Skip to content

Commit 2964d8d

Browse files
committed
fix(runtime): integrate current policy and SSH launch contracts
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
1 parent 2ca39a8 commit 2964d8d

5 files changed

Lines changed: 15 additions & 14 deletions

File tree

‎crates/openshell-cli/src/run.rs‎

Lines changed: 5 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -6899,12 +6899,11 @@ mod tests {
68996899
format_endpoint, format_log_line, forward_requires_session_token, git_sync_files,
69006900
has_main_process_result, parse_cli_setting_value, parse_credential_expiry_cli_value,
69016901
parse_driver_config_json, parse_env_from_pairs, parse_secret_material_env_pairs,
6902-
policy_revision_list_json,
6903-
policy_revision_to_json, proto_execution_timeout, provisioning_timeout_message,
6904-
ready_false_condition_message, relay_local_socket, resolve_from,
6905-
rootfs_tar_sources_supported_for_gateway, sandbox_should_persist, sandbox_upload_plan,
6906-
service_endpoint_to_json, service_expose_status_error, service_url_for_gateway,
6907-
workspace_member_to_json,
6902+
policy_revision_list_json, policy_revision_to_json, proto_execution_timeout,
6903+
provisioning_timeout_message, ready_false_condition_message, relay_local_socket,
6904+
resolve_from, rootfs_tar_sources_supported_for_gateway, sandbox_should_persist,
6905+
sandbox_upload_plan, service_endpoint_to_json, service_expose_status_error,
6906+
service_url_for_gateway, workspace_member_to_json,
69086907
};
69096908
use openshell_core::proto::TcpForwardFrame;
69106909

‎crates/openshell-server/src/compute/mod.rs‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1327,7 +1327,7 @@ impl ComputeRuntime {
13271327
// cancelled. Keep the creation guard until its public identity and
13281328
// protected launch bundle have been committed.
13291329
let prepared = async {
1330-
if let Some(encoded) = launch_authentication {
1330+
if let Some(encoded) = runtime_inputs.launch_authentication {
13311331
let authentication = serde_json::from_slice(&encoded)
13321332
.map_err(|_| Status::internal("invalid sandbox launch authentication"))?;
13331333
let encoded = self
@@ -1362,7 +1362,7 @@ impl ComputeRuntime {
13621362
}
13631363
if let Some(spec) = driver_sandbox.spec.as_mut() {
13641364
spec.await_main_process_attachment = await_main_process_attachment;
1365-
spec.launch_authentication = runtime_inputs.launch_authentication.unwrap_or_default();
1365+
spec.launch_authentication = launch_authentication.unwrap_or_default();
13661366
}
13671367
let result = Box::pin(self.await_provisioning_operation(
13681368
&sandbox,
@@ -8666,7 +8666,7 @@ mod tests {
86668666
version: 2,
86678667
..Default::default()
86688668
});
8669-
let launch_authentication = b"protected-launch-material".to_vec();
8669+
let launch_authentication = test_launch_authentication(&sandbox);
86708670
runtime_inputs.launch_authentication = Some(launch_authentication.clone());
86718671

86728672
runtime

‎crates/openshell-server/src/grpc/policy.rs‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3555,7 +3555,7 @@ pub(super) async fn resolve_sandbox_create_runtime_inputs(
35553555
provider_names,
35563556
)
35573557
.await?;
3558-
let effective_policy = current_effective_policy_from_records(
3558+
let (effective_policy, _) = current_effective_policy_from_records(
35593559
state,
35603560
&provider_profile_catalog,
35613561
sandbox,

‎crates/openshell-server/src/storage_proto.rs‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -143,9 +143,9 @@ mod tests {
143143
// Legacy payloads decode empty owners; the gateway rebuilds their authority
144144
// from effective policy rather than trusting persisted owner stamps.
145145
const PUBLIC_RPC_SCHEMA_SHA256: &str =
146-
"18206c52e68fdb0af60f8bb8dfaf47d9bc8021222cb49cacffab6352d3ad5549";
146+
"3fead4a66e57e6828072109564fa25b5b65ef541b35098d9ed7f0785387fe0aa";
147147
const DURABLE_SCHEMA_SHA256: &str =
148-
"76487ab369fc3a4b03a179bb5e7ea6be8d20e380ad5563075dff8ee50e539406";
148+
"96269474903e077df4d4861db0dd1004b8a7205604ffadcdaff98d0124f18147";
149149
const PUBLIC_DURABLE_OVERLAP_SHA256: &str =
150150
"761dea31a521b0650840fe2a823ad6e36a265ed323ba4506889781d630df0ee3";
151151
// A persisted Sandbox without endpoint status retains its lifecycle fields;
@@ -612,7 +612,7 @@ mod tests {
612612
overlap_hash.as_str(),
613613
),
614614
(
615-
(306, 27),
615+
(307, 27),
616616
(93, 21),
617617
(81, 21),
618618
PUBLIC_RPC_SCHEMA_SHA256,

‎crates/openshell-supervisor/src/lib.rs‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -803,7 +803,9 @@ async fn run_sandbox_with_backend(
803803
#[cfg(not(unix))]
804804
let ssh_host_key = {
805805
if ssh_socket_path.is_some() {
806-
return Err(miette::miette!("SSH access sockets are unsupported on this host"));
806+
return Err(miette::miette!(
807+
"SSH access sockets are unsupported on this host"
808+
));
807809
}
808810
None
809811
};

0 commit comments

Comments
 (0)