Pin Windows cross-instance destructive-command safety (W-G3h + W-G4h)
Summary
- Closes the Windows multi-instance cross-safety gap identified in the global audit. Mirrors Linux Section G G3h + G4h pins at the Windows-CLI / filesystem layer.
-
W-G3h:
service uninstall --purge --instance AlphaMUST NOT destroy Beta's state (the most operator-critical multi-instance regression vector). -
W-G4h:
delete-instance --instance AlphaMUST NOT destroy Beta's state (same safety contract at the instance-management layer; cross-platform). - New file in
TentacleMultiInstanceE2Ecategory (already in workflow filter). Applied[Collection(WindowsTentacleHostStateCollection.Name)]forinstances.jsonserialization.
Coverage delta vs existing tests
Existing TentacleMultiInstanceE2ETests (G1.h + G2.h) cover SCM lifecycle (sc.exe direct, two services RUNNING + uninstall isolation). This new file covers the CLI / filesystem layer: register state + cert dir + registry entry boundaries when destructive commands target a single instance. Together they cover both layers of the multi-instance contract on Windows.
Test plan
-
dotnet buildgreen -
Verified locally: 2/2 pass on macOS dev box (W-G3 short-circuits on non-Windows, W-G4 runs cross-platform) -
Windows CI passes both new tests -
Existing 92 Windows E2E tests still pass