Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/workflows/capsule-governed.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,11 +13,13 @@ on:
- src/devices/src/virtio/console/**
- src/init_blob/init/init.c
- src/libkrun/src/lib.rs
- src/libkrun/tests/**
- src/vmm/src/resources.rs
- src/vmm/src/vmm_config/block.rs
push:
branches:
- codex/governed-capsule-v1.19.4
- codex/governed-console-fd-coverage-v1.19.4
paths:
- .github/CODEOWNERS
- .github/workflows/capsule-governed.yml
Expand All @@ -27,6 +29,7 @@ on:
- src/devices/src/virtio/console/**
- src/init_blob/init/init.c
- src/libkrun/src/lib.rs
- src/libkrun/tests/**
- src/vmm/src/resources.rs
- src/vmm/src/vmm_config/block.rs
workflow_dispatch:
Expand Down
3 changes: 2 additions & 1 deletion governance/capsule-v1.19.4/PATCH_QUEUE.json
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,8 @@
"fork": {
"repository": "https://github.com/dills122/libkrun",
"baselineBranch": "capsule/upstream-v1.19.4",
"workBranch": "codex/governed-capsule-v1.19.4"
"baselineCommit": "4ea8d1de861ed1c0636fc800b6da8fb71a086aa5",
"workBranch": "codex/governed-console-fd-coverage-v1.19.4"
},
"capsuleEvidence": {
"repository": "https://github.com/dills122/capsule-corp",
Expand Down
11 changes: 7 additions & 4 deletions governance/capsule-v1.19.4/README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Capsule governed libkrun v1.19.4 patch line

This directory governs one narrowly scoped downstream patch queue over the immutable upstream libkrun v1.19.4 commit `728df8125077d0db44265f6e997c72b81b65c015`. The baseline branch is `capsule/upstream-v1.19.4`; the proposed work branch is `codex/governed-capsule-v1.19.4`.
This directory governs one narrowly scoped downstream patch queue over the immutable upstream libkrun v1.19.4 commit `728df8125077d0db44265f6e997c72b81b65c015`. The queue was merged as `4ea8d1de861ed1c0636fc800b6da8fb71a086aa5`, which is the immutable head of `capsule/upstream-v1.19.4`; follow-up coverage work uses `codex/governed-console-fd-coverage-v1.19.4`.

This line is local library and source-governance evidence only. It does not admit a Capsule backend or profile, create or execute a guest, wire product code, change libkrunfw or a kernel, exercise a Supervisor, sign a release, or grant path, image, network, mount, write, or deployment authority.

Expand All @@ -18,7 +18,7 @@ The first two patches are prerequisites. They remain independently hashed and ar

## Review and branch policy

The baseline branch is an immutable pointer to the exact upstream tag commit. It must never be rebased, force-pushed, or advanced. Updates use a new versioned baseline and work branch.
The upstream anchor and the governed merge are immutable. The baseline branch must remain at the exact governed merge commit and must never be rebased, force-pushed, or advanced. Updates use a new versioned baseline and work branch. Patch reconstruction always starts from the upstream anchor and compares the retained queue to the governed merge, so reviewed follow-up changes cannot rewrite its provenance.

Changes to this line require:

Expand All @@ -35,6 +35,8 @@ A green workflow is necessary but not sufficient for merge. The PR stays draft w

`.github/workflows/capsule-governed.yml` runs only for the versioned governed branch, pull requests targeting the versioned baseline, manual dispatch, and changes to this exact patch line or its touched source paths. It adds no exception to upstream checks. The governed checks use fixed local fixtures and library/unit processes only; the scripts reject opt-in guest execution.

The governed wrapper is an offline library-only gate and does not bootstrap a Linux sysroot. `scripts/verify-default-init.sh` remains a standalone, fail-closed probe for a pre-provisioned exact sysroot and cross-toolchain. The existing upstream macOS cross-compilation job provisions that environment and runs `make` with the default Linux init blob, without executing a guest; its result is the pull request's build evidence for that route.

The upstream integration workflow is precisely routed away from pull requests whose base is `capsule/upstream-v1.19.4`, because it installs firmware and executes guests. All other pull requests retain upstream integration behavior. The governed replacement performs no guest execution. Governed Clippy uses the retained Rust 1.93.1 toolchain with only the documented deprecated `GuestMemory::try_access` allowance. Rust 1.97.1 formatting must report exactly the one retained P0-2 line-wrap drift recorded in `expected/cargo-fmt-1.97.1.txt`; any additional difference fails CI. The 53-test `blk` corpus runs with one test thread because two exact retained raw-FD tests use a clock-derived temporary name that can collide under parallel execution on macOS. Serial routing preserves every assertion and the exact retained source bytes. This preserves exact retained patch bytes without silently exempting another path.

The default upstream test surface is intentionally preserved. Where the governed direct-block-root profile conflicts with unmodified upstream NullFs behavior, the difference is isolated to this queue and its `blk` feature tests instead of disabling or weakening an upstream security check.
Expand All @@ -49,9 +51,10 @@ The compile-only C header contract treats the pre-existing `/dev/input/*` text i

## Known blockers and limitations

- The measured retained console corpus has zero line/function coverage in `port.rs` and `process_tx.rs`; `coverage-baseline.json` preserves this rather than hiding it. Bounded library tests must close or explicitly review this gap before merge.
- `coverage-baseline.json` preserves the original zero line/function coverage in `port.rs` and `process_tx.rs`. The follow-up bounded library corpus must report exact before/after measurements without rewriting that baseline evidence.
- `coverage-followup.json` records the bounded follow-up measurement and the remaining uncovered functions, lines, and regions for those two files.
- AddressSanitizer is supported only on the pinned macOS AArch64 nightly/toolchain route and remains a required governed check there.
- The macOS library gate checks and lints `libkrun` with `blk` and without its default embedded init-blob feature. Compiling the Linux init blob requires the upstream Linux sysroot/cross-toolchain route; this fork supplements, but does not disable, that upstream build gate and retains an installed-build blocker until it passes.
- The macOS library gate checks and lints `libkrun` with `blk` and without its default embedded init-blob feature. The standalone no-network default-init probe remains blocked when its exact pre-provisioned Linux sysroot/cross-toolchain is absent; the pull request's upstream macOS cross-compilation job must independently pass the default-init build route.
- No installed-product, real-guest, VMM transport, fuzzing, backend-admission, signing, firmware, kernel, or Supervisor evidence is produced here.
- The raw-FD contract is validated with Rust library tests, source-route mutations, and a compile-only C header contract. It is not runtime guest evidence.
- libkrunfw and kernel license/source obligations remain outside this patch line and must be resolved by any eventual distributor.
Expand Down
55 changes: 55 additions & 0 deletions governance/capsule-v1.19.4/coverage-followup.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
{
"status": "local library coverage only; not real transport, guest, VMM, or admission evidence",
"sourceEvidenceDate": "2026-08-03",
"governedBaseCommit": "4ea8d1de861ed1c0636fc800b6da8fb71a086aa5",
"corpus": {
"retainedDefaultTests": 51,
"retainedBlockFeatureTests": 53,
"boundedConsolePropertyTests": 4,
"rawFdLibraryBoundaryTests": 2
},
"before": {
"aggregateChangedConsoleFiles": {
"functions": { "count": 88, "covered": 13, "percent": 14.772727 },
"lines": { "count": 728, "covered": 90, "percent": 12.362637 },
"regions": { "count": 1091, "covered": 156, "percent": 14.298808 }
},
"files": [
{
"file": "src/devices/src/virtio/console/port.rs",
"functions": { "count": 17, "covered": 0, "percent": 0.0 },
"lines": { "count": 137, "covered": 0, "percent": 0.0 },
"regions": { "count": 172, "covered": 0, "percent": 0.0 }
},
{
"file": "src/devices/src/virtio/console/process_tx.rs",
"functions": { "count": 4, "covered": 0, "percent": 0.0 },
"lines": { "count": 91, "covered": 0, "percent": 0.0 },
"regions": { "count": 120, "covered": 0, "percent": 0.0 }
}
]
},
"after": {
"aggregateChangedConsoleFiles": {
"functions": { "count": 88, "covered": 37, "percent": 42.045455 },
"lines": { "count": 733, "covered": 298, "percent": 40.654843 },
"regions": { "count": 1099, "covered": 399, "percent": 36.305732 }
},
"files": [
{
"file": "src/devices/src/virtio/console/port.rs",
"functions": { "count": 17, "covered": 15, "percent": 88.235294 },
"lines": { "count": 137, "covered": 111, "percent": 81.021898 },
"regions": { "count": 173, "covered": 121, "percent": 69.942197 },
"remaining": { "functions": 2, "lines": 26, "regions": 52 }
},
{
"file": "src/devices/src/virtio/console/process_tx.rs",
"functions": { "count": 4, "covered": 4, "percent": 100.0 },
"lines": { "count": 96, "covered": 82, "percent": 85.416667 },
"regions": { "count": 127, "covered": 102, "percent": 80.314961 },
"remaining": { "functions": 0, "lines": 14, "regions": 25 }
}
]
}
}
56 changes: 56 additions & 0 deletions governance/capsule-v1.19.4/scripts/verify-default-init.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
#!/bin/sh
set -eu

script_dir=$(CDPATH='' cd -- "$(dirname -- "$0")" && pwd)
governance_dir=$(CDPATH='' cd -- "$script_dir/.." && pwd)
repo_dir=$(CDPATH='' cd -- "$governance_dir/../.." && pwd)
task_tmp=$(mktemp -d "${TMPDIR:-/tmp}/libkrun-capsule-default-init.XXXXXX")
trap 'rm -rf "$task_tmp"' EXIT HUP INT TERM

if [ "${CAPSULE_ALLOW_GUEST:-0}" != 0 ]; then
printf 'guest execution is outside this governed verification route\n' >&2
exit 2
fi

case "$(uname -s)" in
Darwin)
sysroot=${SYSROOT_LINUX:-$repo_dir/linux-sysroot}
if [ ! -f "$sysroot/.sysroot_ready" ]; then
printf 'defaultInitBlobBuild=BLOCKED\n'
printf 'defaultInitBlobReason=exact Linux sysroot is unavailable for the no-network macOS cross-build\n'
printf 'defaultInitBlobSysroot=%s\n' "$sysroot"
printf 'guestExecution=NOT_RUN\n'
exit 1
fi
arch=$(uname -m | sed 's/^arm64$/aarch64/')
gcc_triplet="$arch-linux-gnu"
gcc_version=${GCC_VERSION:-12}
gcc_lib_dir="$sysroot/usr/lib/gcc/$gcc_triplet/$gcc_version"
if [ ! -d "$gcc_lib_dir" ] || ! command -v /usr/bin/clang >/dev/null 2>&1 || ! command -v ld.lld >/dev/null 2>&1; then
printf 'defaultInitBlobBuild=BLOCKED\n'
printf 'defaultInitBlobReason=exact clang-lld Linux cross-toolchain is unavailable\n'
printf 'guestExecution=NOT_RUN\n'
exit 1
fi
cc_linux="/usr/bin/clang -target $gcc_triplet -fuse-ld=lld -Wl,-strip-debug --sysroot $sysroot -B$gcc_lib_dir -L$gcc_lib_dir -Wno-c23-extensions"
;;
Linux)
cc_linux=${CC_LINUX:-${CC:-cc}}
;;
*)
printf 'defaultInitBlobBuild=BLOCKED\n'
printf 'defaultInitBlobReason=unsupported host for the upstream Linux default-init build route\n'
printf 'guestExecution=NOT_RUN\n'
exit 1
;;
esac

(
cd "$repo_dir"
CARGO_NET_OFFLINE=true CARGO_TARGET_DIR="$task_tmp/target" CC_LINUX="$cc_linux" \
cargo build --locked --offline -p libkrun --lib --features blk
)

printf 'defaultInitBlobBuild=PASS\n'
printf 'defaultInitBlobNetwork=DISABLED\n'
printf 'guestExecution=NOT_RUN\n'
50 changes: 49 additions & 1 deletion governance/capsule-v1.19.4/scripts/verify-library.sh
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,15 @@ default_log="$task_tmp/default-tests.log"
) | tee "$default_log"
grep -Eq 'test result: ok\. 51 passed; 0 failed' "$default_log"

bounded_console_log="$task_tmp/bounded-console-tests.log"
(
cd "$repo_dir"
CARGO_NET_OFFLINE=true CARGO_TARGET_DIR="$target_dir/tests" \
cargo test --locked --offline -p krun-devices --lib \
virtio::console::coverage_tests -- --ignored --test-threads=1
) | tee "$bounded_console_log"
grep -Eq 'test result: ok\. 4 passed; 0 failed' "$bounded_console_log"

blk_log="$task_tmp/blk-tests.log"
(
cd "$repo_dir"
Expand All @@ -48,6 +57,15 @@ blk_log="$task_tmp/blk-tests.log"
) | tee "$blk_log"
grep -Eq 'test result: ok\. 53 passed; 0 failed' "$blk_log"

raw_fd_log="$task_tmp/raw-fd-tests.log"
(
cd "$repo_dir"
CARGO_NET_OFFLINE=true CARGO_TARGET_DIR="$target_dir/tests-libkrun" \
cargo test --locked --offline -p libkrun --test governed_fd \
--no-default-features --features blk -- --test-threads=1
) | tee "$raw_fd_log"
grep -Eq 'test result: ok\. 2 passed; 0 failed' "$raw_fd_log"

(
cd "$repo_dir"
CARGO_NET_OFFLINE=true CARGO_TARGET_DIR="$target_dir/clippy" \
Expand All @@ -56,6 +74,9 @@ grep -Eq 'test result: ok\. 53 passed; 0 failed' "$blk_log"
CARGO_NET_OFFLINE=true CARGO_TARGET_DIR="$target_dir/clippy-libkrun" \
cargo clippy --locked --offline -p libkrun --lib --no-default-features --features blk --no-deps -- \
-D warnings
CARGO_NET_OFFLINE=true CARGO_TARGET_DIR="$target_dir/clippy-libkrun-tests" \
cargo clippy --locked --offline -p libkrun --test governed_fd \
--no-default-features --features blk --no-deps -- -D warnings
)

repeat=1
Expand All @@ -70,13 +91,25 @@ while [ "$repeat" -le 25 ]; do
repeat=$((repeat + 1))
done

repeat=1
while [ "$repeat" -le 25 ]; do
(
cd "$repo_dir"
CARGO_NET_OFFLINE=true CARGO_TARGET_DIR="$target_dir/tests" \
cargo test --locked --offline -p krun-devices --lib \
virtio::console::coverage_tests::shutdown_cancels_a_queued_backpressured_write \
-- --exact --ignored --test-threads=1 >/dev/null 2>&1
)
repeat=$((repeat + 1))
done

coverage_raw="$task_tmp/coverage.json"
coverage_summary="$task_tmp/coverage-summary.json"
(
cd "$repo_dir"
CARGO_NET_OFFLINE=true CARGO_TARGET_DIR="$target_dir/coverage" \
cargo llvm-cov --locked --offline -p krun-devices --lib \
--json --output-path "$coverage_raw"
--json --output-path "$coverage_raw" -- --include-ignored --test-threads=1
)
python3 "$script_dir/summarize-coverage.py" "$coverage_raw" "$coverage_summary"
if [ -n "${CAPSULE_COVERAGE_OUTPUT:-}" ]; then
Expand All @@ -93,6 +126,18 @@ if [ "$(uname -s)" = Darwin ] && [ "$(uname -m)" = arm64 ]; then
CARGO_TARGET_DIR="$target_dir/asan" \
cargo +"$sanitizer_toolchain" test --locked --target aarch64-apple-darwin \
--offline -p krun-devices --lib
CARGO_NET_OFFLINE=true \
CARGO_TARGET_AARCH64_APPLE_DARWIN_RUSTFLAGS=-Zsanitizer=address \
CARGO_TARGET_DIR="$target_dir/asan" \
cargo +"$sanitizer_toolchain" test --locked --target aarch64-apple-darwin \
--offline -p krun-devices --lib virtio::console::coverage_tests -- \
--ignored --test-threads=1
CARGO_NET_OFFLINE=true \
CARGO_TARGET_AARCH64_APPLE_DARWIN_RUSTFLAGS=-Zsanitizer=address \
CARGO_TARGET_DIR="$target_dir/asan-libkrun" \
cargo +"$sanitizer_toolchain" test --locked --target aarch64-apple-darwin \
--offline -p libkrun --test governed_fd --no-default-features --features blk -- \
--test-threads=1
)
asan_status=PASS
fi
Expand All @@ -101,11 +146,14 @@ printf 'governedConsoleRustfmt=PASS\n'
printf 'cargoFmt=PASS_EXACT_RETAINED_DRIFT_ONLY\n'
printf 'cargoCheck=PASS\n'
printf 'consoleCorpusTests=51\n'
printf 'boundedConsoleCoverageTests=4\n'
printf 'blockFeatureTests=53\n'
printf 'rawFdContractTests=2\n'
printf 'rawFdLibraryBoundaryTests=2\n'
printf 'clippyWarningsDenied=PASS\n'
printf 'clippyAllowance=deprecated-GuestMemory-try_access-only\n'
printf 'shutdownRepetitions=25\n'
printf 'queuedBackpressureShutdownRepetitions=25\n'
printf 'addressSanitizer=%s\n' "$asan_status"
cat "$coverage_summary"
printf 'guestExecution=NOT_RUN\n'
19 changes: 12 additions & 7 deletions governance/capsule-v1.19.4/scripts/verify-patch-queue.sh
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,8 @@ set -eu
script_dir=$(CDPATH='' cd -- "$(dirname -- "$0")" && pwd)
governance_dir=$(CDPATH='' cd -- "$script_dir/.." && pwd)
repo_dir=$(CDPATH='' cd -- "$governance_dir/../.." && pwd)
base_commit=728df8125077d0db44265f6e997c72b81b65c015
upstream_commit=728df8125077d0db44265f6e997c72b81b65c015
governed_base_commit=4ea8d1de861ed1c0636fc800b6da8fb71a086aa5
patch_set_sha256=d19fd0ff159c699acccda2621519de45a09408bf3847b418ac34e02b79e805d5

patches='0001-pin-libkrunfw-rpath.patch
Expand Down Expand Up @@ -34,18 +35,19 @@ expected_hash_for() {
esac
}

git -C "$repo_dir" cat-file -e "$base_commit^{commit}"
git -C "$repo_dir" cat-file -e "$upstream_commit^{commit}"
git -C "$repo_dir" cat-file -e "$governed_base_commit^{commit}"
actual_base=$(git -C "$repo_dir" rev-parse --verify refs/heads/capsule/upstream-v1.19.4 2>/dev/null || git -C "$repo_dir" rev-parse --verify refs/remotes/origin/capsule/upstream-v1.19.4)
[ "$actual_base" = "$base_commit" ] || {
printf 'baseline branch moved: got %s, want %s\n' "$actual_base" "$base_commit" >&2
[ "$actual_base" = "$governed_base_commit" ] || {
printf 'governed baseline branch moved: got %s, want %s\n' "$actual_base" "$governed_base_commit" >&2
exit 1
}

task_tmp=$(mktemp -d "${TMPDIR:-/tmp}/libkrun-capsule-patches.XXXXXX")
trap 'rm -rf "$task_tmp"' EXIT HUP INT TERM
reconstructed="$task_tmp/reconstructed"
mkdir -p "$reconstructed"
git -C "$repo_dir" archive "$base_commit" | tar -x -C "$reconstructed"
git -C "$repo_dir" archive "$upstream_commit" | tar -x -C "$reconstructed"

identity_file="$task_tmp/identities"
: >"$identity_file"
Expand All @@ -70,7 +72,9 @@ actual_patch_set=$(shasum -a 256 "$identity_file" | awk '{print $1}')
}

for governed_path in $governed_paths; do
cmp "$reconstructed/$governed_path" "$repo_dir/$governed_path"
governed_base_path="$task_tmp/governed-base"
git -C "$repo_dir" show "$governed_base_commit:$governed_path" >"$governed_base_path"
cmp "$reconstructed/$governed_path" "$governed_base_path"
done

for patch_name in \
Expand All @@ -82,7 +86,8 @@ for patch_name in \
patch -d "$reconstructed" -p1 --batch --reverse --dry-run <"$governance_dir/patches/$patch_name" >/dev/null
done

printf 'baseCommit=%s\n' "$base_commit"
printf 'upstreamCommit=%s\n' "$upstream_commit"
printf 'governedBaseCommit=%s\n' "$governed_base_commit"
printf 'patchSetSha256=%s\n' "$actual_patch_set"
printf 'cleanReconstruction=PASS\n'
printf 'reverseDryRun=PASS\n'
Expand Down
Loading
Loading