Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
461 commits
Select commit Hold shift + click to select a range
a5161d0
refactor(server): normalize compute driver config acquisition (#1974)
elezar Jun 29, 2026
a226806
test(e2e): run gpu workloads from manifest (#1709)
elezar Jun 30, 2026
f27ff15
fix(providers): reserve credential placeholder revisions (#2049)
johntmyers Jun 30, 2026
474d2d4
fix(CONTRIBUTING): update label format for good first issues (#2056)
jgarciao Jun 30, 2026
ed0026a
fix(helm): generate namespace-aware SANs in certgen and cert-manager …
akram Jun 30, 2026
0a25fdf
refactor(core): remove unused extra bind addresses (#2059)
elezar Jun 30, 2026
5477e2f
docs(mcp): fix granular policy lifecycle examples (#2066)
shiju-nv Jun 30, 2026
914da33
feat(kubernetes): add combined topology config surface (#2074)
TaylorMutch Jun 30, 2026
450685c
fix(drivers): reject whitespace in mount fields (#2086)
elezar Jul 1, 2026
45614a3
refactor(api): remove SandboxTemplate.volume_claim_templates (#2088)
elezar Jul 1, 2026
abcd15d
feat(helm): add TLS termination for Envoy Gateway ingress (#2015)
zhaohuabing Jul 1, 2026
45060f4
feat(agents): add manifest-driven gator agent (#1826)
johntmyers Jul 1, 2026
43bb030
feat(docker,podman): add SELinux label support for bind mounts (#2092)
bergmannf Jul 2, 2026
5f9bf9c
test(e2e): run rootless podman on ubuntu host (#2119)
elezar Jul 2, 2026
6461677
feat(policy): accept numeric UIDs for sandbox process identity (#1973)
sjenning Jul 2, 2026
f852d07
docs: add Hermes Agent to supported agents table (#2131)
mesutoezdil Jul 3, 2026
6252aa1
rfc-0006: add driver config passthrough proposal (#1589)
elezar Jul 6, 2026
31807d6
chore(deps): bump docker/login-action from 4.2.0 to 4.4.0 (#2146)
dependabot[bot] Jul 6, 2026
5656240
docs: fix STYLEGUIDE heading to match filename (#2134)
mesutoezdil Jul 6, 2026
290297f
docs(kubernetes): bump cert-manager to v1.20.3 (#2129)
mesutoezdil Jul 6, 2026
9c14de7
docs: fix article before OpenShell in sync-files (#2133)
mesutoezdil Jul 6, 2026
eba5dd7
docs: warn to redact credentials from log output before sharing (#2124)
elezar Jul 6, 2026
abe42fb
fix(podman): deliver sandbox JWTs as secrets (#2156)
maxamillion Jul 6, 2026
a727116
chore: remove deprecated --keep flag from docs, scripts, and e2e test…
Ygnas Jul 7, 2026
f7aa3aa
chore(deps): bump astral-sh/setup-uv from 8.2.0 to 8.3.0 (#2160)
dependabot[bot] Jul 7, 2026
2e2b497
fix(driver-podman): gate Linux-only Path import (#2188)
krishicks Jul 8, 2026
ed8ce82
docs: fix Docker version format from 28.04 to 28.0 (#2136)
mesutoezdil Jul 8, 2026
5207f11
docs: update man page date to 2026 (#2135)
mesutoezdil Jul 8, 2026
ff9af8e
fix(sandbox): acknowledge initial policy revision; expose SDK labels/…
KyleZheng1284 Jul 9, 2026
709aa0f
chore(deps): bump astral-sh/setup-uv from 8.3.0 to 8.3.1 (#2191)
dependabot[bot] Jul 9, 2026
83131d7
feat(cli): add --secret-material-env to provider refresh configure (#…
hunglp6d Jul 9, 2026
8871022
docs(telemetry): Added first telemetry report for the community (#2190)
kirit93 Jul 9, 2026
4970108
change packit target to new correct copr project (#2185)
maxamillion Jul 9, 2026
420a855
test(supervisor-network): add proxy hostname parser regression tests …
shaneutt Jul 9, 2026
5f38b7c
fix(tui): route warning logs to status bar instead of stderr (#2210)
r3v5 Jul 10, 2026
ccdac9c
fix(mcp): include tool names in policy logs (#2189)
kirit93 Jul 10, 2026
caaa516
chore(deps): bump astral-sh/setup-uv from 8.3.1 to 8.3.2 (#2206)
dependabot[bot] Jul 10, 2026
8c0ecac
docs(openshift): simplify install steps and add Helm README entries f…
ChristianZaccaria Jul 10, 2026
233d207
docs(issues): require release and duplicate checks (#2214)
elezar Jul 10, 2026
1070213
fix(core): pin supervisor image tag to gateway version for all driver…
benoitf Jul 10, 2026
bebf440
fix(helm): propagate supervisor image overrides (#2216)
TaylorMutch Jul 10, 2026
8eacb47
feat(kubernetes): add sidecar supervisor topology (#2076)
TaylorMutch Jul 10, 2026
614c8c1
feat(kubernetes): support PVC subPath driver config (#2034)
mjamiv Jul 10, 2026
40194f9
fix(network): fail closed when credential placeholders cannot be rewr…
TonyLuo-NV Jul 11, 2026
bb72d01
fix(server): allow newlines in exec command arguments (#1965)
zanetworker Jul 13, 2026
94cdd69
chore(deps): bump actions/stale from 10.3.0 to 10.4.0 (#2234)
dependabot[bot] Jul 13, 2026
88f2656
fix(tui): redraw after sandbox shell exits (#2230)
johntmyers Jul 13, 2026
0fe24a4
fix(agents): add confirmation gate to triage-issue batch mode (#2239)
rhuss Jul 13, 2026
9ad53b3
fix(gator): retry review after draft blocker clears (#2200)
johntmyers Jul 13, 2026
4e1ffef
fix(certgen): stage temp dir inside output dir to fix cross-device re…
gracesmith6504 Jul 13, 2026
fcc9db3
refactor(jsonrpc): carry typed inspection errors (#2244)
shiju-nv Jul 13, 2026
ee9b455
docs(agents): add gator launch skill (#2203)
johntmyers Jul 13, 2026
df06286
chore(python): lower minimum supported Python to 3.11 (#2247)
maxdubrinsky Jul 13, 2026
e3d26dd
fix(policy): keep approved chunk when a mechanistic denial resubmits …
laitingsheng Jul 13, 2026
97e1051
fix(tasks): format all Rust workspaces (#2268)
krishicks Jul 14, 2026
a41cd12
docs: fix stray bracket in provider create command example (#2275)
mesutoezdil Jul 14, 2026
96fd31f
rfc-0010: gateway interceptors (#1927)
drew Jul 14, 2026
e8c16eb
fix(release-dev): update azure/setup-helm to v5.0.1 (#2274)
krishicks Jul 14, 2026
994750e
feat(snap): vendor ssh in openshell snap and remove ssh-keys interfac…
olivercalder Jul 15, 2026
83003e8
feat(interceptors): initial gateway interceptor implementation and re…
drew Jul 15, 2026
e6f319c
feat(sdk): add openshell-sdk crate (#1862)
maxdubrinsky Jul 15, 2026
8029321
fix(sdk): initialize sandbox annotations (#2296)
drew Jul 15, 2026
392ad63
fix(driver-vm): run sandbox supervisor as guest pid 1 (#2299)
drew Jul 15, 2026
b4be33e
feat(ci): introduce merge queue (#2024)
elezar Jul 15, 2026
21aaa89
feat(gateway): add elevated gateway info (#2202)
elezar Jul 15, 2026
3dee557
fix(ci): prune snap assets from dev release (#2302)
pimlock Jul 15, 2026
dd3f27c
feat!(openshell-cli): remove openshell policy prove command and z3 de…
SDAChess Jul 16, 2026
077adb7
fix(server): persist sandbox labels on create (#2306)
matthewgrossman Jul 16, 2026
008193a
fix: remove mentions of bundled-z3 in CI and wheel builds (#2322)
SDAChess Jul 16, 2026
cf4decc
fix(gateway): probe Docker socket during driver auto-detection (#2303)
krishicks Jul 16, 2026
1a0c101
chore(deps): bump actions/setup-node from 6.4.0 to 7.0.0 (#2289)
dependabot[bot] Jul 16, 2026
fe7135a
chore(deps): bump softprops/action-gh-release from 3.0.1 to 3.0.2 (#2…
dependabot[bot] Jul 16, 2026
d0961cd
feat(tui): navigate panels via Up/Down arrow overflow at list boundar…
varshaprasad96 Jul 16, 2026
aa483ec
feat(providers): AWS STS AssumeRole refresh strategy and aws-s3 profi…
russellb Jul 16, 2026
32f0524
rfc-0009: supervisor middleware (#1738)
pimlock Jul 16, 2026
5402551
test(e2e): run VM suite in CI (#2305)
drew Jul 16, 2026
d70adaf
fix(vm-driver): fixes BYOC sandbox creation failing with ext4-fs writ…
bornav Jul 17, 2026
d556748
feat(supervisor-middleware): add network egress middleware (#2027)
pimlock Jul 17, 2026
0606202
docs(gator): require inline review comments (#2346)
johntmyers Jul 17, 2026
98f253b
fix(cli): preserve symlinks in sandbox upload (#2319)
loveRhythm1990 Jul 17, 2026
1fd4d2b
fix(kubernetes): validate sandbox names against RFC 1123 requirements…
2000krysztof Jul 17, 2026
8cf2673
docs: bump stated Rust MSRV from 1.88 to 1.90 (#2276)
mesutoezdil Jul 17, 2026
9a4f8a8
ci: pin docker actions to commit SHA (#2328)
mesutoezdil Jul 20, 2026
339eae5
ci(e2e): reuse prebuilt CLI and gateway artifacts (#2311)
elezar Jul 20, 2026
80987e9
docs: fix broken links and small inconsistencies (#2329)
mesutoezdil Jul 20, 2026
a2cd5f8
fix(gateway): honor tty flag for interactive exec (#2315)
emonq Jul 20, 2026
a9f7131
fix(ci): grant E2E permissions to release workflows (#2376)
pimlock Jul 20, 2026
f32c46d
chore(ci): pin pr gate action (#2368)
elezar Jul 20, 2026
2575585
chore(deps): bump actions/attest from 4.1.1 to 4.2.0 (#2357)
dependabot[bot] Jul 20, 2026
9377e0d
fix(providers): allow git clone/fetch via default GitHub provider (#2…
russellb Jul 20, 2026
745512e
fix(build): raise open-file limit for host musl cross-compile on macO…
purp Jul 20, 2026
ad29ab9
fix(supervisor-network): warn on unsupported L7 access presets (#2177)
lunarwhite Jul 21, 2026
5952a5a
feat(workspace): add workspace resource model with scoping, membershi…
derekwaynecarr Jul 21, 2026
f169084
fix(supervisor): tailor Landlock rights by inode type (#2380)
drew Jul 21, 2026
8d9502d
perf(build): share sccache across worktrees (#2379)
matthewgrossman Jul 21, 2026
e9ac0ee
chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#2381)
dependabot[bot] Jul 21, 2026
744a65d
fix(driver-podman): avoid panic when HOME is unset on macOS (#2327)
mesutoezdil Jul 21, 2026
3ff15a1
fix(ci): fix mirror SHA detection in e2e-label-help workflow (#2236)
rhuss Jul 21, 2026
dae9261
docs(agents): keep project skills synchronized (#2349)
pimlock Jul 21, 2026
472e23f
fix(proxy): include OPA deny reason in CONNECT 403 response (#2363)
zanetworker Jul 21, 2026
bdd1ce8
fix(cli): respect CARGO_TARGET_DIR in openshell wrapper script (#2391)
jhjaggars Jul 21, 2026
396a3b7
docs(brand): add OpenShell brand assets (#2398)
drew Jul 21, 2026
d35d52d
fix(dco): Fix mismatched wording that breaks initial DCO checks (#2399)
matthewgrossman Jul 21, 2026
8b0e54b
docs(extensibility): add gateway interceptor guide (#2397)
drew Jul 21, 2026
2d5652b
docs(docker-compose): replace removed OpenClaw community sandbox with…
Schimuneck Jul 22, 2026
ac3d5c9
docs(prover): correct prove() exit code doc comment (#2395)
eviehoward Jul 22, 2026
cbdeb4d
fix(server): prevent unrelated sandbox deletes from blocking deletion…
pimlock Jul 22, 2026
fd1d3de
fix(e2e): detect gateway workload for health port-forward (#2400)
krishicks Jul 22, 2026
5432d01
feat(tui): add config key support to provider create/update forms (#2…
letv1nnn Jul 22, 2026
ca31805
fix(vm): reduce registry rootfs staging pressure (#2425)
pimlock Jul 22, 2026
cd9a0bf
fix(driver-k8s): add label selector to sandbox watch stream and list …
rhuss Jul 22, 2026
7b444bd
fix(agents): make baked payload readable (#2419)
elezar Jul 22, 2026
0674a00
refactor(cli): extract shared helpers into commands/common module (#2…
varshaprasad96 Jul 22, 2026
8a14b3a
fix(sandbox): skip read-only mounts during recursive chown of /sandbo…
varshaprasad96 Jul 22, 2026
541b97f
fix(mise): initialize Python dependencies in fresh worktrees (#2429)
matthewgrossman Jul 22, 2026
1d4ac70
fix(policy): keep internal allowed IP proposals pending (#2416)
alangou Jul 23, 2026
75d2468
fix(examples): add missing workspace fields to governance interceptor…
pavelanni Jul 23, 2026
59f7839
fix(auth): report gateway authentication status (#2435)
drew Jul 23, 2026
21da343
refactor(supervisor): pass agent proposal state explicitly (#2421)
elezar Jul 24, 2026
f7cd910
fix: eliminate parallel Rust test flakes (#2434)
pimlock Jul 24, 2026
b422b67
feat(cli): add --output json/yaml to sandbox get, status, and sandbox…
rhuss Jul 24, 2026
850bd42
refactor(tui): default create form state (#2458)
elezar Jul 24, 2026
77e5c32
feat(sandbox,gateway): route sandbox egress through corporate HTTP pr…
feloy Jul 24, 2026
01daf3a
chore(deps): bump astral-sh/setup-uv from 8.3.2 to 9.0.0 (#2440)
dependabot[bot] Jul 24, 2026
deced87
refactor(policy): extract shared L7 endpoint validation (#2389)
gracesmith6504 Jul 24, 2026
d4cd37b
chore(deps): bump docker/login-action from 4.4.0 to 4.5.1 (#2488)
dependabot[bot] Jul 27, 2026
afb462f
fix(router): strip unsupported Anthropic beta fields from Vertex rawP…
zanetworker Jul 27, 2026
516be60
fix: assorted byte-index slicing safety fixes (#2452)
andrewwhitecdw Jul 27, 2026
76a5397
fix: assorted arithmetic and indexing robustness fixes (#2451)
andrewwhitecdw Jul 27, 2026
2d10881
fix(policy): avoid panic truncating multi-byte UTF-8 paths for displa…
andrewwhitecdw Jul 27, 2026
39bf94e
fix(server): bind gateway listeners before sandbox resume (#2495)
elezar Jul 27, 2026
79bcf29
fix(proxy): retry with backoff on transient accept errors instead of …
politerealism Jul 27, 2026
2022d53
fix(tasks): scope pre-commit to lint checks (#2503)
drew Jul 27, 2026
0d5e5c5
fix(cli): write exec stderr events to stderr in interactive mode (#2447)
andrewwhitecdw Jul 27, 2026
52f9e9e
fix(cli): eliminate flaky subprocess integration tests (#2504)
rhuss Jul 27, 2026
24d491a
refactor(cli): extract gateway commands into commands/gateway module …
varshaprasad96 Jul 28, 2026
f00ad23
fix(podman): tolerate shutdown transport closes (#2498)
elezar Jul 28, 2026
7e9a7f5
fix(sandbox): gate Linux-only ordering import (#2513)
elezar Jul 28, 2026
b78c861
fix(server): stabilize flaky delete telemetry unit test (#2521)
derekwaynecarr Jul 28, 2026
efb2d9c
fix(e2e): bound podman stop timeout in tests (#2516)
elezar Jul 28, 2026
b1c7ff6
ci: add focused macOS Rust lint (#2515)
elezar Jul 28, 2026
2b7f04f
feat(examples): add supervisor middleware content guard (#2169)
pimlock Jul 28, 2026
7955c83
feat(k8s): support configuring workspace PVC storageClassName (#2463)
loveRhythm1990 Jul 29, 2026
bc14018
feat(sandbox): use policy-first OCI image identity (#2509)
matthewgrossman Jul 29, 2026
101cbc9
fix(cli): avoid panic on multi-byte UTF-8 in --since duration (#2446)
andrewwhitecdw Jul 29, 2026
8d252f4
chore(deps): bump docker/login-action from 4.5.1 to 4.5.2 (#2537)
dependabot[bot] Jul 29, 2026
662dee6
refactor(compute): make sandbox readiness gateway-owned across all dr…
elezar Jul 29, 2026
d0f9301
chore(deps): bump actions/stale from 10.4.0 to 11.0.0 (#2536)
dependabot[bot] Jul 29, 2026
1221b58
fix(cli): isolate subprocess tests from host OPENSHELL_ env vars (#2523)
rhuss Jul 29, 2026
eb380d7
ci(e2e): probe VM gateway readiness (#2544)
elezar Jul 29, 2026
0cecb54
fix(cli): bracket IPv6 bind literals in SSH forwards (#2552)
russellb Jul 29, 2026
1cbfc0d
test(e2e): add reusable QEMU infrastructure for E2E tests (#2471)
drew Jul 29, 2026
9c019a9
Wire authorization into workspace model (#2445)
derekwaynecarr Jul 30, 2026
7f53f78
fix(gator): preserve resolved review feedback (#2533)
drew Jul 30, 2026
fe15caa
test(e2e): add VM-backed E2E suite runner (#2473)
drew Jul 30, 2026
df69804
refactor(server): isolate gateway listener context (#2542)
elezar Jul 30, 2026
28f3bee
fix(server): notify watchers after atomic policy commits (#2556)
NaveCohenMonday Jul 30, 2026
fa24299
feat(gateway): export traces over OTLP (#2534)
krishicks Jul 30, 2026
02e890c
docs: document issue lifecycle labels and roadmap sequencing (#2524)
krishicks Jul 30, 2026
596d729
fix(ci): preserve KVM access across udev restarts (#2566)
matthewgrossman Jul 30, 2026
5541398
fix(deps): update russh dompurify and base image of the gateway (#2575)
alangou Jul 31, 2026
1a25439
refactor(otel): share OTLP trace provider setup (#2567)
krishicks Jul 31, 2026
d220d89
feat(compute): negotiate gateway callback listeners (#2492)
elezar Jul 31, 2026
489bb0d
fix(server): isolate otel tracing test exporters (#2579)
krishicks Jul 31, 2026
770d4e6
chore(deps): bump actions/attest from 4.2.0 to 4.2.1 (#2572)
dependabot[bot] Jul 31, 2026
905b554
refactor(network): consolidate proxy egress pipeline (#2373)
johntmyers Jul 31, 2026
06c2db7
fix(podman): combine sandbox stop and removal (#2570)
pimlock Jul 31, 2026
584f7db
chore(deps): bump docker/login-action from 4.5.2 to 4.6.0 (#2573)
dependabot[bot] Jul 31, 2026
c42268b
chore(build): bump sccache to 0.16.0 (#2581)
matthewgrossman Jul 31, 2026
e753317
test(server): stabilize watch span cancellation test (#2582)
pimlock Aug 1, 2026
736e431
fix(supervisor): quote nft log prefix in bypass rules (#2555)
gracesmith6504 Aug 1, 2026
1959ea1
build(bazel): establish RFC 0012 Rust reference graph (#2414)
SDAChess Aug 3, 2026
fde96f0
build(bazel): add OpenTelemetry crate targets (#2595)
SDAChess Aug 3, 2026
704880e
test(podman): gate gateway discovery test on Linux (#2580)
krishicks Aug 3, 2026
0a3ec7a
feat(bazel): add rustfmt checks to tests (#2599)
SDAChess Aug 3, 2026
8328412
feat(vm): export driver traces over OTLP (#2564)
krishicks Aug 3, 2026
b981861
test: disable tests flaky under parallel stress (#2611)
SDAChess Aug 4, 2026
0e9a44c
feat(build): add system CA root mode (#2324)
politerealism Aug 4, 2026
4d55265
test(server): close traced handler before span assertion (#2604)
krishicks Aug 4, 2026
d063751
docs: add experimental Bazel build commands to CONTRIBUTING.md (#2600)
rhuss Aug 4, 2026
5378055
feat(sandbox): honor OCI image working directories (#2530)
matthewgrossman Aug 4, 2026
490f66f
docs(cli): recommend providers for secrets (#2603)
krishicks Aug 4, 2026
8c7dd14
perf(net): set TCP_NODELAY on latency-sensitive TCP hops (#2220)
purp Aug 4, 2026
5548405
feat(credentials): add provider credential storage drivers (#2437)
sjenning Aug 5, 2026
f383ee1
feat(mise): run fmt as part of pre-commit (#2621)
krishicks Aug 5, 2026
284da54
docs(readme): add theme-aware banner (#2619)
johnnygreco Aug 5, 2026
c5f8366
feat(sdk/go): add Go SDK foundation, types, and sandbox client (A) (#…
rhuss Aug 5, 2026
85d992f
RFC 0005: Sandbox proxy egress adapter model (#2155)
johntmyers Aug 5, 2026
d2c44b0
fix(supervisor-middleware): configure HTTP/2 keepalive on middleware …
letv1nnn Aug 5, 2026
0c7e59a
fix(deps): bump russh, jsonwebtoken, tar and npm lint deps (#2617)
alangou Aug 6, 2026
d85339d
build(bazel): add credential driver targets (#2649)
SDAChess Aug 7, 2026
8ddd98c
feat(bazel): build vm driver and pull runtime from Github (#2650)
SDAChess Aug 7, 2026
4cb77a9
fix(e2e): separate Podman Machine loopback listeners (#2622)
matthewgrossman Aug 7, 2026
5e2f0d1
fix(policy): prevent implicit authorization inheritance (#2499)
shiju-nv Aug 9, 2026
f48b05e
fix(gateway-interceptors): apply tls-native-roots for HTTPS intercept…
sauagarwa Aug 10, 2026
a8bdebe
fix(sandbox): acknowledge unchanged policy revisions (#2557)
NaveCohenMonday Aug 10, 2026
3ebed4e
fix(gator): allow same-sha state nudges (#2681)
johntmyers Aug 10, 2026
0120535
feat(proxy): bind static credentials to provider endpoints (#2510)
johntmyers Aug 10, 2026
815615f
fix(gateway-interceptors): configure connect timeout and HTTP/2 keepa…
letv1nnn Aug 10, 2026
1709619
chore(ci): disable telemetry in internal test runs (#2648)
matthewgrossman Aug 10, 2026
c825b1f
perf(supervisor-middleware): remove body clones from local dispatch (…
shiju-nv Aug 10, 2026
3e19155
feat(build): add glibc-static supervisor libc variant (#2682)
EmilienM Aug 11, 2026
0310cbe
fix(sbom): detect sha256 hashes in expression-form licenses in needs_…
mesutoezdil Aug 11, 2026
2f96c53
feat(gateway,cli): windows compilation support (#2496)
araza008 Aug 11, 2026
dd2b4e3
feat(cli): warn when --env values look like credentials (#2655)
letv1nnn Aug 11, 2026
d22859c
fix(gator): separate review budget from approval gate (#2704)
johntmyers Aug 12, 2026
f24a5ae
perf(supervisor-network): avoid reparsing native policy input (#2654)
shiju-nv Aug 12, 2026
245fe27
fix(dev): separate Podman Machine loopback listeners (#2725)
krishicks Aug 12, 2026
0f8fad2
feat(sandbox): add stop and start operations (#2653)
sjenning Aug 13, 2026
cd4d905
ci(cargo-deny): add dependency audit with cargo-deny (#2677)
Ygnas Aug 13, 2026
8dc55e2
feat(sdk/go): complete Go SDK with domain clients, auth, and hardenin…
rhuss Aug 13, 2026
403dc75
chore(deps): bump jdx/mise-action from 4.2.0 to 4.2.4 (#2716)
dependabot[bot] Aug 13, 2026
496659c
chore(deps): bump Swatinem/rust-cache from 2.9.1 to 2.9.2 (#2670)
dependabot[bot] Aug 13, 2026
35fb27e
feat(sdk): add TypeScript SDK (@nvidia/openshell-sdk) (#2122)
maxdubrinsky Aug 13, 2026
c549823
docs(telemetry): split reports into one file per period and add Jul 2…
kirit93 Aug 13, 2026
c4b500a
feat(helm): cert-manager external issuer + OpenShift passthrough Rout…
jhjaggars Aug 14, 2026
7547edc
docs(issues): Center reports on user stories (#2615)
krishicks Aug 14, 2026
7a7b3ee
chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#2746)
dependabot[bot] Aug 14, 2026
d0c6dc3
feat(kubernetes): support corporate upstream proxy (#2633)
loveRhythm1990 Aug 14, 2026
1074566
chore(deps): bump astral-sh/setup-uv from 9.0.0 to 10.0.0 (#2747)
dependabot[bot] Aug 14, 2026
f12f3ef
fix(macos): restore Homebrew sandbox callbacks (#2739)
drew Aug 14, 2026
bdabb54
fix(security): authenticate extension services (#2638)
pimlock Aug 14, 2026
ae40cf6
fix(gateway): respect OPENSHELL_BIND_ADDRESS in dev task (#2756)
krishicks Aug 14, 2026
3581b9e
CODEOWNERS: remove maxamillion and add sjenning (#2755)
sjenning Aug 14, 2026
59479f4
feat(k8s): add namespace-per-workspace support (RFC 0011 Phase 3) (#2…
derekwaynecarr Aug 14, 2026
44bf0df
feat(middleware): inspect WebSocket text messages (#2477)
pimlock Aug 14, 2026
d51a653
feat(driver-podman): add userns config (#2562)
giuseppe Aug 15, 2026
88cf35e
fix(bazel): enable driver extraction in core (#2769)
SDAChess Aug 17, 2026
6ebf10e
fix(build): preserve version prefixes in mise lockfile (#2778)
alangou Aug 17, 2026
5d9b0f0
fix(inference): prepend publisher prefix for Vertex non-Anthropic mod…
politerealism Aug 17, 2026
4dfeff5
docs(rfc): add RFC 0013 native Windows support via MXC (#2071)
shailendra-nv Aug 17, 2026
6340d18
Update docs.yml to remove warning banner (#2687)
kirit93 Aug 17, 2026
877ddba
fix(supervisor-network): canonicalize dot-segments before policy eval…
alangou Aug 17, 2026
2115b0c
fix(driver-podman): compile container spec on macOS (#2789)
elezar Aug 18, 2026
dc374e8
chore(sdk/go): remove coverage.out from tracking (#2774)
rhuss Aug 18, 2026
600bbae
feat(ocsf): emit AI inference events via ai_operation profile on ApiA…
zanetworker Aug 18, 2026
8d67250
fix(providers): keep refresh credential handles stable (#2780)
mrunalp Aug 18, 2026
0d708d6
fix(policy): gate uninspected credentialed endpoints (#2493)
alangou Aug 19, 2026
3a16012
fix(cli): prompt for fresh OIDC login after logout (#2773)
grs Aug 19, 2026
2eb0880
feat(cli): support OIDC device authorization grant for headless login…
jhjaggars Aug 19, 2026
998db04
feat(policy): allow non-root sandbox identities (#2785)
drew Aug 19, 2026
6e90f3d
feat(providers): store refresh credentials in credential drivers (#2801)
mrunalp Aug 19, 2026
b7078dc
chore(gitignore): add Pi agent state (#2813)
krishicks Aug 19, 2026
c90fd64
fix(cli): reuse sandbox provisioning display (#2816)
sjenning Aug 19, 2026
701382d
fix(podman): wait for container stop completion (#2820)
pimlock Aug 20, 2026
7909fb5
refactor(compute): unify gateway restart reconciliation (#2743)
drew Aug 20, 2026
9505ca5
chore: remove Bazel build support (#2840)
SDAChess Aug 20, 2026
4c5fce6
refactor(compute): support external driver parity (#2744)
drew Aug 20, 2026
5d9c3b3
Merge remote-tracking branch 'upstream/main' into chore/resync-20260820
rodbutters Aug 20, 2026
bddc58d
feat(python): restore Aible SDK wrappers on upstream API (workspace-s…
rodbutters Aug 21, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
122 changes: 77 additions & 45 deletions .agents/skills/build-from-issue/SKILL.md

Large diffs are not rendered by default.

341 changes: 341 additions & 0 deletions .agents/skills/build-openshell-mxc-windows/SKILL.md

Large diffs are not rendered by default.

230 changes: 230 additions & 0 deletions .agents/skills/build-openshell-mxc-windows/reference.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,230 @@
# Reference: Windows MSVC maintenance lane

Companion to [SKILL.md](SKILL.md). Use this file for quick lookup while
maintaining the existing build-only Windows MSVC lane.

## Lane Files

| File | Purpose |
|---|---|
| `tasks/windows.toml` | Mise task definitions for `windows:*`. |
| `tasks/scripts/windows-msvc.ps1` | Visual Studio environment discovery, rustup target setup, Cargo invocation, logs, artifact report. |
| `.github/workflows/windows-msvc.yml` | Manual GitHub Actions x64 job and disabled ARM64 scaffold, each with an architecture-specific Rust dependency cache. |
| `architecture/windows-msvc-build.md` | Human-readable design contract. |

## Commands

Use `--skip-tools` for all Windows mise tasks:

```powershell
mise run --skip-tools windows:check:x64
mise run --skip-tools windows:check:arm64
mise run --skip-tools windows:build:x64
mise run --skip-tools windows:build:arm64
mise run --skip-tools windows:test:x64
mise run --skip-tools windows:test:arm64
mise run --skip-tools windows:test:unsupported:x64
mise run --skip-tools windows:test:unsupported:arm64
mise run --skip-tools windows:ci
```

For host-native full validation, detect architecture first:

```powershell
$arch = [System.Runtime.InteropServices.RuntimeInformation]::OSArchitecture
if ($arch -eq [System.Runtime.InteropServices.Architecture]::Arm64) {
mise run --skip-tools windows:check:arm64
mise run --skip-tools windows:build:arm64
mise run --skip-tools windows:test:arm64
mise run --skip-tools windows:test:unsupported:arm64
mise run --skip-tools windows:artifacts
} else {
mise run --skip-tools windows:ci
}
```

The native test tasks reject a target that does not match the host architecture.
Do not report x64 compatibility-under-emulation coverage from an ARM64 run.

The wrapper adds missing rustup targets and clears inherited
`RUSTC_WRAPPER`. It does not install Visual Studio, Rust, Docker, Kubernetes,
Podman, WSL, Hyper-V, or VM tooling.

On Windows, `mise run pre-commit` routes `rust:check`, `rust:lint`, and
`test:rust` through this wrapper for the host-native target. The shared task
definitions retain their existing Unix commands. Only tests for Linux glibc
installer behavior, Linux build-environment shell helpers, and Linux
service/RPM packaging assets skip on Windows. The Windows Clippy command
excludes unsupported runtime packages as top-level targets and allows only
unused imports, dead code, and unused async functions caused by cfg-gated
Windows stubs; other warnings remain errors.

The wrapper limits Cargo to four jobs by default and serializes wrapper-owned
Cargo commands with a host-local mutex. It does not set `CL` or `_CL_` because
`clang-cl` also consumes them and can parse a global `/MP4` option as an input
file.

For ARM64, verify the Visual Studio instance contains the ARM64 MSVC tools,
ARM64 Spectre-mitigated libraries, Clang tools, CMake tools, and a Windows SDK.
Clang supplies host-native `libclang.dll` for `bindgen` and `clang-cl.exe` for
ARM64 crypto dependencies such as `ring` and `aws-lc-sys`. Native ARM64 uses
the normal bundled-Z3 CMake path. An x64-to-ARM64 check/build discovers and
adds host-native Ninja to `PATH`, while the crypto crates select `clang-cl`.
Bundled Z3 uses CMake's Visual Studio ARM64 generator with native MSVC `cl.exe`
because `z3-sys 0.10.9` passes the MSBuild-only `-m` argument. Use a short
`CARGO_TARGET_DIR` if Windows path-length limits are reached.

## Unsupported Driver Rules

Windows is a build target only. These runtimes remain unsupported:

- Docker
- Kubernetes
- Podman
- VM

Rules:

- Keep config/library stubs where the gateway needs them.
- Return clear unsupported errors at runtime.
- Do not build standalone Windows driver binaries.
- Do not add Docker Desktop, WSL, Hyper-V, Podman machine, Podman Desktop, or
VM-backed execution as part of this skill.

Current focused unsupported-contract tests:

```text
windows_builtin_compute_drivers_report_unsupported
```

Run them with the architecture-specific focused task on the native host.

## Cargo Excludes

The Windows wrapper intentionally excludes unsupported runtime packages as
top-level workspace targets for check/test:

```text
--exclude openshell-driver-docker
--exclude openshell-driver-kubernetes
--exclude openshell-driver-kubernetes-secrets
--exclude openshell-driver-podman
--exclude openshell-driver-vault
--exclude openshell-driver-vm
--exclude openshell-sandbox
--exclude openshell-supervisor-network
--exclude openshell-supervisor-process
--exclude openshell-vfio
```

The gateway keeps platform configuration and unsupported-operation contracts
without depending on the Docker, Kubernetes, Podman, sandbox supervisor,
process supervisor, VM, or VFIO runtime crates. The Kubernetes Secrets and
Vault libraries still compile as gateway dependencies; only their standalone
Unix-socket binaries and package-level tests are excluded as top-level targets.

## Common Errors

### Unix imports leak into Windows builds

Symptoms:

```text
unresolved import std::os::unix
unresolved import tokio::net::UnixListener
unresolved import nix::...
```

Fix pattern:

```rust
#[cfg(unix)]
use tokio::net::{UnixListener, UnixStream};
```

Move Unix-only functions into Unix-only modules, or add a Windows stub that
returns an unsupported error.

### Linux-only dependency reaches Windows

Symptoms:

```text
failed to run custom build command for libseccomp-sys
pkg-config could not find libsecret
```

Fix pattern:

```toml
[target.'cfg(target_os = "linux")'.dependencies]
libseccomp = "..."
```

Only gate the dependency if no Windows path should use it.

### ARM64 check fails but x64 passes

Likely causes:

- Native dependency does not support `aarch64-pc-windows-msvc`.
- ARM64 MSVC or Spectre-mitigated libraries are missing.
- Host-native `clang-cl`, Ninja, or CMake is missing during an x64-to-ARM64 build.
- `CL` or `_CL_` injects a global MSVC option such as `/MP4` into `clang-cl`.
- Build script assumes x64 tools.
- Inline assembly or prebuilt artifact lacks ARM64 handling.

Do not skip ARM64 silently. Either fix the target handling or report the exact
blocked dependency.

### Focused tests report many filtered-out tests

This is expected for `windows:test:unsupported:x64`. Cargo runs one named test
and filters the other `openshell-server` tests. Report these as filtered, not
ignored.

## Reporting Counts

Use the log summaries from:

| Log | Count source |
|---|---|
| `test-x86_64-pc-windows-msvc.log` | Full x64 workspace test pass. |
| `test-aarch64-pc-windows-msvc.log` | Full native ARM64 workspace test pass. |
| `test-x86_64-pc-windows-msvc-unsupported-*.log` | Focused unsupported-contract re-runs and filtered counts. |
| `test-aarch64-pc-windows-msvc-unsupported-*.log` | Focused native ARM64 re-runs and filtered counts. |

Separate:

- passed
- failed
- ignored
- filtered out
- cfg-gated zero-test targets
- package-level excludes

Package-level excludes are not printed as ignored tests by Cargo.

## Final Sanity Checks

Before committing Windows-lane changes, choose checks based on the host
architecture:

```powershell
cargo fmt --all
git diff --check
$arch = [System.Runtime.InteropServices.RuntimeInformation]::OSArchitecture
if ($arch -eq [System.Runtime.InteropServices.Architecture]::Arm64) {
mise run --skip-tools windows:check:arm64
mise run --skip-tools windows:build:arm64
mise run --skip-tools windows:test:arm64
mise run --skip-tools windows:test:unsupported:arm64
} else {
mise run --skip-tools windows:check:x64
mise run --skip-tools windows:check:arm64
mise run --skip-tools windows:test:unsupported:x64
}
```

Run the full x64-host `windows:ci` lane when build or test behavior changed and
the host can run that lane natively.
50 changes: 34 additions & 16 deletions .agents/skills/create-github-issue/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,22 +17,27 @@ This project uses YAML form issue templates. When creating issues, match the tem

### Bug Reports

Do not add a type label automatically. The body must include an **Agent Diagnostic** section — this is required by the template and enforced by project convention. Apply area or topic labels only when they are clearly known.
Do not add a type label automatically. The body must include a **User Story**, **Problem Statement**, **Impact / Why This Matters**, and **Acceptance Criteria**, followed by bug-specific reproduction steps and environment details. Logs are optional and must be concise and redacted. Apply area or topic labels only when they are clearly known.

```bash
gh issue create \
--title "bug: <concise description>" \
--body "$(cat <<'EOF'
## Agent Diagnostic
## User Story

<Paste the output from the agent's investigation. What skills were loaded?
What was found? What was tried?>
As a <persona>, I want <capability or outcome>, so that <benefit or impact>.

## Description
## Problem Statement

<Summarize what is broken or missing in OpenShell's current behavior and when the issue occurs>

## Impact / Why This Matters

**Actual behavior:** <what happened>
<Explain the consequences for users, the current workaround, and why that workaround is insufficient>

**Expected behavior:** <what should happen>
## Acceptance Criteria

- [ ] <observable outcome that demonstrates the bug is fixed>

## Reproduction Steps

Expand All @@ -41,43 +46,54 @@ What was found? What was tried?>

## Environment

- OS: <os>
- Docker: <version>
- OpenShell: <version>
- OS: <os>
- Runtime, deployment, or integration: <relevant details>

## Logs

```
<relevant output>
<optional minimal, redacted output>
```
EOF
)"
```

### Feature Requests

Do not add a type label automatically. The body must include a **Proposed Design** — not a "please build this" request. Apply area or topic labels only when they are clearly known.
Do not add a type label automatically. The body must include a **User Story**, **Problem Statement**, **Impact / Why This Matters**, **Proposed Design**, **Acceptance Criteria**, and **Alternatives Considered**. The proposed design should define the user-facing workflow and externally observable behavior without prescribing internal implementation. Agent investigation is optional. Apply area or topic labels only when they are clearly known.

```bash
gh issue create \
--title "feat: <concise description>" \
--body "$(cat <<'EOF'
## User Story

As a <persona>, I want <capability or outcome>, so that <benefit or impact>.

## Problem Statement

<What problem does this solve? Why does it matter?>
<Summarize the capability or behavior missing from OpenShell today>

## Impact / Why This Matters

<Explain what users must do today, why it is insufficient, and the operational cost, risk, blocked workflow, or adoption barrier>

## Proposed Design

<How should this work? Describe the system behavior, components involved,
and user-facing interface.>
<The desired user-facing workflow and externally observable behavior, without prescribing internal implementation>

## Acceptance Criteria

- [ ] <specific, observable outcome>

## Alternatives Considered

<What other approaches were evaluated? Why is this design better?>
<Other user-facing workflows or behaviors considered and why this approach best satisfies the user story>

## Agent Investigation

<If the agent explored the codebase to assess feasibility, paste findings here.>
<Optional findings from codebase exploration>
EOF
)"
```
Expand Down Expand Up @@ -107,6 +123,8 @@ EOF

GitHub built-in issue types (`Bug`, `Feature`, `Task`) should come from the matching issue template when possible, or be set manually afterward. Do not try to emulate them through labels.

Creating an issue does not accept it or queue agent work. Agents never apply `state:accepted`, the `roadmap` label, add issues to the roadmap project, or apply `agent:plan-requested` or `agent:implementation-requested`. Community issues proceed through `triage-issue`; a human accepts technically validated work with `state:accepted` or roadmap placement. The request labels queue work for unattended agents; a user may instead direct an agent to a specific issue.

## Useful Options

| Option | Description |
Expand Down
14 changes: 10 additions & 4 deletions .agents/skills/create-github-pr/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ Create pull requests on GitHub using the `gh` CLI.

- The `gh` CLI must be authenticated (`gh auth status`)
- You must have commits on a branch that's pushed to the remote
- Branch should follow naming convention: `<issue-number>-<description>/<username>`
- For issue-backed work, the branch should follow `<issue-number>-<description>/<username>`. Exempt issue-less changes may use `<description>/<username>`.

## Before Creating a PR

Expand All @@ -24,6 +24,10 @@ in the same branch. If the change affects user-facing compute-driver setup,
also update `docs/reference/sandbox-compute-drivers.mdx` or the relevant
deployment docs.

### Check Agent Infrastructure

Use the `sync-agent-infra` skill's maintenance map to identify related skill updates when the branch changes behavior, commands, or development workflows. Run its full consistency check when the branch adds, removes, or renames skills or crates; changes workflow relationships or skill coverage; modifies issue or PR templates; or changes agent cross-references. Resolve any drift before creating the PR.

### Run Pre-commit Checks

Run the local pre-commit task before opening a PR:
Expand All @@ -43,7 +47,7 @@ Before creating a PR, verify:
git branch --show-current
```

2. **Branch follows naming convention** - Format: `<issue-number>-<description>/<initials>`
2. **Branch follows naming convention** - Use `<issue-number>-<description>/<initials>` for issue-backed work or `<description>/<initials>` for an exempt issue-less change.

```bash
# Example: 1234-add-pagination/jd
Expand Down Expand Up @@ -110,7 +114,7 @@ gh pr create --title "PR title" --body "PR description"

### Link to an Issue

Use `Closes #<issue-number>` in the body to auto-close the issue when merged:
Features, user-visible behavior changes, public API changes, architecture changes, and multi-PR efforts must link an accepted issue. Use `Closes #<issue-number>` in the body to auto-close the issue when merged:

```bash
gh pr create \
Expand All @@ -122,6 +126,8 @@ gh pr create \
- Returns 400 instead of 500"
```

Small documentation fixes, mechanical maintenance, and obvious localized bug fixes may omit a separate issue when the PR contains enough context to review the decision and implementation together. In that case, write `No issue required: <brief reason>` in the Related Issue section. Do not use this exception for security fixes; follow `SECURITY.md`.

### Create as Draft

For work-in-progress that's not ready for review:
Expand Down Expand Up @@ -153,7 +159,7 @@ PR descriptions must follow the project's [PR template](.github/PULL_REQUEST_TEM
<!-- 1-3 sentences: what this PR does and why -->

## Related Issue
<!-- Fixes #NNN or Closes #NNN -->
<!-- Fixes #NNN / Closes #NNN, or "No issue required: <reason>" for an exempt change -->

## Changes
<!-- Bullet list of key changes -->
Expand Down
Loading
Loading