Skip to content

Add --isolated for per-launch process isolation - #48

Open
irvingouj@Devolutions (irvingoujAtDevolution) wants to merge 4 commits into
masterfrom
feat/isolated-mode
Open

irvingouj@Devolutions (irvingoujAtDevolution) wants to merge 4 commits into
masterfrom
feat/isolated-mode

Conversation

@irvingoujAtDevolution

@irvingoujAtDevolution irvingouj@Devolutions (irvingoujAtDevolution) commented Sep 30, 2026 •

Copy link
Copy Markdown

Adds --isolated: that launch gets its own process, never forwards to a running instance, and never becomes the broker for later ones.

RDM needs this to swap its bundled wt-distro for dt. It starts one terminal per entry, each with its own env vars (secrets included), WT_BASE_SETTINGS_PATH and WT_PARENT_WINDOW_HANDLE. With the broker, the second launch forwards to the first process and exits, so entry B's shell gets entry A's env and settings, and the parent HWND is dropped. RDM gets around this today with WT's compatibility.isolatedMode (WindowManager.cpp), but WT removed that setting in 1.23 (microsoft/terminal#18215). DHowett floated bringing it back as wt --isolated in microsoft/terminal#19468.

Why a flag and not the old setting: a dt that doesn't know the setting silently ignores it and leaks, while an unknown flag fails the launch (dt: Unknown command '--isolated'.). It's also per launch, and nothing has to be read from settings.json before the election.

With --isolated:

  • the host and dt.exe skip forwarding, election and the endpoint file, so a normal launch later can't land in an isolated process either
  • persisted layouts aren't restored or saved, same as WT's ShouldUsePersistedLayout
  • -w use-existing / window ids exit with 3

Testing

  • Cli, App, Settings, Broker, Compatibility, Settings.Editor and UI tests pass; NativeAOT win-x64 publish has no warnings
  • Repro: start A, then B, each with a different RDM_SECRET and settings dir. Without the flag, B's shell is a child of A and prints A's secret. With --isolated, each launch keeps its own process, secret and settings dir. Checked on Debug and AOT builds, through both the host and dt.exe. A later launch without the flag also stays out of A.

Not tested yet: HWND embedding inside RDM, macOS/Linux.

When set, a launch neither forwards to a running instance nor becomes the
broker, so each process keeps its own environment, parent window handle and
settings directory. Persisted layouts are skipped, like Windows Terminal.
The setting is silently ignored by a dt that does not know it, which
would leak one launch's environment into another. An unknown flag fails
the launch instead, the caller decides per launch, and nothing has to be
read from settings.json before the broker election.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Isolation is lost during serialization and silently ignored by the in-window command-line path.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Adds per-launch process isolation, preventing broker participation and persisted-layout reuse.

Changes:

  • Adds and documents the --isolated CLI option.
  • Skips broker forwarding/election for isolated launches.
  • Disables automatic persisted-layout restoration and saving.
File Description
README.md Documents isolated launches.
src/​Devolutions.Terminal/​Program.cs Skips broker setup and forwarding.
src/​Devolutions.Terminal/​App.axaml.cs Propagates isolation into routing.
src/​Devolutions.Terminal/​TerminalWindowRouter.cs Passes isolation to windows.
src/​Devolutions.Terminal.Cli/​Program.cs Launches an isolated host directly.
src/​Devolutions.Terminal.Cli/​CliParser.cs Parses and advertises --isolated.
src/​Devolutions.Terminal.Cli/​CliContracts.cs Adds isolation to invocation data.
src/​Devolutions.Terminal.App/​Views/​MainWindow.axaml.cs Gates persisted-layout behavior.
src/​Devolutions.Terminal.App/​Models/​TerminalLayoutStateStore.cs Centralizes the layout decision.
tests/​Devolutions.Terminal.Cli.Tests/​CliParserTests.cs Tests option parsing.
tests/​Devolutions.Terminal.App.Tests/​LayoutDescriptorTests.cs Tests isolated layout behavior.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/Devolutions.Terminal.Cli/CliContracts.cs
Comment thread src/Devolutions.Terminal.Cli/CliParser.cs

This branch was successfully deployed

1 active deployment
publish-dry-run — 566f70fa Deployed Sep 30, 2026 by irvingoujAtDevolution via MSIX packages #300
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants