Repository navigation
The pre-lock ACL refusal names each principal once per path (#4043) - #4069
Merged
Merged
Conversation
A folder made under C:\ inherits BUILTIN\Users as two ACEs, and dev's upgrade refused DARLING01's pre-#4038 install root with "BUILTIN\Users on C:\PerformanceMonitorDarling" listed twice. Two of the four callers of Get-UntrustedWriteGrantees dropped repeated lines and two did not. The function now returns each finding once (both script copies change identically, so the byte-identity test still holds), and the two call-site de-duplications it replaces are removed. New test: two write ACEs for one principal produce one finding; red before the fix (count=2). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ua31ugERL5DmhFVRtf6keQ
erikdarlingdata
marked this pull request as ready for review
September 23, 2026 20:37
erikdarlingdata
deleted the
feature/4043-refusal-names-principal-once
branch
September 23, 2026 20:37
erikdarlingdata
added a commit
that referenced
this pull request
Sep 23, 2026
…ntries in their sections (#4080) Adds 42 entries and 42 link refs (#3992, #3995, #3996, #3998, #4001, #4002, #4003, #4007, #4010, #4011, #4013, #4015, #4020, #4022, #4025, #4029, #4030, #4031, #4036, #4038, #4039, #4040, #4044, #4047, #4048, #4049, #4050, #4051, #4055, #4061, #4063, #4064, #4065, #4066, #4067, #4068, #4069, #4070, #4071, #4073, #4074, #4078). Each PR's entry was buffered, and this lands every entry whose PR was merged on origin/dev when it ran. #3989 left 26 entries under bare 'Changed' and 'Fixed' lines above '### Added'. They move into '### Changed' and '### Fixed', below the new entries, and one blank line stays under [Unreleased]. Claude-Session: https://claude.ai/code/session_01Ua31ugERL5DmhFVRtf6keQ Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Today I deployed dev to DARLING01. Its install folder is older than #4038, so the upgrade script refused it, as #4050 intends. But the refusal named one principal twice:
A folder made under C:\ gets BUILTIN\Users as two ACEs: one gives append rights and one gives write rights.
Get-UntrustedWriteGranteeswrites one line for each ACE. Two of its four callers removed the repeated lines. The other two did not: the install folder check and the SHA256SUMS folder check in upgrade-darling.ps1.What changes
Get-UntrustedWriteGranteesreturns each finding once. Both scripts get the same change, so the test that keeps the two copies identical still passes.ThePreLockWritableExtractionCheck_NamesAPrincipalOnce_WhenTwoOfItsAcesGrantWrite, gives one principal two write ACEs and expects one finding. Before the fix, it failed withcount=2.This PR has no CHANGELOG entry. #4050 is not released yet, and its entry is still true.
Test plan
-AcceptWritableExtraction, the upgrade ran and locked the folder. A second run without the switch passed the install folder check and refused the staging folder, which ordinary users can write to.🤖 Generated with Claude Code
https://claude.ai/code/session_01Ua31ugERL5DmhFVRtf6keQ