mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-04 08:28:19 +08:00
* feat(sandbox): default to official Alpine sandbox image default_sandbox_image() now returns docker.io/library/alpine:3.22, a generic version-qualified official image, so a fresh install no longer depends on the community sandbox image catalog. All compute drivers (docker, podman, kubernetes, vm) inherit this fallback. Part of #3116. Signed-off-by: Akram Signed-off-by: Akram <akram.benaissi@gmail.com> * feat(deploy): default deployment configs to the official Alpine sandbox image Update the shared gateway default_image, Helm chart values, the standalone Kubernetes manifest, and the dev gateway task scripts to use docker.io/library/alpine:3.22 instead of the community base image, consistent with default_sandbox_image(). GPU e2e image-build base is left unchanged (CUDA needs a glibc base). Part of #3116. Signed-off-by: Akram Signed-off-by: Akram <akram.benaissi@gmail.com> * feat(driver): default to numeric non-root identity for USER-less images With the default sandbox image now Alpine, images that declare no OCI USER must start instead of being rejected. When the image declares no USER and the policy requests none, the Podman and Docker drivers now supply a numeric non-root identity (DEFAULT_SANDBOX_UID/GID = 1000) instead of rejecting, matching the numeric-identity behavior of the Kubernetes and VM drivers. The supervisor's resolved-identity path runs the sandbox as a synthesized non-root account without the account existing in the image. Images that declare a USER keep the OCI resolution path unchanged. Part of #3116. Signed-off-by: Akram <akram.benaissi@gmail.com> Signed-off-by: Evan Lezar <elezar@nvidia.com> * test(conformance): use Alpine workload image Signed-off-by: Evan Lezar <elezar@nvidia.com> * refactor(policy): drop community image /app path from default policy The restrictive default policy granted read-only access to /app, a directory that only existed in the community base image. A generic Alpine default has no /app, so remove it. Landlock best-effort already ignores absent paths; this just stops advertising a community-specific layout in the default. Part of #3116. Signed-off-by: Akram Signed-off-by: Akram <akram.benaissi@gmail.com> * docs(config): document Alpine default images Signed-off-by: Evan Lezar <elezar@nvidia.com> * fix(podman): report early sandbox termination Signed-off-by: Evan Lezar <elezar@nvidia.com> * fix(podman): initialize rootless workspace ownership Signed-off-by: Evan Lezar <elezar@nvidia.com> * fix(sandbox): qualify NVIDIA Ubuntu default Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(podman): initialize rootful default workspace Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(sftp): add native sandbox adapter Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sftp): gate runtime helper support to Linux Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sftp): support standard OpenSSH file operations Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sftp): harden rename and special file handling Signed-off-by: Drew Newberry <anewberry@nvidia.com> * refactor(runtime): remove community image dependencies Signed-off-by: Drew Newberry <anewberry@nvidia.com> * test(e2e): build provider readiness tool fixture Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(e2e): use a dedicated Noble fixture for Docker tests Signed-off-by: Evan Lezar <elezar@nvidia.com> --------- Signed-off-by: Akram Signed-off-by: Akram <akram.benaissi@gmail.com> Signed-off-by: Evan Lezar <elezar@nvidia.com> Signed-off-by: Drew Newberry <anewberry@nvidia.com> Co-authored-by: Evan Lezar <elezar@nvidia.com> Co-authored-by: Drew Newberry <anewberry@nvidia.com>
279 lines
9.6 KiB
Rust
279 lines
9.6 KiB
Rust
// SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
// SPDX-License-Identifier: Apache-2.0
|
|
|
|
use std::ffi::OsStr;
|
|
use std::future::Future;
|
|
|
|
use clap_complete::engine::CompletionCandidate;
|
|
use openshell_bootstrap::edge_token::load_edge_token;
|
|
use openshell_bootstrap::oidc_token::{is_token_expired, load_oidc_token, store_oidc_token};
|
|
use openshell_bootstrap::{list_gateways, load_active_gateway, load_gateway_metadata};
|
|
use openshell_core::ObjectName;
|
|
use openshell_core::auth::EdgeAuthInterceptor;
|
|
use openshell_core::proto::open_shell_client::OpenShellClient;
|
|
use openshell_core::proto::{ListProvidersRequest, ListSandboxesRequest, ListWorkspacesRequest};
|
|
use tonic::service::interceptor::InterceptedService;
|
|
use tonic::transport::Channel;
|
|
|
|
use crate::oidc_auth::oidc_refresh_token;
|
|
use crate::tls::{TlsOptions, build_channel};
|
|
|
|
/// Complete gateway names from local metadata files (no network call).
|
|
pub fn complete_gateway_names(_prefix: &OsStr) -> Vec<CompletionCandidate> {
|
|
let Ok(gateways) = list_gateways() else {
|
|
return Vec::new();
|
|
};
|
|
gateways
|
|
.into_iter()
|
|
.map(|g| CompletionCandidate::new(g.name))
|
|
.collect()
|
|
}
|
|
|
|
/// Complete sandbox names by querying the active gateway.
|
|
pub fn complete_sandbox_names(_prefix: &OsStr) -> Vec<CompletionCandidate> {
|
|
blocking_complete(async {
|
|
let (endpoint, gateway_name) = resolve_active_gateway()?;
|
|
let mut client = completion_grpc_client(&endpoint, &gateway_name).await?;
|
|
let response = client
|
|
.list_sandboxes(ListSandboxesRequest {
|
|
page_size: 200,
|
|
page_token: String::new(),
|
|
label_selector: String::new(),
|
|
workspace_scope: Some(openshell_core::proto::workspace_selector(
|
|
workspace_from_args(),
|
|
)),
|
|
})
|
|
.await
|
|
.ok()?;
|
|
Some(
|
|
response
|
|
.into_inner()
|
|
.sandboxes
|
|
.into_iter()
|
|
.map(|s| CompletionCandidate::new(s.object_name()))
|
|
.collect(),
|
|
)
|
|
})
|
|
}
|
|
|
|
/// Complete provider names by querying the active gateway.
|
|
pub fn complete_provider_names(_prefix: &OsStr) -> Vec<CompletionCandidate> {
|
|
blocking_complete(async {
|
|
let (endpoint, gateway_name) = resolve_active_gateway()?;
|
|
let mut client = completion_grpc_client(&endpoint, &gateway_name).await?;
|
|
let response = client
|
|
.list_providers(ListProvidersRequest {
|
|
page_size: 200,
|
|
page_token: String::new(),
|
|
workspace_scope: Some(openshell_core::proto::workspace_selector(
|
|
workspace_from_args(),
|
|
)),
|
|
})
|
|
.await
|
|
.ok()?;
|
|
Some(
|
|
response
|
|
.into_inner()
|
|
.providers
|
|
.into_iter()
|
|
.map(|p| CompletionCandidate::new(p.object_name()))
|
|
.collect(),
|
|
)
|
|
})
|
|
}
|
|
|
|
/// Complete workspace names by querying the active gateway.
|
|
pub fn complete_workspace_names(_prefix: &OsStr) -> Vec<CompletionCandidate> {
|
|
blocking_complete(async {
|
|
let (endpoint, gateway_name) = resolve_active_gateway()?;
|
|
let mut client = completion_grpc_client(&endpoint, &gateway_name).await?;
|
|
let response = client
|
|
.list_workspaces(ListWorkspacesRequest {
|
|
page_size: 200,
|
|
page_token: String::new(),
|
|
label_selector: String::new(),
|
|
})
|
|
.await
|
|
.ok()?;
|
|
Some(
|
|
response
|
|
.into_inner()
|
|
.workspaces
|
|
.into_iter()
|
|
.map(|w| CompletionCandidate::new(w.object_name()))
|
|
.collect(),
|
|
)
|
|
})
|
|
}
|
|
|
|
fn workspace_from_args() -> String {
|
|
let args: Vec<String> = std::env::args().collect();
|
|
for (i, arg) in args.iter().enumerate() {
|
|
if arg == "--workspace" {
|
|
if let Some(val) = args.get(i + 1) {
|
|
return val.clone();
|
|
}
|
|
} else if let Some(val) = arg.strip_prefix("--workspace=") {
|
|
return val.to_string();
|
|
}
|
|
}
|
|
std::env::var("OPENSHELL_WORKSPACE").unwrap_or_else(|_| "default".to_string())
|
|
}
|
|
|
|
fn resolve_active_gateway() -> Option<(String, String)> {
|
|
let name = std::env::var("OPENSHELL_GATEWAY")
|
|
.ok()
|
|
.filter(|v| !v.trim().is_empty())
|
|
.or_else(load_active_gateway)?;
|
|
let metadata = load_gateway_metadata(&name).ok()?;
|
|
Some((metadata.gateway_endpoint, name))
|
|
}
|
|
|
|
async fn completion_grpc_client(
|
|
server: &str,
|
|
gateway_name: &str,
|
|
) -> Option<OpenShellClient<InterceptedService<Channel, EdgeAuthInterceptor>>> {
|
|
let mut tls_opts = TlsOptions::default().with_gateway_name(gateway_name);
|
|
tls_opts.gateway_insecure = std::env::var("OPENSHELL_GATEWAY_INSECURE")
|
|
.is_ok_and(|v| !v.is_empty() && v != "0" && v != "false");
|
|
|
|
if let Ok(meta) = load_gateway_metadata(gateway_name) {
|
|
match meta.auth_mode.as_deref() {
|
|
Some("oidc") => {
|
|
if let Some(bundle) = load_oidc_token(gateway_name) {
|
|
if is_token_expired(&bundle) {
|
|
match oidc_refresh_token(
|
|
&bundle,
|
|
meta.oidc_scopes.as_deref(),
|
|
tls_opts.gateway_insecure,
|
|
)
|
|
.await
|
|
{
|
|
Ok(refreshed) => {
|
|
let _ = store_oidc_token(gateway_name, &refreshed);
|
|
tls_opts.oidc_token = Some(refreshed.access_token);
|
|
}
|
|
Err(_) => {
|
|
tls_opts.oidc_token = Some(bundle.access_token);
|
|
}
|
|
}
|
|
} else {
|
|
tls_opts.oidc_token = Some(bundle.access_token);
|
|
}
|
|
}
|
|
}
|
|
Some("cloudflare_jwt") => {
|
|
if let Some(token) = load_edge_token(gateway_name) {
|
|
tls_opts.edge_token = Some(token);
|
|
}
|
|
}
|
|
_ => {}
|
|
}
|
|
}
|
|
|
|
let channel = build_channel(server, &tls_opts).await.ok()?;
|
|
let interceptor = EdgeAuthInterceptor::new(
|
|
tls_opts.oidc_token.as_deref(),
|
|
tls_opts.edge_token.as_deref(),
|
|
)
|
|
.ok()?;
|
|
Some(OpenShellClient::with_interceptor(channel, interceptor))
|
|
}
|
|
|
|
/// Run an async future on a dedicated thread to avoid nested tokio runtime panics.
|
|
///
|
|
/// `#[tokio::main]` creates a runtime, and `CompleteEnv::complete()` runs synchronously
|
|
/// inside its `block_on`. Creating another runtime on the same thread would panic, so
|
|
/// we spawn a new OS thread with its own single-threaded runtime.
|
|
fn blocking_complete<F>(future: F) -> Vec<CompletionCandidate>
|
|
where
|
|
F: Future<Output = Option<Vec<CompletionCandidate>>> + Send + 'static,
|
|
{
|
|
std::thread::spawn(move || {
|
|
let rt = tokio::runtime::Builder::new_current_thread()
|
|
.enable_all()
|
|
.build()
|
|
.ok()?;
|
|
rt.block_on(future)
|
|
})
|
|
.join()
|
|
.ok()
|
|
.flatten()
|
|
.unwrap_or_default()
|
|
}
|
|
|
|
#[cfg(test)]
|
|
mod tests {
|
|
use super::*;
|
|
use crate::TEST_ENV_LOCK;
|
|
use openshell_bootstrap::{GatewayMetadata, store_gateway_metadata};
|
|
use temp_env::with_vars;
|
|
|
|
fn with_isolated_cli_env<F: FnOnce()>(tmp: &std::path::Path, f: F) {
|
|
let _guard = TEST_ENV_LOCK
|
|
.lock()
|
|
.unwrap_or_else(std::sync::PoisonError::into_inner);
|
|
let tmp = tmp.to_string_lossy().into_owned();
|
|
with_vars(
|
|
[
|
|
("XDG_CONFIG_HOME", Some(tmp.as_str())),
|
|
("OPENSHELL_SYSTEM_GATEWAY_DIR", Some(tmp.as_str())),
|
|
("OPENSHELL_GATEWAY", None::<&str>),
|
|
],
|
|
f,
|
|
);
|
|
}
|
|
|
|
#[test]
|
|
fn gateway_completer_returns_empty_when_no_config() {
|
|
let temp = tempfile::tempdir().unwrap();
|
|
with_isolated_cli_env(temp.path(), || {
|
|
let result = complete_gateway_names(OsStr::new(""));
|
|
assert!(result.is_empty());
|
|
});
|
|
}
|
|
|
|
#[test]
|
|
fn sandbox_completer_returns_empty_when_no_active_gateway() {
|
|
let temp = tempfile::tempdir().unwrap();
|
|
with_isolated_cli_env(temp.path(), || {
|
|
let result = complete_sandbox_names(OsStr::new(""));
|
|
assert!(result.is_empty());
|
|
});
|
|
}
|
|
|
|
#[test]
|
|
fn provider_completer_returns_empty_when_no_active_gateway() {
|
|
let temp = tempfile::tempdir().unwrap();
|
|
with_isolated_cli_env(temp.path(), || {
|
|
let result = complete_provider_names(OsStr::new(""));
|
|
assert!(result.is_empty());
|
|
});
|
|
}
|
|
|
|
#[test]
|
|
fn gateway_completer_returns_registered_gateways() {
|
|
let temp = tempfile::tempdir().unwrap();
|
|
with_isolated_cli_env(temp.path(), || {
|
|
store_gateway_metadata(
|
|
"alpha",
|
|
&GatewayMetadata {
|
|
name: "alpha".to_string(),
|
|
gateway_endpoint: "https://alpha.example.com".to_string(),
|
|
is_remote: true,
|
|
auth_mode: Some("cloudflare_jwt".to_string()),
|
|
..Default::default()
|
|
},
|
|
)
|
|
.unwrap();
|
|
|
|
let result = complete_gateway_names(OsStr::new("a"));
|
|
assert!(
|
|
result
|
|
.iter()
|
|
.any(|candidate| candidate.get_value().to_string_lossy() == "alpha")
|
|
);
|
|
});
|
|
}
|
|
}
|