Repository navigation
fix: retain enclave startup diagnostics and recompile CH smoke with gh-aw v0.91.7 - #9756
Conversation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: c4bfaada-d9ab-469e-8882-b2d2c77da42d
There was a problem hiding this comment.
🟢 Approval recommended
The focused generated changes are internally consistent and preserve the documented workflow constraints.
0 open findings
What changed in this PR
Recompiles the Cloud Hypervisor enclave smoke workflow with gh-aw v0.91.7 while preserving its existing runtime and artifact pins.
Changes:
- Updates compiler and setup-action pins to v0.91.7.
- Adds engine metadata to safe-output reporting.
- Records the new setup-action pin.
| File | Description |
|---|---|
.github/workflows/smoke-enclave-cloud-hypervisor.lock.yml |
Updates generated workflow metadata and reporting. |
.github/aw/actions-lock.json |
Adds the v0.91.7 setup-action pin. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
✅ Coverage Check PassedOverall Coverage
📁 Per-file Coverage Changes (4 files)
✨ New Files (1 files)
Coverage comparison generated by |
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: c4bfaada-d9ab-469e-8882-b2d2c77da42d
|
✅ Copilot review passed with no inline comments. @lpcox Add the |
| base_url="https://storage.googleapis.com/gvisor/releases/release/latest/${arch}" | ||
| curl -fsSL "${base_url}/runsc" -o "${RUNNER_TEMP}/runsc" | ||
| sudo install -m 0755 "${RUNNER_TEMP}/runsc" /usr/local/bin/runsc |
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: c4bfaada-d9ab-469e-8882-b2d2c77da42d
Capture safe server startup evidence before retry teardown and final cleanup. Keep published Cloud Hypervisor smoke pins unchanged and document the release prerequisite for live verification. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: c4bfaada-d9ab-469e-8882-b2d2c77da42d
Documentation PreviewDocumentation has been built for this PR. To view locally:
Built from commit 127855a |
|
@copilot address review feedback |
Removed the postprocessor check-then-read race in commit |
Summary
Recompile only the experimental Cloud Hypervisor enclave smoke with gh-aw v0.91.7, and add AWF-owned startup evidence for the enclave MCP server before cleanup removes it.
--container-runtimeoverride and no gVisor installation. Keep the smoke-only idempotent postprocessor guard and regression coverage.enclaves[].runtime: cloud-hypervisor, preview configuration, real mcpg, manual-only experimental trigger, published AWF v0.28.49, and release-matched attested guest artifacts/images. No unrelated workflows upgraded.enclave-startup/attempt-*/diagnostic.json), including runner-visible ARC/DinD host captures and default-log cleanup preservation.The failure in run 37961903075 remains unexplained: mcpg authentication succeeded, the enclave server disappeared before readiness, and cleanup found exit code 1 without OOM. This change adds missing server evidence; it does not speculate about or fix the crash. mcpg's
mcp-logs/awf-enclave.logis a backend connection log, not server stderr.Deployment prerequisite / live-verification limitation
The smoke still runs published AWF v0.28.49. These source changes are not exercised by that installed binary or its published server image. Live verification requires a release containing the host capture and server diagnostics, followed by a coordinated package/image/Cloud Hypervisor artifact pin update with matching release attestation. This PR intentionally does not switch the release-attested smoke to a local build or mix package/artifact releases. Local source regressions are verified below; release-attested live proof remains pending that release.
Validation
gh aw compile smoke-enclave-cloud-hypervisor --no-check-update,npx --no-install tsx scripts/ci/postprocess-smoke-workflows.ts; compiler validation passed with the expected experimental warning.Latest commit:
3688ced57e627b0c9fb2aa92164cf943e86a4ab9.No workflow dispatch for this diagnostic update. No merge. The unrelated parent-checkout Dockerfile edit was not touched.