Files
orca/.github/workflows/relay-windows-process-tree.yml
T
OrcaWinandm4air 6d1a97ef98 fix(ssh): launch the Windows relay outside sshd's job so standard users work (#24224)
* fix(ssh): launch the Windows relay outside sshd's job without WMI

Win32-OpenSSH kills a session's job on close but allows breakaway. relay.js
gains a one-shot launcher mode that starts the detached relay with
CREATE_BREAKAWAY_FROM_JOB through the staged process-tree addon, so a standard
user no longer needs a WMI Remote Enable grant. WMI stays as the fallback for a
relay without the addon, and a refusal there is named. The Windows SSH-host
lanes drop their WMI grant and assert the breakaway route and adoption.

* fix(ssh): find runtime holds without WMI on a standard-user Windows host

The store GC read held runtimes through Get-CimInstance Win32_Process, which
WMI refuses to a standard user's SSH logon, so the pass kept every runtime.
On a refusal it now reads this account's own process image paths through
Get-Process.

* build(relay): ship the Windows relay launcher addon in every desktop package

macOS and Linux packages carried Windows relays without windows-process-tree.node,
so a legacy-runtime relay they uploaded to a Windows SSH host could not launch
outside sshd's job and fell back to WMI, which a standard user is refused.

A reusable Windows job now compiles the x64 and arm64 addons once and uploads
them; release-cut, release-mac-build, and the hourly/daily/adhoc mac builds
download them before build:release and require both arches. Staging now rejects
a binary with the wrong PE machine, the ReadProcessMemory import, or no
spawnOutsideJob export, so a stale pre-launcher build cannot ship.

* ci(ssh): run the Windows SSH-host lanes when the relay process-tree build scripts change

The staging and gyp-rebuild scripts decide which windows-process-tree addon the
relay ships, so a change to either must re-prove the Windows host cells.

* test(ci): find the mac orcad-template download by artifact name

The release mac job now also downloads the relay Windows process-tree addons, so
the first download-artifact step is no longer the template's.

---------

Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
2026-10-01 05:32:09 -07:00

72 lines
2.5 KiB
YAML

name: Relay Windows process-tree addons
# Why a reusable workflow: every desktop package ships relays for Windows SSH hosts,
# but only a Windows runner can compile the addon that launches a relay outside
# sshd's job. macOS and Linux packaging jobs download this artifact into
# .build/windows-process-tree before `pnpm build:release` stages it.
on:
workflow_call:
inputs:
ref:
description: Commit or tag to build; must match what the packaging job checks out.
required: true
type: string
permissions:
contents: read
jobs:
build:
# Why windows-2022: windows-latest moved to VS 2026 before node-gyp could detect
# it. GitHub-hosted, so release-cut's SignPath provenance rule still holds.
runs-on: windows-2022
timeout-minutes: 30
steps:
- name: Checkout
uses: actions/checkout@v6
with:
ref: ${{ inputs.ref }}
persist-credentials: false
# Plain setup rather than a composite action: `uses: ./` resolves from the
# checked-out ref, which may be a release tag that predates the action.
- name: Setup pnpm
uses: pnpm/setup@v2
with:
install: false
- name: Setup Node.js
uses: actions/setup-node@v6
with:
node-version-file: package.json
cache: pnpm
cache-dependency-path: pnpm-lock.yaml
# Why host-only: the addon is compiled from the patched source pnpm
# materializes, and arm64 cross-compiles through node-gyp --arch.
- name: Install dependencies
uses: nick-fields/retry@v4
with:
timeout_minutes: 10
max_attempts: 3
retry_wait_seconds: 30
command: pnpm install --frozen-lockfile
# The build script refuses unpatched source and checks each output's PE
# machine, ReadProcessMemory import, and spawnOutsideJob export.
- name: Build Windows process-table addons for the relay
shell: bash
run: |
node config/scripts/build-windows-process-tree-relay-addon.mjs --arch=x64
node config/scripts/build-windows-process-tree-relay-addon.mjs --arch=arm64
- name: Upload relay addons
uses: actions/upload-artifact@v7
with:
name: relay-windows-process-tree
path: .build/windows-process-tree/
if-no-files-found: error
retention-days: 7
# A rerun attempt re-uploads under the same name, which is otherwise refused.
overwrite: true