Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Windows sandbox: toolchain access is granted on the shared Program Files folder itself

Aperta
#207 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
55/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
typescript
Ambito
desktop, security

Direzione di ricerca

Start by reading native/sandbox-helper/src/win.rs, especially the ACL grant near line 1732 and recovery around line 1646; trace how Program Files toolchains are selected for staging versus a shared-folder grant. Compare the proposal's staging default, narrower bin grant, and launch-time recovery options. Done means the chosen approach limits access to the necessary files and cleans up any temporary permissions after forced termination.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

enhancement platform: windows priority: low security severity: low

From Finding 1 of the earlier SECURITY-REVIEW.md, checked against the current code on 2026-10-07.

Problem

When a Program Files toolchain folder isn't readable by app containers but its permissions are writable, the helper grants that run's container SID FILE_READ_EXECUTE on the shared install folder itself (native/sandbox-helper/src/win.rs:1732: edit_acl(&plan.source, sid, FILE_READ_EXECUTE, Change::Grant)). The grant is inherited by everything below it. It is revoked at cleanup, or by recovery at the next helper start after a forced kill (record.granted, win.rs:1646).

Impact (bounded)

  • While the command runs, it can read every file in that install folder, not just the toolchain's public files.
  • After a forced kill, the ACE stays until the next helper start. The SID is unique per run, so no later process gets that access. The leftover is clutter on a system folder rather than an open door.

Proposal

Make staging (the private read-only copy, already used for protected installs) the default for Program Files toolchains, and keep the shared-folder grant as a last resort. Or grant only the smallest folder needed (for example bin). Optionally start a recovery pass when the app launches, so a forced kill leaves no ACE behind until the next command.

Lingua principale
TypeScript
Stelle
2
Fork
2
Merge medio
5h 28m
PR unite (30g)
24

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di PierrunoYT/patch

Tutte le issue di PierrunoYT/patch

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.