Skip to content

Document supported containment policy contracts - #1416

Open
Gudge (MGudgin) wants to merge 1 commit into
mainfrom
user/gudge/policy_docs
Open

Gudge (MGudgin) wants to merge 1 commit into
mainfrom
user/gudge/policy_docs

Conversation

@MGudgin

@MGudgin Gudge (MGudgin) commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

This PR adds policy-first guidance for supported 0.9.0-alpha and 1.0.0
containment contracts and the mutable V1 development contract. It separates
typed SDK authoring from exact raw JSON, and uses container terminology for
generic MXC instances without changing runtime behavior or wire identifiers.

Details

  • Document policy defaults, direct-egress rules, backend networking postures,
    and lifecycle support.
  • Keep the mutable development guide in v1-dev/ and reserve 1.1.0/ for
    published contract documentation.
  • Clarify the Windows vm experimental gate, WSLC's cooperative proxy,
    and development-only port mappings.
  • Show typed Node V1 policy authoring and link the consumer lifecycle guide.
  • Explain backend-specific apply/reject/ignore handling and distinguish typed
    ContainerId from the raw JSON sandboxId field.
  • Preserve concurrent WSLC exec behavior while aligning its
    documentation, test descriptions, and comments with container terminology.

Tests

  • cargo fmt --manifest-path src\Cargo.toml --all -- --check — passed.
  • PowerShell Parser.ParseFile on all three touched test scripts — passed.
  • Inline python - check — passed: 148 Markdown links and anchors across
    31 changed pages.
  • Inline Node.js schema check with Ajv — passed: seven policy JSON examples
    match their exact schemas.
  • git --no-pager diff --check origin/main...HEAD — passed.
  • Parsed the typed Node example and four lifecycle TypeScript
    snippets with TypeScript 6.0.3 — passed.
  • Verified the squashed tree equals the validated backup tree.
  • Rust build/unit tests and host-dependent backend suites — not run; this
    change affects documentation, comments, and test diagnostic text only.
Microsoft Reviewers: Open in CodeFlow

@MGudgin
Gudge (MGudgin) requested a review from a team as a code owner October 6, 2026 20:33
Copilot AI balanced review requested due to automatic review settings October 6, 2026 20:33
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The new contract pages misstate cross-platform containment defaults, WSLC proxy requirements, and the abstract vm selection.

Review effort: Balanced
Findings: 3 Low severity

Open (3)
What changed in this PR

Documents supported sandbox policy contracts and replaces retired policy references without runtime changes.

Changes:

  • Adds contract documentation for 0.9, 1.0, and development 1.1.
  • Removes retired 0.7/0.8 documentation.
  • Updates SDK, backend, and test references.
File Description
tests/​scripts/​run_lxc_network_no_network_test.sh Updates contract references.
tests/​scripts/​lib/​WinProcessContainer.Common.ps1 Updates networking reference.
src/​mxc-sdk/​src/​core/​mxc_common/​network_parser_ingress_default_tests.rs Updates test documentation.
src/​mxc-sdk/​src/​backends/​bubblewrap/​common/​network_rules.rs Updates policy citation.
sdk/​node/​README.md Links stable policy.
sdk/​dotnet/​README.md Links stable policy.
README.md Links policy index.
docs/​seatbelt/​seatbelt-backend.md Updates policy guidance.
docs/​schema.md Introduces versioned policy documentation.
docs/​sandbox-policy/​README.md Adds supported-contract index.
docs/​sandbox-policy/​1.1.0/​policy.md Documents development contract.
docs/​sandbox-policy/​1.0.0/​policy.md Documents stable contract.
docs/​sandbox-policy/​0.9.0/​policy.md Documents minimum supported contract.
docs/​sandbox-policy/​0.8.0/​policy.md Removes retired policy.
docs/​sandbox-policy/​0.8.0/​networking/​schema-updates.md Removes retired migration document.
docs/​sandbox-policy/​0.8.0/​networking/​networking.md Removes retired networking design.
docs/​sandbox-policy/​0.7.0/​policy.md Removes retired policy.
docs/​process-container/​os-version-support.md Updates stable-policy link.
docs/​process-container/​networking.md Updates shared-policy references.
docs/​process-container/​guide.md Updates prerequisites and legacy guidance.
docs/​process-container/​examples/​0.8.0-schema.md Redirects historical guidance.
docs/​examples.md Updates networking references.
docs/​authoring-a-new-feature.md Updates authoring references.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread docs/sandbox-policy/0.9.0/policy.md Outdated
Comment thread docs/sandbox-policy/1.0.0/policy.md Outdated
Comment thread docs/sandbox-policy/1.1.0/policy.md Outdated
Copilot AI balanced review requested due to automatic review settings October 6, 2026 20:56

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The documentation accurately reflects the registered exact contracts and removes stale references without affecting code behavior.

Review effort: Balanced
Findings: None

Resolved since last review (3)

Copilot AI balanced review requested due to automatic review settings October 6, 2026 23:04

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The documentation matches the registered exact contracts, and obsolete references were consistently removed.

Review effort: Balanced
Findings: None

Copilot AI balanced review requested due to automatic review settings October 6, 2026 23:22

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The development policy omits that vm requests on Windows require experimental authorization.

Review effort: Balanced
Findings: 1 Low severity

Open (1)

Comment thread docs/containment-configuration/1.1.0/policy.md Outdated
Comment thread docs/development/guides/authoring-a-new-feature.md Outdated
Comment thread docs/containment-configuration/1.1.0/policy.md Outdated
Comment thread docs/containment-configuration/1.0.0/policy.md Outdated
Copilot AI balanced review requested due to automatic review settings October 7, 2026 02:35

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The 1.1 guide incorrectly states that vm resolves to Windows Sandbox, while runtime dispatch rejects it as unimplemented.

Review effort: Balanced
Findings: 2 Low severity

Open (2)

Comment thread docs/containment-configuration/v1-dev/policy.md Outdated
Copilot AI balanced review requested due to automatic review settings October 7, 2026 15:42

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The documentation matches the registered exact contracts, parser defaults, SDK target, and backend validation behavior.

2 open findings

🧠 Review effort: Balanced

Copilot AI balanced review requested due to automatic review settings October 7, 2026 21:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The documented contract versions, lifecycle coverage, backend constraints, and relative links align with the registered contracts and validators.

2 open findings

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

@MGudgin Gudge (MGudgin) changed the title Document supported sandbox policy contracts Document supported containment policy contracts Oct 7, 2026
Copilot AI balanced review requested due to automatic review settings October 9, 2026 16:44

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The new guides incorrectly promise universal rejection of unenforceable policy and still conflate typed ContainerId APIs with raw sandboxId terminology.

5 open findings
2 resolved since last review

🧠 Review effort: Balanced

Comment thread docs/containment-configuration/0.9.0/policy.md Outdated
Comment thread docs/containment-configuration/1.0.0/policy.md Outdated
Comment thread docs/containment-configuration/README.md Outdated
Comment thread docs/containment-configuration/v1-dev/policy.md Outdated
Comment thread docs/development/architecture/container-lifecycle.md Outdated
Copilot AI balanced review requested due to automatic review settings October 9, 2026 18:08

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The documented contract behavior matches the registered schemas and runtime validation, with changes limited to documentation and diagnostic wording.

5 open findings

🧠 Review effort: Balanced

Copilot AI balanced review requested due to automatic review settings October 9, 2026 19:51

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The documentation matches the registered contracts and SDK surfaces, and the remaining changes are terminology-only.

0 open findings

5 resolved since last review

🧠 Review effort: Balanced

Copilot AI balanced review requested due to automatic review settings October 9, 2026 19:56

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The lifecycle architecture still documents unsupported Node AbortSignal and SandboxSpawnOptions APIs.

1 open finding

🧠 Review effort: Balanced

Comment thread docs/development/architecture/container-lifecycle.md Outdated
Copilot AI balanced review requested due to automatic review settings October 9, 2026 20:27

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The stable policy guide omits a port-range constraint and overstates LXC egress enforcement despite its documented raw-socket bypass.

2 open findings
1 resolved since last review

🧠 Review effort: Balanced

Comment thread docs/containment-configuration/1.0.0/policy.md Outdated
Comment thread docs/containment-configuration/1.0.0/policy.md Outdated
This PR adds policy-first guidance for the published 0.9.0-alpha and 1.0.0
contracts and the V1 development contract. It distinguishes typed SDK
authoring from raw JSON, documents backend-specific policy handling, and
aligns lifecycle guidance with supported SDK operations.

Details

* Describe network rules, backend postures, and WSLC port mappings with
  complete policy examples.
* Distinguish request shape from backend enforcement: policy fields can be
  applied, rejected, or ignored.
* Document port-range validation and the LXC raw-socket bypass of direct
  network rules for workloads that retain CAP_NET_RAW.
* Use ContainerId for typed lifecycle identities and sandboxId in raw
  envelopes, distinct from the creation containerId label.
* Align lifecycle options, type exports, exact-version fields, and error
  semantics with supported SDK and wire contracts.

Tests

* `cargo fmt --manifest-path src\Cargo.toml --all -- --check` passed.
* `node -` parsed 15 lifecycle TypeScript examples.
* `python -` checked 10 unchanged lifecycle JSON examples and Markdown
  targets, optional creation containment, WSLC version boundaries, and
  the network range and LXC limits against their implementation sources.
* `git diff --check origin/main...HEAD` passed.
* Backend runtime suites were not run (documentation and wording changes).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a30a59a8-e257-4e4b-9995-762f3611dabe
Generated-with: gpt-6-sol
Copilot AI balanced review requested due to automatic review settings October 9, 2026 20:35

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The documentation matches the registered contracts, SDK surfaces, and current backend validation behavior.

0 open findings

2 resolved since last review

🧠 Review effort: Balanced

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants