Automated Sync from main to stable - #8
Merged
Merged
Conversation
…VIDIA#3753) * fix(network): refuse protocol upgrades on JSON-RPC and MCP endpoints JSON-RPC and MCP rules apply to each HTTP request, but the proxy could forward a request that also carried upgrade headers. After an upstream answered 101, route selection and the forward proxy relayed the connection without inspection. Refuse any request that carries an Upgrade header on JSON-RPC-family endpoints before the L7 policy decision, in every enforcement mode. Share the check with the existing h2c refusal and call it from relay_jsonrpc as well. Record the refusal as a policy denial and answer with the unsupported_l7_protocol error, because no policy rule can allow the request. If a JSON-RPC-family endpoint still receives 101, close the connection instead of relaying raw bytes. Document the refusal and the WebSocket alternative. Signed-off-by: Shiju <shiju@nvidia.com> * docs(observability): remove duplicate protocol error definition Keep unsupported_l7_protocol in the response error-code list and retain its explanation in the policy troubleshooting table. Signed-off-by: Shiju <shiju@nvidia.com> --------- Signed-off-by: Shiju <shiju@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Evan Lezar <elezar@nvidia.com>
…IDIA#3335) * fix(sandbox-backend): sort boundary request objects before hashing Sort boundary request objects recursively before hashing so serde_json's preserve_order feature cannot change digest identity. Cover canonical bytes, envelope round trips, and rejection of modified provider values and operations. Signed-off-by: Shiju <shiju@nvidia.com> * feat(mcp): upgrade tower-mcp-types to 0.22.2 Upgrade tower-mcp-types from 0.12.0 to an exact-pinned 0.22.2 and use its inspection APIs to validate MCP requests against the selected revision. Carry inspection metadata into policy evaluation and validate requests after header rewriting, before forwarding. Add explicit support for the sessionless 2026-07-28 revision while keeping 2025-11-25 as the default. Validate per-request metadata and standard HTTP header mirrors, and support discovery, tools, and subscription requests. Delegate batch availability and parameter schemas to Tower. Share typed request names between policy and HTTP checks, retain the local batch resource cap, and centralize MCP policy version parsing and ordering. Keep supported MCP revisions and shared allowlist parsing in the canonical policy schema; core re-exports those types. Tower owns wire-profile semantics, and every supported policy revision must map to the matching inspector profile. Reject duplicate JSON keys, invalid known-method parameters, unavailable methods, and unsupported batches. Keep exact extension allow rules and deny precedence. Document request inspection boundaries and add unit, forwarding, and sandbox coverage. Refs NVIDIA#2174. Signed-off-by: Shiju <shiju@nvidia.com> * test(mcp): prove authorization at the forwarding boundary Cover March batch denial in both member orders, valid and malformed controls, and audit behavior across both relay entry paths. Exercise real middleware tool rewrites with matching metadata and assert the exact upstream representation or zero forwarded bytes. Verify legacy bodyless SSE GET remains usable while GET tool bodies and unsupported DELETE cleanup are rejected. Clarify request-selected profile and middleware mutation comments without changing production behavior. Signed-off-by: Shiju <shiju@nvidia.com> * test(mcp): exercise permitted profiles through the sandbox proxy Cover March and June singleton policies and select November and July separately under one endpoint allowlist. Capture upstream tool receipts to distinguish proxy policy denial from an upstream rejection. Extend middleware rewrite coverage to June and multi-version policies, and preserve the sessionless discovery and subscription checks through the shared fixture helpers. Signed-off-by: Shiju <shiju@nvidia.com> * test(kubernetes): box the admission check future Keep the admission test future below Clippy's size limit when the workspace dependency features are unified. Signed-off-by: Shiju <shiju@nvidia.com> * test(mcp): reuse the forwarding fixture identity cache Share the binary identity cache across protocol-profile cases, matching the proxy lifecycle and avoiding repeated hashes of the test executable. Keep procfs authorization and all forwarding assertions intact. Signed-off-by: Shiju <shiju@nvidia.com> --------- Signed-off-by: Shiju <shiju@nvidia.com>
* feat(sandbox): add main restart policy Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): harden policy-driven restarts Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): address restart review feedback Signed-off-by: Drew Newberry <385+drew@users.noreply.github.com> * fix(sandbox): port restart policy to current runtime Signed-off-by: Drew Newberry <anewberry@nvidia.com> * perf(sandbox): restart promptly after terminal delivery Signed-off-by: Drew Newberry <anewberry@nvidia.com> --------- Signed-off-by: Drew Newberry <anewberry@nvidia.com> Signed-off-by: Drew Newberry <385+drew@users.noreply.github.com>
…A#3700) - Kubernetes now checks supervisor readiness by connecting to TCP port 5501 - Stop starting a supervisor process in every sandbox each second - The supervisor opens the port only while its gateway session is up - Accept IPv4 and IPv6 probes, even when net.ipv6.bindv6only is set - Keep the health socket for Docker, Podman, and debugging - Add tests and update the docs Signed-off-by: divesh <dgude@nvidia.com>
* feat(docker): support corporate proxy CA bundles Closes NVIDIA#3545 Validate and stage operator-owned proxy CA bundles for Docker supervisors, add corporate proxy E2E coverage, and document the trust contract. Signed-off-by: Philippe Martin <phmartin@redhat.com> * fix(docker): validate proxy config on startup Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com> * test(docker): use the E2E workload image for proxy tests Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com> * test(docker): generate strict corporate proxy certificates Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com> * test(docker): surface intercepted TLS fixture errors Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com> * test(docker): drain buffered TLS proxy data Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com> * test(docker): relay intercepted HTTP deterministically Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com> --------- Signed-off-by: Philippe Martin <phmartin@redhat.com> Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com> Co-authored-by: John Myers <9696606+johntmyers@users.noreply.github.com>
* fix(e2e): stop sandbox leaks from async Drop cleanup Closes NVIDIA#2922 SandboxGuard::Drop spawned a detached thread to delete the sandbox. The thread got killed with the test process before the delete finished. Switch to a blocking command in Drop, like ManagedCleanup already does. Also wrap two tests' manual cleanup in RAII guards so a panic does not leak a sandbox. Signed-off-by: Eric Curtin <eric.curtin@docker.com> * test(e2e): arm sandbox guards before create Address review: install guards with explicit names first. Signed-off-by: Eric Curtin <eric.curtin@docker.com> --------- Signed-off-by: Eric Curtin <eric.curtin@docker.com>
Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com> Co-authored-by: red-hat-konflux[bot] <126015336+red-hat-konflux[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Automated Sync from main to stable
This PR automatically syncs the
mainbranch to thestablebranch by opening a pull request frommainintostable.Sync Summary
Latest commit:
53b94040Merge remote-tracking branch 'upstream/main'Total commits to sync: 20
Source:
https://github.com/red-hat-data-services/OpenShell.git@mainTarget:
https://github.com/red-hat-data-services/OpenShell.git@stablePR head:
mainCommits to be synced
53b94040Merge remote-tracking branch 'upstream/main'74b71c0achore(deps): refresh rpm lockfiles (chore(deps): refresh rpm lockfiles opendatahub-io/openshell#63)080cfa9aMerge remote-tracking branch 'upstream/main'a6fb865dMerge remote-tracking branch 'upstream/main'cfcc3733fix(e2e): stop sandbox leaks from async Drop cleanup (fix(e2e): stop sandbox leaks from async Drop cleanup NVIDIA/OpenShell#3750)14032bddMerge remote-tracking branch 'upstream/main'0d781260Merge remote-tracking branch 'upstream/main'9cb72baafeat(docker): support corporate proxy CA bundles (feat(docker): support corporate proxy CA bundles NVIDIA/OpenShell#3549)2fe5a0e1perf(kubernetes): use a TCP readiness probe for the supervisor (perf(kubernetes): use a TCP readiness probe for the supervisor NVIDIA/OpenShell#3700)a76f1edcMerge remote-tracking branch 'upstream/main'bcf21891Merge remote-tracking branch 'upstream/main'acbac9cbfeat(sandbox): add main restart policy (feat(sandbox): add main restart policy NVIDIA/OpenShell#2798)aa71e124Merge remote-tracking branch 'upstream/main'5343080dMerge remote-tracking branch 'upstream/main'1358941bfeat(mcp): inspect requests with Tower-selected protocol profiles (feat(mcp): inspect requests with Tower-selected protocol profiles NVIDIA/OpenShell#3335)b77f5ddftest(install): support Bash 3.2 mock capture (test(install): support Bash 3.2 mock capture NVIDIA/OpenShell#3790)4b6d92a2Merge remote-tracking branch 'upstream/main'e63cfa11fix(cli): keep SSH forwards owned by spawned process (fix(cli): prevent orphaned SSH forward muxes NVIDIA/OpenShell#3759)36b0386cfeat(cli): detach sandbox sessions with Ctrl-D (feat(cli): detach sandbox sessions with Ctrl-D NVIDIA/OpenShell#3744)45e3308dfix(network): refuse protocol upgrades on JSON-RPC and MCP endpoints (fix(network): refuse protocol upgrades on JSON-RPC and MCP endpoints NVIDIA/OpenShell#3753)Merging
GitHub automerge is enabled for this pull request once required checks pass.