Skip to content

feat(installer): harden package safety#3

Draft
zagrosi-code wants to merge 49 commits into
mainfrom
feat/installer-package-safety
Draft

feat(installer): harden package safety#3
zagrosi-code wants to merge 49 commits into
mainfrom
feat/installer-package-safety

Conversation

@zagrosi-code

Copy link
Copy Markdown
Owner

Implements installer and package safety.

Reject unsupported ACLs, xattrs, and flags before receipt trust.
Candidate bytes and generated metadata could mint unusable bundle evidence, while archive and process edge cases escaped the stable failure contract.
Treat denied ancestor renames as a safe Windows result only after proving live authority and post-close handle release.
Preserve unmanaged Codex config representation while binding publication and recovery to exact ownership, file, and metadata evidence.
Run native DACL, ACL, file-flag, and hard-link cases in every platform cell and retain sanitized JUnit evidence.
icacls grant removal does not restore the original exact security descriptor, while the unsupported-DACL assertion already covers the security behavior.
Use a retained capability-bound kernel lock so stale diagnostics and creator failures cannot split lock authority.
Recursive runtime closure keeps the installed candidate self-contained.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant