Skip to content

test(e2e): complete mixed-image rolling-upgrade coverage#820

Open
kvinwang wants to merge 8 commits into
masterfrom
fix/full-stack-local-pccs
Open

test(e2e): complete mixed-image rolling-upgrade coverage#820
kvinwang wants to merge 8 commits into
masterfrom
fix/full-stack-local-pccs

Conversation

@kvinwang

Copy link
Copy Markdown
Collaborator

Summary

Follow-up to #819. The production TDX run exposed additional harness gaps after Local-Key-Provider became healthy. This PR:

  • waits for a VM to be conclusively stopped before restarting it;
  • provisions traceable v0.5.11/current guest images and measurement archives;
  • uses a legacy-compatible manifest for the v0.5.11 guest;
  • authorizes both exact OS image hashes;
  • preserves durable Gateway state while ignoring transient WireGuard addresses;
  • audits the mixed-image policy and verified artifact paths without assuming an onboarding cache miss.

Verification

  • prek run --all-files
  • saved-state audit from the real TDX/SGX run: current archive GET=1, v0.5.11 archive GET=2, exact two-image allowlist, no disabled verification path, both KMS app keys present
  • a clean full real-hardware rerun is in progress

Artifacts used:

  • meta-dstack v0.5.11 archive SHA-256: 6f95a2a0b59975780e6f5d8bfbf016d50148092889554e4f8272c401ee549e42
  • v0.5.11 image digest: c2aa0186182fe8a404f16d5f3facb334d89be32703b3571c401b114a8b6e700d
  • current image digest: 91bc72e3ca6f283cc0549d761ee436d381d1e8c4ddc4c23354e05c9bbccfdec1

Copilot AI review requested due to automatic review settings July 23, 2026 06:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants