Skip to content

Switch .NET to exact JSON FFI ingress - #1351

Open
Gudge (MGudgin) wants to merge 1 commit into
user/gudge/node-json-ffifrom
user/gudge/dotnet-json-ffi
Open

Gudge (MGudgin) wants to merge 1 commit into
user/gudge/node-json-ffifrom
user/gudge/dotnet-json-ffi

Conversation

@MGudgin

@MGudgin Gudge (MGudgin) commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

This PR moves the .NET SDK's high-level one-shot calls onto the JSON-only
FFI ingress. A new C# emitter generates internal wire types for
the exact 1.0.0 contract, and an exact 1.0.0 writer in
Microsoft.Mxc.Sdk.V1 maps the public V1 types to that contract before
calling mxc_run_json / mxc_spawn_json.

Details

  • Add C# emission to mxc_schema_support and mxc_schema_gen csharp,
    generating internal records under Generated/MxcConfigV1_0_0.g.cs, with
    drift detection in check-contract-codegen and regeneration documented in
    docs/schema-codegen.md.
  • Add ExactOneShotRequestWriter (V1/) that always emits version,
    containerId (minted when unnamed), lifecycle, process.timeout, and
    filesystem, omits absent members, migrates legacy CaptureDenials to
    ProcessContainer containment, rejects undefined enum values, and treats
    InheritDefaultEnvironment without Environment as having no effect.
  • V1.MxcSandbox.Run / Spawn call mxc_run_json / mxc_spawn_json with
    the experimental opt-in off.
  • Stable V1.MxcLifecycle rejects wsb: ids with UnsupportedContainment.
  • check-dotnet-api-parity.js compares the C# surface to the exact
    contract instead of the private binding request.

Tests

  • Rust unit tests for the C# emitter and CLI; cargo fmt, clippy
    (-D warnings), and mxc_schema_support / mxc_schema_gen tests (23).
  • .NET: tests/policy/sdk-v1 conformance for every input and invalid case,
    writer negative tests, and lifecycle wsb: rejection;
    dotnet test --solution Microsoft.Mxc.Sdk.slnx (260 passed, 27
    host-dependent tests skipped). Every commit builds.
  • Contract codegen, bindings codegen, API parity, error-code parity,
    schema-version, version-sync, and config validation checks;
    git diff --check.
Microsoft Reviewers: Open in CodeFlow

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@MGudgin
Gudge (MGudgin) force-pushed the user/gudge/dotnet-json-ffi branch from 0492605 to 53f0bfa Compare September 30, 2026 17:18
@MGudgin
Gudge (MGudgin) force-pushed the user/gudge/dotnet-json-ffi branch 2 times, most recently from eafb96a to 8d1b835 Compare September 30, 2026 17:32
@MGudgin
Gudge (MGudgin) force-pushed the user/gudge/dotnet-json-ffi branch from 8d1b835 to 83eb313 Compare September 30, 2026 20:29
@MGudgin
Gudge (MGudgin) changed the base branch from user/gudge/rust_ffi_json_ingress to user/gudge/node-json-ffi September 30, 2026 20:29
@MGudgin
Gudge (MGudgin) force-pushed the user/gudge/dotnet-json-ffi branch from 83eb313 to eaffaf6 Compare September 30, 2026 20:31
@MGudgin
Gudge (MGudgin) added this pull request to stack #1356 September 30, 2026 21:26
@MGudgin
Gudge (MGudgin) marked this pull request as ready for review September 30, 2026 21:27
@MGudgin
Gudge (MGudgin) requested review from a team and a balanced review from Copilot September 30, 2026 21:27
@MGudgin
Gudge (MGudgin) requested a review from a team as a code owner September 30, 2026 21:27
@MGudgin
Gudge (MGudgin) force-pushed the user/gudge/dotnet-json-ffi branch from eaffaf6 to 9fe4ac0 Compare September 30, 2026 21:30

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Exact-wire numeric and environment mappings are incorrect, and two public API paths provide misleading experimental behavior.

Review effort: Balanced
Findings: 1 High severity · 2 Medium severity · 1 Low severity

Open (4)
What changed in this PR

Moves the .NET V1 SDK to exact 1.0.0 JSON FFI ingress.

Changes:

  • Adds generated C# wire types and drift validation.
  • Maps public .NET policies to exact JSON requests.
  • Routes one-shot APIs through JSON FFI and expands conformance tests.
File Description
src/​tools/​mxc_schema_gen/​tests/​cli.rs Tests C# generation.
src/​tools/​mxc_schema_gen/​src/​main.rs Adds the csharp command.
src/​core/​mxc_schema_support/​src/​lib.rs Exposes C# emission.
src/​core/​mxc_schema_support/​src/​cs_emit.rs Implements the C# emitter.
src/​core/​mxc_config_contract/​src/​registry.rs Registers C# artifact paths.
sdk/​dotnet/​Microsoft.Mxc.Sdk/​V1/​MxcSandbox.cs Uses JSON FFI entry points.
sdk/​dotnet/​Microsoft.Mxc.Sdk/​V1/​MxcLifecycle.cs Rejects stable wsb: lifecycle IDs.
sdk/​dotnet/​Microsoft.Mxc.Sdk/​V1/​ExactOneShotRequestWriter.cs Maps V1 requests to exact wire types.
sdk/​dotnet/​Microsoft.Mxc.Sdk/​Generated/​MxcConfigV1_0_0.g.cs Adds generated 1.0.0 models.
sdk/​dotnet/​Microsoft.Mxc.Sdk.Tests/​V1/​SandboxPolicyTests.cs Updates exact-contract assertions.
sdk/​dotnet/​Microsoft.Mxc.Sdk.Tests/​V1/​MxcSandboxTests.cs Updates one-shot serialization tests.
sdk/​dotnet/​Microsoft.Mxc.Sdk.Tests/​V1/​MxcLifecycleTests.cs Tests wsb: rejection.
sdk/​dotnet/​Microsoft.Mxc.Sdk.Tests/​V1/​ExactOneShotRequestWriterTests.cs Adds writer conformance tests.
sdk/​dotnet/​Microsoft.Mxc.Sdk.Tests/​Microsoft.Mxc.Sdk.Tests.csproj Embeds SDK-v1 fixtures.
sdk/​dotnet/​Microsoft.Mxc.Sdk.Tests/​JsonAssert.cs Generalizes JSON comparison.
scripts/​versioning/​check-contract-codegen.js Adds C# drift checks.
scripts/​check-dotnet-bindings-codegen.js Marks JSON exports as consumed.
scripts/​check-dotnet-api-parity.js Checks against the exact contract.
docs/​schema-codegen.md Documents C# generation.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +353 to +355
fn integer_type(object: &serde_json::Map<String, Value>) -> String {
let minimum = object.get("minimum").and_then(Value::as_i64);
let maximum = object.get("maximum").and_then(Value::as_u64);
Comment on lines +90 to +95
Env = request.Environment is null
? null
: request.Environment
.OrderBy(pair => pair.Key, StringComparer.Ordinal)
.Select(pair => $"{pair.Key}={pair.Value}")
.ToList(),
public static class MxcSandbox
{
private const string LegacyCaptureDenialsName = "CaptureDenials";
private const int NoExperimentalOptIn = 0;
Comment on lines +564 to +568
"wsb" => throw new MxcException(
ErrorCode.UnsupportedContainment,
"Windows Sandbox sandbox ids with the 'wsb:' prefix require "
+ "the experimental .NET lifecycle API; stable MxcLifecycle "
+ "accepts only 'iso:' and 'wslc:' ids."),
Copilot AI balanced review requested due to automatic review settings September 30, 2026 21:33
This PR moves the .NET SDK's high-level one-shot calls onto the JSON-only
FFI ingress. A new C# emitter generates internal wire types for the exact
1.0.0 contract, and an exact 1.0.0 writer in Microsoft.Mxc.Sdk.V1 maps the
public V1 types to that contract before calling mxc_run_json and
mxc_spawn_json.

Details

* Add C# emission to mxc_schema_support and mxc_schema_gen csharp,
  generating internal records in Generated/MxcConfigV1_0_0.g.cs, with drift
  detection in check-contract-codegen and regeneration documented in
  docs/schema-codegen.md.
* Add ExactOneShotRequestWriter (V1/) that always emits version,
  containerId (minted when unnamed), lifecycle, process.timeout, and
  filesystem, omits absent members, migrates legacy CaptureDenials to
  ProcessContainer containment, rejects undefined enum values, and treats
  InheritDefaultEnvironment without Environment as having no effect.
* V1.MxcSandbox.Run and Spawn call mxc_run_json and mxc_spawn_json with the
  experimental opt-in off.
* Stable V1.MxcLifecycle rejects wsb: ids with UnsupportedContainment.
* check-dotnet-api-parity.js compares the C# surface to the exact contract
  instead of the private binding request.

Tests

* Rust unit tests for the C# emitter and CLI; cargo fmt, clippy
  (-D warnings), and mxc_schema_support / mxc_schema_gen tests.
* .NET: tests/policy/sdk-v1 conformance for every input and invalid case,
  writer negative tests, and lifecycle wsb: rejection;
  dotnet test --solution Microsoft.Mxc.Sdk.slnx (260 passed, 27
  host-dependent tests skipped).
* Contract codegen, bindings codegen, API parity, error-code parity,
  schema-version, version-sync, and config validation checks;
  git diff --check.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 33217f7b-dc7d-4da0-af5f-018fef64013c
Generated-with: gpt-5.5
Generated-with: claude-opus-5.5
@MGudgin
Gudge (MGudgin) force-pushed the user/gudge/dotnet-json-ffi branch from 9fe4ac0 to 885b720 Compare September 30, 2026 21:40

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The generated wire model narrows valid u64 values, while request mapping also changes supplied IDs and environment ordering.

Review effort: Balanced
Findings: 1 High severity · 3 Medium severity · 1 Low severity

Open (5)

Comment on lines +32 to +34
ContainerId = string.IsNullOrWhiteSpace(normalized.ContainerName)
? MintContainerId()
: normalized.ContainerName,
Copilot AI balanced review requested due to automatic review settings September 30, 2026 21:40

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Valid ulong memory values regress, environment validation is weakened, and the public experimental opt-in becomes silently ineffective.

Review effort: Balanced
Findings: 2 High severity · 3 Medium severity · 1 Low severity

Open (6)

Comment on lines +90 to +95
Env = request.Environment is null
? null
: request.Environment
.OrderBy(pair => pair.Key, StringComparer.Ordinal)
.Select(pair => $"{pair.Key}={pair.Value}")
.ToList(),

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants