Skip to content

Recover malformed Windows deny-read ACL state safely - #50940

Merged
copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/4aca32df00d015df3763fdc447ffdfbe3fd6cec0
Oct 4, 2026
Merged

copyberry[bot] merged 1 commit into
mainfrom
copyberry/codex-internal-to-codex-oss/4aca32df00d015df3763fdc447ffdfbe3fd6cec0

Conversation

@copyberry

@copyberry copyberry Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Recover malformed Windows deny-read ACL state safely

Why

Malformed deny_read_acl_state.json previously caused deny-read ACL reconciliation to fail. Recovery must restore bookkeeping without removing unknown existing restrictions or modifying a linked file's contents.

What changed

  • Retry malformed reads for up to two seconds, then rebuild bookkeeping only after excluding active writers and successfully applying current deny-read ACLs. Preserve unknown historical denies and continue propagating I/O errors.
  • Validate the opened state file before reading or writing, rejecting reparse points and files with multiple hard links.
  • Write state in place without truncating before validation, preserving file identity and permissions. Retry sharing violations during writes while preventing replacement through delete access.

Testing

Add Windows tests for corrupt-state recovery, linked-file rejection, concurrent writer and delete-handle behavior, file identity and ACL preservation, and subsequent permission-profile changes. Extend the elevated sandbox integration test to verify that denied reads remain blocked after recovery while allowed writes and deletes succeed.

## Why

Malformed `deny_read_acl_state.json` previously caused deny-read ACL reconciliation to fail. Recovery must restore bookkeeping without removing unknown existing restrictions or modifying a linked file's contents.

## What changed

- Retry malformed reads for up to two seconds, then rebuild bookkeeping only after excluding active writers and successfully applying current deny-read ACLs. Preserve unknown historical denies and continue propagating I/O errors.
- Validate the opened state file before reading or writing, rejecting reparse points and files with multiple hard links.
- Write state in place without truncating before validation, preserving file identity and permissions. Retry sharing violations during writes while preventing replacement through delete access.

## Testing

Add Windows tests for corrupt-state recovery, linked-file rejection, concurrent writer and delete-handle behavior, file identity and ACL preservation, and subsequent permission-profile changes. Extend the elevated sandbox integration test to verify that denied reads remain blocked after recovery while allowed writes and deletes succeed.

GitOrigin-RevId: 4aca32df00d015df3763fdc447ffdfbe3fd6cec0
@copyberry
copyberry Bot force-pushed the copyberry/codex-internal-to-codex-oss/4aca32df00d015df3763fdc447ffdfbe3fd6cec0 branch from 8cdf263 to de3721a Compare October 4, 2026 19:07
@copyberry
copyberry Bot merged commit de3721a into main Oct 4, 2026
1 check failed
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor


Thank you for your submission, we really appreciate it. Like many open-source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution. You can sign the CLA by just posting a Pull Request Comment same as the below format.


I have read the CLA Document and I hereby sign the CLA


You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@copyberry
copyberry Bot deleted the copyberry/codex-internal-to-codex-oss/4aca32df00d015df3763fdc447ffdfbe3fd6cec0 branch October 4, 2026 19:07
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 4, 2026
@meeloo
meeloo deployed to issue-triage October 4, 2026 19:11 — with GitHub Actions Active
@meeloo
meeloo deployed to issue-triage October 4, 2026 19:11 — with GitHub Actions Active
@meeloo
meeloo deployed to issue-triage October 4, 2026 19:11 — with GitHub Actions Active
@meeloo
meeloo deployed to issue-triage October 4, 2026 19:12 — with GitHub Actions Active
@idurucz
idurucz deployed to issue-triage October 4, 2026 19:21 — with GitHub Actions Active
@idurucz
idurucz deployed to issue-triage October 4, 2026 19:21 — with GitHub Actions Active
@idurucz
idurucz deployed to issue-triage October 4, 2026 19:21 — with GitHub Actions Active
@idurucz
idurucz deployed to issue-triage October 4, 2026 19:35 — with GitHub Actions Active
@idurucz
idurucz deployed to issue-triage October 4, 2026 19:35 — with GitHub Actions Active
@idurucz
idurucz deployed to issue-triage October 4, 2026 19:35 — with GitHub Actions Active
@idurucz
idurucz deployed to issue-triage October 4, 2026 19:36 — with GitHub Actions Active
@marjedka
marjedka deployed to issue-triage October 4, 2026 19:50 — with GitHub Actions Active
@marjedka
marjedka deployed to issue-triage October 4, 2026 19:50 — with GitHub Actions Active
@marjedka
marjedka deployed to issue-triage October 4, 2026 19:50 — with GitHub Actions Active
@marjedka
marjedka deployed to issue-triage October 4, 2026 19:51 — with GitHub Actions Active
@Command1264
Command1264 deployed to issue-triage October 4, 2026 19:54 — with GitHub Actions Active
@Command1264
Command1264 deployed to issue-triage October 4, 2026 19:54 — with GitHub Actions Active
@Command1264
Command1264 deployed to issue-triage October 4, 2026 19:54 — with GitHub Actions Active
@Command1264
Command1264 deployed to issue-triage October 4, 2026 19:56 — with GitHub Actions Active
@lucav76
lucav76 deployed to issue-triage October 4, 2026 19:57 — with GitHub Actions Active
@lucav76
lucav76 deployed to issue-triage October 4, 2026 19:57 — with GitHub Actions Active
@lucav76
lucav76 deployed to issue-triage October 4, 2026 19:57 — with GitHub Actions Active
@lucav76
lucav76 deployed to issue-triage October 4, 2026 19:58 — with GitHub Actions Active
@Celtian
Celtian deployed to issue-triage October 4, 2026 20:18 — with GitHub Actions Active
@aaronson2012
aaronson2012 deployed to issue-triage October 4, 2026 20:38 — with GitHub Actions Active
@aaronson2012
aaronson2012 deployed to issue-triage October 4, 2026 20:38 — with GitHub Actions Active
@aaronson2012
aaronson2012 deployed to issue-triage October 4, 2026 20:39 — with GitHub Actions Active
@gwdonnor
gwdonnor deployed to issue-triage October 4, 2026 20:51 — with GitHub Actions Active
@gwdonnor
gwdonnor deployed to issue-triage October 4, 2026 20:51 — with GitHub Actions Active
@gwdonnor
gwdonnor deployed to issue-triage October 4, 2026 20:51 — with GitHub Actions Active
@AdamFrisby
AdamFrisby deployed to issue-triage October 4, 2026 20:55 — with GitHub Actions Active
@AdamFrisby
AdamFrisby deployed to issue-triage October 4, 2026 20:55 — with GitHub Actions Active
@AdamFrisby
AdamFrisby deployed to issue-triage October 4, 2026 20:55 — with GitHub Actions Active
@ninjaguy454
ninjaguy454 deployed to issue-triage October 4, 2026 20:56 — with GitHub Actions Active
@ninjaguy454
ninjaguy454 deployed to issue-triage October 4, 2026 20:56 — with GitHub Actions Active
@ninjaguy454
ninjaguy454 deployed to issue-triage October 4, 2026 20:56 — with GitHub Actions Active
@ninjaguy454
ninjaguy454 deployed to issue-triage October 4, 2026 20:57 — with GitHub Actions Active
@zelezo
zelezo deployed to issue-triage October 4, 2026 21:00 — with GitHub Actions Active
@zelezo
zelezo deployed to issue-triage October 4, 2026 21:00 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
issue-triage — de3721a7 Deployed Oct 4, 2026 by zelezo via Identify potential duplicates (open issues fallback) #51809
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.