Skip to content

Add role-specific Cloud Hypervisor enclave export layouts - #9341

Merged
lpcox merged 3 commits into
mainfrom
copilot/add-virtio-fs-export-layouts
Oct 2, 2026
Merged

lpcox merged 3 commits into
mainfrom
copilot/add-virtio-fs-export-layouts

Conversation

Copilot AI commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Cloud Hypervisor enclave layouts must expose only role-required inputs and writable paths, without inheriting the primary agent’s /workspace. Export plans derive from trusted host run state; enclave launches remain fail-closed pending host-executor integration.

  • Closed layouts: Script and agent plans mount the selected seed and invocation request read-only, with only per-invocation output and runtime directories writable. Agent plans additionally expose designated session handoff and state directories. Neither role exports /workspace.
  • Validation: Reject mismatched run, entry, invocation, or seed state; non-canonical, overlapping, or missing host sources; and out-of-profile targets, tags, modes, or mount overrides. Read-only access is enforced on the host.
  • Compatibility and gate: Preserve primary-agent export behavior. Keep script- and agent-enclave VM launches fail-closed.
const plan = await resolveCloudHypervisorEnclaveExportPlan(runState, invocation);
// plan.exports contains only the fixed, role-approved exports.

Copilot AI changed the title [WIP] Add enclave-specific Cloud Hypervisor virtio-fs export layouts Add role-specific Cloud Hypervisor enclave export layouts Oct 1, 2026
Copilot AI requested a review from lpcox October 1, 2026 23:00
@lpcox
lpcox marked this pull request as ready for review October 1, 2026 23:03
Copilot AI balanced review requested due to automatic review settings October 1, 2026 23:03

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Filesystem isolation needs human security review, and the networked guest boot contract remains unresolved.

Review effort: Balanced
Findings: 1 High severity · 1 Low severity

Open (2)
What changed in this PR

Adds role-specific Cloud Hypervisor enclave filesystem layouts as a foundation for future host-executor integration.

Changes:

  • Defines bounded script and agent exports without /workspace.
  • Validates trusted source paths, identities, targets, and access modes.
  • Preserves primary-agent behavior and keeps enclave launches gated.
File Description
src/​cloud-hypervisor/​workload-profile.ts Integrates closed export plans and launch gates.
src/​cloud-hypervisor/​workload-profile.test.ts Tests role layouts and profile rejection.
src/​cloud-hypervisor/​vm-config-builder.ts Supports six workspace-less exports in boot arguments.
src/​cloud-hypervisor/​manager.test-utils.ts Adds role-specific export fixtures.
src/​cloud-hypervisor/​manager-start.ts Adjusts workspace-less export validation.
src/​cloud-hypervisor/​manager-launch.test.ts Checks rejection before launch side effects.
src/​cloud-hypervisor/​manager-connectivity.test.ts Updates enclave connectivity fixtures.
src/​cloud-hypervisor/​exports.ts Adds configurable export-count validation.
src/​cloud-hypervisor/​enclave-network.test.ts Updates network tests with export plans.
src/​cloud-hypervisor/​enclave-export-plan.ts Resolves and validates trusted role layouts.
src/​cloud-hypervisor/​enclave-export-plan.test.ts Tests layouts, paths, permissions, and boot arguments.
docs/​cloud-hypervisor-foundation.md Documents layouts, trust boundaries, and execution gates.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

entryId: options.enclaveId,
invocationId: options.invocationId,
}),
workspaceMount: null,
Comment on lines +198 to +203
expect(() => createScriptEnclaveCloudHypervisorProfile({
enclaveId: 'script-entry',
invocationId: 'invocation',
guest: supervisor,
exportPlan: { ...plan, exports: [workspaceExport] },
})).toThrow();
@lpcox

lpcox commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

@copilot address review feedback

Copilot AI commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

@copilot address review feedback

Addressed in 12773c4: workspace-less networked enclave boot now parses, generated agent arguments are checked against the guest parser, and workspace-export tests assert the specific seed-export rejection.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

✅ Copilot review passed with no inline comments.

@copilot Add the ready-for-aw label to this PR to trigger agentic CI smoke tests.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Documentation Preview

Documentation has been built for this PR.

Download preview artifact

To view locally:

  1. Download the docs-preview-pr-9341 artifact from the workflow run
  2. Unzip and open index.html in your browser

Built from commit 20aca3a

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

⚠️ Coverage Regression Detected

This PR decreases test coverage. Please add tests to maintain coverage levels.

Overall Coverage

Metric Base PR Delta
Lines 92.82% 92.78% 📉 -0.04%
Statements 91.33% 91.30% 📉 -0.03%
Functions 89.37% 89.35% 📉 -0.02%
Branches 84.57% 84.61% 📈 +0.04%
📁 Per-file Coverage Changes (5 files)
File Lines (Before → After) Statements (Before → After)
src/cloud-hypervisor/manager-start.ts 86.3% → 81.2% (-5.13%) 85.8% → 80.8% (-5.00%)
src/cloud-hypervisor/manager.test-utils.ts 100.0% → 95.5% (-4.55%) 100.0% → 96.7% (-3.28%)
src/cloud-hypervisor/workload-profile.ts 100.0% → 99.1% (-0.86%) 100.0% → 99.2% (-0.82%)
src/cloud-hypervisor/exports.ts 92.6% → 92.7% (+0.09%) 89.5% → 89.7% (+0.12%)
src/log-directory-setup.ts 96.2% → 100.0% (+3.78%) 96.3% → 100.0% (+3.71%)
✨ New Files (1 files)
  • src/cloud-hypervisor/enclave-export-plan.ts: 90.9% lines

Coverage comparison generated by scripts/ci/compare-coverage.ts

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...

🪪 BYOK (AOAI Entra) report filed by Smoke Copilot BYOK AOAI (Entra)

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

✅ Smoke Claude passed

Generated by Smoke Claude for #9341

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓

🔑 BYOK report filed by Smoke Copilot BYOK

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

❌ Smoke Gemini reports failed. Facets need polishing...

💎 Faceted by Smoke Gemini

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅

🛡️ Egress verdict from Smoke Copilot Network Isolation

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅

📡 OTel tracing validated by Smoke OTel Tracing

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

🚀 Security Guard has started processing this pull request

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

✅ Build Test Suite completed successfully!

Generated by Build Test Suite for #9341

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

🔮 The oracle has spoken through Smoke Codex

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Smoke Cloud Hypervisor reports failed. Cloud Hypervisor + Copilot failed.

Cloud Hypervisor + Copilot smoke test by Smoke Cloud Hypervisor

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

🔌 Smoke Services — All services reachable! ✅

🔌 Service connectivity validated by Smoke Services

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤

📰 BREAKING: Report filed by Smoke Copilot

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.

Tested by Smoke Chroot

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...

🔑 BYOK (AOAI api-key) report filed by Smoke Copilot BYOK AOAI (api-key)

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Smoke Test: Claude Engine Validation

  • API status: ✅ PASS
  • GitHub check: ✅ PASS
  • File status: ✅ PASS

Overall result: PASS

Generated by Smoke Claude for #9341 · claude · haiku45 · 49.8 AIC · ⊞ 6.2K · ◷
Add label ready-for-aw to run again

@github-actions github-actions Bot added smoke-claude smoke-copilot-network-isolation Copilot network-isolation egress smoke test labels Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

EGRESS_RESULT allow=pass deny=pass

  • ✅ Allowed domain (api.github.com): HTTP 200
  • ✅ Blocked domain (example.com): blocked (curl failed, cert error)

Overall: PASS — cc @lpcox

🛡️ Egress verdict from Smoke Copilot Network Isolation
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Smoke Test: Copilot BYOK (Direct) Mode ✅ PASS

Test Status
GitHub MCP Connectivity ✅
GitHub.com HTTP ✅ (200)
File Write/Read ✅
BYOK Inference Path ✅

Mode: Direct BYOK (COPILOT_PROVIDER_API_KEY) via api-proxy → api.githubcopilot.com

🔑 BYOK report filed by Smoke Copilot BYOK
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Smoke Copilot: PASS

  • ✅ GitHub MCP (latest merged: "Reuse shared logger mock in branch-coverage tests")
  • ✅ github.com HTTP 200
  • ✅ File write/read
    Author @Copilot; assignees @lpcox @Copilot

📰 BREAKING: Report filed by Smoke Copilot
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

OTEL smoke test

  • ✅ S1: otel.js loads; exports startRequestSpan, setTokenAttributes, setBudgetAttributes, endSpan, endSpanError, shutdown, isEnabled, and others.
  • ✅ S2: 3 OTEL suites, 68/68 tests pass.
  • ✅ S3: env-passthrough.ts forwards GITHUB_AW_OTEL_TRACE_ID/PARENT_SPAN_ID. api-proxy-env-config.ts forwards the OTEL vars to the api-proxy.
  • ✅ S4: the onUsage hook is present in token-tracker-http.js.
  • ✅ S5: otel.jsonl has 1 line, which I counted but did not inspect. I did not check for OTLP exports.

📡 OTel tracing validated by Smoke OTel Tracing
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Services smoke test:

  • Redis PING: ✅ PONG
  • pg_isready: ✅ accepting connections
  • psql SELECT 1: ✅ 1

Overall: PASS

🔌 Service connectivity validated by Smoke Services
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

🏗️ Build Test Suite Results

Ecosystem Project Build/Install Tests Status
Bun elysia ❌ not run ❌ FAIL
Bun hono ❌ not run ❌ FAIL
C++ fmt ✅ N/A ✅ PASS
C++ json ✅ N/A ✅ PASS
Deno oak ❌ not run ❌ FAIL
Deno std ❌ not run ❌ FAIL
.NET hello-world ✅ N/A ✅ PASS
.NET json-parse ✅ N/A ✅ PASS
Go color ✅ all passed ✅ PASS
Go env ✅ all passed ✅ PASS
Go uuid ✅ all passed ✅ PASS
Java gson ✅ 1/1 passed ✅ PASS*
Java caffeine ✅ 1/1 passed ✅ PASS*
Node.js clsx ✅ passed ✅ PASS
Node.js execa ✅ passed ✅ PASS
Node.js p-limit ✅ passed ✅ PASS
Rust fd ✅ 1/1 passed ✅ PASS
Rust zoxide ✅ 1/1 passed ✅ PASS

Overall: 6/8 ecosystems passed — FAIL

Failures

  • Bun / Deno: The sandbox denied the install commands (curl ... | bash / | sh): "Permission denied and could not request permission from user". bun and deno are not on the PATH, so these tests were not run. I did not try to work around this.
  • *Java: with the default ~/.m2/repository, Maven failed with Could not create local repository at /home/runner/.m2/repository. With -Dmaven.repo.local pointed at a writable temp directory, compile and test passed for both projects.

Generated by Build Test Suite for #9341 · copilot · auto · 25.1 AIC · ⊞ 11.8K · ◷
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Chroot Version Comparison

Runtime Host Version Chroot Version Match?
Python Python 3.12.14 Python 3.12.14 ✅ YES
Node.js v24.21.0 v22.23.2 ❌ NO
Go go1.22.12 go1.22.12 ✅ YES

Result: Not all tests passed (Node.js version mismatch), so the smoke-chroot label was not added.

Tested by Smoke Chroot
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Smoke test results

  • Last 2 merged PRs: ❌
  • 2 PR details: ❌
  • Playwright title check: ❌
  • Temp file write/read: ❌
  • AWF build: ❌
  • Overall: FAIL

🔮 The oracle has spoken through Smoke Codex
Add label ready-for-aw to run again

@lpcox
lpcox merged commit f88e087 into main Oct 2, 2026
135 of 141 checks passed
@lpcox
lpcox deleted the copilot/add-virtio-fs-export-layouts branch October 2, 2026 00:05

This branch was successfully deployed

1 active deployment
aoai-model — 12773c44 Deployed Oct 1, 2026 by lpcox via conclusion #1848
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add enclave-specific Cloud Hypervisor virtio-fs export layouts

3 participants