Extract shared directory lock helper from VMM identity managers - #8895
Conversation
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The refactor preserves existing semantics, retains manager-specific policies, and includes focused tests.
Review effort: Balanced
Findings: None
What changed in this PR
Extracts duplicated, security-sensitive directory locking into a shared helper while preserving manager-specific recovery and release behavior.
Changes:
- Adds a reusable directory-lock lifecycle helper and ownership types.
- Delegates Cloud Hypervisor and NVX locking to the helper.
- Adds focused coverage for acquisition, retries, cleanup, and errors.
| File | Description |
|---|---|
src/microvm/directory-lock.ts |
Implements the shared lock lifecycle. |
src/microvm/directory-lock.test.ts |
Tests locking behavior and failures. |
src/cloud-hypervisor/vmm-identity.ts |
Delegates VMM identity locking. |
src/nvx/runtime-lifecycle.ts |
Delegates NVX lifecycle locking. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
✅ Copilot review passed with no inline comments. @copilot Add the |
✅ Coverage Check PassedOverall Coverage
📁 Per-file Coverage Changes (4 files)
✨ New Files (1 files)
Coverage comparison generated by |
|
🔌 Smoke Services — All services reachable! ✅
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅ Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "o205451.ingest.us.sentry.io"
- "registry.npmjs.org"See Network Configuration for more information.
|
|
Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed. Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"
- "github.com"See Network Configuration for more information.
|
|
🚀 Security Guard has started processing this pull request |
|
✅ Smoke Claude passed Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
|
❌ Smoke Gemini reports failed. Facets need polishing...
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅ Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "api.github.com"
- "example.com"See Network Configuration for more information.
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
✅ Build Test Suite completed successfully! Warning Firewall blocked 8 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.nuget.org"
- "bun.sh"
- "dc.services.visualstudio.com"
- "deno.land"
- "dl.deno.land"
- "github.com"
- "releaseassets.githubusercontent.com"
- "repo.maven.apache.org"See Network Configuration for more information.
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟 Warning Firewall blocked 12 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"
- "accounts.google.com"
- "api.github.com"
- "clients2.google.com"
- "collector.github.com"
- "contentautofill.googleapis.com"
- "github.com"
- "github.githubassets.com"
- "msfeed25.pkgs.visualstudio.com"
- "update.googleapis.com"
- "www.google.com"
- "www.gstatic.com"See Network Configuration for more information.
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅ Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "api.github.com"
- "example.com"See Network Configuration for more information.
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "o205451.ingest.us.sentry.io"See Network Configuration for more information.
|
|
Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed. Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"
- "github.com"See Network Configuration for more information.
|
|
❌ Smoke Gemini reports failed. Facets need polishing...
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
🚀 Security Guard has started processing this pull request |
|
✅ Build Test Suite completed successfully! Warning Firewall blocked 8 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.nuget.org"
- "bun.sh"
- "dc.services.visualstudio.com"
- "deno.land"
- "dl.deno.land"
- "github.com"
- "releaseassets.githubusercontent.com"
- "repo.maven.apache.org"See Network Configuration for more information.
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
✅ Smoke Claude passed Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
|
EGRESS_RESULT allow=pass deny=pass ✅ Allowed domain (github.com): reachable (HTTP 200) Overall: PASS cc PR author Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "api.github.com"
- "example.com"See Network Configuration for more information.
|
Smoke Test: Claude Engine Validation
Overall result: PASS Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
Smoke Test: Cloud Hypervisor + Copilot
Overall: PASS Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"
- "github.com"See Network Configuration for more information.
|
|
Smoke Test: Copilot Engine —
Overall: PASS
|
|
Smoke Test: Copilot BYOK (Direct) Mode ✅ GitHub MCP Connectivity - Verified Status: PASS — Direct BYOK mode (COPILOT_PROVIDER_API_KEY) working correctly via api-proxy sidecar.
|
Smoke Test: Services Connectivity
Overall: PASS
|
Chroot Version Comparison Results
Overall result: ❌ Not all tests passed — Node.js version mismatch between host and chroot environments (host has a newer major version).
|
|
Smoke Test: API Proxy OTEL Tracing — all scenarios passed ✅
No unexpected failures found. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "o205451.ingest.us.sentry.io"See Network Configuration for more information.
|
🏗️ Build Test Suite Results
Overall: 8/8 ecosystems passed — ✅ PASS All 18 projects across Bun, C++, Deno, .NET, Go, Java, Node.js, and Rust built/ran successfully under the AWF firewall. No failures observed. Note: Maven required a writable Warning Firewall blocked 8 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.nuget.org"
- "bun.sh"
- "dc.services.visualstudio.com"
- "deno.land"
- "dl.deno.land"
- "github.com"
- "releaseassets.githubusercontent.com"
- "repo.maven.apache.org"See Network Configuration for more information.
|
|
chore: update model-to-API mapping (2026-09-23) Warning Firewall blocked 12 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"
- "accounts.google.com"
- "api.github.com"
- "clients2.google.com"
- "collector.github.com"
- "contentautofill.googleapis.com"
- "github.com"
- "github.githubassets.com"
- "msfeed25.pkgs.visualstudio.com"
- "update.googleapis.com"
- "www.google.com"
- "www.gstatic.com"See Network Configuration for more information.
|
The
mkdir-based lock acquisition loop was duplicated betweenCloudHypervisorVmmIdentityManagerand the NVX runtime lifecycle manager — ~28 identical lines in a security-sensitive path where lock ownership, timeout, and retry behavior could silently drift apart.Changes
src/microvm/directory-lock.ts—withDirectoryLock()owns the flow that was byte-for-byte identical: parent directorymkdirat0o711, process start-time resolution, owner record with a 16-byte nonce, themkdir/EEXISTretry loop, theowner.jsonwrite with{ flag: 'wx', mode: 0o600 }, deadline check, and retry sleep. Also exportsDirectoryLockOwnerandDirectoryLockDependencies.retryMs(ACCOUNT_LOCK_RETRY_MSvsLOCK_RETRY_MS) and the two error strings become options;reclaimStaleLockandremoveOwnedLockstay injected callbacks, so each manager keeps its own stale-lock strategy (reaper-directory claim vs rename-quarantine) and ownership-verified release unchanged.withLock()methods collapse to a delegating call.LockOwnerin the Cloud Hypervisor manager is now an alias ofDirectoryLockOwner; NVX's inline owner shape is replaced with it.src/microvm/directory-lock.test.tscovers the happy path, stale reclaim + retry, release when the operation throws, both caller-supplied error messages, and propagation of unexpectedmkdirerrors.Note on behavior
One pre-existing inconsistency is preserved rather than normalized:
reclaimStaleLockruns before the deadline check, so a contended lock is always offered for recovery at least once even after the timeout has elapsed. This is now documented on the helper since it is subtle and callers depend on it.