Research investigation R0928 / policy impact

OpenShell 0.1.0’s Read-Only API Rules Need Enforce Mode to Block Writes

NVIDIA’s versioned documentation distinguishes connection denial from request-level enforcement. For an allowed REST endpoint, a read-only rule in the default audit mode logs and forwards a disallowed write; enforce mode blocks it.

Archived snapshotv1Sep 30, 2026
Verified observations
9

5 measured fields

Supported claims
8

8 material findings

Cited sources
6

6 primary or authoritative

Research score
84

Automated topic and evidence score

Interactive figureOpenShell 0.1.0’s Read-Only API Rules Need...
CSV JSON
Data statusAwaiting verified observations

Version-pinned OpenShell 0.1.0 documentation and the five selected examples only. The requested cutoff was September 28, 2026, 20:31 UTC, but four supplied documentation snapshots were retrieved afterward, at 20:35:37 UTC. Their exact pre-cutoff contents are unverified.

Verified observationNo chart values are being inferredLast updated Sep 30, 2026

Version ledger

Frozen public editions

Each edition preserves the records, method, sources, and downloads available at publication time.

  1. v1 / latestSep 30, 20269 records / 6 sources

    Initial public snapshot with 9 records and 6 cited sources.

Coverage note

Version-pinned OpenShell 0.1.0 documentation and the five selected examples only. The requested cutoff was September 28, 2026, 20:31 UTC, but four supplied documentation snapshots were retrieved afterward, at 20:35:37 UTC. Their exact pre-cutoff contents are unverified.

Dataset ID
spd:openshell-s-read-only-rules-when-do-they-block-writes-rather-than-log-them-ae21dc17
Stable URL
/research/openshell-s-read-only-rules-when-do-they-block-writes-rather-than-log-them-ae21dc17
Version
v1
Coverage
Live collection
Records
9
Fields
7
Updated

Read the data

The records behind the figure

CSV JSON
OpenShell 0.1.0’s Read-Only API Rules Need Enforce Mode to Block Writes data records
EntityMetricValueUnitObservedSourceTransform
Inspected REST endpoint with read-only accessdocumented policy outcome: disallowed POST with enforcement auditRequest forwarded and rule violation logged——https://docs.nvidia.com/openshell/v0.1.0/how-it-works/policies/network-rules—
Inspected REST endpoint with read-only accessdocumented policy outcome: disallowed POST with enforcement enforceRequest blocked; HTTP client receives OpenShell policy_denied——https://docs.nvidia.com/openshell/v0.1.0/how-it-works/policies/network-rules—
Outbound connectiondocumented policy outcome: no matching host/port/binary ruleConnection denied before request inspection——https://docs.nvidia.com/openshell/v0.1.0/how-it-works/policies/network-rules—
Allowed endpointdocumented policy outcome: protocol omittedNo method/path rule applied; requests permitted subject to separate checks——https://docs.nvidia.com/openshell/v0.1.0/how-it-works/policies/network-rules—
First Network Policy: GitHub APIexplicit enforcement settingenforce——https://docs.nvidia.com/openshell/v0.1.0/tutorials/first-network-policy—
Network Rules: GitHub read-only APIexplicit enforcement settingenforce——https://docs.nvidia.com/openshell/v0.1.0/how-it-works/policies/network-rules—
Network Rules: internal APIexplicit enforcement settingenforce——https://docs.nvidia.com/openshell/v0.1.0/how-it-works/policies/network-rules—
Network Rules: npm installsexplicit enforcement settingenforce——https://docs.nvidia.com/openshell/v0.1.0/how-it-works/policies/network-rules—
Network Rules: PyPI downloadsexplicit enforcement settingenforce on both listed REST endpoints——https://docs.nvidia.com/openshell/v0.1.0/how-it-works/policies/network-rules—

Measurement technique

How to read this report

  1. 01Treat September 28, 2026, 20:31 UTC as the evidence cutoff. The supplied documentation snapshots were retrieved at 20:35:37 UTC; recovering them is not a new collection or experiment and cannot establish their exact contents at the cutoff.
  2. 02Use the supplied OpenShell 0.1.0 default-policy, network-rules, schema, security-guidance and tutorial evidence to separate connection matching, request inspection and enforcement. Label outcomes as documented rather than runtime-observed.
  3. 03Count only the bounded sample of five distinct REST read-only configurations: the network-rules page’s GitHub, PyPI, npm and internal-API examples, plus the first-network-policy tutorial. All five explicitly specify enforce; this is not a documentation-wide count.
  4. 04Apply the checklist to the whole effective policy: identify matching host, port and binary rules; check protocol and access; check enforcement; then account for provider rules, overlapping endpoints and matching denies.
Next report / 01AI Model Economics Index All research reports
YOUR READING SPACE

Notifications