Skip to content
7 changes: 7 additions & 0 deletions docs/backends/process-container/networking.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,13 @@ narrows the outbound public and private destinations reachable through the grant
| `allow` | `allow` | Both capabilities | Internet outbound and bidirectional private-network traffic are allowed. |

This matrix covers the direction defaults without explicit internet egress rules or proxy mode.
It describes the ordinary non-capture capability posture. Native PSEC
`captureDenials` temporarily adds `internetClient` only when the option-aware
trace collects network decisions and the caller explicitly supplies a direct
`network.egress` section, allowing Tessera's WFP policy to observe and record
the attempt while the authored egress table continues to enforce it. Legacy
access-only capture, absent or ingress-only network policy, non-capture
runs, and proxy mode retain the matrix posture.

### Model 1: direct egress, WFP-filtered (least restrictive)

Expand Down
22 changes: 22 additions & 0 deletions docs/backends/process-container/os-version-support.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,3 +10,25 @@ This is the reference for **Windows OS support of the `processcontainer` and `is
| 25H2 | [26200.9278](https://support.microsoft.com/en-us/servicing/os/windows-11/2026/08/kb5120998-windows-11-24h2-25h2-update) | [26200.9550](https://support.microsoft.com/en-us/servicing/os/windows-11/2026/09/kb5124010-windows-11-24h2-25h2-update) |
| 26H2 | [26300.9550](https://support.microsoft.com/en-us/servicing/os/windows-11/2026/09/kb5124010-windows-11-24h2-25h2-update) | [26300.9550](https://support.microsoft.com/en-us/servicing/os/windows-11/2026/09/kb5124010-windows-11-24h2-25h2-update) |
| 26H1 | [28000.2804](https://support.microsoft.com/en-us/servicing/os/windows-11/2026/08/kb5120996-windows-11-26h1-update) | [28000.3086](https://support.microsoft.com/en-us/servicing/os/windows-11/2026/09/kb5124006-windows-11-26h1-update) |

## Learning Mode capture compatibility

`processContainer.captureDenials` selects its capture provider by runtime
capability probing rather than by the release table above. Native
ProcessContainer capture requires the PSEC create/query/close exports plus one
compatible Learning Mode start export and both lifecycle exports:

- `StartLearningModeTraceWithOptions` (preferred) or `StartLearningModeTrace`
- `StopLearningModeTrace`
- `CloseLearningModeTrace`

The option-aware start collects access and network events. The legacy start
collects access events only, so its trace cannot contain WFP network decisions.
If the selected option-aware call fails, MXC reports that failure and does not
retry through the legacy export. When native capture is unavailable, MXC uses
the guarded WPR provider only when the selected AppContainer tier and helper can
fully honor the request.

Internal validation found no native capture support on build `26657.1002` and
the complete option-aware contract on build `26663.1000`. These are validation
points, not public support boundaries; runtime probing remains authoritative.
17 changes: 10 additions & 7 deletions docs/development/architecture/telemetry.md
Original file line number Diff line number Diff line change
Expand Up @@ -200,13 +200,16 @@ Emitted on execution errors.

Emitted when a telemetry-enabled ProcessContainer run successfully produces a
Learning Mode `captureDenials` verbose logging artifact. MXC reads the
versioned `*.verbose.json` sibling, validates it as a
`VerboseLoggingDocument`, derives each provider GUID from the document's
closed provider enum, drops every verbose property name and value and the
schema name, sums the counts of signatures that become identical, and
serializes that telemetry-specific projection as compact JSON. The event never
contains the actionable denials file, raw ETL, commands, sandbox output, or
general logger text.
versioned `*.verbose.json` sibling and dispatches document versions 3, 4, and 5
to their separate closed schemas. It rejects cross-version or unknown
vocabulary, derives each provider GUID from the version's closed provider
vocabulary, removes schema `eventName`, every verbose property name and value,
and structured network endpoints, then regroups signatures that become
identical and sums their counts before compact serialization. Version 5
retains the WFP provider and its closed typed reason and
configuration-recommendation fields. Unsupported document versions are
rejected. The event never contains the actionable denials file, raw ETL,
commands, sandbox output, or general logger text.

One verbose document may require multiple ETW events. Every `mxc.content`
value is an independently parseable compact JSON array of complete verbose
Expand Down
Loading