[Process Container] Report policy rejections as exit 1 with a policy_validation code - #1364
Open
Elliot (theelliotm) wants to merge 2 commits into
Open
Elliot (theelliotm) wants to merge 2 commits into
Elliot (theelliotm) wants to merge 2 commits into
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
AppContainer P8a/P8d paths remain generic errors, and the global phase mapping misclassifies some backend-unavailable failures.
Review effort: Balanced
Findings: 3
Open (3)
What changed in this PR
Updates one-shot backend policy refusals to return actionable policy_validation errors with exit code 1.
Changes:
- Adds phase-based wire error-code mapping.
- Introduces
ScriptResponse::rejected. - Converts selected Process Container and shared network-policy rejection paths.
| File | Description |
|---|---|
src/core/wxc_common/src/validator.rs |
Converts shared network-policy failures to rejected responses. |
src/core/wxc_common/src/script_runner.rs |
Derives envelope codes from failure phases. |
src/core/wxc_common/src/models.rs |
Adds error-code mapping and rejected-response construction. |
src/backends/process_container/common/src/launch_diagnostics.rs |
Converts environment rejection handling. |
src/backends/process_container/common/src/base_container_runner.rs |
Converts unsupported PSEC-version handling. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
A backend that refuses a policy exited -1 with a generic "code":"backend_error", so callers could not tell a refused policy from a crash, a launch failure, or a timeout. The rejection sites already set FailurePhase::Rejected, but it was dropped on the way out. - FailurePhase::error_code() maps Rejected to policy_validation and every other phase to backend_error. - emit_backend_error_envelope derives the wire code from the phase rather than hardcoding backend_error. - ScriptResponse::rejected() exits 1 and leaves standard_err empty, so the message no longer prints bare and then again, unseparated, ahead of the JSON envelope. Applied to the policy refusals in both ProcessContainer tiers' validate() and to the shared network policy-support validator. The two are complementary: each tier advertises the network features it can enforce, so the shared validator only refuses what a tier does not advertise, and the tier refuses unsupported values of what it does. Both paths are reachable, so both had to change. Setup and launch failures (BFS availability, CreateProcess, capture provider probes) keep backend_error: they are host conditions, not request refusals. Fixes #1247 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Elliot (theelliotm)
force-pushed
the
user/emichlin/fix-processcontainer-wrongexitcode
branch
from
October 1, 2026 00:32
f46643e to
c0620d3
Compare
Elliot (theelliotm)
marked this pull request as ready for review
October 1, 2026 00:42
Elliot (theelliotm)
requested review from
Gudge (MGudgin) and
Jeff Whiteside (jsidewhite)
October 1, 2026 00:47
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


📖 Description
A backend that refuses a policy exited -1 with a generic "code":"backend_error", so callers could not tell a refused policy from a crash, a launch failure, or a timeout. The rejection sites already set FailurePhase::Rejected, but it was dropped on the way out.
Applied to the ProcessContainer rejection sites and to the shared network policy-support validator, whose entire purpose is refusing policy a backend cannot enforce.
This change also revealed test 13B was falsely passing. Fixed.
🔗 References
Resolves #1247
I think this ties into the larger issue of #612. Should probably be reclassified into a bug cause no backend is consistent at all with errors.
🔍 Validation
Ran process container validation tests locally. The error is gone.
Running in CI now...
✅ Checklist
Cargo.lock, thedependency-feed-checkcheck passes (see docs/pull-requests.md)📋 Issue Type
Microsoft Reviewers: Open in CodeFlow