feat(snap): ship the standalone prover binary in the snap - #3717
Conversation
eb5197c to
874c5b4
Compare
politerealism
left a comment
There was a problem hiding this comment.
Overview
Fixes an oversight where the Snap package omitted openshell-prover, unlike the Debian/RPM/Homebrew installs. Adds the binary to the snap build/packaging pipeline, exposes it as openshell.prover (pending Snap Store alias approval for openshell-prover), and adds a real policy-containment check to both the release canary and the Nix repro script.
What looks good
- Minimal permission surface: the new
proverapp plugs onlyhome(snapcraft.yaml:89-92) — nonetwork,docker, orsystem-observe— matching the documented claim that the prover "does not connect to the gateway." - Guardrail test enforces that scope:
tasks/scripts/test-packaging-assets.sh:139-156parses theprover:block ofsnapcraft.yamland fails if it ever gains a broad plug (docker,network,network-bind,log-observe,system-observe), preventing silent scope creep later. - Real containment check, not just
--version: bothrelease-canary.yml:236-259andsnap-gateway-repro.sh:130-146write an actual boundary/candidate policy pair and assertresult: within_boundary, rather than only checking the binary runs. - Alias unavailability handled transparently: docs consistently instruct
openshell.proverfor Snap users and flag that theopenshell-proveralias needs separate Store approval, and the CI/canary scripts correctly use the qualified name rather than the not-yet-available alias. - Artifact naming (
openshell-prover-${{ matrix.rust_arch }}-unknown-linux-musl) matches the existing convention for the other prebuilt binaries, and docs/tests/CI were all updated together.
No concerns — small, well-scoped fix. Approving.
874c5b4 to
d190b98
Compare
elezar
left a comment
There was a problem hiding this comment.
Reviewed at 0ee6081. The architecture-specific prover artifact is downloaded and staged consistently with the Snapcraft installation and app declaration. Documentation and runtime smoke coverage match the new openshell.prover command. The packaging-assets script passed locally; Debian artifact staging was skipped because dpkg-deb is unavailable, and I did not build or install the Snap. No blocking findings. The overlapping source-text assertions can be addressed in the follow-up PR adding candidate-built Snap tests.
|
/ok-to-test 0ee6081 |
Signed-off-by: Oliver Calder <oliver.calder@canonical.com> Signed-off-by: Evan Lezar <elezar@nvidia.com>
0ee6081 to
b01dd91
Compare
elezar
left a comment
There was a problem hiding this comment.
Reapproved at b01dd91 after rebasing onto main (8719fc9) and folding the fixup commit. Verified that the resulting patch is identical to the original PR changes. mise run pre-commit and the packaging-assets tests pass. Debian artifact staging remains unverified locally because dpkg-deb is unavailable; I did not build or install the Snap. No blocking findings.
|
/ok-to-test b01dd91 |
Summary
Include the
openshell-proverbinary in the snap package. For now, this is exposed asopenshell.prover, but I'll request store approval for theopenshell-proveralias once this lands so it should be usable asopenshell-proverlike the other package formats provide.Related Issue
No issue required: the snap packaging omitted the prover binary unintentionally, this is a small fix
Changes
openshell-proverbinary in the snapTesting
mise run pre-commitpassesChecklist