Skip to content

[Process Container] Report policy rejections as exit 1 with a policy_validation code - #1364

Open
Elliot (theelliotm) wants to merge 2 commits into
mainfrom
user/emichlin/fix-processcontainer-wrongexitcode
Open

Elliot (theelliotm) wants to merge 2 commits into
mainfrom
user/emichlin/fix-processcontainer-wrongexitcode

Conversation

@theelliotm

@theelliotm Elliot (theelliotm) commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

📖 Description

A backend that refuses a policy exited -1 with a generic "code":"backend_error", so callers could not tell a refused policy from a crash, a launch failure, or a timeout. The rejection sites already set FailurePhase::Rejected, but it was dropped on the way out.

  • FailurePhase::error_code() maps Rejected to policy_validation and every other phase to backend_error.
  • emit_backend_error_envelope derives the wire code from the phase rather than hardcoding backend_error.
  • ScriptResponse::rejected() exits 1 and leaves standard_err empty, so the message no longer prints bare and then again, unseparated, ahead of the JSON envelope.

Applied to the ProcessContainer rejection sites and to the shared network policy-support validator, whose entire purpose is refusing policy a backend cannot enforce.

This change also revealed test 13B was falsely passing. Fixed.

🔗 References

Resolves #1247

I think this ties into the larger issue of #612. Should probably be reclassified into a bug cause no backend is consistent at all with errors.

🔍 Validation

Ran process container validation tests locally. The error is gone.
Running in CI now...

✅ Checklist

📋 Issue Type

  • Bug fix
  • Feature
  • Task
Microsoft Reviewers: Open in CodeFlow

Copilot AI balanced review requested due to automatic review settings October 1, 2026 00:21
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

AppContainer P8a/P8d paths remain generic errors, and the global phase mapping misclassifies some backend-unavailable failures.

Review effort: Balanced
Findings: 3 Medium severity

Open (3)
What changed in this PR

Updates one-shot backend policy refusals to return actionable policy_validation errors with exit code 1.

Changes:

  • Adds phase-based wire error-code mapping.
  • Introduces ScriptResponse::rejected.
  • Converts selected Process Container and shared network-policy rejection paths.
File Description
src/​core/​wxc_common/​src/​validator.rs Converts shared network-policy failures to rejected responses.
src/​core/​wxc_common/​src/​script_runner.rs Derives envelope codes from failure phases.
src/​core/​wxc_common/​src/​models.rs Adds error-code mapping and rejected-response construction.
src/​backends/​process_container/​common/​src/​launch_diagnostics.rs Converts environment rejection handling.
src/​backends/​process_container/​common/​src/​base_container_runner.rs Converts unsupported PSEC-version handling.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/core/wxc_common/src/models.rs
Comment thread src/core/wxc_common/src/validator.rs
Comment thread src/core/wxc_common/src/validator.rs
A backend that refuses a policy exited -1 with a generic
"code":"backend_error", so callers could not tell a refused policy from a
crash, a launch failure, or a timeout. The rejection sites already set
FailurePhase::Rejected, but it was dropped on the way out.

- FailurePhase::error_code() maps Rejected to policy_validation and every
  other phase to backend_error.
- emit_backend_error_envelope derives the wire code from the phase rather
  than hardcoding backend_error.
- ScriptResponse::rejected() exits 1 and leaves standard_err empty, so the
  message no longer prints bare and then again, unseparated, ahead of the
  JSON envelope.

Applied to the policy refusals in both ProcessContainer tiers' validate()
and to the shared network policy-support validator. The two are
complementary: each tier advertises the network features it can enforce,
so the shared validator only refuses what a tier does not advertise, and
the tier refuses unsupported values of what it does. Both paths are
reachable, so both had to change.

Setup and launch failures (BFS availability, CreateProcess, capture
provider probes) keep backend_error: they are host conditions, not
request refusals.

Fixes #1247

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 00:32
@theelliotm
Elliot (theelliotm) force-pushed the user/emichlin/fix-processcontainer-wrongexitcode branch from f46643e to c0620d3 Compare October 1, 2026 00:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Some legacy host-list policy failures still return backend_error, and the new wire-envelope behavior lacks a regression assertion.

Review effort: Balanced
Findings: 1 Medium severity · 1 Low severity

Open (2)
Resolved since last review (3)

Comment thread src/core/wxc_common/src/validator.rs
Comment thread src/core/wxc_common/src/script_runner.rs
Copilot AI balanced review requested due to automatic review settings October 1, 2026 00:39
@theelliotm Elliot (theelliotm) self-assigned this Oct 1, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The changes consistently preserve rejection details while producing the expected exit status and structured error code.

Review effort: Balanced
Findings: None

Resolved since last review (2)

@theelliotm
Elliot (theelliotm) marked this pull request as ready for review October 1, 2026 00:42
@theelliotm
Elliot (theelliotm) requested a review from a team October 1, 2026 00:42
@theelliotm
Elliot (theelliotm) requested a review from a team as a code owner October 1, 2026 00:42

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Process container: backend policy rejections exit -1 with a generic backend_error code

2 participants