Repository navigation
Make Iseberg NativeAOT-safe with a private PowerShell subprocess - #52
Merged
Marc-André Moreau (mamoreau-devolutions) merged 8 commits intoOct 9, 2026
Merged
Marc-André Moreau (mamoreau-devolutions) merged 8 commits into
Marc-André Moreau (mamoreau-devolutions) merged 8 commits into
Conversation
Keep the desktop SMA-free, ship a private managed binary module, and support PowerShell 7.4.6 through 7.6 with authenticated typed IPC. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Marc-André Moreau (mamoreau-devolutions)
requested a review
from a team
as a code owner
October 9, 2026 00:53
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 00:59 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 00:59 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 00:59 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 00:59 — with
GitHub Actions
Active
Acknowledge terminal-size changes before execution, queue command-catalog refreshes behind execution, and shorten test endpoints to fit macOS Unix socket limits. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 01:22 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 01:22 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 01:22 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 01:22 — with
GitHub Actions
Active
Retain early layout dimensions locally and queue the initial size atomically with subsequent resize requests. Add a real-child startup/ready resize regression. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 01:42 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 01:42 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 01:43 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 01:43 — with
GitHub Actions
Active
The 60-minute whole-suite deadline canceled healthy, still-progressing UI cases on hosted runners. Allow 120 minutes for the sequential suite while retaining the five-minute individual hang guard, all assertions and runtime matrices. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 02:47 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 02:47 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 02:48 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 02:48 — with
GitHub Actions
Active
Keep the SMA-free contracts project for the NativeAOT parent while compiling its canonical sources and build fingerprint into the child module. Ship only Iseberg.PowerShell.dll and verify isolated single-assembly loading across supported PowerShell runtimes. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 12:22 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 12:22 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 12:23 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 12:23 — with
GitHub Actions
Active
Add one stable generated workbench profile from the existing Windows and Unix PowerShell discovery paths. Preserve source disabling, user profile overrides and default terminal selection, and omit discovery in terminal-only builds. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 13:15 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 13:15 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 13:15 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 13:15 — with
GitHub Actions
Active
Publish Devolutions.Iseberg.PowerShell.dll beside DT executables, update discovery and packaging, and enforce the DT signer and timestamp for the module in release CI. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 13:43 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 13:43 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 13:43 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 13:43 — with
GitHub Actions
Active
Assert owned child termination before deleting the isolated module copy. Log and bound retries to five seconds for Windows access/sharing errors, preserving all engine assertions and propagating persistent cleanup failures. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 14:36 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 14:36 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 14:36 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
deployed
to
publish-dry-run
October 9, 2026 14:36 — with
GitHub Actions
Active
Marc-André Moreau (mamoreau-devolutions)
merged commit Oct 9, 2026
bda58de
into
master
52 checks passed
Marc-André Moreau (mamoreau-devolutions)
deleted the
copilot/iseberg-nativeaot-options
branch
October 9, 2026 17:42
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
pwshchild that imports a DT-shipped managed binary module and hosts a persistent custom-host runspace.$psISEcallbacks.Devolutions.Iseberg.PowerShell.dll, directly besidedt.exeandDevolutions.Terminal.exe, not a separate contracts DLL or PowerShell/CoreCLR. Compile canonical SMA-free contract sources into the child module and separately into the parent contracts project. A shared target generates matching build fingerprints and JSON serialization; no assembly merger or duplicated source files.Contents/Resources, keepingContents/MacOSMach-O-only. MSI installs the module directly under<INSTALLLOCATION>, with no bridge subdirectory.Latest-head CI: green (
1138163)Both completed workflows target
1138163a5fc78570aed24b5ef56d2bd7acedbf06:The current PR has 48 passed checks, four expected release-only skips, no failures or pending checks. Windows/Linux/macOS managed suites pass across PowerShell 7.4.6, 7.5.11 and 7.6.6. NativeAOT publishing, MSI/MSIX/Linux packaging, Linux ARM64 runtime, NuGet distribution, macOS NuGet signature checks, and browser WASM/E2E gates all pass. Windows signing-selection/verification regressions pass in their managed CI jobs. Protected production release signing/notarization/publication is not claimed by these ordinary PR/push workflows.
Compatibility
The child module and parent contracts project target .NET 8 against SDK 7.4.20. Supported installed runtimes: 7.4.6+ within 7.4.x, 7.5.x and 7.6.x, with bundled .NET 8/9/10. Earlier 7.4 patches cannot bind the patched SDK's SMA 7.4.6.500 reference; recommend current servicing releases. Automatic discovery does not eagerly start PowerShell; compatibility is validated when opening the workbench.
CI runs pinned 7.4.6, 7.5.11 and 7.6.6 managed suites on Windows/Linux/macOS, plus default/terminal-only native publish gates.
Windows CI cleanup repair (
1138163)At
170fba7, the PR's Windows 7.6.6 App run failed only while deleting the isolated module copy:UnauthorizedAccessExceptionfromDirectory.Delete. That run passed the other 588 App tests and all 665 UI tests. The Linux/macOS managed matrices and Windows/macOS/Linux native publishing/packaging checks also passed.The isolated-module regression now explicitly verifies session disposal and actual child termination before directory cleanup. Windows access/sharing/lock errors are logged and retried for at most five seconds, then propagated; non-Windows and other filesystem errors are not retried. Engine assertions, per-test hang guard, suite budget and production behavior are unchanged. Copied file attributes are retained in test diagnostics.
After the repair, the complete App suite passes 589 tests, 0 failed, 0 skipped on each of 7.4.6, 7.4.20, 7.5.11 and installed 7.6.6 locally. Successful command:
dotnet test tests\Devolutions.Terminal.App.Tests\Devolutions.Terminal.App.Tests.csproj -c Release -p:SkipNativeRestore=true --no-build;DT_ISEBERG_PSHOMEselected each isolated runtime. All fresh latest-head CI checks also pass as recorded above.Renamed module/layout/signing verification
Devolutions.Iseberg.PowerShell.dll, discovered beside executables, retains private IPC behaviorSingleAssemblyModuleAuthenticatesAndExecutesWithoutContractsDllasserts the exact root discovery path, copies only this DLL, authenticates, checks the child assembly identityDevolutions.Iseberg.PowerShell, verifies no contracts reference/load, executes persistent state, parses incomplete input, checks the SMA-free parent, and verifies disposal/child exit. Full App runs above include this regression.INSTALLLOCATION. Published Windows GUI-subsystemdt.exe --helpwas explicitly waited for and exited 0.IsebergModuleIncludedInReleaseSigningInputexecutes the actualSign-Packages.ps1against an inert signer fixture and verifies the complete input-file list, including the root DLL.TrustedTimestampedRecursivePayload,UnsignedBinaryRejected-Devolutions.Iseberg.PowerShell.dll,MissingTimestampRejected-Devolutions.Iseberg.PowerShell.dll,PublisherMismatchRejected-Devolutions.Iseberg.PowerShell.dll, andMissingRequiredIsebergModuleRejectedprove the signature-verification contract. All 17 regressions passed usingpwsh -NoLogo -NoProfile -File src\Devolutions.Terminal.Package\Scripts\Test-WindowsPayloadSignaturesRegression.ps1. These use simulated certificate/tool responses, not production signing credentials.TerminalOnlyPayloadDoesNotRequireIsebergModulepreserves signature validation for explicitly terminal-only payloads. Eight checks against the actual publish target accept the root module and reject a missing module, old root DLL, old bridge directory, nested renamed module, separate contracts DLL, SMA and CoreCLR.The original renamed-module process/handshake subset passed 14 tests on 7.4.6 and 14 on installed 7.6.6 using
dotnet test tests\Devolutions.Terminal.App.Tests\Devolutions.Terminal.App.Tests.csproj -c Release -p:SkipNativeRestore=true --no-build --filter 'FullyQualifiedName~PortableIseProcessTests|FullyQualifiedName~PortableIseHandshakeTests'. Fresh manual-test native output is underartifacts\iseberg-module-renamed\win-x64; the follow-up changes only test cleanup and documentation.No additional comprehensive native GUI verification was run, as requested. Release-only CA signing requires the existing protected signing environment; normal PR CI exercises its signing-selection/verification regressions rather than claiming signed release artifacts.
Prior automatic-profile verification
AutomaticIsebergProfileFollowsDetectedPowerShellAndBuildFlag,MissingPowerShellDoesNotGenerateIseberg,DisabledPowerShellSourceAlsoDisablesAutomaticIseberg, andAutomaticIsebergPreservesExistingProfilesDefaultAndUserOverridesprovide focused behavioral evidence.dotnet test tests\Devolutions.Terminal.Settings.Tests\Devolutions.Terminal.Settings.Tests.csproj -c Release -p:EnablePowerShellIse=false --filter 'FullyQualifiedName~DynamicProfileGeneratorTests|FullyQualifiedName~LinuxRuntimeEnvironmentTests'.Prior single-DLL verification (before the assembly rename/layout change)
Iseberg.PowerShellassembly, noIseberg.Contractsreference/load, persistent execution/parser behavior and the SMA-free parent.Prior native GUI evidence
Before assembly consolidation, delivery-published native GUI automation passed on 7.4.6/.NET 8.0.10 and installed 7.6.6/.NET 10.0.12: editor/native-console shared state, accepted completion, typed Read-Host, Stop/recovery,
$psISEreverse callbacks, saved-script breakpoint/Step Over/Continue, resize/RawUI updates and cleanup. A prior compatibility publish also passed on 7.4.20.Each retained the same child PID and loaded the then-two published net8 bridge/contracts assemblies. Parent enumeration found 80 modules with no SMA/CoreCLR/hostfxr/hostpolicy; all eight smoke-owned processes exited normally. An opening/pre-initialization resize could not be observed through GUI automation;
ResizingDuringInitializationDefersIpcUntilTheSessionIsReadycovers it through a real child instead.Cross-platform CI repairs
These are representative ISE workflows, not exhaustive Windows PowerShell ISE parity. Boundaries and evidence are documented in
docs/iseberg.md.