Skip to content

[mxc] - Integrate MXC-enforced process execution with trust profiles #1471

Description

@JoshuaRowePhantom

Summary

Note: This bug has been split into implementation sub-items. Each child contains its complete approved design.

Integrate Microsoft's preview MXC C# SDK into the Windows build and enforce effective trust-profile filesystem/network restrictions for stdio MCP servers and the GitHub Copilot CLI. Replace the undeployed Docker-shaped trust schema directly, compile effective profiles into a portable host-local MXC process policy, and launch through one streaming executor. Constrained launches fail closed; unconstrained launches use the executor's ordinary-process branch or the SDK's direct Copilot runtime as specified below. MXC preview profiles must not be represented as production security boundaries.

Root Cause

  • Trust/TrustProfile.cs, TrustProfileEntityReader.cs, TrustProfileComposer.cs, and llm-trust-profile.json model Docker mount types and an ordinal network topology rather than MXC host-path grants and AppContainer capabilities.
  • AgentFactory.cs:1178-1195 resolves trust profiles only for an application-level local-execution check; process restrictions do not reach launch sites.
  • McpTransportFactory.cs:494-552 delegates stdio process creation to sealed StdioClientTransport, which has no executor hook.
  • CopilotSdkChatClient.cs:527-546,1298-1325 delegates CLI creation to GitHub.Copilot.SDK 1.0.11, whose ForStdio(path,args) API has no process-launch callback.
  • Publishing currently targets win-x64 and win-arm64, while the initial source-built MXC integration is host-native win-x64.

Chosen Design

Schema

#1472 directly removes TrustNetworkAccessPolicy, TrustMountType, old mount-points, network-access-policy, and their parser branches. No compatibility or migration is required because no trust profiles are deployed. New filesystem-paths entries contain source, optional target (defaults to source), and read-only/read-write access. Optional network-capabilities preserves absent, present-empty, and populated states. Restrictive composition intersects capabilities; permissive composition unions them, with absence meaning unconstrained.

MXC build, compiler, and executor

#1473 pins and source-builds Microsoft.Mxc.Sdk and its native payload for win-x64; release publishing drops win-arm64 until it can build natively. #1475 compiles an effective profile on the launch host into a versioned serializable MxcProcessPolicy; it rejects target remapping and unsupported capabilities. #1474 owns both ordinary and MXC pipe-mode process launch, live stdin/stdout/stderr, quoting, wait/kill/dispose, diagnostics, and tree cleanup. MXC failure never falls back unsandboxed. DACL mutation is allowed and its warnings/restoration failures are surfaced.

Copilot CLI

#1476 adds a separate phantom-copilot-wrapper.exe. For constrained execution Phantom creates a secured one-use local policy file and calls:

RuntimeConnection.ForStdio(
    wrapperPath,
    ["--policy", policyFilePath, "--copilot", realCliPath]);

The wrapper validates/deletes the envelope, invokes the real unmodified CLI through #1474, relays raw stdin/stdout/stderr concurrently, and returns its exit code. Policy JSON is not placed on the command line. For remote model execution the remote host resolves/compiles and creates its own local handoff; files and compiled policy never cross the network. Unconstrained Copilot sessions retain direct SDK launch.

stdio MCP

#1477 always uses ProcessExecutorBackedClientTransport for stdio. It launches through #1474, then adapts executor stdin/stdout with ModelContextProtocol's public StreamClientTransport, so Phantom does not reimplement JSON-RPC framing. Null policy selects ordinary execution; a compiled policy selects MXC. Stderr is drained separately and process ownership is tied to ITransport.DisposeAsync. Remote MCP carries only a trust-profile reference/revision and compiles on the launch host. Constrained HTTP/SSE is rejected because Phantom does not own a server process to contain.

Application-level client-instance and MCP tool-schema authorization remain separate and cumulative.

Implementation Sub-Items

Complete in these dependency waves (same-wave items may proceed in parallel):

  1. [mxc] - Align trust-profile filesystem and network schema with MXC #1472 — Align trust-profile filesystem and network schema with MXC (no dependencies)
  2. [mxc] - Add Microsoft.Mxc.Sdk and native build support #1473 — Build and package the MXC C# SDK for win-x64 (no dependencies)
  3. [mxc] - Streaming process executor backed by MXC #1474 — Add a policy-aware streaming process executor (depends on [mxc] - Add Microsoft.Mxc.Sdk and native build support #1473)
  4. [mxc] - Compile effective trust profiles into MXC sandbox policies #1475 — Compile effective trust profiles into MXC sandbox policies (depends on [mxc] - Align trust-profile filesystem and network schema with MXC #1472, [mxc] - Add Microsoft.Mxc.Sdk and native build support #1473)
  5. [mxc] - Launch copilot.exe through the MXC process executor #1476 — Launch copilot.exe through the MXC process executor (depends on [mxc] - Align trust-profile filesystem and network schema with MXC #1472, [mxc] - Streaming process executor backed by MXC #1474, [mxc] - Compile effective trust profiles into MXC sandbox policies #1475)
  6. [mxc] - Execute MCP tools through MXC-constrained process executor #1477 — Enforce trust-profile MXC policy for stdio MCP servers (depends on [mxc] - Align trust-profile filesystem and network schema with MXC #1472, [mxc] - Streaming process executor backed by MXC #1474, [mxc] - Compile effective trust profiles into MXC sandbox policies #1475)

#1476 and #1477 may proceed in parallel after their dependencies.

Affected Areas

Area Responsibility
Trust profile model/schema/composer/defaults Direct MXC-aligned schema replacement.
MXC source/build/publish pipeline Pinned SDK/native build and win-x64 payload.
Trust policy compiler Host-local validation and portable process-policy generation.
Shared process executor Ordinary/MXC launch, streams, lifecycle, diagnostics.
Copilot wrapper and SDK connection selection ForStdio wrapper arguments, secure handoff, byte relay.
MCP transport and remote host Executor-backed stdio streams and host-local compilation.

Expected Tests

Each child owns its detailed unit/integration test table. End-to-end acceptance additionally requires:

Test Name Class What It Verifies
TrustedProcess_FilesystemPolicy_DeniesUnlistedPath TrustedProcessIntegrationTests A contained child cannot access an ungranted path.
TrustedProcess_EmptyNetworkCapabilities_DeniesNetwork TrustedProcessIntegrationTests Present-empty networking launches contained without network grants.
McpStdio_ConstrainedTrustProfile_LaunchesThroughMxc McpStdioIntegrationTests MCP JSON-RPC works through the executor-backed MXC process.
CopilotCli_ConstrainedTrustProfile_LaunchesThroughMxcWrapper CopilotCliIntegrationTests SDK → wrapper → executor → real CLI works with transparent stdio.
RemoteExecution_TrustReference_CompilesPolicyOnLaunchHost RemoteExecutionTrustTests Remote boundaries never trust caller-compiled policy.
ReleaseArtifacts_CurrentMatrix_ContainsOnlyWinX64 ReleasePackagingTests Release output does not advertise unsupported ARM64 containment.

Activity

  1. changed the title [-]Integrate MXC-enforced process execution with trust profiles[/-] [+][mxc] - Integrate MXC-enforced process execution with trust profiles[/+] on Sep 7, 2026
  2. JoshuaRowePhantom commented on Sep 14, 2026

    @JoshuaRowePhantom
    OwnerAuthor

    Completed

    All implementation sub-items #1472 through #1477 are closed and integrated on eatures.

    Current features tip: $sha

    The completed arc includes the MXC-aligned trust schema, native SDK packaging, policy-aware process execution, host-local policy compilation, the contained Copilot wrapper, and single-owner stdio MCP execution. Release-gate regressions found during integration were corrected and verified through fast/full and stability runs.

  3. removed
    queuedIn the active work queue (tracked in work-queue.md)
    on Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingdiagnosedRoot cause identified

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions