mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-02 07:34:45 +08:00
test(policy): expect advisor overlay for new binary
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
This commit is contained in:
@@ -297,9 +297,10 @@ through the proposal loop instead of treating the denial as terminal.
|
||||
2. **Build and validate the candidate.** The gateway first canonicalizes a
|
||||
mechanistic proposal against the live effective policy. If an endpoint is
|
||||
already governed by an inspected or provider-owned contract, the candidate
|
||||
preserves that contract and adds only the proposed sandbox binary. Provider
|
||||
rules are immutable inputs; the sandbox contribution is stored as an
|
||||
overlay. The gateway then performs the same merge, policy validation,
|
||||
preserves that contract and adds only the proposed sandbox binary. A new
|
||||
binary gets a separate overlay rule, leaving the existing sandbox or
|
||||
provider rule intact. The gateway then performs the same merge, policy
|
||||
validation,
|
||||
provider composition, credential preflight, and prover evaluation that the
|
||||
candidate would encounter when applied. Each chunk stores the resulting
|
||||
effective candidate, its hashes, any application error, and a review token
|
||||
|
||||
@@ -72,7 +72,7 @@ done
|
||||
|
||||
printf '%s\n' "$RULE_OUTPUT"
|
||||
grep -q "Status: approved" <<<"$RULE_OUTPUT"
|
||||
grep -q "Rule: cargo_registry" <<<"$RULE_OUTPUT"
|
||||
grep -q "Rule: allow_index_crates_io_443" <<<"$RULE_OUTPUT"
|
||||
grep -q "Prover: prover: no new findings" <<<"$RULE_OUTPUT"
|
||||
if grep -q "Application:" <<<"$RULE_OUTPUT"; then
|
||||
echo "auto-approved chunk unexpectedly retained an application error" >&2
|
||||
@@ -80,6 +80,8 @@ if grep -q "Application:" <<<"$RULE_OUTPUT"; then
|
||||
fi
|
||||
|
||||
POLICY_OUTPUT="$($OPENSHELL_BIN policy get "$SANDBOX" --full 2>&1 | strip_ansi)"
|
||||
grep -q '^ allow_index_crates_io_443:' <<<"$POLICY_OUTPUT"
|
||||
grep -q '^ cargo_registry:' <<<"$POLICY_OUTPUT"
|
||||
grep -q "protocol: rest" <<<"$POLICY_OUTPUT"
|
||||
grep -q "access: read-only" <<<"$POLICY_OUTPUT"
|
||||
grep -q "/usr/bin/cargo" <<<"$POLICY_OUTPUT"
|
||||
|
||||
Reference in New Issue
Block a user