Skip to content

test: add Cloud Hypervisor enclave conformance and gated host probes - #9399

Merged
lpcox merged 8 commits into
mainfrom
copilot/awf-add-live-kvm-coverage
Oct 3, 2026
Merged

lpcox merged 8 commits into
mainfrom
copilot/awf-add-live-kvm-coverage

Conversation

Copilot AI commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Delivered scope

Updates the previously empty branch to merged main, including #9397 and #9398, and adds useful conformance coverage without claiming unsupported live execution.

  • Adds a dedicated deterministic enclave CI job covering the authenticated broker/host protocol, both static roles, finite results, settlement, cancellation, recovery, and fail-closed startup.
  • Extends broker tests for oversized/invalid-UTF-8/non-JSON/schema-invalid output; storage rejection, partial startup, guest failure, simulated OOM and timeout; exact snapshot deletion/unmount/invocation deletion before settlement; no automatic replay; and raw-output/error exclusion from audit calls and host journals.
  • Checks that manifest and both rootfs attestation verification calls retain the release signer, repository, bundle, and self-hosted-runner denial constraints.
  • Moves privileged storage and supervisor probes out of ordinary artifact-build CI. A separate host-probe job defaults off and requires explicit dispatch or the cloud-hypervisor-enclave-conformance label, production GitHub-hosted Ubuntu x86_64 eligibility, privileged KVM device access, and cgroup v2. Adds the existing real nftables packet suite, with stronger process/interface/namespace cleanup assertions and busy-storage preservation.
  • Makes Unix-socket fixtures short and canonical without weakening invocation ancestor trust; fixes manager fixture isolation on Linux.
  • Documents delivered evidence versus every still-unverified live criterion. The enclave job uploads no raw guest/repository diagnostics and introduces no artifact verification bypass.

Full live acceptance remains blocked

Related to #9395; this PR does not resolve or close that issue. Neither the existing primary-agent KVM smoke nor these host-only probes prove broker-to-enclave-VM conformance.

The merged storage helper bounds invocation writable exports, but production startup still supplies no TrustedCloudHypervisorEnclaveStorageProvider. Its broader contract also requires artifact/rootfs copies and runtime state to be bounded for the full invocation lifecycle. Investigation of the expanded integration scope found that supplying a provider through simple redirection would not enforce that contract safely:

  1. Executable snapshots are independently allocated under /var/lib/awf-cloud-hypervisor/trusted-artifacts/run-*, while bounded invocation tmpfs is noexec.
  2. Rootfs preparation under <workDir>/cloud-hypervisor-rootfs/<vmRunId> and writable copies/state under independently derived /run/awf-cloud-hypervisor paths are not jointly charged to the invocation capacity.
  3. Snapshot resource journals and VM cleanup validate fixed trusted snapshot roots; moving copies into invocation children alone breaks identity-checked recovery.

A complete integration needs coordinated invocation-owned allocation, executable artifact staging, and durable mount/inode recovery changes. No empty provider, global mount substitution, relaxed path validation, fallback, or unverified-artifact mode is installed here. Public startup remains fail-closed for script-only, agent-only, and combined configurations before seeds, runtime probes, listener, or VM effects.

Mandatory remaining live assertions include successful release-attested script/agent calls through the public broker; real guest identity/limits, read-only seeds, no-NIC and exact-peer/port policies, capability denial and guest-visible ENOSPC; actual VM OOM, timeout/cancellation, partial startup and recovery; and raw repository-output exclusion in real VM diagnostics. See the evidence and blocker matrix.

Local validation

  • Exact deterministic CI selection: 24 suites, 548 tests passed in a network-isolated local Linux ARM64 container with Node 22 and Go 1.25; this is not x86_64 KVM evidence.
  • Changed macOS suites: 216 tests passed; privileged integration suites skipped under their explicit gates.
  • npm run build, npm run type-check, npm run lint, and diff hygiene checks pass. Lint reports warnings but zero errors; commit hooks also pass.
  • Privileged eligible-runner probes and live KVM execution were not run locally.

The PR remains draft and is not merged.

Copilot AI linked an issue Oct 2, 2026 that may be closed by this pull request
Copilot AI changed the title [WIP] Add live KVM conformance coverage for Cloud Hypervisor enclaves [Blocked] Add live KVM conformance coverage for Cloud Hypervisor enclaves Oct 2, 2026
Copilot AI requested a review from lpcox October 2, 2026 23:08
lpcox and others added 2 commits October 2, 2026 20:08
Preserve the public full-storage admission gate and document remaining allocation/recovery gaps.
Bounded exports alone do not support safe end-to-end KVM conformance.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@lpcox lpcox changed the title [Blocked] Add live KVM conformance coverage for Cloud Hypervisor enclaves Add Cloud Hypervisor enclave conformance and gated host probes Oct 3, 2026
@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Documentation Preview

Documentation has been built for this PR.

Download preview artifact

To view locally:

  1. Download the docs-preview-pr-9399 artifact from the workflow run
  2. Unzip and open index.html in your browser

Built from commit cdec5b1

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ Coverage Check Passed

Overall Coverage

Metric Base PR Delta
Lines 92.65% 92.91% 📈 +0.26%
Statements 91.13% 91.38% 📈 +0.25%
Functions 89.28% 89.55% 📈 +0.27%
Branches 84.87% 85.03% 📈 +0.16%
📁 Per-file Coverage Changes (6 files)
File Lines (Before → After) Statements (Before → After)
src/nvx/one-shot-adapter.ts 83.5% → 82.9% (-0.60%) 80.3% → 79.8% (-0.56%)
src/enclave/cloud-hypervisor-lifecycle.ts 92.9% → 94.7% (+1.77%) 90.8% → 92.3% (+1.54%)
src/enclave/paths.ts 97.2% → 100.0% (+2.78%) 97.2% → 100.0% (+2.78%)
src/log-directory-setup.ts 96.8% → 100.0% (+3.18%) 96.9% → 100.0% (+3.13%)
src/bounded-execution/repository-staging.ts 80.0% → 100.0% (+20.00%) 80.0% → 100.0% (+20.00%)
src/enclave/manager.ts 59.3% → 86.4% (+27.12%) 57.9% → 85.2% (+27.32%)

Coverage comparison generated by scripts/ci/compare-coverage.ts

@lpcox
lpcox marked this pull request as ready for review October 3, 2026 03:43
Copilot AI balanced review requested due to automatic review settings October 3, 2026 03:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Security-relevant diagnostic and attestation tests do not fully enforce the contracts they claim to cover.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Adds deterministic Cloud Hypervisor enclave conformance coverage and explicitly gated privileged host probes without claiming live broker-to-VM acceptance.

Changes:

  • Adds broker, lifecycle, attestation, and fail-closed conformance tests.
  • Introduces a gated workflow for privileged storage, network, and supervisor probes.
  • Documents verified evidence and remaining live-KVM blockers.
File Description
src/​enclave/​manager.test.ts Expands fail-closed role coverage and isolates fixtures.
src/​enclave/​host-executor-protocol.test.ts Shortens Unix-socket fixture paths.
src/​enclave/​host-executor-broker.test.ts Adds failure, cleanup-order, and diagnostic-disclosure tests.
src/​cloud-hypervisor/​host-enclave-executor.test.ts Verifies attestation command constraints.
src/​cloud-hypervisor/​enclave-storage.integration.test.ts Asserts no mounted-storage residue.
src/​cloud-hypervisor/​enclave-network.integration.test.ts Strengthens process and network cleanup checks.
scripts/​ci/​test-cloud-hypervisor-enclave-workflow.test.ts Validates workflow gates and security boundaries.
docs/​INTEGRATION-TESTS.md Describes conformance coverage and limitations.
docs/​cloud-hypervisor-foundation.md Adds the evidence and remaining-live-gate matrix.
.github/​workflows/​test-cloud-hypervisor.yml Removes privileged enclave probes from artifact CI.
.github/​workflows/​test-cloud-hypervisor-enclaves.yml Adds deterministic and opt-in privileged jobs.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/cloud-hypervisor/host-enclave-executor.test.ts
Comment thread src/enclave/host-executor-broker.test.ts
@lpcox

lpcox commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator

@copilot Fix the code for all comments in this review thread.

When a review comment includes a suggested change, apply the suggestion exactly.

Do not make changes beyond what is described in the linked review thread.

Copilot AI commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

@copilot Fix the code for all comments in this review thread.

When a review comment includes a suggested change, app...

Addressed both review findings in 219b004.

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ Copilot review passed with no inline comments.

@copilot Add the ready-for-aw label to this PR to trigger agentic CI smoke tests.

@lpcox

lpcox commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator

Copilot AI commented Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

@copilot fix this failing ci check https://github.com/github/gh-aw-firewall/actions/runs/37095072644/job/111231703296?pr=9399

I investigated both failed audit jobs. The root audit is blocked by braces ≤3.0.3; the docs audit is blocked by Astro’s http-cache-semantics ≤4.2.0 dependency. Neither has a published patched release, and the failures are unrelated to this PR’s changes. I did not weaken the audit gate or pin nonexistent versions, so there is no code change to commit; the check will need an upstream fix or an explicitly approved temporary exception.

@lpcox

lpcox commented Oct 3, 2026

Copy link
Copy Markdown
Collaborator

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✅ Security Guard completed successfully!

Security review complete: PR #9399 contains Docker build resilience improvements only. The sole security-relevant file changed (containers/agent/Dockerfile) adds apt package installation retry logic with mirror fallback. This is a build-time only change that does not affect the agent's runtime security posture, firewall rules, iptables configuration, capabilities, seccomp policies, domain allowlists, or egress controls. No security weakening detected.

Generated by Security Guard for #9399

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅

🛡️ Egress verdict from Smoke Copilot Network Isolation

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...

🔑 BYOK (AOAI api-key) report filed by Smoke Copilot BYOK AOAI (api-key)

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed.

Cloud Hypervisor + Copilot smoke test by Smoke Cloud Hypervisor

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟

🔮 The oracle has spoken through Smoke Codex

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Smoke Test: Copilot BYOK (Direct) Mode

✅ MCP connectivity: github-list_pull_requests verified
✅ GitHub.com connectivity: HTTP 200
✅ File write/read test: smoke test marker file confirmed
✅ BYOK inference: Direct mode active (agent → api-proxy → api.githubcopilot.com)

Status: PASS — Running in direct BYOK mode via COPILOT_PROVIDER_API_KEY

🔑 BYOK report filed by Smoke Copilot BYOK
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Smoke Test: Claude Engine Validation

  • API status: ✅ PASS
  • GitHub check: ✅ PASS
  • File status: ✅ PASS

Overall result: PASS

Generated by Smoke Claude for #9399 · claude · haiku45 · 49.9 AIC · ⊞ 6.2K · ◷
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Smoke test summary: 1) list merged PRs SKIP - no direct tool call available in session; 2) curl github.com FAIL - bash denied curl outright (not AWF 000/403); 3) write/read tmp file PASS; 4) curl example.com FAIL - bash denied curl outright. Overall: incomplete, label not applied.

Cloud Hypervisor + Copilot smoke test by Smoke Cloud Hypervisor
Add label ready-for-aw to run again

@lpcox
lpcox deployed to aoai-model October 3, 2026 17:23 — with GitHub Actions Active
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

OTEL smoke test

  • ✅ 1 Module loading: otel.js exports startRequestSpan, setTokenAttributes, setBudgetAttributes, endSpan, endSpanError, shutdown, isEnabled
  • ✅ 2 Tests: 3 suites, 68/68 passed
  • ✅ 3 Env forwarding: trace/parent span IDs in env-passthrough.ts; OTEL vars in api-proxy-env-config.ts
  • ✅ 4 Token tracker: onUsage callback present in token-tracker-http.js
  • ✅ 5 Diagnostics: otel.jsonl present (1 line recorded)

📡 OTel tracing validated by Smoke OTel Tracing
Add label ready-for-aw to run again

@github-actions github-actions Bot added the smoke-copilot-network-isolation Copilot network-isolation egress smoke test label Oct 3, 2026
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

EGRESS_RESULT allow=pass deny=pass

  • ✅ Allowed: api.github.com returned HTTP 403 (curl exit 0; reachable)
  • ✅ Blocked: example.com failed (SSL self-signed cert error, i.e. intercepted/denied)

Overall: PASS. cc @lpcox

🛡️ Egress verdict from Smoke Copilot Network Isolation
Add label ready-for-aw to run again

@lpcox
lpcox deployed to aoai-model October 3, 2026 17:23 — with GitHub Actions Active
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Smoke Copilot: PASS

  • ✅ GitHub MCP: "[WIP] Fix Squid crashes with assertion failure in Claude inference"
  • ✅ github.com HTTP 200
  • ✅ File write/read
    Author: @Copilot · Assignees: @lpcox @Copilot

📰 BREAKING: Report filed by Smoke Copilot
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Services smoke test: PASS

  • Redis PING: ✅
  • pg_isready: ✅
  • PostgreSQL SELECT 1: ✅

🔌 Service connectivity validated by Smoke Services
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Chroot Version Comparison

Runtime Host Version Chroot Version Match?
Python Python 3.12.14 Python 3.12.14 ✅ YES
Node.js v24.21.0 v22.23.2 ❌ NO
Go go1.22.12 go1.22.12 ✅ YES

Node.js versions differ, so the tests did not all pass and the smoke-chroot label was not added.

Tested by Smoke Chroot
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

🏗️ Build Test Suite Results

Ecosystem Project Build/Install Tests Status
Bun elysia ❌ not run ❌ FAIL
Bun hono ❌ not run ❌ FAIL
C++ fmt ✅ N/A ✅ PASS
C++ json ✅ N/A ✅ PASS
Deno oak ❌ not run ❌ FAIL
Deno std ❌ not run ❌ FAIL
.NET hello-world ✅ N/A ✅ PASS
.NET json-parse ✅ N/A ✅ PASS
Go color ✅ all passed ✅ PASS
Go env ✅ all passed ✅ PASS
Go uuid ✅ all passed ✅ PASS
Java gson ❌ not run ❌ FAIL
Java caffeine ❌ not run ❌ FAIL
Node.js clsx ✅ passed ✅ PASS
Node.js execa ✅ passed ✅ PASS
Node.js p-limit ✅ passed ✅ PASS
Rust fd ✅ 1/1 passed ✅ PASS
Rust zoxide ✅ 1/1 passed ✅ PASS

Overall: 5/8 ecosystems passed — FAIL

Failures:

  • Bun / Deno: install scripts (bun.sh, deno.land) could not run — "Permission denied and could not request permission from user"; bun/deno are not on PATH.
  • Java: Maven failed with LocalRepositoryNotAccessibleException (cannot access the local ~/.m2 repository in this sandbox).

Generated by Build Test Suite for #9399 · copilot · auto · 24.6 AIC · ⊞ 11.8K · ◷
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Smoke Test

  • Merged PR review: ❌
  • PR detail fetch: ❌
  • Playwright title check: ❌
  • File write/read: ✅
  • AWF build: ❌
  • Overall: FAIL

🔮 The oracle has spoken through Smoke Codex
Add label ready-for-aw to run again

@lpcox
lpcox enabled auto-merge (squash) October 3, 2026 17:28
@lpcox
lpcox merged commit 212bb74 into main Oct 3, 2026
141 of 145 checks passed
@lpcox
lpcox deleted the copilot/awf-add-live-kvm-coverage branch October 3, 2026 17:32

This branch was successfully deployed

1 active deployment
aoai-model — 670c10c9 Deployed Oct 3, 2026 by lpcox via conclusion #1864
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[awf] Add live KVM conformance coverage for Cloud Hypervisor enclaves

3 participants