Conversation
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
3be2384 to
3cf6200
Compare
|
Label |
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
PR Review StatusThe independent code review found no blocking defects in the unsafe-code cleanup. Drew, I checked your CI follow-up: the macOS lint and both Linux Rust test jobs now pass on this head, and the full E2E suite is green. I applied Blocking findings: None. Carried findings: None. Gator metadata
|
Summary
Reduce Rust unsafe syntax sites from 503 to 344 (159 removed), and confine the remaining sites to
openshell-sandbox(238),openshell-driver-vm(56), and the explicitly excluded Windows MXC driver (50). Replace ordinary descriptor, resource, identity and build configuration operations with safe APIs while retaining explicit kernel ABI, fork/pre-exec and FFI boundaries.Related Issue
Directly requested maintainer cleanup. No matching accepted issue is currently linked. This is a draft because moving the Linux mechanism module across crate boundaries requires an accepted issue reference before the PR is ready.
Changes
openshell-isolation-interface::linuxtoopenshell-sandbox::linux; migrate all in-repository consumers and leave the backend interface dependency-light.forbid(unsafe_code)to the CLI, supervisor, sandbox backend and isolation interface targets, and network supervisor library.PROTOC_INCLUDEin a child process rather than mutating build-script globals.plans/unsafe-catalog/directory; the current crate summary is below.Counts include unsafe blocks, functions, implementations and FFI function-pointer declarations, not individual syscalls. Relocated sites are not counted as removals. Generated Go unsafe calls are unchanged.
Compatibility details: external Rust users of
openshell_isolation_interface::linuxmust migrate their imports. The private driver/supervisor flag is now--parent-liveness-stdin, so those binaries must be built together. Tokio foreground signal handlers remain installed for the process lifetime. TheIsolationBackendcontract and public wire protocol are unchanged.Testing
mise run pre-commitpasses, including workspace and sandbox perf-harness lint checks.RUST_TEST_THREADS=4 mise run testpasses after the final descriptor batch. The initial run had two supervisor-network plaintext failures; all five plaintext tests passed on a serial retry, and both failures also passed in the full-suite retry. Their initial failure cause is not proven.OPENSHELL_E2E_DOCKER_TEST=transparent_tcp mise run e2e:dockerpasses after the final batch: six CLI conformance scenarios and native TCP policy-DNS/fail-closed coverage. The Podman-specific scenario is skipped in the Docker lane.git diff --checkverified.mise run ci: attempted, but stopped at 20 Go lint errors in unchanged SDK files (5 errcheck, 12 revive, 3 staticcheck).Checklist
Rebase validation
Rebased onto main at
a48920ac0. Retained main's driver-independent mTLS/bearer TLS behavior, bearer-passthrough exposure assertions, 0600 provider memfd metadata and new upload/broker tests. Pre-commit and Docker transparent-TCP/conformance passed after rebase. The first full run timed out in main's new metadata-loopback broker test; that test passed alone on retry. The fullRUST_TEST_THREADS=4 mise run testretry passed after the heavy Docker builds completed, including the metadata-loopback test and updated mTLS tests.CI follow-up
Commit
06907512efixes the macOS dead-code lint by compiling the boundary environment installer only on Linux, and fixes both Linux nextest signal-probe failures by publishing readiness from an executed Rust workload rather than checking the externalsleepexecutable filename. The old failure was reproduced with a renamed binary; the revised fixture passes nextest with that PATH. Pre-commit and the full local test suite passed. Remote verification on commit06907512epassed all three previously failing jobs in Branch Checks run 37051739763: macOS Rust lint and both Linux Rust test jobs. Other checks are still running; no failures are currently reported.