Add role-specific Cloud Hypervisor enclave export layouts - #9341
Conversation
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Filesystem isolation needs human security review, and the networked guest boot contract remains unresolved.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Adds role-specific Cloud Hypervisor enclave filesystem layouts as a foundation for future host-executor integration.
Changes:
- Defines bounded script and agent exports without
/workspace. - Validates trusted source paths, identities, targets, and access modes.
- Preserves primary-agent behavior and keeps enclave launches gated.
| File | Description |
|---|---|
| src/cloud-hypervisor/workload-profile.ts | Integrates closed export plans and launch gates. |
| src/cloud-hypervisor/workload-profile.test.ts | Tests role layouts and profile rejection. |
| src/cloud-hypervisor/vm-config-builder.ts | Supports six workspace-less exports in boot arguments. |
| src/cloud-hypervisor/manager.test-utils.ts | Adds role-specific export fixtures. |
| src/cloud-hypervisor/manager-start.ts | Adjusts workspace-less export validation. |
| src/cloud-hypervisor/manager-launch.test.ts | Checks rejection before launch side effects. |
| src/cloud-hypervisor/manager-connectivity.test.ts | Updates enclave connectivity fixtures. |
| src/cloud-hypervisor/exports.ts | Adds configurable export-count validation. |
| src/cloud-hypervisor/enclave-network.test.ts | Updates network tests with export plans. |
| src/cloud-hypervisor/enclave-export-plan.ts | Resolves and validates trusted role layouts. |
| src/cloud-hypervisor/enclave-export-plan.test.ts | Tests layouts, paths, permissions, and boot arguments. |
| docs/cloud-hypervisor-foundation.md | Documents layouts, trust boundaries, and execution gates. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| entryId: options.enclaveId, | ||
| invocationId: options.invocationId, | ||
| }), | ||
| workspaceMount: null, |
| expect(() => createScriptEnclaveCloudHypervisorProfile({ | ||
| enclaveId: 'script-entry', | ||
| invocationId: 'invocation', | ||
| guest: supervisor, | ||
| exportPlan: { ...plan, exports: [workspaceExport] }, | ||
| })).toThrow(); |
|
@copilot address review feedback |
Addressed in |
|
✅ Copilot review passed with no inline comments. @copilot Add the |
Documentation PreviewDocumentation has been built for this PR. To view locally:
Built from commit 20aca3a |
|
| Metric | Base | PR | Delta |
|---|---|---|---|
| Lines | 92.82% | 92.78% | 📉 -0.04% |
| Statements | 91.33% | 91.30% | 📉 -0.03% |
| Functions | 89.37% | 89.35% | 📉 -0.02% |
| Branches | 84.57% | 84.61% | 📈 +0.04% |
📁 Per-file Coverage Changes (5 files)
| File | Lines (Before → After) | Statements (Before → After) |
|---|---|---|
src/cloud-hypervisor/manager-start.ts |
86.3% → 81.2% (-5.13%) | 85.8% → 80.8% (-5.00%) |
src/cloud-hypervisor/manager.test-utils.ts |
100.0% → 95.5% (-4.55%) | 100.0% → 96.7% (-3.28%) |
src/cloud-hypervisor/workload-profile.ts |
100.0% → 99.1% (-0.86%) | 100.0% → 99.2% (-0.82%) |
src/cloud-hypervisor/exports.ts |
92.6% → 92.7% (+0.09%) | 89.5% → 89.7% (+0.12%) |
src/log-directory-setup.ts |
96.2% → 100.0% (+3.78%) | 96.3% → 100.0% (+3.71%) |
✨ New Files (1 files)
src/cloud-hypervisor/enclave-export-plan.ts: 90.9% lines
Coverage comparison generated by scripts/ci/compare-coverage.ts
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...
|
|
✅ Smoke Claude passed
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
❌ Smoke Gemini reports failed. Facets need polishing...
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅
|
|
🚀 Security Guard has started processing this pull request |
|
✅ Build Test Suite completed successfully!
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟
|
|
Smoke Cloud Hypervisor reports failed. Cloud Hypervisor + Copilot failed.
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
Smoke Test: Claude Engine Validation
Overall result: PASS
|
|
EGRESS_RESULT allow=pass deny=pass
Overall: PASS — cc
|
|
Smoke Test: Copilot BYOK (Direct) Mode ✅ PASS
Mode: Direct BYOK (COPILOT_PROVIDER_API_KEY) via api-proxy → api.githubcopilot.com
|
|
Smoke Copilot: PASS
|
|
OTEL smoke test
|
|
Services smoke test:
Overall: PASS
|
🏗️ Build Test Suite Results
Overall: 6/8 ecosystems passed — FAIL Failures
|
Chroot Version Comparison
Result: Not all tests passed (Node.js version mismatch), so the
|
|
Smoke test results
|


Cloud Hypervisor enclave layouts must expose only role-required inputs and writable paths, without inheriting the primary agent’s
/workspace. Export plans derive from trusted host run state; enclave launches remain fail-closed pending host-executor integration./workspace.