Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
26 commits
Select commit Hold shift + click to select a range
3fa116b
mason: implement Windows host fs module and raw-spelling validation
ualtinok Oct 10, 2026
76b9008
mason: add comprehensive Windows fs refusal tests and deterministic t…
ualtinok Oct 10, 2026
3d184fc
mason: suppress unused import warning in fs test module on non-unix
ualtinok Oct 10, 2026
c63f497
Merge: the Windows fs built-in, with Windows refusal tests
ualtinok Oct 10, 2026
0611455
Refuse the superscript COM and LPT device names on Windows
ualtinok Oct 10, 2026
5621897
mason: implement Windows host git module and job containment
ualtinok Oct 10, 2026
7d24263
mason: fix the Windows fs built-in from its security review
ualtinok Oct 10, 2026
51662ad
mason: add basal-launch, the Windows confined worker launcher
ualtinok Oct 10, 2026
1f8d083
mason: clarify basal-launch comments for a reader without context
ualtinok Oct 10, 2026
8c40332
mason: treat a job-killed worker as killed, and give the worker a lon…
ualtinok Oct 10, 2026
02b46b1
Merge commit '7d24263' into alfonso/task/bg_d6985ae075a52784-basal-wi…
ualtinok Oct 10, 2026
9ea2994
Merge: Windows fs built-in fixes from its security review (44 Windows…
ualtinok Oct 10, 2026
651c119
Draw host entropy from BCryptGenRandom on Windows
ualtinok Oct 10, 2026
9cafad6
Run basal-host's tests on their own in the Windows baseline job
ualtinok Oct 10, 2026
0897adc
Re-anchor the random-source control on the shared entropy call
ualtinok Oct 10, 2026
4ada060
Merge: basal-launch, the Windows confined worker launcher (all 18 lau…
ualtinok Oct 10, 2026
0eb28a0
mason: confine Windows git reads and pin their approved directories
ualtinok Oct 10, 2026
80c4314
mason: accept the host Windows temp directory separator
ualtinok Oct 10, 2026
4bd6090
mason: observe handle inheritance in the exact Windows git child
ualtinok Oct 10, 2026
c61d815
mason: Windows worker entry and startup checks
ualtinok Oct 10, 2026
8cad58c
Merge: the Windows git built-in, redone from its security review (all…
ualtinok Oct 10, 2026
719a928
mason: run the Windows worker tests under a development name
ualtinok Oct 10, 2026
74cfacf
Merge: the Windows worker entry and startup checks (every new Windows…
ualtinok Oct 10, 2026
bafd737
Check text out with LF on every OS
ualtinok Oct 10, 2026
90525fc
mason: basal-launch shared spawn lock, OwnedProcess and spawn_plain f…
ualtinok Oct 10, 2026
998fc1e
mason: port the shared test kit and rig to Windows
ualtinok Oct 10, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .cargo/config.toml
Original file line number Diff line number Diff line change
@@ -1,3 +1,9 @@
[env]
# Allocation accounting is unused; its global mutex serializes SQLite callers.
LIBSQLITE3_FLAGS = "-DSQLITE_DEFAULT_MEMSTATUS=0"

# Link the C runtime statically on Windows, so no image imports a C runtime
# DLL. The confined worker should load only the system's own DLLs, and the
# dynamic C runtime is a separately installed component.
[target.x86_64-pc-windows-msvc]
rustflags = ["-C", "target-feature=+crt-static"]
3 changes: 3 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
# Check text out with LF on every OS. Tests read docs, fixtures and digest
# test vectors byte for byte, and a CRLF checkout on Windows would change them.
* text=auto eol=lf
46 changes: 46 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -386,6 +386,42 @@ jobs:
${{ runner.os }}-${{ runner.arch }}-cargo-${{ hashFiles('Cargo.lock') }}-${{ steps.rust.outputs.version }}-windows-baseline-
- name: Prepare the log directory
run: mkdir -p "$RUNNER_TEMP/windows-baseline"
# The Windows launcher's own tests start real confined children, so
# they can only run here. The deviations feature adds the test-only
# launch variants, one per confinement check. They run first and print
# what the parent read back, so the log shows it even when the
# workspace steps below fail.
- name: Test the Windows launcher with its test variants
id: test-launch
continue-on-error: true
timeout-minutes: 20
run: cargo test -p basal-launch --features deviations --locked -- --show-output 2>&1 | tee "$RUNNER_TEMP/windows-baseline/test-basal-launch.log"
# The worker's tests on their own: its Windows startup checks, its image
# and a real activation, each worker started through the launcher. The
# plain build is the production worker, which must refuse the
# launcher's request to skip a check. The deviations build is a test
# worker that honours that request, for the three checks the parent
# cannot break from outside.
- name: Test the worker on its own
id: test-worker
continue-on-error: true
timeout-minutes: 30
run: cargo test -p basal-worker --locked --no-fail-fast -- --show-output 2>&1 | tee "$RUNNER_TEMP/windows-baseline/test-basal-worker.log"
- name: Test the worker with its test variants
id: test-worker-deviations
continue-on-error: true
timeout-minutes: 30
run: cargo test -p basal-worker --features deviations --locked --no-fail-fast -- --show-output 2>&1 | tee "$RUNNER_TEMP/windows-baseline/test-basal-worker-deviations.log"
- name: Test the shared test kit on its own
id: test-testkit
continue-on-error: true
timeout-minutes: 30
run: cargo test -p basal-testkit --locked --no-fail-fast 2>&1 | tee "$RUNNER_TEMP/windows-baseline/test-basal-testkit.log"
- name: Test the integration rig on its own
id: test-rig
continue-on-error: true
timeout-minutes: 30
run: cargo test -p basal-rig --locked --no-fail-fast 2>&1 | tee "$RUNNER_TEMP/windows-baseline/test-basal-rig.log"
- name: Check every workspace target
id: check
continue-on-error: true
Expand All @@ -406,6 +442,13 @@ jobs:
continue-on-error: true
timeout-minutes: 40
run: cargo test --workspace --locked --no-fail-fast 2>&1 | tee "$RUNNER_TEMP/windows-baseline/test-no-fail-fast.log"
# The workspace test can't build until every crate compiles on Windows,
# so basal-host's own tests run separately to report its built-ins now.
- name: Test basal-host on its own
id: test-host
continue-on-error: true
timeout-minutes: 30
run: cargo test -p basal-host --lib --locked --no-fail-fast 2>&1 | tee "$RUNNER_TEMP/windows-baseline/test-basal-host.log"
- name: Summarize the baseline
if: always()
run: |
Expand All @@ -414,6 +457,9 @@ jobs:
echo
echo "- cargo check --workspace --all-targets --locked: ${{ steps.check.outcome }}"
echo "- cargo test --workspace --locked: ${{ steps.test.outcome }}"
echo "- cargo test -p basal-launch --features deviations --locked: ${{ steps.test-launch.outcome }}"
echo "- cargo test -p basal-testkit --locked --no-fail-fast: ${{ steps.test-testkit.outcome }}"
echo "- cargo test -p basal-rig --locked --no-fail-fast: ${{ steps.test-rig.outcome }}"
} >> "$GITHUB_STEP_SUMMARY"
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
if: always()
Expand Down
14 changes: 14 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 2 additions & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@ members = [
"crates/basal-core",
"crates/basal-testkit",
"crates/basal-module",
"crates/basal-launch",
"crates/basal-rig",
]

Expand All @@ -20,6 +21,7 @@ rust-version = "1.88"
# Dependencies do not require sibling checkouts.
basal-core = { path = "crates/basal-core" }
basal-host = { path = "crates/basal-host" }
basal-launch = { path = "crates/basal-launch" }
basal-proto = { path = "crates/basal-proto" }
basal-testkit = { path = "crates/basal-testkit" }
blake3 = "1.8"
Expand Down
3 changes: 3 additions & 0 deletions crates/basal-host/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -36,5 +36,8 @@ tokio.workspace = true
tracing.workspace = true
webpki-roots.workspace = true

[target.'cfg(windows)'.dependencies]
windows-sys = { version = "0.61.2", features = ["Win32_Foundation", "Win32_Security", "Win32_Security_Authorization", "Win32_Security_Cryptography", "Win32_Storage_FileSystem", "Win32_System_IO", "Win32_System_JobObjects", "Win32_System_Pipes", "Win32_System_Threading"] }

[dev-dependencies]
subc-transport.workspace = true
Loading
Loading