Repository navigation
feat: implement trusted bounded storage for Cloud Hypervisor enclaves - #9441
Conversation
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Documentation PreviewDocumentation has been built for this PR. To view locally:
Built from commit 97c5bb9 |
|
| Metric | Base | PR | Delta |
|---|---|---|---|
| Lines | 92.90% | 92.77% | 📉 -0.13% |
| Statements | 91.37% | 91.19% | 📉 -0.18% |
| Functions | 89.56% | 89.67% | 📈 +0.11% |
| Branches | 85.02% | 84.75% | 📉 -0.27% |
📁 Per-file Coverage Changes (10 files)
| File | Lines (Before → After) | Statements (Before → After) |
|---|---|---|
src/cloud-hypervisor/cleanup-network.ts |
100.0% → 85.5% (-14.55%) | 96.1% → 82.5% (-13.54%) |
src/cloud-hypervisor/cleanup-identity.ts |
98.4% → 90.1% (-8.29%) | 98.5% → 90.5% (-8.01%) |
src/cloud-hypervisor/cleanup-registry.ts |
98.5% → 93.0% (-5.53%) | 98.6% → 91.1% (-7.48%) |
src/enclave/host-executor-journal.ts |
91.4% → 88.7% (-2.76%) | 89.6% → 85.3% (-4.27%) |
src/cloud-hypervisor/virtiofsd.ts |
81.7% → 80.8% (-0.90%) | 80.2% → 79.4% (-0.82%) |
src/cloud-hypervisor/manager.ts |
88.7% → 88.9% (+0.15%) | 87.1% → 87.2% (+0.17%) |
src/cloud-hypervisor/enclave-artifact-preflight.ts |
97.6% → 98.0% (+0.36%) | 96.5% → 97.1% (+0.56%) |
src/enclave/manager.ts |
86.4% → 86.8% (+0.37%) | 85.2% → 85.6% (+0.39%) |
src/cloud-hypervisor/host-enclave-executor.ts |
94.5% → 95.6% (+1.07%) | 89.8% → 91.0% (+1.19%) |
src/log-directory-setup.ts |
96.8% → 100.0% (+3.18%) | 96.9% → 100.0% (+3.13%) |
✨ New Files (2 files)
src/cloud-hypervisor/trusted-enclave-preflight.ts: 94.2% linessrc/cloud-hypervisor/trusted-enclave-storage.ts: 88.2% lines
Coverage comparison generated by scripts/ci/compare-coverage.ts
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The required privileged host-probes have not yet validated these security-sensitive mount and recovery changes on an eligible runner.
Review effort: Balanced
Findings: None
What changed in this PR
Implements production bounded storage for Cloud Hypervisor enclaves while preserving fail-closed admission, artifact integrity, and identity-checked recovery.
Changes:
- Adds role-sized, invocation-wide tmpfs storage with sealed executable artifacts and
noexecwritable state. - Routes preflight, snapshots, rootfs preparation, VM state, and exports through the bounded domain.
- Expands recovery validation, privileged probes, deterministic tests, and architecture documentation.
| File | Description |
|---|---|
src/enclave/manager.ts |
Installs the production provider and isolates storage roots. |
src/enclave/manager.test.ts |
Tests primary-agent storage exposure rejection. |
src/enclave/host-executor-journal.ts |
Journals storage mount and inode identities. |
src/enclave/host-executor-journal.test.ts |
Covers storage cleanup and recovery safeguards. |
src/enclave/cloud-hypervisor-lifecycle.ts |
Moves invocation mount points under trusted storage. |
src/enclave/cloud-hypervisor-lifecycle.test.ts |
Updates lifecycle path expectations. |
src/cloud-hypervisor/virtiofsd.ts |
Adds bounded-storage verification injection. |
src/cloud-hypervisor/trusted-enclave-storage.ts |
Implements the production storage provider. |
src/cloud-hypervisor/trusted-enclave-storage.test.ts |
Tests eligibility, allocation, and sealing. |
src/cloud-hypervisor/trusted-enclave-preflight.ts |
Runs preflight inside temporary bounded domains. |
src/cloud-hypervisor/trusted-enclave-preflight.test.ts |
Tests immutable capture and cleanup behavior. |
src/cloud-hypervisor/manager.ts |
Supports trusted manager dependency overrides. |
src/cloud-hypervisor/manager-types.ts |
Adds invocation-derived run paths. |
src/cloud-hypervisor/manager-stop.ts |
Removes the actual derived run directory. |
src/cloud-hypervisor/manager-construction.test.ts |
Tests dependency resolution isolation. |
src/cloud-hypervisor/manager-cleanup.test.ts |
Tests cleanup of shortened invocation paths. |
src/cloud-hypervisor/host-enclave-executor.ts |
Integrates storage, preflight, and digest checks. |
src/cloud-hypervisor/host-enclave-executor.test.ts |
Adds source-replacement and bounded-preflight coverage. |
src/cloud-hypervisor/enclave-trusted-storage.integration.test.ts |
Adds privileged storage and recovery probes. |
src/cloud-hypervisor/enclave-executor-types.ts |
Defines storage and preflight dependency hooks. |
src/cloud-hypervisor/enclave-artifact-preflight.ts |
Verifies bounded captures of role artifacts. |
src/cloud-hypervisor/cleanup-registry.ts |
Records invocation storage ownership. |
src/cloud-hypervisor/cleanup-network.ts |
Validates storage identity during recovery. |
src/cloud-hypervisor/cleanup-identity.ts |
Validates invocation-owned cleanup paths. |
src/cloud-hypervisor/cleanup-identity.test.ts |
Tests shortened path validation. |
src/cloud-hypervisor/artifact-snapshot.ts |
Supports invocation-local artifact snapshots. |
src/cloud-hypervisor/artifact-snapshot.test.ts |
Tests bounded executable snapshot roots. |
scripts/ci/test-cloud-hypervisor-enclave-workflow.test.ts |
Asserts new suites are included in CI. |
docs/enclaves-architecture.md |
Documents production storage admission. |
docs/cloud-hypervisor-foundation.md |
Documents storage accounting and remaining gates. |
docs/adr/0002-cloud-hypervisor-enclave-executor.md |
Records the bounded-storage design decision. |
.github/workflows/test-cloud-hypervisor-enclaves.yml |
Adds deterministic and privileged storage tests. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
@copilot address this feedback |
Checked the latest run for |
|
Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed.
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅
|
|
✅ Smoke Claude passed
|
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅
|
|
❌ Smoke Gemini reports failed. Facets need polishing...
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
🚀 Security Guard has started processing this pull request |
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
Smoke Test: Claude Engine Validation
Overall result: PASS
|
|
EGRESS_RESULT allow=pass deny=pass
cc
|
|
Smoke Copilot: PASS ✅
|
|
Smoke test: PASS checks 1,3; FAIL checks 2,4 (curl blocked by sandbox permission layer, not measurable as HTTP code).
|
|
Services smoke test:
Overall: PASS
|
Smoke Test: Copilot BYOK (Direct) Mode — PASS ✅
Mode: COPILOT_PROVIDER_API_KEY (direct BYOK)
|
|
OTEL smoke test
|
🏗️ Build Test Suite Results
Overall: 6/8 ecosystems passed — FAIL Failure details
No
|
|
Merged PR review: ❌
|
Chroot version comparison: ❌ failed
Node.js differs between host and chroot, so the
|
Summary
Implement the production
TrustedCloudHypervisorEnclaveStorageProvider, preserving protocol v2, static script/agent roles, artifact attestation, launch confinement, and fail-closed host eligibility.noexec./var/lib/awf-cloud-hypervisor/host-invocations, reject primary-agent exposure of storage/control roots, and preserve mount/device/inode-checked recovery, no-replay tombstones, and ordinary unmounts. Reclaim identity-known partial allocations while retaining uncertain or busy resources; fix teardown of the actual invocation run path.No Docker fallback, capacity increase, identity-validation relaxation, or runner-user KVM access is introduced.
Validation
At
a4e0eec7:Required before merge
Keep this PR draft until the integrated
host-probesjob in.github/workflows/test-cloud-hypervisor-enclaves.ymlpasses on an eligible privileged GitHub-hosted Ubuntu x86_64 KVM/cgroup-v2 runner. These Linux mount/KVM probes could not run in the macOS development checkout; earlier baseline probe results do not validate the final integration.The probes cover aggregate sparse/concurrent ENOSPC, executable/read-only artifacts,
noexecwritable state, partial snapshot-copy recovery, busy close, replaced mount identities, SIGKILL recovery, and no replay. No CI run was triggered by the implementation session, no checks were lowered, and no privileged success is claimed.Addresses #9440. Live release-attested broker-to-VM script/agent acceptance remains a separate gate in #9395; this PR does not claim to complete it.