microsoft/mxc

▲ 135 stars today★ 1,701⑂ 103

Policy-driven, layered isolation and containment

About microsoft/mxc

microsoft/mxc is an open-source project on GitHub, mainly written in Rust. Policy-driven, layered isolation and containment It currently holds 1,701 stars and 103 forks with 52 open issues, and was last pushed on 2026-10-08 (repository created 2026-02-06).

Project Overview

Git Homed tracks it on the Today's Trending board, currently at rank #35 with 135 new stars today.

GitHub Repository Details

Repository microsoft/mxc · default branch main · size 37770 KB · watchers 8 · source: GitHub REST API and repository README

README

Microsoft eXecution Container (MXC)

MXC is a sandboxed code execution system for running untrusted code (model output, plugins, and tools) on Windows, Linux, and macOS. It provides multiple containment backends, from OS-native process sandboxes to full VMs, behind a unified containment model and typed SDKs.

Features

platform-appropriate containment backends security policies Bubblewrap, Seatbelt, MicroVM (Nanvix), Hyperlight, IsolationSession, and WSLC host filtering persistent containers execution

What is MXC?

MXC is an SDK dependency that builds into your app.

flowchart LR
    App["Your application
Launch API"] --> SDK["MXC SDK
Rust / .NET / Node
(in process)"] SDK --> Backend["Selected backend
(in process)"] Backend --> Container["Isolated workload
ProcessContainer / WSLC / Bubblewrap / ..."]

Your application specifies:

MXC validates the request, selects the backend, and launches the workload in the resulting container.

What container types are supported?

MXC runs workloads through platform-appropriate container backends on Windows, Linux, and macOS.

| Runtime platform | Default backend | Other backends | Minimum host OS | |---|---|---|---| | Windows 11 x64 / ARM64 | processcontainer | windows_sandbox\, wslc, microvm\, hyperlight\*, isolation_session | Windows OS-version support| | Linux x64 / ARM64 | bubblewrap | lxc, microvm, hyperlight | - | | macOS ARM64 / x64 | seatbelt | - | - |

\* These backends are experimental.

How do I use MXC?

Install an SDK through your package manager. You do not need to clone this repository.

| SDK | Package | |---|---| | Rust | https://crates.io/crates/mxc-sdk | | .NET | https://www.nuget.org/packages/Microsoft.Mxc.Sdk | | Node | https://www.npmjs.com/package/@microsoft/mxc-sdk |

The Node and .NET packages include the native runtime assets. The Rust crate builds the MXC SDK, engine, and selected backends into the consuming application.

Non-SDK consumption: Platform-specific executor binaries, such as wxc-exec.exe, accept JSON container-creation requests defined by the stable schema. Use for testing or when the SDK cannot be embedded in your app.

Running a contained workload

For complete SDK samples, see the Rust, .NET, and Node samples.

Sample Node snippet

import { spawn, type ContainerRequest } from '@microsoft/mxc-sdk/v1';

const request: ContainerRequest = { command: 'node -e "console.log(\'hello from container\')"', network: { egress: { default: 'deny' } }, timeoutMs: 30_000, };

const child = await spawn(request);

See the runnable streaming standard-I/O sample and the SDK API reference.

My application won't run in the sandbox!

Your application will hit access issues when running in a sandbox, until you've had time to tune your containment rules. We're here to help.

Debug console mode

Native executors normally reserve standard input, output, and error for the workload. Use --debug for MXC diagnostic output:

wxc-exec.exe --debug config.json

See MXC diagnostics for the complete developer reference.

Audit mode

Warning: --audit turns off all sandbox security for the workload being
analyzed. Never use it to run untrusted code.

Audit mode helps a policy author find access-denied failures and reconstruct a ProcessContainer policy that grants the files and capabilities a trusted tool actually needs. On supported Windows releases, run:

wxc-exec.exe --audit policy.json

MXC records the observed accesses and produces policy-authoring artifacts. See logging access denied for safe deny-and-record diagnostics, audit outputs, and supported workflows.

Telemetry

Official Microsoft builds can send optional diagnostic telemetry to Microsoft. Telemetry is off unless the individual run opts in, the Windows user has explicitly consented, administrative policy permits collection, and your application enables the telemetry option in a contained workload request. An administrator can block telemetry but cannot grant consent for the user.

Local open-source builds are not configured to route telemetry to Microsoft, and telemetry is a no-op on non-Windows platforms. See telemetry policy and consent for controls and privacy details.

Building from source

Build from source when developing MXC, changing the native runtime, or using the standalone executor binaries instead of a packaged SDK. Repository builds produce the platform-native runtime and executors and stage the native assets used by the Node SDK.

Build prerequisites are:

src/rust-toolchain.toml

Build

Windows

build.bat --all             # Release build for current architecture

Linux

./build.sh --all            # Release build

macOS

./build-mac.sh --all        # Release build for native architecture

Documentation

Consumer documentation

| Document | Repository location | Purpose | |---|---|---| | SDK samples | samples/ | Runnable Rust, .NET, and Node scenarios | | SDK API reference | docs/api-reference/ | Supported V1 operations and types | | Container lifecycle | docs/container-lifecycle.md | Persistent container lifecycle overview | | Logging access denied | docs/logging-access-denied.md | Diagnose blocked accesses and author policy | | Telemetry | docs/telemetry.md | Consent and administrative controls | | Backend guides | docs/backends/ | Platform and backend prerequisites and behavior |

Repository contributors should start with the MXC development documentation.

Contributing

See CONTRIBUTING.md for contribution guidelines.

License

See LICENSE.md for details.

GitHub Stars & Activity

1,701Stars
103Forks
52Open issues
RustLanguage

GitHub Popularity

GitHub stars1,701
Forks103
Open issues52
Primary languageRust
LicenseMIT
Stars gained today135
Created2026-02-06
Last pushed2026-10-08

Trending History

Daily boardrank #35 · ▲ 135 stars

Related GitHub Projects

1

vercel-labs / agent-browser

Rust★ 43,685⑂ 2,960▲ 69 stars
→
2

ajeetdsouza / zoxide

Rust★ 39,981⑂ 920▲ 30 stars
→
3

emilk / egui

Rust★ 31,042⑂ 2,172▲ 67 stars
→
4

AprilNEA / OpenLogi

Rust★ 23,171⑂ 775▲ 102 stars
→
5

akitaonrails / ai-memory

Rust★ 9,056⑂ 628▲ 123 stars
→
6

storytold / artcraft

Rust★ 7,892⑂ 1,103▲ 2,103 stars
→
7

martin-olivier / airgorah

Rust★ 3,963⑂ 685▲ 101 stars
→
8

HakanSeven12 / OpenCADStudio

Rust★ 2,550⑂ 273▲ 32 stars
→

More Trending Repositories