Skip to content

Leave the profile alone in an elevated window, replace only snapshots with --force, skip language files beside the program when elevated - #51

Merged
donislawdev merged 1 commit into
mainfrom
fix/security-package-sd
Oct 6, 2026
Merged

donislawdev merged 1 commit into
mainfrom
fix/security-package-sd

Conversation

@donislawdev

Copy link
Copy Markdown
Owner

Summary

Security report package SD (S-7, S-8, S-9, S-10), owner's decisions.

  • An administrator window under User Account Control writes nothing into the profile. With the administrator role and a token that has a linked limited token, the window no longer creates the layout folder, writes the layout file or moves a damaged one aside - it still reads it. The folder's location follows settings and an environment that the unelevated half of the account controls, so checking the path would not close this. The built-in Administrator and machines with UAC turned off keep saving the layout. A process under a restricted token reports the same token type without the role, so the rule asks for both.
  • snapshot create --force replaces only a snapshot (narrows the documented meaning of the switch). A file this build cannot read as a snapshot is refused with code 2, with or without --force, before signatures are read, and left untouched. Quarantine is gone from this path. The size is asked before the file is read: a 1.5 GB file used to end 0.3.0 with an out of memory error after four seconds.
  • A process with administrator rights does not read languages\gui.<code>.json beside the program and says so in the line under the list when such a file is there.
  • Snapshot access lists unchanged - measured that an account without administrator rights reads 781 of 801 entries identically by itself.

Checks

  • Release build clean. Narrow test run green: core 19, command line 18, window 115, architecture 185, integration 2.
  • Mutation entries for the package: 25 of 25 caught.
  • End to end on published builds: --force over a text file now exits 2 in about 0.3 s with the file untouched (0.3.0 exits 0 and moves it aside), and opening and closing an elevated window leaves the layout file untouched (0.3.0 rewrites it).

🤖 Generated with Claude Code

… with --force, skip language files beside the program when elevated

Security report package SD (S-7, S-8, S-9, S-10), owner's decisions.

- An administrator window under User Account Control (administrator role and a token with a
  linked limited token) no longer creates the layout folder, writes the layout file or moves a
  damaged one aside. It still reads it. The folder's location is chosen by settings and an
  environment the unelevated half of the account controls, so checking the path would not close
  this. The built-in Administrator and machines with UAC off keep saving the layout.
- snapshot create --force replaces only a file this build reads as a snapshot. Any other file is
  refused with code 2, with or without --force, before signatures are read, and left untouched.
  Quarantine of an unreadable file is gone from this path. The size is asked before reading, so a
  very large file no longer ends the command with an out of memory error. This narrows the
  documented meaning of --force.
- A process with administrator rights does not read languages\gui.<code>.json beside the program
  and says so in the line under the list when such a file is there.
- Snapshot access lists stay as they are (measured: an account without administrator rights reads
  781 of 801 entries identically by itself).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Repository UI (base), Organization UI (inherited)
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 45be5710-40c3-4acc-aa0e-695c73adb1a5
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@donislawdev
donislawdev merged commit b67150d into main Oct 6, 2026
8 checks passed
@donislawdev
donislawdev deleted the fix/security-package-sd branch October 6, 2026 14:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant