Skip to content

feat: enforce one workload sandbox backend per run - #9771

Merged
lpcox merged 2 commits into
mainfrom
lpcox-single-sandbox-backend-pr
Oct 9, 2026
Merged

lpcox merged 2 commits into
mainfrom
lpcox-single-sandbox-backend-pr

Conversation

@lpcox

@lpcox lpcox commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

This is the backend-resolution first step toward one workload sandbox backend per AWF run, not further lifecycle integration.

  • Resolve omitted/runc primary selections to Docker and runsc to gVisor; inherit omitted enclave runtimes from the primary selection during buildConfig.
  • Reject explicit backend mismatches during configuration assembly and check already assembled configurations before runMainWorkflow stages seeds or starts infrastructure. gVisor remains distinct from Docker despite Docker orchestration; no fallback or implicit primary switch occurs in enclave-enabled runs.
  • Keep each primary/enclave workload in a separate isolated instance, not a shared guest. Supporting Squid, API proxy, and MCP infrastructure may still use Docker.
  • Preserve standalone Docker and Cloud Hypervisor behavior, including existing unsupported-host fallback for standalone Cloud Hypervisor. Cloud Hypervisor primary-with-enclave execution remains gated and NVX enclaves remain unsupported; this PR does not enable either integration. Existing Cloud Hypervisor host-executor internals are retained for later same-backend lifecycle work.
  • Update the configuration specification, synchronized schemas, and enclave architecture documentation.
  • Add ADR 0004: Unified workload sandbox backends, with a reciprocal link from ADR 0002. It records preserved Cloud Hypervisor managers/profiles/host executor and isolation mechanisms, practical shared CH/NVX microVM orchestration, and the rollout from verified Docker to unified CH static enclaves, then NVX. Dynamic repository admission follows static acceptance and is distinct from creating fresh instances on demand.

Validation

Verified in a clean main-based worktree:

  • Build succeeds.
  • Eight focused suites pass (253 tests): backend resolver, enclave parser, config builder, main workflow, enclave preflight, and standalone Cloud Hypervisor runtime validation/config/manager construction.
  • Scoped ESLint and full pre-commit ESLint complete with warnings only; no errors.
  • git diff --check passes; canonical and embedded config schemas match.
  • Markdownlint passes for the new ADR and ADR 0002; the documentation commit also passes the existing lint/build hooks.

The original scoped 12-file backend-resolution patch plus the requested new ADR and ADR 0002 cross-link are included. The parent's Dockerfile edit, untracked research documents, and previously committed unrelated test fixes are excluded.

Resolve the primary workload backend and inherit omitted enclave runtimes.
Reject explicit or assembled backend conflicts before staging.
Preserve unsupported Cloud Hypervisor and NVX integration guards.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2d29b77f-7ee8-4e53-8e41-6dfee822ffaf
Copilot AI balanced review requested due to automatic review settings October 9, 2026 17:53
@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Documentation Preview

Documentation has been built for this PR.

Download preview artifact

To view locally:

  1. Download the docs-preview-pr-9771 artifact from the workflow run
  2. Unzip and open index.html in your browser

Built from commit 421ce35

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

Backend normalization, fail-closed validation, tests, schemas, and documentation are consistent with the stated scope.

0 open findings

What changed in this PR

Enforces a single normalized sandbox backend across primary and enclave workloads while preserving existing runtime gates.

Changes:

  • Adds backend normalization, inheritance, and mismatch validation.
  • Validates assembled configurations before workflow infrastructure starts.
  • Updates focused tests, schemas, and enclave documentation.
File Description
src/​parsers/​enclave-parser.ts Inherits and validates enclave backends.
src/​parsers/​enclave-parser.test.ts Tests inheritance and mismatch rejection.
src/​enclave/​run-backend.ts Adds backend resolution and validation.
src/​enclave/​run-backend.test.ts Tests aliases and assembled configurations.
src/​commands/​build-config.ts Passes primary runtime during assembly.
src/​commands/​build-config.test.ts Tests assembly behavior.
src/​cli-workflow.ts Adds early backend consistency checks.
src/​cli-workflow.test.ts Verifies rejection before startup.
src/​awf-config-schema.json Synchronizes the runtime schema.
docs/​enclaves-architecture.md Documents the run-wide invariant.
docs/​awf-config.schema.json Updates the canonical schema.
docs/​awf-config-spec.md Specifies inheritance and runtime gates.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Define separate workload instances of one resolved backend per enclave run.
Preserve host executor mechanisms and sequence static CH then NVX integration.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2d29b77f-7ee8-4e53-8e41-6dfee822ffaf
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

✅ Copilot review passed with no inline comments.

@lpcox Add the ready-for-aw label to this PR to trigger agentic CI smoke tests.

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

✅ Coverage Check Passed

Overall Coverage

Metric Base PR Delta
Lines 93.07% 93.10% 📈 +0.03%
Statements 91.60% 91.63% 📈 +0.03%
Functions 90.28% 90.32% 📈 +0.04%
Branches 85.33% 85.37% 📈 +0.04%
📁 Per-file Coverage Changes (3 files)
File Lines (Before → After) Statements (Before → After)
src/parsers/enclave-parser.ts 97.0% → 97.6% (+0.51%) 97.4% → 97.8% (+0.39%)
src/cli-workflow.ts 95.4% → 97.0% (+1.55%) 95.1% → 97.2% (+2.11%)
src/log-directory-setup.ts 96.8% → 100.0% (+3.18%) 96.9% → 100.0% (+3.13%)
✨ New Files (1 files)
  • src/enclave/run-backend.ts: 100.0% lines

Coverage comparison generated by scripts/ci/compare-coverage.ts

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

✅ Build Test Suite completed successfully!

Generated by Build Test Suite for #9771

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

🔌 Smoke Services — All services reachable! ✅

🔌 Service connectivity validated by Smoke Services

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅

🛡️ Egress verdict from Smoke Copilot Network Isolation

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed.

Cloud Hypervisor + Copilot smoke test by Smoke Cloud Hypervisor

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

💎 Smoke Gemini is crystallizing results on this pull request...

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

🚀 Security Guard has started processing this pull request

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

🔮 The ancient spirits stir... Smoke Codex awakens to divine this pull request...

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

✅ Smoke Claude passed

Generated by Smoke Claude for #9771

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.

Tested by Smoke Chroot

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓

🔑 BYOK report filed by Smoke Copilot BYOK

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅

📡 OTel tracing validated by Smoke OTel Tracing

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

🪪 Smoke Copilot BYOK AOAI (Entra) is testing Azure OpenAI BYOK (Entra / GitHub OIDC) mode on this pull request...

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤

📰 BREAKING: Report filed by Smoke Copilot

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

🔑 Smoke Copilot BYOK AOAI (api-key) is testing Azure OpenAI BYOK (api-key) mode on this pull request...

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Smoke Test: Cloud Hypervisor + Copilot

  1. PASS — list_pull_requests returned PR Accept Codex standalone search input and output limits #9750 (closed)
  2. PASS — https://github.com returned 200
  3. PASS — wrote/read /tmp/gh-aw/agent/smoke-cloud-hypervisor-37972347490.txt
  4. PASS — (example.com/redacted) blocked (000, curl exit 60)

Result: ALL CHECKS PASSED

Cloud Hypervisor + Copilot smoke test by Smoke Cloud Hypervisor
Add label ready-for-aw to run again

@github-actions github-actions Bot added smoke-cloud-hypervisor smoke-copilot-network-isolation Copilot network-isolation egress smoke test labels Oct 9, 2026
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

EGRESS_RESULT allow=pass deny=pass

  • ✅ Allowed domain (api.github.com → 200)
  • ✅ Blocked domain (example.com blocked; curl failed with a self-signed cert error)

Overall: PASS — @lpcox

🛡️ Egress verdict from Smoke Copilot Network Isolation
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Smoke Test: Claude Engine Validation

  • API status: ✅ PASS
  • GitHub check: ✅ PASS
  • File status: ✅ PASS

Overall result: PASS

Generated by Smoke Claude for #9771 · claude · haiku45 · 45.4 AIC · ⊞ 6.1K · ◷
Add label ready-for-aw to run again

@lpcox
lpcox deployed to aoai-model October 9, 2026 18:29 — with GitHub Actions Active
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Smoke services: ✅ Redis PONG · ✅ pg_isready accepting connections · ✅ SELECT 1 → 1. PASS

🔌 Service connectivity validated by Smoke Services
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Smoke Test: Copilot BYOK (Direct) Mode ✅

Test Result
GitHub MCP ✅ (PR list retrieved)
HTTP Connectivity ✅ (200 OK)
File Read ✅ (smoke-test-copilot-byok.txt)
BYOK Inference ✅ (Direct mode active)

Mode: Direct BYOK (COPILOT_PROVIDER_API_KEY) → api-proxy sidecar → api.githubcopilot.com

Status: PASS

🔑 BYOK report filed by Smoke Copilot BYOK
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

OTEL smoke test

  • ✅ S1 Module loading: otel.js loads; exports startRequestSpan, setTokenAttributes, setBudgetAttributes, endSpan, endSpanError, shutdown, isEnabled.
  • ✅ S2 Tests: 3 OTEL suites, 68/68 passed.
  • ✅ S3 Env forwarding: trace context in env-passthrough.ts; OTEL vars in api-proxy-env-config.ts.
  • ✅ S4 Token tracker: onUsage hook present in token-tracker-http.js.
  • ✅ S5 Diagnostics: /tmp/gh-aw/otel.jsonl has 1 span record.

📡 OTel tracing validated by Smoke OTel Tracing
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Smoke Copilot: PASS

  • ✅ GitHub MCP (last merged PR: "fix: retain enclave startup diagnostics and recompile CH smoke with gh-aw v0.91.7")
  • ✅ github.com connectivity (HTTP 200)
  • ✅ File write/read

Author: @lpcox

📰 BREAKING: Report filed by Smoke Copilot
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Chroot version comparison

Runtime Host Version Chroot Version Match?
Python Python 3.12.15 Python 3.12.15 ✅
Node.js v24.21.0 v22.23.2 ❌
Go go1.22.12 go1.22.12 ✅

Node.js differs between host and chroot, so not all tests passed. The smoke-chroot label was not added.

Tested by Smoke Chroot
Add label ready-for-aw to run again

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

🏗️ Build Test Suite Results

Ecosystem Project Build/Install Tests Status
Bun elysia ❌ not run ❌ FAIL
Bun hono ❌ not run ❌ FAIL
C++ fmt ✅ N/A ✅ PASS
C++ json ✅ N/A ✅ PASS
Deno oak ❌ not run ❌ FAIL
Deno std ❌ not run ❌ FAIL
.NET hello-world ✅ N/A ✅ PASS
.NET json-parse ✅ N/A ✅ PASS
Go color ✅ 1/1 pkg passed ✅ PASS
Go env ✅ 1/1 pkg passed ✅ PASS
Go uuid ✅ 1/1 pkg passed ✅ PASS
Java gson ✅ 1/1 passed ✅ PASS
Java caffeine ✅ 1/1 passed ✅ PASS
Node.js clsx ✅ passed ✅ PASS
Node.js execa ✅ passed ✅ PASS
Node.js p-limit ✅ passed ✅ PASS
Rust fd ✅ 1/1 passed ✅ PASS
Rust zoxide ✅ 1/1 passed ✅ PASS

Overall: 6/8 ecosystems passed — FAIL

Failures:

  • Bun / Deno: the sandbox denied the install commands (curl ... | bash / | sh for bun.sh and deno.land). Bun and Deno are not preinstalled, so the tests could not run.
  • Java note: the default ~/.m2/repository was not writable (LocalRepositoryNotAccessibleException). Java passed using -Dmaven.repo.local pointing to a temp directory.

All 8 repos cloned successfully. The build-test label was not added because of the failures.

Generated by Build Test Suite for #9771 · copilot · auto · 23.2 AIC · ⊞ 11.9K · ◷
Add label ready-for-aw to run again

@lpcox
lpcox merged commit 98959bd into main Oct 9, 2026
139 of 147 checks passed
@lpcox
lpcox deleted the lpcox-single-sandbox-backend-pr branch October 9, 2026 18:39

This branch had an error being deployed

1 failed deployment
aoai-model — 01920b16 Deployed Oct 9, 2026 by lpcox via conclusion #1922
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants