You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Adds real-MXC regression coverage for ProcessContainer token isolation, including an unsandboxed SCM positive control, and documents the AppContainer authorization model.
Copy file name to clipboardExpand all lines: docs/reference/gateway-config.mdx
+11Lines changed: 11 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -949,6 +949,17 @@ debug = false
949
949
etw_audit = false
950
950
```
951
951
952
+
The default `pc_least_privilege = false` still runs the workload with an
953
+
AppContainer token. Set it to `true` to request the stricter Less Privileged
954
+
AppContainer (LPAC) variant. Windows AppContainer tokens retain the launching
955
+
account's user SID and group SIDs. Seeing the same username or
956
+
`BUILTIN\\Administrators` in `whoami /all` therefore does not mean the sandbox
957
+
can exercise administrator access: Windows
958
+
requires both the user/group and AppContainer package/capability sides of an
959
+
access check to grant the requested operation. The MXC real-binary integration
960
+
suite verifies `TokenIsAppContainer`, `TokenAppContainerSid`, and denial of a
961
+
non-mutating administrator-gated Service Control Manager open.
962
+
952
963
Set `egress_proxy = true` with `egress_proxy_addr = "127.0.0.1:18080"` to enable the Windows Pattern C split. The address must be a `127.0.0.1:PORT` socket. The driver allocates a unique ephemeral port per sandbox, injects that listener through proxy environment variables, and stages the public proxy CA beneath the sandbox's configured `<cwd>/.openshell-proxy/<sandbox-id>/`. A non-empty per-sandbox `cwd` is therefore required when governed egress is enabled; sandbox-specific subdirectories prevent concurrent sandboxes from overwriting each other's trust files. MXC denies direct Internet egress but allows `127.0.0.1/32`; this permits dynamic forwarding but also means the sandbox can reach unrelated host services bound to loopback.
953
964
954
965
MXC rejects policies containing `network_middlewares` before launch because this host-proxy path does not receive the gateway middleware registry.
0 commit comments