refactor(policy)!: remove NetworkBinary harness field - #3222
johntmyers merged 5 commits into
Conversation
|
@varshaprasad96 I did a manual validation and it works as explained, scalar provider profile lint/import/export/delete works against a local Docker gateway; legacy harness profiles are rejected with the intended migration diagnostic; sandbox creation works. |
|
Label |
|
/ok to test 28495d8 |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
PR Review Status
This implementation matches the linked removal and migration scope, preserves advisor-origin provenance at the endpoint boundary, and has no blocking findings from the initial code review. Required Branch Checks and E2E workflows are running for the current head, so Gator will monitor them before requesting maintainer approval.
Blocking findings:
- No blocking findings remain
Carried findings:
- None
Non-blocking suggestions:
- None
Gator metadata
- Validation: Project-valid implementation of linked issue #3054
- Docs: Architecture, provider profile, and 0.1.0 migration documentation updated
- Checks: Current-head Branch Checks and E2E are in progress; Helm Lint is green
- E2E:
test:e2eapplied, mirror authorization posted, and Branch E2E Checks running - Head SHA:
28495d8803b4380252435ea0d72fed565bbb5611 - Base SHA:
e1084e19db622fd1134454d3b589aab2022aaddf - Merge base SHA:
2ad86c1b2e3e81a26e0fd38ec860398acb31f2fc - Patch ID:
7e8e9eb0678cc383090be852ce40f199d97608ca - Gator payload:
8 - Review mode:
initial - Previous reviewed SHA: none
- Review budget exhausted: no
- Maintainer decision required: no
- Next state:
gator:watch-pipeline
|
Thanks @gmenher, have added in The stored-policy compatibility regression adds an unrelated future field (tag 99) alongside the former Validation steps:
|
|
/ok to test 758f643 |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
Re-check After Author Update
Thanks @varshaprasad96. I checked the regression test added in 758f64309 after your September 9 response: it exercises an unrelated future nested protobuf field through the stored-policy record/payload round trip and then confirms the legacy provenance migration still separates explicit and advisor binaries correctly. The focused follow-up review found no blocking issues. Required current-head Branch E2E Checks are now queued and running.
Disposition: resolved.
Remaining items:
- No blocking items remain
Gator metadata
- Validation: Project-valid implementation of linked issue #3054
- Docs: Architecture, provider profile, and 0.1.0 migration documentation were updated in the reviewed patch; this follow-up is test-only
- Checks: Current-head required Branch Checks, Helm Lint, and E2E status contexts are pending
- E2E:
test:e2eis applied; current-head mirror authorization was posted and Branch E2E Checks run 34410134126 is queued/running - Head SHA:
758f64309b497cbbc06779dc695d73b6b0cae28f - Base SHA:
e1084e19db622fd1134454d3b589aab2022aaddf - Merge base SHA:
2ad86c1b2e3e81a26e0fd38ec860398acb31f2fc - Patch ID:
b5d4531b4160b71369e101b89a00d980584b4346 - Gator payload:
8 - Review mode:
follow_up - Previous reviewed SHA:
28495d8803b4380252435ea0d72fed565bbb5611 - Review budget exhausted: no
- Maintainer decision required: no
- Next state:
gator:watch-pipeline
|
@varshaprasad96 looks like some tests need to be fixed, if you could take a look then we should be able to prep to merge |
|
/ok to test d50f18a |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
Re-check After Maintainer Update
Thanks @johntmyers. I checked the test and provenance concern you raised on September 9 against the author-only 758f64309..d50f18a7 delta. The update now treats clearing advisor provenance as an authorization change, rejects an undeclared existing binary inheriting exact-host private-address trust, keeps distinct-rule fallback separated, and adds focused regressions for both paths. The independent follow-up review found no blocking issues, and required current-head workflows are queued or running.
Disposition: resolved.
Remaining items:
- No blocking items remain
Gator metadata
- Validation: Project-valid implementation of linked issue #3054
- Docs: Architecture, provider profile, and 0.1.0 migration documentation were updated in the reviewed patch; this follow-up changes policy merge behavior and focused tests without adding a new user-facing surface
- Checks: Current-head Branch Checks and Helm Lint are queued/running
- E2E:
test:e2eis applied; current-head mirror authorization was posted and Branch E2E Checks run 34430279538 is queued - Head SHA:
d50f18a79d26cbcf4c8b9b51b1bb0c424455d2b2 - Base SHA:
e1084e19db622fd1134454d3b589aab2022aaddf - Merge base SHA:
2ad86c1b2e3e81a26e0fd38ec860398acb31f2fc - Patch ID:
a08ffb08aae0d60185fc0e618e1866178dc8959e - Gator payload:
8 - Review mode:
follow_up - Previous reviewed SHA:
758f64309b497cbbc06779dc695d73b6b0cae28f - Review budget exhausted: no
- Maintainer decision required: no
- Next state:
gator:watch-pipeline
Closes NVIDIA#3054 Signed-off-by: Varsha Prasad Narsing <varshaprasad96@gmail.com>
Signed-off-by: Varsha Prasad Narsing <varshaprasad96@gmail.com>
Signed-off-by: Varsha Prasad Narsing <varshaprasad96@gmail.com>
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
80f9dac to
fd31886
Compare
|
/ok to test fd31886 |
|
Label |
johntmyers
left a comment
There was a problem hiding this comment.
gator-agent
Re-check After Maintainer Update
Thanks @johntmyers. I verified your current-head mirror authorization and the requested Branch E2E rerun; attempt 2 completed successfully. I also reviewed the author-only 80f9dac2..fd31886d patch delta after the rebase: the compatibility test moved cleanly with its module context, schema fingerprints were refreshed for the new base, and a redundant NetworkBinary default initializer was removed. The independent follow-up review found no blocking issues. Branch Checks are still running, so Gator will continue monitoring this head.
Disposition: resolved.
Remaining items:
- No blocking review items remain
Gator metadata
- Validation: Project-valid implementation of linked issue #3054
- Docs: Architecture and migration documentation remain updated; this follow-up adds no new direct user-facing UX surface
- Checks: Current-head Helm Lint, Trivy Changes, and E2E are green; Branch Checks remain in progress
- E2E:
test:e2eis applied; Branch E2E Checks run 34621923853 attempt 2 succeeded - Head SHA:
fd31886d4b130d7c823513438528e16f19131eba - Base SHA:
d99f12a33be61a89de9d3a29a10a9c732f6cd47e - Merge base SHA:
d99f12a33be61a89de9d3a29a10a9c732f6cd47e - Patch ID:
fe14b5440c439743ff93e828689d71c27760f43c - Gator payload:
8 - Review mode:
follow_up - Previous reviewed SHA:
80f9dac2f709da9dd38b837d501b2756be461dd4 - Review budget exhausted: no
- Maintainer decision required: no
- Next state:
gator:watch-pipeline
Monitoring CompleteMonitoring is complete because this PR has merged. Final status: the current head passed Branch Checks, Helm Lint, and E2E; the latest independent review found no blocking issues, and maintainer approval was present before merge. I removed the active Gator metadata
|
Summary
Remove the deprecated
NetworkBinary.harnessfield before 0.1.0 while preserving advisor-origin provenance at the endpoint/rule boundary.Related Issue
Closes #3054
Changes
harness, update generated Go bindings, and remove runtime, SDK, and profile uses.harnessinput with migration guidance while retaining protobuf wire compatibility.Testing
mise run pre-commitcargo test --workspace --exclude openshell-server -qcargo test -p openshell-server --lib -qcargo test -p openshell-supervisor-network --lib -qcargo test -p openshell-sandbox --lib -qmise run go:cimise run sdk:ts:cimise run test:pythonmise run e2e:docker— blocked before execution because the local Docker daemon was unreachable.Checklist