Engineering Improvement
Area for Improvement
Implement section 1 of the #12887 plan, "Centralize the windowless non-interactive policy," as a separate draft PR. Keep this sub-task limited to the shared pkg/process policy and its focused tests/documentation.
Observed behavior
pkg/process currently returns *exec.Cmd from Command and CommandContext. On Windows, process_windows.go uses GetConsoleCP to detect whether Radius has an attached console. With no console, it applies HideWindow and CREATE_NO_WINDOW; on other platforms, configuration is a no-op.
The console policy is not exposed as a shared query for tool adapters. Default child stdin is nil, which Go already connects to the null device and therefore supplies EOF. Making this an explicit, documented windowless default is policy clarification, not a claim that nil stdin currently permits interactive reads or that EOF alone prevents all credential/plugin prompts.
Desired behavior
Expose one small, documented query for the current Windows no-console policy so later tool-specific changes can reuse it. Make the command constructors use that same policy and explicitly provide EOF stdin by default in Windows no-console mode, while preserving caller-supplied data streams.
Acceptance criteria:
- Preserve automatic Windows console detection using
GetConsoleCP, including Windows Terminal/ConPTY compatibility. Do not use GetConsoleWindow as the console-presence probe.
- Expose the shared policy without adding an environment switch, CLI flag, cross-platform automation mode, or terminal query during package initialization.
- Keep the existing
Command and CommandContext signatures and *exec.Cmd contract. Both constructors use the same policy decision.
- In Windows no-console mode, initialize stdin to an explicit EOF source only when no input has been supplied. Preserve an existing input reader and allow callers to set a finite payload after construction; PostgreSQL restore must continue to send SQL through stdin.
- Leave attached-console and non-Windows input/process behavior unchanged.
- Preserve existing
SysProcAttr fields and creation flags while applying HideWindow and CREATE_NO_WINDOW. Do not set DETACHED_PROCESS or CREATE_BREAKAWAY_FROM_JOB, and preserve caller Job Object containment.
- Preserve caller context cancellation, normal stdout/stderr, and exit behavior. Add no execution timeout defaults, deadline requirements, watchdog, child-process launcher, or global environment mutation.
- Cover the policy query, both constructors, explicit EOF, preserved finite input, attached-console/non-Windows behavior, and Windows flag preservation with focused existing Go test infrastructure. Use helper processes where needed to prove actual input delivery rather than only inspecting fields.
- Document the default-input contract and its limitation: it does not force arbitrary external tools or SDK-owned credential helpers to be non-interactive.
Proposed Fix
Make a small change in pkg/process/process.go, pkg/process/process_windows.go, pkg/process/process_other.go, and relevant process tests. Reuse the existing console-test hook and test patterns where appropriate. Patch current documentation only as necessary to accurately describe the shared policy.
This sub-task can be implemented independently against current main because it does not depend on the Azure-wrapper removal in #12942 or Git-archive removal in #12944. Do not duplicate either removal or stack this branch on them. Preserve their eventual documentation changes if touching the same current guide.
Out of scope: Bicep context/pipe changes; kubeconfig exec-auth validation; PostgreSQL --no-password; tool-specific prompt handling or environment-merging helpers; Azure SDK changes; Git archive changes; OCI storage changes; SDK migrations; broad CI/test reorganization. Do not edit eng/design-notes or add migration guidance. These other parts of #12887 remain separate work.
Open the PR as draft, apply pr:standard to the PR, and close only this sub-issue. Reference #12887 as the parent without closing it. Do not merge the PR.
System information
rad Version
Source inspection at a0654b16470228271daa8875889b189bb8951c21 on main. Refresh main before implementation.
Operating system
Windows amd64 and arm64, with unchanged behavior on non-Windows platforms.
Additional context
Parent: #12887. Preserve the behavior established by #12883 / #12885, including non-detached callers and the discriminating FreeConsole-based Windows regression setup. This is a shared-policy foundation for subsequent Bicep/kubectl work, not completion of the parent issue's full prompt-prevention scope.
Engineering Improvement
Area for Improvement
Implement section 1 of the #12887 plan, "Centralize the windowless non-interactive policy," as a separate draft PR. Keep this sub-task limited to the shared
pkg/processpolicy and its focused tests/documentation.Observed behavior
pkg/processcurrently returns*exec.CmdfromCommandandCommandContext. On Windows,process_windows.gousesGetConsoleCPto detect whether Radius has an attached console. With no console, it appliesHideWindowandCREATE_NO_WINDOW; on other platforms, configuration is a no-op.The console policy is not exposed as a shared query for tool adapters. Default child stdin is nil, which Go already connects to the null device and therefore supplies EOF. Making this an explicit, documented windowless default is policy clarification, not a claim that nil stdin currently permits interactive reads or that EOF alone prevents all credential/plugin prompts.
Desired behavior
Expose one small, documented query for the current Windows no-console policy so later tool-specific changes can reuse it. Make the command constructors use that same policy and explicitly provide EOF stdin by default in Windows no-console mode, while preserving caller-supplied data streams.
Acceptance criteria:
GetConsoleCP, including Windows Terminal/ConPTY compatibility. Do not useGetConsoleWindowas the console-presence probe.CommandandCommandContextsignatures and*exec.Cmdcontract. Both constructors use the same policy decision.SysProcAttrfields and creation flags while applyingHideWindowandCREATE_NO_WINDOW. Do not setDETACHED_PROCESSorCREATE_BREAKAWAY_FROM_JOB, and preserve caller Job Object containment.Proposed Fix
Make a small change in
pkg/process/process.go,pkg/process/process_windows.go,pkg/process/process_other.go, and relevant process tests. Reuse the existing console-test hook and test patterns where appropriate. Patch current documentation only as necessary to accurately describe the shared policy.This sub-task can be implemented independently against current main because it does not depend on the Azure-wrapper removal in #12942 or Git-archive removal in #12944. Do not duplicate either removal or stack this branch on them. Preserve their eventual documentation changes if touching the same current guide.
Out of scope: Bicep context/pipe changes; kubeconfig exec-auth validation; PostgreSQL
--no-password; tool-specific prompt handling or environment-merging helpers; Azure SDK changes; Git archive changes; OCI storage changes; SDK migrations; broad CI/test reorganization. Do not editeng/design-notesor add migration guidance. These other parts of #12887 remain separate work.Open the PR as draft, apply
pr:standardto the PR, and close only this sub-issue. Reference #12887 as the parent without closing it. Do not merge the PR.System information
rad Version
Source inspection at
a0654b16470228271daa8875889b189bb8951c21on main. Refresh main before implementation.Operating system
Windows amd64 and arm64, with unchanged behavior on non-Windows platforms.
Additional context
Parent: #12887. Preserve the behavior established by #12883 / #12885, including non-detached callers and the discriminating
FreeConsole-based Windows regression setup. This is a shared-policy foundation for subsequent Bicep/kubectl work, not completion of the parent issue's full prompt-prevention scope.