test: add Cloud Hypervisor enclave conformance and gated host probes - #9399
Conversation
Preserve the public full-storage admission gate and document remaining allocation/recovery gaps. Bounded exports alone do not support safe end-to-end KVM conformance. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Documentation PreviewDocumentation has been built for this PR. To view locally:
Built from commit cdec5b1 |
✅ Coverage Check PassedOverall Coverage
📁 Per-file Coverage Changes (6 files)
Coverage comparison generated by |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Security-relevant diagnostic and attestation tests do not fully enforce the contracts they claim to cover.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Adds deterministic Cloud Hypervisor enclave conformance coverage and explicitly gated privileged host probes without claiming live broker-to-VM acceptance.
Changes:
- Adds broker, lifecycle, attestation, and fail-closed conformance tests.
- Introduces a gated workflow for privileged storage, network, and supervisor probes.
- Documents verified evidence and remaining live-KVM blockers.
| File | Description |
|---|---|
src/enclave/manager.test.ts |
Expands fail-closed role coverage and isolates fixtures. |
src/enclave/host-executor-protocol.test.ts |
Shortens Unix-socket fixture paths. |
src/enclave/host-executor-broker.test.ts |
Adds failure, cleanup-order, and diagnostic-disclosure tests. |
src/cloud-hypervisor/host-enclave-executor.test.ts |
Verifies attestation command constraints. |
src/cloud-hypervisor/enclave-storage.integration.test.ts |
Asserts no mounted-storage residue. |
src/cloud-hypervisor/enclave-network.integration.test.ts |
Strengthens process and network cleanup checks. |
scripts/ci/test-cloud-hypervisor-enclave-workflow.test.ts |
Validates workflow gates and security boundaries. |
docs/INTEGRATION-TESTS.md |
Describes conformance coverage and limitations. |
docs/cloud-hypervisor-foundation.md |
Adds the evidence and remaining-live-gate matrix. |
.github/workflows/test-cloud-hypervisor.yml |
Removes privileged enclave probes from artifact CI. |
.github/workflows/test-cloud-hypervisor-enclaves.yml |
Adds deterministic and opt-in privileged jobs. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
@copilot Fix the code for all comments in this review thread. When a review comment includes a suggested change, apply the suggestion exactly. Do not make changes beyond what is described in the linked review thread. |
Addressed both review findings in 219b004. |
|
✅ Copilot review passed with no inline comments. @copilot Add the |
|
@copilot fix this failing ci check https://github.com/github/gh-aw-firewall/actions/runs/37095072644/job/111231703296?pr=9399 |
I investigated both failed audit jobs. The root audit is blocked by |
|
@copilot fix this failing ci check https://github.com/github/gh-aw-firewall/actions/runs/37095072591/job/111231702782?pr=9399 |
|
✅ Security Guard completed successfully! Security review complete: PR #9399 contains Docker build resilience improvements only. The sole security-relevant file changed (containers/agent/Dockerfile) adds apt package installation retry logic with mirror fallback. This is a build-time only change that does not affect the agent's runtime security posture, firewall rules, iptables configuration, capabilities, seccomp policies, domain allowlists, or egress controls. No security weakening detected.
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅
|
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed.
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟
|
Smoke Test: Copilot BYOK (Direct) Mode✅ MCP connectivity: github-list_pull_requests verified Status: PASS — Running in direct BYOK mode via
|
Smoke Test: Claude Engine Validation
Overall result: PASS
|
|
Smoke test summary: 1) list merged PRs SKIP - no direct tool call available in session; 2) curl github.com FAIL - bash denied curl outright (not AWF 000/403); 3) write/read tmp file PASS; 4) curl example.com FAIL - bash denied curl outright. Overall: incomplete, label not applied.
|
|
OTEL smoke test
|
|
EGRESS_RESULT allow=pass deny=pass
Overall: PASS. cc
|
|
Smoke Copilot: PASS
|
|
Services smoke test: PASS
|
Chroot Version Comparison
Node.js versions differ, so the tests did not all pass and the
|
🏗️ Build Test Suite Results
Overall: 5/8 ecosystems passed — FAIL Failures:
|
Smoke Test
|

Delivered scope
Updates the previously empty branch to merged main, including #9397 and #9398, and adds useful conformance coverage without claiming unsupported live execution.
cloud-hypervisor-enclave-conformancelabel, production GitHub-hosted Ubuntu x86_64 eligibility, privileged KVM device access, and cgroup v2. Adds the existing real nftables packet suite, with stronger process/interface/namespace cleanup assertions and busy-storage preservation.Full live acceptance remains blocked
Related to #9395; this PR does not resolve or close that issue. Neither the existing primary-agent KVM smoke nor these host-only probes prove broker-to-enclave-VM conformance.
The merged storage helper bounds invocation writable exports, but production startup still supplies no
TrustedCloudHypervisorEnclaveStorageProvider. Its broader contract also requires artifact/rootfs copies and runtime state to be bounded for the full invocation lifecycle. Investigation of the expanded integration scope found that supplying a provider through simple redirection would not enforce that contract safely:/var/lib/awf-cloud-hypervisor/trusted-artifacts/run-*, while bounded invocation tmpfs isnoexec.<workDir>/cloud-hypervisor-rootfs/<vmRunId>and writable copies/state under independently derived/run/awf-cloud-hypervisorpaths are not jointly charged to the invocation capacity.A complete integration needs coordinated invocation-owned allocation, executable artifact staging, and durable mount/inode recovery changes. No empty provider, global mount substitution, relaxed path validation, fallback, or unverified-artifact mode is installed here. Public startup remains fail-closed for script-only, agent-only, and combined configurations before seeds, runtime probes, listener, or VM effects.
Mandatory remaining live assertions include successful release-attested script/agent calls through the public broker; real guest identity/limits, read-only seeds, no-NIC and exact-peer/port policies, capability denial and guest-visible ENOSPC; actual VM OOM, timeout/cancellation, partial startup and recovery; and raw repository-output exclusion in real VM diagnostics. See the evidence and blocker matrix.
Local validation
npm run build,npm run type-check,npm run lint, and diff hygiene checks pass. Lint reports warnings but zero errors; commit hooks also pass.The PR remains draft and is not merged.