Switch .NET to exact JSON FFI ingress - #1351
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
0492605 to
53f0bfa
Compare
eafb96a to
8d1b835
Compare
8d1b835 to
83eb313
Compare
83eb313 to
eaffaf6
Compare
eaffaf6 to
9fe4ac0
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Exact-wire numeric and environment mappings are incorrect, and two public API paths provide misleading experimental behavior.
Review effort: Balanced
Findings: 1
Open (4)
What changed in this PR
Moves the .NET V1 SDK to exact 1.0.0 JSON FFI ingress.
Changes:
- Adds generated C# wire types and drift validation.
- Maps public .NET policies to exact JSON requests.
- Routes one-shot APIs through JSON FFI and expands conformance tests.
| File | Description |
|---|---|
src/tools/mxc_schema_gen/tests/cli.rs |
Tests C# generation. |
src/tools/mxc_schema_gen/src/main.rs |
Adds the csharp command. |
src/core/mxc_schema_support/src/lib.rs |
Exposes C# emission. |
src/core/mxc_schema_support/src/cs_emit.rs |
Implements the C# emitter. |
src/core/mxc_config_contract/src/registry.rs |
Registers C# artifact paths. |
sdk/dotnet/Microsoft.Mxc.Sdk/V1/MxcSandbox.cs |
Uses JSON FFI entry points. |
sdk/dotnet/Microsoft.Mxc.Sdk/V1/MxcLifecycle.cs |
Rejects stable wsb: lifecycle IDs. |
sdk/dotnet/Microsoft.Mxc.Sdk/V1/ExactOneShotRequestWriter.cs |
Maps V1 requests to exact wire types. |
sdk/dotnet/Microsoft.Mxc.Sdk/Generated/MxcConfigV1_0_0.g.cs |
Adds generated 1.0.0 models. |
sdk/dotnet/Microsoft.Mxc.Sdk.Tests/V1/SandboxPolicyTests.cs |
Updates exact-contract assertions. |
sdk/dotnet/Microsoft.Mxc.Sdk.Tests/V1/MxcSandboxTests.cs |
Updates one-shot serialization tests. |
sdk/dotnet/Microsoft.Mxc.Sdk.Tests/V1/MxcLifecycleTests.cs |
Tests wsb: rejection. |
sdk/dotnet/Microsoft.Mxc.Sdk.Tests/V1/ExactOneShotRequestWriterTests.cs |
Adds writer conformance tests. |
sdk/dotnet/Microsoft.Mxc.Sdk.Tests/Microsoft.Mxc.Sdk.Tests.csproj |
Embeds SDK-v1 fixtures. |
sdk/dotnet/Microsoft.Mxc.Sdk.Tests/JsonAssert.cs |
Generalizes JSON comparison. |
scripts/versioning/check-contract-codegen.js |
Adds C# drift checks. |
scripts/check-dotnet-bindings-codegen.js |
Marks JSON exports as consumed. |
scripts/check-dotnet-api-parity.js |
Checks against the exact contract. |
docs/schema-codegen.md |
Documents C# generation. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
9fe4ac0 to
885b720
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Valid ulong memory values regress, environment validation is weakened, and the public experimental opt-in becomes silently ineffective.
Review effort: Balanced
Findings: 2
Open (6)
Projection drops key validation and changes caller entry order · New Parse unsigned schema minima without lossy Int64 conversion Empty container names are incorrectly replaced with generated IDs Reject or deprecate silently ignored Experimental requests Preserve caller order for environment variables Document the actual supported Windows Sandbox request path
885b720 to
4bb99c7
Compare
There was a problem hiding this comment.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Copilot review overview
Review effort: Lite
Findings: 1
Open (4)
Required-but-nullable schema properties (e.g., viaanyOf: [T, null]while still listed in… · New This regex-based field extractor is brittle: it only matches when[JsonPropertyName(...)]appears… · New This now scans the entireMxcLifecycle.cssource for\"...\" => StateAwareContainment.X… · New This always assignsPreservePolicya non-null boolean, so it will serialize as `preservePolicy:… · New
Resolved since last review (6)
Projection drops key validation and changes caller entry order Parse unsigned schema minima without lossy Int64 conversion Empty container names are incorrectly replaced with generated IDs Reject or deprecate silently ignored Experimental requests Preserve caller order for environment variables Document the actual supported Windows Sandbox request path
4bb99c7 to
44e58a0
Compare
This PR maps V1 .NET execution and request probing to the SDK-owned exact 1.0.0 JSON contract. It generates C# wire types from the registered Rust contract and uses one writer for all native entry points, preserving Native AOT through source-generated serialization. Details * Generate closed C# contract types and drift checks, preserving unsigned numeric bounds and required nullable fields under null-omitting options. * Move Run, Spawn, and Probe onto exact JSON FFI with shared source-generated serialization and actionable errors for unsupported policy. * Preserve environment order and caller IDs; reject invalid keys, enum values, and unsupported stable experimental authorization before native. * Correct lifecycle guidance and keep managed API parity checks precise for attribute ordering, ignored fields, and sandbox-id prefix dispatch. Tests * Cargo format, compiler, clippy and schema emitter tests passed. * Contract codegen, .NET API parity and exact fixture gates passed. * dotnet test --solution Microsoft.Mxc.Sdk.slnx: 329 passed, 29 skipped. * XML docs and reflection-disabled win-x64 Native AOT publish/run passed. * Native Linux/macOS and elevated live-host tests were not run locally. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 30c4f940-9c8e-4d3e-89ff-b1776045bb1c Generated-with: gpt-6-sol
There was a problem hiding this comment.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Copilot review overview
Review effort: Lite
Findings: 1
Open (6)
Required-but-nullable schema properties (e.g., viaanyOf: [T, null]while still listed in… MintingcontainerIdfrom only 4 random bytes (32 bits) makes collisions plausible in… · NewinheritDefaultEnvcan currently be emitted even whenenvis omitted (i.e.,process.envis… · New This now scans the entireMxcLifecycle.cssource for\"...\" => StateAwareContainment.X… This regex-based field extractor is brittle: it only matches when[JsonPropertyName(...)]appears…camelCaseappears to be unused after the refactor to schema-based comparisons and the updated… · New
Resolved since last review (1)
| if (cwd !== undefined) process.cwd = cwd; | ||
| const env = environment(config, options); | ||
| if (env !== undefined) process.env = env; | ||
| if (inheritDefaultEnv(config, options)) process.inheritDefaultEnv = true; |
44e58a0 to
260bd1c
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Malformed C# artifact metadata can silently bypass drift validation, and migration documentation remains stale.
Review effort: Balanced
Findings: 2
Open (3)
Resolved since last review (5)
Required-but-nullable schema properties (e.g., viaanyOf: [T, null]while still listed in… MintingcontainerIdfrom only 4 random bytes (32 bits) makes collisions plausible in… This now scans the entireMxcLifecycle.cssource for\"...\" => StateAwareContainment.X… This regex-based field extractor is brittle: it only matches when[JsonPropertyName(...)]appears…camelCaseappears to be unused after the refactor to schema-based comparisons and the updated…
| const hasCsharpPath = | ||
| typeof contract.csharpPath === "string" && contract.csharpPath.length > 0; |
| { | ||
| ArgumentNullException.ThrowIfNull(request); | ||
| return MxcJson.Serialize(PrepareRequest(request), MxcJson.Options); | ||
| return ExactOneShotRequestWriter.Serialize(request); |



This PR maps V1 .NET execution and request probing to the SDK-owned exact
1.0.0 JSON contract. It generates C# wire types from the registered Rust
contract and uses one writer for all native entry points, preserving Native
AOT through source-generated serialization.
Details
numeric bounds and required nullable fields under null-omitting options.
serialization and actionable errors for unsupported policy.
values, and unsupported stable experimental authorization before native.
attribute ordering, ignored fields, and sandbox-id prefix dispatch.
Tests
Microsoft Reviewers: Open in CodeFlow