Skip to content

Windows: shell tool fails under machine ExecutionPolicy — proposal: process-scoped -ExecutionPolicy Bypass (sign-off request) #6745

Description

@asto18089

Summary

On Windows, machine/Group Policy Set-ExecutionPolicy makes CodeWhale's PowerShell shell tool refuse to run: shell_dispatcher.rs writes a temp .ps1 and launches powershell -File <temp>, which is blocked by policy with a localized refusal ("running scripts is disabled on this system" / 中文 / 日本語 variants). The shell surface is effectively dead on those machines even though CodeWhale itself is properly installed.

Evidence

Current main: crates/tui/src/shell_dispatcher.rs builds the temp .ps1 + -File invocation (preferring pwsh when present) but never passes -ExecutionPolicy, and the only upstream Bypass hits are installer NSI scripts and the computer-use plugin — not the shell tool.

Proposal (from the Pinvou fork, Pinvou/CodeWhale #66)

We fixed this in our fork and would like to upstream it — but it deliberately circumvents machine script policy for CodeWhale's own scripts, which is trust-boundary adjacent, so we're asking for sign-off here before opening a PR:

  1. Launch both the -File and -EncodedCommand forms with process-scoped -ExecutionPolicy Bypass (scoped to the CodeWhale child process only; machine policy is untouched and the scripts are CodeWhale-generated temp files, not user content).
  2. Bound the -EncodedCommand UTF-16LE base64 payload by the 32767-character Windows command-line limit.
  3. Retry only our own temp script's refusal — exact -File path match, with en-US/zh-CN/ja-JP refusal fingerprints; nested powershell -File inner.ps1 refusals inside script output are NOT retried; only Failed results are retried (never Killed/TimedOut).
  4. Key the UTF-8 output prefix handling on the PowerShell family including ShellKind::Custom{pwsh}.

About half the fork diff is tests (behavior tests + refusal-fingerprint fixtures). We'd re-validate on upstream's Windows CI and drop the fork-specific test prefixes. Happy to adjust the approach (e.g., a config opt-in instead of default-on) however maintainers prefer — we're looking for a direction call before writing the PR.

Linked fork work

  • Fork commit: Pinvou/CodeWhale c4e6caf94 (author zhuowp) — happy to re-author/co-author on the upstream PR.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestneeds-triageNew external report awaiting maintainer triage; repro, logs and version output help

    Projects

    • Status
      Backlog

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions