Skip to content

OpenShell v0.1.3

Latest

Choose a tag to compare

@github-actions github-actions released this 09 Oct 15:22
· 9 commits to main since this release
e1f3c82

OpenShell v0.1.3

Quick install

curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | OPENSHELL_VERSION=v0.1.3 sh

What's Changed

  • feat(helm): make cluster-scoped RBAC optional by @ansjindal in #3459
  • fix(supervisor): keep session retries during startup by @drew in #3765
  • fix(e2e): reserve distinct corporate proxy fixture ports by @drew in #3761
  • test(cli): migrate gateway-free smoke coverage by @elezar in #3641
  • test(conformance): migrate file transfer coverage by @elezar in #3597
  • fix(server): retry provider attachment CAS conflicts by @drew in #3501
  • test(e2e): run podman suite with tmachine by @elezar in #3637
  • fix(network): refuse protocol upgrades on JSON-RPC and MCP endpoints by @shiju-nv in #3753
  • feat(cli): detach sandbox sessions with Ctrl-D by @drew in #3744
  • fix(cli): prevent orphaned SSH forward muxes by @drew in #3759
  • test(install): support Bash 3.2 mock capture by @elezar in #3790
  • feat(mcp): inspect requests with Tower-selected protocol profiles by @shiju-nv in #3335
  • feat(sandbox): add main restart policy by @drew in #2798
  • perf(kubernetes): use a TCP readiness probe for the supervisor by @FrostGod in #3700
  • feat(docker): support corporate proxy CA bundles by @feloy in #3549
  • fix(e2e): stop sandbox leaks from async Drop cleanup by @ericcurtin in #3750
  • fix(cli): keep policy and provider diagnostics readable by @shiju-nv in #3444
  • feat(server): write gateway OCSF events to JSONL by @krishicks in #3264
  • test(sandbox): bind ephemeral port in accepted loopback stream test by @krishicks in #3872
  • fix(network): preserve pipelined requests after chunked inspection by @shiju-nv in #3861
  • docs: remove the architecture directory by @krishicks in #3799
  • fix(ci): restore repository permission vetters by @pimlock in #3875
  • feat(helm): configure gateway OCSF JSONL output by @krishicks in #3876
  • fix(supervisor): restore canonical stdin after connection loss by @shiju-nv in #3852
  • fix(mcp): explain revision-scoped policy and rejections by @shiju-nv in #3850
  • feat(providers): add Oracle Cloud Infrastructure Generative AI provider profile by @fede-kamel in #3904
  • feat(providers): serve sandbox config files on demand by @drew in #3832
  • fix(policy): validate raw OPA settings and redact startup errors by @shiju-nv in #3788
  • Fix/startup provider readiness by @ebusto in #3819
  • test(podman): move podman_preflight into driver-podman integration tests by @politerealism in #3783
  • fix(conformance): require successful list to certify deletion by @elezar in #3792
  • test(tmachine): add K3s conformance scenario by @SDAChess in #3848
  • perf(otel): stop exporting spans from steady-state polling by @krishicks in #3915
  • fix(cli): accept sandbox name before -- in exec by @ericcurtin in #3901
  • fix(network): refuse protocol upgrades on GraphQL endpoints by @shiju-nv in #3841
  • feat(service): add bearer authorization passthrough by @derekwaynecarr in #3796
  • fix(server): log polled request responses at debug by @krishicks in #3974
  • refactor(sandbox): remove unreachable root-side identity and workspace code by @matthewgrossman in #3979
  • fix(e2e): keep locally built Kubernetes images off the chart's default registry by @krishicks in #3991
  • fix(gator): require full head SHA for /ok to test by @purp in #4007
  • fix(gateway): delete finalized ephemeral sandboxes while connected by @johntmyers in #3984
  • refactor(auth): separate sandbox identity from TLS by @drew in #3110
  • chore(build): remove bundled Z3 support by @SDAChess in #3275
  • fix(runtime): recover SSH relays and bound startup diagnostics by @drew in #4011
  • fix(ci): align integration inputs with release candidate source by @SDAChess in #4048
  • test(e2e): remove schema parity campaign by @elezar in #3864
  • fix(ci): qualify protobuf compatibility by release train by @SDAChess in #4049
  • feat(flake): Add missing packages to flake for running mise commands by @bornav in #2151
  • test(tmachine): add Fedora RPM package installer by @elezar in #4025
  • ci: use package installers consistently in integration tests by @elezar in #4056
  • fix(snap): simplify snap hooks by @olivercalder in #3988
  • fix(supervisor): wait for repair when the gateway refuses a startup policy write by @shiju-nv in #3785
  • fix(cli): start sandbox exec without waiting for piped stdin EOF by @fede-kamel in #4006
  • chore(agents): simplify contributor instructions and workflows by @johntmyers in #3987
  • fix(supervisor): bound pending exec stdin and cancel stalled writers by @shiju-nv in #3846
  • fix(policy): refresh pending proposals when the sandbox policy changes by @fede-kamel in #3923
  • feat(sandbox): write agent output to the container log by @krishicks in #4005
  • chore(gator): default to GPT-6.1 Sol by @johntmyers in #4065
  • feat(examples): run Jupyter notebooks in an OpenShell sandbox by @drew in #2253
  • test(python): synchronize interactive exec TTY readiness by @matthewgrossman in #4076
  • fix(sandbox): restrict provider file mode by @drew in #4093
  • fix(ci): retry Nix shell and app dependency preparation by @matthewgrossman in #4066
  • feat(snap): ship the standalone prover binary in the snap by @olivercalder in #3717
  • fix(kubernetes): serialize lifecycle cleanup with sandbox restart by @matthewgrossman in #4078
  • fix(deps): upgrade russh to address Dependabot alert 40 by @alangou in #4116
  • fix(cli)!: stop uploads when Git filtering fails or selects no files by @alangou in #3957
  • fix(providers): restore supervisor-backed GCP metadata discovery by @feloy in #3973
  • feat(helm): add sandbox UID and GID values by @ericcurtin in #3947
  • ci(vm): codesign macOS driver-vm with hypervisor entitlement in CI by @benoitf in #3507
  • ci: pin CI images by digest and add native architecture smoke checks by @alangou in #4114
  • fix(providers): stabilize provider environment revisions by @drew in #4122
  • fix(deps): upgrade ratatui to resolve lru vulnerability by @alangou in #4131
  • fix(sandbox): replace lifetime exec cap with retry deadlines by @drew in #4105
  • fix(cli): check final exec status and warn on partial input by @shiju-nv in #3803
  • fix(install): stop waiting when the gateway service fails by @ericcurtin in #4143
  • fix(docker): pull only :latest for a tagless --from, not every tag by @udsy19 in #4124
  • fix(vm): reject conflicting workload identity selectors by @shiju-nv in #4036
  • fix(vm): reclaim cancelled image preparation after worker exit by @shiju-nv in #4039
  • feat(gateway): check VM host tools during config preflight by @shiju-nv in #4037
  • fix(relay): close outbound relay stream when target closes first by @ericcurtin in #3772
  • fix(tui): preserve quoted post-create command arguments by @thotashashank302 in #4137
  • fix(gateway): give image preparation its own deadline by @shiju-nv in #4038
  • fix(gateway): check launch signing before VM image preparation by @shiju-nv in #4034
  • ci(release): notify duty engineers of prerelease failures by @purp in #4134
  • feat(gateway): support runtime image env overrides by @elezar in #3504
  • test(tmachine): support package-installed Podman driver suites by @elezar in #4107
  • fix(ci): gate tagged publication on qualification by @SDAChess in #4198
  • feat(server): add gateway capacity metrics and optional HPA by @EmilienM in #3978
  • fix(kubernetes): wait for OpenShift SCC annotations by @Ygnas in #4054
  • fix(podman): create managed workspace volumes owned by the workload identity by @matthewgrossman in #3981
  • revert(tmachine): revert package-installed Podman driver suites by @SDAChess in #4206
  • refactor(supervisor): move backend setup behind the selected backend by @shiju-nv in #4176
  • fix(e2e): override provider readiness supervisor image via environment by @SDAChess in #4207
  • fix(docker): generate gateway JWT keys in compose quickstart by @ericcurtin in #3838
  • feat(providers): add multiple tokens to one request by @shiju-nv in #4047
  • fix(test): stabilize tracing span cleanup and assertions by @matthewgrossman in #4212
  • feat(supervisor): export OTLP traces from sandbox supervisors by @krishicks in #3977
  • chore(agents): resolve contributor guidance review gaps by @purp in #4002
  • fix(sandbox): accept local connections natively on loopback-confined sockets by @drew in #4150
  • ci(security): use gpt-6.1-sol with high reasoning effort by @alangou in #4203
  • fix(deps): upgrade pageant to address Dependabot alert 38 by @alangou in #4127
  • fix(ci): stop running e2e in merge queues by @elezar in #4232
  • fix(images): update gateway base and allow supervisor base override by @alangou in #4236
  • chore(deps-dev): bump source-map-js from 1.2.1 to 1.2.2 in /sdk/typescript by @dependabot[bot] in #4224
  • fix(compute): revalidate late exit events after restart by @SDAChess in #4235
  • fix(gator): preserve literal Codex account routing identity by @johntmyers in #4215
  • fix(ssh): persist sandbox host identities by @quocanh261997 in #4094
  • fix(policy): require full binary scope when enabling uninspected credentials by @ericcurtin in #4171
  • fix(license): restore canonical Apache 2.0 wording by @purp in #4249
  • fix(cli): plan sandbox uploads before provisioning by @ericcurtin in #4193
  • perf(server): drop per-connection session tokens for TCP forwards by @n1hility in #3734
  • docs(observability): correct supervisor log access and retention by @johntmyers in #4243
  • feat(server): place supervisor sessions by consistent hash by @FrostGod in #3661
  • feat(ci): add the maintainer approval decision tools by @purp in #3791
  • ci(release): add advisory compatibility review by @SDAChess in #4200
  • fix(sandbox): cut executable identity hashing cost by @ericcurtin in #4221
  • feat(podman): honor OCI image working directories by @matthewgrossman in #3982
  • fix(cli): preserve existing directories during single-file upload by @shiju-nv in #4177
  • fix(auth): match Bearer scheme case-insensitively by @ericcurtin in #4187
  • fix(ci): retain sanitized Codex scan diagnostics on failure by @alangou in #4304
  • fix(providers): prepare dynamic credentials across HTTP relay paths by @shiju-nv in #4152
  • fix(policy): name the field in policy type errors by @ericcurtin in #4174
  • fix(sandbox): remove privileged control socket filters by @FrostGod in #4279
  • fix(ha): keep sandboxes ready across gateway pod rolls by @pimlock in #4321
  • feat(ocsf): emit full JSON records to supervisor stderr by @johntmyers in #4323
  • fix(drivers): validate vendor-agnostic CDI device names by @alangou in #4306
  • fix(gator): handle oversized PR diffs in review ledger by @johntmyers in #4309
  • fix(vm): bump libkrun to v1.19.6 by @benoitf in #4282
  • chore(vm): bump libkrunfw to v5.6.2 by @benoitf in #4285
  • feat(helm): migrate gateway configuration to gatewayConfig by @gmenher in #3384
  • test(supervisor-network): isolate metadata OCSF capture by @grs in #4318
  • fix(sandbox): audit every endpoint in a proposal by @ericcurtin in #4313
  • fix(policy): share endpoint path matching between Rust and Rego by @alangou in #4336
  • fix(sandbox): preserve exec capacity under failure and load by @cjagwani in #4324
  • fix(helm): improve GatewayClass overrides by @danehans in #4345
  • fix(deps): update noyalib and preserve policy null rejection by @drew in #4348

New Contributors

Full Changelog: v0.1.2...v0.1.3