Research investigation R0928 / policy impact
OpenShell 0.1.0’s Read-Only API Rules Need Enforce Mode to Block Writes
NVIDIA’s versioned documentation distinguishes connection denial from request-level enforcement. For an allowed REST endpoint, a read-only rule in the default audit mode logs and forwards a disallowed write; enforce mode blocks it.
Version-pinned OpenShell 0.1.0 documentation and the five selected examples only. The requested cutoff was September 28, 2026, 20:31 UTC, but four supplied documentation snapshots were retrieved afterward, at 20:35:37 UTC. Their exact pre-cutoff contents are unverified.
Version ledger
Frozen public editions
Each edition preserves the records, method, sources, and downloads available at publication time.
Version-pinned OpenShell 0.1.0 documentation and the five selected examples only. The requested cutoff was September 28, 2026, 20:31 UTC, but four supplied documentation snapshots were retrieved afterward, at 20:35:37 UTC. Their exact pre-cutoff contents are unverified.
- Dataset ID
- spd:openshell-s-read-only-rules-when-do-they-block-writes-rather-than-log-them-ae21dc17
- Stable URL
- /research/openshell-s-read-only-rules-when-do-they-block-writes-rather-than-log-them-ae21dc17
- Version
- v1
- Coverage
- Live collection
- Records
- 9
- Fields
- 7
- Updated
Measurement technique
How to read this report
- 01Treat September 28, 2026, 20:31 UTC as the evidence cutoff. The supplied documentation snapshots were retrieved at 20:35:37 UTC; recovering them is not a new collection or experiment and cannot establish their exact contents at the cutoff.
- 02Use the supplied OpenShell 0.1.0 default-policy, network-rules, schema, security-guidance and tutorial evidence to separate connection matching, request inspection and enforcement. Label outcomes as documented rather than runtime-observed.
- 03Count only the bounded sample of five distinct REST read-only configurations: the network-rules page’s GitHub, PyPI, npm and internal-API examples, plus the first-network-policy tutorial. All five explicitly specify enforce; this is not a documentation-wide count.
- 04Apply the checklist to the whole effective policy: identify matching host, port and binary rules; check protocol and access; check enforcement; then account for provider rules, overlapping endpoints and matching denies.
Sources
Evidence
2 publishers supporting 9 records. Expand a publisher to inspect its cited pages.