Skip to content

fix(providers): stabilize provider environment revisions - #4122

Merged
drew merged 1 commit into
mainfrom
fix/3929-stabilize-provider-env-revision/drew
Oct 2, 2026
Merged

drew merged 1 commit into
mainfrom
fix/3929-stabilize-provider-env-revision/drew

Conversation

@drew

@drew drew commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Summary

Make provider profile revision hashing independent of protobuf map iteration order. Multiple profile annotations previously caused an unchanged sandbox's provider environment revision to change between polls, preventing stable credential installation.

Related Issue

Closes #3929

Changes

  • Canonicalize profile annotations and nested endpoint maps before hashing user profile sources and effective profiles.
  • Reuse the existing canonical policy rule encoding for endpoint maps.
  • Add regression tests for repeated profile snapshots, config and provider environment revision agreement, and nested endpoint map changes.

Testing

  • cargo test -p openshell-server --lib provider_profile_sources::tests:: (45 passed)
  • cargo test -p openshell-server --lib annotated_profile_has_stable_provider_environment_revision
  • cargo clippy -p openshell-server --lib --tests -- -D warnings
  • cargo fmt --all -- --check
  • Repository commit hooks passed
  • Kubernetes sandbox e2e validation

Checklist

  • Follows Conventional Commits
  • Commit is signed off (DCO)
  • Architecture docs updated (not applicable)

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
@drew
drew requested review from a team, derekwaynecarr, mrunalp and sjenning as code owners October 2, 2026 15:07
@johntmyers johntmyers added the test:e2e Requires end-to-end coverage label Oct 2, 2026

@johntmyers johntmyers left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

PR Review Status

The initial review found no blocking issues in the profile revision hashing fix and its regression tests. This is a focused fix for #3929; E2E coverage is still required before the testing handoff is complete.

Blocking findings: No blocking findings remain.

Carried findings: None.

Gator metadata
  • Validation: Focused gateway provider revision correctness fix for #3929, authored by a verified maintainer.
  • Docs: No new user-facing configuration or workflow; existing behavior is restored.
  • Checks: Branch Checks, Helm Lint, Trivy Changes, DCO, and vouch checks passed on the current head.
  • E2E: Applied test:e2e; the earlier run skipped runtime suites. Awaiting E2E Label Help instructions and current-head runtime dispatch.
  • Head SHA: 01028980b10184ed824699844512a91fc0bbb599
  • Base SHA: 36819f476d14e59f29fa6e50ef6c829976ac41d0
  • Merge base SHA: 6e369f23964ad7c5a1cbc243340cfb723dd263f4
  • Patch ID: 5280512fd0f35430a22d6b2f34323febf6c544be
  • Gator payload: 10
  • Review mode: initial
  • Previous reviewed SHA: none
  • Review budget exhausted: no
  • Maintainer decision required: no
  • Next state: gator:in-review

@johntmyers johntmyers added the gator:in-review Gator is reviewing or awaiting PR review feedback label Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Label test:e2e applied for 0102898. Open the existing run and click Re-run all jobs to execute with the label set. The run will execute the standard E2E suite after building the required gateway, sandbox, and supervisor images once. The matching required CI gate status on this PR will flip green automatically once the run finishes.

@johntmyers johntmyers added gator:blocked Gator is blocked by process or repository gates gator:watch-pipeline Gator is monitoring PR CI/CD status and removed gator:in-review Gator is reviewing or awaiting PR review feedback gator:blocked Gator is blocked by process or repository gates labels Oct 2, 2026
@johntmyers johntmyers added gator:merge-ready and removed gator:watch-pipeline Gator is monitoring PR CI/CD status labels Oct 2, 2026
@drew
drew added this pull request to the merge queue Oct 2, 2026
Merged via the queue into main with commit ec49209 Oct 2, 2026
171 of 174 checks passed
@drew
drew deleted the fix/3929-stabilize-provider-env-revision/drew branch October 2, 2026 18:55
@johntmyers

Copy link
Copy Markdown
Collaborator

gator-agent

Monitoring Complete

Monitoring is complete because this PR has merged.

Final status: The existing current-head review found no blocking findings, and the PR reached gator:merge-ready with maintainer approval before merging.

I removed the active gator:* label because there is nothing left for gator to monitor on this PR.

Gator metadata
  • Head SHA: 01028980b10184ed824699844512a91fc0bbb599
  • Gator payload: 10

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

test:e2e Requires end-to-end coverage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(gateway): provider environment revision is not deterministic when a provider profile has several annotations

2 participants