Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
38 commits
Select commit Hold shift + click to select a range
2a5d7ef
fix(server): read replay buses atomically under one lock
letv1nnn Sep 23, 2026
c28356d
fix(server): clamp replay to cross-source coverage floor
letv1nnn Sep 23, 2026
8ec87ac
docs: document cross-source coverage floor for WatchSandbox resume
letv1nnn Sep 23, 2026
ffb3e8a
fix(server): validate resume cursor under the snapshot_after lock hold
letv1nnn Sep 23, 2026
9f4441c
fix(server): validate resume cursor under the snapshot_after lock hold
letv1nnn Sep 23, 2026
45e3308
fix(network): refuse protocol upgrades on JSON-RPC and MCP endpoints …
shiju-nv Sep 28, 2026
36b0386
feat(cli): detach sandbox sessions with Ctrl-D (#3744)
drew Sep 28, 2026
e63cfa1
fix(cli): keep SSH forwards owned by spawned process (#3759)
drew Sep 28, 2026
b77f5dd
test(install): support Bash 3.2 mock capture (#3790)
elezar Sep 28, 2026
1358941
feat(mcp): inspect requests with Tower-selected protocol profiles (#3…
shiju-nv Sep 28, 2026
acbac9c
feat(sandbox): add main restart policy (#2798)
drew Sep 29, 2026
2fe5a0e
perf(kubernetes): use a TCP readiness probe for the supervisor (#3700)
FrostGod Sep 29, 2026
9cb72ba
feat(docker): support corporate proxy CA bundles (#3549)
feloy Sep 29, 2026
cfcc373
fix(e2e): stop sandbox leaks from async Drop cleanup (#3750)
ericcurtin Sep 29, 2026
12ef86c
fix(cli): keep policy and provider diagnostics readable (#3444)
shiju-nv Sep 29, 2026
a875add
feat(server): write gateway OCSF events to JSONL (#3264)
krishicks Sep 29, 2026
2ad77ad
test(sandbox): bind ephemeral port in accepted loopback stream test (…
krishicks Sep 29, 2026
a6eefcf
fix(network): preserve pipelined requests after chunked inspection (#…
shiju-nv Sep 29, 2026
cf1bbb9
docs: remove the architecture directory (#3799)
krishicks Sep 29, 2026
c0eb3db
fix(ci): restore repository permission vetters (#3875)
pimlock Sep 29, 2026
33a8eac
feat(helm): configure gateway OCSF JSONL output (#3876)
krishicks Sep 29, 2026
0ea0d31
fix(supervisor): restore canonical stdin after connection loss (#3852)
shiju-nv Sep 29, 2026
ba16b9f
fix(mcp): explain revision-scoped policy and rejections (#3850)
shiju-nv Sep 29, 2026
5c0c9e4
feat(providers): add OCI Generative AI example provider profile (#3904)
fede-kamel Sep 29, 2026
252882f
feat(providers): serve sandbox config files on demand (#3832)
drew Sep 30, 2026
798500c
fix(policy): validate raw OPA settings and redact startup errors (#3788)
shiju-nv Sep 30, 2026
b8932d4
Fix/startup provider readiness (#3819)
ebusto Sep 30, 2026
b8ffe52
test(podman): move podman_preflight into driver-podman integration te…
politerealism Sep 30, 2026
5acaaba
test(conformance): verify deletion through sandbox list (#3792)
elezar Sep 30, 2026
a3ef97b
fix(server): keep the delivered window above the coverage floor
letv1nnn Sep 30, 2026
84c29f9
fix(server): snapshot initial watch tails under one lock
letv1nnn Sep 30, 2026
21fea95
test(tmachine): add K3s conformance scenario (#3848)
SDAChess Sep 30, 2026
7caff12
perf(otel): stop exporting spans from steady-state polling (#3915)
krishicks Sep 30, 2026
07a486d
fix(cli): accept sandbox name before -- in exec (#3901)
ericcurtin Sep 30, 2026
374c035
fix(network): refuse protocol upgrades on GraphQL endpoints (#3841)
shiju-nv Sep 30, 2026
912a077
feat(service): add bearer authorization passthrough (#3796)
derekwaynecarr Sep 30, 2026
0a86765
docs(server): correct equal-depth coverage floor claim and add tests
letv1nnn Sep 30, 2026
23744fe
Merge branch 'upstream-main' into fix/server-atomic-replay-boundary
letv1nnn Sep 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 0 additions & 1 deletion .agents/skills/build-openshell-mxc-windows/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,6 @@ The Windows build lane is implemented by these tracked files:
| `tasks/rust.toml`, `tasks/test.toml`, and `tasks/markdown.toml` | Windows routing for compiler-bearing checks, explicit Unix-only test skips, and Markdown dependency setup. |
| `tasks/scripts/windows-msvc.ps1` | PowerShell wrapper that enters the Visual Studio developer environment and invokes Cargo. |
| `.github/workflows/windows-msvc.yml` | Opt-in PR lint and test plus advisory `windows` branch cache seeding and dependent binary builds on native x64 and ARM64 runners. |
| `architecture/windows-msvc-build.md` | Design notes and validation contract. |
| `.agents/skills/build-openshell-mxc-windows/` | This skill and companion reference material. |

Use the code that is already in the repo. Do not generate a parallel Windows
Expand Down
1 change: 0 additions & 1 deletion .agents/skills/build-openshell-mxc-windows/reference.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,6 @@ maintaining the existing build-only Windows MSVC lane.
| `tasks/windows.toml` | Mise task definitions for `windows:*`. |
| `tasks/scripts/windows-msvc.ps1` | Visual Studio environment discovery, rustup target setup, Cargo invocation, logs, artifact report. |
| `.github/workflows/windows-msvc.yml` | Opt-in PR lint and test plus `windows` branch cache seeding and dependent binary builds on native x64 and ARM64 runners. |
| `architecture/windows-msvc-build.md` | Human-readable design contract. |

## Commands

Expand Down
4 changes: 2 additions & 2 deletions .agents/skills/create-rfc/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,12 +33,12 @@ Keep the template as the source of truth for section guidance.
## Writing Standards

- Prefer concrete design statements over placeholder language.
- Link to relevant issues, prior RFCs, and architecture docs when they provide
- Link to relevant issues, prior RFCs, and published docs when they provide
needed context.
- Keep rejected or left-out designs in Alternatives, not Proposal.
- Use Mermaid diagrams for architecture or data flow when a diagram would make
the proposal easier to review.
- Do not update `architecture/` or published docs just because an RFC was
- Do not update published docs just because an RFC was
drafted. Those updates belong with implementation or with an accepted RFC when
the user asks for them.

Expand Down
6 changes: 3 additions & 3 deletions .agents/skills/create-spike/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -91,7 +91,7 @@ The prompt to the reviewer **must** instruct it to:

8. **Look at relevant tests to understand test coverage expectations.** What test patterns exist? What level of coverage is expected for this area?

9. **Check architecture docs** in the `architecture/` directory for relevant documentation about the affected subsystems.
9. **Check design records** in `rfc/` and the affected crate `README.md` files for relevant decisions and constraints.

10. **Assess gateway config documentation impact.** If the change would add, remove, rename, or change defaults for gateway TOML keys or driver-specific config options, call out that `docs/how-it-works/gateways/configuration.mdx` must be updated. If the change is surfaced through Helm or compute-driver setup docs, call out the relevant deployment or compute-driver docs too.

Expand Down Expand Up @@ -156,7 +156,7 @@ gh issue create \
### Architecture Overview
<How the affected subsystems work today. Include data flow, component interactions, and relevant design decisions. Reference architecture docs if applicable.>
<How the affected subsystems work today. Include data flow, component interactions, and relevant design decisions. Reference RFCs or crate READMEs if applicable.>
### Code References
Expand Down Expand Up @@ -278,7 +278,7 @@ User says: "Allow sandbox egress to private IP space via networking policy"
- Reads OPA policy evaluation pipeline in `opa.rs` and `crates/openshell-sandbox/data/sandbox-policy.rego`
- Reads proto definitions in `sandbox.proto` for `NetworkEndpoint`
- Maps the 4-layer defense model: netns, seccomp, OPA, SSRF check
- Reads `architecture/security-policy.md` and `architecture/sandbox.md`
- Reads RFC 0002 and the `openshell-policy` crate README
- Identifies exact insertion points: policy field addition, SSRF check bypass path, OPA rule extension
- Assesses: Medium complexity, High confidence, ~6 files
3. Fetch labels — select `area:sandbox`, `area:proxy`, `area:policy`, `state:validated`
Expand Down
4 changes: 2 additions & 2 deletions .agents/skills/sync-agent-infra/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -150,8 +150,8 @@ For each file in the table above, check for the following inconsistencies:
3. **Unique names** — Parse the `name` field from every `SKILL.md` under both roots. Every name must be globally unique and match the documented inventory.
4. **Local references** — Every relative Markdown link and referenced file in a skill must resolve within that installed skill directory unless the reference is an explicit published URL.
5. **Canonical paths** — Contributor skills that name the source location of a public skill must use `skills/<name>/...`, never `.agents/skills/<name>/...`.
6. **Public portability** — Public skills must not require repository-relative files under `docs/`, `architecture/`, `crates/`, `deploy/`, or `.agents/`; source builds; `mise`; or repository E2E workflows. Use installed `openshell --help` for command syntax and Markdown endpoints under `https://docs.nvidia.com/openshell/latest/` (URLs ending in `.md`) for product documentation.
7. **No canonical documentation copies** — Review public reference files and large command/schema blocks. Remove material that merely copies CLI help, policy schemas, architecture docs, or published operational documentation; retain only skill-specific reasoning and worked interactions.
6. **Public portability** — Public skills must not require repository-relative files under `docs/`, `crates/`, `deploy/`, or `.agents/`; source builds; `mise`; or repository E2E workflows. Use installed `openshell --help` for command syntax and Markdown endpoints under `https://docs.nvidia.com/openshell/latest/` (URLs ending in `.md`) for product documentation.
7. **No canonical documentation copies** — Review public reference files and large command/schema blocks. Remove material that merely copies CLI help, policy schemas, RFCs, or published operational documentation; retain only skill-specific reasoning and worked interactions.
8. **Discovery** — Run `npx -y skills add . --list` from a clean checkout or disposable copy. It must list exactly the four public skills. Remove any generated lock file or installed directory after the check.

## Step 3: Report Drift
Expand Down
8 changes: 4 additions & 4 deletions .agents/skills/tui-development/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -102,7 +102,7 @@ match app.screen {
}
```

Within the `Sandbox` screen, the top 20% renders sandbox metadata (`sandbox_detail`), and the bottom 80% dispatches based on focus and tab state:
Within the `Sandbox` screen, `sandbox_detail::required_height` sizes the metadata and restart status pane to its contents. The remaining area dispatches based on focus and tab state:

```rust
match app.focus {
Expand Down Expand Up @@ -262,7 +262,7 @@ The `Theme` struct has 16 `Style` fields, accessed at runtime via `app.theme`:
| `border` | EVERGLADE fg | Light sage fg | Unfocused panel borders |
| `border_focused` | NVIDIA_GREEN fg | NVIDIA_GREEN_DARK fg | Focused panel borders |
| `status_ok` | NVIDIA_GREEN fg | NVIDIA_GREEN_DARK fg | Healthy, INFO, Ready |
| `status_warn` | Yellow fg | Dark yellow fg | Degraded, WARN, Provisioning |
| `status_warn` | Yellow fg | Dark yellow fg | Degraded, WARN, Provisioning, Starting |
| `status_err` | Red fg | Dark red fg | Unhealthy, ERROR |
| `key_hint` | NVIDIA_GREEN fg | NVIDIA_GREEN_DARK fg | Keyboard shortcut labels |
| `log_cursor` | EVERGLADE bg | Light green bg | Selected log line highlight |
Expand Down Expand Up @@ -297,7 +297,7 @@ fn draw_detail_popup(frame: &mut Frame<'_>, data: &MyData, area: Rect, theme: &T

- **Selected row**: Green `▌` left-border marker on the selected row. Active gateway also gets a green `●` dot.
- **Focused panel**: Border changes from `border` to `border_focused` style.
- **Status indicators**: Green for healthy/ready/info, yellow for degraded/provisioning/warn, red for unhealthy/error.
- **Status indicators**: Green for healthy/ready/info, yellow for degraded/provisioning/starting/warn, red for unhealthy/error.
- **Separators**: Muted `│` characters between title bar segments and nav bar sections.
- **Log source labels**: `"sandbox"` source renders in `accent` (green), `"gateway"` in `muted`.

Expand Down Expand Up @@ -423,7 +423,7 @@ All actions are accessible via keyboard shortcuts displayed in the nav bar. The
| `crates/openshell-tui/src/ui/providers.rs` | Provider list table with profile-aware columns: Name, Category, Type, Credentials, Workspace |
| `crates/openshell-tui/src/ui/global_settings.rs` | Global settings table: Key, Type, Value. Includes edit overlay, confirm-set, and confirm-delete popups |
| `crates/openshell-tui/src/ui/sandboxes.rs` | Reusable sandbox table widget with columns: Name, Status, Created, Age, Image, Workspace, Notes |
| `crates/openshell-tui/src/ui/sandbox_detail.rs` | Sandbox metadata view — name, status, image, created, age, providers, policy version |
| `crates/openshell-tui/src/ui/sandbox_detail.rs` | Sandbox metadata view — name, status, image, created, age, restart policy/status, providers, policy version |
| `crates/openshell-tui/src/ui/sandbox_policy.rs` | Policy viewer — rendered policy lines with scroll support, tab title |
| `crates/openshell-tui/src/ui/sandbox_settings.rs` | Sandbox settings table: Key, Type, Value, Scope. Includes edit overlay and confirm popups |
| `crates/openshell-tui/src/ui/sandbox_logs.rs` | Structured log viewer — timestamp, source, level, target, message, key=value fields, scroll position, source filter, visual selection mode, clipboard copy |
Expand Down
Loading
Loading