Skip to content

[code-improvement] documentation: document run network policy options - #220

Merged
Pedro Henrique Penna (ppenna) merged 2 commits into
devfrom
code-improvement/document-run-network-policy-4a198c1136775c6c
Sep 27, 2026
Merged

Pedro Henrique Penna (ppenna) merged 2 commits into
devfrom
code-improvement/document-run-network-policy-4a198c1136775c6c

Conversation

@ppenna

Copy link
Copy Markdown
Contributor

Scope

Category: documentation

The run parser and doc/run.md already expose and explain directional network policy, but the canonical CLI reference omitted those options. This adds the existing egress, ingress, host-loopback, proxy, and forwarding controls to doc/usage.md.

Live searches found no open issue or pull request for this omission. Recent documentation code-improvement proposals were merged, and no maintainer rejection covers this candidate.

Patch

  • Changed doc/usage.md.
  • Added 14 lines; deleted 0 lines; total changed lines: 14.
  • Made no dependency, public API/CLI/ABI, gitlink, or OpenVMM change.

Validation

  • python3 scripts/nvx.py run --help — passed; all documented options are present.
  • grep -E -- '--network-egress|--network-ingress|--host-loopback|--network-proxy' over the help output — passed.
  • Verified defaults and rule semantics against doc/run.md and scripts/nvx.py.
  • git diff --check — passed.
  • git diff --numstat — 14 0 doc/usage.md.
  • git diff --raw — one regular 100644 documentation file; no 160000 gitlink.

Generated by code-improvement · copilot · gpt56 · 97.6 AIC · ⌖ 21.9 AIC · ⊞ 15.9K · ◷

  • expires on Oct 11, 2026, 4:52 AM UTC

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 27, 2026 04:52

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Several documented choices omit runtime constraints and would produce rejected invocations.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Documents existing directional network-policy options in the canonical CLI reference.

Changes:

  • Adds network policy options to the run synopsis.
  • Documents defaults and rule behavior.
File Description
doc/​usage.md Adds run network-policy reference entries.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread doc/usage.md Outdated
Clarify the behavior of the --network-ingress option in the portable profile.

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 27, 2026 15:32
@ppenna
Pedro Henrique Penna (ppenna) marked this pull request as ready for review September 27, 2026 15:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Several enforced option dependencies and endpoint constraints are omitted.

Review effort: Balanced
Findings: None

Resolved since last review (1)
Previously missed (1)

In code that hasn't changed since last review

Low severity Document required --network-egress for rule options

doc/​usage.md:330

These rule options are rejected unless --network-egress is explicitly supplied, even though the preceding row lists an implicit allow default. Without documenting that requirement, the canonical reference leads to commands that fail with --network-egress is required (also described in doc/run.md:121-140).

This issue also appears on line 331 of the same file.

@ppenna
Pedro Henrique Penna (ppenna) merged commit 58b7bf6 into dev Sep 27, 2026
38 checks passed
@ppenna
Pedro Henrique Penna (ppenna) deleted the code-improvement/document-run-network-policy-4a198c1136775c6c branch September 27, 2026 15:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants