You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Keep the first cross-platform desktop release functional and fail-closed by shipping Windows update checks/install as explicitly unsupported, then complete the held-byte native Windows installation authority as a separate post-MVP child.
Why this is separate
On packaging PR #1972, both the direct fixed csc.exe build and packaged helper authentication complete, but the ordinary-user native broker cannot reach its first child MANIFEST frame on hosted Windows Server 2025. Exact head 0a37eccc475447b400033379559577233b009574 still returns fixed TRANSPORT_SPAWN in 22.57 ms in x64 job 99334496232 after the narrowly scoped session-temp owner/DACL normalization. This falsifies the prior temp-owner hypothesis. Continuing speculative launch changes would delay otherwise functional Windows MSI, Linux, and macOS packages.
Scope
Implement and prove an ordinary-user Windows transport that consumes the exact held, authenticated update bytes without pathname re-open, mutable feed re-fetch, or TOCTOU.
Bind bootstrap/helper/launcher image identity, signer, owner/DACL, protocol version and child lifetime; retain authenticated handles through bounded shutdown.
Prefer a documented same-object/native handle or appropriately isolated installed-service design. Do not rely on inherited CRT descriptors whose identity cannot be proved across Node/native/.NET boundaries.
Re-enable Windows signed-update availability/application only after x64 and ARM64 native tests reach READY, exercise inspect/setup/held reads, verify exact signer/hash/size, and pass timeout/exit/replay/substitution tests.
Restore packaged authority resources and any authority-specific MSI behavior only with those gates green. Keep the application package/MSI, local setup wizard, remote API profiles, and ProPR Connect discovery independent of this authority.
Start only after #1972 is integrated into the Electron runtime epic. Add the AI label and the then-current runtime descendant base label at that point. Require exact-head review and real hosted Windows x64/ARM64 CI. Never target or merge directly to main.
Objective
Keep the first cross-platform desktop release functional and fail-closed by shipping Windows update checks/install as explicitly unsupported, then complete the held-byte native Windows installation authority as a separate post-MVP child.
Why this is separate
On packaging PR #1972, both the direct fixed
csc.exebuild and packaged helper authentication complete, but the ordinary-user native broker cannot reach its first childMANIFESTframe on hosted Windows Server 2025. Exact head0a37eccc475447b400033379559577233b009574still returns fixedTRANSPORT_SPAWNin 22.57 ms in x64 job 99334496232 after the narrowly scoped session-temp owner/DACL normalization. This falsifies the prior temp-owner hypothesis. Continuing speculative launch changes would delay otherwise functional Windows MSI, Linux, and macOS packages.Scope
READY, exercise inspect/setup/held reads, verify exact signer/hash/size, and pass timeout/exit/replay/substitution tests.Dependency and integration
Start only after #1972 is integrated into the Electron runtime epic. Add the AI label and the then-current runtime descendant base label at that point. Require exact-head review and real hosted Windows x64/ARM64 CI. Never target or merge directly to main.
Part of #1950, #1952, #1957, and #1962.