Prekshi Vyas
0b8f3821e2
fix(network): normalize Windows binary paths (NVBug 6782969) ( #3482 )
...
* fix(network): normalize Windows policy binary paths
Match Windows executable identities using a stable case-insensitive, separator-normalized representation across policy data, L4 input, and L7 relay evaluation. Preserve exact matching on other platforms and keep the original path for hashing and filesystem access.
NVBug 6782969
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com >
* fix(network): harden Windows binary matching
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com >
* fix(ci): scope Windows relay test imports
* fix(network): harden Windows binary path matching
---------
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com >
2026-09-22 13:47:25 -07:00
Drew Newberry
49b4f0eb7f
feat(mxc): add UI policy, credentials, relay lifecycle, and proxy auth
...
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
2026-09-17 12:06:06 -07:00
Shiju
8751e35e28
fix(supervisor-network): reject malformed OPA policy containers ( #3337 )
...
Validate raw OPA object and array containers before normalization and
access-preset expansion can skip malformed values. Return one fixed
structural error without embedding authored policy data.
Preserve versionless and runtime-only OPA data and existing semantic
validation. Cover initial string/file loading, middleware callback order,
valid deny-rule enforcement, and rejected reload state and generation.
Document the loader contract and its engine-local rejection behavior.
Signed-off-by: Shiju <shiju@nvidia.com >
2026-09-15 20:00:51 +00:00
John T. Myers and John Myers
226a83b323
fix(supervisor): classify credential placeholders in request bodies ( #3246 )
...
* fix(supervisor): classify credential placeholders in request bodies
Closes #2904
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
* fix(supervisor): preserve same-provider placeholders in request bodies
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
---------
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
Co-authored-by: John Myers <johntmyers@users.noreply.github.com >
2026-09-10 23:10:01 +00:00
Shiju
ea8eda6d5b
feat(supervisor): enforce MCP request protocol versions ( #3241 )
...
* feat(supervisor): enforce MCP request protocol versions
Signed-off-by: Shiju <shiju@nvidia.com >
* fix(supervisor): enforce MCP versions across HTTP forwarding
Apply shared request-version guards before authorization and after forward-request rewriting. Require version metadata to survive HTTP header cleanup, and cover valid initialization and selected-revision forwarding through middleware.
Signed-off-by: Shiju <shiju@nvidia.com >
---------
Signed-off-by: Shiju <shiju@nvidia.com >
2026-09-09 20:28:55 +00:00
Artem Lytvyn
7f4bd49a47
fix(policy): harden landlock.compatibility validation ( #2541 )
...
* fix(policy): reject invalid landlock.compatibility values at parse time
Signed-off-by: Artem Lytvyn <alytvyn@redhat.com >
* fix(policy): abort sandbox startup when hard_requirement has no filesystem paths
Signed-off-by: Artem Lytvyn <alytvyn@redhat.com >
* fix(policy): validate landlock.compatibility at gateway and fix zero-path logging
Signed-off-by: Artem Lytvyn <alytvyn@redhat.com >
* fix(policy): reject invalid landlock.compatibility on serialization
Signed-off-by: Artem Lytvyn <alytvyn@redhat.com >
* fix: fixed linting error
Signed-off-by: Artem Lytvyn <alytvyn@redhat.com >
---------
Signed-off-by: Artem Lytvyn <alytvyn@redhat.com >
2026-09-09 18:22:55 +00:00
Shiju
592df3e014
feat(policy): preserve exact MCP revision allowlists ( #3027 )
...
* feat(mcp): add version-aware wire profile metadata
Signed-off-by: Shiju <shiju@nvidia.com >
* feat(policy): canonicalize MCP version allowlists
Signed-off-by: Shiju <shiju@nvidia.com >
* fix(policy): align MCP policy tests with current main
Signed-off-by: Shiju <shiju@nvidia.com >
* fix(policy): canonicalize supervisor protobuf ingress
Materialize defaultable MCP revisions before ambiguity checks, OPA construction, and sidecar delivery. Reject invalid sidecar policies with bounded errors.
Signed-off-by: Shiju <shiju@nvidia.com >
---------
Signed-off-by: Shiju <shiju@nvidia.com >
2026-09-05 04:24:49 +00:00
John T. Myers and John Myers
fc0929749c
fix(policy): harden advisor transport proposals ( #3136 )
...
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
Co-authored-by: John Myers <johntmyers@users.noreply.github.com >
2026-09-04 19:38:00 +00:00
John T. Myers and John Myers
07df822090
feat(providers): make profiles authoritative ( #2962 )
...
* feat(providers): make profiles authoritative
Closes #1988
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
* docs(providers): move profiles into provider navigation
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
* docs(providers): clarify provider attachment lifecycle
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
* fix(tui): scroll provider profile picker
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
* fix(providers): honor profile credential semantics
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
* fix(providers): prefer exact profile IDs
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
* fix(providers): harden authoritative profile adoption
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
* test(oidc): align provider fixtures with profiles
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
* fix(providers): preserve authoritative profile lifecycle
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
---------
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
Co-authored-by: John Myers <johntmyers@users.noreply.github.com >
2026-09-01 19:22:07 +00:00
John T. Myers
b2ea81822b
feat(network): enable Docker and Podman policy DNS and transparent TCP ( #2723 )
...
* feat(network): enable Docker transparent TCP egress
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(e2e): cover Docker transparent TCP egress
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* feat(network): correlate transparent TCP audit events
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* docs(examples): add transparent TCP Redis demo
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* docs(examples): demonstrate blocked TCP connections
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* docs(examples): focus Redis demo audit output
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(network): close transparent TCP policy bypasses
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(sandbox): reject unsupported TCP policy reloads
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(ci): satisfy Linux transparent TCP lints
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* feat(podman): enable transparent TCP egress
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(podman): permit policy DNS port binding
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(e2e): use qualified transparent TCP hostname
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(podman): preserve exact policy DNS names
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(podman): route policy DNS over TCP
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(dns): serve multiple TCP queries per connection
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* docs(network): explain native DNS and TCP egress
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(sandbox): reconcile runtime reload with upstream
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(network): harden transparent DNS capture
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(podman): preserve resolver behavior for native tcp
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* docs(network): clarify native tcp runtime constraints
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(network): remove unused transparent tcp pin
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(network): admit redirected transparent tcp
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(network): restore podman transparent networking
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(podman): permit alpine busybox binaries
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(podman): use portable alpine keepalive
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(podman): build musl networking fixture
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(podman): isolate musl DNS probe
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(podman): keep privileged port capability dropped
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(network): preserve transparent TCP port 53
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(network): report synthetic pool pressure by family
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(podman): bind tcp fixtures before readiness
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(podman): grant fixture low-port bind
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
---------
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
2026-08-20 19:26:53 +00:00
John T. Myers
4d7f402ce2
feat(policy): establish direct TCP egress foundation ( #2711 )
...
* feat(policy): accept explicit tcp endpoint protocol
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* refactor(network): snapshot authoritative egress decisions
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* docs(policy): document explicit tcp protocol
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* docs(policy): defer transparent TCP release guidance
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* chore(go): regenerate sandbox protobuf bindings
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(network): complete tcp egress foundation
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* docs(policy): document explicit tcp contract
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(network): fail closed on authorization errors
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(podman): fence delayed exit events before restart
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(policy): validate network endpoint destinations
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(providers): opt in tcp credential fixture
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(policy): require dns host for transparent tcp
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
---------
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
2026-08-20 16:43:09 +00:00
Drew Newberry
998db04780
feat(policy): allow non-root sandbox identities ( #2785 )
...
Signed-off-by: Drew Newberry <anewberry@nvidia.com >
2026-08-19 21:20:14 +00:00
alangou
0d708d6d51
fix(policy): gate uninspected credentialed endpoints ( #2493 )
...
* fix(policy): gate uninspected credentialed endpoints
Signed-off-by: Adrien Langou <alangou@nvidia.com >
* refactor(cli): extract allowed-ip option parsing
Signed-off-by: Adrien Langou <alangou@nvidia.com >
* fix(policy): gate endpointless credential bindings
Signed-off-by: Adrien Langou <alangou@nvidia.com >
---------
Signed-off-by: Adrien Langou <alangou@nvidia.com >
2026-08-19 15:18:02 +00:00
Piotr Mlocek
44bf0df485
feat(middleware): inspect WebSocket text messages ( #2477 )
...
* feat(middleware): inspect websocket text messages
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(middleware): address websocket review feedback
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(network): bound websocket message assembly
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(network): harden websocket upgrade lifecycle
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* refactor(middleware): unify in-process and remote transports
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* feat(middleware): support regex websocket redaction
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(middleware): bound persistent streaming sessions
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(middleware): accept websocket sequence gaps
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* refactor(middleware): refine websocket introspection contract
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(middleware): clarify websocket preflight lifecycle
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(middleware): clarify websocket coverage semantics
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(network): type websocket frame failures
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(network): return 503 when middleware admission is exhausted
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(middleware): align streaming API contract
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(middleware): clarify WebSocket event result scope
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* docs(rfc): simplify middleware revision history
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* feat(examples): add WebSocket content guard support
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(middleware): unify binding payload limits
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* refactor(middleware): align payload limit terminology
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(middleware): address websocket review feedback
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(network): address websocket review findings
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* test(network): allow Linux handler setup in preflight regression
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(network): harden websocket relay finalization
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(network): inspect compressed websocket messages
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* test(network): stabilize compressed websocket regressions
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(go-sdk): regenerate middleware protobuf binding
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(middleware): clarify websocket skip lifecycle
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
* fix(middleware): address WebSocket review feedback
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
---------
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
2026-08-14 21:51:42 +00:00
John T. Myers and John Myers
0120535efc
feat(proxy): bind static credentials to provider endpoints ( #2510 )
...
* feat(proxy): bind static credentials to provider endpoints
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
* test(e2e): verify static credential endpoint isolation
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
* docs(provider): explain static credential endpoint binding
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
* fix(e2e): use valid endpoint isolation fixtures
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
* docs(provider): explain static credential endpoint binding
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
* fix(credentials): preserve binding identity across rotations
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(proxy): enforce bindings across request lifecycle
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(proxy): close credential relay gaps
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* docs(credentials): clarify binding failure behavior
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(credentials): hash selected provider profile scope
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(proxy): resolve credentials after request admission
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* docs(credentials): clarify binding failure diagnostics
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(proxy): align single-route credential denials
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(credentials): harden endpoint-bound rotation
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(credentials): enforce identity and authority binding
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(credentials): snapshot provider environment atomically
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(e2e): include authority port in query proxy requests
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(credentials): close credential revocation gaps
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* docs(proxy): explain authority mismatch diagnostics
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(credentials): enforce binding lifecycle invariants
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(provider): reject credential config collisions
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(network): capture credential scope atomically
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(network): distinguish origin and absolute targets
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(provider): isolate endpointless profile credentials
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(network): normalize IPv6 request authorities
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* docs(credentials): clarify endpointless profile isolation
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* feat(policy): bind endpointless provider credentials
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(credentials): use current GCP placeholder revision
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* docs(providers): explain policy credential bindings
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(credentials): cover endpointless fail-closed invariant
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(policy): expect ambiguity rejection at creation
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(server): authenticate rebased policy requests
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* refactor(proxy): share credential mismatch finding builder
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(credentials): cover malformed binding metadata
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(credentials): verify multi-key endpoint isolation
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(e2e): cover same-host credential path denial
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* docs(credentials): document serialized refresh contract
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* refactor(proxy): consolidate L7 log formatting
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* perf(credentials): precompile endpoint binding patterns
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* perf(credentials): share identity epoch revisions
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(proxy): require explicit request default ports
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(policy): validate SigV4 credential sources
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(credentials): preserve endpoint bindings for credential handles
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* feat(go-sdk): expose network credential bindings
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
---------
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
Co-authored-by: John Myers <johntmyers@users.noreply.github.com >
2026-08-10 19:19:45 +00:00
Matthew Grossman
537805568d
feat(sandbox): honor OCI image working directories ( #2530 )
...
* feat(sandbox): honor Docker OCI working directories
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
* fix(sandbox): honor effective workspace access
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
* test(sandbox): cover enforced workspace denial
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
* docs(docker): explain effective workdir checks
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
* fix(sandbox): validate effective workspace writes
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
* fix(sandbox): reserve supervisor control roots
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
* refactor(sandbox): centralize control paths
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
* fix(sandbox): reserve OCI runtime mount roots
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
---------
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
2026-08-04 17:38:51 +00:00
John T. Myers and John Myers
905b554c7c
refactor(network): consolidate proxy egress pipeline ( #2373 )
...
* refactor(network): introduce shared egress pipeline
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(network): cover shared proxy egress paths
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* refactor(network): make destination authorization explicit
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* refactor(network): pin proxy relay policy context
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(network): lock relay generation contracts
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(network): establish phase zero compatibility baseline
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* feat(policy): detect ambiguous network endpoints
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* feat(sandbox): fail closed on invalid policy updates
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* refactor(network): invalidate relays on policy changes
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* docs(policy): document validation failure posture
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(network): cover validation and middleware egress
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(config): move policy failure mode to gateway toml
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(network): name proxy contracts by behavior
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(network): align overlap validation with endpoint selection
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(network): expect hard loopback denial
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(network): match declared endpoint denial
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(policy): preserve path-specific endpoint overrides
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(network): respect hard-blocked host gateways
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(network): reconcile proxy refactor with main
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(network): preserve CONNECT policy generation
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(policy): cover runtime endpoint glob semantics
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(server): reject ambiguous policies before persistence
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* docs(policy): explain ambiguity preflight behavior
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(policy): compare body limits within protocol
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(proxy): avoid global tracing capture race
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
* chore(server): format rebased provider tests
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* test(server): authenticate rebased policy requests
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(sandbox): retain runtime on middleware outage
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(server): preflight provider composition activation
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* fix(sandbox): distinguish runtime failure transitions
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
---------
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
Signed-off-by: John Myers <johntmyers@users.noreply.github.com >
Co-authored-by: John Myers <johntmyers@users.noreply.github.com >
2026-07-31 20:59:00 +00:00
Matthew Grossman
bc14018cad
feat(sandbox): use policy-first OCI image identity ( #2509 )
...
* feat(sandbox): use policy-first OCI image identity
Closes #2331
Preserve per-field policy omission, derive Docker and Podman fallbacks from the inspected immutable image, and resolve the final numeric identity before starting agent children.
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
* fix(sandbox): preserve declared process identities
Keep explicit policy values and OCI-declared names intact, defer passwd lookup until a primary GID is required, and refresh stale policy examples.
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
* fix(supervisor): reuse resolved OCI identity
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
* fix(supervisor): allow Linux pre-exec arguments
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
* fix(kubernetes): protect resolved sandbox identity
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
* fix(sandbox): prepare workspace for OCI identity
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
* refactor(sandbox): own only workspace root
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
* fix(sandbox): harden partial identity drops
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
* test(sandbox): scope OCI image e2e to Docker
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
* fix(sandbox): narrow OCI identity fallback scope
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
* test(podman): cover OCI identity launch
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
* fix(podman): exercise OCI fallback in E2E
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
---------
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com >
2026-07-29 05:27:21 +00:00
Grace Smith
deced8716b
refactor(policy): extract shared L7 endpoint validation ( #2389 )
...
Move L7 endpoint semantic checks into the openshell-policy crate so both
profile lint and the runtime validator share one implementation. This
eliminates drift between the two validation paths.
The shared validator covers 9 checks: unknown protocol, rules/access
mutual exclusivity, JSON-RPC family access rejection, json-rpc requires
rules, non-JSON-RPC protocol requires rules or access, MCP requires
rules when allow_all is false, rules-would-deny-all detection,
deny_rules require protocol, and deny_rules require base allow set.
Changes rules/deny_rules fields to Option<Vec<...>> so absent vs empty
is distinguishable at lint time. Adds is_effectively_empty() to
L7AllowProfile for deny-all detection of allow: {} objects. Makes
rules_would_deny_all MCP-aware by checking tool/params.name selectors
before classifying a rule as deny-all. Adds params field to
L7AllowProfile so MCP tool selectors survive proto round-trip.
Signed-off-by: Grace Smith <gsmith@redhat.com >
Signed-off-by: Grace Smith <grasmith@redhat.com >
2026-07-24 17:48:24 +00:00
Piotr Mlocek
d556748771
feat(supervisor-middleware): add network egress middleware ( #2027 )
...
Signed-off-by: Piotr Mlocek <pmlocek@nvidia.com >
2026-07-16 17:47:49 -07:00
Shiju
5477e2f21d
docs(mcp): fix granular policy lifecycle examples ( #2066 )
...
Signed-off-by: Shiju <shiju@nvidia.com >
2026-06-30 13:36:37 -07:00
krishicks and ddurst
7bce1223dc
feat(policy): add JSON-RPC and MCP L7 policies ( #1865 )
...
Add policy schema, proto, provider profile, OPA, and L7 proxy support for
`protocol: json-rpc` and `protocol: mcp`. Generic JSON-RPC endpoints match
exact method names only, with `method: "*"` as the all-method sentinel;
wildcard/glob methods and params matchers are rejected.
Parse JSON-RPC request bodies and batches in the forward proxy, deny
response-shaped client frames, limit receive-stream GET allowance to MCP
endpoints, and redact params in decision logs. Preserve L7 rule params on the
proto load path so MCP `tools/call` tool filters behave like YAML-loaded
policies.
Add MCP conformance coverage, JSON-RPC L7 e2e coverage, and docs for the new
protocols and current matcher limitations.
Signed-off-by: Kris Hicks <khicks@nvidia.com >
Co-authored-by: ddurst <267424412+ddurst-nvidia@users.noreply.github.com >
2026-06-26 15:52:16 -07:00
Jesse Jaggars and Russell Bryant
f569a0ade6
feat(sandbox): proxy-side AWS SigV4 credential signing for CONNECT tunnels ( #1638 )
...
Signed-off-by: Jesse Jaggars <jjaggars@redhat.com >
Co-authored-by: Russell Bryant <russell.bryant@gmail.com >
2026-06-26 10:52:24 -07:00
mjamiv and John Myers
f1fc87e1ad
fix(sandbox): trust exact declared private endpoints ( #1560 )
...
* fix(sandbox): trust exact declared private endpoints
* fix(sandbox): preserve advisor endpoint provenance
* fix(sandbox): repair advisor provenance lint failures
---------
Co-authored-by: John Myers <9696606+johntmyers@users.noreply.github.com >
2026-05-29 16:18:42 -07:00
mjamiv and John Myers
528fb29147
fix(sandbox): allow first-label L7 host wildcards ( #1304 )
...
* fix(sandbox): allow first-label L7 host wildcards
* docs(sandbox): document L7 host wildcard contract + add OPA runtime tests
- Add Host Wildcards section to architecture/security-policy.md
describing accepted (first-label *, **, intra-label *-X) and
rejected (bare, TLD, non-first-label, recursive-in-label) forms,
and noting that wildcards never cross '.' boundaries.
- Expand the policy-schema.mdx 'host' field description to reflect
the same contract instead of only mentioning '*.example.com'.
- Add OPA runtime tests asserting '*-aiplatform.googleapis.com'
matches 'us-central1-aiplatform.googleapis.com' and does not match
'us-central1.aiplatform.googleapis.com' (cross-dot boundary). Locks
validator/runtime alignment for intra-label wildcards.
* chore: update mise lockfile
* test(server): tolerate serialized inference upserts
---------
Co-authored-by: John Myers <9696606+johntmyers@users.noreply.github.com >
2026-05-21 09:32:37 -07:00
Miyoung Choi
8322e4fd00
docs: style fixes ( #1341 )
...
* docs: style fixes
* docs: drop observability section overview page and rename a section title
* docs: title updates
2026-05-12 16:36:15 -07:00
Aaron Erickson 🦞 and John Myers
9ea94b645d
fix(sandbox): rewrite messaging credential placeholders ( #1286 )
...
* fix(sandbox): rewrite credential placeholders in websocket text frames
Signed-off-by: Aaron Erickson <aerickson@nvidia.com >
* fix(sandbox): harden websocket credential rewrite
Signed-off-by: Aaron Erickson <aerickson@nvidia.com >
* feat(sandbox): add websocket l7 inspection and compression
Signed-off-by: Aaron Erickson <aerickson@nvidia.com >
* fix(sandbox): harden websocket upgrade validation
Signed-off-by: Aaron Erickson <aerickson@nvidia.com >
* test(sandbox): cover route-selected websocket upgrades
Signed-off-by: Aaron Erickson <aerickson@nvidia.com >
* fix(sandbox): harden websocket negotiation parsing
Signed-off-by: Aaron Erickson <aerickson@nvidia.com >
* test(sandbox): add websocket conformance relay matrix
Signed-off-by: Aaron Erickson <aerickson@nvidia.com >
* test(e2e): add websocket conformance lane
Signed-off-by: Aaron Erickson <aerickson@nvidia.com >
* fix(policy): support websocket incremental rules
Signed-off-by: Aaron Erickson <aerickson@nvidia.com >
* feat(policy): enable websocket credential rewrite updates
Signed-off-by: Aaron Erickson <aerickson@nvidia.com >
* fix(cli): make websocket rewrite endpoint-local
Signed-off-by: Aaron Erickson <aerickson@nvidia.com >
* feat(sandbox): support graphql websocket policy
Signed-off-by: Aaron Erickson <aerickson@nvidia.com >
* fix(policy): allow private IPs for websocket endpoints
* feat(sandbox): rewrite REST credential placeholders
Signed-off-by: Aaron Erickson <aerickson@nvidia.com >
* refactor(sandbox): generalize credential aliases
Signed-off-by: Aaron Erickson <aerickson@nvidia.com >
* fix(sandbox): rewrite encoded form credentials
Signed-off-by: Aaron Erickson <aerickson@nvidia.com >
* fix(sandbox): close websocket policy and provider alias gaps
Signed-off-by: Aaron Erickson <aerickson@nvidia.com >
* fix(e2e): route websocket probe through host gateway
* fix(e2e): stabilize websocket probe handshake
* fix(e2e): exercise websocket probe through proxy
* ci: remove websocket conformance workflow
---------
Signed-off-by: Aaron Erickson <aerickson@nvidia.com >
Co-authored-by: John Myers <9696606+johntmyers@users.noreply.github.com >
2026-05-11 22:40:44 -07:00
John T. Myers
6b21804258
feat(policy): add GraphQL L7 inspection ( #1083 )
...
Support GraphQL L7 policies
2026-05-04 11:50:09 -07:00
Piotr Mlocek
ee2de81bc9
fix(sandbox): preserve encoded slash policy from proto ( #1073 )
2026-04-29 16:36:49 -07:00
John T. Myers
40e9bf6feb
feat(policy): add incremental sandbox policy updates ( #860 )
...
* feat(policy): add incremental sandbox policy updates
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* docs(policies): expand incremental update guidance
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
* feat(policy): audit incremental updates in gateway logs
* docs(policy): quote glob specs in shell examples
---------
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com >
2026-04-20 08:00:02 -07:00
John T. Myers
28e1ff7b40
feat(policy): add deny rules to network policy schema ( #822 )
...
* feat(policy): add deny rules to network policy schema
Closes #565
Add L7 deny rules that block specific requests even when allowed by
access presets or explicit allow rules. Deny rules mirror the full
capability set of allow rules (method, path, query params, SQL command)
and take precedence -- if a request matches any deny rule, it is blocked
regardless of allow rules.
This enables the "allow everything except these specific operations"
pattern without enumerating every allowed endpoint. For example, granting
read-write access to GitHub while blocking PR approvals, branch
protection changes, and ruleset modifications.
* fix(policy): deny query matching fails closed, mirror allow-side validation
Addresses PR review findings P1 and P3:
P1: Deny-side query matching now uses fail-closed semantics. If ANY
value for a query key matches the deny matcher, the deny fires. The
previous implementation reused allow-side "all values must match"
logic which allowed ?force=true&force=false to bypass a deny on
force=true.
P3: Deny-side query validation now mirrors the full allow-side checks:
empty any lists, non-string matcher values, glob+any mutual exclusion,
glob type checks, and glob syntax warnings are all validated.
2026-04-14 21:52:14 -07:00
John T. Myers
2ca553a4a0
fix(sandbox): validate always-blocked IPs at load time, enrich denial logs, and filter un-fixable proposals ( #814 ) ( #815 )
...
Policies with allowed_ips entries targeting loopback, link-local, or
unspecified ranges now fail at connection time instead of being silently
blocked at runtime. The shorthand log format for DENIED events includes
a [reason:...] suffix so operators can distinguish 'allowlist miss' from
'structurally un-allowable'. The mechanistic mapper skips proposals for
always-blocked destinations, preventing the infinite TUI notification
loop. The gateway validates proposed rules on approval as defense-in-depth.
- Extract shared IP helpers (is_always_blocked_ip, is_always_blocked_net,
is_internal_ip) to openshell_core::net
- Reject always-blocked entries in parse_allowed_ips with hard error
- Skip implicit allowed_ips synthesis for always-blocked literal IP hosts
- Add status_detail to HttpActivityBuilder for denial reason propagation
- Enrich NET and HTTP shorthand with [reason:...] for DENIED events
- Add engine: tag to HTTP shorthand (consistency with NET shorthand)
- Filter always-blocked proposals in mechanistic mapper generate_proposals
- Add validate_rule_not_always_blocked server-side defense-in-depth
- Update architecture docs, published docs, and E2E test assertions
2026-04-13 09:47:50 -07:00
Piotr Mlocek
8b15ef772e
docs(fern): move published docs into docs tree ( #796 )
...
Remove the legacy Sphinx pipeline and make docs/ the single source of truth so the published site matches the repository layout.
2026-04-09 15:02:27 -07:00