Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# The governed Capsule patch line requires review by the fork owner.
# This records governed ownership; sole-maintainer branch protection does not
# require CODEOWNER approval.
* @dills122

/governance/capsule-v1.19.4/ @dills122
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/capsule-governed.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ name: Capsule governed libkrun v1.19.4
on:
pull_request:
branches:
- capsule/upstream-v1.19.4
- "capsule/upstream-v1.19.4*"
paths:
- .github/CODEOWNERS
- .github/workflows/capsule-governed.yml
Expand All @@ -20,6 +20,7 @@ on:
branches:
- codex/governed-capsule-v1.19.4
- codex/governed-console-fd-coverage-v1.19.4
- codex/governed-console-control-validation-v1.19.4
paths:
- .github/CODEOWNERS
- .github/workflows/capsule-governed.yml
Expand Down
12 changes: 6 additions & 6 deletions .github/workflows/code-quality.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,15 +6,15 @@ jobs:
name: libkrun (Linux x86_64)
runs-on: ubuntu-26.04
env:
CAPSULE_DEPRECATED_LEVEL: ${{ github.base_ref == 'capsule/upstream-v1.19.4' && 'A' || 'D' }}
CAPSULE_DEPRECATED_LEVEL: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') && 'A' || 'D' }}
steps:
- uses: actions/checkout@v4

- name: Setup build environment
uses: ./.github/actions/setup-build-env

- name: Pin governed Clippy toolchain
if: github.base_ref == 'capsule/upstream-v1.19.4'
if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }}
run: |
rustup toolchain install 1.93.1 --profile minimal --component clippy
rustup default 1.93.1
Expand All @@ -38,15 +38,15 @@ jobs:
name: libkrun (Linux aarch64)
runs-on: ubuntu-26.04-arm
env:
CAPSULE_DEPRECATED_LEVEL: ${{ github.base_ref == 'capsule/upstream-v1.19.4' && 'A' || 'D' }}
CAPSULE_DEPRECATED_LEVEL: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') && 'A' || 'D' }}
steps:
- uses: actions/checkout@v4

- name: Setup build environment
uses: ./.github/actions/setup-build-env

- name: Pin governed Clippy toolchain
if: github.base_ref == 'capsule/upstream-v1.19.4'
if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }}
run: |
rustup toolchain install 1.93.1 --profile minimal --component clippy
rustup default 1.93.1
Expand All @@ -64,15 +64,15 @@ jobs:
name: libkrun (macOS aarch64)
runs-on: macos-latest
env:
CAPSULE_DEPRECATED_LEVEL: ${{ github.base_ref == 'capsule/upstream-v1.19.4' && 'A' || 'D' }}
CAPSULE_DEPRECATED_LEVEL: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') && 'A' || 'D' }}
steps:
- uses: actions/checkout@v4

- name: Setup build environment
uses: ./.github/actions/setup-build-env

- name: Pin governed Clippy toolchain
if: github.base_ref == 'capsule/upstream-v1.19.4'
if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }}
run: |
rustup toolchain install 1.93.1 --profile minimal --component clippy
rustup default 1.93.1
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/formatting.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,15 +15,15 @@ jobs:
run: find init -iname '*.h' -o -iname '*.c' | xargs clang-format -n -Werror

- name: Install governed formatting toolchain
if: github.base_ref == 'capsule/upstream-v1.19.4'
if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }}
run: rustup toolchain install 1.97.1 --profile minimal --component rustfmt

- name: Rust code formatting (governed profile)
if: github.base_ref == 'capsule/upstream-v1.19.4'
if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }}
run: governance/capsule-v1.19.4/scripts/verify-cargo-fmt.sh

- name: Rust code formatting
if: github.base_ref != 'capsule/upstream-v1.19.4'
if: ${{ !startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }}
run: cargo fmt -- --check

- name: Rust code formatting (examples)
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/integration_tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ on: [pull_request]
jobs:
integration-tests-x86_64:
name: Integration Tests (Linux x86_64)
if: github.base_ref != 'capsule/upstream-v1.19.4'
if: ${{ !startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }}
runs-on: ubuntu-26.04
steps:
- uses: actions/checkout@v4
Expand Down Expand Up @@ -74,7 +74,7 @@ jobs:

integration-tests-aarch64:
name: Integration Tests (Linux aarch64)
if: github.base_ref != 'capsule/upstream-v1.19.4'
if: ${{ !startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }}
runs-on: self-hosted
steps:
- uses: actions/checkout@v4
Expand Down
11 changes: 6 additions & 5 deletions governance/capsule-v1.19.4/PATCH_QUEUE.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,10 +8,11 @@
"commit": "728df8125077d0db44265f6e997c72b81b65c015"
},
"fork": {
"repository": "https://github.com/dills122/libkrun",
"baselineBranch": "capsule/upstream-v1.19.4",
"repository": "https://github.com/Shrimpworks/libkrun",
"baselineBranch": "capsule/baseline-v1.19.4-r1",
"baselineCommit": "4ea8d1de861ed1c0636fc800b6da8fb71a086aa5",
"workBranch": "codex/governed-console-fd-coverage-v1.19.4"
"historicalAcceptedHead": "cf0333cdba478cc34a8570a65b38412da7fd3ecc",
"candidateBranch": "capsule/upstream-v1.19.4-r3"
},
"capsuleEvidence": {
"repository": "https://github.com/dills122/capsule-corp",
Expand Down Expand Up @@ -57,9 +58,9 @@
],
"restorationMutations": [
{ "file": "mutations/restore-duplicate-start.patch", "sha256": "07dfafaf9008d8a0ec588fae398fa6363a3a2575ceb1f6efe36c3bb8344f412d" },
{ "file": "mutations/restore-malformed-control-acceptance.patch", "sha256": "197ec5b3d5e0b81728a841bfbdd2b38b0f895a98899f6c535694dfcde8434d8d" },
{ "file": "mutations/restore-malformed-control-acceptance.patch", "sha256": "b9f488b862f695d04406e7259e86cd461ae6be60f3b513cc52856621c86a6545" },
{ "file": "mutations/restore-stop-blind-output-wait.patch", "sha256": "59d63e70f74586c9c418718cb6b6ec16c1a63b8f23d82501edb38b46e33f44e6" },
{ "file": "mutations/restore-unchecked-port-id.patch", "sha256": "869e3b4c1959b2c8f7fa8eac919d82ed10ac932288125a15474d111cd7e44221" }
{ "file": "mutations/restore-unchecked-port-id.patch", "sha256": "d390f65363b965b95036f18908fb7359edf73e6b1cdee66718717a5083cccf2c" }
],
"governedSourcePaths": [
"include/libkrun.h",
Expand Down
19 changes: 11 additions & 8 deletions governance/capsule-v1.19.4/README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Capsule governed libkrun v1.19.4 patch line

This directory governs one narrowly scoped downstream patch queue over the immutable upstream libkrun v1.19.4 commit `728df8125077d0db44265f6e997c72b81b65c015`. The queue was merged as `4ea8d1de861ed1c0636fc800b6da8fb71a086aa5`, which is the immutable head of `capsule/upstream-v1.19.4`; follow-up coverage work uses `codex/governed-console-fd-coverage-v1.19.4`.
This directory governs one narrowly scoped downstream patch queue over the immutable upstream libkrun v1.19.4 commit `728df8125077d0db44265f6e997c72b81b65c015`. The queue was merged as `4ea8d1de861ed1c0636fc800b6da8fb71a086aa5` and is preserved by the locked `capsule/baseline-v1.19.4-r1` ref. The historical `capsule/upstream-v1.19.4` line ended at coverage follow-up merge `cf0333cdba478cc34a8570a65b38412da7fd3ecc` and is also locked. Later governed updates use a fresh versioned target branch based on the preceding accepted head.

This line is local library and source-governance evidence only. It does not admit a Capsule backend or profile, create or execute a guest, wire product code, change libkrunfw or a kernel, exercise a Supervisor, sign a release, or grant path, image, network, mount, write, or deployment authority.

Expand All @@ -18,13 +18,16 @@ The first two patches are prerequisites. They remain independently hashed and ar

## Review and branch policy

The upstream anchor and the governed merge are immutable. The baseline branch must remain at the exact governed merge commit and must never be rebased, force-pushed, or advanced. Updates use a new versioned baseline and work branch. Patch reconstruction always starts from the upstream anchor and compares the retained queue to the governed merge, so reviewed follow-up changes cannot rewrite its provenance.
The upstream anchor, retained patch-queue merge, and every accepted governed head are immutable. `capsule/baseline-v1.19.4-r1` must remain at the exact original governed merge and must never be rebased, force-pushed, or advanced. Each update starts a fresh versioned target branch from the preceding accepted head; after acceptance that target is locked and may become the fork default. Patch reconstruction always starts from the upstream anchor and compares the retained queue to the original governed merge, so reviewed follow-up changes cannot rewrite its provenance.

The fork's `main` branch is upstream-oriented integration state, not Capsule product state. A change merged only into `main` is unadopted by Capsule. Applicable fixes must be backported as logical commits through a separate governed pull request; never merge `main` wholesale into a governed line. Every pull request must name and read back its base and head explicitly.

Changes to this line require:

- a draft pull request targeting the exact versioned baseline;
- CODEOWNER review by `@dills122` and an independent human review before merge;
- DCO sign-off and the repository's required assistance trailer on every commit;
- a draft pull request targeting a fresh versioned branch created from the preceding accepted head;
- maintainer self-review with green required checks, resolved conversations, and exact evidence and settings readback;
- zero GitHub-required approving reviews, no most-recent-push approval, and no required CODEOWNER approval while `@dills122` is the only qualified maintainer; external approval enforcement may be enabled when a second qualified maintainer is available;
- separate human acceptance of DCO responsibility and the repository's required assistance trailer on every commit; automation must not add a human `Signed-off-by` trailer;
- exact patch reconstruction plus all governed checks in `scripts/verify-governed.sh`;
- explicit resolution of the blockers below; and
- no force-push after review begins unless reviewers are told exactly what changed.
Expand All @@ -33,11 +36,11 @@ A green workflow is necessary but not sufficient for merge. The PR stays draft w

## CI routing

`.github/workflows/capsule-governed.yml` runs only for the versioned governed branch, pull requests targeting the versioned baseline, manual dispatch, and changes to this exact patch line or its touched source paths. It adds no exception to upstream checks. The governed checks use fixed local fixtures and library/unit processes only; the scripts reject opt-in guest execution.
`.github/workflows/capsule-governed.yml` runs only for versioned governed work branches, pull requests targeting a `capsule/upstream-v1.19.4*` branch, manual dispatch, and changes to this exact patch line or its touched source paths. It adds no exception to upstream checks. The governed checks use fixed local fixtures and library/unit processes only; the scripts reject opt-in guest execution.

The governed wrapper is an offline library-only gate and does not bootstrap a Linux sysroot. `scripts/verify-default-init.sh` remains a standalone, fail-closed probe for a pre-provisioned exact sysroot and cross-toolchain. The existing upstream macOS cross-compilation job provisions that environment and runs `make` with the default Linux init blob, without executing a guest; its result is the pull request's build evidence for that route.

The upstream integration workflow is precisely routed away from pull requests whose base is `capsule/upstream-v1.19.4`, because it installs firmware and executes guests. All other pull requests retain upstream integration behavior. The governed replacement performs no guest execution. Governed Clippy uses the retained Rust 1.93.1 toolchain with only the documented deprecated `GuestMemory::try_access` allowance. Rust 1.97.1 formatting must report exactly the one retained P0-2 line-wrap drift recorded in `expected/cargo-fmt-1.97.1.txt`; any additional difference fails CI. The 53-test `blk` corpus runs with one test thread because two exact retained raw-FD tests use a clock-derived temporary name that can collide under parallel execution on macOS. Serial routing preserves every assertion and the exact retained source bytes. This preserves exact retained patch bytes without silently exempting another path.
The upstream integration workflow is precisely routed away from pull requests whose base starts with `capsule/upstream-v1.19.4`, because it installs firmware and executes guests. All other pull requests retain upstream integration behavior. The governed replacement performs no guest execution. Governed Clippy uses the retained Rust 1.93.1 toolchain with only the documented deprecated `GuestMemory::try_access` allowance. Rust 1.97.1 formatting must report exactly the one retained P0-2 line-wrap drift recorded in `expected/cargo-fmt-1.97.1.txt`; any additional difference fails CI. The 55-test `blk` corpus runs with one test thread because two exact retained raw-FD tests use a clock-derived temporary name that can collide under parallel execution on macOS. Serial routing preserves every assertion and the exact retained source bytes. This preserves exact retained patch bytes without silently exempting another path.

The default upstream test surface is intentionally preserved. Where the governed direct-block-root profile conflicts with unmodified upstream NullFs behavior, the difference is isolated to this queue and its `blk` feature tests instead of disabling or weakening an upstream security check.

Expand All @@ -58,6 +61,6 @@ The compile-only C header contract treats the pre-existing `/dev/input/*` text i
- No installed-product, real-guest, VMM transport, fuzzing, backend-admission, signing, firmware, kernel, or Supervisor evidence is produced here.
- The raw-FD contract is validated with Rust library tests, source-route mutations, and a compile-only C header contract. It is not runtime guest evidence.
- libkrunfw and kernel license/source obligations remain outside this patch line and must be resolved by any eventual distributor.
- Independent human/CODEOWNER review remains required.
- Zero GitHub approval enforcement does not satisfy or waive later independent product-admission review, DCO acceptance, or final upstream-submission authorization.

Security reports for upstream behavior should follow the private contact documented by upstream. Capsule-specific review must not disclose credentials, proprietary user data, or third-party targets.
Original file line number Diff line number Diff line change
@@ -1,8 +1,6 @@
diff --git a/src/devices/src/virtio/console/device.rs b/src/devices/src/virtio/console/device.rs
--- a/src/devices/src/virtio/console/device.rs
+++ b/src/devices/src/virtio/console/device.rs
@@ -28,3 +28,3 @@ fn control_descriptor_shape_valid(len: u32, write_only: bool, chained: bool) -> bool {
fn control_descriptor_shape_valid(len: u32, write_only: bool, chained: bool) -> bool {
- !write_only && !chained && len as usize == size_of::<VirtioConsoleControl>()
+ let _ = (len, write_only, chained); true
}
@@ -71 +71 @@ fn read_control_command(
- if readable_len != size_of::<VirtioConsoleControl>() {
+ if false && readable_len != size_of::<VirtioConsoleControl>() {
Original file line number Diff line number Diff line change
@@ -1,11 +1,9 @@
diff --git a/src/devices/src/virtio/console/device.rs b/src/devices/src/virtio/console/device.rs
--- a/src/devices/src/virtio/console/device.rs
+++ b/src/devices/src/virtio/console/device.rs
@@ -32,5 +32,4 @@ fn checked_port_index(port_count: usize, port_id: u32) -> Option<usize> {
fn checked_port_index(port_count: usize, port_id: u32) -> Option<usize> {
- usize::try_from(port_id)
- .ok()
- .filter(|port_id| *port_id < port_count)
+ let _ = port_count;
+ usize::try_from(port_id).ok()
}
@@ -271,4 +271 @@ impl Console {
- let Some(port) = self.ports.get(cmd.id as usize) else {
- log::warn!("Guest reported unknown console port {} ready", cmd.id);
- continue;
- };
+ let port = &self.ports[cmd.id as usize];
8 changes: 4 additions & 4 deletions governance/capsule-v1.19.4/scripts/verify-library.sh
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ default_log="$task_tmp/default-tests.log"
CARGO_NET_OFFLINE=true CARGO_TARGET_DIR="$target_dir/tests" \
cargo test --locked --offline -p krun-devices --lib
) | tee "$default_log"
grep -Eq 'test result: ok\. 51 passed; 0 failed' "$default_log"
grep -Eq 'test result: ok\. 53 passed; 0 failed' "$default_log"

bounded_console_log="$task_tmp/bounded-console-tests.log"
(
Expand All @@ -55,7 +55,7 @@ blk_log="$task_tmp/blk-tests.log"
cargo test --locked --offline -p krun-devices --lib --features blk -- \
--test-threads=1
) | tee "$blk_log"
grep -Eq 'test result: ok\. 53 passed; 0 failed' "$blk_log"
grep -Eq 'test result: ok\. 55 passed; 0 failed' "$blk_log"

raw_fd_log="$task_tmp/raw-fd-tests.log"
(
Expand Down Expand Up @@ -145,9 +145,9 @@ fi
printf 'governedConsoleRustfmt=PASS\n'
printf 'cargoFmt=PASS_EXACT_RETAINED_DRIFT_ONLY\n'
printf 'cargoCheck=PASS\n'
printf 'consoleCorpusTests=51\n'
printf 'consoleCorpusTests=53\n'
printf 'boundedConsoleCoverageTests=4\n'
printf 'blockFeatureTests=53\n'
printf 'blockFeatureTests=55\n'
printf 'rawFdContractTests=2\n'
printf 'rawFdLibraryBoundaryTests=2\n'
printf 'clippyWarningsDenied=PASS\n'
Expand Down
4 changes: 2 additions & 2 deletions governance/capsule-v1.19.4/scripts/verify-mutations.sh
Original file line number Diff line number Diff line change
Expand Up @@ -82,9 +82,9 @@ run_console_mutation() {
}

run_console_mutation restore-malformed-control-acceptance \
virtio::console::device::tests::control_descriptor_requires_one_exact_readable_object
virtio::console::device::tests::invalid_control_chains_are_completed_without_side_effects
run_console_mutation restore-unchecked-port-id \
virtio::console::device::tests::port_index_rejects_unknown_identifiers
virtio::console::device::tests::unknown_port_ids_are_completed_without_side_effects
run_console_mutation restore-duplicate-start \
virtio::console::device::tests::repeated_or_active_port_start_is_not_scheduled_twice
run_console_mutation restore-stop-blind-output-wait \
Expand Down
4 changes: 2 additions & 2 deletions governance/capsule-v1.19.4/scripts/verify-patch-queue.sh
Original file line number Diff line number Diff line change
Expand Up @@ -37,9 +37,9 @@ expected_hash_for() {

git -C "$repo_dir" cat-file -e "$upstream_commit^{commit}"
git -C "$repo_dir" cat-file -e "$governed_base_commit^{commit}"
actual_base=$(git -C "$repo_dir" rev-parse --verify refs/heads/capsule/upstream-v1.19.4 2>/dev/null || git -C "$repo_dir" rev-parse --verify refs/remotes/origin/capsule/upstream-v1.19.4)
actual_base=$(git -C "$repo_dir" rev-parse --verify refs/heads/capsule/baseline-v1.19.4-r1 2>/dev/null || git -C "$repo_dir" rev-parse --verify refs/remotes/origin/capsule/baseline-v1.19.4-r1)
[ "$actual_base" = "$governed_base_commit" ] || {
printf 'governed baseline branch moved: got %s, want %s\n' "$actual_base" "$governed_base_commit" >&2
printf 'governed immutable baseline moved: got %s, want %s\n' "$actual_base" "$governed_base_commit" >&2
exit 1
}

Expand Down
Loading
Loading