Skip to content

Add scenario-based SDK samples - #1399

Merged
Jeff Whiteside (jsidewhite) merged 6 commits into
mainfrom
user/jwhites/samples
Oct 6, 2026
Merged

Jeff Whiteside (jsidewhite) merged 6 commits into
mainfrom
user/jwhites/samples

Conversation

@jsidewhite

@jsidewhite Jeff Whiteside (jsidewhite) commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

📖 Description

Adds a scenario-first sample suite with parallel Rust, .NET, and Node implementations for:

  • transient and persisted containers
  • captured, streaming, and PTY I/O
  • filesystem and network containment, including blocked-access assertions
  • ProcessContainer access-denial logging
  • containment support discovery
  • telemetry consent and per-run telemetry enablement

The samples use public V1 typed APIs, bounded commands, explicit errors and warnings, and backend-appropriate cleanup. The previous combined .NET sample is replaced by focused scenario projects.

🔗 References

None.

🔍 Validation

  • cargo fmt --manifest-path samples\Cargo.toml --all
  • cargo generate-lockfile --manifest-path samples\Cargo.toml
  • cargo metadata --manifest-path samples\Cargo.toml --no-deps --format-version 1
  • Built the Node SDK and strict type-checked every Node sample
  • Parsed every sample .csproj and Microsoft.Mxc.Sdk.slnx, and verified all sample projects are included
  • git diff --check origin/main
  • Verified the filesystem sample's writable control fails as expected

Full Rust compilation is unavailable in this environment because the MSVC toolchain is not installed. Full .NET compilation is unavailable because the .NET SDK is not installed.

✅ Checklist

📋 Issue Type

  • Bug fix
  • Feature
  • Task

GitHub Actions runs the PR validation build automatically. The ADO pipeline
(MXC-PR-Build) is the Azure version of the PR pipeline, kept in parity with the GitHub
Actions build; it runs on merge to main, and Microsoft reviewers with write access can trigger it
on a PR with /azp run. See docs/pull-requests.md.

If the dependency-feed-check check fails on a new dependency, the crate must be added to
the feed before the PR can pass. See docs/pull-requests.md
for the steps.

Microsoft Reviewers: Open in CodeFlow

Add parallel Rust, .NET, and Node examples for transient and persisted containers, I/O modes, containment policy, access-denial logging, support discovery, and telemetry consent.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 50ad2d13-4e54-49f2-a50d-0afaddc54611
@jsidewhite
Jeff Whiteside (jsidewhite) requested a review from a team as a code owner October 6, 2026 00:01
Copilot AI balanced review requested due to automatic review settings October 6, 2026 00:01
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Several samples currently fail or can report false success, including Windows PTY validation, denial assertions, and clean-checkout Node setup.

Review effort: Balanced
Findings: 6 High severity · 8 Medium severity · 14 Low severity

Open (28)

And 8 more that still need to be addressed.

What changed in this PR

Adds scenario-oriented V1 SDK samples with parallel Rust, .NET, and Node implementations.

Changes:

  • Adds ten samples covering lifecycle, containment, I/O, discovery, and telemetry.
  • Introduces shared Rust workspace and .NET solution integration.
  • Replaces the monolithic .NET sample and links the suite from root documentation.
File Description
sdk/​dotnet/​Microsoft.Mxc.Sdk.slnx Registers the new .NET samples.
sdk/​dotnet/​Microsoft.Mxc.Sdk.Sample/​Program.cs Removes the combined legacy sample.
samples/​run-with-telemetry/​rust/​src/​main.rs Adds Rust telemetry sample.
samples/​run-with-telemetry/​rust/​Cargo.toml Defines its Rust package.
samples/​run-with-telemetry/​README.md Documents telemetry behavior.
samples/​run-with-telemetry/​node/​tsconfig.json Configures Node TypeScript compilation.
samples/​run-with-telemetry/​node/​src/​main.ts Adds Node telemetry sample.
samples/​run-with-telemetry/​node/​package.json Defines its Node package.
samples/​run-with-telemetry/​node/​.npmrc Configures local package linking.
samples/​run-with-telemetry/​dotnet/​Program.cs Adds .NET telemetry sample.
samples/​run-with-telemetry/​dotnet/​Mxc.Sample.RunWithTelemetry.csproj Defines its .NET project.
samples/​run-with-logging-access-denied/​rust/​src/​main.rs Adds Rust denial-capture sample.
samples/​run-with-logging-access-denied/​rust/​Cargo.toml Defines its Rust package.
samples/​run-with-logging-access-denied/​README.md Documents denial capture.
samples/​run-with-logging-access-denied/​node/​tsconfig.json Configures Node TypeScript compilation.
samples/​run-with-logging-access-denied/​node/​src/​main.ts Adds Node denial-capture sample.
samples/​run-with-logging-access-denied/​node/​package.json Defines its Node package.
samples/​run-with-logging-access-denied/​node/​.npmrc Configures local package linking.
samples/​run-with-logging-access-denied/​dotnet/​Program.cs Adds .NET denial-capture sample.
samples/​run-with-logging-access-denied/​dotnet/​Mxc.Sample.RunWithLoggingAccessDenied.csproj Defines its .NET project.
samples/​run-with-logging-access-denied/​denied.txt Supplies the denied test resource.
samples/​run-with-io-stdio-streaming/​rust/​src/​main.rs Adds Rust streaming-output sample.
samples/​run-with-io-stdio-streaming/​rust/​Cargo.toml Defines its Rust package.
samples/​run-with-io-stdio-streaming/​README.md Documents streaming I/O.
samples/​run-with-io-stdio-streaming/​node/​tsconfig.json Configures Node TypeScript compilation.
samples/​run-with-io-stdio-streaming/​node/​src/​main.ts Adds Node streaming-output sample.
samples/​run-with-io-stdio-streaming/​node/​package.json Defines its Node package.
samples/​run-with-io-stdio-streaming/​node/​.npmrc Configures local package linking.
samples/​run-with-io-stdio-streaming/​dotnet/​Program.cs Adds .NET streaming-output sample.
samples/​run-with-io-stdio-streaming/​dotnet/​Mxc.Sample.RunWithIoStdioStreaming.csproj Defines its .NET project.
samples/​run-with-io-pty-interactive/​rust/​src/​main.rs Adds Rust interactive PTY sample.
samples/​run-with-io-pty-interactive/​rust/​Cargo.toml Enables its Rust backend feature.
samples/​run-with-io-pty-interactive/​README.md Documents interactive PTY usage.
samples/​run-with-io-pty-interactive/​node/​tsconfig.json Configures Node TypeScript compilation.
samples/​run-with-io-pty-interactive/​node/​src/​main.ts Adds Node interactive PTY sample.
samples/​run-with-io-pty-interactive/​node/​package.json Defines its Node package.
samples/​run-with-io-pty-interactive/​node/​.npmrc Configures local package linking.
samples/​run-with-io-pty-interactive/​dotnet/​Program.cs Adds .NET interactive PTY sample.
samples/​run-with-io-pty-interactive/​dotnet/​Mxc.Sample.RunWithIoPtyInteractive.csproj Defines its .NET project.
samples/​run-with-io-captured/​rust/​src/​main.rs Adds Rust captured-I/O sample.
samples/​run-with-io-captured/​rust/​Cargo.toml Defines its Rust package.
samples/​run-with-io-captured/​README.md Documents captured I/O.
samples/​run-with-io-captured/​node/​tsconfig.json Configures Node TypeScript compilation.
samples/​run-with-io-captured/​node/​src/​main.ts Adds Node captured-I/O sample.
samples/​run-with-io-captured/​node/​package.json Defines its Node package.
samples/​run-with-io-captured/​node/​.npmrc Configures local package linking.
samples/​run-with-io-captured/​dotnet/​Program.cs Adds .NET captured-I/O sample.
samples/​run-with-io-captured/​dotnet/​Mxc.Sample.RunWithIoCaptured.csproj Defines its .NET project.
samples/​run-with-containment-of-network/​rust/​src/​main.rs Adds Rust network-containment sample.
samples/​run-with-containment-of-network/​rust/​Cargo.toml Defines its Rust package.
samples/​run-with-containment-of-network/​README.md Documents network containment.
samples/​run-with-containment-of-network/​node/​tsconfig.json Configures Node TypeScript compilation.
samples/​run-with-containment-of-network/​node/​src/​main.ts Adds Node network-containment sample.
samples/​run-with-containment-of-network/​node/​package.json Defines its Node package.
samples/​run-with-containment-of-network/​node/​.npmrc Configures local package linking.
samples/​run-with-containment-of-network/​dotnet/​Program.cs Adds .NET network-containment sample.
samples/​run-with-containment-of-network/​dotnet/​Mxc.Sample.RunWithContainmentOfNetwork.csproj Defines its .NET project.
samples/​run-with-containment-of-filesystem/​rust/​src/​main.rs Adds Rust filesystem-containment sample.
samples/​run-with-containment-of-filesystem/​rust/​Cargo.toml Defines its Rust package.
samples/​run-with-containment-of-filesystem/​README.md Documents filesystem containment.
samples/​run-with-containment-of-filesystem/​node/​tsconfig.json Configures Node TypeScript compilation.
samples/​run-with-containment-of-filesystem/​node/​src/​main.ts Adds Node filesystem-containment sample.
samples/​run-with-containment-of-filesystem/​node/​package.json Defines its Node package.
samples/​run-with-containment-of-filesystem/​node/​.npmrc Configures local package linking.
samples/​run-with-containment-of-filesystem/​input.txt Supplies the readable test resource.
samples/​run-with-containment-of-filesystem/​dotnet/​Program.cs Adds .NET filesystem-containment sample.
samples/​run-with-containment-of-filesystem/​dotnet/​Mxc.Sample.RunWithContainmentOfFilesystem.csproj Defines its .NET project.
samples/​run-in-transient-container/​rust/​src/​main.rs Adds Rust transient-container sample.
samples/​run-in-transient-container/​rust/​Cargo.toml Defines its Rust package.
samples/​run-in-transient-container/​README.md Documents transient execution.
samples/​run-in-transient-container/​node/​tsconfig.json Configures Node TypeScript compilation.
samples/​run-in-transient-container/​node/​src/​main.ts Adds Node transient-container sample.
samples/​run-in-transient-container/​node/​package.json Defines its Node package.
samples/​run-in-transient-container/​node/​.npmrc Configures local package linking.
samples/​run-in-transient-container/​dotnet/​Program.cs Adds .NET transient-container sample.
samples/​run-in-transient-container/​dotnet/​Mxc.Sample.RunInTransientContainer.csproj Defines its .NET project.
samples/​run-in-persisted-container/​rust/​src/​main.rs Adds Rust persisted lifecycle sample.
samples/​run-in-persisted-container/​rust/​Cargo.toml Enables its Rust backend feature.
samples/​run-in-persisted-container/​README.md Documents persisted lifecycle usage.
samples/​run-in-persisted-container/​node/​tsconfig.json Configures Node TypeScript compilation.
samples/​run-in-persisted-container/​node/​src/​main.ts Adds Node persisted lifecycle sample.
samples/​run-in-persisted-container/​node/​package.json Defines its Node package.
samples/​run-in-persisted-container/​node/​.npmrc Configures local package linking.
samples/​run-in-persisted-container/​dotnet/​Program.cs Adds .NET persisted lifecycle sample.
samples/​run-in-persisted-container/​dotnet/​Mxc.Sample.RunInPersistedContainer.csproj Defines its .NET project.
samples/​README.md Indexes scenarios and conventions.
samples/​dryrun-check-containment-support/​rust/​src/​main.rs Adds Rust support-discovery sample.
samples/​dryrun-check-containment-support/​rust/​Cargo.toml Defines its Rust package.
samples/​dryrun-check-containment-support/​README.md Documents support discovery.
samples/​dryrun-check-containment-support/​node/​tsconfig.json Configures Node TypeScript compilation.
samples/​dryrun-check-containment-support/​node/​src/​main.ts Adds Node support-discovery sample.
samples/​dryrun-check-containment-support/​node/​package.json Defines its Node package.
samples/​dryrun-check-containment-support/​node/​.npmrc Configures local package linking.
samples/​dryrun-check-containment-support/​dotnet/​Program.cs Adds .NET support-discovery sample.
samples/​dryrun-check-containment-support/​dotnet/​Mxc.Sample.DryRunCheckContainmentSupport.csproj Updates its SDK reference.
samples/​Cargo.toml Defines the samples Rust workspace.
samples/​Cargo.lock Locks sample workspace dependencies.
samples/​.gitignore Ignores Node build artifacts.
README.md Links and describes the sample suite.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread samples/run-with-io-pty-interactive/dotnet/Program.cs
Comment thread samples/run-with-io-pty-interactive/node/src/main.ts
Comment thread samples/run-with-io-pty-interactive/rust/src/main.rs
Comment thread samples/run-with-logging-access-denied/dotnet/Program.cs Outdated
Comment thread samples/run-with-logging-access-denied/node/src/main.ts Outdated
Comment thread samples/run-with-io-stdio-streaming/README.md
Comment thread samples/run-with-io-stdio-streaming/rust/src/main.rs Outdated
Comment thread samples/run-with-logging-access-denied/README.md
Comment thread samples/run-with-telemetry/README.md Outdated
Comment thread samples/run-with-telemetry/README.md
Comment thread samples/dryrun-check-containment-support/node/package.json
Comment thread samples/run-in-persisted-container/node/src/main.ts
Comment thread samples/run-in-persisted-container/rust/src/main.rs
Comment thread samples/run-in-persisted-container/README.md Outdated
Comment thread samples/run-in-transient-container/README.md Outdated
Keep native-owned telemetry string outputs opaque until they are decoded and released with mxc_string_free.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 50ad2d13-4e54-49f2-a50d-0afaddc54611
Copilot AI balanced review requested due to automatic review settings October 6, 2026 03:33

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Several samples can mask workload or containment failures, the .NET PTY can hang on exit, and clean-checkout Node instructions omit a required SDK build.

Review effort: Balanced
Findings: 6 High severity · 8 Medium severity · 14 Low severity

Open (28)

And 8 more that still need to be addressed.

Previously missed (5)

In code that hasn't changed since last review

Medium severity Fix Node setup instructions for clean checkouts

samples/​README.md:26

The documented Node commands do not work from a clean checkout. Every sample type-checks against ../../../sdk/node/dist, and the installed local package exports dist, but that directory is ignored/not checked in and the SDK only defines prepublishOnly, which npm install here does not build. Update all Node run instructions or automate the prerequisite so the SDK is installed and built before the sample package is installed.

Medium severity Return workload status and print MXC warnings

samples/​run-with-telemetry/​dotnet/​Program.cs:89

Discarding ExecutionResult makes a timeout or nonzero workload exit look successful and suppresses every warning returned by MXC. Return the workload status and print warnings as the other .NET scenarios do.

Medium severity Handle Node execution results and warnings

samples/​run-with-telemetry/​node/​src/​main.ts:130

This drops the execution result, so timeout/nonzero exit conditions are reported as sample success and run warnings are never shown. Handle the result consistently with the other Node scenarios.

Medium severity Preserve telemetry execution results and warnings

samples/​run-with-telemetry/​rust/​src/​main.rs:104

The telemetry run result is discarded, so a timeout or nonzero workload exit still makes this sample return success and all SDK warnings disappear. Preserve the result just as the other scenario samples do so the suite's documented failure/warning behavior remains visible.

Low severity Correctly describe missing stdin streaming

samples/​README.md:16

The streaming implementations only consume stdout and stderr; none forwards stdin to the spawned process. Describing this scenario as streaming stdin overstates the demonstrated API behavior.

Remove DACL and isolation-tier implementation details from the cross-SDK sample and its documentation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 50ad2d13-4e54-49f2-a50d-0afaddc54611
Copilot AI balanced review requested due to automatic review settings October 6, 2026 03:46

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Denial samples can falsely succeed, Node setup is incomplete, and .NET PTY shutdown may hang.

Review effort: Balanced
Findings: 6 High severity · 8 Medium severity · 14 Low severity

Open (28)

And 8 more that still need to be addressed.

Previously missed (2)

In code that hasn't changed since last review

Low severity Clarify sample does not support stdin streaming

samples/​README.md:16

This table promises stdin streaming, but none of the three implementations reads or forwards stdin; the scenario README correctly describes only stdout and stderr. Narrow the purpose text so users are not directed to this sample for bidirectional streaming.

Low severity Build the Node SDK before running sample commands

samples/​README.md:26

The documented Node commands do not work from a clean checkout. Every sample resolves types from sdk/node/dist and installs the local SDK package whose exports also point to dist, but that directory is untracked and the SDK has only prepublishOnly (no install/prepare build). The PR validation likewise had to build the Node SDK first. Add a shared prerequisite to install/build sdk/node before installing each sample, or make each sample automate that prerequisite.

Close PTY input and observe the console relay asynchronously so shell exit does not wait for another keystroke.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 50ad2d13-4e54-49f2-a50d-0afaddc54611
Set the Node sample runtime floor to 24.21, remove obsolete IsolationSession build caveats, and use run-to-completion terminology.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 50ad2d13-4e54-49f2-a50d-0afaddc54611

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Several validation samples can report success without confirming the behavior they claim to demonstrate.

Review effort: Balanced
Findings: 6 High severity · 7 Medium severity · 14 Low severity

Open (27)

And 7 more that still need to be addressed.

Resolved since last review (1)
Previously missed (1)

In code that hasn't changed since last review

Low severity Remove stdin from the streaming behavior summary

samples/​README.md:16

The streaming implementations only consume stdout and stderr; none forwards stdin to the spawned process. Remove stdin from this summary so it does not advertise behavior the sample omits.

Copilot AI balanced review requested due to automatic review settings October 6, 2026 04:16
Add required IsolationSession networking, bounded persisted runs, enforcement assertions, accurate documentation, and fresh-checkout Node build steps.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 50ad2d13-4e54-49f2-a50d-0afaddc54611

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Several containment samples can falsely report success, and the documented Node workflow fails from a clean checkout.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Resolved since last review (27)

And 7 more resolved.

Previously missed (8)

In code that hasn't changed since last review

Medium severity Ensure success requires a successful read

samples/​run-with-containment-of-filesystem/​dotnet/​Program.cs:11

The readable control is not enforced: if input.txt is missing or unreadable, cat/type fails but the final success message makes the command exit 0. Chain the message to the read so this scenario actually proves the documented read access.

Medium severity Prevent success status after failed read

samples/​run-with-containment-of-filesystem/​node/​src/​main.ts:15

The readable control is not enforced: if input.txt is missing or unreadable, cat/type fails but the following success message resets the command status to 0. Chain the success message to the read so the sample cannot report success without proving read access.

Medium severity Chain success output to cat status

samples/​run-with-containment-of-filesystem/​rust/​src/​main.rs:16

The readable control is not enforced: if input.txt is missing or unreadable, cat fails but the final printf succeeds, so this sample still exits 0 while claiming the read worked. Chain the success message to cat so a failed read remains a failed workload.

Medium severity Reject zero-denial captures

samples/​run-with-logging-access-denied/​dotnet/​Program.cs:60

A successful capture artifact may contain zero denials, so this scenario can exit 0 without observing the intended blocked read. Reject a zero count before printing success.

Medium severity Validate totalDenials before reporting success

samples/​run-with-logging-access-denied/​node/​src/​main.ts:59

A successful capture artifact may contain zero denials, so this currently exits 0 even when the intended blocked read was not observed. Check totalDenials before reporting success.

Medium severity Reject capture reports with zero denials

samples/​run-with-logging-access-denied/​rust/​src/​main.rs:70

A capture report can validly contain zero denials, so merely finding metadata lets this scenario succeed without observing the intended blocked read. Reject total_denials == 0 before reporting success.

Low severity Document directory-level readonly grant

samples/​README.md:11

This description says one file is granted, but all three implementations put the entire sample directory in readonlyPaths and use it as the working directory. Describe the directory-level grant so readers do not infer narrower containment than the sample applies.

Low severity Remove stdin from streaming summary

samples/​README.md:16

None of the standard-I/O streaming implementations forwards stdin; they only consume live stdout and stderr. Remove stdin from this summary so it matches the scenario and its implementations.

Comment thread samples/README.md
- Requests use typed SDK models rather than JSON or generated wire types.
- Commands are harmless, bounded, and selected for the current operating system.
- Workload failures, timeouts, SDK errors, warnings, and cleanup failures remain visible.
- Projects reference the SDK in this repository so the samples track the current source.
Copilot AI balanced review requested due to automatic review settings October 6, 2026 04:24

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Network and telemetry samples can report false success, and Node source-run prerequisites remain incomplete.

Review effort: Balanced
Findings: 1 High severity · 1 Low severity

Open (2)
Previously missed (7)

In code that hasn't changed since last review

Medium severity Avoid sandbox loopback and validate policy with a positive control

samples/​run-with-containment-of-network/​dotnet/​Program.cs:20

The non-Windows branch is also used by Linux Bubblewrap, where 127.0.0.1 is private sandbox loopback rather than this host listener (docs/bwrap-support/bubblewrap-backend.md:276-280,752-759). Thus curl fails regardless of whether the requested policy is the cause, and the sample can falsely claim enforcement. Target a backend-reachable host address and validate it with a positive control.

Medium severity Use a reachable endpoint and establish a positive control

samples/​run-with-containment-of-network/​node/​src/​main.ts:28

On Linux, process containment uses Bubblewrap, where 127.0.0.1 refers to the sandbox itself rather than this Node server (docs/bwrap-support/bubblewrap-backend.md:276-280,752-759). The request consequently fails even without demonstrating that the deny policy blocked a reachable endpoint, so this can print a false success. Use a backend-reachable host address and establish a positive control first.

Medium severity Use a reachable host address and verify positive control

samples/​run-with-containment-of-network/​rust/​src/​main.rs:24

On Linux, Containment::Process resolves to Bubblewrap, whose private network namespace makes 127.0.0.1 the sandbox's own loopback, not the host endpoint (docs/bwrap-support/bubblewrap-backend.md:276-280,752-759). This curl therefore fails even if the requested deny policy is not what blocked access, and the sample reports a false containment success. Use a backend-reachable host address and verify a positive control before treating failure as policy enforcement.

Medium severity Handle RunAsync results and returned warnings

samples/​run-with-telemetry/​dotnet/​Program.cs:89

Ignoring RunAsync's result makes this sample return 0 for timed-out or nonzero workloads and suppresses all returned warnings. Handle the result like the other .NET run samples.

Medium severity Propagate execution results and warnings

samples/​run-with-telemetry/​node/​src/​main.ts:130

The execution result is discarded, so SDK warnings, timeouts, and nonzero workload exits are all reported as a successful sample run. Propagate the result consistently with the other Node scenarios.

Medium severity Inspect run results to expose workload failures

samples/​run-with-telemetry/​rust/​src/​main.rs:104

Discarding run's result hides telemetry warnings and reports success even when the workload times out or exits nonzero. Inspect the result as the other run-to-completion samples do so workload failures remain visible.

Medium severity Add mocked-native tests for Koffi pointer ownership

sdk/​node/​src/​bindings/​telemetry.ts:49

The telemetry tests replace the async binding implementation and do not exercise this ownership-critical Koffi declaration, so the pointer-conversion/freeing regression this change fixes could recur unnoticed. Add a binding-level mocked-native test, analogous to the probe ownership tests, that verifies decoding, freeing the original pointer, and unloading in order.

Comment thread samples/README.md
Comment on lines +28 to +29
Running a sample requires a supported and prepared host. See the applicable
backend guide under [`docs/`](../docs/) for platform-specific prerequisites.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:shipit:

@jsidewhite
Jeff Whiteside (jsidewhite) merged commit dc42ea0 into main Oct 6, 2026
31 checks passed
@jsidewhite
Jeff Whiteside (jsidewhite) deleted the user/jwhites/samples branch October 6, 2026 04:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants