diff --git a/.github/workflows/capsule-governed.yml b/.github/workflows/capsule-governed.yml index e796d12a3b..5d4265b919 100644 --- a/.github/workflows/capsule-governed.yml +++ b/.github/workflows/capsule-governed.yml @@ -3,36 +3,14 @@ name: Capsule governed libkrun v1.19.4 on: pull_request: branches: - - "capsule/upstream-v1.19.4*" - paths: - - .github/CODEOWNERS - - .github/workflows/capsule-governed.yml - - governance/capsule-v1.19.4/** - - include/libkrun.h - - src/devices/src/virtio/block/device.rs - - src/devices/src/virtio/console/** - - src/init_blob/init/init.c - - src/libkrun/src/lib.rs - - src/libkrun/tests/** - - src/vmm/src/resources.rs - - src/vmm/src/vmm_config/block.rs + - "capsule/upstream-v1.19.4-r*" + - "capsule/review-v1.19.4-r*" + - "capsule/accepted-v1.19.4-r*" push: branches: - - codex/governed-capsule-v1.19.4 - - codex/governed-console-fd-coverage-v1.19.4 - - codex/governed-console-control-validation-v1.19.4 - paths: - - .github/CODEOWNERS - - .github/workflows/capsule-governed.yml - - governance/capsule-v1.19.4/** - - include/libkrun.h - - src/devices/src/virtio/block/device.rs - - src/devices/src/virtio/console/** - - src/init_blob/init/init.c - - src/libkrun/src/lib.rs - - src/libkrun/tests/** - - src/vmm/src/resources.rs - - src/vmm/src/vmm_config/block.rs + - "capsule/upstream-v1.19.4-r*" + - "capsule/review-v1.19.4-r*" + - "capsule/accepted-v1.19.4-r*" workflow_dispatch: permissions: @@ -44,7 +22,7 @@ concurrency: jobs: governed-library: - name: No-guest governed library gates + name: Governed admission runs-on: macos-15 timeout-minutes: 45 env: diff --git a/.github/workflows/code-quality.yml b/.github/workflows/code-quality.yml index 1a90c46241..0b84fba104 100644 --- a/.github/workflows/code-quality.yml +++ b/.github/workflows/code-quality.yml @@ -6,7 +6,7 @@ jobs: name: libkrun (Linux x86_64) runs-on: ubuntu-26.04 env: - CAPSULE_DEPRECATED_LEVEL: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') && 'A' || 'D' }} + CAPSULE_DEPRECATED_LEVEL: ${{ (startsWith(github.base_ref, 'capsule/upstream-v1.19.4') || startsWith(github.base_ref, 'capsule/review-v1.19.4-r') || startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r')) && 'A' || 'D' }} steps: - uses: actions/checkout@v4 @@ -14,7 +14,7 @@ jobs: uses: ./.github/actions/setup-build-env - name: Pin governed Clippy toolchain - if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }} + if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') || startsWith(github.base_ref, 'capsule/review-v1.19.4-r') || startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r') }} run: | rustup toolchain install 1.93.1 --profile minimal --component clippy rustup default 1.93.1 @@ -38,7 +38,7 @@ jobs: name: libkrun (Linux aarch64) runs-on: ubuntu-26.04-arm env: - CAPSULE_DEPRECATED_LEVEL: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') && 'A' || 'D' }} + CAPSULE_DEPRECATED_LEVEL: ${{ (startsWith(github.base_ref, 'capsule/upstream-v1.19.4') || startsWith(github.base_ref, 'capsule/review-v1.19.4-r') || startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r')) && 'A' || 'D' }} steps: - uses: actions/checkout@v4 @@ -46,7 +46,7 @@ jobs: uses: ./.github/actions/setup-build-env - name: Pin governed Clippy toolchain - if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }} + if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') || startsWith(github.base_ref, 'capsule/review-v1.19.4-r') || startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r') }} run: | rustup toolchain install 1.93.1 --profile minimal --component clippy rustup default 1.93.1 @@ -64,7 +64,7 @@ jobs: name: libkrun (macOS aarch64) runs-on: macos-latest env: - CAPSULE_DEPRECATED_LEVEL: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') && 'A' || 'D' }} + CAPSULE_DEPRECATED_LEVEL: ${{ (startsWith(github.base_ref, 'capsule/upstream-v1.19.4') || startsWith(github.base_ref, 'capsule/review-v1.19.4-r') || startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r')) && 'A' || 'D' }} steps: - uses: actions/checkout@v4 @@ -72,7 +72,7 @@ jobs: uses: ./.github/actions/setup-build-env - name: Pin governed Clippy toolchain - if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }} + if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') || startsWith(github.base_ref, 'capsule/review-v1.19.4-r') || startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r') }} run: | rustup toolchain install 1.93.1 --profile minimal --component clippy rustup default 1.93.1 diff --git a/.github/workflows/formatting.yml b/.github/workflows/formatting.yml index 880a502b7b..f36c4fb1a1 100644 --- a/.github/workflows/formatting.yml +++ b/.github/workflows/formatting.yml @@ -15,15 +15,15 @@ jobs: run: find init -iname '*.h' -o -iname '*.c' | xargs clang-format -n -Werror - name: Install governed formatting toolchain - if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }} + if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4-r') || startsWith(github.base_ref, 'capsule/review-v1.19.4-r') || startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r') }} run: rustup toolchain install 1.97.1 --profile minimal --component rustfmt - name: Rust code formatting (governed profile) - if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }} + if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4-r') || startsWith(github.base_ref, 'capsule/review-v1.19.4-r') || startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r') }} run: governance/capsule-v1.19.4/scripts/verify-cargo-fmt.sh - name: Rust code formatting - if: ${{ !startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }} + if: ${{ !startsWith(github.base_ref, 'capsule/upstream-v1.19.4-r') && !startsWith(github.base_ref, 'capsule/review-v1.19.4-r') && !startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r') }} run: cargo fmt -- --check - name: Rust code formatting (examples) diff --git a/.github/workflows/integration_tests.yml b/.github/workflows/integration_tests.yml index 37312d2568..03d3505f97 100644 --- a/.github/workflows/integration_tests.yml +++ b/.github/workflows/integration_tests.yml @@ -4,7 +4,7 @@ on: [pull_request] jobs: integration-tests-x86_64: name: Integration Tests (Linux x86_64) - if: ${{ !startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }} + if: ${{ !startsWith(github.base_ref, 'capsule/upstream-v1.19.4') && !startsWith(github.base_ref, 'capsule/review-v1.19.4-r') && !startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r') }} runs-on: ubuntu-26.04 steps: - uses: actions/checkout@v4 @@ -74,7 +74,7 @@ jobs: integration-tests-aarch64: name: Integration Tests (Linux aarch64) - if: ${{ !startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }} + if: ${{ !startsWith(github.base_ref, 'capsule/upstream-v1.19.4') && !startsWith(github.base_ref, 'capsule/review-v1.19.4-r') && !startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r') }} runs-on: self-hosted steps: - uses: actions/checkout@v4 diff --git a/governance/capsule-v1.19.4/README.md b/governance/capsule-v1.19.4/README.md index aca98406ca..2faed0c193 100644 --- a/governance/capsule-v1.19.4/README.md +++ b/governance/capsule-v1.19.4/README.md @@ -1,6 +1,6 @@ # Capsule governed libkrun v1.19.4 patch line -This directory governs one narrowly scoped downstream patch queue over the immutable upstream libkrun v1.19.4 commit `728df8125077d0db44265f6e997c72b81b65c015`. The queue was merged as `4ea8d1de861ed1c0636fc800b6da8fb71a086aa5` and is preserved by the locked `capsule/baseline-v1.19.4-r1` ref. The historical `capsule/upstream-v1.19.4` line ended at coverage follow-up merge `cf0333cdba478cc34a8570a65b38412da7fd3ecc` and is also locked. Later governed updates use a fresh versioned target branch based on the preceding accepted head. +This directory governs one narrowly scoped downstream patch queue over the immutable upstream libkrun v1.19.4 commit `728df8125077d0db44265f6e997c72b81b65c015`. The queue was merged as `4ea8d1de861ed1c0636fc800b6da8fb71a086aa5` and is preserved by the locked `capsule/baseline-v1.19.4-r1` ref. The historical `capsule/upstream-v1.19.4` line ended at coverage follow-up merge `cf0333cdba478cc34a8570a65b38412da7fd3ecc` and is also locked. The current accepted/default line is `capsule/upstream-v1.19.4-r3` at `7432eda5a49220976b0167005aa43ee622f9d632`, accepted from reviewed head `445df8823a9aa46f7121db8a24a4deac530989aa`. The current mutable target is `capsule/review-v1.19.4-r4`, created at the exact accepted commit `7432eda5a49220976b0167005aa43ee622f9d632`. Later governed updates use a fresh versioned target branch based on the preceding accepted head. This line is local library and source-governance evidence only. It does not admit a Capsule backend or profile, create or execute a guest, wire product code, change libkrunfw or a kernel, exercise a Supervisor, sign a release, or grant path, image, network, mount, write, or deployment authority. @@ -36,11 +36,15 @@ A green workflow is necessary but not sufficient for merge. The PR stays draft w ## CI routing -`.github/workflows/capsule-governed.yml` runs only for versioned governed work branches, pull requests targeting a `capsule/upstream-v1.19.4*` branch, manual dispatch, and changes to this exact patch line or its touched source paths. It adds no exception to upstream checks. The governed checks use fixed local fixtures and library/unit processes only; the scripts reject opt-in guest execution. +`.github/workflows/capsule-governed.yml` runs for current/future versioned governed review and accepted targets, manual dispatch, and no other branch family. It has no path filter, so every pull request to a protected governed target emits the stable `Governed admission` context. The governed checks use fixed local fixtures and library/unit processes only; the scripts reject opt-in guest execution. + +The repository formatting workflow recognizes the same three versioned governed target families +and routes them through `verify-cargo-fmt.sh`. It does not substitute ordinary moving-toolchain +formatting for the retained exact Rust 1.97.1 drift contract. The governed wrapper is an offline library-only gate and does not bootstrap a Linux sysroot. `scripts/verify-default-init.sh` remains a standalone, fail-closed probe for a pre-provisioned exact sysroot and cross-toolchain. The existing upstream macOS cross-compilation job provisions that environment and runs `make` with the default Linux init blob, without executing a guest; its result is the pull request's build evidence for that route. -The upstream integration workflow is precisely routed away from pull requests whose base starts with `capsule/upstream-v1.19.4`, because it installs firmware and executes guests. All other pull requests retain upstream integration behavior. The governed replacement performs no guest execution. Governed Clippy uses the retained Rust 1.93.1 toolchain with only the documented deprecated `GuestMemory::try_access` allowance. Rust 1.97.1 formatting must report exactly the one retained P0-2 line-wrap drift recorded in `expected/cargo-fmt-1.97.1.txt`; any additional difference fails CI. The 55-test `blk` corpus runs with one test thread because two exact retained raw-FD tests use a clock-derived temporary name that can collide under parallel execution on macOS. Serial routing preserves every assertion and the exact retained source bytes. This preserves exact retained patch bytes without silently exempting another path. +The upstream integration workflow is precisely routed away from pull requests whose base is a versioned `capsule/upstream-v1.19.4*`, `capsule/review-v1.19.4-r*`, or `capsule/accepted-v1.19.4-r*` target, because it installs firmware and executes guests. All other pull requests retain upstream integration behavior. The governed replacement performs no guest execution. Governed Clippy uses the retained Rust 1.93.1 toolchain with only the documented deprecated `GuestMemory::try_access` allowance. Rust 1.97.1 formatting must report exactly the one retained P0-2 line-wrap drift recorded in `expected/cargo-fmt-1.97.1.txt`; any additional difference fails CI. The 55-test `blk` corpus runs with one test thread because two exact retained raw-FD tests use a clock-derived temporary name that can collide under parallel execution on macOS. Serial routing preserves every assertion and the exact retained source bytes. This preserves exact retained patch bytes without silently exempting another path. The default upstream test surface is intentionally preserved. Where the governed direct-block-root profile conflicts with unmodified upstream NullFs behavior, the difference is isolated to this queue and its `blk` feature tests instead of disabling or weakening an upstream security check.