This check exists because the failure is silent: `zig cc` accepts `-static`
# for `*-linux-gnu` targets and emits a dynamically linked binary anyway, so a
Expand Down Expand Up @@ -57,7 +58,7 @@ if [[ -z $READELF ]]; then
host_os=""
command -v uname >/dev/null 2>&1 && host_os=$(uname -s 2>/dev/null || true)
# Skip only on a host positively identified as non-Linux — e.g. a macOS dev
# cross-building the Linux supervisor via cargo-zigbuild, where mise installs
# cross-building a Linux musl binary via cargo-zigbuild, where mise installs
# no binutils. Linux (including CI), or any host whose OS cannot be determined,
# fails closed so a missing inspector never silently passes. Static linkage is
# still enforced in CI, which runs on Linux.
Expand Down
Loading