Skip to content

feat(mxc): integrate Windows runtime on portable isolation foundations - #4084

Draft
drew wants to merge 32 commits into
codex/runtime-foundationsfrom
drew-mxc
Draft

drew wants to merge 32 commits into
codex/runtime-foundationsfrom
drew-mxc

Conversation

@drew

@drew drew commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Implement native Windows MXC behind the compute-driver and isolation-backend extension points, on top of the backend-neutral foundations in #4106. The host supervisor remains a separate process; the dedicated openshell-windows-sandbox executable runs inside the ProcessContainer.

Related Issue

Follow-up to #1737 (RFC 0012); Windows scope tracked in #2050 and RFC 0013.

Changes

  • Provision and monitor the host supervisor and Windows sandbox as one authenticated runtime generation.
  • Reuse the shared Sandbox Protocol for workload lifecycle, retained output, exec, forwarding, and supervisor sessions.
  • Keep Windows containment evidence and process operations in openshell-mxc-boundary, with driver-owned provisioning and ETW.
  • Keep supervisor-owned network policy/provider resolution and generation-authenticated explicit proxying.
  • Carry effective-policy delivery, UI policy/capability work, CLI improvements, and portable audit output as residual changes in this second PR; these were intentionally not included in the narrow base.
  • Preserve the base's Unix signal behavior and correct RFC references to openshell-windows-sandbox.

Testing

  • mise run pre-commit passes through the stacking commit hook.
  • Native Windows runtime qualification without mocks.
  • Linux sandbox E2E regression validation.
  • Native ARM64 runtime qualification.

The prior PR head passed the native workspace suite (6082 passed, 27 skipped), but that is prior verification, not a fresh result for this stacking commit. Native MXC E2E remains incomplete, not passed.

Checklist

  • Follows Conventional Commits.
  • New stacking commit is signed off (DCO).
  • Runtime documentation, configuration examples, contributor inventories, and RFC binary references updated.

Stack

  1. refactor(runtime): decouple supervisor access and boundary audit validation #4106: main -> codex/runtime-foundations.
  2. This PR: codex/runtime-foundations -> drew-mxc.

Merge #4106 first, then retarget this PR to main. If the base is squash-merged, merge updated main into drew-mxc so its comparison stays incremental. Existing MXC history is retained through a normal merge; no force-push is used.

Known blockers

  • This host lacks native ProcessContainer PSEC/host-loopback support required by the real path.
  • Independently of the host, MXC currently establishes no outer-fence guarantees: broad host loopback and unverified live revocation remain implementation/qualification gaps. Admission stays fail-closed; a newer host alone does not resolve this.
  • Direct-proxy traffic uses the admitted main binary identity, not per-descendant socket-owner attribution. This is a separately reviewed networking model, not portability cleanup.
  • Delete identity CLI flags are not yet transmitted in the public delete request. They currently do not protect against a same-name replacement; this incomplete residual must be completed or removed before merge.
  • Windows ConPTY resize and durable restart recovery remain unsupported.

Keep this PR draft. Do not weaken admission checks or substitute mock E2E to claim runtime completion.

shailendra-nv and others added 28 commits September 16, 2026 17:29
Signed-off-by: Shailendra Singh <shailendras@nvidia.com>
Signed-off-by: Shailendra Singh <shailendras@nvidia.com>
- Introduced `pending_provider_credentials` in `MxcComputeBackend` to manage out-of-band provider credential state.
- Added `append_provider_child_env` function to merge provider credentials into the agent environment, ensuring sensitive values are not exposed.
- Updated `create_sandbox` method to validate egress requirements for provider credentials.
- Implemented `resolve_sandbox_create_runtime_inputs` to prepare driver-specific sandbox creation state, including effective policy and provider credentials.
- Modified gRPC handlers to utilize the new provider credential management features.
- Updated documentation to clarify the use of provider credentials and their requirements for governed egress.

Signed-off-by: Akber Raza <akberr@nvidia.com>
Add an end-to-end Windows MXC scenario for verifying provider credential
handling without exposing the raw credential to the sandbox.

The scenario confirms that the sandbox receives a revision-scoped
GITHUB_TOKEN placeholder, the host CONNECT proxy substitutes the credential
only for api.github.com, and use of the same placeholder against github.com
is rejected with credential_endpoint_mismatch.

Use inbox Windows PowerShell and curl for the probe so the standard Windows
build requires no additional test executable. Configure SystemRoot and
PATHEXT explicitly through agent_env, which provides the minimum environment
needed to locate and execute curl while avoiding implicit inheritance of the
gateway environment.

Add pc_disable_ui for process-container workloads that require Win32k during
startup. Preserve the hardened default and continue denying clipboard access
and input injection when UI compatibility is enabled.

Collect redacted diagnostic artifacts, check for raw-token leakage, and
document the MXC configuration and credential-validation workflow.

Tests:
- cargo test -p openshell-driver-mxc
- Windows PowerShell curl launch with only SystemRoot and PATHEXT

Signed-off-by: Akber Raza <akberr@nvidia.com>
- pass effective provider policy and credential state into MXC sandbox creation
- inject revision-scoped placeholders into the MXC child environment
- resolve provider credentials only through governed host CONNECT proxy requests
- add gateway and driver coverage for secret isolation and policy propagation
- update MXC documentation and remove obsolete provider-v2 test setup

Signed-off-by: Akber Raza <akberr@nvidia.com>
Clarify that the provider credential example uses process_container and does not require the isolation_session DLL or build feature.

Signed-off-by: Akber Raza <akberr@nvidia.com>
Mark the credential scenario failed and suppress its ZIP bundle when any result artifact cannot be inspected for raw-token leakage.

Signed-off-by: Akber Raza <akberr@nvidia.com>
Detect and redact a raw provider token before the credential probe result can reach console or CI logs.

Signed-off-by: Akber Raza <akberr@nvidia.com>
Derive provider layers, credential scopes, and binding records from the same loaded provider snapshot to eliminate cross-read inconsistency.

Signed-off-by: Akber Raza <akberr@nvidia.com>
Require workspace authorization before returning sandbox provider environment or credential binding data, while preserving sandbox-principal scope checks and not-found concealment.

Signed-off-by: Akber Raza <akberr@nvidia.com>
Fail sandbox creation for expiring static provider credentials because MXC has no live refresh channel, while retaining request-time dynamic token grants and documenting recreation requirements.

Signed-off-by: Akber Raza <akberr@nvidia.com>
Clarify that per-sandbox ports provide routing separation rather than peer authentication, place host-local processes in the trusted computing base, and retain M3 as the stronger source-attribution dependency.

Signed-off-by: Akber Raza <akberr@nvidia.com>
- preserve native JSON arguments under Windows PowerShell
- tolerate existing gateway registrations
- reject network executable paths with actionable launch diagnostics
- record redacted failure context in result bundles

Signed-off-by: Akber Raza <akberr@nvidia.com>
… env keys

Address the three blocking findings from the automated review of
#3296 (head 550b81a):

- Already-expired static provider credentials were silently withheld by
  the shared resolver before the create-time fail-closed check ran, so
  an MXC sandbox could be created without the configured credential
  instead of rejecting the request. Track withheld expired keys
  separately in ProviderEnvironment so the MXC create-time validator
  can still reject them.
- Provider credential environment keys that collided case-insensitively
  with each other, or with the reserved TLS trust env vars injected
  later, were not validated before staging, producing an ambiguous or
  silently overwritten sandbox environment on Windows. Reject these
  synchronously at CreateSandbox instead.
- The Global Policy Override docs said the global payload only supplies
  dynamic policy fields, but the implementation replaces the complete
  effective policy except UI. Corrected the description.

Signed-off-by: Prashant S Khodade <pkhodade@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Stack the combined GitLab !98, !105, and !108 port on the provider-credential branch without the later main integration. Preserve prerequisite configuration and protobuf compatibility, and include native Windows validation fixes.

Co-authored-by: Prashant S Khodade <pkhodade@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
…ation/drew

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

# Conflicts:
#	crates/openshell-server/src/storage_proto.rs
#	proto/openshell.proto
#	sdk/go/proto/openshellv1/openshell.pb.go
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
@drew
drew requested review from mrunalp and sjenning as code owners October 1, 2026 22:13
@drew
drew requested review from a team and derekwaynecarr as code owners October 1, 2026 22:13
@copy-pr-bot

copy-pr-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

drew added 2 commits October 1, 2026 21:10
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
@drew drew changed the title chore: (wip) merge windows support on 0.1.x feat(mxc): integrate Windows runtime on portable isolation foundations Oct 2, 2026
@drew
drew changed the base branch from main to codex/runtime-foundations October 2, 2026 05:56

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants