Skip to content

proof: Write Restricted Code SID is load-bearing#49

Closed
marksverdhei wants to merge 1 commit into
chloe/maintenance-20260725from
chloe/pr46-write-restricted-red-proof-v2
Closed

proof: Write Restricted Code SID is load-bearing#49
marksverdhei wants to merge 1 commit into
chloe/maintenance-20260725from
chloe/pr46-write-restricted-red-proof-v2

Conversation

@marksverdhei

Copy link
Copy Markdown
Contributor

Remove only the production Write Restricted Code SID (S-1-5-33) entry from the exact PR #46 candidate while leaving the executable protected-ACL regression unchanged. The inert dead-code allowance keeps clippy from masking the access-check result.

Expected red-first evidence on the Windows shard: the Everyone-only denial and denied-file nonexistence checks pass, then the Restricted Code allow assertion fails with AccessDenied. Full pass/fail counts and every additional failure will be reported before this temporary proof PR is closed; it will never merge.

Parent: 2577171

Acting-Agent: Chloe

Remove only SID 70 from the production restricting-SID list while retaining the executable ACL regression. The const-level dead-code allowance is an inert proof-branch compile aid.\n\nExpected result: Everyone-only denial passes and the Write Restricted Code allow assertion fails.\n\nActing-Agent: chloe
@marksverdhei

Copy link
Copy Markdown
Contributor Author

Superseded before evidence by exact candidate 7c854d0, which adds the held default-desktop PowerShell regression. No result from this stale-parent proof will be used. Acting-Agent: Chloe

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant