Skip to content

Pin Windows cross-instance destructive-command safety (W-G3h + W-G4h)

Summary

  • Closes the Windows multi-instance cross-safety gap identified in the global audit. Mirrors Linux Section G G3h + G4h pins at the Windows-CLI / filesystem layer.
  • W-G3h: service uninstall --purge --instance Alpha MUST NOT destroy Beta's state (the most operator-critical multi-instance regression vector).
  • W-G4h: delete-instance --instance Alpha MUST NOT destroy Beta's state (same safety contract at the instance-management layer; cross-platform).
  • New file in TentacleMultiInstanceE2E category (already in workflow filter). Applied [Collection(WindowsTentacleHostStateCollection.Name)] for instances.json serialization.

Coverage delta vs existing tests

Existing TentacleMultiInstanceE2ETests (G1.h + G2.h) cover SCM lifecycle (sc.exe direct, two services RUNNING + uninstall isolation). This new file covers the CLI / filesystem layer: register state + cert dir + registry entry boundaries when destructive commands target a single instance. Together they cover both layers of the multi-instance contract on Windows.

Test plan

  • dotnet build green
  • Verified locally: 2/2 pass on macOS dev box (W-G3 short-circuits on non-Windows, W-G4 runs cross-platform)
  • Windows CI passes both new tests
  • Existing 92 Windows E2E tests still pass

🤖 Generated with Claude Code

Merge request reports

Loading