Skip to content

fix(policy): name the field in policy type errors - #4174

Merged
johntmyers merged 3 commits into
NVIDIA:mainfrom
ericcurtin:fix/4168-policy-type-error-path/ericcurtin
Oct 8, 2026
Merged

johntmyers merged 3 commits into
NVIDIA:mainfrom
ericcurtin:fix/4168-policy-type-error-path/ericcurtin

Conversation

@ericcurtin

Copy link
Copy Markdown
Contributor

Summary

Policy type errors now name the bad field, like unknown-field errors do.

Related Issue

Closes #4168

Changes

  • Decode with serde_path_to_error (already in the lockfile) and prefix the error with the field path.
  • Share the path length cap with unknown-field errors.

Testing

  • Checks appropriate to the affected code and behavior pass
  • Unit tests added/updated (if applicable)
  • E2E tests added/updated (if applicable)

cargo fmt, cargo clippy -D warnings and cargo test for openshell-policy-schema and openshell-policy. Prover tests not run (no local Z3).

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

Signed-off-by: Eric Curtin <eric.curtin@docker.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 4, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@ericcurtin

Copy link
Copy Markdown
Contributor Author

@mrunalp @johntmyers PTAL when you get a chance, and /ok to test f61db311e if it looks good. Thank you!

@johntmyers johntmyers added the test:e2e Requires end-to-end coverage label Oct 5, 2026
@johntmyers

Copy link
Copy Markdown
Collaborator

/ok to test f61db31

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

Label test:e2e applied, but pull-request/4174 does not exist yet. A maintainer needs to comment /ok to test f61db311e13f27737c0720f9b652f42f03121804 to mirror this PR. Once the mirror exists, re-apply the label or re-run Branch E2E Checks from the Actions tab.

@johntmyers

Copy link
Copy Markdown
Collaborator

gator-agent

PR Review Status

Thanks @ericcurtin, I checked your request for review and current-head test authorization. The independent review found no blocking issues: the parser adds bounded field paths to type errors while preserving validation and unknown-field handling. I posted the full-SHA test authorization and confirmed the mirror matches this head.

Blocking findings: None.

Carried findings: None.

Required workflows are now queued or running, including Branch Checks, E2E, and Trivy Changes; Helm Lint has passed. The E2E bot requested creation of the missing mirror, which is now present, and the E2E build jobs are running without a rerun. Gator will inspect the results next cycle.

Gator metadata
  • Validation: Concentrated diagnostic fix for accepted issue bug: policy type errors don't say which field is wrong #4168; no competing implementation identified.
  • Docs: Diagnostic wording correction preserves the existing policy workflow and schema; no operational contract change requiring Fern updates under pragmatic review calibration.
  • Checks: DCO and vouch passed; current-head Branch Checks and Trivy Changes dispatched; Helm gate passed.
  • E2E: test:e2e applied; current-head Branch E2E Checks dispatched with build jobs queued/running.
  • Head SHA: f61db311e13f27737c0720f9b652f42f03121804
  • Base SHA: 71c3cd957abef062eb7f37010056717cd49f2ed3
  • Merge base SHA: 71c3cd957abef062eb7f37010056717cd49f2ed3
  • Patch ID: 893b1adf32e84e2992bbed9c7295d2373228e1a3
  • Gator payload: 10
  • Review mode: initial
  • Previous reviewed SHA: none
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Next state: gator:watch-pipeline

@johntmyers johntmyers added gator:watch-pipeline Gator is monitoring PR CI/CD status gator:in-review Gator is reviewing or awaiting PR review feedback and removed gator:watch-pipeline Gator is monitoring PR CI/CD status labels Oct 5, 2026
Signed-off-by: Eric Curtin <eric.curtin@docker.com>
@ericcurtin

Copy link
Copy Markdown
Contributor Author

@johntmyers @sjenning Fixed the example lockfiles that broke CI. PTAL, and /ok to test 90bf975689cb072f21e6f7ff54b28840feef2f15 if it looks good. Thank you!

@johntmyers

Copy link
Copy Markdown
Collaborator

/ok to test 90bf975

@johntmyers

Copy link
Copy Markdown
Collaborator

gator-agent

PR Review Status

Thanks @ericcurtin, I checked your update about the example lockfiles. The independent follow-up review confirmed that both lockfiles include the policy schema's new dependency with the matching version and checksum; no blocking findings remain.

I posted current-head test authorization and confirmed the mirror matches. Branch Checks and E2E are queued, and Helm Lint passed. Trivy Changes is awaiting GitHub workflow approval; the sandbox policy denied the approval endpoint, so Gator cannot advance to pipeline monitoring yet.

Action required: A maintainer must approve the current-head Trivy Changes run to run. Alternatively, the sandbox operator can allow POST /repos/NVIDIA/OpenShell/actions/runs/37398374708/approve for api.github.com:443 using /usr/bin/gh so Gator can dispatch it.

Blocking findings: None.

Carried findings: None.

Gator metadata
  • Validation: Concentrated diagnostic fix for previously validated issue bug: policy type errors don't say which field is wrong #4168; this delta only refreshes two example lockfiles.
  • Docs: No new user-facing behavior in the follow-up delta; prior diagnostic docs disposition preserved.
  • Checks: DCO passed; current-head Branch Checks queued; Helm Lint passed; Trivy Changes requires workflow approval.
  • E2E: test:e2e retained; current-head Branch E2E Checks queued after mirror refresh; no bot-required rerun outstanding.
  • Head SHA: 90bf975689cb072f21e6f7ff54b28840feef2f15
  • Base SHA: 71c3cd957abef062eb7f37010056717cd49f2ed3
  • Merge base SHA: 71c3cd957abef062eb7f37010056717cd49f2ed3
  • Patch ID: c5bd04df2e8ab5c9b1d73a8244a174a49d5db600
  • Gator payload: 10
  • Review mode: follow_up
  • Previous reviewed SHA: f61db311e13f27737c0720f9b652f42f03121804
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Next state: gator:blocked
  • Blocked reason: test_dispatch_required

@johntmyers johntmyers added gator:blocked Gator is blocked by process or repository gates gator:watch-pipeline Gator is monitoring PR CI/CD status gator:approval-needed Gator completed review; maintainer approval needed and removed gator:in-review Gator is reviewing or awaiting PR review feedback gator:blocked Gator is blocked by process or repository gates gator:watch-pipeline Gator is monitoring PR CI/CD status labels Oct 6, 2026
@johntmyers
johntmyers added this pull request to the merge queue Oct 6, 2026
@johntmyers johntmyers added gator:merge-ready and removed gator:approval-needed Gator completed review; maintainer approval needed labels Oct 6, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 6, 2026
@johntmyers

Copy link
Copy Markdown
Collaborator

@ericcurtin this isn't able to merge as branch checks fail on the queue, can you rebase and take a look?

@johntmyers johntmyers added gator:in-review Gator is reviewing or awaiting PR review feedback and removed gator:merge-ready labels Oct 6, 2026
Signed-off-by: Eric Curtin <eric.curtin@docker.com>
@ericcurtin

Copy link
Copy Markdown
Contributor Author

Merged main. The queue failure was an unrelated port-reuse flake in sandbox_create_keeps_sandbox_with_forwarding. @johntmyers PTAL, and /ok to test 17934ba903a86fc03cc953088b64504b8f3018f6 if it looks good. Thank you!

@johntmyers

Copy link
Copy Markdown
Collaborator

/ok to test 17934ba

@johntmyers

Copy link
Copy Markdown
Collaborator

gator-agent

PR Review Status

Thanks @ericcurtin, I checked your update that main was merged after @johntmyers requested a rebase for the queue failure. The feedback ledger confirms the effective PR patch is identical to the previously reviewed patch, so the earlier review remains valid and no repeat review is needed. Your port-reuse flake diagnosis remains to be confirmed by the new CI results.

No blocking or carried Gator findings remain. I posted current-head /ok to test and confirmed the mirror matches. Branch Checks is running, E2E is queued, and the Helm workflow passed its change-detection gate. Maintainer approval is present, but required checks are not yet green.

Action required: A maintainer must approve the current-head Trivy Changes workflow, or the sandbox operator must apply the approved narrow policy proposal allowing that run's approval endpoint. The proposal has been approved but the policy has not reloaded, so Gator cannot dispatch Trivy yet.

Gator metadata
  • Validation: Concentrated policy diagnostic fix for previously validated issue bug: policy type errors don't say which field is wrong #4168.
  • Docs: Prior diagnostic-wording disposition preserved; effective patch unchanged.
  • Checks: DCO passed; Branch Checks running; Helm workflow completed successfully; Trivy Changes requires workflow approval.
  • E2E: test:e2e retained; current-head Branch E2E Checks queued; no bot-required rerun outstanding.
  • Head SHA: 17934ba903a86fc03cc953088b64504b8f3018f6
  • Base SHA: 3fc93e28273fe304db634e6d5e9a52d57200389e
  • Merge base SHA: 3fc93e28273fe304db634e6d5e9a52d57200389e
  • Patch ID: c5bd04df2e8ab5c9b1d73a8244a174a49d5db600
  • Gator payload: 10
  • Review mode: already_reviewed
  • Previous reviewed SHA: 90bf975689cb072f21e6f7ff54b28840feef2f15
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Next state: gator:blocked
  • Blocked reason: test_dispatch_required
  • Policy proposal: d58cf20d-fd62-44df-9c34-ea8159d7cc5b
  • Proposed policy allowance: POST /repos/NVIDIA/OpenShell/actions/runs/37606182564/approve on api.github.com:443 for /usr/bin/gh only.

@johntmyers johntmyers added gator:blocked Gator is blocked by process or repository gates gator:watch-pipeline Gator is monitoring PR CI/CD status gator:merge-ready and removed gator:in-review Gator is reviewing or awaiting PR review feedback gator:blocked Gator is blocked by process or repository gates gator:watch-pipeline Gator is monitoring PR CI/CD status labels Oct 7, 2026
@johntmyers
johntmyers added this pull request to the merge queue Oct 8, 2026
Merged via the queue into NVIDIA:main with commit 5cfb0e2 Oct 8, 2026
113 of 116 checks passed
@johntmyers

Copy link
Copy Markdown
Collaborator

gator-agent

Monitoring Complete

Monitoring is complete because this PR has merged.

Final status: Gator's last state was gator:merge-ready; the effective patch was already reviewed with no blocking Gator findings remaining.

I removed the active gator:* label because there is nothing left for Gator to monitor on this PR.

Gator metadata
  • Head SHA: 17934ba903a86fc03cc953088b64504b8f3018f6
  • Gator payload: 10

@ericcurtin
ericcurtin deleted the fix/4168-policy-type-error-path/ericcurtin branch October 8, 2026 00:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

test:e2e Requires end-to-end coverage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug: policy type errors don't say which field is wrong

3 participants