Repository navigation
feat(workspaces): add list and launch CLI - #51114
Boliang Zhang (LegendaryBlair) wants to merge 3 commits into
Conversation
Add the PATH-visible shim, saved-workspace discovery and synchronous launch with terminal trust confirmation, verified non-elevated workers and coordinated launch-history persistence. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 664ee900-ce2d-4112-ac57-395314d818dc
Move only the new Workspaces entries so current main can retain its Settings CLI additions. Registration contents and installed mappings are unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 664ee900-ce2d-4112-ac57-395314d818dc
🧭 PR intakeVisual evidence: Not needed — The changed files do not indicate a visible UI change. Visual evidence was detected in the PR description. Recommendation
✅ Ready for reviewThis PR passed the automated intake checks and is ready for maintainer review. Automated PR intake; PowerToys maintainers make final decisions. |
There was a problem hiding this comment.
🟡 Changes recommended
A failed new-workspace save currently removes excluded applications from the retained editor model before persistence succeeds.
1 open finding
What changed in this PR
Adds a supported Workspaces CLI for listing saved workspaces and synchronously launching them through the existing engine.
Changes:
- Adds CLI parsing, JSON output, localization, shim, signing, and installer integration.
- Adds authenticated worker/arranger IPC, administrator de-elevation, confirmation, cancellation, and result handling.
- Coordinates native and managed workspace persistence and adds focused tests and documentation.
| File | Description |
|---|---|
tools/CliShim/CliShimManifest.props |
Registers the CLI shim target. |
src/modules/Workspaces/WorkspacesWindowArranger/WindowArranger.h |
Adds CLI IPC state. |
src/modules/Workspaces/WorkspacesWindowArranger/WindowArranger.cpp |
Returns final arranger results. |
src/modules/Workspaces/WorkspacesWindowArranger/main.cpp |
Adds CLI arranger mode. |
src/modules/Workspaces/WorkspacesLib/WorkspaceStore.h |
Defines coordinated persistence API. |
src/modules/Workspaces/WorkspacesLib/WorkspaceStore.cpp |
Implements locked atomic writes. |
src/modules/Workspaces/WorkspacesLib/WorkspacesLib.vcxproj.filters |
Registers new library sources. |
src/modules/Workspaces/WorkspacesLib/WorkspacesLib.vcxproj |
Builds CLI and authentication support. |
src/modules/Workspaces/WorkspacesLib/two_way_pipe_message_ipc.cpp |
Adds peer authentication and limits. |
src/modules/Workspaces/WorkspacesLib/OperationLifetime.h |
Bounds worker lifetime. |
src/modules/Workspaces/WorkspacesLib/JsonUtils.cpp |
Routes writes through the store. |
src/modules/Workspaces/WorkspacesLib/IPCHelper.h |
Extends authenticated IPC API. |
src/modules/Workspaces/WorkspacesLib/IPCHelper.cpp |
Implements peer policy and callback replacement. |
src/modules/Workspaces/WorkspacesLib/CliCommands.h |
Defines CLI contracts. |
src/modules/Workspaces/WorkspacesLib/CliCommands.cpp |
Implements parsing, selection, and results. |
src/modules/Workspaces/WorkspacesLib.UnitTests/WorkspaceStoreTests.cpp |
Tests coordinated persistence. |
src/modules/Workspaces/WorkspacesLib.UnitTests/WorkspacesLibUnitTests.vcxproj.filters |
Registers new tests. |
src/modules/Workspaces/WorkspacesLib.UnitTests/WorkspacesLibUnitTests.vcxproj |
Builds CLI test slices. |
src/modules/Workspaces/WorkspacesLib.UnitTests/CliWorkerTests.cpp |
Tests worker launch behavior. |
src/modules/Workspaces/WorkspacesLib.UnitTests/CliJsonOutputTests.cpp |
Tests JSON formatting. |
src/modules/Workspaces/WorkspacesLib.UnitTests/CliHandoffTests.cpp |
Tests de-elevation handoff. |
src/modules/Workspaces/WorkspacesLib.UnitTests/CliContractTests.cpp |
Tests public CLI contracts. |
src/modules/Workspaces/WorkspacesLib.UnitTests/CliApprovalTests.cpp |
Tests approval protocol behavior. |
src/modules/Workspaces/WorkspacesLib.UnitTests/CliApprovalConsoleTests.cpp |
Tests isolated console prompts. |
src/modules/Workspaces/WorkspacesLauncher/WindowArrangerHelper.h |
Extends arranger launch API. |
src/modules/Workspaces/WorkspacesLauncher/WindowArrangerHelper.cpp |
Launches operation-scoped arrangers. |
src/modules/Workspaces/WorkspacesLauncher/main.cpp |
Uses coordinated metadata writes. |
src/modules/Workspaces/WorkspacesLauncher/Launcher.h |
Exposes synchronous CLI results. |
src/modules/Workspaces/WorkspacesLauncher/Launcher.cpp |
Integrates CLI cancellation and results. |
src/modules/Workspaces/WorkspacesLauncher/AppLauncher.h |
Exposes native launch errors. |
src/modules/Workspaces/WorkspacesLauncher/AppLauncher.cpp |
Captures per-application errors. |
src/modules/Workspaces/WorkspacesEditor/WorkspacesEditorPage.xaml.cs |
Keeps the editor open after failed saves. |
src/modules/Workspaces/WorkspacesEditor/ViewModels/MainViewModel.cs |
Makes editor updates transactional. |
src/modules/Workspaces/WorkspacesEditor/Utils/WorkspacesEditorIO.cs |
Reports save success and failure. |
src/modules/Workspaces/WorkspacesEditor/Properties/Resources.resx |
Adds localized save failure text. |
src/modules/Workspaces/WorkspacesEditor/Properties/Resources.Designer.cs |
Exposes the new resource. |
src/modules/Workspaces/WorkspacesEditor/Models/Project.cs |
Preserves project timestamps when copying. |
src/modules/Workspaces/WorkspacesCsharpLibrary/Utils/IOUtils.cs |
Adds managed locking and atomic replacement. |
src/modules/Workspaces/WorkspacesCsharpLibrary.UnitTests/WorkspaceWriteTests.cs |
Tests managed persistence. |
src/modules/Workspaces/WorkspacesCsharpLibrary.UnitTests/WorkspacesCsharpLibrary.UnitTests.csproj |
Adds the managed test project. |
src/modules/Workspaces/WorkspacesCLI/WorkspacesCLI.vcxproj |
Defines and stages the CLI executable. |
src/modules/Workspaces/WorkspacesCLI/WorkspacesCLI.base.rc |
Adds executable version metadata. |
src/modules/Workspaces/WorkspacesCLI/WorkerHandoff.h |
Defines restricted worker capabilities. |
src/modules/Workspaces/WorkspacesCLI/Tests/WindowFixture/WindowFixture.vcxproj |
Builds the window fixture. |
src/modules/Workspaces/WorkspacesCLI/Tests/WindowFixture/main.cpp |
Implements the disposable test window. |
src/modules/Workspaces/WorkspacesCLI/Tests/HandoffFixture/version.rc |
Versions the handoff fixture. |
src/modules/Workspaces/WorkspacesCLI/Tests/HandoffFixture/main.cpp |
Exercises restricted handoff behavior. |
src/modules/Workspaces/WorkspacesCLI/Tests/HandoffFixture/HandoffFixture.vcxproj |
Builds the handoff fixture. |
src/modules/Workspaces/WorkspacesCLI/Tests/ApprovalConsoleFixture/main.cpp |
Exercises terminal approval scenarios. |
src/modules/Workspaces/WorkspacesCLI/Tests/ApprovalConsoleFixture/ApprovalConsoleFixture.vcxproj |
Builds the approval fixture. |
src/modules/Workspaces/WorkspacesCLI/Resources.h |
Maps localized CLI resources. |
src/modules/Workspaces/WorkspacesCLI/Resource.resx |
Defines CLI-facing strings. |
src/modules/Workspaces/WorkspacesCLI/resource.base.h |
Provides the resource header base. |
src/modules/Workspaces/WorkspacesCLI/README.md |
Documents development and testing. |
src/modules/Workspaces/WorkspacesCLI/JsonOutput.h |
Formats indented JSON output. |
src/modules/Workspaces/WorkspacesCLI/ConsoleApproval.h |
Defines console confirmation handling. |
src/modules/Workspaces/WorkspacesCLI/ConsoleApproval.cpp |
Implements fail-closed terminal prompts. |
src/modules/Workspaces/WorkspacesCLI/CommandLogging.h |
Sanitizes CLI diagnostics. |
src/modules/Workspaces/WorkspacesCLI/ApprovalChannel.h |
Defines framed approval IPC. |
src/modules/Workspaces/WorkspacesCLI/ApprovalChannel.cpp |
Implements approval request/reply handling. |
src/common/UnitTests-CommonUtils/PipeCallerAuth.Tests.cpp |
Tests server identity validation. |
src/common/interop/pipe_caller_auth.h |
Adds server authentication API. |
src/common/interop/pipe_caller_auth.cpp |
Reuses process authentication for servers. |
PowerToys.slnx |
Registers the CLI and managed tests. |
installer/PowerToysSetupVNext/CliShims.wxs |
Installs the Workspaces shim. |
installer/PowerToysSetupCustomActionsVNext/CustomAction.cpp |
Stops CLI processes during servicing. |
doc/devdocs/modules/workspaces-cli.md |
Documents the public CLI contract. |
.pipelines/ESRPSigning_core.json |
Adds the CLI payload to signing. |
Files not reviewed (1)
- src/modules/Workspaces/WorkspacesEditor/Properties/Resources.Designer.cs: Generated file
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
Defer excluded-application removal and preview initialization until persistence succeeds. Exercise failure preservation, re-inclusion and retry, and post-save filtering through a small internal persistence seam without touching real settings or editor UI. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 664ee900-ce2d-4112-ac57-395314d818dc

Summary of the Pull Request
Add a supported Workspaces CLI for discovering saved workspaces and synchronously launching one through the existing Workspaces engine.
Related to #49900. This implements the agreed list and launch subset; capture/create and other workspace CRUD operations are out of scope, so this PR does not automatically close the broader proposal.
This is a draft for implementation review. Local x64 Debug validation is complete for the scenarios below; outstanding release/installer checks are explicitly listed rather than represented as passing.
PR Checklist
doc/devdocs/modules/workspaces-cli.mdand the local build/testing README.PowerToys.slnx,tools/CliShim/CliShimManifest.props,.pipelines/ESRPSigning_core.jsonandinstaller/PowerToysSetupVNext/CliShims.wxs; include payload and wrapper in installer process shutdown.Detailed Description of the Pull Request / Additional comments
Command and output contract
listreads saved data without launching applications or modifying the workspace. Select by GUID or exact case-insensitive name; ambiguous names fail. Braced/unbraced GUIDs and either hex case are accepted, while output preserves stored IDs.list --jsonreturns only top-levelviewandworkspaces. Summary entries reuseid,nameandapplications[].application; detail uses the existing native serializer. Arrays, saved application order and duplicates are preserved.launchretains its status/result/warnings envelope, distinguishing complete, partial and failed outcomes.Reuse, PATH integration and privilege boundaries
src/modules/Workspaces/WorkspacesCLIlinks shared Workspaces logic and reuses the launcher/arranger rather than introducing another application-launch engine.bin\PowerToys.Workspaces.CLI.exeforwards to the realPowerToys.WorkspacesCLI.exepayload. Onlybinbelongs on PATH; self-contained application/DLL directories are not added.WorkerHandoffcreates and verifies a Medium-integrity worker through the normal Explorer context. It transfers only restricted operation handles, never a token or general administrator-process capability. Failure to obtain the correct user/session/context fails closed.src/common/interop/pipe_caller_auth.*adds server verification using the existing client policy implementation without weakening Runner policies.Persistence and review focus
WorkspacesCsharpLibrary/Utils/IOUtils.csand editor save handling preserve newer history and retain edits when saving fails. This is directly coupled to avoiding lost updates when CLI launches and the editor share the same workspace store.User-provided screenshots
1. Saved-workspace discovery (
list --json). The terminal output shows the simplified top-levelview: "summary"andworkspacesarray, without aschemaVersion/command/state/resultwrapper. Each entry preserves the saved braced GUID, workspace name and minimal application names.2. Terminal confirmation and partial launch (
launch --id ... --json). The unbraced GUID is accepted. The shared trust gate reportsinvalid-signature(0x80096010) for the configured elevatedTamperedSignature.exe; the user explicitly selectsA(Allow once). The final response reports two applications asarranged, Terminal asarrangeFailed, aggregatestate: "partial",persistenceStatus: "updated"and an empty warnings array.The second screenshot demonstrates the confirmation and partial-result contract, not an all-apps-successful launch or a Windows UAC test. A read-only investigation separately reproduced an existing shared Workspaces matching limitation: a running older Terminal package can no longer match the refreshed package path/display name. That shared-engine issue is not fixed or hidden by this CLI PR; the CLI correctly does not report complete success.
Validation Steps Performed
Current local x64 Debug evidence
CliContractTests,CliJsonOutputTestsandCliApprovalTests. Coverage includes the exact flat list shape, empty arrays, existing payload fields, errors, unchanged launch results and JSON formatting.git diff --checkpassed.Earlier supporting evidence and remaining gates
Earlier implementation stages also built the editor/managed tests, x64 Release and ARM64 Debug CLI/arranger, and installer custom actions, and exercised shim/peer-identity/persistence tests. Those earlier Release/ARM64 builds do not cover the latest confirmation, de-elevation and list-output changes.
Still required before release/merge sign-off:
Reproduction/build instructions and compatibility boundaries are in
doc/devdocs/modules/workspaces-cli.mdandsrc/modules/Workspaces/WorkspacesCLI/README.md.