Repository navigation
Windows worker entry (CI run only) - #8
Closed
basal-alfonso[bot] wants to merge 16 commits into
Closed
basal-alfonso[bot] wants to merge 16 commits into
basal-alfonso[bot] wants to merge 16 commits into
Conversation
Windows reserves COM and LPT followed by a superscript one, two or three as well as the ASCII digits. Also write the device-name check as one matches! so it passes clippy.
The module now compiles for Windows (x86_64 and aarch64 MSVC) with no warnings under clippy -D warnings, and its tests can run. Writes: - Every directory from the volume root down to the target's parent is held without FILE_SHARE_DELETE until the rename returns, so none can be moved out of the root mid-write; the parent's location is re-checked just before the rename. - A failed flush of the temporary file stops the write before the rename. - A new file is created with no explicit security descriptor, so NTFS applies real inheritance; the CreatePrivateObjectSecurity path is gone. A replaced file keeps its DACL, protection flag included. - The root is selected by the whole path, so a write to a file root works. - Intermediate directories are opened with attribute and traverse access only; a directory target is refused as "not a regular file". - A read-only target is replaced, as renameat ignores a target's mode. Roots and opens: - Root handles are reopened with the access each use needs, so a file root can be read and a directory root listed. - A failed directory query is an error, never an empty listing. - Walk errors keep their kind across roots (IO, then NOT_FOUND, then the refusal); a volume root X:\ grants its children; a file root is opened without FILE_TRAVERSE. - The reparse check fails closed, and the temp-file cleanup removes only regular files. - Directory replies are parsed as bytes bounded by the reported length, the rename buffer is 8-byte aligned and written through raw pointers, UNICODE_STRING lengths are checked, and OwnedHandle's field is private. - remove_temp walks to the lease's own directory. Tests: link-based tests assert the link exists; the swap test uses expect_err; the DACL tests apply a DACL and compare SDDL (P on replace, ID ACEs on create); new tests cover list, subdirectory create, remove_temp, legacy temps, volume roots, mount points, the held parent, flush failure and temp-name collisions. The test hooks are thread-local. The POSIX refusal test now matches the real message. fs.rs only gates helpers Windows does not use, and shares outside/io_denial/TEMP_SEQ.
A new workspace crate that starts basal's worker under the Windows confinement; off Windows it contains no code. - Profile: one shared AppContainer profile, created or opened under a session-wide named mutex; failure is appcontainer-profile-unavailable. Userenv and User32 are loaded at run time from System32 only. - Tokens: the primary is a restricted copy of the parent's token (every access group deny-only, no privileges, NULL SID as the only restricting SID, Low), lowboxed at creation with zero capabilities. The start-up thread token is a Low same-package impersonation token derived from a never-resumed AppContainer process, set on the suspended main thread and closed before resume. - Creation: CreateProcessAsUserW with STARTUPINFOEX, suspended: LPAC security capabilities with the ALL_APPLICATION_PACKAGES opt-out, the job list, eight always-on mitigations, the child-process ban, and a handle list of exactly the three stdio pipes. Explicit sorted environment (SYSTEMROOT, windir, SYSTEMDRIVE, PATH to System32, TEMP/TMP/LOCALAPPDATA to a private read-only directory), the image directory as cwd, and a private window station and desktop. The parent's environment is never passed on. - Job: flags 0x2508, one live process, no breakaway, the caller's commit limit, UI restrictions 0xff. - Checks before resume: job-limits-mismatch, not-in-owned-job, birth-token-mismatch and initial-token-open, each killing the child. - ConfinedProcess owns process, job and pipes: kill (job, then process, exit 137), try_wait, wait, token and job read-back. - Deviation: Full only without the `deviations` feature; with it, the LPAC-only and plain controls and one variant per worker and parent check. - Tests start a GUI-subsystem test child for real. CI's Windows job runs them first with `--features deviations`. - +crt-static for x86_64-pc-windows-msvc in .cargo/config.toml.
…g TEMP path On windows-latest, kill() failed with access denied: TerminateJobObject had already begun ending the worker, so the following TerminateProcess was refused while the process was not yet signaled. A successful job kill of a worker that is a member of the job is now a successful kill. The LPAC-only control's TEMP write failed with Win32 3, not 5: the system TEMP path holds 8.3 short names (RUNNER~1). The worker's TEMP is now the canonical long path, and the control's assertion accepts any denial, since only the plain control needs to show the path is writable.
… fs tests pass natively)
getentropy exists only on Unix. On Windows the system-preferred RNG supplies each journaled draw, and there is still no fallback when it fails. (cherry picked from commit a69f2b0)
The workspace test can't build until every crate compiles on Windows, so basal-host's built-ins get their own test step that reports now. (cherry picked from commit 990ce58)
…nch tests pass natively)
The worker builds and confines itself on Windows under basal-launch: - GUI-subsystem image (no console host); an import test checks the subsystem, the forbidden GUI/COM DLLs and that no C runtime DLL is imported. - --package-sid parsing: missing exits 70 package-sid-argument-missing, unparsable or repeated exits 64. - Startup steps 1-6 before the first frame read: revert and require ERROR_NO_TOKEN, lower the primary to Untrusted and close the handle, close the CSR ALPC port and private File handles, check the actual primary token, check single mitigation bits, check the handle table against two per-image profiles that are never combined. Each failure exits 70 with its reason token. A step-3 failure (snapshot or close) is reported as handle-not-allowed, since the spec names no token for it. - The checks are pure functions tested on every system; the readers and the sequence are Windows-only. - Thread CPU clock from GetThreadTimes; JsClock takes an injectable sample source. The existing real-clock test keeps its claim but uses budgets and burns of several scheduler ticks, because Windows advances the clock a tick (~15.6 ms) at a time. - A `deviations` feature lets a test worker act on --confinement-deviation for the three checks the parent cannot break; without it the argument is refused as unknown (exit 64). Tests that use basal-testkit are gated off Windows until it builds there, and basal-testkit becomes a non-Windows dev-dependency. Windows worker tests spawn through basal-launch. The windows-baseline job runs the worker's tests on their own, with and without the feature.
The executable-name fence requires test processes to run a ckdev- copy of the worker, never a ck- named binary. The Windows worker tests copy the built worker to ckdev-basal-worker.exe (their own helper, since basal-testkit does not build on Windows yet) and launch or inspect that. The worker-depends-on-a-subc-crate control anchors on basal-worker's Cargo.lock dependency list, which now also names windows-sys; its anchor and replacement include that entry.
Author
|
Closing: its contents are merged on the integration/windows branch. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Draft to run the Windows CI job on the Windows worker startup checks. Not for merge as-is.
Summary by cubic
Draft to run the Windows CI job against the Windows worker entry and its startup checks. Not for merge as-is.
The PR lands the Windows worker path: a new
basal-launchcrate that starts the worker under the Windows confinement, the worker's six startup checks, a Windows implementation of thefsbuilt-in, a thread CPU clock fromGetThreadTimes, and the CI workflow changes that exercise them.basal-launchbuilds the AppContainer profile, restricted tokens, job, mitigations, and the parent's checks on the suspended child before it resumes.windows_imagetests assert both.deviationsfeature adds test-only launch variants, one per confinement check, used by the launcher and worker tests.basal-testkitare gated off Windows until that crate builds there; Windows worker tests copy the built worker to ackdev-name and spawn it throughbasal-launch.windows-baselineCI job runs the launcher and worker tests on their own, before the workspace steps that still cannot build.Written for commit 719a928. Summary will update on new commits.