Skip to content

Windows worker entry (CI run only) - #8

Closed
basal-alfonso[bot] wants to merge 16 commits into
mainfrom
ci/windows-worker
Closed

basal-alfonso[bot] wants to merge 16 commits into
mainfrom
ci/windows-worker

Conversation

@basal-alfonso

@basal-alfonso basal-alfonso Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Draft to run the Windows CI job on the Windows worker startup checks. Not for merge as-is.


Summary by cubic

Draft to run the Windows CI job against the Windows worker entry and its startup checks. Not for merge as-is.

The PR lands the Windows worker path: a new basal-launch crate that starts the worker under the Windows confinement, the worker's six startup checks, a Windows implementation of the fs built-in, a thread CPU clock from GetThreadTimes, and the CI workflow changes that exercise them.

  • basal-launch builds the AppContainer profile, restricted tokens, job, mitigations, and the parent's checks on the suspended child before it resumes.
  • The worker checks its own tokens, mitigation bits, and handle table before reading its first frame, exiting with a reason token on the first failure.
  • The Windows image links the C runtime statically and imports no GUI or COM DLLs; windows_image tests assert both.
  • The deviations feature adds test-only launch variants, one per confinement check, used by the launcher and worker tests.
  • Tests that need basal-testkit are gated off Windows until that crate builds there; Windows worker tests copy the built worker to a ckdev- name and spawn it through basal-launch.
  • The windows-baseline CI job runs the launcher and worker tests on their own, before the workspace steps that still cannot build.

Written for commit 719a928. Summary will update on new commits.

View guided diff Turn on auto-fix

Windows reserves COM and LPT followed by a superscript one, two or three
as well as the ASCII digits. Also write the device-name check as one
matches! so it passes clippy.
The module now compiles for Windows (x86_64 and aarch64 MSVC) with no
warnings under clippy -D warnings, and its tests can run.

Writes:
- Every directory from the volume root down to the target's parent is
  held without FILE_SHARE_DELETE until the rename returns, so none can be
  moved out of the root mid-write; the parent's location is re-checked
  just before the rename.
- A failed flush of the temporary file stops the write before the rename.
- A new file is created with no explicit security descriptor, so NTFS
  applies real inheritance; the CreatePrivateObjectSecurity path is gone.
  A replaced file keeps its DACL, protection flag included.
- The root is selected by the whole path, so a write to a file root works.
- Intermediate directories are opened with attribute and traverse access
  only; a directory target is refused as "not a regular file".
- A read-only target is replaced, as renameat ignores a target's mode.

Roots and opens:
- Root handles are reopened with the access each use needs, so a file
  root can be read and a directory root listed.
- A failed directory query is an error, never an empty listing.
- Walk errors keep their kind across roots (IO, then NOT_FOUND, then the
  refusal); a volume root X:\ grants its children; a file root is opened
  without FILE_TRAVERSE.
- The reparse check fails closed, and the temp-file cleanup removes only
  regular files.
- Directory replies are parsed as bytes bounded by the reported length,
  the rename buffer is 8-byte aligned and written through raw pointers,
  UNICODE_STRING lengths are checked, and OwnedHandle's field is private.
- remove_temp walks to the lease's own directory.

Tests: link-based tests assert the link exists; the swap test uses
expect_err; the DACL tests apply a DACL and compare SDDL (P on replace,
ID ACEs on create); new tests cover list, subdirectory create,
remove_temp, legacy temps, volume roots, mount points, the held parent,
flush failure and temp-name collisions. The test hooks are thread-local.
The POSIX refusal test now matches the real message. fs.rs only gates
helpers Windows does not use, and shares outside/io_denial/TEMP_SEQ.
A new workspace crate that starts basal's worker under the Windows
confinement; off Windows it contains no code.

- Profile: one shared AppContainer profile, created or opened under a
  session-wide named mutex; failure is appcontainer-profile-unavailable.
  Userenv and User32 are loaded at run time from System32 only.
- Tokens: the primary is a restricted copy of the parent's token (every
  access group deny-only, no privileges, NULL SID as the only restricting
  SID, Low), lowboxed at creation with zero capabilities. The start-up
  thread token is a Low same-package impersonation token derived from a
  never-resumed AppContainer process, set on the suspended main thread
  and closed before resume.
- Creation: CreateProcessAsUserW with STARTUPINFOEX, suspended: LPAC
  security capabilities with the ALL_APPLICATION_PACKAGES opt-out, the
  job list, eight always-on mitigations, the child-process ban, and a
  handle list of exactly the three stdio pipes. Explicit sorted
  environment (SYSTEMROOT, windir, SYSTEMDRIVE, PATH to System32,
  TEMP/TMP/LOCALAPPDATA to a private read-only directory), the image
  directory as cwd, and a private window station and desktop. The
  parent's environment is never passed on.
- Job: flags 0x2508, one live process, no breakaway, the caller's
  commit limit, UI restrictions 0xff.
- Checks before resume: job-limits-mismatch, not-in-owned-job,
  birth-token-mismatch and initial-token-open, each killing the child.
- ConfinedProcess owns process, job and pipes: kill (job, then process,
  exit 137), try_wait, wait, token and job read-back.
- Deviation: Full only without the `deviations` feature; with it, the
  LPAC-only and plain controls and one variant per worker and parent
  check.
- Tests start a GUI-subsystem test child for real. CI's Windows job
  runs them first with `--features deviations`.
- +crt-static for x86_64-pc-windows-msvc in .cargo/config.toml.
…g TEMP path

On windows-latest, kill() failed with access denied: TerminateJobObject
had already begun ending the worker, so the following TerminateProcess
was refused while the process was not yet signaled. A successful job
kill of a worker that is a member of the job is now a successful kill.

The LPAC-only control's TEMP write failed with Win32 3, not 5: the
system TEMP path holds 8.3 short names (RUNNER~1). The worker's TEMP is
now the canonical long path, and the control's assertion accepts any
denial, since only the plain control needs to show the path is writable.
getentropy exists only on Unix. On Windows the system-preferred RNG supplies
each journaled draw, and there is still no fallback when it fails.

(cherry picked from commit a69f2b0)
The workspace test can't build until every crate compiles on Windows, so
basal-host's built-ins get their own test step that reports now.

(cherry picked from commit 990ce58)
The worker builds and confines itself on Windows under basal-launch:

- GUI-subsystem image (no console host); an import test checks the
  subsystem, the forbidden GUI/COM DLLs and that no C runtime DLL is
  imported.
- --package-sid parsing: missing exits 70 package-sid-argument-missing,
  unparsable or repeated exits 64.
- Startup steps 1-6 before the first frame read: revert and require
  ERROR_NO_TOKEN, lower the primary to Untrusted and close the handle,
  close the CSR ALPC port and private File handles, check the actual
  primary token, check single mitigation bits, check the handle table
  against two per-image profiles that are never combined. Each failure
  exits 70 with its reason token. A step-3 failure (snapshot or close)
  is reported as handle-not-allowed, since the spec names no token for it.
- The checks are pure functions tested on every system; the readers and
  the sequence are Windows-only.
- Thread CPU clock from GetThreadTimes; JsClock takes an injectable
  sample source. The existing real-clock test keeps its claim but uses
  budgets and burns of several scheduler ticks, because Windows advances
  the clock a tick (~15.6 ms) at a time.
- A `deviations` feature lets a test worker act on
  --confinement-deviation for the three checks the parent cannot break;
  without it the argument is refused as unknown (exit 64).

Tests that use basal-testkit are gated off Windows until it builds there,
and basal-testkit becomes a non-Windows dev-dependency. Windows worker
tests spawn through basal-launch. The windows-baseline job runs the
worker's tests on their own, with and without the feature.
The executable-name fence requires test processes to run a ckdev- copy of
the worker, never a ck- named binary. The Windows worker tests copy the
built worker to ckdev-basal-worker.exe (their own helper, since
basal-testkit does not build on Windows yet) and launch or inspect that.

The worker-depends-on-a-subc-crate control anchors on basal-worker's
Cargo.lock dependency list, which now also names windows-sys; its anchor
and replacement include that entry.
@basal-alfonso

basal-alfonso Bot commented Oct 10, 2026

Copy link
Copy Markdown
Author

Closing: its contents are merged on the integration/windows branch.

@basal-alfonso basal-alfonso Bot closed this Oct 10, 2026
@ualtinok
ualtinok deleted the ci/windows-worker branch October 10, 2026 17:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant