{"_id":"@microsoft/mxc-sdk","_rev":"13-c009939095271c20ca6df5bbf14fc76a","name":"@microsoft/mxc-sdk","dist-tags":{"latest":"0.8.0"},"versions":{"0.1.6":{"name":"@microsoft/mxc-sdk","version":"0.1.6","keywords":["wxc","sandbox","security","appcontainer","windows","node-pty"],"author":{"name":"Microsoft Corporation"},"license":"MIT","_id":"@microsoft/mxc-sdk@0.1.6","maintainers":[{"name":"microsoft1es","email":"npmjs@microsoft.com"},{"name":"microsoft-oss-releases","email":"microsoft-oss-publishing@microsoft.com"}],"os":["win32","linux"],"dist":{"shasum":"565ee5ebadad04e10adc45b578e594a3006dfc17","tarball":"https://registry.npmjs.org/@microsoft/mxc-sdk/-/mxc-sdk-0.1.6.tgz","fileCount":61,"integrity":"sha512-DcFX7jitI8Ig0iLSzi3v4YeInHvuqdEV7Pv2GVZnCp42RDIKtFcy89B1xbn1Fu7A/ZHN7RMcra9F4EPMRfUFIA==","signatures":[{"sig":"MEQCICEvzGE7++HEcBxbczLBBwCmnFOvXv2+CkhTN1riIGcIAiAydZ8DB1NbV1q8NC1CmeLmXDdHSRkR8CZl+/FZI7lAeQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25701320},"main":"dist/index.js","_from":"file:M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App2\\temp\\38ff6069-bee3-4476-91e9-91b44a24d693\\microsoft-mxc-sdk-0.1.6.tgz","types":"dist/index.d.ts","engines":{"node":">=16.0.0"},"scripts":{"test":"npm run test:unit","build":"tsc","clean":"rimraf dist","watch":"tsc --watch","test:unit":"npm run build:test-unit && node --test dist-tests/tests/unit/sandbox.test.js dist-tests/tests/unit/policy.test.js dist-tests/tests/unit/logger.test.js","prepublishOnly":"npm run build","build:test-unit":"cd tests/unit && npx tsc","test:integration":"cd tests/integration && npm install && npm run build && npm test"},"_npmUser":{"name":"microsoft1es","email":"npmjs@microsoft.com"},"_resolved":"M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App2\\temp\\38ff6069-bee3-4476-91e9-91b44a24d693\\microsoft-mxc-sdk-0.1.6.tgz","_integrity":"sha512-DcFX7jitI8Ig0iLSzi3v4YeInHvuqdEV7Pv2GVZnCp42RDIKtFcy89B1xbn1Fu7A/ZHN7RMcra9F4EPMRfUFIA==","description":"TypeScript SDK for MXC (Microsoft eXecution Containers)","directories":{},"_nodeVersion":"18.5.0","dependencies":{"semver":"^7.7.4","node-pty":"^1.2.0-beta.12"},"_hasShrinkwrap":false,"devDependencies":{"rimraf":"^6.1.3","typescript":"^5.3.3","@types/node":"^20.10.0","@types/semver":"^7.7.1"},"_npmOperationalInternal":{"tmp":"tmp/mxc-sdk_0.1.6_1777533958150_0.39830880226825216","host":"s3://npm-registry-packages-npm-production"}},"0.1.7":{"name":"@microsoft/mxc-sdk","version":"0.1.7","keywords":["wxc","sandbox","security","appcontainer","windows","node-pty"],"author":{"name":"Microsoft Corporation"},"license":"MIT","_id":"@microsoft/mxc-sdk@0.1.7","maintainers":[{"name":"microsoft1es","email":"npmjs@microsoft.com"},{"name":"microsoft-oss-releases","email":"microsoft-oss-publishing@microsoft.com"}],"os":["win32","linux"],"dist":{"shasum":"88a62e7f3fe5a9f2d99d1269be4311b036d9c50a","tarball":"https://registry.npmjs.org/@microsoft/mxc-sdk/-/mxc-sdk-0.1.7.tgz","fileCount":61,"integrity":"sha512-6CNshkL2f5oMDyt0Tdv1MtfB70Ev82mHV/cGogKgNlMa8ITSI/XqdiIriLunqcY4WyyHZfggL/mOBgCtcL48eQ==","signatures":[{"sig":"MEYCIQD1aIjTw67vkXSM7ZMx/jyQIu0yUgBax3TBJ+iWPYcf7QIhANAK3lSV4qyrenxvPscs98cEAjAdb7UFy4FNI0wdHJCA","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25840293},"main":"dist/index.js","_from":"file:M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App2\\temp\\fb7fe2c7-8dcb-4a45-a90b-e947a4754ccd\\microsoft-mxc-sdk-0.1.7.tgz","types":"dist/index.d.ts","engines":{"node":">=16.0.0"},"scripts":{"test":"npm run test:unit","build":"tsc","clean":"rimraf dist","watch":"tsc --watch","test:unit":"npm run build:test-unit && node --test dist-tests/tests/unit/sandbox.test.js dist-tests/tests/unit/policy.test.js dist-tests/tests/unit/logger.test.js","prepublishOnly":"npm run build","build:test-unit":"cd tests/unit && npx tsc","test:integration":"cd tests/integration && npm install && npm run build && npm test"},"_npmUser":{"name":"microsoft1es","email":"npmjs@microsoft.com"},"_resolved":"M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App2\\temp\\fb7fe2c7-8dcb-4a45-a90b-e947a4754ccd\\microsoft-mxc-sdk-0.1.7.tgz","_integrity":"sha512-6CNshkL2f5oMDyt0Tdv1MtfB70Ev82mHV/cGogKgNlMa8ITSI/XqdiIriLunqcY4WyyHZfggL/mOBgCtcL48eQ==","description":"TypeScript SDK for MXC (Microsoft eXecution Containers)","directories":{},"_nodeVersion":"18.5.0","dependencies":{"semver":"^7.7.4","node-pty":"^1.2.0-beta.12"},"_hasShrinkwrap":false,"devDependencies":{"rimraf":"^6.1.3","typescript":"^5.3.3","@types/node":"^20.10.0","@types/semver":"^7.7.1"},"_npmOperationalInternal":{"tmp":"tmp/mxc-sdk_0.1.7_1777938805225_0.15085628937457352","host":"s3://npm-registry-packages-npm-production"}},"0.1.8":{"name":"@microsoft/mxc-sdk","version":"0.1.8","keywords":["wxc","sandbox","security","appcontainer","windows","node-pty"],"author":{"name":"Microsoft Corporation"},"license":"MIT","_id":"@microsoft/mxc-sdk@0.1.8","maintainers":[{"name":"microsoft1es","email":"npmjs@microsoft.com"},{"name":"microsoft-oss-releases","email":"microsoft-oss-publishing@microsoft.com"}],"dist":{"shasum":"72b1c3f4d5e74948149826330449671be07ac41e","tarball":"https://registry.npmjs.org/@microsoft/mxc-sdk/-/mxc-sdk-0.1.8.tgz","fileCount":61,"integrity":"sha512-sjywLhMc/eAnBxauw5Fj+7tXJtvoFKpUjD6++g44vPVauy4wJzWHlw8NmIwIuEWlkkyIXEijdTa+hCU+AqtkDQ==","signatures":[{"sig":"MEYCIQC6BowfNziJdz/+mTd4WCvNg6Ohg/QEC4iIp1eTxbuctwIhAM4+CTk/OBYjk5xcnysfoOOFVpdAroXPOivM1MWTmcwQ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25396454},"main":"dist/index.js","_from":"file:M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\f84226c6-e66f-4100-a052-6273dee37658\\microsoft-mxc-sdk-0.1.8.tgz","types":"dist/index.d.ts","engines":{"node":">=16.0.0"},"scripts":{"test":"npm run test:unit","build":"tsc","clean":"rimraf dist","watch":"tsc --watch","test:unit":"npm run build:test-unit && node --test dist-tests/tests/unit/sandbox.test.js dist-tests/tests/unit/policy.test.js dist-tests/tests/unit/logger.test.js","prepublishOnly":"npm run build","build:test-unit":"cd tests/unit && npx tsc","test:integration":"cd tests/integration && npm install && npm run build && npm test"},"_npmUser":{"name":"microsoft1es","email":"npmjs@microsoft.com"},"_resolved":"M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\f84226c6-e66f-4100-a052-6273dee37658\\microsoft-mxc-sdk-0.1.8.tgz","_integrity":"sha512-sjywLhMc/eAnBxauw5Fj+7tXJtvoFKpUjD6++g44vPVauy4wJzWHlw8NmIwIuEWlkkyIXEijdTa+hCU+AqtkDQ==","description":"TypeScript SDK for MXC (Microsoft eXecution Containers)","directories":{},"_nodeVersion":"18.5.0","dependencies":{"semver":"^7.7.4","node-pty":"^1.2.0-beta.12"},"_hasShrinkwrap":false,"devDependencies":{"rimraf":"^6.1.3","typescript":"^5.3.3","@types/node":"^20.10.0","@types/semver":"^7.7.1"},"_npmOperationalInternal":{"tmp":"tmp/mxc-sdk_0.1.8_1778022754739_0.44224465118767475","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@microsoft/mxc-sdk","version":"0.2.0","keywords":["wxc","sandbox","security","processcontainer","windows","node-pty"],"author":{"name":"Microsoft Corporation"},"license":"MIT","_id":"@microsoft/mxc-sdk@0.2.0","maintainers":[{"name":"microsoft1es","email":"npmjs@microsoft.com"},{"name":"microsoft-oss-releases","email":"microsoft-oss-publishing@microsoft.com"}],"dist":{"shasum":"3d5e0c0ca160c4cad386a05c81af1c865f1244b0","tarball":"https://registry.npmjs.org/@microsoft/mxc-sdk/-/mxc-sdk-0.2.0.tgz","fileCount":83,"integrity":"sha512-xgWTV0nvIzl+IjlIhLGw++/A1eeZYORDoMLGLlDpSE8tMPWLbQIF627Xsb0pkb04MB9vtZl9P+RRNB7fwS3PXA==","signatures":[{"sig":"MEUCIQCij7JNMrbXO/F050zWXzuwmerMeVrYFMmyGplE7quiawIgIQ4j1j0xY11YP2BKtjwFNqXfNv4M7t8LE/AcHnJb1vM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":32295042},"type":"module","_from":"file:M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\6a909a77-a628-44b6-ac1f-033f7edbf496\\microsoft-mxc-sdk-0.2.0.tgz","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./package.json":"./package.json"},"scripts":{"test":"npm run test:unit","build":"tsc","clean":"rimraf dist","watch":"tsc --watch","test:unit":"npm run build:test-unit && node --test dist-tests/tests/unit/sandbox.test.js dist-tests/tests/unit/policy.test.js dist-tests/tests/unit/logger.test.js dist-tests/tests/unit/errors.test.js dist-tests/tests/unit/state-aware-types.test.js dist-tests/tests/unit/state-aware.test.js","prepublishOnly":"npm run build","build:test-unit":"cd tests/unit && npx tsc","test:integration":"cd tests/integration && npm install && npm run build && npm test"},"_npmUser":{"name":"microsoft1es","email":"npmjs@microsoft.com"},"_resolved":"M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\6a909a77-a628-44b6-ac1f-033f7edbf496\\microsoft-mxc-sdk-0.2.0.tgz","_integrity":"sha512-xgWTV0nvIzl+IjlIhLGw++/A1eeZYORDoMLGLlDpSE8tMPWLbQIF627Xsb0pkb04MB9vtZl9P+RRNB7fwS3PXA==","description":"TypeScript SDK for MXC (Microsoft eXecution Containers)","directories":{},"_nodeVersion":"18.5.0","dependencies":{"semver":"^7.7.4","node-pty":"^1.2.0-beta.12"},"_hasShrinkwrap":false,"devDependencies":{"rimraf":"^6.1.3","typescript":"^5.3.3","@types/node":"^20.10.0","@types/semver":"^7.7.1"},"_npmOperationalInternal":{"tmp":"tmp/mxc-sdk_0.2.0_1778958036879_0.04273187683292279","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@microsoft/mxc-sdk","version":"0.2.1","keywords":["wxc","sandbox","security","processcontainer","windows","node-pty"],"author":{"name":"Microsoft Corporation"},"license":"MIT","_id":"@microsoft/mxc-sdk@0.2.1","maintainers":[{"name":"microsoft1es","email":"npmjs@microsoft.com"},{"name":"microsoft-oss-releases","email":"microsoft-oss-publishing@microsoft.com"}],"dist":{"shasum":"430567f08c71f28319840a0ef719d34ef265629e","tarball":"https://registry.npmjs.org/@microsoft/mxc-sdk/-/mxc-sdk-0.2.1.tgz","fileCount":85,"integrity":"sha512-1dL42Abc1ocapZR01aPeSEcvuzWuvOslmWNZvdYs6+yTVqAnpWrMk+aFf0Odry9SqJbcW9FABYzPlFtJW6clAQ==","signatures":[{"sig":"MEUCIQC8HH65FhcVHAVPOFxKjorWccloTrnag9+UUVY1C5NsbgIgXdtZrb9JZ2Cqu3UegJfAOzk6I5dUfMj1hhgTYCjsLw8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":43327530},"type":"module","_from":"file:M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\fdf20f24-d793-496c-aaab-93843687a02d\\microsoft-mxc-sdk-0.2.1.tgz","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./package.json":"./package.json"},"scripts":{"test":"npm run test:unit","build":"tsc","clean":"rimraf dist","watch":"tsc --watch","test:unit":"npm run build:test-unit && node --test dist-tests/tests/unit/sandbox.test.js dist-tests/tests/unit/policy.test.js dist-tests/tests/unit/logger.test.js dist-tests/tests/unit/errors.test.js dist-tests/tests/unit/state-aware-types.test.js dist-tests/tests/unit/state-aware.test.js","prepublishOnly":"npm run build","build:test-unit":"cd tests/unit && npx tsc","test:integration":"cd tests/integration && npm install && npm run build && npm test"},"_npmUser":{"name":"microsoft1es","email":"npmjs@microsoft.com"},"_resolved":"M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\fdf20f24-d793-496c-aaab-93843687a02d\\microsoft-mxc-sdk-0.2.1.tgz","_integrity":"sha512-1dL42Abc1ocapZR01aPeSEcvuzWuvOslmWNZvdYs6+yTVqAnpWrMk+aFf0Odry9SqJbcW9FABYzPlFtJW6clAQ==","description":"TypeScript SDK for MXC (Microsoft eXecution Containers)","directories":{},"_nodeVersion":"18.5.0","dependencies":{"semver":"^7.7.4","node-pty":"^1.2.0-beta.12"},"_hasShrinkwrap":false,"devDependencies":{"rimraf":"^6.1.3","node-gyp":"^12.2.0","typescript":"^5.3.3","@types/node":"^20.10.0","@types/semver":"^7.7.1"},"_npmOperationalInternal":{"tmp":"tmp/mxc-sdk_0.2.1_1779493204583_0.3523384716668261","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@microsoft/mxc-sdk","version":"0.3.0","keywords":["wxc","sandbox","security","processcontainer","windows","node-pty"],"author":{"name":"Microsoft Corporation"},"license":"MIT","_id":"@microsoft/mxc-sdk@0.3.0","maintainers":[{"name":"microsoft1es","email":"npmjs@microsoft.com"},{"name":"microsoft-oss-releases","email":"microsoft-oss-publishing@microsoft.com"}],"dist":{"shasum":"43ab2540bccc4f7ee2695f45c8119f2395ecb068","tarball":"https://registry.npmjs.org/@microsoft/mxc-sdk/-/mxc-sdk-0.3.0.tgz","fileCount":87,"integrity":"sha512-eAjVfS4+RdG03Wh/DemgaMmjkuTGPDDNR3xRxkRLRs6lCpezNZq8OdNLjCy4N9cKr/H9mlpYAwPQUs07/+BywA==","signatures":[{"sig":"MEUCIFrocm10g48a1Uo3NMeTcRApKV8pWz0YkK3tnjkCNTwAAiEAn1vZdbmg+hx3X6/d4eP1igbIIyj2+jTuGmt6SeIPNoc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":48751660},"type":"module","_from":"file:M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\2c570b1e-5f38-41ec-9458-0be93a5ab3b2\\microsoft-mxc-sdk-0.3.0.tgz","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./package.json":"./package.json"},"scripts":{"test":"npm run test:unit","build":"tsc","clean":"rimraf dist","watch":"tsc --watch","test:unit":"npm run build:test-unit && node --test dist-tests/tests/unit/sandbox.test.js dist-tests/tests/unit/policy.test.js dist-tests/tests/unit/logger.test.js dist-tests/tests/unit/errors.test.js dist-tests/tests/unit/state-aware-types.test.js dist-tests/tests/unit/state-aware.test.js dist-tests/tests/unit/platform.test.js","prepublishOnly":"npm run build","build:test-unit":"cd tests/unit && npx tsc","test:integration":"cd tests/integration && npm install && npm run build && npm test"},"_npmUser":{"name":"microsoft1es","email":"npmjs@microsoft.com"},"_resolved":"M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\2c570b1e-5f38-41ec-9458-0be93a5ab3b2\\microsoft-mxc-sdk-0.3.0.tgz","_integrity":"sha512-eAjVfS4+RdG03Wh/DemgaMmjkuTGPDDNR3xRxkRLRs6lCpezNZq8OdNLjCy4N9cKr/H9mlpYAwPQUs07/+BywA==","description":"TypeScript SDK for MXC (Microsoft eXecution Containers)","directories":{},"_nodeVersion":"18.5.0","dependencies":{"semver":"^7.7.4","node-pty":"^1.2.0-beta.12"},"_hasShrinkwrap":false,"devDependencies":{"rimraf":"^6.1.3","node-gyp":"^12.2.0","typescript":"^5.3.3","@types/node":"^20.10.0","@types/semver":"^7.7.1"},"_npmOperationalInternal":{"tmp":"tmp/mxc-sdk_0.3.0_1779940386201_0.7990001085716232","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@microsoft/mxc-sdk","version":"0.6.0","keywords":["wxc","sandbox","security","processcontainer","windows","node-pty"],"author":{"name":"Microsoft Corporation"},"license":"MIT","_id":"@microsoft/mxc-sdk@0.6.0","maintainers":[{"name":"microsoft1es","email":"npmjs@microsoft.com"},{"name":"microsoft-oss-releases","email":"microsoft-oss-publishing@microsoft.com"}],"dist":{"shasum":"95b9b41b0f6826ebdc57c8f06625c68f419395f6","tarball":"https://registry.npmjs.org/@microsoft/mxc-sdk/-/mxc-sdk-0.6.0.tgz","fileCount":89,"integrity":"sha512-O+cKLjO4mE/D4dDp2GmVJ8hAj43vQHLf1YTMUWUtU4+41ddThhb1SYkn6W9b3FLl63bJW/4dqReJG6PIBk8jqQ==","signatures":[{"sig":"MEUCIQDmwio3Y7guB48ffHkyzvB3bFZBzsbEv4F4++tagWsLtwIgNpq1tXVrZkZiEwrfvw8grYXREEQo3NkKEfmjecyBTDM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":50803347},"type":"module","_from":"file:M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\95f0de3e-77c0-4ad4-b2dc-204df09966f7\\microsoft-mxc-sdk-0.6.0.tgz","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./package.json":"./package.json"},"scripts":{"test":"npm run test:unit","build":"tsc","clean":"rimraf dist","watch":"tsc --watch","test:unit":"npm run build:test-unit && node --test dist-tests/tests/unit/sandbox.test.js dist-tests/tests/unit/policy.test.js dist-tests/tests/unit/logger.test.js dist-tests/tests/unit/errors.test.js dist-tests/tests/unit/state-aware-types.test.js dist-tests/tests/unit/state-aware.test.js dist-tests/tests/unit/platform.test.js","prepublishOnly":"npm run build","build:test-unit":"cd tests/unit && npx tsc","test:integration":"cd tests/integration && npm install && npm run build && npm test"},"_npmUser":{"name":"microsoft1es","email":"npmjs@microsoft.com"},"_resolved":"M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\95f0de3e-77c0-4ad4-b2dc-204df09966f7\\microsoft-mxc-sdk-0.6.0.tgz","_integrity":"sha512-O+cKLjO4mE/D4dDp2GmVJ8hAj43vQHLf1YTMUWUtU4+41ddThhb1SYkn6W9b3FLl63bJW/4dqReJG6PIBk8jqQ==","description":"TypeScript SDK for MXC (Microsoft eXecution Containers)","directories":{},"_nodeVersion":"18.5.0","dependencies":{"semver":"^7.7.4","node-pty":"^1.2.0-beta.12"},"_hasShrinkwrap":false,"devDependencies":{"rimraf":"^6.1.3","node-gyp":"^12.2.0","typescript":"^5.3.3","@types/node":"^20.10.0","@types/semver":"^7.7.1"},"_npmOperationalInternal":{"tmp":"tmp/mxc-sdk_0.6.0_1780127690076_0.5444891713053954","host":"s3://npm-registry-packages-npm-production"}},"0.6.1":{"name":"@microsoft/mxc-sdk","version":"0.6.1","keywords":["wxc","sandbox","security","processcontainer","windows","node-pty"],"author":{"name":"Microsoft Corporation"},"license":"MIT","_id":"@microsoft/mxc-sdk@0.6.1","maintainers":[{"name":"microsoft1es","email":"npmjs@microsoft.com"},{"name":"microsoft-oss-releases","email":"microsoft-oss-publishing@microsoft.com"}],"dist":{"shasum":"fd19794f73aae8038b20974e9681cb524c472ccf","tarball":"https://registry.npmjs.org/@microsoft/mxc-sdk/-/mxc-sdk-0.6.1.tgz","fileCount":89,"integrity":"sha512-jpbJU/xfF4qLWcNMplDTUX/q13m2A6vYao1QN3lkZaQlzsRce95H+iU0Qu0wlweJZ2gx6eY1PRQU+/bnQki/dw==","signatures":[{"sig":"MEUCIQCaFYwhLLMOVgZMpGxI7Z4KKE9dU1/cTFM6Q+q+hMGszAIgbx3Cu1DjoxIeJKOJu/WozOLak9pKejoNhuNFym0eoDk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":48677622},"type":"module","_from":"file:M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\d3df3e83-33a4-4cfb-bbd5-4115df01becc\\microsoft-mxc-sdk-0.6.1.tgz","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./package.json":"./package.json"},"scripts":{"test":"npm run test:unit","build":"tsc","clean":"rimraf dist","watch":"tsc --watch","test:unit":"npm run build:test-unit && node --test dist-tests/tests/unit/sandbox.test.js dist-tests/tests/unit/policy.test.js dist-tests/tests/unit/logger.test.js dist-tests/tests/unit/errors.test.js dist-tests/tests/unit/state-aware-types.test.js dist-tests/tests/unit/state-aware.test.js dist-tests/tests/unit/platform.test.js","prepublishOnly":"npm run build","build:test-unit":"cd tests/unit && npx tsc","test:integration":"cd tests/integration && npm install && npm run build && npm test"},"_npmUser":{"name":"microsoft1es","email":"npmjs@microsoft.com"},"_resolved":"M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\d3df3e83-33a4-4cfb-bbd5-4115df01becc\\microsoft-mxc-sdk-0.6.1.tgz","_integrity":"sha512-jpbJU/xfF4qLWcNMplDTUX/q13m2A6vYao1QN3lkZaQlzsRce95H+iU0Qu0wlweJZ2gx6eY1PRQU+/bnQki/dw==","description":"TypeScript SDK for MXC (Microsoft eXecution Containers)","directories":{},"_nodeVersion":"18.5.0","dependencies":{"semver":"^7.7.4","node-pty":"^1.2.0-beta.12"},"_hasShrinkwrap":false,"devDependencies":{"rimraf":"^6.1.3","node-gyp":"^12.2.0","typescript":"^5.3.3","@types/node":"^20.10.0","@types/semver":"^7.7.1"},"_npmOperationalInternal":{"tmp":"tmp/mxc-sdk_0.6.1_1780374555262_0.17398446750774688","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@microsoft/mxc-sdk","version":"0.7.0","keywords":["wxc","sandbox","security","processcontainer","windows","node-pty"],"author":{"name":"Microsoft Corporation"},"license":"MIT","_id":"@microsoft/mxc-sdk@0.7.0","maintainers":[{"name":"microsoft1es","email":"npmjs@microsoft.com"},{"name":"microsoft-oss-releases","email":"microsoft-oss-publishing@microsoft.com"}],"dist":{"shasum":"561a269b8cb5a4eb7e71fc9158ffd0f74760b640","tarball":"https://registry.npmjs.org/@microsoft/mxc-sdk/-/mxc-sdk-0.7.0.tgz","fileCount":87,"integrity":"sha512-EWhz2pKkcPluZHAOI1yneV+JK0NO/3hdh7nABBb0x4PjyUWMeSWPTBAjtIu+BhtMYOqlaijSPZMZ0Hs/J4ZL4A==","signatures":[{"sig":"MEUCIQCEUsDxf9oOUb6pSRhXCDidRBndBITDf4YT33bpvARR9wIgH7B4G6jNAgvlzItDvZEUDLnSxjfWKCxkmirOEFnTO44=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":41696174},"type":"module","_from":"file:M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\f02c2b0c-7f54-434c-bf54-4eb79de370d3\\microsoft-mxc-sdk-0.7.0.tgz","types":"dist/index.d.ts","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./package.json":"./package.json"},"scripts":{"test":"npm run test:unit","build":"tsc","clean":"rimraf dist","watch":"tsc --watch","test:unit":"npm run build:test-unit && node --test dist-tests/tests/unit/sandbox.test.js dist-tests/tests/unit/policy.test.js dist-tests/tests/unit/logger.test.js dist-tests/tests/unit/errors.test.js dist-tests/tests/unit/state-aware-types.test.js dist-tests/tests/unit/state-aware.test.js dist-tests/tests/unit/platform.test.js","prepublishOnly":"npm run build","build:test-unit":"cd tests/unit && npx tsc","test:integration":"cd tests/integration && npm install && npm run build && npm test"},"_npmUser":{"name":"microsoft1es","email":"npmjs@microsoft.com"},"_resolved":"M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\f02c2b0c-7f54-434c-bf54-4eb79de370d3\\microsoft-mxc-sdk-0.7.0.tgz","_integrity":"sha512-EWhz2pKkcPluZHAOI1yneV+JK0NO/3hdh7nABBb0x4PjyUWMeSWPTBAjtIu+BhtMYOqlaijSPZMZ0Hs/J4ZL4A==","description":"TypeScript SDK for MXC (Microsoft eXecution Containers)","directories":{},"_nodeVersion":"18.5.0","dependencies":{"semver":"^7.7.4","node-pty":"^1.2.0-beta.12"},"_hasShrinkwrap":false,"devDependencies":{"rimraf":"^6.1.3","node-gyp":"^12.2.0","typescript":"^5.3.3","@types/node":"^20.10.0","@types/semver":"^7.7.1"},"_npmOperationalInternal":{"tmp":"tmp/mxc-sdk_0.7.0_1781329742001_0.5553698715142339","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@microsoft/mxc-sdk","version":"0.8.0","description":"TypeScript SDK for MXC (Microsoft eXecution Containers)","type":"module","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./package.json":"./package.json"},"scripts":{"build":"tsc","build:test-unit":"cd tests/unit && npx tsc","watch":"tsc --watch","clean":"rimraf dist","test":"npm run test:unit","test:unit":"npm run build:test-unit && node --test dist-tests/tests/unit/sandbox.test.js dist-tests/tests/unit/policy.test.js dist-tests/tests/unit/logger.test.js dist-tests/tests/unit/errors.test.js dist-tests/tests/unit/state-aware-types.test.js dist-tests/tests/unit/state-aware.test.js dist-tests/tests/unit/platform.test.js dist-tests/tests/unit/wire-conformance.test.js dist-tests/tests/unit/wire-conformance-state-aware.test.js","test:integration":"cd tests/integration && npm install && npm run build && npm test","prepublishOnly":"npm run build"},"keywords":["wxc","sandbox","security","processcontainer","windows","node-pty"],"author":{"name":"Microsoft Corporation"},"license":"MIT","devDependencies":{"@types/node":"^20.10.0","@types/semver":"^7.7.1","node-gyp":"^12.2.0","rimraf":"^6.1.3","typescript":"^5.3.3"},"dependencies":{"node-pty":"^1.2.0-beta.12","semver":"^7.7.4"},"engines":{"node":">=18.0.0"},"_id":"@microsoft/mxc-sdk@0.8.0","_integrity":"sha512-pnf5QsASwp+qtRi5uth2GDjwuyG0rHWRpxCf3RbAjQ4wDTNfBX/9l0A+RVZspU2agpF3/11uWB1JisIS7WrNYg==","_resolved":"M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\b641de4d-e774-45fa-8461-e2dc9c991955\\microsoft-mxc-sdk-0.8.0.tgz","_from":"file:M:\\SvcFab\\_App\\MS.Ess.PackageManager.Publisher_App1\\temp\\b641de4d-e774-45fa-8461-e2dc9c991955\\microsoft-mxc-sdk-0.8.0.tgz","_nodeVersion":"18.5.0","dist":{"integrity":"sha512-pnf5QsASwp+qtRi5uth2GDjwuyG0rHWRpxCf3RbAjQ4wDTNfBX/9l0A+RVZspU2agpF3/11uWB1JisIS7WrNYg==","shasum":"bc818a81e03e4ad767299f2f52ca4d3a36df7eae","tarball":"https://registry.npmjs.org/@microsoft/mxc-sdk/-/mxc-sdk-0.8.0.tgz","fileCount":101,"unpackedSize":68392767,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCICnHtTFsh5lTLuS6iCYSiPRMk0ru8eFDMXf1KSsiqE1KAiBWv1Mb2ftbq0CjovjHM5UFSnisqPeroea5NFe3OXmmfA=="}]},"_npmUser":{"name":"microsoft1es","email":"npmjs@microsoft.com"},"directories":{},"maintainers":[{"name":"microsoft1es","email":"npmjs@microsoft.com"},{"name":"microsoft-oss-releases","email":"microsoft-oss-publishing@microsoft.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mxc-sdk_0.8.0_1787424765386_0.4518099663715407"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-30T07:25:58.063Z","modified":"2026-08-22T18:52:46.126Z","0.1.6":"2026-04-30T07:25:58.618Z","0.1.7":"2026-05-04T23:53:26.953Z","0.1.8":"2026-05-05T23:12:35.270Z","0.2.0":"2026-05-16T19:00:37.346Z","0.2.1":"2026-05-22T23:40:05.020Z","0.3.0":"2026-05-28T03:53:06.616Z","0.6.0":"2026-05-30T07:54:50.558Z","0.6.1":"2026-06-02T04:29:15.612Z","0.7.0":"2026-06-13T05:49:02.368Z","0.8.0":"2026-08-22T18:52:45.965Z"},"author":{"name":"Microsoft Corporation"},"license":"MIT","keywords":["wxc","sandbox","security","processcontainer","windows","node-pty"],"description":"TypeScript SDK for MXC (Microsoft eXecution Containers)","maintainers":[{"name":"microsoft1es","email":"npmjs@microsoft.com"},{"name":"microsoft-oss-releases","email":"microsoft-oss-publishing@microsoft.com"}],"readme":"# `@microsoft/mxc-sdk`\n\n> Node.js / TypeScript SDK for **MXC** (Microsoft eXecution Containers) — a policy-driven sandbox for running untrusted code (model output, plugins, tools) on Windows, Linux, and macOS.\n\n> **Status: Public Preview.** Schemas and APIs may change between minor versions until 1.0.\n\n```bash\nnpm install @microsoft/mxc-sdk\n```\n\n```typescript\nimport {\n  spawnSandboxFromConfig, createConfigFromPolicy,\n  getAvailableToolsPolicy, getTemporaryFilesPolicy,\n  getPlatformSupport,\n} from '@microsoft/mxc-sdk';\n\nif (!getPlatformSupport().isSupported) {\n  throw new Error('MXC not available on this host');\n}\n\n// Discover host tools (python, node, etc.) and a writable temp dir.\nconst tools = getAvailableToolsPolicy(process.env);\nconst temp  = getTemporaryFilesPolicy();\n\nconst config = createConfigFromPolicy({\n  version: '0.6.0-alpha',\n  filesystem: {\n    readonlyPaths:  tools.readonlyPaths,    // PATH, PYTHONPATH, JAVA_HOME, …\n    readwritePaths: temp.readwritePaths,    // %TEMP% / $TMPDIR\n  },\n  network: { allowOutbound: false },\n  timeoutMs: 30_000,\n});\nconfig.process!.commandLine = 'python -c \"print(\\'hello from sandbox\\')\"';\n\nconst child = spawnSandboxFromConfig(config, { usePty: false });\nchild.stdout!.on('data', (d) => process.stdout.write(d));\nchild.on('close', (code) => console.log('exit:', code));\n```\n\n---\n\n## Compatibility\n\n<!--\n  Keep this section in sync with:\n    - sdk/node/src/sandbox.ts          (SUPPORTED_VERSION / MIN_VERSION)\n    - sdk/node/src/platform.ts         (availableMethods per platform)\n    - schemas/{stable,dev}/*.json (supported policy.version values)\n  When a new schema graduates or a new backend ships, update only this block.\n-->\n\n**Policy / config schema versions:**\n\n| Version | Status | Schema file |\n| --- | --- | --- |\n| `0.4.0-alpha` | Retired — below the `0.6.0-alpha` floor (no longer accepted) | [`schemas/stable/mxc-config.schema.0.4.0-alpha.json`](https://github.com/microsoft/mxc/blob/main/schemas/stable/mxc-config.schema.0.4.0-alpha.json) |\n| `0.5.0-alpha` | Retired — below the `0.6.0-alpha` floor (no longer accepted) | [`schemas/stable/mxc-config.schema.0.5.0-alpha.json`](https://github.com/microsoft/mxc/blob/main/schemas/stable/mxc-config.schema.0.5.0-alpha.json) |\n| `0.6.0-alpha` | Stable (minimum supported) | [`schemas/stable/mxc-config.schema.0.6.0-alpha.json`](https://github.com/microsoft/mxc/blob/main/schemas/stable/mxc-config.schema.0.6.0-alpha.json) |\n| `0.7.0-alpha` | Stable | [`schemas/stable/mxc-config.schema.0.7.0-alpha.json`](https://github.com/microsoft/mxc/blob/main/schemas/stable/mxc-config.schema.0.7.0-alpha.json) |\n| `0.8.0-alpha` | Stable (current) | [`schemas/stable/mxc-config.schema.0.8.0-alpha.json`](https://github.com/microsoft/mxc/blob/main/schemas/stable/mxc-config.schema.0.8.0-alpha.json) |\n| `0.9.0-alpha` | Dev (experimental backends, the `experimental.*` block, state-aware sandbox lifecycle) | [`schemas/dev/mxc-config.schema.0.9.0-dev.json`](https://github.com/microsoft/mxc/blob/main/schemas/dev/mxc-config.schema.0.9.0-dev.json) |\n\nPick `0.8.0-alpha` for new code on any supported platform.\n\n> **Stable schemas document only the non-experimental surface.** Experimental backends (`windows_sandbox`, `wslc`, `microvm`, `hyperlight`, `isolation_session`), the `experimental.*` block, and state-aware lifecycle live in `0.9.0-dev`. The parser still accepts them when paired with `--experimental` regardless of which schema your config validates against — schema choice affects editor validation, not runtime behavior.\n\n> **Network host allow/block lists are not implemented on Windows.** `network.allowedHosts` / `network.blockedHosts` have no enforcement on this platform — use `network.defaultPolicy` (`allow` / `block`) or `network.proxy` to constrain network access.\n\n<a id=\"schema-080-networking\"></a>\n\n**Schema 0.8 directional networking:** `createConfigFromPolicy` accepts\n`network.egress` / `network.ingress`, `runtimeConfig.networkProxy`, and\n`processContainer.network.allowedProxyPeer`. Do not mix those fields with the\nlegacy `network.allowOutbound`, `network.allowLocalNetwork`,\n`network.allowedHosts`, `network.blockedHosts`, or `network.proxy` fields.\n`createConfigFromPolicy` authors either shape according to the supplied policy\nversion and fields. Schema 0.6 and 0.7 policies continue to produce the legacy\nwire shape. With schema 0.8, omitting all network fields leaves the\n`network` block out of the generated config; the native parser interprets that\nas directional default-deny for egress, ingress, and host loopback. See the\n[Sandbox Policy 0.8.0 specification](https://github.com/microsoft/mxc/blob/main/docs/sandbox-policy/0.8.0/policy.md)\nfor the complete cross-platform authoring shape.\n\nModel 1 permits direct connections selected by IP/CIDR, protocol, and port\nrules; it does not configure an application-layer proxy. Model 2 denies direct\ninternet access and supplies a loopback HTTP/S proxy endpoint. Backend-specific\nrequirements determine how that proxy endpoint is made reachable.\n\n**Simple model 1 example — direct egress with L3/L4 filtering:**\n\n```typescript\nimport {\n  createConfigFromPolicy,\n  spawnSandboxFromConfig,\n} from '@microsoft/mxc-sdk';\n\nconst directConfig = createConfigFromPolicy({\n  version: '0.8.0-alpha',\n  network: {\n    egress: {\n      default: 'deny',\n      allow: [{\n        to: [{ cidr: '192.0.2.0/24' }],\n        ports: [{ protocol: 'tcp', port: 443 }],\n      }],\n    },\n    ingress: { default: 'deny', hostLoopback: 'deny' },\n  },\n});\ndirectConfig.process!.commandLine = 'node agent.js';\nspawnSandboxFromConfig(directConfig);\n```\n\n**Simple model 2 example — loopback HTTP/S proxy:**\n\n```typescript\nconst proxyConfig = createConfigFromPolicy({\n  version: '0.8.0-alpha',\n  network: {\n    egress: { default: 'deny' },\n    ingress: { default: 'deny', hostLoopback: 'deny' },\n  },\n  runtimeConfig: { networkProxy: 'http://127.0.0.1:8080' },\n});\nproxyConfig.process!.commandLine = 'node agent.js';\nspawnSandboxFromConfig(proxyConfig);\n```\n\nThese are example configurations rather than universal backend recipes.\nProcessContainer proxy configurations have additional criteria; see the\n[ProcessContainer 0.8 proxy example](https://github.com/microsoft/mxc/blob/main/docs/process-container/examples/0.8.0-schema.md).\nSee the [networking specification](https://github.com/microsoft/mxc/blob/main/docs/sandbox-policy/0.8.0/networking/networking.md)\nfor all three connectivity modes and backend-specific support.\n\n**Platforms:**\n\n| Platform | Default backend | Other backends | Minimum build |\n| --- | --- | --- | --- |\n| Windows 11 24H2+ (verified on 25H2) | `processcontainer` | `windows_sandbox`, `wslc`, `microvm`, `isolation_session` | `processcontainer`: 26100 (24H2)<br>`isolation_session`: 26340.9212 ([Insider Preview](https://learn.microsoft.com/en-us/windows-insider/release-notes/experimental/preview-build-26340-9212)) |\n| Linux x64 / ARM64 | `bubblewrap` | `lxc` | — |\n| macOS ARM64 (schema `0.7.0-alpha`+) | `seatbelt` | — | — |\n\nThe default `processcontainer`, `bubblewrap`, `lxc`, and `seatbelt` backends work out of the box. **Experimental backends** (`windows_sandbox`, `wslc`, `microvm`, `isolation_session`, `hyperlight`) require `{ experimental: true }` in `SandboxSpawnOptions` when you spawn — see [Choosing a Backend](#choosing-a-backend).\n\n> **Hyperlight** is an opt-in build flavor (Linux x64 and Windows x64) gated by the `--with-hyperlight` cargo feature. Default shipped binaries do not include it; build from source with `build.bat --with-hyperlight` (Windows) or the equivalent cargo invocation on Linux.\n\n`getPlatformSupport()` reports backend availability and, when the native probe can determine it, `uiCapabilities`: a platform-neutral view of which UI restrictions the host can enforce. This is currently populated only by the Windows native probe, where it is derived from `JOB_OBJECT_UILIMIT_*` support; Linux and macOS omit the field until their probes expose equivalent data.\n\n**Node.js:** ≥ 18.\n\n---\n\n## Three Ways to Spawn\n\nThe SDK provides three entry points. **Prefer the config-based path** (`createConfigFromPolicy` + `spawnSandboxFromConfig`) — it gives you backend selection, backend-specific tuning, and (with `usePty: false`) separated stdout/stderr.\n\n### 1. Config-based — recommended\n\n```typescript\nimport {\n  createConfigFromPolicy, spawnSandboxFromConfig,\n  getAvailableToolsPolicy, getTemporaryFilesPolicy,\n} from '@microsoft/mxc-sdk';\n\nconst tools = getAvailableToolsPolicy(process.env);\nconst temp  = getTemporaryFilesPolicy();\n\nconst config = createConfigFromPolicy(\n  {\n    version: '0.6.0-alpha',\n    filesystem: {\n      readonlyPaths:  tools.readonlyPaths,\n      readwritePaths: temp.readwritePaths,\n    },\n    network: { allowOutbound: true },\n    timeoutMs: 30_000,\n  },\n  'process', // intent: \"process\" | \"vm\" | \"microvm\"\n);\n\n// Add the script and any backend-specific runtime settings on the returned config.\nconfig.process!.commandLine = 'python script.py';\n\n// PTY mode (default) — IPty, merged stdout+stderr\nconst pty = spawnSandboxFromConfig(config);\npty.onData((d) => process.stdout.write(d));\npty.onExit(({ exitCode }) => console.log('exit:', exitCode));\n\n// Pipe mode — ChildProcess with separated stdout/stderr + reliable exit codes\nconst child = spawnSandboxFromConfig(config, { usePty: false });\nchild.stdout!.on('data', (d) => process.stdout.write(d));\nchild.stderr!.on('data', (d) => process.stderr.write(d));\nchild.on('close', (code) => console.log('exit:', code));\n```\n\n### 2. `spawnSandbox(script, policy, ...)` — convenience\n\nQuick path for **process-isolation only** (`processcontainer` on Windows, `lxc` on Linux, `seatbelt` on macOS). Returns a `node-pty` `IPty` with merged stdout/stderr.\n\n```typescript\nimport {\n  spawnSandbox,\n  getAvailableToolsPolicy, getTemporaryFilesPolicy,\n} from '@microsoft/mxc-sdk';\n\nconst tools = getAvailableToolsPolicy(process.env);\nconst temp  = getTemporaryFilesPolicy();\n\nconst pty = spawnSandbox('python script.py', {\n  version: '0.6.0-alpha',\n  filesystem: {\n    readonlyPaths:  tools.readonlyPaths,\n    readwritePaths: temp.readwritePaths,\n  },\n  timeoutMs: 30_000,\n});\npty.onData((d) => process.stdout.write(d));\npty.onExit(({ exitCode }) => console.log('exit:', exitCode));\n```\n\n### 3. `spawnSandboxAsync(script, policy, ...)` — promise-style\n\nThe `await`-friendly version of `spawnSandbox`. Same arguments, same restriction (process-isolation only), but resolves with `{ stdout, stderr, exitCode }` instead of returning an `IPty`. `stderr` is always `''` because the underlying PTY merges streams.\n\n```typescript\nimport {\n  spawnSandboxAsync,\n  getAvailableToolsPolicy, getTemporaryFilesPolicy,\n} from '@microsoft/mxc-sdk';\n\nconst tools = getAvailableToolsPolicy(process.env);\nconst temp  = getTemporaryFilesPolicy();\n\nconst result = await spawnSandboxAsync(\n  'python -c \"import sys; print(sys.version)\"',\n  {\n    version: '0.6.0-alpha',\n    filesystem: {\n      readonlyPaths:  tools.readonlyPaths,\n      readwritePaths: temp.readwritePaths,\n    },\n    timeoutMs: 30_000,\n  },\n);\nconsole.log(result.stdout);\n```\n\n> **Tip:** for agentic workloads, prefer **multiple narrow sandboxes** (one policy per task step) over a single broad policy. Add task-specific paths on top of the discovered base (e.g. a scoped output directory in `readwritePaths`, a project source tree in `readonlyPaths`, secrets in `deniedPaths`).\n\n---\n\n## Choosing a Backend\n\n<details>\n<summary>Table of all backends and links to per-backend guides — click to expand.</summary>\n\n`SandboxPolicy` is cross-platform. The backend is selected by the second argument to `createConfigFromPolicy(policy, containment)`. Pass an **abstract intent** (`\"process\"`, `\"vm\"`, `\"microvm\"`) whenever possible — the SDK and native binary resolve it to the right concrete backend for the host. Pass a **concrete backend name** when you need a specific runner.\n\n| Backend | Intent | Platforms | Stable? | Guide |\n| --- | --- | --- | --- | --- |\n| `processcontainer` | `process` | Windows | ✅ | [`docs/process-container/guide.md`](https://github.com/microsoft/mxc/blob/main/docs/process-container/guide.md) |\n| `bubblewrap` | `process` | Linux | ✅ | [`docs/bwrap-support/bubblewrap-backend.md`](https://github.com/microsoft/mxc/blob/main/docs/bwrap-support/bubblewrap-backend.md) |\n| `lxc` | (concrete only) | Linux | ✅ | [`docs/lxc-support/lxc-backend.md`](https://github.com/microsoft/mxc/blob/main/docs/lxc-support/lxc-backend.md) |\n| `seatbelt` | `process` | macOS | ✅ (schema `0.7.0-alpha`+) | [`docs/seatbelt/seatbelt-backend.md`](https://github.com/microsoft/mxc/blob/main/docs/seatbelt/seatbelt-backend.md) |\n| `windows_sandbox` | `vm` | Windows | Experimental | [`docs/windows-sandbox/windows-sandbox.md`](https://github.com/microsoft/mxc/blob/main/docs/windows-sandbox/windows-sandbox.md) |\n| `microvm` | `microvm` | Windows | Experimental | [`docs/nanvix-microvm/nanvix.md`](https://github.com/microsoft/mxc/blob/main/docs/nanvix-microvm/nanvix.md) — MicroVM via NanVix on Windows Hypervisor Platform |\n| `wslc` | (concrete only) | Windows | Experimental | [`docs/wsl/wsl-container-getting-started.md`](https://github.com/microsoft/mxc/blob/main/docs/wsl/wsl-container-getting-started.md) |\n| `isolation_session` | (concrete only) | Windows | Experimental | [`docs/isolation-session/oneshot.md`](https://github.com/microsoft/mxc/blob/main/docs/isolation-session/oneshot.md) |\n\nExperimental backends require `{ experimental: true }` in `SandboxSpawnOptions`:\n\n```typescript\nconst config = createConfigFromPolicy(policy, 'vm'); // → windows_sandbox on Windows\nconfig.process!.commandLine = 'cmd /c whoami';\nconst pty = spawnSandboxFromConfig(config, { experimental: true });\n```\n\nBackend-specific tuning lives on the returned `ContainerConfig`. The full set of fields per backend is in the JSON schemas — they're the source of truth:\n\n- Stable backends: [`schemas/stable/`](https://github.com/microsoft/mxc/tree/main/schemas/stable/)\n- Experimental backends: [`schemas/dev/`](https://github.com/microsoft/mxc/tree/main/schemas/dev/)\n\nOpen the schema file matching your `policy.version` (e.g. `mxc-config.schema.0.6.0-alpha.json`) and look up `processContainer`, `lxc`, `experimental.wslc`, `experimental.windows_sandbox`, etc.\n\nFor Windows ProcessContainer configs, `processContainer.learningMode: true`\nenables deny-and-record learning mode: failed accesses are logged but remain\ndenied. The internal `learningModeLogging` and `permissiveLearningMode`\ncapability names are reserved and must not be added directly to\n`processContainer.capabilities`.\n\n</details>\n\n## State-Aware Sandboxes\n\n<details>\n<summary>Provision once, exec many, tear down (long-lived workflows) — click to expand.</summary>\n\nFor long-lived sandboxes where you provision once, exec many times, and tear down at the end (e.g. agentic loops), use the state-aware lifecycle.\n\n> **Backend support:** the state-aware lifecycle is currently implemented for `isolation_session`, `windows_sandbox`, and `wslc` (all Windows-only; all still experimental, so every call must pass `{ experimental: true }`). The one-shot spawn APIs (`spawnSandbox` / `spawnSandboxFromConfig`) are the supported path for every other backend.\n\n```typescript\nimport {\n  provisionSandbox, startSandbox, execInSandboxAsync,\n  stopSandbox, deprovisionSandbox,\n} from '@microsoft/mxc-sdk';\n\n// Every call takes a single options object (3rd arg). Experimental backends\n// must pass `experimental: true`.\n// isolation_session provision requires the unrestricted-network acknowledgment:\n// the container's network cannot be filtered or denied, so you must opt in.\nconst { sandboxId } = await provisionSandbox(\n  'isolation_session',\n  { network: { defaultPolicy: 'allow', allowLocalNetwork: true } },\n  { experimental: true },\n);\nconst opts = { experimental: true };\n\nawait startSandbox(sandboxId, undefined, opts);\n\nconst r1 = await execInSandboxAsync(sandboxId, { process: { commandLine: 'echo hello' } }, opts);\nconst r2 = await execInSandboxAsync(sandboxId, { process: { commandLine: 'whoami' } }, opts);\n\nawait stopSandbox(sandboxId, undefined, opts);\nawait deprovisionSandbox(sandboxId, undefined, opts);\n```\n\n`windows_sandbox` follows the same shape (substitute the containment string and provide `filesystem.readwritePaths` / `readonlyPaths` at provision if needed). See [`docs/windows-sandbox/windows-sandbox.md`](https://github.com/microsoft/mxc/blob/main/docs/windows-sandbox/windows-sandbox.md) for the per-phase config matrix.\n\n`wslc` follows the same shape and needs no provision config at all (it defaults to an `alpine:latest` container with no network). Provide `filesystem.readwritePaths` / `readonlyPaths` (mounted for the sandbox's lifetime), `network.defaultPolicy: 'allow'` (a bridged container; the default `'block'` gives no network), and/or a backend-specific `image` / `imageTarPath` at provision; inject a cooperative `network.proxy: { url }` per-exec. WSLc state-aware requests default to schema `0.8.0-alpha`. See [`docs/wsl/wslc-state-aware.md`](https://github.com/microsoft/mxc/blob/main/docs/wsl/wslc-state-aware.md) for the per-phase config matrix.\n\n**Handling failures.** Every lifecycle call rejects with a typed `MxcError`. Branch on `code` first; when the failure came from an underlying platform API, the error also carries discrete diagnostic fields rather than a prose blob:\n\n```typescript\nimport { MxcError } from '@microsoft/mxc-sdk';\n\ntry {\n  await startSandbox(sandboxId, {}, { experimental: true });\n} catch (err) {\n  if (err instanceof MxcError) {\n    if (err.code === 'stale_id') { /* the sandbox is gone -- re-provision */ }\n    console.error(err.message);      // bare, human-readable\n    console.error(err.operation);    // e.g. 'IsoSessionOps.StartSessionAsync'\n    console.error(err.nativeCode);   // e.g. '0x80070490'\n    console.error(err.remediation);  // the API's own fix-it hint, when it supplies one\n  }\n}\n```\n\n`operation`, `nativeCode` and `remediation` are optional. A failure MXC raises before reaching the backend — a malformed request or id, or a policy rejection — carries only `code` and `message`.\n\nThese three are currently populated only by **IsolationSession state-aware** operations. Windows Sandbox has no semantic error channel to derive them from, and the one-shot surface folds the same detail into `message` instead, so they are uniformly absent there — always treat them as optional.\n\nBranch program logic on `code`, which is a closed, versioned union. The *values* of `operation` and `nativeCode` are best-effort diagnostics derived from the underlying platform API and may change without a version bump — use them for telemetry, logging and diagnosis rather than control flow.\n\nFull design and API: [`docs/state-aware-lifecycle/`](https://github.com/microsoft/mxc/tree/main/docs/state-aware-lifecycle/).\n\n</details>\n\n## Policy Discovery Helpers\n\n<details>\n<summary>Auto-enumerate host tools, profile, and temp dirs — click to expand.</summary>\n\nThe SDK ships helpers that enumerate the host environment so your policy stays portable:\n\n```typescript\nimport {\n  getAvailableToolsPolicy, getUserProfilePolicy, getTemporaryFilesPolicy,\n} from '@microsoft/mxc-sdk';\n\nconst tools   = getAvailableToolsPolicy(process.env); // PATH, PYTHONPATH, JAVA_HOME, …\nconst profile = getUserProfilePolicy();               // %LOCALAPPDATA%\\Programs, ~/.local/*\nconst tmp     = getTemporaryFilesPolicy();            // %TEMP% / $TMPDIR\n\nconst policy = {\n  version: '0.6.0-alpha',\n  filesystem: {\n    readonlyPaths: [...tools.readonlyPaths, ...profile.readonlyPaths],\n    readwritePaths: tmp.readwritePaths,\n  },\n  network: { allowOutbound: false },\n};\n```\n\nEach helper returns `{ readonlyPaths, readwritePaths }` — merge what you want into `SandboxPolicy.filesystem`.\n\n</details>\n\n---\n\n## Common Pitfalls\n\n### UI is blocked by default on 0.5.0+ — some shells need it\n\nThe `policy.ui` block is enforced on all supported schema versions, and `policy.ui.allowWindows` defaults to `false`. Most non-interactive command-line tools work fine, but on Windows some shells make win32k system calls during startup and fail without UI access. **All versions of PowerShell are affected** — both Windows PowerShell 5.1 (`powershell.exe`) and PowerShell 7 (`pwsh.exe`). Set `ui.allowWindows: true` when launching a shell:\n\n```typescript\nimport { spawnSandboxFromConfig, createConfigFromPolicy } from '@microsoft/mxc-sdk';\n\nconst config = createConfigFromPolicy({\n  version: '0.6.0-alpha',\n  ui: { allowWindows: true },     // ← required for powershell.exe to start\n});\nconfig.process!.commandLine = 'powershell.exe -NoProfile -Command \"Get-Date\"';\n\nconst child = spawnSandboxFromConfig(config, { usePty: false });\n```\n\n### PTY APIs merge stdout and stderr\n\n`spawnSandbox` and `spawnSandboxAsync` use a PTY, so `stderr` is always empty in their result. Use `spawnSandboxFromConfig(config, { usePty: false })` for separated streams.\n\n### `createConfigFromPolicy` leaves `commandLine` empty\n\nYou must set `config.process!.commandLine = '…'` before calling `spawnSandboxFromConfig`.\n\n### Default-deny applies to everything\n\nNo `network` field → no network. No `readwritePaths` → process can't write `%TEMP%`. No `ui` → no GUI. Use the discovery helpers to compose a sensible baseline.\n\n### `process.cwd` doesn't grant filesystem access\n\nSetting `cwd` (or the `workingDirectory` argument) does **not** add that path to the policy. Add it to `readonlyPaths` / `readwritePaths` explicitly.\n\n---\n\n## Troubleshooting\n\n<details>\n<summary>Common errors and what they mean — click to expand.</summary>\n\n| Error | Cause | Fix |\n| --- | --- | --- |\n| `MXC is not supported on this platform` | `getPlatformSupport()` returned `isSupported: false`. On Linux: neither LXC nor Bubblewrap on PATH. On macOS: schema version < `0.6.0-alpha`. | Install LXC/Bubblewrap, or switch to schema `0.6.0-alpha` (or `0.7.0-alpha` if you need state-aware lifecycle). |\n| `wxc-exec.exe not found` / `lxc-exec not found` | The SDK couldn't locate the native binary. | Set `MXC_BIN_DIR=<dir>` so `<dir>/<arch>/wxc-exec.exe` (or `lxc-exec`) exists, or pass `options.executablePath` explicitly. |\n| `Invalid containment value '<x>'` | `containment` field doesn't match the parser's accepted values. | Use one of the abstract intents (`process`, `vm`, `microvm`) or a concrete backend listed in [Choosing a Backend](#choosing-a-backend). |\n| `'<x>' containment requires experimental mode` | A `windows_sandbox` / `wslc` / `microvm` / `isolation_session` / `hyperlight` backend was selected without the flag. | Pass `{ experimental: true }` in `SandboxSpawnOptions`. |\n| `process.commandLine starts with an unquoted Windows path containing a space` | `wxc-exec` rejects unquoted paths with spaces at parse time. | Quote the executable: `'\"C:\\\\Program Files\\\\…\\\\foo.exe\" args'`. |\n| `Experimental_CreateProcessInSandbox failed: WIN32_ERROR(...)` | Native sandbox API returned an OS-level error, e.g. `448` = device feature not supported (Windows build / WIP feature not enabled). Note `120` (call not implemented / BaseContainer disabled) is now handled automatically — the default `process` backend falls back to AppContainer+DACL, so it no longer surfaces here. | Check the Windows build / WIP requirements for the backend you selected. |\n| Process exits `-1` / `4294967295` with no stdout | Native binary terminated abnormally. | Re-run with `options.debug: true` (or `options.logDir: '<dir>'`) to capture diagnostic logs. |\n| `policy.version '<x>' is older than supported` / `newer than supported` | Version is outside the SDK's accepted range. | Use `0.6.0-alpha`, `0.7.0-alpha`, `0.8.0-alpha`, or `0.9.0-alpha`. See [Compatibility](#compatibility). |\n\nFor backend-specific errors, see the per-backend guide linked from the [Choosing a Backend](#choosing-a-backend) table.\n\n</details>\n\n---\n\n## API Surface\n\n<details>\n<summary>Every export at a glance — click to expand.</summary>\n\n```typescript\n// Spawn — config-based (recommended)\ncreateConfigFromPolicy(policy, containment?, containerName?) → ContainerConfig\nspawnSandboxFromConfig(config, options?, workingDirectory?, env?) → IPty | ChildProcess\n\n// Spawn — convenience (process containment only)\nspawnSandbox(script, policy, options?, workingDirectory?, containerName?, env?) → IPty\nspawnSandboxAsync(script, policy, ...) → Promise<{ stdout, stderr, exitCode }>\n\n// State-aware lifecycle (currently `isolation_session`, `windows_sandbox`, and `wslc` — all Windows-only)\n// `config` on provisionSandbox is required for backends whose provision config\n// has a required member (isolation_session: the network acknowledgment) and\n// optional otherwise (windows_sandbox, wslc).\nprovisionSandbox(containment, config, options?)  → Promise<ProvisionResult>\nstartSandbox(sandboxId, config?, options?)       → Promise<StartResult>\nexecInSandbox(sandboxId, config, options?)       → IPty             // streaming\nexecInSandboxAsync(sandboxId, config, options?)  → Promise<ExecResult>\nstopSandbox(sandboxId, config?, options?)        → Promise<StopResult>\ndeprovisionSandbox(sandboxId, config?, options?) → Promise<DeprovisionResult>\n\n// Platform & policy discovery\ngetPlatformSupport() → PlatformSupport\ngetAvailableToolsPolicy(env?, options?) → FilesystemPolicyResult\ngetUserProfilePolicy()                  → FilesystemPolicyResult\ngetTemporaryFilesPolicy(env?)           → FilesystemPolicyResult\n\n// Capability types\nUiCapabilitySupport\n\n// Errors (typed wire-format errors from wxc-exec)\nErrorCode, MxcError, MxcErrorFields\nmxcErrorFromCode(code, message, details?)   → MxcError\n```\n\nFull TypeScript definitions ship with the package (`dist/index.d.ts`). All exports are named exports from `@microsoft/mxc-sdk`.\n\n</details>\n\n---\n\n## Telemetry Consent\n\nTelemetry is off-by-default unless the caller opts in with top-level `telemetry.enabled: true` and the applicable Windows consent/policy gates permit collection.\n\nTelemetry consent behavior follows\n[`docs/telemetry/telemetry-consent-design.md`](https://github.com/microsoft/mxc/blob/main/docs/telemetry/telemetry-consent-design.md):\nthe SDK stays UI-agnostic, renders the canonical resource verbatim through a\nhost presenter, persists only explicit yes/no decisions, treats dismissal and\nfailures as non-grants, and never lets policy or transport failures opt a user\nin.\n\n### Administrative policy\n\nAn IT administrator can still block MXC telemetry device-wide via MXC's own\nregistry policy setting. See\n[`docs/telemetry/telemetry-administrative-policy.md`](https://github.com/microsoft/mxc/blob/main/docs/telemetry/telemetry-administrative-policy.md)\nfor the stable registry contract and interaction rules.\n\n---\n\n## Further Reading\n\n- [`docs/schema.md`](https://github.com/microsoft/mxc/blob/main/docs/schema.md) — full configuration schema reference\n- [`docs/versioning.md`](https://github.com/microsoft/mxc/blob/main/docs/versioning.md) — schema versioning model and experimental-feature lifecycle\n- [`docs/examples.md`](https://github.com/microsoft/mxc/blob/main/docs/examples.md) — annotated configuration examples\n- [Sandbox policy 0.8.0](https://github.com/microsoft/mxc/blob/main/docs/sandbox-policy/0.8.0/policy.md)\n  — policy specification\n- Backend-specific guides linked in the [Choosing a Backend](#choosing-a-backend) section above.\n\n---\n\n## License\n\n[MIT](https://github.com/microsoft/mxc/blob/main/sdk/node/LICENSE.md). Contributions welcome — see the main [MXC repository](https://github.com/microsoft/mxc).\n","readmeFilename":"README.md"}