Skip to content

Add Rust SDK crates.io release pipeline - #1337

Merged
Branden Bonaby (bbonaby) merged 7 commits into
mainfrom
user/bbonaby/rust-crates-publishing
Oct 6, 2026
Merged

Branden Bonaby (bbonaby) merged 7 commits into
mainfrom
user/bbonaby/rust-crates-publishing

Conversation

@bbonaby

@bbonaby Branden Bonaby (bbonaby) commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

📖 Description

  • Adds a manual Azure DevOps release pipeline that packages and publishes the single Rust release crate, mxc-sdk, to crates.io through ESRP.
  • Keeps dry run as the default and requires an immutable refs/tags/v* tag before a production release.
  • Validates crates.io metadata, rejects first-party runtime path dependencies, and keeps the non-overridable release list synchronized with Cargo.
  • Packages the crate once for official builds and validates the release configuration in GitHub repository-consistency checks.

🔗 References

🔍 Validation

  • pwsh -NoProfile -File scripts/ci/Invoke-CratePackage.ps1 -ValidateOnly — passed.
  • node scripts/versioning/check-rust-toolchain-sync.js — passed.
  • pwsh -NoProfile -File scripts/ci/Invoke-CratePackage.ps1 -OutDir <temp> — passed and produced mxc-sdk-0.9.0.crate.
  • cargo publish --dry-run --locked --manifest-path src/Cargo.toml -p mxc-sdk — passed, including compilation from the packaged crate.
  • git diff origin/main...HEAD --check — passed.

✅ Checklist

📋 Issue Type

  • Bug fix
  • Feature
  • Task

GitHub Actions runs the PR validation build automatically. The ADO pipeline
(MXC-PR-Build) is the Azure version of the PR pipeline, kept in parity with the GitHub
Actions build; it runs on merge to main, and Microsoft reviewers with write access can trigger it
on a PR with /azp run. See docs/pull-requests.md.

If the dependency-feed-check check fails on a new dependency, the crate must be added to
the feed before the PR can pass. See docs/pull-requests.md
for the steps.

Prepare mxc-sdk and its required internal crates for crates.io publication, validate publishing metadata in CI, derive dependency order from Cargo metadata, and add guarded private packaging and ESRP release infrastructure.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d1b2a24b-fa9f-45bd-96df-b1b7df002555
@bbonaby
Branden Bonaby (bbonaby) requested review from a team and a balanced review from Copilot September 29, 2026 23:42
@bbonaby
Branden Bonaby (bbonaby) requested a review from a team as a code owner September 29, 2026 23:42
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The production order is not enforced, the official macOS package list is stale, and toolchain synchronization omits the publish template.

Review effort: Balanced
Findings: 2 High severity · 1 Medium severity

Open (3)
What changed in this PR

Adds crates.io packaging and ESRP release infrastructure for the Rust SDK and its internal dependency closure.

Changes:

  • Renames 23 publishable crates with mxc- package names while preserving Rust library names.
  • Adds metadata/order validation, packaging, dry-run, and sequential ESRP publication.
  • Updates CI, build scripts, documentation, lockfile, and platform gates.
File Description
tests/​scripts/​run_dacl_tests.ps1 Updates package selectors.
tests/​scripts/​lib/​WinProcessContainer.Common.ps1 Updates PLM build commands.
src/​testing/​fuzz/​Cargo.toml Maps renamed dependency packages.
src/​mxc_telemetry/​Cargo.toml Makes telemetry publishable.
src/​host/​plm/​readme.md Updates PLM commands.
src/​host/​plm/​Cargo.toml Renames and versions PLM.
src/​core/​wxc/​Cargo.toml Maps the renamed PLM package.
src/​core/​wxc_common/​Cargo.toml Makes common runtime publishable.
src/​core/​mxc-sdk/​Cargo.toml Adds repository metadata.
src/​core/​mxc_pty/​Cargo.toml Makes PTY helpers publishable.
src/​core/​mxc_engine/​Cargo.toml Renames the engine package.
src/​core/​mxc_config_contract/​Cargo.toml Makes contracts publishable.
src/​core/​mxc_build_common/​Cargo.toml Makes build helpers publishable.
src/​core/​learning_mode_platforms/​windows/​examples/​lm_analyze.rs Updates example command.
src/​core/​learning_mode_platforms/​windows/​Cargo.toml Renames the Windows learning crate.
src/​core/​learning_mode_core/​Cargo.toml Renames the learning core crate.
src/​core/​generated/​process_security_environment_specification/​regenerate.ps1 Updates generated-crate selector.
src/​core/​generated/​process_security_environment_specification/​Cargo.toml Renames generated bindings package.
src/​Cargo.toml Adds publication names, versions, and metadata.
src/​Cargo.lock Records renamed workspace packages.
src/​backends/​wslc/​common/​src/​lib.rs Gates WSLC to Windows.
src/​backends/​wslc/​common/​Cargo.toml Makes WSLC support publishable.
src/​backends/​windows_sandbox/​lifecycle/​src/​vm.rs Adds non-Windows compilation fallback.
src/​backends/​windows_sandbox/​lifecycle/​Cargo.toml Renames lifecycle package.
src/​backends/​windows_sandbox/​guest/​Cargo.toml Maps renamed common dependency.
src/​backends/​windows_sandbox/​daemon/​Cargo.toml Maps renamed common dependency.
src/​backends/​windows_sandbox/​common/​Cargo.toml Renames shared sandbox package.
src/​backends/​seatbelt/​common/​Cargo.toml Renames Seatbelt package.
src/​backends/​process_container/​common/​examples/​lm_probe.rs Updates example command.
src/​backends/​process_container/​common/​examples/​lm_capture.rs Updates example command.
src/​backends/​process_container/​common/​Cargo.toml Renames ProcessContainer package.
src/​backends/​nanvix/​runner/​src/​lib.rs Gates runner to supported hosts.
src/​backends/​nanvix/​runner/​Cargo.toml Renames NanVix runner package.
src/​backends/​nanvix/​common/​src/​lib.rs Adds non-Windows packaging constants.
src/​backends/​nanvix/​common/​Cargo.toml Renames NanVix common package.
src/​backends/​nanvix/​build_common/​Cargo.toml Maps renamed NanVix dependency.
src/​backends/​nanvix/​binaries/​Cargo.toml Maps renamed NanVix dependencies.
src/​backends/​lxc/​common/​Cargo.toml Renames LXC package.
src/​backends/​isolation_session/​common/​src/​lib.rs Gates implementation to Windows.
src/​backends/​isolation_session/​common/​Cargo.toml Renames and target-gates dependencies.
src/​backends/​isolation_session/​bindings/​src/​lib.rs Gates bindings to Windows.
src/​backends/​isolation_session/​bindings/​Cargo.toml Makes bindings publishable.
src/​backends/​hyperlight/​common/​Cargo.toml Renames Hyperlight package.
src/​backends/​bubblewrap/​common/​Cargo.toml Renames Bubblewrap package.
scripts/​versioning/​check-rust-toolchain-sync.js Extends toolchain-pin validation.
scripts/​versioning/​check-psec-codegen.js Updates generated-crate selector.
scripts/​ci/​Invoke-CratePackage.ps1 Validates and packages release closure.
README.md Updates Rust commands.
docs/​wsl/​wslc-sdk-bindings.md Updates WSLC commands.
docs/​telemetry/​telemetry.md Updates telemetry commands.
docs/​pull-requests.md Documents publication validation.
CONTRIBUTING.md Updates test commands.
build.sh Updates Linux package selectors.
build.bat Updates PLM package selector.
.github/​workflows/​Versioning.Checks.Job.yml Adds publication metadata validation.
.github/​workflows/​Lint.Job.yml Updates macOS lint selector.
.github/​workflows/​Build.Windows.Job.yml Updates common-crate tests.
.github/​workflows/​Build.MacOS.Job.yml Updates macOS build selectors.
.github/​workflows/​Build.Linux.Job.yml Updates Linux test selectors.
.github/​copilot-instructions.md Updates documented commands.
.azure-pipelines/​templates/​Rust.Build.Steps.Official.yml Removes target-cache references.
.azure-pipelines/​templates/​Rust.Build.Job.yml Removes cache and updates selectors.
.azure-pipelines/​templates/​Publish.CratesIo.Job.yml Adds dry-run and ESRP publication jobs.
.azure-pipelines/​templates/​Package.Crates.Job.yml Adds crate packaging job.
.azure-pipelines/​templates/​Mac.Build.Job.yml Removes cache and updates selectors.
.azure-pipelines/​templates/​Lint.Job.yml Updates macOS lint selector.
.azure-pipelines/​templates/​1ES.Build.Stages.yml Adds crate packaging stage.
.azure-pipelines/​README.md Documents crates.io releases.
.azure-pipelines/​1ES.Release.Crates.yml Defines the manual release pipeline.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .azure-pipelines/templates/Mac.Build.Job.yml Outdated
Comment thread .azure-pipelines/templates/Publish.CratesIo.Job.yml
Comment thread scripts/versioning/check-rust-toolchain-sync.js
Copilot AI balanced review requested due to automatic review settings September 29, 2026 23:53
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d1b2a24b-fa9f-45bd-96df-b1b7df002555

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The release path targets the private registry and can publish archives without Cargo verification.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Resolved since last review (3)
Previously missed (2)

In code that hasn't changed since last review

Medium severity Package for crates.io instead of the private registry

.azure-pipelines/​templates/​Package.Crates.Job.yml:50

These artifacts are submitted to crates.io, but this argument asks Cargo to package for Mxc-Azure-Feed; Cargo uses the selected registry when generating package lockfiles for interdependent crates. That validates and prepares the archives under the private-feed assumption rather than the destination registry. The source replacement configured earlier already keeps dependency downloads on the private feed, so leave the package target at Cargo's default crates.io registry.

Medium severity Validate publication against crates.io, not the private registry

.azure-pipelines/​templates/​Publish.CratesIo.Job.yml:89

This job is labeled as a crates.io publication check, but --registry Mxc-Azure-Feed makes Cargo validate a dry run for the internal registry instead. Registry-specific dependency and package checks can therefore pass here and still fail during the ESRP crates.io release. Keep the private source replacement for downloads, but omit this target-registry override so the dry run models crates.io.

Comment thread scripts/ci/Invoke-CratePackage.ps1 Outdated
Copilot AI balanced review requested due to automatic review settings September 30, 2026 00:06
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d1b2a24b-fa9f-45bd-96df-b1b7df002555

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The shared package stage uses official-only authenticated Rust tasks and will fail in fork and unofficial PR builds.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Resolved since last review (1)

Comment thread .azure-pipelines/templates/1ES.Build.Stages.yml
@bbonaby

Copy link
Copy Markdown
Collaborator Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

Copilot AI balanced review requested due to automatic review settings September 30, 2026 01:04
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: d1b2a24b-fa9f-45bd-96df-b1b7df002555
@bbonaby

Copy link
Copy Markdown
Collaborator Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The non-Windows launch path is unsafe, and production publishing does not bind the crate version to the release tag.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Resolved since last review (1)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Validate Tag Version Matches Packaged Crate Version

.azure-pipelines/​templates/​Publish.CratesIo.Job.yml:126

This only checks that the ref starts with v; it never verifies that the tag version matches the packaged crate version. A run queued on a stale or mistyped tag such as v1.0.0 can therefore publish mxc-sdk-0.9.0.crate, leaving the crates.io release untraceable to its version tag. Compare the tag suffix with the SDK archive filename before starting any ESRP task.

Comment on lines +141 to +142
#[cfg(not(windows))]
let sandbox_exe = std::path::PathBuf::from("WindowsSandbox.exe");
Copilot AI balanced review requested due to automatic review settings September 30, 2026 01:21
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: d1b2a24b-fa9f-45bd-96df-b1b7df002555
@bbonaby

Copy link
Copy Markdown
Collaborator Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The production flow lacks partial-release recovery, permits restricted-registry metadata, and introduces an unsafe non-Windows executable lookup.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Previously missed (2)

In code that hasn't changed since last review

Medium severity Support resuming partially completed releases

.azure-pipelines/​templates/​Publish.CratesIo.Job.yml:132

This sequence has no recovery path after a partial release. If crate N fails after earlier immutable versions were accepted by crates.io, rerunning the tag starts at crate 1; the duplicate-version failure stops the job before it reaches crate N. Add an order-validated resume mechanism or make exact-version duplicates idempotent so a transient ESRP failure does not permanently strand the release.

Medium severity Reject publish allowlists that omit crates.io

scripts/​ci/​Invoke-CratePackage.ps1:75

This only rejects publish = false; a crate restricted to another registry (for example, publish = ["internal"]) passes CI even though this pipeline publishes to crates.io. Treat any non-null allowlist that omits crates-io as non-publishable.

Copilot AI balanced review requested due to automatic review settings September 30, 2026 01:36
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: d1b2a24b-fa9f-45bd-96df-b1b7df002555
@bbonaby

Copy link
Copy Markdown
Collaborator Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The release validation and platform fallback contain unresolved publication-integrity and executable-launch issues.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Previously missed (2)

In code that hasn't changed since last review

Medium severity Verify release tag matches the packaged crate version

.azure-pipelines/​templates/​Publish.CratesIo.Job.yml:125

The production gate accepts any nonempty v* tag without checking it against the packaged crate version. A run queued from refs/tags/v1.0.0 can therefore publish the 0.9.0 archives, leaving misleading release provenance and consuming an immutable crates.io version under the wrong source tag. Derive the expected version from the packaged mxc-sdk-<version>.crate (or emitted package metadata) and require an exact refs/tags/v<version> match before the first ESRP task.

Medium severity Require crates.io in the Cargo publish registry list

scripts/​ci/​Invoke-CratePackage.ps1:76

This only rejects publish = false; Cargo metadata also represents publish = ["some-private-registry"] as a nonempty list, so such a crate passes CI even though this pipeline cannot publish it to crates.io. When publish is non-null, require that the list contains crates-io.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:shipit:

Resolve the crate-consolidation conflicts and update the crates.io release flow to package, validate, and publish only mxc-sdk.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 433e5b70-c2bd-496d-9b8d-bd2085bb2706

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The mandatory Cargo publication check omits the explicit registry selection required by the configured source replacement, blocking releases.

Review effort: Balanced
Findings: 2 High severity

Open (2)

Comment on lines +57 to +59
$arguments.Add('publish')
$arguments.Add('--dry-run')
$arguments.Add('--locked')
@bbonaby
Branden Bonaby (bbonaby) merged commit a97d51b into main Oct 6, 2026
31 checks passed
@bbonaby
Branden Bonaby (bbonaby) deleted the user/bbonaby/rust-crates-publishing branch October 6, 2026 03:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add the Rust SDK crates.io release pipeline

4 participants