mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-04 16:39:35 +08:00
* feat(policy): add validation layer to reject unsafe sandbox policies Add policy validation that checks for root process identity, path traversal sequences, overly broad filesystem paths, and exceeding filesystem rule limits. Validation runs at three entry points: disk-loaded YAML policies (fallback to restrictive default on violation), gRPC CreateSandbox, and gRPC UpdateSandboxPolicy (returns INVALID_ARGUMENT). Filesystem paths are normalized before storage to collapse traversal components. Closes #33 * fix(e2e): correct policy update test to match immutable field behavior The update policy test was asserting on validation errors for fields (process, filesystem) that are immutable on live sandboxes. The server rejects changes to these fields before validation runs. Updated the test to verify the immutability guard instead. --------- Co-authored-by: John Myers <johntmyers@users.noreply.github.com>