Skip to content

feat: compose gated unified Cloud Hypervisor lifecycle - #9776

Open
lpcox wants to merge 1 commit into
mainfrom
lpcox-unified-cloud-hypervisor-lifecycle
Open

lpcox wants to merge 1 commit into
mainfrom
lpcox-unified-cloud-hypervisor-lifecycle

Conversation

@lpcox

@lpcox lpcox commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

Summary

Next AWF-only slice of ADR 0004, following #9771. Reuses the existing primary CloudHypervisorManager/runtime boot loop and authenticated host enclave executor/broker/storage lifecycle. The primary has its own VM; enclave invocations continue to use fresh, separately isolated VMs. Supporting Squid/API proxies and compiler-owned mcpg remain Docker infrastructure.

  • Require the owning host-enclave lifecycle before infrastructure startup, require completion of the existing mcpg readiness callback before primary VM creation, and recheck admissions after asynchronous setup and before primary execution.
  • Check actual virtio-fs export sources (including read-only runner-temp/tool-cache exports and symlink aliases) against seeds, broker/capability state, invocation storage, allocation domains, and recovery roots.
  • Close admissions before primary cancellation, drain invocation VMs even when primary teardown fails, reject cross-configuration shutdown ownership, and preserve infrastructure/private recovery state on uncertain VM cleanup. Preserve-mode still drains enclave invocations.
  • Keep standalone unsupported-host fallback, forbid cross-backend fallback for enclave-enabled runs, avoid treating primary CH as an OCI runtime, and report CH accurately in broker metadata.
  • Add focused internal-composition, cancellation/ownership, export-isolation, supporting-Compose and compatibility regressions; document what is wired and what remains gated.

Gates and precise remaining contracts

Production CH-primary-with-enclave execution remains rejected by both existing public validation paths. No new config/env bypass, launcher replacement, experimental production enablement, workflow dispatch, merge, or retag is included. NVX and dynamic repository admission are out of scope. This work is separate from #9756 and makes no inferred permissions fix for the earlier broker readiness failure.

The internal integration tests use mocked VM/host-service boundaries and a readiness callback; they are not real KVM or real mcpg acceptance. Subsequent acceptance must use compiler-owned real mcpg, first CH primary + static script, then CH primary + static agent with the dedicated model proxy. It must demonstrate guest public-gateway routing and denial of seeds/broker credentials/private storage/recovery state (including submount/alias/race cases), independent fresh invocation VMs, credential custody, bounded resources/results, cancellation/drain, uncertain cleanup preservation, and orphan recovery. Path-overlap checks alone are not proof of live virtio-fs confinement.

Static agent GitHub tools remain explicitly blocked on a compiler-scoped executor bearer handoff: the current static identity alone is insufficient. This PR does not substitute a gateway-wide key or broaden privileges. Agent acceptance without GitHub tools does not satisfy that separate gate.

Validation

  • npm run build and npm run type-check passed.
  • Focused regression run: 21 suites / 657 tests passed, covering primary runtime, host executor/protocol/broker, host lifecycle/storage cleanup, gateway contracts, mount policy, Compose services, CLI workflow/cleanup, fallback, and guest environment exclusions.
  • Lifecycle/primary runtime run with --detectOpenHandles: 2 suites / 49 tests passed.
  • Changed-file ESLint, related Markdown lint, and git diff --check passed. Full pre-commit lint/build hooks passed (existing lint warnings remain).
  • No live Actions dispatch or Linux/KVM end-to-end run was performed from this macOS worktree.

Commit: 34052180bc7a99c5a79fbabad7282c3be3be91b0. Parent checkout and its local changes were left untouched.

Require authenticated host-enclave readiness and compiler gateway callback completion
before primary VM creation. Check actual guest exports, enforce lifecycle ownership,
and preserve infrastructure on uncertain teardown. Retain production execution gates
pending real end-to-end acceptance.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a75ff200-52e9-49aa-8f67-34bfa5199399
Copilot AI balanced review requested due to automatic review settings October 9, 2026 20:56
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Documentation Preview

Documentation has been built for this PR.

Download preview artifact

To view locally:

  1. Download the docs-preview-pr-9776 artifact from the workflow run
  2. Unzip and open index.html in your browser

Built from commit 5467cc8

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

A diagnostics failure can bypass primary VM teardown and leave the runtime running.

1 open finding
What changed in this PR

Composes the gated unified Cloud Hypervisor primary/enclave lifecycle while retaining production validation gates.

Changes:

  • Adds lifecycle readiness, ownership, cancellation, and cleanup coordination.
  • Validates primary virtio-fs exports against enclave-private state.
  • Expands regression coverage and documents remaining acceptance gates.
File Description
src/​services/​enclave-mcp-service.test.ts Tests CH-only supporting Compose services.
src/​enclave/​runtime-preflight.ts Recognizes CH as a primary backend.
src/​enclave/​runtime-preflight.test.ts Tests CH backend normalization.
src/​enclave/​preflight.ts Separates structural and production validation.
src/​enclave/​mount-policy.ts Checks CH exports against private roots.
src/​enclave/​mount-policy.test.ts Tests export overlap and aliases.
src/​enclave/​manager.ts Excludes CH from OCI runtime probing.
src/​enclave/​cloud-hypervisor-lifecycle.ts Adds backend and shutdown ownership checks.
src/​enclave/​cloud-hypervisor-lifecycle.test.ts Tests ownership and backend consistency.
src/​commands/​main-action.ts Adjusts fallback and cleanup preservation.
src/​commands/​main-action.test.ts Tests unified cleanup and fallback behavior.
src/​cloud-hypervisor/​unified-lifecycle.test.ts Tests internal lifecycle composition.
src/​cloud-hypervisor/​runtime-validation.ts Updates the production gate rationale.
src/​cloud-hypervisor/​runtime-validation.test.ts Updates gate assertions.
src/​cloud-hypervisor/​runtime-boot-loop.ts Adds readiness and export-isolation gates.
src/​cloud-hypervisor/​runtime-backend.ts Coordinates execution and teardown lifecycle.
src/​cloud-hypervisor-runtime-backend.test.ts Tests coordinated stop and preserve behavior.
src/​cloud-hypervisor-runtime-backend.env-mapping.test.ts Updates compatibility assertions.
docs/​cloud-hypervisor-foundation.md Documents the gated integration.
docs/​adr/​0004-unified-workload-sandbox-backends.md Records lifecycle design and acceptance requirements.
docs/​adr/​0002-cloud-hypervisor-enclave-executor.md Cross-references unified orchestration constraints.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +326 to +328
config.containerRuntime === 'cloud-hypervisor' && config.enclaves?.enabled
? 'Unified Cloud Hypervisor cleanup failed; infrastructure and recovery state must be preserved.'
: 'External runtime cleanup failed; continuing with infrastructure teardown.',
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

✅ Coverage Check Passed

Overall Coverage

Metric Base PR Delta
Lines 93.08% 93.11% 📈 +0.03%
Statements 91.61% 91.65% 📈 +0.04%
Functions 90.32% 90.33% 📈 +0.01%
Branches 85.35% 85.41% 📈 +0.06%
📁 Per-file Coverage Changes (10 files)
File Lines (Before → After) Statements (Before → After)
src/enclave/manager.ts 87.2% → 86.8% (-0.35%) 86.5% → 86.1% (-0.32%)
src/commands/main-action.ts 94.7% → 94.7% (+0.03%) 94.5% → 94.5% (+0.04%)
src/enclave/preflight.ts 92.0% → 92.1% (+0.10%) 92.4% → 92.5% (+0.09%)
src/cloud-hypervisor/runtime-backend.ts 96.3% → 96.5% (+0.20%) 91.5% → 93.2% (+1.65%)
src/enclave/cloud-hypervisor-lifecycle.ts 93.7% → 93.9% (+0.23%) 91.6% → 92.6% (+0.96%)
src/nvx/one-shot-adapter.ts 81.7% → 82.3% (+0.56%) 79.1% → 79.6% (+0.52%)
src/cloud-hypervisor/runtime-boot-loop.ts 96.5% → 97.2% (+0.64%) 96.6% → 95.5% (-1.10%)
src/enclave/mount-policy.ts 94.6% → 95.2% (+0.64%) 93.4% → 94.3% (+0.89%)
src/enclave/runtime-preflight.ts 70.0% → 70.7% (+0.73%) 71.4% → 72.7% (+1.30%)
src/log-directory-setup.ts 96.8% → 100.0% (+3.18%) 96.9% → 100.0% (+3.13%)

Coverage comparison generated by scripts/ci/compare-coverage.ts

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants