Skip to content

CLI: Global option scopes for nested commands (related to compose support) - #41546

Merged
David Bennett (dkbennett) merged 24 commits into
masterfrom
user/dkbennett/globaloptionrefactor
Sep 16, 2026
Merged

David Bennett (dkbennett) merged 24 commits into
masterfrom
user/dkbennett/globaloptionrefactor

Conversation

@dkbennett

@dkbennett David Bennett (dkbennett) commented Sep 9, 2026 •

Copy link
Copy Markdown
Member

Summary of the Pull Request

Adds command-scoped global options to the WSLC CLI.

Global options are accepted after the command that declares them and are inherited by its descendants:

wslc --session foo compose --progress plain up

The command model is now a persistent, lazily populated tree with stable parent references. CommandInvocation owns that tree and the lifecycle of one invocation, including the original arguments, parsing cursor, selected command, parsing, environment option application, execution, and error help. CLIExecutionContext remains separate and owns parsed values and execution services.

Commands declare command-local and global arguments separately through GetArguments() and GetGlobalArguments(). Global arguments retain their declaring command through Argument::GlobalOwner(), and Argument::Scope() derives whether an argument is global or command-local from that ownership. All parsed values share CLIExecutionContext::Args.

Argument source restrictions are represented by the composable argument::Flags bitmask in ArgumentOverrides. Flags::EnvironmentOnly arguments participate in environment loading and validation, but are excluded from command-line parsing and help. Environment bindings for ordinary arguments remain inert, so an argument must explicitly opt into environment-only behavior.

Help groups global options by their declaring command so users can see where each option must be specified:

Global Options for 'wslc':
Global Options for 'compose':

Clearer help for misplaced global arguments

This also improves errors for misplaced global arguments, particularly --session, by explaining where the option must appear in the command line. This addresses #41222.

image

PR Checklist

Detailed Description of the Pull Request / Additional comments

  • Adds global argument inheritance along the selected command path.
  • Requires global options to appear after their declaring command and before its subcommand.
  • Reports corrective placement guidance for misplaced ancestor globals; options from other branches remain unknown arguments.
  • Uses argument ownership consistently for scope, parsing, help grouping, and diagnostics.
  • Separates environment-only arguments from command-line arguments as an explicit argument property.
  • Simplifies the parser by removing environment-default replacement state now that argument sources do not overlap.
  • Applies environment options idempotently and resolves NO_COLOR before user-visible output.
  • Preserves lazy command creation when handling positional arguments and invalid options.

Validation Steps Performed

  • Built the complete x64 Debug configuration.
  • Passed all 472 focused WSLC CLI unit tests.
  • Passed all 64 tests selected by the *Help* filter.

Copilot AI lite review requested due to automatic review settings September 9, 2026 18:04

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The newly added localized strings include placeholder metadata that doesn’t match the number of {} inserts, which can break/impair localization tooling and should be corrected before approval.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This PR introduces a new command-line parsing pipeline for wslc that supports command-scoped “global” options across nested subcommands (to enable Compose-style syntax like wslc --session foo compose --progress plain up). It centralizes command resolution + scoped global parsing in a reusable parser and updates help/output and tests accordingly.

Changes:

  • Added CommandLineParser to resolve subcommands while parsing scoped global options into CLIExecutionContext::GlobalArgs.
  • Enhanced diagnostics/help to show scoped global options and emit targeted errors for misplaced global options.
  • Updated and expanded unit tests to cover scoped-global accumulation, placement errors, and command-tree invariants.
File summaries
File Description
test/windows/wslc/WSLCCLIExecutionUnitTests.cpp Adds scoped-global parser tests and switches the parsing matrix to use ParseCommandLine.
test/windows/wslc/WSLCCLICommandUnitTests.cpp Extends command validation to include global args; adds inherited-global collision/invariant checks.
src/windows/wslc/core/Main.cpp Replaces the previous multi-pass parsing pipeline with ParseCommandLine.
src/windows/wslc/core/Exceptions.h Extends ArgumentException to preserve an unknown-option token for higher-level diagnostics.
src/windows/wslc/core/CommandLineParser.h Declares the new scoped-global parsing and scope/introspection helpers.
src/windows/wslc/core/CommandLineParser.cpp Implements scoped-global parsing, scope/path discovery, and misplaced-global diagnostics.
src/windows/wslc/core/Command.h Updates the contract/comment for GetGlobalArguments() semantics.
src/windows/wslc/core/Command.cpp Updates help rendering to include scoped global options and a [global-options] usage placeholder.
src/windows/wslc/core/CLIExecutionContext.h Updates documentation to reflect that GlobalArgs are accumulated across scopes.
src/windows/wslc/commands/RootCommand.cpp Updates documentation comment for root global option positioning.
src/windows/wslc/arguments/ArgumentParser.cpp Tags invalid-name/alias errors with the unknown token for misplaced-global detection.
localization/strings/en-US/Resources.resw Adds new localized strings for misplaced scoped-global diagnostics and scoped-global help headings.
Review details

Suppressed comments (1)

localization/strings/en-US/Resources.resw:2226

  • This resource string has two "{}" placeholders but the only includes one {FixedPlaceholder="{}"}. For consistency with nearby strings (e.g., WSLCCLI_Usage), the comment should include two FixedPlaceholder entries.
  <data name="WSLCCLI_MisplacedGlobalOptionMultipleScopesError" xml:space="preserve">
    <value>Global option '{}' is not valid at this position. It is defined for these commands: {}. Specify it after the intended command and before its subcommand.</value>
    <comment>{FixedPlaceholder="{}"}Command line arguments, file names and string inserts should not be translated</comment>
  • Files reviewed: 12/12 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread localization/strings/en-US/Resources.resw Outdated
Copilot AI review requested due to automatic review settings September 9, 2026 18:19

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

src/windows/wslc/core/Command.cpp should include precomp.h first to match core directory conventions and ensure consistent PCH usage.

Review details

Suppressed comments (1)

src/windows/wslc/core/Command.cpp:21

  • src/windows/wslc/core/*.cpp files conventionally include precomp.h first; Command.cpp currently doesn’t, which can break PCH usage and makes include ordering inconsistent with the rest of the directory (e.g. Main.cpp, TableOutput.cpp). Please include precomp.h as the first include in this translation unit.
#include "Argument.h"
#include "Command.h"
#include "CommandLineParser.h"
#include "Invocation.h"
#include "ArgumentParser.h"
#include "RootCommand.h"
#include "TableOutput.h"

  • Files reviewed: 12/12 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Copilot AI review requested due to automatic review settings September 9, 2026 18:32

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

It changes the core CLI parsing behavior and error-reporting paths, so a final human review is warranted despite strong test coverage.

Review details

Suppressed comments (2)

Previously missed (2) — in code that hasn't changed since the last review.

src/windows/wslc/core/CommandLineParser.cpp:255

  • ParseCommandLine always builds globalScopes by traversing the entire command tree (GetGlobalArgumentScopes) even on successful parses. Because RootCommand::GetCommands() eagerly constructs many command objects, this adds avoidable overhead to every invocation when the scopes are only needed for misplaced-global diagnostics. Consider deferring scope collection until an unknown/misplaced option is detected.
    src/windows/wslc/core/CommandLineParser.cpp:79
  • CollectGlobalArgumentPath calls GetGlobalArguments() twice (once to check emptiness, again via MakeGlobalArgumentScope), which duplicates work and could be problematic if GetGlobalArguments() ever becomes non-trivial or order-dependent. Cache the vector once and move it into the scope.
  • Files reviewed: 12/12 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Copilot AI review requested due to automatic review settings September 9, 2026 18:48
@dkbennett
David Bennett (dkbennett) marked this pull request as ready for review September 9, 2026 18:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Main.cpp now duplicates root-scope environment option scanning with the new scoped parser, and this redundancy should be cleaned up to keep parsing responsibilities consistent and avoid unnecessary work.

Review details

Suppressed comments (1)

Previously missed (1) — in code that hasn't changed since the last review.

src/windows/wslc/core/Main.cpp:110

  • ParseCommandLine() now applies environment-backed defaults as each command scope is entered; with the current flow, the root scope gets scanned twice (once here and once inside ParseCommandLine), which is redundant work and splits the responsibility across two places. Consider restricting the pre-try scan to env-only arguments needed before any output (e.g. NO_COLOR) and letting ParseCommandLine handle env defaults for globals/scoped commands.
  • Files reviewed: 12/12 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Copilot AI review requested due to automatic review settings September 9, 2026 19:44

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

It changes the core CLI parsing and help/diagnostics path in user-facing code, so it warrants final human review despite strong test coverage.

Review details
  • Files reviewed: 13/13 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

ggarzia-MSFT
ggarzia-MSFT previously approved these changes Sep 9, 2026
Comment thread src/windows/wslc/core/Main.cpp Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

It substantially refactors core CLI parsing/control flow and command-tree ownership semantics, warranting careful human validation beyond the added tests.

Review details
  • Files reviewed: 30/30 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Copilot AI review requested due to automatic review settings September 11, 2026 23:50

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

A critical parser issue can silently accept misplaced inherited globals after unlimited positional arguments.

Get a fresh assessment by requesting another Copilot review.

Review details
  • Files reviewed: 42/42 changed files
  • Comments generated: 1
  • Review effort level: Lite

Comment thread src/windows/wslc/core/Invocation.cpp
Copilot AI review requested due to automatic review settings September 14, 2026 04:06
Co-authored-by: Copilot <[email protected]>
Copilot-Session: b218715f-3b09-4fd3-ad77-a4ca9c74c2f7

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Critical session selection remains unimplemented, and command-local NO_COLOR environment handling can be ignored.

Get a fresh assessment by requesting another Copilot review.

Review details

Suppressed comments (1)

src/windows/wslc/core/Main.cpp:97

  • This freezes NoColor before the selected command's environment-only arguments are loaded. If a command declares the new Flags::EnvironmentOnly binding for NoColor locally, GetValue records the default false as immutable; ParseCommandLine then cannot add the NO_COLOR value, and ApplyEnvironmentOptions catches that failure, so NO_COLOR is silently ignored for that command. Apply selected-command environment options before freezing terminal state (while still doing so before output).
  • Files reviewed: 43/43 changed files
  • Comments generated: 1
  • Review effort level: Lite

Comment thread src/windows/wslc/core/Invocation.cpp
Copilot AI review requested due to automatic review settings September 14, 2026 04:34

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Three moderate issues remain in forwarding, help filtering, and same-command global parsing.

Review details

Suppressed comments (3)

src/windows/wslc/arguments/ArgumentParser.cpp:207

  • This check runs before ProcessAnchoredPositionals, so an inherited global token after the image in a command with ForwardArgs is rejected instead of being forwarded. For example, the added ScopedGlobalArguments_GlobalTokenAfterRunImageIsCommandArgument case (run debian --session foo) reaches this branch: --session is the forwarded command token and foo should remain in ForwardArgs. Keep the inherited-option diagnostic for non-forwarding unlimited positionals, but let anchored forwarding paths proceed first.
    if (inheritedGlobalOption != nullptr)

src/windows/wslc/core/Command.cpp:352

  • GetGlobalArgumentsForPath uses its default Flags::All, so this vector still contains EnvironmentOnly arguments. OutputHelp passes every entry to AddArgumentRows, which makes root help advertise --no-color even though environment-only arguments are intended to be excluded from command-line help and parsing. Filter those arguments before building the scoped help sections (and add a regression assertion for the absence of this option).
    const auto globalArguments = GetGlobalArgumentsForPath(*this);

src/windows/wslc/core/Invocation.cpp:104

  • This two-pass flow makes same-command globals order-dependent. If a command-local option (including the synthetic --help) appears first, the global-only pass stops at it, and the final pass parses only command-local plus inherited globals—not the selected command's own globals—so compose --help --progress plain reports --progress as unknown even though it is after compose and before any subcommand. Parse both scopes together or otherwise preserve/reparse the current command's globals after local options.
  • Files reviewed: 43/43 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Copilot AI review requested due to automatic review settings September 14, 2026 06:20

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The critical dangling-reference issue in src/windows/wslc/core/Invocation.h must be fixed before approval.

Get a fresh assessment by requesting another Copilot review.

Review details
  • Files reviewed: 43/43 changed files
  • Comments generated: 1
  • Review effort level: Lite

Comment thread src/windows/wslc/core/Invocation.h
@dkbennett
David Bennett (dkbennett) marked this pull request as ready for review September 14, 2026 17:06
Copilot AI review requested due to automatic review settings September 16, 2026 00:01
@dkbennett
David Bennett (dkbennett) requested a review from a team as a code owner September 16, 2026 00:01

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The broad CLI parsing and command-tree refactor requires final human review.

Review details
  • Files reviewed: 42/42 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Copilot AI review requested due to automatic review settings September 16, 2026 16:57

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

A moderate issue remains in environment option filtering; ordinary arguments must not be populated from environment bindings unless Flags::EnvironmentOnly is enforced.

Get a fresh assessment by requesting another Copilot review.

Review details
  • Files reviewed: 42/42 changed files
  • Comments generated: 1
  • Review effort level: Lite

Comment thread src/windows/wslc/core/EnvironmentOptions.cpp

@ggarzia-MSFT ggarzia-MSFT left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, minor nit that may need to wait until post-GA

// Build usage line with Write calls for each segment.
{
std::wstring usageText = Localization::WSLCCLI_Usage(s_ExecutableName, std::wstring_view{commandChain});
std::wstring usageText = Localization::WSLCCLI_Usage(commandInvocation, L"");

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: we can change WSLCCLI_Usage string to only take one parameter now that commandInvocation contains the executable in it

@dkbennett
David Bennett (dkbennett) merged commit bf9b8aa into master Sep 16, 2026
12 checks passed
@dkbennett
David Bennett (dkbennett) deleted the user/dkbennett/globaloptionrefactor branch September 16, 2026 22:48
Blue (OneBlue) added a commit that referenced this pull request Sep 22, 2026
* Fix tracked routes being collapsed by incomplete comparison (#41393)

Mirrored route tracking used an incomplete comparator that considered only route class, destination address, and metric. Distinct routes with different prefix lengths or next hops could therefore be treated as equivalent and silently omitted.

The fix preserves the existing route-class ordering while using the complete EndpointRoute comparison for route identity. Regression tests cover prefix length, next hop, metric, exact duplicates, and dependency ordering.

* Add github issue suggestion in user visible error (#41432)

This PR adds a "search or file issue on github" suggestion in all user visible errors to:
Help users find solutions faster.
Collect more user reported issues to help reliability improvements.

This PR also updates all tests checking the error message to use a unified function for creating the expected error message.

* Match Docker output for prune operations and container inspection (#41430)

Cleanup various miscellaneous output divergences

Co-authored-by: Copilot <[email protected]>

* CLI: Mount PR followup & fix two docker parser bugs (#41436)

* Invalid the TestImageRegistry cache after running prune --all (#41442)

* Fix unit test build failure on arm64 (#41437)

* Solve various issues found by verifier (#41445)

* Save state

* Save state

* Save state

* Cleanup diff

* Add a command line option to run the tests under verifier  (#41440)

* Save state

* Save state

* Save state

* Add a /verifier option to run-tests.ps1 to run the test under verifier

* Localization change from build: 155859879 (#41450)

Co-authored-by: WSL localization <[email protected]>

* Fix various arm64 test failures (#41444)

* Fix various arm64 test failures

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <[email protected]>

* Fix LF

* Format

* Cleanup diff

---------

Co-authored-by: Copilot Autofix powered by AI <[email protected]>

* Fix unity build ODR collisions on duplicate file-local constants (#41446)

* CLI: Align alias listing with docker, Apple and other CLIs (#41439)

* Align container list format with Docker specifications (#41375)

wslc: match column order, status text, and json shape for container list


Co-authored-by: Copilot <[email protected]>

* Localization change from build: 156161979 (#41479)

Co-authored-by: WSL localization <[email protected]>

* wslc: alias -f to --format on inspect commands for docker parity (#41463)

Co-authored-by: Copilot <[email protected]>

* CLI: Add explicit per-command argument overrides (#41478)

* archlinux: Release 2026.09.01.176721 (#41493)

This is an automated release [1].

[1] https://gitlab.archlinux.org/archlinux/archlinux-wsl/-/blob/main/.gitlab-ci.yml

* Fix WSLC parser unit test argument overrides (#41496)

Update the remaining parser test call site to use ArgumentOverrides after the Argument::Create API change.

Co-authored-by: Copilot <[email protected]>

Co-authored-by: Ben Hillis <[email protected]>
Copilot-Session: eb7946ff-cc0b-4ff1-a059-571334b1c988

* Fix systemd-tmpfiles failure on systemd v261+ with systemd boot disabled (#41491)

In systemd v261, the systemd's tmpfiles.d/x11.conf was changed from D! to D. systemd/systemd@5474cad.
This means the systemd-tmpfiles command will try to execute it when called out of the boot sequence. In the linked issue's case, it's called by the post install script by dpkg. This will fail as the wsl override is not in place when systemd is disabled.

This PR enables the wsl override file generation for all distros with wslg enabled, regardless of if the distro boots with systemd.

* Fix unvalidated TerminalProfileSize during distribution import (#41495)

* Fix unvalidated TerminalProfileSize when importing a distribution

_ProcessImportResultMessage constructed the terminal profile string_view
using the message-supplied TerminalProfileSize without validating it
against the received buffer length. Use the bounds-checked two-argument
span::subspan() overload (matching the existing ShortcutIconSize handling
a few lines above) so an inconsistent size value throws instead of
producing a string_view that runs past the end of the buffer.

Co-authored-by: Copilot <[email protected]>
Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5

* format source

---------

Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot <[email protected]>
Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5

* Bump WSL DeviceHost to 1.2.62 (#41499)

* Bump WSL DeviceHost to 1.2.62

Co-authored-by: damanm24 <[email protected]>

* Correct WSL DeviceHost version to 1.2.62-0

Co-authored-by: damanm24 <[email protected]>

---------

Co-authored-by: copilot-swe-agent[bot] <[email protected]>
Co-authored-by: damanm24 <[email protected]>

* Enable unity build repo-wide via WSL_UNITY_BATCH_SIZE (#41441)

Enable unity build repo-wide via WSL_UNITY_BATCH_SIZE

Co-authored-by: Copilot <[email protected]>

* Add wslc system info command (#41408)

* updated source code paths in the wslservice tab (#41509)

Co-authored-by: Tega Ajise <[email protected]>

* Harden Windows macros against dangling-else ambiguity (#41513)

* Harden Windows macros against dangling-else ambiguity

* Harden Windows macros against dangling-else ambiguity

* Fix dangling-else bugs in FAIL_FAST_IF and EMIT_USER_WARNING macros (#41504)

* Fix dangling-else bugs in FAIL_FAST_IF and EMIT_USER_WARNING macros  

Both macros were bare if-statements without do/while(0) guards, causing
the dangling else problem when used as a single statement under an if.

* Fix dangling-else bugs in FAIL_FAST_IF and EMIT_USER_WARNING macros

* harden EMIT_USER_WARNING macro on Windows against dangling-else

* Fix dangling-else bugs in FAIL_FAST_IF and EMIT_USER_WARNING macros

* Fix intermittent ImportDistroInvalidTar test failures (#41490)

* Fix test to be more resilient

* Make WSL1 more lenient, make WSL2 exact

* Wslc events (#40971)

* Revert "Mount plugin folders on behalf of the user owning the wsl session" (#41331) (#41515)

Temporarily reverting the identity-based plugin folder mount change
(both the WslCoreVm.cpp behavior change and the accompanying
MountFolderAccess test coverage) introduced in #41331.

This reverts commit 78b9cf2.

Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot <[email protected]>

* Add container restart runtime support (#41454)

* Fix p9 drvfs read only mount regression (#41487)

#41129 introduces a regression where the ";ro" option is passed to the host for p9 shares. However, that option is not supported by the p9 server and causes the mount to fail.

This PR removes the special handling of "ro" in the common parser. And use MountParseFlags to add the required virtio option.

* Fix WSLC Plan9 mount and image-build failures (#41535)

* Fix WSLC Plan9 mounts using a per-user server

* remove debug code

* wslc: add --size to inspect for docker parity (#41489)

Co-authored-by: Copilot <[email protected]>

* Bump actions/deploy-pages in the github-actions group (#41537)

Bumps the github-actions group with 1 update: [actions/deploy-pages](https://github.com/actions/deploy-pages).


Updates `actions/deploy-pages` from 5.0.0 to 5.0.1
- [Release notes](https://github.com/actions/deploy-pages/releases)
- [Commits](actions/deploy-pages@cd2ce8f...368f825)

---
updated-dependencies:
- dependency-name: actions/deploy-pages
  dependency-version: 5.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Add wslc container restart command (#41435)

* init: fix dhcpcd option name in bridged-mode config (#41538)

* init: fix dhcpcd option name in bridged-mode config

dhcpcd has no option named "broadcast"; option 28 is "broadcast_address".
dhcpcd 10 rejects the whole "option" line, so DNS servers, domain, search
list, hostname and MTU were never requested from the DHCP server, leaving
/mnt/wsl/resolv.conf without nameservers on servers that honour the PRL.

* init: apply clang-format to dhcpcd config string

The longer broadcast_address option name pushed the literal past the
130-column limit in .clang-format. Split it as clang-format does; the
concatenated value is unchanged.

* Update SLE15SP7 [QU5] (#41506)

* Host plugin Plan9 shares as the session user (#41548)

* Host plugin Plan9 shares as the session user

Use a dedicated per-user Plan9 server for plugin folder mounts so host filesystem permissions are preserved without relying on HCS-managed share identity.

Co-authored-by: Copilot <[email protected]>

Copilot-Session: c20b1da0-c613-489d-92a3-9c27527c0c54

* Simplify plugin Plan9 port plumbing

Use the fixed plugin port directly in mini_init and mirror the existing per-user Plan9 server lifecycle.

Co-authored-by: Copilot <[email protected]>

Copilot-Session: c20b1da0-c613-489d-92a3-9c27527c0c54

* Recreate stopped plugin Plan9 servers

Recreate the per-user server before adding a share when its process is no longer running.

Co-authored-by: Copilot <[email protected]>

Copilot-Session: c20b1da0-c613-489d-92a3-9c27527c0c54

---------

Co-authored-by: Ben Hillis <[email protected]>
Copilot-Session: c20b1da0-c613-489d-92a3-9c27527c0c54

* Fix virtiofs bind mounts exposing files as root-owned (#40719) (#40733)

* Fix virtiofs bind mounts exposing files as root-owned (#40719)

Add the 'metadata' option to virtiofs shares created via
HcsVirtualMachine::AddShare (the WSLC/Docker container path). Without
this option, the virtiofs device host cannot persist per-file uid/gid
in NTFS extended attributes, so all files default to uid=0/gid=0
regardless of the creating user.

This matches the behavior of the regular distro mount path
(WslCoreVm::AddVirtioFsShare) which receives metadata/uid/gid options
from the Linux init's ConvertDrvfsMountOptionsToPlan9.

Also adds a regression test (WindowsMountsVirtioFsFileOwnership) that
verifies file ownership is preserved on virtiofs mounts.

Fixes #40719

Co-authored-by: Copilot <[email protected]>

* Address code review feedback

- Add inline comment explaining why 'metadata' is required
- Use unique mount point (/virtiofs-ownership-test) to avoid test interference
- Use numeric UID (su '#65534') instead of username to avoid environment dependency

Co-authored-by: Copilot <[email protected]>

* test: use 'nobody' user instead of numeric UID in virtiofs ownership test

The su command with numeric UID syntax ('#65534') requires the user to
exist in /etc/passwd. Use the 'nobody' account directly since it is
already available in the test VHD.

Co-authored-by: Copilot <[email protected]>

* fix: wrap long test command strings to satisfy clang-format 130-col limit

Co-authored-by: Copilot <[email protected]>

* test: unmount inline with VERIFY_SUCCEEDED to match file convention

Replace the scope_exit unmount cleanup with an inline VERIFY_SUCCEEDED
call at the end of the test, matching every other mount test in this
file (e.g. WindowsMountsVirtioFsShareReuse). This also asserts the
unmount HRESULT rather than silently swallowing it.

Co-authored-by: Copilot <[email protected]>
Copilot-Session: 9213b7da-c5c8-4d9c-89ab-e80048d288a2

* Fix Windows mount test API calls

Co-authored-by: Copilot <[email protected]>

---------

Co-authored-by: Copilot <[email protected]>
Co-authored-by: Blue <[email protected]>
Copilot-Session: 9213b7da-c5c8-4d9c-89ab-e80048d288a2

* wslc: match docker prune semantics (confirmation prompt, -f aliases --force) (#41455)

Co-authored-by: Copilot <[email protected]>

* wslc: add --all to image list for docker parity (#41456)

Co-authored-by: Copilot <[email protected]>

* wslc: add --details to container logs for docker parity (#41467)

Co-authored-by: Copilot <[email protected]>
Co-authored-by: JohnMcPMS <[email protected]>

* Localization change from build: 157218885 (#41559)

Co-authored-by: WSL localization <[email protected]>

* Don't fail the installation if DeprovisionMsix() fails (#41453)

* Don't fail the installation if DeprovisionMsix() fails

* Apply PR feedback

* Notice change from build: 157227119 (#41564)

Co-authored-by: WSL notice <[email protected]>

* wslc: add --size to container list for docker parity (#41477)

Co-authored-by: Copilot <[email protected]>

* wslc: add --all-tags to push for docker parity (#41500)

Co-authored-by: Copilot <[email protected]>

* Fix build issue for wslsettings, and add more logging to the pipelines (#40388)

* Validate variable-length message strings (#41567)

Co-authored-by: Copilot <[email protected]>

Co-authored-by: Ben Hillis <[email protected]>
Copilot-Session: 3086bdaf-bc43-4fed-88d1-3a95a21fd14e

* Fix WSLC fallback gateway collision (#41547)

Avoid selecting the guest IPv4 address as its synthesized default gateway when the host adapter does not expose one.

Co-authored-by: Copilot <[email protected]>

Co-authored-by: Ben Hillis <[email protected]>
Copilot-Session: ce168659-cb9d-4f0e-8fd1-2834d065ba9d

* Reduce distro termination log noise (#41541)

Co-authored-by: Copilot <[email protected]>

Co-authored-by: Ben Hillis <[email protected]>
Copilot-Session: adf24228-67c0-452e-9cc2-c698a8d7b3b7

* Localization change from build: 157277214 (#41571)

Co-authored-by: WSL localization <[email protected]>

* CLI: Add global options to root help, adjust options usage (#41534)

* Add global options to root help, adjust options usage to match CLI conventions

* Trim some unnecessary test code

* Localization change from build: 157310027 (#41574)

Co-authored-by: WSL localization <[email protected]>

* wslc: add docker --quiet to image load, image push and container cp (#41466)

Co-authored-by: Copilot <[email protected]>

* Tear down the stale plugin Plan9 server before recreating it (#41565)

When the per-user plugin Plan9 server is no longer running, the previous instance was dropped without a Teardown call, so it could still hold the Plan9 port when the replacement tries to bind it.

Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot <[email protected]>
Copilot-Session: 0d028ad4-fe5e-4ef1-9832-18ee0e4825cc

* Use a locally imported version of docker/dockerfile instead of downloading it from the default registry (#41575)

* Use a locally imported version of docker/dockerfile instead of downloading it from the default registry

* Cleanup diff

* Use canonical path in VolumeMount_Parse_ReturnExpectedResult (#41577)

* Document WSL security model (#41556)

* Document WSL security model

Clarify WSL trust boundaries and explain that configuration settings do not establish a sandbox.

Co-authored-by: Copilot <[email protected]>

Copilot-Session: c77eaf09-799a-416e-b4b4-19f37a4201ef

* Update WSL security model explanation

Co-authored-by: Copilot Autofix powered by AI <[email protected]>

* Clarify WSL isolation guidance

Distinguish functional distribution separation from a security boundary and recommend a separately managed VM for untrusted workloads.

Co-authored-by: Copilot <[email protected]>

Copilot-Session: c77eaf09-799a-416e-b4b4-19f37a4201ef

* Document shared WSL VM trust model

Clarify that elevated and non-elevated sessions can share utility VM state and are not separate guest security boundaries.

Co-authored-by: Copilot <[email protected]>

Copilot-Session: c77eaf09-799a-416e-b4b4-19f37a4201ef

---------

Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot Autofix powered by AI <[email protected]>
Copilot-Session: c77eaf09-799a-416e-b4b4-19f37a4201ef

* Bump GitPython to 3.1.59 (#41580)

Resolves open Dependabot alerts for GitPython <= 3.1.58 in
distributions/requirements.txt and tools/devops/requirements.txt.

Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot <[email protected]>
Copilot-Session: 6fcfe0f1-6be5-4913-ab36-71823443cc36

* Remove two noisy warnings from the distro validation scripts (#41579)

* Remove two noisy warnings from the distro validation scripts

* Cleanup diff

* Fix formatting of USR_SHARE_WSL assignment

Co-authored-by: Copilot Autofix powered by AI <[email protected]>

---------

Co-authored-by: Copilot Autofix powered by AI <[email protected]>

* Fix activating a stopping service treated as OOM (#41460)

The current factory function for LxssUserSession and WSLCSessionManager translates the error code CO_E_SERVER_STOPPING to S_FALSE. Which combined with *ppCreated == NULL causes COM to treat this as an OOM. Leading to error messages like this when activating a stopping service:

Not enough memory resources are available to complete this operation.
Error code: Wsl/E_OUTOFMEMORY
This PR removes this conversion. So, COM actually retries when the service is stopping. And returns CO_E_SERVER_EXEC_FAILURE if the retry times out.

* Set distributionStartTimeout to 2 minutes in the tests to solve distribution start timeouts errors (#41583)

* Set distributionStartTimeout to 2 minutes in the tests to solve distribution start timeouts errors

* Update tests

* Localization change from build: 157504221 (#41602)

Co-authored-by: WSL localization <[email protected]>

* Enable RedirectionGuard process mitigation (#41542)

Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot <[email protected]>

* Updates Ubuntu latest LTS images (#41465)

* Updates Ubuntu 26.04 to the .1 release

Just announced today.
Also published the up-to-date Ubuntu package to MS Store,
but I'm not referencing it here.

* Updates the 24.04.5 images just released today.

* Use the cdimages.u.c host for consistency

---------

Co-authored-by: Carlos Nihelton <[email protected]>

* diagnostics: improve collect-wsl-logs for analysis (summary.json, README, profile info, WSL/guest state) (#40776)

* diagnostics: record capture profile in collected logs

collect-wsl-logs.ps1 did not record which WPR profile was used for a
capture. When analyzing an archive (e.g. a networking-only capture that
lacks the WSL core trace providers), there was no way to tell which
profile produced it without inferring it from the provider mix.

Write a collection-info.txt into the log folder capturing the selected
LogProfile, the mapped WPRP profile and file, the Dump and
RestartWslReproMode switches, and the collection timestamp.

Co-authored-by: Copilot <[email protected]>

* diagnostics: collect WSL version, guest state, and drop empty dumps

Add three further debugging improvements to collect-wsl-logs.ps1:

- Collect wsl --version / --status / --list --verbose into wsl-info.txt
  instead of forcing analyzers to infer the version and distro layout
  from the appx package and registry.
- Collect guest-side state (dmesg, free, uptime, ulimit, pid_max,
  threads-max, process/thread counts, top RSS) into linux_diagnostics.log
  after the repro. This is the data needed to diagnose in-distro failures
  such as 'Resource temporarily unavailable' (EAGAIN) from resource limits.
- Remove 0-byte dump files left behind when MiniDumpWriteDump fails, so
  the archive only contains real dumps.

Also set WSL_UTF8 and the console output encoding so wsl.exe output is
captured to the log files readably.

Co-authored-by: Copilot <[email protected]>

* diagnostics: add summary.json and README.md to log archive

Make collected log archives easier to analyze (by a human or an agent)
without having to run tools or infer state from individual artifacts:

- summary.json: machine-readable overview of the capture - profile,
  WSL/Windows versions, networking mode, installed distributions and
  their state, .wslconfig presence, and an inventory of non-empty dumps.
- README.md: an index of the archive contents describing each file, plus
  a note on how to decode logs.etl and how to tell when a non-default
  log profile was used.

Co-authored-by: Copilot <[email protected]>

* diagnostics: address PR feedback (utf8 wsl-info, wsl.exe timeouts, slimmer summary.json)

- Write wsl-info.txt as UTF-8 instead of the PS5.1 default UTF-16LE.
- Guard every newly-added wsl.exe call (wsl-info and guest diagnostics) with a
  timeout via a background job so a deadlocked service or bad VM state cannot
  hang log collection.
- Drop the duplicated distro-registry enumeration and .wslconfig networkingMode
  parsing from summary.json; that state is readily derived from HKCU.txt and the
  archived .wslconfig.

Co-authored-by: Copilot <[email protected]>

* diagnostics: drop wsl-info.txt and guest diagnostics collection

Remove the unconditional wsl.exe calls this PR introduced (wsl-info.txt and
linux_diagnostics.log) along with the now-unused timeout helper, per review
feedback that the log collection script should not call wsl.exe (which can hang
if the service is deadlocked or the VM is in a bad state). Pre-existing
networking-profile wsl.exe calls are left untouched.

Co-authored-by: Copilot <[email protected]>

* collect-wsl-logs: drop bundled summary.json and README per review

OneBlue noted the agent-readable index and the summary values are redundant
in every archive (an analyzer can derive them from the archive contents).
Keep only collection-info.txt, which records non-derivable capture provenance
(which WPR profile/switches were used).

Co-authored-by: Copilot <[email protected]>

---------

Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot <[email protected]>

* Move security model under technical documentation (#41605)

* Move security model under technical documentation

Co-authored-by: Copilot <[email protected]>

Copilot-Session: 43c7b692-ffc5-43bf-88b9-ecc927a1aa55

* Move security model into technical documentation

Co-authored-by: Copilot <[email protected]>

Copilot-Session: 43c7b692-ffc5-43bf-88b9-ecc927a1aa55

---------

Co-authored-by: Ben Hillis <[email protected]>
Copilot-Session: 43c7b692-ffc5-43bf-88b9-ecc927a1aa55

* Fix typos (#41589)

* Don't stop parsing linux config files on invalid lines (#41606)

* wslc: add --all-tags to pull for docker parity (#41494)

Co-authored-by: Copilot <[email protected]>

* Added WSL container to OOBE (#41402)

* Pre merge Localization strings prior to GA (#41585)

Co-authored-by: Copilot <[email protected]>

* wslc: keep image list json CreatedSince locale-invariant (#41609)

Co-authored-by: Copilot <[email protected]>

* Localization change from build: 157621275 (#41610)

Co-authored-by: WSL localization <[email protected]>

* Warn on an escaped CR in wsl.conf instead of dropping it silently (#41591)

`case '\r': break;` made a backslash before a CR the only unrecognised
escape the parser accepts without a diagnostic. In a CRLF file that left
the value truncated at the backslash and the remainder parsed as its own
line, with nothing reported.

Letting it fall into the default case gives the same
MessageConfigInvalidEscape warning as any other bad escape. As with those,
the line is then discarded rather than kept truncated.

* Localization change from build: 157667513 (#41614)

Co-authored-by: WSL localization <[email protected]>

* Set a restricted ephemeral port range for test case ConsommeTests::PortZeroBindIsTracked (#41616)

* repo: modify CODEOWNERS to change wsl-maintainers to wsl-reviewers team (#41617)

Co-authored-by: Ben Hillis <[email protected]>

* Localization change from build: 157736413 (#41621)

Co-authored-by: WSL localization <[email protected]>

* CLI: Global option scopes for nested commands (related to compose support) (#41546)

* Change default relay  buffer size to 64KiB (#41603)

The current logic uses a fixed 4KiB buffer for stdio relay on the Windows side. And uses an initial 4KiB buffer for stdio relay on the Linux side, which grows only if the message won't fit. This can severely limit the relay performance in some situations. For example, in #41572, when redirecting stdout to a SMB share.

This PR increases thedefault relay buffer size to 64KiB. Which shows significant performance improvements according to buffer size tests.

* Fix redirect stdout and stderror to the same file overlapping (#41611)

Currently the stdout and stderr relay tracks the output offset separately. And when redirected to the same file, the writes could overlap.

This PR uses the append mode for overlap io writes instead of the separate offsets in the relay. So, the file write offset is correctly tracked by the system.

* move installer log collection after repro (#41620)

The installer log files were collected before the log collection starts. Which will miss the user repro.

This PR moves it after the user repro.

* wslc: add --digests to image list for docker parity (#41457)

Co-authored-by: Copilot <[email protected]>

* Localization change from build: 157843092 (#41630)

Co-authored-by: WSL localization <[email protected]>

* Explicitely return SOCKET from WSLCPluginAPI_ProcessGetFd() (#41626)

* In mirrored mode, handle route update as add instead of replace (#41391)

In mirrored mode, handle route update as add instead of replace
Remove usage of route update as it can overwrite routes on other interfaces. add tests that verify host routing changes are correctly reflected in Linux

---------

Co-authored-by: Catalin-Emil Fetoiu <[email protected]>

* Add wslc events command (#41608)

* Don't fail the UnitTests::Warnings test case if GlobalSecureAccess VPN is running (#41638)

* Don't fail the UnitTests::Warnings test case if GlobalSecureAccess VPN is running

* Cleanup diff

* Fix test

* Wait for wslservice to be started when running tests (#41639)

* Wait for wslservice to be started when running tests

* Fail on timeout

* Improve check

* Format

* Create new namespaces for distro cgroups (#41512)

In 2.9.8, the distro processes are separated into their own cgroups. But they remain in the same cgroup namespace. That caused compatibility issues with softwares that assume a fixed systemd cgroup layout. For example, rootless docker and nerdctl.
Fixes on Moby and nertctl are being worked on. However, to avoid issues with other software, WSL's cgroup handling should also be improved.

This PR creates new cgroup namespaces for the distros. So, to the non-critical distro processes, the systemd cgroup layout stays the same as before.
This PR also introduces a cgroup structure change to accomplish this. The systemd init is moved from wsl-user/distro-N/systemd to wsl-user/distro-N. And the initialization of the distro-N controllers is handled by systemd instead.
The processes are also moved into the non-systemd cgroup in systemdless distros. This makes sure that sub-group controllers can be enabled in the distro root.
Cgroup v2 is now enforced when distro isolation is enabled. Instead of constructing an unusable cgroup v1 layout when cgroup v1 and distro isolation are both enabled.

* Fix unnecessary delay in the port tracking loop (#41472)

Before this change, an additional 10ms delay was added in the port tracker loop presumably to make the main loop slower than the worker loop. So, the worker result does not get super dated. This is not reliable. And the 10ms delay also slows down every consecutive bind call.

This PR refactors the thread synchronization method. So, the timing between those two loops is more deterministic. And removes the performance penalty for all bind calls.

* Localization change from build: 157954210 (#41643)

Co-authored-by: WSL localization <[email protected]>

* wslc: add --follow-link to cp (#41501)

Co-authored-by: Copilot <[email protected]>

* Disable unstable bind cap test and re-enable Loopback test that was incorrectly disabled- #41648 (#41648)

Co-authored-by: Catalin-Emil Fetoiu <[email protected]>

* Move objects shared by wslc.exe and the tests to src/windows/common (#41619)

* Move objects shared by wslc.exe and the tests to src/windows/common

Co-authored-by: Copilot <[email protected]>

* Link yaml-cpp, advapi32 and Crypt32 into common

Co-authored-by: Copilot <[email protected]>

* Drop yaml-cpp, advapi32 and crypt32 from wslclib now that common provides them

Co-authored-by: Copilot <[email protected]>

* Move wslc code in common under common/wslc and namespace CLI types as wslc::cli

Co-authored-by: Copilot <[email protected]>

---------

Co-authored-by: Copilot <[email protected]>

* Fix various protocol parsing issues (#41637)

* Save state

* Use proper arrays

* Format

* Add new tests

* Cleanup tests

* Cleanup diff

* Format

* Apply PR feedback

* Apply PR feedback

* Format

* Apply PR feedback

* Move logging call

* Apply PR feedback

* Apply PR feedback

* Localization change from build: 157980831 (#41647)

Co-authored-by: WSL localization <[email protected]>

* Add WSLC network lifecycle events (#41576)

* Add WSLC network lifecycle events

* Localize pending network prune errors

* Fix network operation wait ownership and cleanup ordering

* Fix prune event correlation after timed-out

* Fix network event rollback and timeout recovery

* Format

* Forward Docker network events directly

* Restore lock_guard after removing event waits

* fix test

* align event stream test helpers after merge

* feedback

* Fix potential out of bound access when pretty-printing string field in init messages (#41664)

* Localization change from build: 158197536 (#41662)

Co-authored-by: WSL localization <[email protected]>

---------

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: Feng Wang <[email protected]>
Co-authored-by: ggarzia-MSFT <[email protected]>
Co-authored-by: Copilot <[email protected]>
Co-authored-by: David Bennett <[email protected]>
Co-authored-by: WSL localization <[email protected]>
Co-authored-by: Copilot Autofix powered by AI <[email protected]>
Co-authored-by: beena352 <[email protected]>
Co-authored-by: Arch Linux Technical User <[email protected]>
Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Ben Hillis <[email protected]>
Co-authored-by: Copilot <[email protected]>
Co-authored-by: damanm24 <[email protected]>
Co-authored-by: tega-ajise <[email protected]>
Co-authored-by: Tega Ajise <[email protected]>
Co-authored-by: Eamon <[email protected]>
Co-authored-by: Kevin Vega <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: DesertRatUa <[email protected]>
Co-authored-by: Scott Bradnick <[email protected]>
Co-authored-by: Stephen Halter <[email protected]>
Co-authored-by: JohnMcPMS <[email protected]>
Co-authored-by: Flor Chacón <[email protected]>
Co-authored-by: Carlos Nihelton <[email protected]>
Co-authored-by: Carlos Nihelton <[email protected]>
Co-authored-by: Anton Kesy <[email protected]>
Co-authored-by: Craig Loewen <[email protected]>
Co-authored-by: Leo Camus <[email protected]>
Co-authored-by: FetoiuCatalin <[email protected]>
Co-authored-by: Catalin-Emil Fetoiu <[email protected]>
Copilot-Session: eb7946ff-cc0b-4ff1-a059-571334b1c988
Copilot-Session: 35281c30-3d08-4f05-8c84-2ce4711023d5
Copilot-Session: c20b1da0-c613-489d-92a3-9c27527c0c54
Copilot-Session: 9213b7da-c5c8-4d9c-89ab-e80048d288a2
Copilot-Session: 3086bdaf-bc43-4fed-88d1-3a95a21fd14e
Copilot-Session: ce168659-cb9d-4f0e-8fd1-2834d065ba9d
Copilot-Session: adf24228-67c0-452e-9cc2-c698a8d7b3b7
Copilot-Session: 0d028ad4-fe5e-4ef1-9832-18ee0e4825cc
Copilot-Session: c77eaf09-799a-416e-b4b4-19f37a4201ef
Copilot-Session: 6fcfe0f1-6be5-4913-ab36-71823443cc36
Copilot-Session: 43c7b692-ffc5-43bf-88b9-ecc927a1aa55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants