Skip to content

Fail unavailable guarded denial capture before sandbox creation - #1290

Merged
Richie Gomez (richiemsft) merged 1 commit into
mainfrom
richiemsft/fix-capture-denials-preflight
Sep 28, 2026
Merged

Richie Gomez (richiemsft) merged 1 commit into
mainfrom
richiemsft/fix-capture-denials-preflight

Conversation

@richiemsft

@richiemsft Richie Gomez (richiemsft) commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

📖 Description

Fail captureDenials requests before ProcessContainer backend construction when the selected AppContainer tier requires guarded WPR but WPR/plm.exe prerequisites are unavailable.

The availability check now runs at the shared tier-selection boundary used by both run-to-completion and streaming execution, before DACL mutation or sandbox creation. Native PSEC/V2 capture remains usable without guarded-WPR prerequisites.

🔗 References

Resolves #1248

🔍 Validation

  • cargo fmt --all -- --check
  • cargo test -p process_container_common capture_denials --lib (11 passed)
  • cargo test -p mxc_engine --lib (150 passed)
  • cargo clippy -p process_container_common -p mxc_engine --all-targets -- -D warnings

The full process_container_common suite reached 313/314 tests; the unrelated host-to-container loopback runtime test timed out and reproduced when rerun alone.

✅ Checklist

  • Signed the Contributor License Agreement
  • Linked to an issue
  • Updated documentation (if applicable)
  • Updated Copilot instructions (not required; no build, architecture, or convention change)
  • Cargo.lock is unchanged

📋 Issue Type

  • Bug fix
  • Feature
  • Task
Microsoft Reviewers: Open in CodeFlow

Verify guarded WPR prerequisites after ProcessContainer tier selection but before backend construction or DACL mutation. Keep native PSEC capture independent from guarded fallback availability.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Copilot AI balanced review requested due to automatic review settings September 26, 2026 01:13
@richiemsft
Richie Gomez (richiemsft) requested a review from a team as a code owner September 26, 2026 01:13
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The shared dispatch gate correctly covers both execution paths while leaving native capture independent of guarded-WPR prerequisites.

Review effort: Balanced
Findings: None

What changed in this PR

Adds an early guarded-WPR prerequisite check so unsupported captureDenials requests fail before ProcessContainer sandbox creation.

Changes:

  • Adds reusable prerequisite verification with actionable errors.
  • Gates AppContainer fallback selection while preserving native PSEC/V2 capture.
  • Adds dispatch tests and documents the early failure behavior.
File Description
src/​core/​mxc_engine/​src/​guarded_capture.rs Exposes prerequisite errors through the production factory.
src/​backends/​process_container/​common/​src/​guarded_capture.rs Adds the factory availability-check interface.
src/​backends/​process_container/​common/​src/​dispatcher.rs Rejects unavailable guarded capture before backend or DACL setup.
docs/​schema.md Documents pre-sandbox rejection.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@richiemsft

Copy link
Copy Markdown
Contributor Author

@@ -453,7 +464,14 @@ fn select_backend_with_fallback(
});

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think you need to merge from main - these should be updated.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

:shipit:

@richiemsft
Richie Gomez (richiemsft) merged commit 781e621 into main Sep 28, 2026
31 checks passed
@richiemsft
Richie Gomez (richiemsft) deleted the richiemsft/fix-capture-denials-preflight branch September 28, 2026 18:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

captureDenials run path does not check guarded capture availability before creating the sandbox

3 participants