Procházet zdrojové kódy

Merge codex/subprocess-win32-process-primitives into codex/subprocess-native-containment

pku-xht před 1 měsícem
rodič
revize
cd1a8552f7

+ 2 - 2
packages/sandbox/sandbox-windows-acl/README.i18n.yaml

@@ -2,5 +2,5 @@
 # side as of the last confirmed-consistent state. Both languages carry equal authority;
 # after editing either side, bring the other along and re-record with:
 #   pnpm run verify-translation-pairing --write packages/sandbox/sandbox-windows-acl/README.md
-README.md: 91172cc0b2fcab1daceb75f7c02f3eecc679bab1
-README.zh.md: 0e8435e3d1a27a2868f97d6af4ce9e66953e8a26
+README.md: 2cf79c8eede0943630f79bea717c9e072226fa7f
+README.zh.md: 690b5d10ecbeae0192dc98095c785ab64030e9f6

+ 0 - 2
packages/sandbox/sandbox-windows-acl/README.md

@@ -68,8 +68,6 @@ The sandbox-owned SID, ACL, token, file, and lock constants and layouts were ver
 g++ -std=c++20 -municode -O2 -o abi-probe.exe verify/abi-probe.cpp -ladvapi32 && ./abi-probe.exe
 ```
 
-The koffi struct definitions assert their sizes against the probe at module load, so a header/koffi layout drift fails loudly instead of corrupting memory.
-
 ## Verified boundaries (inherent to restricted tokens, not this port)
 
 - **Everyone grants remain ambient write authority.** Everyone must stay in both restricting lists: removing it breaks early DLL initialization and CNG. An external NTFS object whose normal DACL grants Everyone a requested write right therefore clears both access checks and stays writable under both modes. The real runner suite provisions an external `Everyone:Modify` directory and pins that behavior; the provider reports `enforcement: 'partial'` so callers can reject or surface the weaker boundary.

+ 0 - 2
packages/sandbox/sandbox-windows-acl/README.zh.md

@@ -70,8 +70,6 @@ sandbox 自有的 SID、ACL、token、文件与锁常量和布局均已在开发
 g++ -std=c++20 -municode -O2 -o abi-probe.exe verify/abi-probe.cpp -ladvapi32 && ./abi-probe.exe
 ```
 
-koffi 结构体定义在模块加载时对照探针断言其大小,因此头文件/koffi 布局漂移会大声失败而不是破坏内存。
-
 ## 已验证边界(受限令牌固有,非本移植引入)
 
 - **Everyone 授权仍是环境中的写权限来源。** Everyone 必须保留在两种 restricting 列表中:移除它会破坏早期 DLL 初始化与 CNG。因此,如果外部 NTFS 对象的正常 DACL 向 Everyone 授予所请求的写权限,它就会同时通过两次访问检查,并在两种模式下保持可写。真实 runner 套件配置一个外部 `Everyone:Modify` 目录并钉住该行为;提供方报告 `enforcement: 'partial'`,使调用方能够拒绝或向上暴露这项较弱的边界。

+ 2 - 2
packages/subprocess/win32-process/README.i18n.yaml

@@ -2,5 +2,5 @@
 # side as of the last confirmed-consistent state. Both languages carry equal authority;
 # after editing either side, bring the other along and re-record with:
 #   pnpm run verify-translation-pairing --write packages/subprocess/win32-process/README.md
-README.md: bc539a9acd5129081255ff08d7b99b062314b6ea
-README.zh.md: 5730055133af00243d3614b034262e6cd1115995
+README.md: d541b90448a4f42879a62a015374d139aa502395
+README.zh.md: 6a542ff0a83571198756d8362d3be581f192ae2d

+ 2 - 2
packages/subprocess/win32-process/README.md

@@ -17,13 +17,13 @@ The Windows ACL sandbox adds SID, DACL, grant, workspace, and public child polic
 
 ## Header verification
 
-The process, stdio, and Job constants, signatures, and layouts are checked against the MinGW Windows headers by [`verify/abi-probe.cpp`](verify/abi-probe.cpp):
+The process, stdio, and Job constants plus selected structure sizes and offsets are checked against the MinGW Windows headers by [`verify/abi-probe.cpp`](verify/abi-probe.cpp):
 
 ```sh
 g++ -std=c++20 -municode -O2 -o abi-probe.exe verify/abi-probe.cpp && ./abi-probe.exe
 ```
 
-The Koffi struct definitions also assert their sizes at module load, so a header or layout mismatch fails before native process creation.
+The Koffi `STARTUPINFOW` and `PROCESS_INFORMATION` definitions also assert their 64-bit sizes at module load. The probe remains the evidence for the other recorded offsets and constants.
 
 ## Model Experience
 

+ 2 - 2
packages/subprocess/win32-process/README.zh.md

@@ -17,13 +17,13 @@ Windows ACL 沙箱在这些原语上增加 SID、DACL、grant、workspace 与公
 
 ## 头部验证
 
-process、stdio 与 Job 的常量、签名和布局由 [`verify/abi-probe.cpp`](verify/abi-probe.cpp) 对照 MinGW Windows 头文件检查:
+process、stdio 与 Job 的常量以及选定结构体的大小和偏移由 [`verify/abi-probe.cpp`](verify/abi-probe.cpp) 对照 MinGW Windows 头文件检查:
 
 ```sh
 g++ -std=c++20 -municode -O2 -o abi-probe.exe verify/abi-probe.cpp && ./abi-probe.exe
 ```
 
-Koffi 结构体定义还会在模块加载时断言自身大小,因此头文件或布局不匹配会在创建 native process 前失败。
+Koffi 的 `STARTUPINFOW` 与 `PROCESS_INFORMATION` 定义还会在模块加载时断言各自的 64 位大小;其余已记录偏移和常量由该探针提供证据。
 
 ## Model Experience