Repository navigation
Document supported containment policy contracts - #1416
Open
Gudge (MGudgin) wants to merge 1 commit into
Open
Gudge (MGudgin) wants to merge 1 commit into
Gudge (MGudgin) wants to merge 1 commit into
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The new contract pages misstate cross-platform containment defaults, WSLC proxy requirements, and the abstract vm selection.
Review effort: Balanced
Findings: 3
Open (3)
What changed in this PR
Documents supported sandbox policy contracts and replaces retired policy references without runtime changes.
Changes:
- Adds contract documentation for 0.9, 1.0, and development 1.1.
- Removes retired 0.7/0.8 documentation.
- Updates SDK, backend, and test references.
| File | Description |
|---|---|
tests/scripts/run_lxc_network_no_network_test.sh |
Updates contract references. |
tests/scripts/lib/WinProcessContainer.Common.ps1 |
Updates networking reference. |
src/mxc-sdk/src/core/mxc_common/network_parser_ingress_default_tests.rs |
Updates test documentation. |
src/mxc-sdk/src/backends/bubblewrap/common/network_rules.rs |
Updates policy citation. |
sdk/node/README.md |
Links stable policy. |
sdk/dotnet/README.md |
Links stable policy. |
README.md |
Links policy index. |
docs/seatbelt/seatbelt-backend.md |
Updates policy guidance. |
docs/schema.md |
Introduces versioned policy documentation. |
docs/sandbox-policy/README.md |
Adds supported-contract index. |
docs/sandbox-policy/1.1.0/policy.md |
Documents development contract. |
docs/sandbox-policy/1.0.0/policy.md |
Documents stable contract. |
docs/sandbox-policy/0.9.0/policy.md |
Documents minimum supported contract. |
docs/sandbox-policy/0.8.0/policy.md |
Removes retired policy. |
docs/sandbox-policy/0.8.0/networking/schema-updates.md |
Removes retired migration document. |
docs/sandbox-policy/0.8.0/networking/networking.md |
Removes retired networking design. |
docs/sandbox-policy/0.7.0/policy.md |
Removes retired policy. |
docs/process-container/os-version-support.md |
Updates stable-policy link. |
docs/process-container/networking.md |
Updates shared-policy references. |
docs/process-container/guide.md |
Updates prerequisites and legacy guidance. |
docs/process-container/examples/0.8.0-schema.md |
Redirects historical guidance. |
docs/examples.md |
Updates networking references. |
docs/authoring-a-new-feature.md |
Updates authoring references. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Gudge (MGudgin)
force-pushed
the
user/gudge/policy_docs
branch
from
October 6, 2026 23:04
c9fdfe7 to
88cd785
Compare
Gudge (MGudgin)
force-pushed
the
user/gudge/policy_docs
branch
from
October 6, 2026 23:22
88cd785 to
3678ee5
Compare
1 of 8 tasks
Gudge (MGudgin)
force-pushed
the
user/gudge/policy_docs
branch
from
October 7, 2026 02:35
3678ee5 to
f4fbf2d
Compare
Gudge (MGudgin)
force-pushed
the
user/gudge/policy_docs
branch
from
October 7, 2026 15:42
f4fbf2d to
7e65507
Compare
Gudge (MGudgin)
force-pushed
the
user/gudge/policy_docs
branch
from
October 7, 2026 21:43
7e65507 to
8318ad9
Compare
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
The documented contract versions, lifecycle coverage, backend constraints, and relative links align with the registered contracts and validators.
2 open findings
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
Gudge (MGudgin)
force-pushed
the
user/gudge/policy_docs
branch
from
October 9, 2026 16:44
8318ad9 to
59d1a46
Compare
Gudge (MGudgin)
force-pushed
the
user/gudge/policy_docs
branch
from
October 9, 2026 18:08
59d1a46 to
cf74840
Compare
Gudge (MGudgin)
force-pushed
the
user/gudge/policy_docs
branch
from
October 9, 2026 19:51
cf74840 to
28fc82e
Compare
Gudge (MGudgin)
force-pushed
the
user/gudge/policy_docs
branch
from
October 9, 2026 19:53
28fc82e to
9dd66cc
Compare
Gudge (MGudgin)
force-pushed
the
user/gudge/policy_docs
branch
from
October 9, 2026 20:27
9dd66cc to
eea54a7
Compare
This PR adds policy-first guidance for the published 0.9.0-alpha and 1.0.0 contracts and the V1 development contract. It distinguishes typed SDK authoring from raw JSON, documents backend-specific policy handling, and aligns lifecycle guidance with supported SDK operations. Details * Describe network rules, backend postures, and WSLC port mappings with complete policy examples. * Distinguish request shape from backend enforcement: policy fields can be applied, rejected, or ignored. * Document port-range validation and the LXC raw-socket bypass of direct network rules for workloads that retain CAP_NET_RAW. * Use ContainerId for typed lifecycle identities and sandboxId in raw envelopes, distinct from the creation containerId label. * Align lifecycle options, type exports, exact-version fields, and error semantics with supported SDK and wire contracts. Tests * `cargo fmt --manifest-path src\Cargo.toml --all -- --check` passed. * `node -` parsed 15 lifecycle TypeScript examples. * `python -` checked 10 unchanged lifecycle JSON examples and Markdown targets, optional creation containment, WSLC version boundaries, and the network range and LXC limits against their implementation sources. * `git diff --check origin/main...HEAD` passed. * Backend runtime suites were not run (documentation and wording changes). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a30a59a8-e257-4e4b-9995-762f3611dabe Generated-with: gpt-6-sol
Gudge (MGudgin)
force-pushed
the
user/gudge/policy_docs
branch
from
October 9, 2026 20:35
eea54a7 to
775fbdb
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


This PR adds policy-first guidance for supported
0.9.0-alphaand1.0.0containment contracts and the mutable V1 development contract. It separates
typed SDK authoring from exact raw JSON, and uses container terminology for
generic MXC instances without changing runtime behavior or wire identifiers.
Details
and lifecycle support.
v1-dev/and reserve1.1.0/forpublished contract documentation.
vmexperimental gate, WSLC's cooperative proxy,and development-only port mappings.
ContainerIdfrom the raw JSONsandboxIdfield.documentation, test descriptions, and comments with container terminology.
Tests
cargo fmt --manifest-path src\Cargo.toml --all -- --check— passed.Parser.ParseFileon all three touched test scripts — passed.python -check — passed: 148 Markdown links and anchors across31 changed pages.
match their exact schemas.
git --no-pager diff --check origin/main...HEAD— passed.snippets with TypeScript 6.0.3 — passed.
change affects documentation, comments, and test diagnostic text only.
Microsoft Reviewers: Open in CodeFlow