Skip to content

Tell a refused file from a missing one, and read driver and network paths the way Windows does - #45

Merged
donislawdev merged 1 commit into
mainfrom
fix/stability-package-g
Oct 5, 2026
Merged

donislawdev merged 1 commit into
mainfrom
fix/stability-package-g

Conversation

@donislawdev

Copy link
Copy Markdown
Owner

Package G of the stability report: reading no longer mistakes a file or a network path.

What changes

  • R-1 A file the current token may not look at is reported as refused, not missing - for the launch path, the signature, the file version and the hash. Existence goes through File.GetAttributes (FileOnDisk), and in the prefix walk the first candidate that is there or refuses is the answer.
  • R-2 \\?\ and \\.\ count as local only before a drive letter or a volume. \\.\UNC\, GLOBALROOT and \??\UNC\ are no longer followed without --follow-network.
  • R-3 A driver path is one file name: no splitting at spaces, no appended .exe, and \Device\... becomes its \\?\GLOBALROOT spelling. A service written as a bare file name is searched for in System32, System, the Windows directory and the machine's PATH, in the order the CreateProcess documentation gives.
  • R-4 Configuration strings and the description are read no further than the block returned, and a pointer outside it refuses that field.
  • R-5 A listing turn without progress is asked again up to three times before the listing fails.
  • R-6 A file no SHA-256 catalogue lists is looked up again with SHA-1 before it is called unsigned.
  • R-7 A recognizer driver (type 0x8) is treated as a driver without a new entryType value, and "no access" is said only for a refusal of access - any other failed reading says "could not be read".

No change to the JSON shape. binaryOnDisk can now be null with an unreadable entry where it used to be false, which is the existing shape for a refused field.

Checked

  • Narrow test run over the classes this touches: core, command line, window, architecture and the integration contracts that read the real machine (binary paths, signatures, listing, plan).
  • Mutation entries anchored in the touched files: all caught once one test that two rules both satisfied was made specific.
  • The listing with signatures, from the previous build and this one on the same machine: identical on every entry, elevated and under a restricted token.

🤖 Generated with Claude Code

…aths the way Windows does

Stability report, package G (R-1 to R-7).

- A file the current token may not look at was reported as missing, because File.Exists answers
  false for it. Existence is now asked through File.GetAttributes, and a refusal comes back as a
  refusal with its code - for the launch path, the signature, the file version and the hash.
  In the prefix walk, the first candidate that is there or refuses is the answer.
- The device namespace (\\?\ and \\.\) counts as local only before a drive letter or a volume.
  \\.\UNC\, GLOBALROOT and \??\UNC\ used to be followed as local paths to a share.
- A driver path is one file name: no splitting at spaces and no appended .exe, so a planted
  C:\Program cannot stand in for a driver under C:\Program Files. A kernel namespace path
  (\Device\...) becomes its \\?\GLOBALROOT spelling instead of C:\Device\..., and a service
  written as a bare file name is searched for in System32, System, the Windows directory and
  the machine's PATH, as CreateProcess documents.
- The account, launch command, load order group and description are read no further than the
  block the service manager returned, and a pointer outside it is refused for that field.
- A listing turn that makes no progress is asked again up to three times before the listing
  gives up, instead of failing the whole listing at once.
- A file no SHA-256 catalogue lists is looked up again with SHA-1 before it is called unsigned.
- A recognizer driver (type 0x8) is treated as a driver, without a new entry type value.
- "No access" is said only for a refusal of access. Every other failed reading says
  "could not be read".

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Repository UI (base), Organization UI (inherited)
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 6a2cefed-6f8e-4e8d-aa59-bd018c6d6226
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@donislawdev
donislawdev merged commit 9b7534b into main Oct 5, 2026
8 checks passed
@donislawdev
donislawdev deleted the fix/stability-package-g branch October 5, 2026 18:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant