User Story
I'm trying OpenShell locally (0.1.2, Homebrew install on macOS, Docker driver) and experimenting with policy files based on examples/sandbox-policy-quickstart. When a field has the wrong type, for example a quoted port (port: "443"), sandbox create rejects the file but doesn't tell me which field is wrong. A misspelled key in the same file is reported with its exact path, so I expected the same here.
Problem Statement
A type error in an authored policy is reported without the field name or location:
Error: × failed to decode sandbox policy fields
╰─▶ type mismatch: expected unsigned integer, found string
An unknown field in the same file is reported with its full path:
Error: × unknown field 'network_policies.github_api.endpoints[0].prt' in authored policy
sandbox create --policy and openshell-prover check both reproduce the type-mismatch message. From reading the code, policy set (including --global) goes through the same parser.
Impact / Why This Matters
I have to inspect the policy by hand to find the bad field, and there's no line number to go on. Unknown-field errors already report full paths since #3334. Invalid policies are still rejected, so this only affects diagnostics.
I'm happy to send a PR if this is accepted.
Acceptance Criteria
Reproduction Steps
-
Start a local gateway (OpenShell 0.1.2, Docker driver).
-
Save this as policy.yaml:
version: 1
network_policies:
github_api:
name: github-api-readonly
endpoints:
- host: api.github.com
port: "443"
binaries:
- { path: /usr/bin/curl }
-
Run openshell sandbox create --name demo --policy policy.yaml --no-auto-providers --no-tty -- true. The error doesn't name the field.
-
Run openshell-prover check --boundary policy.yaml policy.yaml. It prints the same type-mismatch message.
-
For contrast, change port: "443" to prt: 443 and run step 3 again. The error names network_policies.github_api.endpoints[0].prt.
Environment
- OpenShell: 0.1.2 (Homebrew)
- OS: macOS 26.3 (arm64)
- Runtime: local gateway, Docker driver, Docker Desktop 4.46.0 (Docker Engine 28.4.0)
Suggested UX
Error: × failed to decode sandbox policy fields
╰─▶ network_policies.github_api.endpoints[0].port: type mismatch: expected unsigned integer, found string
User Story
I'm trying OpenShell locally (0.1.2, Homebrew install on macOS, Docker driver) and experimenting with policy files based on
examples/sandbox-policy-quickstart. When a field has the wrong type, for example a quoted port (port: "443"),sandbox createrejects the file but doesn't tell me which field is wrong. A misspelled key in the same file is reported with its exact path, so I expected the same here.Problem Statement
A type error in an authored policy is reported without the field name or location:
An unknown field in the same file is reported with its full path:
sandbox create --policyandopenshell-prover checkboth reproduce the type-mismatch message. From reading the code,policy set(including--global) goes through the same parser.Impact / Why This Matters
I have to inspect the policy by hand to find the bad field, and there's no line number to go on. Unknown-field errors already report full paths since #3334. Invalid policies are still rejected, so this only affects diagnostics.
I'm happy to send a PR if this is accepted.
Acceptance Criteria
network_policies.github_api.endpoints[0].port.Reproduction Steps
Start a local gateway (OpenShell 0.1.2, Docker driver).
Save this as
policy.yaml:Run
openshell sandbox create --name demo --policy policy.yaml --no-auto-providers --no-tty -- true. The error doesn't name the field.Run
openshell-prover check --boundary policy.yaml policy.yaml. It prints the same type-mismatch message.For contrast, change
port: "443"toprt: 443and run step 3 again. The error namesnetwork_policies.github_api.endpoints[0].prt.Environment
Suggested UX