Skip to content

fix: route captured network decisions through Tessera - #1419

Open
Richie Gomez (richiemsft) wants to merge 6 commits into
mainfrom
richiemsft/wfp-learning-mode-integration
Open

Richie Gomez (richiemsft) wants to merge 6 commits into
mainfrom
richiemsft/wfp-learning-mode-integration

Conversation

@richiemsft

@richiemsft Richie Gomez (richiemsft) commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

📖 Description

Routes direct ProcessContainer denial-capture traffic through Tessera so WFP Learning Mode can observe the policy decision without weakening enforcement.

  • Synthesizes internetClient only for direct directional captureDenials requests.
  • Keeps the serialized PSEC egress policy authoritative.
  • Deliberately excludes runtime proxy mode from the synthesized direct-egress capability.
  • Adds regression coverage for direct and proxy postures and shared capability helpers.

This is PR 3 of 4 in the WFP Learning Mode stack. Its base is the decoder-layer branch.

🔗 References

Related to #1286.

Depends on the preceding decoder PR in this stack.

🔍 Validation

  • cargo test -p mxc-sdk --lib 'capture_denials_' — 25 passed.
  • cargo test -p mxc-sdk --lib 'network_policy_helpers::tests::' — 5 passed.

✅ Checklist

  • Signed the Contributor License Agreement
  • Linked to an issue
  • Updated documentation (covered by the following documentation PR)
  • Updated Copilot instructions (not applicable)
  • If this PR changes Cargo.lock, the dependency-feed-check check passes (not applicable)

📋 Issue Type

  • Bug fix
  • Feature
  • Task

🧱 Stack

  1. feat: prefer option-aware Learning Mode trace startup #1417 — API startup and compatibility
  2. feat: decode WFP Learning Mode network events #1418 — WFP event decoding
  3. fix: route captured network decisions through Tessera #1419 — ProcessContainer integration
  4. docs: describe WFP denial capture #1420 — Documentation

Review and merge in this order.

Microsoft Reviewers: Open in CodeFlow

@richiemsft
Richie Gomez (richiemsft) requested a review from a team as a code owner October 6, 2026 20:38
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@MGudgin Gudge (MGudgin) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified review notes

The substantive issue is treating the normalized network_egress Option as evidence that a caller explicitly requested egress; the second comment asks for a negative control on the separate no-capture guard. This is a comment-only review, not a change request.

Verified clean: GitHub's patch matches the local delta. The new tests preserve the proxy posture and prove that the default-deny egress table is still serialized. ensure_capability avoids duplicate capability strings. The runner gains only two new tests (48 to 50); neither covers a parsed request with absent or ingress-only network policy. I did not reproduce a brokered-DNS/Tessera bypass on a PSEC host and am not asserting one.

Verified pre-existing — not attributed to this PR

src/mxc-sdk/src/core/mxc_common/network_parser.rs:159-175 is byte-identical at base and head. Its normalization of absent egress to Some(default) is not itself charged to this PR; the new gate's reliance on presence is the introduced defect. The existing egress-rule serializer and guarded AppContainer capability helper are also unchanged and are not being treated as regressions.

@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-decoder branch from d66c3b4 to b3f6785 Compare October 7, 2026 18:37
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-integration branch from 731c328 to cd9e80a Compare October 7, 2026 18:37
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-decoder branch from b3f6785 to 31a0195 Compare October 7, 2026 18:45
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-integration branch 4 times, most recently from cdbd9d6 to 82dce5d Compare October 7, 2026 20:37
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-decoder branch from 05c16d0 to 183a905 Compare October 7, 2026 22:36
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-integration branch 2 times, most recently from 72c85b5 to 67e25e8 Compare October 8, 2026 17:29
@richiemsft

Copy link
Copy Markdown
Contributor Author

Gudge (@MGudgin) The remaining capability-presence finding is fixed in a01d125. network.egress absence now remains distinct through parsing, and the parse-to-PSEC matrix covers absent network, ingress-only, explicit deny-default egress, plus the no-capture negative control. The complete mxc-sdk library run passed 2,775 tests; one unrelated host-dependent loopback proxy test timed out consistently on this machine. Please re-review the updated tip.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Security-sensitive network enforcement changes depend on preceding stacked ABI and decoder changes, warranting final human validation.

0 open findings

What changed in this PR

Routes ProcessContainer denial-capture network decisions through Tessera while preserving authoritative PSEC enforcement and proxy isolation.

Changes:

  • Synthesizes direct-egress capability only for eligible network-aware captures.
  • Emits and validates version 5 capture diagnostics.
  • Adds regression coverage for direct, proxy, and legacy postures.
File Description
src/​tools/​wxc/​src/​audit.rs Validates and publishes versioned verbose diagnostics.
src/​mxc-sdk/​src/​core/​mxc_common/​network_parser.rs Preserves explicit egress-section presence.
src/​mxc-sdk/​src/​core/​mxc_common/​mod.rs Exposes the parser within the crate.
src/​mxc-sdk/​src/​backends/​process_container/​common/​capture_output.rs Writes version 5 native-capture diagnostics.
src/​mxc-sdk/​src/​backends/​process_container/​common/​base_container_runner.rs Selects network-aware capture routing and decoding.
src/​mxc-sdk/​src/​backends/​process_container/​common/​base_container_helpers/​tests.rs Updates helper invocations for capture routing.
src/​mxc-sdk/​src/​backends/​process_container/​common/​base_container_helpers.rs Adds conditional internetClient synthesis.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-decoder branch from 2492bb0 to aa925c7 Compare October 8, 2026 19:26
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-integration branch 2 times, most recently from 6150aa6 to 7bc39c7 Compare October 8, 2026 19:31
@richiemsft
Richie Gomez (richiemsft) requested a balanced review from Copilot and removed request for Copilot October 8, 2026 19:33
Base automatically changed from richiemsft/wfp-learning-mode-decoder to main October 9, 2026 20:39
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Copilot AI balanced review requested due to automatic review settings October 10, 2026 00:03
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-integration branch from 7bc39c7 to 4ce4047 Compare October 10, 2026 00:03

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The security-sensitive, Windows-specific interaction between capability gating, Tessera enforcement, and WFP capture warrants final human validation.

0 open findings

🧠 Review effort: Balanced

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants