mirror of https://github.com/garrytan/gstack.git
An unqualified username is ambiguous. On a machine whose hostname equals the username, it does not resolve to the user account; icacls silently writes an ACE for the machine SID instead. Combined with /inheritance:r, the directory is left with a single ACE that matches nobody, so the process that just created it can no longer enumerate or write to it. In practice this means browse can never start on an affected machine: it bricks .gstack/ on first run, then reports "Another instance is starting the server" because acquireServerLock() returns null on the resulting EACCES. The real cause is invisible, since icacls reports success and stdio is ignored. Resolve the current user's SID and pass icacls the literal *<SID> form, which is immune to name-resolution ambiguity. Fall back to the domain-qualified name if the lookup fails. The SID lookup pins %SystemRoot%\System32\whoami.exe rather than a bare `whoami`, which under a bash-flavoured PATH resolves to the MSYS build and rejects /user. Without the pin the primary path would silently fail on Git Bash, one of the most common Windows setups for this tool. Tests assert the directory stays usable by the calling process after hardening. The existing Windows cases only asserted "does not throw", which this bug sails straight past. On the pre-fix code path 8 of 15 tests fail, several of them pre-existing. Refs #2478 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| bin | ||
| scripts | ||
| src | ||
| test | ||
| PLAN-snapshot-dropdown-interactive.md | ||
| SKILL.md | ||
| SKILL.md.tmpl | ||