Files
Johnny Greco 854b2370b8 fix(policy): align quickstart, policy skills, and pypi profile with current behavior (#3695)
* fix(examples): add quickstart rule with policy update and show OCSF logs

The quickstart applied policy.yaml with `openshell policy set`, which replaces
the whole policy. The file omitted /bin from the restrictive default, so the
live filesystem additivity check could reject it. Add the rule with
`openshell policy update` instead, and keep policy.yaml as a complete policy
for `sandbox create --policy` that covers the default read-only paths.

The demo and README filtered logs with `--level warn`, but the server ranks
OCSF events as INFO, which hid the policy decisions the demo shows. Query
`--source sandbox` without a level filter and match the OCSF shorthand
(DENIED/ALLOWED) instead of the retired key=value format.

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(skills): align generate-sandbox-policy with proxy behavior

Remove the `protocol: sql` validation check and the SQL `command` matcher,
which the published policy docs no longer describe.

Correct the private IP guidance: exact user-declared hostnames may reach
private addresses without allowed_ips. Wildcard, hostless, and
advisor-proposed endpoints still need allowed_ips, and loopback, link-local,
unspecified, and cloud metadata addresses stay blocked.

Stop describing an omitted protocol as pure L4 or uninspected. The proxy
still terminates TLS, parses HTTP strictly, and enforces request authority;
it only skips method and path rules.

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(providers): drop pip script paths from pypi profile binaries

OpenShell identifies a process by /proc/<pid>/exe, so a pip script runs as
its Python interpreter and the .venv/bin/pip entries could never match. The
venv interpreters that run those scripts are already listed, so remove the
script paths and explain in the header that users must list interpreters.

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(skills): fix openshell-cli policy iteration steps

Monitoring denials with `--level warn` hides them, because the server ranks
OCSF policy events as INFO. Drop the level filter and describe the OCSF
shorthand DENIED lines instead of the retired `action: deny` format.

`policy get --full > file` produced input that `policy set` cannot parse: the
output starts with revision details before the `---` separator, and --full
adds provider-composed rules. Export `--base` and keep only the YAML after the
separator. Also stop recommending full replacement for filesystem, Landlock,
or process changes, which require recreating the sandbox, and drop the SQL
mention that generate-sandbox-policy no longer covers.

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(skills): qualify authority checks for omitted-protocol endpoints

An endpoint without `protocol` only receives authority checks on HTTP requests
the proxy parses after default TLS handling. Without an L7 route or required
middleware, other CONNECT payloads such as HTTP/2 prior knowledge can use the
raw relay, and `tls: skip` bypasses termination and parsing. Stop describing
omitted-protocol endpoints as always authority-checked.

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

---------

Signed-off-by: Johnny Greco <jogreco@nvidia.com>
2026-09-25 16:34:43 +00:00

57 lines
2.5 KiB
YAML

# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
# Example provider profile. OpenShell does not load it; import it explicitly:
# openshell provider profile lint -f providers/pypi.yaml
# openshell provider profile import -f providers/pypi.yaml --global
#
# Copy and edit this file rather than importing it unchanged. `binaries` is the
# least-privilege control that decides which processes may reach the endpoints
# below, so it has to name the paths in *your* image.
#
# Client binaries: python, python3 (which also run pip), uv.
# Reference layout: the paths below assume a particular image layout — a
# virtualenv at /sandbox/.venv or /app/.venv, uv at
# /usr/local/bin/uv, uv-managed interpreters under
# /sandbox/.uv/python. Almost every other image differs
# (/usr/bin/python3, /usr/local/bin/python3, a venv
# elsewhere). Edit `binaries` before importing or the
# profile is inert.
# OpenShell identifies a process by its executable, not its
# command line, so pip and other Python scripts match the
# interpreter that runs them. List that interpreter, never
# a script path such as .venv/bin/pip. Exact paths resolve
# symlinks; globs must match the interpreter's real path.
# Credential scope: none. PyPI access here is anonymous.
# Endpoint access: pypi.org and files.pythonhosted.org for packages;
# downloads.python.org for interpreters; github.com,
# api.github.com and objects.githubusercontent.com for
# sdists that build from a Git source.
# Smoke test: openshell sandbox create --provider <name> -- \
# python -m pip download --no-deps -d /tmp/wheels requests
id: pypi
display_name: PyPI
description: Python package installation from PyPI and related package sources
category: data
endpoints:
- host: pypi.org
port: 443
- host: files.pythonhosted.org
port: 443
- host: github.com
port: 443
- host: objects.githubusercontent.com
port: 443
- host: api.github.com
port: 443
- host: downloads.python.org
port: 443
binaries:
- /sandbox/.venv/bin/python
- /sandbox/.venv/bin/python3
- /app/.venv/bin/python
- /app/.venv/bin/python3
- /usr/local/bin/uv
- /sandbox/.uv/python/**