mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-04 16:39:35 +08:00
* feat(prover): add standalone policy maximum checker Signed-off-by: Johnny Greco <jogreco@nvidia.com> * refactor(prover): simplify check scope schema Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(prover): align containment and cancellation with runtime Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(prover): stabilize containment checks in CI Signed-off-by: Johnny Greco <jogreco@nvidia.com> * test(prover): avoid solver in fast-path guard test Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(prover): align string containment with runtime Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(prover): reject ambiguous z3 string escapes Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(prover): align containment with runtime boundaries Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(prover-cli): harden cancellation and invalid input Signed-off-by: Johnny Greco <jogreco@nvidia.com> * feat(packaging): install policy prover with OpenShell Signed-off-by: Johnny Greco <jogreco@nvidia.com> * docs(prover): clarify installation and check results Signed-off-by: Johnny Greco <jogreco@nvidia.com> * docs(build): describe prover distribution directly Signed-off-by: Johnny Greco <jogreco@nvidia.com> * refactor(prover): rename maximum policy to boundary Signed-off-by: Johnny Greco <jogreco@nvidia.com> * refactor(prover): localize fail-closed validation Signed-off-by: Johnny Greco <jogreco@nvidia.com> * test(prover): cover fail-closed CLI surfaces Signed-off-by: Johnny Greco <jogreco@nvidia.com> * test(prover): allow CI load for REST solver proof Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(prover): use canonical policy schema for containment Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(prover): preserve uncertainty for runtime binary globs Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(prover): bound policy validation work Signed-off-by: Johnny Greco <jogreco@nvidia.com> * docs(prover): document validation resource limits Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(prover): make containment API extensible Signed-off-by: Johnny Greco <jogreco@nvidia.com> * docs(prover): define containment API contract Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(ci): integrate prover with consolidated builds Signed-off-by: Johnny Greco <jogreco@nvidia.com> * fix(ci): declare release packaging dependency Signed-off-by: Johnny Greco <jogreco@nvidia.com> --------- Signed-off-by: Johnny Greco <jogreco@nvidia.com>
94 lines
3.1 KiB
Bash
Executable File
94 lines
3.1 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
#
|
|
# Build OpenShell from source and install the resulting Debian package
|
|
# locally for testing. Intended for developers iterating on the deb itself
|
|
# or on the gateway-as-a-service flow.
|
|
#
|
|
# Steps:
|
|
# 1. cargo build --release the four binaries that go into the deb.
|
|
# 2. Run tasks/scripts/package-deb.sh against those binaries.
|
|
# 3. sudo dpkg -i the resulting artifact.
|
|
# 4. Start the packaged user gateway service and register it locally.
|
|
#
|
|
# Usage:
|
|
# mise run package:deb:install
|
|
#
|
|
# Optional env:
|
|
# OPENSHELL_DEB_VERSION override the package version (default: 0.0.0-local)
|
|
# OPENSHELL_DEB_ARCH override the deb architecture (default: host)
|
|
# OPENSHELL_OUTPUT_DIR override the artifact directory (default: artifacts)
|
|
|
|
set -euo pipefail
|
|
|
|
repo_root="$(cd "$(dirname "$0")/../.." && pwd)"
|
|
cd "$repo_root"
|
|
|
|
VERSION="${OPENSHELL_DEB_VERSION:-0.0.0-local}"
|
|
OUTPUT_DIR="${OPENSHELL_OUTPUT_DIR:-artifacts}"
|
|
ARCH="${OPENSHELL_DEB_ARCH:-$(dpkg --print-architecture 2>/dev/null || uname -m)}"
|
|
GATEWAY_NAME="openshell"
|
|
GATEWAY_ENDPOINT="https://127.0.0.1:17670"
|
|
|
|
remove_existing_gateway_registration() {
|
|
local config_home="${XDG_CONFIG_HOME:-${HOME}/.config}"
|
|
local openshell_config_dir="${config_home}/openshell"
|
|
local gateway_dir="${openshell_config_dir}/gateways/${GATEWAY_NAME}"
|
|
local active_gateway_path="${openshell_config_dir}/active_gateway"
|
|
|
|
if [ ! -f "${gateway_dir}/metadata.json" ]; then
|
|
return
|
|
fi
|
|
|
|
echo "==> Removing existing ${GATEWAY_NAME} gateway registration"
|
|
rm -f \
|
|
"${gateway_dir}/metadata.json" \
|
|
"${gateway_dir}/edge_token" \
|
|
"${gateway_dir}/cf_token" \
|
|
"${gateway_dir}/oidc_token.json"
|
|
|
|
if [ -f "$active_gateway_path" ] && [ "$(cat "$active_gateway_path")" = "$GATEWAY_NAME" ]; then
|
|
rm -f "$active_gateway_path"
|
|
fi
|
|
}
|
|
|
|
echo "==> Building release binaries"
|
|
cargo build --release \
|
|
-p openshell-cli \
|
|
-p openshell-gateway \
|
|
-p openshell-prover-cli \
|
|
-p openshell-driver-vm
|
|
|
|
echo "==> Building Debian package"
|
|
OPENSHELL_CLI_BINARY="${repo_root}/target/release/openshell" \
|
|
OPENSHELL_GATEWAY_BINARY="${repo_root}/target/release/openshell-gateway" \
|
|
OPENSHELL_PROVER_BINARY="${repo_root}/target/release/openshell-prover" \
|
|
OPENSHELL_DRIVER_VM_BINARY="${repo_root}/target/release/openshell-driver-vm" \
|
|
OPENSHELL_DEB_VERSION="$VERSION" \
|
|
OPENSHELL_DEB_ARCH="$ARCH" \
|
|
OPENSHELL_OUTPUT_DIR="$OUTPUT_DIR" \
|
|
"${repo_root}/tasks/scripts/package-deb.sh"
|
|
|
|
deb_path="${OUTPUT_DIR}/openshell_${VERSION}_${ARCH}.deb"
|
|
case "$deb_path" in
|
|
/*) ;;
|
|
*) deb_path="${repo_root}/${deb_path}" ;;
|
|
esac
|
|
|
|
echo "==> Installing ${deb_path}"
|
|
sudo dpkg -i "$deb_path"
|
|
|
|
openshell --version
|
|
openshell-gateway --version
|
|
openshell-prover --version
|
|
|
|
echo "==> Starting user gateway service"
|
|
systemctl --user daemon-reload
|
|
systemctl --user enable --now openshell-gateway
|
|
systemctl --user is-active --quiet openshell-gateway
|
|
|
|
echo "==> Registering local gateway"
|
|
remove_existing_gateway_registration
|
|
openshell gateway add "$GATEWAY_ENDPOINT" --local --name "$GATEWAY_NAME"
|