Skip to content

fix(atomics): retain Windows YARA fixtures until scanning can finish - #55

Merged
Karib0u merged 2 commits into
mainfrom
fix/windows-atomic-fixture-lifetime
Sep 11, 2026
Merged

fix(atomics): retain Windows YARA fixtures until scanning can finish#55
Karib0u merged 2 commits into
mainfrom
fix/windows-atomic-fixture-lifetime

Conversation

@Karib0u

@Karib0u Karib0u commented Sep 10, 2026

Copy link
Copy Markdown
Owner

Windows YARA atomics delete their fixture executables immediately after process exit. The asynchronous scanner then reports missing paths and the same three atomics fail on main and engine PR #467.

Keep fixtures available for five seconds after execution, fail on setup errors, and always remove them in a finally block. No detection assertion or failure policy is relaxed.

Validation: all rules CI checks passed, including Linux, macOS, and Windows. All three Windows YARA fixtures now pass; Windows reports 28/29 detections with the existing allowed EICAR miss unchanged. Engine PR Karib0u/rustinel#467 pins this commit and runs its own atomic suite.

@Karib0u
Karib0u merged commit be877b7 into main Sep 11, 2026
5 checks passed
@Karib0u
Karib0u deleted the fix/windows-atomic-fixture-lifetime branch September 11, 2026 17:28
Karib0u added a commit to Karib0u/rustinel that referenced this pull request Sep 11, 2026
CI pinned 5b8f001, a commit on the unmerged fix/windows-atomic-fixture-lifetime
branch, and release pinned c1d78b4, which predates that fix. The fix is now
merged as be877b7 (Karib0u/rustinel-rules#55), so both workflows run the same
atomic suite from the rules repository's main branch.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant