diff --git a/app/igneum-app/src/platform.rs b/app/igneum-app/src/platform.rs index 181b2a0d..bb41df4f 100644 --- a/app/igneum-app/src/platform.rs +++ b/app/igneum-app/src/platform.rs @@ -173,14 +173,16 @@ pub fn lock_permissions(path: &Path, dir: bool) { } } -/// The icacls arguments that lock a path to the user. A folder gets an INHERITABLE grant applied to everything -/// inside (`(OI)(CI)F`, `/T`): the old non-inheritable `user:F` cut the folder's inheritance and left any file that -/// was COPIED in before the engine started with no entry at all (6 October 2026, PC 1: a measurement engine's -/// settings.json, machine-id and wallet.json copied by a job read as nothing, so the engine ran on defaults with no -/// payout address; the engine's own files, written after the lock, got the creator's default DACL and hid it). +/// The icacls arguments that lock a path to the user. A folder gets an INHERITABLE grant (`user:(OI)(CI)F`) and +/// NO `/T`: Windows propagates the inheritable entry to every child, existing or future, as `(I)(F)`. Measured on +/// PC 1, 6 October 2026 (collect ember-acl-2): the old non-inheritable `user:F` cut the folder's inheritance and +/// left a file COPIED in before the engine started with no entry at all (the measurement engine's settings.json, +/// machine-id and wallet.json read as nothing, so it ran on defaults with no payout address; its own files, written +/// after the lock, inherited fine and hid it); the same grant WITH `/T` also left the file empty, because `/T` +/// re-applies `/inheritance:r` to the file after the propagation and an `(OI)(CI)` entry on a file is inherit-only. pub fn icacls_lock_args(dir: bool, user: &str) -> Vec { if dir { - vec!["/inheritance:r".into(), "/grant:r".into(), format!("{user}:(OI)(CI)F"), "/T".into()] + vec!["/inheritance:r".into(), "/grant:r".into(), format!("{user}:(OI)(CI)F")] } else { vec!["/inheritance:r".into(), "/grant:r".into(), format!("{user}:F")] } @@ -514,7 +516,7 @@ mod lock_tests { #[test] fn a_locked_folder_grants_the_user_inheritably_and_covers_what_is_inside() { let d = super::icacls_lock_args(true, "Admin"); - assert_eq!(d, vec!["/inheritance:r", "/grant:r", "Admin:(OI)(CI)F", "/T"]); + assert_eq!(d, vec!["/inheritance:r", "/grant:r", "Admin:(OI)(CI)F"], "inheritable, and never /T (it empties the children)"); let f = super::icacls_lock_args(false, "Admin"); assert_eq!(f, vec!["/inheritance:r", "/grant:r", "Admin:F"]); } diff --git a/relay/playbooks/ember-tune-pc1.ps1 b/relay/playbooks/ember-tune-pc1.ps1 index 91b04ce0..130b9c45 100644 --- a/relay/playbooks/ember-tune-pc1.ps1 +++ b/relay/playbooks/ember-tune-pc1.ps1 @@ -49,7 +49,7 @@ if ($installedVer -match 'igneum-app (\d+)\.(\d+)\.(\d+)') { $installedHasEmber $ember = $null # ember-kit-3 (the engine with Settings::for_measurement) is preferred when present, whatever the installed version; # older kits only when the installed app predates Ember Tune -$k3 = Join-Path $appDir 'jobs\ember-kit-4\igneum-app-ember.exe' +$k3 = Join-Path $appDir 'jobs\ember-kit-5\igneum-app-ember.exe' if (Test-Path $k3) { $ember = $k3 } elseif (-not $installedHasEmber) { foreach ($cand in @((Join-Path $appDir 'jobs\ember-kit-2\igneum-app-ember.exe'), (Join-Path $appDir 'jobs\ember-kit-1\igneum-app-ember.exe'))) { if (Test-Path $cand) { $ember = $cand; break } } } if ($ember) {