fix: filter workflow commands from microVM output - #7892
Conversation
Neutralize untrusted Actions command syntax at the runner-facing boundary. Retain bounded raw guest output for diagnostics and audit. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Legacy runner commands remain executable, and transport failures can discard buffered ordinary output.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review tier: Balanced
Findings: 1
New issues introduced by this change (2)
| Severity | Finding |
|---|---|
src/microvm/vsock-client.ts — This finalizer is only called for result/error frames and cancellation-grace expiry. Transport… |
|
src/microvm/workflow-command-filter.ts — This only neutralizes the ::...:: form, so a guest can still invoke the runner's legacy workflow… |
What changed in this PR
Adds host-side filtering and private auditing for untrusted microVM output.
Changes:
- Neutralizes workflow-command syntax across streamed output.
- Captures bounded raw stdout/stderr audit tails.
- Documents and tests filtering, backpressure, and persistence behavior.
| File | Description |
|---|---|
src/microvm/workflow-command-filter.ts |
Implements streaming command filtering. |
src/microvm/workflow-command-filter.test.ts |
Tests filtering edge cases. |
src/microvm/vsock-client.ts |
Filters presented output and captures raw bytes. |
src/microvm/vsock-client.test.ts |
Tests VSOCK filtering and finalization. |
src/cloud-hypervisor/manager.ts |
Manages bounded guest-output captures. |
src/cloud-hypervisor/manager.test.ts |
Tests capture and audit persistence. |
src/cloud-hypervisor/diagnostics.ts |
Writes private raw-output artifacts. |
src/cloud-hypervisor-runtime-backend.ts |
Enables filtering and audit collection. |
src/cloud-hypervisor-runtime-backend.test.ts |
Tests backend integration. |
docs/cloud-hypervisor-foundation.md |
Documents the output security boundary. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
| Metric | Base | PR | Delta |
|---|---|---|---|
| Lines | 93.86% | 93.92% | 📈 +0.06% |
| Statements | 92.67% | 92.68% | 📈 +0.01% |
| Functions | 93.24% | 93.19% | 📉 -0.05% |
| Branches | 86.14% | 86.17% | 📈 +0.03% |
📁 Per-file Coverage Changes (5 files)
| File | Lines (Before → After) | Statements (Before → After) |
|---|---|---|
src/microvm/vsock-client.ts |
97.3% → 96.3% (-1.05%) | 93.8% → 92.5% (-1.27%) |
src/cloud-hypervisor-runtime-backend.ts |
96.3% → 96.3% (+0.03%) | 93.5% → 93.5% (+0.05%) |
src/cloud-hypervisor/manager.ts |
88.9% → 89.4% (+0.50%) | 87.5% → 88.0% (+0.53%) |
src/cloud-hypervisor/diagnostics.ts |
84.7% → 87.2% (+2.53%) | 82.8% → 85.4% (+2.66%) |
src/log-directory-setup.ts |
96.2% → 100.0% (+3.78%) | 96.3% → 100.0% (+3.71%) |
✨ New Files (1 files)
src/microvm/workflow-command-filter.ts: 98.8% lines
Coverage comparison generated by scripts/ci/compare-coverage.ts
Neutralize legacy runner commands and flush filter state on transport failures. Add regression coverage for split commands, disconnects, and stream errors. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
✅ Copilot review passed with no inline comments. @lpcox Add the |
✅ Coverage Check PassedOverall Coverage
📁 Per-file Coverage Changes (5 files)
✨ New Files (1 files)
Coverage comparison generated by |
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
🚀 Security Guard has started processing this pull request |
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟 Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "msfeed25.pkgs.visualstudio.com"
- "registry.npmjs.org"See Network Configuration for more information.
|
|
✅ Smoke Copilot BYOK AOAI (api-key) completed. Copilot AOAI BYOK (api-key) mode operational. 🔓
|
|
❌ Smoke Gemini reports failed. Facets need polishing...
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"See Network Configuration for more information.
|
|
✅ Smoke Copilot BYOK AOAI (Entra) completed. Copilot AOAI BYOK (Entra) mode operational. 🔓
|
|
✅ Build Test Suite completed successfully!
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
📰 VERDICT: Smoke Docker Sbx has concluded. All systems operational. This is a developing story. 🎤
|
|
✅ Smoke Claude passed Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
❌ Contribution Check failed. Please review the logs for details.
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
EGRESS_RESULT allow=pass deny=pass ✅ Allowed domain (github.com) reachable: Overall: PASS cc @lpcox Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"See Network Configuration for more information.
|
|
Smoke Test: Copilot Engine — @lpcox
Overall: PASS
|
|
Smoke Test: Copilot BYOK (Direct Mode) ✅ PASS
Running in direct BYOK mode (COPILOT_PROVIDER_API_KEY)
|
Smoke Test: Claude Engine Validation
Overall result: PASS Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
|
fix(microvm): block legacy workflow commands Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "msfeed25.pkgs.visualstudio.com"
- "registry.npmjs.org"See Network Configuration for more information.
|
|
|
Smoke Test Results: Copilot BYOK (Direct) Mode
Test Results:
Running in direct BYOK mode (AWF_AUTH_TYPE=github-oidc + AWF_AUTH_AZURE_* + COPILOT_PROVIDER_BASE_URL) via api-proxy → Azure OpenAI (Foundry, o4-mini-aw) authenticated via Microsoft Entra. Overall: PASS
|
|
Smoke Test: Services Connectivity
Overall: FAIL — DNS resolution for
|
|
Smoke Test: Docker Sbx Validation
Overall: PASS cc @lpcox
|
Chroot Version Comparison
Overall: FAILED — Node.js version mismatch between host and chroot environments.
|
Smoke Test: API Proxy OpenTelemetry Tracing
Result: All 5 scenarios pass or are expected-pending. No issues found.
|
🏗️ Build Test Suite Results
Overall: 8/8 ecosystems passed — PASS Notes:
|


Summary
Validation
npm test -- --runInBand(330 suites, 5,285 tests)npm run type-checknpm run buildnpm run lintnpm run lint:md