Enforce Cloud Hypervisor enclave resource limits - #9349
Conversation
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Documentation PreviewDocumentation has been built for this PR. To view locally:
Built from commit 82888ad |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Enclave workspace validation, writable agent storage, process-wide privilege dropping, artifact hardening, and effective guest tests remain incomplete.
Review effort: Balanced
Findings: 2
Open (5)
What changed in this PR
Adds fixed resource limits and privilege hardening for future Cloud Hypervisor enclave workloads.
Changes:
- Defines role-specific VM, cgroup, storage, tmpfs, and rlimit budgets.
- Enforces guest identity, capabilities, and
no_new_privs. - Hardens and validates enclave rootfs artifacts.
| File | Description |
|---|---|
src/cloud-hypervisor/workload-profile.ts |
Defines closed resource profiles. |
src/cloud-hypervisor/workload-profile.test.ts |
Tests profile pinning. |
src/cloud-hypervisor/vm-config-builder.ts |
Applies VM limits and read-only rootfs. |
src/cloud-hypervisor/vm-config-builder.test.ts |
Tests VM resource configuration. |
src/cloud-hypervisor/virtiofsd.ts |
Validates writable storage capacity. |
src/cloud-hypervisor/virtiofsd.test.ts |
Tests storage validation. |
src/cloud-hypervisor/manager-types.ts |
Adds resource-profile types. |
src/cloud-hypervisor/manager-start.ts |
Wires limits into startup. |
src/cloud-hypervisor/launcher.ts |
Supports fractional CPU quotas. |
src/cloud-hypervisor/launcher.test.ts |
Tests CPU quota enforcement. |
scripts/ci/cloud-hypervisor-enclave-artifacts.test.ts |
Extends artifact assertions. |
guest/microvm-supervisor/runtime_linux.go |
Applies enclave setup before execution. |
guest/microvm-supervisor/resources_linux.go |
Implements guest resource controls. |
guest/microvm-supervisor/resources_linux_test.go |
Tests guest limit helpers. |
guest/microvm-supervisor/main.go |
Adds the verified execution trampoline. |
guest/microvm-supervisor/config.go |
Parses enclave role configuration. |
guest/microvm-supervisor/config_test.go |
Tests role parsing. |
guest/cloud-hypervisor/verify-test-artifacts.sh |
Verifies hardened artifacts. |
guest/cloud-hypervisor/build-test-artifacts.sh |
Builds hardened rootfs images. |
docs/cloud-hypervisor-foundation.md |
Documents resource enforcement. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| if values["awf.enclave-role"] != "" { | ||
| if device != "" || workspaceMount != "" { | ||
| return bootConfig{}, fmt.Errorf("enclave cannot declare a primary workspace") | ||
| } | ||
| for _, fsMount := range virtiofsMounts { |
| mounts = append(mounts, struct { | ||
| target string | ||
| size uint64 | ||
| mode os.FileMode | ||
| uid uint32 |
| sudo find "$tree" -xdev \( -type f -o -type l \) \ | ||
| \( -name apk -o -name apt -o -name apt-cache -o -name apt-get -o -name apt-mark \ | ||
| -o -name dpkg -o -name dpkg-deb -o -name dpkg-query \ | ||
| -o -name rpm -o -name dnf -o -name yum -o -name zypper -o -name pacman -o -name emerge \ | ||
| -o -name pip -o -name pip3 -o -name pipx -o -name npm -o -name npx -o -name corepack \ |
| if _, _, errno := syscall.RawSyscall( | ||
| syscall.SYS_CAPSET, | ||
| uintptr(unsafe.Pointer(&header)), | ||
| uintptr(unsafe.Pointer(&data[0])), | ||
| 0, |
| func TestEnclavePrivilegeStatusMustBeVerified(t *testing.T) { | ||
| status := strings.Join([]string{ | ||
| "CapEff:\t0000000000000000", | ||
| "CapPrm:\t0000000000000000", | ||
| "CapInh:\t0000000000000000", |
|
⏳ Copilot review left inline comments. @copilot To proceed:
|
|
@copilot address review feedback |
Addressed all five review findings in 28455bb:
|
|
✅ Build Test Suite completed successfully!
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅
|
|
Smoke Cloud Hypervisor reports failed. Cloud Hypervisor + Copilot failed.
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅
|
|
❌ Smoke Gemini reports failed. Facets need polishing...
|
|
🚀 Security Guard has started processing this pull request |
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟 Smoke test complete: FAIL. Posted PR comment; discussion comment and label skipped because required checks could not be completed in this environment.
|
|
EGRESS_RESULT allow=pass deny=pass
|
|
Smoke Copilot: PASS
|
|
Smoke Test: Copilot BYOK (Direct Mode) ✅ PASS
Mode:
|
Smoke Test: Claude Engine Validation
Overall result: PASS
|
|
OTEL smoke test (checked locally)
|
|
Services smoke test:
Overall: PASS
|
🏗️ Build Test Suite Results
Overall: 8/8 ecosystems passed — PASS *Java: the first Maven run failed with
|
Chroot Version Comparison
Result: FAILED. Node.js differs between host and chroot, so the
|
|



Enclave VM memory and vCPU settings alone do not bound guest processes, temporary files, open files, or writable storage. This adds fixed, host-derived resource budgets and verifies their enforcement before workload code runs.
no_new_privsbeforeexec. Remove package managers, setuid/setgid bits, and file capabilities from enclave rootfs artifacts./query256 MiB/tmp96 MiB