R6.3: preserve mutable data and detect install conflicts - #244
Merged
Merged
Conversation
R6.3 keeps units, journals, timer state, and linger records outside MSI file components across repair, upgrade, and uninstall. The servicing helper fails closed on conflicting services, custom base directories, pilot launchers, and unsafe directories before it stops or starts the service. Co-authored-by: PLN <PLN@users.noreply.github.com>
PLN
marked this pull request as ready for review
September 22, 2026 23:31
A clean Windows runner owns a new temp directory as Administrators, so preflight rejects it for a non-administrator write grant. Keep that fail-closed conflict, and still accept unexpected ownership when the token is not elevated. Co-authored-by: PLN <PLN@users.noreply.github.com>
Windows Installer sets Installed to a date/time such as 00:00:00, not a product-code list. Repair, same-package reinstall, and uninstall were rejected as an invalid installer context. Garbage tokens still fail closed. Co-authored-by: PLN <PLN@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes MILESTONES R6.3 for #243. This does not close overall R6, and it does not change A3 / R4.4.
PermissionEx, so repair does not overwrite units, reset enable records, recreate user configuration, or reapply those ACLs. There is no purge option.winunitdservice, an unmanaged binary path, a custom base directory (no silent adopt or relocate), a machine-wide pilot launcher, and a data directory that is a reparse point or has unexpected ownership. It does not follow the link.Installedvalue when it is a date/time (00:00:00or 14-digitYYYYMMDDHHMMSS). Windows Installer sets that property to an installation date, not a product-code list. Product-code lists are unchanged. Garbage tokens still fail closed, and the log marker stayspreflight conflict:.docs/R6-EVIDENCE.mdrecords R6.2 native evidence idb915fbd-r62-servicingand the R6.3 retention and preflight contract. Native SYSTEM execution of the corrected preflight is not claimed.Tests
go test ./tools/msi-check/ ./internal/version/(repair/upgrade/uninstall fixture, authoring split, conflict and unsafe-directory decisions)GOOS=windows go test -c ./tools/msi-check/(Windows helper compiles, including the user-owned directory and reparse inspections)00:00:00and20260923000000are repair context. The same dates withREMOVE=ALLare uninstall. Malformed dates, and a date passed asWIX_UPGRADE_DETECTED, still fail closed withpreflight conflict: invalid installer context.A native SYSTEM repair, reinstall, and uninstall previously failed closed because
Installedwas an MSI date. This change accepts those dates. A later pass should still capture thepreflight conflict:log line for a junction under the data root and for a pre-existing service whose image is not the package binary.