Files
msd-core/gsd-core/workflows
Tom Boucher 79ed181ec0 fix(#2667): run-with-timeout mediates .cmd/.bat spawns on Windows (CVE-2024-27980); fallow pre-pass names failure kind (#2897)
* fix(#2667): mediate .cmd/.bat/.exe spawns on Windows; split fallow pre-pass failure diagnostic

run-with-timeout spawned .cmd/.bat/.exe commands without shell:true on Windows,
tripping Node's CVE-2024-27980 EINVAL (April 2024 security hardening). The fallow
structural pre-pass then no-op'd silently — a hard execution failure read the same
as 'optional dependency absent'.

(A) gsd-core/bin/gsd-tools.cjs runWithTimeout: gate shell:true on
    (win32 && command ends in .cmd/.bat/.exe). Narrow by design — never fires for
    the 7 `bash -c` callers (command is `bash`, no such suffix), so the recorded
    no-shell-for-argv-array security contract (DEFECT.UNBOUNDED-SUBPROCESS) is
    preserved; cmdArgs stays an array. POSIX untouched.
(B) code-review.md fallow pre-pass: name the failure KIND (timeout / spawn failure
    / crash / not-found) so a Windows .cmd spawn failure is not mistaken for an
    absent binary.

Regression test in tests/run-with-timeout.test.cjs gated to win32 (.cmd/.bat/.exe
shims run with exit 0 + non-empty stdout; pre-fix EINVAL → exit 125/empty). POSIX
negative-space test guards the unchanged bash -c callers.

* chore(#2667): changeset fragment

* chore(#2667): backfill changeset PR 2897 + correct body (cmd.exe array, not shell:true)

* fix(#2667): exclude .exe from the win32 spawn-mediation gate; ack code-review.md growth

CI caught two failures on the first push:

1. windows-24: 'exits 124 when the wall-clock budget is exceeded' regressed. The
   gate matched .exe, so the HANG command (node.exe -e 'setTimeout(...)') was
   wrapped in 'cmd.exe /c node.exe ...' — the wrapped child escaped the timeout
   cap's process-group reap (exit 124 never fired; hit the 30s harness backstop)
   AND cmd.exe risked mis-parsing the -e script arg. .exe is INTENTIONALLY
   excluded now: real PE executables spawn fine directly; only .cmd/.bat are the
   CVE-2024-27980 EINVAL cases. The .exe test becomes a negative-space test
   (node.exe spawned directly, exit 0).

2. ubuntu-22: emitted-attribution — code-review.md grew 1177 bytes from the
   #2667 fallow pre-pass failure-KIND case statement; acknowledge it.

---------

Co-authored-by: Test <test@example.com>
2026-07-30 23:14:17 -04:00
..