Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
32 commits
Select commit Hold shift + click to select a range
27548fa
feat(policy): add portable UI policy controls
shailendra-nv Sep 4, 2026
4cf0e41
fix(policy): address UI policy review feedback
shailendra-nv Sep 11, 2026
975de90
feat: enhance MXC backend with provider credential management
araza008 Aug 13, 2026
ba196e9
feat(mxc): validate provider credentials through host proxy
araza008 Aug 20, 2026
f44e95d
feat(mxc): route provider credentials through host proxy
araza008 Sep 10, 2026
c9beb07
docs(mxc): scope isolation session prerequisites
araza008 Sep 10, 2026
621443b
test(mxc): fail closed on artifact scan errors
araza008 Sep 10, 2026
0815ec8
test(mxc): redact probe output before logging
araza008 Sep 10, 2026
f6f6ed5
fix(policy): reuse provider snapshot for merge validation
araza008 Sep 10, 2026
f39b314
fix(auth): authorize provider environment access
araza008 Sep 10, 2026
45494a5
fix(mxc): reject expiring credential snapshots
araza008 Sep 10, 2026
0e8ff34
docs(mxc): define the host proxy trust boundary
araza008 Sep 10, 2026
30e2d78
fix(mxc): harden provider credential test runner
araza008 Sep 12, 2026
9deb7e6
fix(mxc): address PR #3296 review findings on credential lifetime and…
pkhodade-NV Sep 15, 2026
6c97108
fix(mxc): reject expired handle credentials
prekshivyas Sep 15, 2026
36e62a8
feat(mxc): add relay lifecycle and per-sandbox proxy authentication
prekshivyas Sep 14, 2026
7ea2631
fix(mxc): keep workload config sandbox-scoped
prekshivyas Sep 16, 2026
ba73e13
fix(mxc): harden relay integration after rebase
drew Sep 16, 2026
23362f7
test(cli): isolate completers from system gateways
drew Sep 16, 2026
026afbf
fix(sdk-go): honor system gateway directory override
drew Sep 16, 2026
438bcf0
fix(mxc): preserve relayed TCP half-closes
drew Sep 16, 2026
dc1242f
fix(mxc): reconcile rebased main APIs
drew Sep 17, 2026
c554589
Merge remote-tracking branch 'origin/main' into 1737-mxc-rfc12-integr…
drew Sep 17, 2026
7cd18e1
refactor(isolation): make confirmation backend-neutral
drew Sep 16, 2026
a5301e8
fix(sandbox): validate confirmation evidence at host boundary
drew Sep 16, 2026
ff98bab
refactor(isolation): keep fence evidence driver-owned
drew Sep 16, 2026
7228e69
refactor(mxc): adopt RFC 0012 sandbox runtime
drew Sep 17, 2026
1a5a7a9
fix(mxc): repair Windows runtime launch and validation
drew Sep 30, 2026
fdc0951
refactor(mxc): adopt main isolation backend contracts
drew Oct 2, 2026
cbbdc74
chore(mxc): preserve drew-mxc history in main-based port
drew Oct 2, 2026
d7a5458
refactor(mxc): isolate platform setup and portable supervisor access
drew Oct 2, 2026
e81750f
chore(mxc): stack runtime implementation on portable foundations
drew Oct 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
83 changes: 73 additions & 10 deletions .agents/skills/build-openshell-mxc-windows/SKILL.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: build-openshell-mxc-windows
description: Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64. Use when working on Windows compilation, `windows:*` mise tasks, unsupported Windows compute-driver contracts, or Windows build reports. This skill does not implement Docker, Kubernetes, Podman, VM, MXC driver, policy translation, MSI, service, or supervisor runtime support on Windows.
description: Maintain and validate OpenShell's native Windows MSVC and MXC runtime lane for x64 and ARM64. Use when working on Windows compilation, `windows:*` mise tasks, the MXC supervisor/sandbox pairing, unsupported Windows compute-driver contracts, or Windows build reports. This skill does not implement Docker, Kubernetes, Podman, VM, MSI, or service support on Windows.
metadata:
internal: true
---
Expand All @@ -12,11 +12,13 @@ OpenShell repository. The Windows lane is already present in `main`; do not
treat this skill as a first-time porting recipe unless the user explicitly asks
for a new fork or a from-scratch bring-up.

The lane is build-only. It validates that OpenShell can compile and test on
Windows MSVC for the supported deliverables:
The lane validates that OpenShell can compile and test on Windows MSVC for the
supported deliverables:

- `openshell-gateway.exe`
- `openshell.exe`
- `openshell-supervisor.exe` (host RFC 0012 isolation backend)
- `openshell-windows-sandbox.exe` (MXC ProcessContainer boundary)

It intentionally does not make Windows a Docker, Kubernetes, Podman, or VM
runtime host.
Expand All @@ -29,6 +31,38 @@ Preserve readiness gating on authenticated gateway acceptance and reconnection.
Shared Sandbox Protocol audit validation defaults to strict Linux evidence;
concrete platform validators must be selected by the implementing backend.

The dedicated Windows sandbox binary links the Windows-only `openshell-mxc-boundary`
library for process operations, containment confirmation, and loopback
forwarding. The generic sandbox does not link this library and remains a Linux
runtime. Do not reintroduce a dedicated supervisor-relay executable or link
the compute driver into the sandbox. The supervisor remains a separate host
process. Include boundary-library regression tests in native workspace tests;
their real process/socket checks are not qualification of MXC enforcement.

Keep MXC audit schemas and their validators in the Windows boundary library.
Register its `MxcRuntimeBackend` under `openshell-mxc` at supervisor composition;
it reuses the shared authenticated Sandbox Protocol, whose default Linux
backend remains separate. Shared protocol code
must not interpret MXC evidence. Do not reintroduce driver-owned proxy startup
or gateway create-time credential snapshots. Gateway JSONL audit output
is portable and an explicit operator opt-in, independent of the selected driver.
Keep platform directory conventions in shared path utilities and ETW capture
in the MXC driver. Gateway composition supplies generic connection inputs; the
driver resolves its endpoint defaults and TLS server name. Supervisor gateway
sessions and main attachment must work without SSH on any host. Gate only the
Unix socket adapter, not TCP readiness or authenticated session retries.

Adopt the shared protocol's authenticated policy discovery and monotonic
provider-publication generations. Do not order opaque credential revisions
numerically. MXC rejects unsupported provider file delivery before launch or
environment replacement; it must not acknowledge files it did not install.

Preserve main's explicit outer-fence evidence contract. The current MXC mapper
allows broad host loopback and has no verified live-revocation evidence, so
configuration flags cannot establish the required guarantees. Keep confirmation
fail-closed until native qualification proves each property; a supported PSEC
host alone does not close these implementation gaps.

## Current Repository Shape

The Windows build lane is implemented by these tracked files:
Expand All @@ -52,8 +86,8 @@ In scope:
- Refreshing a local checkout to the latest upstream GitHub `main`.
- Maintaining `tasks/windows.toml` and `tasks/scripts/windows-msvc.ps1`.
- Running x64 and ARM64 MSVC checks.
- Building x64 and ARM64 release binaries for `openshell-gateway` and
`openshell`.
- Building x64 and ARM64 release binaries for `openshell-gateway`, `openshell`,
`openshell-supervisor`, and `openshell-windows-sandbox`.
- Running workspace tests on a native x64 or ARM64 host.
- Running focused unsupported-driver contract tests.
- Reporting test counts, skipped/gated areas, warnings, artifacts, and logs.
Expand All @@ -66,12 +100,9 @@ Out of scope:
- Kubernetes support on Windows.
- Podman, Podman machine, or Podman Desktop support on Windows.
- VM, Hyper-V, WSL, libkrun, or VM-backed sandbox execution on Windows.
- New MXC compute driver crate.
- OpenShell to MXC policy translation.
- Windows named-pipe driver IPC.
- Windows Credential Manager or DPAPI integration.
- MSI, WinGet, Windows service registration, or installer work.
- Windows supervisor runtime port.

## Hard Rules

Expand Down Expand Up @@ -164,6 +195,16 @@ mise run --skip-tools windows:test:x64
mise run --skip-tools windows:test:unsupported:x64
```

The two `windows:test:mxc-real:*` tasks are host-specific and mutually
exclusive on a single host (each rejects the other architecture -- see the
table below): run `windows:test:mxc-real:x64` on an x64 host, or
`windows:test:mxc-real:arm64` on an ARM64 host, as part of validating this
subsystem -- run the one matching your host architecture, not both, and not
neither. Both are skip-safe (they print a SKIP reason and exit 0 when
`wxc-exec` or the matching backend isn't available), so running the
arch-appropriate task is always safe even without real MXC hardware. Neither
is part of `windows:ci`'s ordered contract, so invoke it explicitly.

For full validation, detect the Windows host architecture first and choose the
native lane dynamically:

Expand All @@ -172,12 +213,14 @@ $arch = [System.Runtime.InteropServices.RuntimeInformation]::OSArchitecture
switch ($arch.ToString()) {
"X64" {
mise run --skip-tools windows:ci
mise run --skip-tools windows:test:mxc-real:x64
}
"Arm64" {
mise run --skip-tools windows:check:arm64
mise run --skip-tools windows:build:arm64
mise run --skip-tools windows:test:arm64
mise run --skip-tools windows:test:unsupported:arm64
mise run --skip-tools windows:test:mxc-real:arm64
mise run --skip-tools windows:artifacts
}
default {
Expand Down Expand Up @@ -249,12 +292,14 @@ crypto dependency builds.
|---|---|
| `windows:check:x64` | `cargo check --workspace` for `x86_64-pc-windows-msvc`, excluding unsupported Windows packages as top-level workspace targets. |
| `windows:check:arm64` | `cargo check --workspace` for `aarch64-pc-windows-msvc`, with the same top-level exclusions. |
| `windows:build:x64` | Release-builds `openshell-gateway.exe` and `openshell.exe` for x64. |
| `windows:build:arm64` | Release-builds `openshell-gateway.exe` and `openshell.exe` for ARM64. |
| `windows:build:x64` | Release-builds `openshell-gateway.exe`, `openshell.exe`, `openshell-supervisor.exe`, and `openshell-windows-sandbox.exe` for x64. |
| `windows:build:arm64` | Release-builds the same four binaries for ARM64. |
| `windows:test:x64` | Runs native x64 workspace tests with `--no-fail-fast`, excluding unsupported Windows packages as top-level workspace targets. |
| `windows:test:arm64` | Runs native ARM64 workspace tests with `--no-fail-fast` and the same package exclusions. Rejects non-ARM64 hosts. |
| `windows:test:unsupported:x64` | Re-runs focused `openshell-gateway` tests for unsupported Windows driver behavior. |
| `windows:test:unsupported:arm64` | Re-runs the same focused contracts natively on ARM64. Rejects non-ARM64 hosts. |
| `windows:test:mxc-real:x64` | Runs the serial, ignored real-`wxc-exec` integration suite natively on x64 through the MSVC wrapper. Rejects non-x64 hosts. |
| `windows:test:mxc-real:arm64` | Runs the same real-`wxc-exec` suite natively on ARM64. Rejects non-ARM64 hosts. |
| `windows:artifacts` | Reports size and SHA256 for release artifacts that exist. |
| `windows:ci` | Runs the full ordered x64-host Windows CI lane, plus ARM64 check/build when not skipped. |

Expand Down Expand Up @@ -299,6 +344,22 @@ validation; GitHub Actions does not re-run it after the full suite.

## Test Accounting Guidance

For MXC validation, also run `windows:e2e:mxc`
after the native release build. The harness uses .NET port discovery, disposable
TOML and CLI registration, and owner-only Ed25519 keys generated by OpenSSL on
PATH. Results live under `target/windows-e2e-results`; signing keys stay outside
bundles and are deleted unless `-KeepRunning` is explicitly requested.

E2E has no mock mode and rejects `OPENSHELL_MXC_MOCK_WXC=1`. Unit-test mocks
are not E2E coverage. Every selected scenario must pass for a successful exit;
any skip reports `INCOMPLETE` and exits non-zero. Never bypass audit to make
tests pass. Real runtime scenarios require native ProcessContainer PSEC egress
filtering and ingress host-loopback support. `wxc-exec --probe` is authoritative,
not the Windows build number. All-skipped real runs are not passes. Separate
test-internal `SKIP` messages from Cargo's passed count in the real integration
suite, and report a verified unsupported-host rejection independently from
positive admission coverage.

When reporting `windows:ci`, distinguish these categories:

- Passed tests from the full x64 workspace test log.
Expand All @@ -324,6 +385,8 @@ Useful log files:
| `test-aarch64-pc-windows-msvc.log` | Full native ARM64 workspace test output. |
| `test-x86_64-pc-windows-msvc-unsupported-*.log` | Focused unsupported-driver contract output. |
| `test-aarch64-pc-windows-msvc-unsupported-*.log` | Focused native ARM64 contract output. |
| `test-x86_64-pc-windows-msvc-mxc-real.log` | Native x64 real-MXC integration output. |
| `test-aarch64-pc-windows-msvc-mxc-real.log` | Native ARM64 real-MXC integration output. |

The first check downloads the pinned official Z3 archive for the target
architecture through `z3-sys`. GitHub Actions authenticates the lookup with its
Expand Down
14 changes: 6 additions & 8 deletions .agents/skills/build-openshell-mxc-windows/reference.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# Reference: Windows MSVC maintenance lane

Companion to [SKILL.md](SKILL.md). Use this file for quick lookup while
maintaining the existing build-only Windows MSVC lane.
maintaining the native Windows MSVC and MXC runtime lane.

## Lane Files

Expand Down Expand Up @@ -75,7 +75,7 @@ Ninja to `PATH`, while the crypto crates select `clang-cl`. Use a short

## Unsupported Driver Rules

Windows is a build target only. These runtimes remain unsupported:
These Windows runtimes remain unsupported:

- Docker
- Kubernetes
Expand Down Expand Up @@ -110,16 +110,14 @@ top-level workspace targets for check/test:
--exclude openshell-driver-podman
--exclude openshell-driver-vault
--exclude openshell-driver-vm
--exclude openshell-sandbox
--exclude openshell-vfio
```

The gateway keeps platform configuration and unsupported-operation contracts
without depending on the Docker, Kubernetes, Podman, sandbox runtime,
standalone supervisor, supervisor process runtime, VM, or VFIO crates. The MXC
driver does depend on the cross-platform supervisor network library for its host
egress proxy. The Kubernetes Secrets and Vault libraries still compile as
gateway dependencies; only their standalone Unix-socket binaries and
without depending on the Docker, Kubernetes, Podman, VM, or VFIO runtime crates.
The MXC runtime compiles the supervisor, supervisor-process library, and sandbox
boundary on Windows. The Kubernetes Secrets and Vault libraries still compile
as gateway dependencies; only their standalone Unix-socket binaries and
package-level tests are excluded as top-level targets.

The supervisor and supervisor-process packages now participate as top-level
Expand Down
3 changes: 2 additions & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,7 @@ Do not rely on this file for a full inventory. The detailed public and contribut
| `crates/openshell-conformance-cli/` | Conformance CLI | Legacy local `list` and `run` entrypoint pending follow-up cleanup |
| `crates/openshell-server/` | Gateway server | Control-plane API, sandbox lifecycle, auth boundary |
| `crates/openshell-sandbox/` | Sandbox runtime | Capability-free workload launcher, process identity, and seccomp-mediated I/O |
| `crates/openshell-mxc-boundary/` | Windows sandbox boundary | Windows boundary library and dedicated openshell-windows-sandbox binary for MXC process operations, containment confirmation, and shared-protocol forwarding |
| `crates/openshell-supervisor/` | Supervisor runtime | Gateway session, policy evaluation, credentials, and upstream networking |
| `crates/openshell-binary-identity/` | Binary identity | Shared trusted procfs executable identity resolution for isolation backends |
| `crates/openshell-isolation-interface/` | Isolation backend interface | RFC 0012 `IsolationBackend` trait and types; the supervisor-facing runtime contract |
Expand All @@ -50,7 +51,7 @@ Do not rely on this file for a full inventory. The detailed public and contribut
| `crates/openshell-driver-docker/` | Docker compute driver | In-process `ComputeDriver` backend for local Docker sandbox containers |
| `crates/openshell-driver-podman/` | Podman compute driver | In-process `ComputeDriver` backend for local Podman sandbox containers |
| `crates/openshell-driver-vm/` | VM compute driver | Standalone libkrun-backed `ComputeDriver` subprocess (embeds its own rootfs + runtime) |
| `crates/openshell-driver-mxc/` | Microsoft MXC compute driver | In-process Windows AppContainer and isolation-session compute backend |
| `crates/openshell-driver-mxc/` | Microsoft MXC compute driver | In-process Windows ProcessContainer backend that pairs a host isolation-backend supervisor with `openshell-windows-sandbox` inside MXC |
| `crates/openshell-prover/` | Policy prover | Policy verification and proof generation |
| `crates/openshell-prover-cli/` | Policy prover CLI | Standalone local policy boundary checks |
| `crates/openshell-server-macros/` | Server macros | Compile-time helpers for gateway RPC authorization |
Expand Down
2 changes: 1 addition & 1 deletion CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -105,7 +105,7 @@ Contributor and maintainer skills live in `.agents/skills/`. They are marked int
| Triage | `triage-issue` | Assess, classify, and route community-filed issues |
| Platform | `helm-dev-environment` | Start and manage the local Kubernetes development environment |
| Platform | `tui-development` | Development guide for the ratatui-based terminal UI |
| Platform | `build-openshell-mxc-windows` | Maintain and validate the build-only x64 and ARM64 Windows MSVC lane |
| Platform | `build-openshell-mxc-windows` | Maintain and validate the x64 and ARM64 Windows MSVC and MXC runtime lane |
| Documentation | `update-docs-from-commits` | Scan recent commits and draft doc updates for user-facing changes |
| Maintenance | `sync-agent-infra` | Detect and fix drift across agent-first infrastructure files |
| Reference | `sbom` | Generate SBOMs and resolve dependency licenses |
Expand Down
32 changes: 31 additions & 1 deletion Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,7 @@ miette = { version = "7", features = ["fancy"] }
thiserror = "2"

# Windows platform APIs (ETW/TDH audit consumer in openshell-driver-mxc; Windows-only)
windows = { version = "0.62", features = ["Wdk_System_Threading", "Win32_Foundation", "Win32_System_Diagnostics_Etw", "Win32_System_Time"] }
windows = { version = "0.62", features = ["Wdk_System_Threading", "Win32_Foundation", "Win32_Security", "Win32_System_Diagnostics_Etw", "Win32_System_Threading", "Win32_System_Time"] }
anyhow = "1"

# Logging/Tracing
Expand Down
41 changes: 41 additions & 0 deletions crates/openshell-cli/src/commands/common.rs
Original file line number Diff line number Diff line change
Expand Up @@ -891,6 +891,47 @@ pub fn parse_env_pairs(items: &[String]) -> Result<HashMap<String, String>> {
Ok(map)
}

/// Resolve `--env-from KEY[=ENVVAR]` values from the CLI process environment.
///
/// This keeps environment values out of process arguments while preserving the
/// same sandbox environment validation as `--env KEY=VALUE`.
pub fn parse_env_from_pairs(items: &[String]) -> Result<HashMap<String, String>> {
let mut map = HashMap::new();

for item in items {
let (key, env_name) = match item.split_once('=') {
Some((key, env_name)) => (key.trim(), env_name.trim()),
None => (item.trim(), item.trim()),
};
if !is_valid_env_name(key) {
return Err(miette::miette!(
"--env-from key must match [A-Za-z_][A-Za-z0-9_]*; got '{key}'"
));
}
if key.starts_with("OPENSHELL_") {
return Err(miette::miette!(
"--env-from keys starting with OPENSHELL_ are reserved; got '{key}'"
));
}
if !is_valid_env_name(env_name) {
return Err(miette::miette!(
"--env-from source must match [A-Za-z_][A-Za-z0-9_]*; got '{env_name}'"
));
}
if map.contains_key(key) {
return Err(miette::miette!("duplicate --env-from sandbox key '{key}'"));
}
let value = std::env::var(env_name).map_err(|_| {
miette::miette!(
"--env-from source environment variable '{env_name}' is not set or is not valid Unicode"
)
})?;
map.insert(key.to_string(), value);
}

Ok(map)
}

/// Resolve `--secret-material-env KEY[=ENVVAR]` values from the CLI process
/// environment (`ENVVAR` defaults to `KEY`) so secrets never transit argv.
pub fn parse_secret_material_env_pairs(items: &[String]) -> Result<HashMap<String, String>> {
Expand Down
Loading
Loading