fix: stabilize post-merge KVM checks - #7922
Conversation
Persist identity-validated Cloud Hypervisor cleanup records. Safely reap stale resources after abrupt owner death. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Capture executable inode identity from the live procfs object. Verify firewall rule absence after deletion. Cover cleanup races at base coverage levels. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 92d2c346-d396-40d3-8b74-1f1447a04871
Resolve Cloud Hypervisor lifecycle overlaps. Preserve durable cleanup and current runtime confinement. Assign the VMM cgroup before durable identity capture. This avoids a PID-reuse window. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 92d2c346-d396-40d3-8b74-1f1447a04871
Ensure VMM cgroup assignment precedes durable process identity capture. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 92d2c346-d396-40d3-8b74-1f1447a04871
Reconcile durable identity-validated cleanup with atomic network reservations, current virtiofsd worker confinement, and per-run firewall ownership. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 92d2c346-d396-40d3-8b74-1f1447a04871
Count gh alongside Docker and the eleven Cloud Hypervisor runtime tools. This keeps preflight assertions aligned with manifest attestation verification. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 92d2c346-d396-40d3-8b74-1f1447a04871
Reuse the backend-owned attested snapshot during workflow startup and every boot retry. This prevents duplicate rootfs copies from exhausting the runner's /run filesystem. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 92d2c346-d396-40d3-8b74-1f1447a04871
Match the live virtiofsd sandbox state while retaining exact effective and permitted capability checks. Reject capabilities reacquirable across exec. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 92d2c346-d396-40d3-8b74-1f1447a04871
Merge current origin/main without rebasing and preserve durable cleanup across dedicated accounts, device ACLs, network reservations, and artifact snapshots. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 92d2c346-d396-40d3-8b74-1f1447a04871
Use a bounded production-scale API readiness budget so coverage instrumentation cannot race the mocked socket probe. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 92d2c346-d396-40d3-8b74-1f1447a04871
Acquire worker identity, cgroup membership, and same-process validation as one retryable operation when a setup worker exits during procfs inspection. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 92d2c346-d396-40d3-8b74-1f1447a04871
|
🚀 Security Guard has started processing this pull request |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Broad ENOENT handling masks cgroup loss, and the cgroup-assignment retry path lacks coverage.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review tier: Balanced
Findings: 1
New issues introduced by this change (2)
| Severity | Finding |
|---|---|
src/cloud-hypervisor/virtiofsd-sandbox.ts — The newly supported cgroup-assignment race is not exercised by the added test: that test throws… |
|
src/cloud-hypervisor/virtiofsd-sandbox.ts — ENOENT is handled here as if the candidate exited regardless of which operation failed. However,… |
What changed in this PR
Stabilizes Cloud Hypervisor worker discovery and readiness tests against transient process and timing races.
Changes:
- Retries transient virtiofsd worker exits during identity capture and cgroup assignment.
- Adds worker-exit regression coverage.
- Uses a realistic readiness timeout in the manager fixture.
| File | Description |
|---|---|
src/cloud-hypervisor/virtiofsd-sandbox.ts |
Moves worker validation and assignment into the retry loop. |
src/cloud-hypervisor/virtiofsd.test.ts |
Tests worker exit during identity capture. |
src/cloud-hypervisor/manager.test.ts |
Increases the fixture readiness timeout. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
| Metric | Base | PR | Delta |
|---|---|---|---|
| Lines | 92.95% | 92.93% | 📉 -0.02% |
| Statements | 91.60% | 91.57% | 📉 -0.03% |
| Functions | 92.07% | 92.07% | ➡️ +0.00% |
| Branches | 85.37% | 85.30% | 📉 -0.07% |
📁 Per-file Coverage Changes (2 files)
| File | Lines (Before → After) | Statements (Before → After) |
|---|---|---|
src/cloud-hypervisor/virtiofsd-sandbox.ts |
100.0% → 95.9% (-4.09%) | 99.3% → 93.6% (-5.62%) |
src/log-directory-setup.ts |
96.2% → 100.0% (+3.78%) | 96.3% → 100.0% (+3.71%) |
Coverage comparison generated by scripts/ci/compare-coverage.ts
Retry assignment only for ESRCH or when procfs proves the candidate exited. Preserve cgroup ENOENT while the worker remains alive. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 92d2c346-d396-40d3-8b74-1f1447a04871
|
✅ Copilot review passed with no inline comments. @lpcox Add the |
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
📰 VERDICT: Smoke Docker Sbx has concluded. All systems operational. This is a developing story. 🎤
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
✅ Smoke Copilot BYOK AOAI (api-key) completed. Copilot AOAI BYOK (api-key) mode operational. 🔓
|
|
🚀 Security Guard has started processing this pull request |
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"See Network Configuration for more information.
|
|
✅ Smoke Copilot BYOK AOAI (Entra) completed. Copilot AOAI BYOK (Entra) mode operational. 🔓
|
|
Smoke Test: Copilot Engine — @lpcox
Overall: PASS
|
Smoke Test Results: Copilot BYOK (Direct) Mode✅ GitHub MCP Testing — connectivity verified Status: PASS
|
|
Smoke Test: Docker Sbx Validation PR #7920: fix: preserve sparse rootfs staging
Overall: PASS cc @lpcox
|
Chroot Version Comparison Results
Overall: FAILED — Node.js version differs between host and chroot environments.
|
|
Smoke test: FAIL Reviewed:
Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "msfeed25.pkgs.visualstudio.com"
- "registry.npmjs.org"See Network Configuration for more information.
|
|
EGRESS_RESULT allow=pass deny=pass ✅ Allowed domain (github.com) reachable: Overall: PASS cc @lpcox Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"See Network Configuration for more information.
|
|
@lpcox Tests:
Running in direct BYOK mode (COPILOT_PROVIDER_API_KEY + COPILOT_PROVIDER_BASE_URL) via api-proxy → Azure OpenAI (Foundry, o4-mini-aw)
|
🏗️ Build Test Suite Results
Overall: 8/8 ecosystems passed — PASS Note (non-blocking): Java's Maven build initially failed with All 18 test projects across 8 language ecosystems built and passed their test suites successfully through the AWF firewall.
|
|
@lpcox
|
Smoke Test: Claude Engine Validation
Overall result: PASS Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
|
Smoke Test Results:
Overall: FAIL —
|
|
📡 OTel Tracing Smoke Test Results
Overall: All testable scenarios pass. No regressions detected.
|
|
🚀 Security Guard has started processing this pull request |


Summary
/procidentity capture or cgroup assignmentContext
PR #7896 was merged while its final coverage and live-KVM runs were still completing. The coverage run exposed a 1 ms test-only readiness race, and live-KVM run 33425529718 observed a virtiofsd child disappear between discovery and
/proc/<pid>/statcapture.Validation
npm test -- --runInBand— 335 suites, 5,428 tests passednpm run buildnpm run lint— zero errorsbash -n scripts/ci/cloud-hypervisor-live-smoke.shFollow-up to #7896. Do not merge until live-KVM completes successfully.