Commit Graph
1506 Commits
Author SHA1 Message Date
Drew Newberry 2cabec7e20 test(podman): align credential host alias assertion with isolation
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 06:17:30 -07:00
Drew Newberry 456cd7a96e fix(sqlite): wait through concurrent gateway writes
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 05:16:12 -07:00
Drew Newberry 56a155d24a test(podman): route support fixtures through pinned host alias
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 05:06:53 -07:00
Drew Newberry 6d58414138 fix(docker): retry transient runtime volume removal
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 04:48:48 -07:00
Drew Newberry d2e8e9e96c fix(podman): restore policy DNS in isolated workloads
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 04:39:26 -07:00
Drew Newberry 48213bdf6e fix(cli): retry sync during supervisor reconnect
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 03:50:41 -07:00
Drew Newberry e7c88cbc8f fix(e2e): avoid gateway health port collisions
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 03:40:43 -07:00
Drew Newberry e0c7bde7d5 fix(e2e): serialize Kubernetes HA deployment tests
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 03:26:02 -07:00
Drew Newberry 3e197a78ad fix(e2e): use non-root workload fixture for Podman
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 03:22:04 -07:00
Drew Newberry 9c7863907b fix(proxy): ignore exited socket owners and isolate middleware tests
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 03:10:07 -07:00
Drew Newberry e391bee5cd test(policy): expect advisor overlay for new binary
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 02:38:21 -07:00
Drew Newberry 2a9ad0383a test(kubernetes): wait for HA replica readiness before exec
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 02:29:20 -07:00
Drew Newberry 75b364556c fix(e2e): use gateway sandbox image in TypeScript exec test
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 02:23:46 -07:00
Drew Newberry f152a96f93 fix(policy): report transparent denials to proposal aggregator
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 02:19:34 -07:00
Drew Newberry 40b10432f9 fix(e2e): pin managed Podman runtime image
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 01:59:26 -07:00
Drew Newberry a1f8e5839c test(go): isolate gateway listing from host config
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 01:49:16 -07:00
Drew Newberry 5024eceac3 chore(stack): include concurrent relay fix
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 01:38:14 -07:00
Drew Newberry af0f29a670 fix(server): retry create binding after HA status race
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 01:33:34 -07:00
Drew Newberry 5c224d6470 ci(e2e): isolate concurrent integration rounds
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 01:21:40 -07:00
Drew Newberry 0fbc69a8e9 ci(e2e): cover additional Linux stability suites
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 01:17:13 -07:00
Evan Lezar 44fa425c43 fix(server): avoid duplicate relay opens on reconnect
Signed-off-by: Evan Lezar <elezar@nvidia.com>
2026-09-23 10:13:44 +02:00
Drew Newberry c98b3c4aac ci(e2e): isolate parallel stability runs
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 01:04:29 -07:00
Drew Newberry f59b4afe8e ci(e2e): enable Linux stability campaign dispatch
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 00:57:10 -07:00
Drew Newberry 2f488649be fix(ci): recover relay opens and isolate VM proxy ports
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 00:16:19 -07:00
Divesh Chowdary d02ebe2c4b fix(kubernetes): prevent false sandbox suspension (#3567)
Signed-off-by: divesh <dgude@nvidia.com>
2026-09-22 21:57:33 -07:00
Drew Newberry c8b20bf0a2 ci(windows): seed caches on windows branch (#3576)
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-22 21:12:05 -07:00
Drew Newberry b671171091 fix(sandbox): qualify task memory against workload child (#3574)
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 03:36:56 +00:00
Evan Lezar df88bedb31 fix(podman): support rootless user namespace configurations (#3527)
* test(podman): cover user namespace configurations

Signed-off-by: Evan Lezar <elezar@nvidia.com>

* fix(podman): support keep-id runtime groups

Signed-off-by: Evan Lezar <elezar@nvidia.com>

refactor(podman): generalize keep-id group handling

Signed-off-by: Evan Lezar <elezar@nvidia.com>

* ci(podman): run driver integration tests

Signed-off-by: Evan Lezar <elezar@nvidia.com>

---------

Signed-off-by: Evan Lezar <elezar@nvidia.com>
2026-09-23 00:30:29 +00:00
Drew Newberry 84960e70a3 fix(kubernetes): scope resource admission RBAC (#3571)
* fix(kubernetes): scope resource admission RBAC

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(helm): gate PVC admission reads

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

---------

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-23 00:02:10 +00:00
Drew Newberry feff897968 fix(sandbox): await SFTP writes before acknowledging (#3568)
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-22 23:04:15 +00:00
Evan Lezar 49df4d7ca7 fix(server): drain supervisor ownership cleanup on shutdown (#3547)
Closes #3546

Signed-off-by: Evan Lezar <elezar@nvidia.com>
2026-09-22 22:29:54 +00:00
Mrunal Patel bdffa102c3 feat(api): add durable exec launch admission (#3324)
* feat(api): add durable exec launch admission

Fence duplicate exec launches with keyed durable admission and producer-owned terminal completion. Keep uncertain launches unresolved and never replay output or interactive input.

Part of #3051 (phase 4a).

Signed-off-by: Mrunal Patel <mrunalp@gmail.com>

* fix(api): fence exec identity across authorization lookups

Signed-off-by: Mrunal Patel <mrunalp@gmail.com>

---------

Signed-off-by: Mrunal Patel <mrunalp@gmail.com>
2026-09-22 21:52:19 +00:00
Drew Newberry 1e34e8c576 fix(drivers): require admission labels for external resources (#3538)
* fix(drivers): require admission labels for external resources

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(drivers): address resource admission review findings

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(core): reserve driver-owned admission labels

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(core): clarify workspace admission label

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(drivers): clarify resource admission failures

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* test(e2e): configure resource admission fixtures

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(kubernetes): retry forbidden admission lookups

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(e2e): preserve external driver admission defaults

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

---------

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-22 21:22:30 +00:00
krishicks f8002d19ad fix(e2e): repair the credential driver test (#3565)
The credential driver e2e has not passed end to end, and the disabled
kubernetes-credential-drivers CI lane hid three problems.

The test broke when the JSON format of provider list changed.
Continuation-token pagination (#3249) changed
provider list --output json from a bare array of providers to an object
with next_page_token and a providers array. The test still parsed the
output as an array, so it failed before checking either storage
backend. Read the providers array from the new object instead.

Its sandbox name was about 58 characters, but sandbox names are
DNS-routable and limited to 19, so sandbox creation was rejected. Build
a short unique name instead.

The sandbox guard deletes its sandbox from a detached thread on drop, so
the test deleted the provider while the sandbox still existed. The
gateway rejects deleting a provider that is attached to a sandbox, the
test ignored that error, and the credential Secret remained. Delete the
sandbox explicitly before returning from the sandbox check.

Signed-off-by: Kris Hicks <khicks@nvidia.com>
v0.1.0-pre.7
2026-09-22 20:55:04 +00:00
Akram Ben Aissi 293fab75d4 fix(sandbox): support kernels < 5.19 via seccomp WAIT_KILLABLE_RECV fallback (#3420)
* fix(sandbox): fall back to plain seccomp listener when WAIT_KILLABLE_RECV is unavailable

SECCOMP_FILTER_FLAG_WAIT_KILLABLE_RECV was added in Linux 5.19. On older
kernels (for example RHEL 9.x / 5.14 nodes such as RHCOS on OpenShift) the
flag is rejected with EINVAL, which made the capability-free sandbox fail to
start during the notification probe with "notification launcher disappeared".

Install the notification listener with WAIT_KILLABLE_RECV when the kernel
supports it and fall back to a plain NEW_LISTENER on EINVAL. The fallback
listener records wait_killable_recv = false: its notification receive is
uninterruptible, but the sandbox is otherwise fully functional.

Signed-off-by: Akram <akram.benaissi@gmail.com>

* fix(sandbox): address review — legacy read-only listener mode + cancellation invariant

Follow-up to the PR review (GATOR-de00bfcc-01 / mrunalp): make the < 5.19
fallback cancellation-safe instead of racing broker writes.

- Record an explicit ListenerMode (Killable vs LegacyReadOnly); add
  writes_disabled()/mode() and emit the selected mode in qualification output
  (seccomp_listener_mode).
- Centralize task-memory output writes behind NotificationListener::
  write_task_output; in LegacyReadOnly mode getpeername, accept/accept4 with a
  non-null address, and sendmmsg length write-backs fail closed with EOPNOTSUPP.
  accept with a null address, socket/connect/bind/listen/sendto/sendmsg keep
  working (copied inputs, scalar responses, atomic ADDFD_SEND).
- Enforce the launch invariant `cancellation || task_memory_writes_disabled` in
  SandboxConfirmEvidence::validate() rather than dropping cancellation
  unconditionally; add task_memory_writes_disabled to SeccompEvidence.
- Add per-path fail-closed tests (write_task_output, write_socket_addr, a real
  plain listener installed on a modern kernel) and confirmation-invariant tests.
- Correct the flag-semantics comments and document both modes plus the reduced
  legacy syscall compatibility in architecture/sandbox.md.

Signed-off-by: Akram <akram.benaissi@gmail.com>

* docs: document legacy read-only sandbox mode on kernels before 5.19

Kernels without SECCOMP_FILTER_FLAG_WAIT_KILLABLE_RECV (< 5.19, e.g. RHEL 9.x /
RHCOS 5.14) run the sandbox in a legacy read-only cancellation mode where the
broker fails closed with EOPNOTSUPP on the mediated operations that write results
back into workload memory (getpeername, accept/accept4 with a non-null address,
sendmmsg length write-backs). Document this observable behavior and its syscall
limitations in the public Fern docs: the support-matrix kernel requirements and
the OpenShift runtime guidance.

Signed-off-by: Akram <akram.benaissi@gmail.com>

* style(sandbox): satisfy rustfmt and clippy doc_markdown

Match the pinned rustfmt (Rust 1.95.0) line-wrapping for the write_task_output
call, and backtick `legacy_read_only` in the qualification-report doc comment
so clippy::doc_markdown (-D warnings) passes.

Signed-off-by: Akram <akram.benaissi@gmail.com>

* fix(sandbox): migrate task_memory_writes_disabled into backend protocol

Add the `task_memory_writes_disabled` field to `SeccompEvidence` in the
backend protocol contract and relax the validation from requiring
`cancellation` to accepting `cancellation || task_memory_writes_disabled`.

This completes the rebase migration missed by the isolation-interface
refactor: the sandbox reports this field but the backend struct lacked
it, and the validator rejected every pre-5.19 legacy listener.

Signed-off-by: Akram <akram.benaissi@gmail.com>

---------

Signed-off-by: Akram <akram.benaissi@gmail.com>
2026-09-22 20:37:19 +00:00
Piotr Mlocek 5a81d2b37b fix(network): bound chunked relay memory (#3537)
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
2026-09-22 20:03:52 +00:00
Artem LytvynandJohn Myers 470a34635d fix(api): make WatchSandbox loss-aware and resumable (#3209)
* fix(api): emit warning on WatchSandbox broadcast lag instead of terminating

Broadcast lag on the status, log, and platform receivers was converted to a RESOURCE_EXHAUSTED status that terminated the whole watch stream. Lag is recoverable: the receiver resumes at the oldest surviving message. Emit a SandboxStreamWarning and continue streaming instead; keep terminating on Closed. Add helpers and unit tests covering the warning payload and receiver recovery after lag.

Partially addresses #3055 (cursor/resume follow up separately).

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* refactor(server): group per-sandbox log bus state and stamp sequence numbers

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* feat(proto): add resume cursor fields to sandbox watch API

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* feat(server): stamp watch cursors from a shared per-sandbox sequence

Allocate cursors from a single SeqAllocator shared by the log and
platform event buses, so a sandbox's merged watch stream carries
unique, strictly increasing cursors. A single resume_after_cursor can
then unambiguously locate a client's position across both sources.

Rewrite both publish paths to allocate the sequence, stamp
event.cursor, send, and append to the tail under one lock. This
removes the previous get_mut().expect() TOCTOU race where a concurrent
remove() between the two lock sections could panic.

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* feat(server): serve WatchSandbox resume from cursor with gap detection

Add tail_after() to the log and platform event buses, returning every
buffered event newer than a client's resume cursor. Each PerSandbox now
tracks last_trimmed_seq (the highest seq it has evicted) so a resume is
reported as an unrecoverable ResumeGap only when this bus dropped an
event the client still needs.

Judging gaps by evictions, not by the tail's oldest seq, is required
under the shared cursor space: each bus's tail is non-contiguous in the
global sequence because the other bus owns the missing seqs, so
comparing against tail.front() would flag false gaps.

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* feat(server): resume WatchSandbox from cursor across log and platform buses

Wire resume_after_cursor into the watch producer. On a non-zero cursor,
replay events strictly after it from both the log and platform buses,
merge by shared cursor, and emit in order before entering the live loop.
A trimmed range on either bus is an unrecoverable gap and terminates the
stream with OUT_OF_RANGE carrying the requested and earliest-available
cursors, distinct from recoverable lag which warns and continues.

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* test(server): cover WatchSandbox cursor resume paths

Add handler-level tests for the resumable watch stream: replay strictly
after the client cursor, merge log and platform events in shared-cursor
order, suppress duplicates when resuming at the latest cursor, and
terminate with OUT_OF_RANGE when the requested cursor has been trimmed.

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* docs(api): document WatchSandbox loss-awareness and resume

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* fix(server): deliver watch events once and harden cursor teardown

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* feat(sdk): add loss-aware resumable watch_logs to Rust SDK client

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* fix(server): keep watch cursors monotonic across teardown and restart

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* fix(server): merge live watch sources by cursor before emission

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* fix(api): bind watch cursors to a cursor space and merge tail sources

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* fix(server): revalidate the watch cursor space after collecting replay

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* test(server): update the public RPC schema fingerprint for the string cursor

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* fix(server): hold watch events above the publication watermark and emit the watch lag warning before its batch

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* test(server): synchronize the watch live-order test with the end of initialization

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* fix(sdk): use canonical sandbox name in watch_logs

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* test(sdk): guard canonical-name addressing in watch_logs

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* fix(server): fix public rpc schema

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>

* fix(api): reconcile watch resume rebase

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* fix(server): bound interactive relay cleanup

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

---------

Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
Co-authored-by: John Myers <9696606+johntmyers@users.noreply.github.com>
2026-09-22 19:45:55 +00:00
Jim Meyer 88357775ad docs(windows): align Z3 pin with z3-sys 0.13 (#3561)
z3-sys 0.13 generates bindings for the Z3 5.x series and resolves
GH_RELEASE_VERSION to 5.1.0 for the prebuilt-release path. The Windows
wrapper still pinned Z3_SYS_Z3_VERSION to 4.16.0, so a prebuilt Windows
build would fetch an archive that does not match the generated bindings.

Move the wrapper pin to 5.1.0 and update the contributor, architecture,
and skill references that still named 4.16.0.

Signed-off-by: Jim Meyer <jimeyer@nvidia.com>
2026-09-22 19:29:24 +00:00
Piotr Mlocek e367d47394 fix(sandbox): reclaim socket descriptors before exhaustion (#3532)
* fix(sandbox): reclaim socket descriptors before exhaustion

Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>

* fix(sandbox): separate socket and descriptor limits

Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>

* fix(sandbox): account for existing broker descriptors

Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>

---------

Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
2026-09-22 19:15:51 +00:00
Piotr Mlocek 4b1c09de28 fix(network): preserve chunked request boundaries (#3530)
* fix(network): preserve chunked request boundaries

Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>

* fix(network): bound chunk framing amplification

Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>

* fix(supervisor): box sandbox runtime future

Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>

* fix(network): buffer chunked relay read-ahead

Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>

* fix(network): flush completed chunks promptly

Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>

---------

Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com>
2026-09-22 19:04:59 +00:00
Yuedong Wu 718dba3430 fix(policy)!: reject removed tls endpoint values (#3414)
Signed-off-by: Yuedong Wu <dwcn22@outlook.com>
2026-09-22 17:58:19 +00:00
Philippe Martin 35e0a68e4a feat(kubernetes): support corporate proxy CA bundle (#3447)
* feat(kubernetes): support corporate proxy CA bundle

The Kubernetes driver had no way to supply a CA bundle for the corporate
egress proxy, so an `https://` proxy with a private CA, or a TLS-intercepting
proxy, could not be used. Podman and VM already expose `proxy_ca_bundle`.

Add `proxy_ca_bundle` to `[openshell.drivers.kubernetes]` as a path the
gateway Pod reads. The gateway stages the PEM into the existing
per-generation supervisor bootstrap Secret and passes
`--upstream-proxy-ca-bundle` on the supervisor argv. That Secret is already
immutable, owner-referenced and garbage-collected, and its volume mounts
every key at /.openshell/supervisor with no items filter, so this needs no
new object kind, volume, mount, or RBAC verb, and works in shared, managed
and operator workspace modes.

The bundle is deliberately read from the gateway's filesystem rather than
referenced as an object in the sandbox namespace. It becomes a trust anchor
for every upstream the sandbox reaches, so it must stay in the gateway's
trust domain; the immutable staging Secret also keeps the anchor from
changing underneath a running sandbox.

Bound the staged bundle at 256 KiB. The shared reader's limit is exactly the
apiserver's own Secret limit and the bootstrap Secret carries four other
keys, so a bundle between the two would pass gateway startup and then fail
every sandbox create with an opaque `data: Too long`.

Delegate the URL, no_proxy, connect_by_hostname and ca_bundle rules to the
shared validate_upstream_proxy_settings, keeping the Secret-specific
credential block local: this driver accepts an explicit
`proxy_auth_allow_insecure = false` without credentials, which the shared
rules reject. This also fixes the acknowledgement being demanded for an
`https://` proxy, where the credential travels inside the verified TLS
session. Add auth_setting_label so the inline-credential diagnostic names
the Secret keys instead of proxy_auth_file, which this driver rejects as an
unknown key.

Document that the bundle should carry only the CA that signs the proxy's
certificate, or that an intercepting proxy re-signs upstream certificates
with. Public roots already reach the sandbox through the supervisor image and
its TLS stack, and the bundle is concatenated with that system store into a
single boundary control frame, so a full merged trust bundle spends the frame
budget on duplicated roots. The frame, not the apiserver Secret limit, is the
tighter of the two ceilings in practice; raising the staging bound requires
checking it.

Closes #3443

Signed-off-by: Philippe Martin <phmartin@redhat.com>

* fix(helm): quote proxy CA ConfigMap references

Signed-off-by: Philippe Martin <phmartin@redhat.com>

---------

Signed-off-by: Philippe Martin <phmartin@redhat.com>
2026-09-22 17:57:40 +00:00
Evan Lezar 3107ff1f82 ci(security): stage release finding enforcement (#3552)
Signed-off-by: Evan Lezar <elezar@nvidia.com>
2026-09-22 17:21:23 +00:00
krishicks f8b1fd8b57 fix(supervisor): restore OCSF schema downgrade (#3554)
The RFC-0012 architecture migration preserved sandbox OCSF JSON enablement but
introduced a regression: ocsf_schema_version was no longer honored.

This fixes the regression so that schema downgrades occur again.

Signed-off-by: Kris Hicks <khicks@nvidia.com>
2026-09-22 16:42:15 +00:00
Varsha 7139df8ca5 fix(exec): preserve output after stdin EOF and verify stream completion (#3359)
* fix(exec): preserve output after stdin EOF and verify stream completion

Signed-off-by: Varsha Prasad Narsing <varshaprasad96@gmail.com>

* test(exec): cover fair duplex progress and live SDK completion

Signed-off-by: Varsha Prasad Narsing <varshaprasad96@gmail.com>

* test(sdk): compare large exec buffers with native equality

Signed-off-by: Varsha Prasad Narsing <varshaprasad96@gmail.com>

* test(exec): use workspace-scoped sandbox name in EOF regression

Signed-off-by: Varsha Prasad Narsing <varshaprasad96@gmail.com>

---------

Signed-off-by: Varsha Prasad Narsing <varshaprasad96@gmail.com>
2026-09-22 14:11:06 +00:00
Artem Lytvyn ca4573588d fix(driver-vm): resolve lifecycle requests on sandbox_id alone (#3305)
Signed-off-by: Artem Lytvyn <alytvyn@redhat.com>
2026-09-22 14:10:10 +00:00
50230616d5 refactor(runtime): retire Community image dependencies (#3386)
* feat(sandbox): default to official Alpine sandbox image

default_sandbox_image() now returns docker.io/library/alpine:3.22, a generic
version-qualified official image, so a fresh install no longer depends on the
community sandbox image catalog. All compute drivers (docker, podman,
kubernetes, vm) inherit this fallback.

Part of #3116.

Signed-off-by: Akram
Signed-off-by: Akram <akram.benaissi@gmail.com>

* feat(deploy): default deployment configs to the official Alpine sandbox image

Update the shared gateway default_image, Helm chart values, the standalone
Kubernetes manifest, and the dev gateway task scripts to use
docker.io/library/alpine:3.22 instead of the community base image, consistent
with default_sandbox_image(). GPU e2e image-build base is left unchanged (CUDA
needs a glibc base).

Part of #3116.

Signed-off-by: Akram
Signed-off-by: Akram <akram.benaissi@gmail.com>

* feat(driver): default to numeric non-root identity for USER-less images

With the default sandbox image now Alpine, images that declare no OCI USER
must start instead of being rejected. When the image declares no USER and
the policy requests none, the Podman and Docker drivers now supply a numeric
non-root identity (DEFAULT_SANDBOX_UID/GID = 1000) instead of rejecting,
matching the numeric-identity behavior of the Kubernetes and VM drivers. The
supervisor's resolved-identity path runs the sandbox as a synthesized
non-root account without the account existing in the image. Images that
declare a USER keep the OCI resolution path unchanged.

Part of #3116.

Signed-off-by: Akram <akram.benaissi@gmail.com>
Signed-off-by: Evan Lezar <elezar@nvidia.com>

* test(conformance): use Alpine workload image

Signed-off-by: Evan Lezar <elezar@nvidia.com>

* refactor(policy): drop community image /app path from default policy

The restrictive default policy granted read-only access to /app, a directory
that only existed in the community base image. A generic Alpine default has no
/app, so remove it. Landlock best-effort already ignores absent paths; this
just stops advertising a community-specific layout in the default.

Part of #3116.

Signed-off-by: Akram
Signed-off-by: Akram <akram.benaissi@gmail.com>

* docs(config): document Alpine default images

Signed-off-by: Evan Lezar <elezar@nvidia.com>

* fix(podman): report early sandbox termination

Signed-off-by: Evan Lezar <elezar@nvidia.com>

* fix(podman): initialize rootless workspace ownership

Signed-off-by: Evan Lezar <elezar@nvidia.com>

* fix(sandbox): qualify NVIDIA Ubuntu default

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(podman): initialize rootful default workspace

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* feat(sftp): add native sandbox adapter

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(sftp): gate runtime helper support to Linux

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(sftp): support standard OpenSSH file operations

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(sftp): harden rename and special file handling

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* refactor(runtime): remove community image dependencies

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* test(e2e): build provider readiness tool fixture

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(e2e): use a dedicated Noble fixture for Docker tests

Signed-off-by: Evan Lezar <elezar@nvidia.com>

---------

Signed-off-by: Akram
Signed-off-by: Akram <akram.benaissi@gmail.com>
Signed-off-by: Evan Lezar <elezar@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Co-authored-by: Evan Lezar <elezar@nvidia.com>
Co-authored-by: Drew Newberry <anewberry@nvidia.com>
2026-09-22 14:43:51 +02:00
Simon ScattonandEvan Lezar 24706c175b ci(rust): parallelize branch checks (#3462)
* ci(rust): parallelize branch checks

Signed-off-by: Simon Scatton <sscatton@nvidia.com>

* ci(rust): acknowledge trusted sccache environment

Signed-off-by: Simon Scatton <sscatton@nvidia.com>

* ci(rust): remove ineffective sccache backend

Signed-off-by: Simon Scatton <sscatton@nvidia.com>

* ci(rust): retain dependency boundary checks

Signed-off-by: Evan Lezar <elezar@nvidia.com>

---------

Signed-off-by: Simon Scatton <sscatton@nvidia.com>
Signed-off-by: Evan Lezar <elezar@nvidia.com>
Co-authored-by: Evan Lezar <elezar@nvidia.com>
v0.1.0-pre.6
2026-09-22 08:35:42 +00:00
Evan Lezar 551a81c729 test(tmachine): add interactive shell testsuite (#3522)
* test(tmachine): add interactive shell testsuite

Signed-off-by: Evan Lezar <elezar@nvidia.com>

* test(tmachine): add no-install profile

Signed-off-by: Evan Lezar <elezar@nvidia.com>

* docs(tmachine): document interactive shell usage

Signed-off-by: Evan Lezar <elezar@nvidia.com>

---------

Signed-off-by: Evan Lezar <elezar@nvidia.com>
2026-09-22 07:01:56 +00:00
John T. MyersandDrew Newberry c8a4ff5f19 fix(kubernetes): bind bootstrap to runtime identity (#3531)
* fix(kubernetes): bind bootstrap to runtime identity

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* fix(compute): compensate runtime binding failures

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* fix(compute): clean up backend on store failure

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* fix(compute): merge runtime binding after start

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* fix(auth): bind restarted sandbox sessions

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* refactor(compute): fold runtime binding into authentication

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

---------

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Co-authored-by: Drew Newberry <anewberry@nvidia.com>
2026-09-22 05:08:37 +00:00