Skip to content

feat: compose gated unified Cloud Hypervisor lifecycle - #9776

Merged
lpcox merged 3 commits into
mainfrom
lpcox-unified-cloud-hypervisor-lifecycle
Oct 10, 2026
Merged

lpcox merged 3 commits into
mainfrom
lpcox-unified-cloud-hypervisor-lifecycle

Conversation

@lpcox

@lpcox lpcox commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

Summary

Next AWF-only slice of ADR 0004, following #9771. Reuses the existing primary CloudHypervisorManager/runtime boot loop and authenticated host enclave executor/broker/storage lifecycle. The primary has its own VM; enclave invocations continue to use fresh, separately isolated VMs. Supporting Squid/API proxies and compiler-owned mcpg remain Docker infrastructure.

  • Require the owning host-enclave lifecycle before infrastructure startup, require completion of the existing mcpg readiness callback before primary VM creation, and recheck admissions after asynchronous setup and before primary execution.
  • Check actual virtio-fs export sources (including read-only runner-temp/tool-cache exports and symlink aliases) against seeds, broker/capability state, invocation storage, allocation domains, and recovery roots.
  • Close admissions before primary cancellation, drain invocation VMs even when primary teardown fails, reject cross-configuration shutdown ownership, and preserve infrastructure/private recovery state on uncertain VM cleanup. Preserve-mode still drains enclave invocations.
  • Keep standalone unsupported-host fallback, forbid cross-backend fallback for enclave-enabled runs, avoid treating primary CH as an OCI runtime, and report CH accurately in broker metadata.
  • Add focused internal-composition, cancellation/ownership, export-isolation, supporting-Compose and compatibility regressions; document what is wired and what remains gated.

Gates and precise remaining contracts

Production CH-primary-with-enclave execution remains rejected by both existing public validation paths. No new config/env bypass, launcher replacement, experimental production enablement, workflow dispatch, merge, or retag is included. NVX and dynamic repository admission are out of scope. This work is separate from #9756 and makes no inferred permissions fix for the earlier broker readiness failure.

The internal integration tests use mocked VM/host-service boundaries and a readiness callback; they are not real KVM or real mcpg acceptance. Subsequent acceptance must use compiler-owned real mcpg, first CH primary + static script, then CH primary + static agent with the dedicated model proxy. It must demonstrate guest public-gateway routing and denial of seeds/broker credentials/private storage/recovery state (including submount/alias/race cases), independent fresh invocation VMs, credential custody, bounded resources/results, cancellation/drain, uncertain cleanup preservation, and orphan recovery. Path-overlap checks alone are not proof of live virtio-fs confinement.

Static agent GitHub tools remain explicitly blocked on a compiler-scoped executor bearer handoff: the current static identity alone is insufficient. This PR does not substitute a gateway-wide key or broaden privileges. Agent acceptance without GitHub tools does not satisfy that separate gate.

Validation

  • npm run build and npm run type-check passed.
  • Focused regression run: 21 suites / 657 tests passed, covering primary runtime, host executor/protocol/broker, host lifecycle/storage cleanup, gateway contracts, mount policy, Compose services, CLI workflow/cleanup, fallback, and guest environment exclusions.
  • Lifecycle/primary runtime run with --detectOpenHandles: 2 suites / 49 tests passed.
  • Changed-file ESLint, related Markdown lint, and git diff --check passed. Full pre-commit lint/build hooks passed (existing lint warnings remain).
  • No live Actions dispatch or Linux/KVM end-to-end run was performed from this macOS worktree.

Commit: 34052180bc7a99c5a79fbabad7282c3be3be91b0. Parent checkout and its local changes were left untouched.

Require authenticated host-enclave readiness and compiler gateway callback completion
before primary VM creation. Check actual guest exports, enforce lifecycle ownership,
and preserve infrastructure on uncertain teardown. Retain production execution gates
pending real end-to-end acceptance.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a75ff200-52e9-49aa-8f67-34bfa5199399
Copilot AI balanced review requested due to automatic review settings October 9, 2026 20:56
@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Documentation Preview

Documentation has been built for this PR.

Download preview artifact

To view locally:

  1. Download the docs-preview-pr-9776 artifact from the workflow run
  2. Unzip and open index.html in your browser

Built from commit 8d3d688

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

A diagnostics failure can bypass primary VM teardown and leave the runtime running.

1 open finding
What changed in this PR

Composes the gated unified Cloud Hypervisor primary/enclave lifecycle while retaining production validation gates.

Changes:

  • Adds lifecycle readiness, ownership, cancellation, and cleanup coordination.
  • Validates primary virtio-fs exports against enclave-private state.
  • Expands regression coverage and documents remaining acceptance gates.
File Description
src/​services/​enclave-mcp-service.test.ts Tests CH-only supporting Compose services.
src/​enclave/​runtime-preflight.ts Recognizes CH as a primary backend.
src/​enclave/​runtime-preflight.test.ts Tests CH backend normalization.
src/​enclave/​preflight.ts Separates structural and production validation.
src/​enclave/​mount-policy.ts Checks CH exports against private roots.
src/​enclave/​mount-policy.test.ts Tests export overlap and aliases.
src/​enclave/​manager.ts Excludes CH from OCI runtime probing.
src/​enclave/​cloud-hypervisor-lifecycle.ts Adds backend and shutdown ownership checks.
src/​enclave/​cloud-hypervisor-lifecycle.test.ts Tests ownership and backend consistency.
src/​commands/​main-action.ts Adjusts fallback and cleanup preservation.
src/​commands/​main-action.test.ts Tests unified cleanup and fallback behavior.
src/​cloud-hypervisor/​unified-lifecycle.test.ts Tests internal lifecycle composition.
src/​cloud-hypervisor/​runtime-validation.ts Updates the production gate rationale.
src/​cloud-hypervisor/​runtime-validation.test.ts Updates gate assertions.
src/​cloud-hypervisor/​runtime-boot-loop.ts Adds readiness and export-isolation gates.
src/​cloud-hypervisor/​runtime-backend.ts Coordinates execution and teardown lifecycle.
src/​cloud-hypervisor-runtime-backend.test.ts Tests coordinated stop and preserve behavior.
src/​cloud-hypervisor-runtime-backend.env-mapping.test.ts Updates compatibility assertions.
docs/​cloud-hypervisor-foundation.md Documents the gated integration.
docs/​adr/​0004-unified-workload-sandbox-backends.md Records lifecycle design and acceptance requirements.
docs/​adr/​0002-cloud-hypervisor-enclave-executor.md Cross-references unified orchestration constraints.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +326 to +328
config.containerRuntime === 'cloud-hypervisor' && config.enclaves?.enabled
? 'Unified Cloud Hypervisor cleanup failed; infrastructure and recovery state must be preserved.'
: 'External runtime cleanup failed; continuing with infrastructure teardown.',
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

✅ Coverage Check Passed

Overall Coverage

Metric Base PR Delta
Lines 93.08% 93.11% 📈 +0.03%
Statements 91.61% 91.65% 📈 +0.04%
Functions 90.32% 90.33% 📈 +0.01%
Branches 85.35% 85.41% 📈 +0.06%
📁 Per-file Coverage Changes (10 files)
File Lines (Before → After) Statements (Before → After)
src/enclave/manager.ts 87.2% → 86.8% (-0.35%) 86.5% → 86.1% (-0.32%)
src/commands/main-action.ts 94.7% → 94.7% (+0.03%) 94.5% → 94.5% (+0.04%)
src/enclave/preflight.ts 92.0% → 92.1% (+0.10%) 92.4% → 92.5% (+0.09%)
src/cloud-hypervisor/runtime-backend.ts 96.3% → 96.5% (+0.20%) 91.5% → 93.2% (+1.65%)
src/enclave/cloud-hypervisor-lifecycle.ts 93.7% → 93.9% (+0.23%) 91.6% → 92.6% (+0.96%)
src/nvx/one-shot-adapter.ts 81.7% → 82.3% (+0.56%) 79.1% → 79.6% (+0.52%)
src/cloud-hypervisor/runtime-boot-loop.ts 96.5% → 97.2% (+0.64%) 96.6% → 95.5% (-1.10%)
src/enclave/mount-policy.ts 94.6% → 95.2% (+0.64%) 93.4% → 94.3% (+0.89%)
src/enclave/runtime-preflight.ts 70.0% → 70.7% (+0.73%) 71.4% → 72.7% (+1.30%)
src/log-directory-setup.ts 96.8% → 100.0% (+3.18%) 96.9% → 100.0% (+3.13%)

Coverage comparison generated by scripts/ci/compare-coverage.ts

lpcox added 2 commits October 9, 2026 22:35
Configure ephemeral Linux CI daemons with the verified Docker Hub cache.
Prepare pinned scanners once and use digest-identical Anchore GHCR distributions
for Grype and Grant without changing scan targets or failure thresholds.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: a75ff200-52e9-49aa-8f67-34bfa5199399
Preserve the v0.91.7 compiler upgrade alongside the CI registry retrieval fix.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: a75ff200-52e9-49aa-8f67-34bfa5199399
@github-actions

Copy link
Copy Markdown
Contributor

✅ Copilot review passed with no inline comments.

@lpcox Add the ready-for-aw label to this PR to trigger agentic CI smoke tests.

@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.

Tested by Smoke Chroot

@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤

📰 BREAKING: Report filed by Smoke Copilot

@github-actions

Copy link
Copy Markdown
Contributor

🔑 Smoke Copilot BYOK AOAI (api-key) is testing Azure OpenAI BYOK (api-key) mode on this pull request...

@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

✅ Build Test Suite completed successfully!

Generated by Build Test Suite for #9776

@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅

🛡️ Egress verdict from Smoke Copilot Network Isolation

@github-actions

Copy link
Copy Markdown
Contributor

🚀 Security Guard has started processing this pull request

@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓

🔑 BYOK report filed by Smoke Copilot BYOK

@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed.

Cloud Hypervisor + Copilot smoke test by Smoke Cloud Hypervisor

@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

✅ Smoke Claude passed

Generated by Smoke Claude for #9776

@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅

📡 OTel tracing validated by Smoke OTel Tracing

@github-actions

Copy link
Copy Markdown
Contributor

🔮 The ancient spirits stir... Smoke Codex awakens to divine this pull request...

@github-actions

Copy link
Copy Markdown
Contributor

🪪 Smoke Copilot BYOK AOAI (Entra) is testing Azure OpenAI BYOK (Entra / GitHub OIDC) mode on this pull request...

@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

🔌 Smoke Services — All services reachable! ✅

🔌 Service connectivity validated by Smoke Services

@github-actions

Copy link
Copy Markdown
Contributor

💎 Smoke Gemini is crystallizing results on this pull request...

@lpcox
lpcox enabled auto-merge (squash) October 10, 2026 20:29
@github-actions

Copy link
Copy Markdown
Contributor

Smoke Claude Results

  • API status: ✅ PASS
  • gh check: ✅ PASS
  • File status: ✅ PASS

Overall result: PASS

Generated by Smoke Claude for #9776 · claude · haiku45 · 45.3 AIC · ⊞ 6.1K · ◷
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test: Cloud Hypervisor + Copilot

  1. List merged PRs (github MCP): PASS — returned PR Adopt declarative NVX runtime in smoke workflows #9752
  2. curl https://github.com/: PASS — HTTP 200
  3. Write/read /tmp/gh-aw/agent/smoke-cloud-hypervisor-*.txt: PASS — content round-tripped correctly
  4. curl (example.com/redacted) (should be blocked): PASS — returned 000 (blocked by AWF firewall)

Overall: PASS — all 4 checks succeeded.

Cloud Hypervisor + Copilot smoke test by Smoke Cloud Hypervisor
Add label ready-for-aw to run again

@lpcox
lpcox deployed to aoai-model October 10, 2026 20:33 — with GitHub Actions Active
@github-actions

Copy link
Copy Markdown
Contributor

Smoke Copilot — PASS

  • ✅ GitHub MCP: "feat: enforce one workload sandbox backend per run"
  • ✅ github.com HTTP 200
  • ✅ File write/read
    cc @lpcox

📰 BREAKING: Report filed by Smoke Copilot
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

🏗️ Build Test Suite Results

Ecosystem Project Build/Install Tests Status
Bun elysia ❌ (install blocked) not run ❌ FAIL
Bun hono ❌ (install blocked) not run ❌ FAIL
C++ fmt ✅ N/A ✅ PASS
C++ json ✅ N/A ✅ PASS
Deno oak ❌ (install blocked) not run ❌ FAIL
Deno std ❌ (install blocked) not run ❌ FAIL
.NET hello-world ✅ N/A ✅ PASS
.NET json-parse ✅ N/A ✅ PASS
Go color ✅ 1 pkg ok ✅ PASS
Go env ✅ 1 pkg ok ✅ PASS
Go uuid ✅ 1 pkg ok ✅ PASS
Java gson ❌ not run ❌ FAIL
Java caffeine ❌ not run ❌ FAIL
Node.js clsx ✅ passed ✅ PASS
Node.js execa ✅ passed ✅ PASS
Node.js p-limit ✅ passed ✅ PASS
Rust fd ✅ 1/1 passed ✅ PASS
Rust zoxide ✅ 1/1 passed ✅ PASS

Overall: 5/8 ecosystems passed — FAIL

Failures

  • Bun / Deno: the curl | bash / curl | sh installer commands were denied by the sandbox permission policy, so the tools were never installed. I did not work around this.
  • Java: Maven failed with Could not create local repository at /home/runner/.m2/repository (LocalRepositoryNotAccessibleException). The ~/.m2/settings.xml proxy file was present, but the repository dir is not writable in this environment. I did not work around this either.

All 8 repos cloned successfully. The build-test label was not added because of the failures.

Generated by Build Test Suite for #9776 · copilot · auto · 21.3 AIC · ⊞ 11.9K · ◷
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Services smoke test: PASS

  • ✅ Redis PING → PONG
  • ✅ pg_isready → accepting connections
  • ✅ psql SELECT 1 → 1

🔌 Service connectivity validated by Smoke Services
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke OTEL tracing:

  • ✅ S1 otel.js loads and exports functions
  • ✅ S2 OTEL tests: 3 suites, 68 passed
  • ✅ S3 env forwarding: trace context in env-passthrough.ts; OTEL vars in api-proxy-env-config.ts
  • ✅ S4 onUsage hook present in token-tracker-http.js
  • ✅ S5 /tmp/gh-aw/otel.jsonl exists (1 line)

📡 OTel tracing validated by Smoke OTel Tracing
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Smoke Test: Copilot BYOK (Direct) Mode ✅ PASS

Test Results:

  • ✅ GitHub MCP connectivity
  • ✅ GitHub.com HTTP 200
  • ✅ File write/read test
  • ✅ BYOK inference via api-proxy → api.githubcopilot.com

Running in direct BYOK mode (COPILOT_PROVIDER_API_KEY) with placeholder credential in agent, real key held by sidecar.

/cc @lpcox

🔑 BYOK report filed by Smoke Copilot BYOK
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

Chroot version comparison

Runtime Host Version Chroot Version Match?
Python Python 3.12.15 Python 3.12.15 ✅
Node.js v24.21.0 v22.23.2 ❌
Go go1.22.12 go1.22.12 ✅

Node.js differs between host and chroot, so the tests did not all pass. I did not add the smoke-chroot label.

Tested by Smoke Chroot
Add label ready-for-aw to run again

@github-actions

Copy link
Copy Markdown
Contributor

EGRESS_RESULT allow=pass deny=pass

  • ✅ Allowed domain (api.github.com): HTTP 200
  • ✅ Blocked domain (example.com): blocked
  • Overall: PASS

cc @lpcox

🛡️ Egress verdict from Smoke Copilot Network Isolation
Add label ready-for-aw to run again

This branch had an error being deployed

1 failed deployment
aoai-model — 24eb09fd Deployed Oct 10, 2026 by lpcox via conclusion #1925
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants