bug: driver-controlled runtimes do not apply live policy revisions
Les mainteneurs répondent en général sous 1 jour
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 5/5
- Temps estimé
- Plus d'une semaine
- Accessibilité débutants
- 35/100
Piste de recherche
Commencez par suivre MxcComputeBackend à travers ValidateSandboxCreate et CreateSandbox, puis examinez le contrat existant de GetSandboxConfig et ReportPolicyStatus. Utilisez les étapes de reproduction et le comportement de openshell policy status/--wait pour vérifier comment les révisions sont livrées et accusées réception. Le travail est terminé lorsque les cas répertoriés d’application en direct, d’échec, de rejet, d’accusé de réception, de reconnexion, de redémarrage et de documentation sont couverts par des tests.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
User Story
As an OpenShell operator, I want policy updates accepted for a running sandbox to be applied live by its active compute runtime, so that the policy reported by the gateway always matches the policy the workload is actually enforcing.
Problem Statement
PR #2823 gives driver-controlled runtimes the canonical create-time policy in DriverSandboxSpec.policy and removes the MXC-specific rejection for live policy mutations. The MXC backend reads and maps that policy only during ValidateSandboxCreate and CreateSandbox; it does not fetch later revisions or report their load status.
The gateway can therefore accept and persist a later policy revision for a running driver-controlled sandbox without the runtime consuming it. The desired policy returned by the gateway then differs from the policy enforced by the workload.
The existing sandbox configuration contract already exposes later revisions through GetSandboxConfig and load acknowledgement through ReportPolicyStatus. This bug does not require a compute-driver reconcile RPC.
Impact / Why This Matters
A tightening update can appear accepted while the workload continues under the previous policy. A loosening update remains unavailable even though the gateway records it. --wait can time out because the driver never reports the revision as loaded.
The current workaround is to delete and recreate the sandbox so the policy is delivered again at creation. That interrupts the workload, discards runtime state, and violates the expected live policy-update workflow.
Acceptance Criteria
- A driver-controlled runtime without the standard supervisor observes every new effective policy revision for each running sandbox.
- The runtime applies supported live policy changes without deleting or recreating the sandbox.
- The runtime calls
ReportPolicyStatuswith the exact revision and reportsloadedonly after enforcement has switched to that revision. - A load or enforcement failure is reported as failed and is visible through
openshell policy statusand--wait. - A policy change the selected runtime cannot enforce live is rejected before it can be mistaken for an applied revision.
- Reconnects, gateway restarts, and temporarily missed notifications converge the runtime to the latest effective revision.
- Tests cover successful live application, rejected unsupported changes, failed application, acknowledgement, and catch-up after reconnect/restart.
- MXC documentation no longer claims live revision support unless the MXC runtime implements and validates this behavior.
Reproduction Steps
- Build the Windows gateway from PR #2823 with the MXC driver enabled.
- Create and start an MXC sandbox with a policy that the driver maps successfully.
- Submit an otherwise valid live policy replacement or merge update with
openshell policy set --waitoropenshell policy update --wait. - Observe that the gateway persists the new revision, while
MxcComputeBackendcontinues using only the policy captured duringCreateSandboxand never acknowledges the later revision. - Observe that
--waitcannot confirm the revision as loaded and the running workload remains governed by its create-time policy.
Environment
- OpenShell: PR #2823 at
d26297a214b40809e4b4dfcd5513e3e257b0552c - OS: Windows 11 Insider build supported by MXC
- Runtime, deployment, or integration: in-process
openshell-driver-mxc, without the standard sandbox supervisor - Verification note: identified through code review; native Windows execution was not available on the review host
Related Work
- #2417
- #2823
- Langage dominant
- Rust
- Étoiles
- 15.4k
- Forks
- 1.7k
- Merge moyen
- 1 j 21 h
- PR mergées (30 j)
- 366
Préparer son environnement
- Aucun Dockerfile ni fichier Docker Compose
- Propose un modèle de pull request
- Lire le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de NVIDIA/OpenShell
-
state:triage-needed
Difficulté 2/5 1-3 heures Accessibilité débutants 70/100
Les mainteneurs répondent en général sous 1 jour
-
docs: document workspace and provider label capabilitiesPeut-être pris @johntmyers l’a pris il y a 3 jours. Ouvertearea:docs
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
NVIDIA/OpenShell#4250 · 2 commentaires ·
Les mainteneurs répondent en général sous 1 jour
-
bug(driver-mxc): test helper fails to compile after gateway-name argumentPeut-être pris @feloy l’a pris il y a 5 jours. Ouvertestate:triage-needed
Difficulté 1/5 Moins d'une heure Accessibilité débutants 88/100
Les mainteneurs répondent en général sous 1 jour
-
bug: install.sh ignores XDG_CONFIG_HOME for the local gateway configPeut-être pris @fede-kamel l’a pris il y a 8 jours. Ouvertearea:cli os:linux os:macos state:validated
Difficulté 2/5 1-3 heures Accessibilité débutants 88/100
NVIDIA/OpenShell#4042 · 2 commentaires ·
Les mainteneurs répondent en général sous 1 jour
-
state:triage-needed
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
NVIDIA/OpenShell#3995 · 2 commentaires ·
Les mainteneurs répondent en général sous 1 jour
Toutes les issues de NVIDIA/OpenShell
Issues similaires
-
Difficulté 2/5 1-3 heures Accessibilité débutants 62/100
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 1/5 Moins d'une heure Accessibilité débutants 90/100
chroma-core/chroma#7879 ·
Les mainteneurs répondent en général sous 1 jour
-
priority middle
Difficulté 1/5 Moins d'une heure Accessibilité débutants 72/100
KATO-Hiro/AtCoderClans#12838 ·
Les mainteneurs répondent en général sous 1 jour
-
clap_complete env (PowerShell): values after a space don't complete in Windows PowerShell 5.1Ouverte
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
Les mainteneurs répondent en général sous 1 jour
-
enhancement
Difficulté 2/5 1-3 heures Accessibilité débutants 74/100
Les mainteneurs répondent en général sous 1 jour