Skip to content

feat: implement host-side Cloud Hypervisor enclave executor - #9376

Merged
lpcox merged 5 commits into
mainfrom
copilot/implement-host-side-cloud-hypervisor-executor
Oct 2, 2026
Merged

lpcox merged 5 commits into
mainfrom
copilot/implement-host-side-cloud-hypervisor-executor

Conversation

Copilot AI commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Implements the trusted host-side Cloud Hypervisor enclave executor for static script and agent invocations while keeping user-facing Cloud Hypervisor enclave selection fail-closed.

  • Upgrades the authenticated broker-to-host protocol to v2 so the host independently validates the finite result schema and derives trusted invocation timeouts.
  • Adds release-attested role-rootfs preflight and a single-use backend with role-specific fixed VM profiles, bounded per-invocation tmpfs storage, cancellation/deadline handling, schema-validated result collection, and cleanup.
  • Adds guest compatibility links for the established script/agent entrypoints and makes the static GitHub session-handoff export read-only.
  • Adds focused protocol, export-plan, backend lifecycle, guest compatibility, and workload-profile coverage, and updates the enclave architecture/ADR status.

Validation

  • npm run build -- --pretty false
  • npm run lint -- --quiet
  • Focused Jest suites: 9 suites, 207 tests passed
  • cd guest/microvm-supervisor && go test ./...
  • Markdown lint for the changed architecture documents

Remaining rollout gate

The host executor and broker client are not wired into runtime selection. Cloud Hypervisor enclave configuration therefore still fails closed; this PR does not enable general execution, dynamic repository admission, or durable end-to-end broker reconciliation. Real-KVM integration/security validation remains a rollout requirement.

Fixes #9375

Copilot AI linked an issue Oct 2, 2026 that may be closed by this pull request
Copilot AI changed the title [WIP] Implement the host-side Cloud Hypervisor enclave executor Implement the host-side Cloud Hypervisor enclave executor Oct 2, 2026
Copilot AI requested a review from lpcox October 2, 2026 15:50
@lpcox
lpcox marked this pull request as ready for review October 2, 2026 15:53
Copilot AI balanced review requested due to automatic review settings October 2, 2026 15:53

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request. Check if the Files changed in this pull request are included in default exclusions.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

✅ Copilot review passed with no inline comments.

@copilot Add the ready-for-aw label to this PR to trigger agentic CI smoke tests.

@lpcox lpcox changed the title Implement the host-side Cloud Hypervisor enclave executor feat(cloud-hypervisor): implement host-side enclave executor Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Documentation Preview

Documentation has been built for this PR.

Download preview artifact

To view locally:

  1. Download the docs-preview-pr-9376 artifact from the workflow run
  2. Unzip and open index.html in your browser

Built from commit ea1d410

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Comment thread src/cloud-hypervisor/host-enclave-executor.ts Fixed
@lpcox lpcox changed the title feat(cloud-hypervisor): implement host-side enclave executor feat: implement host-side Cloud Hypervisor enclave executor Oct 2, 2026
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@lpcox
lpcox requested a balanced review from Copilot October 2, 2026 16:59
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

⚠️ Coverage Regression Detected

This PR decreases test coverage. Please add tests to maintain coverage levels.

Overall Coverage

Metric Base PR Delta
Lines 92.76% 92.07% 📉 -0.69%
Statements 91.29% 90.56% 📉 -0.73%
Functions 89.37% 88.93% 📉 -0.44%
Branches 84.66% 83.59% 📉 -1.07%
📁 Per-file Coverage Changes (7 files)
File Lines (Before → After) Statements (Before → After)
src/cloud-hypervisor/workload-profile.ts 97.7% → 96.9% (-0.73%) 97.0% → 96.4% (-0.68%)
src/nvx/one-shot-adapter.ts 83.5% → 82.9% (-0.60%) 80.3% → 79.8% (-0.56%)
src/enclave/host-executor-server.ts 90.8% → 90.9% (+0.08%) 88.7% → 88.8% (+0.10%)
src/enclave/host-executor-protocol.ts 97.5% → 97.6% (+0.09%) 94.7% → 94.8% (+0.17%)
src/cloud-hypervisor/manager.ts 85.8% → 85.9% (+0.10%) 84.2% → 84.3% (+0.11%)
src/bounded-execution/finite-schema.ts 52.8% → 53.4% (+0.52%) 49.3% → 49.8% (+0.46%)
src/log-directory-setup.ts 96.8% → 100.0% (+3.18%) 96.9% → 100.0% (+3.13%)
✨ New Files (2 files)
  • src/bounded-execution/schema-hash.ts: 92.3% lines
  • src/cloud-hypervisor/host-enclave-executor.ts: 50.0% lines

Coverage comparison generated by scripts/ci/compare-coverage.ts

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

VMM snapshot selection, guest filesystem ownership, missing output staging, and incomplete startup deadlines currently prevent safe reliable execution.

Review effort: Balanced
Findings: 3 High severity · 2 Medium severity

Open (5)

Comment on lines +178 to +187
createManager: (config, workDir, profile, runId, artifacts, managerDependencies) => new CloudHypervisorManager(
config,
workDir,
managerDependencies,
runId,
profile,
undefined,
artifacts,
true,
),
Comment on lines +546 to +550
for (const name of ['request', 'output', 'runtime']) {
const directory = filePath(plan.invocationHostDir, name);
await dependencies.mkdir(directory, { mode: 0o700 });
await dependencies.chown(directory, identity.uid, identity.gid);
}
Comment on lines +586 to +588
await dependencies.writeFile(filePathValue, contents, { encoding: 'utf8', mode, flag: 'wx' });
await dependencies.chown(filePathValue, uid, gid);
await dependencies.chmod(filePathValue, mode);
Comment thread src/cloud-hypervisor/host-enclave-executor.ts
Comment on lines +832 to +841
const abortManager = (): void => {
filesystemState.aborted = true;
void manager?.cancel('host executor cancelled').catch(() => undefined);
// Stopping concurrently with startup can miss resources created after stop returns.
};
signal.addEventListener('abort', abortManager, { once: true });
const deadline = setTimeout(() => {
filesystemState.timedOut = true;
abortManager();
}, plan.timeoutMs);
@lpcox

lpcox commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

@copilot address review feedback

Copilot AI commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

@copilot address review feedback

Addressed the executor review feedback in commit 6b2d5ce. The attested VMM snapshot, fixed guest ownership/identity and output staging, and deadline-aware startup teardown are implemented and tested.

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

⚠️ Coverage Regression Detected

This PR decreases test coverage. Please add tests to maintain coverage levels.

Overall Coverage

Metric Base PR Delta
Lines 92.75% 92.08% 📉 -0.67%
Statements 91.28% 90.55% 📉 -0.73%
Functions 89.37% 88.88% 📉 -0.49%
Branches 84.64% 83.56% 📉 -1.08%
📁 Per-file Coverage Changes (6 files)
File Lines (Before → After) Statements (Before → After)
src/cloud-hypervisor/workload-profile.ts 97.7% → 96.9% (-0.73%) 97.0% → 96.4% (-0.68%)
src/enclave/host-executor-server.ts 90.8% → 90.9% (+0.08%) 88.7% → 88.8% (+0.10%)
src/enclave/host-executor-protocol.ts 97.5% → 97.6% (+0.09%) 94.7% → 94.8% (+0.17%)
src/cloud-hypervisor/manager.ts 85.8% → 85.9% (+0.10%) 84.2% → 84.3% (+0.11%)
src/bounded-execution/finite-schema.ts 52.8% → 53.4% (+0.52%) 49.3% → 49.8% (+0.46%)
src/log-directory-setup.ts 96.8% → 100.0% (+3.18%) 96.9% → 100.0% (+3.13%)
✨ New Files (2 files)
  • src/bounded-execution/schema-hash.ts: 92.3% lines
  • src/cloud-hypervisor/host-enclave-executor.ts: 55.0% lines

Coverage comparison generated by scripts/ci/compare-coverage.ts

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...

🪪 BYOK (AOAI Entra) report filed by Smoke Copilot BYOK AOAI (Entra)

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.

Tested by Smoke Chroot

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...

🔑 BYOK (AOAI api-key) report filed by Smoke Copilot BYOK AOAI (api-key)

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

✅ Security Guard completed successfully!

Security review of PR #9376: No security concerns found. The PR adds protocol version 2 support for host-side Cloud Hypervisor enclave executor with proper input validation and bounded schema parameter size (4096 bytes). No firewall rules weakened, no capabilities added, no egress expansion, no secrets exposure. All changes maintain existing security properties.

Generated by Security Guard for #9376

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

🔮 The oracle has spoken through Smoke Codex

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

✅ Smoke Claude passed

Generated by Smoke Claude for #9376

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

🔌 Smoke Services — All services reachable! ✅

🔌 Service connectivity validated by Smoke Services

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

EGRESS_RESULT allow=pass deny=pass

  • ✅ Allowed domain (api.github.com): 200
  • ✅ Blocked domain (example.com): failed (curl exit 60, TLS cert error)
  • Overall: PASS

cc @lpcox

🛡️ Egress verdict from Smoke Copilot Network Isolation
Add label ready-for-aw to run again

@github-actions github-actions Bot added smoke-copilot-network-isolation Copilot network-isolation egress smoke test smoke-copilot labels Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Smoke Copilot: PASS

  • ✅ GitHub MCP (last merged: "Recompile workflows with latest gh-aw pre-release")
  • ✅ github.com connectivity (HTTP 200)
  • ✅ File write/read
    Author: @Copilot · Assignees: @lpcox @Copilot

📰 BREAKING: Report filed by Smoke Copilot
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

smoke-copilot-byok Test Results

✅ GitHub MCP Test — Connected, merged PRs verified
✅ GitHub.com Connectivity — HTTP 200
✅ File Write/Read — File exists and readable
✅ BYOK Inference — Direct mode via api-proxy → api.githubcopilot.com

Overall: PASS — Running in direct BYOK mode (COPILOT_PROVIDER_API_KEY)

🔑 BYOK report filed by Smoke Copilot BYOK
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

OTEL smoke test results:

  • ✅ 1. Module loading: otel.js loads and exports startRequestSpan, setTokenAttributes, endSpan, shutdown, isEnabled, and others.
  • ✅ 2. Test suite: 3 suites, 68 tests, all passing.
  • ✅ 3. Env var forwarding: OTEL references are present in env-passthrough.ts and api-proxy-env-config.ts.
  • ✅ 4. Token tracker: onUsage is present in token-tracker-http.js.
  • ✅ 5. Diagnostics: /tmp/gh-aw/otel.jsonl exists with 1 line. I did not inspect its contents, so I can't confirm that spans were exported.

📡 OTel tracing validated by Smoke OTel Tracing
Add label ready-for-aw to run again

@lpcox
lpcox deployed to aoai-model October 2, 2026 17:34 — with GitHub Actions Active
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Smoke Test: Claude Engine Validation

  • API status: ✅ PASS
  • GitHub check: ✅ PASS
  • File status: ✅ PASS

Overall result: PASS

Generated by Smoke Claude for #9376 · claude · haiku45 · 49.8 AIC · ⊞ 6.2K · ◷
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

🏗️ Build Test Suite Results

Ecosystem Project Build/Install Tests Status
Bun elysia ❌ not run ❌ FAIL
Bun hono ❌ not run ❌ FAIL
C++ fmt ✅ N/A ✅ PASS
C++ json ✅ N/A ✅ PASS
Deno oak ❌ not run ❌ FAIL
Deno std ❌ not run ❌ FAIL
.NET hello-world ✅ N/A ✅ PASS
.NET json-parse ✅ N/A ✅ PASS
Go color ✅ 1/1 pkg passed ✅ PASS
Go env ✅ 1/1 pkg passed ✅ PASS
Go uuid ✅ 1/1 pkg passed ✅ PASS
Java gson ❌ not run ❌ FAIL
Java caffeine ❌ not run ❌ FAIL
Node.js clsx ✅ passed ✅ PASS
Node.js execa ✅ passed ✅ PASS
Node.js p-limit ✅ passed ✅ PASS
Rust fd ✅ 1/1 passed ✅ PASS
Rust zoxide ✅ 1/1 passed ✅ PASS

Overall: 5/8 ecosystems passed — FAIL

Failures

  • Bun/Deno: the install scripts (curl ... | bash/sh) were denied by the sandbox permission policy, so the runtimes were not installed and the tests were not run. Neither bun nor deno is preinstalled.
  • Java: Maven failed with Could not create local repository at /home/runner/.m2/repository (LocalRepositoryNotAccessibleException), so compile and test did not run.

Generated by Build Test Suite for #9376 · copilot · auto · 25 AIC · ⊞ 11.8K · ◷
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Smoke services: PASS

  • ✅ Redis PING → PONG
  • ✅ pg_isready → accepting connections
  • ✅ psql SELECT 1 → 1

🔌 Service connectivity validated by Smoke Services
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Chroot Version Comparison

Runtime Host Version Chroot Version Match?
Python Python 3.12.14 Python 3.12.14 ✅ YES
Node.js v24.21.0 v2.98.0 ❌ NO
Go go1.22.12 go1.22.12 ✅ YES

Result: FAILED. The Node.js versions differ, so the smoke-chroot label was not added. The chroot reports v2.98.0, which does not look like a Node.js version. It may come from a different binary or output.

Tested by Smoke Chroot
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

PR titles: ❌
Merged PR review: ❌
PR details: ❌
Playwright title: ❌
Smoke file write/read: ❌
Latest discussion lookup/comment: ❌
Build (npm ci && npm run build): ❌
Overall status: FAIL

🔮 The oracle has spoken through Smoke Codex
Add label ready-for-aw to run again

@lpcox
lpcox enabled auto-merge (squash) October 2, 2026 17:41
@lpcox
lpcox merged commit 0d10a5d into main Oct 2, 2026
135 of 140 checks passed
@lpcox
lpcox deleted the copilot/implement-host-side-cloud-hypervisor-executor branch October 2, 2026 17:43

This branch was successfully deployed

1 active deployment
aoai-model — 6b2d5ce0 Deployed Oct 2, 2026 by lpcox via conclusion #1856
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Implement the host-side Cloud Hypervisor enclave executor

4 participants