-
Notifications
You must be signed in to change notification settings - Fork 3.1k
fix(docs): mount reviewer inputs before startup #9365
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🩺 Stability & Availability | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: NVIDIA/NemoClaw
Length of output: 13928
🏁 Script executed:
Repository: NVIDIA/NemoClaw
Length of output: 50372
🏁 Script executed:
Repository: NVIDIA/NemoClaw
Length of output: 50372
🏁 Script executed:
Repository: NVIDIA/NemoClaw
Length of output: 22926
🌐 Web query:
OpenShell sandbox filesystem_policy read_write path creation /sandbox/output Docker driver mounts💡 Result:
In NVIDIA OpenShell, the filesystem_policy controls access within the sandbox using Landlock LSM [1][2]. Paths not explicitly listed in the filesystem_policy (read_only or read_write) are inaccessible to the agent [1]. Filesystem Path Creation and Permissions When defining read_write paths in the policy, paths are generally expected to exist or be created by the environment [3]. Historically, the OpenShell sandbox supervisor's prepare_filesystem function would unconditionally apply chown to all directories in the read_write list to match the agent's user and group identity [3]. Recent updates have moved toward preserving original directory ownership for pre-existing paths while ensuring newly created paths are appropriately owned for the sandbox user [3]. Docker Driver Mounts OpenShell sandboxes utilize compute drivers to provision environments [4][5]. The Docker driver handles user-supplied mounts through the --driver-config-json flag, accepting the following types [6][7]: 1. volume: Mounts existing Docker named volumes [6]. The driver validates that the volume exists before provisioning and does not create or remove it [7][8]. 2. tmpfs: Mounts in-memory filesystems [7]. 3. bind: Mounts absolute host paths [6]. These are disabled by default for security, as they can expose gateway-host filesystem state and negate sandbox isolation [6][4]. To use bind mounts, they must be explicitly enabled by setting enable_bind_mounts = true in the [openshell.drivers.docker] table of the gateway.toml configuration file [6][7]. User-supplied bind and volume mounts are read-only by default; you must explicitly set read_only: false in the driver mount configuration to grant write access [7][9]. Mount targets must be absolute container paths and are restricted from overlapping with reserved OpenShell supervisor files (e.g., /etc/openshell, /etc/openshell-tls) or the /sandbox/work root (though subpaths within /sandbox are generally supported) [6][7][9].
Citations:
🏁 Script executed:
Repository: NVIDIA/NemoClaw
Length of output: 420
Provision
/sandbox/outputfor review sandboxes.The policy grants write access but does not create the directory. Review mode has no output mount or upload, so writing
/sandbox/output/decision.jsoncan fail. Provision a writable output path before the agent runs. Updatetest/post-merge-docs.test.tsso the fixture writes and downloads through the modeled sandbox output path.📍 Affects 2 files
tools/post-merge-docs/run.mts#L198-L245(this comment)test/post-merge-docs.test.ts#L368-L404🤖 Prompt for AI Agents
Source: Path instructions