Files
Johnny GrecoandKirit93 5bce19ab47 feat(prover): check process, Landlock, and destination IP containment (#3394)
* feat(prover): check process, landlock, and destination IP containment

Signed-off-by: Kirit93 <kthadaka@nvidia.com>
Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(prover): reject ambiguous implicit IP modes

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(prover): validate implicit IP modes policy-wide

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(prover): tighten containment edge handling

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* test(prover): cover boundary v2 evidence shapes

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(prover): document boundary v2 evidence limits

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* refactor(prover): simplify result version contract

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* refactor(prover): clarify coverage terminology

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

---------

Signed-off-by: Kirit93 <kthadaka@nvidia.com>
Signed-off-by: Johnny Greco <jogreco@nvidia.com>
Co-authored-by: Kirit93 <kthadaka@nvidia.com>
2026-09-18 21:38:08 +00:00
..

OpenShell policy prover CLI

This package builds the standalone openshell-prover executable. It is a thin synchronous adapter around the reusable containment engine in openshell-prover; it owns local file loading, command parsing, result rendering, and process exit codes.

openshell-prover check candidate.yaml --boundary boundary.yaml
openshell-prover check candidate.yaml --boundary boundary.yaml --output json

The command checks whether a fully composed candidate policy stays within an operator-supplied boundary. It does not discover a gateway, fetch policy state, or apply policy changes.

Results use these exit codes:

Exit code Meaning
0 The candidate is within the boundary.
1 The candidate exceeds the boundary.
2 Usage, input, output, or internal error.
3 Unsupported policy semantics or an inconclusive solve.
130 Interrupted with Ctrl-C on Unix; graceful JSON output reports an inconclusive cancellation.

Build and test the package with:

cargo build -p openshell-prover-cli --bin openshell-prover
cargo test -p openshell-prover-cli

See the policy prover reference for installed usage and interpretation guidance.

JSON output uses a numeric schema_version for the result contract and a prover_version for the implementation that produced it. Consumers must inspect coverage.domains for the machine-readable modeled-domain declaration. A passing check compares configuration under the documented assumptions; it does not attest that a running sandbox installed its restrictions.