Commit Graph
174 Commits
Author SHA1 Message Date
John T. MyersandJohn Myers e8950e624c feat(sandbox): add L7 query parameter matchers (#617)
* feat(sandbox): add L7 query parameter matchers

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* fix(sandbox): decode + as space in query params and validate glob syntax

Three improvements from PR #617 review:

1. Decode + as space in query string values per the
   application/x-www-form-urlencoded convention. This matches Python's
   urllib.parse, JavaScript's URLSearchParams, Go's url.ParseQuery, and
   most HTTP frameworks. Literal + should be sent as %2B.

2. Add glob pattern syntax validation (warnings) for query matchers.
   Checks for unclosed brackets and braces in glob/any patterns. These
   are warnings (not errors) because OPA's glob.match is forgiving,
   but they surface likely typos during policy loading.

3. Add missing test cases: empty query values, keys without values,
   unicode after percent-decoding, empty query strings, and literal +
   via %2B encoding.

* fix(sandbox): add missing query_params field in forward proxy L7 request info

* style(sandbox): fix formatting in proxy L7 query param parsing

---------

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
Co-authored-by: John Myers <johntmyers@users.noreply.github.com>
2026-03-30 13:53:12 -07:00
John T. MyersandJohn Myers 758c62d18d fix(sandbox): handle per-path Landlock errors instead of abandoning entire ruleset (#677)
* fix(sandbox): handle per-path Landlock errors instead of abandoning entire ruleset

A single missing path (e.g., /app in containers without that directory)
caused PathFd::new() to propagate an error out of the entire Landlock
setup closure. Under BestEffort mode, this silently disabled all
filesystem restrictions for the sandbox.

Changes:
- Extract try_open_path() and classify_path_error() helpers that handle
  PathFd failures per-path instead of per-ruleset
- BestEffort mode: skip inaccessible paths with a warning, apply
  remaining rules
- HardRequirement mode: fail immediately on any inaccessible path
- Add zero-rule safety check to prevent applying an empty ruleset that
  would block all filesystem access
- Pre-filter system-injected baseline paths (e.g., /app) in enrichment
  functions so missing paths never reach Landlock
- Add unit tests for try_open_path, classify_path_error, and error
  classification for ENOENT, EACCES, ELOOP, ENAMETOOLONG, ENOTDIR
- Update user-facing docs and architecture docs with Landlock behavior
  tables, baseline path filtering, and compatibility mode semantics
- Fix stale ABI::V1 references in docs (code uses ABI::V2)

Closes #664

* fix(sandbox): use debug log for NotFound in Landlock best-effort mode

NotFound errors for stale baseline paths (e.g. /app persisted in the
server-stored policy but absent in this container) are expected in
best-effort mode. Downgrade from warn! to debug! so the message does
not leak into SSH exec stdout (the pre_exec hook inherits the tracing
subscriber whose writer targets fd 1).

Genuine errors (permission denied, symlink loops, etc.) remain at warn!
for operator visibility.

Also move custom_image e2e marker from /opt to /etc (a Landlock baseline
read-only path) since the security fix now properly enforces filesystem
restrictions.

---------

Co-authored-by: John Myers <johntmyers@users.noreply.github.com>
2026-03-30 13:19:19 -07:00
John T. Myers f37b69b5e5 feat(sandbox): auto-detect TLS and terminate unconditionally for credential injection (#544)
* feat(sandbox): auto-detect TLS and terminate unconditionally for credential injection

Closes #533

The proxy now auto-detects TLS by peeking the first bytes of each
connection. When TLS is detected, it terminates unconditionally —
enabling credential injection and optional L7 inspection without
requiring explicit 'tls: terminate' in the policy.
2026-03-23 18:45:18 -07:00
Miyoung Choi 0792dcb425 docs: unify install command in landing page, change docs skill name, update contributing guides (#355) 2026-03-16 07:51:42 -07:00
Miyoung ChoiandKirit93 c420109a6a docs: add dedicated gateway docs, network policy tutorial, and license page (#294)
* Added gateway and tutorial

* add new content and polish, add license terms

* small fix

* tiny fix

* polish bit more

* change warning to important

* fix support matrix

* small fix

* add a note about example script

* fix link

* fix link

* improve

* fix links

* unclutter sandbax index more

* improve titles

* tiny style fix

* style guide on inferences, release notes link to gh

* polish

* nit

* switch version to 0.0.3

* incorporate feedback

---------

Co-authored-by: Kirit93 <kthadaka@nvidia.com>
2026-03-14 09:53:01 -07:00
Drew Newberry fbd93a4632 refactor: rename navigator- crate prefix to openshell- (#277) 2026-03-13 02:02:18 -07:00
Miyoung Choi 7430c75438 remove manully generated cli reference (#272) 2026-03-12 22:08:17 -07:00
Drew Newberry 89d21d7852 refactor(sandbox): sandboxes are managed as separate community images (#267) 2026-03-12 22:06:52 -07:00
Piotr Mlocek 14e296d318 fix(cli): add --no-keep for ephemeral sandbox create cleanup (#258) 2026-03-12 17:18:39 -07:00
Drew Newberry 95d7ae077e refactor(cli): remove kubeconfig port, add doctor llm-help, update debug docs (#252) 2026-03-11 21:25:25 -07:00
Drew Newberry bcc6dad1d0 feat(cli): launch sandbox editors via managed ssh include (#226) 2026-03-11 20:06:38 -07:00
Drew Newberry f97270f988 refactor(docker): rename server image to gateway (#246)
* refactor(docker): rename server image to gateway

Rename Dockerfile.server to Dockerfile.gateway and update all image
references from openshell/server to openshell/gateway across Helm
charts, Kubernetes manifests, mise tasks, build/deploy scripts, CI
workflows, and documentation.

The underlying Rust binary (navigator-server) is unchanged -- this
rename only affects the Docker image name and Dockerfile.

* fix: catch remaining server->gateway references in docs and comments
2026-03-11 16:01:26 -07:00
Miyoung Choi 4e893322a1 update docs per new dev prs (#238) 2026-03-11 13:48:03 -07:00
Drew Newberry 756950140c refactor(python): rename navigator module to openshell and migrate config to gateway paths (#220) 2026-03-10 22:24:04 -07:00
Miyoung Choi bc25c9b6fe docs: add frontmatter, add json output and search extensions, for improving SEO (#217)
* add frontmatter

* add custom extensions
2026-03-10 18:04:25 -07:00
Miyoung Choi a666b895e5 docs: improve the new revision (#215)
* improve the new revision

* update the animated commands

* more improvements and unifying text

* more fixes
2026-03-10 17:40:17 -07:00
Drew Newberry f4af0ee848 chore: replace all nemoclaw references with openshell (#214)
- Update registry URLs from ghcr.io/nvidia/nemoclaw to ghcr.io/nvidia/openshell
- Rename NEMOCLAW_* environment variables to OPENSHELL_*
- Update CLI command references in documentation
- Update PyPI package name references
- Update GitHub repository URLs
- Rename .agents/skills/nemoclaw-cli directory to openshell-cli
2026-03-10 16:10:57 -07:00
Kirit ThadakaandPiotr Mlocek e57c247bc8 docs: Structural and content updates (#195)
* Removed network access docs

* Simplified docs for sandboxes and inference

* Fixed build

* docs(inference): clarify local inference routing

* docs(inference): update provider and model examples

* docs: add Docker prerequisite warning for connection-refused error

Made-with: Cursor

* Minor edits to quickstart safety and privacy

* Doc restructured

* removed tutorials

* Added tutorial

* Inference section reformatting

* Updated CLI ref

* removed troubleshooting

* Updated inference

* Updated pip install command for bug bash

* Updated arch diagram

* Updated tutorial

* Updated install commands

* Updated getting started

* Updated brev link

---------

Co-authored-by: Piotr Mlocek <pmlocek@nvidia.com>
2026-03-10 12:15:02 -07:00
Drew Newberry 984d1a6e5c chore: rename project from NemoClaw to OpenShell (#198) 2026-03-10 11:49:09 -07:00
Piotr MlocekandMiyoung Choi 107c85d1d7 docs(inference): clarify local inference routing (#190)
* docs(inference): clarify local inference routing

* docs(inference): update provider and model examples

* fix doc build

---------

Co-authored-by: Miyoung Choi <miyoungc@nvidia.com>
2026-03-09 21:34:14 -07:00
Miyoung Choi 95410a065f docs: restructure and polish safety and policy section (#189)
* restructure safty and policy section

* put the table autogeneration back

* enhance generate policy ref doc

* typo
2026-03-09 21:26:35 -07:00
Kirit Thadaka f8d2d824ce docs: Simplified the sandbox docs (#186)
* Removed network access docs

* Simplified docs for sandboxes and inference

* Fixed build
2026-03-09 16:52:30 -07:00
Miyoung Choi 574ef18dfc docs: consolidate information architecture and author content (#124)
* initial doc filling

* improvements

* stage provided get started, and add clean tutorials

* pull in Kirit's content and polish

* improve observability

* moving pieces

* move TOC around

* drop support matrix from concepts

* fix links

* minor fixes and fix badges

* minor fixes

* incorporate missed content

* minor improvements

* clean up

* run dori style guide review

* clean up

* updates impacting docs

* incorporate feedback

* minor fix

* some edits

* enterprise structure

* update cards

* improve

* add some emojis

* improve landing page with animated getting started code

* fix the animated code

* small improvements

* refresh content based on PR 156 and 158

* README as the source of truth for quickstart

* update README

* run edits

* change to the new prod name, text only, code swipe later

* add Home

* incorporate dev feedback on README

* krit's edits

* edit and improve index pages

* fix build

* revert README

* revert quickstart to not pull from README
2026-03-09 11:33:56 -07:00
Miyoung ChoiandDrew Newberry 11f795a462 docs: setup initial docs/ infrastructure and scaffolding (#94)
* set up docs

* rm nv sphinx theme version

* rm v* trigger

* incorporate feedback with cursor

* minor updates

* doc docs

* more small tweaks

* clean contributing

---------

Co-authored-by: Drew Newberry <anewberry@nvidia.com>
2026-03-04 22:31:45 -08:00