Skip to content

Consume published IsolationSession SDK NuGet package - #1440

Draft
Dan Legg (danlegg) wants to merge 25 commits into
mainfrom
user/dalegg/isosession-nuget-rebased
Draft

Dan Legg (danlegg) wants to merge 25 commits into
mainfrom
user/dalegg/isosession-nuget-rebased

Conversation

@danlegg

@danlegg Dan Legg (danlegg) commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Description

Replace the checked-in IsolationSession SDK package with the published
Microsoft.AI.IsolationSession.SDK package while preserving MXC's existing
default and inbox behavior.

Build modes

  • Default builds still enable neither IsolationSession feature.
  • isolation_session continues to use committed bindings and the inbox Windows
    runtime.
  • isolation_session_lifted restores the pinned SDK package, generates bindings
    from its WinMDs, and stages IsoSessionApp.dll plus
    IsoSession.manifest for registration-free activation. The published runtime
    payload is AMD64, so lifted mode is explicitly x64-only.
  • Managed equivalents remain MxcWithIsolationSession=true for inbox and
    MxcIsolationSessionLifted=true for lifted.

Package acquisition and validation

  • Pins Microsoft.AI.IsolationSession.SDK version 0.202610.5.
  • Restores through NuGet using the repository-configured public
    MxcDependencies source rather than contacting NuGet.org directly.
  • Uses an MXC-owned NuGet cache under the Cargo target profile; NuGet creates
    the normal extracted package and metadata layout.
  • Preserves the explicit ISOLATION_SESSION_SDK_PACKAGE offline override.
  • Independently verifies the package SHA-256 before using its contents.
  • Validates package structure, runtime identity, manifest metadata, PE
    architecture, and staged payload hashes.
  • Rejects lifted ARM64 and multi-RID builds before native compilation or
    packaging.
  • Keeps committed inbox-binding provenance separate from updater-managed
    lifted-package provenance.
  • Adds authenticated feed-seeding support for the locked Cargo dependencies and
    pinned IsolationSession SDK package.

Pinned package metadata:

  • Package: Microsoft.AI.IsolationSession.SDK
  • Version: 0.202610.5
  • Package SHA-256:
    b387c9d11808bf8864d3d7e4d6924f79bdcd6e7c4c54c4e2e49ab0e3525b3d2e
  • Runtime instance: 2026.10

Reliability and CI

  • Makes lifted Windows validation required.
  • Builds and tests the lifted managed SDK, pins the build-switch test, packs a
    win-x64 NuGet package, and verifies both runtime payload files are present.
  • Reconciles stale lifted payloads when Cargo switches between feature
    fingerprints.
  • Removes the invalid standalone lifted-activation Cargo feature, so every
    selectable feature combination acquires the matching bindings and payload.
  • Runs package validation through the normal Cargo integration-test harness.
  • Keeps inbox and lifted activation diagnostics mode-correct.
  • Balances COM initialization owned by lifted activation on the originating
    thread.
  • Restores the current one-shot contract and policy documentation, adding only
    the new acquisition and activation details.

Validation

Validated after rebasing onto main at
1ce2f68c6dc91b678be464fdcb917dfa66501360 on October 7, 2026:

  • cargo fmt --all -- --check
  • Package validation integration test: 9 passed, 0 failed
  • cargo check -p mxc-sdk --all-features with the exact pinned package
  • Inbox mxc-sdk --lib: 2,918 passed, 3 ignored, 0 failed
  • Lifted mxc-sdk --lib: 2,923 passed, 3 ignored, 0 failed
  • Lifted Rust, FFI, and CLI compilation with the exact pinned package
  • Lifted-to-inbox FFI and CLI payload cleanup
  • Managed lifted build
  • Direct xUnit v3 run: 354 total, 0 failed, 31 host-gated skips
  • Pinned IsolationSessionBuildSwitch test: 1 passed, 0 skipped
  • Managed lifted pack and archive-content verification
  • Lifted ARM64 and multi-RID batch/MSBuild rejection checks
  • Updater idempotence and inbox-provenance stability
  • Package and staged payload SHA-256 verification

The full inbox integration suite additionally reaches host-dependent
IsolationSession operations; this development host returns 0x80070520 for
five logon-dependent cases. That host/session limitation is separate from
package acquisition and compilation.

Feed prerequisite

Before governed CI can pass, run the manually triggered
MXC-Update-Feed-Dependencies pipeline (definition 33) for PR #1440. It seeds:

  • windows-bindgen 0.62.1 into the Cargo feed
  • Microsoft.AI.IsolationSession.SDK 0.202610.5 into the NuGet feed

The current CLI identity is not authorized to queue that shine-oss pipeline;
the public feed correctly reports both packages as not yet cached.

References

Checklist

Issue Type

  • Bug fix
  • Feature
  • Task
Microsoft Reviewers: Open in CodeFlow

Copilot AI balanced review requested due to automatic review settings October 7, 2026 15:36
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Package acquisition, packaged-build compatibility, mode reconciliation, CI coverage, diagnostics, tests, and one-shot documentation contain unresolved issues.

7 open findings
What changed in this PR

Adds published NuGet-based IsolationSession lifted builds while preserving inbox mode.

Changes:

  • Pins, validates, and restores the IsolationSession SDK package.
  • Generates lifted bindings and stages reg-free runtime assets.
  • Extends CLI, FFI, .NET packaging, CI, tests, and documentation.
File Description
src/​tools/​wxc/​Cargo.toml Adds lifted feature and build dependencies.
src/​tools/​wxc/​build.rs Reconciles CLI runtime payloads.
src/​mxc-sdk/​src/​backends/​isolation_session/​common/​regfree.rs Implements lifted activation and framework verification.
src/​mxc-sdk/​src/​backends/​isolation_session/​common/​process_options.rs Activates lifted process options.
src/​mxc-sdk/​src/​backends/​isolation_session/​common/​mod.rs Registers the reg-free module.
src/​mxc-sdk/​src/​backends/​isolation_session/​common/​manager.rs Selects inbox or lifted activation.
src/​mxc-sdk/​src/​backends/​isolation_session/​common/​error.rs Adds lifted-runtime diagnostics.
src/​mxc-sdk/​src/​backends/​isolation_session/​common/​availability.rs Probes lifted runtime availability.
src/​mxc-sdk/​src/​backends/​isolation_session/​bindings/​mod.rs Selects committed or generated bindings.
src/​mxc-sdk/​Cargo.toml Defines lifted features and bindgen dependency.
src/​mxc-sdk/​build/​isolation_session_bindings/​Update-IsoSessionSdk.ps1 Adds package pin/provenance updater.
src/​mxc-sdk/​build/​isolation_session_bindings/​README.md Documents build modes and updates.
src/​mxc-sdk/​build/​isolation_session_bindings/​GENERATION_INFO.toml Records package provenance.
src/​mxc-sdk/​build/​build_mxc_build_common.rs Acquires, verifies, and stages the package.
src/​mxc-sdk/​build/​build_isolation_session_bindings.rs Generates lifted bindings.
src/​mxc-sdk/​build.rs Runs binding generation and staging.
src/​ffi/​mxc_ffi/​Cargo.toml Exposes lifted FFI builds.
src/​ffi/​mxc_ffi/​build.rs Reconciles FFI runtime payloads.
src/​Cargo.toml Enables required Windows APIs.
src/​Cargo.lock Locks bindgen and related dependencies.
sdk/​dotnet/​README.md Documents lifted managed builds.
sdk/​dotnet/​Microsoft.Mxc.Sdk/​Microsoft.Mxc.Sdk.csproj Packages lifted runtime assets.
sdk/​dotnet/​Microsoft.Mxc.Sdk.Tests/​V1/​MxcContainerTests.cs Checks backend probe consistency.
sdk/​dotnet/​Microsoft.Mxc.Sdk.Tests/​Microsoft.Mxc.Sdk.Tests.csproj Propagates lifted test features.
docs/​development/​architecture/​backends/​isolation-session/​state-aware-rust.md Documents framework verification.
docs/​development/​architecture/​backends/​isolation-session/​oneshot.md Revises one-shot integration documentation.
build.bat Adds lifted build and SDK staging.
.github/​workflows/​Build.yml Connects the lifted CI input.
.github/​workflows/​Build.Windows.Job.yml Adds lifted Rust validation.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/mxc-sdk/build/build_isolation_session_bindings.rs Outdated
Comment thread src/mxc-sdk/build/build_mxc_build_common.rs Outdated
Comment thread .github/workflows/Build.yml Outdated
Comment thread src/ffi/mxc_ffi/build.rs Outdated
Comment thread src/mxc-sdk/src/backends/isolation_session/common/error.rs Outdated
Comment thread src/mxc-sdk/src/backends/isolation_session/common/manager.rs Outdated
Comment thread docs/development/architecture/backends/isolation-session/oneshot.md Outdated
@danlegg

Copy link
Copy Markdown
Contributor Author

Adversarial pre-publish review

Reviewed the complete main...user/dalegg/isosession-nuget-rebased scope: 20 commits, 29 files, 89 hunks. Critic adjudication retained one blocking defect and one non-blocking suggestion.

Blocking

src/mxc-sdk/build/build_isolation_session_bindings.rs:139-145 — packaged-crate lockfile lookup regression

The build script reads only ../Cargo.lock. A published mxc-sdk package can place Cargo.lock at the crate root, which the previous implementation supported. A consumer enabling isolation_session can therefore panic before compilation. Restore lookup at both the package root and workspace root, with an explicit error when neither exists.

Suggestion

src/mxc-sdk/src/backends/isolation_session/common/regfree.rs:89-94 — balance successful COM initialization

Successful CoInitializeEx calls are not paired with CoUninitialize. Repeated activation calls may accumulate per-thread COM initialization references and prevent embedded hosts from restoring their previous COM state.

Residual risk

The package exposes one leaf-named runtime/IsoSessionApp.dll and validates it against the target architecture. If the published package contains only one machine type, another lifted architecture fails closed. The review did not independently prove every package architecture, so this remains a validation/documentation risk rather than a confirmed defect.

The opt-in repository-variable gate for lifted CI was reviewed and dropped as a false positive because it is explicitly documented as intentional.

Copilot AI balanced review requested due to automatic review settings October 7, 2026 18:12
@danlegg

Copy link
Copy Markdown
Contributor Author

Blocking review finding resolved

Fixed in 0d9624fe722b45a378a85c3006735b5648890164.

The inbox binding verifier now searches for Cargo.lock at both the packaged crate root and the workspace root, reports both attempted paths if neither exists, and registers the selected lockfile plus GENERATION_INFO.toml as build-script rerun inputs.

Validation:

  • cargo fmt --all -- --check
  • Inbox mxc-sdk library tests with isolation_session: 3,036 passed, 3 ignored, 0 failed
  • cargo package -p mxc-sdk --allow-dirty --no-default-features --features isolation_session: packaged and verified successfully, exercising the crate-root Cargo.lock layout

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread src/mxc-sdk/Cargo.toml
serde_json.workspace = true
sha2.workspace = true
uuid.workspace = true
windows-bindgen = { version = "=0.62.1", optional = true }

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The code-side remediation is in 1040b76: definition 33 now seeds both locked Cargo dependencies and the pinned IsolationSession NuGet package, with authenticated NuGet publication and hash verification. Current CI confirms windows-bindgen 0.62.1 is still not cached, and the public NuGet feed likewise reports Microsoft.AI.IsolationSession.SDK 0.202610.5 is not cached. I attempted to queue the shine-oss pipeline, but this CLI identity is rejected with TF400813, so I am leaving this thread open until an authorized user runs definition 33 for PR #1440 and the dependency-feed check passes.

dalegg and others added 21 commits October 7, 2026 13:32
Load IsoSessionApp.dll by full path from the paired IsoSession MSI runtime
dir (hardcoded default C:\Program Files\Microsoft\Agentic Runtime\2026.08,
overridable via MXC_ISOSESSION_RUNTIME_DIR) and obtain the activation factory
directly via DllGetActivationFactory, bypassing the WinRT catalog (which would
otherwise shadow reg-free activation and resolve to System32). This binds the
MSI-installed runtime with no machine-wide registry mutation. Falls back to
inbox system activation when no coresident App.dll is present.

CoInitializeEx(MTA) is called best-effort before the explicit ActivateInstance
because, unlike inbox RoActivateInstance, the direct factory path does not
implicitly initialize the COM apartment the coresident client->service
activation requires (otherwise CO_E_NOTINITIALIZED).

Routes both IsoSessionOps and IsoSessionProcessOptions activation through the
new regfree helper.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
Address the code-review findings on the coresident explicit-load change
(38dbd88). Runtime binding still activates the MSI IsoSessionApp.dll by
absolute path with zero registry mutation; this commit hardens the
surrounding load, error, and diagnostic behavior.

regfree.rs (#1,#5,#6,#7,#8,#9,#10):
- Load the App DLL with LoadLibraryExW using
  LOAD_LIBRARY_SEARCH_DLL_LOAD_DIR | LOAD_LIBRARY_SEARCH_SYSTEM32 so
  the runtime directory is the sole search root for its dependencies
  (search-order hijack hardening). Reject non-absolute
  MXC_ISOSESSION_RUNTIME_DIR overrides.
- Replace the 2-state load cache with a 3-state RuntimeLoad enum
  (Absent / Loaded / Unloadable). A missing default folder still falls
  back to inbox activation, but an honored-but-broken explicit override
  or a present-but-unloadable DLL now surfaces the error instead of
  silently falling back.
- Report real Win32 errors (GetProcAddress) and null-check the returned
  factory pointer before from_raw.
- Gate success-path eprintln! on MXC_DIAG_CONSOLE.
- Correct the CoInitializeEx SAFETY comment.
- Add unit tests for runtime-dir resolution and app-dll path building.

manager.rs (#2): wrap the over-length activate line for rustfmt.

oneshot.md (#4,#11): document the two activation paths, the
runtime-folder resolution table (MXC_ISOSESSION_RUNTIME_DIR /
DEFAULT_RUNTIME_DIR), apartment init, and prerequisites; fix
RoInitialize -> CoInitializeEx wording.

tests/scripts (#3): accept EITHER inbox (System32 DLL + registry) OR the
coresident MSI runtime dir in the prerequisite probe, so the suites no
longer skip on an MSI-only host.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
When MXC_ISOSESSION_RUNTIME_DIR is set explicitly but IsoSessionApp.dll
does not exist there, load_app_dll() returns Unloadable (fail-closed,
no inbox fallback) -- correct, but previously silent. The manager drops
the error detail, so the operator got availability=false with no reason.

Emit an ungated eprintln naming the env var, the missing DLL, and the
resolved path, matching the existing ungated `LoadLibraryExW failed`
convention (a misconfiguration is not success-path diagnostic spam).
detail is now computed once and reused for both the eprintln and the
Unloadable struct.

Validated on VM iso-sf2-repro-0 against Eric's MSI (Agentic Runtime
2026.08): 5/5 binding cases pass (A default->MSI, B bogus override->
fail-closed with this diagnostic, C alt-path override, D coresident
client via System32-client-removal, E default-absent->inbox fallback).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
Pin Microsoft.Windows.AI.IsolationSession.SDK.0.2606.0.nupkg beside the
generated bindings so a clean clone can regenerate bindings.rs offline from
its Preview WinMD, mirroring external/wslc-sdk's checked-in nupkg. This is the
source package the committed bindings.rs was generated from
(preview WinMD sha256 1A9DBDC2...).

A normal `cargo build` is unchanged: it compiles the committed bindings.rs and
build.rs only version-gates on GENERATION_INFO.toml (target_windows_crate). The
nuget is consumed only by the manual regeneration step.

- README.md: document the checked-in nuget + the regenerate-from-WinMD steps.
- GENERATION_INFO.toml: record [source] provenance (nupkg, winmd, sha256, namespace).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
…uild time

The bindings crate previously compiled a committed bindings.rs snapshot;
the checked-in SDK nuget was only reference material. Wire build.rs to
regenerate the projection from that nuget on every build so MXC is built
directly against the OS-produced package (parity with the OS-side
RustBindingsGenerator), and there is no snapshot to drift.

build.rs now:
  - locates the single *.nupkg under external/windows-sdk/isolation-session/,
  - extracts its Preview WinMD (a .nupkg is a zip) into OUT_DIR,
  - runs windows-bindgen (=0.62.1, build-dep) with the canonical args
    (filter Windows.AI.IsolationSession.Preview,
     --reference windows,skip-root,Windows.Foundation --flat --implement),
  - strips the emitted leading #![allow(...)] inner-attribute block so the
    file can be include!-ed inside `mod bindings`.

lib.rs now include!s OUT_DIR/bindings.rs under an outer #[allow(...)]; the
committed src/bindings.rs is removed. Verified the build-generated output is
byte-identical to the old snapshot (modulo the stripped header), and that
wxc-exec (release, --features isolation_session), fmt, clippy, and the 173
bindings+common tests are all green.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
Match the OS SDK package relabel (2606 -> 2608) so MXC binds the same
MSI runtime folder the package now advertises.

- regfree.rs DEFAULT_RUNTIME_DIR: ...\Agentic Runtime\2026.08 -> \2608
  (this is the folder the IsoSessionApp.dll shim is loaded from by full
  path; it must equal the paired MSI install location).
- Relabel the checked-in SDK nuget 0.2606.0 -> 0.2608.0. The winmd and
  IsoSessionApp.dll bytes are unchanged (preview winmd sha256 still
  1A9DBDC2..., full winmd 193B8BA6...); only the embedded nuspec,
  metadata/GENERATION_INFO.toml, and OPC core-properties version strings
  are updated. GENERATION_INFO.toml (external) nupkg reference bumped.
- oneshot.md + the three tests/scripts runtime-dir constants -> 2608.

Verified: cargo build --release -p wxc --bin wxc-exec --features
isolation_session and the common+bindings tests are green against the
relabeled package.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
Replace the LoadLibrary-based IsoSessionApp.dll activation prototype with
the real design: MXC loads IsoSessionApp.dll from its own nuget package
(staged next to wxc-exec.exe) through a reg-free classic-COM private
CLSID, letting the OS loader resolve it. No LoadLibrary and no
runtime-path logic in Rust; IsoSessionApp.dll (C++) owns how to reach
the MSI-installed runtime binaries.

regfree.rs:
- Add ActivatorClsid trait mapping IsoSessionOps ->
  {6EF3155B-D1A2-4A34-BCAA-089F8A6D9916} and IsoSessionProcessOptions ->
  {36B03FF1-21AA-4F3C-819D-2430EC830DD0} (contract duplicated in OS
  dll.cpp and the nuget .comClass.manifest).
- Replace activate_from_runtime_dir/LoadLibrary/OnceLock/runtime-dir
  machinery with activate_via_private_clsid<T>() using
  CoCreateInstance(<private CLSID>, CLSCTX_INPROC_SERVER,
  IID_IActivationFactory). REGDB_E_CLASSNOTREG -> None (inbox fallback);
  any other error is surfaced as Some(Err).
- Add CLSID-contract unit tests.

manager.rs / process_options.rs: call activate_via_private_clsid and fix
the stale "by full path from the MSI" doc comments.

Build wiring (isolation_session feature):
- mxc_build_common: add embed_version_info_with_manifest so the reg-free
  COM manifest is fused into wxc-exec in the same winresource compile as
  the version info (two compiles would clobber each other).
- wxc build.rs: extract IsoSessionApp.dll + IsoSessionApp.comClass.manifest
  from the pinned nupkg, stage the DLL next to wxc-exec.exe, and fuse the
  manifest. Degrades gracefully (cargo:warning) if the nupkg lacks the
  reg-free payload. Adds a zip build-dependency.

nupkg: repack 0.2608.0 with the DllGetClassObject-capable IsoSessionApp.dll
and the .comClass.manifest fragment.

Verified: cargo build -p wxc --features isolation_session succeeds; the
fused manifest (both CLSIDs, comClass, IsoSessionApp.dll) is present in
wxc-exec.exe; IsoSessionApp.dll is staged next to it; regfree unit tests
pass.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
…README

Repack the consumable SDK nupkg and align the E2E harness with the v2
reg-free activation model. Validated end-to-end: wxc-exec built against
this nupkg activates IsoSessionOps via the fused private-CLSID manifest
(no env var, no LoadLibrary) and passed 16/16 functional lifecycle tests
on the VM.

- nupkg: fresh runtime\\IsoSessionApp.dll (2026.08 shim);
  IsoSessionApp.comClass.manifest with the illegal '--' XML-comment
  removed (was breaking SxS activation with "side-by-side configuration
  is incorrect"); README rewritten to the v2 reg-free classic-COM
  private-CLSID model; nuspec runtime folder 2608 -> 2026.08.
- tests/scripts/run_isolation_session_tests.ps1: coresident backend
  probe default runtime dir 2608 -> 2026.08 to match the shipping MSI.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
… network policy

Rebuild the 0.2608.0 SDK nuget's runtime/IsoSessionApp.dll from the OS
commit that pins the reg-free runtime dir to HKLM IsoSession\2026_08
InstallDir (Eric's authoritative MSI contract). wxc-exec re-fused +
re-staged that App.dll. regfree.rs/manager.rs/process_options.rs drive
CoCreateInstance on the private-CLSID activator; error.rs surfaces the
underlying HRESULT as error.nativeCode so a broken deployment hard-fails
instead of masquerading as feature-off.

E2E harness fix: the backend-availability probe sent a provision request
with no network block, which wxc-exec rejects at config validation
(code 'policy_validation') BEFORE activation -- a false hard-failure.
Add the canonical network policy (defaultPolicy=allow, allowLocalNetwork)
so the probe passes validation and actually exercises the reg-free chain.

Validated on iso-sf2-repro-0 (interactive/Abby): 16/16 E2E PASS via
co-located App.dll -> HKLM IsoSession\2026_08 InstallDir -> MSI 2026.08
client -> IsolationSession service. Backend probe provisions + deprovisions
an agent user cleanly; no leaked agents.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
IsoSessionApp.dll is version-agnostic at OS build time and reads its paired
runtime version from a co-located sidecar (IsoSessionApp.runtimeversion) to
resolve the MSI reg key + runtime dir. Extract that sidecar from the pinned
SDK nupkg and stage it alongside the co-located App.dll next to wxc-exec.exe
so the read works in the fused reg-free activation scenario.

Best-effort: a nupkg predating the stamping pipeline (no sidecar) logs a
cargo:warning and lets the shim fall back to its compile-time default; it
does NOT skip the manifest fuse.

Also repacks the pinned SDK nupkg with the version-agnostic App.dll and the
stamped 2026_08 sidecar.

Validated on iso-sf2-repro-0 via wxc-exec --probe (see OS commit).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f5cc2011-5308-43d6-a8ea-2b8ed9b6ceb3
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 77a3362a-1fd0-4850-aaf9-ad0d8e0bc7d8
Consume the matching OS-produced SDK package, stage the lifted activation payload across Rust and C# build surfaces, and activate through DllGetActivationFactory while preserving Adib's in-process support.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 77a3362a-1fd0-4850-aaf9-ad0d8e0bc7d8
Keep isolation_session on the committed OS bindings and normal WinRT activation. Add isolation_session_lifted for hash-pinned NuGet restore, generated bindings, staged activation payloads, and fail-closed MSI activation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 77a3362a-1fd0-4850-aaf9-ad0d8e0bc7d8
Update the pinned SDK package to the manifest-complete pipeline artifact. Stage IsoSession.manifest byte-for-byte from the package and remove MXC's dependency on the runtime-version sidecar.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e37e4eb2-1e56-42ca-a48e-4b35e9100d16
Remove the obsolete runtime sidecars from the pinned package and update the verified package hash.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e37e4eb2-1e56-42ca-a48e-4b35e9100d16
Align mxc-sdk and mxc_ffi with wxc: `isolation_session` is the inbox OS
API and `isolation_session_lifted` adds the lifted SDK + MSI runtime.
Their build scripts called a removed helper; they now stage the payload
through mxc_build_common::isolation_session_sdk::stage_runtime only in
lifted mode. This keeps main's CI (`--features isolation_session`,
`-p:MxcWithIsolationSession=true`) on the inbox path.

- build.bat: add --with-isolation-session-lifted; copy the payload into
  the Node/.NET runtimes only in lifted mode; stamp the lifted bit.
- .NET: add MxcIsolationSessionLifted (implies MxcWithIsolationSession);
  gate payload requirements on it, include the payload in the prebuilt
  native unit, and stamp the lifted bit.
- regfree: resolve the payload beside the module hosting mxc_ffi first,
  so in-process hosts (node.exe, dotnet) find it beside mxc_ffi.dll.
- mxc_build_common: resolve the checked-in, hash-pinned SDK package
  before the NuGet cache / NuGet.org; test that it matches the pin.
- Lifted error remediation names `winget install
  Microsoft.AI.IsolationSession`.
- Docs: replace stale fused private-CLSID prerequisites, describe both
  modes, the checked-in package, and the winget MSI.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e37e4eb2-1e56-42ca-a48e-4b35e9100d16
Co-authored-by: Dom Giandinoto <dgiandinoto@microsoft.com>
Remove the checked-in SDK package, harden package and activation validation,
and add opt-in x64 Cargo coverage for the lifted feature path.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: f67f236f-a9cb-4ff1-b180-25b798dd4967
Pin Microsoft.AI.IsolationSession.SDK 0.202610.5 from NuGet.org and refresh the generated provenance and package diagnostics.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 1d43372e-f942-4bb7-a358-48f9218c2332
Correct the relocated updater paths, refresh the Cargo lockfile, and fix lifted-mode validation discovered after rebasing.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 1d43372e-f942-4bb7-a358-48f9218c2332
Support Cargo.lock at either the packaged crate root or workspace root, and track the selected provenance inputs for build-script reruns.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 1d43372e-f942-4bb7-a358-48f9218c2332
Resolve the blocking acquisition and validation findings by restoring through MxcDependencies into an MXC-owned cache, seeding the pinned package, and requiring lifted CI coverage. Also reconcile staged payloads, improve activation diagnostics, balance COM initialization, and update the backend documentation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 1d43372e-f942-4bb7-a358-48f9218c2332
@danlegg
Dan Legg (danlegg) force-pushed the user/dalegg/isosession-nuget-rebased branch from 0d9624f to 1040b76 Compare October 7, 2026 20:37
Copilot AI balanced review requested due to automatic review settings October 7, 2026 20:37

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread src/mxc-sdk/build/build_mxc_build_common.rs
Comment thread src/mxc-sdk/Cargo.toml Outdated
Comment thread src/mxc-sdk/build/build_mxc_build_common.rs Outdated
Comment thread src/mxc-sdk/build/build_isolation_session_bindings.rs Outdated
Comment thread src/mxc-sdk/build/isolation_session_bindings/README.md Outdated
Comment thread src/mxc-sdk/build/isolation_session_bindings/README.md Outdated
Comment thread src/mxc-sdk/build/isolation_session_bindings/Update-IsoSessionSdk.ps1 Outdated
Comment thread src/mxc-sdk/src/backends/isolation_session/bindings/mod.rs Outdated
Comment thread src/mxc-sdk/src/backends/isolation_session/common/error.rs
Restrict the AMD64-only lifted payload to x64 builds, remove the invalid standalone activation feature, execute package validation tests through Cargo, and separate inbox binding provenance from lifted SDK provenance.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 1d43372e-f942-4bb7-a358-48f9218c2332
Copilot AI balanced review requested due to automatic review settings October 7, 2026 21:14

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread build.bat
Comment on lines +189 to +194
for %%B in (IsoSessionApp.dll IsoSession.manifest) do (
if not exist "!BIN_DIR!\%%B" (
echo ERROR: Lifted IsolationSession Node runtime is missing !BIN_DIR!\%%B
exit /b 1
)
copy /Y "!BIN_DIR!\%%B" "sdk\node\bin\!SDK_ARCH!\" >nul
dalegg added 2 commits October 7, 2026 15:14
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 1d43372e-f942-4bb7-a358-48f9218c2332
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 1d43372e-f942-4bb7-a358-48f9218c2332
Copilot AI balanced review requested due to automatic review settings October 7, 2026 23:01

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Host-based staging gates and profile-global cleanup can produce or invalidate lifted artifacts incorrectly.

3 open findings
Previously missed (2)

In code that hasn't changed since last review

Medium severity Prevent shared-profile cleanup from clobbering lifted outputs

src/​ffi/​mxc_ffi/​build.rs:69

This cleanup also clobbers lifted outputs from other packages in the shared profile directory. Building lifted wxc followed by inbox mxc_ffi removes the payload required by the already-built CLI, even though those package features are independently selectable. Keep payload ownership artifact-specific, or leave the shared files in place and make only feature-aware packaging exclude them.

Medium severity Prevent inbox cleanup from deleting another package's lifted payload

src/​tools/​wxc/​build.rs:62

This inbox cleanup can delete another package's valid lifted payload because wxc and mxc_ffi have independent features but share the same Cargo profile directory. For example, building lifted mxc_ffi and then inbox wxc in the same target/profile leaves the existing lifted DLL unusable. Do not let one artifact own/delete profile-global files; stage per artifact/package, or retain the shared payload and exclude it only from inbox packaging.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment thread src/mxc-sdk/build.rs
Comment on lines +33 to +35
#[cfg(all(windows, feature = "isolation_session_lifted"))]
build_mxc_build_common::isolation_session_sdk::stage_runtime()
.unwrap_or_else(|error| panic!("IsolationSession SDK staging failed: {error}"));

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants