Repository navigation
Conversation
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
3be2384 to
3cf6200
Compare
|
Label |
PR Review StatusThe independent code review found no blocking defects in the unsafe-code cleanup. Drew, I checked your CI follow-up: the macOS lint and both Linux Rust test jobs now pass on this head, and the full E2E suite is green. I applied Blocking findings: None. Carried findings: None. Gator metadata
|
0690751 to
34d4bab
Compare
PR Review StatusDrew, I checked your latest platform-specific SSH lint fix against the four errors from the earlier Windows run. The independent follow-up review of that change and the author-only rebase adaptations found no blocking defects; the prior review remains satisfied. Branch Checks, Helm Lint, Trivy Changes and DCO pass on this head. E2E is running. I restored Action required: The sandbox operator must activate the approved policy proposal Blocking findings: None. Carried findings: None. Gator metadata
|
Blocker Follow-Up NudgeThis PR still needs follow-up more than 48 business hours after the last Gator handoff. Next action: @drew, please resolve the merge conflicts and work with maintainers to restore the required Windows and E2E gates. The Windows failure is in unchanged MXC code, so please coordinate its upstream fix; the E2E failures still need diagnosis. |
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
34d4bab to
d5c466d
Compare
PR Review StatusDrew, I checked the latest rebase adaptations against the previously reviewed patch series. The independent follow-up review found no blocking defects, and the earlier review remains satisfied. The merge conflicts and E2E failures noted in the previous nudge are cleared on this head. Branch Checks, Helm Lint, Trivy Changes, DCO and E2E pass, and maintainer approval is present. I restored Blocking findings: None. Carried findings: None. Gator metadata
|
Summary
Reduce Rust unsafe syntax sites from 503 to 344 (159 removed), and confine the remaining sites to
openshell-sandbox(238),openshell-driver-vm(56), and the explicitly excluded Windows MXC driver (50). Replace ordinary descriptor, resource, identity and build configuration operations with safe APIs while retaining explicit kernel ABI, fork/pre-exec and FFI boundaries.Related Issue
Directly requested maintainer cleanup. No matching accepted issue is currently linked. This is a draft because moving the Linux mechanism module across crate boundaries requires an accepted issue reference before the PR is ready.
Changes
openshell-isolation-interface::linuxtoopenshell-sandbox::linux; migrate all in-repository consumers and leave the backend interface dependency-light.forbid(unsafe_code)to the CLI, supervisor, sandbox backend and isolation interface targets, and network supervisor library.PROTOC_INCLUDEin a child process rather than mutating build-script globals.plans/unsafe-catalog/directory; the current crate summary is below.Counts include unsafe blocks, functions, implementations and FFI function-pointer declarations, not individual syscalls. Relocated sites are not counted as removals. Generated Go unsafe calls are unchanged.
Compatibility details: external Rust users of
openshell_isolation_interface::linuxmust migrate their imports. The private driver/supervisor flag is now--parent-liveness-stdin, so those binaries must be built together. Tokio foreground signal handlers remain installed for the process lifetime. TheIsolationBackendcontract and public wire protocol are unchanged.Testing
mise run pre-commitpasses, including workspace and sandbox perf-harness lint checks.RUST_TEST_THREADS=4 mise run testpasses after the final descriptor batch. The initial run had two supervisor-network plaintext failures; all five plaintext tests passed on a serial retry, and both failures also passed in the full-suite retry. Their initial failure cause is not proven.OPENSHELL_E2E_DOCKER_TEST=transparent_tcp mise run e2e:dockerpasses after the final batch: six CLI conformance scenarios and native TCP policy-DNS/fail-closed coverage. The Podman-specific scenario is skipped in the Docker lane.git diff --checkverified.mise run ci: attempted, but stopped at 20 Go lint errors in unchanged SDK files (5 errcheck, 12 revive, 3 staticcheck).Checklist
Rebase validation
Rebased onto main at
a48920ac0. Retained main's driver-independent mTLS/bearer TLS behavior, bearer-passthrough exposure assertions, 0600 provider memfd metadata and new upload/broker tests. Pre-commit and Docker transparent-TCP/conformance passed after rebase. The first full run timed out in main's new metadata-loopback broker test; that test passed alone on retry. The fullRUST_TEST_THREADS=4 mise run testretry passed after the heavy Docker builds completed, including the metadata-loopback test and updated mTLS tests.CI follow-up
Commit
06907512efixes the macOS dead-code lint by compiling the boundary environment installer only on Linux, and fixes both Linux nextest signal-probe failures by publishing readiness from an executed Rust workload rather than checking the externalsleepexecutable filename. The old failure was reproduced with a renamed binary; the revised fixture passes nextest with that PATH. Pre-commit and the full local test suite passed. Remote verification on commit06907512epassed all three previously failing jobs in Branch Checks run 37051739763: macOS Rust lint and both Linux Rust test jobs. Other checks are still running; no failures are currently reported.