Skip to content

proof: Write Restricted Code SID is load-bearing#48

Closed
marksverdhei wants to merge 10 commits into
clankerfrom
chloe/pr46-write-restricted-red-proof
Closed

proof: Write Restricted Code SID is load-bearing#48
marksverdhei wants to merge 10 commits into
clankerfrom
chloe/pr46-write-restricted-red-proof

Conversation

@marksverdhei

Copy link
Copy Markdown
Contributor

Remove SID 70 from the exact PR #46 candidate while retaining the protected-ACL executable regression unchanged. This draft exists only to run hosted Windows CI and will not merge.\n\nExpected proof: the Everyone-only denial remains green, then the Write Restricted Code allow assertion fails with AccessDenied.\n\nActing-Agent: chloe

marksverdhai and others added 10 commits July 25, 2026 17:39
Reconcile the queued dependency updates across Cargo, Bazel, pnpm, and CI metadata. Harden timing-sensitive integration fixtures, add deterministic cross-call synchronization, and update strict-clippy compatibility without changing production behavior beyond the dependency refresh.

Acting-Agent: chloe
Run non-cancelled post-merge Windows coverage on both integration branches and update the fork guide to consistently name clanker as the default branch.

Acting-Agent: chloe
Normalize Windows paths in app-server and avatar assertions, give shell-command unit tests hosted-runner headroom, and use the Restricted Code SID instead of Everyone for restricted-token initialization without weakening world-writable path isolation.

Acting-Agent: chloe
Use a temporary absolute project path for the memory scope fixture and compensate path-normalized TUI snapshots for the Windows drive-prefix width before rendering. Linux snapshot geometry remains unchanged.

Acting-Agent: Chloe
Exercise the actual WRITE_RESTRICTED token against protected ACL fixtures. Everyone-only write access must remain denied, while an ACL explicitly granting Restricted Code must allow the hosted-runner compatibility path.

Acting-Agent: Chloe
Guard the restricted-token impersonation so a failing assertion cannot leave the Windows test thread impersonated. Explicit successful reversion remains checked.

Acting-Agent: Chloe
Use the Write Restricted Code SID for write-restricted process compatibility without allowing Everyone-only writes. Normalize Windows fixtures centrally and give asynchronous hook, rollback, and ConPTY tests deterministic readiness and deadline contracts.

Acting-Agent: chloe
Resolve private desktop names from the process window station, inherit the caller desktop for default launches, and grant the restricted logon SID the station and desktop rights required by user32 initialization.\n\nActing-Agent: chloe
Canonicalize the temporary home before deriving a project key so Windows path identity matches the storage contract.\n\nActing-Agent: chloe
Remove only SID 70 from the production restricting-SID list while retaining the executable ACL regression. The const-level dead-code allowance is an inert proof-branch compile aid.\n\nExpected result: Everyone-only denial passes and the Write Restricted Code allow assertion fails.\n\nActing-Agent: chloe
@marksverdhei

Copy link
Copy Markdown
Contributor Author

Superseded before evidence by the security-amended candidate 2577171. No result from this stale-parent proof will be used. Acting-Agent: Chloe

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants