Skip to content

Owner-only files and directories on Windows - #19

Closed
subc-alfonso[bot] wants to merge 2 commits into
masterfrom
windows-owner-only
Closed

subc-alfonso[bot] wants to merge 2 commits into
masterfrom
windows-owner-only

Conversation

@subc-alfonso

@subc-alfonso subc-alfonso Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Windows verification run for cortexkit-lease 0.1.2, cortexkit-log 0.3.5 and cortexkit-store 0.2.4: protect_file and create_private_dir set a protected owner-only DACL on Windows, and narrowing an existing directory propagates to files already inside. The Windows-only tests run here, since commons CI covers Windows on pull requests.


Summary by cubic

Enforces owner-only access on Windows for protect_file and create_private_dir, which previously did nothing and returned Ok. cortexkit-log and cortexkit-store now use these helpers, and cortexkit-test-support writes the daemon PID file atomically so a polling reader never sees it empty.

  • New directories are private from creation, and files get a protected DACL granting only the current process user full control.
  • Narrowing an existing directory also strips broad inherited ACLs from existing descendants, leaving protected child DACLs and parent folders intact.
  • Symlink and junction targets are never modified; such paths are refused or skipped.
  • cortexkit-store no longer treats in-memory databases and SQLite URIs as file paths to protect.

Written for commit 3c46117. Summary will update on new commits.

View guided diff Turn on auto-fix

@cortexkit-ci

cortexkit-ci Bot commented Oct 8, 2026

Copy link
Copy Markdown

This PR needs a linked issue with the design-approved label before it can be reviewed or merged. Link the approved issue with Approved issue: #<issue> (or Refs #<issue>) in the description. A maintainer will apply the design-approved label on the issue, or trivial on the pull request when there is genuinely no design to agree. The issue stays open until the change ships; maintainers take care of it then.

@ualtinok
ualtinok force-pushed the windows-owner-only branch from cb22784 to 5ece3c0 Compare October 8, 2026 22:35
…ortexkit-log 0.3.5, cortexkit-store 0.2.4)

protect_file and create_private_dir did nothing on Windows and still
returned Ok, so stores and logs kept whatever the parent folder granted.
They now set a protected DACL whose only entry grants the current user full
control: new directories get it at creation, and narrowing an existing
directory propagates to the files already inside. cortexkit-log uses the
same helpers. Unix and other platforms are unchanged.
@ualtinok
ualtinok force-pushed the windows-owner-only branch from 5ece3c0 to 27d3799 Compare October 9, 2026 07:28
A test polling for the PID file could see it empty mid-write and fail to parse
it (seen on macOS CI).
@ualtinok
ualtinok force-pushed the windows-owner-only branch 3 times, most recently from cf1a677 to 3c46117 Compare October 9, 2026 08:13
@ualtinok ualtinok closed this Oct 9, 2026
@ualtinok
ualtinok deleted the windows-owner-only branch October 9, 2026 09:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant