Add --isolated for per-launch process isolation - #48
Open
irvingouj@Devolutions (irvingoujAtDevolution) wants to merge 4 commits into
Open
irvingouj@Devolutions (irvingoujAtDevolution) wants to merge 4 commits into
irvingouj@Devolutions (irvingoujAtDevolution) wants to merge 4 commits into
Conversation
When set, a launch neither forwards to a running instance nor becomes the broker, so each process keeps its own environment, parent window handle and settings directory. Persisted layouts are skipped, like Windows Terminal.
irvingouj@Devolutions (irvingoujAtDevolution)
deployed
to
publish-dry-run
September 30, 2026 18:32 — with
GitHub Actions
Active
irvingouj@Devolutions (irvingoujAtDevolution)
deployed
to
publish-dry-run
September 30, 2026 18:32 — with
GitHub Actions
Active
irvingouj@Devolutions (irvingoujAtDevolution)
deployed
to
publish-dry-run
September 30, 2026 18:34 — with
GitHub Actions
Active
irvingouj@Devolutions (irvingoujAtDevolution)
deployed
to
publish-dry-run
September 30, 2026 18:34 — with
GitHub Actions
Active
The setting is silently ignored by a dt that does not know it, which would leak one launch's environment into another. An unknown flag fails the launch instead, the caller decides per launch, and nothing has to be read from settings.json before the broker election.
irvingouj@Devolutions (irvingoujAtDevolution)
deployed
to
publish-dry-run
September 30, 2026 19:15 — with
GitHub Actions
Active
irvingouj@Devolutions (irvingoujAtDevolution)
deployed
to
publish-dry-run
September 30, 2026 19:15 — with
GitHub Actions
Active
irvingouj@Devolutions (irvingoujAtDevolution)
deployed
to
publish-dry-run
September 30, 2026 19:15 — with
GitHub Actions
Active
irvingouj@Devolutions (irvingoujAtDevolution)
deployed
to
publish-dry-run
September 30, 2026 19:15 — with
GitHub Actions
Active
irvingouj@Devolutions (irvingoujAtDevolution)
deployed
to
publish-dry-run
September 30, 2026 21:21 — with
GitHub Actions
Active
irvingouj@Devolutions (irvingoujAtDevolution)
deployed
to
publish-dry-run
September 30, 2026 21:21 — with
GitHub Actions
Active
irvingouj@Devolutions (irvingoujAtDevolution)
deployed
to
publish-dry-run
September 30, 2026 21:22 — with
GitHub Actions
Active
irvingouj@Devolutions (irvingoujAtDevolution)
deployed
to
publish-dry-run
September 30, 2026 21:22 — with
GitHub Actions
Active
irvingouj@Devolutions (irvingoujAtDevolution)
marked this pull request as ready for review
September 30, 2026 21:28
irvingouj@Devolutions (irvingoujAtDevolution)
requested review from
Marc-André Moreau (mamoreau-devolutions)
and
a balanced review from Copilot
and removed request for
Copilot
September 30, 2026 21:30
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Isolation is lost during serialization and silently ignored by the in-window command-line path.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Adds per-launch process isolation, preventing broker participation and persisted-layout reuse.
Changes:
- Adds and documents the
--isolatedCLI option. - Skips broker forwarding/election for isolated launches.
- Disables automatic persisted-layout restoration and saving.
| File | Description |
|---|---|
README.md |
Documents isolated launches. |
src/Devolutions.Terminal/Program.cs |
Skips broker setup and forwarding. |
src/Devolutions.Terminal/App.axaml.cs |
Propagates isolation into routing. |
src/Devolutions.Terminal/TerminalWindowRouter.cs |
Passes isolation to windows. |
src/Devolutions.Terminal.Cli/Program.cs |
Launches an isolated host directly. |
src/Devolutions.Terminal.Cli/CliParser.cs |
Parses and advertises --isolated. |
src/Devolutions.Terminal.Cli/CliContracts.cs |
Adds isolation to invocation data. |
src/Devolutions.Terminal.App/Views/MainWindow.axaml.cs |
Gates persisted-layout behavior. |
src/Devolutions.Terminal.App/Models/TerminalLayoutStateStore.cs |
Centralizes the layout decision. |
tests/Devolutions.Terminal.Cli.Tests/CliParserTests.cs |
Tests option parsing. |
tests/Devolutions.Terminal.App.Tests/LayoutDescriptorTests.cs |
Tests isolated layout behavior. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Marc-André Moreau (mamoreau-devolutions)
approved these changes
Sep 30, 2026
irvingouj@Devolutions (irvingoujAtDevolution)
deployed
to
publish-dry-run
September 30, 2026 22:14 — with
GitHub Actions
Active
irvingouj@Devolutions (irvingoujAtDevolution)
deployed
to
publish-dry-run
September 30, 2026 22:14 — with
GitHub Actions
Active
irvingouj@Devolutions (irvingoujAtDevolution)
deployed
to
publish-dry-run
September 30, 2026 22:15 — with
GitHub Actions
Active
irvingouj@Devolutions (irvingoujAtDevolution)
deployed
to
publish-dry-run
September 30, 2026 22:15 — with
GitHub Actions
Active
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Adds
--isolated: that launch gets its own process, never forwards to a running instance, and never becomes the broker for later ones.RDM needs this to swap its bundled wt-distro for dt. It starts one terminal per entry, each with its own env vars (secrets included),
WT_BASE_SETTINGS_PATHandWT_PARENT_WINDOW_HANDLE. With the broker, the second launch forwards to the first process and exits, so entry B's shell gets entry A's env and settings, and the parent HWND is dropped. RDM gets around this today with WT'scompatibility.isolatedMode(WindowManager.cpp), but WT removed that setting in 1.23 (microsoft/terminal#18215). DHowett floated bringing it back aswt --isolatedin microsoft/terminal#19468.Why a flag and not the old setting: a dt that doesn't know the setting silently ignores it and leaks, while an unknown flag fails the launch (
dt: Unknown command '--isolated'.). It's also per launch, and nothing has to be read fromsettings.jsonbefore the election.With
--isolated:dt.exeskip forwarding, election and the endpoint file, so a normal launch later can't land in an isolated process eitherShouldUsePersistedLayout-w use-existing/ window ids exit with 3Testing
RDM_SECRETand settings dir. Without the flag, B's shell is a child of A and prints A's secret. With--isolated, each launch keeps its own process, secret and settings dir. Checked on Debug and AOT builds, through both the host anddt.exe. A later launch without the flag also stays out of A.Not tested yet: HWND embedding inside RDM, macOS/Linux.