| 1 | <?xml version="1.0" encoding="utf-8"?> |
| 2 | <!-- (c) 2006 Microsoft Corporation --> |
| 3 | <policyDefinitionResources xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" revision="0.1" schemaVersion="0.1" xmlns="http://schemas.microsoft.com/GroupPolicy/2006/07/PolicyDefinitions"> |
| 4 | <displayName><!-- _locComment_text='{Locked="WSL"}' -->WSL</displayName> |
| 5 | <description><!-- _locComment_text='{Locked="Windows Subsystem for Linux"}' -->Windows Subsystem for Linux</description> |
| 6 | <resources> |
| 7 | <stringTable> |
| 8 | <string id="WindowsSubsystemForLinux"><!-- _locComment_text='{Locked="Windows Subsystem for Linux"}' -->Windows Subsystem for Linux</string> |
| 9 | |
| 10 | <string id="AllowWSL"><!-- _locComment_text='{Locked="Windows Subsystem for Linux"}' -->允许使用 Windows Subsystem for Linux</string> |
| 11 | <string id="AllowWSLExplain"><!-- _locComment_text='{Locked="Windows Subsystem for Linux"}' -->设置为“已禁用”后,此策略将禁止计算机上的所有用户访问在 Windows Subsystem for Linux 中运行的 Linux 分发版。</string> |
| 12 | |
| 13 | <string id="AllowInboxWSL"><!-- _locComment_text='{Locked="Windows Subsystem for Linux"}' -->允许使用 Windows Subsystem for Linux 的预装版本</string> |
| 14 | <string id="AllowInboxWSLExplain"><!-- _locComment_text='{Locked="Windows Subsystem for Linux"}{Locked="WSL"}' -->设置为“已禁用”后,此策略将禁用 Windows Subsystem for Linux 的预装版本(可选组件)。如果禁用此策略,则只能使用 WSL 的 Microsoft Store 版本。</string> |
| 15 | |
| 16 | <string id="AllowWSL1"><!-- _locComment_text='{Locked="WSL1"}' -->允许 WSL1</string> |
| 17 | <string id="AllowWSL1Explain"><!-- _locComment_text='{Locked="WSL1"}{Locked="WSL2"}' -->设置为禁用时,此策略将禁用 WSL1。禁用后,只能使用 WSL2 分发。</string> |
| 18 | |
| 19 | <string id="CustomKernelUserSettingConfigurable">允许自定义内核配置</string> |
| 20 | <string id="CustomKernelExplain"><!-- _locComment_text='{Locked=".wslconfig"}{Locked="wsl2.kernel"}{Locked="Store WSL"}' -->设置为“已禁用”后,此策略将通过 .wslconfig (wsl2.kernel)禁用自定义内核配置。此策略仅适用于 Microsoft Store WSL。</string> |
| 21 | |
| 22 | <string id="CustomSystemDistroUserSettingConfigurable">允许自定义系统分发配置</string> |
| 23 | <string id="CustomSystemDistroExplain"><!-- _locComment_text='{Locked=".wslconfig"}{Locked="wsl2.systemDistro"}{Locked="Store WSL"}' -->设置为“已禁用”后,此策略通过 .wslconfig (wsl2.systemDistro)禁用自定义系统分发配置。此策略仅适用于 Microsoft Store WSL。</string> |
| 24 | |
| 25 | <string id="CustomKernelCommandLineUserSettingConfigurable">允许内核命令行配置</string> |
| 26 | <string id="CustomKernelCommandLineExplain"><!-- _locComment_text='{Locked=".wslconfig"}{Locked="wsl2.kernelCommandLine"}{Locked="Store WSL"}' -->设置为“已禁用”后,此策略通过 .wslconfig (wsl2.kernelCommandLine)禁用内核命令行配置。此策略仅适用于 Microsoft Store WSL。</string> |
| 27 | |
| 28 | <string id="AllowDebugShell">允许调试 shell</string> |
| 29 | <string id="AllowDebugShellExplain"><!-- _locComment_text='{Locked="wsl.exe"}{Locked="debug-shell"}{Locked="Store WSL"}' -->设置为“已禁用”后,此策略将禁用调试 shell (wsl.exe --debug-shell)。此策略仅适用于 Microsoft Store WSL。</string> |
| 30 | |
| 31 | <string id="NestedVirtualizationUserSettingConfigurable">允许嵌套虚拟化</string> |
| 32 | <string id="NestedVirtualizationExplain"><!-- _locComment_text='{Locked=".wslconfig"}{Locked="wsl2.nestedVirtualization"}{Locked="Store WSL"}' -->设置为“已禁用”后,此策略通过 .wslconfig (wsl2.nestedVirtualization)禁用嵌套虚拟化配置。此策略仅适用于 Microsoft Store WSL。</string> |
| 33 | |
| 34 | <string id="KernelDebugUserSettingConfigurable">允许内核调试</string> |
| 35 | <string id="KernelDebugExplain"><!-- _locComment_text='{Locked=".wslconfig"}{Locked="wsl2.kernelDebugPort"}{Locked="Store WSL"}' -->设置为“已禁用”后,此策略通过 .wslconfig (wsl2.kernelDebugPort)禁用内核调试配置。此策略仅适用于 Microsoft Store WSL。</string> |
| 36 | |
| 37 | <string id="CustomNetworkingUserSettingConfigurable">允许自定义网络配置</string> |
| 38 | <string id="CustomNetworkingExplain"><!-- _locComment_text='{Locked=".wslconfig"}{Locked="wsl2.networkingMode"}{Locked="Store WSL"}' -->设置为“已禁用”后,此策略将通过 .wslconfig (wsl2.networkingMode)禁用自定义网络配置。此策略仅适用于 Microsoft Store WSL。</string> |
| 39 | |
| 40 | <string id="FirewallUserSettingConfigurable">允许用户设置防火墙配置</string> |
| 41 | <string id="FirewallExplain"><!-- _locComment_text='{Locked=".wslconfig"}{Locked="wsl2.firewall"}{Locked="Store WSL"}' -->设置为“已禁用”后,此策略将通过 .wslconfig (wsl2.firewall)禁用防火墙配置。此策略仅适用于 Microsoft Store WSL。</string> |
| 42 | |
| 43 | <string id="AllowDiskMount">允许直通磁盘装载</string> |
| 44 | <string id="AllowDiskMountExplain"><!-- _locComment_text='{Locked="WSL2"}{Locked="wsl.exe"}{Locked="mount"}{Locked="Store WSL"}' -->When set to disabled, this policy disables passthrough disk mounting in WSL2 (wsl.exe --mount). This policy only applies to Store WSL.</string> |
| 45 | |
| 46 | <string id="DefaultNetworkingMode">配置默认网络模式</string> |
| 47 | <string id="DefaultNetworkingModeExplain"><!-- _locComment_text='{Locked="WSL2"}' -->此策略指定要用于 WSL2 的默认网络模式。</string> |
| 48 | <string id="NetworkingModeNone"><!-- _locComment_text="{Locked}" -->None</string> |
| 49 | <string id="NetworkingModeNAT"><!-- _locComment_text="{Locked}" -->NAT</string> |
| 50 | <string id="NetworkingModeMirrored"><!-- _locComment_text="{Locked}" -->Mirrored</string> |
| 51 | <string id="NetworkingModeVirtioProxy"><!-- _locComment_text="{Locked}" -->Consomme</string> |
| 52 | |
| 53 | <string id="WSLContainer"><!-- _locComment_text='{Locked="WSL"}' -->WSL 容器</string> |
| 54 | |
| 55 | <string id="AllowWSLContainer"><!-- _locComment_text='{Locked="WSL"}' -->允许 WSL 容器</string> |
| 56 | <string id="AllowWSLContainerExplain"><!-- _locComment_text='{Locked="WSL"}{Locked="Disabled"}' -->此策略控制是否可在此计算机上使用 WSL 容器。如果已启用或未配置,则用户和 Windows 应用程序可以通过 WSL 运行 Linux 容器。如果设置为“Disabled”,则会阻止所有用户使用 WSL 容器,并且 Windows 应用无法运行 Linux 容器。警告: 将此项设置为“Disabled”可能会导致依赖 Linux 容器的 Windows 应用无法正常工作。</string> |
| 57 | |
| 58 | <string id="AllowWSLContainerPrivileged"><!-- _locComment_text='{Locked="WSL"}' -->允许特权 WSL 容器</string> |
| 59 | <string id="AllowWSLContainerPrivilegedExplain"><!-- _locComment_text='{Locked="WSL"}{Locked="Disabled"}' -->此策略控制 WSL 容器是否可以在此计算机上以特权模式运行。如果已启用或未配置,则用户和 Windows 应用程序可以启动特权容器。如果设置为 "Disabled",则所有用户和 Windows 应用都会拒绝启动特权容器的请求。特权容器使用提升的 Linux 功能运行,并减少与容器主机的隔离。</string> |
| 60 | |
| 61 | <string id="WSLContainerRegistryAllowlist"><!-- _locComment_text='{Locked="WSL"}' -->WSL 容器注册表的允许列表</string> |
| 62 | <string id="WSLContainerRegistryAllowlistExplain"><!-- _locComment_text='{Locked="WSL"}' -->启用后,WSL 容器将仅允许从此处列出的注册表中拉取映像。这会影响 WSL 容器 CLI 和所有使用 WSL 容器 API 的应用程序。</string> |
| 63 | </stringTable> |
| 64 | <presentationTable> |
| 65 | <presentation id="DefaultNetworkingMode"> |
| 66 | <dropdownList refId="DefaultNetworkingMode_Dropdown" noSort="true" defaultItem="1">默认网络模式</dropdownList> |
| 67 | </presentation> |
| 68 | <presentation id="WSLContainerRegistryAllowlist"> |
| 69 | <listBox refId="WSLContainerRegistryAllowlist_Input">允许的注册表</listBox> |
| 70 | </presentation> |
| 71 | </presentationTable> |
| 72 | </resources> |
| 73 | </policyDefinitionResources> |