lock_permissions: the folder grant is user:(OI)(CI)F WITHOUT /T (measured on PC 1, collect ember-acl-2: /T re-applies /inheritance:r to each file after the propagation and an (OI)(CI) entry on a file is inherit-only, so the copied settings still read as nothing); the playbook prefers ember-kit-5
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
0da0b65180
commit
0cba03027e
2 changed files with 10 additions and 8 deletions
|
|
@ -173,14 +173,16 @@ pub fn lock_permissions(path: &Path, dir: bool) {
|
|||
}
|
||||
}
|
||||
|
||||
/// The icacls arguments that lock a path to the user. A folder gets an INHERITABLE grant applied to everything
|
||||
/// inside (`(OI)(CI)F`, `/T`): the old non-inheritable `user:F` cut the folder's inheritance and left any file that
|
||||
/// was COPIED in before the engine started with no entry at all (6 October 2026, PC 1: a measurement engine's
|
||||
/// settings.json, machine-id and wallet.json copied by a job read as nothing, so the engine ran on defaults with no
|
||||
/// payout address; the engine's own files, written after the lock, got the creator's default DACL and hid it).
|
||||
/// The icacls arguments that lock a path to the user. A folder gets an INHERITABLE grant (`user:(OI)(CI)F`) and
|
||||
/// NO `/T`: Windows propagates the inheritable entry to every child, existing or future, as `(I)(F)`. Measured on
|
||||
/// PC 1, 6 October 2026 (collect ember-acl-2): the old non-inheritable `user:F` cut the folder's inheritance and
|
||||
/// left a file COPIED in before the engine started with no entry at all (the measurement engine's settings.json,
|
||||
/// machine-id and wallet.json read as nothing, so it ran on defaults with no payout address; its own files, written
|
||||
/// after the lock, inherited fine and hid it); the same grant WITH `/T` also left the file empty, because `/T`
|
||||
/// re-applies `/inheritance:r` to the file after the propagation and an `(OI)(CI)` entry on a file is inherit-only.
|
||||
pub fn icacls_lock_args(dir: bool, user: &str) -> Vec<String> {
|
||||
if dir {
|
||||
vec!["/inheritance:r".into(), "/grant:r".into(), format!("{user}:(OI)(CI)F"), "/T".into()]
|
||||
vec!["/inheritance:r".into(), "/grant:r".into(), format!("{user}:(OI)(CI)F")]
|
||||
} else {
|
||||
vec!["/inheritance:r".into(), "/grant:r".into(), format!("{user}:F")]
|
||||
}
|
||||
|
|
@ -514,7 +516,7 @@ mod lock_tests {
|
|||
#[test]
|
||||
fn a_locked_folder_grants_the_user_inheritably_and_covers_what_is_inside() {
|
||||
let d = super::icacls_lock_args(true, "Admin");
|
||||
assert_eq!(d, vec!["/inheritance:r", "/grant:r", "Admin:(OI)(CI)F", "/T"]);
|
||||
assert_eq!(d, vec!["/inheritance:r", "/grant:r", "Admin:(OI)(CI)F"], "inheritable, and never /T (it empties the children)");
|
||||
let f = super::icacls_lock_args(false, "Admin");
|
||||
assert_eq!(f, vec!["/inheritance:r", "/grant:r", "Admin:F"]);
|
||||
}
|
||||
|
|
|
|||
|
|
@ -49,7 +49,7 @@ if ($installedVer -match 'igneum-app (\d+)\.(\d+)\.(\d+)') { $installedHasEmber
|
|||
$ember = $null
|
||||
# ember-kit-3 (the engine with Settings::for_measurement) is preferred when present, whatever the installed version;
|
||||
# older kits only when the installed app predates Ember Tune
|
||||
$k3 = Join-Path $appDir 'jobs\ember-kit-4\igneum-app-ember.exe'
|
||||
$k3 = Join-Path $appDir 'jobs\ember-kit-5\igneum-app-ember.exe'
|
||||
if (Test-Path $k3) { $ember = $k3 }
|
||||
elseif (-not $installedHasEmber) { foreach ($cand in @((Join-Path $appDir 'jobs\ember-kit-2\igneum-app-ember.exe'), (Join-Path $appDir 'jobs\ember-kit-1\igneum-app-ember.exe'))) { if (Test-Path $cand) { $ember = $cand; break } } }
|
||||
if ($ember) {
|
||||
|
|
|
|||
Loading…
Reference in a new issue