Vouch request:Adityakumarrama #4008
Adityakumarrama
started this conversation in
Vouch Request
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
What do you want to work on?
Hi! I'm Aditya, and I'd like to contribute to OpenShell.
A bit about me: I'm doing a BCA in AI at Rama University in Kanpur. I also run a small security startup, CyberSharcX, where we build honeypot-based threat detection for Indian SMEs, so isolation and "what is this process actually allowed to touch" are things I think about a lot. [Rust: e.g. "I'm still fairly new to Rust" or whatever is true.]
I'd like to start with #3058 (gRPC reflection on the gateway). While reading the code I noticed the auth bypass for /grpc.reflection. is already in place and FILE_DESCRIPTOR_SET is compiled into openshell-core, but no reflection service is registered. So the plumbing is mostly there. I'd add the service, an integration test that lists the expected services, and a grpcurl example in the docs.
Next would be #3560. I'm on Windows, so I can actually run the MXC driver. Since #3538, every MXC sandbox create gets rejected unless you manually add allow_driver_config = true and resource_admission.enabled = false. My understanding is the defaults in MxcComputeConfig::default() and admission_config_from_context need to change, though I haven't fully worked out how the two should stay in sync yet.
If those go well, I'd be interested in #3997 (the regulated industry example) and maybe #3928 (agent stdout/stderr not showing up in kubectl logs). I haven't dug into the supervisor code for that one, so no promises.
Why OpenShell: [one or two honest sentences. Are you using it, planning to, or did the agent-sandboxing problem connect to your security work?]
I'll read the relevant READMEs and existing tests before opening anything, and I'll keep PRs small. Thanks for taking a look!
Why this change?
The gateway already lets reflection requests through auth and compiles the descriptor set, but never registers the service. So if you point grpcurl at it, you get nothing back unless you have the .proto files on hand. That's a small fix with a real payoff for anyone poking at a running gateway.
I'm also on Windows, and since #3538 MXC rejects every sandbox create unless you edit gateway.toml by hand. I hit this kind of thing while building security tooling at my startup, and I'd rather fix it than work around it.
Checklist
All reactions