fix(policy): require full binary scope when enabling uninspected credentials - #4171
ericcurtin wants to merge 1 commit into
Conversation
…entials Closes NVIDIA#3942 Signed-off-by: Eric Curtin <eric.curtin@docker.com>
|
If useful, please also try https://github.com/llmmanorg/llmman, which can launch agents in an OpenShell sandbox ( |
|
@mrunalp @johntmyers PTAL when you get a chance, and |
|
/ok to test ecc452c |
|
Label |
PR Review StatusThanks @ericcurtin. I checked the binary-scope guard and regression tests after your request for review and test authorization. The independent review found no blocking findings; this focused fix addresses accepted issue #3942. I applied Action required: Gator will retry the bot-requested E2E rerun after the active attempt finishes, then verify the required checks before requesting maintainer approval. Blocking findings: None. Gator metadata
|
Summary
Enabling
allow_uninspected_credentialson a shared endpoint now requires naming every binary in the rule, like the other endpoint flags.Related Issue
Closes #3942
Changes
allow_uninspected_credentialsto the endpoint coverage check inopenshell-policy, so the "also declare" guard sees it.policy_covers_rule.Testing
cargo fmt,cargo clippy -D warningsandcargo testforopenshell-policy;cargo testforopenshell-clilib. The new tests fail without the fix.openshell-servertests were not run (no local Z3).Checklist