Repository navigation
Conversation
Require authenticated host-enclave readiness and compiler gateway callback completion before primary VM creation. Check actual guest exports, enforce lifecycle ownership, and preserve infrastructure on uncertain teardown. Retain production execution gates pending real end-to-end acceptance. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: a75ff200-52e9-49aa-8f67-34bfa5199399
Contributor
Documentation PreviewDocumentation has been built for this PR. To view locally:
Built from commit 5467cc8 |
Contributor
There was a problem hiding this comment.
🟡 Changes recommended
A diagnostics failure can bypass primary VM teardown and leave the runtime running.
1 open finding
What changed in this PR
Composes the gated unified Cloud Hypervisor primary/enclave lifecycle while retaining production validation gates.
Changes:
- Adds lifecycle readiness, ownership, cancellation, and cleanup coordination.
- Validates primary virtio-fs exports against enclave-private state.
- Expands regression coverage and documents remaining acceptance gates.
| File | Description |
|---|---|
src/services/enclave-mcp-service.test.ts |
Tests CH-only supporting Compose services. |
src/enclave/runtime-preflight.ts |
Recognizes CH as a primary backend. |
src/enclave/runtime-preflight.test.ts |
Tests CH backend normalization. |
src/enclave/preflight.ts |
Separates structural and production validation. |
src/enclave/mount-policy.ts |
Checks CH exports against private roots. |
src/enclave/mount-policy.test.ts |
Tests export overlap and aliases. |
src/enclave/manager.ts |
Excludes CH from OCI runtime probing. |
src/enclave/cloud-hypervisor-lifecycle.ts |
Adds backend and shutdown ownership checks. |
src/enclave/cloud-hypervisor-lifecycle.test.ts |
Tests ownership and backend consistency. |
src/commands/main-action.ts |
Adjusts fallback and cleanup preservation. |
src/commands/main-action.test.ts |
Tests unified cleanup and fallback behavior. |
src/cloud-hypervisor/unified-lifecycle.test.ts |
Tests internal lifecycle composition. |
src/cloud-hypervisor/runtime-validation.ts |
Updates the production gate rationale. |
src/cloud-hypervisor/runtime-validation.test.ts |
Updates gate assertions. |
src/cloud-hypervisor/runtime-boot-loop.ts |
Adds readiness and export-isolation gates. |
src/cloud-hypervisor/runtime-backend.ts |
Coordinates execution and teardown lifecycle. |
src/cloud-hypervisor-runtime-backend.test.ts |
Tests coordinated stop and preserve behavior. |
src/cloud-hypervisor-runtime-backend.env-mapping.test.ts |
Updates compatibility assertions. |
docs/cloud-hypervisor-foundation.md |
Documents the gated integration. |
docs/adr/0004-unified-workload-sandbox-backends.md |
Records lifecycle design and acceptance requirements. |
docs/adr/0002-cloud-hypervisor-enclave-executor.md |
Cross-references unified orchestration constraints. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+326
to
+328
| config.containerRuntime === 'cloud-hypervisor' && config.enclaves?.enabled | ||
| ? 'Unified Cloud Hypervisor cleanup failed; infrastructure and recovery state must be preserved.' | ||
| : 'External runtime cleanup failed; continuing with infrastructure teardown.', |
Contributor
✅ Coverage Check PassedOverall Coverage
📁 Per-file Coverage Changes (10 files)
Coverage comparison generated by |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
Next AWF-only slice of ADR 0004, following #9771. Reuses the existing primary
CloudHypervisorManager/runtime boot loop and authenticated host enclave executor/broker/storage lifecycle. The primary has its own VM; enclave invocations continue to use fresh, separately isolated VMs. Supporting Squid/API proxies and compiler-owned mcpg remain Docker infrastructure.Gates and precise remaining contracts
Production CH-primary-with-enclave execution remains rejected by both existing public validation paths. No new config/env bypass, launcher replacement, experimental production enablement, workflow dispatch, merge, or retag is included. NVX and dynamic repository admission are out of scope. This work is separate from #9756 and makes no inferred permissions fix for the earlier broker readiness failure.
The internal integration tests use mocked VM/host-service boundaries and a readiness callback; they are not real KVM or real mcpg acceptance. Subsequent acceptance must use compiler-owned real mcpg, first CH primary + static script, then CH primary + static agent with the dedicated model proxy. It must demonstrate guest public-gateway routing and denial of seeds/broker credentials/private storage/recovery state (including submount/alias/race cases), independent fresh invocation VMs, credential custody, bounded resources/results, cancellation/drain, uncertain cleanup preservation, and orphan recovery. Path-overlap checks alone are not proof of live virtio-fs confinement.
Static agent GitHub tools remain explicitly blocked on a compiler-scoped executor bearer handoff: the current static identity alone is insufficient. This PR does not substitute a gateway-wide key or broaden privileges. Agent acceptance without GitHub tools does not satisfy that separate gate.
Validation
npm run buildandnpm run type-checkpassed.--detectOpenHandles: 2 suites / 49 tests passed.git diff --checkpassed. Full pre-commit lint/build hooks passed (existing lint warnings remain).Commit:
34052180bc7a99c5a79fbabad7282c3be3be91b0. Parent checkout and its local changes were left untouched.