Microsoft eXecution Container (MXC) is a sandboxed code execution system designed to run untrusted code such as model outputs, plugins, and tools across Windows, Linux, and macOS. It provides a unified containment model with multiple backend options, including OS-native sandboxes and full VMs, accessible via Rust, . NET, and Node SDKs.
MXC uses JSON-based configuration for versioned container creation and security policies, enabling fine-grained control over filesystem, network, and UI access. Supported backends include Process Container, Windows Sandbox, LXC, Bubblewrap, Seatbelt, MicroVM (Nanvix), Hyperlight, Isolation Session, and WSLC, with some marked as experimental. The system provisions containers through a lifecycle of provision, start, execute, stop, and deprovision, supporting both one-shot and state-aware workloads.
Developers specify container type, containment rules, and workload commands, which MXC validates before launching the isolated environment. Diagnostic tools help troubleshoot access-denied failures, while audit mode assists in policy development by logging observed accesses—though it disables security and should not be used with untrusted code. MXC SDKs are available via package managers (crates.io, NuGet, npm), and native executors like wxc-exec.exe allow non-SDK usage for testing or embedding limitations.
The platform emphasizes policy-driven sandboxing to balance security and usability in development workflows.
Source: Hacker News · Summarized by HeadlinesBriefing