* feat(prover): check process, landlock, and destination IP containment Signed-off-by: Kirit93 <kthadaka@nvidia.com> Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(prover): reject ambiguous implicit IP modes Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(prover): validate implicit IP modes policy-wide Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(prover): tighten containment edge handling Signed-off-by: Johnny Greco <jogreco@nvidia.com> * test(prover): cover boundary v2 evidence shapes Signed-off-by: Johnny Greco <jogreco@nvidia.com> * docs(prover): document boundary v2 evidence limits Signed-off-by: Johnny Greco <jogreco@nvidia.com> * refactor(prover): simplify result version contract Signed-off-by: Johnny Greco <jogreco@nvidia.com> * refactor(prover): clarify coverage terminology Signed-off-by: Johnny Greco <jogreco@nvidia.com> --------- Signed-off-by: Kirit93 <kthadaka@nvidia.com> Signed-off-by: Johnny Greco <jogreco@nvidia.com> Co-authored-by: Kirit93 <kthadaka@nvidia.com>
OpenShell policy prover CLI
This package builds the standalone openshell-prover executable. It is a thin synchronous adapter around the reusable containment engine in openshell-prover; it owns local file loading, command parsing, result rendering, and process exit codes.
openshell-prover check candidate.yaml --boundary boundary.yaml
openshell-prover check candidate.yaml --boundary boundary.yaml --output json
The command checks whether a fully composed candidate policy stays within an operator-supplied boundary. It does not discover a gateway, fetch policy state, or apply policy changes.
Results use these exit codes:
| Exit code | Meaning |
|---|---|
0 |
The candidate is within the boundary. |
1 |
The candidate exceeds the boundary. |
2 |
Usage, input, output, or internal error. |
3 |
Unsupported policy semantics or an inconclusive solve. |
130 |
Interrupted with Ctrl-C on Unix; graceful JSON output reports an inconclusive cancellation. |
Build and test the package with:
cargo build -p openshell-prover-cli --bin openshell-prover
cargo test -p openshell-prover-cli
See the policy prover reference for installed usage and interpretation guidance.
JSON output uses a numeric schema_version for the result contract and a
prover_version for the implementation that produced it. Consumers must inspect
coverage.domains for the machine-readable modeled-domain declaration. A
passing check compares configuration under the documented assumptions; it does
not attest that a running sandbox installed its restrictions.