fix: enforce per-invocation Cloud Hypervisor enclave storage limits - #9397
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The privileged enforcement suite is not run in CI, and an existing broker fixture now inherits the real storage verifier and fails.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Adds host-enforced, per-invocation tmpfs storage limits for Cloud Hypervisor enclaves.
Changes:
- Provisions and validates role-sized bounded storage.
- Accounts for storage in enclave cgroups and cleanup lifecycle.
- Adds unit, privileged integration, and architecture documentation coverage.
| File | Description |
|---|---|
src/cloud-hypervisor/virtiofsd.ts |
Delegates bounded-storage verification. |
src/cloud-hypervisor/virtiofsd.test.ts |
Tests pre-launch verification. |
src/cloud-hypervisor/manager-start.ts |
Passes storage budget to cgroups. |
src/cloud-hypervisor/manager-launch.test.ts |
Verifies enclave-only accounting. |
src/cloud-hypervisor/launcher.ts |
Adds storage memory headroom. |
src/cloud-hypervisor/launcher.test.ts |
Tests cgroup limits and validation. |
src/cloud-hypervisor/host-enclave-executor.ts |
Integrates mount, verification, and unmount. |
src/cloud-hypervisor/host-enclave-executor.test.ts |
Tests startup rejection and cleanup. |
src/cloud-hypervisor/enclave-storage.ts |
Implements bounded storage lifecycle. |
src/cloud-hypervisor/enclave-storage.test.ts |
Tests storage identity validation. |
src/cloud-hypervisor/enclave-storage.integration.test.ts |
Exercises real tmpfs enforcement. |
docs/cloud-hypervisor-foundation.md |
Documents limits and failure behavior. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| tools, | ||
| ); | ||
| await onMounted(); | ||
| await dependencies.verifyStorage(plan.invocationHostDir, resourceProfile.writableStorageBytes); |
|
|
||
| // Exercise the host sources served by the closed guest-visible virtio-fs | ||
| // exports. Live VM transport conformance is gated separately on KVM artifacts. | ||
| (live ? describe : describe.skip)('host-enforced enclave storage', () => { |
|
@copilot address the review feedback |
Addressed both points in 70fd0fe. I added a |
|
✅ Copilot review passed with no inline comments. @copilot Add the |
Documentation PreviewDocumentation has been built for this PR. To view locally:
Built from commit bae1655 |
✅ Coverage Check PassedOverall Coverage
📁 Per-file Coverage Changes (6 files)
✨ New Files (1 files)
Coverage comparison generated by |
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅
|
|
✅ Smoke Claude passed
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
🚀 Security Guard has started processing this pull request |
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
Chroot tests failed Smoke Chroot failed - See logs for details.
|
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟
|
|
Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed.
|
|
❌ Smoke Gemini reports failed. Facets need polishing...
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
✅ Build Test Suite completed successfully!
|
Smoke Test: Claude Engine Validation
Overall result: PASS
|
|
EGRESS_RESULT allow=pass deny=pass
Overall: PASS — cc
|
|
Services smoke test:
PASS
|
|
OTEL smoke test results
|
|
Smoke Copilot: PASS
|
✅ Smoke Test: Copilot BYOK (Direct) ModeTest Results:
Status: PASS Running in direct BYOK mode (
|
Smoke Test: Cloud Hypervisor + Copilot
Note: checks 2 and 4 could not run any outbound curl at all - the bash tool refused network commands uniformly (even curl --version-style network calls), reflecting a sandbox/tool restriction rather than the AWF firewall domain allow/deny behavior.
|
🏗️ Build Test Suite Results
Overall: 6/8 ecosystems passed — FAIL Failures
|
|


Cloud Hypervisor enclaves need host-enforced writable storage limits across all exports: 1 GiB per script invocation and 512 MiB per agent invocation, without an unbounded fallback.
Bounded backing store
Memory accounting and lifecycle
Coverage and documentation
ENOSPC, isolation, startup-rejection, busy-unmount, and cgroup-accounting coverage.