Skip to content

fix: preserve user access to daemon diagnostics - #255

Merged
PLN merged 1 commit into
mainfrom
fix/daemonlog-user-acl
Sep 24, 2026
Merged

PLN merged 1 commit into
mainfrom
fix/daemonlog-user-acl

Conversation

@PLN

@PLN PLN commented Sep 24, 2026 •

Copy link
Copy Markdown
Owner

Problem and change

Tracks #253.

User managers could not open their own diagnostics after #236 applied a SYSTEM/Administrators-only daemon-log DACL. The fix adds the validated process user SID to the protected directory and file DACLs, preserves the existing LocalSystem policy, and carries the policy through rotation and restart. Before changing a DACL it rejects owners other than that process user, SYSTEM or Administrators. Root containment, reparse rejection and nonblocking diagnostics remain unchanged.

Permanent regressions cover exact ACEs, owner validation, restricted-user create/write/rotation/reopen, repair of the legacy directory DACL, and persistence of daemon.open from the real user-manager entry point. Recovery backoff is tracked separately in #254 and is unchanged here.

Validation

  • Windows Go 1.27.1 focused journal/manager race lanes, including owner and restricted-identity regressions: passed.
  • Windows user-manager startup persistence race lane: passed.
  • go vet ./... and Staticcheck v0.8.1 ./...: passed.
  • The local full manager race suite passed. The local journal suite passed with only TestDaemonLogRejectsSymlinkEscape explicitly excluded because the local token lacks symlink-creation privilege; that test remains enabled in hosted CI.
  • Exact-source CI run 35987962097 passed all three jobs on 344bf2d2e970a347b71f03c0da0ab456324f9f85. Windows full race tests passed with the symlink regression enabled.
  • Native Windows artifact: windows-amd64, ID 10803655676; cross-build manifest artifact ID 10802544533. Artifact and manifest verification passed during native qualification.

Native qualification — PASS

Evidence ID: qualification-344bf2d-daemonlog-acl. Qualified source
344bf2d2e970a347b71f03c0da0ab456324f9f85, clean tree
629a6bd7d9b39d2d3c478aec38fe9994293e8c36.
CI run 35987962097
passed all three jobs. Windows artifact ID 10803655676 and cross-manifest
artifact ID 10802544533 were verified; native/cross manifests match.

Lane Result
a — SYSTEM PASS: healthy broker; protected daemon-directory/file DACLs byte-identical to the original SYSTEM/Administrators policy.
b — Interactive PASS: two standard WTS users and a genuine filtered administrator reached running with control endpoints and persisted daemon.open; protected directory/current/archive ACLs, product rotation and 65-second instance stability verified.
c — Headless PASS: S4U via linger passed the same startup, ACL, rotation and stability checks; linger disabled and profile unloaded afterward.
d — Cross-user denial PASS: a genuine standard WTS token received exact WinError 5 for four read-only opens of peer and SYSTEM daemon directories/logs.
e — Legacy repair PASS: three legacy user-owned SYSTEM/Administrators-only directories were repaired by first successful startup without manual ACL grants.

Native security suites passed in standard WTS, genuine filtered-administrator
and headless S4U lanes, with selective-inheritance positive controls in each
lane. The privileged SYSTEM symlink regression also passed. Total: 7 PASS,
0 skips, 0 race warnings
. Native race-test binaries were separately built
with Go 1.27.1 from the clean exact-source checkout; their source binding is
the guarded build and clean-source evidence, not an embedded VCS revision.
Final checks found healthy interactive managers, empty recovery and the
headless profile unloaded.

Limits: 65-second stability is a bounded observation, not a soak or resolution
of backoff issue #254. The separate live endpoint-open and server-owner
security cases (A/B) were not run; remaining release prerequisites remain
open. Raw fixture evidence stays private. Merge still requires authorization
and an equal tested/merged tree.

🤖 Generated with Claude Code

Grant the manager process user full access alongside SYSTEM and Administrators on protected daemon-log directories and files. Keep the LocalSystem ACL unchanged and preserve the same policy through rotation and reopen. Reject unexpected existing owners before changing a DACL.

Cover descriptor scope, owner validation, restricted-user create/write/rotation/restart and legacy directory repair, and verify user-manager startup persists its diagnostic event.

Tracks #253.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@PLN
PLN merged commit 45e374a into main Sep 24, 2026
3 checks passed
PLN added a commit that referenced this pull request Sep 24, 2026
Tracks #253. Docs-only. Record native qualification of #255, exact-source evidence, the SCM stop/start rotation mechanism and remaining scope limits.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant