Repository navigation
feat: implement host-side Cloud Hypervisor enclave executor - #9376
Conversation
There was a problem hiding this comment.
Copilot wasn't able to review any files in this pull request. Check if the Files changed in this pull request are included in default exclusions.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
✅ Copilot review passed with no inline comments. @copilot Add the |
Documentation PreviewDocumentation has been built for this PR. To view locally:
Built from commit ea1d410 |
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
| Metric | Base | PR | Delta |
|---|---|---|---|
| Lines | 92.76% | 92.07% | 📉 -0.69% |
| Statements | 91.29% | 90.56% | 📉 -0.73% |
| Functions | 89.37% | 88.93% | 📉 -0.44% |
| Branches | 84.66% | 83.59% | 📉 -1.07% |
📁 Per-file Coverage Changes (7 files)
| File | Lines (Before → After) | Statements (Before → After) |
|---|---|---|
src/cloud-hypervisor/workload-profile.ts |
97.7% → 96.9% (-0.73%) | 97.0% → 96.4% (-0.68%) |
src/nvx/one-shot-adapter.ts |
83.5% → 82.9% (-0.60%) | 80.3% → 79.8% (-0.56%) |
src/enclave/host-executor-server.ts |
90.8% → 90.9% (+0.08%) | 88.7% → 88.8% (+0.10%) |
src/enclave/host-executor-protocol.ts |
97.5% → 97.6% (+0.09%) | 94.7% → 94.8% (+0.17%) |
src/cloud-hypervisor/manager.ts |
85.8% → 85.9% (+0.10%) | 84.2% → 84.3% (+0.11%) |
src/bounded-execution/finite-schema.ts |
52.8% → 53.4% (+0.52%) | 49.3% → 49.8% (+0.46%) |
src/log-directory-setup.ts |
96.8% → 100.0% (+3.18%) | 96.9% → 100.0% (+3.13%) |
✨ New Files (2 files)
src/bounded-execution/schema-hash.ts: 92.3% linessrc/cloud-hypervisor/host-enclave-executor.ts: 50.0% lines
Coverage comparison generated by scripts/ci/compare-coverage.ts
| createManager: (config, workDir, profile, runId, artifacts, managerDependencies) => new CloudHypervisorManager( | ||
| config, | ||
| workDir, | ||
| managerDependencies, | ||
| runId, | ||
| profile, | ||
| undefined, | ||
| artifacts, | ||
| true, | ||
| ), |
| for (const name of ['request', 'output', 'runtime']) { | ||
| const directory = filePath(plan.invocationHostDir, name); | ||
| await dependencies.mkdir(directory, { mode: 0o700 }); | ||
| await dependencies.chown(directory, identity.uid, identity.gid); | ||
| } |
| await dependencies.writeFile(filePathValue, contents, { encoding: 'utf8', mode, flag: 'wx' }); | ||
| await dependencies.chown(filePathValue, uid, gid); | ||
| await dependencies.chmod(filePathValue, mode); |
| const abortManager = (): void => { | ||
| filesystemState.aborted = true; | ||
| void manager?.cancel('host executor cancelled').catch(() => undefined); | ||
| // Stopping concurrently with startup can miss resources created after stop returns. | ||
| }; | ||
| signal.addEventListener('abort', abortManager, { once: true }); | ||
| const deadline = setTimeout(() => { | ||
| filesystemState.timedOut = true; | ||
| abortManager(); | ||
| }, plan.timeoutMs); |
|
@copilot address review feedback |
Addressed the executor review feedback in commit |
|
| Metric | Base | PR | Delta |
|---|---|---|---|
| Lines | 92.75% | 92.08% | 📉 -0.67% |
| Statements | 91.28% | 90.55% | 📉 -0.73% |
| Functions | 89.37% | 88.88% | 📉 -0.49% |
| Branches | 84.64% | 83.56% | 📉 -1.08% |
📁 Per-file Coverage Changes (6 files)
| File | Lines (Before → After) | Statements (Before → After) |
|---|---|---|
src/cloud-hypervisor/workload-profile.ts |
97.7% → 96.9% (-0.73%) | 97.0% → 96.4% (-0.68%) |
src/enclave/host-executor-server.ts |
90.8% → 90.9% (+0.08%) | 88.7% → 88.8% (+0.10%) |
src/enclave/host-executor-protocol.ts |
97.5% → 97.6% (+0.09%) | 94.7% → 94.8% (+0.17%) |
src/cloud-hypervisor/manager.ts |
85.8% → 85.9% (+0.10%) | 84.2% → 84.3% (+0.11%) |
src/bounded-execution/finite-schema.ts |
52.8% → 53.4% (+0.52%) | 49.3% → 49.8% (+0.46%) |
src/log-directory-setup.ts |
96.8% → 100.0% (+3.18%) | 96.9% → 100.0% (+3.13%) |
✨ New Files (2 files)
src/bounded-execution/schema-hash.ts: 92.3% linessrc/cloud-hypervisor/host-enclave-executor.ts: 55.0% lines
Coverage comparison generated by scripts/ci/compare-coverage.ts
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
✅ Security Guard completed successfully! Security review of PR #9376: No security concerns found. The PR adds protocol version 2 support for host-side Cloud Hypervisor enclave executor with proper input validation and bounded schema parameter size (4096 bytes). No firewall rules weakened, no capabilities added, no egress expansion, no secrets exposure. All changes maintain existing security properties.
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟
|
|
✅ Smoke Claude passed
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
EGRESS_RESULT allow=pass deny=pass
cc
|
|
Smoke Copilot: PASS
|
smoke-copilot-byok Test Results✅ GitHub MCP Test — Connected, merged PRs verified Overall: PASS — Running in direct BYOK mode (COPILOT_PROVIDER_API_KEY)
|
|
OTEL smoke test results:
|
Smoke Test: Claude Engine Validation
Overall result: PASS
|
🏗️ Build Test Suite Results
Overall: 5/8 ecosystems passed — FAIL Failures
|
|
Smoke services: PASS
|
Chroot Version Comparison
Result: FAILED. The Node.js versions differ, so the
|
|
PR titles: ❌
|


Summary
Implements the trusted host-side Cloud Hypervisor enclave executor for static script and agent invocations while keeping user-facing Cloud Hypervisor enclave selection fail-closed.
Validation
npm run build -- --pretty falsenpm run lint -- --quietcd guest/microvm-supervisor && go test ./...Remaining rollout gate
The host executor and broker client are not wired into runtime selection. Cloud Hypervisor enclave configuration therefore still fails closed; this PR does not enable general execution, dynamic repository admission, or durable end-to-end broker reconciliation. Real-KVM integration/security validation remains a rollout requirement.
Fixes #9375