## NVIDIA/OpenShell — v0.1.3-pre.3…v0.1.3-pre.4

_21 commits._

### Features
- **Validate VM tools before startup** — The gateway now checks that required VM filesystem tools are available during configuration preflight validation, catching missing dependencies early with actionable error messages before attempting to create any gateway or sandbox state. This validation is skipped for remote driver endpoints and only applies to relevant local VM operations. (1c123a4)
- **Add sandbox UID and GID configuration** — Added new `server.sandboxUid` and `server.sandboxGid` Helm chart values to allow operators to configure the user and group IDs for sandbox pods. These values accept integers between 1 and 4294967294, with validation to reject invalid inputs like booleans or out-of-range numbers. (a48920a)

### Fixes
- **Validate launch credentials upfront** — The system now checks that launch signing credentials are properly configured before preparing virtual machines, preventing incomplete setups from proceeding. This validation happens earlier in the process and includes enhanced documentation on how to configure gateway JWT signing for VM launches. (71c3cd9)
- **Image prep gets separate timeout** — Sandbox image preparation now has its own deadline separate from the admission deadline, allowing the system to better handle timeouts during the preparation phase and provide clearer recovery guidance when either phase expires. The change persists both timing phases across gateway restarts and improves how the system manages stalled sandbox creation operations. (8983642)
- **Fix command argument parsing in sandbox creation** — The sandbox creation form now properly parses and preserves quoted command arguments before execution. If a user enters a command with quotes or escapes (like `/bin/sh -c "echo test"`), those are correctly interpreted as separate arguments rather than literal text, and invalid quoting now shows an error without creating the sandbox. (a2429fc)
- **Fix relay stream hanging on target close** — Fixed an issue where relay connections would hang indefinitely when a target server closed its connection first. The fix ensures that when a target closes a keep-alive connection, the outbound relay stream properly closes immediately while still allowing the client to finish uploading any remaining data. (e7d14ed)
- **Fix image worker cleanup race** — Improved the VM driver's image preparation process to use owned worker processes with file locks and leases, preventing race conditions during cancellation and cleanup. This ensures temporary staging files are safely removed after image workers stop, and concurrent preparation attempts don't interfere with each other. (4188eab)
- **Enforce workload identity validation** — VM workload identity selectors are now validated to reject conflicting policy users and groups before VM image preparation and startup. This prevents invalid identity configurations from being applied to sandboxes and ensures supervisor policy updates align with protected VM workload identities. (d676e03)
- **Docker now pulls single image tag** — Fixed an issue where Docker was pulling all tags from a repository when using a tagless image reference (like `nicolaka/netshoot`). The system now automatically appends `:latest` to untagged references, matching standard Docker behavior and preventing unnecessary downloads of every tag. (fcd8fe5)
- **Stop waiting for gateway if service fails** — The installer now detects when the openshell-gateway service fails and stops waiting immediately instead of timing out, providing a clearer error message directing users to restart the service. (adcd28b)
- **CLI now validates complete execution status** — Fixed the CLI to properly check final execution status and warn users when streamed stdin input is only partially processed. The command now continues draining the response even after seeing an exit code to ensure that gRPC errors don't mask partial execution results. (48d9ab3)
- **Exec requests now expire after 30 seconds** — Changed how sandbox execution requests are managed—instead of a lifetime limit on the total number of executions, requests now expire 30 seconds after creation. The expiration deadline is embedded in each request and validated before execution, ensuring retries can't bypass the time window. This affects how the sandbox backend handles execution recovery and admission. (121930b)
- **Updated ratatui dependency for security** — Upgraded the ratatui terminal UI library to address a vulnerability in its lru dependency. This also updated related code to use the current ratatui API (`frame.area()` instead of the deprecated `frame.size()`). (d0a4e19)
- **Stabilize provider environment revisions** — Fixed provider environment revision calculations to produce consistent results regardless of how internal data structures are ordered. This ensures that provider configurations remain deterministic across multiple requests, improving reliability when managing provider profiles and their associated environments. (ec49209)
- **Sign macOS driver with hypervisor entitlement** — The macOS driver binary is now code-signed with the required Hypervisor.framework entitlements during the build process, preventing runtime failures when the system's security framework validates the binary. (8e9136b)
- **Fix GCP metadata discovery via supervisor** — Restored the ability for Google Cloud SDKs running in sandboxes to discover GCP metadata (project ID, service account, tokens) by relaying metadata requests through the supervisor instead of treating them as ordinary local connections. The metadata service now correctly handles repeated refreshes and missing service account email values. (f7273e4)
- **Stop uploads on Git filter errors** — The CLI now halts file uploads when Git filtering fails or selects no files, and provides clearer guidance on when `.gitignore` rules apply. Outside Git repositories, uploads proceed with a warning; users can use `--no-git-ignore` to bypass filtering entirely. (36819f4)
- **Upgrade russh SSH library** — Updated the russh SSH library from version 0.62 to 0.63.1 to address a security alert. This required minor code adjustments to match the new API, specifically updating a public key type reference. (88afd36)
- **Fix sandbox lifecycle mutation serialization** — Fixed a race condition in Kubernetes sandbox management where cleanup operations could incorrectly delete supervisors created by concurrent restart operations. The fix adds a per-sandbox mutation gate that serializes lifecycle operations (create, start, stop, delete) and ensures cleanup operations refresh the sandbox state before proceeding, preventing stale snapshots from deleting recently-created resources. (5d6b3b8)

### Chore
- **ci(release): notify duty engineers of prerelease failures (#4134)** (e7fdd6b)
- **Pinned CI images by digest** — Updated all CI workflow container images to use specific content digests instead of 'latest' tags, ensuring reproducible and secure builds across multiple workflows including branch checks, release pipelines, and GPU tests. (046fd2a)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/NVIDIA/OpenShell?utm_source=github-action)._