Skip to content

fix(policy): register shared network schema at runtime#7531

Merged
cv merged 1 commit into
NVIDIA:mainfrom
HOYALIM:codex/fix-runtime-network-schema-registration
Jul 25, 2026
Merged

fix(policy): register shared network schema at runtime#7531
cv merged 1 commit into
NVIDIA:mainfrom
HOYALIM:codex/fix-runtime-network-schema-registration

Conversation

@HOYALIM

@HOYALIM HOYALIM commented Jul 25, 2026

Copy link
Copy Markdown
Contributor

Summary

Restore runtime sandbox-policy validation after #6877 extracted network policy definitions into an external schema. The runtime validator now registers that shared schema before compiling the sandbox schema, and the published package ships both files.

Changes

  • Load and register network-policy.schema.json before compiling the sandbox policy schema.
  • Include the shared schema in the npm package.
  • Extend the out-of-tree package contract to prove the referenced schema is shipped and runtime validation succeeds.

Type of Change

  • Code change (feature, bug fix, or refactor)
  • Code change with doc updates
  • Doc only (prose changes, no code sample modifications)
  • Doc only (includes code sample changes)

Quality Gates

  • Tests added or updated for changed behavior
  • Existing tests cover changed behavior — justification:
  • Tests not applicable — justification:
  • Docs updated for user-facing behavior changes
  • Docs not applicable — justification: This restores the existing schema-validation behavior and package contents. It does not change policy syntax, CLI behavior, configuration, or a user procedure.
  • Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging)
  • Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: Maintainer comparison confirmed the runtime registers only the trusted schema shipped by NemoClaw. Policy semantics, rejected input handling, and bounded error disclosure remain unchanged. Independent PR approval remains required before merge.
  • Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue:

Documentation Writer Review

  • Documentation writer subagent reviewed the completed changes
  • Result: no-docs-needed
  • Evidence: The writer reviewed the live body and exact three-file diff against WRITING.md and docs/CONTRIBUTING.md. The fix restores existing policy validation and package contents without changing the schema, configuration, supported behavior, or user workflow.
  • Agent: Codex Desktop

DGX Station Hardware Evidence

  • Tested on DGX Station
  • Tested commit:
  • Station profile/scenario:
  • Result:
  • Supporting evidence:

Verification

  • PR description includes a Signed-off-by: line and every commit appears as Verified in GitHub
  • Normal pre-commit, commit-msg, and pre-push hooks passed, or npm run check:diff passed when hooks were skipped or unavailable
  • Targeted behavior tests pass for the current change set, or tests are marked not applicable above — command/result or justification: The installed package validator contract passes 1/1, and the focused policy suites pass 56/56.
  • Applicable broad gate passed — npm test for broad runtime/test-harness changes; npm run check for repo-wide validation/coverage changes — command/result: Not applicable to this focused three-file integration repair.
  • Quality Gates section completed with required justifications or waivers
  • No secrets, API keys, or credentials committed
  • npm run docs builds without warnings (doc changes only)
  • Doc pages follow the style guide (doc changes only)
  • New doc pages include SPDX header and frontmatter (new pages only)

Follow-up to #6877. Supersedes duplicate #7533 and preserves Ho Lim's original-author credit.


Signed-off-by: Ho Lim subhoya@gmail.com

Summary by CodeRabbit

  • Bug Fixes

    • Improved sandbox policy validation by incorporating network policy schema checks.
    • Added clearer handling when required policy schemas are unavailable or validation cannot be initialized.
  • Chores

    • Ensured the network policy schema is included in published packages.
    • Expanded package verification to confirm the schema is available after installation.

Signed-off-by: Ho Lim <subhoya@gmail.com>
Copilot AI review requested due to automatic review settings July 25, 2026 20:26
@copy-pr-bot

copy-pr-bot Bot commented Jul 25, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai

coderabbitai Bot commented Jul 25, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

The sandbox policy validator now loads and registers the network policy schema alongside the sandbox policy schema. The npm package whitelist and package contract test are updated to include and verify the published network schema.

Changes

Network policy schema support

Layer / File(s) Summary
Load and register network policy schema
src/lib/policy/sandbox-policy-validation.ts
Adds the network schema path, parses both schemas, and registers the network schema with AJV before compiling the sandbox validator.
Publish and verify schema files
package.json, test/package-contract/openshell-policy-boundary.test.ts
Includes schemas/network-policy.schema.json in the published package and verifies its presence in the package contract test.

Estimated code review effort: 2 (Simple) | ~10 minutes

Suggested reviewers: copilot, laitingsheng

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: registering the shared network schema at runtime for policy validation.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Jul 25, 2026

Copy link
Copy Markdown
Contributor

PR Review Advisor — Informational

Advisor assessment: Informational / high confidence
Next action: No advisor follow-up needed.
Findings: 0 blockers · 0 warnings · 0 suggestions
Status: No actionable findings remain in the canonical review ledger.

Model lanes

  • GPT-5.6 Terra (primary): Completed · high confidence · 0 blockers · 0 warnings · 0 suggestions
  • Nemotron 3 Ultra (second opinion): Completed · high confidence · 0 blockers · 0 warnings · 0 suggestions
  • Model comparison: normalized findings match; normalized E2E selections match; severity counts match.

Nemotron output stays in workflow artifacts and does not change the assessment above.

Since last review: 0 prior items resolved · 0 still apply · 0 new items found

E2E guidance

Advisory only. E2E / PR Gate selects and runs jobs independently.

Recommended E2E: cloud-onboard, credential-sanitization, security-posture, inference-routing, network-policy

Workflow run details

This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge.

@apurvvkumaria apurvvkumaria added v0.0.96 Release target bug-fix PR fixes a bug or regression area: policy Network policy, egress rules, presets, or sandbox policy area: packaging Packages, images, registries, installers, or distribution labels Jul 25, 2026
@apurvvkumaria apurvvkumaria self-assigned this Jul 25, 2026
@apurvvkumaria

Copy link
Copy Markdown
Collaborator

PR comparison verdict — #6877 runtime follow-up

Acceptance criteria

  • Register the shared network-policy schema before runtime sandbox-policy compilation.
  • Ship the referenced schema in the npm package.
  • Prove the packed, installed runtime contains both schemas and validates without changing policy semantics.
  • Preserve the original contributor's credit.

Scorecard

Check #7531 #7532 #7533
Open, mergeable commit pass pass closed
DCO declaration and GitHub-verified commit pass pass pass before closure
Exact-head CI and approval pending pending superseded
Unresolved CodeRabbit threads 0 0 1 before closure
Correctness score 12/12 12/12 12/12
Quality score 4/4 4/4 4/4
Weighted score 16/16 16/16 16/16

All three patches have the same three-file behavior shape. In #7531:

  • package.json ships schemas/network-policy.schema.json.
  • src/lib/policy/sandbox-policy-validation.ts loads the trusted local schema, registers its $id with AJV, and then compiles the sandbox schema.
  • test/package-contract/openshell-policy-boundary.test.ts asserts that the packed package contains the referenced schema before exercising the installed validator. That package-presence assertion and validator probe fail on pre-fix main.
  • The patch introduces no mocks, fallback, swallowed error, schema change, CLI output change, or public-surface migration.

Verdict: neither candidate is mergeable yet — select #7531

#7531 wins the deterministic tie because it is the earliest equivalent PR and is authored by Ho Lim, the original #6877 contributor. Duplicate #7533 is closed. #7531 now has the required template, exact-head documentation receipt (no-docs-needed), release labels, and assignment.

Next gate: exact-head CI/E2E must finish successfully and an independent approval must be recorded before merge.

@apurvvkumaria apurvvkumaria left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved at exact head d133ec1. The selected original-author patch registers the shared network schema before sandbox-schema compilation, ships the referenced schema, and proves the packed installed package contains and exercises both schemas. Focused package-contract and policy suites pass; automated review reports no actionable findings.

@cv
cv merged commit 66f9383 into NVIDIA:main Jul 25, 2026
80 of 87 checks passed
@cv cv mentioned this pull request Jul 26, 2026
23 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: packaging Packages, images, registries, installers, or distribution area: policy Network policy, egress rules, presets, or sandbox policy bug-fix PR fixes a bug or regression v0.0.96 Release target

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants