lock_permissions: the folder grant is user:(OI)(CI)F WITHOUT /T (measured on PC 1, collect ember-acl-2: /T re-applies /inheritance:r to each file after the propagation and an (OI)(CI) entry on a file is inherit-only, so the copied settings still read as nothing); the playbook prefers ember-kit-5

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-labs 2026-10-06 14:50:49 +00:00
parent 0da0b65180
commit 0cba03027e
2 changed files with 10 additions and 8 deletions

View file

@ -173,14 +173,16 @@ pub fn lock_permissions(path: &Path, dir: bool) {
} }
} }
/// The icacls arguments that lock a path to the user. A folder gets an INHERITABLE grant applied to everything /// The icacls arguments that lock a path to the user. A folder gets an INHERITABLE grant (`user:(OI)(CI)F`) and
/// inside (`(OI)(CI)F`, `/T`): the old non-inheritable `user:F` cut the folder's inheritance and left any file that /// NO `/T`: Windows propagates the inheritable entry to every child, existing or future, as `(I)(F)`. Measured on
/// was COPIED in before the engine started with no entry at all (6 October 2026, PC 1: a measurement engine's /// PC 1, 6 October 2026 (collect ember-acl-2): the old non-inheritable `user:F` cut the folder's inheritance and
/// settings.json, machine-id and wallet.json copied by a job read as nothing, so the engine ran on defaults with no /// left a file COPIED in before the engine started with no entry at all (the measurement engine's settings.json,
/// payout address; the engine's own files, written after the lock, got the creator's default DACL and hid it). /// machine-id and wallet.json read as nothing, so it ran on defaults with no payout address; its own files, written
/// after the lock, inherited fine and hid it); the same grant WITH `/T` also left the file empty, because `/T`
/// re-applies `/inheritance:r` to the file after the propagation and an `(OI)(CI)` entry on a file is inherit-only.
pub fn icacls_lock_args(dir: bool, user: &str) -> Vec<String> { pub fn icacls_lock_args(dir: bool, user: &str) -> Vec<String> {
if dir { if dir {
vec!["/inheritance:r".into(), "/grant:r".into(), format!("{user}:(OI)(CI)F"), "/T".into()] vec!["/inheritance:r".into(), "/grant:r".into(), format!("{user}:(OI)(CI)F")]
} else { } else {
vec!["/inheritance:r".into(), "/grant:r".into(), format!("{user}:F")] vec!["/inheritance:r".into(), "/grant:r".into(), format!("{user}:F")]
} }
@ -514,7 +516,7 @@ mod lock_tests {
#[test] #[test]
fn a_locked_folder_grants_the_user_inheritably_and_covers_what_is_inside() { fn a_locked_folder_grants_the_user_inheritably_and_covers_what_is_inside() {
let d = super::icacls_lock_args(true, "Admin"); let d = super::icacls_lock_args(true, "Admin");
assert_eq!(d, vec!["/inheritance:r", "/grant:r", "Admin:(OI)(CI)F", "/T"]); assert_eq!(d, vec!["/inheritance:r", "/grant:r", "Admin:(OI)(CI)F"], "inheritable, and never /T (it empties the children)");
let f = super::icacls_lock_args(false, "Admin"); let f = super::icacls_lock_args(false, "Admin");
assert_eq!(f, vec!["/inheritance:r", "/grant:r", "Admin:F"]); assert_eq!(f, vec!["/inheritance:r", "/grant:r", "Admin:F"]);
} }

View file

@ -49,7 +49,7 @@ if ($installedVer -match 'igneum-app (\d+)\.(\d+)\.(\d+)') { $installedHasEmber
$ember = $null $ember = $null
# ember-kit-3 (the engine with Settings::for_measurement) is preferred when present, whatever the installed version; # ember-kit-3 (the engine with Settings::for_measurement) is preferred when present, whatever the installed version;
# older kits only when the installed app predates Ember Tune # older kits only when the installed app predates Ember Tune
$k3 = Join-Path $appDir 'jobs\ember-kit-4\igneum-app-ember.exe' $k3 = Join-Path $appDir 'jobs\ember-kit-5\igneum-app-ember.exe'
if (Test-Path $k3) { $ember = $k3 } if (Test-Path $k3) { $ember = $k3 }
elseif (-not $installedHasEmber) { foreach ($cand in @((Join-Path $appDir 'jobs\ember-kit-2\igneum-app-ember.exe'), (Join-Path $appDir 'jobs\ember-kit-1\igneum-app-ember.exe'))) { if (Test-Path $cand) { $ember = $cand; break } } } elseif (-not $installedHasEmber) { foreach ($cand in @((Join-Path $appDir 'jobs\ember-kit-2\igneum-app-ember.exe'), (Join-Path $appDir 'jobs\ember-kit-1\igneum-app-ember.exe'))) { if (Test-Path $cand) { $ember = $cand; break } } }
if ($ember) { if ($ember) {