Warning
This document is a working artifact for the development of this feature and is meant to be DELETED before merging the PR. Do not reference it from code or docs that will outlive the PR.
As an operator adding instances through ServiceControl Management Utility (SCMU), I want every audit instance to be connected to a ServiceControl (error) instance so that messages the audit instance sends to the error instance always have a valid destination.
Bug: #4753 — SCMU does not set ServiceControlQueueAddress when only adding audit instances. When the
ServiceControl.Audit/ServiceControlQueueAddresssetting is missing fromServiceControl.Audit.exe.config, the audit instance fails at runtime with "no destination specified for message".
When the user installs an error instance and an audit instance together, the audit instance's queue address is the name of the error instance being installed — never an already-installed one.
- Example: The one where both instances are installed together and the audit instance's queue address is the new error instance's name.
- Counter-example: The one where other error instances already exist on the machine, yet no choice is offered — the error instance being installed always wins.
- Example: The one where exactly one error instance exists on the machine and its name is used as the queue address without any user input (no dropdown shown).
Auto-detection cannot guess between several error instances — picking one silently risks routing messages to the wrong instance. The choice dropdown is shown only in this case.
- Example: The one where two error instances exist and the dropdown offers both.
- Example: The one where Save is blocked until the user picks one of the detected instances, and unblocked once a choice is made.
Detection only sees instances installed on the local machine, but the error instance may legitimately live elsewhere — e.g. several VMs each hosting an audit instance that feeds one central error instance for load balancing. When nothing is detected locally, the user must supply the queue address of the (possibly remote) error instance; Save stays blocked until a value is entered so a config entry is always written.
- Example: The one where no error instance is detected and Save is blocked until the user enters the remote error instance's address, then unblocked once entered and the entered value is used as the queue address.
- Example: The one where the entered address contains whitespace and is rejected (instance names — and therefore their queue addresses — never contain whitespace).
- Counter-example: The one where only an error instance is being installed — the queue address does not apply, no entry field is shown, and no validation error is raised.
- Auto-detect source: installed Windows error instances, discovered via
InstanceFinder.ServiceControlInstances(); exposed on the view model through aGetInstalledErrorInstanceNamesfunction seam (mirrors the existingGetWindowsServiceNamespattern) so tests can substitute it. - Multiple instances found: user must choose from a dropdown that is visible only when adding an audit instance alone and more than one error instance is detected.
- No instance found: a required free-text field is shown (only when adding an audit instance alone and nothing is detected); Save is blocked by a validation error until a whitespace-free address is entered. Reachability of the entered address cannot be validated — a typo only surfaces at runtime (accepted limitation).
- Acceptance tier: view model + validator observed through
INotifyDataErrorInfo— the same mechanism the UI uses to block Save. A full SCMU end-to-end test (install a Windows service, inspect the written config file) is not automatable in this repository's test suites. - Out of scope: registering the new audit instance as a remote of the existing
error instance (
AddRemoteInstanceis only called when both instances are installed together) — candidate for a follow-up issue. - Out of scope: overriding auto-detection with a remote address when local error instances ARE detected (Rules 2–3 offer only detected instances). A unified editable ComboBox would remove that asymmetry — candidate for a follow-up issue.