Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

bug: driver-controlled runtimes do not apply live policy revisions

Đang mở
#3,077 1 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
35/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
rust
Lĩnh vực
backend, security

Hướng nghiên cứu

Bắt đầu bằng cách lần theo MxcComputeBackend qua ValidateSandboxCreate và CreateSandbox, sau đó kiểm tra contract hiện có của GetSandboxConfig và ReportPolicyStatus. Sử dụng các bước tái hiện và hành vi của openshell policy status/--wait để xác minh cách các revision được phân phối và xác nhận. Công việc được xem là hoàn tất khi các trường hợp được liệt kê về áp dụng trực tiếp, lỗi, từ chối, xác nhận, kết nối lại, khởi động lại và tài liệu được bao phủ bằng các test.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

area:compute area:policy state:stale

User Story

As an OpenShell operator, I want policy updates accepted for a running sandbox to be applied live by its active compute runtime, so that the policy reported by the gateway always matches the policy the workload is actually enforcing.

Problem Statement

PR #2823 gives driver-controlled runtimes the canonical create-time policy in DriverSandboxSpec.policy and removes the MXC-specific rejection for live policy mutations. The MXC backend reads and maps that policy only during ValidateSandboxCreate and CreateSandbox; it does not fetch later revisions or report their load status.

The gateway can therefore accept and persist a later policy revision for a running driver-controlled sandbox without the runtime consuming it. The desired policy returned by the gateway then differs from the policy enforced by the workload.

The existing sandbox configuration contract already exposes later revisions through GetSandboxConfig and load acknowledgement through ReportPolicyStatus. This bug does not require a compute-driver reconcile RPC.

Impact / Why This Matters

A tightening update can appear accepted while the workload continues under the previous policy. A loosening update remains unavailable even though the gateway records it. --wait can time out because the driver never reports the revision as loaded.

The current workaround is to delete and recreate the sandbox so the policy is delivered again at creation. That interrupts the workload, discards runtime state, and violates the expected live policy-update workflow.

Acceptance Criteria

  • A driver-controlled runtime without the standard supervisor observes every new effective policy revision for each running sandbox.
  • The runtime applies supported live policy changes without deleting or recreating the sandbox.
  • The runtime calls ReportPolicyStatus with the exact revision and reports loaded only after enforcement has switched to that revision.
  • A load or enforcement failure is reported as failed and is visible through openshell policy status and --wait.
  • A policy change the selected runtime cannot enforce live is rejected before it can be mistaken for an applied revision.
  • Reconnects, gateway restarts, and temporarily missed notifications converge the runtime to the latest effective revision.
  • Tests cover successful live application, rejected unsupported changes, failed application, acknowledgement, and catch-up after reconnect/restart.
  • MXC documentation no longer claims live revision support unless the MXC runtime implements and validates this behavior.

Reproduction Steps

  1. Build the Windows gateway from PR #2823 with the MXC driver enabled.
  2. Create and start an MXC sandbox with a policy that the driver maps successfully.
  3. Submit an otherwise valid live policy replacement or merge update with openshell policy set --wait or openshell policy update --wait.
  4. Observe that the gateway persists the new revision, while MxcComputeBackend continues using only the policy captured during CreateSandbox and never acknowledges the later revision.
  5. Observe that --wait cannot confirm the revision as loaded and the running workload remains governed by its create-time policy.

Environment

  • OpenShell: PR #2823 at d26297a214b40809e4b4dfcd5513e3e257b0552c
  • OS: Windows 11 Insider build supported by MXC
  • Runtime, deployment, or integration: in-process openshell-driver-mxc, without the standard sandbox supervisor
  • Verification note: identified through code review; native Windows execution was not available on the review host

Related Work

  • #2417
  • #2823
Ngôn ngữ chính
Rust
Star
8.7k
Fork
1.3k
Merge trung bình
2 ngày 6 giờ
Pull request đã merge (30 ngày)
297

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của NVIDIA/OpenShell

Tất cả issue của NVIDIA/OpenShell

Issue tương tự

Thêm issue về Rust

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.