Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Sandbox-side proposal audit (CONFIG:PROPOSED and /wait decisions) names only the first endpoint

Open Beginner friendly
#4,240 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
78/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
rust
Domain
security

Research direction

Start in openshell-supervisor-network/src/policy_local.rs at summarize_chunk_for_audit (around line 695), then find its existing tests. Trace how the function summarizes endpoints and L7 rules for CONFIG:PROPOSED and /wait decisions. Add coverage for a two-endpoint rule and verify both summaries list every endpoint and L7 allow, or indicate the count when truncated.

Written by the indexing model from the issue text.

Description

state:triage-needed

User Story. As an operator shipping OpenShell's OCSF to a SIEM, I want each proposal's audit record to name every endpoint it asks for, so the trail matches what a reviewer approves.

Problem Statement. Two audit records summarise a proposal with summarize_chunk_for_audit: CONFIG:PROPOSED, and the /wait CONFIG:APPROVED|REJECTED. That function is at openshell-supervisor-network/src/policy_local.rs:695, and it reads rule.endpoints.first() and .first() of its L7 rules. A proposal for [ports.ubuntu.com:80, 169.254.169.254:80] is therefore audited as on ports.ubuntu.com:80 GET /ubuntu-ports/** by /usr/bin/perl, with no sign that a second endpoint exists.

The gateway's own approval audit does list every endpoint (endpoints=[…]), so the two streams disagree about the same chunk.

Impact. Anyone who reads the sandbox-side OCSF record, whether a SIEM or an auditor, sees only the benign endpoint. An agent can put the benign endpoint first.

Acceptance Criteria.

  • The PROPOSED and /wait decision summaries list every endpoint and every L7 allow, or say "N endpoints" when truncated.
  • There is a test with a two-endpoint rule.

Reproduction Steps.

  1. From a sandbox, POST http://policy.local/v1/proposals with one rule containing two endpoints.
  2. Compare openshell rule get <sandbox> (both endpoints listed) with the PROPOSED line in openshell logs <sandbox> --source sandbox (first only).

Environment.

  • openshell 0.1.2 (Homebrew)
  • Docker driver, Docker 29.4.1 linux/arm64 (Docker Desktop)
  • macOS 26.5.2
  • proposal_approval_mode = manual
  • Sources checked at main 0bca9fb

Logs. Only in source: the PROPOSED lines I observed each had a single endpoint. The first-only summary follows from policy_local.rs:699–706.

Dominant language
Rust
Stars
13.2k
Forks
1.6k
Avg merge
1d 19h
Merged PRs (30d)
343

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from NVIDIA/OpenShell

All issues in NVIDIA/OpenShell

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.