Skip to content

docs(architecture): select direct Windows CLI invocation from WSL - #57

Merged
hcoona merged 1 commit into
main-v2from
architecture/direct-wsl-windows-cli
Sep 11, 2026
Merged

hcoona merged 1 commit into
main-v2from
architecture/direct-wsl-windows-cli

Conversation

@hcoona

@hcoona hcoona commented Sep 11, 2026

Copy link
Copy Markdown
Owner

Summary

Select direct WSL invocation of the Windows CLI and document the single Windows authentication owner. Add the deployment view, matching security/validation boundaries, and the concrete company-repository account scenario. Establish from pinned official source that Azure Artifacts consumes the same Azure DevOps token-acquisition capability as Git.

Authorization and Governing Records

Accepted main-v2 2128cb8db5544a38c88b67cb3a8ff37e56789adf, its Delivery Wave, and #35 authorize high-level architecture and public desk research. The owner selected direct Windows CLI invocation and the personal/work-account Azure DevOps scenarios. Decisions 0003/0004 and existing request, interaction, lifetime, and output requirements govern.

Scope and Non-Goals

High-level deployment and evidence only. No product implementation, detailed contract design, Profile activation, platform-support declaration, Linux forwarding layer, package/Git adapter, or experiment. The next Slice's detailed-design authorization will be a separate Wave change.

Record-System Impact

Existing architecture, user-stories, public-research baseline, threat-model narrative, and validation families. No new family, control, policy, or authority. Native TMT input remains unchanged: the existing external caller and Windows CLI exchange the same request/result flows; the deployment view locates those roles on their hosts.

Evidence and Reasoning

Microsoft's WSL documentation supplies direct executable/pipe/argument semantics. Upstream AzureAD#460 remains a forwarding proposal; AzureAD#462 remains open/unmerged Linux-broker work. Azure Artifacts Credential Provider bca6c32fdb9611aea25819147ef4508f730aa5fb and GCM 6760f0ef069c994aa2bb1d703fb374986ee82a3e use the same Azure DevOps MSAL scope. NuGet session-token exchange belongs to the external adapter. This is source evidence and architectural inference, not new runtime evidence.

Identity and Security Effects

Windows owns configuration, selected-account validation, broker/UI/state, deadline, and output. The authorized WSL caller receives the token through the ordinary CLI contract. No account fallback, Linux config authority, network bridge, token file, or assumed Linux-signal termination. Existing Profile/tenant and secure-state boundaries remain. No private account, repository, or feed information is retained.

Validation

  • git diff --check: passed.
  • Normal local hk checks: passed, including all 32 public-build runner conformance groups.
  • GitHub Repository Controls: passed (run).
  • Native TMT input unchanged; no new native open/analysis claim.

Review and Disposition

Independent reviewer /root/preparation_review found no material findings in record-system, research-evidence, architecture/requirements/security consistency, and minimality review. Reviewed base 2128cb8db5544a38c88b67cb3a8ff37e56789adf, tree 52edf223f171cc1118ff6118bc1b5907597554d1; Review binding is recorded in this PR. RECHECK-003/005 fire and have dated source outcomes; all seven registry entries are evaluated in the research addition. Owner's direct-invocation decision is represented by the architecture proposal; no new risk acceptance or runtime effect is sought.

Upstream Provenance

Public-source findings link exact Artifacts and GCM commits. No production code imported; no upstream compatibility or support commitment inherited.

Place the caller in WSL and keep authentication policy, configuration, UI,
state, and result ownership in the Windows CLI. Align the threat model and
scenario coverage, including requested personal and work accounts.

Record pinned Artifacts and GCM source evidence for the shared Azure DevOps
token capability while leaving consumer credential exchange in adapters.

Refs: #35
@hcoona

hcoona commented Sep 11, 2026

Copy link
Copy Markdown
Owner Author

Independent review by /root/preparation_review, independent of the change author and implementation agent /root.

  • Accepted base: 2128cb8db5544a38c88b67cb3a8ff37e56789adf.
  • Exact reviewed tree: 52edf223f171cc1118ff6118bc1b5907597554d1.
  • Carrier: this PR and Develop the V2 high-level architecture and resolve decision-critical feasibility risks #35.
  • Accepted record-system-review Skill: No material findings.
  • Accepted research-evidence-review Skill: No material findings.
  • Contextual architecture, requirements consistency, security, and minimality: No material findings. No material finding requires triage.

The deployment fits the current high-level architecture grant. WSL calls the Windows CLI directly, leaving one configuration/authentication/UI/state/result owner. The C4 view locates existing roles without adding a forwarding engine, protocol, service, or token file. Launch failures stay distinct from CLI outcomes. Windows cancellation/disconnect, deadline, output, and Profile/runtime eligibility remain concrete later design/validation obligations, without a Linux-signal termination guarantee or support claim.

The reviewer independently inspected pinned Artifacts scope and session-exchange sources at bca6c32fdb9611aea25819147ef4508f730aa5fb. They support the shared Azure DevOps MSAL resource/scope and the downstream bearer-to-session-token exchange. They do not imply feed permissions, package operation success, interchangeable account/tenant contexts, or a new adapter.

All seven recheck dispositions were evaluated. RECHECK-003/005 fire and have bounded outcomes. Official WSL interop and MSAL WSL guidance support the separate execution models. The reviewer checked PR AzureAD#462's own embedded OPEN / mergedTime:null metadata and patch ending at dea657fda153a45ffe782755f952a2890e42db13; unrelated merged badges do not describe that PR. The retained Profile/store/account/interaction requirements remain unchanged.

The five existing records update deployment, user context, evidence, security interpretation, and validation together. Existing TMT caller/CLI flows already carry the same request/result assets; host placement adds no new native-model flow or trust boundary. No policy/Wave expansion, implementation, experiment, or private target access occurs. The reviewer performed read-only repository/public-source inspection and exact-tree whitespace checking; normal hk and CI remain separate gates.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant