Skip to content

Use JNA/WMI instead of PowerShell to list Windows processes - #4718

Open
janhoy wants to merge 12 commits into
apache:mainfrom
janhoy:jna-wmi-windows-cmdline
Open

janhoy wants to merge 12 commits into
apache:mainfrom
janhoy:jna-wmi-windows-cmdline

Conversation

@janhoy

@janhoy janhoy commented Aug 7, 2026 •

Copy link
Copy Markdown
Contributor

Description

On Windows, SolrProcessManager (used by the bin/solr status CLI) discovers running Solr processes by reading each Java process's command line. Since ProcessHandle does not expose command lines on Windows, it previously spawned powershell.exe running Get-CimInstance -ClassName Win32_Process ... | ConvertTo-Json and parsed the JSON.

This PR replaces that with a direct WMI (Win32_Process) query via JNA (jna-platform), so no external process is spawned and PowerShell no longer needs to be present/enabled.

Changes

  • Add net.java.dev.jna:jna-platform to solr-core.
  • Rewrite commandLinesWindows() to use CoInitializeEx → WmiQuery → CoUninitialize; drop the PowerShell JSON parsing helper and its unit test.
  • Tighten the test security policy: remove the broad <<ALL FILES>> execute grant (only needed to exec powershell) and add the JNA native-library load / jna.* property-read permissions instead.

Notes

Draft pending validation on a Windows runner.

SolrProcessManager previously spawned a powershell.exe process running
Get-CimInstance to obtain command lines of Java processes on Windows.
Replace this with a WMI (Win32_Process) query via JNA, avoiding an
external process spawn and the dependency on PowerShell being present.

- Add net.java.dev.jna:jna-platform dependency to solr-core
- Drop the PowerShell JSON parsing helper and its test
- Remove the broad "<<ALL FILES>>" execute grant from the test security
  policy (only needed to exec powershell) and add the JNA native-library
  load / jna.* property-read permissions instead
Comment thread solr/core/src/java/org/apache/solr/cli/SolrProcessManager.java Outdated
janhoy added 5 commits August 22, 2026 15:13
…line

# Conflicts:
#	solr/core/gradle.lockfile
#	solr/cross-dc-manager/gradle.lockfile
#	solr/modules/analysis-extras/gradle.lockfile
#	solr/modules/cross-dc/gradle.lockfile
#	solr/modules/jwt-auth/gradle.lockfile
#	solr/modules/ltr/gradle.lockfile
#	solr/modules/s3-repository/gradle.lockfile
#	solr/solrj/gradle.lockfile
#	solr/webapp/gradle.lockfile
Filter java processes with 'WHERE Name LIKE %java%' in the WMI query
instead of checking the process name in the loop. WMI LIKE is
case-insensitive, matching the previous behaviour. Thanks to @chan-dx
for the suggestion and for validating it on Windows.
The initial lockfile regeneration (resolveAndLockAll only) omitted the
compileClasspathCopy/runtimeClasspathCopy/testCompileClasspathCopy/
testRuntimeClasspathCopy configurations that the jar-checks
'collectJarInfos' task resolves, causing CI to fail with 'Resolved
net.java.dev.jna:jna(-platform) which is not part of the dependency lock
state'. Regenerated with 'resolveAndLockAll collectJarInfos --write-locks'
so the *Copy configurations are included.
SOLR-15465 (apache#4793) removed jna-LICENSE-ASL.txt and jna-NOTICE.txt on main
since jna was not shipped there. This PR adds jna-platform to solr-core,
making jna a shipped runtime dependency, so its LICENSE/NOTICE are required
again. The merge dropped them; restore both.
…line

# Conflicts:
#	solr/core/gradle.lockfile
#	solr/modules/jwt-auth/gradle.lockfile
#	solr/modules/s3-repository/gradle.lockfile
#	solr/solrj-zookeeper/gradle.lockfile
#	solr/test-framework/gradle.lockfile
@janhoy
janhoy marked this pull request as ready for review September 20, 2026 23:30
@janhoy

janhoy commented Sep 20, 2026

Copy link
Copy Markdown
Contributor Author

The cost of this change is two added jars ~3.4 MB to the dist.

@janhoy
janhoy requested a review from malliaridis September 21, 2026 08:32
@janhoy
janhoy requested a review from epugh October 6, 2026 10:50
@janhoy

janhoy commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Added @malliaridis and @epugh as reviewers since you know something about Windows and may want to consider this change.

@malliaridis malliaridis left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry for the late reply, I missed this one. Change looks solid, tested it locally, challenged with an agent and reviewed agent output. It is faster too. 👍 Left a comment about a potential edge case.

Comment thread solr/core/src/java/org/apache/solr/cli/SolrProcessManager.java
@epugh

epugh commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

i want our windows users to remain well supported, so +1... I could imagine in the future if we wanted to put the -slim version of Solr on a diet AGAIN, we would remove windows support for example.

janhoy added 2 commits October 7, 2026 15:16
…line

# Conflicts:
#	solr/core/gradle.lockfile
#	solr/solr-ref-guide/gradle.lockfile
@janhoy

janhoy commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

@chan-dx I credited you as author in the changelog, thanks for the help reviewing and testing.
Will merge soon

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants