Repository navigation
Document supported sandbox policy contracts - #1416
Gudge (MGudgin) wants to merge 2 commits into
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The new contract pages misstate cross-platform containment defaults, WSLC proxy requirements, and the abstract vm selection.
Review effort: Balanced
Findings: 3
Open (3)
What changed in this PR
Documents supported sandbox policy contracts and replaces retired policy references without runtime changes.
Changes:
- Adds contract documentation for 0.9, 1.0, and development 1.1.
- Removes retired 0.7/0.8 documentation.
- Updates SDK, backend, and test references.
| File | Description |
|---|---|
tests/scripts/run_lxc_network_no_network_test.sh |
Updates contract references. |
tests/scripts/lib/WinProcessContainer.Common.ps1 |
Updates networking reference. |
src/mxc-sdk/src/core/mxc_common/network_parser_ingress_default_tests.rs |
Updates test documentation. |
src/mxc-sdk/src/backends/bubblewrap/common/network_rules.rs |
Updates policy citation. |
sdk/node/README.md |
Links stable policy. |
sdk/dotnet/README.md |
Links stable policy. |
README.md |
Links policy index. |
docs/seatbelt/seatbelt-backend.md |
Updates policy guidance. |
docs/schema.md |
Introduces versioned policy documentation. |
docs/sandbox-policy/README.md |
Adds supported-contract index. |
docs/sandbox-policy/1.1.0/policy.md |
Documents development contract. |
docs/sandbox-policy/1.0.0/policy.md |
Documents stable contract. |
docs/sandbox-policy/0.9.0/policy.md |
Documents minimum supported contract. |
docs/sandbox-policy/0.8.0/policy.md |
Removes retired policy. |
docs/sandbox-policy/0.8.0/networking/schema-updates.md |
Removes retired migration document. |
docs/sandbox-policy/0.8.0/networking/networking.md |
Removes retired networking design. |
docs/sandbox-policy/0.7.0/policy.md |
Removes retired policy. |
docs/process-container/os-version-support.md |
Updates stable-policy link. |
docs/process-container/networking.md |
Updates shared-policy references. |
docs/process-container/guide.md |
Updates prerequisites and legacy guidance. |
docs/process-container/examples/0.8.0-schema.md |
Redirects historical guidance. |
docs/examples.md |
Updates networking references. |
docs/authoring-a-new-feature.md |
Updates authoring references. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
c9fdfe7 to
88cd785
Compare
88cd785 to
3678ee5
Compare
| **Contract acceptance is not execution authorization.** Selecting MicroVM, | ||
| Hyperlight, or Windows Sandbox requires the runtime `--experimental` option | ||
| (or the equivalent raw API option). The option does not make an unsupported | ||
| backend policy valid, and using the development version alone does not | ||
| authorize experimental execution. See [versioning](../../development/architecture/versioning.md#experimental-flag). |
|
|
||
| 1. [Configuration schema](../../schema.md): supported policy fields and their | ||
| default behavior. | ||
| 1. [Sandbox Policy spec](../../containment-configuration/1.0.0/policy.md): the stable exact |
There was a problem hiding this comment.
note: we should probably update all the non windows sandbox related places that have the word "sandbox" in the docs.
| @@ -0,0 +1,71 @@ | |||
| # MXC Sandbox Policy Spec v1.1.0-alpha | |||
There was a problem hiding this comment.
thought: do you think it would be jarring for folks to see v1.1 and then we have json apis? should we call it folder v1-dev since it'll technically be for all v1 not just v1.1.0.
Perhaps that might be for the best, then we can keep the actual future non-dev folders like 1.1 for when we release it. Thoughts on that?
| `1.0.0` is the current **stable** exact JSON contract and the target of the | ||
| high-level Rust, .NET, and Node V1 SDK APIs. Raw JSON callers must declare | ||
| `"version": "1.0.0"`; SDK policy callers do not supply a schema version. The | ||
| published [schema](../../../schemas/stable/mxc-config.schema.1.0.0.json) is | ||
| immutable. |
There was a problem hiding this comment.
thought: should we be talking about the policies in these files instead of the json? I think consumers might get confused about the json talk here but in our API reference docs we talk about strong types https://github.com/microsoft/mxc/tree/main/docs/api-reference
This PR adds versioned policy guides for the supported 0.9.0-alpha, 1.0.0, and development 1.1.0-alpha contracts. It removes retired 0.7.0 and 0.8.0 policy documents and redirects references to supported guidance. Details * Add a policy index and per-version fields, lifecycle, and migration guidance. * Remove retired policy pages and update docs, SDK README, and code links. Tests * `git diff --check` passed on the staged changes. * Inline Python (`python -`) validated 101 relative Markdown links, five policy JSON examples, and Markdown whitespace. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a30a59a8-e257-4e4b-9995-762f3611dabe Generated-with: gpt-6-sol
This PR fixes the documented containment defaults and proxy requirements in the supported sandbox policy contract guides. Details * Explain that omitted containment resolves the host-native process backend. * Distinguish WSLC's bridged cooperative proxy from proxy-only egress. * Separate abstract VM intent from explicit Windows Sandbox selection. Tests * `git diff --check` passed on the staged changes. * Inline `python -` checked the affected links, JSON examples, and review corrections across all three policy guides. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a30a59a8-e257-4e4b-9995-762f3611dabe Generated-with: gpt-6-sol
3678ee5 to
f4fbf2d
Compare
|
|
||
| | Surface | What the exact contract accepts | | ||
| |---|---| | ||
| | One-shot `vm` | Abstract VM intent. Resolves to `windows_sandbox` on Windows; no VM backend is implemented for other hosts. | |

This PR adds sandbox policy documentation for the supported
0.9.0-alpha,stable
1.0.0, and development1.1.0-alphaexact contracts. It removesthe retired 0.7 and 0.8 policy documents and replaces links to those pages
with supported guidance. No runtime behavior changes.
Details
migration guidance.
Tests
git diff --check— passed on the staged changes.python -(inline documentation checker) — passed: 101 relative Markdownlinks resolved, five policy JSON examples parsed, and no Markdown trailing
whitespace in changed files.
Microsoft Reviewers: Open in CodeFlow