Files
OpenShell/tasks/scripts/package-deb-install.sh
Johnny Greco 58b5f8f976 feat(prover): add standalone policy boundary checker (#3289)
* feat(prover): add standalone policy maximum checker

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* refactor(prover): simplify check scope schema

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(prover): align containment and cancellation with runtime

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(prover): stabilize containment checks in CI

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* test(prover): avoid solver in fast-path guard test

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(prover): align string containment with runtime

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(prover): reject ambiguous z3 string escapes

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(prover): align containment with runtime boundaries

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(prover-cli): harden cancellation and invalid input

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* feat(packaging): install policy prover with OpenShell

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(prover): clarify installation and check results

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(build): describe prover distribution directly

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* refactor(prover): rename maximum policy to boundary

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* refactor(prover): localize fail-closed validation

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* test(prover): cover fail-closed CLI surfaces

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* test(prover): allow CI load for REST solver proof

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(prover): use canonical policy schema for containment

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(prover): preserve uncertainty for runtime binary globs

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(prover): bound policy validation work

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(prover): document validation resource limits

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(prover): make containment API extensible

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(prover): define containment API contract

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(ci): integrate prover with consolidated builds

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(ci): declare release packaging dependency

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

---------

Signed-off-by: Johnny Greco <jogreco@nvidia.com>
2026-09-17 17:30:03 +00:00

94 lines
3.1 KiB
Bash
Executable File

#!/usr/bin/env bash
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
#
# Build OpenShell from source and install the resulting Debian package
# locally for testing. Intended for developers iterating on the deb itself
# or on the gateway-as-a-service flow.
#
# Steps:
# 1. cargo build --release the four binaries that go into the deb.
# 2. Run tasks/scripts/package-deb.sh against those binaries.
# 3. sudo dpkg -i the resulting artifact.
# 4. Start the packaged user gateway service and register it locally.
#
# Usage:
# mise run package:deb:install
#
# Optional env:
# OPENSHELL_DEB_VERSION override the package version (default: 0.0.0-local)
# OPENSHELL_DEB_ARCH override the deb architecture (default: host)
# OPENSHELL_OUTPUT_DIR override the artifact directory (default: artifacts)
set -euo pipefail
repo_root="$(cd "$(dirname "$0")/../.." && pwd)"
cd "$repo_root"
VERSION="${OPENSHELL_DEB_VERSION:-0.0.0-local}"
OUTPUT_DIR="${OPENSHELL_OUTPUT_DIR:-artifacts}"
ARCH="${OPENSHELL_DEB_ARCH:-$(dpkg --print-architecture 2>/dev/null || uname -m)}"
GATEWAY_NAME="openshell"
GATEWAY_ENDPOINT="https://127.0.0.1:17670"
remove_existing_gateway_registration() {
local config_home="${XDG_CONFIG_HOME:-${HOME}/.config}"
local openshell_config_dir="${config_home}/openshell"
local gateway_dir="${openshell_config_dir}/gateways/${GATEWAY_NAME}"
local active_gateway_path="${openshell_config_dir}/active_gateway"
if [ ! -f "${gateway_dir}/metadata.json" ]; then
return
fi
echo "==> Removing existing ${GATEWAY_NAME} gateway registration"
rm -f \
"${gateway_dir}/metadata.json" \
"${gateway_dir}/edge_token" \
"${gateway_dir}/cf_token" \
"${gateway_dir}/oidc_token.json"
if [ -f "$active_gateway_path" ] && [ "$(cat "$active_gateway_path")" = "$GATEWAY_NAME" ]; then
rm -f "$active_gateway_path"
fi
}
echo "==> Building release binaries"
cargo build --release \
-p openshell-cli \
-p openshell-gateway \
-p openshell-prover-cli \
-p openshell-driver-vm
echo "==> Building Debian package"
OPENSHELL_CLI_BINARY="${repo_root}/target/release/openshell" \
OPENSHELL_GATEWAY_BINARY="${repo_root}/target/release/openshell-gateway" \
OPENSHELL_PROVER_BINARY="${repo_root}/target/release/openshell-prover" \
OPENSHELL_DRIVER_VM_BINARY="${repo_root}/target/release/openshell-driver-vm" \
OPENSHELL_DEB_VERSION="$VERSION" \
OPENSHELL_DEB_ARCH="$ARCH" \
OPENSHELL_OUTPUT_DIR="$OUTPUT_DIR" \
"${repo_root}/tasks/scripts/package-deb.sh"
deb_path="${OUTPUT_DIR}/openshell_${VERSION}_${ARCH}.deb"
case "$deb_path" in
/*) ;;
*) deb_path="${repo_root}/${deb_path}" ;;
esac
echo "==> Installing ${deb_path}"
sudo dpkg -i "$deb_path"
openshell --version
openshell-gateway --version
openshell-prover --version
echo "==> Starting user gateway service"
systemctl --user daemon-reload
systemctl --user enable --now openshell-gateway
systemctl --user is-active --quiet openshell-gateway
echo "==> Registering local gateway"
remove_existing_gateway_registration
openshell gateway add "$GATEWAY_ENDPOINT" --local --name "$GATEWAY_NAME"