Skip to content

docs(mxc): add missing demo examples for runbook and mTLS scenario - #3659

Merged
shailendra-nv merged 2 commits into
windowsfrom
add/mxc-examples-missing-files
Oct 1, 2026
Merged

shailendra-nv merged 2 commits into
windowsfrom
add/mxc-examples-missing-files

Conversation

@pkhodade-NV

@pkhodade-NV pkhodade-NV commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Restore the missing MXC filesystem-enforcement runbook and mTLS control-channel scenario.
  • Align both examples with the current schema-v2 gateway configuration and per-sandbox mxc driver configuration.
  • Make the mTLS runner safe for an existing workstation by isolating CLI state, choosing a free loopback port, and stopping only the gateway process it launches.
  • Add drift guards for the shipped assets, current MXC contract, state-safety requirements, and PowerShell syntax.

Related Issue

No issue required — localized repair of missing example assets and their current runtime contract.

Changes

  • Update README-mtls.txt with the mock-backed workflow, state-safety guarantees, and optional binary/output paths.
  • Rework run-mtls-test.ps1 to generate a valid schema-v2 MXC configuration, use the in-process mock, isolate persistent state, and avoid terminating unrelated processes.
  • Replace obsolete gateway-level workload fields in mxc-demo-runbook.md with current --driver-config-json examples and document the backend filesystem constraints.
  • Add tests/mtls_examples.rs to prevent the examples from drifting back to removed fields or unsafe state/process handling.

Testing

Check Result
ARM64 Windows check Passed
ARM64 release build Passed; gateway, CLI, supervisor relay, and libz3.dll produced
Corrected run-mtls-test.ps1 against the release binaries Passed; certified CLI list RPC succeeded and a no-cert client was rejected
cargo test -p openshell-driver-mxc --test mtls_examples -- --nocapture 4 passed, 0 failed
ARM64 Windows pre-commit nextest lane 5,024 passed, 29 skipped, 0 failed
ARM64 unsupported/selective-driver contract lane 10 passed across six feature configurations, 0 failed
Real-MXC ignored integration lane 14 passed (including two skip-safe capability probes), 1 failed: the pre-existing HTTPS proxy test received HTTP 403 for example.com; a focused retry reproduced it
Rust clippy, Rust formatting, Markdown/Mermaid, protobuf lint, SPDX, and Ruff checks Passed
Aggregate mise run pre-commit Host-toolchain blocked: Biome 2.5.4 crashes on Windows ARM64 with 0xC0000005, and Python 3.14 ARM64 cannot build grpcio-tools because MSVC receives both /std:c++17 and /std:c11; applicable checks above were rerun independently

Checklist

  • Conventional Commits messages
  • DCO sign-off on both commits
  • No production code or dependency changes
  • Local ARM64 Windows build and required test lane completed

Add three files present in the internal mirror but absent from the
Windows branch:

- mxc-demo-runbook.md: operator runbook for the MXC demo kit
- README-mtls.txt: usage notes for the mTLS scenario
- run-mtls-test.ps1: PowerShell test runner for the mTLS scenario

These are required by the package-demo.ps1 packager script and are
referenced by the mxc-kit documentation.

No issue required: mechanical sync of missing demo assets.

Signed-off-by: Prashant Khodade <pkhodade@nvidia.com>
@copy-pr-bot

copy-pr-bot Bot commented Sep 24, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@shailendra-nv shailendra-nv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes for four blocking issues:

  • The documented clean mTLS flow cannot start the current MXC driver because it supplies no gateway configuration or wxc-exec path.
  • The runner can force-stop an unrelated gateway process.
  • The runner overwrites/removes persistent CLI registration and mTLS state without restoring it.
  • The runbook targets an obsolete MXC configuration/runtime contract.

Static diff checks and PowerShell parsing passed. The visible GitHub checks are green, but the PR's package-demo validation remains unchecked and there is no Windows x64/ARM64 runtime validation covering these flows.

Comment thread crates/openshell-driver-mxc/examples/run-mtls-test.ps1 Outdated
Comment thread crates/openshell-driver-mxc/examples/run-mtls-test.ps1 Outdated
Comment thread crates/openshell-driver-mxc/examples/run-mtls-test.ps1 Outdated
Comment thread crates/openshell-driver-mxc/examples/mxc-demo-runbook.md Outdated
Signed-off-by: Shailendra Singh <shailendras@nvidia.com>

@shailendra-nv shailendra-nv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-reviewed at 0e988ad. All four requested changes are addressed: valid mock-backed MXC startup, test-owned process cleanup, isolated CLI state, and a current process_container runbook. The ARM64 required lane passed 5,024 tests with 29 skips; the focused example guards passed 4/4. No remaining actionable findings.

@shailendra-nv

Copy link
Copy Markdown
Collaborator

/ok

@shailendra-nv

Copy link
Copy Markdown
Collaborator

/ok to test 0e988ad

@shailendra-nv
shailendra-nv merged commit d1ae20a into windows Oct 1, 2026
63 checks passed
@shailendra-nv
shailendra-nv deleted the add/mxc-examples-missing-files branch October 1, 2026 17:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants