fix(host): guard unqualified native VM operations - #88
Merged
Merged
Conversation
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Signed-off-by: NovusEdge <novusedge0@gmail.com>
Signed-off-by: NovusEdge <novusedge0@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Make the CLI build on macOS ARM64 and Windows AMD64, while refusing unqualified native VM operations before data-root setup, key or parameter resolution, stale runtime-file cleanup, or process startup. Help, version, and doctor remain available.
Separate Linux process identity and host checks from native refusal behavior, add a Windows xattr boundary, and keep metadata readers available. Native CI builds the CLI and executes lock, host-check, and refusal tests.
Why
Successful compilation must not expose the Linux QEMU/KVM runtime on an unqualified host. This prerequisite allows native development and diagnostics while keeping the runtime boundary explicit.
Depends on #79. The companion capability-discovery PR #78 has an independent early read-only dispatch; combined integration must preserve it before the guard.
Tests run
just checkand fulljust testat the production head61161f361161f361161f3: ready with no remaining findings61161f3Darwin ARM64, Windows AMD64, and Linux ARM64 CLI/installer cross-builds pass. The first hosted macOS run exposed an over-broad selector that also matched three Linux runtime tests;
90cb217anchors the expression to the intended native diagnostics, refusal, and capability cases. The next Windows run exposed a hostcheck fixture that omitted.exe;61161f3uses the platform-correct fake executable name without changing production lookup. Cross-builds do not qualify VM runtime support.OS matrix
No guest additions. Linux AMD64 lifecycle regression evidence is tracked in #87.
Docs
No native release archive, HVF/WHPX backend, ARM guest, firmware, or sharing support is introduced. Existing Linux ARM64 release assets are unchanged; that target remains build evidence with the existing x86-only runtime limitation. This remains a draft until hosted CI and #87 finish. Final human review and merge remain with the maintainer.