fix: preserve user access to daemon diagnostics - #255
Merged
Merged
Conversation
Grant the manager process user full access alongside SYSTEM and Administrators on protected daemon-log directories and files. Keep the LocalSystem ACL unchanged and preserve the same policy through rotation and reopen. Reject unexpected existing owners before changing a DACL. Cover descriptor scope, owner validation, restricted-user create/write/rotation/restart and legacy directory repair, and verify user-manager startup persists its diagnostic event. Tracks #253. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
PLN
added a commit
that referenced
this pull request
Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem and change
Tracks #253.
User managers could not open their own diagnostics after #236 applied a SYSTEM/Administrators-only daemon-log DACL. The fix adds the validated process user SID to the protected directory and file DACLs, preserves the existing LocalSystem policy, and carries the policy through rotation and restart. Before changing a DACL it rejects owners other than that process user, SYSTEM or Administrators. Root containment, reparse rejection and nonblocking diagnostics remain unchanged.
Permanent regressions cover exact ACEs, owner validation, restricted-user create/write/rotation/reopen, repair of the legacy directory DACL, and persistence of daemon.open from the real user-manager entry point. Recovery backoff is tracked separately in #254 and is unchanged here.
Validation
344bf2d2e970a347b71f03c0da0ab456324f9f85. Windows full race tests passed with the symlink regression enabled.windows-amd64, ID10803655676; cross-build manifest artifact ID10802544533. Artifact and manifest verification passed during native qualification.Native qualification — PASS
Evidence ID:
qualification-344bf2d-daemonlog-acl. Qualified source344bf2d2e970a347b71f03c0da0ab456324f9f85, clean tree629a6bd7d9b39d2d3c478aec38fe9994293e8c36.CI run 35987962097
passed all three jobs. Windows artifact ID
10803655676and cross-manifestartifact ID
10802544533were verified; native/cross manifests match.Native security suites passed in standard WTS, genuine filtered-administrator
and headless S4U lanes, with selective-inheritance positive controls in each
lane. The privileged SYSTEM symlink regression also passed. Total: 7 PASS,
0 skips, 0 race warnings. Native race-test binaries were separately built
with Go 1.27.1 from the clean exact-source checkout; their source binding is
the guarded build and clean-source evidence, not an embedded VCS revision.
Final checks found healthy interactive managers, empty recovery and the
headless profile unloaded.
Limits: 65-second stability is a bounded observation, not a soak or resolution
of backoff issue #254. The separate live endpoint-open and server-owner
security cases (A/B) were not run; remaining release prerequisites remain
open. Raw fixture evidence stays private. Merge still requires authorization
and an equal tested/merged tree.
🤖 Generated with Claude Code