Skip to content

fix: retain enclave startup diagnostics and recompile CH smoke with gh-aw v0.91.7 - #9756

Merged
lpcox merged 5 commits into
mainfrom
lpcox-enclave-compiler-v0-91-7
Oct 9, 2026
Merged

lpcox merged 5 commits into
mainfrom
lpcox-enclave-compiler-v0-91-7

Conversation

@lpcox

@lpcox lpcox commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Recompile only the experimental Cloud Hypervisor enclave smoke with gh-aw v0.91.7, and add AWF-owned startup evidence for the enclave MCP server before cleanup removes it.

  • Keep the primary runtime unset in source and generated AWF config: default Docker/runc, no --container-runtime override and no gVisor installation. Keep the smoke-only idempotent postprocessor guard and regression coverage.
  • Preserve explicit enclaves[].runtime: cloud-hypervisor, preview configuration, real mcpg, manual-only experimental trigger, published AWF v0.28.49, and release-matched attested guest artifacts/images. No unrelated workflows upgraded.
  • Capture the MCP server on failed infrastructure/readiness/attachment attempts before internal retry teardown, and again on failed graceful shutdown before final container removal. Retain up to eight separate snapshots under the existing firewall log tree (enclave-startup/attempt-*/diagnostic.json), including runner-visible ARC/DinD host captures and default-log cleanup preservation.
  • Capture only allowlisted status/running/exit/OOM/error-presence fields and sanitized startup classifications. Each Docker inspect/log command has a five-second timeout and 16-KiB output bound; logs are limited to the last 50 lines. New server images emit closed-set startup stage/error codes and up to eight fixed AWF module/line/column frames. Host capture validates these fields independently; older images/module-load failures yield coarse classifications.
  • Never persist or echo raw log messages/stacks, environment, headers, capabilities, repository seed data or arbitrary paths. Suppress raw enclave log dumping and arbitrary Docker shutdown state-error text. Capture failures are visible and do not mask the original startup failure; earlier attempts are not overwritten.

The failure in run 37961903075 remains unexplained: mcpg authentication succeeded, the enclave server disappeared before readiness, and cleanup found exit code 1 without OOM. This change adds missing server evidence; it does not speculate about or fix the crash. mcpg's mcp-logs/awf-enclave.log is a backend connection log, not server stderr.

Deployment prerequisite / live-verification limitation

The smoke still runs published AWF v0.28.49. These source changes are not exercised by that installed binary or its published server image. Live verification requires a release containing the host capture and server diagnostics, followed by a coordinated package/image/Cloud Hypervisor artifact pin update with matching release attestation. This PR intentionally does not switch the release-attested smoke to a local build or mix package/artifact releases. Local source regressions are verified below; release-attested live proof remains pending that release.

Validation

  • Initial targeted compilation and required postprocessing: gh aw compile smoke-enclave-cloud-hypervisor --no-check-update, npx --no-install tsx scripts/ci/postprocess-smoke-workflows.ts; compiler validation passed with the expected experimental warning.
  • Latest diagnostic changes: build, TypeScript check, changed-file ESLint (no errors), JavaScript syntax checks, and diff whitespace check passed.
  • Startup diagnostic/lifecycle/gateway/server/cleanup/artifact regression suites: 259 tests passed, covering capture before retry/removal, retained attempts, normal/non-enclave startup, origin diagnostics, bounded/allowlisted output, secret exclusion, unavailable capture, retention errors, ARC/DinD and final cleanup.
  • Focused experimental Cloud Hypervisor smoke checks: 6 passed. Postprocessor/general workflow patch checks: 85 passed.

Latest commit: 3688ced57e627b0c9fb2aa92164cf943e86a4ab9.

No workflow dispatch for this diagnostic update. No merge. The unrelated parent-checkout Dockerfile edit was not touched.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: c4bfaada-d9ab-469e-8882-b2d2c77da42d
Copilot AI balanced review requested due to automatic review settings October 9, 2026 16:09

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The focused generated changes are internally consistent and preserve the documented workflow constraints.

0 open findings

What changed in this PR

Recompiles the Cloud Hypervisor enclave smoke workflow with gh-aw v0.91.7 while preserving its existing runtime and artifact pins.

Changes:

  • Updates compiler and setup-action pins to v0.91.7.
  • Adds engine metadata to safe-output reporting.
  • Records the new setup-action pin.
File Description
.github/​workflows/​smoke-enclave-cloud-hypervisor.lock.yml Updates generated workflow metadata and reporting.
.github/​aw/​actions-lock.json Adds the v0.91.7 setup-action pin.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

✅ Coverage Check Passed

Overall Coverage

Metric Base PR Delta
Lines 93.03% 93.07% 📈 +0.04%
Statements 91.55% 91.60% 📈 +0.05%
Functions 90.23% 90.28% 📈 +0.05%
Branches 85.28% 85.32% 📈 +0.04%
📁 Per-file Coverage Changes (4 files)
File Lines (Before → After) Statements (Before → After)
src/artifact-preservation.ts 95.0% → 95.0% (+0.03%) 94.7% → 94.7% (+0.02%)
src/commands/main-action.ts 94.6% → 94.7% (+0.06%) 94.4% → 94.5% (+0.06%)
src/container-lifecycle.ts 96.7% → 97.9% (+1.15%) 96.3% → 98.0% (+1.61%)
src/log-directory-setup.ts 96.8% → 100.0% (+3.18%) 96.9% → 100.0% (+3.13%)
✨ New Files (1 files)
  • src/enclave/startup-diagnostics.ts: 100.0% lines

Coverage comparison generated by scripts/ci/compare-coverage.ts

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: c4bfaada-d9ab-469e-8882-b2d2c77da42d
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

✅ Copilot review passed with no inline comments.

@lpcox Add the ready-for-aw label to this PR to trigger agentic CI smoke tests.

Comment on lines +54 to +56
base_url="https://storage.googleapis.com/gvisor/releases/release/latest/${arch}"
curl -fsSL "${base_url}/runsc" -o "${RUNNER_TEMP}/runsc"
sudo install -m 0755 "${RUNNER_TEMP}/runsc" /usr/local/bin/runsc
Comment thread scripts/ci/postprocess-smoke-workflows.ts Fixed
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: c4bfaada-d9ab-469e-8882-b2d2c77da42d
Comment thread scripts/ci/postprocess-smoke-workflows.ts Fixed
Capture safe server startup evidence before retry teardown and final cleanup. Keep published Cloud Hypervisor smoke pins unchanged and document the release prerequisite for live verification.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: c4bfaada-d9ab-469e-8882-b2d2c77da42d
@lpcox lpcox changed the title chore: compile Cloud Hypervisor enclave smoke with gh-aw v0.91.7 fix: retain enclave startup diagnostics and recompile CH smoke with gh-aw v0.91.7 Oct 9, 2026
@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Documentation Preview

Documentation has been built for this PR.

Download preview artifact

To view locally:

  1. Download the docs-preview-pr-9756 artifact from the workflow run
  2. Unzip and open index.html in your browser

Built from commit 127855a

@lpcox

lpcox commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator Author

@copilot address review feedback

Copilot AI commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

@copilot address review feedback

Removed the postprocessor check-then-read race in commit 1cd2b9f. The gVisor/runsc finding is not applicable to the current smoke: neither its source nor generated lock installs or downloads gVisor.

@lpcox
lpcox merged commit 8ad503f into main Oct 9, 2026
35 checks passed
@lpcox
lpcox deleted the lpcox-enclave-compiler-v0-91-7 branch October 9, 2026 17:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants