Skip to content

fix(host): guard unqualified native VM operations - #88

Merged
NovusEdge merged 7 commits into
mainfrom
codex/native-build-guard
Sep 6, 2026
Merged

NovusEdge merged 7 commits into
mainfrom
codex/native-build-guard

Conversation

@NovusEdge

@NovusEdge NovusEdge commented Sep 6, 2026 •

Copy link
Copy Markdown
Owner

What changed

Make the CLI build on macOS ARM64 and Windows AMD64, while refusing unqualified native VM operations before data-root setup, key or parameter resolution, stale runtime-file cleanup, or process startup. Help, version, and doctor remain available.

Separate Linux process identity and host checks from native refusal behavior, add a Windows xattr boundary, and keep metadata readers available. Native CI builds the CLI and executes lock, host-check, and refusal tests.

Why

Successful compilation must not expose the Linux QEMU/KVM runtime on an unqualified host. This prerequisite allows native development and diagnostics while keeping the runtime boundary explicit.

Depends on #79. The companion capability-discovery PR #78 has an independent early read-only dispatch; combined integration must preserve it before the guard.

Tests run

  • just check and full just test at the production head
  • Exact CI lint and ShellCheck path through Nix: 0 issues
  • Focused native-refusal, capability-discovery, and hostcheck fixture tests at 61161f3
  • Darwin ARM64 and Windows AMD64 package test compilation at 61161f3
  • Independent Sol-high terminal review, including final selector and fixture-only corrections at 61161f3: ready with no remaining findings
  • Hosted macOS/Windows CI on 61161f3
  • Fresh Linux AMD64 lifecycle regression gate: Run the native-guard Linux lifecycle regression gate #87

Darwin ARM64, Windows AMD64, and Linux ARM64 CLI/installer cross-builds pass. The first hosted macOS run exposed an over-broad selector that also matched three Linux runtime tests; 90cb217 anchors the expression to the intended native diagnostics, refusal, and capability cases. The next Windows run exposed a hostcheck fixture that omitted .exe; 61161f3 uses the platform-correct fake executable name without changing production lookup. Cross-builds do not qualify VM runtime support.

OS matrix

No guest additions. Linux AMD64 lifecycle regression evidence is tracked in #87.

Docs

  • Unsupported native installer diagnostics explain the Linux requirement.

No native release archive, HVF/WHPX backend, ARM guest, firmware, or sharing support is introduced. Existing Linux ARM64 release assets are unchanged; that target remains build evidence with the existing x86-only runtime limitation. This remains a draft until hosted CI and #87 finish. Final human review and merge remain with the maintainer.

Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
@NovusEdge NovusEdge added enhancement New feature needs-live-boot Cannot be verified by agents; needs a real Alpine boot labels Sep 6, 2026
@NovusEdge NovusEdge self-assigned this Sep 6, 2026
@coderabbitai

coderabbitai Bot commented Sep 6, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
@NovusEdge
NovusEdge marked this pull request as ready for review September 6, 2026 10:56
@NovusEdge
NovusEdge merged commit 22089a2 into main Sep 6, 2026
6 checks passed
@NovusEdge
NovusEdge deleted the codex/native-build-guard branch September 6, 2026 10:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature needs-live-boot Cannot be verified by agents; needs a real Alpine boot

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant