Skip to content

Document supported sandbox policy contracts - #1416

Open
Gudge (MGudgin) wants to merge 1 commit into
mainfrom
user/gudge/policy_docs
Open

Gudge (MGudgin) wants to merge 1 commit into
mainfrom
user/gudge/policy_docs

Conversation

@MGudgin

@MGudgin Gudge (MGudgin) commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

This PR adds sandbox policy documentation for the supported 0.9.0-alpha,
stable 1.0.0, and development 1.1.0-alpha exact contracts. It removes
the retired 0.7 and 0.8 policy documents and replaces links to those pages
with supported guidance. No runtime behavior changes.

Details

  • Add an index and per-version request shapes, lifecycle coverage, and
    migration guidance.
  • Update documentation, SDK README, and source/test comment references.

Tests

  • git diff --check — passed on the staged changes.
  • python - (inline documentation checker) — passed: 101 relative Markdown
    links resolved, five policy JSON examples parsed, and no Markdown trailing
    whitespace in changed files.
  • Cargo and SDK suites not run (documentation and comment changes only).
Microsoft Reviewers: Open in CodeFlow

@MGudgin
Gudge (MGudgin) requested a review from a team as a code owner October 6, 2026 20:33
Copilot AI balanced review requested due to automatic review settings October 6, 2026 20:33
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The new contract pages misstate cross-platform containment defaults, WSLC proxy requirements, and the abstract vm selection.

Review effort: Balanced
Findings: 3 Low severity

Open (3)
What changed in this PR

Documents supported sandbox policy contracts and replaces retired policy references without runtime changes.

Changes:

  • Adds contract documentation for 0.9, 1.0, and development 1.1.
  • Removes retired 0.7/0.8 documentation.
  • Updates SDK, backend, and test references.
File Description
tests/​scripts/​run_lxc_network_no_network_test.sh Updates contract references.
tests/​scripts/​lib/​WinProcessContainer.Common.ps1 Updates networking reference.
src/​mxc-sdk/​src/​core/​mxc_common/​network_parser_ingress_default_tests.rs Updates test documentation.
src/​mxc-sdk/​src/​backends/​bubblewrap/​common/​network_rules.rs Updates policy citation.
sdk/​node/​README.md Links stable policy.
sdk/​dotnet/​README.md Links stable policy.
README.md Links policy index.
docs/​seatbelt/​seatbelt-backend.md Updates policy guidance.
docs/​schema.md Introduces versioned policy documentation.
docs/​sandbox-policy/​README.md Adds supported-contract index.
docs/​sandbox-policy/​1.1.0/​policy.md Documents development contract.
docs/​sandbox-policy/​1.0.0/​policy.md Documents stable contract.
docs/​sandbox-policy/​0.9.0/​policy.md Documents minimum supported contract.
docs/​sandbox-policy/​0.8.0/​policy.md Removes retired policy.
docs/​sandbox-policy/​0.8.0/​networking/​schema-updates.md Removes retired migration document.
docs/​sandbox-policy/​0.8.0/​networking/​networking.md Removes retired networking design.
docs/​sandbox-policy/​0.7.0/​policy.md Removes retired policy.
docs/​process-container/​os-version-support.md Updates stable-policy link.
docs/​process-container/​networking.md Updates shared-policy references.
docs/​process-container/​guide.md Updates prerequisites and legacy guidance.
docs/​process-container/​examples/​0.8.0-schema.md Redirects historical guidance.
docs/​examples.md Updates networking references.
docs/​authoring-a-new-feature.md Updates authoring references.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread docs/sandbox-policy/0.9.0/policy.md Outdated
Comment thread docs/sandbox-policy/1.0.0/policy.md Outdated
Comment thread docs/sandbox-policy/1.1.0/policy.md Outdated
Copilot AI balanced review requested due to automatic review settings October 6, 2026 20:56

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The documentation accurately reflects the registered exact contracts and removes stale references without affecting code behavior.

Review effort: Balanced
Findings: None

Resolved since last review (3)

Copilot AI balanced review requested due to automatic review settings October 6, 2026 23:04

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The documentation matches the registered exact contracts, and obsolete references were consistently removed.

Review effort: Balanced
Findings: None

Copilot AI balanced review requested due to automatic review settings October 6, 2026 23:22

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The development policy omits that vm requests on Windows require experimental authorization.

Review effort: Balanced
Findings: 1 Low severity

Open (1)

Comment on lines +67 to +71
**Contract acceptance is not execution authorization.** Selecting MicroVM,
Hyperlight, or Windows Sandbox requires the runtime `--experimental` option
(or the equivalent raw API option). The option does not make an unsupported
backend policy valid, and using the development version alone does not
authorize experimental execution. See [versioning](../../development/architecture/versioning.md#experimental-flag).

1. [Configuration schema](../../schema.md): supported policy fields and their
default behavior.
1. [Sandbox Policy spec](../../containment-configuration/1.0.0/policy.md): the stable exact

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

note: we should probably update all the non windows sandbox related places that have the word "sandbox" in the docs.

@@ -0,0 +1,71 @@
# MXC Sandbox Policy Spec v1.1.0-alpha

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thought: do you think it would be jarring for folks to see v1.1 and then we have json apis? should we call it folder v1-dev since it'll technically be for all v1 not just v1.1.0.

Perhaps that might be for the best, then we can keep the actual future non-dev folders like 1.1 for when we release it. Thoughts on that?

Comment on lines +5 to +9
`1.0.0` is the current **stable** exact JSON contract and the target of the
high-level Rust, .NET, and Node V1 SDK APIs. Raw JSON callers must declare
`"version": "1.0.0"`; SDK policy callers do not supply a schema version. The
published [schema](../../../schemas/stable/mxc-config.schema.1.0.0.json) is
immutable.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thought: should we be talking about the policies in these files instead of the json? I think consumers might get confused about the json talk here but in our API reference docs we talk about strong types https://github.com/microsoft/mxc/tree/main/docs/api-reference

Copilot AI balanced review requested due to automatic review settings October 7, 2026 02:35

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The 1.1 guide incorrectly states that vm resolves to Windows Sandbox, while runtime dispatch rejects it as unimplemented.

Review effort: Balanced
Findings: 2 Low severity

Open (2)


| Surface | What the exact contract accepts |
|---|---|
| One-shot `vm` | Abstract VM intent. Resolves to `windows_sandbox` on Windows; no VM backend is implemented for other hosts. |
This PR adds policy-first documentation for supported 0.9.0-alpha and 1.0.0
contracts and the mutable V1 development contract. It explains typed SDK
and raw JSON authoring without changing runtime behavior.

Details

* Add versioned policy guides and index, including backend enforcement limits.
* Clarify the Windows vm experimental gate and WSLC proxy behavior.
* Keep mutable V1 guidance in v1-dev, leaving 1.1.0 for a published release.
* Align generic containment terminology while preserving SDK and wire names.

Tests

* `git diff --cached --check` passed for the squashed tree.
* Inline Python validated 130 relative Markdown links and five policy JSON
  examples across 31 changed Markdown files.
* Verified the staged tree equals the backed-up pre-squash tree.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a30a59a8-e257-4e4b-9995-762f3611dabe
Generated-with: gpt-6-sol
Copilot AI balanced review requested due to automatic review settings October 7, 2026 15:42

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The documentation matches the registered exact contracts, parser defaults, SDK target, and backend validation behavior.

2 open findings

🧠 Review effort: Balanced

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants