MXC - a sandboxed code execution system
MXC is a sandboxed code execution system designed to run untrusted code on Windows, Linux, and macOS platforms. The system offers various containment backends, ranging from native process sandboxes to full virtual machines, all accessible through a unified model and typed SDKs. As an SDK dependency, MXC can be incorporated into any application, simplifying the process of validating requests, selecting the optimal backend, and launching workloads within a secure environment.
To start using MXC, simply install the corresponding SDK through your package manager. For Node and .NET applications, the packages already include the necessary native runtime assets, while the Rust crate builds the complete SDK, engine, and chosen backends directly into the consuming application. Alternatively, non-SDK consumption is possible by using platform-specific executor binaries like wxc-exec.exe, which accept JSON container-creation requests defined by a stable schema.
These binaries are suitable for testing or situations where embedding the SDK into your application is not feasible.
MXC's primary goal is to ensure secure execution of code within a sandbox environment. However, developers may encounter access issues when running code within the sandbox, particularly during the initial tuning of containment rules. The MXC team is available to assist with these challenges. Native executors typically allocate standard input, output, and error for the workload, so the --debug flag can provide valuable MXC diagnostic output to aid in troubleshooting.
It's essential to note that --audit mode disables all sandbox security for the workload being analyzed, and should never be used to run untrusted code. This mode is intended for policy authors seeking to find access-denied failures and create a ProcessContainer policy that accurately grants the required files and capabilities to trusted tools.
When running in supported Windows releases, MXC records observed accesses and generates policy-authoring artifacts, streamlining the process of creating safe deny-and-record diagnostics and audit outputs.
For Windows users, MXC can optionally send diagnostic telemetry to Microsoft. However, this feature is disabled by default and only activated under certain conditions, such as explicit user consent, administrative policy permitting, and application-level configuration. Open-source builds of MXC are not configured to send telemetry to Microsoft, and telemetry is a no-op on non-Windows platforms.
Detailed information about telemetry policy and consent can be found in dedicated documentation. To develop MXC, modify the native runtime, or utilize the standalone executor binaries instead of a packaged SDK, it is recommended to build from source. The MXC development repository provides comprehensive documentation and contribution guidelines for repository contributors.
Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.