Skip to content

docs: add MXC Policy Store feature spec - #1309

Open
Chaz Gordish (ChazGo) wants to merge 11 commits into
microsoft:mainfrom
ChazGo:chazgo-mxc-policy-spec
Open

Chaz Gordish (ChazGo) wants to merge 11 commits into
microsoft:mainfrom
ChazGo:chazgo-mxc-policy-spec

Conversation

@ChazGo

@ChazGo Chaz Gordish (ChazGo) commented Sep 28, 2026 •

Copy link
Copy Markdown

📖 Description

Adds the MXC Policy Store feature spec, building on #779. After the design review, Policy Store ships inside MXC as SDK APIs (TypeScript, Rust, .NET) over one shared Rust resolver, with V1 policy data embedded at build time. It isn't part of MXC 1.0. Floors are best-effort baselines, not authorization or a guarantee that a workflow works, and Learning Mode is complementary rather than a replacement.

Lookup is keyed on tool identity (packageUrl strong, invocationName as an opt-in fallback), an optional tool-defined intent, and an optional detected version. Host and command line aren't lookup keys. Each entry has one unversioned default plus add-only platform and version overlays, with version ranges in purl vers syntax (npm, semver, pypi, nuget, intdot). Overlays use policyAdditions, intentAdditions for intents the default already declares, and newIntents for new ones.

Each requested tool+intent pair gets a status (matched_default, matched_version, version_out_of_range, version_unparseable, intent_unsupported, tool_unmatched), so a multi-tool request can return a policy that covers only the pairs that resolved. Composition keeps required access: read-write supersedes overlapping read-only, and a catalog filesystem or egress deny that conflicts with another requested tool's required access is removed in full and reported in diagnostics. Caller restrictions still win. Dependencies contribute their default plus platform additions only, unless the reference names dependency intents.

Still open (§13): the exact validator and version mapping, purl equality rules, and final API names, which I think should follow the policy-type rename.

🔗 References

🔍 Validation

Docs-only. Type-checked all TypeScript snippets together against the sdk/node types with tsc --noEmit --strict (passed), parsed the JSON examples (passed), checked internal anchors and relative links (none broken), and ran git diff --check (clean). No runtime build or test suite was run.

✅ Checklist

📋 Issue Type

  • Bug fix
  • Feature
  • Task

GitHub Actions runs the PR validation build automatically. The ADO pipeline
(MXC-PR-Build) is the Azure version of the PR pipeline, kept in parity with the GitHub
Actions build; it runs on merge to main, and Microsoft reviewers with write access can trigger it
on a PR with /azp run. See docs/pull-requests.md.

If the dependency-feed-check check fails on a new dependency, the crate must be added to
the feed before the PR can pass. See docs/pull-requests.md
for the steps.

Microsoft Reviewers: Open in CodeFlow

Proposed feature spec for the MXC Policy Store: an integrity-validated,
versioned, read-only known-tool sandbox requirements catalog and SDK
resolver. Builds on microsoft#779's config-floor data model and
tightens it into a review-ready contract: independent catalog/entry/
policy versioning, ordered strong/weak tool identity, complete
per-platform requirement variants, deterministic cycle-rejecting
dependency resolution with an explicit v1 composition vocabulary, a
resolver API split from catalog metadata inspection, immutable
published revisions, and a reviewed PR/CI contribution pipeline.

Scoped to what MXC owns; consumers retain access-profile mapping,
authorization/elevation, persistence, composition, approval, audit,
and final sandbox creation. Status is proposed and review-ready, not
approved or shipped; open questions are called out explicitly with
recommended answers.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 28, 2026 17:02

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Core revision, matching, dependency-version, composition, metadata, and trust semantics remain ambiguous or inconsistent.

Review effort: Balanced
Findings: 6 Medium severity

Open (6)
What changed in this PR

Defines a proposed read-only MXC Policy Store and resolver contract for known-tool sandbox requirements.

Changes:

  • Specifies catalog identity, versioning, platform variants, dependency composition, and governance.
  • Defines proposed resolver and inspection APIs.
  • Adds the specification to the documentation index.
File Description
README.md Links the new feature specification.
docs/​mxc-policy-store.md Defines the proposed Policy Store contract.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread docs/mxc-policy-store.md Outdated
Comment thread docs/mxc-policy-store.md Outdated
Comment thread docs/mxc-policy-store.md Outdated
Comment thread docs/mxc-policy-store.md Outdated
Comment thread docs/mxc-policy-store.md Outdated
Comment thread docs/mxc-policy-store.md Outdated
@kanismohammed

Copy link
Copy Markdown
Collaborator

Chaz Gordish (@ChazGo) - This work needs a broader discussion. Can you please schedule a meeting to go over the overall product story here?

@MGudgin Gudge (MGudgin) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This doesn't belong in the mxc repository. If we want this, it should be in its own repo, perhaps named microsoft/sandbox-tool-requirements or some such.

@microsoft-github-policy-service microsoft-github-policy-service Bot added the Needs-Author-Feedback Waiting for additional information or action from the issue or pull-request author. label Sep 28, 2026
@ChazGo

Copy link
Copy Markdown
Author

Chaz Gordish (Chaz Gordish (@ChazGo)) - This work needs a broader discussion. Can you please schedule a meeting to go over the overall product story here?

Gudge (@MGudgin) Anis Mohammed Khaja Mohideen (@kanismohammed) sorry I was just getting this started and didn't mean to make it set off alarm bells, but it did get the conversation started early at least! I'll get something booked on the calendar. I think we do need to agree on where this should live first, because that should significantly influence how much scrutiny other design decisions will receive. Alexander Sklar (@asklar) FYI on this draft and the meeting I'll be setting up. This essentially takes your #779 design and expands upon it slightly.

@microsoft-github-policy-service microsoft-github-policy-service Bot added Needs-Attention Requires attention or a decision from the MXC maintainers. and removed Needs-Author-Feedback Waiting for additional information or action from the issue or pull-request author. labels Sep 28, 2026
@ChazGo

Copy link
Copy Markdown
Author

@microsoft-github-policy-service agree company="Microsoft"

Chaz Gordish and others added 5 commits September 29, 2026 09:59
Define revision migration, platform selection, dependency metadata, fail-closed composition, inspection metadata, and trust outcomes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Center the first-run containment problem, document the limited support horizon and Learning Mode replacement, and move catalog ownership outside MXC.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Add an in-place feature-impact and omission-defaults subsection without restructuring the reviewed document.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Use the selected support designation while retaining the limited lifetime, proposed SDK boundary, and not-shipped disclaimer.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Remove speculative MXC SDK integration and describe standalone TypeScript/JavaScript, Rust, and .NET libraries, local catalog consumption, and cross-language conformance.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 29, 2026 22:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread docs/mxc-policy-store.md Outdated
Comment thread docs/mxc-policy-store.md Outdated
Restore single-tool and multi-tool policy APIs, define additive matching and filesystem floor composition, reuse MXC SDK policy types, and clarify symbol discovery, casing, diagnostics, integrity, and language consistency.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 04:30
@ChazGo
Chaz Gordish (ChazGo) marked this pull request as ready for review October 1, 2026 04:32
@ChazGo
Chaz Gordish (ChazGo) requested a review from a team as a code owner October 1, 2026 04:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread docs/mxc-policy-store.md Outdated
Comment on lines +211 to +213
- An embedded `sandboxPolicy` is validated against the real `SandboxPolicy`
schema for its declared `version`. The catalog schema does not duplicate
that validation.
Comment thread docs/mxc-policy-store.md
Comment on lines +265 to +268
Caller-supplied identity is not verified identity. A `packageUrl` match does
not prove that the installed tool belongs to that package; the caller is
responsible for verifying that association. The library does not inspect the
tool to verify it.
Comment thread docs/mxc-policy-store.md Outdated
Comment thread docs/mxc-policy-store.md
Comment thread docs/mxc-policy-store.md Outdated
Comment thread docs/mxc-policy-store.md Outdated
Comment thread docs/mxc-policy-store.md Outdated
Use resolveSandboxPolicy and resolveSandboxPolicyWithDiagnostics throughout the spec, retain the original proposal's name as historical context, and make runtime and inspection declarations valid exported TypeScript signatures.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 17:54

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Matching, cross-SDK compatibility, and integrity-validation semantics remain insufficiently defined.

Review effort: Balanced
Findings: 1 High severity · 5 Medium severity

Open (6)
Resolved since last review (2)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Define cross-binding policy field compatibility

docs/​mxc-policy-store.md:709

“Supported by that SDK” does not ensure shared-catalog parity because the current SDK policy types have different field sets: Rust exposes version/filesystem/network/UI/timeout (src/core/mxc_engine/src/policy.rs:580-592), while Node also exposes runtimeConfig, telemetry, and processContainer (sdk/node/src/types.ts:465-523). Since §4.5 permits a single-entry policy to use otherwise non-composable fields, one revision can be representable in one binding but rejected or truncated in another. Define a common publishable field subset or explicit per-binding revision compatibility so unsupported fields are never silently lost and the §6.2 parity guarantee remains achievable.

Comment thread docs/mxc-policy-store.md Outdated
Make the opening access and safety caveat explicit, map catalog failures to existing MXC error codes with optional reasons, and add the corresponding conformance check.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 18:52

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The contract has unresolved cross-language compatibility, matching, version-range, and digest-format issues.

Review effort: Balanced
Findings: 1 High severity · 4 Medium severity

Open (5)
Resolved since last review (1)
Previously missed (1)

In code that hasn't changed since last review

Low severity Rename undefined requires edge to dependencies

docs/​mxc-policy-store.md:201

The entry shape defines dependencies, but no requires member exists, so this invariant refers to an undefined edge type. Use the field name from the example and the rest of the contract.

Ship as MXC SDK APIs with bundled V1 data, add intents and add-only
platform/version overlays (newIntents vs intentAdditions), per-pair
resolution statuses, default-only dependencies, and catalog filesystem
and egress deny removal on conflict. Linux invocation names match
exactly.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 5, 2026 17:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread docs/mxc-policy-store.md Outdated
Comment thread docs/mxc-policy-store.md Outdated
Comment thread docs/mxc-policy-store.md Outdated
Comment thread docs/mxc-policy-store.md Outdated
Comment on lines +854 to +858
**The returned policy may cover only a subset of the requested tools.**
`tool_unmatched`, `version_unparseable`, and `intent_unsupported` pairs contribute
nothing; other pairs still resolve. Callers inspect per-input diagnostics to
determine coverage. No wildcard entry fills a missing match, and there is no
`requireAllMatches` option.
Chaz Gordish (ChazGo) pushed a commit to ChazGo/mxc that referenced this pull request Oct 5, 2026
Dependencies, overlays and composition now follow the pushed spec
(microsoft#1309 at 5a2c52c, docs/mxc-policy-store.md):

- Dependencies contribute the referenced entry's default plus platform
  base additions only. A reference may name intents
  ({ entryId, intents: [...] }); a named intent the dependency's default
  does not define fails catalog validation. Dependency diagnostics report
  intentSelection mode "none" or "named".
- Overlays use policyAdditions, intentAdditions (default intents only)
  and newIntents. The former overlay `intents` field is renamed to
  `newIntents` in the model, JSON schema, metadata and fixtures.
- A catalog egress deny that overlaps another requested pair's required
  egress allow is removed in full, with a diagnostic naming the full
  destination/port scope and the contributing entries. Non-overlapping
  denies stay. Overlapping denies are no longer composition_conflict.
- Network rule validation parses CIDRs, requires `except` blocks inside
  their peer, and rejects ports on icmp.
- The reviewer view adds an "Added to default" column per row.
- Catalog revision 2026-10-05.1 replaces 2026-10-02.1: git entryRevision
  2 moves the >=2.50 bundle-fetch intent to newIntents.
- New composition-catalog conformance fixture and library tests.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Keep lookup command-free with ContainerRequirements using existing v1 SDK field types. Clarify validation, structured diagnostics, PURL matching, contribution attribution, and filesystem identity while preserving the catalog composition and partial-result contract.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 17:37

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread docs/mxc-policy-store.md
Comment on lines +433 to +437
Compare only type, namespace, and name. Catalog comparison is
locale-independent and case-insensitive for type and namespace; the name
follows its package type's normalization and case rules. Namespace folding is
a catalog lookup rule, not a claim that every ecosystem treats namespaces
case-insensitively.
Comment thread docs/mxc-policy-store.md

type ToolInput = string | ToolCandidate;

interface ResolveContext {
Comment thread docs/mxc-policy-store.md
Comment on lines +1581 to +1583
| Maintainer sign-off | Recommended answer |
|---|---|
| Approve the command-free requirements API surface? | `resolveToolRequirements` / `resolveToolRequirementsWithDiagnostics` return `ContainerRequirements` using existing v1 section types, with optional lookup context, Promise-based Node resolution, corresponding Rust/.NET bindings, and the documented partial-result contract. |

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Needs-Attention Requires attention or a decision from the MXC maintainers.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants