Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 6 additions & 4 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

11 changes: 11 additions & 0 deletions crates/cortexkit-lease/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
# Changelog

## 0.1.2

- Add an opt-in, Windows-only `test-support` module for native ACL observations,
assertions and disposable broad-ACL fixtures. The feature is off by default.
- Windows files and directories are now owner-only, using protected DACLs that
grant only the current process user full control. New directories pass these
permissions on to their children; reparse points are never adjusted.
- Narrowing existing Windows directories also replaces broad inherited ACLs on
existing descendants, while preserving protected child DACLs.
16 changes: 15 additions & 1 deletion crates/cortexkit-lease/Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,11 +1,25 @@
[package]
name = "cortexkit-lease"
version = "0.1.1"
version = "0.1.2"
edition.workspace = true
license.workspace = true
repository.workspace = true
authors.workspace = true
description = "Single-writer durable lease (OS advisory lock + monotonic epoch fence) for CortexKit modules."

[features]
default = []
# Native Windows ACL observations and fixtures for tests, not production use.
test-support = []

[dependencies]
fs2 = "0.4"

[target.'cfg(windows)'.dependencies]
windows-sys = { version = "0.61", features = [
"Win32_Foundation",
"Win32_Security",
"Win32_Security_Authorization",
"Win32_Storage_FileSystem",
"Win32_System_Threading",
] }
21 changes: 19 additions & 2 deletions crates/cortexkit-lease/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,17 @@ use std::{

use fs2::FileExt;

#[cfg(windows)]
mod windows;

/// Native Windows ACL observations and fixtures for tests only.
///
/// Available on Windows with the opt-in `test-support` feature. Enable the
/// feature only on a dev-dependency; the fixture helpers deliberately grant
/// broad access and must not be used to configure production permissions.
#[cfg(all(windows, feature = "test-support"))]
pub use windows::test_support;

/// Force owner-only permissions on a file this process owns the lifecycle of.
///
/// Files created through `File::create` or `OpenOptions::create` get their mode
Expand Down Expand Up @@ -79,7 +90,9 @@ pub fn protect_file(path: &std::path::Path) -> std::io::Result<()> {
std::fs::set_permissions(path, std::fs::Permissions::from_mode(0o600))?;
}
}
#[cfg(not(unix))]
#[cfg(windows)]
windows::protect_file(path)?;
#[cfg(not(any(unix, windows)))]
let _ = path;
Ok(())
}
Expand Down Expand Up @@ -126,7 +139,11 @@ pub fn create_private_dir(dir: &std::path::Path) -> std::io::Result<()> {
}
Ok(())
}
#[cfg(not(unix))]
#[cfg(windows)]
{
windows::create_private_dir(dir)
}
#[cfg(not(any(unix, windows)))]
{
std::fs::create_dir_all(dir)
}
Expand Down
Loading
Loading