From 45fd98f34408e02a0c07da185aeb40e5100246bc Mon Sep 17 00:00:00 2001 From: Atos Lins Date: Fri, 18 Sep 2026 07:49:06 -0300 Subject: [PATCH] Report why Windows VM directory hardening failed The mode check returned 1 without any output, so a launch from the app menu died after the polkit prompt with nothing to diagnose. Name each source directory and the mode it was left with. --- bin/omarchy-windows-vm | 1 + test/shell.d/windows-vm-mount-boundary-test.sh | 10 ++++++++++ 2 files changed, 11 insertions(+) diff --git a/bin/omarchy-windows-vm b/bin/omarchy-windows-vm index c1fbbf9e..96a8d575 100755 --- a/bin/omarchy-windows-vm +++ b/bin/omarchy-windows-vm @@ -592,6 +592,7 @@ prepare_caller_mounts() { if [[ $storage_mode != 700 || $shared_mode != 700 ]]; then exec {storage_fd}<&- exec {shared_fd}<&- + echo "omarchy-windows-vm: could not make the VM data directories private: $LEGACY_STORAGE is mode ${storage_mode:-unknown}, $LEGACY_SHARED is mode ${shared_mode:-unknown} (expected 700)" >&2 return 1 fi diff --git a/test/shell.d/windows-vm-mount-boundary-test.sh b/test/shell.d/windows-vm-mount-boundary-test.sh index 531e2ced..591dec41 100644 --- a/test/shell.d/windows-vm-mount-boundary-test.sh +++ b/test/shell.d/windows-vm-mount-boundary-test.sh @@ -160,6 +160,16 @@ with_vm_lock prepare_caller_mounts || fail "root could not rebind setgid sources mounts_ready || fail "final guard rejected rebound setgid sources" pass "hardening clears the setuid/setgid bits a numeric chmod keeps on directories" +# When hardening still leaves a source non-private, the rejection names the +# directory and its mode instead of failing silently. +chmod() { command chmod "$@" && command chmod g+s /home/shared-target; } +hardening_error=$(with_vm_lock prepare_caller_mounts 2>&1) && fail "root accepted a source that stayed setgid after hardening" +unset -f chmod +[[ $hardening_error == *"/home/alice/Windows is mode 2700"* ]] || fail "setgid rejection did not name the directory and mode: $hardening_error" +chmod g-s /home/shared-target +mounts_ready || fail "verified anchors were disturbed by the rejected hardening" +pass "a source that cannot be made private is rejected with its path and mode" + expected_space=$(command df -P -- /home/storage-target | awk 'NR==2 {print int($4/1024/1024)}') actual_space=$(available_storage_gb) [[ $actual_space == "$expected_space" ]] || fail "disk-space helper did not measure the storage target filesystem"