mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-03 16:11:17 +08:00
* fix(providers): allow git clone/fetch via default GitHub provider The github.com:443 git-transport endpoint used the read-only access preset, which expands to GET/HEAD/OPTIONS only. Git smart HTTP requires a POST to */git-upload-pack for clone and fetch, so the L7 proxy denied those operations and `gh repo clone` / `git clone https://...` failed. Replace the preset with explicit rules that permit the read-only methods plus POST */git-upload-pack, so clone/fetch work while push (git-receive-pack) stays blocked. Enabling push still requires an explicit policy proposal. Why allowing this POST is still read-only: in git's smart HTTP protocol POST is an RPC transport, not a write. A clone/fetch does GET */info/refs (ref discovery) followed by POST */git-upload-pack, whose body is only the client's want/have negotiation; the server responds with a packfile and nothing on the server is modified (data flows server -> client). The service names are from the server's perspective: git-upload-pack = the server uploads a pack to the client (a read/ download), while git-receive-pack = the server receives a pack from the client (the actual write/push). The new rule is scoped to */git-upload-pack only, so push (git-receive-pack) and arbitrary POSTs to github.com remain denied. Add a provider-profile regression test and a rego enforcement test covering ref discovery, upload-pack (allowed), and receive-pack (denied). Closes #1769 Signed-off-by: Russell Bryant <rbryant@redhat.com> * test(providers): strengthen git-transport regression and add clone e2e Pin the exact allowed rule set for the built-in github git-transport endpoint in both the provider-profile and composed-policy tests, so a broader or additional POST rule (e.g. POST **) that could enable push via git-receive-pack fails the test instead of passing a substring check. Add an e2e test that attaches the built-in github provider and clones a public repo over HTTPS, exercising provider attachment, effective-policy composition, TLS interception, and real git behavior. Update the Providers V2 docs so the github.com git-transport endpoint shows explicit clone/fetch rules instead of the stale read-only preset. Refs #1769 Signed-off-by: Russell Bryant <rbryant@redhat.com> * test(providers): isolate providers_v2 mutation in clone e2e The clone e2e enables the gateway-global providers_v2_enabled setting. Restore its exact prior value (or absence) captured via GetGatewayConfig instead of unconditionally deleting it, and serialize the mutation across xdist workers with an exclusive file lock on the run's shared base temp dir, so a shared or pre-configured gateway is left untouched and parallel workers cannot race the read-modify-restore. Refs #1769 Signed-off-by: Russell Bryant <rbryant@redhat.com> * test(providers): serialize providers_v2 mutation with a suite-wide guard The clone e2e's per-fixture lock only coordinated fixtures that acquired it; other xdist workers hit the same gateway without it and could observe the transiently-enabled providers_v2_enabled global during their own sandbox creation (CWE-362). Add an autouse readers-writer guard in conftest: every test holds a shared lock on the gateway config, and a test marked exclusive_gateway_config holds an exclusive lock. Mark the clone test exclusive so no other worker is mid-test while it enables and restores the gateway-global setting. Exact prior-value restoration is retained. Refs #1769 Signed-off-by: Russell Bryant <rbryant@redhat.com> --------- Signed-off-by: Russell Bryant <rbryant@redhat.com>
47 lines
1.5 KiB
YAML
47 lines
1.5 KiB
YAML
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
|
|
id: github
|
|
display_name: GitHub
|
|
description: GitHub API and Git operations
|
|
category: source_control
|
|
credentials:
|
|
- name: api_token
|
|
description: GitHub token
|
|
env_vars: [GITHUB_TOKEN, GH_TOKEN]
|
|
required: true
|
|
auth_style: bearer
|
|
header_name: authorization
|
|
discovery:
|
|
credentials: [api_token]
|
|
endpoints:
|
|
# api.github.com is the REST API surface. Defaults to read-only —
|
|
# writes require an explicit policy proposal so the agentic loop +
|
|
# prover can audit each capability change.
|
|
- host: api.github.com
|
|
port: 443
|
|
protocol: rest
|
|
access: read-only
|
|
enforcement: enforce
|
|
- host: api.github.com
|
|
port: 443
|
|
path: /graphql
|
|
protocol: graphql
|
|
access: read-only
|
|
enforcement: enforce
|
|
# github.com is the git transport (clone / fetch by default). Git smart
|
|
# HTTP needs POST to */git-upload-pack for clone/fetch, which the
|
|
# read-only preset (GET/HEAD/OPTIONS) blocks. Spell the rules out so
|
|
# clone/fetch works while push (git-receive-pack) stays denied — enabling
|
|
# push requires an explicit policy proposal.
|
|
- host: github.com
|
|
port: 443
|
|
protocol: rest
|
|
enforcement: enforce
|
|
rules:
|
|
- allow: { method: GET, path: "**" }
|
|
- allow: { method: HEAD, path: "**" }
|
|
- allow: { method: OPTIONS, path: "**" }
|
|
- allow: { method: POST, path: "/**/git-upload-pack" }
|
|
binaries: [/usr/bin/gh, /usr/local/bin/gh, /usr/bin/git, /usr/local/bin/git]
|