microsoft / microsoft/winget-cli

Upgrade flags --all and --unninstall-previous naively includes own running shell

Open
#5,316 9 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

Issue-Feature
Dominant language
C++
Stars
26.4k
Forks
1.8k
Avg merge
1d 11h
Merged PRs (30d)
15

Description

Brief description of your issue

Running winget upgrade with flags --all and --uninstall-previous will include running shell's package, leaving it's own and any other instances to run out of RAM or crash. If shell can run out of RAM, programs like neovim which rely heavily on i/o feedback become unpredictable and unusable. winget upgrade is interrupted without notice.

Steps to reproduce

Using pwsh.exe.

Shell session 1
pwsh.exe  # shell that can run from RAM
nvim      # any i/o heavy program
Shell session 2
pwsh.exe  # open installed, out-of-date shell
winget upgrade  # assert at least 2 packages and Microsoft.Powershell is not last
winget upgrade --all --uninstall-previous # will remove own shell amid runtime
Then
  • Try interacting with shell session 1.
  • Try opening another pwsh.exe instance.
  • (lastly) Try interacting with shell session 2.
Expected behavior

Error, unskipable warning prompt, or unsafe flag to prevent or force explicit action.

Actual behavior
  • Uninstalls shell it is running in without question.
  • Process terminates/halts without notice.
  • Shell may crash or become unusable.
  • Scrambled/bad data at other sessions of same uninstalled shell.
  • No warnings are issued.
  • Package's executable is not compared with own shell's executable.
Environment
Windows Package Manager v1.10.340
Copyright (c) Microsoft Corporation. All rights reserved.

Windows: Windows.Desktop v10.0.19045.5608
System Architecture: X64
Package: Microsoft.DesktopAppInstaller v1.25.340.0

Winget Directories
-------------------------------------------------------------------------------------------------------------------------------
Logs                               %LOCALAPPDATA%\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\DiagOutputDir
User Settings                      %LOCALAPPDATA%\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\settings.json
Portable Links Directory (User)    %LOCALAPPDATA%\Microsoft\WinGet\Links
Portable Links Directory (Machine) C:\Program Files\WinGet\Links
Portable Package Root (User)       %LOCALAPPDATA%\Microsoft\WinGet\Packages
Portable Package Root              C:\Program Files\WinGet\Packages
Portable Package Root (x86)        C:\Program Files (x86)\WinGet\Packages
Installer Downloads                %USERPROFILE%\Downloads
Configuration Modules              %LOCALAPPDATA%\Microsoft\WinGet\Configuration\Modules

Links
---------------------------------------------------------------------------
Privacy Statement   https://aka.ms/winget-privacy
License Agreement   https://aka.ms/winget-license
Third Party Notices https://aka.ms/winget-3rdPartyNotice
Homepage            https://aka.ms/winget
Windows Store Terms https://www.microsoft.com/en-us/storedocs/terms-of-sale

Admin Setting                             State
--------------------------------------------------
LocalManifestFiles                        Disabled
BypassCertificatePinningForMicrosoftStore Disabled
InstallerHashOverride                     Disabled
LocalArchiveMalwareScanOverride           Disabled
ProxyCommandLineOptions                   Disabled
DefaultProxy                              Disabled

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The reported entry point is winget upgrade --all --uninstall-previous, reproduced from two pwsh.exe sessions; start by reproducing the self-uninstall and tracing how the upgrade list handles the running shell. Done means the command detects or safely warns about its own executable, or requires explicit confirmation or force behavior, with this scenario verified.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp, powershell
Domain
cli, operating-systems
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.