Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
1fff8b9
feat(podman): honor OCI image working directories (#3982)
matthewgrossman Oct 7, 2026
8aa5846
fix(cli): preserve existing directories during single-file upload (#4…
shiju-nv Oct 7, 2026
a4954d3
fix(auth): match Bearer scheme case-insensitively (#4187)
ericcurtin Oct 7, 2026
249c6e7
fix(ci): retain sanitized Codex scan diagnostics on failure (#4304)
alangou Oct 7, 2026
ffb5306
fix(providers): prepare dynamic credentials across HTTP relay paths (…
shiju-nv Oct 7, 2026
5cfb0e2
fix(policy): name the field in policy type errors (#4174)
ericcurtin Oct 8, 2026
3660394
Merge remote-tracking branch 'upstream/main'
moulalis Oct 8, 2026
277f922
fix(sandbox): remove privileged control socket filters (#4279)
FrostGod Oct 8, 2026
46d7361
Merge remote-tracking branch 'upstream/main'
moulalis Oct 8, 2026
709500a
Merge remote-tracking branch 'upstream/main'
moulalis Oct 8, 2026
9b5bcdd
fix(ha): keep sandboxes ready across gateway pod rolls (#4321)
pimlock Oct 8, 2026
67adcf1
feat(ocsf): emit full JSON records to supervisor stderr (#4323)
johntmyers Oct 8, 2026
a1fde04
Merge remote-tracking branch 'upstream/main'
moulalis Oct 8, 2026
7419672
Merge remote-tracking branch 'upstream/main'
moulalis Oct 8, 2026
207485c
Merge remote-tracking branch 'upstream/main'
moulalis Oct 8, 2026
81f712e
fix(drivers): validate vendor-agnostic CDI device names (#4306)
alangou Oct 8, 2026
0e981be
fix(gator): handle oversized PR diffs in review ledger (#4309)
johntmyers Oct 8, 2026
f2c002e
CARRY: fix(konflux): build Rust images on the Red Hat rust-builder image
andre-motta Oct 8, 2026
e92aaa4
Merge remote-tracking branch 'upstream/main'
moulalis Oct 8, 2026
3f630ee
Merge pull request #90 from opendatahub-io/fix/konflux-rust-builder/a…
EmilienM Oct 8, 2026
616024f
fix(vm): bump libkrun to v1.19.6 (#4282)
benoitf Oct 8, 2026
aad551d
chore(vm): bump libkrunfw to v5.6.2 (#4285)
benoitf Oct 8, 2026
fe3942f
feat(helm): migrate gateway configuration to gatewayConfig (#3384)
gmenher Oct 8, 2026
f745aa4
test(supervisor-network): isolate metadata OCSF capture (#4318)
grs Oct 8, 2026
c285934
Merge remote-tracking branch 'upstream/main'
moulalis Oct 8, 2026
1431e42
Merge remote-tracking branch 'upstream/main'
moulalis Oct 8, 2026
05778ec
Merge remote-tracking branch 'upstream/main'
moulalis Oct 9, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .agents/skills/launch-openshell-gator/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -282,6 +282,10 @@ The launcher streams image-build and provisioning output to the terminal. Import
- `/sandbox/.openshell-agent/history.jsonl` contains the latest 100 supervisor transitions, including active-cycle starts and completed cycle results.
- `openshell-agent: still running watch cycle ...` is a heartbeat during long active model cycles.
- `review_feedback_lookup_failed` means Gator could not build the required cross-SHA feedback ledger and deliberately skipped a context-free review.
- Large PRs use local Git trees for patch identity instead of GitHub's
size-limited full-diff endpoint. An unavailable patch ID alone does not block
the ledger; it disables rebase-equivalence shortcuts. Reviewers should inspect
oversized changes file-by-file locally.

### Inspect Active Sandboxes

Expand Down
16 changes: 16 additions & 0 deletions .agents/skills/watch-github-actions/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -125,6 +125,22 @@ gh run list --json databaseId,status,headBranch,url --jq '.[] | {id: .databaseId

## View Job Logs

For `Codex Security`, an exit code of 2 with partial coverage is an incomplete
scan, not a HIGH/CRITICAL threshold failure. Check the execution diagnostics in
the job summary and the `codex-security-diagnostics-<run>-<attempt>` artifact on
scan failure. It contains fixed status values, aggregate coverage counts, and
disk space before, after, and the minimum sampled every five seconds. Missing
coverage or manifest documents indicate no readable final report was available;
deferred items or surfaces needing follow-up can explain partial coverage.
Sampling cannot rule out a disk spike between samples.

Artifacts and logs in this public repository are public. Never upload the raw
scan directory, `report.md`, `coverage.json`, findings, agent state, or scanner
logs. Coverage reasons and notes are free text and may disclose vulnerabilities.
The public diagnostic intentionally omits them; detailed review needs an
approved private destination. Helpers must come from the workflow revision,
not from the candidate under scan.

`setup-nix` retries development-shell preparation once when `prepare-shell`
is enabled. Inspect both attempts in the job log; `setup-rust` assumes the
shell has already been prepared. Cargo, lint, and test commands are not retried.
Expand Down
22 changes: 19 additions & 3 deletions .github/workflows/codex-security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -145,12 +145,13 @@ jobs:
sparse-checkout: tasks/scripts
persist-credentials: false

- name: Stage the range resolver
- name: Stage trusted scan helpers
run: |
set -euo pipefail
install -d -m 700 "$RUNNER_TEMP/range-resolver"
cp workflow-revision/tasks/scripts/release.py \
workflow-revision/tasks/scripts/codex_security_range.py \
workflow-revision/tasks/scripts/codex_security_diagnostics.py \
"$RUNNER_TEMP/range-resolver/"
rm -rf workflow-revision

Expand Down Expand Up @@ -185,6 +186,7 @@ jobs:
python3 "$RUNNER_TEMP/range-resolver/codex_security_range.py" "${args[@]}"

- name: Scan changes since the previous stable
id: scan
env:
BASE_SHA: ${{ steps.range.outputs.base_sha }}
CODEX_SECURITY_BIN: ${{ runner.temp }}/codex-security/node_modules/.bin/codex-security
Expand All @@ -206,7 +208,10 @@ jobs:
exit 2
fi

"$CODEX_SECURITY_BIN" scan . \
python3 "$RUNNER_TEMP/range-resolver/codex_security_diagnostics.py" \
--scan-dir "$SCAN_DIR" \
--output "$RUNNER_TEMP/codex-security-diagnostics.json" \
-- "$CODEX_SECURITY_BIN" scan . \
"${target_args[@]}" \
--auth api-key \
--model "$NVIDIA_INFERENCE_MODEL" \
Expand All @@ -220,7 +225,18 @@ jobs:
--codex "features.multi_agent_v2.max_concurrent_threads_per_session=$CODEX_SECURITY_MAX_CONCURRENT_THREADS" \
--codex 'approval_policy="never"' \
--output-dir "$SCAN_DIR" \
--headless > /dev/null
--headless

# Actions artifacts in this public repository are publicly downloadable.
# Publish only the helper's allowlisted projection, never SCAN_DIR or state.
- name: Upload public execution diagnostics on failure
if: ${{ failure() && steps.scan.outcome == 'failure' }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: codex-security-diagnostics-${{ github.run_id }}-${{ github.run_attempt }}
path: ${{ runner.temp }}/codex-security-diagnostics.json
if-no-files-found: warn
retention-days: 7

- name: Export SARIF
env:
Expand Down
4 changes: 2 additions & 2 deletions .tekton/odh-openshell-cli-push.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -39,8 +39,8 @@ spec:
value: |
[
{"type": "cargo", "path": "."},
{"type": "rpm", "path": "deploy/konflux/cli"},
{"type": "generic", "path": "deploy/konflux/cli", "lockfile": "generic-fetcher.yaml"}
{"type": "cargo", "path": "deploy/konflux/cargo-auditable"},
{"type": "rpm", "path": "deploy/konflux/cli"}
]
pipelineRef:
resolver: git
Expand Down
4 changes: 2 additions & 2 deletions .tekton/odh-openshell-cli-tag.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -40,8 +40,8 @@ spec:
value: |
[
{"type": "cargo", "path": "."},
{"type": "rpm", "path": "deploy/konflux/cli"},
{"type": "generic", "path": "deploy/konflux/cli", "lockfile": "generic-fetcher.yaml"}
{"type": "cargo", "path": "deploy/konflux/cargo-auditable"},
{"type": "rpm", "path": "deploy/konflux/cli"}
]
- name: build-args
value:
Expand Down
4 changes: 2 additions & 2 deletions .tekton/odh-openshell-gateway-push.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -39,8 +39,8 @@ spec:
value: |
[
{"type": "cargo", "path": "."},
{"type": "rpm", "path": "deploy/konflux/gateway"},
{"type": "generic", "path": "deploy/konflux/gateway", "lockfile": "generic-fetcher.yaml"}
{"type": "cargo", "path": "deploy/konflux/cargo-auditable"},
{"type": "rpm", "path": "deploy/konflux/gateway"}
]
pipelineRef:
resolver: git
Expand Down
4 changes: 2 additions & 2 deletions .tekton/odh-openshell-gateway-tag.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -40,8 +40,8 @@ spec:
value: |
[
{"type": "cargo", "path": "."},
{"type": "rpm", "path": "deploy/konflux/gateway"},
{"type": "generic", "path": "deploy/konflux/gateway", "lockfile": "generic-fetcher.yaml"}
{"type": "cargo", "path": "deploy/konflux/cargo-auditable"},
{"type": "rpm", "path": "deploy/konflux/gateway"}
]
- name: build-args
value:
Expand Down
4 changes: 2 additions & 2 deletions .tekton/odh-openshell-sandbox-push.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -39,8 +39,8 @@ spec:
value: |
[
{"type": "cargo", "path": "."},
{"type": "rpm", "path": "deploy/konflux/sandbox"},
{"type": "generic", "path": "deploy/konflux/sandbox", "lockfile": "generic-fetcher.yaml"}
{"type": "cargo", "path": "deploy/konflux/cargo-auditable"},
{"type": "rpm", "path": "deploy/konflux/sandbox"}
]
pipelineRef:
resolver: git
Expand Down
4 changes: 2 additions & 2 deletions .tekton/odh-openshell-sandbox-tag.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -40,8 +40,8 @@ spec:
value: |
[
{"type": "cargo", "path": "."},
{"type": "rpm", "path": "deploy/konflux/sandbox"},
{"type": "generic", "path": "deploy/konflux/sandbox", "lockfile": "generic-fetcher.yaml"}
{"type": "cargo", "path": "deploy/konflux/cargo-auditable"},
{"type": "rpm", "path": "deploy/konflux/sandbox"}
]
- name: build-args
value:
Expand Down
4 changes: 2 additions & 2 deletions .tekton/odh-openshell-supervisor-push.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -39,8 +39,8 @@ spec:
value: |
[
{"type": "cargo", "path": "."},
{"type": "rpm", "path": "deploy/konflux/supervisor"},
{"type": "generic", "path": "deploy/konflux/supervisor", "lockfile": "generic-fetcher.yaml"}
{"type": "cargo", "path": "deploy/konflux/cargo-auditable"},
{"type": "rpm", "path": "deploy/konflux/supervisor"}
]
pipelineRef:
resolver: git
Expand Down
4 changes: 2 additions & 2 deletions .tekton/odh-openshell-supervisor-tag.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -40,8 +40,8 @@ spec:
value: |
[
{"type": "cargo", "path": "."},
{"type": "rpm", "path": "deploy/konflux/supervisor"},
{"type": "generic", "path": "deploy/konflux/supervisor", "lockfile": "generic-fetcher.yaml"}
{"type": "cargo", "path": "deploy/konflux/cargo-auditable"},
{"type": "rpm", "path": "deploy/konflux/supervisor"}
]
- name: build-args
value:
Expand Down
1 change: 1 addition & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -85,6 +85,7 @@ socket2 = "0.6"
# Serialization
serde = { version = "1", features = ["derive"] }
serde_json = "1"
serde_path_to_error = "0.1"
serde_yml = { package = "noyalib", version = "0.0.28", default-features = false, features = ["std", "compat-serde-yaml"] }
toml = "0.8"
apollo-parser = "0.8.5"
Expand Down
6 changes: 5 additions & 1 deletion crates/openshell-cli/src/main.rs
Original file line number Diff line number Diff line change
Expand Up @@ -1781,7 +1781,11 @@ enum SandboxCommands {
#[arg(value_hint = ValueHint::AnyPath)]
local_path: String,

/// Destination path in the sandbox (defaults to the container's working directory).
/// Destination path in the sandbox (defaults to its working directory).
///
/// For an unfiltered single-file upload, an existing directory or a
/// trailing slash places the file inside that directory. A missing
/// nested path without a trailing slash renames the file.
dest: Option<String>,

/// Disable `.gitignore` filtering (uploads everything).
Expand Down
23 changes: 16 additions & 7 deletions crates/openshell-cli/src/run.rs
Original file line number Diff line number Diff line change
Expand Up @@ -1060,15 +1060,17 @@ pub async fn sandbox_create(
"\u{2022}".dimmed(),
);
}
sandbox_upload_planned(
// Boxed so the upload state machine lives on the heap instead of
// inflating the `sandbox_create` future (clippy::large_futures).
Box::pin(sandbox_upload_planned(
upload_plan,
&effective_server,
&sandbox_name,
Path::new(local_path),
dest,
&effective_tls,
workspace,
)
))
.await
.wrap_err_with(|| {
format!(
Expand Down Expand Up @@ -5110,7 +5112,7 @@ async fn sandbox_upload_planned(
sandbox_path: Option<&str>,
tls: &TlsOptions,
workspace: &str,
) -> Result<()> {
) -> Result<Option<String>> {
match plan {
SandboxUploadPlan::GitAware { base_dir, files } => {
sandbox_sync_up_files(
Expand All @@ -5123,10 +5125,13 @@ async fn sandbox_upload_planned(
tls,
workspace,
)
.await
.await?;
Ok(None)
}
SandboxUploadPlan::Regular => {
sandbox_sync_up(server, name, local_path, sandbox_path, tls, workspace).await
sandbox_sync_up(server, name, local_path, sandbox_path, tls, workspace)
.await
.map(Some)
}
}
}
Expand All @@ -5152,7 +5157,7 @@ pub async fn sandbox_upload(
dest_display
);

sandbox_upload_planned(
let uploaded_path = sandbox_upload_planned(
upload_plan,
server,
name,
Expand All @@ -5163,7 +5168,11 @@ pub async fn sandbox_upload(
)
.await?;

eprintln!("{} Upload complete", "✓".green().bold());
if let Some(path) = uploaded_path {
eprintln!("{} Upload complete: {path}", "✓".green().bold());
} else {
eprintln!("{} Upload complete", "✓".green().bold());
}
Ok(())
}

Expand Down
Loading
Loading