You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[mxc] - Integrate MXC-enforced process execution with trust profiles #1471
Note: This bug has been split into implementation sub-items. Each child contains its complete approved design.
Integrate Microsoft's preview MXC C# SDK into the Windows build and enforce effective trust-profile filesystem/network restrictions for stdio MCP servers and the GitHub Copilot CLI. Replace the undeployed Docker-shaped trust schema directly, compile effective profiles into a portable host-local MXC process policy, and launch through one streaming executor. Constrained launches fail closed; unconstrained launches use the executor's ordinary-process branch or the SDK's direct Copilot runtime as specified below. MXC preview profiles must not be represented as production security boundaries.
Root Cause
Trust/TrustProfile.cs, TrustProfileEntityReader.cs, TrustProfileComposer.cs, and llm-trust-profile.json model Docker mount types and an ordinal network topology rather than MXC host-path grants and AppContainer capabilities.
AgentFactory.cs:1178-1195 resolves trust profiles only for an application-level local-execution check; process restrictions do not reach launch sites.
McpTransportFactory.cs:494-552 delegates stdio process creation to sealed StdioClientTransport, which has no executor hook.
CopilotSdkChatClient.cs:527-546,1298-1325 delegates CLI creation to GitHub.Copilot.SDK 1.0.11, whose ForStdio(path,args) API has no process-launch callback.
Publishing currently targets win-x64 and win-arm64, while the initial source-built MXC integration is host-native win-x64.
Chosen Design
Schema
#1472 directly removes TrustNetworkAccessPolicy, TrustMountType, old mount-points, network-access-policy, and their parser branches. No compatibility or migration is required because no trust profiles are deployed. New filesystem-paths entries contain source, optional target (defaults to source), and read-only/read-write access. Optional network-capabilities preserves absent, present-empty, and populated states. Restrictive composition intersects capabilities; permissive composition unions them, with absence meaning unconstrained.
MXC build, compiler, and executor
#1473 pins and source-builds Microsoft.Mxc.Sdk and its native payload for win-x64; release publishing drops win-arm64 until it can build natively. #1475 compiles an effective profile on the launch host into a versioned serializable MxcProcessPolicy; it rejects target remapping and unsupported capabilities. #1474 owns both ordinary and MXC pipe-mode process launch, live stdin/stdout/stderr, quoting, wait/kill/dispose, diagnostics, and tree cleanup. MXC failure never falls back unsandboxed. DACL mutation is allowed and its warnings/restoration failures are surfaced.
Copilot CLI
#1476 adds a separate phantom-copilot-wrapper.exe. For constrained execution Phantom creates a secured one-use local policy file and calls:
The wrapper validates/deletes the envelope, invokes the real unmodified CLI through #1474, relays raw stdin/stdout/stderr concurrently, and returns its exit code. Policy JSON is not placed on the command line. For remote model execution the remote host resolves/compiles and creates its own local handoff; files and compiled policy never cross the network. Unconstrained Copilot sessions retain direct SDK launch.
stdio MCP
#1477 always uses ProcessExecutorBackedClientTransport for stdio. It launches through #1474, then adapts executor stdin/stdout with ModelContextProtocol's public StreamClientTransport, so Phantom does not reimplement JSON-RPC framing. Null policy selects ordinary execution; a compiled policy selects MXC. Stderr is drained separately and process ownership is tied to ITransport.DisposeAsync. Remote MCP carries only a trust-profile reference/revision and compiles on the launch host. Constrained HTTP/SSE is rejected because Phantom does not own a server process to contain.
Application-level client-instance and MCP tool-schema authorization remain separate and cumulative.
Implementation Sub-Items
Complete in these dependency waves (same-wave items may proceed in parallel):
changed the title [-]Integrate MXC-enforced process execution with trust profiles[/-][+][mxc] - Integrate MXC-enforced process execution with trust profiles[/+]on Sep 7, 2026
All implementation sub-items #1472 through #1477 are closed and integrated on eatures.
Current features tip: $sha
The completed arc includes the MXC-aligned trust schema, native SDK packaging, policy-aware process execution, host-local policy compilation, the contained Copilot wrapper, and single-owner stdio MCP execution. Release-gate regressions found during integration were corrected and verified through fast/full and stability runs.
Summary
Integrate Microsoft's preview MXC C# SDK into the Windows build and enforce effective trust-profile filesystem/network restrictions for stdio MCP servers and the GitHub Copilot CLI. Replace the undeployed Docker-shaped trust schema directly, compile effective profiles into a portable host-local MXC process policy, and launch through one streaming executor. Constrained launches fail closed; unconstrained launches use the executor's ordinary-process branch or the SDK's direct Copilot runtime as specified below. MXC preview profiles must not be represented as production security boundaries.
Root Cause
Trust/TrustProfile.cs,TrustProfileEntityReader.cs,TrustProfileComposer.cs, andllm-trust-profile.jsonmodel Docker mount types and an ordinal network topology rather than MXC host-path grants and AppContainer capabilities.AgentFactory.cs:1178-1195resolves trust profiles only for an application-level local-execution check; process restrictions do not reach launch sites.McpTransportFactory.cs:494-552delegates stdio process creation to sealedStdioClientTransport, which has no executor hook.CopilotSdkChatClient.cs:527-546,1298-1325delegates CLI creation to GitHub.Copilot.SDK 1.0.11, whoseForStdio(path,args)API has no process-launch callback.Chosen Design
Schema
#1472 directly removes
TrustNetworkAccessPolicy,TrustMountType, oldmount-points,network-access-policy, and their parser branches. No compatibility or migration is required because no trust profiles are deployed. Newfilesystem-pathsentries contain source, optional target (defaults to source), and read-only/read-write access. Optionalnetwork-capabilitiespreserves absent, present-empty, and populated states. Restrictive composition intersects capabilities; permissive composition unions them, with absence meaning unconstrained.MXC build, compiler, and executor
#1473 pins and source-builds Microsoft.Mxc.Sdk and its native payload for win-x64; release publishing drops win-arm64 until it can build natively. #1475 compiles an effective profile on the launch host into a versioned serializable
MxcProcessPolicy; it rejects target remapping and unsupported capabilities. #1474 owns both ordinary and MXC pipe-mode process launch, live stdin/stdout/stderr, quoting, wait/kill/dispose, diagnostics, and tree cleanup. MXC failure never falls back unsandboxed. DACL mutation is allowed and its warnings/restoration failures are surfaced.Copilot CLI
#1476 adds a separate
phantom-copilot-wrapper.exe. For constrained execution Phantom creates a secured one-use local policy file and calls:The wrapper validates/deletes the envelope, invokes the real unmodified CLI through #1474, relays raw stdin/stdout/stderr concurrently, and returns its exit code. Policy JSON is not placed on the command line. For remote model execution the remote host resolves/compiles and creates its own local handoff; files and compiled policy never cross the network. Unconstrained Copilot sessions retain direct SDK launch.
stdio MCP
#1477 always uses
ProcessExecutorBackedClientTransportfor stdio. It launches through #1474, then adapts executor stdin/stdout with ModelContextProtocol's publicStreamClientTransport, so Phantom does not reimplement JSON-RPC framing. Null policy selects ordinary execution; a compiled policy selects MXC. Stderr is drained separately and process ownership is tied toITransport.DisposeAsync. Remote MCP carries only a trust-profile reference/revision and compiles on the launch host. Constrained HTTP/SSE is rejected because Phantom does not own a server process to contain.Application-level client-instance and MCP tool-schema authorization remain separate and cumulative.
Implementation Sub-Items
Complete in these dependency waves (same-wave items may proceed in parallel):
#1476 and #1477 may proceed in parallel after their dependencies.
Affected Areas
ForStdiowrapper arguments, secure handoff, byte relay.Expected Tests
Each child owns its detailed unit/integration test table. End-to-end acceptance additionally requires:
TrustedProcess_FilesystemPolicy_DeniesUnlistedPathTrustedProcessIntegrationTestsTrustedProcess_EmptyNetworkCapabilities_DeniesNetworkTrustedProcessIntegrationTestsMcpStdio_ConstrainedTrustProfile_LaunchesThroughMxcMcpStdioIntegrationTestsCopilotCli_ConstrainedTrustProfile_LaunchesThroughMxcWrapperCopilotCliIntegrationTestsRemoteExecution_TrustReference_CompilesPolicyOnLaunchHostRemoteExecutionTrustTestsReleaseArtifacts_CurrentMatrix_ContainsOnlyWinX64ReleasePackagingTests