Skip to content

Enforce Cloud Hypervisor enclave resource limits - #9349

Merged
lpcox merged 5 commits into
mainfrom
copilot/enforce-enclave-resource-limits
Oct 2, 2026
Merged

lpcox merged 5 commits into
mainfrom
copilot/enforce-enclave-resource-limits

Conversation

Copilot AI commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Enclave VM memory and vCPU settings alone do not bound guest processes, temporary files, open files, or writable storage. This adds fixed, host-derived resource budgets and verifies their enforcement before workload code runs.

  • Closed role budgets: Script and agent profiles define guest memory, vCPU, host CPU quota, process/file/open-file limits, tmpfs sizes, storage ceilings, and UID/GID. Requests and launch metadata cannot alter them.
  • Host and guest enforcement: Configure VM and cgroup limits; mount bounded tmpfs filesystems; apply and verify rlimits and identity before accepting work. Writable exports fail closed unless their backing filesystem fits the role ceiling.
  • Privilege and artifact hardening: Drop unnecessary capabilities; verify workload privilege state and no_new_privs before exec. Remove package managers, setuid/setgid bits, and file capabilities from enclave rootfs artifacts.
  • Scope: Primary-agent behavior remains unchanged. Cloud Hypervisor enclave execution remains fail-closed pending executor and broker integration.
Resource Script Agent
Guest RAM / vCPU / host CPU 768 MiB / 1 / 500 milli-CPU 768 MiB / 1 / 500 milli-CPU
Processes / open files 47 / 1024 47 / 1024
File size / role work tmpfs 512 MiB / /query 256 MiB 256 MiB / /tmp 96 MiB
Writable filesystem ceiling 1 GiB 512 MiB

Comment thread guest/cloud-hypervisor/verify-test-artifacts.sh Outdated
Copilot AI changed the title [WIP] Enforce enclave resource limits inside Cloud Hypervisor guests Enforce Cloud Hypervisor enclave resource limits Oct 2, 2026
Copilot AI requested a review from lpcox October 2, 2026 01:04
@lpcox
lpcox marked this pull request as ready for review October 2, 2026 02:37
Copilot AI balanced review requested due to automatic review settings October 2, 2026 02:37
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Documentation Preview

Documentation has been built for this PR.

Download preview artifact

To view locally:

  1. Download the docs-preview-pr-9349 artifact from the workflow run
  2. Unzip and open index.html in your browser

Built from commit 82888ad

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Enclave workspace validation, writable agent storage, process-wide privilege dropping, artifact hardening, and effective guest tests remain incomplete.

Review effort: Balanced
Findings: 2 High severity · 2 Medium severity · 1 Low severity

Open (5)
What changed in this PR

Adds fixed resource limits and privilege hardening for future Cloud Hypervisor enclave workloads.

Changes:

  • Defines role-specific VM, cgroup, storage, tmpfs, and rlimit budgets.
  • Enforces guest identity, capabilities, and no_new_privs.
  • Hardens and validates enclave rootfs artifacts.
File Description
src/​cloud-hypervisor/​workload-profile.ts Defines closed resource profiles.
src/​cloud-hypervisor/​workload-profile.test.ts Tests profile pinning.
src/​cloud-hypervisor/​vm-config-builder.ts Applies VM limits and read-only rootfs.
src/​cloud-hypervisor/​vm-config-builder.test.ts Tests VM resource configuration.
src/​cloud-hypervisor/​virtiofsd.ts Validates writable storage capacity.
src/​cloud-hypervisor/​virtiofsd.test.ts Tests storage validation.
src/​cloud-hypervisor/​manager-types.ts Adds resource-profile types.
src/​cloud-hypervisor/​manager-start.ts Wires limits into startup.
src/​cloud-hypervisor/​launcher.ts Supports fractional CPU quotas.
src/​cloud-hypervisor/​launcher.test.ts Tests CPU quota enforcement.
scripts/​ci/​cloud-hypervisor-enclave-artifacts.test.ts Extends artifact assertions.
guest/​microvm-supervisor/​runtime_linux.go Applies enclave setup before execution.
guest/​microvm-supervisor/​resources_linux.go Implements guest resource controls.
guest/​microvm-supervisor/​resources_linux_test.go Tests guest limit helpers.
guest/​microvm-supervisor/​main.go Adds the verified execution trampoline.
guest/​microvm-supervisor/​config.go Parses enclave role configuration.
guest/​microvm-supervisor/​config_test.go Tests role parsing.
guest/​cloud-hypervisor/​verify-test-artifacts.sh Verifies hardened artifacts.
guest/​cloud-hypervisor/​build-test-artifacts.sh Builds hardened rootfs images.
docs/​cloud-hypervisor-foundation.md Documents resource enforcement.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread guest/microvm-supervisor/config.go Outdated
Comment on lines +124 to +128
if values["awf.enclave-role"] != "" {
if device != "" || workspaceMount != "" {
return bootConfig{}, fmt.Errorf("enclave cannot declare a primary workspace")
}
for _, fsMount := range virtiofsMounts {
Comment on lines +74 to +78
mounts = append(mounts, struct {
target string
size uint64
mode os.FileMode
uid uint32
Comment on lines +299 to +303
sudo find "$tree" -xdev \( -type f -o -type l \) \
\( -name apk -o -name apt -o -name apt-cache -o -name apt-get -o -name apt-mark \
-o -name dpkg -o -name dpkg-deb -o -name dpkg-query \
-o -name rpm -o -name dnf -o -name yum -o -name zypper -o -name pacman -o -name emerge \
-o -name pip -o -name pip3 -o -name pipx -o -name npm -o -name npx -o -name corepack \
Comment on lines +244 to +248
if _, _, errno := syscall.RawSyscall(
syscall.SYS_CAPSET,
uintptr(unsafe.Pointer(&header)),
uintptr(unsafe.Pointer(&data[0])),
0,
Comment on lines +97 to +101
func TestEnclavePrivilegeStatusMustBeVerified(t *testing.T) {
status := strings.Join([]string{
"CapEff:\t0000000000000000",
"CapPrm:\t0000000000000000",
"CapInh:\t0000000000000000",
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

⏳ Copilot review left inline comments.

@copilot To proceed:

  1. Ask @copilot to address the review feedback (reply to this comment or the review thread)
  2. Once the fix is pushed, add the ready-for-aw label to trigger agentic CI smoke tests

@lpcox

lpcox commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

@copilot address review feedback

Copilot AI commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

@copilot address review feedback

Addressed all five review findings in 28455bb:

  • Workspace bypass: parseBootConfig now rejects any enclave workspace device, mount, or workspace export before it branches on awf.workspace-mount. Added a regression test.
  • Agent /agent: Agent guests now bind the writable /runtime export at /agent (nosuid,nodev). Boot fails if that export is missing or read-only. On shutdown, /agent is unmounted before /runtime.
  • Per-thread privileges: The bounding-set drop, capset, and no_new_privs now run on every Go runtime thread through syscall.AllThreadsSyscall (the binary is built with CGO_ENABLED=0). The supervisor and trampoline both check every /proc/self/task/*/status entry. As a check, I reverted no_new_privs to the single-thread call and the new probe failed.
  • pip/ensurepip: The build now removes the module directories and pip-*.dist-info, then runs each image's Python in a chroot to confirm neither module resolves. The verifier also checks every Python library tree with debugfs. I ran this against python:3.14.7-alpine3.24: afterwards python3 -m pip and python3 -m venv both fail.
  • Live probe: Added TestEnclaveGuestLimitsLive, a root-only test that the CI workflow runs with sudo. It runs the real agent-role tmpfs, rlimit, read-only-root, and privilege-drop code in a private mount namespace, then launches a workload through --awf-enclave-exec. The workload must see ENOSPC on each bounded tmpfs, EFBIG, EMFILE, EAGAIN, and EROFS, plus UID/GID 65534 with no groups, and zero capabilities with no_new_privs on every thread. It passes locally.
  • Not covered yet: The probe runs on the host kernel, not inside a KVM guest. Booting the enclave rootfs under KVM still needs the host executor integration, which remains fail-closed.

@lpcox
lpcox enabled auto-merge (squash) October 2, 2026 05:04
@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

✅ Build Test Suite completed successfully!

Generated by Build Test Suite for #9349

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

🔌 Smoke Services — All services reachable! ✅

🔌 Service connectivity validated by Smoke Services

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓

🔑 BYOK report filed by Smoke Copilot BYOK

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.

Tested by Smoke Chroot

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...

🔑 BYOK (AOAI api-key) report filed by Smoke Copilot BYOK AOAI (api-key)

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤

📰 BREAKING: Report filed by Smoke Copilot

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅

📡 OTel tracing validated by Smoke OTel Tracing

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Smoke Cloud Hypervisor reports failed. Cloud Hypervisor + Copilot failed.

Cloud Hypervisor + Copilot smoke test by Smoke Cloud Hypervisor

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅

🛡️ Egress verdict from Smoke Copilot Network Isolation

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

❌ Smoke Gemini reports failed. Facets need polishing...

💎 Faceted by Smoke Gemini

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

🚀 Security Guard has started processing this pull request

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...

🪪 BYOK (AOAI Entra) report filed by Smoke Copilot BYOK AOAI (Entra)

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

Smoke test complete: FAIL. Posted PR comment; discussion comment and label skipped because required checks could not be completed in this environment.

🔮 The oracle has spoken through Smoke Codex

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

EGRESS_RESULT allow=pass deny=pass
✅ Allowed domain (api.github.com): 200
✅ Blocked domain (example.com): blocked
Overall: PASS — @lpcox

🛡️ Egress verdict from Smoke Copilot Network Isolation
Add label ready-for-aw to run again

@github-actions github-actions Bot added smoke-copilot-network-isolation Copilot network-isolation egress smoke test smoke-copilot labels Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Smoke Copilot: PASS

  • ✅ GitHub MCP: "fix(api-proxy): read input, cache, and thinking tokens from Anthropic message_delta usage"
  • ✅ github.com HTTP 200
  • ✅ File write/read
    cc @Copilot @lpcox @Copilot

📰 BREAKING: Report filed by Smoke Copilot
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Smoke Test: Copilot BYOK (Direct Mode) ✅ PASS

Mode: COPILOT_PROVIDER_API_KEY (direct BYOK)

🔑 BYOK report filed by Smoke Copilot BYOK
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Smoke Test: Claude Engine Validation

  • API status: ✅ PASS
  • GitHub check: ✅ PASS
  • File status: ✅ PASS

Overall result: PASS

Generated by Smoke Claude for #9349 · claude · haiku45 · 49.8 AIC · ⊞ 6.2K · ◷
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

OTEL smoke test (checked locally)

  • ✅ S1: otel.js loads. It exports startRequestSpan, setTokenAttributes, setBudgetAttributes, endSpan, endSpanError, shutdown, isEnabled, plus internals.
  • ✅ S2: OTEL tests pass (3 suites, 68 tests).
  • ✅ S3: env-passthrough.ts and api-proxy-env-config.ts both reference OTEL/trace vars.
  • ✅ S4: onUsage is present in token-tracker-http.js (4 matches).
  • ⚠️ S5: Not checked. I did not see the pre-step or post-step output, so I can't say whether spans were exported. I only ran the checks above in this sandbox.

📡 OTel tracing validated by Smoke OTel Tracing
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Services smoke test:

  • Redis PING: ✅ PONG
  • pg_isready: ✅ accepting connections
  • psql SELECT 1: ✅ 1

Overall: PASS

🔌 Service connectivity validated by Smoke Services
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

🏗️ Build Test Suite Results

Ecosystem Project Build/Install Tests Status
Bun elysia ✅ 1/1 passed ✅ PASS
Bun hono ✅ 1/1 passed ✅ PASS
C++ fmt ✅ N/A ✅ PASS
C++ json ✅ N/A ✅ PASS
Deno oak N/A 1/1 passed ✅ PASS
Deno std N/A 1/1 passed ✅ PASS
.NET hello-world ✅ N/A ✅ PASS
.NET json-parse ✅ N/A ✅ PASS
Go color ✅ pass ✅ PASS
Go env ✅ pass ✅ PASS
Go uuid ✅ pass ✅ PASS
Java gson ✅ 1/1 passed ✅ PASS*
Java caffeine ✅ 1/1 passed ✅ PASS*
Node.js clsx ✅ pass ✅ PASS
Node.js execa ✅ pass ✅ PASS
Node.js p-limit ✅ pass ✅ PASS
Rust fd ✅ 1/1 passed ✅ PASS
Rust zoxide ✅ 1/1 passed ✅ PASS

Overall: 8/8 ecosystems passed — PASS

*Java: the first Maven run failed with Could not create local repository at /home/runner/.m2/repository (~/.m2 is root-owned in the sandbox, so Maven could not write there). Re-running with -Dmaven.repo.local=/tmp/... passed both projects, so this was an environment permission issue, not a firewall block.

Generated by Build Test Suite for #9349 · copilot · auto · 23.2 AIC · ⊞ 11.8K · ◷
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Chroot Version Comparison

Runtime Host Version Chroot Version Match?
Python Python 3.12.14 Python 3.12.14 ✅
Node.js v24.21.0 v2.98.0 ❌
Go go1.22.12 go1.22.12 ✅

Result: FAILED. Node.js differs between host and chroot, so the smoke-chroot label was not added.

Tested by Smoke Chroot
Add label ready-for-aw to run again

@lpcox
lpcox deployed to aoai-model October 2, 2026 05:09 — with GitHub Actions Active
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor
  • [#9350] Update/update-pr-input-defaults-to-use-default-values-from-form-fields — ❌
  • [#9347] Update gh-aw-mcpg to v0.4.19 — ❌
  • GitHub PR reads — ❌
  • Playwright title check — ❌
  • File write/read — ✅
  • Build (npm ci && npm run build) — ❌
  • Overall: FAIL

🔮 The oracle has spoken through Smoke Codex
Add label ready-for-aw to run again

@lpcox
lpcox merged commit 2d51ba8 into main Oct 2, 2026
134 of 140 checks passed
@lpcox
lpcox deleted the copilot/enforce-enclave-resource-limits branch October 2, 2026 05:16

This branch was successfully deployed

1 active deployment
aoai-model — 28455bb3 Deployed Oct 2, 2026 by lpcox via conclusion #1854
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Enforce enclave resource limits inside Cloud Hypervisor guests

4 participants