Skip to content

Run a baseline for every new build, retry interrupted ones at once, and lock down the data directory - #58

Merged
rodchristiansen merged 1 commit into
mainfrom
feature/round4-throttle-acl
Oct 5, 2026
Merged

rodchristiansen merged 1 commit into
mainfrom
feature/round4-throttle-acl

Conversation

@rodchristiansen

Copy link
Copy Markdown
Contributor

Throttle

  • A baseline ignores BaselineMinIntervalHours while the running BootstrapMate has neither completed one nor tried one. A new build always gets a baseline. Once it has tried and failed, the 24-hour retry applies, so a failing build cannot loop.
  • An interrupted baseline runs again at the next trigger. Only failed and partial_failure wait 24 hours.
  • Retries come only from the normal triggers (the Intune install and the daily Self-Heal task). BootstrapMate never relaunches itself.
  • baseline.json gains tool_version (the version that last completed a baseline) and attempt_version (the version that last tried one).

Data directory permissions

  • C:\ProgramData\ManagedBootstrap inherited ProgramData's default ACL, which lets standard users create files and folders in it. The SYSTEM run reads from that folder.
  • The MSI now sets the folder's own ACL through PermissionEx: owner SYSTEM, SYSTEM and Administrators full control, Users read.
  • Before each run, the CLI resets the same ACL, removes reparse points, and removes anything a non-administrator owns.
  • Logs that an elevated administrator wrote are kept and re-owned, not removed.

Tested on a test PC (signed MSIs)

  • Before: a standard user could create files and folders in the root and in cache.
  • After the install and the first run: the folder is protected and owned by SYSTEM, and the user's files are gone. A second attempt by the same standard user is denied everywhere.
  • Program Files was already read-only for users.
  • A new build ran its baseline although the last one finished minutes earlier. The same build then skipped.
  • dotnet test: 97 pass.

…nd lock down the data directory

Throttle: a baseline is exempt from BaselineMinIntervalHours whenever the
running BootstrapMate has not completed one and has not yet tried. Once the
new build has tried and failed, the 24-hour retry rule applies to it, so a
failing build cannot loop. An interrupted baseline runs again at the next
trigger; only failed and partial_failure wait. Retries come only from the
normal triggers: BootstrapMate never relaunches itself. baseline.json gains
tool_version (last completed) and attempt_version (last tried).

Data directory: C:\ProgramData\ManagedBootstrap inherited ProgramData's ACL,
which lets any user create files and folders in it. The MSI now gives it its
own ACL (owner SYSTEM; SYSTEM and Administrators full control; Users read),
and before each run the CLI resets the same ACL, removes links, and removes
anything a non-administrator owns. Logs written by an elevated administrator
are kept and re-owned rather than removed.
@rodchristiansen
rodchristiansen merged commit 303647e into main Oct 5, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant