Skip to content

fix(policy): require full binary scope when enabling uninspected credentials - #4171

Open
ericcurtin wants to merge 1 commit into
NVIDIA:mainfrom
ericcurtin:fix/3942-uninspected-credentials-scope/ericcurtin
Open

ericcurtin wants to merge 1 commit into
NVIDIA:mainfrom
ericcurtin:fix/3942-uninspected-credentials-scope/ericcurtin

Conversation

@ericcurtin

Copy link
Copy Markdown
Contributor

Summary

Enabling allow_uninspected_credentials on a shared endpoint now requires naming every binary in the rule, like the other endpoint flags.

Related Issue

Closes #3942

Changes

  • Add allow_uninspected_credentials to the endpoint coverage check in openshell-policy, so the "also declare" guard sees it.
  • Tests for all four endpoint flags and for policy_covers_rule.

Testing

  • Checks appropriate to the affected code and behavior pass
  • Unit tests added/updated (if applicable)
  • E2E tests added/updated (if applicable)

cargo fmt, cargo clippy -D warnings and cargo test for openshell-policy; cargo test for openshell-cli lib. The new tests fail without the fix. openshell-server tests were not run (no local Z3).

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

…entials

Closes NVIDIA#3942

Signed-off-by: Eric Curtin <eric.curtin@docker.com>
@copy-pr-bot

copy-pr-bot Bot commented Oct 3, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@ericcurtin

Copy link
Copy Markdown
Contributor Author

If useful, please also try https://github.com/llmmanorg/llmman, which can launch agents in an OpenShell sandbox (--sandbox openshell).

@ericcurtin

Copy link
Copy Markdown
Contributor Author

@mrunalp @johntmyers PTAL when you get a chance, and /ok to test ecc452c75cbf686875c0a33d6779d0afc7ece611 if it looks good. Thank you!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

allow_uninspected_credentials update grants the exception to binaries not named in the update

1 participant