Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

Sandbox-side proposal audit (CONFIG:PROPOSED and /wait decisions) names only the first endpoint

Aberta Para iniciantes
#4,240 0 comentários 0 reações 0 responsáveis Ver no GitHub

Mantenedores costumam responder em até 1 dia

@ericcurtin já está trabalhando nisso.

Desde 7/10/2026.

  • #4313 de @ericcurtin — aberto

Avaliação

Dificuldade
2/5
Tempo estimado
1-3 horas
Facilidade para iniciantes
78/100
Tipo de issue
Bug
Clareza
Claramente especificada
Status de atividade
Ativa
Stack de tecnologia
rust
Domínio
security

Direção de pesquisa

Comece em openshell-supervisor-network/src/policy_local.rs na função summarize_chunk_for_audit (por volta da linha 695), depois encontre seus testes existentes. Rastreie como a função resume endpoints e regras L7 para as decisões CONFIG:PROPOSED e /wait. Adicione cobertura para uma regra de dois endpoints e verifique se ambos os resumos listam todos os endpoints e todas as permissões L7, ou indicam a quantidade quando truncados.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

state:accepted

User Story. As an operator shipping OpenShell's OCSF to a SIEM, I want each proposal's audit record to name every endpoint it asks for, so the trail matches what a reviewer approves.

Problem Statement. Two audit records summarise a proposal with summarize_chunk_for_audit: CONFIG:PROPOSED, and the /wait CONFIG:APPROVED|REJECTED. That function is at openshell-supervisor-network/src/policy_local.rs:695, and it reads rule.endpoints.first() and .first() of its L7 rules. A proposal for [ports.ubuntu.com:80, 169.254.169.254:80] is therefore audited as on ports.ubuntu.com:80 GET /ubuntu-ports/** by /usr/bin/perl, with no sign that a second endpoint exists.

The gateway's own approval audit does list every endpoint (endpoints=[…]), so the two streams disagree about the same chunk.

Impact. Anyone who reads the sandbox-side OCSF record, whether a SIEM or an auditor, sees only the benign endpoint. An agent can put the benign endpoint first.

Acceptance Criteria.

  • The PROPOSED and /wait decision summaries list every endpoint and every L7 allow, or say "N endpoints" when truncated.
  • There is a test with a two-endpoint rule.

Reproduction Steps.

  1. From a sandbox, POST http://policy.local/v1/proposals with one rule containing two endpoints.
  2. Compare openshell rule get <sandbox> (both endpoints listed) with the PROPOSED line in openshell logs <sandbox> --source sandbox (first only).

Environment.

  • openshell 0.1.2 (Homebrew)
  • Docker driver, Docker 29.4.1 linux/arm64 (Docker Desktop)
  • macOS 26.5.2
  • proposal_approval_mode = manual
  • Sources checked at main 0bca9fb

Logs. Only in source: the PROPOSED lines I observed each had a single endpoint. The first-only summary follows from policy_local.rs:699–706.

Linguagem predominante
Rust
Estrelas
13.2k
Forks
1.6k
Merge médio
1d 20h
PRs com merge (30d)
348

Preparar o ambiente

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de NVIDIA/OpenShell

Todas as issues de NVIDIA/OpenShell

Issues semelhantes

Mais issues de Rust

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.