Repository navigation
feat(tui): render policy proposal inbox metadata #1098
Description
Activity
- addedstate:agent-readyApproved for agent implementationApproved for agent implementationarea:policyPolicy engine and policy lifecycle workPolicy engine and policy lifecycle workarea:tuiTerminal UI workTerminal UI work
on Apr 30, 2026 - added 4 commits that reference this issue
on May 12, 2026 🏗️ build-plan
Implementation Plan
Issue type:
feat
Complexity: Medium
Confidence: Medium — the current data model differs from the issue's original field names, but the remaining TUI work is well scopedSummary
Evolve the existing TUI "Network Rules" panel into a single-sandbox policy proposal inbox using the current
PolicyChunkmodel. Treatrule_nameas the proposal headline fallback and labelrationaleas agent-supplied intent; surface the existing validation result, broad L4/no-method-path scope, and persisted rejection guidance without expanding the protobuf schema.Scope
crates/openshell-tui/src/ui/sandbox_draft.rs: reframe list/detail copy, add proposal presentation helpers, validation badges, explicit broad-scope warnings, rejection guidance, and focused unit tests.docs/sandboxes/policy-advisor.mdx: document the TUI inbox metadata, warning semantics, rejection guidance, and existing review controls.crates/openshell-tui/src/lib.rsandcrates/openshell-tui/src/app.rs: verify only; the active-sandbox refresh is already two seconds and the approve/reject hotkeys already exist.
Implementation Steps
- Add small pure presentation helpers for headline fallback, agent-intent labeling, validation status, broad-scope detection, and rejected guidance.
- Rename/reframe the panel as a policy proposal inbox and lead each row with the proposal headline while retaining endpoint, decision status, selection, and navigation behavior.
- Update the detail view to show agent intent, the full validation result, an explicit warning for L4 or REST proposals without method/path scoping, and persisted
rejection_reasonguidance for rejected chunks. - Preserve the existing
a,x, andAactions and the existing two-second active-sandbox refresh path; avoid unrelated input or polling changes. - Document how the TUI maps current proposal fields and how reviewers should interpret validation, scope warnings, and rejection guidance.
Test Plan
- Unit tests: Add adjacent tests in
sandbox_draft.rsfor headline/intent fallbacks, validation badge states, rejection guidance presence/absence, and L4/unscoped versus method/path-scoped endpoint detection. - Integration tests: N/A — the change consumes an unchanged
PolicyChunkresponse and does not alter gateway/TUI integration boundaries; exercise mixed chunks through focused rendering helpers instead. - E2E tests: N/A — no gateway or policy behavior changes. Perform a manual TUI smoke check when a sandbox is available to confirm two-second refresh and unchanged approve/reject controls.
Risks & Open Questions
- The issue names
human_summaryandintent_summary, but currentPolicyChunkexposes neither. Current agent submissions place claimed intent inrationale, whilerule_nameis the only stable headline candidate. This plan follows parent OpenShell Agent-Driven Policy Management #1062's current direction to reuse existing fields; maintainers should explicitly request a schema expansion if that mapping is insufficient. validation_resultis free-form and has evolved. The UI should preserve the full value in details and derive only conservative, graceful badge labels.- Scope-warning detection must avoid claiming that an endpoint is narrowly scoped when it lacks explicit REST method/path constraints.
Documentation Impact
- Update
docs/sandboxes/policy-advisor.mdxfor the user-facing TUI review experience. - No gateway configuration documentation impact.
- No SELinux or AppArmor compatibility impact; this is display-only TUI work.
Revision 1 — initial plan based on current main and the simplified proposal model in #1062
🏗️ build-from-issue-agent
Update: I am not proceeding with this implementation because I will not open a Vouch Request at this time. No code changes or pull request were created, and the issue remains available for another contributor.
#2908 is up for one item from the Definition of Done: "Rejected chunks show persisted guidance."
PolicyChunk.rejection_reasonwas already written by the gateway and already arrived inGetDraftPolicyResponse.chunks—openshell-tuijust never read it. The PR renders it truncated on the list row and in full in the detail popup, gated onstatus == "rejected"because approving passesNoneand the gateway writes the field only when it isSome, so an approved chunk can otherwise still show a stale note.Correcting my plan comment above: it described a wider slice than I shipped. I am claiming only that one item, and I am not working on:
human_summaryas the headline — needs a proto field, or a decision to fall back torule_name.intent_summaryas agent context — this looks reachable through the existingPolicyChunk.rationalewith no proto change, but it is a separate change and I have not started it.- The L4/no-method-path scoping warning.
Three other items look already satisfied on
maineven though their boxes are unticked:validation_resultrenders atui/sandbox_draft.rs:485, the poll cadence isDuration::from_secs(2)atlib.rs:79, and the approve/reject hotkeys still work. Worth ticking those, or correcting me if the intent was different.Happy to pick up the
rationaleitem next if that framing is acceptable.- added a commit that references this issue
on Aug 25, 2026 #2938 is up for the next Definition of Done item: "TUI shows an explicit L4/no-method-path scoping warning when applicable."
endpoint_layer_labelalready tags an endpointL4andformat_allow_rulealready renders an unset method or path as*, so the breadth was displayed but never flagged — a broad proposal looked the same as a tightly scoped one. The PR adds a warning under the offending endpoint in the detail popup, covering L4 endpoints, REST endpoints with no allow rules, and REST allow rules that leave the method or path unset. Protocols other than REST scope oncommand, so they are left alone.Two notes on the remaining items while I was checking what was left:
intent_summarylooks already satisfied.crates/openshell-supervisor-network/src/policy_local.rs:1050setsrationale: intent_summary, and the detail popup has rendered aRationale:line for some time — so the agent's intent already reaches the reviewer as agent-supplied context. Unless the intent was a separate field or a different label, that box looks tickable without code. I would rather flag it than build something redundant.human_summaryis the only item left that needs a decision. It does not exist anywhere in the repo, so it needs either a newPolicyChunkfield or a decision to fall back torule_nameas the headline. That is a design call rather than an implementation one — happy to do it either way once someone picks.
With #2908 merged and #2938 open, that would leave
human_summaryas the only outstanding item on this issue.This issue has had no activity for 14 days and is now marked stale. It may be closed in 7 days if there is no further activity. Comment or remove the state:stale label to keep it open.
- addedstate:staleInactive item at risk of automatic closure.Inactive item at risk of automatic closure.
on Sep 9, 2026
Description
Update the TUI draft policy panel into the MVP inbox experience for single-sandbox review.
Context
Parent: #1062
RFC artifact: https://github.com/NVIDIA/OpenShell/blob/feat/agent-driven-policy-management/rfc/0001-agent-driven-policy-management.md
This is part of the locked Agent-Driven Policy Management MVP. GitHub issues are the development source of truth; Linear is only a roadmap pointer.
The MVP keeps polling rather than adding server-streaming push.
Definition of Done
human_summaryas the primary proposal headline when present.intent_summaryas agent-supplied context.validation_resultas a badge/status.