Tell a refused file from a missing one, and read driver and network paths the way Windows does - #45
Merged
Merged
Conversation
…aths the way Windows does Stability report, package G (R-1 to R-7). - A file the current token may not look at was reported as missing, because File.Exists answers false for it. Existence is now asked through File.GetAttributes, and a refusal comes back as a refusal with its code - for the launch path, the signature, the file version and the hash. In the prefix walk, the first candidate that is there or refuses is the answer. - The device namespace (\\?\ and \\.\) counts as local only before a drive letter or a volume. \\.\UNC\, GLOBALROOT and \??\UNC\ used to be followed as local paths to a share. - A driver path is one file name: no splitting at spaces and no appended .exe, so a planted C:\Program cannot stand in for a driver under C:\Program Files. A kernel namespace path (\Device\...) becomes its \\?\GLOBALROOT spelling instead of C:\Device\..., and a service written as a bare file name is searched for in System32, System, the Windows directory and the machine's PATH, as CreateProcess documents. - The account, launch command, load order group and description are read no further than the block the service manager returned, and a pointer outside it is refused for that field. - A listing turn that makes no progress is asked again up to three times before the listing gives up, instead of failing the whole listing at once. - A file no SHA-256 catalogue lists is looked up again with SHA-1 before it is called unsigned. - A recognizer driver (type 0x8) is treated as a driver, without a new entry type value. - "No access" is said only for a refusal of access. Every other failed reading says "could not be read". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configuration
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Package G of the stability report: reading no longer mistakes a file or a network path.
What changes
File.GetAttributes(FileOnDisk), and in the prefix walk the first candidate that is there or refuses is the answer.\\?\and\\.\count as local only before a drive letter or a volume.\\.\UNC\,GLOBALROOTand\??\UNC\are no longer followed without--follow-network..exe, and\Device\...becomes its\\?\GLOBALROOTspelling. A service written as a bare file name is searched for in System32, System, the Windows directory and the machine's PATH, in the order the CreateProcess documentation gives.entryTypevalue, and "no access" is said only for a refusal of access - any other failed reading says "could not be read".No change to the JSON shape.
binaryOnDiskcan now benullwith anunreadableentry where it used to befalse, which is the existing shape for a refused field.Checked
🤖 Generated with Claude Code