Skip to content

Windows probes and provenance (CI run only) - #9

Closed
basal-alfonso[bot] wants to merge 27 commits into
mainfrom
ci/windows-probes
Closed

basal-alfonso[bot] wants to merge 27 commits into
mainfrom
ci/windows-probes

Conversation

@basal-alfonso

@basal-alfonso basal-alfonso Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Draft to run the Windows CI jobs on the Windows probes and handle provenance. Not for merge as-is.


Summary by cubic

Enables the Windows CI run and the Windows implementation end to end: a new basal-launch crate starts the worker confined under an AppContainer profile, restricted tokens, a kill-on-close job, and mitigations; the worker then finishes confinement with its own startup checks before reading input. The fs and git built-ins get Windows implementations with refusal tests, and the windows-baseline job now runs the whole worker test suite with and without the deviations feature. Draft, not for merge as-is.

Notable changes:

  • Worker startup drops the start-up token, lowers integrity to Untrusted, and checks token, mitigation bits, and handle table against per-image profiles before its first frame.
  • Windows git reads run suspended in a non-breakaway kill-on-close job with a private config and pinned approved directories; fs writes hold parent directories and flush before rename.
  • The worker links the C runtime statically and is a GUI-subsystem image; .gitattributes forces LF checkouts so docs, fixtures, and digest vectors are byte-identical.
  • Tests using basal-testkit stay gated off Windows; the new Windows tests run the worker through basal-launch under a ckdev- copy, and a mutation-witness script removes a guard and requires the named test to fail.
  • Only socket probes preload Winsock under the start-up token before running the unchanged startup checks, so the production worker image keeps its measured five-DLL import inventory. The provenance tool records the pre-input handle table of a production release worker under full confinement; both images' measured tables fit the unchanged per-image ceilings at 25 handles, and the measurement is committed as a one-off artifact rather than a per-run check.
  • CI matrixes windows-baseline across windows-latest and windows-2022, and runs basal-host's built-in tests in their own step. Unrelated Windows workspace builds still fail in basal-core/src/retention.rs.

Written for commit c40cfc8. Summary will update on new commits.

View guided diff Turn on auto-fix

Windows reserves COM and LPT followed by a superscript one, two or three
as well as the ASCII digits. Also write the device-name check as one
matches! so it passes clippy.
The module now compiles for Windows (x86_64 and aarch64 MSVC) with no
warnings under clippy -D warnings, and its tests can run.

Writes:
- Every directory from the volume root down to the target's parent is
  held without FILE_SHARE_DELETE until the rename returns, so none can be
  moved out of the root mid-write; the parent's location is re-checked
  just before the rename.
- A failed flush of the temporary file stops the write before the rename.
- A new file is created with no explicit security descriptor, so NTFS
  applies real inheritance; the CreatePrivateObjectSecurity path is gone.
  A replaced file keeps its DACL, protection flag included.
- The root is selected by the whole path, so a write to a file root works.
- Intermediate directories are opened with attribute and traverse access
  only; a directory target is refused as "not a regular file".
- A read-only target is replaced, as renameat ignores a target's mode.

Roots and opens:
- Root handles are reopened with the access each use needs, so a file
  root can be read and a directory root listed.
- A failed directory query is an error, never an empty listing.
- Walk errors keep their kind across roots (IO, then NOT_FOUND, then the
  refusal); a volume root X:\ grants its children; a file root is opened
  without FILE_TRAVERSE.
- The reparse check fails closed, and the temp-file cleanup removes only
  regular files.
- Directory replies are parsed as bytes bounded by the reported length,
  the rename buffer is 8-byte aligned and written through raw pointers,
  UNICODE_STRING lengths are checked, and OwnedHandle's field is private.
- remove_temp walks to the lease's own directory.

Tests: link-based tests assert the link exists; the swap test uses
expect_err; the DACL tests apply a DACL and compare SDDL (P on replace,
ID ACEs on create); new tests cover list, subdirectory create,
remove_temp, legacy temps, volume roots, mount points, the held parent,
flush failure and temp-name collisions. The test hooks are thread-local.
The POSIX refusal test now matches the real message. fs.rs only gates
helpers Windows does not use, and shares outside/io_denial/TEMP_SEQ.
A new workspace crate that starts basal's worker under the Windows
confinement; off Windows it contains no code.

- Profile: one shared AppContainer profile, created or opened under a
  session-wide named mutex; failure is appcontainer-profile-unavailable.
  Userenv and User32 are loaded at run time from System32 only.
- Tokens: the primary is a restricted copy of the parent's token (every
  access group deny-only, no privileges, NULL SID as the only restricting
  SID, Low), lowboxed at creation with zero capabilities. The start-up
  thread token is a Low same-package impersonation token derived from a
  never-resumed AppContainer process, set on the suspended main thread
  and closed before resume.
- Creation: CreateProcessAsUserW with STARTUPINFOEX, suspended: LPAC
  security capabilities with the ALL_APPLICATION_PACKAGES opt-out, the
  job list, eight always-on mitigations, the child-process ban, and a
  handle list of exactly the three stdio pipes. Explicit sorted
  environment (SYSTEMROOT, windir, SYSTEMDRIVE, PATH to System32,
  TEMP/TMP/LOCALAPPDATA to a private read-only directory), the image
  directory as cwd, and a private window station and desktop. The
  parent's environment is never passed on.
- Job: flags 0x2508, one live process, no breakaway, the caller's
  commit limit, UI restrictions 0xff.
- Checks before resume: job-limits-mismatch, not-in-owned-job,
  birth-token-mismatch and initial-token-open, each killing the child.
- ConfinedProcess owns process, job and pipes: kill (job, then process,
  exit 137), try_wait, wait, token and job read-back.
- Deviation: Full only without the `deviations` feature; with it, the
  LPAC-only and plain controls and one variant per worker and parent
  check.
- Tests start a GUI-subsystem test child for real. CI's Windows job
  runs them first with `--features deviations`.
- +crt-static for x86_64-pc-windows-msvc in .cargo/config.toml.
…g TEMP path

On windows-latest, kill() failed with access denied: TerminateJobObject
had already begun ending the worker, so the following TerminateProcess
was refused while the process was not yet signaled. A successful job
kill of a worker that is a member of the job is now a successful kill.

The LPAC-only control's TEMP write failed with Win32 3, not 5: the
system TEMP path holds 8.3 short names (RUNNER~1). The worker's TEMP is
now the canonical long path, and the control's assertion accepts any
denial, since only the plain control needs to show the path is writable.
getentropy exists only on Unix. On Windows the system-preferred RNG supplies
each journaled draw, and there is still no fallback when it fails.

(cherry picked from commit a69f2b0)
The workspace test can't build until every crate compiles on Windows, so
basal-host's built-ins get their own test step that reports now.

(cherry picked from commit 990ce58)
Retain both process-attribute payloads through attribute deletion, create suspended, verify membership in the exact kill-on-close job, then resume. Use an explicit canonical drive image and a UTF-16 CRT encoder. Give each call exclusively created private config/hooks resources and read-only NUL stdin. Reuse the fs worker's no-delete-sharing handle walk via a small PinnedDirectory seam; the guard survives every git child in the operation.

Retry failed job termination and put kill/close plus bounded worker cancellation inside the thread scope. Replace handwritten ABI declarations with windows-sys. Replace the original recipe-only or vacuous Windows tests with native argv round trips, job/handle observations, pinned-path controls, live descendant death, byte/line-cap writers, exceptional cleanup watchdogs, and real helper/global-config positive and negative controls. Hook controls now perform checkout rather than log, and tag writers exceed the byte budget rather than merely truncating small output.

Mac and Linux basal-host tests/clippy pass; mounted MSVC lib/tests clippy and child fixture metadata checks pass with warnings denied. Native Windows execution is pending the parent-owned push/CI gate. The shared Unix canonicalize-then-git-C path race is deliberately unchanged in this slice.
Native run 38065124338 exercised all new git tests: seven failed only because GetTempPathW's trailing backslash was passed unchanged to the fs raw-spelling validator. Normalize just that host-selected base before the unchanged reparse-refusing fs walk; repository path policy remains strict.

Add a regression test for that native temp spelling, inspect the actual protected DACL of directory/hooks/config (only SYSTEM and owner rights), refuse a temp junction, and attempt config/hook replacements concurrently while their guards are live. MSVC scratch lib/tests clippy -D warnings passes. Mac/Linux gates are unchanged by these Windows-only edits. All 44 fs tests passed in the first native run; rerun Windows host tests to close the seven git failures.
Native run 38065638982 had 44 fs and 21 git passes, with one handle test failure: PeekNamedPipe returned TRUE after parent writer closure. That establishes that a writer exists somewhere, not that the tested process owns it; concurrent ordinary setup/rustc spawns can inherit the same sentinel. Microsoft CreateProcessW Remarks explicitly document this multithreaded inheritance problem, and its bInheritHandles documentation says inherited handles have the same numeric value and access rights.

Keep the parent's writer alive and DuplicateHandle from the exact tested child's handle table before resume and after it starts; CompareObjectHandles distinguishes the sentinel from a reused numeric slot or OS-created object. Add a deliberately unrestricted suspended CreateProcess(TRUE) positive control requiring that same-object observation to succeed. This strengthens the child-specific no-leak claim instead of relaxing it or retrying global EOF. No product handle allowlist is weakened; a real target-child leak will fail these assertions.

References: learn.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-createprocessw (Parameters/Remarks), learn.microsoft.com/en-us/windows/win32/api/handleapi/nf-handleapi-duplicatehandle (Parameters/Remarks), learn.microsoft.com/en-us/windows/win32/api/handleapi/nf-handleapi-compareobjecthandles (Return value).

Also preserve the original uniform git repository-denial contract when the fs pin walk fails (including missing unapproved paths), with an existence-privacy regression test. Strengthen global isolation with a real default HOME/.gitconfig positive control as well as the explicit GIT_CONFIG_GLOBAL control, so clearing inherited environment alone cannot satisfy the test. MSVC mounted lib/tests clippy with -D warnings passes; edits are Windows-only and do not impact earlier Mac/Linux gates. Native rerun pending.
The worker builds and confines itself on Windows under basal-launch:

- GUI-subsystem image (no console host); an import test checks the
  subsystem, the forbidden GUI/COM DLLs and that no C runtime DLL is
  imported.
- --package-sid parsing: missing exits 70 package-sid-argument-missing,
  unparsable or repeated exits 64.
- Startup steps 1-6 before the first frame read: revert and require
  ERROR_NO_TOKEN, lower the primary to Untrusted and close the handle,
  close the CSR ALPC port and private File handles, check the actual
  primary token, check single mitigation bits, check the handle table
  against two per-image profiles that are never combined. Each failure
  exits 70 with its reason token. A step-3 failure (snapshot or close)
  is reported as handle-not-allowed, since the spec names no token for it.
- The checks are pure functions tested on every system; the readers and
  the sequence are Windows-only.
- Thread CPU clock from GetThreadTimes; JsClock takes an injectable
  sample source. The existing real-clock test keeps its claim but uses
  budgets and burns of several scheduler ticks, because Windows advances
  the clock a tick (~15.6 ms) at a time.
- A `deviations` feature lets a test worker act on
  --confinement-deviation for the three checks the parent cannot break;
  without it the argument is refused as unknown (exit 64).

Tests that use basal-testkit are gated off Windows until it builds there,
and basal-testkit becomes a non-Windows dev-dependency. Windows worker
tests spawn through basal-launch. The windows-baseline job runs the
worker's tests on their own, with and without the feature.
The executable-name fence requires test processes to run a ckdev- copy of
the worker, never a ck- named binary. The Windows worker tests copy the
built worker to ckdev-basal-worker.exe (their own helper, since
basal-testkit does not build on Windows yet) and launch or inspect that.

The worker-depends-on-a-subc-crate control anchors on basal-worker's
Cargo.lock dependency list, which now also names windows-sys; its anchor
and replacement include that entry.
… worker test passes natively, with a real confined activation)
Tests read docs, fixtures and digest test vectors byte for byte. On the
Windows runner a CRLF checkout broke the sandbox page test and could change
the vector digests.
Keep the production image free of WS2_32 imports. Socket probes alone preload the DLL under the startup token, then still run every unchanged startup check before attempting WSAStartup or sockets. Preserve raw kernel trace prefixes and require PDB-resolved user creators. Disable only the diagnostic handle-tracing database after snapshot; do not change permanent strict-handle mitigation or accept a fatal checkpoint exit. Commit the identical five-DLL import inventory measured on both Windows images in CI run 38074402001. Its now-mandatory import fence gets a kernel32-removal mutation control.
Preserve both unedited production release inventories from CI run 38075560568 and render their type/access/count/creator tables. Both fit the unchanged per-image ceiling constants at 25 handles. Keep kernel trace prefixes raw and all user creators PDB-resolved to initialization. Quote every probe, thread barrier, pool and non-vacuity result from both images, including default and deviations builds. Both mutation controls redden only their named oracle and restore to an empty diff. Remove the temporary always-on provenance step: this is a one-off measurement, not a per-run worker test. The import allowlist and live handle ceilings stay enforced. Unrelated Windows workspace builds still fail in basal-core/src/retention.rs.
@basal-alfonso

basal-alfonso Bot commented Oct 10, 2026

Copy link
Copy Markdown
Author

Closing: its contents are merged on the integration/windows branch.

@basal-alfonso basal-alfonso Bot closed this Oct 10, 2026
@ualtinok
ualtinok deleted the ci/windows-probes branch October 10, 2026 19:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant