Skip to content

fix(policy): require full binary scope when enabling uninspected credentials - #4171

Open
ericcurtin wants to merge 1 commit into
NVIDIA:mainfrom
ericcurtin:fix/3942-uninspected-credentials-scope/ericcurtin
Open

ericcurtin wants to merge 1 commit into
NVIDIA:mainfrom
ericcurtin:fix/3942-uninspected-credentials-scope/ericcurtin

Conversation

@ericcurtin

Copy link
Copy Markdown
Contributor

Summary

Enabling allow_uninspected_credentials on a shared endpoint now requires naming every binary in the rule, like the other endpoint flags.

Related Issue

Closes #3942

Changes

  • Add allow_uninspected_credentials to the endpoint coverage check in openshell-policy, so the "also declare" guard sees it.
  • Tests for all four endpoint flags and for policy_covers_rule.

Testing

  • Checks appropriate to the affected code and behavior pass
  • Unit tests added/updated (if applicable)
  • E2E tests added/updated (if applicable)

cargo fmt, cargo clippy -D warnings and cargo test for openshell-policy; cargo test for openshell-cli lib. The new tests fail without the fix. openshell-server tests were not run (no local Z3).

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

…entials

Closes NVIDIA#3942

Signed-off-by: Eric Curtin <eric.curtin@docker.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@ericcurtin

Copy link
Copy Markdown
Contributor Author

If useful, please also try https://github.com/llmmanorg/llmman, which can launch agents in an OpenShell sandbox (--sandbox openshell).

@ericcurtin

Copy link
Copy Markdown
Contributor Author

@mrunalp @johntmyers PTAL when you get a chance, and /ok to test ecc452c75cbf686875c0a33d6779d0afc7ece611 if it looks good. Thank you!

@johntmyers johntmyers added the test:e2e Requires end-to-end coverage label Oct 5, 2026
@johntmyers

Copy link
Copy Markdown
Collaborator

/ok to test ecc452c

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Label test:e2e applied for ecc452c. Open the existing run and click Re-run all jobs to execute with the label set. The run will execute the standard E2E suite after building the required gateway, sandbox, and supervisor images once. The matching required CI gate status on this PR will flip green automatically once the run finishes.

@johntmyers

Copy link
Copy Markdown
Collaborator

gator-agent

PR Review Status

Thanks @ericcurtin. I checked the binary-scope guard and regression tests after your request for review and test authorization. The independent review found no blocking findings; this focused fix addresses accepted issue #3942.

I applied test:e2e and posted /ok to test for the current head. The mirror is current, and Branch Checks, Helm Lint, E2E, and Trivy are queued. The E2E Label Help bot requested Re-run all jobs, but GitHub refused the rerun because the workflow is already running.

Action required: Gator will retry the bot-requested E2E rerun after the active attempt finishes, then verify the required checks before requesting maintainer approval.

Blocking findings: None.
Carried findings: None.

Gator metadata
  • Validation: Focused policy correctness fix for accepted issue allow_uninspected_credentials update grants the exception to binaries not named in the update #3942.
  • Docs: No new interface or policy surface; restores the existing documented requirement that new permissions cannot reach unnamed binaries.
  • Checks: DCO and vouch passed. Current-head Branch Checks, Helm Lint, and Trivy are queued; required results are not yet green.
  • E2E: test:e2e applied; current-head Branch E2E Checks run 37390046107 attempt 1 is queued. Bot-required rerun rejected by GitHub as already running; retry once it finishes.
  • Head SHA: ecc452c75cbf686875c0a33d6779d0afc7ece611
  • Base SHA: 8983642e280e7b0f2ed423edbffd705ef259e7c0
  • Merge base SHA: a2429fcdcdf3b6e80f185317d3910fd8f84055f6
  • Patch ID: 7fe61f4cd61d4bf6d8cb6745c6b50104b2280a85
  • Gator payload: 10
  • Review mode: initial
  • Previous reviewed SHA: none
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Next state: gator:blocked
  • Blocked reason: test_dispatch_required

@johntmyers johntmyers added gator:blocked Gator is blocked by process or repository gates gator:watch-pipeline Gator is monitoring PR CI/CD status gator:approval-needed Gator completed review; maintainer approval needed and removed gator:blocked Gator is blocked by process or repository gates gator:watch-pipeline Gator is monitoring PR CI/CD status labels Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gator:approval-needed Gator completed review; maintainer approval needed test:e2e Requires end-to-end coverage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

allow_uninspected_credentials update grants the exception to binaries not named in the update

2 participants