Objective
Keep secret-free read-only propr connect status discovery independent of MSI/admin/native execution, while completing privileged Windows authority hardening as a separate post-discovery child.
Scope
- The ordinary status JSON contract must execute no package-controlled native binary and require no installed service or elevation.
- Own the machine-wide LocalSystem service/MSI, reciprocal named-pipe server authentication, standard-user access, bounded expiring replay state, per-identity/global capacity, read deadlines, service SID/image/hash/signer/ACL validation, install/repair/upgrade/uninstall and actionable absence/version errors.
- Prove service-absent pipe squatting, replay, cache exhaustion, partial-client starvation, image/path replacement, ACL downgrade and non-admin client behavior on hosted Windows.
- Gate the service only around privileged native launch/operations; never make it a dependency of endpoint auto-discovery.
Dependency and integration
Start only after the minimal service-free discovery contract from #1987/#1989 is integrated into the transport epic. Add the AI label and the then-current transport descendant base label before implementation. Require exact-head Ultrafix and native Windows MSI tests. Never target or merge directly to main.
Part of #1950, #1953, #1985, and #1987.
Objective
Keep secret-free read-only propr connect status discovery independent of MSI/admin/native execution, while completing privileged Windows authority hardening as a separate post-discovery child.
Scope
Dependency and integration
Start only after the minimal service-free discovery contract from #1987/#1989 is integrated into the transport epic. Add the AI label and the then-current transport descendant base label before implementation. Require exact-head Ultrafix and native Windows MSI tests. Never target or merge directly to main.
Part of #1950, #1953, #1985, and #1987.