mirror of
https://github.com/stablyai/orca.git
synced 2026-09-29 16:02:50 +00:00
test(windows): pin the nested and update-inherited grants against real icacls
The live spec asserted the grant landed on the root-level module file only. It now also pins that the flagless /T pass reaches a nested file carrying its own protected DACL (the shape app.asar.unpacked and node_modules have), and that a file written after the repair inherits the (OI)(CI) root grant - the stated reason that grant form exists.
This commit is contained in:
@@ -112,6 +112,13 @@ describeOnWindows('install-dir package ACL repair against the real icacls', () =
|
||||
|
||||
// A directory grant is not enough: the file carries its own DACL.
|
||||
expect((await icacls(moduleFile)).out).toMatch(RESTRICTED_PACKAGES_NAME)
|
||||
// The /T pass must also reach a NESTED protected file — the shape app.asar.unpacked
|
||||
// and node_modules actually have.
|
||||
expect((await icacls(trapFile)).out).toMatch(RESTRICTED_PACKAGES_NAME)
|
||||
// And the (OI)(CI) root grant exists so files a later update writes inherit it.
|
||||
const updateFile = join(installDir, 'resources', 'added-by-update.dll')
|
||||
writeFileSync(updateFile, 'binary')
|
||||
expect((await icacls(updateFile)).out).toMatch(RESTRICTED_PACKAGES_NAME)
|
||||
expect((await probeVerdict()).matchesPoisonSignature).toBe(false)
|
||||
})
|
||||
})
|
||||
|
||||
Reference in New Issue
Block a user