Skip to content

fix(prover): distinguish sibling endpoints and fail closed on solver errors - #4326

Open
alangou wants to merge 1 commit into
mainfrom
fix/9-prover-endpoint-validation/alangou
Open

alangou wants to merge 1 commit into
mainfrom
fix/9-prover-endpoint-validation/alangou

Conversation

@alangou

@alangou alangou commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Summary

Keep sibling endpoints distinct in the prover and read each endpoint's own allowed methods. Propagate inconsistent or inconclusive solver results as validation errors so policy approval requires successful analysis of both the current and proposed policies.

Changes

  • Index endpoint facts by rule, endpoint position, and effective port, using unambiguous keys.
  • Propagate analysis errors through the CLI and gateway; advance evaluation tokens to v3 so stored verdicts are reevaluated.
  • Add prover and gateway regression tests and update the prover README, advisor documentation, and CLI skill.

Compatibility

  • Protobuf messages and RPC signatures are unchanged.
  • The Rust openshell-prover API changes: run_all_queries and check_credential_safety now return Result<Vec<Finding>>, and EndpointId adds endpoint_index. Repository callers are updated.
  • Pending proposals with older evaluation tokens require reevaluation. Unavailable analysis blocks approval, including when analysis of the current policy fails.

Testing

  • Prover suite: 110 tests passed.
  • Gateway policy suite: 254 tests passed.
  • Regression tests fail when the previous endpoint encoding or lookup is restored, then pass with the final implementation.
  • Prover and server Clippy with all targets and -D warnings, Rust formatting, and git diff --check passed.
  • mise run docs: navigation passed; Fern reported 0 errors and 3 warnings.
  • Policy-advisor E2E passed with the official workload fixture and a temporary copy of the scenario whose only assertion change expects allow_index_crates_io_443, the rule name produced by the base implementation. This exercised approval, the active REST/read-only policy, and a successful request after hot-reload. The unmodified scenario still fails on its stale cargo_registry name assertion; the tracked E2E script is unchanged.
  • Standard E2E CI requested through test:e2e.

Checklist

  • Follows Conventional Commits.
  • Commit is signed off for DCO.
  • Relevant implementation documentation, user documentation, and agent guidance updated.

…errors

Signed-off-by: Adrien Langou <alangou@nvidia.com>
@alangou alangou added the test:e2e Requires end-to-end coverage label Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Label test:e2e applied for 2a29ab2. Open the existing run and click Re-run all jobs to execute with the label set. The run will execute the standard E2E suite after building the required gateway, sandbox, and supervisor images once. The matching required CI gate status on this PR will flip green automatically once the run finishes.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

test:e2e Requires end-to-end coverage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant