Conversation
Signed-off-by: Shailendra Singh <shailendras@nvidia.com>
Signed-off-by: Shailendra Singh <shailendras@nvidia.com>
- Introduced `pending_provider_credentials` in `MxcComputeBackend` to manage out-of-band provider credential state. - Added `append_provider_child_env` function to merge provider credentials into the agent environment, ensuring sensitive values are not exposed. - Updated `create_sandbox` method to validate egress requirements for provider credentials. - Implemented `resolve_sandbox_create_runtime_inputs` to prepare driver-specific sandbox creation state, including effective policy and provider credentials. - Modified gRPC handlers to utilize the new provider credential management features. - Updated documentation to clarify the use of provider credentials and their requirements for governed egress. Signed-off-by: Akber Raza <akberr@nvidia.com>
Add an end-to-end Windows MXC scenario for verifying provider credential handling without exposing the raw credential to the sandbox. The scenario confirms that the sandbox receives a revision-scoped GITHUB_TOKEN placeholder, the host CONNECT proxy substitutes the credential only for api.github.com, and use of the same placeholder against github.com is rejected with credential_endpoint_mismatch. Use inbox Windows PowerShell and curl for the probe so the standard Windows build requires no additional test executable. Configure SystemRoot and PATHEXT explicitly through agent_env, which provides the minimum environment needed to locate and execute curl while avoiding implicit inheritance of the gateway environment. Add pc_disable_ui for process-container workloads that require Win32k during startup. Preserve the hardened default and continue denying clipboard access and input injection when UI compatibility is enabled. Collect redacted diagnostic artifacts, check for raw-token leakage, and document the MXC configuration and credential-validation workflow. Tests: - cargo test -p openshell-driver-mxc - Windows PowerShell curl launch with only SystemRoot and PATHEXT Signed-off-by: Akber Raza <akberr@nvidia.com>
- pass effective provider policy and credential state into MXC sandbox creation - inject revision-scoped placeholders into the MXC child environment - resolve provider credentials only through governed host CONNECT proxy requests - add gateway and driver coverage for secret isolation and policy propagation - update MXC documentation and remove obsolete provider-v2 test setup Signed-off-by: Akber Raza <akberr@nvidia.com>
Clarify that the provider credential example uses process_container and does not require the isolation_session DLL or build feature. Signed-off-by: Akber Raza <akberr@nvidia.com>
Mark the credential scenario failed and suppress its ZIP bundle when any result artifact cannot be inspected for raw-token leakage. Signed-off-by: Akber Raza <akberr@nvidia.com>
Detect and redact a raw provider token before the credential probe result can reach console or CI logs. Signed-off-by: Akber Raza <akberr@nvidia.com>
Derive provider layers, credential scopes, and binding records from the same loaded provider snapshot to eliminate cross-read inconsistency. Signed-off-by: Akber Raza <akberr@nvidia.com>
Require workspace authorization before returning sandbox provider environment or credential binding data, while preserving sandbox-principal scope checks and not-found concealment. Signed-off-by: Akber Raza <akberr@nvidia.com>
Fail sandbox creation for expiring static provider credentials because MXC has no live refresh channel, while retaining request-time dynamic token grants and documenting recreation requirements. Signed-off-by: Akber Raza <akberr@nvidia.com>
Clarify that per-sandbox ports provide routing separation rather than peer authentication, place host-local processes in the trusted computing base, and retain M3 as the stronger source-attribution dependency. Signed-off-by: Akber Raza <akberr@nvidia.com>
- preserve native JSON arguments under Windows PowerShell - tolerate existing gateway registrations - reject network executable paths with actionable launch diagnostics - record redacted failure context in result bundles Signed-off-by: Akber Raza <akberr@nvidia.com>
… env keys Address the three blocking findings from the automated review of #3296 (head 550b81a): - Already-expired static provider credentials were silently withheld by the shared resolver before the create-time fail-closed check ran, so an MXC sandbox could be created without the configured credential instead of rejecting the request. Track withheld expired keys separately in ProviderEnvironment so the MXC create-time validator can still reject them. - Provider credential environment keys that collided case-insensitively with each other, or with the reserved TLS trust env vars injected later, were not validated before staging, producing an ambiguous or silently overwritten sandbox environment on Windows. Reject these synchronously at CreateSandbox instead. - The Global Policy Override docs said the global payload only supplies dynamic policy fields, but the implementation replaces the complete effective policy except UI. Corrected the description. Signed-off-by: Prashant S Khodade <pkhodade@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Stack the combined GitLab !98, !105, and !108 port on the provider-credential branch without the later main integration. Preserve prerequisite configuration and protobuf compatibility, and include native Windows validation fixes. Co-authored-by: Prashant S Khodade <pkhodade@nvidia.com> Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
…ation/drew Signed-off-by: Drew Newberry <anewberry@nvidia.com> # Conflicts: # crates/openshell-server/src/storage_proto.rs # proto/openshell.proto # sdk/go/proto/openshellv1/openshell.pb.go
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
|
🌿 Preview your docs: https://nvidia-preview-pr-4084.docs.buildwithfern.com/openshell |
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
drew
marked this pull request as draft
October 2, 2026 04:52
7 of 9 tasks
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implement native Windows MXC behind the compute-driver and isolation-backend extension points, on top of the backend-neutral foundations in #4106. The host supervisor remains a separate process; the dedicated openshell-windows-sandbox executable runs inside the ProcessContainer.
Related Issue
Follow-up to #1737 (RFC 0012); Windows scope tracked in #2050 and RFC 0013.
Changes
Testing
The prior PR head passed the native workspace suite (6082 passed, 27 skipped), but that is prior verification, not a fresh result for this stacking commit. Native MXC E2E remains incomplete, not passed.
Checklist
Stack
Merge #4106 first, then retarget this PR to main. If the base is squash-merged, merge updated main into drew-mxc so its comparison stays incremental. Existing MXC history is retained through a normal merge; no force-push is used.
Known blockers
Keep this PR draft. Do not weaken admission checks or substitute mock E2E to claim runtime completion.