Repository navigation
Remove remaining pre-v0.9 runtime vestiges - #1425
Closed
Gudge (MGudgin) wants to merge 1 commit into
Closed
Gudge (MGudgin) wants to merge 1 commit into
Gudge (MGudgin) wants to merge 1 commit into
Conversation
This PR removes obsolete shared network fields, the built-in test proxy, and retired CLI testing switches after the backends adopt supported directional policy. Caller-managed proxy behavior remains available. Details * Drop unrepresentable runtime fields and ownerless Unix coordinator. * Simplify ProcessContainer ownership and preserve network audits. * Keep published schemas immutable and update active guidance. Tests * cargo fmt --all -- --check and cargo test --workspace --quiet: passed. * cargo check --workspace --all-targets --all-features --quiet: passed. * cargo clippy --workspace --all-targets --all-features --quiet -- -D warnings: passed. * Feature suite: 3292 passed, 3 ignored; Linux LXC/Bwrap: 603 passed. * Linux host suite and macOS target check passed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 7570a662-a429-46d2-aa24-47fae6655cc4 Generated-with: gpt-6-sol
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
3 of 8 tasks
Contributor
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The sweeping cross-platform enforcement cleanup has an inaccurate Windows Sandbox support matrix and lacks native macOS and live LXC validation.
Review effort: Balanced
Findings: 1
What changed in this PR
Retires pre-v0.9 runtime compatibility paths while retaining exact contracts and supported directional networking.
Changes:
- Removes legacy network/environment markers, built-in proxy plumbing, and testing CLI switches.
- Simplifies backend policy enforcement around directional networking.
- Updates integration tests, SDK references, and backend documentation.
| File | Description |
|---|---|
tests/scripts/run_processcontainer_network_proxy_test.ps1 |
Requires downlevel proxy rejection. |
tests/scripts/run_processcontainer_network_loopback_test.ps1 |
Requires downlevel loopback rejection. |
tests/scripts/run_lxc_network_no_network_test.sh |
Updates default-deny references. |
tests/scripts/run_bwrap_network_proxy_test.sh |
Removes retired CLI flag. |
tests/scripts/run_bwrap_localnet_test.sh |
Removes retired CLI flag. |
tests/scripts/run_bwrap_inbound_deny_test.sh |
Removes retired CLI flag. |
tests/scripts/run_bwrap_firewall_test.sh |
Removes retired CLI flag. |
tests/scripts/run_bwrap_directional_test.sh |
Updates proxy parity testing. |
tests/scripts/lib/WinProcessContainer.Common.ps1 |
Updates contract reference. |
tests/configs/bubblewrap_network_proxy_parity_implicit_ingress.json |
Replaces legacy-named proxy fixture. |
tests/configs/bubblewrap_network_directional_proxy.json |
Removes guest curl dependency. |
src/tools/wxc/src/main.rs |
Removes testing-features switch. |
src/tools/mxc_darwin/src/main.rs |
Removes testing-features switch. |
src/tools/lxc/src/main.rs |
Removes testing-features switch. |
src/testing/wxc_test_proxy/src/main.rs |
Reframes proxy as caller-managed. |
src/testing/wxc_test_proxy/README.md |
Documents external proxy ownership. |
src/testing/wxc_test_driver/src/main.rs |
Removes built-in proxy detection. |
src/testing/unix_test_proxy/src/main.rs |
Documents caller-managed usage. |
src/mxc-sdk/tests/mxc_common_proxy_env_spec.rs |
Updates proxy model tests. |
src/mxc-sdk/tests/mxc_common_proxy_address_spec.rs |
Updates proxy usage documentation. |
src/mxc-sdk/src/policy.rs |
Removes compatibility assertion. |
src/mxc-sdk/src/core/mxc_engine/run.rs |
Removes compatibility attribution tests. |
src/mxc-sdk/src/core/mxc_common/wire.rs |
Removes retired wire fields. |
src/mxc-sdk/src/core/mxc_common/validator.rs |
Removes legacy validation paths. |
src/mxc-sdk/src/core/mxc_common/state_aware_binding_tests.rs |
Updates proxy snapshots. |
src/mxc-sdk/src/core/mxc_common/sdk_input.rs |
Maps directional fields directly. |
src/mxc-sdk/src/core/mxc_common/script_runner.rs |
Uses empty feature support. |
src/mxc-sdk/src/core/mxc_common/sandbox_process.rs |
Updates default network support. |
src/mxc-sdk/src/core/mxc_common/policy_identity.rs |
Removes retired hash inputs. |
src/mxc-sdk/src/core/mxc_common/network_parser.rs |
Parses runtime proxy URLs directly. |
src/mxc-sdk/src/core/mxc_common/network_parser_ingress_default_tests.rs |
Updates directional default tests. |
src/mxc-sdk/src/core/mxc_common/models.rs |
Removes legacy runtime models. |
src/mxc-sdk/src/core/mxc_common/mod.rs |
Removes Unix proxy coordinator. |
src/mxc-sdk/src/core/mxc_common/error.rs |
Removes host-list error constant. |
src/mxc-sdk/src/core/mxc_common/diagnostic.rs |
Redacts runtime proxy credentials. |
src/mxc-sdk/src/core/mxc_common/default_env.rs |
Removes environment compatibility marker. |
src/mxc-sdk/src/core/mxc_common/config_parser.rs |
Simplifies normalized requests. |
src/mxc-sdk/src/core/mxc_common/config_contract_adapters/v1_0/state_aware.rs |
Removes compatibility scaffolding. |
src/mxc-sdk/src/core/mxc_common/config_contract_adapters/v1_0/state_aware_tests/exec.rs |
Updates adapter assertions. |
src/mxc-sdk/src/core/mxc_common/config_contract_adapters/v1_0/one_shot.rs |
Removes compatibility scaffolding. |
src/mxc-sdk/src/core/mxc_common/config_contract_adapters/v1_0/one_shot_tests/stable_candidate.rs |
Updates wire assertions. |
src/mxc-sdk/src/core/mxc_common/config_contract_adapters/v1_0/common.rs |
Maps directional network only. |
src/mxc-sdk/src/core/mxc_common/config_contract_adapters/v0_9/state_aware.rs |
Removes compatibility scaffolding. |
src/mxc-sdk/src/core/mxc_common/config_contract_adapters/v0_9/state_aware_tests/exec.rs |
Updates adapter assertions. |
src/mxc-sdk/src/core/mxc_common/config_contract_adapters/v0_9/one_shot.rs |
Removes compatibility scaffolding. |
src/mxc-sdk/src/core/mxc_common/config_contract_adapters/v0_9/one_shot_tests/stable_candidate.rs |
Updates wire assertions. |
src/mxc-sdk/src/core/mxc_common/config_contract_adapters/v0_9/common.rs |
Maps directional network only. |
src/mxc-sdk/src/core/mxc_common/config_contract_adapters/dev/state_aware.rs |
Removes compatibility scaffolding. |
src/mxc-sdk/src/core/mxc_common/config_contract_adapters/dev/state_aware_tests/provision.rs |
Updates network assertions. |
src/mxc-sdk/src/core/mxc_common/config_contract_adapters/dev/state_aware_tests/exec.rs |
Updates adapter assertions. |
src/mxc-sdk/src/core/mxc_common/config_contract_adapters/dev/one_shot.rs |
Removes compatibility scaffolding. |
src/mxc-sdk/src/core/mxc_common/config_contract_adapters/dev/one_shot_tests/stable_candidate.rs |
Updates wire assertions. |
src/mxc-sdk/src/core/mxc_common/config_contract_adapters/dev/common.rs |
Maps directional network only. |
src/mxc-sdk/src/core/mxc_common/common_request_ir.rs |
Removes compatibility markers. |
src/mxc-sdk/src/core/mxc_common/audit.rs |
Removes legacy vocabulary test. |
src/mxc-sdk/src/configs/process_container.rs |
Removes compatibility assertion. |
src/mxc-sdk/src/backends/wslc/common/state_aware.rs |
Uses directional network posture. |
src/mxc-sdk/src/backends/wslc/common/process_env.rs |
Removes environment marker. |
src/mxc-sdk/src/backends/wslc/common/policy_mapping.rs |
Removes host-list plumbing. |
src/mxc-sdk/src/backends/windows_sandbox/lifecycle/state_aware.rs |
Updates immutable-policy validation. |
src/mxc-sdk/src/backends/windows_sandbox/lifecycle/policy.rs |
Validates directional policy directly. |
src/mxc-sdk/src/backends/windows_sandbox/lifecycle/one_shot.rs |
Updates network support declaration. |
src/mxc-sdk/src/backends/seatbelt/common/seatbelt_policy.rs |
Removes legacy policy branches. |
src/mxc-sdk/src/backends/seatbelt/common/default_env.rs |
Removes environment marker. |
src/mxc-sdk/src/backends/process_container/common/proxy_coordinator.rs |
Removes built-in proxy ownership. |
src/mxc-sdk/src/backends/process_container/common/network_policy_helpers.rs |
Centralizes directional capability auditing. |
src/mxc-sdk/src/backends/process_container/common/mod.rs |
Removes legacy network manager. |
src/mxc-sdk/src/backends/process_container/common/dispatcher.rs |
Updates proxy model usage. |
src/mxc-sdk/src/backends/process_container/common/base_container_helpers.rs |
Uses directional defaults. |
src/mxc-sdk/src/backends/lxc/common/signal_cleanup.rs |
Updates directional test policy. |
src/mxc-sdk/src/backends/lxc/common/network_ingress_permissive_spec_tests.rs |
Deletes legacy ingress tests. |
src/mxc-sdk/src/backends/lxc/common/lxc_bindings.rs |
Removes obsolete proxy-env test. |
src/mxc-sdk/src/backends/isolation_session/common/state_aware.rs |
Updates proxy model usage. |
src/mxc-sdk/src/backends/isolation_session/common/policy.rs |
Validates directional allow posture. |
sdk/node/README.md |
Links supported networking guide. |
sdk/dotnet/README.md |
Links supported networking guide. |
sdk/dotnet/Microsoft.Mxc.Sdk/V1/ContainerRequestSections.cs |
Updates network API documentation. |
README.md |
Removes retired policy link. |
docs/wsl/wsl-container-getting-started.md |
Documents directional WSLC rejection. |
docs/windows-sandbox/windows-sandbox.md |
Updates network support matrix. |
docs/versioning.md |
Clarifies immutable contract behavior. |
docs/telemetry/telemetry.md |
Documents revised network auditing. |
docs/seatbelt/seatbelt-backend.md |
Removes legacy migration guidance. |
docs/schema.md |
Consolidates supported networking guidance. |
docs/sandbox-policy/0.8.0/policy.md |
Deletes retired policy guide. |
docs/sandbox-policy/0.8.0/networking/schema-updates.md |
Deletes retired migration guide. |
docs/reference/dotnet/v1/types.md |
Updates network references and floor. |
docs/process-container/os-version-support.md |
Distinguishes retired network matrix. |
docs/process-container/networking.md |
Updates enforcement and audit guidance. |
docs/process-container/guide.md |
Updates supported network prerequisites. |
docs/process-container/examples/0.8.0-schema.md |
Reframes proxy manifest example. |
docs/nanvix-microvm/nanvix.md |
Removes legacy host-filter guidance. |
docs/lxc-support/lxc-backend.md |
Documents directional-only behavior. |
docs/examples.md |
Links current schema guidance. |
docs/ci-validation-infrastructure.md |
Updates directional test descriptions. |
docs/bwrap-support/bubblewrap-backend.md |
Clarifies unsupported policies. |
docs/authoring-a-new-feature.md |
Replaces retired policy references. |
build-mac.sh |
Retains externally managed test proxy. |
.github/workflows/Build.Linux.Job.yml |
Updates proxy test description. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| | Default network policy `allow` | Rejected | | ||
| | `allowedHosts` / `blockedHosts` | Rejected | | ||
| | Omitted network policy | Guest firewall blocks external networking | | ||
| | Directional allow or egress rules | Rejected; the guest cannot enforce them | |
Gudge (MGudgin)
force-pushed
the
user/gudge/retire-network-combined
branch
from
October 6, 2026 21:23
355ab53 to
5102a7a
Compare
Gudge (MGudgin)
changed the base branch from
main
to
user/gudge/retire-network-unix
October 6, 2026 21:24
Member
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

📖 Description
This PR removes the remaining pre-v0.9 runtime vestiges after the backend cleanup in the preceding stack PRs. It drops obsolete shared network fields, the built-in test proxy, retired CLI testing switches, and the unused Unix proxy coordinator while preserving supported directional and caller-managed proxy behavior.
Details
🔗 References
Depends on #1424; the stack begins at #1421. #1397 is the single-commit alternative to these five PRs; merge either the stack or the combined PR, not both. Follows #1382 and #1383.
🔍 Validation
Tests
src/,cargo fmt --all -- --check: passed.cargo check --workspace --all-targets --all-features --quiet: passed.cargo clippy --workspace --all-targets --all-features --quiet -- -D warnings: passed.cargo test --workspace --quiet: passed.cargo test -p mxc-sdk --lib --features wslc,isolation_session,microvm,hyperlight --quiet: 3,292 passed, 3 ignored.cargo check -p mxc-sdk --all-targets --target x86_64-apple-darwin --quiet: passed.src/,cargo check -p mxc-sdk --all-targets --quiet: passed.cargo test -p mxc-sdk --lib lxc::common --quiet -- --test-threads=1: 302 passed.cargo test -p mxc-sdk --lib bubblewrap::common --quiet -- --test-threads=1: 301 passed.cargo build -p lxc -p unix_test_proxy --quiet: passed;bash ../tests/scripts/run_bwrap_directional_test.sh: nine checks passed.node --test scripts/versioning/tests/check-contract-codegen.test.js: 9 passed;node scripts/versioning/check-contract-codegen.js --check: passed, three artifact sets matched.✅ Checklist
Cargo.lock, thedependency-feed-checkcheck passes (see docs/pull-requests.md)📋 Issue Type
GitHub Actions runs the PR validation build automatically. The ADO pipeline
(
MXC-PR-Build) is the Azure version of the PR pipeline, kept in parity with the GitHubActions build; it runs on merge to
main, and Microsoft reviewers with write access can trigger iton a PR with
/azp run. See docs/pull-requests.md.If the
dependency-feed-checkcheck fails on a new dependency, the crate must be added tothe feed before the PR can pass. See docs/pull-requests.md
for the steps.
Microsoft Reviewers: Open in CodeFlow