You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Consume published IsolationSession SDK NuGet package - #1440
Replace the checked-in IsolationSession SDK package with the published Microsoft.AI.IsolationSession.SDK package while preserving MXC's existing
default and inbox behavior.
Build modes
Default builds still enable neither IsolationSession feature.
isolation_session continues to use committed bindings and the inbox Windows
runtime.
isolation_session_lifted restores the pinned SDK package, generates bindings
from its WinMDs, and stages IsoSessionApp.dll plus IsoSession.manifest for registration-free activation. The published runtime
payload is AMD64, so lifted mode is explicitly x64-only.
Managed equivalents remain MxcWithIsolationSession=true for inbox and MxcIsolationSessionLifted=true for lifted.
Package acquisition and validation
Pins Microsoft.AI.IsolationSession.SDK version 0.202610.5.
Restores through NuGet using the repository-configured public MxcDependencies source rather than contacting NuGet.org directly.
Uses an MXC-owned NuGet cache under the Cargo target profile; NuGet creates
the normal extracted package and metadata layout.
Preserves the explicit ISOLATION_SESSION_SDK_PACKAGE offline override.
Independently verifies the package SHA-256 before using its contents.
Validates package structure, runtime identity, manifest metadata, PE
architecture, and staged payload hashes.
Rejects lifted ARM64 and multi-RID builds before native compilation or
packaging.
Keeps committed inbox-binding provenance separate from updater-managed
lifted-package provenance.
Adds authenticated feed-seeding support for the locked Cargo dependencies and
pinned IsolationSession SDK package.
Builds and tests the lifted managed SDK, pins the build-switch test, packs a win-x64 NuGet package, and verifies both runtime payload files are present.
Reconciles stale lifted payloads when Cargo switches between feature
fingerprints.
Removes the invalid standalone lifted-activation Cargo feature, so every
selectable feature combination acquires the matching bindings and payload.
Runs package validation through the normal Cargo integration-test harness.
Keeps inbox and lifted activation diagnostics mode-correct.
Balances COM initialization owned by lifted activation on the originating
thread.
Restores the current one-shot contract and policy documentation, adding only
the new acquisition and activation details.
Validation
Validated after rebasing onto main at 1ce2f68c6dc91b678be464fdcb917dfa66501360 on October 7, 2026:
Managed lifted pack and archive-content verification
Lifted ARM64 and multi-RID batch/MSBuild rejection checks
Updater idempotence and inbox-provenance stability
Package and staged payload SHA-256 verification
The full inbox integration suite additionally reaches host-dependent
IsolationSession operations; this development host returns 0x80070520 for
five logon-dependent cases. That host/session limitation is separate from
package acquisition and compilation.
Feed prerequisite
Before governed CI can pass, run the manually triggered MXC-Update-Feed-Dependencies pipeline (definition 33) for PR #1440. It seeds:
windows-bindgen0.62.1 into the Cargo feed
Microsoft.AI.IsolationSession.SDK0.202610.5 into the NuGet feed
The current CLI identity is not authorized to queue that shine-oss pipeline;
the public feed correctly reports both packages as not yet cached.
The build script reads only ../Cargo.lock. A published mxc-sdk package can place Cargo.lock at the crate root, which the previous implementation supported. A consumer enabling isolation_session can therefore panic before compilation. Restore lookup at both the package root and workspace root, with an explicit error when neither exists.
Suggestion
src/mxc-sdk/src/backends/isolation_session/common/regfree.rs:89-94 — balance successful COM initialization
Successful CoInitializeEx calls are not paired with CoUninitialize. Repeated activation calls may accumulate per-thread COM initialization references and prevent embedded hosts from restoring their previous COM state.
Residual risk
The package exposes one leaf-named runtime/IsoSessionApp.dll and validates it against the target architecture. If the published package contains only one machine type, another lifted architecture fails closed. The review did not independently prove every package architecture, so this remains a validation/documentation risk rather than a confirmed defect.
The opt-in repository-variable gate for lifted CI was reviewed and dropped as a false positive because it is explicitly documented as intentional.
Fixed in 0d9624fe722b45a378a85c3006735b5648890164.
The inbox binding verifier now searches for Cargo.lock at both the packaged crate root and the workspace root, reports both attempted paths if neither exists, and registers the selected lockfile plus GENERATION_INFO.toml as build-script rerun inputs.
The reason will be displayed to describe this comment to others. Learn more.
The code-side remediation is in 1040b76: definition 33 now seeds both locked Cargo dependencies and the pinned IsolationSession NuGet package, with authenticated NuGet publication and hash verification. Current CI confirms windows-bindgen 0.62.1 is still not cached, and the public NuGet feed likewise reports Microsoft.AI.IsolationSession.SDK 0.202610.5 is not cached. I attempted to queue the shine-oss pipeline, but this CLI identity is rejected with TF400813, so I am leaving this thread open until an authorized user runs definition 33 for PR #1440 and the dependency-feed check passes.
Load IsoSessionApp.dll by full path from the paired IsoSession MSI runtime
dir (hardcoded default C:\Program Files\Microsoft\Agentic Runtime\2026.08,
overridable via MXC_ISOSESSION_RUNTIME_DIR) and obtain the activation factory
directly via DllGetActivationFactory, bypassing the WinRT catalog (which would
otherwise shadow reg-free activation and resolve to System32). This binds the
MSI-installed runtime with no machine-wide registry mutation. Falls back to
inbox system activation when no coresident App.dll is present.
CoInitializeEx(MTA) is called best-effort before the explicit ActivateInstance
because, unlike inbox RoActivateInstance, the direct factory path does not
implicitly initialize the COM apartment the coresident client->service
activation requires (otherwise CO_E_NOTINITIALIZED).
Routes both IsoSessionOps and IsoSessionProcessOptions activation through the
new regfree helper.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
Address the code-review findings on the coresident explicit-load change
(38dbd88). Runtime binding still activates the MSI IsoSessionApp.dll by
absolute path with zero registry mutation; this commit hardens the
surrounding load, error, and diagnostic behavior.
regfree.rs (#1,#5,#6,#7,#8,#9,#10):
- Load the App DLL with LoadLibraryExW using
LOAD_LIBRARY_SEARCH_DLL_LOAD_DIR | LOAD_LIBRARY_SEARCH_SYSTEM32 so
the runtime directory is the sole search root for its dependencies
(search-order hijack hardening). Reject non-absolute
MXC_ISOSESSION_RUNTIME_DIR overrides.
- Replace the 2-state load cache with a 3-state RuntimeLoad enum
(Absent / Loaded / Unloadable). A missing default folder still falls
back to inbox activation, but an honored-but-broken explicit override
or a present-but-unloadable DLL now surfaces the error instead of
silently falling back.
- Report real Win32 errors (GetProcAddress) and null-check the returned
factory pointer before from_raw.
- Gate success-path eprintln! on MXC_DIAG_CONSOLE.
- Correct the CoInitializeEx SAFETY comment.
- Add unit tests for runtime-dir resolution and app-dll path building.
manager.rs (#2): wrap the over-length activate line for rustfmt.
oneshot.md (#4,#11): document the two activation paths, the
runtime-folder resolution table (MXC_ISOSESSION_RUNTIME_DIR /
DEFAULT_RUNTIME_DIR), apartment init, and prerequisites; fix
RoInitialize -> CoInitializeEx wording.
tests/scripts (#3): accept EITHER inbox (System32 DLL + registry) OR the
coresident MSI runtime dir in the prerequisite probe, so the suites no
longer skip on an MSI-only host.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
When MXC_ISOSESSION_RUNTIME_DIR is set explicitly but IsoSessionApp.dll
does not exist there, load_app_dll() returns Unloadable (fail-closed,
no inbox fallback) -- correct, but previously silent. The manager drops
the error detail, so the operator got availability=false with no reason.
Emit an ungated eprintln naming the env var, the missing DLL, and the
resolved path, matching the existing ungated `LoadLibraryExW failed`
convention (a misconfiguration is not success-path diagnostic spam).
detail is now computed once and reused for both the eprintln and the
Unloadable struct.
Validated on VM iso-sf2-repro-0 against Eric's MSI (Agentic Runtime
2026.08): 5/5 binding cases pass (A default->MSI, B bogus override->
fail-closed with this diagnostic, C alt-path override, D coresident
client via System32-client-removal, E default-absent->inbox fallback).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
Pin Microsoft.Windows.AI.IsolationSession.SDK.0.2606.0.nupkg beside the
generated bindings so a clean clone can regenerate bindings.rs offline from
its Preview WinMD, mirroring external/wslc-sdk's checked-in nupkg. This is the
source package the committed bindings.rs was generated from
(preview WinMD sha256 1A9DBDC2...).
A normal `cargo build` is unchanged: it compiles the committed bindings.rs and
build.rs only version-gates on GENERATION_INFO.toml (target_windows_crate). The
nuget is consumed only by the manual regeneration step.
- README.md: document the checked-in nuget + the regenerate-from-WinMD steps.
- GENERATION_INFO.toml: record [source] provenance (nupkg, winmd, sha256, namespace).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
…uild time
The bindings crate previously compiled a committed bindings.rs snapshot;
the checked-in SDK nuget was only reference material. Wire build.rs to
regenerate the projection from that nuget on every build so MXC is built
directly against the OS-produced package (parity with the OS-side
RustBindingsGenerator), and there is no snapshot to drift.
build.rs now:
- locates the single *.nupkg under external/windows-sdk/isolation-session/,
- extracts its Preview WinMD (a .nupkg is a zip) into OUT_DIR,
- runs windows-bindgen (=0.62.1, build-dep) with the canonical args
(filter Windows.AI.IsolationSession.Preview,
--reference windows,skip-root,Windows.Foundation --flat --implement),
- strips the emitted leading #![allow(...)] inner-attribute block so the
file can be include!-ed inside `mod bindings`.
lib.rs now include!s OUT_DIR/bindings.rs under an outer #[allow(...)]; the
committed src/bindings.rs is removed. Verified the build-generated output is
byte-identical to the old snapshot (modulo the stripped header), and that
wxc-exec (release, --features isolation_session), fmt, clippy, and the 173
bindings+common tests are all green.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
Match the OS SDK package relabel (2606 -> 2608) so MXC binds the same
MSI runtime folder the package now advertises.
- regfree.rs DEFAULT_RUNTIME_DIR: ...\Agentic Runtime\2026.08 -> \2608
(this is the folder the IsoSessionApp.dll shim is loaded from by full
path; it must equal the paired MSI install location).
- Relabel the checked-in SDK nuget 0.2606.0 -> 0.2608.0. The winmd and
IsoSessionApp.dll bytes are unchanged (preview winmd sha256 still
1A9DBDC2..., full winmd 193B8BA6...); only the embedded nuspec,
metadata/GENERATION_INFO.toml, and OPC core-properties version strings
are updated. GENERATION_INFO.toml (external) nupkg reference bumped.
- oneshot.md + the three tests/scripts runtime-dir constants -> 2608.
Verified: cargo build --release -p wxc --bin wxc-exec --features
isolation_session and the common+bindings tests are green against the
relabeled package.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
Replace the LoadLibrary-based IsoSessionApp.dll activation prototype with
the real design: MXC loads IsoSessionApp.dll from its own nuget package
(staged next to wxc-exec.exe) through a reg-free classic-COM private
CLSID, letting the OS loader resolve it. No LoadLibrary and no
runtime-path logic in Rust; IsoSessionApp.dll (C++) owns how to reach
the MSI-installed runtime binaries.
regfree.rs:
- Add ActivatorClsid trait mapping IsoSessionOps ->
{6EF3155B-D1A2-4A34-BCAA-089F8A6D9916} and IsoSessionProcessOptions ->
{36B03FF1-21AA-4F3C-819D-2430EC830DD0} (contract duplicated in OS
dll.cpp and the nuget .comClass.manifest).
- Replace activate_from_runtime_dir/LoadLibrary/OnceLock/runtime-dir
machinery with activate_via_private_clsid<T>() using
CoCreateInstance(<private CLSID>, CLSCTX_INPROC_SERVER,
IID_IActivationFactory). REGDB_E_CLASSNOTREG -> None (inbox fallback);
any other error is surfaced as Some(Err).
- Add CLSID-contract unit tests.
manager.rs / process_options.rs: call activate_via_private_clsid and fix
the stale "by full path from the MSI" doc comments.
Build wiring (isolation_session feature):
- mxc_build_common: add embed_version_info_with_manifest so the reg-free
COM manifest is fused into wxc-exec in the same winresource compile as
the version info (two compiles would clobber each other).
- wxc build.rs: extract IsoSessionApp.dll + IsoSessionApp.comClass.manifest
from the pinned nupkg, stage the DLL next to wxc-exec.exe, and fuse the
manifest. Degrades gracefully (cargo:warning) if the nupkg lacks the
reg-free payload. Adds a zip build-dependency.
nupkg: repack 0.2608.0 with the DllGetClassObject-capable IsoSessionApp.dll
and the .comClass.manifest fragment.
Verified: cargo build -p wxc --features isolation_session succeeds; the
fused manifest (both CLSIDs, comClass, IsoSessionApp.dll) is present in
wxc-exec.exe; IsoSessionApp.dll is staged next to it; regfree unit tests
pass.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
…README
Repack the consumable SDK nupkg and align the E2E harness with the v2
reg-free activation model. Validated end-to-end: wxc-exec built against
this nupkg activates IsoSessionOps via the fused private-CLSID manifest
(no env var, no LoadLibrary) and passed 16/16 functional lifecycle tests
on the VM.
- nupkg: fresh runtime\\IsoSessionApp.dll (2026.08 shim);
IsoSessionApp.comClass.manifest with the illegal '--' XML-comment
removed (was breaking SxS activation with "side-by-side configuration
is incorrect"); README rewritten to the v2 reg-free classic-COM
private-CLSID model; nuspec runtime folder 2608 -> 2026.08.
- tests/scripts/run_isolation_session_tests.ps1: coresident backend
probe default runtime dir 2608 -> 2026.08 to match the shipping MSI.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
… network policy
Rebuild the 0.2608.0 SDK nuget's runtime/IsoSessionApp.dll from the OS
commit that pins the reg-free runtime dir to HKLM IsoSession\2026_08
InstallDir (Eric's authoritative MSI contract). wxc-exec re-fused +
re-staged that App.dll. regfree.rs/manager.rs/process_options.rs drive
CoCreateInstance on the private-CLSID activator; error.rs surfaces the
underlying HRESULT as error.nativeCode so a broken deployment hard-fails
instead of masquerading as feature-off.
E2E harness fix: the backend-availability probe sent a provision request
with no network block, which wxc-exec rejects at config validation
(code 'policy_validation') BEFORE activation -- a false hard-failure.
Add the canonical network policy (defaultPolicy=allow, allowLocalNetwork)
so the probe passes validation and actually exercises the reg-free chain.
Validated on iso-sf2-repro-0 (interactive/Abby): 16/16 E2E PASS via
co-located App.dll -> HKLM IsoSession\2026_08 InstallDir -> MSI 2026.08
client -> IsolationSession service. Backend probe provisions + deprovisions
an agent user cleanly; no leaked agents.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
IsoSessionApp.dll is version-agnostic at OS build time and reads its paired
runtime version from a co-located sidecar (IsoSessionApp.runtimeversion) to
resolve the MSI reg key + runtime dir. Extract that sidecar from the pinned
SDK nupkg and stage it alongside the co-located App.dll next to wxc-exec.exe
so the read works in the fused reg-free activation scenario.
Best-effort: a nupkg predating the stamping pipeline (no sidecar) logs a
cargo:warning and lets the shim fall back to its compile-time default; it
does NOT skip the manifest fuse.
Also repacks the pinned SDK nupkg with the version-agnostic App.dll and the
stamped 2026_08 sidecar.
Validated on iso-sf2-repro-0 via wxc-exec --probe (see OS commit).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
Consume the matching OS-produced SDK package, stage the lifted activation payload across Rust and C# build surfaces, and activate through DllGetActivationFactory while preserving Adib's in-process support.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 77a3362a-1fd0-4850-aaf9-ad0d8e0bc7d8
Keep isolation_session on the committed OS bindings and normal WinRT activation. Add isolation_session_lifted for hash-pinned NuGet restore, generated bindings, staged activation payloads, and fail-closed MSI activation.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 77a3362a-1fd0-4850-aaf9-ad0d8e0bc7d8
Update the pinned SDK package to the manifest-complete pipeline artifact. Stage IsoSession.manifest byte-for-byte from the package and remove MXC's dependency on the runtime-version sidecar.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e37e4eb2-1e56-42ca-a48e-4b35e9100d16
Remove the obsolete runtime sidecars from the pinned package and update the verified package hash.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e37e4eb2-1e56-42ca-a48e-4b35e9100d16
Align mxc-sdk and mxc_ffi with wxc: `isolation_session` is the inbox OS
API and `isolation_session_lifted` adds the lifted SDK + MSI runtime.
Their build scripts called a removed helper; they now stage the payload
through mxc_build_common::isolation_session_sdk::stage_runtime only in
lifted mode. This keeps main's CI (`--features isolation_session`,
`-p:MxcWithIsolationSession=true`) on the inbox path.
- build.bat: add --with-isolation-session-lifted; copy the payload into
the Node/.NET runtimes only in lifted mode; stamp the lifted bit.
- .NET: add MxcIsolationSessionLifted (implies MxcWithIsolationSession);
gate payload requirements on it, include the payload in the prebuilt
native unit, and stamp the lifted bit.
- regfree: resolve the payload beside the module hosting mxc_ffi first,
so in-process hosts (node.exe, dotnet) find it beside mxc_ffi.dll.
- mxc_build_common: resolve the checked-in, hash-pinned SDK package
before the NuGet cache / NuGet.org; test that it matches the pin.
- Lifted error remediation names `winget install
Microsoft.AI.IsolationSession`.
- Docs: replace stale fused private-CLSID prerequisites, describe both
modes, the checked-in package, and the winget MSI.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e37e4eb2-1e56-42ca-a48e-4b35e9100d16
Pin Microsoft.AI.IsolationSession.SDK 0.202610.5 from NuGet.org and refresh the generated provenance and package diagnostics.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 1d43372e-f942-4bb7-a358-48f9218c2332
Support Cargo.lock at either the packaged crate root or workspace root, and track the selected provenance inputs for build-script reruns.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 1d43372e-f942-4bb7-a358-48f9218c2332
Resolve the blocking acquisition and validation findings by restoring through MxcDependencies into an MXC-owned cache, seeding the pinned package, and requiring lifted CI coverage. Also reconcile staged payloads, improve activation diagnostics, balance COM initialization, and update the backend documentation.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 1d43372e-f942-4bb7-a358-48f9218c2332
The reason will be displayed to describe this comment to others. Learn more.
🟡 Changes recommended
The single architecture-specific runtime payload cannot support both advertised Windows targets, and an exposed feature combination produces unusable builds.
Restrict the AMD64-only lifted payload to x64 builds, remove the invalid standalone activation feature, execute package validation tests through Cargo, and separate inbox binding provenance from lifted SDK provenance.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 1d43372e-f942-4bb7-a358-48f9218c2332
Prevent shared-profile cleanup from clobbering lifted outputs
src/ffi/mxc_ffi/build.rs:69
This cleanup also clobbers lifted outputs from other packages in the shared profile directory. Building lifted wxc followed by inbox mxc_ffi removes the payload required by the already-built CLI, even though those package features are independently selectable. Keep payload ownership artifact-specific, or leave the shared files in place and make only feature-aware packaging exclude them.
Prevent inbox cleanup from deleting another package's lifted payload
src/tools/wxc/build.rs:62
This inbox cleanup can delete another package's valid lifted payload because wxc and mxc_ffi have independent features but share the same Cargo profile directory. For example, building lifted mxc_ffi and then inbox wxc in the same target/profile leaves the existing lifted DLL unusable. Do not let one artifact own/delete profile-global files; stage per artifact/package, or retain the shared payload and exclude it only from inbox packaging.
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Replace the checked-in IsolationSession SDK package with the published
Microsoft.AI.IsolationSession.SDKpackage while preserving MXC's existingdefault and inbox behavior.
Build modes
isolation_sessioncontinues to use committed bindings and the inbox Windowsruntime.
isolation_session_liftedrestores the pinned SDK package, generates bindingsfrom its WinMDs, and stages
IsoSessionApp.dllplusIsoSession.manifestfor registration-free activation. The published runtimepayload is AMD64, so lifted mode is explicitly x64-only.
MxcWithIsolationSession=truefor inbox andMxcIsolationSessionLifted=truefor lifted.Package acquisition and validation
Microsoft.AI.IsolationSession.SDKversion0.202610.5.MxcDependenciessource rather than contacting NuGet.org directly.the normal extracted package and metadata layout.
ISOLATION_SESSION_SDK_PACKAGEoffline override.architecture, and staged payload hashes.
packaging.
lifted-package provenance.
pinned IsolationSession SDK package.
Pinned package metadata:
Microsoft.AI.IsolationSession.SDK0.202610.5b387c9d11808bf8864d3d7e4d6924f79bdcd6e7c4c54c4e2e49ab0e3525b3d2e2026.10Reliability and CI
win-x64NuGet package, and verifies both runtime payload files are present.fingerprints.
selectable feature combination acquires the matching bindings and payload.
thread.
the new acquisition and activation details.
Validation
Validated after rebasing onto
mainat1ce2f68c6dc91b678be464fdcb917dfa66501360on October 7, 2026:cargo fmt --all -- --checkcargo check -p mxc-sdk --all-featureswith the exact pinned packagemxc-sdk --lib: 2,918 passed, 3 ignored, 0 failedmxc-sdk --lib: 2,923 passed, 3 ignored, 0 failedIsolationSessionBuildSwitchtest: 1 passed, 0 skippedThe full inbox integration suite additionally reaches host-dependent
IsolationSession operations; this development host returns
0x80070520forfive logon-dependent cases. That host/session limitation is separate from
package acquisition and compilation.
Feed prerequisite
Before governed CI can pass, run the manually triggered
MXC-Update-Feed-Dependenciespipeline (definition 33) for PR #1440. It seeds:windows-bindgen0.62.1into the Cargo feedMicrosoft.AI.IsolationSession.SDK0.202610.5into the NuGet feedThe current CLI identity is not authorized to queue that shine-oss pipeline;
the public feed correctly reports both packages as not yet cached.
References
Checklist
dependency-feed-checkpasses after definition 33 seeds the pinned dependenciesIssue Type
Microsoft Reviewers: Open in CodeFlow