Skip to content

Complete verified Windows update installation after MVP desktop packaging #2000

Description

@integry

Objective

Keep the first cross-platform desktop release functional and fail-closed by shipping Windows update checks/install as explicitly unsupported, then complete the held-byte native Windows installation authority as a separate post-MVP child.

Why this is separate

On packaging PR #1972, both the direct fixed csc.exe build and packaged helper authentication complete, but the ordinary-user native broker cannot reach its first child MANIFEST frame on hosted Windows Server 2025. Exact head 0a37eccc475447b400033379559577233b009574 still returns fixed TRANSPORT_SPAWN in 22.57 ms in x64 job 99334496232 after the narrowly scoped session-temp owner/DACL normalization. This falsifies the prior temp-owner hypothesis. Continuing speculative launch changes would delay otherwise functional Windows MSI, Linux, and macOS packages.

Scope

  • Implement and prove an ordinary-user Windows transport that consumes the exact held, authenticated update bytes without pathname re-open, mutable feed re-fetch, or TOCTOU.
  • Bind bootstrap/helper/launcher image identity, signer, owner/DACL, protocol version and child lifetime; retain authenticated handles through bounded shutdown.
  • Prefer a documented same-object/native handle or appropriately isolated installed-service design. Do not rely on inherited CRT descriptors whose identity cannot be proved across Node/native/.NET boundaries.
  • Re-enable Windows signed-update availability/application only after x64 and ARM64 native tests reach READY, exercise inspect/setup/held reads, verify exact signer/hash/size, and pass timeout/exit/replay/substitution tests.
  • Restore packaged authority resources and any authority-specific MSI behavior only with those gates green. Keep the application package/MSI, local setup wizard, remote API profiles, and ProPR Connect discovery independent of this authority.
  • Coordinate build-only compiler/catalog/job/image lifetime hardening with Harden Windows desktop packaging build object identity after functional release #1998 and privileged ProPR Connect service work with Isolate and harden the privileged Windows ProPR Connect authority #1997; do not duplicate either scope.

Dependency and integration

Start only after #1972 is integrated into the Electron runtime epic. Add the AI label and the then-current runtime descendant base label at that point. Require exact-head review and real hosted Windows x64/ARM64 CI. Never target or merge directly to main.

Part of #1950, #1952, #1957, and #1962.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions