| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
REA ships one Windows x64 Node-API 8 addon. Users do not compile it or install another runtime. Ghidra and a full JDK remain bring-your-own prerequisites. The addon uses Windows 10+ APIs and admits fixed local NTFS volumes only.
The package owns the artifact path. The loader checks the package version, ABI, Node-API compatibility, PE architecture, and SHA-256 before loading it. There is no environment override for loading an arbitrary native module.
The artifact lane requires Linux, MinGW-w64 x86_64-w64-mingw32-g++, x86_64-w64-mingw32-dlltool, and tar. It never installs these commands. Node-API headers are reused from the build cache or downloaded from the pinned official Node release with its published SHA-256 checked.
npm run build:windows-native
npm run verify:windows-native:artifact
npm packbuild/ is ignored by Git. The npm file inventory includes only the addon and its manifest. Release CI builds both, and prepublishOnly rejects a missing, stale, mismatched, or wrong-architecture artifact. A development tarball built without this lane reports Windows native controls as unavailable.
Windows failures retain their constraint, requested coordinate, Win32 code, and system message. Unsupported filesystems and reparse paths are distinct from OS access denial and missing packaged controls.
The bearer-token descriptor remains under its immutable private lease until runtime_close on Windows; POSIX removes the descriptor after the bridge reads it. Job ownership guarantees process termination on owner death, not deletion of private files after a crash. SUBST drive aliases and changing DOS-device namespaces are outside the verified P0 scope and are not detected as a separate alias policy. Mounted-folder paths that report a reparse tag are rejected by component admission; broader namespace variants remain unverified. Preserve requested and final handle coordinates rather than treating them as one identity.
npm run verify:windows-native
npm run verify:ghidra:windowsThe native lane checks DACL readback independently, source write/replacement rejection, unrelated sibling renames, reparse rejection, immutable snapshots, asynchronous cancellation, cleanup containment, descendant termination, unrelated-process preservation, normal exit, owner close, and forced owner exit. An optional independently built tests/fixtures/windows/processBoundary.cc executable adds breakaway and caller/child token observations and an in-place ancestor reparse attempt:
node scripts/verify-windows-native.mjs . C:\fixtures\process-boundary.exenonAdminRunner.cc is a test-only launcher for an elevated development shell. It duplicates an existing non-elevated Explorer token belonging to the same user, creates private temporary window-station objects, and launches the test inside a kill-on-close fixture job. It does not create accounts, modify host policy, or change the caller's token. A real-provider claim must additionally verify the packaged CLI and MCP on that ordinary-user token.
| Back | FazBrowse Home | New Git URL |