fix(tauri): bind elevated scripts to catalog authority

Preserve required UAC elevation for game_setup.cmd, game_start.cmd, and server_start.cmd through a fixed-role elevated launcher worker. The worker reloads and matches embedded catalog authority, verifies the exact script from a no-follow locked handle, resolves System32 cmd.exe, and transfers path locks into the command process.

Setup still waits for completion; game and server return after the verified handoff while their command process retains the locks. Unmanifested, changed, reparse-backed, markerless, and streamed-only scripts fail closed.

Test Plan:
- just test
- just clippy
- just frontend-test
- just build-fixture
- nine Linux-visible authority/parser/digest tests
- Windows-only lock-transfer test added but not run (no Windows target/runtime available)
- git diff --check
This commit is contained in:
ddidderr committed 2026-09-12 13:10:36 +02:00
1 parent 42cf98ecec
commit 67ea355599
6 files changed
+1491 -170

No files matched your search

Generated
+1
View File
@@ -2247,6 +2247,7 @@ name = "lanspread-tauri-deno-ts"
version = "0.1.0"
dependencies = [
"base64 0.23.1",
"blake3",
"cap-fs-ext",
"cap-primitives",
"eyre",