Use fixed user-profile state for UI and Sandbox - #931
Conversation
Keep the unreleased coordination and target records in fixed user-profile state, independent of the cache override and package identity. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Drop premature user documentation for unreleased internal state paths. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Two moderate storage-path and error-classification issues remain unresolved.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Moves UI coordination and Sandbox target state to stable, cache-independent user-profile storage.
Changes:
- Adds
%USERPROFILE%\.winapp\statepath resolution. - Updates UI and Sandbox defaults while preserving overrides.
- Adds focused tests and documentation.
Unresolved comments:
- Moderate (2 votes): Use a distinct storage-unavailable error instead of
sandbox_target_stalefor invalid profile paths, with tests and documentation. - Moderate (1 vote): Prevent the fallback cache path from placing project files alongside shared profile state.
| File | Description |
|---|---|
src/winapp-CLI/WinApp.Cli/Services/WinappDirectoryService.cs |
Resolves profile state and separates it from project cache discovery. |
src/winapp-CLI/WinApp.Cli/Services/InteractiveDesktop/InteractiveDesktopPaths.cs |
Uses profile-based UI coordination state. |
src/winapp-CLI/WinApp.Cli/ExecutionTargets/Orchestration/TargetStateDirectoryProvider.cs |
Uses profile-based Sandbox target state. |
src/winapp-CLI/WinApp.Cli.Tests/WinappDirectoryServiceTests.cs |
Tests cache and profile-state separation. |
src/winapp-CLI/WinApp.Cli.Tests/TargetStateDirectoryProviderTests.cs |
Tests target paths and override precedence. |
src/winapp-CLI/WinApp.Cli.Tests/InteractiveDesktopStoreTests.cs |
Tests cache-independent UI paths. |
docs/usage.md |
Documents shared runtime state. |
docs/ui-automation.md |
Documents UI coordination storage. |
docs/sandbox-execution.md |
Documents Sandbox target storage. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Avoid treating an unusable user-profile state root as a stale Sandbox; give callers a storage-specific recovery code. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Build Metrics ReportValidation passed. All required build and validation jobs succeeded. Binary Sizes
.NET Test Results (TRX reports)Other suites are reflected in the overall validation status above. ✅ 7843 passed, 37 skipped out of 7880 tests in 1249.6s (+7 tests, -39.7s vs. baseline) Test Coverage✅ 86% line coverage, 80.7% branch coverage · ✅ no change vs. baseline CLI Startup Time64ms median (x64, Try This BuildInstalls the MSIX for your architecture, replacing any previously installed build. Needs the GitHub CLI — the command offers to install it and sign you in if it is missing. & ([scriptblock]::Create((irm https://raw.githubusercontent.com/microsoft/winappCli/main/scripts/winapp-pr.ps1))) 931Switching between builds often?Put the tool on your PATH once: & ([scriptblock]::Create((irm https://raw.githubusercontent.com/microsoft/winappCli/main/scripts/winapp-pr.ps1))) -AddToPathThen this build is just: winapp-pr 931Run Updated 2026-09-23 04:46:03 UTC · commit |
|
On the overview's remaining fallback-cache concern: when a project is beneath the user profile, GetLocalWinappDirectory skips the profile .winapp even if WINAPP_CLI_CACHE_DIRECTORY points elsewhere, then returns the project's own .winapp (covered by GetLocalWinappDirectory_WithCacheOverride_DoesNotUseProfileStateAsProjectCache). If the user profile itself is the project directory, its fallback has always been profile/.winapp; the new coordination data sits in a distinct state/ subdirectory, so no project file is placed in the coordination directory. Changing project-cache fallback for that pre-existing case would expand this location-only PR without fixing a collision. |
Decision: mergeable as-is. Clean, well-scoped relocation; build is warning-free and all changed-area tests pass. One non-blocking gap noted below. Non-blocking:
|
Map state-directory creation failures to the existing storage error while preserving read-only resolution and target-path validation. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
Addressed the non-blocking storage-error finding from Zach Teutsch (@zateutsch) in 03a124d. A local regression test reproduced raw |

Description
Keep unreleased UI coordination and Windows Sandbox target state in a shared physical user-profile location, rather than LocalAppData or package-redirected storage. UI locks now default to
%USERPROFILE%\.winapp\state\ui; each Sandbox target defaults to%USERPROFILE%\.winapp\state\targets\<target-key>. These paths do not followWINAPP_CLI_CACHE_DIRECTORY. ExistingWINAPP_UI_LOCK_DIRECTORYandWINAPP_TARGET_STATE_ROOToverrides retain precedence. A profile.winappused for state is not mistaken for a project's local cache when the global cache is overridden. Invalid or inaccessible target-state storage reportssandbox_state_unavailable, not a stale Sandbox; one troubleshooting row describes recovery.Usage Example
winapp ui click Submit -a MyAppcoordinates through%USERPROFILE%\.winapp\state\uiby default; commands on--on sandboxkeep target records under%USERPROFILE%\.winapp\state\targets\<target-key>. The exact paths and override precedence are covered by focused tests, not a live Sandbox session.Related Issue
N/A — intentionally separate from the broader, still-open #873; no changes to that PR.
Type of Change
Checklist
build-and-packageCI on latest commit03a124dc(in progress; previous head passed)Screenshots / Demo
N/A — nonvisual path relocation.
Additional Notes
The released 0.6.2 behavior has no UI coordination or Sandbox target state contract to migrate. This PR intentionally excludes filesystem fallback, cache relocation, ACL redesign, and changes to #873. No merge or auto-merge requested.
AI Description
This section is auto-generated by AI when the PR is opened or updated. To opt out, delete this entire section including the marker comments.