HN
Today

MXC - a sandboxed code execution system

Microsoft has open-sourced MXC, a policy-driven, cross-platform sandboxing system designed for untrusted code, generating significant interest among developers looking to secure AI agents and plugins. The Hacker News crowd praises its practical features like audit modes and unified SDKs, while also debating the inherent complexity and questioning the proliferation of similar sandboxing solutions in the ecosystem. This release highlights the growing need for robust containment in modern software development.

121
Score
58
Comments
#3
Highest Rank
14h
on Front Page
First Seen
Oct 9, 8:00 AM
Last Seen
Oct 9, 9:00 PM
Rank Over Time
6435691415131317242626

The Lowdown

Microsoft's new open-source project, MXC (Microsoft eXecution Container), offers a sandboxed environment for running untrusted code across Windows, Linux, and macOS. Designed to encapsulate model outputs, plugins, and tools, MXC aims to provide a unified containment model, leveraging platform-native sandboxes from ProcessContainer to LXC and Bubblewrap.

Key features include:

  • Cross-platform Compatibility: Supports Windows, Linux, and macOS with appropriate backend integration.
  • Policy-Driven Sandboxing: Granular control over filesystem access (read-only, read-write, denied paths), network policies (egress, proxy support), and UI interactions (clipboard, display).
  • Multiple Containment Backends: Integrates with various existing sandboxing technologies like Windows Sandbox, LXC, Bubblewrap, and Seatbelt.
  • SDKs for Developers: Provides Rust, .NET, and Node.js SDKs for seamless integration into applications, supporting both one-shot and state-aware execution.
  • Diagnostic Tools: Includes debug and audit modes to help developers understand access-denied failures and tune policies without compromising security.
  • Optional Telemetry: Clearly outlines its opt-in telemetry policy, emphasizing user control and privacy.

MXC positions itself as an SDK dependency that applications can build upon, validating requests, selecting suitable backends, and launching workloads in isolated containers. This approach promises a more secure and controlled environment for executing potentially risky code within larger applications.

The Gossip

Praising Practical Protections

Many users expressed positive surprise and appreciation for MXC, highlighting its practical utility in abstracting complex sandboxing mechanisms. The 'learning' or 'audit' mode, which helps discover necessary permissions, received particular praise as a valuable diagnostic tool. Commenters noted the clear optional telemetry disclosures and the project's MIT license as further positives, seeing it as a high-quality initial release despite Microsoft's general reputation.

Tweaking Technical Details

While largely positive, some technically astute users pointed out potential areas for improvement or concern. Critiques included the build process of the Rust SDK, which bundles binaries and performs Windows-specific work on all platforms, and a perceived dependency-heavy nature. A specific limitation highlighted was the lack of fine-grained network policies for macOS compared to Windows and Linux, attributing this to the challenges of abstracting disparate underlying technologies.

A Proliferation of Protection Platforms

A significant theme was the observation that 'everyone is building the same thing' in the sandboxing space, especially for AI agents. Commenters compared MXC to numerous existing or emerging solutions like smolvm, wasmtime, OpenShell, and even proposed a need for a unified sandboxing policy design. This led to discussions on the difficulty of porting between different systems and the potential for increased vulnerabilities due to fragmented approaches, while others argued that diverse use-cases necessitate different solutions.

Scrutinizing Sandbox Security

Some users voiced strong skepticism, both about the project's security and Microsoft's involvement. One commenter explicitly claimed to have found a 'sandbox escape' in MXC and its underlying bubblewrap component, although others requested evidence for these serious allegations. There was also a general wariness, with some users quickly dismissing the project due to its Microsoft origin or questioning the necessity of such complexity for common development scenarios, preferring simpler solutions or established security models like SELinux.