fix: preserve sparse rootfs staging - #7920
Conversation
Use trusted rsync for sparse rootfs copies. Avoid expanding ext4 holes into host disk exhaustion. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: b657421c-9b57-46c6-a32c-6012d90e5117
|
🚀 Security Guard has started processing this pull request |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The production rootfs preparation path still performs an intermediate regular copy that can exhaust disk space before sparse staging.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review tier: Balanced
Findings: 1
New issues introduced by this change (2)
| Severity | Finding |
|---|---|
src/cloud-hypervisor/preflight.ts — The new helper's behavior is not exercised by the added tests: preflight mocks copySparseFile,… |
|
src/cloud-hypervisor/manager-start.ts — This sparse copy runs too late for the normal runtime path. The production backend always supplies… |
What changed in this PR
Preserves sparse Cloud Hypervisor rootfs images during trusted snapshot and /run staging.
Changes:
- Adds rsync-based sparse copying.
- Wires sparse staging through preflight and manager dependencies.
- Adds delegation tests and documents the invariant.
| File | Description |
|---|---|
src/cloud-hypervisor/preflight.ts |
Adds sparse snapshot copying. |
src/cloud-hypervisor/preflight.test.ts |
Tests preflight delegation. |
src/cloud-hypervisor/manager.ts |
Registers the sparse copier. |
src/cloud-hypervisor/manager.test.ts |
Tests manager delegation. |
src/cloud-hypervisor/manager-types.ts |
Extends manager dependencies. |
src/cloud-hypervisor/manager-start.ts |
Uses sparse /run staging. |
src/cloud-hypervisor/diagnostics.ts |
Supports custom artifact copying. |
docs/cloud-hypervisor-foundation.md |
Documents sparse staging. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
| Metric | Base | PR | Delta |
|---|---|---|---|
| Lines | 92.99% | 92.97% | 📉 -0.02% |
| Statements | 91.72% | 91.70% | 📉 -0.02% |
| Functions | 92.22% | 92.18% | 📉 -0.04% |
| Branches | 85.31% | 85.28% | 📉 -0.03% |
📁 Per-file Coverage Changes (5 files)
| File | Lines (Before → After) | Statements (Before → After) |
|---|---|---|
src/cloud-hypervisor/preflight.ts |
85.8% → 83.9% (-1.90%) | 85.2% → 83.3% (-1.83%) |
src/cloud-hypervisor/manager-start.ts |
96.0% → 96.0% (+0.05%) | 96.2% → 96.2% (+0.05%) |
src/cloud-hypervisor/manager.ts |
88.6% → 88.7% (+0.09%) | 87.4% → 87.5% (+0.10%) |
src/cloud-hypervisor/diagnostics.ts |
87.6% → 87.7% (+0.12%) | 85.3% → 85.6% (+0.26%) |
src/log-directory-setup.ts |
96.2% → 100.0% (+3.78%) | 96.3% → 100.0% (+3.71%) |
Coverage comparison generated by scripts/ci/compare-coverage.ts
|
@copilot address review feedback |
Use the trusted sparse copier before guest customization. Cover rsync arguments and failure behavior. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
✅ Copilot review passed with no inline comments. @lpcox Add the |
|
❌ Smoke Gemini reports failed. Facets need polishing...
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
✅ Smoke Claude passed Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"See Network Configuration for more information.
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟 Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "msfeed25.pkgs.visualstudio.com"
- "registry.npmjs.org"See Network Configuration for more information.
|
|
✅ Smoke Copilot BYOK AOAI (api-key) completed. Copilot AOAI BYOK (api-key) mode operational. 🔓
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
📰 VERDICT: Smoke Docker Sbx has concluded. All systems operational. This is a developing story. 🎤
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
✅ Smoke Copilot BYOK AOAI (Entra) completed. Copilot AOAI BYOK (Entra) mode operational. 🔓
|
|
❌ Contribution Check failed. Please review the logs for details.
|
|
✅ Build Test Suite completed successfully!
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
🚀 Security Guard has started processing this pull request |
|
📰 VERDICT: Smoke Docker Sbx has concluded. All systems operational. This is a developing story. 🎤
|
|
✅ Contribution Check completed successfully! Contribution check complete for PR #7920: no issues found against CONTRIBUTING.md. The PR includes tests for the new sparse-copy behavior, updates documentation, and the description is clear and references the related issue.
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"See Network Configuration for more information.
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟 Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "msfeed25.pkgs.visualstudio.com"
- "registry.npmjs.org"See Network Configuration for more information.
|
|
✅ Build Test Suite completed successfully!
|
|
❌ Smoke Gemini reports failed. Facets need polishing...
|
|
✅ Smoke Claude passed Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
|
🚀 Security Guard has started processing this pull request |
|
Smoke Test: Copilot Network Isolation Egress — @lpcox EGRESS_RESULT allow=pass deny=pass
Overall status: PASS Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"See Network Configuration for more information.
|
|
Smoke Test: Docker Sbx — @lpcox
Overall: PASS
|
|
Smoke Test: Copilot Engine — PASS ✅
Overall: PASS cc @lpcox
|
Smoke Test: Services Connectivity
Overall: FAIL — DNS resolution for
|
Copilot BYOK Smoke Test ✅Test Results:
Status: PASS
|
Smoke Test: Claude Engine Validation
Overall result: PASS Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
Chroot Version Comparison Results
Overall: FAILED — Node.js version mismatch between host and chroot environments (
|
Smoke Test: API Proxy OTEL Tracing — Results
Overall: All 5 scenarios passed. No unexpected failures detected.
|
|
@lpcox
|
|
fix: preserve sparse rootfs staging
|
|
Smoke test: FAIL PR titles:
Checks: merged review ✅ | safeinputs-gh ❌ | playwright ✅ | file+cat ✅ | discussion comment ❌ | build ✅ Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "msfeed25.pkgs.visualstudio.com"
- "registry.npmjs.org"See Network Configuration for more information.
|
🏗️ Build Test Suite Results
Overall: 8/8 ecosystems passed — PASS Notes:
|


Summary
rsync --sparse/runfs.copyFile(..., COPYFILE_EXCL)staging for binaries and attestation manifestsRoot cause
The live-KVM run after #7894 copied a sparse ext4 rootfs through regular file-copy paths. The trusted snapshot and writable guest-preparation copies could materialize the rootfs holes before the final per-run staging step, multiplying the image's logical size into host storage and failing with
ENOSPCbefore the VM could boot.Security rationale
The fix reuses the already preflight-resolved, trusted
rsyncbinary and passes--sparsewith an argument terminator. Only rootfs copies use this path. Executables, kernels, supervisors, manifests, and bundles continue to use exclusivefs.copyFilestaging, preserving the existing no-overwrite and trusted-snapshot protections.Validation
npm test -- --runInBand src/cloud-hypervisor/preflight.test.ts src/cloud-hypervisor/manager.test.ts src/microvm/workspace.test.ts(59 tests)npm run buildnpm run lintnpm run lint:mdnpm test -- --runInBand(5,374 tests)bash -n scripts/ci/cloud-hypervisor-host-preflight.sh scripts/ci/cloud-hypervisor-live-smoke.sh guest/cloud-hypervisor/build-test-artifacts.sh guest/cloud-hypervisor/verify-test-artifacts.sh