Skip to content

Delete Windows workspaces recoverably with daemon and session teardown - #499

Merged
coneilen merged 5 commits into
mainfrom
coneilen-microsoft-recoverable-workspace-deletion
Sep 28, 2026
Merged

coneilen merged 5 commits into
mainfrom
coneilen-microsoft-recoverable-workspace-deletion

Conversation

@coneilen

@coneilen coneilen commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Enable safe deletion of non-current Windows workspaces through the workspace manager and existing menu path. Deletion stages the folder, stops its own daemon, moves it to the Recycle Bin, then ends saved terminal sessions; failure paths report whether the folder was restored or remains staged.

Changes

  • Add a tested teardown policy with target-daemon identity checks, bounded shutdown, recoverable recycle operation, rollback reporting, and session termination only after successful recycle.
  • Enable the manager Delete action using the existing Default/current/open/unidentified-workspace refusals and post-confirmation identity validation.
  • Keep the parity ledger row Partial; real daemon/session/recycle and UIA walkthrough evidence is not available, and extra tab/split sessions saved outside the workspace folder remain undiscoverable.

Test plan

RED: zig test src\WorkspaceTeardown.zig -target x86_64-windows-msvc -lc -ladvapi32 -lshell32 -lkernel32 -ID:\depot\GraphCode-worktrees\graphcode-win.graphcode-tools\providers-public\winghosty\include -> 188 passed, 13 failed with WorkspaceTeardownUnimplemented; manager/form API-boundary failures were compile errors, not behavioral evidence.
GREEN: zig test src\WorkspaceTeardown.zig -target x86_64-windows-msvc -lc -ladvapi32 -lshell32 -lkernel32 -ID:\depot\GraphCode-worktrees\graphcode-win.graphcode-tools\providers-public\winghosty\include -> 218 passed; WorkspaceManager 31 passed; WorkspaceManagerForm 282 passed; filtered App workspace tests 86 passed.
REGRESSION: pwsh -NoProfile -File Tools\windows\Tests\WindowsShell.Tests.ps1 -ZigExecutable D:\depot\GraphCode-worktrees\graphcode-win.graphcode-tools\zig-0.15.2\zig.exe -> 668 tests passed, 51 source files executed; zig build -Doptimize=ReleaseSafe -Dwinghostty-dir=D:\depot\GraphCode-worktrees\graphcode-win.graphcode-tools\providers-public\winghostty -> passed.

All commands used the repository's already-pinned Zig/provider by absolute path with caches redirected to session scratch; no toolchain was installed or downloaded. The Windows shell suite and ReleaseSafe build were run before the final line-ending-only normalization; the teardown test root was rerun after it and passed 218 tests. git diff --check origin/main...HEAD passes. The full validate.ps1 -Task windows-shell was not run because it builds Winghostty inside a shared provider tree; unfiltered App-root linking also remains unavailable in this worktree due to the provider host library build constraint.

Checklist

  • I have read the Contributing Guidelines
  • I have signed off my commits (git commit -s) per the DCO
  • Focused tests and the Windows shell suite pass locally (the repo-wide make test is macOS-only and was not run)
  • Code follows the existing style (make check is macOS-only and was not run)
  • I added the test/contract before the implementation and observed the intended RED failure

coneilen and others added 5 commits September 28, 2026 12:22
Introduce WorkspaceTeardown, the Windows counterpart of the macOS
WorkspaceClient.delete contract: stage the folder aside, stop the
workspace's daemon, move the folder to the Recycle Bin, and only then
end its saved terminal sessions. Killing a session cannot be undone, so
it runs after the fallible steps; every failure before it puts the
folder back and says so.

Extract daemonLockNameFor from DaemonClient.currentDaemonLockName so a
daemon other than this window's own can be addressed, and refuse any
target whose lock name matches the current one.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin O'Neill <coneilen@microsoft.com>
Delete becomes a real manager action guarded by the rules rename already
uses: never Default, never this window's workspace, never one open
elsewhere or behind a window we could not identify, and revalidated
against the live path after the choice is made.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin O'Neill <coneilen@microsoft.com>
Route both the menu path and the manager's Delete button through one
teardown: refuse, reserve, confirm, revalidate identity after the
confirmation, then stop the daemon, recycle the folder and end the saved
sessions. The status now reports what actually happened, including a
rollback or a folder left staged, instead of a flat success.

Register the new test root in the Windows shell suite.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin O'Neill <coneilen@microsoft.com>
The row stays Partial: the teardown is proven through an injected seam,
so nothing here claims a live recycle, a real daemon exit, or sessions
actually ending, and sessions saved outside the workspace folder are
still out of reach.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin O'Neill <coneilen@microsoft.com>
The new WorkspaceTeardown.zig was written with CRLF endings while every
other Windows shell source in the repository uses LF, so git diff --check
reported trailing whitespace on every added line.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Colin Neilens <coneilen@microsoft.com>
@coneilen
coneilen merged commit 558206c into main Sep 28, 2026
17 of 19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant