Skip to content

Retire pre-v0.9 schema contracts and migrate configs - #1382

Open
Gudge (MGudgin) wants to merge 19 commits into
mainfrom
user/gudge/remove-schema-0-6-to-0-8
Open

Gudge (MGudgin) wants to merge 19 commits into
mainfrom
user/gudge/remove-schema-0-6-to-0-8

Conversation

@MGudgin

@MGudgin Gudge (MGudgin) commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

This PR retires exact schema contracts before v0.9 and raises the raw-config
support floor to 0.9.0-alpha. It migrates configs, SDK version checks, and
authoring documentation to the supported contract set.

Details

  • Remove v0.6-v0.8 contract modules, adapters, and obsolete version tests.
  • Migrate fixtures and examples to supported directional networking.
  • Keep end-to-end enforcement checks for supported policies and fail-closed
    rejection tests for retired or unsupported network policy.
  • Update the Rust, Node, and .NET version surfaces and migration guidance.
  • Retire the Node testing-feature option after its only wire form was removed.

Tests

  • cargo fmt --manifest-path .\src\Cargo.toml --all -- --check: passed.
  • From src, cargo test -p bwrap_common -p lxc_common --lib --quiet:
    100 and 373 passed. cargo test -p lxc_common --test chain_name_script_drift_spec --quiet: 3 passed.
  • In WSL/Linux, cargo test -p bwrap_common --lib --quiet -- --test-threads=1: 354 passed; cargo clippy -p bwrap_common --all-targets -- -D warnings: passed. The default parallel lib suite
    had one intermittent provider-monitor test failure; it passed alone.
  • From sdk/node, npm run typecheck:integration: passed, including
    corrected v0.9 LXC test labels.
  • node scripts/versioning/validate-configs.js: passed (396 configs,
    14 intentionally invalid). node scripts/versioning/check-tests-present.js,
    node scripts/versioning/check-contract-codegen.js, and
    node scripts/versioning/check-schema-versions.js: passed.
  • Hyperlight migration assertions passed (2 cases) against a local debug
    executor. Migrated numeric examples passed exact-policy dry-run parsing.
    Changed Bash scripts passed syntax checks.
  • In WSL/Linux, bash tests/scripts/run_bwrap_localnet_test.sh: 3 cases
    passed; bash tests/scripts/run_bwrap_environment_test.sh: 21 assertions
    passed. Both changed scripts passed bash -n on Windows. The updated proxy
    documentation example parsed as JSON; v0.9 Hello World passed dry-run parsing.
  • The canonical docs/schema.md network example parsed as JSON with valid
    CIDRs; the external-proxy example's Python workload passed syntax checking.
    src\target\debug\wxc-exec.exe --dry-run tests\examples\11_localhost_proxy_processcontainer.json reached backend
    validation (exit 1: this Windows host lacks PSEC 1.1 host-loopback support).
    tests\scripts\run_processcontainer_all_tests.ps1 passed PowerShell parsing.
  • From src, cargo test -p lxc_common --lib --quiet: 373 passed;
    cargo clippy -p lxc_common --all-targets -- -D warnings: passed.
    The LXC proxy-refusal test checks that its guidance names a supported
    alternative rather than a retired contract.
  • In WSL/Linux, bash tests/scripts/run_bwrap_network_test.sh: passed with
    a live reachable listener and a blocked sandbox probe. On Windows,
    bash -n tests/scripts/run_bwrap_network_test.sh: passed.
  • PowerShell parsed tests/scripts/run_processcontainer_lifecycle_test.ps1
    without errors. src\target\debug\wxc-exec.exe --dry-run tests\configs\lxc_network_retired_v08.json exited 1 with the expected
    unsupported-contract diagnostic. The host-dependent lifecycle suite was
    not run locally.
  • From sdk/node, npm run build, npm test (398 passed, 20 skipped),
    and npm run typecheck:integration: passed on the updated mapper and types.
  • bash -n tests/scripts/run_seatbelt_examples_test.sh: passed. The
    Seatbelt example's CIDR passed strict syntax checking; its host-only backend
    rejection awaits macOS validation. The Bubblewrap guide's nine JSON blocks
    and five links were checked.
  • From src, cargo test -p wxc_common -p seatbelt_common --lib --quiet:
    907 and 104 passed; cargo clippy -p seatbelt_common -p wxc_common --all-targets -- -D warnings: passed. The updated macOS examples passed
    schema validation; host-only Seatbelt behavior awaits macOS CI.
  • In WSL/Linux, bash tests/scripts/run_lxc_network_proxy_rejection_test.sh:
    three pre-container rejections passed, including the credentialed case;
    bash -n passed. The full LXC container suite needs host tooling not
    available locally.
  • From src, cargo test -p wxc_e2e_tests --test e2e_windows -- --list:
    compiled and listed 20 tests; the obsolete built-in proxy case is absent.
  • Parsed all six JSON snippets in docs/examples.md. With a command added
    to the one policy fragment, src\target\debug\wxc-exec.exe --dry-run --config-base64 accepted every exact request shape: four exited 0, and
    two reached host-dependent backend checks (exit 1, not a parse error).
  • In WSL/Linux, cargo test -p bwrap_common --lib bwrap_command::tests --quiet: 71 passed; cargo clippy -p bwrap_common --all-targets -- -D warnings: passed. On Windows, cargo test -p nanvix_runner -p process_container_common --lib --quiet: 41 and 315 passed; Clippy with
    -D warnings passed for both crates.
  • Host-dependent LXC and macOS E2E suites cannot run on this Windows host;
    CI is rerunning on the latest head.
Microsoft Reviewers: Open in CodeFlow

Gudge and others added 4 commits October 2, 2026 18:04
This PR removes the retired pre-v0.9 exact contracts from the Rust parser,
registry, adapters, schema generator, and backend compatibility tests. The
only registered contracts are now 0.9.0-alpha, 1.0.0, and 1.1.0-alpha, and
old declared versions fail through the unsupported-contract-version path.

Details

* Delete the v0.6, v0.7, and v0.8 exact contract modules and adapters.
* Shrink ContractVersion, registry descriptors, generator dispatch, and parser
  dispatch to v0.9, v1.0, and v1.1.
* Remove pre-v0.9 network/default-env compatibility modes from runtime tests.
* Keep backend policy fields used by normalized directional and proxy paths.

Tests

* cargo fmt --all -- --check; cargo check --workspace --all-targets
  --all-features; cargo clippy --workspace --all-targets --all-features --
  -D warnings; cargo build -p wxc --all-features; cargo test --workspace.
* RUSTDOCFLAGS=-D warnings cargo doc -p mxc-sdk -p mxc_ffi -p
  mxc_config_contract --no-deps --all-features.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 33217f7b-dc7d-4da0-af5f-018fef64013c
Generated-with: gpt-5.5
This PR migrates repository config fixtures and versioning gates to the new
0.9.0-alpha support floor. Fixtures that still exercise supported behavior now
declare v0.9 and use directional networking, while stale invalid exemptions and
obsolete exact-contract fixture suites are removed.

Details

* Move test configs, examples, regression snippets, and scripts to v0.9.
* Translate legacy network defaults, host lists, and proxy fields into
  directional network and runtimeConfig shapes where needed.
* Update versioning tests and config-validation exemptions for the smaller
  registered contract set.

Tests

* node scripts/versioning/check-schema-versions.js; node
  scripts/versioning/check-contract-codegen.js; node
  scripts/versioning/validate-configs.js; node
  scripts/versioning/check-tests-present.js.
* scripts/versioning npm test: 67 passed.
* cargo test --workspace.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 33217f7b-dc7d-4da0-af5f-018fef64013c
Generated-with: gpt-5.5
This PR updates the Node and .NET SDK version surfaces, raw-config tests, and
changelogs for the v0.9.0-alpha minimum contract. Raw configs that declare
earlier published alpha contracts now match the native parser and fail as
unsupported.

Details

* Set .NET SchemaVersions.Minimum to 0.9.0-alpha and remove legacy default
  helpers from the managed surface.
* Narrow Node legacy alias acceptance to the only remaining pre-v1 contract.
* Retarget SDK tests and integration fixtures to v0.9 directional networking.
* Add a breaking changelog entry for the raised raw-contract floor.

Tests

* sdk/node: npm install; npm run build; npm test; integration npm install;
  npm run typecheck.
* sdk/dotnet: dotnet test --solution Microsoft.Mxc.Sdk.slnx (260 passed,
  27 skipped).
* node scripts/check-dotnet-api-parity.js; node
  scripts/check-dotnet-bindings-codegen.js; node
  scripts/check-dotnet-errorcode-parity.js.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 33217f7b-dc7d-4da0-af5f-018fef64013c
Generated-with: gpt-5.5
This PR updates repository documentation to describe the current supported raw
config contracts after retiring the pre-v0.9 alpha contracts. Historical stable
schema files remain immutable history, but current authoring guidance now points
at v0.9, v1.0, and v1.1 only.

Details

* Update versioning and schema documentation with the new registered set.
* Refresh backend guides and examples to use v0.9 directional networking.
* Clarify that earlier alpha schema files are retired history, not accepted
  runtime contracts.

Tests

* Documentation-only commit; covered by final repo validation: cargo fmt,
  cargo check, cargo clippy, cargo test, rustdoc, Node SDK, .NET SDK, and
  versioning/parity script checks.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 33217f7b-dc7d-4da0-af5f-018fef64013c
Generated-with: gpt-5.5
@MGudgin
Gudge (MGudgin) requested review from a team and a balanced review from Copilot October 3, 2026 01:25
@MGudgin
Gudge (MGudgin) requested a review from a team as a code owner October 3, 2026 01:25
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Multiple migrated fixtures are invalid under the 0.9 contract or no longer match their test harnesses, causing unit and host-dependent suites to fail.

Review effort: Balanced
Findings: 27 High severity · 2 Low severity

Open (29)

And 9 more that still need to be addressed.

What changed in this PR

Raises the exact raw-config support floor to 0.9.0-alpha, removes older Rust contracts, and migrates documentation, SDKs, examples, and test fixtures.

Changes:

  • Removes v0.6–v0.8 contracts, adapters, fixtures, and compatibility behavior.
  • Updates SDK version surfaces and documentation.
  • Migrates network configurations to directional policy and runtime proxy fields.
File group Description
schemas/​schema-version.json Raises minimum supported contract to 0.9.
src/​core/​mxc_config_contract/​** Removes retired contracts and updates boundary tests.
src/​core/​wxc_common/​** Removes legacy compatibility paths and parsing behavior.
src/​backends/​** Updates backend tests and environment/network compatibility handling.
src/​core/​mxc-sdk/​**, src/​ffi/​**, src/​tools/​** Updates SDK, FFI, and schema-generation version usage.
sdk/​node/​** Updates Node types, tests, documentation, and version checks.
sdk/​dotnet/​** Updates .NET version constants, tests, and documentation.
tests/​configs/​**, tests/​examples/​** Migrates repository configurations to 0.9 directional networking.
tests/​scripts/​**, tests/​regression_tests/​** Updates host and regression test versions.
README.md, docs/​** Documents the new support floor and migration guidance.
scripts/​versioning/​** Updates code-generation tests and validation exemptions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread sdk/node/tests/integration/windows-process-container.test.ts Outdated
Comment thread src/backends/bubblewrap/common/src/network_rules.rs
Comment thread tests/configs/bubblewrap_network_directional_pre08_rejected.json Outdated
Comment thread tests/configs/bubblewrap_network_firewall.json Outdated
Comment thread tests/configs/bubblewrap_network_proxy_allowlist.json
Comment thread tests/configs/seatbelt_proxy_host_denied.json Outdated
Comment thread tests/configs/seatbelt_proxy_testing_gate.json Outdated
Comment thread tests/configs/seatbelt_reject_directional_pre08.json Outdated
Comment thread docs/playground-limitations.md Outdated
Comment thread docs/sandbox-policy/0.7.0/policy.md
This PR fixes CI and host-test drift after raising the raw schema floor to
v0.9. Tests now exercise supported directional policies and reject retired
network forms before a workload starts.

Details

* Keep live Bubblewrap, LXC, and Seatbelt allow/deny controls while removing
  legacy acceptance paths that cannot run under the supported contracts.
* Run proxy tests against a real endpoint and assert unsupported hostname
  rules and non-loopback proxies fail closed.
* Align Hyperlight, Node, and macOS characterization tests with the actual
  exact-parser diagnostics; preserve historical documentation as history.

Tests

* cargo fmt --manifest-path .\src\Cargo.toml --all -- --check: passed.
* cargo test -p bwrap_common -p wxc_common --lib --quiet: 100 + 907 passed.
* cargo clippy -p bwrap_common -p wxc_common -p wxc_e2e_tests
  --all-targets --all-features -- -D warnings: passed.
* npm run typecheck:integration: passed; versioning and schema checks passed
  for 401 configs (14 intentional invalid fixtures).
* Hyperlight migration script: both cases passed; Bash and PowerShell scripts
  parsed successfully. Linux/macOS host-dependent E2E awaits CI.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7570a662-a429-46d2-aa24-47fae6655cc4
Generated-with: gpt-6-sol
Copilot AI balanced review requested due to automatic review settings October 3, 2026 01:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Several migrated tests and examples now fail parsing or can pass without exercising the behavior they claim to validate.

Review effort: Balanced
Findings: 13 High severity · 4 Medium severity · 3 Low severity

Open (20)
Resolved since last review (20)

Comment thread sdk/node/tests/integration/linux-bubblewrap.test.ts Outdated
Comment thread src/backends/bubblewrap/common/src/bwrap_runner.rs Outdated
Comment thread src/backends/bubblewrap/common/src/bwrap_runner.rs Outdated
Comment thread src/backends/bubblewrap/common/src/bwrap_runner.rs Outdated
Comment thread src/backends/bubblewrap/common/src/bwrap_runner.rs Outdated
Comment thread tests/examples/03_network_restricted.json Outdated
Comment thread tests/examples/04_combined_restrictions.json Outdated
Comment thread tests/examples/13_lxc_network_restricted.json Outdated
Comment thread docs/process-container/examples/0.8.0-schema.md Outdated
Comment thread docs/sandbox-policy/0.8.0/policy.md Outdated
This PR fixes the remaining CI regressions and review findings after the v0.9
schema floor change. Supported network examples use numeric CIDRs, retired
compatibility tests no longer claim acceptance, and LXC rejection checks
validate the actual parser result and firewall state.

Details

* Align LXC CIDR boundary and retired-version fixtures with exact parsing;
  make rejected-policy chain checks observe real firewall snapshots.
* Replace stale Bubblewrap compatibility cases with Strict fail-closed
  assertions and remove unsupported Linux SDK legacy-proxy cases.
* Restore historical v0.8 examples, remove an obsolete built-in proxy fixture,
  and use numeric addresses in runnable examples.

Tests

* cargo fmt --manifest-path .\src\Cargo.toml --all -- --check: passed.
* cargo test -p bwrap_common -p lxc_common --lib --quiet: 100 + 373 passed;
  cargo test -p lxc_common --test chain_name_script_drift_spec: 3 passed.
* Linux bwrap_common lib tests: 354 passed with --test-threads=1; Linux
  cargo clippy -p bwrap_common --all-targets -- -D warnings: passed.
* npm run typecheck:integration: passed; config and versioning checks passed
  for 400 configs (14 intentionally invalid). Exact example dry runs passed
  parsing, and changed Bash scripts passed syntax checks.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7570a662-a429-46d2-aa24-47fae6655cc4
Generated-with: gpt-6-sol
Copilot AI balanced review requested due to automatic review settings October 3, 2026 02:09

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Two migrated Bubblewrap fixtures contradict their existing test harnesses, proxy E2E coverage is silently disabled, and several SDK migration documents still recommend retired fields.

Review effort: Balanced
Findings: 10 High severity · 4 Low severity

Open (14)
Resolved since last review (12)

Comment thread tests/configs/bwrap_env_08_inherit_rejected.json Outdated
Comment thread docs/examples.md Outdated
Comment thread sdk/dotnet/README.md Outdated
Comment thread sdk/node/CHANGELOG.md Outdated
Comment thread tests/configs/hello_world_v090.json Outdated
This PR aligns the remaining examples and host tests with the v0.9 contract
floor. Authoring guidance now names the runtime proxy field, historical
changelog entries retain their original version, and Bubblewrap tests check
supported ingress policy instead of contradictory legacy assumptions.

Details

* Replace pre-0.9 local-network controls with distinct ingress and
  host-loopback rejection checks plus an implicit-deny success case.
* Keep positive environment inheritance coverage and retire its obsolete
  pre-0.9 gate fixture.
* Correct the runtime-proxy example, managed SDK guidance, historical
  changelog entry, and v0.9 Hello World identifier.

Tests

* bash tests/scripts/run_bwrap_localnet_test.sh: 3 cases passed in WSL.
* bash tests/scripts/run_bwrap_environment_test.sh: 21 assertions passed in
  WSL; bash -n passed for both changed scripts on Windows.
* node scripts/versioning/validate-configs.js: 397 configs validated with
  14 intentional invalid fixtures; check-tests-present and contract-codegen
  checks passed. The proxy documentation example parsed as JSON.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7570a662-a429-46d2-aa24-47fae6655cc4
Generated-with: gpt-6-sol
Copilot AI balanced review requested due to automatic review settings October 3, 2026 02:18

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Two migrated ProcessContainer proxy examples are invalid, and canonical documentation still advertises retired contract behavior.

Review effort: Balanced
Findings: 8 High severity · 2 Medium severity · 2 Low severity

Open (12)
Resolved since last review (6)
Previously missed (1)

In code that hasn't changed since last review

Low severity Architecture docs still describe removed LegacyCompatible contracts

src/​core/​wxc_common/​src/​models.rs:1126

Removing LegacyCompatible leaves the architecture documentation stale: docs/versioning.md:227-233 still describes that variant and says Strict starts at v0.8. Nearby ExecutionRequest docs also still describe pre-v0.9 typed contracts that no longer exist. Update those descriptions to match the single supported compatibility behavior.

Comment thread tests/examples/11_localhost_proxy_processcontainer.json
Comment thread tests/examples/12_builtin_test_proxy_processcontainer.json Outdated
Comment thread schemas/schema-version.json
Comment thread tests/scripts/run_processcontainer_all_tests.ps1 Outdated
This PR updates the remaining ProcessContainer proxy examples and canonical
schema guidance for the supported exact contracts. The runnable example now
requires an external proxy and the native host-loopback capability instead of
silently reporting success when no proxy is present.

Details

* Document directional networking as the only supported authoring shape and
  keep legacy host-list semantics explicitly historical.
* Add the required ingress posture to the external proxy example, propagate
  workload failures, and remove the retired built-in proxy example.
* Correct the Windows suite header to reflect stable 1.0.0 generated configs.

Tests

* node scripts/versioning/validate-configs.js: 396 configs validated, with
  14 intentionally invalid fixtures; codegen and test-presence checks passed.
* Parsed the canonical network example as JSON and checked its CIDRs; the
  external-proxy Python command compiled and PowerShell suite parsed.
* Native dry-run passed exact parsing and reached the expected host-capability
  rejection on this Windows host, which lacks PSEC 1.1 host-loopback support.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7570a662-a429-46d2-aa24-47fae6655cc4
Generated-with: gpt-6-sol
Copilot AI balanced review requested due to automatic review settings October 3, 2026 02:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Retired-field guidance remains in shipped examples and errors, and deleting the built-in proxy fixture leaves a registered E2E test silently exercising nothing.

Review effort: Balanced
Findings: 1 Medium severity · 1 Low severity

Open (2)
Resolved since last review (12)
Previously missed (3)

In code that hasn't changed since last review

Low severity Update workload text to document supported egress rules

tests/​examples/​06_network_capabilities_only.json:11

After migrating this policy to directional egress, the workload text at line 6 still tells users to select enforcementMode: "firewall" or "both". Exact 0.9 rejects that retired field; update the example text to point to supported egress.allow/egress.deny CIDR and port rules.

Low severity Update workload text to describe the directional egress policy

tests/​examples/​19_mac_network_restricted.json:6

The workload text was not migrated with the policy: it still describes allowedHosts under defaultPolicy=block, while this file now uses directional egress.default=deny. This shipped example should explain the policy it actually contains (and refer to the supported proxy example without presenting retired field names as current authoring).

Low severity Replace retired defaultPolicy guidance with egress.default

tests/​examples/​22_mac_network_allow_all.json:6

The output still says “With defaultPolicy allow” even though this migrated example no longer contains that retired field. Change the note to name network.egress.default = allow, otherwise users copying the example receive contradictory guidance.

Comment thread schemas/schema-version.json
Comment thread src/core/mxc-sdk/README.md
This PR fixes LXC's runtime-proxy refusal so it no longer recommends a
contract version or proxy field that production parsing rejects. The LXC
backend guide and Rust SDK README now describe the supported directional
networking surface consistently.

Details

* Tell LXC callers that supported contracts have no proxy surface and to
  select a backend that can enforce the requested loopback proxy instead.
* Remove retired networking advice from the LXC guide and pin the error
  message's supported-alternative behavior with a unit assertion.

Tests

* cargo fmt --manifest-path .\src\Cargo.toml --all -- --check: passed.
* From src, cargo test -p lxc_common --lib --quiet: 373 passed.
* From src, cargo clippy -p lxc_common --all-targets -- -D warnings: passed.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7570a662-a429-46d2-aa24-47fae6655cc4
Generated-with: gpt-6-sol
Copilot AI balanced review requested due to automatic review settings October 3, 2026 02:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The Node testing-feature API is now unusable, and several public migration examples still recommend retired fields.

Review effort: Balanced
Findings: 6 Low severity

Open (6)

Comment thread sdk/dotnet/README.md
Comment thread sdk/node/tests/unit/sandbox.test.ts
Comment thread src/backends/seatbelt/common/src/seatbelt_runner.rs Outdated
Comment thread src/core/wxc_common/src/models.rs
Comment thread tests/examples/19_mac_network_restricted.json Outdated
Comment thread tests/examples/22_mac_network_allow_all.json Outdated
This PR removes a Node testing-feature option whose only wire use was the
retired built-in proxy form. It also corrects migration guidance and examples
that still described pre-v0.9 network and environment behavior.

Details

* Remove allowTestingFeatures from the Node API, CLI argument forwarding, and
  obsolete tests; retain a supported runtime-proxy argument check.
* Direct .NET callers to supported directional/runtime proxy policy and
  describe DefaultBlock as the only registered environment behavior.
* Update two Seatbelt examples to describe their actual directional policy
  and make outbound-connect failures visible.

Tests

* From sdk/node, npm run build, npm test (398 passed, 20 skipped), and
  npm run typecheck:integration: passed.
* cargo fmt --manifest-path .\src\Cargo.toml --all -- --check: passed.
* From src, cargo test -p wxc_common -p seatbelt_common --lib --quiet:
  907 and 104 passed; cargo clippy for both crates with -D warnings passed.
* node scripts/versioning/validate-configs.js: 396 configs validated,
  including 14 intentionally invalid fixtures.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7570a662-a429-46d2-aa24-47fae6655cc4
Generated-with: gpt-6-sol
Copilot AI balanced review requested due to automatic review settings October 3, 2026 03:18

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The LXC proxy-rejection test currently fails in its fixture guard, and several updated guides still contain contradictory retired-contract guidance.

Review effort: Balanced
Findings: 1 Medium severity · 1 Low severity

Open (2)
Resolved since last review (6)
Previously missed (3)

In code that hasn't changed since last review

Medium severity Remove obsolete E2E test with deleted fixture

tests/​configs/​processcontainer_proxy_builtin_test.json:1

Deleting this fixture leaves test_processcontainer_proxy in src/testing/wxc_e2e_tests/tests/e2e_windows.rs:218-227,669-673 silently returning because the file is missing, so the test remains in the suite but can never exercise anything. Remove that obsolete E2E case in the same retirement change rather than retaining a permanently skipped test.

Low severity Update semantics paragraph for sole Strict mode

docs/​versioning.md:166

This retirement statement conflicts with the runtime-semantics paragraph later in this same document (docs/versioning.md:227-233), which still says the removed NetworkEnforcementCompatibility::LegacyCompatible accepts v0.6/v0.7 JSON and typed inputs. Update that paragraph to describe the sole Strict mode and supported contracts.

Low severity Remove duplicate supported-version entries

sdk/​node/​README.md:619

The supported-version recommendation now repeats 0.9.0-alpha four times. The registered set is only 0.9.0-alpha, 1.0.0, and 1.1.0-alpha, so list each once to avoid confusing users.

Comment thread tests/scripts/run_lxc_network_proxy_rejection_test.sh Outdated
Comment thread docs/seatbelt/seatbelt-backend.md Outdated
This PR fixes the LXC proxy rejection guard so it checks the raw fixture
while keeping credentials out of diagnostics. It also removes an ignored
Windows E2E case whose fixture was retired and updates public guidance for
the supported directional networking contracts.

Details

* Preserve raw proxy URL comparison and redacted output in LXC rejection
  checks, including credential-bearing requests.
* Remove the permanently skipped built-in ProcessContainer proxy test.
* Update Seatbelt, versioning, and Node guidance to distinguish supported
  directional policy from retired legacy network forms.

Tests

* WSL live run of run_lxc_network_proxy_rejection_test.sh: all 3 rejection
  cases passed, including credential redaction; bash -n passed.
* cargo fmt --manifest-path .\src\Cargo.toml --all -- --check: passed.
* cargo test -p wxc_e2e_tests --test e2e_windows -- --list: compiled and
  listed 20 tests, without the deleted-fixture proxy case.
* node scripts/versioning/validate-configs.js: 396 configs validated with
  14 intentionally invalid fixtures; check-tests-present passed.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7570a662-a429-46d2-aa24-47fae6655cc4
Generated-with: gpt-6-sol
Copilot AI balanced review requested due to automatic review settings October 3, 2026 03:27

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The updated authoring guide still contains a prominent network example using fields that every newly supported contract rejects.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
Resolved since last review (2)

Comment thread docs/examples.md
This PR updates the starter examples in the public authoring page to use
registered exact contracts. The network example now demonstrates numeric
CIDR-and-port policy instead of legacy host-list fields that production
parsing rejects.

Details

* Give Hello World and filesystem examples v1.0 process requests and
  supported containment and lifecycle fields.
* Make the network sample use directional egress and ingress with a numeric
  destination; keep the proxy guidance on its supported runtime surface.

Tests

* Parsed all six JSON code blocks in docs/examples.md. Five are complete
  requests; the policy fragment was completed with a command for validation.
* wxc-exec.exe --dry-run --config-base64 accepted all six exact policy shapes:
  four completed (exit 0), two reached host-dependent backend checks (exit 1).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7570a662-a429-46d2-aa24-47fae6655cc4
Generated-with: gpt-6-sol
Copilot AI balanced review requested due to automatic review settings October 3, 2026 03:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The active WSLC example guide still describes a retired network.proxy.url shape despite the new support floor.

Review effort: Balanced
Findings: None

Resolved since last review (1)
Previously missed (1)

In code that hasn't changed since last review

Low severity Update WSLC guide to reference runtimeConfig.networkProxy

schemas/​schema-version.json:3

Raising the floor leaves the active WSLC guide inconsistent: docs/wsl/wsl-container-getting-started.md:627 still describes tests/configs/wslc_network_proxy.json as using network.proxy.url, but that fixture now uses runtimeConfig.networkProxy and no registered contract accepts network.proxy. Update that example description as part of the documented migration so users are not directed to the retired field.

This PR updates the active WSLC guide to describe supported directional
networking and `runtimeConfig.networkProxy` rather than a retired
`network.proxy.url` request. It distinguishes a proxy on the container's own
loopback from one bound to the unreachable host or distro loopback.

Details

* Name the current runtime field in the runnable proxy-fixture link.
* Mark pre-v0.9 network fields as retired and point readers to directional
  policy and `wslc.portMappings` for supported network intent.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7570a662-a429-46d2-aa24-47fae6655cc4
Generated-with: gpt-6-sol
Copilot AI balanced review requested due to automatic review settings October 3, 2026 03:46

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The 313-file contract removal affects every backend and several host-dependent suites remain dependent on final CI validation.

Review effort: Balanced
Findings: None

Previously missed (4)

In code that hasn't changed since last review

Low severity Remove redundant Strict compatibility loop

src/​backends/​bubblewrap/​common/​src/​bwrap_command.rs:1731

This outer loop now repeats Strict twice, making strict unconditionally true and executing the full matrix twice. Remove the compatibility loop and simplify the expectations/comments to the only supported strict behavior.

Low severity Remove duplicate Strict compatibility case

src/​backends/​nanvix/​runner/​src/​lib.rs:1276

The compatibility loop now contains Strict twice, so every matrix case runs twice without covering a second behavior. Collapse the outer loop to a single strict case (and rename the legacy-oriented test) so the suite does not imply removed compatibility coverage.

Low severity Remove obsolete duplicate legacy-mode test

src/​backends/​process_container/​common/​src/​base_container_runner.rs:2628

Replacing the removed legacy mode with DefaultBlock makes this test identical to explicitly_empty_env_yields_an_empty_block_not_the_default immediately above, and the below_0_9 name now describes an unsupported state. Remove this obsolete duplicate rather than retaining it as apparent compatibility coverage.

Low severity Remove duplicate compatibility assertion

src/​backends/​process_container/​common/​src/​launch_diagnostics.rs:514

Both entries are now the same sole compatibility variant, so this test executes the identical assertion twice while its name claims coverage across schema versions. Collapse this to one request/assertion and rename it to describe the supported behavior.

This PR removes duplicate backend test cases left by retiring the legacy
network and environment compatibility variants. The supported Strict and
DefaultBlock behavior remains covered once, with test names that reflect the
registered-contract floor.

Details

* Run the Bubblewrap namespace and Nanvix argument matrices once under
  the sole Strict mode.
* Remove a duplicate empty-environment test and collapse the Windows
  validation case to its single supported default.

Tests

* In WSL, cargo test -p bwrap_common --lib bwrap_command::tests --quiet:
  71 passed; cargo clippy -p bwrap_common --all-targets -- -D warnings passed.
* From src on Windows, cargo test -p nanvix_runner -p
  process_container_common --lib --quiet: 41 and 315 passed; Clippy for both
  crates with -D warnings passed.
* cargo fmt --manifest-path .\src\Cargo.toml --all -- --check: passed.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7570a662-a429-46d2-aa24-47fae6655cc4
Generated-with: gpt-6-sol
Copilot AI balanced review requested due to automatic review settings October 3, 2026 03:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The 313-file cross-platform policy migration still warrants human approval, particularly because host-dependent LXC and macOS suites were not run locally.

Review effort: Balanced
Findings: None

Previously missed (2)

In code that hasn't changed since last review

Low severity Document removal of public allowTestingFeatures API

sdk/​node/​CHANGELOG.md:13

The public allowTestingFeatures option is removed in this PR, but the breaking-change section only mentions the contract floor. Add that API removal here so Node consumers upgrading to 0.9 can identify and fix the resulting type/API break.

Low severity Update test labels and policy reference from schema 0.8 to 0.9

sdk/​node/​tests/​integration/​linux-process-container.test.ts:205

This request now uses 0.9, but the test title, container ID, and failure diagnostic still call it schema 0.8 and link the retired 0.8 policy. A failure will therefore identify the wrong contract; update those labels and the documentation reference to the 0.9/current behavior together.

This PR records the removal of Node's public testing-feature option and
updates Linux LXC integration diagnostics to match the supported v0.9
contract they actually send.

Details

* Document the removed allowTestingFeatures option and its retired built-in
  proxy wire form in the current Node changelog.
* Name the v0.9 contract in the LXC test, fixture id, and failure message;
  remove the unreachable pre-v0.9 network helper branch.

Tests

* From sdk/node, npm run typecheck:integration: passed. The root-only LXC
  integration test requires a configured Linux LXC host and was not run here.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7570a662-a429-46d2-aa24-47fae6655cc4
Generated-with: gpt-6-sol
Copilot AI balanced review requested due to automatic review settings October 3, 2026 04:05

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Two migrated runnable examples still direct users to retired network fields that every supported exact contract rejects.

Review effort: Balanced
Findings: None

Previously missed (1)

In code that hasn't changed since last review

Low severity Update migration guidance to use directional egress policy fields

tests/​examples/​06_network_capabilities_only.json:12

The migrated policy is directional, but the workload still tells users to use the retired enforcementMode: "firewall" | "both" field and describes this as an explicitly selected capabilities mode. Every registered contract rejects enforcementMode, so running this example now prints unusable migration guidance. Describe network.egress.default=allow here and point granular policies to directional CIDR/port rules instead.

This PR updates runnable examples to describe and exercise supported
network.egress policy instead of retired defaultPolicy and enforcementMode
fields. The old capabilities-only example is renamed for the posture it
actually declares.

Details

* Describe general outbound access with egress.default=allow and point
  granular policies to numeric CIDR/port allow rules.
* Keep the combined Seatbelt example and the directional ProcessContainer
  example consistent with their declared supported contracts.

Tests

* node scripts/versioning/validate-configs.js: 396 configs validated,
  including 14 intentionally invalid fixtures; check-tests-present passed.
* Parsed the three changed examples as JSON, checked embedded Python/Bash
  syntax, and dry-ran all exact requests: two passed validation; the macOS
  backend request reached host-specific validation on this Windows host.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7570a662-a429-46d2-aa24-47fae6655cc4
Generated-with: gpt-6-sol
Copilot AI balanced review requested due to automatic review settings October 3, 2026 04:13

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The 315-file cross-platform contract retirement requires final human review despite broad validation coverage.

Review effort: Balanced
Findings: None

Previously missed (1)

In code that hasn't changed since last review

Low severity Update ExecutionRequest docs to remove retired compatibility behavior

src/​core/​wxc_common/​src/​models.rs:1128

Removing the last legacy variant leaves the public ExecutionRequest documentation stale: network_enforcement_compatibility still claims requests can preserve pre-v0.8 behavior (lines 1045-1047), and the environment docs still describe below-0.9 behavior (lines 1073-1076), although retired contracts can no longer construct either state. Update those public docs to describe supported requests only.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants