Skip to content

Commit 38f2aef

Browse files
authored
feat(gateway): support selective compute driver builds (#3118)
* feat(gateway): support selective compute driver builds Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(gateway): support selective Windows MXC builds Signed-off-by: Drew Newberry <anewberry@nvidia.com> --------- Signed-off-by: Drew Newberry <anewberry@nvidia.com>
1 parent 1860010 commit 38f2aef

12 files changed

Lines changed: 240 additions & 50 deletions

File tree

‎.agents/skills/build-openshell-mxc-windows/SKILL.md‎

Lines changed: 15 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -252,6 +252,13 @@ in the gateway build graph, but their Unix-socket standalone binaries do not.
252252

253253
Windows must continue to reject unsupported compute drivers clearly.
254254

255+
The gateway's `compute-driver-mxc` feature independently links and registers
256+
MXC on Windows. Each other `compute-driver-*` feature installs its own Windows
257+
rejection stub without linking that driver crate. The default
258+
`in-tree-compute-drivers` alias enables all five features. An MXC-only build
259+
uses `--no-default-features --features compute-driver-mxc` (add `telemetry`
260+
and `bundled-z3` as needed).
261+
255262
| Driver | Windows build behavior | Runtime behavior |
256263
|---|---|---|
257264
| Docker | Driver crate excluded; gateway registration stub retained. | Gateway construction returns unsupported. |
@@ -263,11 +270,16 @@ The focused contract tasks for either native architecture run:
263270

264271
```text
265272
windows_builtin_compute_drivers_report_unsupported
273+
default_registry_contains_exactly_the_enabled_compute_drivers
266274
```
267275

268-
These tests are also included in the full x64 workspace test run. The focused
269-
task is available for local diagnosis; GitHub Actions does not re-run it after
270-
the full suite.
276+
The same tasks also run gateway library tests for protocol-only, MXC-only,
277+
Docker-stub-only, and MXC plus Docker-stub builds. Their logs use
278+
`test-<target>-selective-<variant>.log`.
279+
280+
The default-feature tests are also included in the full workspace test run.
281+
The focused task is available for local diagnosis and selective-build
282+
validation; GitHub Actions does not re-run it after the full suite.
271283

272284
## Test Accounting Guidance
273285

‎.github/workflows/branch-checks.yml‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -182,6 +182,16 @@ jobs:
182182
cargo build -p openshell-sandbox --bin openshell-sandbox --no-default-features --features defaults-without-telemetry
183183
tasks/scripts/verify-telemetry-compiled-out.sh absent target/debug/openshell-sandbox
184184
185+
- name: Verify selective gateway compute-driver builds
186+
run: |
187+
cargo test -p openshell-gateway --all-targets --no-default-features
188+
cargo test -p openshell-gateway --all-targets --no-default-features --features compute-driver-docker
189+
cargo test -p openshell-gateway --all-targets --no-default-features --features compute-driver-kubernetes
190+
cargo test -p openshell-gateway --all-targets --no-default-features --features compute-driver-podman
191+
cargo test -p openshell-gateway --all-targets --no-default-features --features compute-driver-vm
192+
cargo test -p openshell-gateway --all-targets --no-default-features --features compute-driver-mxc
193+
cargo test -p openshell-gateway --all-targets --no-default-features --features compute-driver-docker,compute-driver-vm
194+
185195
- name: Verify the defaults-without-telemetry feature alias tracks the default feature set
186196
run: tasks/scripts/verify-defaults-without-telemetry.sh
187197

‎Cargo.lock‎

Lines changed: 2 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎README.md‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -274,6 +274,21 @@ cargo build --release -p openshell-driver-vm --no-default-features --features de
274274

275275
The resulting binaries contain no telemetry endpoint, no telemetry HTTP client, and no emission code. With telemetry compiled out, the gateway emits nothing and reports telemetry disabled to the sandboxes it launches. Cargo has no way to subtract a single default feature, so `defaults-without-telemetry` must be paired with `--no-default-features`; passing it on its own leaves the defaults in place and fails the build rather than producing a binary that still emits.
276276

277+
The gateway also exposes separate Cargo features for its built-in compute drivers: `compute-driver-kubernetes`, `compute-driver-docker`, `compute-driver-podman`, `compute-driver-vm`, and `compute-driver-mxc`. Disable the default feature set, then enable only the drivers and telemetry mode required by the target binary. For example:
278+
279+
```shell
280+
# Docker only, with telemetry support.
281+
cargo build --release -p openshell-gateway --no-default-features --features telemetry,compute-driver-docker
282+
283+
# Docker and VM only, with telemetry compiled out.
284+
cargo build --release -p openshell-gateway --no-default-features --features compute-driver-docker,compute-driver-vm
285+
286+
# Windows MXC only, with telemetry support and bundled Z3.
287+
cargo build --release -p openshell-gateway --no-default-features --features telemetry,compute-driver-mxc,bundled-z3
288+
```
289+
290+
Regular builds retain their platform driver set through the default `in-tree-compute-drivers` compatibility feature. On Windows, `compute-driver-mxc` selects MXC; the other four features install unsupported-driver stubs. On other platforms, MXC is excluded.
291+
277292
Telemetry events are limited to anonymous operational categories and counts, such as sandbox lifecycle outcomes, provider profile buckets, policy decision counts, and aggregate network activity denial categories. OpenShell telemetry does not collect sandbox names or IDs, hostnames, file paths, binary paths, prompts, credentials, provider names, model names, or user content.
278293

279294
Opting out applies only to telemetry emitted by OpenShell. Third-party services, model providers, inference endpoints, agents, or tools that you configure and use with OpenShell may have their own terms and privacy practices.

‎architecture/compute-runtimes.md‎

Lines changed: 12 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -133,13 +133,18 @@ server constructs the common runtime adapter and snapshots `GetCapabilities`
133133
for either result. A configured UDS endpoint still takes precedence over a
134134
compiled registration with the same name.
135135

136-
The `openshell-gateway` composition crate groups first-party registrations
137-
behind the `in-tree-compute-drivers` feature. `openshell-server` has no compute
138-
driver dependencies or backend-name dispatch. Protocol-only gateway builds
139-
disable the composition feature and link no compute-driver crates. E2E lanes
140-
compose that gateway with Docker, Podman, Kubernetes, and VM driver executables
141-
over the public UDS gRPC contract so an in-tree driver cannot silently depend
142-
on a server-only API.
136+
The `openshell-gateway` composition crate exposes one feature per first-party
137+
registration: `compute-driver-kubernetes`, `compute-driver-docker`,
138+
`compute-driver-podman`, `compute-driver-vm`, and `compute-driver-mxc`. Builds
139+
can enable any subset. MXC links only on Windows; the other four features
140+
install rejection stubs on Windows and link their drivers on other platforms.
141+
The default `in-tree-compute-drivers` feature remains an alias for all five,
142+
preserving each platform's default registrations.
143+
`openshell-server` has no compute driver dependencies or backend-name dispatch.
144+
Protocol-only gateway builds disable the default features and link no
145+
compute-driver crates. E2E lanes compose that gateway with Docker, Podman,
146+
Kubernetes, and VM driver executables over the public UDS gRPC contract so an
147+
in-tree driver cannot silently depend on a server-only API.
143148

144149
## Stop and Start Lifecycle
145150

‎architecture/windows-msvc-build.md‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,14 @@ Windows. These registrations preserve config-file selection and reject
3131
unsupported drivers with a clear error without depending on their runtime
3232
crates.
3333

34+
Each stub follows its corresponding `compute-driver-*` Cargo feature.
35+
`compute-driver-mxc` independently links and registers MXC, so a gateway built
36+
with only that feature has only the MXC registration. The default
37+
`in-tree-compute-drivers` alias enables all five features and preserves the
38+
existing MXC plus unsupported-driver registrations. The focused Windows
39+
contract tasks cover default, protocol-only, MXC-only, Docker-stub-only, and
40+
MXC plus Docker-stub compositions.
41+
3442
The Windows lane does not build, release, package, or smoke-test standalone
3543
driver binaries for Docker, Kubernetes, Podman, or VM. Those binaries are Linux
3644
or macOS deliverables only.

‎crates/openshell-driver-mxc/Cargo.toml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ repository.workspace = true
1414
name = "openshell_driver_mxc"
1515

1616
[dependencies]
17-
openshell-core = { path = "../openshell-core" }
17+
openshell-core = { path = "../openshell-core", default-features = false }
1818
tokio = { workspace = true }
1919
tonic = { workspace = true }
2020
futures = { workspace = true }

‎crates/openshell-gateway/Cargo.toml‎

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -40,9 +40,17 @@ openshell-driver-mxc = { path = "../openshell-driver-mxc", optional = true }
4040
[features]
4141
default = ["telemetry", "in-tree-compute-drivers"]
4242
in-tree-compute-drivers = [
43-
"dep:openshell-driver-docker",
44-
"dep:openshell-driver-kubernetes",
45-
"dep:openshell-driver-podman",
43+
"compute-driver-docker",
44+
"compute-driver-kubernetes",
45+
"compute-driver-podman",
46+
"compute-driver-vm",
47+
"compute-driver-mxc",
48+
]
49+
compute-driver-mxc = ["dep:openshell-driver-mxc"]
50+
compute-driver-docker = ["dep:openshell-driver-docker", "dep:openshell-otel"]
51+
compute-driver-kubernetes = ["dep:openshell-driver-kubernetes", "dep:openshell-otel"]
52+
compute-driver-podman = ["dep:openshell-driver-podman", "dep:openshell-otel"]
53+
compute-driver-vm = [
4654
"dep:openshell-otel",
4755
"dep:hyper-util",
4856
"dep:nix",
@@ -51,7 +59,6 @@ in-tree-compute-drivers = [
5159
"dep:tonic",
5260
"dep:tower",
5361
"dep:tracing",
54-
"dep:openshell-driver-mxc",
5562
]
5663
telemetry = ["openshell-core/telemetry", "openshell-server/telemetry"]
5764
## Convenience alias: every default feature except `telemetry`. Build a

0 commit comments

Comments
 (0)