fix(tauri): bind elevated scripts to catalog authority
Preserve required UAC elevation for game_setup.cmd, game_start.cmd, and server_start.cmd through a fixed-role elevated launcher worker. The worker reloads and matches embedded catalog authority, verifies the exact script from a no-follow locked handle, resolves System32 cmd.exe, and transfers path locks into the command process. Setup still waits for completion; game and server return after the verified handoff while their command process retains the locks. Unmanifested, changed, reparse-backed, markerless, and streamed-only scripts fail closed. Test Plan: - just test - just clippy - just frontend-test - just build-fixture - nine Linux-visible authority/parser/digest tests - Windows-only lock-transfer test added but not run (no Windows target/runtime available) - git diff --check
This commit is contained in:
1 parent
42cf98ecec
commit
67ea355599
6 files changed
+1491
-170
No files matched your search
Generated
+1
@@ -2247,6 +2247,7 @@ name = "lanspread-tauri-deno-ts"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"base64 0.23.1",
|
||||
"blake3",
|
||||
"cap-fs-ext",
|
||||
"cap-primitives",
|
||||
"eyre",
|
||||
|
||||
Reference in new issue
Block a user