Skip to content

feat(process-container): discover identity-less loopback proxy support - #1406

Merged
Carlos Alexandro Becker (caarlos0) merged 15 commits into
mainfrom
proxy-8d
Oct 6, 2026
Merged

Carlos Alexandro Becker (caarlos0) merged 15 commits into
mainfrom
proxy-8d

Conversation

@caarlos0

@caarlos0 Carlos Alexandro Becker (caarlos0) commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

📖 Description

Support an identity-less loopback proxy on PSEC 1.0-only hosts and let callers discover that capability on both PSEC 1.0 and ingress-capable PSEC 1.1 hosts.

  • Require explicit runtimeConfig.networkProxy, network.ingress.hostLoopback: "allow", and no processContainer.network.allowedProxyPeer. The existing Model 2 policy requirements still apply.
  • Report identitylessLoopbackProxy in backend discovery and baseContainerSupportsIdentitylessLoopbackProxy in the Windows request probe, with matching Rust, Node, and .NET V1 APIs.
  • Report support when normal host-loopback ingress is available, or when the host supports PSEC 1.0 but not 1.1. PSEC 1.1 or newer without the ingress flag remains unsupported; accepting a 1.0 payload does not bypass that requirement.
  • Keep this separate from general ingressHostLoopbackAllow. Version-query failures omit the capability, report a false probe fact, and retain a warning.
  • Require workload launch and a successful proxy fetch when the host probe advertises support. A clean rejection cannot skip those assertions. Older binaries that omit the fact retain the harness's existing fallback behavior.
  • Keep detailed documentation in the ProcessContainer networking guide and correct the host requirements in docs/examples.md. SDK READMEs remain high-level. No redundant runtime compatibility warning is emitted.
import { probe } from '@microsoft/mxc-sdk/v1';

const supported =
  probe().probes.baseContainerSupportsIdentitylessLoopbackProxy;
Host Identity-less loopback proxy
PSEC 1.0 only Supported
PSEC 1.1 or newer, with ingress support Supported
PSEC 1.1 or newer, without ingress support Not supported
No BaseContainer API Not supported

The signal reports host support, not whether a particular request will succeed or whether the proxy is reachable. Other requested features still require their own host support. The documented inbound host-to-container limitation remains; this does not establish full bidirectional host-loopback support.

The author chose to retain the request-probe output field. Commit ce9bb314 reverts the backend-discovery-only change in e6604eb2, while preserving the example correction in 5557e86b. Ordinary callers that query and read results are unaffected by the added field; callers manually constructing ProbeFacts or exhaustively destructuring it in Rust must account for it.

🔗 References

🔍 Validation

Revert verification, before committing ce9bb314:

Directory Command Result
Repository root git diff --cached --check Passed.
Repository root git diff --cached --exit-code e6604eb2^ -- . ':(exclude)docs/examples.md' Passed: exact restoration of the tree before e6604eb2, except the retained example correction.
Repository root git diff --cached --exit-code HEAD -- docs/examples.md Passed: the correction in 5557e86b was untouched.
Repository root node scripts/check-dotnet-api-parity.js Passed.

No local build was repeated for the exact revert. Earlier local validation of the restored implementation at a0defb90:

Directory Command Result
src/ cargo fmt --all -- --check Passed.
src/ CARGO_BUILD_JOBS=2 cargo test -p mxc-sdk --lib mxc_engine::probe::tests --quiet Passed: 9 tests.
src/ CARGO_BUILD_JOBS=2 cargo test -p mxc_ffi --test ffi extern_discovery_returns_owned_json --quiet Passed: 1 test.
src/ CARGO_BUILD_JOBS=2 cargo clippy -p mxc-sdk --lib --tests --target x86_64-pc-windows-msvc --quiet -- -D warnings Passed, including Windows-gated test compilation.
sdk/node/ npm run build:test-unit Passed.
sdk/node/ node --test dist-tests/tests/unit/probe.test.js dist-tests/tests/unit/platform.test.js Passed: 96 tests; 40 platform-dependent tests skipped.

Windows runtime tests and the live Windows proxy suite were not executed on this macOS host. Cross-target compilation does not establish Windows enforcement. Local .NET tests and AOT execution were not run because dotnet is unavailable. Native/SDK coverage includes PSEC support gates, renamed probe fields, discovery, and .NET AOT serialization.

Earlier evidence, not a validation claim for the current head:

Validation of the now-reverted backend-discovery-only harness and source-compatibility fixtures is not claimed as coverage of the restored request-probe path.

✅ Checklist

📋 Issue Type

  • Bug fix
  • Feature
  • Task

GitHub Actions runs the PR validation build automatically. The ADO pipeline
(MXC-PR-Build) is the Azure version of the PR pipeline, kept in parity with the GitHub
Actions build; it runs on merge to main, and Microsoft reviewers with write access can trigger it
on a PR with /azp run. See pull request builds.

If the dependency-feed-check check fails on a new dependency, the crate must be added to
the feed before the PR can pass. See pull request builds
for the steps.

Microsoft Reviewers: Open in CodeFlow

Retain explicit host-loopback opt-in and PSEC 1.1+ support-flag checks. Add compatibility gate tests and target-host proxy assertions.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d91c468f-e7d6-4cfd-a21d-d01f30f2ae69
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 671f3dd1-048a-4b89-acb6-e762eae992af
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Report the PSEC 1.0-only proxy workaround through native discovery and the Rust, Node, and .NET V1 probe surfaces. Share the execution version gate, retain diagnostics, and document the narrow policy requirements.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 671f3dd1-048a-4b89-acb6-e762eae992af
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 14:59

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The runtime regression check can skip the workaround assertion, and the Rust README link is broken.

Review effort: Balanced
Findings: 1 Medium severity · 1 Low severity

Open (2)
What changed in this PR

Enables scoped PSEC 1.0 proxy-loopback compatibility and exposes host capability discovery across supported SDKs.

Changes:

  • Adds PSEC version gating and runtime workaround behavior.
  • Exposes capability and probe facts through Rust, Node, and .NET V1 APIs.
  • Adds tests, AOT coverage, and documentation.
File Description
tests/​scripts/​run_processcontainer_network_proxy_test.ps1 Adds runtime workaround assertion.
src/​mxc-sdk/​src/​core/​mxc_engine/​probe.rs Adds backend capability discovery.
src/​mxc-sdk/​src/​backends/​process_container/​common/​probe.rs Reports the probe fact and warnings.
src/​mxc-sdk/​src/​backends/​process_container/​common/​base_container_runner.rs Implements the PSEC 1.0 workaround.
src/​mxc-sdk/​README.md Documents Rust discovery APIs.
src/​ffi/​mxc_ffi/​tests/​ffi.rs Accepts the new capability in FFI tests.
sdk/​node/​tests/​unit/​probe.test.ts Tests Node probe parsing.
sdk/​node/​tests/​unit/​platform.test.ts Tests Node discovery parsing.
sdk/​node/​src/​v1/​types.ts Adds Node V1 types.
sdk/​node/​src/​v1/​probe.ts Validates the new probe fact.
sdk/​node/​src/​v1/​platform.ts Recognizes the discovery capability.
sdk/​node/​README.md Documents Node discovery.
sdk/​dotnet/​README.md Documents .NET discovery.
sdk/​dotnet/​Microsoft.Mxc.Sdk/​V1/​PlatformDiscovery.cs Adds .NET V1 capability types.
sdk/​dotnet/​Microsoft.Mxc.Sdk/​V1/​MxcPlatform.cs Maps the native capability.
sdk/​dotnet/​Microsoft.Mxc.Sdk/​V1/​MxcContainer.cs Maps the probe fact.
sdk/​dotnet/​Microsoft.Mxc.Sdk/​MxcJsonSerialization.cs Registers AOT serialization metadata.
sdk/​dotnet/​Microsoft.Mxc.Sdk.Tests/​V1/​MxcContainerTests.cs Tests .NET parsing and enum stability.
sdk/​dotnet/​Microsoft.Mxc.Sdk.AotSmokeTest/​Program.cs Exercises AOT serialization paths.
docs/​reference/​rust/​v1/​types.md Updates Rust V1 reference types.
docs/​reference/​node/​v1/​types.md Updates Node V1 reference types.
docs/​reference/​dotnet/​v1/​types.md Updates .NET V1 reference types.
docs/​process-container/​networking.md Documents compatibility semantics.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread tests/scripts/run_processcontainer_network_proxy_test.ps1 Outdated
Comment thread src/mxc-sdk/README.md Outdated
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-assisted review of 381835f4, with independent code-review, maintainer, and anvil checks. The scoped workaround has a concrete use case; no critical production-code defect was found. The two inline findings confirm the existing automated comments after an independent source check.

No local builds or tests were run. Build success was assumed as requested; Windows runtime enforcement and .NET/AOT execution were not verified. This is a comment review because the PR belongs to the authenticated author.

Comment thread tests/scripts/run_processcontainer_network_proxy_test.ps1 Outdated
Comment thread src/mxc-sdk/README.md Outdated
Gate the PSEC 1.0 workaround assertions on the host probe instead of the runtime log. Require launch and the compatibility log, and exercise proxy reachability even when the first workload fails on an eligible host.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 671f3dd1-048a-4b89-acb6-e762eae992af
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 671f3dd1-048a-4b89-acb6-e762eae992af
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 15:32

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-assisted follow-up review of 381835f4..a7b85eca: no new findings. Both prior findings are addressed. The host capability now requires workload launch and the compatibility log, and enters the proxy-fetch check even when the initial launch fails. The Rust README link resolves to the existing document and heading. The addressed threads are resolved.

This supersedes my findings in review #1406 (review); the diagram there records the old behavior at 381835f4. No local builds or Windows runtime tests were run. Source review only; build success remains assumed. GitHub does not allow approval of my own PR, so this is a comment review.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The PowerShell capability reader can abort under strict mode when used with an older probe binary.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Resolved since last review (2)

Comment thread tests/scripts/lib/WinProcessContainer.Common.ps1 Outdated
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 671f3dd1-048a-4b89-acb6-e762eae992af
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Preserve the harness's optional probe-field behavior under StrictMode. Missing proxy compatibility facts remain false; explicit true and false remain unchanged.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 671f3dd1-048a-4b89-acb6-e762eae992af
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 16:08

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-assisted incremental review of a7b85eca..3c030b36: no new findings. The optional probe-field check follows the adjacent compatibility checks for older binaries and retains the required launch/log/proxy-fetch assertions when the capability is present. The other network-test changes came from the merge of main (#1401), not a new branch change. All prior threads remain resolved.

This is the current verdict, superseding review #1406 (review). No local build or Windows runtime test was run; build success was assumed as requested. Comment review only because this is the authenticated author's PR.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The security-sensitive Windows networking workaround is well covered in code but lacks a live PSEC 1.0 runtime validation.

Review effort: Balanced
Findings: None

Resolved since last review (1)

@theelliotm

Copy link
Copy Markdown
Contributor

@caarlos0

Copy link
Copy Markdown
Collaborator Author

Testing in CI: https://github.com/microsoft/mxc/actions/runs/37519009183

Seems like all the images are on PSEC 1.1.

FWIW I manually tested on PSEC 1.0 and it works as expected.

Comment thread docs/reference/dotnet/v1/types.md Outdated
Comment thread docs/reference/node/v1/types.md Outdated
Comment thread docs/reference/rust/v1/types.md Outdated
Address review feedback by keeping the compatibility explanation in the networking guide rather than repeating it in each V1 type reference. Leave all API declarations unchanged.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 671f3dd1-048a-4b89-acb6-e762eae992af
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

AI-assisted incremental review of 3c030b36..f4d81337: no new findings. This removes only duplicate prose from the three SDK type references; their API declarations are unchanged. The canonical explanation and SDK README links remain. All review threads are resolved.

This supersedes my prior verdict in #1406 (review). No local build was run. Comment review only because this is the authenticated author's PR.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It changes Windows security-environment enforcement, and the latest referenced validation run still contains failures requiring human review.

Review effort: Balanced
Findings: None

Comment thread docs/process-container/networking.md Outdated
Comment thread sdk/dotnet/Microsoft.Mxc.Sdk/V1/PlatformDiscovery.cs Outdated
Comment thread sdk/dotnet/README.md Outdated
Comment thread src/mxc-sdk/src/backends/process_container/common/base_container_runner.rs Outdated
Address review feedback on capability naming and PSEC 1.1 support across all SDKs. Remove the SDK README details and redundant runtime warning, preserving capability-driven launch and proxy-reachability assertions.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 19cfef35-3eab-4f33-ba4c-3408938fc50d
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 22:13
@caarlos0 Carlos Alexandro Becker (caarlos0) changed the title feat(process-container): expose PSEC 1.0 proxy compatibility feat(process-container): discover identity-less loopback proxy support Oct 6, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It changes Windows PSEC policy enforcement, while live Windows validation for the latest revision and current CI remain incomplete.

Review effort: Balanced
Findings: None

Preserve identityless loopback proxy documentation and API references at their new upstream paths.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 19cfef35-3eab-4f33-ba4c-3408938fc50d
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The Rust and Node V1 type additions break published API compatibility, and an existing example retains contradictory PSEC requirements.

Review effort: Balanced
Findings: 2 High severity · 1 Low severity

Open (3)

Comment thread sdk/node/src/v1/types.ts
Comment thread src/mxc-sdk/src/backends/process_container/common/probe.rs
Comment thread docs/backends/process-container/networking.md
Address review feedback confirmed against published Rust and Node 1.0.0 packages. Keep the existing ProbeFacts shape and expose identityless proxy support through backend discovery. Add source-compatibility regressions and keep capability-driven proxy checks.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 19cfef35-3eab-4f33-ba4c-3408938fc50d
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Address review feedback: document PSEC 1.0-only support and retain the ingress-flag requirement on PSEC 1.1 and newer hosts.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 19cfef35-3eab-4f33-ba4c-3408938fc50d
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 22:58

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The advertised V1 request-probe fact is absent from the native and SDK probe surfaces.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
Resolved since last review (3)

Comment thread src/mxc-sdk/tests/sdk_helpers.rs Outdated
This reverts commit e6604eb at the author's request. Keep the output-only probe fact and preserve the later example documentation correction.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 19cfef35-3eab-4f33-ba4c-3408938fc50d
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 23:07
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 19cfef35-3eab-4f33-ba4c-3408938fc50d
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The required Rust and Node V1 probe fields break published source compatibility.

Review effort: Balanced
Findings: 2 High severity

Open (2)
Resolved since last review (1)

Comment thread sdk/node/src/v1/types.ts
Comment thread src/mxc-sdk/src/backends/process_container/common/probe.rs
Copilot AI balanced review requested due to automatic review settings October 6, 2026 23:12

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The OS-sensitive Windows enforcement path lacks live validation on the exact head, while current CI is still running.

Review effort: Balanced
Findings: None

Resolved since last review (2)

@caarlos0
Carlos Alexandro Becker (caarlos0) merged commit 70fc7d5 into main Oct 6, 2026
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants