Repository navigation
Update the DACL to only allow access to the user when creating virtual disks - #41678
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The ACL test reuses a VHD path across iterations and needs unique-path cleanup.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
This pull request restricts newly created virtual disks to the creating user and uses impersonation for VM access management.
Changes:
- Applies protected, user-only DACLs to new VHDs.
- Updates VHD access and revocation to use user impersonation.
- Adds permission validation tests.
| File | Summary |
|---|---|
test/windows/UnitTests.cpp |
Adds VHD ACL validation tests; the reviewed test needs unique paths and cleanup per iteration. |
src/windows/service/exe/WslCoreVm.cpp |
Uses user impersonation for VHD access operations. |
src/windows/service/exe/HcsVirtualMachine.cpp |
Passes user tokens during disk cleanup. |
src/windows/common/WslCoreFilesystem.h |
Documents the updated VHD permission contract. |
src/windows/common/WslCoreFilesystem.cpp |
Creates protected, user-only VHD ACLs. |
src/windows/common/hcs.hpp |
Extends the revoke-access API with an optional token. |
src/windows/common/hcs.cpp |
Impersonates users during access revocation. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Preserve service-identity fallback for inaccessible VHDs and fix the test to verify the original filesystem path.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 2
Open (2)
Resolved since last review (1)
Ben Hillis (benhillis)
left a comment
There was a problem hiding this comment.
The product change looks reasonable, but the new non-elevated regression path uses GetNonElevatedToken(TokenPrimary), which only lowers integrity and leaves an elevated process's administrator groups enabled. Please use the restricted impersonation-token-to-primary-token pattern so the test actually validates the user-only access path.



Summary of the Pull Request
This change updates the DACL passed to CreateVirtualDisk() to grant full access only to the creating user and BUILTIN\Administrators, with inherited access disabled. Administrator access preserves compatibility with older WSL versions that open VHDs as SYSTEM, whose token includes the Administrators group.
PR Checklist
Detailed Description of the Pull Request / Additional comments
Validation Steps Performed