Skip to content

feat(openshell): inventory explicitly selected policy documents - #949

Open
pengfei-threemoonslab wants to merge 1 commit into
mainfrom
codex/openshell-inventory-943
Open

pengfei-threemoonslab wants to merge 1 commit into
mainfrom
codex/openshell-inventory-943

Conversation

@pengfei-threemoonslab

Copy link
Copy Markdown
Contributor

A reviewer can now register arbitrary repository-local OpenShell YAML/JSON policies in .shipgate/openshell.json and inspect their typed authority facts with shipgate audit --host. The reader pins OpenShell 0.1.2 separately from policy schema 1, preserves authored/effective-snapshot roles and default provenance, and names missing, malformed, unsupported, or escaping inputs as blocking coverage limits.

Network facts retain binary/endpoint correlation. Parsing is bounded, identity-bound and offline; credential-shaped labels cannot silently collapse under redaction. New host inventory/baseline/drift v0.8 schemas leave historical schemas frozen. Discovery, the zero-install launcher, independent census, generated references and a sample are included.

Semantic comparison, Git-selected input binding, review routing, composition and optional native proof follow in #944–#948. This stage makes no deployed enforcement or tool-effect claim.

Validation: full suite exercised 14,979 cases (14,955 initially passed); all seven failing cases and twelve packaging errors passed in the corrected regression run with build-dependency network access. OpenShell fixtures, schema generation check, Ruff, diff whitespace check and self-check passed. Reviewed the implementation and addressed census/launcher discovery, coverage parity and generated-document gaps. check/verify now report review_publishable: publishing is allowed; human review of the new registration and trigger catalog is required before merge.

Closes #943
Part of #942

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OpenShell: read selected policy files into a versioned static authority inventory

1 participant