Merge nucleic/lucid-river-toad-6efj into dev

This commit is contained in:
2026-07-29 03:57:12 -07:00
parent 71157c0d6e
commit f5cd4a3023
3 changed files with 102 additions and 7 deletions
+11 -6
View File
@@ -180,12 +180,17 @@ for, and nothing above it should move. These three are different:
mounted vs. in-VM). Deliberately held back until `WslcApiDump` has run: written now, against
guessed names, it would not compile, and fixing it blind is the mistake this whole approach
exists to avoid.
- **The internal arm itself** (`WslcInternal.cs` in the broker, not a spike) — now fully
de-risked by `--internal-call`: entry point, vtable, impersonation requirement and the
session→compat handoff are all confirmed on hardware. Shape is *find, then hand off*:
`OpenSessionByName` / `ListContainers` / `OpenContainer`, each result QI'd onto its compat
interface and passed to `FromAbi()`, after which the existing facade code drives it. The
container-level QI is the one step still unobserved — confirm it in `WslcSpike` below.
- **The internal arm, Tier 1 — "recover"** (`WslcInternal.cs` in the broker, not a spike).
Everything it needs is confirmed on hardware: entry point, vtable, impersonation, and
`OpenSessionByName`. On broker restart, open the orphaned session, `ListContainers` for
reporting, `Terminate` it, and create a fresh one through the compat SDK — automatic clean
recovery instead of a manual `wsl --shutdown`. Enough for M2.
- **Tier 2 — "adopt"** (keep containers running across a broker restart) is **blocked**. The
`Session.FromAbi()` handoff throws `InvalidCastException` even though the QI to
`IWSLCCompatSession` succeeds: the WinRT layer appears to be a client-side wrapper in
`wslcsdk.dll`, not the service object. `--internal-call` now compares COM identity to confirm.
If confirmed, Tier 2 means driving exec/stdio through internal COM directly
(`IWSLCContainer::Exec`, `IWSLCProcess::GetStdHandle` — handle-based, not event-based).
- **`GatewaySpike`** — M1 (b), and the control-plane spike that actually matters now: can a
`Bridged` wslc container reach the host at the `vEthernet (WSL)` address `WslcFacade` returns,
under the **default** Windows firewall, and does `control-bridge.js` complete an MCP round trip