Skip to content

Repair Windows updater, trust-store security and integration fixtures - #170

Merged
RobLe3 merged 2 commits into
mainfrom
fix/windows-updater-compilation
Sep 7, 2026
Merged

RobLe3 merged 2 commits into
mainfrom
fix/windows-updater-compilation

Conversation

@RobLe3

@RobLe3 RobLe3 commented Sep 6, 2026 •

Copy link
Copy Markdown
Owner

Owning defects

Closes #168. Closes #169. Closes #171. Part of #150.

  • Non-Unix updater compilation: automatic self-update reports unsupported and re-exec does not spawn an overlapping provider. Unix behavior is unchanged.
  • Conservative Windows PID checks: non-inheritable synchronization handles, zero-time waits, every valid handle closed; denied/unknown owners still refuse takeover.
  • Windows trust store: explicit current-owner/LocalSystem DACLs at exclusive creation, actual permission checks, broad-ACL and reparse refusal, bounded platform adapter. File data is flushed before replacement; the Unix-only parent-directory barrier is documented without a Windows power-loss claim.
  • Portable service quoting, Python interpreter and native tunnel fixtures. The native fake avoids a Unix shebang and orphaned sleep subprocesses; it is created inside the per-test cleanup root. Production tunnel behavior is unchanged.

Verification

  • Complete Windows cargo test --locked: PASS (exit 0) on the existing diagnostic VM. Existing ignored tests remain ignored; this is not qualification credit.
  • Focused Windows trust-store/operator checks: 6/6 PASS; native tunnel checks: 8/8 PASS; no focused skips.
  • Local dependency policy, formatting, locked tests and all-feature clippy preflight PASS. Disposable build output cleaned by the existing guard.
  • Private clean-HEAD Sentrux comparison: no additional degradation. The tracked official baseline already has complexity 58 versus 64 on unchanged source; it was not reset. This PR does not claim that old baseline is green.
  • Companion Python ACL parity is tracked in Verify Windows ACL enforcement for the opt-in dispatch trust store iicp-client-python#136; TypeScript repair is PR Make credential-bearing identity writes interruption-safe #117.

Keep draft pending cumulative artifact/install result review. No new allocation, deployment, publication or stable designation. Source/artifact pins must be refreshed after reviewed source changes; diagnostic overlays never amend the immutable candidate or earn qualification credit.

@RobLe3

RobLe3 commented Sep 6, 2026

Copy link
Copy Markdown
Owner Author

Same-VM update: the quoted-path correction passes all 44 node binary tests; all 245 library tests pass. Additional integration suites passed before the separate dispatch trust-store failure tracked in #171. The complete Windows lane remains FAIL and this PR remains draft; no qualification credit.

@RobLe3 RobLe3 changed the title Fix Windows updater build and conservative instance-lock recovery Repair Windows updater, trust-store security and integration fixtures Sep 6, 2026
@RobLe3

RobLe3 commented Sep 6, 2026

Copy link
Copy Markdown
Owner Author

The complete Windows cargo test --locked rerun passed at the current repaired source (exit 0), including Windows ACL and native tunnel fixtures. Existing ignored tests are still excluded. The cumulative artifact/install attempt has started on the same VM; PR remains draft pending that result. No new allocation or qualification credit.

@RobLe3

RobLe3 commented Sep 7, 2026

Copy link
Copy Markdown
Owner Author

Bounded source review completed at 61684d2: reviewed all 13 changed files, including non-Unix updater refusal, non-inheritable Windows process synchronization handles, ACL checks/private creation, platform-specific directory flushing and portable fixtures. Required test check is SUCCESS at this exact head; no new Rust compilation was performed for this review. No merge-blocking finding in the reviewed diff. This does not resolve #172 or provide Windows qualification: the clean packaged guest run and original Cargo failure diagnosis remain pending. New Cargo diagnostics and builder instrumentation are kept outside this PR.

@RobLe3
RobLe3 marked this pull request as ready for review September 7, 2026 19:23
@RobLe3
RobLe3 merged commit 97c2558 into main Sep 7, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant