Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
36 changes: 7 additions & 29 deletions .github/workflows/capsule-governed.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,36 +3,14 @@ name: Capsule governed libkrun v1.19.4
on:
pull_request:
branches:
- "capsule/upstream-v1.19.4*"
paths:
- .github/CODEOWNERS
- .github/workflows/capsule-governed.yml
- governance/capsule-v1.19.4/**
- include/libkrun.h
- src/devices/src/virtio/block/device.rs
- src/devices/src/virtio/console/**
- src/init_blob/init/init.c
- src/libkrun/src/lib.rs
- src/libkrun/tests/**
- src/vmm/src/resources.rs
- src/vmm/src/vmm_config/block.rs
- "capsule/upstream-v1.19.4-r*"
- "capsule/review-v1.19.4-r*"
- "capsule/accepted-v1.19.4-r*"
push:
branches:
- codex/governed-capsule-v1.19.4
- codex/governed-console-fd-coverage-v1.19.4
- codex/governed-console-control-validation-v1.19.4
paths:
- .github/CODEOWNERS
- .github/workflows/capsule-governed.yml
- governance/capsule-v1.19.4/**
- include/libkrun.h
- src/devices/src/virtio/block/device.rs
- src/devices/src/virtio/console/**
- src/init_blob/init/init.c
- src/libkrun/src/lib.rs
- src/libkrun/tests/**
- src/vmm/src/resources.rs
- src/vmm/src/vmm_config/block.rs
- "capsule/upstream-v1.19.4-r*"
- "capsule/review-v1.19.4-r*"
- "capsule/accepted-v1.19.4-r*"
workflow_dispatch:

permissions:
Expand All @@ -44,7 +22,7 @@ concurrency:

jobs:
governed-library:
name: No-guest governed library gates
name: Governed admission
runs-on: macos-15
timeout-minutes: 45
env:
Expand Down
12 changes: 6 additions & 6 deletions .github/workflows/code-quality.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,15 +6,15 @@ jobs:
name: libkrun (Linux x86_64)
runs-on: ubuntu-26.04
env:
CAPSULE_DEPRECATED_LEVEL: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') && 'A' || 'D' }}
CAPSULE_DEPRECATED_LEVEL: ${{ (startsWith(github.base_ref, 'capsule/upstream-v1.19.4') || startsWith(github.base_ref, 'capsule/review-v1.19.4-r') || startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r')) && 'A' || 'D' }}
steps:
- uses: actions/checkout@v4

- name: Setup build environment
uses: ./.github/actions/setup-build-env

- name: Pin governed Clippy toolchain
if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }}
if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') || startsWith(github.base_ref, 'capsule/review-v1.19.4-r') || startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r') }}
run: |
rustup toolchain install 1.93.1 --profile minimal --component clippy
rustup default 1.93.1
Expand All @@ -38,15 +38,15 @@ jobs:
name: libkrun (Linux aarch64)
runs-on: ubuntu-26.04-arm
env:
CAPSULE_DEPRECATED_LEVEL: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') && 'A' || 'D' }}
CAPSULE_DEPRECATED_LEVEL: ${{ (startsWith(github.base_ref, 'capsule/upstream-v1.19.4') || startsWith(github.base_ref, 'capsule/review-v1.19.4-r') || startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r')) && 'A' || 'D' }}
steps:
- uses: actions/checkout@v4

- name: Setup build environment
uses: ./.github/actions/setup-build-env

- name: Pin governed Clippy toolchain
if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }}
if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') || startsWith(github.base_ref, 'capsule/review-v1.19.4-r') || startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r') }}
run: |
rustup toolchain install 1.93.1 --profile minimal --component clippy
rustup default 1.93.1
Expand All @@ -64,15 +64,15 @@ jobs:
name: libkrun (macOS aarch64)
runs-on: macos-latest
env:
CAPSULE_DEPRECATED_LEVEL: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') && 'A' || 'D' }}
CAPSULE_DEPRECATED_LEVEL: ${{ (startsWith(github.base_ref, 'capsule/upstream-v1.19.4') || startsWith(github.base_ref, 'capsule/review-v1.19.4-r') || startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r')) && 'A' || 'D' }}
steps:
- uses: actions/checkout@v4

- name: Setup build environment
uses: ./.github/actions/setup-build-env

- name: Pin governed Clippy toolchain
if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }}
if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') || startsWith(github.base_ref, 'capsule/review-v1.19.4-r') || startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r') }}
run: |
rustup toolchain install 1.93.1 --profile minimal --component clippy
rustup default 1.93.1
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/formatting.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,15 +15,15 @@ jobs:
run: find init -iname '*.h' -o -iname '*.c' | xargs clang-format -n -Werror

- name: Install governed formatting toolchain
if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }}
if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4-r') || startsWith(github.base_ref, 'capsule/review-v1.19.4-r') || startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r') }}
run: rustup toolchain install 1.97.1 --profile minimal --component rustfmt

- name: Rust code formatting (governed profile)
if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }}
if: ${{ startsWith(github.base_ref, 'capsule/upstream-v1.19.4-r') || startsWith(github.base_ref, 'capsule/review-v1.19.4-r') || startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r') }}
run: governance/capsule-v1.19.4/scripts/verify-cargo-fmt.sh

- name: Rust code formatting
if: ${{ !startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }}
if: ${{ !startsWith(github.base_ref, 'capsule/upstream-v1.19.4-r') && !startsWith(github.base_ref, 'capsule/review-v1.19.4-r') && !startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r') }}
run: cargo fmt -- --check

- name: Rust code formatting (examples)
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/integration_tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ on: [pull_request]
jobs:
integration-tests-x86_64:
name: Integration Tests (Linux x86_64)
if: ${{ !startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }}
if: ${{ !startsWith(github.base_ref, 'capsule/upstream-v1.19.4') && !startsWith(github.base_ref, 'capsule/review-v1.19.4-r') && !startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r') }}
runs-on: ubuntu-26.04
steps:
- uses: actions/checkout@v4
Expand Down Expand Up @@ -74,7 +74,7 @@ jobs:

integration-tests-aarch64:
name: Integration Tests (Linux aarch64)
if: ${{ !startsWith(github.base_ref, 'capsule/upstream-v1.19.4') }}
if: ${{ !startsWith(github.base_ref, 'capsule/upstream-v1.19.4') && !startsWith(github.base_ref, 'capsule/review-v1.19.4-r') && !startsWith(github.base_ref, 'capsule/accepted-v1.19.4-r') }}
runs-on: self-hosted
steps:
- uses: actions/checkout@v4
Expand Down
10 changes: 7 additions & 3 deletions governance/capsule-v1.19.4/README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Capsule governed libkrun v1.19.4 patch line

This directory governs one narrowly scoped downstream patch queue over the immutable upstream libkrun v1.19.4 commit `728df8125077d0db44265f6e997c72b81b65c015`. The queue was merged as `4ea8d1de861ed1c0636fc800b6da8fb71a086aa5` and is preserved by the locked `capsule/baseline-v1.19.4-r1` ref. The historical `capsule/upstream-v1.19.4` line ended at coverage follow-up merge `cf0333cdba478cc34a8570a65b38412da7fd3ecc` and is also locked. Later governed updates use a fresh versioned target branch based on the preceding accepted head.
This directory governs one narrowly scoped downstream patch queue over the immutable upstream libkrun v1.19.4 commit `728df8125077d0db44265f6e997c72b81b65c015`. The queue was merged as `4ea8d1de861ed1c0636fc800b6da8fb71a086aa5` and is preserved by the locked `capsule/baseline-v1.19.4-r1` ref. The historical `capsule/upstream-v1.19.4` line ended at coverage follow-up merge `cf0333cdba478cc34a8570a65b38412da7fd3ecc` and is also locked. The current accepted/default line is `capsule/upstream-v1.19.4-r3` at `7432eda5a49220976b0167005aa43ee622f9d632`, accepted from reviewed head `445df8823a9aa46f7121db8a24a4deac530989aa`. The current mutable target is `capsule/review-v1.19.4-r4`, created at the exact accepted commit `7432eda5a49220976b0167005aa43ee622f9d632`. Later governed updates use a fresh versioned target branch based on the preceding accepted head.

This line is local library and source-governance evidence only. It does not admit a Capsule backend or profile, create or execute a guest, wire product code, change libkrunfw or a kernel, exercise a Supervisor, sign a release, or grant path, image, network, mount, write, or deployment authority.

Expand Down Expand Up @@ -36,11 +36,15 @@ A green workflow is necessary but not sufficient for merge. The PR stays draft w

## CI routing

`.github/workflows/capsule-governed.yml` runs only for versioned governed work branches, pull requests targeting a `capsule/upstream-v1.19.4*` branch, manual dispatch, and changes to this exact patch line or its touched source paths. It adds no exception to upstream checks. The governed checks use fixed local fixtures and library/unit processes only; the scripts reject opt-in guest execution.
`.github/workflows/capsule-governed.yml` runs for current/future versioned governed review and accepted targets, manual dispatch, and no other branch family. It has no path filter, so every pull request to a protected governed target emits the stable `Governed admission` context. The governed checks use fixed local fixtures and library/unit processes only; the scripts reject opt-in guest execution.

The repository formatting workflow recognizes the same three versioned governed target families
and routes them through `verify-cargo-fmt.sh`. It does not substitute ordinary moving-toolchain
formatting for the retained exact Rust 1.97.1 drift contract.

The governed wrapper is an offline library-only gate and does not bootstrap a Linux sysroot. `scripts/verify-default-init.sh` remains a standalone, fail-closed probe for a pre-provisioned exact sysroot and cross-toolchain. The existing upstream macOS cross-compilation job provisions that environment and runs `make` with the default Linux init blob, without executing a guest; its result is the pull request's build evidence for that route.

The upstream integration workflow is precisely routed away from pull requests whose base starts with `capsule/upstream-v1.19.4`, because it installs firmware and executes guests. All other pull requests retain upstream integration behavior. The governed replacement performs no guest execution. Governed Clippy uses the retained Rust 1.93.1 toolchain with only the documented deprecated `GuestMemory::try_access` allowance. Rust 1.97.1 formatting must report exactly the one retained P0-2 line-wrap drift recorded in `expected/cargo-fmt-1.97.1.txt`; any additional difference fails CI. The 55-test `blk` corpus runs with one test thread because two exact retained raw-FD tests use a clock-derived temporary name that can collide under parallel execution on macOS. Serial routing preserves every assertion and the exact retained source bytes. This preserves exact retained patch bytes without silently exempting another path.
The upstream integration workflow is precisely routed away from pull requests whose base is a versioned `capsule/upstream-v1.19.4*`, `capsule/review-v1.19.4-r*`, or `capsule/accepted-v1.19.4-r*` target, because it installs firmware and executes guests. All other pull requests retain upstream integration behavior. The governed replacement performs no guest execution. Governed Clippy uses the retained Rust 1.93.1 toolchain with only the documented deprecated `GuestMemory::try_access` allowance. Rust 1.97.1 formatting must report exactly the one retained P0-2 line-wrap drift recorded in `expected/cargo-fmt-1.97.1.txt`; any additional difference fails CI. The 55-test `blk` corpus runs with one test thread because two exact retained raw-FD tests use a clock-derived temporary name that can collide under parallel execution on macOS. Serial routing preserves every assertion and the exact retained source bytes. This preserves exact retained patch bytes without silently exempting another path.

The default upstream test surface is intentionally preserved. Where the governed direct-block-root profile conflicts with unmodified upstream NullFs behavior, the difference is isolated to this queue and its `blk` feature tests instead of disabling or weakening an upstream security check.

Expand Down
Loading