Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
49 commits
Select commit Hold shift + click to select a range
09afd57
Bridge netfilter enabled
theelliotm Aug 17, 2026
56a1402
adding host forwarding
theelliotm Aug 17, 2026
a668c36
NAT tests lxc
theelliotm Aug 18, 2026
f6a5af1
Remove strict mode issues ; made LXC more honest with failures
theelliotm Aug 18, 2026
6c8c833
testing scaleset
theelliotm Aug 18, 2026
fbef27d
scaleset isn't supported yet
theelliotm Aug 18, 2026
cfaa550
create test file that wslc test script expects
theelliotm Aug 18, 2026
1ce43fd
stagger WSLC jobs
theelliotm Aug 18, 2026
c6aad16
log upload should now include all windows logs
theelliotm Aug 18, 2026
a2bf450
removed math in yml
theelliotm Aug 18, 2026
87fc7bb
Simpler way to collect logs
theelliotm Aug 18, 2026
4902c42
reducing time between wslc jobs to 45 seconds to avoid idle agent fro…
theelliotm Aug 18, 2026
ecff441
Making PR ready
theelliotm Aug 18, 2026
d6ebe7c
Document backendDelayedStart and the CI TEMP redirect
theelliotm Aug 18, 2026
40055f1
Merge remote-tracking branch 'origin/main' into user/emichlin/validat…
theelliotm Aug 18, 2026
2d6df7e
removing old comments
theelliotm Aug 18, 2026
233dc19
updating backend status in docs
theelliotm Aug 18, 2026
02140c5
isolation session test
theelliotm Aug 20, 2026
24c7d28
isolation session test
theelliotm Aug 20, 2026
bc34892
Merge branch 'user/emichlin/validation-infra-3' of https://github.com…
theelliotm Aug 20, 2026
c613b26
Added bubblewrap slirp4netns prereq
theelliotm Aug 20, 2026
b04cd3a
added additional bubblewrap prereqs
theelliotm Aug 20, 2026
14553bf
cleaning up for PR
theelliotm Aug 20, 2026
7e09f72
testing wsl install during image provision
theelliotm Aug 24, 2026
ff8ff5f
migrate ci scripts into ci folder, and updated artifact script (to be…
theelliotm Aug 25, 2026
e455194
Merge remote-tracking branch 'origin' into user/emichlin/validation-i…
theelliotm Aug 26, 2026
1756ccf
testing new wslc artifact on all windows versions
theelliotm Aug 26, 2026
c5964a2
corrected arm64 support for canary
theelliotm Aug 26, 2026
9ad0130
Added T3-workloads.ps1 to tests
theelliotm Aug 26, 2026
d46ab36
fixed installed interpreter requirements
theelliotm Aug 26, 2026
dd932a1
added TEMPORARY path grant for tests that need $temp access. remove w…
theelliotm Aug 27, 2026
dfed48b
Add optional parameter to T3-Workloads script. Splitting macos and li…
theelliotm Aug 27, 2026
9cfaf8a
fix git repo ownership errors
theelliotm Aug 27, 2026
2c2253e
expanded list of asserted interpreters
theelliotm Aug 27, 2026
26fba6f
preparing windows/linux by now installing packages on linux and winge…
theelliotm Aug 28, 2026
8aec188
fix bwrap script regression and azure cli not resolving on debian sys…
theelliotm Aug 28, 2026
76d547f
testing pre-provisioning linux packages
theelliotm Aug 31, 2026
e8a7b34
testing macos image pre-provision status
theelliotm Aug 31, 2026
1523def
test new windows provisioning script
theelliotm Sep 1, 2026
760c9a0
testing 25H2 fully provisioned
theelliotm Sep 2, 2026
a18d953
Merge remote-tracking branch 'origin' into user/emichlin/validation-i…
theelliotm Sep 2, 2026
f18d4dd
linux no longer installs workload interpreters during the job.
theelliotm Sep 2, 2026
4293730
Testing nightly plan before PR
theelliotm Sep 2, 2026
b8410c6
remove infrastructure testing yml
theelliotm Sep 2, 2026
8cd7686
fix minor bugs
theelliotm Sep 2, 2026
b8532aa
Merge branch 'main' into user/emichlin/validation-infra-3
theelliotm Sep 3, 2026
ef8780b
Fixed duplicated docs
theelliotm Sep 3, 2026
1d00419
condensed copilot instructions and addressed PR feedback
theelliotm Sep 8, 2026
3b8701f
Update backend preparation and validation instructions
theelliotm Sep 8, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
78 changes: 28 additions & 50 deletions .github/copilot-instructions.md
Original file line number Diff line number Diff line change
Expand Up @@ -52,53 +52,30 @@ parallel, then to the lint / versioning / SDK jobs.

**Validation (E2E) test infrastructure.** Fully documented in
[`docs/ci-validation-infrastructure.md`](../docs/ci-validation-infrastructure.md)
(matrix contents, job names, per-backend coverage and status, and the runbook
for adding/removing an OS, backend, or plan). Backend E2E tests run from those
same build artifacts β€” never from a fresh build β€” so artifact production and
consumption stay in one workflow run:

- `.github/workflows/Validation.Tests.Scheduled.yml` β€” scheduled entry point.
The `nightly` plan runs Mon–Sat; Sunday runs `nightly` *and* `weekly`.
`workflow_dispatch` takes a `plan` input to run one on demand.
β€” read it before changing any of the pieces below. Backend E2E tests run from
the build artifacts, never from a fresh build, so an entry point must call the
three `Build.*.Job.yml` workflows before calling the matrix job.

- `.github/workflows/Validation.Tests.Scheduled.yml` β€” scheduled entry point
(`nightly` Mon–Sat, `nightly` + `weekly` on Sunday); `workflow_dispatch`
takes a `plan` input.
- `.github/workflows/Validation.Tests.Matrix.Job.yml` β€” workflow-call-only,
takes a `plan` input. Its `resolve` job expands the plan into per-family
matrices, then the `windows` / `linux` / `macos` jobs each download the
artifact, prepare the host, and run the backend suite.

An entry point must build the artifacts (call the three `Build.*.Job.yml`
workflows) before calling the matrix job.

**The matrix is declarative:**

- `scripts/ci/validation-test-matrix.json` is the catalog: `platforms` (each
with per-architecture target/artifact/1ES pool and the backends that platform
supports), `triggers` (which OS/backend pairs each plan runs), and the
optional `backendDelayedStart` (per-backend job-start stagger, in seconds).
The `triggers` keys *are* the plan list β€” the resolver reads them at run time,
so adding a plan needs no script change.
- `scripts/ci/resolve-validation-test-matrix.mjs` validates that catalog and
expands a plan (currently `pr`, `nightly`, `weekly`, `enabled`) into GitHub
Actions matrices. It rejects an invalid catalog before any specialized test
runner is allocated, so add a backend to a trigger only where the platform
declares it.
- A non-macOS platform architecture with an empty `pool` is never scheduled,
which is how a catalog entry stays declared but dormant. macOS entries use a
GitHub-hosted `runner` instead of a 1ES `pool`.

**Host preparation** happens in the matrix job before the tests, keyed by the
matrix `backend` id: `scripts/ci/prepare-windows-host.ps1` and
`scripts/ci/prepare-linux-host.sh`. A backend with no prerequisites is an
explicit no-op, so the step runs unconditionally for every entry.

**Test dispatch** goes through `tests/scripts/run_ci_backend_tests.ps1`
(Windows) and `tests/scripts/run_ci_backend_tests.sh` (Linux/macOS), which map
the matrix `backend` id to the repository's existing backend suite. Ids that
share a suite get their own case (`process-t1` and `process-t3` both run
`WinProcessContainer-Tests.ps1`, which derives the tier it expects from the
host's own `--probe`). A backend with no wired suite fails loudly rather than
reporting a false success. The Windows dispatcher points `TEMP` at
`$RUNNER_TEMP` before running a suite, so anything a test writes to the temp
directory is picked up by the job's log upload without per-file CI wiring.
takes a `plan`. Its `resolve` job expands the plan into per-family matrices;
the `windows` / `linux` / `macos` jobs then download the artifact, prepare
the host, and run the backend suite.
- `scripts/ci/validation-test-matrix.json` β€” the declarative catalog
(`platforms`, `triggers`, `backendDelayedStart`). Its `triggers` keys *are*
the plan list. `scripts/ci/resolve-validation-test-matrix.mjs` validates the
catalog and expands a plan, so a backend may only be triggered where its
platform declares it.
- `scripts/ci/prepare-{windows,linux,macos}-host.{ps1,sh}` β€” per-backend host
prep, plus an inventory of the workload interpreters. Backend prerequisites
are installed per job; most workload interpreters come from image provisioning
scripts outside this repository, while Windows prep installs packaged `winapp`
and OpenSSL per job.
- `scripts/ci/run_backend_validation_tests.{ps1,sh}` β€” map a matrix `backend`
id to the repository's existing backend suite. An unwired id fails loudly
rather than reporting a false success.

### Individual components

Expand Down Expand Up @@ -151,19 +128,20 @@ tests\scripts\run_windows_sandbox_one_shot_tests.ps1 # Windows Sandbox one
tests\scripts\run_windows_sandbox_state_aware_tests.ps1 # Windows Sandbox state-aware lifecycle E2E (provision/start/exec*/stop/deprovision; requires the Windows Sandbox optional feature; skips if absent)
tests\scripts\run_lxc_all_tests.sh # All LXC tests (Linux)
tests\scripts\run_bwrap_all_tests.sh # All Bubblewrap tests (Linux, requires bwrap). Must NOT run as root β€” several tests assert the sandbox drops capabilities, which cannot hold under a root launcher; the script refuses root explicitly.
sudo tests\scripts\run_bwrap_inbound_deny_test.sh # Bubblewrap inbound default-deny E2E (root-only: needs host CAP_NET_ADMIN to read the sandbox netns and inject a peer). Reported as skipped by the suite above; CI runs it separately from run_ci_backend_tests.sh.
sudo tests\scripts\run_bwrap_inbound_deny_test.sh # Bubblewrap inbound default-deny E2E (root-only: needs host CAP_NET_ADMIN to read the sandbox netns and inject a peer). Reported as skipped by the suite above; CI runs it separately from run_backend_validation_tests.sh.

# E2E test crate β€” Rust executor integration tests (from src/)
cargo test -p wxc_e2e_tests # Invokes MXC binaries directly
cargo test -p wxc_e2e_tests -- --ignored # Include stress tests (run_on_repeat)

# WSLC has no cargo E2E suite β€” it is covered by tests\scripts\run_wslc_all_tests.ps1,
# which the validation matrix runs via tests\scripts\run_ci_backend_tests.ps1.
# which the validation matrix runs via scripts\ci\run_backend_validation_tests.ps1.

# CI validation entry points β€” run a backend suite against a downloaded artifact
# the way the validation matrix does. Take the matrix backend id exactly as it
# appears in scripts/ci/validation-test-matrix.json.
tests\scripts\run_ci_backend_tests.ps1 -Backend process-t1 -BinaryDirectory <dir> -Architecture x64
tests\scripts\run_ci_backend_tests.sh <bubblewrap|lxc|seatbelt> <binary-directory>
scripts\ci\run_backend_validation_tests.ps1 -Backend process-t1 -BinaryDirectory <dir> -Architecture x64
scripts\ci\run_backend_validation_tests.sh <bubblewrap|lxc|seatbelt> <binary-directory>

# Resolve a plan locally to see exactly what CI would schedule
node scripts/ci/resolve-validation-test-matrix.mjs --plan nightly
Expand Down
19 changes: 14 additions & 5 deletions .github/workflows/Validation.Tests.Matrix.Job.yml
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,7 @@ jobs:
timeout-minutes: 45
shell: pwsh
run: |
& ./tests/scripts/run_ci_backend_tests.ps1 `
& ./scripts/ci/run_backend_validation_tests.ps1 `
-Backend '${{ matrix.backend }}' `
-BinaryDirectory (Join-Path $env:GITHUB_WORKSPACE 'artifacts\bin') `
-Architecture '${{ matrix.architecture }}' *>&1 |
Expand Down Expand Up @@ -147,11 +147,11 @@ jobs:
run: |
set -euo pipefail
if [[ '${{ matrix.backend }}' == 'lxc' ]]; then
sudo --preserve-env=RUNNER_TEMP bash tests/scripts/run_ci_backend_tests.sh \
sudo --preserve-env=RUNNER_TEMP bash scripts/ci/run_backend_validation_tests.sh \
'${{ matrix.backend }}' "$GITHUB_WORKSPACE/artifacts/bin" 2>&1 |
tee -a "$RUNNER_TEMP/mxc-ci.log"
else
bash tests/scripts/run_ci_backend_tests.sh \
bash scripts/ci/run_backend_validation_tests.sh \
'${{ matrix.backend }}' "$GITHUB_WORKSPACE/artifacts/bin" 2>&1 |
tee -a "$RUNNER_TEMP/mxc-ci.log"
fi
Expand Down Expand Up @@ -195,15 +195,24 @@ jobs:
echo "Waiting $seconds second(s) before starting tests."
sleep "$seconds"

- name: Prepare backend prerequisites
timeout-minutes: 15
shell: bash
run: |
set -euo pipefail
bash scripts/ci/prepare-macos-host.sh \
'${{ matrix.backend }}' "$GITHUB_WORKSPACE/artifacts/bin" 2>&1 |
tee "$RUNNER_TEMP/mxc-ci.log"

- name: Run backend tests
timeout-minutes: 60
shell: bash
run: |
set -euo pipefail
chmod +x artifacts/bin/mxc-exec-mac artifacts/bin/unix-test-proxy
bash tests/scripts/run_ci_backend_tests.sh \
bash scripts/ci/run_backend_validation_tests.sh \
'${{ matrix.backend }}' "$GITHUB_WORKSPACE/artifacts/bin" 2>&1 |
tee "$RUNNER_TEMP/mxc-ci.log"
tee -a "$RUNNER_TEMP/mxc-ci.log"

- name: Upload logs
if: always()
Expand Down
Loading
Loading