From 7bf94a0e71ebfd1f0e541de2aa1c7c69eb581be1 Mon Sep 17 00:00:00 2001 From: Orca Worker Date: Thu, 3 Sep 2026 18:13:42 -0700 Subject: [PATCH] test(windows): pin the nested and update-inherited grants against real icacls The live spec asserted the grant landed on the root-level module file only. It now also pins that the flagless /T pass reaches a nested file carrying its own protected DACL (the shape app.asar.unpacked and node_modules have), and that a file written after the repair inherits the (OI)(CI) root grant - the stated reason that grant form exists. --- .../startup/windows-install-dir-acl-repair.win32.test.ts | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/src/main/startup/windows-install-dir-acl-repair.win32.test.ts b/src/main/startup/windows-install-dir-acl-repair.win32.test.ts index 6d60bb4342b..9a04aa1edef 100644 --- a/src/main/startup/windows-install-dir-acl-repair.win32.test.ts +++ b/src/main/startup/windows-install-dir-acl-repair.win32.test.ts @@ -112,6 +112,13 @@ describeOnWindows('install-dir package ACL repair against the real icacls', () = // A directory grant is not enough: the file carries its own DACL. expect((await icacls(moduleFile)).out).toMatch(RESTRICTED_PACKAGES_NAME) + // The /T pass must also reach a NESTED protected file — the shape app.asar.unpacked + // and node_modules actually have. + expect((await icacls(trapFile)).out).toMatch(RESTRICTED_PACKAGES_NAME) + // And the (OI)(CI) root grant exists so files a later update writes inherit it. + const updateFile = join(installDir, 'resources', 'added-by-update.dll') + writeFileSync(updateFile, 'binary') + expect((await icacls(updateFile)).out).toMatch(RESTRICTED_PACKAGES_NAME) expect((await probeVerdict()).matchesPoisonSignature).toBe(false) }) })