fix(drivers): normalize label namespace (#3609)

Signed-off-by: Evan Lezar <elezar@nvidia.com>
This commit is contained in:
Evan Lezar
2026-09-23 14:30:27 +00:00
committed by GitHub
parent 907f894ebc
commit 6cb1140c66
7 changed files with 10 additions and 10 deletions
+2 -2
View File
@@ -39,8 +39,8 @@ does not share the workload's PID, mount, or network namespaces.
## Troubleshooting
Inspect both containers with the same sandbox-ID label, distinguishing
`openshell.io/isolation-role=sandbox` from
`openshell.io/isolation-role=supervisor`.
`openshell.ai/isolation-role=sandbox` from
`openshell.ai/isolation-role=supervisor`.
- Sandbox fails its qualification probe: use its log to identify the denied
kernel/runtime primitive. Do not add capabilities or disable runtime seccomp.
@@ -21,8 +21,8 @@ use openshell_sandbox_backend::boundary_protocol::{
};
use serde::{Deserialize, Serialize};
pub const LABEL_ROLE: &str = "openshell.io/isolation-role";
pub const WORKLOAD_FILTER: &str = "openshell.io/isolation-role=sandbox";
pub const LABEL_ROLE: &str = "openshell.ai/isolation-role";
pub const WORKLOAD_FILTER: &str = "openshell.ai/isolation-role=sandbox";
pub const CHANNEL_ROOT: &str = "/.openshell/channel";
pub const BOOTSTRAP_PATH: &str = "/.openshell/channel/sandbox/bootstrap.json";
pub const RUNTIME_DESCRIPTOR_PATH: &str = "/.openshell/supervisor/runtime-descriptor.json";
@@ -618,7 +618,7 @@ mod tests {
vec![
StubResponse::new(
StatusCode::OK,
r#"{"Id":"workload","Name":"workload","State":{"Status":"running","Running":true},"Config":{"Labels":{"openshell.ai/sandbox-id":"test","openshell.io/isolation-role":"sandbox"}}}"#,
r#"{"Id":"workload","Name":"workload","State":{"Status":"running","Running":true},"Config":{"Labels":{"openshell.ai/sandbox-id":"test","openshell.ai/isolation-role":"sandbox"}}}"#,
),
StubResponse::new(StatusCode::NOT_FOUND, "missing companion"),
StubResponse::new(StatusCode::NO_CONTENT, ""),
@@ -651,7 +651,7 @@ mod tests {
vec![
StubResponse::new(
StatusCode::OK,
r#"{"Id":"workload","Name":"workload","State":{"Status":"running","Running":true},"Config":{"Labels":{"openshell.ai/sandbox-id":"test","openshell.io/isolation-role":"sandbox"}}}"#,
r#"{"Id":"workload","Name":"workload","State":{"Status":"running","Running":true},"Config":{"Labels":{"openshell.ai/sandbox-id":"test","openshell.ai/isolation-role":"sandbox"}}}"#,
),
StubResponse::new(
StatusCode::OK,
+1 -1
View File
@@ -18,7 +18,7 @@ use crate::runtime::VmBackend;
/// gateway), so a guest cannot self-activate an extension. This contract
/// lives with the lifecycle framework that consumes it rather than in the
/// shared settings registry.
pub const SANDBOX_EXTENSION_LABEL_PREFIX: &str = "openshell.io/extension.";
pub const SANDBOX_EXTENSION_LABEL_PREFIX: &str = "openshell.ai/extension.";
#[derive(Debug, Clone, PartialEq, Eq)]
pub enum LaunchAbortReason {
+1 -1
View File
@@ -55,7 +55,7 @@ fn sandbox_container_running(sandbox_name: &str) -> Result<bool, String> {
"--filter",
MANAGED_BY_LABEL_FILTER,
"--filter",
"label=openshell.io/isolation-role=sandbox",
"label=openshell.ai/isolation-role=sandbox",
"--filter",
])
.arg(sandbox_name_filter)
+1 -1
View File
@@ -137,7 +137,7 @@ fn container_id_for_role(
role: &str,
) -> Result<String, String> {
let name_filter = format!("label=openshell.ai/sandbox-name={sandbox_name}");
let role_filter = format!("label=openshell.io/isolation-role={role}");
let role_filter = format!("label=openshell.ai/isolation-role={role}");
let stdout = run_engine(
engine,
&[
+1 -1
View File
@@ -196,7 +196,7 @@ cleanup() {
local workload_ids workload_id
workload_ids="$(podman_cmd ps -aq --filter "label=openshell.managed=true" \
--filter "label=openshell.ai/sandbox-id=${sandbox_id}" \
--filter "label=openshell.io/isolation-role=sandbox" 2>/dev/null || true)"
--filter "label=openshell.ai/isolation-role=sandbox" 2>/dev/null || true)"
for workload_id in ${workload_ids}; do
podman_cmd rm -f "${workload_id}" >/dev/null 2>&1 || true
done