Repository navigation
Configurable user-profile loading: loadUserProfile() and --profile (#139) - #184
Merged
bertysentry merged 1 commit intoSep 27, 2026
Conversation
) The shell Create request hardcoded WINRS_NOPROFILE=TRUE, so commands could never get the user's profile. Unless something else had already loaded it on the host (an interactive session, for example), they ran with the Default profile: USERPROFILE and the starting directory were C:\Users\Default, APPDATA was unset, and HKEY_CURRENT_USER was not the user's hive. - WinRMClient.Builder.loadUserProfile() sends WINRS_NOPROFILE=FALSE on every shell the client creates: commands, file transfers, remote file operations, and a shell recreated after the server reaped the previous one. Not loading the profile stays the default. - It is a client setting, next to consoleCodePage (WINRS_CODEPAGE rides the same OptionSet), rather than the per-command option the issue proposed. With a per-command option pinned by the first command, a long-lived client would get whatever its first command happened to ask for, and the option would have had to be threaded through the WindowsRemoteExecutor SPI and every file-transfer leg. - The unreleased LightWinRMService.createInstance overload added by #141 takes the new parameter; no further overload. - CLI: --profile, for the command and shell subcommands. - Docs: a "Loading the user profile" section in commands.md, the cli.md options table (and the -d default, which is C:\Users\Default when the profile is not loaded), and the winrm4j migration page: winrm4j always loads the profile. Verified live on Windows Server 2008 R2 with an account that has no session: without the profile, USERPROFILE and the starting directory are C:\Users\Default, APPDATA is unset and an HKCU marker is invisible; with --profile, all of them are the user's own. On hosts where the account's profile was already loaded, both modes behave the same. Co-Authored-By: Claude Opus 5.5 <[email protected]>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5ada4cf891
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
bertysentry
deleted the
139-configurable-user-profile-loading-winrs_noprofile-is-hardcoded-winrs--noprofile
branch
September 27, 2026 23:03
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #139.
What
Load the user profile in the remote command shell, the opposite of
winrs -noprofile. The default is unchanged: without the option, the client still sendsWINRS_NOPROFILE=TRUE.CLI:
--profile, valid withcommandandshell, like-dand--env.Design: a client setting, not a per-command one
The issue proposed
client.command(...).loadUserProfile(), pinned by the client's first command likeworkingDirectory(...). This PR makes it a builder setting instead (decided while implementing), next toconsoleCodePage(...), whoseWINRS_CODEPAGEtravels in the same CreateOptionSet:upload(...)transfer legs, the PowerShell file fallback, remote file operations, and the silent recreation of a reaped shell. The per-command form needed two newWindowsRemoteExecutorSPI overloads and threading through everyShellFileCopyleg; Codex caught exactly that gap forenvironmenton Shell environment variables: environment(name, value) on the fluent API and --env NAME=VALUE on the CLI (winrs -env) #156.LightWinRMService.createInstanceoverload added by Kerberos credential delegation: allowDelegation() and CLI --allow-delegate (winrs -allowdelegate) #141 is not released yet, so it takes the new parameter in place rather than gaining yet another overload.Verified live
On Windows Server 2008 R2, with a local account that has no session on the host:
--profile%USERPROFILE%, starting directoryC:\Users\DefaultC:\Users\<user>%APPDATA%,%LOCALAPPDATA%%TEMP%C:\Windows\TempHKEY_CURRENT_USERThe CLI
shellsubcommand shows the same difference in its prompt:C:\Users\Default>without the option,C:\Users\<user>>with it.On the Server 2016, 2019 and 2022 test hosts both modes behave the same, because those accounts' profiles were already loaded: interactive or disconnected sessions, and on the 2016 host a hive that the User Profile Service log shows loaded since 2026-09-04. The docs state this: without the option, a command sees the profile only if something else already loaded it.
Not verified: the failure for an account that is not a local administrator, because every test account is an administrator. The docs cite Microsoft's
winrsdocumentation for it; the failure surfaces as aWinRMFaultException, the path every Create fault takes.Tests
WinRMClientTest.expiredCachedShellIsRecreatedAndTheCommandRetried: withloadUserProfile(), both Create requests carryWINRS_NOPROFILE=FALSE, the original shell's and the one recreated after the reap.WinRmCliTest: the full-stackexecandshelltests pass--profileand assert it on the wire (theshellsession opens its own connection). The help test covers the new line.CliArgumentsTest: off by default;--profileis rejected outsidecommandandshell.WsmanProtocolTestalready asserted the defaultTRUE.mvn clean verify siteis green on JDK 25: 319 tests, and checkstyle, PMD and SpotBugs report nothing. CI runs it on JDK 17.Docs
--profilerow, and a fix to the-ddefault, which isC:\Users\Defaultwhen the profile is not loaded.WINRS_NOPROFILE=FALSE, so migrated commands lose the profile unless the client callsloadUserProfile().Found along the way
#183: piping input into a command that exits without reading it fails the run with fault 232 and loses the output. It is a pre-existing race, unrelated to this change.
🤖 Generated with Claude Code