Skip to content

Windows launcher (CI run only) - #7

Closed
basal-alfonso[bot] wants to merge 8 commits into
mainfrom
ci/windows-launch
Closed

basal-alfonso[bot] wants to merge 8 commits into
mainfrom
ci/windows-launch

Conversation

@basal-alfonso

@basal-alfonso basal-alfonso Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Draft to run the Windows CI job on the Windows launcher crate. Not for merge as-is.


Summary by cubic

Draft to run the Windows CI job over the new basal-launch crate and the Windows fs built-in; it's not for merge as-is.

What's in the diff

  • basal-launch starts the worker under the Windows confinement: AppContainer profile, restricted lowboxed tokens, owned job, eight mitigation policies, child-process ban, explicit handle list, minimal environment, and parent checks on the suspended process before resume.
  • The Windows fs built-in enforces raw-spelling grammar, component-wise path resolution, temp-and-rename replacement, and reparse-point denial, with Windows-specific refusal tests.
  • CI runs the launcher's own tests first with the deviations feature and continue-on-error, so their output appears in the log even when later workspace steps fail.
  • Windows targets now link the C runtime statically via .cargo/config.toml.

Fixes from the first Windows run

  • A worker already being ended by the job now counts as killed, so kill() no longer fails with access denied.
  • The worker's TEMP uses the canonical long path, since the system's short-name (8.3) paths are not writable under Low integrity.

Written for commit 8c40332. Summary will update on new commits.

View guided diff Turn on auto-fix

Windows reserves COM and LPT followed by a superscript one, two or three
as well as the ASCII digits. Also write the device-name check as one
matches! so it passes clippy.
A new workspace crate that starts basal's worker under the Windows
confinement; off Windows it contains no code.

- Profile: one shared AppContainer profile, created or opened under a
  session-wide named mutex; failure is appcontainer-profile-unavailable.
  Userenv and User32 are loaded at run time from System32 only.
- Tokens: the primary is a restricted copy of the parent's token (every
  access group deny-only, no privileges, NULL SID as the only restricting
  SID, Low), lowboxed at creation with zero capabilities. The start-up
  thread token is a Low same-package impersonation token derived from a
  never-resumed AppContainer process, set on the suspended main thread
  and closed before resume.
- Creation: CreateProcessAsUserW with STARTUPINFOEX, suspended: LPAC
  security capabilities with the ALL_APPLICATION_PACKAGES opt-out, the
  job list, eight always-on mitigations, the child-process ban, and a
  handle list of exactly the three stdio pipes. Explicit sorted
  environment (SYSTEMROOT, windir, SYSTEMDRIVE, PATH to System32,
  TEMP/TMP/LOCALAPPDATA to a private read-only directory), the image
  directory as cwd, and a private window station and desktop. The
  parent's environment is never passed on.
- Job: flags 0x2508, one live process, no breakaway, the caller's
  commit limit, UI restrictions 0xff.
- Checks before resume: job-limits-mismatch, not-in-owned-job,
  birth-token-mismatch and initial-token-open, each killing the child.
- ConfinedProcess owns process, job and pipes: kill (job, then process,
  exit 137), try_wait, wait, token and job read-back.
- Deviation: Full only without the `deviations` feature; with it, the
  LPAC-only and plain controls and one variant per worker and parent
  check.
- Tests start a GUI-subsystem test child for real. CI's Windows job
  runs them first with `--features deviations`.
- +crt-static for x86_64-pc-windows-msvc in .cargo/config.toml.
…g TEMP path

On windows-latest, kill() failed with access denied: TerminateJobObject
had already begun ending the worker, so the following TerminateProcess
was refused while the process was not yet signaled. A successful job
kill of a worker that is a member of the job is now a successful kill.

The LPAC-only control's TEMP write failed with Win32 3, not 5: the
system TEMP path holds 8.3 short names (RUNNER~1). The worker's TEMP is
now the canonical long path, and the control's assertion accepts any
denial, since only the plain control needs to show the path is writable.
@basal-alfonso

basal-alfonso Bot commented Oct 10, 2026

Copy link
Copy Markdown
Author

Closing: its contents are merged on the integration/windows branch.

@basal-alfonso basal-alfonso Bot closed this Oct 10, 2026
@ualtinok
ualtinok deleted the ci/windows-launch branch October 10, 2026 16:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant