Skip to content

feat(snap): ship the standalone prover binary in the snap - #3717

Merged
elezar merged 1 commit into
NVIDIA:mainfrom
olivercalder:snap-ship-prover
Oct 2, 2026
Merged

elezar merged 1 commit into
NVIDIA:mainfrom
olivercalder:snap-ship-prover

Conversation

@olivercalder

Copy link
Copy Markdown
Contributor

Summary

Include the openshell-prover binary in the snap package. For now, this is exposed as openshell.prover, but I'll request store approval for the openshell-prover alias once this lands so it should be usable as openshell-prover like the other package formats provide.

Related Issue

No issue required: the snap packaging omitted the prover binary unintentionally, this is a small fix

Changes

  • Include the openshell-prover binary in the snap
  • Adjust tests and documentation to account for it

Testing

  • mise run pre-commit passes
  • Unit tests added/updated
  • E2E tests added/updated (if applicable)

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

@copy-pr-bot

copy-pr-bot Bot commented Sep 25, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@politerealism politerealism left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overview

Fixes an oversight where the Snap package omitted openshell-prover, unlike the Debian/RPM/Homebrew installs. Adds the binary to the snap build/packaging pipeline, exposes it as openshell.prover (pending Snap Store alias approval for openshell-prover), and adds a real policy-containment check to both the release canary and the Nix repro script.

What looks good

  • Minimal permission surface: the new prover app plugs only home (snapcraft.yaml:89-92) — no network, docker, or system-observe — matching the documented claim that the prover "does not connect to the gateway."
  • Guardrail test enforces that scope: tasks/scripts/test-packaging-assets.sh:139-156 parses the prover: block of snapcraft.yaml and fails if it ever gains a broad plug (docker, network, network-bind, log-observe, system-observe), preventing silent scope creep later.
  • Real containment check, not just --version: both release-canary.yml:236-259 and snap-gateway-repro.sh:130-146 write an actual boundary/candidate policy pair and assert result: within_boundary, rather than only checking the binary runs.
  • Alias unavailability handled transparently: docs consistently instruct openshell.prover for Snap users and flag that the openshell-prover alias needs separate Store approval, and the CI/canary scripts correctly use the qualified name rather than the not-yet-available alias.
  • Artifact naming (openshell-prover-${{ matrix.rust_arch }}-unknown-linux-musl) matches the existing convention for the other prebuilt binaries, and docs/tests/CI were all updated together.

No concerns — small, well-scoped fix. Approving.

Comment thread tasks/scripts/test-packaging-assets.sh

@elezar elezar left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed at 0ee6081. The architecture-specific prover artifact is downloaded and staged consistently with the Snapcraft installation and app declaration. Documentation and runtime smoke coverage match the new openshell.prover command. The packaging-assets script passed locally; Debian artifact staging was skipped because dpkg-deb is unavailable, and I did not build or install the Snap. No blocking findings. The overlapping source-text assertions can be addressed in the follow-up PR adding candidate-built Snap tests.

@elezar

elezar commented Oct 2, 2026

Copy link
Copy Markdown
Member

/ok-to-test 0ee6081

Signed-off-by: Oliver Calder <oliver.calder@canonical.com>
Signed-off-by: Evan Lezar <elezar@nvidia.com>

@elezar elezar left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reapproved at b01dd91 after rebasing onto main (8719fc9) and folding the fixup commit. Verified that the resulting patch is identical to the original PR changes. mise run pre-commit and the packaging-assets tests pass. Debian artifact staging remains unverified locally because dpkg-deb is unavailable; I did not build or install the Snap. No blocking findings.

@elezar

elezar commented Oct 2, 2026

Copy link
Copy Markdown
Member

/ok-to-test b01dd91

@elezar
elezar enabled auto-merge October 2, 2026 07:45
@elezar
elezar added this pull request to the merge queue Oct 2, 2026
Merged via the queue into NVIDIA:main with commit 6e865df Oct 2, 2026
94 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants