Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

Sandbox-side proposal audit (CONFIG:PROPOSED and /wait decisions) names only the first endpoint

Offen Anfängerfreundlich
#4,240 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 1 Tag

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
2/5
Geschätzter Aufwand
1-3 Stunden
Anfängerfreundlichkeit
78/100
Issue-Typ
Bug
Klarheit
Klar beschrieben
Aktivitätsstatus
Aktiv
Tech-Stack
rust
Bereich
security

Rechercherichtung

Starte in openshell-supervisor-network/src/policy_local.rs bei summarize_chunk_for_audit (ca. Zeile 695), finde dann die vorhandenen Tests für die Funktion. Verfolge, wie die Funktion Endpunkte und L7-Regeln für CONFIG:PROPOSED und /wait-Entscheidungen zusammenfasst. Füge Abdeckung für eine Regel mit zwei Endpunkten hinzu und überprüfe, dass beide Zusammenfassungen jeden Endpunkt und jede L7-Freigabe auflisten oder die Anzahl bei Kürzung angeben.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

state:triage-needed

User Story. As an operator shipping OpenShell's OCSF to a SIEM, I want each proposal's audit record to name every endpoint it asks for, so the trail matches what a reviewer approves.

Problem Statement. Two audit records summarise a proposal with summarize_chunk_for_audit: CONFIG:PROPOSED, and the /wait CONFIG:APPROVED|REJECTED. That function is at openshell-supervisor-network/src/policy_local.rs:695, and it reads rule.endpoints.first() and .first() of its L7 rules. A proposal for [ports.ubuntu.com:80, 169.254.169.254:80] is therefore audited as on ports.ubuntu.com:80 GET /ubuntu-ports/** by /usr/bin/perl, with no sign that a second endpoint exists.

The gateway's own approval audit does list every endpoint (endpoints=[…]), so the two streams disagree about the same chunk.

Impact. Anyone who reads the sandbox-side OCSF record, whether a SIEM or an auditor, sees only the benign endpoint. An agent can put the benign endpoint first.

Acceptance Criteria.

  • The PROPOSED and /wait decision summaries list every endpoint and every L7 allow, or say "N endpoints" when truncated.
  • There is a test with a two-endpoint rule.

Reproduction Steps.

  1. From a sandbox, POST http://policy.local/v1/proposals with one rule containing two endpoints.
  2. Compare openshell rule get <sandbox> (both endpoints listed) with the PROPOSED line in openshell logs <sandbox> --source sandbox (first only).

Environment.

  • openshell 0.1.2 (Homebrew)
  • Docker driver, Docker 29.4.1 linux/arm64 (Docker Desktop)
  • macOS 26.5.2
  • proposal_approval_mode = manual
  • Sources checked at main 0bca9fb

Logs. Only in source: the PROPOSED lines I observed each had a single endpoint. The first-only summary follows from policy_local.rs:699–706.

Vorherrschende Sprache
Rust
Sterne
13.2k
Forks
1.6k
Ø Merge
1 T. 19 Std.
Gemergte PRs (30 T.)
343

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus NVIDIA/OpenShell

Alle Issues in NVIDIA/OpenShell

Ähnliche Issues

Weitere Issues zu Rust

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.