Skip to content

feat(sdk): probe denial capture support - #778

Open
Carlos Alexandro Becker (caarlos0) wants to merge 1 commit into
mainfrom
probe-denial-capture
Open

feat(sdk): probe denial capture support#778
Carlos Alexandro Becker (caarlos0) wants to merge 1 commit into
mainfrom
probe-denial-capture

Conversation

@caarlos0

@caarlos0 Carlos Alexandro Becker (caarlos0) commented Aug 8, 2026

Copy link
Copy Markdown
Collaborator

📖 Description

Expose captureDenials through the Rust SDK's existing available_backends() host-capability probe.

ProcessContainer reports BackendCapability::CaptureDenials only after the host successfully creates a minimal PSEC environment and starts a Learning Mode trace. The probe session is immediately discarded. This remains advisory; launch still returns ErrorCode::BackendUnavailable if support changes before execution.

🔗 References

No linked issue.

🔍 Validation

  • cargo test -p mxc_engine -p mxc-sdk
  • cargo clippy -p mxc_engine -p mxc-sdk --all-targets -- -D warnings
  • cargo test -p mxc_engine probe::tests
  • cargo clippy -p mxc_engine --all-targets -- -D warnings

✅ Checklist

📋 Issue Type

  • Bug fix
  • Feature
  • Task

GitHub Actions runs the PR validation build automatically. The ADO pipeline
(MXC-PR-Build) is the Azure version of the PR pipeline, kept in parity with the GitHub
Actions build; it runs on merge to main, and Microsoft reviewers with write access can trigger it
on a PR with /azp run. See docs/pull-requests.md.

If the dependency-feed-check check fails on a new dependency, the crate must be added to
the feed before the PR can pass. See docs/pull-requests.md
for the steps.

Microsoft Reviewers: Open in CodeFlow

Expose captureDenials as a typed ProcessContainer capability when the host can create a PSEC environment and start a Learning Mode trace.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: d5bfbefb-3948-452d-a03e-445a179c7352
Signed-off-by: Carlos Alexandro Becker <caarlos0@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings August 8, 2026 02:05
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Exposes denial-capture availability through the Rust SDK’s backend capability probe.

Changes:

  • Adds and re-exports BackendCapability.
  • Probes Windows denial-capture support.
  • Documents capability discovery and schema requirements.
Show a summary per file
File Description
src/backends/appcontainer/common/src/base_container_runner.rs Adds the denial-capture host probe.
src/core/mxc_engine/src/probe.rs Reports backend capabilities.
src/core/mxc_engine/src/lib.rs Exports capability types.
src/core/mxc-sdk/src/lib.rs Re-exports capabilities publicly.
src/core/mxc-sdk/README.md Documents capability probing.

Review details

Tip

Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

  • Files reviewed: 5/5 changed files
  • Comments generated: 1
  • Review effort level: Balanced

Comment on lines +507 to +508
static USABLE: std::sync::OnceLock<bool> = std::sync::OnceLock::new();
*USABLE.get_or_init(|| {
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants