Audience: MXC consumers
For a more comprehensive list of examples, see
tests/examples/.
{
"version": "1.0.0",
"containment": "processcontainer",
"process": {
"commandLine": "python -c \"import sys; print('Hello from MXC!'); print(sys.version)\""
}
}{
"version": "1.0.0",
"containment": "processcontainer",
"process": {
"commandLine": "python -c \"open('C:\\\\temp\\\\output.txt', 'w').write('test')\""
},
"filesystem": {
"readwritePaths": [
"C:\\temp"
],
"deniedPaths": [
"C:\\Windows\\System32"
]
}
}Create C:\temp before running this example, or replace it with an existing
writable directory.
{
"version": "1.0.0",
"containment": "processcontainer",
"process": {
"commandLine": "python -c \"import socket; socket.create_connection(('140.82.114.6', 443), timeout=5).close(); print('Allowed destination reached')\"",
"timeout": 30000
},
"processContainer": {
"capabilities": ["internetClient"]
},
"network": {
"egress": {
"default": "deny",
"allow": [{
"to": [{ "cidr": "140.82.114.6/32" }],
"ports": [{ "protocol": "tcp", "port": 443 }]
}]
},
"ingress": { "default": "deny", "hostLoopback": "deny" }
}
}The destination is numeric because directional rules accept IP/CIDR, not hostnames. It must be reachable from the host to demonstrate the allow rule; see the ProcessContainer networking guide for host requirements and enforcement limits.
Supported contracts use explicit egress CIDR, protocol, and port rules plus separate ingress defaults:
{
"version": "0.9.0-alpha",
"containment": "processcontainer",
"process": {
"commandLine": "cmd.exe /c echo directional network example"
},
"network": {
"egress": {
"default": "deny",
"allow": [
{
"to": [{ "cidr": "192.0.2.0/24" }],
"ports": [{ "protocol": "tcp", "port": 443 }]
}
]
},
"ingress": {
"default": "deny",
"hostLoopback": "deny"
}
}
}See
tests/examples/30_network_0_8_directional.json
for the complete config and the
supported schema guide
for current backend authoring.
Supported contracts name a running localhost proxy using
runtimeConfig.networkProxy. Egress must default to deny, with no direct
allow or deny rules. For an unpackaged host proxy on ProcessContainer,
the development/testing configuration is:
{
"version": "1.0.0",
"containment": "processcontainer",
"process": {
"commandLine": "python -c \"import urllib.request; print(urllib.request.urlopen('https://api.github.com').status)\"",
"timeout": 30000
},
"processContainer": {
"capabilities": ["internetClient"]
},
"network": {
"egress": { "default": "deny" },
"ingress": { "default": "allow", "hostLoopback": "allow" }
},
"runtimeConfig": {
"networkProxy": "http://127.0.0.1:8080"
}
}This identity-less host-loopback deployment restricts client egress to the
configured proxy address and port, but does not verify which process owns that
endpoint. It supports PSEC 1.0-only hosts and hosts with PSEC 1.1 or newer that
advertise ingress support. PSEC 1.1 or newer without that flag rejects the
request, even if the host also accepts PSEC 1.0 payloads. For production
ProcessContainer deployments, identify a packaged proxy through
processContainer.network.allowedProxyPeer instead; see
proxy deployment choices.
Bubblewrap and Seatbelt also support a caller-managed loopback proxy, but
their supported ingress policies differ. See their backend guides.
Every supported contract (0.9.0-alpha or later) accepts the directional
shape and rejects the retired defaultPolicy, host-list, and network.proxy
fields. This is the cross-backend schema,
not a backend-specific format: it's parsed the same way regardless of
containment. Each backend independently declares which parts of it — if
any — it actually enforces; a backend that hasn't declared support for a
given field rejects a config that sets it.
Note that EGRESS_RULES is what carries per-CIDR/port rules; a backend
without it accepts only egress.default. On Seatbelt,
runtimeConfig.networkProxy covers only loopback endpoints; there is no
supported equivalent for a remote proxy URL or builtinTestServer. See
tests/examples/31_mac_network_0_8.json
for a complete example:
{
"version": "0.9.0-alpha",
"containment": "seatbelt",
"network": {
"egress": { "default": "deny" },
"ingress": { "default": "deny", "hostLoopback": "deny" }
},
"runtimeConfig": {
"networkProxy": "http://127.0.0.1:8080"
}
}