Skip to content

governance: establish Capsule libkrun v1.19.4 patch line - #1

Merged
dills122 merged 9 commits into
capsule/upstream-v1.19.4from
codex/governed-capsule-v1.19.4
Aug 3, 2026
Merged

dills122 merged 9 commits into
capsule/upstream-v1.19.4from
codex/governed-capsule-v1.19.4

Conversation

@dills122

@dills122 dills122 commented Aug 3, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Establish the review-only Capsule governed libkrun v1.19.4 patch line over the immutable upstream commit 728df8125077d0db44265f6e997c72b81b65c015.

Base: capsule/upstream-v1.19.4

Head: codex/governed-capsule-v1.19.4

This is source/patch governance and controlled local library validation only. It does not admit a backend/profile, wire product code, change libkrunfw or a kernel, exercise a Supervisor, sign a release, or grant path/image/network/mount/write/deployment authority. The governed route creates no guest; the CI remediation disclosure below records one upstream integration job that ran automatically before precise routing was added.

Provenance and ordered queue

The retained artifacts were re-read from dills122/capsule-corp merge commit ada09cd2695035774e359552d8a9a9ce061dd4ca and reviewed head a3148374e9fc8d6b7ee89aba0cdb18daff897d21. The two repaired prerequisite blobs match at both commits. Clean reconstruction from the exact upstream base and reverse dry-run both pass.

Order Commit Retained patch SHA-256
1 726dd76aa4105f3bc00bb6d5c8de9c0680c60e43 firmware @rpath prerequisite a845cce3cd479a73c6a698164dc1b466e8d67796018b107077504478e0ec9cd5
2 80bceae75c50645ed741512c5eb30a7b94bcf1c7 immutable-root mount flags b2120d4cc848e138a28165906d6c5cc4da1efee8004e392a7ddddc2334136823
3 6bef122b6195db1236fc5d6075cf7c3af79e2f66 P0-2 direct block root / NullFs removal 642d9e196cbb752347e06a8ce4ca35ea38ef94bf7e15ca9e1b136ed58229ef59
4 ab3c9a57a0ac7a4f6664c6b18d775c35ef0b8684 P0-1 raw-only FD-native read-only root API 48cdbc307b3fa1209fa0ec68fc3f817634af312983d68f0de259db86c0b43333
5 5eefb9f594370ff5f9304488a21e63a270878722 P0-3 directional console hardening 584ce48548fe969684fe3c55e57fbf56e7dae40af28c241c24c47b138faf1283

Canonical queue identity: d19fd0ff159c699acccda2621519de45a09408bf3847b418ac34e02b79e805d5.

Governance and CI are separate commits: 4b3169f9d7f5e99f403aa43e86c0aad283691cd7 and f6376fd62bdea9c965d589d9e88d4b6d85f47584. Follow-up CI remediation commits are a5a33381bf4ac29d7a12b0649e505286d695d1bf and 56afc9bd0e423ddfe37460c769227e4cc168b0ff.

Security properties

  • The new root API is additive, immediately duplicates caller ownership, rejects writable, linked, non-regular, non-0400, mis-sized, or identity-mismatched objects, and passes a File directly to raw storage without reconstructing a pathname or probing an image format.
  • The direct-root route accepts only /dev/vda, ext4, and ro,nosuid,nodev, removes NullFs only from that governed route, and preserves other upstream APIs and behavior.
  • Console changes validate descriptor/control direction and port IDs, suppress duplicate starts, preserve partial-write progress, and make shutdown wake blocked output before joining workers.
  • Exact patches, provenance, CODEOWNERS, review/update/removal policy, license/SBOM inputs, and source-route audits are fork-local and versioned.

CI scope

The added workflow is limited to this work branch, PRs targeting the exact versioned baseline, manual dispatch, and the governed policy/source paths. It uses fixed local fixtures and library processes only and explicitly rejects guest opt-in. For PRs targeting capsule/upstream-v1.19.4, the upstream integration jobs are precisely skipped because they install firmware and execute guests; all other PR bases retain upstream integration behavior. Governed library checks replace that route without weakening an upstream security assertion.

The remediation also verifies the baseline through an existing local or remote-tracking ref, pins governed Clippy to retained-evidence Rust 1.93.1, denies warnings except the documented retained GuestMemory::try_access deprecation, and checks Rust 1.97.1 formatter output against one exact retained P0-2 line-wrap fixture. Any additional formatter difference fails. The 53-test blk corpus uses one test thread to prevent the two exact retained clock-named raw-FD fixtures from colliding on macOS; all tests and assertions remain enabled.

On the initial CI run, the x86_64 upstream integration job had already executed before the out-of-scope route was identified. Its failure and artifacts were not used as evidence. The queued self-hosted AArch64 job was canceled before executing any step. The replacement workflow prevents either guest job from starting for this exact governed baseline.

Local no-guest validation

  • Clean five-patch reconstruction: PASS
  • Patch reverse dry-run: PASS
  • Direct-root source contract: PASS
  • Raw-FD source and compile-only C header contracts: PASS
  • Rust 1.97.1 formatting: PASS with exactly the retained P0-2 line-wrap drift; 0 additional differences
  • Cargo check (krun-devices with blk; libkrun blk without embedded init blob): PASS
  • Console corpus: 51/51 PASS
  • blk corpus: 53/53 PASS, including 2/2 raw-FD contract tests
  • Clippy with warnings denied: PASS; only documented allowance is retained deprecated GuestMemory::try_access in process_tx.rs
  • AddressSanitizer on pinned nightly-2026-05-28, macOS AArch64: 51/51 PASS
  • Shutdown repetition: 25/25 PASS
  • Raw-FD mutations caught: 5/5
  • Console restoration mutations caught: 4/4
  • Governed/local guest execution: NOT RUN (see the initial upstream-CI disclosure above)
  • Backend/profile admission: NOT PERFORMED

Measured changed-console-file coverage reproduces the retained result: 13/88 functions (14.772727%), 90/728 lines (12.362637%), and 156/1091 regions (14.298808%). port.rs remains 0/137 lines and process_tx.rs remains 0/91 lines.

Draft blockers

  • Add bounded library coverage for port.rs and process_tx.rs, or obtain explicit reviewer disposition of the retained zero-coverage blocker.
  • Run the upstream Linux-sysroot/default-init-blob build route and installed-library checks. The macOS gate intentionally uses libkrun --no-default-features --features blk and source-audits init behavior.
  • Add/complete fuzzing for the governed console and raw-FD boundaries.
  • Obtain independent human and CODEOWNER review.
  • Complete any later separately authorized owned-disposable-guest validation; the governed route authorizes and runs none, and the initial automatic upstream-CI execution is disclosed above rather than counted as evidence.
  • Complete any eventual distribution review for libkrunfw/kernel licensing, SBOM, signing, and provenance. Those components are unchanged and out of scope here.

Keep this PR draft until every required governed check and review blocker is resolved. A merge does not by itself admit a Capsule backend or profile.

Carry Capsule retained prerequisite patch SHA-256 a845cce3cd479a73c6a698164dc1b466e8d67796018b107077504478e0ec9cd5 so the signed bundle can resolve its colocated libkrunfw through the caller-controlled rpath.

This changes load location policy only; it does not establish firmware identity, bundle admission, or a trusted search path by itself.

Assisted-by: Codex: gpt-5.6-sol
Signed-off-by: Dylan Steele <dylansteele57@gmail.com>
Carry Capsule retained prerequisite patch SHA-256 b2120d4cc848e138a28165906d6c5cc4da1efee8004e392a7ddddc2334136823.

Recognize only the tested ro,nosuid,nodev profile and pass those generic VFS flags to mount(2). All other option strings retain upstream behavior; this does not generalize mount-option parsing or admit a root profile.

Assisted-by: Codex: gpt-5.6-sol
Signed-off-by: Dylan Steele <dylansteele57@gmail.com>
Carry Capsule P0-2 patch SHA-256 642d9e196cbb752347e06a8ce4ca35ea38ef94bf7e15ca9e1b136ed58229ef59.

Restrict the retained helper to the tested /dev/vda ext4 ro,nosuid,nodev profile, boot its manifest-bound init directly, and remove the NullFs bootstrap device from that route. This is removal evidence for one governed profile only, not broad virtiofs absence or backend admission.

Assisted-by: Codex: gpt-5.6-sol
Signed-off-by: Dylan Steele <dylansteele57@gmail.com>
Carry Capsule P0-1 patch SHA-256 48cdbc307b3fa1209fa0ec68fc3f817634af312983d68f0de259db86c0b43333.

Add the fixed runtime-root:vda:raw:read-only API, take duplicate ownership, verify exact finalized descriptor identity, and construct raw imago storage directly from File. Existing APIs remain unchanged. This is an additive patch candidate; signed installed App Sandbox custody and closed descriptor-manifest evidence remain required.

Assisted-by: Codex: gpt-5.6-sol
Signed-off-by: Dylan Steele <dylansteele57@gmail.com>
Carry Capsule P0-3 console patch SHA-256 584ce48548fe969684fe3c55e57fbf56e7dae40af28c241c24c47b138faf1283.

Reject malformed control shapes and unknown port IDs, suppress duplicate starts, make output waits stop-aware, signal shutdown before joins, and preserve partial-write progress. The retained low coverage, shared O_NONBLOCK caller flags, deprecated try_access use, and real transport/guest gaps remain explicit blockers.

Assisted-by: Codex: gpt-5.6-sol
Signed-off-by: Dylan Steele <dylansteele57@gmail.com>
Preserve the exact retained patch and mutation artifacts, provenance, review policy, update/removal rules, license and SBOM inputs, and the measured coverage blockers for the versioned downstream line.

Assisted-by: Codex: gpt-5.6-sol
Signed-off-by: Dylan Steele <dylansteele57@gmail.com>
Add narrowly routed reconstruction, source contract, Cargo, Clippy, ASan, repetition, mutation, and per-file coverage checks. Preserve the retained format and low-coverage results as explicit blockers instead of weakening the checks.

Assisted-by: Codex: gpt-5.6-sol
Signed-off-by: Dylan Steele <dylansteele57@gmail.com>
Keep the exact retained patch queue unchanged while fixing remote baseline resolution, deterministic formatting and Clippy validation, and no-guest workflow routing for the versioned governed baseline.

Assisted-by: Codex: gpt-5.6-sol
Signed-off-by: Dylan Steele <dylansteele57@gmail.com>
Run the governed blk corpus with one test thread so the exact retained clock-named raw-FD fixtures cannot collide on macOS. Keep every test, assertion, and retained patch byte unchanged.

Assisted-by: Codex: gpt-5.6-sol
Signed-off-by: Dylan Steele <dylansteele57@gmail.com>
@dills122
dills122 marked this pull request as ready for review August 3, 2026 20:55
@dills122
dills122 merged commit 4ea8d1d into capsule/upstream-v1.19.4 Aug 3, 2026
15 of 16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant