Switch .NET to exact JSON FFI ingress - #1351
Open
Gudge (MGudgin) wants to merge 1 commit into
Open
Gudge (MGudgin) wants to merge 1 commit into
Gudge (MGudgin) wants to merge 1 commit into
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Gudge (MGudgin)
force-pushed
the
user/gudge/dotnet-json-ffi
branch
from
September 30, 2026 17:18
0492605 to
53f0bfa
Compare
Gudge (MGudgin)
force-pushed
the
user/gudge/dotnet-json-ffi
branch
2 times, most recently
from
September 30, 2026 17:32
eafb96a to
8d1b835
Compare
Gudge (MGudgin)
force-pushed
the
user/gudge/dotnet-json-ffi
branch
from
September 30, 2026 20:29
8d1b835 to
83eb313
Compare
Gudge (MGudgin)
changed the base branch from
user/gudge/rust_ffi_json_ingress
to
user/gudge/node-json-ffi
September 30, 2026 20:29
Gudge (MGudgin)
force-pushed
the
user/gudge/dotnet-json-ffi
branch
from
September 30, 2026 20:31
83eb313 to
eaffaf6
Compare
Gudge (MGudgin)
added this pull request to stack #1356
September 30, 2026 21:26
Gudge (MGudgin)
marked this pull request as ready for review
September 30, 2026 21:27
Gudge (MGudgin)
requested review from
a team
and
a balanced review from Copilot
September 30, 2026 21:27
Gudge (MGudgin)
force-pushed
the
user/gudge/dotnet-json-ffi
branch
from
September 30, 2026 21:30
eaffaf6 to
9fe4ac0
Compare
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Exact-wire numeric and environment mappings are incorrect, and two public API paths provide misleading experimental behavior.
Review effort: Balanced
Findings: 1
Open (4)
What changed in this PR
Moves the .NET V1 SDK to exact 1.0.0 JSON FFI ingress.
Changes:
- Adds generated C# wire types and drift validation.
- Maps public .NET policies to exact JSON requests.
- Routes one-shot APIs through JSON FFI and expands conformance tests.
| File | Description |
|---|---|
src/tools/mxc_schema_gen/tests/cli.rs |
Tests C# generation. |
src/tools/mxc_schema_gen/src/main.rs |
Adds the csharp command. |
src/core/mxc_schema_support/src/lib.rs |
Exposes C# emission. |
src/core/mxc_schema_support/src/cs_emit.rs |
Implements the C# emitter. |
src/core/mxc_config_contract/src/registry.rs |
Registers C# artifact paths. |
sdk/dotnet/Microsoft.Mxc.Sdk/V1/MxcSandbox.cs |
Uses JSON FFI entry points. |
sdk/dotnet/Microsoft.Mxc.Sdk/V1/MxcLifecycle.cs |
Rejects stable wsb: lifecycle IDs. |
sdk/dotnet/Microsoft.Mxc.Sdk/V1/ExactOneShotRequestWriter.cs |
Maps V1 requests to exact wire types. |
sdk/dotnet/Microsoft.Mxc.Sdk/Generated/MxcConfigV1_0_0.g.cs |
Adds generated 1.0.0 models. |
sdk/dotnet/Microsoft.Mxc.Sdk.Tests/V1/SandboxPolicyTests.cs |
Updates exact-contract assertions. |
sdk/dotnet/Microsoft.Mxc.Sdk.Tests/V1/MxcSandboxTests.cs |
Updates one-shot serialization tests. |
sdk/dotnet/Microsoft.Mxc.Sdk.Tests/V1/MxcLifecycleTests.cs |
Tests wsb: rejection. |
sdk/dotnet/Microsoft.Mxc.Sdk.Tests/V1/ExactOneShotRequestWriterTests.cs |
Adds writer conformance tests. |
sdk/dotnet/Microsoft.Mxc.Sdk.Tests/Microsoft.Mxc.Sdk.Tests.csproj |
Embeds SDK-v1 fixtures. |
sdk/dotnet/Microsoft.Mxc.Sdk.Tests/JsonAssert.cs |
Generalizes JSON comparison. |
scripts/versioning/check-contract-codegen.js |
Adds C# drift checks. |
scripts/check-dotnet-bindings-codegen.js |
Marks JSON exports as consumed. |
scripts/check-dotnet-api-parity.js |
Checks against the exact contract. |
docs/schema-codegen.md |
Documents C# generation. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+353
to
+355
| fn integer_type(object: &serde_json::Map<String, Value>) -> String { | ||
| let minimum = object.get("minimum").and_then(Value::as_i64); | ||
| let maximum = object.get("maximum").and_then(Value::as_u64); |
Comment on lines
+90
to
+95
| Env = request.Environment is null | ||
| ? null | ||
| : request.Environment | ||
| .OrderBy(pair => pair.Key, StringComparer.Ordinal) | ||
| .Select(pair => $"{pair.Key}={pair.Value}") | ||
| .ToList(), |
| public static class MxcSandbox | ||
| { | ||
| private const string LegacyCaptureDenialsName = "CaptureDenials"; | ||
| private const int NoExperimentalOptIn = 0; |
Comment on lines
+564
to
+568
| "wsb" => throw new MxcException( | ||
| ErrorCode.UnsupportedContainment, | ||
| "Windows Sandbox sandbox ids with the 'wsb:' prefix require " | ||
| + "the experimental .NET lifecycle API; stable MxcLifecycle " | ||
| + "accepts only 'iso:' and 'wslc:' ids."), |
This PR moves the .NET SDK's high-level one-shot calls onto the JSON-only FFI ingress. A new C# emitter generates internal wire types for the exact 1.0.0 contract, and an exact 1.0.0 writer in Microsoft.Mxc.Sdk.V1 maps the public V1 types to that contract before calling mxc_run_json and mxc_spawn_json. Details * Add C# emission to mxc_schema_support and mxc_schema_gen csharp, generating internal records in Generated/MxcConfigV1_0_0.g.cs, with drift detection in check-contract-codegen and regeneration documented in docs/schema-codegen.md. * Add ExactOneShotRequestWriter (V1/) that always emits version, containerId (minted when unnamed), lifecycle, process.timeout, and filesystem, omits absent members, migrates legacy CaptureDenials to ProcessContainer containment, rejects undefined enum values, and treats InheritDefaultEnvironment without Environment as having no effect. * V1.MxcSandbox.Run and Spawn call mxc_run_json and mxc_spawn_json with the experimental opt-in off. * Stable V1.MxcLifecycle rejects wsb: ids with UnsupportedContainment. * check-dotnet-api-parity.js compares the C# surface to the exact contract instead of the private binding request. Tests * Rust unit tests for the C# emitter and CLI; cargo fmt, clippy (-D warnings), and mxc_schema_support / mxc_schema_gen tests. * .NET: tests/policy/sdk-v1 conformance for every input and invalid case, writer negative tests, and lifecycle wsb: rejection; dotnet test --solution Microsoft.Mxc.Sdk.slnx (260 passed, 27 host-dependent tests skipped). * Contract codegen, bindings codegen, API parity, error-code parity, schema-version, version-sync, and config validation checks; git diff --check. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 33217f7b-dc7d-4da0-af5f-018fef64013c Generated-with: gpt-5.5 Generated-with: claude-opus-5.5
Gudge (MGudgin)
force-pushed
the
user/gudge/dotnet-json-ffi
branch
from
September 30, 2026 21:40
9fe4ac0 to
885b720
Compare
Comment on lines
+32
to
+34
| ContainerId = string.IsNullOrWhiteSpace(normalized.ContainerName) | ||
| ? MintContainerId() | ||
| : normalized.ContainerName, |
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Valid ulong memory values regress, environment validation is weakened, and the public experimental opt-in becomes silently ineffective.
Review effort: Balanced
Findings: 2
Open (6)
Projection drops key validation and changes caller entry order · New Parse unsigned schema minima without lossy Int64 conversion Empty container names are incorrectly replaced with generated IDs Reject or deprecate silently ignored Experimental requests Preserve caller order for environment variables Document the actual supported Windows Sandbox request path
Comment on lines
+90
to
+95
| Env = request.Environment is null | ||
| ? null | ||
| : request.Environment | ||
| .OrderBy(pair => pair.Key, StringComparer.Ordinal) | ||
| .Select(pair => $"{pair.Key}={pair.Value}") | ||
| .ToList(), |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



This PR moves the .NET SDK's high-level one-shot calls onto the JSON-only
FFI ingress. A new C# emitter generates internal wire types for
the exact 1.0.0 contract, and an exact 1.0.0 writer in
Microsoft.Mxc.Sdk.V1maps the public V1 types to that contract beforecalling
mxc_run_json/mxc_spawn_json.Details
mxc_schema_supportandmxc_schema_gen csharp,generating internal records under
Generated/MxcConfigV1_0_0.g.cs, withdrift detection in
check-contract-codegenand regeneration documented indocs/schema-codegen.md.ExactOneShotRequestWriter(V1/) that always emitsversion,containerId(minted when unnamed),lifecycle,process.timeout, andfilesystem, omits absent members, migrates legacyCaptureDenialstoProcessContainer containment, rejects undefined enum values, and treats
InheritDefaultEnvironmentwithoutEnvironmentas having no effect.V1.MxcSandbox.Run/Spawncallmxc_run_json/mxc_spawn_jsonwiththe experimental opt-in off.
V1.MxcLifecyclerejectswsb:ids withUnsupportedContainment.check-dotnet-api-parity.jscompares the C# surface to the exactcontract instead of the private binding request.
Tests
cargo fmt, clippy(-D warnings), and
mxc_schema_support/mxc_schema_gentests (23).tests/policy/sdk-v1conformance for every input and invalid case,writer negative tests, and lifecycle
wsb:rejection;dotnet test --solution Microsoft.Mxc.Sdk.slnx(260 passed, 27host-dependent tests skipped). Every commit builds.
schema-version, version-sync, and config validation checks;
git diff --check.Microsoft Reviewers: Open in CodeFlow