Files
supervisor/tests
Stefan AgnerandClaude Fable 5.1 1d184b2758 Model OS Agent AppArmor profile rejections as API errors (#7226)
* Model OS Agent AppArmor profile rejections as API errors

When the OS Agent's AppArmor parser rejects a profile (for example an
app profile that defines an unexpected profile name), the resulting
HostAppArmorError surfaced through api_process as an "Unexpected error"
with a full traceback and a Sentry event. The profile content is
user-supplied through the app repository, so a parser rejection is a
client error rather than a Supervisor fault.

Add HostAppArmorLoadProfileError, a HostAppArmorError that also
inherits APIError, and raise it from the D-Bus load path. It carries
the profile name and the OS Agent's error message as extra fields so
the reason is still relayed to the API caller, while the error is now
answered with a plain 400 and no Sentry capture. Existing catch sites
keep working since the class remains a HostAppArmorError.

Extend the AppArmor D-Bus mock to inject load failures and add a test
covering the relayed message and error metadata.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

* Limit the AppArmor API error to OS Agent parser rejections

Only DBusFatalError, which from_dbus_error uses for service-specific
failures, indicates the OS Agent rejected the profile. Transport
failures such as timeouts or a missing reply keep raising the plain
HostAppArmorError so they still surface as unexpected errors.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-15 15:56:06 +02:00
..
…