Skip to content

R6.3: preserve mutable data and detect install conflicts - #244

Merged
PLN merged 3 commits into
mainfrom
cursor/r63-data-compatibility-5b77
Sep 23, 2026
Merged

PLN merged 3 commits into
mainfrom
cursor/r63-data-compatibility-5b77

Conversation

@PLN

@PLN PLN commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

Summary

Closes MILESTONES R6.3 for #243. This does not close overall R6, and it does not change A3 / R4.4.

  • Machine and user units, journals, timer state, and linger records stay outside MSI file components. Mutable directories remain permanent. Child directories no longer carry PermissionEx, so repair does not overwrite units, reset enable records, recreate user configuration, or reapply those ACLs. There is no purge option.
  • The deferred servicing helper runs before stop, file replacement, and service start. It fails closed on an unowned or unrelated winunitd service, an unmanaged binary path, a custom base directory (no silent adopt or relocate), a machine-wide pilot launcher, and a data directory that is a reparse point or has unexpected ownership. It does not follow the link.
  • Uninstall still removes the service, package binaries, event registration, and the PATH entry this package added, and it keeps the mutable data above. Reinstall over that tree starts units that are already enabled.
  • Format changes stay an explicit migration. The package does not rewrite on-disk state, and MSI rollback does not undo an application-data migration. The Hermes pilot move remains R6.5 / R7.
  • Repair, same-MSI reinstall, and uninstall accept the MSI Installed value when it is a date/time (00:00:00 or 14-digit YYYYMMDDHHMMSS). Windows Installer sets that property to an installation date, not a product-code list. Product-code lists are unchanged. Garbage tokens still fail closed, and the log marker stays preflight conflict:.
  • docs/R6-EVIDENCE.md records R6.2 native evidence id b915fbd-r62-servicing and the R6.3 retention and preflight contract. Native SYSTEM execution of the corrected preflight is not claimed.

Tests

  • go test ./tools/msi-check/ ./internal/version/ (repair/upgrade/uninstall fixture, authoring split, conflict and unsafe-directory decisions)
  • GOOS=windows go test -c ./tools/msi-check/ (Windows helper compiles, including the user-owned directory and reparse inspections)
  • Installed date forms 00:00:00 and 20260923000000 are repair context. The same dates with REMOVE=ALL are uninstall. Malformed dates, and a date passed as WIX_UPGRADE_DETECTED, still fail closed with preflight conflict: invalid installer context.

A native SYSTEM repair, reinstall, and uninstall previously failed closed because Installed was an MSI date. This change accepts those dates. A later pass should still capture the preflight conflict: log line for a junction under the data root and for a pre-existing service whose image is not the package binary.

Open in Web Open in Cursor 

R6.3 keeps units, journals, timer state, and linger records outside MSI
file components across repair, upgrade, and uninstall. The servicing
helper fails closed on conflicting services, custom base directories,
pilot launchers, and unsafe directories before it stops or starts the
service.

Co-authored-by: PLN <PLN@users.noreply.github.com>
@PLN
PLN marked this pull request as ready for review September 22, 2026 23:31
cursoragent and others added 2 commits September 22, 2026 23:40
A clean Windows runner owns a new temp directory as Administrators, so
preflight rejects it for a non-administrator write grant. Keep that
fail-closed conflict, and still accept unexpected ownership when the
token is not elevated.

Co-authored-by: PLN <PLN@users.noreply.github.com>
Windows Installer sets Installed to a date/time such as 00:00:00, not a
product-code list. Repair, same-package reinstall, and uninstall were
rejected as an invalid installer context. Garbage tokens still fail closed.

Co-authored-by: PLN <PLN@users.noreply.github.com>
@PLN
PLN merged commit 97c464c into main Sep 23, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants