Skip to content

Grant ALL APPLICATION PACKAGES read access on the app install root - #1918

Open
codebytere wants to merge 2 commits into
Squirrel:developfrom
codebytere:grant-app-packages-read
Open

codebytere wants to merge 2 commits into
Squirrel:developfrom
codebytere:grant-app-packages-read

Conversation

@codebytere

Copy link
Copy Markdown

Apps whose child processes run in a restricted-token sandbox (Chromium, Electron, CEF) fail to start from a Squirrel install when %LocalAppData% carries an inherited ACE for some AppContainer package SID: Windows then evaluates the restricted token against the folder as if it were an AppContainer, and only an ALL APPLICATION PACKAGES entry can grant access. Per-machine installs under Program Files always have that entry; per-user Squirrel installs do not, so the sandboxed processes are denied their own install directory (electron/electron#51761 has the reports and the ACL analysis).

This adds an inheritable read/execute ACE for ALL APPLICATION PACKAGES (S-1-15-2-1) on the app root during install, before files are extracted, and again at the start of an update so existing installs pick it up. Failure to set it is logged and does not fail the install.

Restricted-token sandbox processes (Chromium, Electron, CEF children) are
denied access to a directory whose ACL carries an AppContainer package ACE
but no ALL APPLICATION PACKAGES entry. Per-user installs under
%LocalAppData% can inherit the former from other software; Program Files
installs always have the latter. Add the same inheritable read/execute
grant on the app root at install time and at the start of an update.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant