## What changed
- Probe whether the native Windows MXC process security environment is usable
when selecting a sandbox.
- Emit `codex.windows_mxc.available` at most once per process, labeled with the
probe result.
- Add the MXC workspace dependencies for Cargo and Bazel, and pin
`tracelogging` to a version compatible with the GNU Windows toolchain.
GitOrigin-RevId: d7cfeed6f0333feda5764e1ee44fe5bbd50f9a58