test(windows): pin the nested and update-inherited grants against real icacls

The live spec asserted the grant landed on the root-level module file only.
It now also pins that the flagless /T pass reaches a nested file carrying
its own protected DACL (the shape app.asar.unpacked and node_modules have),
and that a file written after the repair inherits the (OI)(CI) root grant -
the stated reason that grant form exists.
This commit is contained in:
Orca Worker
2026-09-03 18:13:42 -07:00
parent 79d3734e0a
commit 7bf94a0e71
@@ -112,6 +112,13 @@ describeOnWindows('install-dir package ACL repair against the real icacls', () =
// A directory grant is not enough: the file carries its own DACL.
expect((await icacls(moduleFile)).out).toMatch(RESTRICTED_PACKAGES_NAME)
// The /T pass must also reach a NESTED protected file — the shape app.asar.unpacked
// and node_modules actually have.
expect((await icacls(trapFile)).out).toMatch(RESTRICTED_PACKAGES_NAME)
// And the (OI)(CI) root grant exists so files a later update writes inherit it.
const updateFile = join(installDir, 'resources', 'added-by-update.dll')
writeFileSync(updateFile, 'binary')
expect((await icacls(updateFile)).out).toMatch(RESTRICTED_PACKAGES_NAME)
expect((await probeVerdict()).matchesPoisonSignature).toBe(false)
})
})