fix(tauri): bind elevated scripts to catalog authority
Preserve required UAC elevation for game_setup.cmd, game_start.cmd, and server_start.cmd through a fixed-role elevated launcher worker. The worker reloads and matches embedded catalog authority, verifies the exact script from a no-follow locked handle, resolves System32 cmd.exe, and transfers path locks into the command process. Setup still waits for completion; game and server return after the verified handoff while their command process retains the locks. Unmanifested, changed, reparse-backed, markerless, and streamed-only scripts fail closed. Test Plan: - just test - just clippy - just frontend-test - just build-fixture - nine Linux-visible authority/parser/digest tests - Windows-only lock-transfer test added but not run (no Windows target/runtime available) - git diff --check
This commit is contained in:
1 parent
42cf98ecec
commit
67ea355599
6 files changed
+1491
-170
No files matched your search
@@ -1,4 +1,8 @@
|
||||
use std::{env, fs};
|
||||
use std::{
|
||||
env,
|
||||
fs,
|
||||
path::{Path, PathBuf},
|
||||
};
|
||||
|
||||
use build_support::catalog_gate::{
|
||||
CatalogBuildMode,
|
||||
@@ -13,6 +17,9 @@ mod build_support {
|
||||
}
|
||||
|
||||
const FIXTURE_DEVELOPMENT_ENV: &str = "LANSPREAD_USE_FIXTURE_CATALOG";
|
||||
const CATALOG_CONTENT_INDEX_NAME: &str = "catalog-content-index-v1.jsonl";
|
||||
const EMBEDDED_CATALOG_INDEX_NAME: &str = "embedded-catalog-content-index-v1.jsonl";
|
||||
const FIXTURE_MANIFEST_ROOT: &str = "../../lanspread-peer-cli/catalogs/default/manifests";
|
||||
|
||||
fn main() {
|
||||
println!("cargo:rerun-if-env-changed=TAURI_CONFIG");
|
||||
@@ -29,9 +36,27 @@ fn main() {
|
||||
{
|
||||
panic!("production catalog authority gate failed: {error}");
|
||||
}
|
||||
embed_catalog_content_index(mode).unwrap_or_else(|error| {
|
||||
panic!("failed to embed catalog launch authority: {error}");
|
||||
});
|
||||
tauri_build::build();
|
||||
}
|
||||
|
||||
fn embed_catalog_content_index(mode: CatalogBuildMode) -> Result<(), Box<dyn std::error::Error>> {
|
||||
let manifest_root = match mode {
|
||||
CatalogBuildMode::FixtureDevelopment => Path::new(FIXTURE_MANIFEST_ROOT),
|
||||
CatalogBuildMode::Production => Path::new("manifests"),
|
||||
};
|
||||
let source = manifest_root.join(CATALOG_CONTENT_INDEX_NAME);
|
||||
println!("cargo:rerun-if-changed={}", source.display());
|
||||
let bytes = fs::read(&source)?;
|
||||
let out_dir =
|
||||
env::var_os("OUT_DIR").ok_or_else(|| std::io::Error::other("OUT_DIR is not set"))?;
|
||||
let output = PathBuf::from(out_dir).join(EMBEDDED_CATALOG_INDEX_NAME);
|
||||
fs::write(output, bytes)?;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
fn catalog_build_mode() -> Result<CatalogBuildMode, Box<dyn std::error::Error>> {
|
||||
let base_config = fs::read_to_string("tauri.conf.json")?;
|
||||
let config_override = env::var_os("TAURI_CONFIG")
|
||||
|
||||
Reference in new issue
Block a user