Reject a blank ProcessContainer proxy peer - #1348
Open
Gudge (MGudgin) wants to merge 1 commit into
Open
Gudge (MGudgin) wants to merge 1 commit into
Gudge (MGudgin) wants to merge 1 commit into
Conversation
Gudge (MGudgin)
requested review from
a team
and
a balanced review from Copilot
September 30, 2026 16:13
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
Validation, contract coverage, and documentation consistently implement the intended behavior.
Review effort: Balanced
Findings: None
What changed in this PR
Rejects blank ProcessContainer proxy identities during shared network-policy parsing.
Changes:
- Validates empty and whitespace-only
allowedProxyPeervalues. - Adds cross-contract parser coverage and preserves valid values verbatim.
- Documents the non-empty requirement.
| File | Description |
|---|---|
src/core/wxc_common/src/network_parser.rs |
Adds blank-peer validation. |
src/core/wxc_common/src/config_parser.rs |
Adds multi-version parser tests. |
docs/schema.md |
Clarifies proxy identity requirements. |
docs/sandbox-policy/0.8.0/networking/networking.md |
Updates networking guidance. |
docs/process-container/networking.md |
Documents non-empty peer behavior. |
docs/process-container/examples/0.8.0-schema.md |
Updates schema example guidance. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Gudge (MGudgin)
force-pushed
the
user/gudge/reject-blank-proxy-peer
branch
from
September 30, 2026 16:35
64e294c to
422f64d
Compare
Gudge (MGudgin)
pushed a commit
that referenced
this pull request
Sep 30, 2026
This PR adds a handoff for the v1 SDK and JSON-only FFI ingress stack and updates the ingress plan to match what was built. It records the pull requests, branches, worktrees, and backups, the design decisions and their reasons, review status, open items, and working notes for a new session. Details * Add docs/version-aware-stack-session-handoff-2026-09-30.md covering #1271, #1348, and #1349-#1353, the backend-based experimental opt-in, JSON-only ingress, V1 namespaces and MxcPlatform, the pinned SDK target, Node export conditions, shared goldens, and E0. * Mark the plan adopted, replace the planned branch table with the opened pull requests, record the unified experimental check, the serde removal, the V1 writer location, and E0, and add the namespace, goldens, and E0 decisions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 33217f7b-dc7d-4da0-af5f-018fef64013c Generated-with: claude-opus-5.5
This PR makes the config parser reject an empty or whitespace-only processContainer.network.allowedProxyPeer. The parser treated a blank peer as absent when detecting network fields but as present in the proxy checks, so a blank peer could pass validation and reach BaseContainer as the proxy identity. Both paths now agree, and a blank peer fails early. Details * network_parser.rs rejects a blank peer with "processContainer.network. allowedProxyPeer must not be blank" before the proxy and host-loopback checks, for every contract with the field. * Any present allowedProxyPeer now counts as a ProcessContainer network field, so pre-0.8 contracts still reject it as unsupported. * Non-blank peers are preserved exactly as authored. * Parser tests use registered 0.8+ contracts to survive version promotion. * The schema and ProcessContainer networking docs state that the peer must be non-blank. Tests * New parser tests cover empty and whitespace-only peers on every registered contract from 0.8 onward, non-blank preservation, and pre-0.8 rejection. * cargo fmt --all -- --check; cargo clippy --workspace --all-targets --all-features -- -D warnings; cargo test for wxc_common, mxc_engine, and wxc. * A simulated CI merge passed all 949 wxc_common library tests; wxc-exec --dry-run with a blank peer rejects it with the new message. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 33217f7b-dc7d-4da0-af5f-018fef64013c Generated-with: gpt-5.5 Copilot-Session: 0b73bdac-b73e-4e23-9d96-b6acd031ebf9 Generated-with: gpt-6-sol
Gudge (MGudgin)
force-pushed
the
user/gudge/reject-blank-proxy-peer
branch
from
September 30, 2026 18:54
422f64d to
76eb8cc
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

📖 Description
Reject a blank ProcessContainer proxy peer
This PR makes the config parser reject an empty or whitespace-only
processContainer.network.allowedProxyPeer. The parser previously treated a
blank peer as absent when detecting network fields but as present during
proxy validation, allowing it to reach BaseContainer as a proxy identity.
Both paths now agree and reject blank peers early.
Details
diagnostic "processContainer.network.allowedProxyPeer must not be blank".
including for pre-0.8 contracts where the field is unsupported.
registered contract from 0.8 onward without hardcoded future versions.
ProcessContainer networking documentation.
🔗 References
🔍 Validation
Tests (from
src/on Windows, against the amended commit)cargo fmt --all -- --check— passed.cargo check --workspace --all-targets --quiet— passed.cargo clippy --workspace --all-targets --all-features --quiet -- -D warnings— passed.cargo test -p wxc_common --quiet— passed (918 library tests and 83 othercrate tests); covers blank and non-blank peers across registered contracts.
✅ Checklist
Cargo.lock, thedependency-feed-checkcheck passes (see docs/pull-requests.md)📋 Issue Type
GitHub Actions runs the PR validation build automatically. The ADO pipeline
(
MXC-PR-Build) is the Azure version of the PR pipeline, kept in parity with the GitHubActions build; it runs on merge to
main, and Microsoft reviewers with write access can trigger iton a PR with
/azp run. See docs/pull-requests.md.If the
dependency-feed-checkcheck fails on a new dependency, the crate must be added tothe feed before the PR can pass. See docs/pull-requests.md
for the steps.
Microsoft Reviewers: Open in CodeFlow