Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
30 changes: 0 additions & 30 deletions .github/actions/setup-e2e-cli/action.yml
Original file line number Diff line number Diff line change
@@ -1,12 +1,6 @@
name: Setup E2E CLI
description: Download architecture-matched prebuilt OpenShell host CLIs for E2E tests

inputs:
conformance-artifact-prefix:
description: Optional conformance CLI artifact name prefix; linux-<arch> is appended automatically
required: false
default: ""

runs:
using: composite
steps:
Expand All @@ -23,27 +17,3 @@ runs:
chmod +x "$cli"
"$cli" --version
echo "OPENSHELL_BIN=$cli" >> "$GITHUB_ENV"

- name: Download prebuilt conformance CLI
if: inputs.conformance-artifact-prefix != ''
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: ${{ format('{0}-{1}', inputs.conformance-artifact-prefix, runner.arch == 'X64' && 'x86_64-unknown-linux-musl' || 'aarch64-unknown-linux-musl') }}
path: .e2e/prebuilt-conformance

- name: Configure prebuilt conformance CLI
if: inputs.conformance-artifact-prefix != ''
shell: bash
run: | # zizmor: ignore[github-env] validated filename under the trusted workspace path
set -euo pipefail
conformance="$GITHUB_WORKSPACE/.e2e/prebuilt-conformance/openshell-conformance"
if [[ ! -f "$conformance" ]]; then
echo "downloaded artifact is missing $conformance" >&2
exit 1
fi
# TODO: Remove this temporary mode diagnostic after CI confirms artifact permission handling.
echo "conformance binary mode before chmod: $(ls -l "$conformance")"
chmod +x "$conformance"
echo "conformance binary mode after chmod: $(ls -l "$conformance")"
"$conformance" list --output json >/dev/null
echo "OPENSHELL_CONFORMANCE_BIN=$conformance" >> "$GITHUB_ENV"
14 changes: 0 additions & 14 deletions .github/workflows/branch-e2e.yml
Original file line number Diff line number Diff line change
Expand Up @@ -321,7 +321,6 @@ jobs:
with:
image-tag: ${{ github.sha }}
runner: linux-arm64-cpu8
conformance-artifact-prefix: openshell-conformance

podman-e2e:
needs: [pr_metadata, build-binaries, build-images]
Expand All @@ -333,7 +332,6 @@ jobs:
uses: ./.github/workflows/e2e-podman-test.yml
with:
image-tag: ${{ github.sha }}
conformance-artifact-prefix: openshell-conformance
suite-matrix: >-
[{"suite":"ci","runner":"ubuntu-26.04","podman_major":"5","podman_package_version":"5.7.0+ds2-3build1","conmon_package_version":"2.1.13+ds1-2","cmd":"mise run --no-deps --skip-deps e2e:podman:ci"}]

Expand All @@ -345,8 +343,6 @@ jobs:
contents: read
packages: read
uses: ./.github/workflows/e2e-vm-test.yml
with:
conformance-artifact-prefix: openshell-conformance

docker-external-driver-e2e:
needs: [pr_metadata, build-binaries, build-gateway-plain, build-external-drivers, build-images]
Expand All @@ -361,7 +357,6 @@ jobs:
runner: linux-arm64-cpu8
gateway-artifact: openshell-gateway-plain-aarch64-unknown-linux-gnu
external-driver-binary: openshell-driver-docker
conformance-artifact-prefix: openshell-conformance
suite-matrix: >-
[{"suite":"external-driver","cmd":"mise run --no-deps --skip-deps e2e:docker:external-driver","apt_packages":"openssh-client","python_proto":false,"mcp":false}]

Expand All @@ -377,7 +372,6 @@ jobs:
image-tag: ${{ github.sha }}
gateway-artifact: openshell-gateway-plain-x86_64-unknown-linux-gnu
external-driver-binary: openshell-driver-podman
conformance-artifact-prefix: openshell-conformance
suite-matrix: >-
[{"suite":"external-driver","runner":"ubuntu-26.04","podman_major":"5","podman_package_version":"5.7.0+ds2-3build1","conmon_package_version":"2.1.13+ds1-2","cmd":"mise run --no-deps --skip-deps e2e:podman:external-driver"}]

Expand All @@ -393,7 +387,6 @@ jobs:
gateway-artifact: openshell-gateway-plain-x86_64-unknown-linux-gnu
suite-name: external-driver
e2e-task: e2e:vm:external-driver
conformance-artifact-prefix: openshell-conformance

gpu-e2e:
needs: [pr_metadata, build-binaries, build-images]
Expand All @@ -405,7 +398,6 @@ jobs:
uses: ./.github/workflows/e2e-gpu-test.yaml
with:
image-tag: ${{ github.sha }}
conformance-artifact-prefix: openshell-conformance

kubernetes-e2e:
needs: [pr_metadata, build-binaries, build-images]
Expand All @@ -427,7 +419,6 @@ jobs:
image-tag: ${{ github.sha }}
job-name: Kubernetes E2E (Rust smoke, Agent Sandbox ${{ matrix.agent_sandbox_api }})
agent-sandbox-version: ${{ matrix.agent_sandbox_version }}
conformance-artifact-prefix: openshell-conformance

kubernetes-workspace-managed-e2e:
needs: [pr_metadata, build-binaries, build-images]
Expand All @@ -441,7 +432,6 @@ jobs:
image-tag: ${{ github.sha }}
job-name: Kubernetes E2E (workspace managed mode)
e2e-task: e2e:kubernetes:workspace-managed
conformance-artifact-prefix: openshell-conformance

kubernetes-external-driver-e2e:
needs: [pr_metadata, build-binaries, build-gateway-plain, build-external-drivers, build-images]
Expand All @@ -458,7 +448,6 @@ jobs:
gateway-artifact: openshell-gateway-plain-x86_64-unknown-linux-gnu
external-driver-binary: openshell-driver-kubernetes
cluster-images: sandbox supervisor
conformance-artifact-prefix: openshell-conformance

kubernetes-workspace-operator-e2e:
needs: [pr_metadata, build-binaries, build-images]
Expand All @@ -472,7 +461,6 @@ jobs:
image-tag: ${{ github.sha }}
job-name: Kubernetes E2E (workspace operator mode)
e2e-task: e2e:kubernetes:workspace-operator
conformance-artifact-prefix: openshell-conformance

kubernetes-ha-e2e:
needs: [pr_metadata, build-binaries, build-images]
Expand All @@ -490,7 +478,6 @@ jobs:
test-name: kubernetes_ha_rebalancing
kubernetes-features: e2e,e2e-host-gateway,e2e-kubernetes,e2e-kubernetes-ha
use-envoy-gateway: true
conformance-artifact-prefix: openshell-conformance

kubernetes-credential-drivers-e2e:
needs: [pr_metadata, build-binaries, build-images]
Expand All @@ -504,7 +491,6 @@ jobs:
image-tag: ${{ github.sha }}
job-name: Kubernetes Credential Drivers E2E
e2e-task: e2e:kubernetes:credential-drivers
conformance-artifact-prefix: openshell-conformance

core-e2e-result:
name: Core E2E result
Expand Down
16 changes: 0 additions & 16 deletions .github/workflows/build-binaries.yml
Original file line number Diff line number Diff line change
Expand Up @@ -62,22 +62,6 @@ jobs:
supervisor-image-tag: ${{ inputs.supervisor-image-tag }}
extra-cargo-flags: ${{ env.EXTRA_CARGO_FLAGS }}

conformance:
name: openshell-conformance (${{ matrix.triple }})
env:
PACKAGE: openshell-conformance-cli
BINARY: openshell-conformance
strategy:
matrix:
include:
- triple: x86_64-unknown-linux-musl
runner: linux-amd64-cpu8
- triple: aarch64-unknown-linux-musl
runner: linux-arm64-cpu8
runs-on: ${{ matrix.runner }}
timeout-minutes: 60
steps: *build_steps

prover:
name: openshell-prover (${{ matrix.triple }})
env:
Expand Down
6 changes: 0 additions & 6 deletions .github/workflows/e2e-docker-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,10 +25,6 @@ on:
required: false
type: string
default: ""
conformance-artifact-prefix:
required: false
type: string
default: ""
suite-matrix:
required: false
type: string
Expand Down Expand Up @@ -71,8 +67,6 @@ jobs:
persist-credentials: false

- uses: ./.github/actions/setup-e2e-cli
with:
conformance-artifact-prefix: ${{ inputs.conformance-artifact-prefix }}

- uses: ./.github/actions/setup-e2e-gateway
with:
Expand Down
7 changes: 0 additions & 7 deletions .github/workflows/e2e-gpu-test.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,11 +7,6 @@ on:
description: "Image tag to test (typically the commit SHA)"
required: true
type: string
conformance-artifact-prefix:
description: "Optional prebuilt conformance CLI artifact prefix (artifact suffix is <triple>)"
required: false
type: string
default: ""

permissions:
actions: read
Expand Down Expand Up @@ -66,8 +61,6 @@ jobs:

- name: Use prebuilt OpenShell CLI
uses: ./.github/actions/setup-e2e-cli
with:
conformance-artifact-prefix: ${{ inputs.conformance-artifact-prefix }}

- name: Use prebuilt OpenShell gateway
uses: ./.github/actions/setup-e2e-gateway
Expand Down
7 changes: 0 additions & 7 deletions .github/workflows/e2e-kubernetes-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -67,11 +67,6 @@ on:
required: false
type: string
default: ""
conformance-artifact-prefix:
description: "Optional prebuilt conformance CLI artifact prefix (artifact suffix is <triple>)"
required: false
type: string
default: ""
external-driver-binary:
description: "Optional standalone compute driver binary used to compose a local test image"
required: false
Expand Down Expand Up @@ -112,8 +107,6 @@ jobs:

- name: Use prebuilt OpenShell CLI
uses: ./.github/actions/setup-e2e-cli
with:
conformance-artifact-prefix: ${{ inputs.conformance-artifact-prefix }}

- name: Use prebuilt OpenShell gateway
if: inputs.gateway-artifact != ''
Expand Down
6 changes: 0 additions & 6 deletions .github/workflows/e2e-podman-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,10 +21,6 @@ on:
required: false
type: string
default: ""
conformance-artifact-prefix:
required: false
type: string
default: ""
suite-matrix:
required: true
type: string
Expand Down Expand Up @@ -56,8 +52,6 @@ jobs:
persist-credentials: false

- uses: ./.github/actions/setup-e2e-cli
with:
conformance-artifact-prefix: ${{ inputs.conformance-artifact-prefix }}

- uses: ./.github/actions/setup-e2e-gateway
with:
Expand Down
6 changes: 0 additions & 6 deletions .github/workflows/e2e-vm-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,10 +22,6 @@ on:
required: false
type: string
default: e2e:vm
conformance-artifact-prefix:
required: false
type: string
default: ""

permissions:
actions: read
Expand All @@ -47,8 +43,6 @@ jobs:
persist-credentials: false

- uses: ./.github/actions/setup-e2e-cli
with:
conformance-artifact-prefix: ${{ inputs.conformance-artifact-prefix }}

- uses: ./.github/actions/setup-e2e-gateway
with:
Expand Down
2 changes: 0 additions & 2 deletions .github/workflows/release-dev.yml
Original file line number Diff line number Diff line change
Expand Up @@ -159,7 +159,6 @@ jobs:
image-tag: ${{ github.sha }}
checkout-ref: ${{ github.sha }}
runner: linux-arm64-cpu8
conformance-artifact-prefix: openshell-conformance

vm-e2e:
needs: [build-binaries, build-vm-driver]
Expand All @@ -170,7 +169,6 @@ jobs:
uses: ./.github/workflows/e2e-vm-test.yml
with:
checkout-ref: ${{ github.sha }}
conformance-artifact-prefix: openshell-conformance

tag-ghcr-dev:
name: Tag GHCR Images as Dev
Expand Down
2 changes: 0 additions & 2 deletions .github/workflows/release-tag.yml
Original file line number Diff line number Diff line change
Expand Up @@ -210,7 +210,6 @@ jobs:
image-tag: ${{ needs.compute-versions.outputs.source_sha }}
checkout-ref: ${{ needs.compute-versions.outputs.source_sha }}
runner: linux-arm64-cpu8
conformance-artifact-prefix: openshell-conformance

vm-e2e:
needs: [compute-versions, build-binaries, build-vm-driver]
Expand All @@ -221,7 +220,6 @@ jobs:
uses: ./.github/workflows/e2e-vm-test.yml
with:
checkout-ref: ${{ needs.compute-versions.outputs.source_sha }}
conformance-artifact-prefix: openshell-conformance

protobuf-compatibility:
name: Protobuf Compatibility
Expand Down
1 change: 0 additions & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,6 @@ Do not rely on this file for a full inventory. The detailed public and contribut
|------|-----------|---------|
| `crates/openshell-cli/` | CLI binary | User-facing command-line interface |
| `crates/openshell-conformance/` | CLI conformance library | Reusable driver-agnostic scenarios and command runner |
| `crates/openshell-conformance-cli/` | Conformance CLI | Legacy local `list` and `run` entrypoint pending follow-up cleanup |
| `crates/openshell-server/` | Gateway server | Control-plane API, sandbox lifecycle, auth boundary |
| `crates/openshell-sandbox/` | Sandbox runtime | Capability-free workload launcher, process identity, and seccomp-mediated I/O |
| `crates/openshell-supervisor/` | Supervisor runtime | Gateway session, policy evaluation, credentials, and upstream networking |
Expand Down
11 changes: 0 additions & 11 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

39 changes: 24 additions & 15 deletions TESTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -213,11 +213,12 @@ HTTP `Host`, TLS SNI, and mTLS handling.
Suites:

- Common suite (`--features e2e`) - driver-neutral CLI behavior, sandbox lifecycle, sync, port forwarding, policy, and provider tests.
- CLI conformance (`openshell-conformance`) - named scenarios for lifecycle,
mechanistic drafts, and the sandbox-local API, including agent-authored
permission requests. Driver E2E wrappers run every scenario. The
installed-artifact conformance suite runs all scenarios and offers a focused
`policy-advisor` testsuite for manual integration runs.
- CLI conformance (`tests/suites/conformance`) - portable Cargo tests for
lifecycle, mechanistic drafts, file transfer, and the sandbox-local API,
including agent-authored permission requests. Driver E2E runs the complete
Cargo test package. The installed-artifact conformance suite runs the same
tests from a nextest archive and offers a focused `policy-advisor` testsuite
for manual integration runs.
- Driver suites (`--features e2e-docker`, `e2e-podman`, `e2e-kubernetes`, or
`e2e-vm`) - CLI conformance plus the common and driver-specific coverage for
the selected deployment.
Expand All @@ -242,17 +243,25 @@ Run the Docker-backed Rust CLI e2e suite:
mise run e2e:docker
```

Run the minimal portable CLI conformance profile against the gateway selected
in your OpenShell CLI configuration:
Run the portable CLI conformance suite against the gateway selected in your
OpenShell CLI configuration:

```shell
mise run e2e:cli-conformance
cargo build --package openshell-cli
OPENSHELL_BIN="$PWD/target/debug/openshell" \
cargo test \
--locked \
--manifest-path tests/suites/conformance/Cargo.toml \
--package openshell-test-conformance-cli \
--no-fail-fast \
-- \
--test-threads=1 \
--nocapture
```

The gateway must already be installed, reachable, and selected before the task
starts. The task does not provision a gateway or select a compute driver. Set
`OPENSHELL_BIN` to test a prebuilt CLI; otherwise, the task builds the CLI from
the current checkout.
The gateway must already be installed, reachable, and selected before the tests
start. The test suite does not provision a gateway or select a compute driver.
Set `OPENSHELL_BIN` to another executable to test a different prebuilt CLI.

The phase-1 scenario verifies the complete CLI-to-gateway-to-driver path without
depending on how the gateway was installed or which driver is configured. It
Expand All @@ -278,9 +287,9 @@ openshell sandbox list --output json
openshell sandbox delete <sandbox-name>
```

Gateway-backed Rust E2E tasks build the standalone conformance CLI, run its
registered scenarios against the configured gateway, then run any lane-specific
Rust tests that still apply. Run the Podman-backed Rust CLI e2e suite:
Gateway-backed Rust E2E tasks run the CLI conformance Cargo tests against the
configured gateway, then run any lane-specific Rust tests that still apply.
Run the Podman-backed Rust CLI e2e suite:

```shell
mise run e2e:podman
Expand Down
Loading
Loading