Skip to content

fix: windows-safe config discovery and OS-independent policy globs - #599

Merged
wagoodman merged 1 commit into
mainfrom
fix/windows-config-and-policy-globs
Oct 2, 2026
Merged

wagoodman merged 1 commit into
mainfrom
fix/windows-config-and-policy-globs

Conversation

@wagoodman

Copy link
Copy Markdown
Contributor

Two pre-existing issues that start to matter once grant ships windows binaries (#440). Safe to land before or alongside it.

  • skip the /etc/xdg default for XDG_CONFIG_DIRS on windows. there it resolves to \etc\xdg at the drive root, which any local user can create, so a planted grant.yaml could override the user's policy. an explicit XDG_CONFIG_DIRS is still honored
  • match allow and ignore-packages patterns with path.Match instead of filepath.Match, so results are the same on every OS. linux and mac are unchanged. on windows * no longer crosses / (e.g. github.com/*/foo no longer matches github.com/a/b/foo) and a backslash is now an escape
  • the pattern syntax is now documented on Policy

@wagoodman wagoodman added the bug Something isn't working label Oct 2, 2026
- skip the `/etc/xdg` default for `XDG_CONFIG_DIRS` on windows. there it resolves to `\etc\xdg` at the drive root, which any local user can create, so a planted `grant.yaml` could override the user's policy. an explicit `XDG_CONFIG_DIRS` is still honored
- match `allow` and `ignore-packages` patterns with `path.Match` instead of `filepath.Match`, so results are the same on every OS. on windows this means `*` no longer crosses `/` and a backslash is now an escape, matching linux and mac
- document the pattern syntax on `Policy`

Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
@wagoodman
wagoodman force-pushed the fix/windows-config-and-policy-globs branch from 9bcd54d to 841f8b7 Compare October 2, 2026 16:55
@wagoodman
wagoodman merged commit ed6b323 into main Oct 2, 2026
16 checks passed
@wagoodman
wagoodman deleted the fix/windows-config-and-policy-globs branch October 2, 2026 20:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant