Repository navigation
fix(supervisor): report plaintext scheme to middleware - #4397
Open
ericcurtin wants to merge 1 commit into
Open
ericcurtin wants to merge 1 commit into
ericcurtin wants to merge 1 commit into
Conversation
Closes NVIDIA#4253 Signed-off-by: Eric Curtin <eric.curtin@docker.com>
ericcurtin
requested review from
a team,
derekwaynecarr,
mrunalp and
sjenning
as code owners
October 10, 2026 08:25
Contributor
Author
|
@pimlock @krishicks PTAL when you get a chance, and |
10 of 12 tasks
bettyc925
pushed a commit
to AtlaSent/atlasent-mcp-server
that referenced
this pull request
Oct 10, 2026
Makes "this OpenShell release reports the real scheme" a measurement rather than a changelog read, following the startup-probe pattern. - runTransportIdentityProbe sends a TLS and a tunnelled-plaintext request and compares the scheme middleware was told. Passes only if TLS reads https and plaintext reads http; not_observed fails; the TLS case is the in-run positive control; defect_4397 flags plaintext reported as https. - npm run test:openshell-transport-acceptance: opt-in live harness (OPENSHELL_VERSION + OPENSHELL_TRANSPORT_PROBE_CMD), never in npm test. - The workload guard now logs the scheme/host/port OpenShell reported, on allow and deny; reportedSchemeFromGuardLog reads it back. - The #4397 advisory drops only for a version listed in OPENSHELL_TRANSPORT_IDENTITY_CONFIRMED, which is empty until a live pass is recorded. Not yet run against a live OpenShell. Dry-run against stub commands: emulated #4397 fails with defect_4397, emulated fix passes, a blind harness fails not_observed. Six mutations of the probe and log each fail a test. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012SejQX5UcKWoqk5xQvP1yd
|
Thanks for picking this up and putting together the fix — I really appreciate it. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Plaintext HTTP in a tunnel reached middleware as
https(andwss). Derive the scheme from the transport.Related Issue
Closes #4253
Changes
request_schemeandwebsocket_schemetoL7EvalContext.httpsandwss.Testing
cargo test,cargo clippy -D warningsandcargo fmtpass foropenshell-supervisor-network.Checklist