Skip to content

bug: policy type errors don't say which field is wrong #4168

Description

@likun-fang

User Story

I'm trying OpenShell locally (0.1.2, Homebrew install on macOS, Docker driver) and experimenting with policy files based on examples/sandbox-policy-quickstart. When a field has the wrong type, for example a quoted port (port: "443"), sandbox create rejects the file but doesn't tell me which field is wrong. A misspelled key in the same file is reported with its exact path, so I expected the same here.

Problem Statement

A type error in an authored policy is reported without the field name or location:

Error:   × failed to decode sandbox policy fields
  ╰─▶ type mismatch: expected unsigned integer, found string

An unknown field in the same file is reported with its full path:

Error:   × unknown field 'network_policies.github_api.endpoints[0].prt' in authored policy

sandbox create --policy and openshell-prover check both reproduce the type-mismatch message. From reading the code, policy set (including --global) goes through the same parser.

Impact / Why This Matters

I have to inspect the policy by hand to find the bad field, and there's no line number to go on. Unknown-field errors already report full paths since #3334. Invalid policies are still rejected, so this only affects diagnostics.

I'm happy to send a PR if this is accepted.

Acceptance Criteria

  • Type mismatches in nested endpoint fields report the mapping keys and sequence index, e.g. network_policies.github_api.endpoints[0].port.
  • Adding the path keeps the existing type-mismatch message and doesn't append the rejected value or other policy contents.
  • Invalid policies are still rejected, and unknown-field errors keep their current wording.
  • Schema parser tests cover a type error in a nested endpoint field.

Reproduction Steps

  1. Start a local gateway (OpenShell 0.1.2, Docker driver).

  2. Save this as policy.yaml:

    version: 1
    network_policies:
      github_api:
        name: github-api-readonly
        endpoints:
          - host: api.github.com
            port: "443"
        binaries:
          - { path: /usr/bin/curl }
  3. Run openshell sandbox create --name demo --policy policy.yaml --no-auto-providers --no-tty -- true. The error doesn't name the field.

  4. Run openshell-prover check --boundary policy.yaml policy.yaml. It prints the same type-mismatch message.

  5. For contrast, change port: "443" to prt: 443 and run step 3 again. The error names network_policies.github_api.endpoints[0].prt.

Environment

  • OpenShell: 0.1.2 (Homebrew)
  • OS: macOS 26.3 (arm64)
  • Runtime: local gateway, Docker driver, Docker Desktop 4.46.0 (Docker Engine 28.4.0)

Suggested UX

Error:   × failed to decode sandbox policy fields
  ╰─▶ network_policies.github_api.endpoints[0].port: type mismatch: expected unsigned integer, found string

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    state:acceptedA maintainer decided OpenShell should pursue this issue

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions