fix(windows): replace the managed CLI launcher with a native one (#24094)

* docs(security): add the antivirus clearance path for future releases

Every AV false positive here has been handled one vendor and one shipped
version at a time. Document the programs that clear future releases instead --
signer and product enrollment rather than per-build sample submission -- and add
a script that reports an RC's current detection state by hash, so a verdict is
found before users meet it in an issue report.

Hash lookup only by default; --upload transmits the artifact and stays manual.

* fix(windows): replace the managed CLI launcher with a native one

resources\bin\orca.exe was a csc-compiled MSIL assembly: a small, freshly
compiled .NET image in a user-writable directory that mutates environment
variables and proxies a child process. That is the shape .NET dropper
heuristics are trained on, and every verdict against it named the family --
MSILHeracles from two vendors, Wacatac!ml from a third. Signing the file does
not change its shape, so signing never cleared it.

Rebuild it in Rust. Same resolution, same environment contract, same argv
passthrough that keeps newline-bearing orchestration bodies intact (#8374), and
the child still inherits our environment block rather than an explicit map, so
a block carrying both PATH and Path survives (#12046). The PE now carries
publisher, version, icon and an asInvoker manifest from build.rs.

Refs #23383

* ci(windows): install the Rust toolchain before building the CLI launcher

The hosted runners happen to ship cargo, but a real Windows dev box does not --
verified on our own Windows QA host, where cargo and rustc were both absent.
Relying on the image means a future image change fails deep inside
electron-builder's native hook instead of at an obvious step.
This commit is contained in:
Neil
2026-09-30 02:49:03 -07:00
committed by GitHub
parent cef66fbab8
commit d2dbe2c385
16 changed files with 844 additions and 220 deletions
+8 -12
View File
@@ -13,19 +13,15 @@ describe('packaged Windows CLI launcher asset', () => {
})
it('marks the packaged child and propagates its exact exit status', () => {
const sourcePath = join(process.cwd(), 'native', 'windows-cli-launcher', 'OrcaCliLauncher.cs')
const sourcePath = join(process.cwd(), 'native', 'windows-cli-launcher', 'src', 'main.rs')
const source = readFileSync(sourcePath, 'utf8')
// Why: the marker and command name must ride the launcher's own environment, never
// ProcessStartInfo's case-insensitive copy of a PATH/Path block (stablyai/orca#12046).
expect(source).toContain(
'Environment.SetEnvironmentVariable("ORCA_WINDOWS_PACKAGED_CLI_LAUNCHER", "1");'
)
expect(source).toContain(
'string requestedCliCommand = Environment.GetEnvironmentVariable("ORCA_CLI_COMMAND");'
)
expect(source).toContain('requestedCliCommand == "orca-ide" ? "orca-ide" : "orca"')
expect(source).toContain('child.WaitForExit();')
expect(source).toContain('return child.ExitCode;')
// Why: the marker and command name must ride the launcher's own environment, never an
// explicit child map, whose case-insensitive keys collapse PATH and Path (stablyai/orca#12046).
expect(source).toContain('env::set_var("ORCA_WINDOWS_PACKAGED_CLI_LAUNCHER", "1")')
expect(source).toContain('env::var("ORCA_CLI_COMMAND")')
expect(source).toContain('if requested_command == "orca-ide"')
expect(source).toContain('command.status()')
expect(source).toContain('exit(status.code().unwrap_or(1))')
})
})