Files
OpenShell/Cargo.toml
Shiju 1358941b81 feat(mcp): inspect requests with Tower-selected protocol profiles (#3335)
* fix(sandbox-backend): sort boundary request objects before hashing

Sort boundary request objects recursively before hashing so serde_json's
preserve_order feature cannot change digest identity. Cover canonical
bytes, envelope round trips, and rejection of modified provider values
and operations.

Signed-off-by: Shiju <shiju@nvidia.com>

* feat(mcp): upgrade tower-mcp-types to 0.22.2

Upgrade tower-mcp-types from 0.12.0 to an exact-pinned 0.22.2 and use its
inspection APIs to validate MCP requests against the selected revision.
Carry inspection metadata into policy evaluation and validate requests
after header rewriting, before forwarding.

Add explicit support for the sessionless 2026-07-28 revision while keeping
2025-11-25 as the default. Validate per-request metadata and standard HTTP
header mirrors, and support discovery, tools, and subscription requests.

Delegate batch availability and parameter schemas to Tower. Share typed
request names between policy and HTTP checks, retain the local batch
resource cap, and centralize MCP policy version parsing and ordering.

Keep supported MCP revisions and shared allowlist parsing in the canonical
policy schema; core re-exports those types. Tower owns wire-profile
semantics, and every supported policy revision must map to the matching
inspector profile.

Reject duplicate JSON keys, invalid known-method parameters, unavailable
methods, and unsupported batches. Keep exact extension allow rules and
deny precedence. Document request inspection boundaries and add unit,
forwarding, and sandbox coverage.

Refs #2174.

Signed-off-by: Shiju <shiju@nvidia.com>

* test(mcp): prove authorization at the forwarding boundary

Cover March batch denial in both member orders, valid and malformed
controls, and audit behavior across both relay entry paths. Exercise real
middleware tool rewrites with matching metadata and assert the exact
upstream representation or zero forwarded bytes.

Verify legacy bodyless SSE GET remains usable while GET tool bodies and
unsupported DELETE cleanup are rejected. Clarify request-selected profile
and middleware mutation comments without changing production behavior.

Signed-off-by: Shiju <shiju@nvidia.com>

* test(mcp): exercise permitted profiles through the sandbox proxy

Cover March and June singleton policies and select November and July
separately under one endpoint allowlist. Capture upstream tool receipts
to distinguish proxy policy denial from an upstream rejection.

Extend middleware rewrite coverage to June and multi-version policies,
and preserve the sessionless discovery and subscription checks through
the shared fixture helpers.

Signed-off-by: Shiju <shiju@nvidia.com>

* test(kubernetes): box the admission check future

Keep the admission test future below Clippy's size limit when the
workspace dependency features are unified.

Signed-off-by: Shiju <shiju@nvidia.com>

* test(mcp): reuse the forwarding fixture identity cache

Share the binary identity cache across protocol-profile cases, matching
the proxy lifecycle and avoiding repeated hashes of the test executable.
Keep procfs authorization and all forwarding assertions intact.

Signed-off-by: Shiju <shiju@nvidia.com>

---------

Signed-off-by: Shiju <shiju@nvidia.com>
2026-09-28 20:48:50 +00:00

184 lines
6.0 KiB
TOML

# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
[workspace]
resolver = "2"
members = ["crates/*"]
[workspace.package]
version = "0.0.0"
edition = "2024"
rust-version = "1.94"
license = "Apache-2.0"
repository = "https://github.com/NVIDIA/OpenShell"
[workspace.dependencies]
# Async runtime
tokio = { version = "1.43", features = ["full"] }
# gRPC/Protobuf
tonic = "0.14"
tonic-types = "0.14"
tonic-prost = "0.14"
tonic-prost-build = "0.14"
prost = "0.14"
prost-types = "0.14"
prost-reflect = { version = "0.16.5", features = ["serde"] }
# HTTP server
axum = { version = "0.8", features = ["ws"] }
tower = "0.5"
tower-http = { version = "0.6", features = ["cors", "trace", "request-id"] }
hyper = { version = "1.6", features = ["full"] }
hyper-util = { version = "0.1", features = ["tokio", "server-auto"] }
http = "1.2"
http-body = "1.0"
http-body-util = "0.1"
h2 = "0.4"
# TLS
tokio-rustls = { version = "0.26", default-features = false, features = ["logging", "tls12", "aws_lc_rs"] }
rustls = { version = "0.23", default-features = false, features = ["std", "logging", "tls12", "aws_lc_rs"] }
rustls-pemfile = "2"
rcgen = { version = "0.13", default-features = false, features = ["crypto", "pem", "aws_lc_rs", "x509-parser"] }
webpki-roots = "1"
rustls-native-certs = "0.8"
# CLI
clap = { version = "4.5", features = ["derive", "env"] }
clap_complete = { version = "4.5", features = ["unstable-dynamic"] }
indicatif = "0.17"
owo-colors = "4"
ratatui = "0.26"
crossterm = "0.28"
terminal-colorsaurus = "1.0"
# Error handling
miette = { version = "7", features = ["fancy"] }
thiserror = "2"
# Windows platform APIs (ETW/TDH audit consumer in openshell-driver-mxc; Windows-only)
windows = { version = "0.62", features = ["Wdk_System_Threading", "Win32_Foundation", "Win32_System_Diagnostics_Etw", "Win32_System_Time"] }
anyhow = "1"
# Logging/Tracing
tracing = "0.1"
tracing-subscriber = { version = "0.3", features = ["env-filter", "json"] }
tracing-appender = "0.2"
# OpenTelemetry — OTLP/gRPC export. Kept in lockstep with the workspace's
# tonic 0.14 / prost 0.14 via opentelemetry-proto's `grpc-tonic` feature.
opentelemetry = "0.32"
opentelemetry_sdk = { version = "0.32", features = ["rt-tokio"] }
opentelemetry-otlp = { version = "0.32", default-features = false, features = ["grpc-tonic", "trace"] }
tracing-opentelemetry = { version = "0.33", default-features = false, features = ["tracing-log"] }
# Metrics
metrics = "0.24"
metrics-exporter-prometheus = { version = "0.18", default-features = false, features = ["http-listener"] }
# Unix/Process
nix = { version = "0.29", features = ["signal", "process", "user", "fs", "term"] }
rustix = { version = "1.1", features = ["process"] }
socket2 = "0.6"
# Serialization
serde = { version = "1", features = ["derive"] }
serde_json = "1"
serde_yml = { package = "noyalib", version = "0.0.28", default-features = false, features = ["std", "compat-serde-yaml"] }
toml = "0.8"
apollo-parser = "0.8.5"
tower-mcp-types = "=0.22.2"
regex = "1"
# HTTP client
reqwest = { version = "0.12.28", default-features = false, features = ["json", "rustls-tls-native-roots-no-provider"] }
# AWS SDK
aws-config = { version = "1", default-features = false, features = ["default-https-client", "rt-tokio", "behavior-version-latest"] }
aws-sdk-sts = { version = "1", default-features = false, features = ["default-https-client", "rt-tokio", "behavior-version-latest"] }
# WebSocket
tokio-tungstenite = { version = "0.26", default-features = false, features = ["connect", "rustls-tls-native-roots"] }
# Clipboard (OSC 52)
base64 = "0.22"
# Crypto / Auth
sha2 = "0.10"
rand = "0.9"
jsonwebtoken = { version = "10", features = ["aws_lc_rs"] }
zeroize = { version = "1", features = ["derive"] }
getrandom = "0.3"
aws-lc-rs = "1.16"
spiffe = { version = "0.15", default-features = false, features = ["workload-api-jwt", "jwt-verify-rust-crypto", "tracing"] }
# Filesystem embedding
include_dir = "0.7"
# Glob matching
glob = "0.3"
# Utilities
futures = "0.3"
bytes = "1"
hickory-proto = "0.26.1"
pin-project-lite = "0.2"
tokio-stream = "0.1"
protoc-bin-vendored = "3.2.0"
url = "2"
indexmap = "2"
# Database
sqlx = { version = "0.9", default-features = false, features = ["runtime-tokio", "tls-rustls-aws-lc-rs", "postgres", "sqlite", "migrate", "macros"] }
# SQLx's facade couples native roots to ring; select native roots independently.
sqlx-core = { version = "0.9", default-features = false, features = ["rustls-native-certs"] }
# Kubernetes
kube = { version = "0.99", default-features = false, features = ["client", "runtime", "derive", "rustls-tls", "aws-lc-rs"] }
kube-runtime = "0.99"
k8s-openapi = { version = "0.24", features = ["v1_29"] }
# IDs
uuid = { version = "1.10", features = ["v4"] }
signal-hook = "0.3"
# SMT solver (uses system libz3; enable z3/bundled via the prover's bundled-z3 feature for local dev without system z3)
z3 = "0.21"
[workspace.lints.rust]
unsafe_code = "warn"
rust_2018_idioms = { level = "warn", priority = -1 }
trivial_casts = "warn"
trivial_numeric_casts = "warn"
unused_lifetimes = "warn"
unused_qualifications = "warn"
[workspace.lints.clippy]
all = { level = "warn", priority = -1 }
pedantic = { level = "warn", priority = -1 }
nursery = { level = "warn", priority = -1 }
# Allow certain pedantic lints that are too noisy
module_name_repetitions = "allow"
must_use_candidate = "allow"
missing_errors_doc = "allow"
missing_panics_doc = "allow"
# Allow noisy nursery lints
significant_drop_tightening = "allow" # Often gives incorrect suggestions
missing_const_for_fn = "allow" # Too noisy for async code patterns
# Allow noisy pedantic lints
too_many_lines = "allow" # Function length limits are subjective
needless_pass_by_value = "allow" # Common pattern in async handlers
ref_option = "allow" # Common pattern for optional references
missing_fields_in_debug = "allow" # Manual Debug impls often intentionally omit fields
[profile.release]
strip = true
[profile.dev]
# Faster compile times for dev builds
debug = 1