Repository navigation
feat(process-container): discover identity-less loopback proxy support - #1406
Conversation
Retain explicit host-loopback opt-in and PSEC 1.1+ support-flag checks. Add compatibility gate tests and target-host proxy assertions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d91c468f-e7d6-4cfd-a21d-d01f30f2ae69
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 671f3dd1-048a-4b89-acb6-e762eae992af Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Report the PSEC 1.0-only proxy workaround through native discovery and the Rust, Node, and .NET V1 probe surfaces. Share the execution version gate, retain diagnostics, and document the narrow policy requirements. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 671f3dd1-048a-4b89-acb6-e762eae992af Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The runtime regression check can skip the workaround assertion, and the Rust README link is broken.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Enables scoped PSEC 1.0 proxy-loopback compatibility and exposes host capability discovery across supported SDKs.
Changes:
- Adds PSEC version gating and runtime workaround behavior.
- Exposes capability and probe facts through Rust, Node, and .NET V1 APIs.
- Adds tests, AOT coverage, and documentation.
| File | Description |
|---|---|
tests/scripts/run_processcontainer_network_proxy_test.ps1 |
Adds runtime workaround assertion. |
src/mxc-sdk/src/core/mxc_engine/probe.rs |
Adds backend capability discovery. |
src/mxc-sdk/src/backends/process_container/common/probe.rs |
Reports the probe fact and warnings. |
src/mxc-sdk/src/backends/process_container/common/base_container_runner.rs |
Implements the PSEC 1.0 workaround. |
src/mxc-sdk/README.md |
Documents Rust discovery APIs. |
src/ffi/mxc_ffi/tests/ffi.rs |
Accepts the new capability in FFI tests. |
sdk/node/tests/unit/probe.test.ts |
Tests Node probe parsing. |
sdk/node/tests/unit/platform.test.ts |
Tests Node discovery parsing. |
sdk/node/src/v1/types.ts |
Adds Node V1 types. |
sdk/node/src/v1/probe.ts |
Validates the new probe fact. |
sdk/node/src/v1/platform.ts |
Recognizes the discovery capability. |
sdk/node/README.md |
Documents Node discovery. |
sdk/dotnet/README.md |
Documents .NET discovery. |
sdk/dotnet/Microsoft.Mxc.Sdk/V1/PlatformDiscovery.cs |
Adds .NET V1 capability types. |
sdk/dotnet/Microsoft.Mxc.Sdk/V1/MxcPlatform.cs |
Maps the native capability. |
sdk/dotnet/Microsoft.Mxc.Sdk/V1/MxcContainer.cs |
Maps the probe fact. |
sdk/dotnet/Microsoft.Mxc.Sdk/MxcJsonSerialization.cs |
Registers AOT serialization metadata. |
sdk/dotnet/Microsoft.Mxc.Sdk.Tests/V1/MxcContainerTests.cs |
Tests .NET parsing and enum stability. |
sdk/dotnet/Microsoft.Mxc.Sdk.AotSmokeTest/Program.cs |
Exercises AOT serialization paths. |
docs/reference/rust/v1/types.md |
Updates Rust V1 reference types. |
docs/reference/node/v1/types.md |
Updates Node V1 reference types. |
docs/reference/dotnet/v1/types.md |
Updates .NET V1 reference types. |
docs/process-container/networking.md |
Documents compatibility semantics. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Carlos Alexandro Becker (caarlos0)
left a comment
There was a problem hiding this comment.
AI-assisted review of 381835f4, with independent code-review, maintainer, and anvil checks. The scoped workaround has a concrete use case; no critical production-code defect was found. The two inline findings confirm the existing automated comments after an independent source check.
No local builds or tests were run. Build success was assumed as requested; Windows runtime enforcement and .NET/AOT execution were not verified. This is a comment review because the PR belongs to the authenticated author.
Gate the PSEC 1.0 workaround assertions on the host probe instead of the runtime log. Require launch and the compatibility log, and exercise proxy reachability even when the first workload fails on an eligible host. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 671f3dd1-048a-4b89-acb6-e762eae992af Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 671f3dd1-048a-4b89-acb6-e762eae992af Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Carlos Alexandro Becker (caarlos0)
left a comment
There was a problem hiding this comment.
AI-assisted follow-up review of 381835f4..a7b85eca: no new findings. Both prior findings are addressed. The host capability now requires workload launch and the compatibility log, and enters the proxy-fetch check even when the initial launch fails. The Rust README link resolves to the existing document and heading. The addressed threads are resolved.
This supersedes my findings in review #1406 (review); the diagram there records the old behavior at 381835f4. No local builds or Windows runtime tests were run. Source review only; build success remains assumed. GitHub does not allow approval of my own PR, so this is a comment review.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 671f3dd1-048a-4b89-acb6-e762eae992af Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Preserve the harness's optional probe-field behavior under StrictMode. Missing proxy compatibility facts remain false; explicit true and false remain unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 671f3dd1-048a-4b89-acb6-e762eae992af Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Carlos Alexandro Becker (caarlos0)
left a comment
There was a problem hiding this comment.
AI-assisted incremental review of a7b85eca..3c030b36: no new findings. The optional probe-field check follows the adjacent compatibility checks for older binaries and retains the required launch/log/proxy-fetch assertions when the capability is present. The other network-test changes came from the merge of main (#1401), not a new branch change. All prior threads remain resolved.
This is the current verdict, superseding review #1406 (review). No local build or Windows runtime test was run; build success was assumed as requested. Comment review only because this is the authenticated author's PR.
|
Testing in CI: https://github.com/microsoft/mxc/actions/runs/37519009183 |
FWIW I manually tested on PSEC 1.0 and it works as expected. |
Address review feedback by keeping the compatibility explanation in the networking guide rather than repeating it in each V1 type reference. Leave all API declarations unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 671f3dd1-048a-4b89-acb6-e762eae992af Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Carlos Alexandro Becker (caarlos0)
left a comment
There was a problem hiding this comment.
AI-assisted incremental review of 3c030b36..f4d81337: no new findings. This removes only duplicate prose from the three SDK type references; their API declarations are unchanged. The canonical explanation and SDK README links remain. All review threads are resolved.
This supersedes my prior verdict in #1406 (review). No local build was run. Comment review only because this is the authenticated author's PR.
Address review feedback on capability naming and PSEC 1.1 support across all SDKs. Remove the SDK README details and redundant runtime warning, preserving capability-driven launch and proxy-reachability assertions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 19cfef35-3eab-4f33-ba4c-3408938fc50d Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Preserve identityless loopback proxy documentation and API references at their new upstream paths. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 19cfef35-3eab-4f33-ba4c-3408938fc50d Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Address review feedback confirmed against published Rust and Node 1.0.0 packages. Keep the existing ProbeFacts shape and expose identityless proxy support through backend discovery. Add source-compatibility regressions and keep capability-driven proxy checks. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 19cfef35-3eab-4f33-ba4c-3408938fc50d Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Address review feedback: document PSEC 1.0-only support and retain the ingress-flag requirement on PSEC 1.1 and newer hosts. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 19cfef35-3eab-4f33-ba4c-3408938fc50d Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
This reverts commit e6604eb at the author's request. Keep the output-only probe fact and preserve the later example documentation correction. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 19cfef35-3eab-4f33-ba4c-3408938fc50d Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 19cfef35-3eab-4f33-ba4c-3408938fc50d Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>



📖 Description
Support an identity-less loopback proxy on PSEC 1.0-only hosts and let callers discover that capability on both PSEC 1.0 and ingress-capable PSEC 1.1 hosts.
runtimeConfig.networkProxy,network.ingress.hostLoopback: "allow", and noprocessContainer.network.allowedProxyPeer. The existing Model 2 policy requirements still apply.identitylessLoopbackProxyin backend discovery andbaseContainerSupportsIdentitylessLoopbackProxyin the Windows request probe, with matching Rust, Node, and .NET V1 APIs.ingressHostLoopbackAllow. Version-query failures omit the capability, report a false probe fact, and retain a warning.docs/examples.md. SDK READMEs remain high-level. No redundant runtime compatibility warning is emitted.The signal reports host support, not whether a particular request will succeed or whether the proxy is reachable. Other requested features still require their own host support. The documented inbound host-to-container limitation remains; this does not establish full bidirectional host-loopback support.
The author chose to retain the request-probe output field. Commit
ce9bb314reverts the backend-discovery-only change ine6604eb2, while preserving the example correction in5557e86b. Ordinary callers that query and read results are unaffected by the added field; callers manually constructingProbeFactsor exhaustively destructuring it in Rust must account for it.🔗 References
🔍 Validation
Revert verification, before committing
ce9bb314:git diff --cached --checkgit diff --cached --exit-code e6604eb2^ -- . ':(exclude)docs/examples.md'e6604eb2, except the retained example correction.git diff --cached --exit-code HEAD -- docs/examples.md5557e86bwas untouched.node scripts/check-dotnet-api-parity.jsNo local build was repeated for the exact revert. Earlier local validation of the restored implementation at
a0defb90:src/cargo fmt --all -- --checksrc/CARGO_BUILD_JOBS=2 cargo test -p mxc-sdk --lib mxc_engine::probe::tests --quietsrc/CARGO_BUILD_JOBS=2 cargo test -p mxc_ffi --test ffi extern_discovery_returns_owned_json --quietsrc/CARGO_BUILD_JOBS=2 cargo clippy -p mxc-sdk --lib --tests --target x86_64-pc-windows-msvc --quiet -- -D warningssdk/node/npm run build:test-unitsdk/node/node --test dist-tests/tests/unit/probe.test.js dist-tests/tests/unit/platform.test.jsWindows runtime tests and the live Windows proxy suite were not executed on this macOS host. Cross-target compilation does not establish Windows enforcement. Local .NET tests and AOT execution were not run because
dotnetis unavailable. Native/SDK coverage includes PSEC support gates, renamed probe fields, discovery, and .NET AOT serialization.Earlier evidence, not a validation claim for the current head:
0db7aec8, including the Build run. CI must validate the revert head.3c030b36had failures in macOS Seatbelt and several Windows ProcessContainer T1 jobs. Their causes were not investigated in this feedback-only pass.Validation of the now-reverted backend-discovery-only harness and source-compatibility fixtures is not claimed as coverage of the restored request-probe path.
✅ Checklist
Cargo.lock, thedependency-feed-checkcheck passes (see pull request builds)📋 Issue Type
GitHub Actions runs the PR validation build automatically. The ADO pipeline
(
MXC-PR-Build) is the Azure version of the PR pipeline, kept in parity with the GitHubActions build; it runs on merge to
main, and Microsoft reviewers with write access can trigger iton a PR with
/azp run. See pull request builds.If the
dependency-feed-checkcheck fails on a new dependency, the crate must be added tothe feed before the PR can pass. See pull request builds
for the steps.
Microsoft Reviewers: Open in CodeFlow