Skip to content

feat(policy): expose proxy filesystem enrichment for policy comparisons #3958

Description

@cv

User story

In NemoClaw, we need to compare requested and observed sandbox policies while accounting for OpenShell’s automatic filesystem grants, without copying private supervisor rules.

Problem statement

At OpenShell 5acaaba, the proxy baseline and its enrichment functions remain private to the supervisor. The openshell-policy crate does not expose an equivalent operation.

NemoClaw currently copies those baseline paths when comparing requested and observed policies. Its comparison therefore depends on implementation details that can change independently of the consumer.

The GPU concern in the original report has already been addressed upstream: #3580, included in v0.1.2, moved GPU allowances into the workload without writing them back into the gateway policy. This request concerns the remaining proxy-baseline duplication.

Related consumer issue: NVIDIA/NemoClaw#12424.

Impact

A baseline change can make an unchanged deployment appear to have drifted until consumers update their copied rules. Ignoring arbitrary additional paths would weaken the comparison.

Consumers also cannot reliably reproduce enrichment by checking their own filesystem: the planning host and sandbox image can contain different paths.

Proposed design

Provide a supported policy-library operation that applies OpenShell’s proxy filesystem enrichment to an authored policy.

The caller supplies evidence about paths present in the sandbox. OpenShell owns the baseline candidates, permission classification, and conditions under which enrichment applies. The supervisor and consumers use the same rules.

Preserve existing behavior, including explicit read-only permissions and include_workdir. This operation would cover proxy enrichment; GPU and workspace permissions retain their existing ownership.

The precise API shape is open for discussion.

Alternatives considered

  • Expose authored policy or its authoritative identity: potentially preferable if OpenShell can provide an observation unaffected by runtime enrichment.
  • Continue copying the baseline: retains the maintenance and compatibility problem.
  • Ignore additional filesystem grants: prevents consumers from distinguishing expected enrichment from unrelated changes.

Acceptance criteria

  • Consumers can compare policies without maintaining a private baseline copy.
  • Sandbox path observations are explicit; the operation does not implicitly inspect the consumer host.
  • Existing permissions are preserved, including explicitly read-only /tmp.
  • Missing paths are excluded and repeated enrichment is stable.
  • Comparisons still detect unrelated grants, permission escalation, and removal of authored paths.
  • Existing supervisor behavior remains unchanged and is covered by regression tests.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    state:triage-neededOpened without agent diagnostics and needs triage

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions